AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard

A company needs to provision and manage public SSL/TLS certificates for its Application Load Balancer at no additional cost, with automatic renewal. Which AWS service should the company use?

  1. AAWS Secrets Manager
  2. BAWS Key Management Service (KMS)
  3. CAWS Identity and Access Management (IAM)
  4. DAWS Certificate Manager (ACM)
Show answer & explanation

Correct answer: D. AWS Certificate Manager (ACM)

AWS Certificate Manager (ACM) provisions, manages, and automatically renews public SSL/TLS certificates for use with AWS services like Application Load Balancer, CloudFront, and API Gateway, at no additional cost for public certificates.

Why the other options are wrong

  • A. Secrets Manager stores secrets like credentials, not certificate issuance/renewal.
  • B. KMS manages encryption keys, not TLS certificates.
  • C. IAM manages identities and permissions, not certificates.

AWS Certificate Manager (ACM)

A service that provisions, manages, and automatically renews public and private SSL/TLS certificates for use with AWS services.

  • Public certificates are free when used with supported AWS services
  • Automatic renewal avoids expired certificate outages
  • Integrates with ALB, CloudFront, API Gateway

Memory trick: ACM = Automatic Certificate Maintenance, free and renewed.

More Security and Compliance questions