A medical company is running a REST API on a set of Amazon EC2 instances The EC2 instances run in an Auto Scaling group behind an Application Load Balancer (ALB) The ALB runs in three public subnets, and the EC2 instances run in three private subnets The company has deployed an Amazon CloudFront distribution that has the ALB as the only origin
Which solution should a solutions architect recommend to enhance the origin security?
Store Secret in AWS Secrets Manager:
Create a random string in AWS Secrets Manager to be used as a custom HTTP header value.
Set Up Automatic Rotation:
Implement a Lambda function to handle automatic rotation of the secret in AWS Secrets Manager, ensuring the header value remains secure.
Configure CloudFront Custom Header:
In the CloudFront distribution settings, configure an origin custom header with the name and value from AWS Secrets Manager. This header will be included in requests forwarded to the ALB.
Create AWS WAF Web ACL:
Create a Web ACL in AWS WAF with a string match rule to allow requests that include the custom header with the correct value.
Associate the Web ACL with the ALB to filter incoming traffic based on the custom header.
By using this method, you can ensure that only requests coming through CloudFront (which injects the custom header) can reach the ALB, enhancing the origin security
Cassandra
3 months agoJesusita
3 months agoLaticia
3 months agoMelissa
4 months agoTesha
4 months agoPearlene
4 months agoSkye
4 months agoLawrence
4 months agoCarlee
5 months agoLovetta
5 months agoOretha
5 months agoMarshall
5 months agoBrock
5 months agoCarma
5 months agoQuentin
5 months agoTruman
5 months agoMarg
2 years agoLinette
2 years agoChana
2 years agoPortia
2 years agoVerlene
2 years agoShakira
2 years agoCyndy
2 years agoTenesha
2 years agoElfrieda
2 years agoLenora
2 years agoDion
2 years agoAlishia
2 years agoYuki
2 years agoYoulanda
2 years agoLynelle
2 years agoShawnda
2 years agoBobbye
2 years agoTammi
2 years agoCandra
2 years agoIra
2 years ago