Amazon
SOA-C02 · Question #226
An Amazon CloudFront distribution has a single Amazon S3 bucket as its origin. A SysOps administrator must ensure that users can access the S3 bucket only through requests from the CloudFront endpoint
Sign in or unlock SOA-C02 to reveal the answer and full explanation for question #226. The question stem and answer options stay visible for context.
Submitted by viktor_hu· Mar 30, 2026Security and Compliance
Question
An Amazon CloudFront distribution has a single Amazon S3 bucket as its origin. A SysOps administrator must ensure that users can access the S3 bucket only through requests from the CloudFront endpoint. Which solution will meet these requirements?
Options
- AConfigure S3 Block Public Access on the S3 bucket.
- BConfigure Origin Shield in the CloudFront distribution.
- CCreate an origin access identity (OAI). Assign the OAI to the CloudFront distribution.
- DCreate an origin access identity (OAI). Assign the OAI to the S3 bucket.
Unlock SOA-C02 to see the answer
You've previewed enough free SOA-C02 questions. Unlock SOA-C02 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.
Topics
#CloudFront OAI#S3 bucket access control#origin access identity#content delivery security