Route 53 hosted zones are centrally managed in a shared AWS account. A developer in the development account needs a new TLS/SSL certificate for an application in that account. What is the correct way for the SysOps administrator to obtain and validate the certificate?
Choose an answer
Tap an option to check your answer.
Correct answer: Request the ACM certificate from the development account and have the shared account create the DNS validation records in the hosted zone in Route 53..
Why this is the answer
The correct approach is to request the ACM certificate from the development account because the certificate will be used by resources in that account. ACM certificates are regional and tied to the account that requests them. The shared account, which manages the Route 53 hosted zones, then needs to create the DNS validation records (CNAME records) in the appropriate hosted zone. This allows ACM to validate ownership of the domain without exposing the shared account's credentials to the development account. Incorrect options: Requesting the ACM certificate from the shared account would mean the certificate is owned by the shared account, complicating its use by resources in the development account. KMS keys are for encryption, not for certificate validation or management. Referencing a KMS key ARN in a Route 53 validation record is not a valid method for ACM certificate validation.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed