Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company uses Amazon CloudFront with an Application Load Balancer (ALB) as the origin. The SysOps administrator needs to restrict access to the ALB so that it only accepts requests from CloudFront. Which solution should the administrator implement?

⚠ Common exam trap

A common mix-up: candidates confuse Origin Access Identity (OAI) as a universal CloudFront feature, not realizing it only works with S3 origins, and they overlook the impracticality of using CloudFront IP ranges in security groups due to their dynamic nature.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure CloudFront to add a custom HTTP header to requests, and configure the ALB to only forward requests that contain that header

It uses a shared secret mechanism: CloudFront is configured to add a custom HTTP header (e.g., X-Origin-Verify) to all requests, and the ALB's listener rule is configured to only forward requests that contain that specific header value. This ensures that only requests originating from your CloudFront distribution reach the ALB, as the header is not present in direct client requests. This approach is recommended by AWS for restricting ALB access to CloudFront when the origin is an ALB, because CloudFront does not support Origin Access Identity (OAI) with ALB origins.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Replace the ALB with a Network Load Balancer and use a VPC endpoint

    Why it's wrong here

    Replacing the ALB with an NLB and using a VPC endpoint does not restrict access to CloudFront only. NLB operates at Layer 4 and does not support security groups, while VPC endpoints are designed for private connectivity to AWS services, not for CloudFront to reach a load balancer. CloudFront would still access the NLB over the internet, and any client with network access could potentially reach the endpoint, so this approach fails to enforce a CloudFront-only policy.

  • ✗

    Create an origin access identity (OAI) and attach it to the CloudFront distribution

    Why it's wrong here

    An origin access identity (OAI) is a CloudFront feature specifically for S3 origins, not for ALB or other HTTP/S origins. OAI works by granting the CloudFront service principal read permissions to an S3 bucket via IAM, but an ALB origin requires a different verification mechanism such as custom headers or AWS WAF to prove requests originate from your distribution. Attaching an OAI to an ALB is unsupported and would not prevent direct access.

  • ✗

    Add a security group rule to the ALB that allows traffic only from the CloudFront IP ranges

    Why it's wrong here

    Adding a security group rule that allows traffic only from CloudFront IP ranges is insecure because those IP ranges are shared across all CloudFront customers and are publicly documented. An attacker could use another CloudFront distribution or spoof a source IP from those ranges, and security groups cannot validate the specific distribution or application payload. Furthermore, CloudFront does not guarantee per-distribution fixed IPs, making this approach both unreliable and insufficiently restrictive.

  • ✓

    Configure CloudFront to add a custom HTTP header to requests, and configure the ALB to only forward requests that contain that header

    Why this is correct

    Configure CloudFront to inject a secret custom HTTP header into every request it forwards to the ALB, and then configure the ALB listener rule to only route traffic that contains that exact header and value. CloudFront strips any client-supplied header with the same name, so the secret cannot be discovered or forged by users making direct requests to the ALB. This ensures only traffic that passed through your CloudFront distribution is accepted, securely restricting access to your origin.

About these practice questions

Courseiva writes every SOA-C02 question from scratch — 1,169 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.