DVA-C02 exam dumps

DVA-C02 practice question 176 of 399

AWS Certified Developer - Associate. Associate level, Amazon Web Services. Free question with the correct answer and a full explanation.

DVA-C02 Question 176

Single answer

Your organization is hosting a secure web application on Amazon ECS using an Application Load Balancer (ALB). You have been asked to set up SSL/TLS certificates for the ALB to ensure secure communication. Additionally, your company has strict compliance requirements to manage and issue private certificates internally. Which AWS service can you use to meet these requirements, and how can you configure it?

  1. A

    Use AWS Certificate Manager (ACM) and request a public certificate directly from ACM for the ALB.

  2. B

    Use AWS Private Certificate Authority (AWS Private CA) to issue private certificates, then import the certificate into AWS Certificate Manager (ACM) for the ALB.

  3. C

    Generate a self-signed certificate locally on your machine and upload it directly to the ALB.

  4. D

    Use AWS Secrets Manager to generate and store the SSL/TLS certificate and configure it with the ALB.

Show answer and explanation

Correct answer: B

Explanation

The scenario requires managing and issuing private certificates for compliance purposes. AWS Private Certificate Authority (AWS Private CA) is the appropriate service for this use case. It allows organizations to create and manage private certificate hierarchies and issue private certificates. These certificates can then be imported into AWS Certificate Manager (ACM), which integrates seamlessly with the Application Load Balancer (ALB) to provide secure SSL/TLS communication.

  • A. Incorrect.

    AWS Certificate Manager (ACM) can issue public certificates, but it cannot issue private certificates for internal compliance requirements. This does not meet the scenario's requirements.

  • B. Correct.

    AWS Private Certificate Authority (AWS Private CA) allows you to manage and issue private certificates for internal use. You can issue a private certificate and import it into ACM, which integrates with the ALB. This meets the compliance and secure communication requirements.

  • C. Incorrect.

    A self-signed certificate does not meet the compliance requirements of the organization and is not a recommended practice for production-grade systems.

  • D. Incorrect.

    AWS Secrets Manager is not used for generating SSL/TLS certificates; it is primarily for storing and managing secrets like database credentials or API keys. This does not meet the scenario's requirements.

Timed practice exam

Take a DVA-C02 practice test under exam conditions

65 questions in 130 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam