Certified Solutions Architect CloudFront and Content Delivery Flashcards
7 cards from real AWS practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Certified Solutions Architect CloudFront and Content Delivery flashcards as text
What is the primary purpose of Amazon CloudFront?
Answer: To distribute content globally with low latency via edge locations
CloudFront is a content delivery network (CDN) that caches and serves content from edge locations close to end users, reducing latency.
A company wants to run custom authentication logic at AWS edge locations before requests reach the origin. Which CloudFront feature enables this?
Answer: Lambda@Edge
Lambda@Edge allows you to run Node.js or Python Lambda functions at CloudFront edge locations to customize content delivery, including at the viewer-request stage for authentication.
Which CloudFront feature restricts access to an S3 bucket so that only CloudFront can read objects, preventing direct S3 access?
Answer: Origin Access Control (OAC)
Origin Access Control (OAC) is the recommended mechanism that grants CloudFront permission to access a private S3 bucket while blocking direct public access.
A CloudFront distribution is configured with an S3 origin. A user requests an object that is not currently cached at the edge location. What happens next?
Answer: CloudFront fetches the object from the S3 origin, caches it, and returns it to the user
On a cache miss, CloudFront forwards the request to the configured origin (e.g., S3), retrieves the object, stores it in the edge cache, and delivers it to the user.
Which CloudFront feature allows you to block or allow content delivery based on a viewer's country?
Answer: CloudFront Geographic Restrictions (Geo-Blocking)
CloudFront Geographic Restrictions (also called geo-blocking) lets you whitelist or blacklist specific countries to control where your content is distributed.
An architect needs to serve HTTPS content via CloudFront using a custom domain name. What must be provisioned?
Answer: An ACM SSL certificate in the us-east-1 (N. Virginia) region
CloudFront requires SSL/TLS certificates from AWS Certificate Manager (ACM) to be provisioned specifically in the us-east-1 (N. Virginia) region for use with distributions.
What is the purpose of setting a TTL (Time-To-Live) value in a CloudFront cache behavior?
Answer: It controls how long CloudFront caches an object at edge locations before checking the origin for updates
TTL specifies the duration (in seconds) that CloudFront keeps a cached copy of an object at an edge location before it is considered stale and the origin is checked.