SAP-C02 Continuous Improvement for Existing Solutions Practice Question
A company has a web application running on Amazon EC2 instances in an Auto Scaling group. The application uses a self-signed SSL certificate on the instances, and an Application Load Balancer (ALB) terminates SSL. Users report intermittent SSL certificate errors. The security team requires that the certificate be managed and rotated automatically. Which solution should a solutions architect implement to meet these requirements?
⚠ Common exam trap
The trap here is assuming that ACM can automatically rotate imported self-signed certificates or that instances need the certificate when an ALB terminates SSL.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Request a public certificate from AWS Certificate Manager (ACM) for the application's domain and attach it to the ALB. Remove the self-signed certificate from the instances.
The intermittent SSL errors are likely due to the self-signed certificate not being trusted by clients. Using a public ACM certificate on the ALB provides a trusted certificate that is automatically managed and renewed. Since the ALB terminates SSL, the instances do not need any certificate. This solution meets the security team's requirement for automatic management and rotation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Request a public certificate from AWS Certificate Manager (ACM) for the application's domain and attach it to the ALB. Remove the self-signed certificate from the instances.
Why this is correct
ACM provides public certificates that are automatically renewed and deployed. Attaching the ACM certificate to the ALB ensures that SSL termination uses a trusted certificate, eliminating intermittent errors caused by the self-signed certificate. Since the ALB handles SSL termination, the instances do not need certificates. This meets the requirements for managed and automatically rotated certificates.
- ✗
Request a public certificate from AWS Certificate Manager (ACM) for the application's domain, attach it to the ALB, and configure the instances to use it.
Why it's wrong here
ACM can issue public certificates and automatically rotate them, but the certificate must be attached to the ALB, not the instances. Since the ALB terminates SSL, the instances do not need the certificate. Configuring the instances to use the certificate is unnecessary and does not address the intermittent errors. The correct approach is to use ACM on the ALB only.
- ✗
Import the self-signed certificate into AWS Certificate Manager (ACM) and use it on the ALB. Configure ACM to rotate the certificate annually.
Why it's wrong here
ACM cannot automatically rotate imported certificates. While you can import a self-signed certificate into ACM and use it on the ALB, ACM does not manage or rotate imported certificates. You would need to manually re-import a new certificate before expiration. This does not meet the requirement for automatic rotation and management.
- ✗
Use AWS Secrets Manager to store the self-signed certificate and configure the instances to retrieve and install it on a schedule using a Lambda function.
Why it's wrong here
Storing the self-signed certificate in Secrets Manager and using a Lambda function to rotate it on the instances adds unnecessary complexity. The instances do not need the certificate because the ALB terminates SSL. This approach does not eliminate the intermittent errors and does not provide a trusted certificate. It also requires custom automation for rotation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAP-C02 question from scratch — 984 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.