Earlier quoted context omitted.
Geo Restrictions on the Cloudfront distribution and a WAF will go a long way in mitigating against abuse and unnecessary costs.
Which locations are you gonna restrict from using your website? Is that how you want the web to generally work? WAF also doesn't seem to be free, where did you read that?
"Is that how you want the web to generally work?"
My suggestions on ways to prevent paying for CloudFront charges from junk requests are not prescriptive. However, they are AWS best practices when dealing with DDoS.
https://aws.amazon.com/answers/networking/aws-ddos-attack-mi...