AWS Certified CloudOps Engineer Associate SOA-C03 Practice Question
A team operates an Application Load Balancer in the us-east-1 Region that fronts an HTTPS API available at api.example.com and several other subdomains. The company's public DNS is hosted in Amazon Route 53. The team must provide TLS termination with a single wildcard certificate that renews automatically and incurs no additional cost or maintenance. Which approach meets these requirements with the least operational effort?
Issue a private wildcard certificate for *.example.com from ACM Private CA, schedule a Lambda function to renew it, and attach the certificate to the listener.
Request a public wildcard certificate for *.example.com in ACM within us-east-1, use DNS validation so ACM creates the required Route 53 record, and attach the certificate to the ALB listener.
Purchase a third-party wildcard certificate, import it into ACM, and associate it with the listener, rotating the certificate before each expiration date.
Enable the ALB's integrated Let's Encrypt option to generate and automatically renew a wildcard certificate for all required subdomains.
ACM public certificates are free and automatically renewed as long as the original validation method remains in place. Because the load balancer is in us-east-1, the certificate must exist in the same Region. Requesting a public wildcard certificate (for example, *.example.com) through ACM, choosing DNS validation, and allowing ACM to create the CNAME in Route 53 lets ACM prove domain ownership and handle renewals without further action. Importing a third-party certificate or issuing one from ACM Private CA transfers cost and future rotation tasks to the operations team. Application Load Balancers do not offer built-in Let's Encrypt generation, so that option does not exist.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is DNS validation in ACM?
Open an interactive chat with Bash
What is a wildcard certificate?
Open an interactive chat with Bash
Why must an ACM certificate reside in the same Region as the Application Load Balancer?
Open an interactive chat with Bash
AWS Certified CloudOps Engineer Associate SOA-C03
Security and Compliance
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .