ETExamTower
Q59Design Cost-Optimized Architectures

A company wants to configure its Amazon CloudFront distribution to use SSL/TLS certificates. The company does not want to use the default domain name for the distribution. Instead, the company wants to use a different domain name for the distribution. Which solution will deploy the certificate without incurring any additional costs?

← → navigate · a answer
Community votes
C
100% (9)
A
0% (0)
B
0% (0)
D
0% (0)
Discussion · 11
C 4
Have to use east-1 region for ACM, and it should be public SSL/TLS for domain, so it should be C
C 4
Yes, C. Just memorize that. For CloudFront distributions with custom domain names, ACM public certificates must be requested from us-east-1.
C 3
AnswerC Per AWS "Public SSL/TLS certificates provisioned through AWS Certificate Manager are free. You pay only for the AWS resources you create to run your application." https://aws.amazon.com/certificate-manager/pricing/?nc=sn&loc=3 But hence AWS is recommending to use US east 1 I think I would go with C Note We recommend that you use ACM to provision, manage, and deploy SSL/TLS certificates on AWS managed resources. You must request an ACM certificate in the US East (N. Virginia) Region. https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/cnames-and-https-procedures.html
C 3
The certificate has to be public. The certificate has to be issued in us-east-1: https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/cnames-and-https-requirements.html "To use an ACM certificate with CloudFront, make sure you request (or import) the certificate in the US East (N. Virginia) Region (us-east-1)."
C 3
It is c
C 2
browsers trust public certificates automatically by default > C or D To use an ACM certificate with Amazon CloudFront, you must request or import the certificate in the US East (N. Virginia) region [Nowhere is it stated why is this though...] > C
2
Why not D.evrn option D is public CA
C 2
https://aws.amazon.com/certificate-manager/pricing/ AWS Certificate Manager Pricing Public SSL/TLS certificates provisioned through AWS Certificate Manager are free. You pay only for the AWS resources you create to run your application. If you manage AWS Private Certificate Authority (CA) through ACM, refer to the AWS Private CA Pricing page for more details and examples.
C 2
This should be C. Private CA is not free
2
Should be c, it is a public certificate
1
CloudFront should have a private cert and browser use public cert aiming to achieve non-repudiation. Ans should be A