How to Notify Before an Imported ACM Certificate Expires?
A company generates SSL certificates from a third-party provider. The company imports the certificates into AWS Certificate Manager (ACM) to use with public web applications. A developer must implement a solution to notify the company’s security team 90 days before an imported certificate expires. The company already has configured an Amazon Simple Queue Service (Amazon SQS) queue. The company also has configured an Amazon Simple Notification Service (Amazon SNS) topic that has the security team’s email address as a subscriber. Which solution will provide the security team with the required notification about certificates?
Community Votes
60% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the subtle difference between ACM-issued and ACM-imported certificates: only ACM-issued certificates emit the 'ACM Certificate Approaching Expiration' EventBridge event, so imported certificates require AWS Config to detect upcoming expiration.
Imported third-party certificates in AWS Certificate Manager (ACM) do not trigger the native 'ACM Certificate Approaching Expiration' EventBridge event. To get a 90-day expiration notification for imported certificates, use the AWS Config managed rule acm-certificate-expiration-check and route Config compliance change events through Amazon EventBridge to an SNS topic.
Many candidates choose Option A, assuming the ACM Certificate Approaching Expiration EventBridge event works for all certificates in ACM. In reality, this event is only emitted for certificates that ACM itself issued and manages renewal for; imported certificates never emit it.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why Option D Is Correct
The key detail in the question is that the certificates are imported from a third-party provider into AWS Certificate Manager (ACM). ACM treats ACM-issued and ACM-imported certificates differently when it comes to expiration notifications:
- ACM-issued certificates are fully managed by AWS, including automatic renewal. For these, ACM emits the
ACM Certificate Approaching Expirationevent to Amazon EventBridge, typically 60 days before expiration. - ACM-imported certificates are not managed by ACM. AWS does not renew them, and — critically — ACM does not emit the Approaching Expiration event for them.
acm-certificate-expiration-check. This rule evaluates whether ACM certificates (including imported ones) will expire within a configurable number of days (default is 90). When a certificate becomes non-compliant, AWS Config emits a Config Rules Compliance Change event, which can be captured by an Amazon EventBridge rule and forwarded to the existing SNS topic subscribed by the security team.Why Option A Is Wrong
Option A looks elegant and is the reason ~40% of the community chooses it. However, the ACM Certificate Approaching Expiration EventBridge event is only generated for certificates issued by ACM. Imported certificates never trigger this event, so the SNS topic would never receive a notification. This is a classic exam trap that rewards reading the question carefully.
Why Option B Is Wrong
Option B proposes a custom Lambda function that periodically scans certificates. While technically feasible, it is:
- Inefficient — it requires you to build, schedule, and maintain custom polling logic.
- Not event-driven — you must manage scheduling (e.g., EventBridge rule invoking Lambda every 24 hours) and implement the expiration-date comparison yourself.
- Redundant — AWS Config already provides a managed rule that does exactly this evaluation.
Why Option C Is Wrong
Option C relies on AWS CloudTrail to emit certificate expiration notifications. CloudTrail logs API activity (e.g., ImportCertificate, RequestCertificate), not certificate lifecycle events like expiration. There is no CloudTrail event for "a certificate is about to expire," so a Step Functions workflow triggered by CloudTrail cannot work for this use case.
Community Consensus
The community is split (D: 60%, A: 40%), but the comments from experienced candidates clearly confirm that the Approaching Expiration event is not emitted for imported certificates, which eliminates Option A and makes Option D the only correct, AWS-recommended solution.
Official Reference
Exam Strategy
When an AWS question mentions 'imported' or 'third-party' resources (certificates, keys, etc.), immediately suspect that native AWS lifecycle events and auto-renewal features do NOT apply. Look for answers that use AWS Config, custom Lambda polling, or CloudWatch metric filters instead of the 'obvious' native event.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →