nerdexam
Amazon

SOA-C02 · Question #370

A company is storing media content in an Amazon S3 bucket and uses Amazon CloudFront to distribute the content to its users. Due to licensing terms, the company is not authorized to distribute the…

The correct answer is C. Enable the geo restriction feature in the CloudFront distribution to prevent access from. https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/georestrictions.html

Submitted by kim_seoul· Mar 30, 2026Networking and Content Delivery

Question

A company is storing media content in an Amazon S3 bucket and uses Amazon CloudFront to distribute the content to its users. Due to licensing terms, the company is not authorized to distribute the content in some countries. A SysOps administrator must restrict access to certain countries. What is the MOST operationally efficient solution that meets these requirements?

Options

  • AConfigure the S3 bucket policy to deny the GetObject operation based on the
  • BCreate a secondary origin access identity (OAI). Configure the S3 bucket policy to prevent access
  • CEnable the geo restriction feature in the CloudFront distribution to prevent access from
  • DUpdate the application to generate signed CloudFront URLs only for IP addresses in authorized

How the community answered

(56 responses)
  • A
    13% (7)
  • B
    5% (3)
  • C
    79% (44)
  • D
    4% (2)

Explanation

https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/georestrictions.html

Topics

#CloudFront geo restriction#S3 content distribution#licensing compliance#content delivery

Community Discussion

No community discussion yet for this question.

Full SOA-C02 Practice