Courseiva

SOA-C02 Cost and Performance Optimization Practice Question

A company uses Amazon CloudFront to deliver content to a global audience. The origin is an Application Load Balancer in us-east-1. The SysOps administrator wants to reduce costs by minimizing the number of requests that reach the origin server. Which action should the administrator take?

⚠ Common exam trap

Candidates often assume increasing cache TTL is the primary way to reduce origin requests, but they overlook that Origin Shield directly reduces origin load by consolidating requests, which is a more targeted cost optimization feature for CloudFront.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable CloudFront Origin Shield.

CloudFront Origin Shield acts as an additional caching layer in front of the origin, reducing the load on the origin by consolidating requests from multiple edge locations. This minimizes the number of requests that reach the Application Load Balancer, directly lowering origin request costs and improving cache hit ratio.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable CloudFront Origin Shield.

    Why this is correct

    CloudFront Origin Shield acts as an intermediary caching layer between all edge locations and the origin, located in a specific AWS Region. When an edge cache misses, it forwards the request to Origin Shield; if the object is already cached there, Origin Shield serves it directly, preventing a redundant fetch to the origin. This aggregation of requests from multiple edges substantially reduces the number of origin requests and the associated compute and data transfer costs, while also providing a single point for cache fills and origin protection.

  • ✗

    Configure multiple origins for failover.

    Why it's wrong here

    Configuring multiple origins for failover creates an origin group where CloudFront automatically switches to a backup origin when the primary returns an error. This mechanism exists solely to provide high availability and resilience against origin failures; it does not cache or consolidate requests in any way. In fact, if the primary origin is down, traffic reroutes to the secondary origin, so the total request load is unchanged or even duplicated, failing to reduce the number of requests to any single origin.

  • ✗

    Enable CloudFront Web Application Firewall (WAF) integration.

    Why it's wrong here

    Enabling CloudFront WAF integration adds a set of security rules that inspect incoming HTTP(S) requests for common attack patterns, such as SQL injection or cross-site scripting, and can block them at the edge. However, WAF operates on the application layer and is not a caching mechanism; it neither stores content nor aggregates requests from different edge locations. While it can reduce some malicious traffic, legitimate user requests still pass through to the origin on cache misses, so it does not meaningfully lower the volume of requests that reach the origin.

  • ✗

    Increase the cache TTL for CloudFront distributions.

    Why it's wrong here

    Increasing the cache TTL extends the duration that CloudFront retains an object at edge locations before checking the origin for a newer version, which can improve the edge cache hit ratio and reduce origin traffic for that object. However, this only affects object freshness at the edge and does not provide a centralized aggregation layer; if multiple edges miss simultaneously, each still fetches from the origin independently. Origin Shield is a more comprehensive solution because it creates a single regional cache that all edges share, thereby reducing redundant origin fetches across the entire distribution, whereas simply raising TTL offers limited and less predictable origin offload.

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on SOA-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. A company is using Amazon CloudFront to deliver content globally. Which feature can help reduce costs by minimizing data transfer from the origin?

easy
  • A.Enable multiple origins for load balancing.
  • ✓ B.Configure caching to serve content from edge locations.
  • C.Configure custom SSL certificates.
  • D.Use Lambda@Edge to process requests.

Why B: Configuring caching in CloudFront allows content to be served from edge locations, reducing the number of requests that need to go to the origin. This minimizes data transfer from the origin and lowers costs. Option A is incorrect because multiple origins are for routing different content, not for reducing origin transfer; load balancing doesn't inherently reduce data transfer costs. Option C is incorrect because custom SSL certificates secure connections but do not affect data transfer costs. Option D is incorrect because Lambda@Edge runs custom code at edge locations but does not directly reduce the volume of data transferred from the origin; it may even add compute costs.

Variation 2. A company is using Amazon CloudFront to deliver content to users worldwide. They notice high data transfer costs. Which THREE actions can reduce CloudFront data transfer costs?

hard
  • A.Use Lambda@Edge to customize content.
  • ✓ B.Use a CloudFront price class that only uses the cheapest edge locations.
  • ✓ C.Enable compression for compressible objects.
  • D.Add more edge locations to improve cache hit ratio.
  • ✓ E.Use CloudFront Origin Shield to reduce requests to the origin.

Why B: Option B is correct because selecting a CloudFront price class (e.g., Price Class 100, which uses only the least expensive North American and European edge locations) excludes costlier regions and directly lowers the per-GB data transfer rates charged for content delivery. Option C is correct because enabling automatic compression (gzip/Brotli) on compressible objects shrinks the payload size transferred from edge locations to viewers, reducing the number of bytes billed for data transfer out. Option E is correct because Origin Shield adds a centralized caching layer that consolidates origin fetches, raising the cache hit ratio and cutting the cache-miss traffic that CloudFront must pull from the origin, which reduces origin-side data transfer charges. Option A does not belong because Lambda@Edge runs custom compute at edge locations and adds request/execution charges rather than reducing data transfer costs. Option D does not belong because adding more edge locations does not lower transfer pricing and can even increase costs, since CloudFront already uses its full global network and the price class determines which locations are billed.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.