How to Deploy ACM SSL Certificates to ALBs Across Multiple AWS Regions?
A developer needs to deploy an application in three AWS Regions by using AWS CloudFormation. Each Region will use an AWS Elastic Beanstalk environment with an Application Load Balancer (ALB). The developer wants to use AWS Certificate Manager (ACM) to deploy SSL certificates to each ALB. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the fundamental understanding that ACM certificates are regional resources, and there is no such thing as a 'global' ACM certificate for use with ALBs.
AWS Certificate Manager (ACM) certificates are regional resources, not global. To secure Application Load Balancers in multiple AWS Regions, you must provision or import a separate ACM certificate in each target Region.
Many candidates choose Option D, mistakenly believing that creating a certificate in us-east-1 and referencing it globally is sufficient, or Option B, confusing ACM's global nature for CloudFront (which only requires a us-east-1 certificate) with its regional nature for ALBs.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
The correct answer is C. To understand why, you must know the core architectural behavior of AWS Certificate Manager (ACM). ACM certificates are regional resources. This means a certificate requested or imported in us-east-1 exists only in us-east-1 and cannot be referenced by an Application Load Balancer (ALB) in eu-west-1.
Because the developer is deploying ALBs in three different AWS Regions, they must have a valid SSL/TLS certificate present in each of those three Regions. Therefore, the developer must create (request or import) a certificate in ACM within each of the three target Regions and associate the respective regional certificate with the ALB in that same Region via the CloudFormation template.
Why the other options are incorrect:
- Option A is incorrect because it suggests creating a certificate in only one Region and importing it into ALBs across different Regions. You cannot attach a certificate from
us-east-1to an ALB inap-southeast-1. - Option B is incorrect because there is no such thing as a "global certificate" in ACM for use with ALBs. While ACM integrates with CloudFront (which requires the certificate to be specifically in
us-east-1), ALBs require regional certificates.
us-east-1 Region. However, for Application Load Balancers, the certificate must reside in the same Region as the ALB.As noted by the community, the AWS documentation explicitly states: "Certificates in ACM are regional resources. To use a certificate with Elastic Load Balancing for the same fully qualified domain name (FQDN) or set of FQDNs in more than one AWS region, you must request or import a certificate for each region."
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →