A company runs applications on Amazon EC2 and needs to use SSL/TLS to encrypt traffic to AWS-managed infrastructure operated by a customer. The engineering team wants to simplify certificate creation, distribution, rotation, and automatic renewal and deployment. Which solution provides this with the least operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Use AWS Certificate Manager (ACM)..
Why this is the answer
AWS Certificate Manager (ACM) is the correct choice because it directly addresses the requirements for simplifying certificate creation, distribution, rotation, and automatic renewal and deployment with minimal operational overhead. ACM integrates seamlessly with other AWS services like Elastic Load Balancing (ELB) and Amazon CloudFront, allowing you to provision, manage, and deploy public and private SSL/TLS certificates. Storing and managing self-signed certificates directly on EC2 instances would create significant operational overhead, as it requires manual processes for creation, distribution, monitoring expiration, and renewal. Building custom automation in AWS Secrets Manager could manage certificate secrets, but it wouldn't handle the full lifecycle (issuance, deployment, and automatic renewal) as comprehensively or with as little effort as ACM. Amazon ECS Service Connect focuses on service-to-service communication within an ECS cluster and doesn't provide a general solution for managing SSL/TLS certificates for traffic to AWS-managed infrastructure.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed