exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 107 discussion

An Amazon CloudFront distribution has a single Amazon S3 bucket as its origin. A SysOps administrator must ensure that users can access the S3 bucket only through requests from the CloudFront endpoint.
Which solution will meet these requirements?

  • A. Configure S3 Block Public Access on the S3 bucket. Update the S3 bucket policy to allow the GetObject action from only the CloudFront distribution.
  • B. Configure Origin Shield in the CloudFront distribution. Update the CloudFront origin to include a custom Origin_Shield header.
  • C. Create an origin access identity (OAI). Assign the OAI to the CloudFront distribution. Update the S3 bucket policy to restrict access to the OAI.
  • D. Create an origin access identity (OAI). Assign the OAI to the S3 bucket. Update the CloudFront origin to include a custom Origin header with the OAI value.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
kati2k22cz
Highly Voted 1 year, 8 months ago
Selected Answer: C
C is the correct answer https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-restricting-access-to-s3.html
upvoted 5 times
...
jipark
Most Recent 8 months, 3 weeks ago
Selected Answer: C
Origin Access Identity (OAI): An OAI is a special CloudFront user that you can associate with one or more CloudFront distributions
upvoted 2 times
...
michaldavid
1 year, 4 months ago
Selected Answer: C
cccccccc
upvoted 2 times
...
Surferbolt
1 year, 6 months ago
Selected Answer: C
C is the answer
upvoted 4 times
...
elnurgu
1 year, 6 months ago
Answer C says, "..restrict access to OAI" I obviously didn't understand it. Why do we restrict access to OAI? Actually, I think we need to allow read-only access to OAI.
upvoted 3 times
jipark
8 months, 3 weeks ago
yes, 'restrict' mank confusion.
upvoted 1 times
...
Surferbolt
1 year, 6 months ago
They probably typed wrongly. If I recall correctly, the button reads somewhere along the lines of 'bucket can restrict access to only OAI', and what it achieves is allowing S3 objects to be accessed only through CloudFront.
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago