ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 752 - SAA-C03 discussion

Report
Export

A company uses an Amazon CloudFront distribution to serve content pages for its website. The company needs to ensure that clients use a TLS certificate when accessing the company's website. The company wants to automate the creation and renewal of the Tl S certificates.

Which solution will meet these requirements with the MOST operational efficiency?

A.
Use a CloudFront security policy lo create a certificate.
Answers
A.
Use a CloudFront security policy lo create a certificate.
B.
Use a CloudFront origin access control (OAC) to create a certificate.
Answers
B.
Use a CloudFront origin access control (OAC) to create a certificate.
C.
Use AWS Certificate Manager (ACM) to create a certificate. Use DNS validation for the domain.
Answers
C.
Use AWS Certificate Manager (ACM) to create a certificate. Use DNS validation for the domain.
D.
Use AWS Certificate Manager (ACM) to create a certificate. Use email validation for the domain.
Answers
D.
Use AWS Certificate Manager (ACM) to create a certificate. Use email validation for the domain.
Suggested answer: C

Explanation:

Understanding the Requirement: The company needs to ensure clients use a TLS certificate when accessing the website and automate the creation and renewal of TLS certificates.

Analysis of Options:

CloudFront Security Policy: Not applicable for creating certificates.

CloudFront Origin Access Control (OAC): Controls access to origins, not relevant for TLS certificate creation.

AWS Certificate Manager (ACM) with DNS Validation: Provides automated certificate management, including creation and renewal, with minimal manual intervention. DNS validation is automated and does not require manual intervention as email validation does.

AWS Certificate Manager (ACM) with Email Validation: Requires manual intervention to approve validation emails, which increases operational effort.

Best Solution:

AWS Certificate Manager (ACM) with DNS Validation: Ensures automated and efficient certificate management with the least operational effort.

AWS Certificate Manager (ACM)

DNS Validation in ACM

asked 16/09/2024
Eduardo Efren Flores Riofrio
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first