โ† All AWS Flashcard Decks

Certified Solutions Architect CloudFront and Content Delivery Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Certified Solutions Architect CloudFront and Content Delivery flashcards as text
  1. A company wants to invalidate specific files cached in CloudFront immediately after a deployment. What is the most efficient approach?

    Answer: Create an invalidation request specifying the paths of the objects to remove from edge caches

    Submitting a cache invalidation request with specific object paths (e.g., /images/logo.png or /*) forces CloudFront to remove those objects from all edge caches immediately.

  2. What is the key difference between CloudFront Signed URLs and Signed Cookies?

    Answer: Signed URLs restrict access to a single file; Signed Cookies can grant access to multiple files

    Signed URLs provide access to a single specific object, making them ideal for individual file downloads, while Signed Cookies can restrict access to multiple files matching a path pattern.

  3. A solutions architect wants to reduce load on the origin by shielding it from repeated cache-miss requests across multiple CloudFront edge locations. Which feature helps?

    Answer: CloudFront Origin Shield

    CloudFront Origin Shield adds an additional caching layer between regional edge caches and the origin, consolidating requests to reduce origin load and improve cache hit ratios.

  4. Which CloudFront Price Class setting would reduce costs by limiting distribution to only North America and Europe edge locations?

    Answer: Price Class 100

    Price Class 100 limits CloudFront delivery to the least expensive edge locations in North America and Europe, reducing costs by excluding higher-priced regions like Asia and South America.

  5. What happens when CloudFront is configured with an origin group containing a primary and secondary origin?

    Answer: CloudFront automatically fails over to the secondary origin if the primary returns specific HTTP error codes

    CloudFront origin groups provide failover by routing requests to a secondary origin when the primary origin returns configurable HTTP error status codes (e.g., 500, 502, 503, 504).

  6. A company needs to encrypt specific sensitive fields (such as credit card numbers) in HTTP POST requests at the CloudFront edge before they reach the origin. Which feature should be used?

    Answer: CloudFront Field-Level Encryption

    Field-Level Encryption allows CloudFront to encrypt specific data fields in HTTPS POST requests using public-key cryptography so the data remains encrypted throughout processing until decrypted at the application layer.

  7. What is a CloudFront Cache Policy used to define?

    Answer: Which HTTP headers, cookies, and query strings are included in the cache key

    A CloudFront Cache Policy specifies which values (headers, cookies, query strings) are included in the cache key, determining how CloudFront differentiates cached objects.