DVA-C02 exam dumps

DVA-C02 practice question 174 of 399

AWS Certified Developer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DVA-C02 Question 174

Single answer

A development team is building a secure internal web application that requires SSL/TLS encryption. The team wants to issue private certificates for the application and ensure the certificates can be managed centrally within AWS. They also want to automate the certificate renewal process to minimize operational overhead. Which AWS service or feature should the team use to meet these requirements?

  1. A

    AWS Certificate Manager (ACM) with an imported certificate

  2. B

    AWS Private Certificate Authority (AWS Private CA) integrated with AWS Certificate Manager (ACM)

  3. C

    AWS Key Management Service (KMS) for certificate issuance and management

  4. D

    Amazon S3 for storing and managing SSL/TLS certificates

Show answer and explanation

Correct answer: B

Explanation

AWS Private Certificate Authority (AWS Private CA) integrated with AWS Certificate Manager (ACM) is the correct solution for issuing and managing private SSL/TLS certificates in AWS. By using AWS Private CA, the development team can automate the issuance and renewal of private certificates while managing them centrally through ACM, reducing operational overhead.

  • A. Incorrect.

    AWS Certificate Manager (ACM) with an imported certificate allows you to manage certificates but does not automate the issuance or renewal of private certificates. Imported certificates must be manually renewed.

  • B. Correct.

    AWS Private Certificate Authority (AWS Private CA) integrated with AWS Certificate Manager (ACM) is specifically designed for issuing and managing private certificates. It allows for centralized management, automation of certificate renewal, and seamless integration with AWS services.

  • C. Incorrect.

    AWS Key Management Service (KMS) is used for managing encryption keys, not SSL/TLS certificates. It cannot be used for private certificate issuance or management.

  • D. Incorrect.

    Amazon S3 is a storage service and does not provide features for SSL/TLS certificate management.

Timed practice exam

Take a DVA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam