For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 3Question 57
    Hard1 markMultiple Choice
    Domain 2.3: Security ControlsSecurityACMCertificates

    AWS SAP-C02 · Question 57 · Domain 2.3: Security Controls

    A company needs to securely manage SSL/TLS certificates for their internal applications hosted on EC2 instances. The certificates must be trusted by internal clients but not public. Which TWO services/features should be used? (Select TWO)

    Answer options:

    A.

    AWS Certificate Manager (ACM) Public Certificates.

    B.

    AWS Certificate Manager (ACM) Private Certificate Authority (CA).

    C.

    AWS Key Management Service (KMS).

    D.

    AWS Systems Manager or custom scripts to deploy the certificates to EC2.

    E.

    Attach the ACM certificate directly to the EC2 instance via the console.

    F.

    AWS Secrets Manager.

    How to approach this question

    Identify the internal PKI service and how it integrates with EC2.

    Full Answer

    AWS Certificate Manager (ACM) Private Certificate Authority (CA)., AWS Systems Manager or custom scripts to deploy the certificates to EC2.
    ACM Private CA issues internal certificates. Because EC2 is not a managed endpoint like an ALB, you must use automation (like Systems Manager) to export and install the certificates on the instances.

    Common mistakes

    Assuming ACM can automatically install certificates on EC2 instances.
    Question 56All questionsQuestion 58

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 3

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01An enterprise has 100 VPCs across 5 AWS Regions. They need to establish a highly available, trans...HardQ02A company uses AWS Organizations. The CISO requires that no EC2 instances can be launched outside...MediumQ03An application uses Amazon Aurora PostgreSQL. To meet disaster recovery requirements, the databas...HardQ04A company is setting up a new multi-account AWS environment. They want to automate the creation o...MediumQ05An organization wants to allocate AWS costs to specific departments. They use multiple AWS accoun...Medium
    View all 75 questions →