Hardening a CloudFront origin with a secret custom header and WAF

Answer Correct answer: A — Store a rotated secret in Secrets Manager, have CloudFront inject it as an origin custom header, and require that header with an AWS WAF rule on the ALB.

A medical company is running a REST API on a set of Amazon EC2 instances. The EC2 instances run in an Auto Scaling group behind an Application Load Balancer (ALB). The ALB runs in three public subnets, and the EC2 instances run in three private subnets. The company has deployed an Amazon CloudFront distribution that has the ALB as the only origin. Which solution should a solutions architect recommend to enhance the origin security?

  1. Store a random string in AWS Secrets Manager. Create an AWS Lambda function for automatic secret rotation. Configure CloudFront to inject the random string as a custom HTTP header for the origin request. Create an AWS WAF web ACL rule with a string match rule for the custom header. Associate the web ACL with the ALB. Correct Answer
  2. Create an AWS WAF web ACL rule with an IP match condition of the CloudFront service IP address ranges. Associate the web ACL with the ALMove the ALB into the three private subnets.
  3. Store a random string in AWS Systems Manager Parameter Store. Configure Parameter Store automatic rotation for the string. Configure CloudFront to inject the random string as a custom HTTP header for the origin request. Inspect the value of the custom HTTP header, and block access in the ALB.
  4. Configure AWS Shield Advanced Create a security group policy to allow connections from CloudFront service IP address ranges. Add the policy to AWS Shield Advanced, and attach the policy to the ALB.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

A secret, rotated custom header injected by CloudFront plus an AWS WAF string-match rule on the ALB restricts origin access to CloudFront only, because direct ALB requests will not carry the secret header.

With CloudFront as the only origin for an ALB, an attacker could hit the ALB directly. Storing a random string in Secrets Manager (with rotation), injecting it as a CloudFront origin-request custom header, and requiring that header via an AWS WAF rule on the ALB ensures only CloudFront-sourced requests reach the origin.

Trying to allowlist CloudFront IP ranges (Options B/D) — the ranges change frequently and are not a robust secret-based control; a secret header is the recommended pattern.

Community Discussion (8 comments)

kejam 👍 6 Selected: A
In this blog post, you’ll see how to use CloudFront custom headers, AWS WAF, and AWS Secrets Manager to restrict viewer requests from accessing your CloudFront origin resources directly. https://aws.amazon.com/blogs/security/how-to-enhance-amazon-cloudfront-origin-security-with-aws-waf-and-aws-secrets-manager/
SIJUTHOMASP 👍 1 Selected: B
While secret manager can auto rotate the secrets why to use Lamda to rotate? The choice B is neater than A?
AzureDP900 👍 1
Option A is right Store a random string in Secrets Manager: This provides a secure way to store sensitive data, such as a token or secret key. Create an AWS Lambda function for automatic secret rotation: This ensures that the secret is regularly rotated and updated to prevent unauthorized access. Configure CloudFront to inject the random string as a custom HTTP header for the origin request: This adds an additional layer of protection by requiring the ALB to verify the custom header before allowing access. Create an AWS WAF web ACL rule with a string match rule for the custom header: This checks that the custom header matches the expected value, preventing unauthorized access if it doesn't. Associate the web ACL with the ALB: This ensures that the security rules are enforced at the edge of the network, protecting against malicious traffic. The other options don't provide sufficient protection:
Win007 👍 1
D is the correct Answer
career360guru 👍 1 Selected: A
Option A
TheCloudGuruu 👍 1 Selected: A
Answer is A
HunkyBunky 👍 2 Selected: A
A - is a proper answer https://aws.amazon.com/blogs/security/how-to-enhance-amazon-cloudfront-origin-security-with-aws-waf-and-aws-secrets-manager/
alexis123456 👍 4
Correct Answer is A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option A stores a random string in Secrets Manager with automatic rotation, configures CloudFront to add it as a custom origin-request header, and attaches an AWS WAF string-match rule to the ALB that allows only requests carrying that header. Direct hits to the ALB without the secret header are blocked, hardening the origin.

Why the Other Options Are Wrong

Option B's text is malformed and relies on CloudFront IP allowlisting, which is brittle because the IP ranges change. Option C uses Parameter Store but only 'inspects' the header at the ALB without a WAF enforcement rule. Option D uses Shield Advanced and security-group IP allowlisting, again dependent on changing CloudFront IP ranges rather than a shared secret.

Community Comment Notes

kejam (likes 6) links the AWS blog on using CloudFront custom headers, WAF, and Secrets Manager to restrict origin access. Win007 argues for D, but Shield Advanced does not by itself enforce the secret-header origin restriction.

Official Reference

Related Analysis

Practice All SAP-C02 Questions

Access 85 questions with complete answers and detailed explanations.

View Full SAP-C02 Practice Test →

← Back to SAP-C02 Study Guide