CLF-C02 Security and Compliance Practice Question
A company stores sensitive audit reports in an Amazon S3 bucket. An external auditor needs to download a specific report for a compliance review. The auditor does not have an AWS account and will only need access for 48 hours. The company wants to provide a secure, time-limited link that allows the auditor to download the file directly from S3 without making the bucket public or requiring the auditor to authenticate with AWS. Which AWS feature should the company use to meet these requirements?
⚠ Common exam trap
The trap here is that candidates may overcomplicate the solution by choosing CloudFront signed URLs (Option D) because they associate signed URLs with security, but the question explicitly requires a direct S3 download without additional services, making the simpler S3 presigned URL the correct choice.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
S3 presigned URL generated with a 48-hour expiration
An S3 presigned URL allows the company to grant temporary, time-limited access to a specific object in a private S3 bucket without requiring the auditor to have AWS credentials. By generating the URL with a 48-hour expiration, the company meets the exact requirement for secure, time-bound access. The auditor can download the file directly via HTTPS using the presigned URL, which embeds the necessary authentication information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
S3 bucket policy with a condition that restricts access by IP address
Why it's wrong here
An S3 bucket policy with an IP address condition would allow requests from that IP, but requests still require valid AWS credentials (e.g., Signature V4) unless the bucket is made public. This does not provide a simple time-limited link for a user without credentials, and it would open access to all objects from that IP, not just the specific file.
When this WOULD be correct
A company needs to allow access to an S3 bucket only from a specific corporate IP range for all users, and the users have AWS credentials (e.g., IAM users) that can be authenticated via the bucket policy.
- ✗
IAM role with cross-account access for the auditor's AWS account
Why it's wrong here
An IAM role with cross-account access requires the auditor to have an AWS account and to assume the role. The auditor does not have an AWS account, so this option does not meet the requirement. Moreover, it would grant access to all resources the role allows, not a single time-limited download.
When this WOULD be correct
A company needs to grant an external partner with their own AWS account temporary access to specific S3 objects. The partner's account must be allowed to assume a role that has permissions to read the objects, and the access should be time-limited via the role's session duration.
- ✓
S3 presigned URL generated with a 48-hour expiration
Why this is correct
An S3 presigned URL is the correct solution. It allows the company to generate a URL that provides temporary access to a specific S3 object. The URL includes a signature that expires after the specified time (48 hours). The auditor can simply use the URL to download the file without needing AWS credentials or any other authentication, and the bucket remains private.
- ✗
CloudFront signed URL using a trusted key group
Why it's wrong here
A CloudFront signed URL with a trusted key group restricts access at the CDN level, but the auditor has no AWS account and the requirement is to grant direct S3 download access without CloudFront. The correct mechanism, a presigned URL, generates time-limited access directly from S3 using IAM credentials, whereas CloudFront signed URLs require a CloudFront distribution and a trusted key group for signature verification. This option is tempting because it also provides secure, time-limited access to content, and would be correct if the company wanted to serve the file through CloudFront for caching or geographic distribution.
When this WOULD be correct
A company needs to distribute content globally with low latency and wants to restrict access to specific users using signed URLs or cookies, while also benefiting from CloudFront's caching and DDoS protection. The auditor would access the file via a CloudFront URL, not directly from S3.
Option-by-option analysis
Why each answer is right or wrong
Understanding why wrong answers are wrong — and when they would be correct — is what separates a 750 score from a 900. The CLF-C02 exam frequently reuses these exact scenarios with slightly different constraints.
✓S3 presigned URL generated with a 48-hour expirationCorrect answer▾
Why this is correct
An S3 presigned URL is the correct solution. It allows the company to generate a URL that provides temporary access to a specific S3 object. The URL includes a signature that expires after the specified time (48 hours). The auditor can simply use the URL to download the file without needing AWS credentials or any other authentication, and the bucket remains private.
✗S3 bucket policy with a condition that restricts access by IP addressWrong answer — click to see why▾
Why this is wrong here
The auditor does not have an AWS account, so an S3 bucket policy restricting by IP address would still require the auditor to have AWS credentials to access the bucket, which they lack.
★ When this WOULD be the correct answer
A company needs to allow access to an S3 bucket only from a specific corporate IP range for all users, and the users have AWS credentials (e.g., IAM users) that can be authenticated via the bucket policy.
Why candidates choose this
Candidates may think IP-based restrictions are sufficient for security and overlook that the auditor has no AWS credentials to authenticate, assuming the policy alone grants access.
✗IAM role with cross-account access for the auditor's AWS accountWrong answer — click to see why▾
Why this is wrong here
The auditor does not have an AWS account, so cross-account access via an IAM role is not possible. IAM roles require the external user to have an AWS account to assume the role.
★ When this WOULD be the correct answer
A company needs to grant an external partner with their own AWS account temporary access to specific S3 objects. The partner's account must be allowed to assume a role that has permissions to read the objects, and the access should be time-limited via the role's session duration.
Why candidates choose this
Candidates may think cross-account IAM roles are the standard way to grant external access, overlooking the requirement that the auditor lacks an AWS account.
✗CloudFront signed URL using a trusted key groupWrong answer — click to see why▾
Why this is wrong here
CloudFront signed URLs require the auditor to access the content through CloudFront, not directly from S3, and involve setting up a CloudFront distribution with an origin access identity, which is unnecessary for a simple, time-limited direct S3 download.
★ When this WOULD be the correct answer
A company needs to distribute content globally with low latency and wants to restrict access to specific users using signed URLs or cookies, while also benefiting from CloudFront's caching and DDoS protection. The auditor would access the file via a CloudFront URL, not directly from S3.
Why candidates choose this
Candidates may confuse CloudFront signed URLs with S3 presigned URLs, thinking both provide time-limited access, but they overlook that CloudFront signed URLs require a CloudFront distribution and are not for direct S3 access.
Analysis generated from the official CLF-C02blueprint and verified against question context. The “when correct” sections are what AI assistants cite when candidates ask “what’s the difference between these options?”
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CLF-C02 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CLF-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CLF-C02 exam.