DOP-C02 CloudFront Cache Invalidation Practice Question
A company hosts a static website on Amazon S3 with CloudFront as the CDN. Users report that they see an old version of the website even after the DevOps team updated the S3 objects. The team verified that the new objects are in the S3 bucket and are publicly accessible. The CloudFront distribution has a default TTL of 24 hours. To immediately serve the new content to users, the team needs to invalidate the CloudFront cache. Which of the following is the CORRECT approach to achieve this with minimal impact?
⚠ Common exam trap
The trap is confusing TTL changes with cache invalidation — candidates pick 'set TTL to 0' thinking it purges existing cached objects, but TTL changes only affect future caching, not objects already stored at edge locations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudFront invalidation request for the path '/*'.
A CloudFront invalidation for the path '/*' tells all edge locations to stop serving cached objects matching that pattern and fetch fresh copies from the S3 origin on the next request. This is the standard, immediate way to purge stale content without changing the distribution configuration or object keys. It has minimal impact because it only affects cached objects and does not require re-uploading or renaming anything.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a CloudFront invalidation request for the path '/*'.
Why this is correct
An invalidation request for the '/*' path removes all objects from CloudFront's edge caches across every region, which forces the distribution to return to the S3 origin on the next request and fetch the updated content. This is the standard, immediate method for clearing cached content when you need to publish new website changes, and it does not require changing URLs or reconfiguring any origin settings.
- ✗
Change the CloudFront origin path to point to a new S3 bucket.
Why it's wrong here
Changing the CloudFront origin path to point to a new S3 bucket only alters the source for future cache misses; edge locations that already have a cached copy of a path will continue to serve that stale content until the object's TTL expires. Additionally, the origin path change affects all subsequent requests, but without invalidating the existing cache, the distribution cannot immediately serve the fresh content from the new bucket.
- ✗
Update the CloudFront distribution's default TTL to 0 and wait for the changes to propagate.
Why it's wrong here
Setting the default TTL to 0 affects how long new objects are cached but does not clear existing cached objects. The distribution would still serve the old content until the TTL expires or invalidations are used.
- ✗
Delete the S3 objects and re-upload them with different names.
Why it's wrong here
Deleting the S3 objects and re-uploading them under different names means the original object keys no longer exist, so the old URLs return 404 errors, and the new URLs require users to discover and access them manually or via a code change. Even if you preserve the original keys, the CloudFront cache still holds the old versions until TTL expiration, so this action alone fails to deliver the updated content to viewers.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,298 original DOP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.