SAA-C03 Design Secure Architectures Practice Question
A image sharing application uses CloudFront in front of an S3 origin. Which two settings help keep users from bypassing CloudFront and accessing the bucket directly?
⚠ Common exam trap
Test-takers frequently confuse enabling S3 static website hosting (which creates a public endpoint) with a security control, when in fact it would undermine the goal of restricting direct access.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure Origin Access Control for the S3 origin
Option C is correct because Origin Access Control (OAC) is the mechanism that lets CloudFront sign requests to the S3 origin using SigV4, so the bucket can reject any request that does not come through the distribution. Option D is correct because an S3 bucket policy that grants access only to the CloudFront distribution's service principal (or to the distribution ARN via the OAC) enforces at the bucket level that direct requests from users are denied. Together, OAC plus a restrictive bucket policy prevent users from bypassing CloudFront and hitting the S3 bucket directly. Option A is not correct because CloudFront standard logging only records requests for auditing and does not block direct access to the origin. Option B is not correct because enabling S3 static website hosting actually makes the bucket more directly reachable via the website endpoint and does not restrict bypassing CloudFront.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable CloudFront standard logging
Why it's wrong here
Standard logging records viewer requests after they reach CloudFront; it neither authenticates the origin nor blocks direct S3 requests, so bypass remains possible. It is tempting because logging supports auditing and troubleshooting distributions, which is its actual purpose, but the stem asks for preventative access controls.
- ✗
Enable S3 static website hosting
Why it's wrong here
Static website hosting exposes the bucket through the S3 website endpoint, which does not support signed URLs or origin access control, so users can still fetch objects directly. It is tempting because it serves index and error documents for public sites, but that is the opposite of restricting access to CloudFront.
- ✓
Configure Origin Access Control for the S3 origin
Why this is correct
Origin Access Control signs CloudFront requests to the S3 origin, letting you remove public read access from the bucket policy so only the distribution's identity is granted `s3:GetObject`. This directly satisfies the requirement that users cannot bypass CloudFront, since unsigned direct requests to the bucket are denied.
- ✓
Use an S3 bucket policy that allows access only from the CloudFront distribution
Why this is correct
An S3 bucket policy restricting access to the CloudFront distribution satisfies the bypass constraint by rejecting requests that arrive directly at the bucket's endpoint. CloudFront reaches the origin using its own identity, so the policy can permit only that distribution while denying all other principals, preventing users from circumventing the CDN.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 935 original SAA-C03 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.