0Pricing
AWS Security Academy · Lesson

Securing the CloudFront Edge

Use the global edge to terminate and protect inbound traffic.

CloudFront as Security Edge

Amazon CloudFront is the AWS content delivery network (CDN) that serves content from global edge locations. Beyond speed, it is a powerful security boundary: it terminates connections at the edge, absorbs DDoS via Shield, hosts WAF inspection, and hides your origin from direct exposure.

TLS Termination at the Edge

CloudFront terminates TLS at the nearest edge location, encrypting traffic between users and the edge with modern protocols and ciphers you configure via a security policy. You can also enforce HTTPS-only by redirecting HTTP to HTTPS, ensuring data in transit is always encrypted.

All lessons in this course

  1. What AWS Network Firewall Provides
  2. Stateful Rule Groups and Suricata Rules
  3. Domain Filtering and Egress Control
  4. Securing the CloudFront Edge
← Back to AWS Security Academy