SCS-C02 · Question #46
A company is using HTTPS for all its public endpoints. A third-party certificate authority (CA) issues the certificates. The company imports the certificates and attaches the certificates to an Elasti
The correct answer is C. The domain has Certification Authority Authorization (CAA) DNS records that allow only specific. This is of of the ways certificate validation can fail. https://aws.amazon.com/premiumsupport/knowledge-center/acm-troubleshoot-caa-errors/ https://aws.amazon.com/blogs/security/easier-certificate-validation-using-dns-with-aws-certificate-
Question
A company is using HTTPS for all its public endpoints. A third-party certificate authority (CA) issues the certificates. The company imports the certificates and attaches the certificates to an Elastic Load Balancer or an Amazon CloudFront distribution. The company also is using a third- party DNS hosting provider. The certificates are near expiration. The company wants to migrate to AWS Certificate Manager (ACM) with automatic renewal. When the company adds the CNAME record during DNS validation, the certificate status changes to Failed. What is the root cause of this issue?
Options
- ADNS validation requires the domain to be hosted on Amazon Route 53.
- BAutomatic renewal for domain validation requires the domain to be hosted on Amazon Route 53.
- CThe domain has Certification Authority Authorization (CAA) DNS records that allow only specific
- DDNS validation requires a TXT record instead of a CNAME record.
How the community answered
(20 responses)- A5% (1)
- B5% (1)
- C75% (15)
- D15% (3)
Explanation
This is of of the ways certificate validation can fail. https://aws.amazon.com/premiumsupport/knowledge-center/acm-troubleshoot-caa-errors/ https://aws.amazon.com/blogs/security/easier-certificate-validation-using-dns-with-aws-certificate-
Topics
Community Discussion
No community discussion yet for this question.