You have an API Gateway REST API in us-east-2 and want to front it with Amazon CloudFront using a custom domain. You have an SSL/TLS certificate from a third-party provider. How should you configure the custom domain and certificate?
Choose an answer
Tap an option to check your answer.
Correct answer: Import the certificate into ACM in the us-east-1 Region. Create a DNS CNAME record for the custom domain..
Why this is the answer
For CloudFront distributions using custom domains with SSL/TLS certificates, the certificate must be provisioned in AWS Certificate Manager (ACM) in the us-east-1 (N. Virginia) region, regardless of the CloudFront distribution's origin region. CloudFront is a global service, and us-east-1 serves as the canonical region for its certificate management. A CNAME record is used to map your custom domain to the CloudFront distribution's domain name (e.g., d1234.cloudfront.net). Incorrect options: Importing the certificate into ACM in us-east-2 is incorrect because CloudFront requires certificates for custom domains to be in us-east-1. Uploading the certificate directly to CloudFront is not a valid option; certificates must be managed through ACM. Creating a DNS A record for the custom domain is incorrect; a CNAME record is used to point to the CloudFront distribution's domain.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed