nerdexam
AmazonAmazon

SCS-C02 · Question #165

SCS-C02 Question #165: Real Exam Question with Answer & Explanation

Sign in or unlock SCS-C02 to reveal the answer and full explanation for question #165. The question stem and answer options stay visible for context.

Submitted by katya_ua· Mar 6, 2026Infrastructure Security

Question

A security engineer needs to set up an Amazon CloudFront distribution for an Amazon S3 bucket that hosts a static website. The security engineer must allow only specified IP addresses to access the website. The security engineer also must prevent users from accessing the website directly by using S3 URLs. Which solution will meet these requirements?

Options

  • AGenerate an S3 bucket policy. Specify cloudfront.amazonaws.com as the principal. Use the
  • BCreate a CloudFront origin access control (OAC). Create the S3 bucket policy so that only the
  • CImplement security groups to allow only the specified IP addresses access and to restrict S3
  • DCreate an S3 bucket access point to allow access from only the CloudFront distribution. Create

Unlock SCS-C02 to see the answer

You've previewed enough free SCS-C02 questions. Unlock SCS-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#CloudFront Security#S3 Bucket Policy#Origin Access Control#IP Restrictions
Full SCS-C02 PracticeBrowse All SCS-C02 Questions