An organization requires encryption for all traffic between users and CloudFront, and also between CloudFront and the origin web application. Which actions will meet these requirements? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Set the origin's Protocol Policy to HTTPS Only., Set the viewer's Protocol Policy to HTTPS Only or Redirect HTTP to HTTPS..
Why this is the answer
To encrypt traffic between users and CloudFront, you must set the viewer's Protocol Policy to "HTTPS Only" or "Redirect HTTP to HTTPS." This ensures that all communication from the user's browser to CloudFront uses HTTPS. To encrypt traffic between CloudFront and the origin web application, you must set the origin's Protocol Policy to "HTTPS Only." This forces CloudFront to use HTTPS when fetching content from your origin. Using AWS KMS to encrypt traffic is incorrect because KMS is a key management service, not a transport layer security mechanism. Setting the origin's HTTP port to 443 is incorrect because port 443 is for HTTPS, and simply changing the port doesn't enforce encryption without the correct protocol policy. Enabling CloudFront's Restrict Viewer Access option is for controlling content access, not for enforcing encryption.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed