Provisioning IoT devices with a pre-provisioning hook that validates the X.509 serial number
A retail company is mounting IoT sensors in all of its stores worldwide. During the manufacturing of each sensor, the company’s private certificate authority (CA) issues an X.509 certificate that contains a unique serial number. The company then deploys each certificate to its respective sensor. A solutions architect needs to give the sensors the ability to send data to AWS after they are installed. Sensors must not be able to send data to AWS until they are installed. Which solution will meet these requirements?
Community Votes
84% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A Lambda pre-provisioning hook validates device attributes (here, the serial number) during provisioning; with auto-registration the thing is created only when the device first connects, satisfying the 'no data until installed' requirement.
Sensors ship with an X.509 certificate from a private CA and must not connect until installed. AWS IoT Core Fleet Provisioning with a Lambda pre-provisioning hook validates the SerialNumber parameter before a thing is registered, and auto-registration provisions the device only on its first connection at install time.
Calling RegisterThing during manufacturing (Option A) provisions the thing at manufacturing time, violating the requirement that devices cannot send data until they are installed.
Community Discussion (10 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option C uses a Lambda pre-provisioning hook to validate the SerialNumber parameter, registers the private CA with IoT Core, and enables auto-registration. Auto-registration means the device is provisioned (thing created and policy attached) only when it first connects at installation, so it cannot send data before being installed. The pre-provisioning hook enforces that the certificate's serial number matches the expected value.Why the Other Options Are Wrong
Option A calls RegisterThing during manufacturing, which provisions the thing at manufacturing time and breaks the 'not until installed' rule. Option B uses a Step Functions state machine rather than the supported Lambda pre-provisioning hook and calls StartThingRegistrationTask during installation without the serial-validation hook. Option D relies on claim certificates and template parameter validation but lacks the Lambda hook that validates the serial number against the CA-issued certificate.Community Comment Notes
kejam highlights that Fleet Provisioning provides Lambda-based provisioning hooks for validating device attributes. The majority vote is C (77) over D (15). TomTom argues A meets the requirements, but A's manufacturing-time RegisterThing conflicts with the install-gated requirement.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →