SCS-C02 Infrastructure Security Practice Question
A company wants to host a static website in an Amazon S3 bucket. The bucket must be private and accessible only through an Amazon CloudFront distribution. Which configuration ensures that CloudFront can access the S3 bucket while blocking direct access via S3 URL?
⚠ Common exam trap
The trap is confusing OAC with OAI or thinking that a bucket policy allowing the CloudFront service principal is enough; the key is that the policy must be tied to the specific distribution via OAC and condition keys.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an Origin Access Control (OAC) and update the bucket policy to allow access only to the CloudFront distribution
Origin Access Control (OAC) is the recommended way to secure an S3 origin for CloudFront. OAC allows CloudFront to sign requests to S3, and the bucket policy can be configured to allow access only from the specific CloudFront distribution using the OAC. This blocks direct access via S3 URL because the bucket policy does not grant public access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use CloudFront signed URLs and configure the bucket policy to allow access from CloudFront IP ranges
Why it's wrong here
Signed URLs are a mechanism for controlling end-user access to CloudFront content, not for authenticating CloudFront to an S3 origin. Relying on CloudFront IP ranges in a bucket policy is insecure because those ranges are shared across all AWS customers and change frequently, meaning any CloudFront distribution or other service using those IPs could fetch your objects. CloudFront origin requests do not consistently originate from a predictable IP, so you should use Origin Access Control (OAC) with a principal-based policy instead of IP-based allow rules.
- ✗
Enable S3 Block Public Access and configure CloudFront to use the bucket as an origin
Why it's wrong here
Enabling S3 Block Public Access only prevents public (anonymous) access; it does not grant CloudFront permission to read the bucket. Without an explicit bucket policy that authorizes the CloudFront distribution's principal (via OAC) or an origin access identity, CloudFront's origin requests will be denied with 403. This option is incomplete because it omits the required authorization mechanism, and merely combining BPA with an origin configuration does not establish a secure or functional private origin.
- ✗
Configure the bucket policy to allow s3:GetObject from the CloudFront service principal
Why it's wrong here
A bucket policy that allows s3:GetObject to the CloudFront service principal without a condition is overly broad and insecure: any CloudFront distribution can use that principal to access your bucket. OAC is the modern secure method, and it requires the service principal plus an aws:SourceArn condition that pins access to your specific distribution. The older OAI method, by contrast, uses a canonical user ID in the bucket policy, not the CloudFront service principal, so this option conflates and misapplies the two mechanisms.
- ✓
Create an Origin Access Control (OAC) and update the bucket policy to allow access only to the CloudFront distribution
Why this is correct
Origin Access Control (OAC) is the recommended way to keep an S3 bucket private while allowing only CloudFront to retrieve objects. You create an OAC, associate it with the distribution's origin, and update the bucket policy to permit s3:GetObject for the cloudfront.amazonaws.com principal under a condition like aws:SourceArn that matches your specific distribution. This prevents direct S3 access via the bucket URL, supports SSE-KMS encryption, and works seamlessly with S3 Block Public Access for a least-privilege, secure static website architecture.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 1,205 original SCS-C02 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Amazon Web Services exam blueprint
This SCS-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SCS-C02 exam.