SAA-C03 Design High-Performing Architectures Practice Question
Exhibit
CloudFront access log sample: 2026-04-18T09:12:41Z LAX1 1234 Miss GET d111111abcdef8.cloudfront.net /app/v42/main.8f3d2.js 200 - Mozilla/5.0 Authorization=Bearer eyJhbGciOi... 2026-04-18T09:12:42Z LAX1 1235 Miss GET d111111abcdef8.cloudfront.net /app/v42/vendor.9c1a0.css 200 - Mozilla/5.0 Authorization=Bearer eyJhbGciOi... Distribution behavior summary: - Origin: S3 bucket - Cache policy: legacy default - Origin request policy: forwards all headers, cookies, and query strings - Objects are immutable after release and have content-hash file names
Based on the exhibit, a media company serves versioned JavaScript and CSS files from an Amazon S3 origin through CloudFront. After a frontend release, the cache hit ratio dropped sharply even though the file names are versioned. The application team says the browser requests include the same Authorization header on every asset request because the frontend and API share one domain. What should the solutions architect do to improve CloudFront cache hit ratio without changing the application authentication model for the API?
⚠ Common exam trap
Candidates often think the Authorization header is required for caching or that forwarding all headers is safe, but in reality, including it in the cache key destroys cache efficiency for static assets, and the correct solution is to exclude it via a cache policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudFront cache policy that excludes Authorization, cookies, and unnecessary query strings from the cache key.
The sharp drop in cache hit ratio is caused by the Authorization header being included in the cache key, which makes each request unique even though the file names are versioned. By creating a CloudFront cache policy that excludes the Authorization header (and unnecessary cookies/query strings) from the cache key, CloudFront can serve cached responses to requests with different Authorization headers, restoring the cache hit ratio without altering the application's authentication model for the API.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable S3 Transfer Acceleration on the bucket so CloudFront fetches objects faster from the origin.
Why it's wrong here
S3 Transfer Acceleration is designed to speed up client uploads into S3 by routing traffic through AWS edge locations, not to reduce CloudFront's cache misses for download distributions. When CloudFront fetches an object from an S3 origin, it already uses AWS's internal backbone and is not bottlenecked by public internet upload speed. It does nothing to address the cache-key fragmentation caused by varying Authorization headers, cookies, or query strings, so viewers still generate separate cached copies of the same immutable JS file.
- ✓
Create a CloudFront cache policy that excludes Authorization, cookies, and unnecessary query strings from the cache key.
Why this is correct
This reduces cache fragmentation because CloudFront can reuse the same cached object for many viewers. Since the assets are immutable and versioned, the Authorization header is not needed to vary the cache for these files. Keeping API authentication separate preserves the application model while improving hit ratio.
- ✗
Switch the origin from S3 to an Application Load Balancer so CloudFront can cache dynamic responses more effectively.
Why it's wrong here
Switching to an Application Load Balancer origin would shift CloudFront to fetching from a dynamic HTTP endpoint, but versioned JavaScript files are immutable static assets that can be cached indefinitely at the edge. An ALB does not strip or normalize viewer headers, cookies, or query strings before CloudFront computes its cache key, so it would not fix the underlying issue of duplicate cache entries. It also introduces additional operational overhead, latency, and cost, because every cache miss would route through the load balancer to compute instances rather than directly to S3.
- ✗
Configure CloudFront to forward every viewer header to the origin so the origin can decide whether the content is cacheable.
Why it's wrong here
Configuring CloudFront to forward every viewer header makes the cache key highly variable because each unique combination of headers creates a separate cached object. Even if the origin marks the response as cacheable, CloudFront's forward-all-header behavior means a request with a different User-Agent, Accept-Language, or Authorization value is treated as a distinct object, so the cache hit ratio collapses. This is the opposite of the required fix, which is to intentionally exclude non-essential headers from the cache key so identical versioned assets are reused across viewers.
Visual reference
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.