SAA-C03 Design Resilient Architectures Practice Question
A SaaS provider runs a multi-tenant application on Amazon EC2 instances behind an Application Load Balancer. Tenants are identified by a subdomain, and each tenant's data is stored in a separate Amazon S3 bucket. The provider wants HTTPS with a single certificate, automatic renewal, and the ability to add new tenant subdomains without redeploying or replacing the certificate. Which solution meets these requirements?
⚠ Common exam trap
The trap here is importing a certificate that covers only today's subdomains, when a wildcard certificate requested through ACM with DNS validation covers future tenants and renews automatically.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request a public certificate in AWS Certificate Manager for the apex domain and a wildcard for its subdomains, validate it with DNS, and attach it to the Application Load Balancer HTTPS listener.
A public ACM certificate that includes the apex domain and a wildcard for its subdomains covers every current and future tenant hostname. DNS validation lets ACM renew the certificate automatically while the validation records persist, and attaching the certificate to the Application Load Balancer listener provides HTTPS termination without touching the application when new tenants are onboarded.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Request a public certificate in AWS Certificate Manager for the apex domain and a wildcard for its subdomains, validate it with DNS, and attach it to the Application Load Balancer HTTPS listener.
Why this is correct
A public ACM certificate that includes the apex domain and a wildcard covers all current and future tenant subdomains, and DNS validation allows ACM to renew the certificate automatically as long as the validation records remain in place. Attaching it to the Application Load Balancer HTTPS listener provides TLS termination without redeploying the application when tenants are added.
- ✗
Import a self-signed certificate covering all current tenant subdomains into AWS Certificate Manager and attach it to the Application Load Balancer listener.
Why it's wrong here
Imported certificates in AWS Certificate Manager are not eligible for managed renewal, so the provider must rotate them manually before expiry. A self-signed certificate is also not trusted by browsers, and it cannot cover future tenant subdomains that were not known at import time, so it fails the automatic renewal and extensibility requirements.
- ✗
Terminate TLS on the EC2 instances using certificates issued by AWS Private Certificate Authority, and pass traffic from the Application Load Balancer to the instances over HTTP.
Why it's wrong here
AWS Private Certificate Authority issues certificates trusted only within the organization's private PKI, so public browsers would reject them. Terminating TLS on the instances also spreads certificate management across the fleet and requires redeployment or automation for renewal, which conflicts with the goal of a single automatically renewed certificate.
- ✗
Store the private key and certificate in AWS Secrets Manager, and configure the Application Load Balancer to retrieve and rotate the certificate at each renewal.
Why it's wrong here
Application Load Balancers do not fetch certificates from AWS Secrets Manager; they require the certificate to be provisioned in AWS Certificate Manager or uploaded to IAM. Secrets Manager can store credentials but does not integrate with the load balancer's TLS configuration, so this design would not terminate HTTPS as required.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SAA-C03 question is part of Courseiva's 935-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.