SAA-C03 Design Secure Architectures Practice Question
A media company uses an Amazon CloudFront distribution to serve content from a private S3 bucket. The security team wants to ensure that users cannot bypass CloudFront and access the S3 bucket directly, and that only the distribution can read objects. Which configuration should be implemented?
⚠ Common exam trap
The trap here is selecting origin access identity (OAI) out of familiarity, when OAC is the current recommended feature that supports additional capabilities like SSE-KMS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an origin access control (OAC) for the distribution, update the bucket policy to allow the OAC, and block public access on the bucket.
Origin access control (OAC) is the modern, recommended way to secure S3 origins for CloudFront. It allows the distribution to sign requests to S3, and the bucket policy can be scoped to the OAC. Blocking public access ensures users cannot bypass CloudFront. This satisfies both requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create an origin access control (OAC) for the distribution, update the bucket policy to allow the OAC, and block public access on the bucket.
Why this is correct
Origin access control (OAC) is the current recommended method to secure S3 origins for CloudFront. It supports SSE-KMS, dynamic requests, and signed requests. Updating the bucket policy to allow the OAC and enabling S3 Block Public Access ensures direct access is denied and only CloudFront can read objects.
- ✗
Configure the S3 bucket as a website endpoint and use a bucket policy that allows only the CloudFront distribution's IP addresses.
Why it's wrong here
Using the S3 website endpoint does not support OAI or OAC and requires public access, which violates the requirement to prevent direct access. CloudFront IP addresses change frequently, so an IP-based policy is unreliable and insecure. This approach also prevents using signed URLs or cookies for private content.
- ✗
Set the S3 bucket ACL to private and enable CloudFront signed URLs for all objects.
Why it's wrong here
Signed URLs control access at the user level but do not prevent direct access to the S3 bucket if the bucket policy allows it. A private ACL alone does not restrict access to CloudFront; the bucket policy must explicitly allow the distribution. This approach does not meet the requirement to block direct S3 access.
- ✗
Create an origin access identity (OAI) for the distribution, update the bucket policy to allow the OAI, and block public access on the bucket.
Why it's wrong here
OAI is the legacy method and still works, but it is not the most current recommended approach. It does satisfy the requirement to restrict access to CloudFront and block direct access. However, the question asks for the configuration to implement; OAI is being replaced by OAC for new distributions, and OAC provides additional features like support for SSE-KMS and dynamic requests.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.