SAA-C03 Design Secure Architectures Practice Question
A startup runs a web application on Amazon EC2 instances behind an Application Load Balancer. The security team wants to encrypt data in transit between clients and the load balancer using a certificate managed by AWS, with minimal operational overhead. Which solution meets these requirements?
⚠ Common exam trap
The trap here is assuming that imported or self-signed certificates in ACM are automatically renewed, when ACM only auto-renews certificates it issued and that use DNS validation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request a public certificate in AWS Certificate Manager (ACM), validate it via DNS, and attach it to an HTTPS listener on the Application Load Balancer.
AWS Certificate Manager (ACM) issues free public certificates that can be automatically renewed when DNS validation is used, and it integrates directly with Application Load Balancers. Attaching an ACM certificate to an HTTPS listener encrypts client traffic with minimal operational effort, satisfying the requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Import a self-signed certificate into AWS Certificate Manager (ACM) and attach it to the load balancer's HTTPS listener.
Why it's wrong here
A self-signed certificate is not trusted by browsers and requires manual renewal, increasing operational overhead. ACM can import certificates, but it cannot automatically renew imported certificates. This does not meet the requirement for minimal operational overhead or a trusted certificate.
- ✓
Request a public certificate in AWS Certificate Manager (ACM), validate it via DNS, and attach it to an HTTPS listener on the Application Load Balancer.
Why this is correct
ACM provides free public certificates that are automatically renewed when validated via DNS and used with integrated services like ALB. Attaching the certificate to an HTTPS listener encrypts client-to-load-balancer traffic. This is the lowest-overhead, fully managed approach that meets the encryption requirement.
- ✗
Use an Amazon-issued certificate from IAM and attach it to the load balancer's HTTPS listener.
Why it's wrong here
IAM can store server certificates, but for Application Load Balancers, certificates must be provisioned through ACM or imported into ACM (or IAM for some older setups). IAM does not issue certificates automatically, and managing them there adds overhead. This is not the recommended or minimal-overhead solution.
- ✗
Generate a certificate using AWS KMS, store it in AWS Secrets Manager, and configure the load balancer to retrieve it at runtime.
Why it's wrong here
AWS KMS does not generate SSL/TLS certificates; it manages encryption keys. Secrets Manager can store certificates but does not integrate with ALB to serve them automatically. This approach is not supported and would require custom automation, adding significant operational overhead.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.