AWS Certificate Manager | Details Flashcards

1
Q

How will I be charged and billed for my use of ACM certificates?

Details

AWS Certificate Manager | Security, Identity & Compliance

A

SSL/TLS certificates provisioned, managed, and deployed through AWS Certificate Manager are free. You pay only for the AWS resources you create to run your application, such as Elastic Load Balancing load balancers or Amazon CloudFront distributions.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

Can I use the same certificate with multiple Elastic Load Balancing load balancers and multiple CloudFront distributions?

Details

AWS Certificate Manager | Security, Identity & Compliance

A

Yes.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Can I use certificates for internal Elastic Load Balancing load balancers with no public Internet access?

Details

AWS Certificate Manager | Security, Identity & Compliance

A

Yes. See Managed Renewal and Deployment for details about how ACM handles renewals for certificates that are not reachable from the public Internet.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
4
Q

Will a certificate for www.example.com also work for example.com?

Details

AWS Certificate Manager | Security, Identity & Compliance

A

No. If you want your site to be referenced by both domain names (www.example.com and example.com), you must request a certificate that includes both names.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
5
Q

Can I import a third party certificate and use it with AWS services?

Details

AWS Certificate Manager | Security, Identity & Compliance

A

Yes. If you want to use a third-party certificate with Amazon CloudFront, Elastic Load Balancing, or Amazon API Gateway, you may import it into ACM using the AWS Management Console, AWS CLI, or ACM APIs. ACM does not manage the renewal process for imported certificates. You can use the AWS Management Console to monitor the expiration dates of an imported certificates and import a new third-party certificate to replace an expiring one.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
6
Q

What is the validity period for certificates provided by ACM?

Details

AWS Certificate Manager | Security, Identity & Compliance

A

Certificates provided by ACM are currently valid for 13 months.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
7
Q

How can ACM help my organization meet my compliance requirements?

Details

AWS Certificate Manager | Security, Identity & Compliance

A

Using ACM helps you comply with regulatory requirements by making it easy to facilitate secure connections, a common requirement across many compliance programs such as PCI, FedRAMP, and HIPAA. For specific information about compliance, please refer to http://aws.amazon.com/compliance.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
8
Q

Does ACM have a service level agreement (SLA)?

Details

AWS Certificate Manager | Security, Identity & Compliance

A

Not at this time.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
9
Q

Does ACM allow local language characters in domain names, otherwise known as Internationalized Domain Names (IDNs)?

Details

AWS Certificate Manager | Security, Identity & Compliance

A

ACM does not allow Unicode encoded local language characters; however, ACM allows ASCII-encoded local language characters for domain names.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
10
Q

Which domain name label formats does ACM allow?

Details

AWS Certificate Manager | Security, Identity & Compliance

A

ACM allows only UTF-8 encoded ASCII, including labels containing “xn—”, commonly known as Punycode for domain names. ACM does not accept Unicode input (u-labels) for domain names.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
11
Q

Does ACM provide a secure site seal or trust logo that I can display on my web site?

Details

AWS Certificate Manager | Security, Identity & Compliance

A

No. If you would like to use a site seal, you can obtain one from a third-party vendor. We recommend choosing a vendor that evaluates and asserts the security of your site, or your business practices, or both.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly