How to Notify Before an Imported ACM Certificate Expires?

A company generates SSL certificates from a third-party provider. The company imports the certificates into AWS Certificate Manager (ACM) to use with public web applications. A developer must implement a solution to notify the company’s security team 90 days before an imported certificate expires. The company already has configured an Amazon Simple Queue Service (Amazon SQS) queue. The company also has configured an Amazon Simple Notification Service (Amazon SNS) topic that has the security team’s email address as a subscriber. Which solution will provide the security team with the required notification about certificates?

  1. Create an Amazon EventBridge rule that specifies the ACM Certificate Approaching Expiration event type. Set the SNS topic as the EventBridge rule’s target.
  2. Create an AWS Lambda function to search for all certificates that are expiring within 90 days. Program the Lambda function to send each identified certificate’s Amazon Resource Name (ARN) in a message to the SQS queue.
  3. Create an AWS Step Functions workflow that is invoked by each certificate’s expiration notification from AWS CloudTrail. Create an AWS Lambda function to send each certificate's Amazon Resource Name (ARN) in a message to the SQS queue.
  4. Configure AWS Config with the acm-certificate-expiration-check managed rule to run every 24 hours. Create an Amazon EventBridge rule that includes an event pattern that specifies the Config Rules Compliance Change detail type and the configured rule. Set the SNS topic as the EventBridge rule’s target. Source Reference Answer

Community Votes

D
60%
A
40%

60% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the subtle difference between ACM-issued and ACM-imported certificates: only ACM-issued certificates emit the 'ACM Certificate Approaching Expiration' EventBridge event, so imported certificates require AWS Config to detect upcoming expiration.

Imported third-party certificates in AWS Certificate Manager (ACM) do not trigger the native 'ACM Certificate Approaching Expiration' EventBridge event. To get a 90-day expiration notification for imported certificates, use the AWS Config managed rule acm-certificate-expiration-check and route Config compliance change events through Amazon EventBridge to an SNS topic.

Many candidates choose Option A, assuming the ACM Certificate Approaching Expiration EventBridge event works for all certificates in ACM. In reality, this event is only emitted for certificates that ACM itself issued and manages renewal for; imported certificates never emit it.

Community Discussion (3 comments)

Dadasar 👍 1 Selected: D
A resposta correta é:D. A. Errado, porque esse evento só é gerado para certificados emitidos pelo ACM. Como a empresa está usando certificados importados, esse evento nunca será disparado. B. Ineficiente, pois exigiria que o Lambda varresse manualmente todos os certificados periodicamente. O AWS Config já faz isso automaticamente. C. Errado, porque o AWS CloudTrail não gera eventos de expiração de certificados no ACM.
italiancloud2025 👍 2 Selected: D
Aunque Amazon EventBridge puede capturar ciertos eventos de ACM, en la práctica el evento ACM Certificate Approaching Expiration se genera únicamente para certificados emitidos y administrados por ACM. Los certificados importados, que son aquellos generados por terceros y luego importados a ACM, no generan ese evento. Por ello, utilizar una regla de EventBridge para capturar el evento de expiración no funcionaría para certificados importados, lo que hace que la opción A no cumpla con el requisito en este caso.
e886835 👍 2 Selected: A
Amazon EventBridge can capture events such as the expiration of SSL certificates imported into AWS Certificate Manager (ACM). The specific event type you are interested in is the ACM Certificate Approaching Expiration event, which is triggered when a certificate in ACM is approaching its expiration date. EventBridge allows you to define rules for such events and trigger actions such as sending a notification to an SNS topic.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why Option D Is Correct

The key detail in the question is that the certificates are imported from a third-party provider into AWS Certificate Manager (ACM). ACM treats ACM-issued and ACM-imported certificates differently when it comes to expiration notifications:

  • ACM-issued certificates are fully managed by AWS, including automatic renewal. For these, ACM emits the ACM Certificate Approaching Expiration event to Amazon EventBridge, typically 60 days before expiration.
  • ACM-imported certificates are not managed by ACM. AWS does not renew them, and — critically — ACM does not emit the Approaching Expiration event for them.
Because the company uses imported certificates, Option A cannot work. The correct approach is to use AWS Config with the managed rule acm-certificate-expiration-check. This rule evaluates whether ACM certificates (including imported ones) will expire within a configurable number of days (default is 90). When a certificate becomes non-compliant, AWS Config emits a Config Rules Compliance Change event, which can be captured by an Amazon EventBridge rule and forwarded to the existing SNS topic subscribed by the security team.

Why Option A Is Wrong

Option A looks elegant and is the reason ~40% of the community chooses it. However, the ACM Certificate Approaching Expiration EventBridge event is only generated for certificates issued by ACM. Imported certificates never trigger this event, so the SNS topic would never receive a notification. This is a classic exam trap that rewards reading the question carefully.

Why Option B Is Wrong

Option B proposes a custom Lambda function that periodically scans certificates. While technically feasible, it is:

  • Inefficient — it requires you to build, schedule, and maintain custom polling logic.
  • Not event-driven — you must manage scheduling (e.g., EventBridge rule invoking Lambda every 24 hours) and implement the expiration-date comparison yourself.
  • Redundant — AWS Config already provides a managed rule that does exactly this evaluation.
AWS best practices favor managed services (AWS Config) over custom polling for compliance-style checks.

Why Option C Is Wrong

Option C relies on AWS CloudTrail to emit certificate expiration notifications. CloudTrail logs API activity (e.g., ImportCertificate, RequestCertificate), not certificate lifecycle events like expiration. There is no CloudTrail event for "a certificate is about to expire," so a Step Functions workflow triggered by CloudTrail cannot work for this use case.

Community Consensus

The community is split (D: 60%, A: 40%), but the comments from experienced candidates clearly confirm that the Approaching Expiration event is not emitted for imported certificates, which eliminates Option A and makes Option D the only correct, AWS-recommended solution.

Official Reference

Exam Strategy

When an AWS question mentions 'imported' or 'third-party' resources (certificates, keys, etc.), immediately suspect that native AWS lifecycle events and auto-renewal features do NOT apply. Look for answers that use AWS Config, custom Lambda polling, or CloudWatch metric filters instead of the 'obvious' native event.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide