Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company wants to securely store and manage SSL/TLS certificates for use with CloudFront. Which AWS service should be used?

⚠ Common exam trap

Many candidates confuse AWS KMS or IAM Server Certificate Store as viable options for CloudFront, but ACM is the only service that provides automatic renewal and native integration with CloudFront, and certificates must be in us-east-1.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

AWS Certificate Manager (ACM)

AWS Certificate Manager (ACM) is the correct service because it is specifically designed to provision, manage, and deploy public and private SSL/TLS certificates for use with AWS services like CloudFront. ACM integrates directly with CloudFront to automatically renew certificates before expiration, eliminating manual renewal overhead. It also handles the complex certificate chain and private key management securely, ensuring HTTPS termination at CloudFront edge locations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS Identity and Access Management (IAM)

    Why it's wrong here

    IAM does support uploading a server certificate for HTTPS-enabled endpoints in some AWS services, but it requires you to supply an existing PEM-encoded certificate and private key. IAM does not automate issuance or renewal, so you must manually track expiration dates and re-upload certificates before they lapse. ACM is the integrated, purpose-built lifecycle manager that supersedes IAM for SSL/TLS use cases, making IAM an incorrect choice here.

  • ✗

    AWS Key Management Service (AWS KMS)

    Why it's wrong here

    AWS KMS is a managed service for creating and controlling cryptographic keys used for data encryption and signing operations. It does not accept or store a complete SSL/TLS certificate chain, nor does it bind a public certificate with a private key for broadcast to load balancers or CDNs. KMS can participate in TLS through client-side key wrapping, but it is not a certificate store or manager for public-facing HTTPS endpoints.

  • ✓

    AWS Certificate Manager (ACM)

    Why this is correct

    AWS Certificate Manager provisions SSL/TLS certificates for public and private domains, handles domain validation via DNS or email, and automatically renews eligible certificates before expiry. It natively deploys the certificate to integrated AWS services such as Application Load Balancers, CloudFront, and API Gateway, eliminating manual installation and tracking. Because the private key is generated in and protected by AWS-managed hardware, ACM is the correct service for the stated requirement to securely store and manage SSL/TLS certificates.

  • ✗

    AWS CloudHSM

    Why it's wrong here

    AWS CloudHSM offers dedicated, FIPS 140-2 Level 3 validated hardware security modules for generating and protecting cryptographic keys, often used to support custom PKI or signing workflows. However, it does not manage SSL/TLS certificate lifecycles—there is no automated issuance, validation, or renewal, and its HSM devices do not natively integrate with AWS load balancers for HTTPS listeners. CloudHSM also requires you to operate the HSM cluster and client infrastructure, so it is not the appropriate managed option for this requirement.

About these practice questions

Courseiva writes every SCS-C02 question from scratch — 1,205 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.