Answer – B
The AWS documentation mentions the following
Amazon CloudFront distributes traffic across multiple Points of Presence (PoP) locations and filters requests to ensure that only valid HTTP(S) requests will be forwarded to backend hosts. CloudFront also supports geo restriction, also known as geoblocking, which can be useful for isolating attacks originating from a particular geographic location
For more information on DDos attack mitigation , please refer to the below link:
https://aws.amazon.com/answers/networking/aws-ddos-attack-mitigation/