Hardening a CloudFront origin with a secret custom header and WAF
A medical company is running a REST API on a set of Amazon EC2 instances. The EC2 instances run in an Auto Scaling group behind an Application Load Balancer (ALB). The ALB runs in three public subnets, and the EC2 instances run in three private subnets. The company has deployed an Amazon CloudFront distribution that has the ALB as the only origin. Which solution should a solutions architect recommend to enhance the origin security?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
A secret, rotated custom header injected by CloudFront plus an AWS WAF string-match rule on the ALB restricts origin access to CloudFront only, because direct ALB requests will not carry the secret header.
With CloudFront as the only origin for an ALB, an attacker could hit the ALB directly. Storing a random string in Secrets Manager (with rotation), injecting it as a CloudFront origin-request custom header, and requiring that header via an AWS WAF rule on the ALB ensures only CloudFront-sourced requests reach the origin.
Trying to allowlist CloudFront IP ranges (Options B/D) — the ranges change frequently and are not a robust secret-based control; a secret header is the recommended pattern.
Community Discussion (8 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option A stores a random string in Secrets Manager with automatic rotation, configures CloudFront to add it as a custom origin-request header, and attaches an AWS WAF string-match rule to the ALB that allows only requests carrying that header. Direct hits to the ALB without the secret header are blocked, hardening the origin.Why the Other Options Are Wrong
Option B's text is malformed and relies on CloudFront IP allowlisting, which is brittle because the IP ranges change. Option C uses Parameter Store but only 'inspects' the header at the ALB without a WAF enforcement rule. Option D uses Shield Advanced and security-group IP allowlisting, again dependent on changing CloudFront IP ranges rather than a shared secret.Community Comment Notes
kejam (likes 6) links the AWS blog on using CloudFront custom headers, WAF, and Secrets Manager to restrict origin access. Win007 argues for D, but Shield Advanced does not by itself enforce the secret-header origin restriction.Official Reference
Related Analysis
Practice All SAP-C02 Questions
Access 85 questions with complete answers and detailed explanations.
View Full SAP-C02 Practice Test →