Question: A Network Engineer is designing a new system on AWS that will take advantage of Amazon CloudFront for both content caching and for protecting the

A Network Engineer is designing a new system on AWS that will take advantage of Amazon CloudFront for both content caching and for protecting the underlying origin. There is concern that an external agency might be able to access the IP addresses for the application's origin and then attack the origin despite it being served by CloudFront. Which of the following solutions provides the strongest level of protection to the origin?
A . Use an IP whitelist rule in AWS WAF within CloudFront to ensure that only known-client IPs are able to access the application.
B . Congure CloudFront to use a custom header and congure an AWS WAF rule on the origin's Application Load Balancer to accept only trac that contains that header.
C . Congure an AWS Lambda@Edge function to validate that the trac to the Application Load Balancer originates from CloudFront.
D . Attach an origin access identity to the CloudFront origin that allows trac to the origin that originates from only CloudFront.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Programming Questions!