CLF-C02 Security and Compliance Practice Question
A company wants to enable HTTPS on their Application Load Balancer using an SSL/TLS certificate. They want a managed service that provisions, renews, and deploys the certificate automatically at no cost for certificates used with integrated AWS services. Which AWS service provides this?
⚠ Common exam trap
A common mix-up: candidates confuse AWS Secrets Manager with ACM because both involve 'secrets' and 'rotation,' but Secrets Manager does not handle SSL/TLS certificate provisioning or deployment to load balancers, and it incurs costs per secret.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Certificate Manager
AWS Certificate Manager (ACM) is the correct service because it is a managed service that provisions, renews, and deploys SSL/TLS certificates automatically at no additional cost when used with integrated AWS services like Application Load Balancers. ACM handles the entire certificate lifecycle, including automatic renewal before expiration, and integrates natively with ALB to enable HTTPS without manual intervention.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS KMS
Why it's wrong here
AWS KMS is a key management service that creates and controls customer master keys (KMS keys) used for cryptographic operations such as encrypting data at rest in S3, EBS, or RDS. It deals with symmetric and asymmetric encryption keys, not X.509 public-key certificates that browsers validate during an HTTPS handshake. While KMS could theoretically be involved in private key protection, it does not provision, validate, or manage SSL/TLS certificates for public websites. Thus KMS is incorrect because it serves data encryption, not certificate lifecycle management.
- ✗
AWS Secrets Manager
Why it's wrong here
AWS Secrets Manager is designed to securely store, rotate, and retrieve secrets like database passwords, API keys, and OAuth tokens. Despite the fact that you could store a certificate chain and private key as a secret, Secrets Manager has no native integration to issue or renew SSL/TLS certificates, nor can AWS services like ALB directly consume a certificate from it. There is no automated domain validation or reissue workflow, and the service is not positioned as a certificate authority. Therefore it is not the correct answer for managed SSL/TLS certificate provisioning.
- ✓
AWS Certificate Manager
Why this is correct
AWS Certificate Manager (ACM) is the purpose-built AWS service for provisioning, deploying, and managing public SSL/TLS certificates at no charge for integrated services such as Application Load Balancers, Amazon CloudFront, and API Gateway. ACM automates certificate renewal by re-validating domain ownership before expiration, eliminating the manual effort and cost of purchasing certificates from a third-party CA. It also integrates natively with AWS services, so you can attach a certificate to a load balancer or distribution with just a few clicks. This is precisely why ACM is the correct answer for free, automated SSL/TLS certificate management.
- ✗
AWS IAM
Why it's wrong here
AWS IAM can technically store server certificates that you upload for legacy Classic Load Balancer HTTPS listeners, but it is not a managed service for certificate provisioning. You must obtain the certificate from an external CA, and IAM performs no automatic renewal or deployment across integrated services. Modern AWS services like ALB, CloudFront, and API Gateway prefer ACM, which issues, renews, and attaches certificates automatically. Therefore IAM is the wrong choice because it is a manual, legacy certificate storage mechanism, not a managed SSL/TLS solution.
Go deeper
Related to this question
About these practice questions
One of 993 original CLF-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.