An application runs on EC2 instances in private subnets behind an internet-facing Application Load Balancer (ALB). The ALB is the origin for a CloudFront distribution. A WAF web ACL (with AWS managed rules) is attached to the CloudFront distribution. The company wants to prevent any internet traffic from reaching the ALB directly. Which option accomplishes this with the least operational overhead?
Choose an answer
Tap an option to check your answer.
Correct answer: Add a security group rule on the ALB that allows inbound traffic only from the AWS-managed CloudFront prefix list..
Why this is the answer
Adding a security group rule to the ALB that allows inbound traffic only from the AWS-managed CloudFront prefix list (e.g., com.amazonaws.global.cloudfront.origin-facing) is the most operationally efficient solution. This prefix list is automatically updated by AWS, ensuring that the ALB always accepts traffic from legitimate CloudFront edge locations without manual intervention. Creating a new WAF web ACL for the ALB or associating the existing CloudFront WAF with the ALB would not prevent direct internet access to the ALB; WAF operates at a higher layer and still requires the ALB to be accessible. Allowing traffic only from current CloudFront IP address ranges is not ideal because these ranges can change, requiring frequent manual updates and increasing operational overhead.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed