Courseiva
Security and Compliance →easyMultiple Choice

CLF-C02 Security and Compliance Practice Question

A company wants to enable HTTPS on their Application Load Balancer using an SSL/TLS certificate. They want a managed service that provisions, renews, and deploys the certificate automatically at no cost for certificates used with integrated AWS services. Which AWS service provides this?

⚠ Common exam trap

A common mix-up: candidates confuse AWS Secrets Manager with ACM because both involve 'secrets' and 'rotation,' but Secrets Manager does not handle SSL/TLS certificate provisioning or deployment to load balancers, and it incurs costs per secret.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Certificate Manager

AWS Certificate Manager (ACM) is the correct service because it is a managed service that provisions, renews, and deploys SSL/TLS certificates automatically at no additional cost when used with integrated AWS services like Application Load Balancers. ACM handles the entire certificate lifecycle, including automatic renewal before expiration, and integrates natively with ALB to enable HTTPS without manual intervention.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS KMS

    Why it's wrong here

    AWS KMS is a key management service that creates and controls customer master keys (KMS keys) used for cryptographic operations such as encrypting data at rest in S3, EBS, or RDS. It deals with symmetric and asymmetric encryption keys, not X.509 public-key certificates that browsers validate during an HTTPS handshake. While KMS could theoretically be involved in private key protection, it does not provision, validate, or manage SSL/TLS certificates for public websites. Thus KMS is incorrect because it serves data encryption, not certificate lifecycle management.

  • ✗

    AWS Secrets Manager

    Why it's wrong here

    AWS Secrets Manager is designed to securely store, rotate, and retrieve secrets like database passwords, API keys, and OAuth tokens. Despite the fact that you could store a certificate chain and private key as a secret, Secrets Manager has no native integration to issue or renew SSL/TLS certificates, nor can AWS services like ALB directly consume a certificate from it. There is no automated domain validation or reissue workflow, and the service is not positioned as a certificate authority. Therefore it is not the correct answer for managed SSL/TLS certificate provisioning.

  • ✓

    AWS Certificate Manager

    Why this is correct

    AWS Certificate Manager (ACM) is the purpose-built AWS service for provisioning, deploying, and managing public SSL/TLS certificates at no charge for integrated services such as Application Load Balancers, Amazon CloudFront, and API Gateway. ACM automates certificate renewal by re-validating domain ownership before expiration, eliminating the manual effort and cost of purchasing certificates from a third-party CA. It also integrates natively with AWS services, so you can attach a certificate to a load balancer or distribution with just a few clicks. This is precisely why ACM is the correct answer for free, automated SSL/TLS certificate management.

  • ✗

    AWS IAM

    Why it's wrong here

    AWS IAM can technically store server certificates that you upload for legacy Classic Load Balancer HTTPS listeners, but it is not a managed service for certificate provisioning. You must obtain the certificate from an external CA, and IAM performs no automatic renewal or deployment across integrated services. Modern AWS services like ALB, CloudFront, and API Gateway prefer ACM, which issues, renews, and attaches certificates automatically. Therefore IAM is the wrong choice because it is a manual, legacy certificate storage mechanism, not a managed SSL/TLS solution.

About these practice questions

One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.