Courseiva
Design Secure Architectures →mediumMultiple Choice

SAA-C03 Design Secure Architectures Practice Question

An organization needs to issue and manage SSL/TLS certificates for its internal microservices, which are not accessible from the public internet. They want to avoid the overhead of managing their own PKI infrastructure. Which service should they use?

⚠ Common exam trap

Candidates often suggest AWS Certificate Manager (ACM) public certificates. ACM public certificates are for internet-facing resources and cannot be used for internal-only, private microservices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Certificate Manager (ACM) Private Certificate Authority (PCA).

AWS Certificate Manager (ACM) Private Certificate Authority (PCA) is a managed private CA service that helps you easily and securely manage the lifecycle of your private certificates. It eliminates the need for organizations to maintain their own complex and costly internal PKI while still providing the security of private certificates.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Certificate Manager (ACM) to request public certificates for the services.

    Why it's wrong here

    Public certificates from ACM require domain ownership validation via DNS or email and are only suitable for publicly accessible endpoints. For internal microservices that do not have public DNS records, public certificates cannot be issued, making a private CA the necessary solution for internal encryption.

  • ✓

    AWS Certificate Manager (ACM) Private Certificate Authority (PCA).

    Why this is correct

    ACM Private CA allows you to create a private CA hierarchy and issue certificates that are trusted within your organization. It integrates with ACM to automate certificate renewal and management, providing a highly available and secure way to implement TLS for internal applications without the manual effort of managing PKI.

  • ✗

    AWS CloudHSM to store and manage the private keys for the certificates.

    Why it's wrong here

    AWS CloudHSM is a cloud-based hardware security module that allows you to generate and use your own encryption keys. While it can be used as a backend for a CA, it requires significant manual configuration and management of the PKI software, which does not meet the requirement of reducing overhead.

  • ✗

    Amazon Inspector to audit the certificates used by the microservices.

    Why it's wrong here

    Amazon Inspector is a vulnerability scanning service and does not have the capability to issue or manage SSL/TLS certificates. While it might identify if a service has an expired certificate, it is a detective tool rather than a management or issuance service for cryptographic identities and secure communication.

About these practice questions

One of 149 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.