A company serves its site through CloudFront using the domain www.example.com and has an ACM certificate for that domain. All connections to CloudFront must use TLS. Which two actions should a SysOps administrator perform to enforce encrypted viewer connections? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: For each cache behavior, set the Viewer Protocol Policy to Redirect HTTP to HTTPS., Add www.example.com as an alternate domain name (CNAME) on the CloudFront distribution and select the custom SSL certificate..
Why this is the answer
To enforce encrypted viewer connections, two key actions are required. First, adding www.example.com as an alternate domain name (CNAME) on the CloudFront distribution and selecting the custom SSL certificate (ACM certificate) ensures CloudFront can serve content over HTTPS for that domain. Without this, browsers would flag certificate mismatches. Second, setting the Viewer Protocol Policy to "Redirect HTTP to HTTPS" for each cache behavior automatically redirects any HTTP requests to HTTPS, guaranteeing that all traffic between viewers and CloudFront is encrypted. Setting the Viewer Protocol Policy to allow both HTTP and HTTPS would not enforce encryption. Attaching an AWS WAF web ACL is for security rules, not for enforcing HTTPS. Enabling Origin Shield optimizes origin requests but doesn't directly control viewer connection encryption.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed