SOA-C02 Reliability and Business Continuity Practice Question
A company runs a static website on Amazon S3 with a custom domain name (www.example.com). The website is accessed via Amazon CloudFront. The company's marketing team recently updated the website content, but users are reporting that they still see the old content. The SysOps administrator checks the S3 bucket and confirms that the new files are present. The administrator also checks CloudFront and finds that the default TTL for the cache behavior is 24 hours. The marketing team needs the new content to be visible immediately. What should the administrator do to make the new content available to users as quickly as possible?
⚠ Common exam trap
SOA-C02 often tests the misconception that lowering the TTL or restarting the distribution refreshes already-cached content — candidates must remember that only an invalidation (or versioned object keys) evicts objects already stored at edge locations.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a CloudFront invalidation for the path '/*' to remove all cached files.
CloudFront caches objects at edge locations according to the cache behavior's TTL settings; changing the TTL only affects future cache fills, not objects already cached. To immediately remove stale content from all edge locations, the administrator must create an invalidation for the affected paths — here '/*' invalidates everything. This forces CloudFront to fetch fresh copies from the S3 origin on the next request, making the new content visible right away.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the CloudFront distribution and re-enable it after 5 minutes.
Why it's wrong here
Disabling and re-enabling a CloudFront distribution is a long-running control-plane operation that can take several minutes or more, and it does not purge the edge caches. Even after the distribution is re-enabled, previously cached objects can still be served from CloudFront's edge locations because disabling only halts traffic, it does not delete cached content. This approach causes unnecessary downtime without achieving the goal of removing stale files, making it an ineffective fix.
- ✗
Change the default TTL for the CloudFront cache behavior to 0 seconds.
Why it's wrong here
Changing the default TTL to 0 seconds only affects objects that CloudFront fetches after the change is deployed. Any objects already cached at edge locations remain valid until their original TTL expires, so users can still receive stale content in the meantime. Setting TTL to 0 would force revalidation of newly requested objects, but it does not proactively invalidate or remove the currently cached copies.
- ✓
Create a CloudFront invalidation for the path '/*' to remove all cached files.
Why this is correct
Creating an invalidation for the path '/*' issues a request that removes all cached objects from every edge location in the CloudFront distribution. When the invalidation completes, the next request for any of those objects causes CloudFront to go back to the S3 origin and fetch the latest version, thereby ensuring users see updated content. This is the immediate, targeted mechanism designed for exactly this scenario.
- ✗
Change the S3 bucket's lifecycle policy to expire objects after 1 day.
Why it's wrong here
An S3 lifecycle policy only governs objects stored in the S3 bucket, such as transitioning them to infrequent access or deleting them after a set number of days. It has no control over CloudFront's edge cache, so any objects already cached remain available even if the underlying S3 object expires. In fact, expiring objects could eventually cause origin fetch failures or 403 errors when CloudFront needs to re-fetch, making the problem worse.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.