Courseiva

SAA-C03 Design Cost-Optimized Architectures Practice Question

Exhibit

CloudFront behavior summary:
  Origin: assets-prod.s3.amazonaws.com
  Cache policy: forwards all cookies, all query strings, and the Authorization header
  Origin request policy: forwards all headers
Access logs:
  x-edge-result-type=Miss: 81%
  x-edge-result-type=Hit: 19%
Object names:
  /static/app.v18a9f3.js
  /static/vendor.v18a9f3.css
Request pattern:
  Many requests include Authorization: Bearer <token>
  Query strings are used only for analytics and do not affect file content

Based on the exhibit, the team serves versioned JavaScript and CSS files from an S3 origin through CloudFront. After a release, the cache hit ratio dropped and origin fetches increased sharply. What change best reduces both CloudFront and S3 costs without changing the application’s public behavior?

⚠ Common exam trap

Many candidates think increasing edge locations (Option A) or using Lambda@Edge (Option D) will improve performance, but for versioned static files, the real cost optimization comes from maximizing cache hits by properly configuring cache and origin request policies, not from adding more infrastructure or rewriting requests.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a cache policy that excludes Authorization, cookies, and unnecessary query strings, and narrow the origin request policy to forward only the headers the S3 origin actually needs.

B is correct because versioned JavaScript and CSS files are immutable, so CloudFront should cache them aggressively. By creating a cache policy that excludes unnecessary headers (like Authorization and cookies) and query strings, and narrowing the origin request policy to forward only required headers, you maximize cache hits and reduce origin fetches. This directly lowers both CloudFront data transfer costs (fewer origin requests) and S3 request costs (fewer GET requests), without altering the application's public behavior.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Increase the CloudFront price class to include more edge locations.

    Why it's wrong here

    A broader price class can change geographic reach and pricing, but it does not address the real problem: the cache key is fragmented by headers and query strings that do not affect the content of these versioned static assets.

  • ✓

    Create a cache policy that excludes Authorization, cookies, and unnecessary query strings, and narrow the origin request policy to forward only the headers the S3 origin actually needs.

    Why this is correct

    The hit ratio is low because CloudFront is varying the cache on request attributes that do not change versioned static files. Removing Authorization, cookies, and irrelevant query strings from the cache key allows CloudFront to reuse cached objects across users and sessions. Reducing the origin request policy avoids sending unnecessary viewer context to the origin. Because the filenames are already versioned, long TTLs can be used safely and will lower origin requests and S3 request costs.

  • ✗

    Disable CloudFront and serve the files directly from S3 to avoid cache invalidation overhead.

    Why it's wrong here

    Serving directly from S3 removes the caching layer entirely, which increases origin requests and data transfer from S3 while also reducing performance for global users. It would likely increase overall cost rather than reduce it.

  • ✗

    Use Lambda@Edge to rewrite every request into a unique path so that clients never receive stale files.

    Why it's wrong here

    Using Lambda@Edge to generate a unique path per request is counterproductive: it deliberately bypasses CloudFront's cache reuse by making every request logically distinct, so the cache hit ratio plummets and S3 receives far more origin fetches. It also adds per-request compute charges for Lambda execution and adds complexity to the request flow, whereas versioned filenames already provide natural cache invalidation by changing the URL only when the content changes. Instead, keep the URL stable and let CloudFront's cache key rely on that versioned filename with a long TTL.

Visual reference

Client DHCP Server 1 Discover (broadcast) 2 Offer (IP: 192.168.1.10) 3 Request (I accept) 4 Acknowledge (lease confirmed) DORA — the four-step DHCP lease process

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.