Security, Identity, and Compliance
CoreAWS Certificate Manager (ACM)
Explicit encryption-in-transit configuration/troubleshooting example.
Key points
- ACM manages supported TLS certificates; troubleshooting includes validation, status, hostname, Region, attachment, chain, and client trust.
Best-known use cases
- D4.1, D4.2, and D5.1: attach or troubleshoot the certificate used by the named supported TLS endpoint.
What candidates often confuse it with
- ACM protects connections with certificates; KMS manages encryption keys for data protection and Secrets Manager stores secret values.
Key takeaway
A certificate does not fix DNS or network reachability; verify identity, trust, Region, attachment, and the serving endpoint separately.
Related services
- Amazon EC2 security groups
- Egress-only internet gateways
- Elastic Load Balancing (ELB)
Relevant exam tasks
- D4.1 — Task 4.1: Implement and manage security and compliance tools and policies.
- 4.1.1 — Implement IAM features (for example, password policies, multi-factor authentication [MFA], roles, federated identity, resource policies, policy conditions).
- D4.2 — Task 4.2: Implement strategies to protect data and infrastructure.
- 4.2.1 — Implement and enforce a data classification scheme.
- D5.1 — Task 5.1: Implement and optimize networking features and connectivity.
- 5.1.1 — Configure a VPC (for example, subnets, route tables, network ACLs, security groups, NAT gateways, internet gateway, egress-only internet gateway).