Content distribution network (CDN)

A distributed set of servers that caches and serves content close to users; it can improve performance and availability, and where it terminates TLS the trust boundary moves to the provider.

A content distribution network, also called a content delivery network, serves content from caching servers placed in many locations, so each user is answered from a site near them rather than from the organisation’s own origin server. Users are directed to a nearby node by DNS or by anycast routing. The result is lower latency, less load on the origin, and resilience when one location fails.

A CDN can improve availability and can absorb volumetric attacks aimed at the content it serves, within its capacity, which is why providers commonly pair it with a web application firewall and distributed denial of service protection. Two design points matter. First, where the CDN terminates TLS, it sees the traffic in clear, so the trust boundary moves to the provider and becomes a matter for contracts and third-party assurance. Second, the origin should accept traffic only from the CDN; an attacker who finds the origin’s address can otherwise go around the CDN and its filtering.

Exam relevance: a scenario is likely to describe a CDN that decrypts traffic, or an origin still reachable from the internet, and ask for the risk. Candidates are expected to treat the CDN as part of the security design and a third party inside the trust boundary, not as a cache sitting outside it.