AWS Certified Solutions Architect Professional SAP-C02 Practice Question

A global e-commerce company is migrating its platform to AWS. For regulatory compliance, the company must use a specific third-party Extended Validation (EV) certificate for all public-facing endpoints. The architecture consists of a CloudFront distribution for caching static content and directing traffic to an Application Load Balancer (ALB) in the eu-west-1 region.

A solutions architect needs to design a strategy to make the EV certificate available to both the CloudFront distribution and the ALB. The private key for the certificate must be protected, and the process must meet all requirements.

Which approach should the architect recommend?

  • Import the certificate and its chain into ACM in the us-east-1 region and associate it with the CloudFront distribution. Then, configure the CloudFront origin to use an 'HTTPS Only' Origin Protocol Policy to connect to the ALB.

  • Store the certificate, private key, and chain in AWS Secrets Manager in the eu-west-1 region. Configure both the ALB and the CloudFront distribution to retrieve and use the certificate from Secrets Manager.

  • Import the certificate and its chain into ACM in the us-east-1 region for the CloudFront distribution. Separately, import the same certificate and chain into ACM in the eu-west-1 region for the ALB.

  • Import the certificate and its chain into ACM in the eu-west-1 region. Associate this certificate with the ALB and reference its Amazon Resource Name (ARN) in the CloudFront distribution settings.

AWS Certified Solutions Architect Professional SAP-C02
Design Solutions for Organizational Complexity
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot