AWS Certificate Manager | Private Key Protection Flashcards

1
Q

How can I notify AWS if the information in the certificate changes?

Private Key Protection

AWS Certificate Manager | Security, Identity & Compliance

A

You notify AWS by sending email to validation-questions[at]amazon.com.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
2
Q

How are the private keys of ACM-provided certificates managed?

Private Key Protection

AWS Certificate Manager | Security, Identity & Compliance

A

A key pair is created for each certificate provided by ACM. AWS Certificate Manager is designed to protect and manage the private keys used with SSL/TLS certificates. Strong encryption and key management best practices are used when protecting and storing private keys.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly
3
Q

Does ACM copy certificates across AWS Regions?

Private Key Protection

AWS Certificate Manager | Security, Identity & Compliance

A

No. The private key of each ACM certificate is stored in the Region in which you request the certificate. For example, when you obtain a new certificate in the US East (N. Virginia) Region, ACM stores the private key in the N. Virginia Region. ACM certificates are only copied across Regions if the certificate is associated with a CloudFront distribution. In that case, CloudFront distributes the ACM certificate to the geographic locations configured for your distribution.

How well did you know this?
1
Not at all
2
3
4
5
Perfectly