exam questions

Exam AWS Certified Security - Specialty All Questions

View all questions & answers for the AWS Certified Security - Specialty exam

Exam AWS Certified Security - Specialty topic 1 question 138 discussion

Exam question from Amazon's AWS Certified Security - Specialty
Question #: 138
Topic #: 1
[All AWS Certified Security - Specialty Questions]

A Web Administrator for the website example.com has created an Amazon CloudFront distribution for dev.example.com, with a requirement to configure HTTPS using a custom TLS certificate imported to AWS Certificate Manager.
Which combination of steps is required to ensure availability of the certificate in the CloudFront console? (Choose two.)

  • A. Call UploadServerCertificate with /cloudfront/dev/ in the path parameter.
  • B. Import the certificate with a 4,096-bit RSA public key.
  • C. Ensure that the certificate, private key, and certificate chain are PKCS #12-encoded.
  • D. Import the certificate in the us-east-1 (N. Virginia) Region.
  • E. Ensure that the certificate, private key, and certificate chain are PEM-encoded.
Show Suggested Answer Hide Answer
Suggested Answer: DE 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
aacliper
Highly Voted 3 years, 7 months ago
DE is correct https://aws.amazon.com/premiumsupport/knowledge-center/custom-ssl-certificate-cloudfront/
upvoted 28 times
...
RaySmith
Highly Voted 3 years, 7 months ago
DE to me
upvoted 15 times
...
Raphaello
Most Recent 1 year, 3 months ago
Selected Answer: DE
DE....
upvoted 1 times
...
Ernestokoro
1 year, 7 months ago
https://docs.aws.amazon.com/acm/latest/userguide/import-certificate-prerequisites.html The above link is too sweet to ignore for this question
upvoted 1 times
...
ITGURU51
2 years, 1 month ago
The best answer is DE.
upvoted 1 times
...
Nikhil0222
2 years, 1 month ago
CD CloudFront can use an SSL/TLS certificate stored in AWS Certificate Manager (ACM) or a custom SSL/TLS certificate. When using a custom SSL/TLS certificate, you must import the certificate, private key, and certificate chain into ACM or IAM. To ensure that the certificate is available in the CloudFront console, it should be imported in the us-east-1 (N. Virginia) Region, and the certificate, private key, and certificate chain must be PKCS #12-encoded. Option A is incorrect because UploadServerCertificate is not a valid API action for importing a certificate to ACM. Option B is incorrect because there is no requirement to use a specific size for the RSA public key. Option E is incorrect because PEM encoding is not required for importing a certificate to ACM.
upvoted 1 times
...
tobedeleted
2 years, 6 months ago
D&E are correct. It's about the custom domain. https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/cnames-and-https-procedures.html#cnames-and-https-getting-certificates
upvoted 2 times
...
Root_Access
2 years, 8 months ago
Selected Answer: DE
Whenever you import a cert to ACM regardless of which service you want to use it with: https://docs.aws.amazon.com/acm/latest/userguide/import-certificate-prerequisites.html
upvoted 1 times
...
sapien45
2 years, 8 months ago
Selected Answer: DE
https://aws.amazon.com/premiumsupport/knowledge-center/custom-ssl-certificate-cloudfront/ To assign an ACM certificate to a CloudFront distribution, you must request or import the certificate in the US East (N. Virginia) Region. If you're using the ACM console, check the Region selector in the navigation bar. Confirm that US East (N. Virginia) is selected before you request or import the certificate. aws iam upload-server-certificate --server-certificate-name CertificateName --certificate-body file://public_key_certificate_file --private-key file://privatekey.pem --certificate-chain file://certificate_chain_file --path /cloudfront/DistributionName/
upvoted 2 times
...
Alexey79
3 years ago
Selected Answer: DE
D: https://aws.amazon.com/premiumsupport/knowledge-center/custom-ssl-certificate-cloudfront/ “ To assign an ACM certificate to a CloudFront distribution, you must request or import the certificate in the US East (N. Virginia) Region. “ E: https://docs.aws.amazon.com/cli/latest/reference/iam/upload-server-certificate.html “ The server certificate entity includes a public key certificate, a private key, and an optional certificate chain, which should all be PEM-encoded.
upvoted 2 times
...
fabvan
3 years, 6 months ago
Answer is D & E. Private Key is .pem encoded aws iam upload-server-certificate --server-certificate-name CertificateName --certificate-body file://public_key_certificate_file --private-key file://privatekey.pem --certificate-chain file://certificate_chain_file --path /cloudfront/DistributionName/ Also ensure that certificate in imported from us-east North VA https://aws.amazon.com/premiumsupport/knowledge-center/custom-ssl-certificate-cloudfront
upvoted 5 times
...
kj07
3 years, 6 months ago
Answer: DE Duplicated with Q22 Topic2
upvoted 3 times
deegadaze1
3 years, 6 months ago
Correct
upvoted 1 times
...
...
lunt
3 years, 7 months ago
Some people are seriously just not thinking at all. A. Nope. B. Really? Go and read the AWS ACM pre-req's. C. Nope. D. Yes. AWS limitation. E. Yes. ACM pre-req's documentation literally has this wording on the site. Answer is DE. Took all of 5 minutes to confirm all of this.
upvoted 9 times
...
gfhbox0083
3 years, 7 months ago
D, E for sure
upvoted 1 times
...
Raj9
3 years, 7 months ago
DE looks fine
upvoted 2 times
...
Raj9
3 years, 7 months ago
can't be B, cloudfront supports max of 2048 bit
upvoted 2 times
...
joeboy
3 years, 7 months ago
Answer: A D
upvoted 1 times
awssecuritynewbie
3 years, 7 months ago
No it is D& E
upvoted 7 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago