Security, Identity, and Compliance
CoreAWS Certificate Manager (ACM)
Managed provisioning, deployment, and renewal of eligible public and private TLS certificates on supported AWS integrations.
Key points
- ACM reduces certificate lifecycle operations when the certificate remains eligible and associated with a supported service.
- Public certificate validation and private certificate trust are different governance concerns.
- ACM manages certificates; it does not manage general data-encryption keys.
Best-known use cases
- Terminate HTTPS at CloudFront, ALB, or other supported integrations.
- Issue private certificates through supported private CA integration.
What candidates often confuse it with
- ACM manages TLS certificates; KMS manages encryption keys.
- ACM integrated renewal reduces operations; imported/external certificate lifecycle retains customer work.
Key takeaway
Choose ACM for supported TLS certificate deployment and managed lifecycle.
Related services
- AWS KMS
- Elastic Load Balancing (ELB)
- Amazon CloudFront
Relevant exam tasks
- D1.3