passdrill
AWS SAA-C03 · IAM & Security · Card 020/024 medium

A team requests three ACM public certificates: one attached to a CloudFront distribution and validated using DNS validation, one requested through ACM using email validation but never attached to any AWS resource, and one imported into ACM from a third-party certificate authority. Which of these will renew before expiry without any manual action from the team?

  1. All three, because ACM automatically manages renewal for every certificate in its inventory regardless of validation method or usage
  2. Only the imported third-party certificate, because ACM tracks externally issued certificates most closely for expiry
  3. Only the certificate attached to the CloudFront distribution: it renews automatically because it is DNS-validated and currently in use by an AWS service, while the email-validated certificate needs the domain owner to click a renewal link and the imported certificate is never eligible for managed renewal at all
  4. None of the three, because ACM never renews any certificate automatically and always requires submitting a brand-new certificate request
Next card → Shuffle