Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company is using Amazon CloudFront to serve static content from an S3 bucket. They want to restrict access so that only CloudFront can access the S3 bucket. How should this be configured?

⚠ Common exam trap

Candidates often confuse viewer-side access control (signed URLs) with origin-side access control (OAC/OAI), or mistakenly think that CloudFront can use IAM roles or static IP addresses to authenticate to S3.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure Origin Access Control (OAC) with the S3 bucket policy.

Origin Access Control (OAC) is the recommended method to restrict access to an S3 bucket so that only CloudFront can retrieve objects. When OAC is enabled, CloudFront signs requests to S3 using a specific principal, and the S3 bucket policy is configured to allow access only to that principal. This prevents direct access to the bucket via S3 URLs or other AWS services, ensuring that content is served exclusively through CloudFront.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure Origin Access Control (OAC) with the S3 bucket policy.

    Why this is correct

    Origin Access Control (OAC) is the modern, recommended way to restrict an S3 bucket to serve content only through CloudFront. OAC uses a service principal of cloudfront.amazonaws.com with a condition that requires the distribution's ID to match, and the bucket policy grants only GetObject to that principal. This blocks direct S3 access from outside CloudFront while also supporting encrypted S3 objects and SSE-KMS, giving verifiable origin security.

  • ✗

    Use CloudFront signed URLs or cookies.

    Why it's wrong here

    Signed URLs or cookies restrict which viewers can access content by requiring temporary, time-limited tokens at the CloudFront edge, but they do nothing to restrict the S3 origin itself. Without OAC or a restrictive bucket policy, anyone who discovers the S3 bucket's direct URL can still download the objects, bypassing CloudFront and its signing requirements. The origin remains publicly exposed, so this solution fails to secure the connection between CloudFront and S3.

  • ✗

    Attach an IAM role to CloudFront that grants S3 read access.

    Why it's wrong here

    CloudFront distributions cannot assume an IAM role to fetch objects from S3 because CloudFront does not support role-based authentication for origins; it uses Origin Access Control (OAC) or the legacy Origin Access Identity (OAI) instead. IAM roles are designed for entities such as EC2 instances, Lambda functions, or container tasks that have a fixed identity and credential lifecycle, whereas CloudFront edge nodes operate as a single managed service. Attaching a role to a distribution is not an available configuration, and even if attempted, it would not grant CloudFront the ability to sign S3 requests.

  • ✗

    Create a bucket policy that allows access only from the CloudFront distribution's IP addresses.

    Why it's wrong here

    Restricting by CloudFront's IP addresses is unreliable because CloudFront does not have a dedicated IP range; its global egress IPs are dynamic and can change without notice, so any bucket policy referencing those addresses is brittle and will break. Additionally, S3 bucket policies using aws:SourceIp cannot distinguish a legitimate CloudFront distribution from any other client that happens to come from the same shared IP range, so security can be bypassed. OAC avoids these issues by using cryptographic SigV4 authentication tied to a specific distribution ID, providing a stable and verifiable access control.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.