nerdexam
Amazon

SCS-C02 · Question #46

A company is using HTTPS for all its public endpoints. A third-party certificate authority (CA) issues the certificates. The company imports the certificates and attaches the certificates to an Elasti

The correct answer is C. The domain has Certification Authority Authorization (CAA) DNS records that allow only specific. This is of of the ways certificate validation can fail. https://aws.amazon.com/premiumsupport/knowledge-center/acm-troubleshoot-caa-errors/ https://aws.amazon.com/blogs/security/easier-certificate-validation-using-dns-with-aws-certificate-

Submitted by the_admin· Mar 6, 2026Data Protection

Question

A company is using HTTPS for all its public endpoints. A third-party certificate authority (CA) issues the certificates. The company imports the certificates and attaches the certificates to an Elastic Load Balancer or an Amazon CloudFront distribution. The company also is using a third- party DNS hosting provider. The certificates are near expiration. The company wants to migrate to AWS Certificate Manager (ACM) with automatic renewal. When the company adds the CNAME record during DNS validation, the certificate status changes to Failed. What is the root cause of this issue?

Options

  • ADNS validation requires the domain to be hosted on Amazon Route 53.
  • BAutomatic renewal for domain validation requires the domain to be hosted on Amazon Route 53.
  • CThe domain has Certification Authority Authorization (CAA) DNS records that allow only specific
  • DDNS validation requires a TXT record instead of a CNAME record.

How the community answered

(20 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    75% (15)
  • D
    15% (3)

Explanation

This is of of the ways certificate validation can fail. https://aws.amazon.com/premiumsupport/knowledge-center/acm-troubleshoot-caa-errors/ https://aws.amazon.com/blogs/security/easier-certificate-validation-using-dns-with-aws-certificate-

Topics

#AWS Certificate Manager#DNS validation#CAA records#certificate renewal

Community Discussion

No community discussion yet for this question.

Full SCS-C02 Practice