Protect HLS CloudFront streams with signed cookies instead of per-chunk signed URLs

Answer Correct answer: B — CloudFront signed cookies authorize all HLS chunks after one authentication, avoiding per-chunk signed URLs.

A company uses HTTP Live Streaming (HLS) to stream live video content to paying subscribers by using Amazon CloudFront. HLS splits the video content into chunks so that the user can request the right chunk based on different conditions. Because the video events last for several hours, the total video is made up of thousands of chunks. The origin URL is not disclosed, and every user is forced to access the CloudFront URL. The company has a web application that authenticates the paying users against an internal repository and a CloudFront key pair that is already issued. What is the simplest and MOST effective way to protect the content?

  1. Develop the application to use the CloudFront key pair to create signed URLs that users will use to access the content.
  2. Develop the application to use the CloudFront key pair to set the signed cookies that users will use to access the content. Correct Answer
  3. Develop the application to issue a security token that Lambda@Edge will receive to authenticate and authorize access to the content.
  4. Keep the CloudFront URL encrypted inside the application, and use AWS KMS to resolve the URL on-the-fly after the user is authenticated.

Community Votes

B
67%
A
33%

67% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

For content composed of many objects (like HLS chunks), signed cookies are far more efficient than signed URLs: one cookie set authorizes all requests to a path/pattern, whereas signed URLs would require generating a unique signed URL for every chunk. With a CloudFront key pair already issued, the app only needs to mint signed cookies post-authentication.

An HLS live stream served through CloudFront is split into thousands of chunks, and only authenticated subscribers should fetch them. Because a single video session requests thousands of objects, signing each chunk URL individually is wasteful. CloudFront signed cookies let the application set a small set of cookies once after authenticating the user, authorizing all chunk requests under a path without per-request URL generation.

Using signed URLs (option A) for HLS—generating a signed URL per chunk adds heavy overhead and complexity across thousands of requests. Lambda@Edge token checks (option C) or KMS URL hiding (option D) are more complex than necessary for this access-control need.

Community Discussion (6 comments)

Pat9595 👍 1 Selected: B
B. Develop the application to use the CloudFront key pair to set the signed cookies that users will use to access the content. ✅ Why? HLS uses thousands of chunks per video stream. If you use signed URLs (Option A), the application would need to generate a signed URL for each chunk, creating unnecessary overhead. Signed cookies allow multiple requests to be authenticated with a single authentication step. This is more efficient for streaming, as the client can request all chunks without needing new signed URLs each time. The origin URL is hidden behind CloudFront, ensuring users can only access content through the authorized method.
youonebe 👍 1 Selected: B
Signed URLs are effective but less efficient than signed cookies for HLS or other scenarios involving many pieces of content. For HLS, where multiple chunks are requested over time, generating signed URLs for each request could become cumbersome and inefficient. Signed cookies are a more scalable solution in such cases. Signed cookies allow the application to grant access to multiple pieces of content (like thousands of video chunks in the case of HLS) without needing to generate signed URLs for each request. This is especially useful for cases where there are many content requests, such as when streaming video or serving large amounts of data that would involve many individual URLs (as in HLS).
TareDHakim 👍 1 Selected: A
is is MOST efficient A using Signed URLs work well for single object access but are inefficient for HLS, which involves thousands of chunk requests. Generating a unique signed URL for each chunk is operationally complex and may degrade performance.
sendjawemail 👍 2 Selected: B
For HLS content, use signed cookies https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-choosing-signed-urls-cookies.html
IPLogic 👍 1 Selected: A
The simplest and most effective way to protect the content is: A. Develop the application to use the CloudFront key pair to create signed URLs that users will use to access the content. Using signed URLs ensures that only authenticated users can access the content by including additional information such as an expiration date and time in the URL. This method is straightforward to implement and provides robust security for your streaming content.
Bad_Mat 👍 1
The answer is B. "signed cookies"

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

HLS delivers a stream as thousands of individual chunk objects. Signed cookies let the application authenticate the user once and then set cookies that authorize all subsequent chunk requests to the protected path, avoiding per-chunk URL signing. This is the simplest and most effective approach given the high object count and the already-issued CloudFront key pair.

Why the Other Options Are Wrong

A (signed URLs) works but is inefficient for HLS because each of the thousands of chunks would need its own signed URL, creating unnecessary operational overhead. C (Lambda@Edge token validation) adds compute and complexity beyond what signed cookies provide. D (hiding the URL in KMS) protects the URL string but does not enforce per-user authorization the way signed cookies do.

Community Comment Notes

Community favored B (67 votes). Commenters noted HLS's thousands of chunks make signed cookies the scalable choice, while signed URLs would require generation per chunk. A minority picked A, but the efficiency argument favors cookies.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide