nerdexam
AmazonAmazon

DOP-C02 · Question #187

DOP-C02 Question #187: Real Exam Question with Answer & Explanation

Sign in or unlock DOP-C02 to reveal the answer and full explanation for question #187. The question stem and answer options stay visible for context.

Submitted by mateo_ar· Mar 6, 2026Security & Compliance

Question

A company uses an Amazon API Gateway regional REST API to host its application API. The REST API has a custom domain. The REST API's default endpoint is deactivated. The company's internal teams consume the API. The company wants to use mutual TLS between the API and the internal teams as an additional layer of authentication. Which combination of steps will meet these requirements? (Choose two.)

Options

  • AUse AWS Certificate Manager (ACM) to create a private certificate authority (CA). Provision a
  • BProvision a client certificate that is signed by a public certificate authority (CA). Import the
  • CUpload the provisioned client certificate to an Amazon S3 bucket. Configure the API Gateway
  • DUpload the provisioned client certificate private key to an Amazon S3 bucket. Configure the API
  • EUpload the root private certificate authority (CA) certificate to an Amazon S3 bucket. Configure

Unlock DOP-C02 to see the answer

You've previewed enough free DOP-C02 questions. Unlock DOP-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#API Gateway#Mutual TLS#ACM Private CA#Security
Full DOP-C02 PracticeBrowse All DOP-C02 Questions