SCS-C02 Infrastructure Security Practice Question
A company uses Amazon CloudFront to distribute content from an S3 bucket. The security team wants to ensure that only CloudFront can access the S3 bucket. Which configuration should be used?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Origin Access Identity (OAI) and grant it read access to the S3 bucket.
An Origin Access Identity (OAI) is a special CloudFront user that you can associate with a distribution, and then the S3 bucket policy can grant read access to that OAI, ensuring that only CloudFront can access the bucket. Option A is incorrect because allowing all principals is too permissive. Option B is incorrect because CloudFront IP addresses can change, so this is not a reliable method. Option D is incorrect because trusted signers are used for signed URLs/cookies to control who can access content, not to restrict origin access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Set the bucket policy to allow all principals and rely on CloudFront to restrict access.
Why it's wrong here
Setting the bucket policy to allow all principals removes S3-level authentication entirely, meaning anyone who discovers the bucket's direct endpoint can retrieve objects without going through CloudFront. CloudFront does not enforce any access policy on the origin when the bucket is publicly readable; it simply caches and serves content that is already open. This configuration makes the content publicly accessible and bypasses CloudFront's security controls.
- ✗
Configure the bucket policy to allow access only from CloudFront's IP addresses.
Why it's wrong here
CloudFront's IP address ranges are published but are shared across all distributions and can change without notice, making a bucket policy that references them brittle and potentially broken. Moreover, S3 bucket policies cannot distinguish requests coming through a specific CloudFront distribution from other traffic that happens to originate within CloudFront's IP space, because those IPs are used by many customers. AWS explicitly recommends against using IP allowlists for origin access control; the correct method is to authorize a CloudFront identity, not a network range.
- ✓
Create an Origin Access Identity (OAI) and grant it read access to the S3 bucket.
Why this is correct
An Origin Access Identity (OAI) is a dedicated CloudFront user identity that CloudFront uses to authenticate to S3 when fetching objects. By granting the OAI read permission (e.g., s3:GetObject) in the bucket policy and removing public access, the bucket becomes private and only requests authenticated as that OAI can succeed. This ensures direct S3 access by anonymous users is denied while CloudFront can still retrieve and distribute the content.
- ✗
Use CloudFront trusted signers to restrict access to the S3 bucket.
Why it's wrong here
Trusted signers are AWS accounts that CloudFront authorizes to create signed URLs or signed cookies; they control which viewers can access content at the edge, not how CloudFront connects to an S3 origin. Using trusted signers in the bucket policy would conflate viewer-level authentication with origin-level access control, and S3 would still see requests coming from CloudFront itself rather than the trusted signer. Trusted signers do not grant any S3 permissions, so they cannot be used to restrict origin access to the bucket.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.