> For the complete documentation index, see [llms.txt](https://karansingh.gitbook.io/tutorialsdojo-wrong-answers-aws-sec-spec/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://karansingh.gitbook.io/tutorialsdojo-wrong-answers-aws-sec-spec/review-mode-test-1-93/cloudfront-security.md).

# CloudFront Security

* For web distributions, **CloudFront provides several options for securing content that it delivers**, including **configuring HTTPS connections, using WAF to control access to your content, or setting up field-level encryption for specific content fields**.

* In addition, you can **prevent users in specific geographic locations from accessing content distributed through a web distribution**.

* You also have the option of **restricting access to private content by requiring that users access that content by using CloudFront signed URLs or signed cookies**.<br>

* For web distributions, you **can configure CloudFront to require that viewers use HTTPS to request your objects**, so that **connections are encrypted when CloudFront communicates with viewers**.

* You also **can configure CloudFront to use HTTPS to get objects from your origin**, so that **connections are encrypted when CloudFront communicates with your origin**.<br>

* If you want to **require HTTPS between viewers and CloudFront**, you **must change the AWS region to US East (N. Virginia) in the AWS Certificate Manager console** before you request or import a certificate.

* If you want to **require HTTPS between CloudFront and your origin**, and **you're using an ELB load balancer as your origin**, you **can request or import a certificate in any region**.

![](https://560082743-files.gitbook.io/~/files/v0/b/gitbook-legacy-files/o/assets%2F-MT1aTjM0U73ienXQ-F0%2F-MTXwI4V2KLdD5b56bho%2F-MTY4xly11gk_DIZ-c4D%2Fimage.png?alt=media\&token=75c8bd9f-d69f-4eaa-9aad-01ef2e34907a)
