Signed URLs and signed cookies let you serve private content through CloudFront only to authorized users — a paid video, a members-only download — that expire after a set time.
Signed URL vs signed cookie
Signed URLs grant access to a single file — good for one paid download. Signed cookies grant access to multiple restricted files without changing each URL — good for a whole members’ area or a streaming library. The tell is “restrict CloudFront content to authorized/paying users.”
Test yourself
A streaming site must let paying subscribers access many private video files via CloudFront without generating a separate URL for each file. What should they use?
- Signed URLs
- Signed cookies
- A public bucket policy
- S3 Transfer Acceleration
👉 Click to reveal the answer & explanation
Correct answer: B. Signed cookies grant access to multiple restricted files at once, ideal for a whole members’ library. Signed URLs (A) are per-file; a public bucket (C) removes protection entirely; Transfer Acceleration (D) speeds uploads, unrelated to access control.
Related topics
Amazon CloudFront · CloudFront caching · Amazon S3
Ready to pass the AWS Solutions Architect Associate (SAA-C03)?
Stop guessing whether you’re ready. Our full-length, exam-realistic practice exams put you through the exact question style you’ll face — with a detailed explanation behind every answer, so you learn why, not just what.
- ✓ 6 full-length practice exams
- ✓ A detailed explanation for every single question
- ✓ Realistic, scenario-based questions — not memory dumps
- ✓ Lifetime access, kept current for 2026
Get the SAA-C03 Practice Exams →or try 25 free questions first