Configuring CloudFront Origin Failover with Minimal Overhead

A media company is planning to host an event that the company will live stream to users. The company wants to use Amazon CloudFront. A network engineer creates a primary origin and a secondary origin for CloudFront. The engineer needs to ensure that the primary origin can fail over to the secondary origin within 15 seconds if a disruption occurs. Which solution will meet this requirement with the LEAST operational overhead?

  1. Configure a Lambda@Edge function to check the health status of both origins every 10 seconds. Reroute incoming requests when the origin health status is unhealthy.
  2. Create a Network Load Balancer (NLB) in front of both origins Configure the NLB as the origin in CloudFront.
  3. Set the CloudFront origin connection timeout value to 5 seconds Set the origin connection attempts value to 2. Source Reference Answer
  4. Configure a Lambda@Edge function to monitor incoming requests for an origin response. Reroute incoming requests if no response is received from the primary origin within 10 seconds.

Community Votes

C
100%

100% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the understanding that CloudFront has built-in origin failover capabilities, allowing engineers to control failover speed via configuration rather than custom code.

This question tests knowledge of native Amazon CloudFront origin failover mechanisms and how to configure timeout settings for rapid switching. The community consensus confirms that adjusting connection timeout and retry counts is the most efficient method.

Candidates often choose Lambda@Edge solutions (Options A or D) because they assume manual health checking is required, failing to recognize CloudFront's native automatic failover feature which incurs zero additional operational overhead.

Community Discussion (3 comments)

AWSLoverLoverLoverLoverLover 👍 1 Selected: C
Amazon CloudFront supports origin failover natively for primary and secondary origins. It can automatically fail over to the secondary origin if the primary is unhealthy. To control how quickly failover happens, you use: Origin connection timeout: Time CloudFront waits to establish a connection. Origin connection attempts: Number of retry attempts before declaring failure. If you set timeout to 5 seconds and attempts to 2, the total failover time is 10 seconds. CloudFront will try the primary origin twice, each with a 5-second timeout. If both fail, it moves to the secondary origin — all within 15 seconds, satisfying your requirement.
ashk123456 👍 1 Selected: C
CloudFront determines origin health based on timeout and retry settings: ✅ Origin connection timeout: The time CloudFront waits before considering the origin unresponsive. Setting this to 5 seconds minimizes failover delay. ✅ Origin connection attempts: The number of retry attempts before marking the origin as unhealthy. Setting this to 2 attempts ensures failover within (5 sec * 2) = 10 seconds, well within the 15-second requirement. B.❌ Incorrect – An NLB does not provide failover between different origins in the way CloudFront does. CloudFront’s origin failover feature is simpler and requires less management.
Sudeepshiv 👍 1 Selected: C
CloudFront Failover Mechanism: • CloudFront allows you to configure multiple origins with automatic failover when the primary origin is unavailable. Connection timeout and retry attempts control how quickly CloudFront will attempt to use a secondary origin if the primary origin fails to respond.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option C is correct because Amazon CloudFront natively supports origin groups for automatic failover. By configuring the 'Origin connection timeout' to 5 seconds and 'Origin connection attempts' to 2, you ensure that if the primary origin does not respond within 10 seconds (5s * 2 retries), CloudFront automatically routes traffic to the secondary origin. This meets the <15 second requirement without any additional infrastructure.

Why the Other Options Are Wrong

Options A and D involve Lambda@Edge functions, which add significant operational overhead including writing, deploying, and maintaining code, as well as potential cold start delays. Option B suggests using an NLB, which is unnecessary complexity since CloudFront handles the failover logic internally at the edge; an NLB would also introduce latency and cost without providing the specific origin-group failover benefits native to CloudFront.

Community Comment Notes

Comments [1], [2], and [3] unanimously support Option C. They highlight that CloudFront determines origin health based on these specific timeout and retry settings. One commenter explicitly calculates the total time as 5 seconds * 2 attempts = 10 seconds, proving it fits within the 15-second constraint.

Official Reference

Exam Strategy

When asked for 'least operational overhead,' always look for managed service features before considering custom integrations like Lambda or external load balancers. For CloudFront questions involving reliability, check for native Origin Groups and their configuration parameters first.

Related Analysis

Practice All ANS-C01 Questions

Access 137 questions with complete answers and detailed explanations.

View Full ANS-C01 Practice Test →

← Back to ANS-C01 Study Guide