Month End Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Amazon Web Services AWS Certified DevOps Engineer - Professional DOP-C02 Question # 41 Topic 5 Discussion

Amazon Web Services AWS Certified DevOps Engineer - Professional DOP-C02 Question # 41 Topic 5 Discussion

DOP-C02 Exam Topic 5 Question 41 Discussion:
Question #: 41
Topic #: 5

A company deployed an Amazon CloudFront distribution that accepts requests and routes to an Amazon API Gateway HTTP API. During a recent security audit, the company discovered that requests from the internet could reach the HTTP API without using the CloudFront distribution.

A DevOps engineer must ensure that connections to the HTTP API use the CloudFront distribution.

Which solution will meet these requirements?


A.

Enable VPC Flow Logs to identify requests that reach the HTTP API.


B.

Deploy AWS WAF in front of the CloudFront distribution.


C.

Implement an identity-based policy on the CloudFront distribution that requires authentication to make requests to the HTTP API.


D.

Implement a custom header in the CloudFront distribution. Implement an AWS Lambda authorizer associated with the HTTP API that verifies the custom header.


Get Premium DOP-C02 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.