AWS SAP-C02 · Question 55 · Domain 2.3: Security Controls
A company is using Amazon S3 to host a static website. They want to use Amazon CloudFront to distribute the content globally. They must ensure that users can ONLY access the content via CloudFront, and direct access to the S3 bucket URL is blocked. How should this be configured?
Answer options:
Make the S3 bucket public and use CloudFront signed URLs.
Configure Origin Access Control (OAC) in CloudFront and update the S3 bucket policy to allow access only from the CloudFront distribution.
Use a VPC Endpoint for S3 and route CloudFront traffic through the VPC.
Configure AWS WAF on the S3 bucket to block non-CloudFront IPs.
75 questions · hints · full answers · grading