Lumen Analytics runs several public-facing ALBs across multiple Regions. Their ACM public certificates use email validation and renewals often fail due to quarantined emails, causing outages. They want fully automated certificate renewal and deployment to ALBs with no manual steps. What should they do?
Choose an answer
Tap an option to check your answer.
Correct answer: Request new ACM public certificates using DNS validation, place the CNAME records in Route 53 for the domains, attach the certificates to ALBs, and rely on ACM to auto-renew and deploy them..
Why this is the answer
The correct option is to request new ACM public certificates using DNS validation because it fully automates renewal and deployment to ALBs without manual intervention. DNS validation involves placing CNAME records in Route 53, allowing ACM to automatically validate domain ownership and renew certificates. This eliminates the problem of quarantined validation emails. The other options are incorrect because: continuing email validation with SES still relies on email, which can be unreliable; ACM Private CA is for private certificates, not public-facing ones; and generating CSRs with OpenSSL and using a Lambda function introduces manual steps and complexity that ACM's integrated solution avoids.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed