AWS Certified Advanced Networking – Specialty (ANS-C01)Network Security, Compliance, and GovernanceMedium
A media company uses Amazon CloudFront to distribute video content globally. To comply with regional content licensing agreements, they need to restrict access to specific content based on the viewer's geographic location. Additionally, they must protect against common web exploits like SQL injection and cross-site scripting. Which combination of AWS services should be used to meet these requirements?
- AVPC Network ACLs and AWS Global Accelerator
- BAWS WAF with Geo-restriction rules and CloudFront
- CAmazon Route 53 Geolocation routing and Security Groups
- DAWS Shield Advanced and Amazon S3 bucket policies
Show answer & explanationAnswer & explanation
Correct answer: B. AWS WAF with Geo-restriction rules and CloudFront
CloudFront's geo-restriction feature, configured at the distribution level, allows restricting content access based on the viewer's country. AWS WAF, when integrated with CloudFront, provides protection against common web exploits like SQL injection and cross-site scripting by inspecting HTTP/S requests.
Why the other options are wrong
- A. VPC Network ACLs are for subnet-level network filtering, and AWS Global Accelerator improves performance by routing traffic through the AWS global network, neither provides geo-restriction for content or web exploit protection.
- C. Route 53 Geolocation routing directs users to different endpoints based on location but doesn't restrict content access or protect against web exploits. Security Groups are for instance-level network filtering.
- D. AWS Shield Advanced provides DDoS protection, and S3 bucket policies control access to S3 objects, neither addresses geo-restriction for CloudFront nor web exploits.
CloudFront Geo-restriction & AWS WAF
CloudFront's built-in feature to control content access based on geographic location, combined with AWS WAF for protection against common web exploits.
- CloudFront Geo-restriction: blocks/allows access by country.
- AWS WAF: protects web applications from common exploits.
- WAF integrates directly with CloudFront.
- Both applied at the edge for optimal performance.
Memory trick: CloudFront serves, Geo-restriction says 'where', WAF blocks 'bad' requests.