SCS-C02 · Question #84
A company has a web server in the AWS Cloud. The company will store the content for the web server in an Amazon S3 bucket. A security engineer must use an Amazon CloudFront distribution to speed up…
The correct answer is B. Create an origin access control (OAC). Associate the OAC with the CloudFront distribution. https://aws.amazon.com/blogs/networking-and-content-delivery/amazon-cloudfront-introduces- origin-access-control-oac/
Question
A company has a web server in the AWS Cloud. The company will store the content for the web server in an Amazon S3 bucket. A security engineer must use an Amazon CloudFront distribution to speed up delivery of the content. None of the files can be publicly accessible from the S3 bucket directly. Which solution will meet these requirements?
Options
- AConfigure the permissions on the individual files in the S3 bucket so that only the CloudFront
- BCreate an origin access control (OAC). Associate the OAC with the CloudFront distribution.
- CCreate an S3 role in AWS Identity and Access Management (IAM). Allow only the CloudFront
- DCreate an S3 bucket policy that uses only the CloudFront distribution ID as the principal and the
How the community answered
(45 responses)- A9% (4)
- B84% (38)
- C4% (2)
- D2% (1)
Explanation
https://aws.amazon.com/blogs/networking-and-content-delivery/amazon-cloudfront-introduces- origin-access-control-oac/
Topics
Community Discussion
No community discussion yet for this question.