Courseiva

SAA-C03 Design Secure Architectures Practice Question

A media company uses an Amazon CloudFront distribution to serve content from a private S3 bucket. The security team wants to ensure that users cannot bypass CloudFront and access the S3 bucket directly, and that only the distribution can read objects. Which configuration should be implemented?

⚠ Common exam trap

The trap here is selecting origin access identity (OAI) out of familiarity, when OAC is the current recommended feature that supports additional capabilities like SSE-KMS.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an origin access control (OAC) for the distribution, update the bucket policy to allow the OAC, and block public access on the bucket.

Origin access control (OAC) is the modern, recommended way to secure S3 origins for CloudFront. It allows the distribution to sign requests to S3, and the bucket policy can be scoped to the OAC. Blocking public access ensures users cannot bypass CloudFront. This satisfies both requirements.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Create an origin access control (OAC) for the distribution, update the bucket policy to allow the OAC, and block public access on the bucket.

    Why this is correct

    Origin access control (OAC) is the current recommended method to secure S3 origins for CloudFront. It supports SSE-KMS, dynamic requests, and signed requests. Updating the bucket policy to allow the OAC and enabling S3 Block Public Access ensures direct access is denied and only CloudFront can read objects.

  • ✗

    Configure the S3 bucket as a website endpoint and use a bucket policy that allows only the CloudFront distribution's IP addresses.

    Why it's wrong here

    Using the S3 website endpoint does not support OAI or OAC and requires public access, which violates the requirement to prevent direct access. CloudFront IP addresses change frequently, so an IP-based policy is unreliable and insecure. This approach also prevents using signed URLs or cookies for private content.

  • ✗

    Set the S3 bucket ACL to private and enable CloudFront signed URLs for all objects.

    Why it's wrong here

    Signed URLs control access at the user level but do not prevent direct access to the S3 bucket if the bucket policy allows it. A private ACL alone does not restrict access to CloudFront; the bucket policy must explicitly allow the distribution. This approach does not meet the requirement to block direct S3 access.

  • ✗

    Create an origin access identity (OAI) for the distribution, update the bucket policy to allow the OAI, and block public access on the bucket.

    Why it's wrong here

    OAI is the legacy method and still works, but it is not the most current recommended approach. It does satisfy the requirement to restrict access to CloudFront and block direct access. However, the question asks for the configuration to implement; OAI is being replaced by OAC for new distributions, and OAC provides additional features like support for SSE-KMS and dynamic requests.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every SAA-C03 question from scratch — 935 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint

This SAA-C03 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAA-C03 exam.