Soru

Zorluk: KolayAmazon CloudFront Caching, Origins, and Security

A company hosts a static website using Amazon CloudFront. The security team mandates that all communication between the viewers and the CloudFront distribution must be encrypted in transit. Which two Viewer Protocol Policy settings will satisfy this requirement? (Select TWO.)

  1. Redirect HTTP to HTTPSCevap
  2. HTTPS OnlyCevap
  3. C
    HTTP and HTTPS
  4. D
    HTTP Only

Cevap

The settings 'Redirect HTTP to HTTPS' and 'HTTPS Only' ensure that all communication between the viewers and the CloudFront distribution is encrypted in transit.
The correct options are 'Redirect HTTP to HTTPS' and 'HTTPS Only'. The 'Redirect HTTP to HTTPS' setting automatically redirects unencrypted HTTP requests to the secure HTTPS protocol. The 'HTTPS Only' setting blocks unencrypted HTTP requests entirely, forcing the viewer to use HTTPS. Both settings ensure that all viewer communication with the distribution is encrypted.

Adım Adım Çözüm

1
Analyze the requirement for transport encryption between viewers and the CloudFront distribution.
The requirement dictates that all client-to-edge connections must use HTTPS.
This establishes the necessary protocol constraint for the CloudFront behavior configuration.
2
Evaluate the Viewer Protocol Policy options available in CloudFront.
Viewer Protocol Policy has three main settings: 'HTTP and HTTPS', 'Redirect HTTP to HTTPS', and 'HTTPS Only'.
Identifying the available settings allows selection of the ones that enforce encryption.
3
Select the settings that enforce HTTPS.
'Redirect HTTP to HTTPS' and 'HTTPS Only' both guarantee that no unencrypted HTTP traffic is served by the distribution.
Choosing these two configurations successfully meets the requirement.

Anahtar Kavram

CloudFront Viewer Protocol Policy options for enforcing HTTPS
Bu soruyu puanla