After a DDoS event against a public Application Load Balancer (ALB), a company placed Amazon CloudFront in front of the ALB. However, some clients still reach the ALB directly, and the Amazon EC2 instances continue to serve that traffic. Which combination of actions ensures the EC2 instances only receive requests that come through CloudFront? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Configure CloudFront to add a custom HTTP header to requests that CloudFront sends to the ALB., Configure the ALB to forward only requests that include the custom HTTP header..
Why this is the answer
To ensure EC2 instances only receive requests via CloudFront, a custom HTTP header acts as a secret handshake. First, CloudFront must be configured to add a unique, custom HTTP header (e.g., X-Origin-Verify: <secretvalue) to all requests it forwards to the ALB. Second, the ALB must be configured (e.g., using W
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed