Provisioning IoT devices with a pre-provisioning hook that validates the X.509 serial number

Answer Correct answer: C — Use a Lambda pre-provisioning hook to validate the serial number and enable auto-registration so the device is provisioned only on first connection.

A retail company is mounting IoT sensors in all of its stores worldwide. During the manufacturing of each sensor, the company’s private certificate authority (CA) issues an X.509 certificate that contains a unique serial number. The company then deploys each certificate to its respective sensor. A solutions architect needs to give the sensors the ability to send data to AWS after they are installed. Sensors must not be able to send data to AWS until they are installed. Which solution will meet these requirements?

  1. Create an AWS Lambda function that can validate the serial number. Create an AWS IoT Core provisioning template. Include the SerialNumber parameter in the Parameters section. Add the Lambda function as a pre-provisioning hook. During manufacturing, call the RegisterThing API operation and specify the template and parameters.
  2. Create an AWS Step Functions state machine that can validate the serial number. Create an AWS IoT Core provisioning template. Include the SerialNumber parameter in the Parameters section. Specify the Step Functions state machine to validate parameters. Call the StartThingRegistrationTask API operation during installation.
  3. Create an AWS Lambda function that can validate the serial number. Create an AWS IoT Core provisioning template. Include the SerialNumber parameter in the Parameters section. Add the Lambda function as a pre-provisioning hook. Register the CA with AWS IoT Core, specify the provisioning template, and set the allow-auto-registration parameter. Correct Answer
  4. Create an AWS IoT Core provisioning template. Include the SerialNumber parameter in the Parameters section. Include parameter validation in the template. Provision a claim certificate and a private key for each device that uses the CA. Grant AWS IoT Core service permissions to update AWS IoT things during provisioning.

Community Votes

C
84%
D
16%

84% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A Lambda pre-provisioning hook validates device attributes (here, the serial number) during provisioning; with auto-registration the thing is created only when the device first connects, satisfying the 'no data until installed' requirement.

Sensors ship with an X.509 certificate from a private CA and must not connect until installed. AWS IoT Core Fleet Provisioning with a Lambda pre-provisioning hook validates the SerialNumber parameter before a thing is registered, and auto-registration provisions the device only on its first connection at install time.

Calling RegisterThing during manufacturing (Option A) provisions the thing at manufacturing time, violating the requirement that devices cannot send data until they are installed.

Community Discussion (10 comments)

kejam 👍 8 Selected: C
In addition to validating the bootstrap certificate presented by devices, Fleet Provisioning also provides Lambda-based provisioning hooks that enable appropriate validation for pertinent device attributes. Examples of device attributes could include a serial number ... https://aws.amazon.com/blogs/iot/how-to-automate-onboarding-of-iot-devices-to-aws-iot-core-at-scale-with-fleet-provisioning/
TomTom 👍 1 Selected: A
Option A, meet the requirements. Why Not C, because C mentioned as Auto Provisioing, while the requirements is to have control.
titi_r 👍 1 Selected: C
Correct ans - C.
career360guru 👍 1 Selected: C
Option C
duriselvan 👍 1
https://docs.aws.amazon.com/iot/latest/developerguide/iot-provision.html
duriselvan 👍 1
AWS provides several different ways to provision a device and install unique client certificates on it. This section describes each way and how to select the best one for your IoT solution. These options are described in detail in the whitepaper titled Device Manufacturing and Provisioning with X.509 Certificates in AWS IoT Core.
duriselvan 👍 3
cANSGiven the requirements, Option C is the most suitable solution: It combines serial number validation using a Lambda function. The pre-provisioning hook ensures validation before registration. The allow-auto-registration parameter provides fine-grained control over auto-registration.
ele 👍 2 Selected: D
Devices can be manufactured with a provisioning claim certificate and private key (which are special purpose credentials) embedded in them. If these certificates are registered with AWS IoT, the service can exchange them for unique device certificates that the device can use for regular operations https://docs.aws.amazon.com/iot/latest/developerguide/provision-wo-cert.html#claim-based
duriselvan 👍 1
C is ans
alexis123456 👍 2
Correct Answer is D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C uses a Lambda pre-provisioning hook to validate the SerialNumber parameter, registers the private CA with IoT Core, and enables auto-registration. Auto-registration means the device is provisioned (thing created and policy attached) only when it first connects at installation, so it cannot send data before being installed. The pre-provisioning hook enforces that the certificate's serial number matches the expected value.

Why the Other Options Are Wrong

Option A calls RegisterThing during manufacturing, which provisions the thing at manufacturing time and breaks the 'not until installed' rule. Option B uses a Step Functions state machine rather than the supported Lambda pre-provisioning hook and calls StartThingRegistrationTask during installation without the serial-validation hook. Option D relies on claim certificates and template parameter validation but lacks the Lambda hook that validates the serial number against the CA-issued certificate.

Community Comment Notes

kejam highlights that Fleet Provisioning provides Lambda-based provisioning hooks for validating device attributes. The majority vote is C (77) over D (15). TomTom argues A meets the requirements, but A's manufacturing-time RegisterThing conflicts with the install-gated requirement.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide