nerdexam
Amazon

SAA-C03 · Question #567

A company uses an Amazon CloudFront distribution to serve content pages for its website. The company needs to ensure that clients use a TLS certificate when accessing the company's website. The compan

The correct answer is C. Use AWS Certificate Manager (ACM) to create a certificate. Use DNS validation for the domain.. AWS Certificate Manager (ACM) issues and automatically renews public TLS certificates used by Amazon CloudFront. With DNS validation, ACM creates CNAME records that prove domain control; once validated, renewals occur automatically without manual approval, providing the lowest op

Submitted by valeria.br· Mar 4, 2026Design Secure Architectures

Question

A company uses an Amazon CloudFront distribution to serve content pages for its website. The company needs to ensure that clients use a TLS certificate when accessing the company's website. The company wants to automate the creation and renewal of the TLS certificates. Which solution will meet these requirements with the MOST operational efficiency?

Options

  • AUse a CloudFront security policy to create a certificate.
  • BUse a CloudFront origin access control (OAC) to create a certificate.
  • CUse AWS Certificate Manager (ACM) to create a certificate. Use DNS validation for the domain.
  • DUse AWS Certificate Manager (ACM) to create a certificate. Use email validation for the domain.

How the community answered

(51 responses)
  • A
    4% (2)
  • B
    2% (1)
  • C
    92% (47)
  • D
    2% (1)

Explanation

AWS Certificate Manager (ACM) issues and automatically renews public TLS certificates used by Amazon CloudFront. With DNS validation, ACM creates CNAME records that prove domain control; once validated, renewals occur automatically without manual approval, providing the lowest operational effort. For CloudFront, ACM certificates must be in the US East (N. Virginia) Region. CloudFront security policies (A) configure protocol/cipher requirements, not certificate issuance. OAC (B) secures origin access and is unrelated to certificate management. Email validation (D) requires mailbox approvals and operational handling at issuance/renewal, which is less efficient than DNS validation. Thus, ACM with DNS validation delivers automated creation and renewal with minimal overhead.

Community Discussion

No community discussion yet for this question.

Full SAA-C03 Practice