Courseiva

DOP-C02 Incident and Event Response Practice Question

A company uses Amazon CloudFront to serve static content from an S3 bucket. Users report that they see outdated content even after the engineer has updated the files in the S3 bucket. What should the engineer do to ensure users see the latest content?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an invalidation for the updated file paths.

Creating a CloudFront invalidation for the specific file paths forces the edge locations to fetch the updated content from the S3 origin immediately, ensuring users see the latest files. Option B is incorrect because changing the bucket policy to allow public access does not affect CloudFront's cache; it only controls direct access to the bucket. Option C is incorrect because reducing the TTL affects how long new content is cached but does not clear already-cached outdated content. Option D is incorrect because deleting and recreating the distribution is an overly disruptive solution; a simple invalidation suffices.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an invalidation for the updated file paths.

    Why this is correct

    CloudFront caches objects at edge locations until their TTL expires, so after you update files in Amazon S3 the edge locations continue serving the old copies. An invalidation request explicitly removes the specified file paths from every CloudFront edge cache, forcing subsequent requests to fetch the latest version from the S3 origin. You can target an individual file with /path/file.js or use a wildcard like /images/* to clear a whole directory. This is the intended, immediate mechanism for propagating content updates without waiting for natural cache expiry.

  • ✗

    Change the S3 bucket policy to allow public access.

    Why it's wrong here

    The bucket policy governs whether clients can directly access the S3 objects, not what CloudFront has already cached at its edge locations. CloudFront is typically configured to access S3 through an origin access identity/control (OAI/OAC), which remains unaffected by making the bucket public. Because the stale objects are stored in CloudFront's cache, not in the S3 bucket's permissions layer, updating the bucket policy will not purge or refresh any cached content. Moreover, allowing public access to the S3 origin is a security misconfiguration that bypasses CloudFront's access controls and is unnecessary for content delivery.

  • ✗

    Reduce the TTL for the CloudFront distribution.

    Why it's wrong here

    TTL settings establish how long CloudFront considers an object fresh before it revalidates with the origin, but these settings are evaluated at the time an object is cached or refreshed. Objects that were already cached under the previous longer TTL will continue to be served until their individual expiration, so reducing the distribution's TTL will not immediately make the updated file paths available. You would still need to either wait out the existing TTL or issue an invalidation to force the edge locations to see your S3 changes sooner. Changing TTL also takes effect gradually as CloudFront propagates the new configuration globally.

  • ✗

    Delete and recreate the CloudFront distribution.

    Why it's wrong here

    Deleting and recreating the distribution gives you a new distribution ID and a new *.cloudfront.net domain name, which would break any existing DNS records, application references, or signed URLs that point to the original endpoint. The entire configuration—origin settings, behaviors, error pages, certificates, and edge functions—would have to be rebuilt, and CloudFront distributions take several minutes to propagate, creating unnecessary downtime. CloudFront invalidations exist precisely to remove stale cached content from all edge locations without altering the distribution's identity or availability. That makes deletion and recreation an over-engineered, disruptive approach to a simple cache-refresh problem.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.