Courseiva
Design for New Solutions →easyMultiple Select

SAP-C02 Design for New Solutions Practice Question

A company is designing a new static website hosted on Amazon S3. They want to use Amazon CloudFront as a content delivery network (CDN) to serve the website globally with low latency. The website content must be encrypted in transit. Which configurations should they use? (Choose TWO.)

⚠ Common exam trap

Candidates often confuse encryption at rest (S3 default encryption) with encryption in transit, or they assume that CloudFront's default HTTPS support automatically secures the S3 origin connection without needing a bucket policy to enforce it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the S3 bucket policy to deny requests that do not use HTTPS.

Option C is correct because enforcing an S3 bucket policy with a Deny effect on aws:SecureTransport false ensures that any request reaching the S3 origin (including from CloudFront or direct callers) must use HTTPS/TLS, satisfying encryption in transit at the origin. Option D is correct because setting the CloudFront distribution's viewer protocol policy to redirect HTTP to HTTPS (or HTTPS only) guarantees that all client-to-edge traffic is encrypted with TLS, which is the primary in-transit path for a global static website. Option A is incorrect because AES-256 default encryption is server-side encryption at rest, not in transit. Option B is incorrect because S3 Transfer Acceleration speeds up uploads/downloads using AWS edge locations but does not enforce or provide encryption in transit. Option E is incorrect because CloudFront signed URLs control access/authorization to content, not transport encryption.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable default encryption on the S3 bucket using AES-256.

    Why it's wrong here

    Default bucket encryption with AES-256 protects data at rest on S3, not in transit between viewers and CloudFront. The requirement is encryption in transit, met by configuring CloudFront to redirect or require HTTPS. SSE-S3 default encryption is correct when the mandate is encrypting stored objects at rest.

  • ✗

    Enable S3 Transfer Acceleration on the bucket.

    Why it's wrong here

    S3 Transfer Acceleration speeds uploads into a bucket via edge locations; it does not encrypt traffic between viewers and CloudFront, nor does it serve cached content globally. It suits accelerating large uploads from geographically distant clients. Encryption in transit here comes from CloudFront enforcing HTTPS to viewers.

  • ✓

    Configure the S3 bucket policy to deny requests that do not use HTTPS.

    Why this is correct

    A bucket policy denying requests where aws:SecureTransport is false rejects any plaintext HTTP access to S3 objects. This satisfies the encrypted-in-transit requirement by ensuring content cannot be fetched from the origin over an unencrypted connection.

  • ✓

    Configure CloudFront to require HTTPS for viewer requests.

    Why this is correct

    Requiring HTTPS for viewer requests encrypts traffic between viewers and CloudFront edge locations, satisfying the in-transit encryption constraint for the public-facing leg. CloudFront terminates TLS at the edge, so viewer-to-edge connections use HTTPS while origin fetches are configured separately. This directly addresses the stem's requirement that website content be encrypted in transit.

  • ✗

    Use CloudFront signed URLs to restrict access.

    Why it's wrong here

    Signed URLs grant or deny access to individual objects, controlling authorisation rather than encrypting traffic. The stem requires encryption in transit, satisfied by CloudFront's viewer protocol policy redirecting HTTP to HTTPS. Signed URLs are the right choice when distributing private paid content or time-limited downloads to specific users.

Quick reference

Symmetric Encryption Algorithm Comparison

AlgorithmKey SizeBlock SizeStatusNotes
AES-128128-bit128-bitCurrent standardNIST approved; WPA3, TLS
AES-256256-bit128-bitCurrent standardPreferred for sensitive / govt data
3DES112-bit effective64-bitDeprecated (2023)Replaced by AES
DES56-bit64-bitBrokenCracked in < 24 h; never deploy
ChaCha20256-bitStream cipherCurrentTLS 1.3, WireGuard

About these practice questions

One of 984 original SAP-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SAP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SAP-C02 exam.