How to Deploy ACM SSL Certificates to ALBs Across Multiple AWS Regions?

A developer needs to deploy an application in three AWS Regions by using AWS CloudFormation. Each Region will use an AWS Elastic Beanstalk environment with an Application Load Balancer (ALB). The developer wants to use AWS Certificate Manager (ACM) to deploy SSL certificates to each ALB. Which solution will meet these requirements?

  1. Create a certificate in ACM in any one of the Regions. Import the certificate into the ALB that is in each Region.
  2. Create a global certificate in ACM. Update the CloudFormation template to deploy the global certificate to each ALB.
  3. Create a certificate in ACM in each Region. Import the certificate into the ALB for each Region. Source Reference Answer
  4. Create a certificate in ACM in the us-east-1 Region. Update the CloudFormation template to deploy the certificate to each ALB.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the fundamental understanding that ACM certificates are regional resources, and there is no such thing as a 'global' ACM certificate for use with ALBs.

AWS Certificate Manager (ACM) certificates are regional resources, not global. To secure Application Load Balancers in multiple AWS Regions, you must provision or import a separate ACM certificate in each target Region.

Many candidates choose Option D, mistakenly believing that creating a certificate in us-east-1 and referencing it globally is sufficient, or Option B, confusing ACM's global nature for CloudFront (which only requires a us-east-1 certificate) with its regional nature for ALBs.

Community Discussion (7 comments)

SerialiDr 👍 6 Selected: C
Regional Certificates: ACM certificates are regional resources. They cannot be shared across different Regions. Creating a certificate in each Region ensures proper certificate management and association with the ALBs. CloudFormation Integration: CloudFormation allows you to define resources and their configurations for individual Regions. Creating certificates within the template for each Region aligns well with this approach.
albert_kuo 👍 1 Selected: C
ACM is a regional service
Saurabh04 👍 1 Selected: D
Given the requirements and cost-effectiveness, I recommend Option D—create a certificate in ACM in the us-east-1 Region and update the CloudFormation template to deploy the certificate to each ALB. This way, you maintain consistency while minimizing certificate management overhead.
65703c1 👍 1 Selected: C
C is the correct answer.
KarBiswa 👍 2 Selected: C
https://docs.aws.amazon.com/elasticloadbalancing/latest/application/create-https-listener.html
nder 👍 2 Selected: C
Certificates in ACM are regional resources. To use a certificate with Elastic Load Balancing for the same fully qualified domain name (FQDN) or set of FQDNs in more than one AWS region, you must request or import a certificate for each region.
tgv 👍 4 Selected: C
The correct solution is to create a certificate in each Region and to assign it to each ALB.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

The correct answer is C. To understand why, you must know the core architectural behavior of AWS Certificate Manager (ACM). ACM certificates are regional resources. This means a certificate requested or imported in us-east-1 exists only in us-east-1 and cannot be referenced by an Application Load Balancer (ALB) in eu-west-1.

Because the developer is deploying ALBs in three different AWS Regions, they must have a valid SSL/TLS certificate present in each of those three Regions. Therefore, the developer must create (request or import) a certificate in ACM within each of the three target Regions and associate the respective regional certificate with the ALB in that same Region via the CloudFormation template.

Why the other options are incorrect:

  • Option A is incorrect because it suggests creating a certificate in only one Region and importing it into ALBs across different Regions. You cannot attach a certificate from us-east-1 to an ALB in ap-southeast-1.
  • Option B is incorrect because there is no such thing as a "global certificate" in ACM for use with ALBs. While ACM integrates with CloudFront (which requires the certificate to be specifically in us-east-1), ALBs require regional certificates.
Option D is a common trap. Candidates often confuse ALB requirements with CloudFront requirements. For Amazon CloudFront, you must* use an ACM certificate in the us-east-1 Region. However, for Application Load Balancers, the certificate must reside in the same Region as the ALB.

As noted by the community, the AWS documentation explicitly states: "Certificates in ACM are regional resources. To use a certificate with Elastic Load Balancing for the same fully qualified domain name (FQDN) or set of FQDNs in more than one AWS region, you must request or import a certificate for each region."

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide