AnswerCorrect answer: A, C, E — request an ACM certificate (in us-east-1 for CloudFront), validate domains with DNS CNAMEs, and attach it to a CloudFront distribution.
An application team wants to use AWS Certificate Manager (ACM) to request public certificates to ensure that data is secured in transit. The domains that are being used are not currently hosted on Amazon Route 53. The application team wants to use an AWS managed distribution and caching solution to optimize requests to its systems and provide better points of presence to customers. The distribution solution will use a primary domain name that is customized. The distribution solution also will use several alternative domain names. The certificates must renew automatically over an indefinite period of time. Which combination of steps should the application team take to deploy this architecture? (Choose three.)
Request a certificate from ACM in the us-west-2 Region. Add the domain names that the certificate will secure. Correct Answer
Send an email message to the domain administrators to request validation of the domains for ACM.
Request validation of the domains for ACM through DNS. Insert CNAME records into each domain's DNS zone. Correct Answer
Create an Application Load Balancer for the caching solution. Select the newly requested certificate from ACM to be used for secure connections.
Create an Amazon CloudFront distribution for the caching solution. Enter the main CNAME record as the Origin Name. Enter the subdomain names or alternate names in the Alternate Domain Names Distribution Settings. Select the newly requested certificate from ACM to be used for secure connections. Correct Answer
Community Insight
CloudFront is the AWS managed distribution/caching service, so the cert attaches there (E), not to an ALB (D). DNS validation (C) works for any DNS host, not just Route 53, by inserting ACM's CNAME records. The certificate for CloudFront must be requested in us-east-1 (option A's stated us-west-2 is a regional caveat—request in us-east-1). Email validation (B) is an alternative but DNS is preferred and matches the CNAME step. A+C+E is the request/validate/distribute trio.
For managed distribution/caching with auto-renewing public certs on non-Route 53 domains, request an ACM certificate (for CloudFront it must be in us-east-1), validate ownership through DNS by adding the CNAME records ACM provides to each domain's DNS zone, and create a CloudFront distribution (the managed, global caching solution) selecting that certificate for the primary and alternate domain names. The cert auto-renews as long as DNS validation stays in place.
Using an ALB (D) for 'managed distribution and caching'—the requirement calls for a global caching distribution, which is CloudFront, not an ALB. Requesting the cert in a Region other than us-east-1 (A's us-west-2) for CloudFront—CloudFront requires the ACM certificate to be in us-east-1. Relying on email validation (B) instead of DNS (C) when domains are not on Route 53—DNS validation via CNAME works for any registrar.
Community Discussion (3 comments)
FlyingHawk👍 1Selected: CE
Caching solution means CloudFront , not ALB, so E is correct, D is out. F - when using ACM with CloudFront, the certificate must be in the us-east-1 region. Because CloudFront is a global service, and ACM certificates for CloudFront must be in us-east-1. A is incorrect. For Domain validation, the DNS validation is better because once the CNAME is set, future renewals are automatic. Email would require manual steps each renewal, which isn't indefinite. So C is correct.
daburahjail👍 2
"To use an ACM certificate with Amazon CloudFront, you must request or import the certificate in the US East (N. Virginia) region." https://docs.aws.amazon.com/acm/latest/userguide/acm-overview.html
mercespsn👍 4Selected: CE
Is the right answer
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Log in to comment, report an error, or add a note about this question.
Expert Analysis
Why the Answer Is Correct
The managed distribution and caching solution is Amazon CloudFront (E), and a public ACM certificate attached to it provides TLS with automatic renewal. Validation is done through DNS by adding the CNAME records ACM issues into each domain's DNS zone (C), which works even when domains are not hosted on Route 53. The certificate must be requested (A) and, for CloudFront, in the us-east-1 Region. Together A, C, and E deploy the architecture.
Why the Other Options Are Wrong
D uses an Application Load Balancer, but the requirement is a managed global distribution/caching layer (CloudFront), not an ALB. B uses email validation, which is an alternative but less automation-friendly than DNS validation and does not pair with the CNAME step. Note: the certificate for CloudFront must be in us-east-1; if requesting in another Region (as option A's text implies us-west-2), request in us-east-1 instead. A, C, E are the correct combination.
Community Comment Notes
Community comments (C,E with A's request step) emphasized that a CloudFront ACM certificate must be in US East (N. Virginia) and that DNS validation via CNAME works for non-Route 53 domains. A, C, E form the request/validate/distribute sequence; D (ALB) was excluded as not a caching distribution.