Courseiva
Infrastructure Security →easyMultiple Choice

SCS-C02 Infrastructure Security Practice Question

A company uses Amazon CloudFront to distribute content from an S3 bucket. The security team wants to ensure that only CloudFront can access the S3 bucket. Which configuration should be used?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create an Origin Access Identity (OAI) and grant it read access to the S3 bucket.

An Origin Access Identity (OAI) is a special CloudFront user that you can associate with a distribution, and then the S3 bucket policy can grant read access to that OAI, ensuring that only CloudFront can access the bucket. Option A is incorrect because allowing all principals is too permissive. Option B is incorrect because CloudFront IP addresses can change, so this is not a reliable method. Option D is incorrect because trusted signers are used for signed URLs/cookies to control who can access content, not to restrict origin access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Set the bucket policy to allow all principals and rely on CloudFront to restrict access.

    Why it's wrong here

    Setting the bucket policy to allow all principals removes S3-level authentication entirely, meaning anyone who discovers the bucket's direct endpoint can retrieve objects without going through CloudFront. CloudFront does not enforce any access policy on the origin when the bucket is publicly readable; it simply caches and serves content that is already open. This configuration makes the content publicly accessible and bypasses CloudFront's security controls.

  • ✗

    Configure the bucket policy to allow access only from CloudFront's IP addresses.

    Why it's wrong here

    CloudFront's IP address ranges are published but are shared across all distributions and can change without notice, making a bucket policy that references them brittle and potentially broken. Moreover, S3 bucket policies cannot distinguish requests coming through a specific CloudFront distribution from other traffic that happens to originate within CloudFront's IP space, because those IPs are used by many customers. AWS explicitly recommends against using IP allowlists for origin access control; the correct method is to authorize a CloudFront identity, not a network range.

  • ✓

    Create an Origin Access Identity (OAI) and grant it read access to the S3 bucket.

    Why this is correct

    An Origin Access Identity (OAI) is a dedicated CloudFront user identity that CloudFront uses to authenticate to S3 when fetching objects. By granting the OAI read permission (e.g., s3:GetObject) in the bucket policy and removing public access, the bucket becomes private and only requests authenticated as that OAI can succeed. This ensures direct S3 access by anonymous users is denied while CloudFront can still retrieve and distribute the content.

  • ✗

    Use CloudFront trusted signers to restrict access to the S3 bucket.

    Why it's wrong here

    Trusted signers are AWS accounts that CloudFront authorizes to create signed URLs or signed cookies; they control which viewers can access content at the edge, not how CloudFront connects to an S3 origin. Using trusted signers in the bucket policy would conflate viewer-level authentication with origin-level access control, and S3 would still see requests coming from CloudFront itself rather than the trusted signer. Trusted signers do not grant any S3 permissions, so they cannot be used to restrict origin access to the bucket.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.