A company is migrating to the AWS Cloud and needs to build a managed Public Key Infrastructure (PKI) using AWS services. The solution must support the following features: - IAM integration. - Auditing with AWS CloudTrail. - Private certificates. - Subordinate certificate authorities (CAs). Which solution should the company use to meet these requirements?