CloudFront & AWS Global Accelerator Flashcards
What is a CDN
Content Delivery Network
- Improves read performance, content is cached at the edge
- 216 Point of Presence globally (edge locations)
- DDoS protection, integration with Shield, AWS Web Application Firewall
AWS CloudFront
A (blank) attack takes place when a bad actor overwhelms a server with malicious internet traffic to prevent legitimate users from accessing
applications, services, and networks
DDoS (Distributed Denial of Service)
What are the CloudFront origins?
S3 bucket & Custom Origin (HTTP)
Allow users to access content from certain countries
Whitelist
Prevent users from accessing content from certain countries
Blacklist
Use case: Copyright Laws to control access to content
Geo Restriction
- Global Edge network
- Files are cached for a TTL (maybe a day)
- Great for static content that must be available everywhere
CloudFront
- Must be setup for each region you want replication to happen
- Files are updated in near real-time
- Read only
- Great for dynamic content that needs to be available at low-latency in few regions
S3 Cross Region Replication
•Allow access to a path, no matter
the origin
• Account wide key-pair, only the root
can manage it
- Can filter by IP, path, date, expiration
- Can leverage caching features
CloudFront Signed URL
- Issue a request as the person who (blank)
- Uses the IAM key of the signing IAM principal
- Limited lifetime
S3 Pre-Signed URL
How can you reduce cost for CloudFront?
Reduce the # of edge locations
How many price classes for CloudFront are there? What are they?
- All
- 200
- 100
All
What CloudFront price class is this?
All regions - best performance
200
What CloudFront price class is this?
Most regions, but excludes most expensive regions