SAA-C03 Design Secure Architectures Practice Question
A company is hosting a web application on EC2 instances behind an Application Load Balancer. The security team requires that all data in transit between the client and the ALB be encrypted using TLS. Which service should the architect use to manage the SSL/TLS certificates for the ALB?
⚠ Common exam trap
The trap is confusing certificate management (ACM) with key management (KMS) or secret storage (Secrets Manager), or falling back to the legacy IAM certificate upload method that lacks automatic renewal.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS Certificate Manager (ACM)
AWS Certificate Manager (ACM) is the managed service designed to provision, manage, and deploy public and private SSL/TLS certificates for use with AWS services like Application Load Balancers, CloudFront, and API Gateway. ACM handles certificate renewal automatically and integrates natively with ALB listeners, making it the correct choice for managing TLS certificates for the ALB.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Secrets Manager
Why it's wrong here
Secrets Manager is designed to manage database credentials, API keys, and other sensitive configuration strings. It does not provide the specialized infrastructure required to serve SSL/TLS certificates for public-facing load balancers. While you could store certificates here, it lacks the integration to automatically attach them to an ALB.
- ✓
AWS Certificate Manager (ACM)
Why this is correct
ACM provides a managed service to generate or import SSL/TLS certificates and associate them directly with an ALB. It handles the complexities of certificate lifecycle management, including automated renewals, ensuring that the web application maintains continuous, encrypted communication with clients without manual intervention or certificate expiration risks.
- ✗
AWS Key Management Service (KMS)
Why it's wrong here
KMS is primarily used for creating and controlling cryptographic keys used to encrypt data at rest within various AWS services. It is not intended for managing public SSL/TLS certificates used for identity verification and encryption in transit for web traffic, as it lacks public certificate authority trust.
- ✗
IAM Server Certificate Upload
Why it's wrong here
Uploading certificates to IAM is a legacy method used primarily for specific AWS services that do not support ACM integration. It requires manual tracking of certificate expiration dates and manual replacement, making it an operationally inefficient and insecure practice for modern ALB deployments when ACM is available.
About these practice questions
This SAA-C03 question is part of Courseiva's 149-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.