@Stephen Wartel Thanks for confirmation. Sharing the resolution which works for you. I am resharing here for helping wider community facing similar issues.
Update- The issue is resolved -
Added new rule in CDN endpoint to modify response header Content Security Policy to frame-ancestors <my referrer URL-which is the custom domain>, which now allows an iFrame (sourced from the CDN backend) to be embedded in the calling WordPress page with no block.
Calling page in WordPress can be restricted to user/membership level to assure that helping exercise safe-use lesson is completed first (safety goal of access restriction).
Please accept as "Yes" if the answer provided is useful, so that you can help others in the community looking for remediation for similar issues.