nerdexam
Amazon

SAA-C03 · Question #678

A company hosts its web applications in the AWS Cloud. The company configures Elastic Load Balancers to use certificate that are imported into AWS Certificate Manager (ACM). The company's security…

The correct answer is B. Create an AWS Config rule that checks for certificates that will expire within 30 days. https://aws.amazon.com/premiumsupport/knowledge-center/acm-certificate-expiration/

Submitted by lars.no· Mar 4, 2026Design Secure Architectures

Question

A company hosts its web applications in the AWS Cloud. The company configures Elastic Load Balancers to use certificate that are imported into AWS Certificate Manager (ACM). The company's security team must be notified 30 days before the expiration of each certificate. What should a solutions architect recommend to meet the requirement?

Options

  • AAdd a rule in ACM to publish a custom message to an Amazon Simple Notification Service
  • BCreate an AWS Config rule that checks for certificates that will expire within 30 days.
  • CUse AWS trusted Advisor to check for certificates that will expire within to days.
  • DCreate an Amazon EventBridge (Amazon CloudWatch Events) rule to detect any certificates that

How the community answered

(52 responses)
  • A
    6% (3)
  • B
    81% (42)
  • C
    12% (6)
  • D
    2% (1)

Explanation

https://aws.amazon.com/premiumsupport/knowledge-center/acm-certificate-expiration/

Community Discussion

No community discussion yet for this question.

Full SAA-C03 Practice