AWS Global Accelerator and Route 53 Configuration

A company has a web application that runs in eight AWS Regions. In each Region, the application is hosted on multiple compute resources behind an Application Load Balancer (ALB). The different Regions are using different domains. Each ALB is configured to accept only HTTPS traffic. Each ALB uses a certificate from AWS Certificate Manager (ACM). The company wants to simplify the application’s appearance on the web by using a new single domain for all Regions. A network engineer needs to implement this change by designing a solution that also will minimize latency for the application's end users. Which combination of actions will meet these requirements? (Choose three.)

  1. Use ACM to create an SSL/TLS certificate in the us-east-1 Region for the new domain.
  2. Set up latency-based routing in Amazon Route 53 for the new domain. Add the ALBs from all the Regions as targets.
  3. Create an alias record for the accelerator in Amazon Route 53 for the new domain. Source Reference Answer
  4. Create a standard accelerator in AWS Global Accelerator. Configure a listener for TCP traffic. Add all the ALBs as targets for the listener. Source Reference Answer
  5. Use ACM to create an SSLITLS certificate for each Region. Configure all the ALBs to use the certificate in their respective Regions. Source Reference Answer

Community Votes

CDE
75%
ACD
25%

75% of anonymous learners picked answer CDE. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the distinction between DNS-based routing (Route 53) and network-layer acceleration (Global Accelerator), highlighting the trap that Global Accelerator requires TCP/TLS listeners rather than HTTP/HTTPS termination at the accelerator level for ALBs.

This question tests the integration of AWS Global Accelerator with Application Load Balancers to provide a single domain entry point while minimizing latency. The community consensus is that Global Accelerator is superior to Route 53 for latency-sensitive applications due to its Anycast IP network, requiring specific listener configurations and alias records.

Candidates often choose ACD because they assume ACM certificates must be created in us-east-1 for global services or confuse API Gateway certificate requirements with Global Accelerator's behavior, failing to realize GA passes traffic through to regional ALBs which hold their own certs.

Community Discussion (4 comments)

youonebe 👍 1 Selected: ACD
For edge-optimized services like Global Accelerator, ACM certificates must be created in the us-east-1 Region. This certificate will be used for the single domain that will front all regional deployments. https://docs.aws.amazon.com/apigateway/latest/developerguide/how-to-specify-certificate-for-custom-domain-name.html
secdaddy 👍 1 Selected: AC
Accelerator better than Route 53 as anycast and not dependent on DNS and delay measurement. (A) GA uses single certificate that must be in us-east-1. Need the alias (C) for GA to work. (F) Custom accelerator terminates TLS using the new certificate from (A).
djangoGroup 👍 2 Selected: CDE
(C) Create an alias record for the accelerator in Route 53 for the new domain • This step stays the same. You want your users to resolve a single domain that leads to Global Accelerator. • (D) Create a standard accelerator in AWS Global Accelerator, configure a listener for TCP (or TLS pass-through), and add all the ALBs as endpoints • Also unchanged. A standard accelerator is how you route traffic at the edge into the correct Region. • (E) Use ACM to create an SSL/TLS certificate for each Region. Configure all the ALBs to use the certificate in their respective Regions • This step is correct if the Region supports ACM for requesting or importing a cert. • If not, you do manual certificate handling (import or direct upload).
c1193d4 👍 1 Selected: CDE
F: NO HTTPS listener available with GA A: NO global certificate is necessary is this case (see CloudFront) B: Could be a solution but GA improves latency more than Route53

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The correct combination is CDE. AWS Global Accelerator (GA) uses Anycast IPs to route traffic to the optimal AWS endpoint based on latency and health, making it ideal for multi-region apps where minimizing latency is critical (Option D). GA does not terminate TLS by default for ALB endpoints; instead, it listens on TCP or TLS pass-through, forwarding encrypted traffic to the regional ALBs which handle the actual SSL termination using their local ACM certificates (Option E). To expose this single global entry point, you must create a Route 53 Alias record pointing to the Global Accelerator DNS name (Option C).

Why the Other Options Are Wrong

Option A is incorrect because ACM certificates used directly by Global Accelerator are rare and typically only for CloudFront or API Gateway; for ALBs behind GA, regional certificates are standard. Option B is incorrect because while Route 53 Latency Routing works, it relies on DNS resolution and client-side retry logic, offering higher latency and less robust failover compared to GA’s persistent TCP connections. Option F is not listed but would be wrong if it suggested terminating TLS at GA for ALBs without proper configuration.

Community Comment Notes

Comment [1] correctly identifies that GA acts as the front door and ALBs remain the back-end endpoints. Comment [2] mistakenly applies API Gateway certificate rules to GA, leading to the wrong answer ACD. Comment [4] highlights the key differentiator: GA improves latency more than Route 53 due to its network layer advantages.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide