AWS Certified Cloud Practitioner (CLF-C02)Security and ComplianceHard
A company needs to provision and manage public SSL/TLS certificates for its Application Load Balancer at no additional cost, with automatic renewal. Which AWS service should the company use?
- AAWS Secrets Manager
- BAWS Key Management Service (KMS)
- CAWS Identity and Access Management (IAM)
- DAWS Certificate Manager (ACM)
Show answer & explanationAnswer & explanation
Correct answer: D. AWS Certificate Manager (ACM)
AWS Certificate Manager (ACM) provisions, manages, and automatically renews public SSL/TLS certificates for use with AWS services like Application Load Balancer, CloudFront, and API Gateway, at no additional cost for public certificates.
Why the other options are wrong
- A. Secrets Manager stores secrets like credentials, not certificate issuance/renewal.
- B. KMS manages encryption keys, not TLS certificates.
- C. IAM manages identities and permissions, not certificates.
AWS Certificate Manager (ACM)
A service that provisions, manages, and automatically renews public and private SSL/TLS certificates for use with AWS services.
- Public certificates are free when used with supported AWS services
- Automatic renewal avoids expired certificate outages
- Integrates with ALB, CloudFront, API Gateway
Memory trick: ACM = Automatic Certificate Maintenance, free and renewed.