If you update the cert before too. The good way of doing this is configuring AutoD Endpoint before anything else and ensure everyone is directed to the legacy (e.g. Ex2010) endpoint. The obviously since mailboxes are not yet migrated, they won't access the new Urls. This leaves all necessary time to update both Urls and Cert and push them to the LB too when doing SSL termination here.
The wizard tells to enter the Product Key after moving mailboxes, same for H/A. This is not logical.
1) trial edition has limitations in term of number of DB, hence in term of scalability
2) DAG should be built right after configuring the FE part and obviouslu before anything else in regard of moving the service
3) Arbitration Mailboxes and System Mailboxes only after DAG too (don't forget this is a must-do to have Admin Audit Logs be stored correctly into the System Mailbox)