โ† All AWS Flashcard Decks

Certified Solutions Architect CloudFront and Content Delivery Flashcards

7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Certified Solutions Architect CloudFront and Content Delivery flashcards as text
  1. A company is migrating to a new CloudFront distribution but wants to gradually shift traffic from the old distribution to the new one. Which CloudFront feature supports this use case?

    Answer: CloudFront Continuous Deployment with traffic weights

    CloudFront Continuous Deployment allows you to create a staging distribution and gradually shift a percentage of traffic to it before promoting it to production.

  2. An architect needs to configure CloudFront to automatically failover to a secondary S3 bucket if the primary S3 bucket returns 5xx errors. What should they configure?

    Answer: CloudFront Origin Group with primary and secondary origins

    CloudFront Origin Groups allow you to define a primary and secondary origin; CloudFront automatically fails over to the secondary when the primary returns specified HTTP status codes.

  3. A solutions architect wants to analyze CloudFront access patterns in near real-time to detect anomalies. Which CloudFront feature delivers log data within seconds of viewer requests?

    Answer: CloudFront Real-Time Logs (Kinesis Data Streams)

    CloudFront Real-Time Logs deliver log records to Amazon Kinesis Data Streams within seconds of viewer requests, enabling near real-time analysis.

  4. A company needs to serve their website through CloudFront using their own domain (www.example.com) with HTTPS. What are the TWO required components?

    Answer: An ACM certificate in us-east-1 and a CNAME/Alias DNS record pointing to the CloudFront domain

    CloudFront requires an ACM certificate provisioned in us-east-1 (N. Virginia) for custom SSL/TLS, plus a DNS CNAME or Route 53 Alias record pointing to the CloudFront distribution domain.

  5. A CloudFront distribution serves both static assets (images, CSS) and dynamic API calls. The architect wants to cache static assets for 1 year but never cache API responses. What is the correct configuration approach?

    Answer: Create separate Cache Behaviors with different path patterns and TTL settings for each content type

    Multiple Cache Behaviors with path patterns (e.g., /api/* vs /static/*) allow different caching policies and TTLs to be applied to different content types within a single distribution.

  6. A financial services company requires that all connections to their CloudFront distribution use TLS 1.2 or higher for compliance. Where is this configured?

    Answer: In the CloudFront distribution's Security Policy setting under Viewer Protocol Policy

    The CloudFront Security Policy setting controls the minimum TLS protocol version and cipher suites allowed for HTTPS connections between viewers and CloudFront.

  7. A company uses CloudFront to serve an S3-hosted website. They want to ensure S3 bucket content cannot be accessed directly via the S3 URL and only through CloudFront. What is the CURRENT recommended approach?

    Answer: Enable S3 Block Public Access and use Origin Access Control (OAC) with a bucket policy

    Origin Access Control (OAC) is the current recommended method (replacing the legacy OAI) to restrict S3 access to CloudFront only, combined with a corresponding S3 bucket policy.