Courseiva

SOA-C02 Networking and Content Delivery Practice Question

A company uses Amazon CloudFront to deliver static content from an S3 bucket. The SysOps administrator wants to restrict access so that only CloudFront can access the S3 bucket. Which solution should be used?

⚠ Common exam trap

Watch out — candidates often confuse origin security (restricting S3 bucket access to CloudFront) with viewer security (restricting who can view content via signed URLs or cookies), leading candidates to incorrectly choose signed URLs or key pairs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an origin access control (OAC) and update the S3 bucket policy to allow CloudFront access.

Origin Access Control (OAC) is the recommended method to restrict S3 bucket access exclusively to CloudFront. OAC uses a CloudFront-owned service principal to sign requests, and the S3 bucket policy must explicitly grant the `s3:GetObject` action to that principal, ensuring no direct S3 access from other sources.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use pre-signed URLs for all objects.

    Why it's wrong here

    Pre-signed URLs grant temporary, time-limited access to specific S3 objects to individual end users who possess the URL. They are designed for authenticating user access to private content, not for authorizing CloudFront's edge servers to fetch the object from the origin. If used for all objects, you would need to generate and rotate URLs constantly, and CloudFront would still require some origin authentication mechanism to retrieve the content in the first place.

  • ✗

    Use an S3 bucket policy that allows access from any AWS service.

    Why it's wrong here

    An S3 bucket policy that allows access from any AWS service is overly broad because it lacks a principal restriction to CloudFront. This would permit any AWS service (e.g., EC2, Lambda, Athena) with appropriate credentials to read your objects, which not only fails to enforce an origin restriction but also expands the attack surface. The correct pattern is to use a service principal of cloudfront.amazonaws.com with a SourceArn condition.

  • ✗

    Generate CloudFront key pairs and configure signed URLs.

    Why it's wrong here

    CloudFront key pairs and signed URLs are used to control whether a user's request to CloudFront is authorized, for example restricting premium content to specific viewers. They do nothing to authenticate CloudFront to the S3 origin; CloudFront would still need OAC/OAI or a public bucket to fetch the object. Note that CloudFront key pairs belong to trusted signers (account holders), not to the CloudFront distribution itself, so they are irrelevant to origin-access restriction.

  • ✓

    Configure an origin access control (OAC) and update the S3 bucket policy to allow CloudFront access.

    Why this is correct

    Configuring an origin access control (OAC) attaches a CloudFront distribution to an S3 bucket using a service principal (cloudfront.amazonaws.com) and an aws:SourceArn condition that uniquely identifies the distribution. The bucket policy then explicitly grants that principal s3:GetObject permission, ensuring only your CloudFront distribution (and not the public or arbitrary AWS services) can read the objects. OAC also supports SSE-KMS encrypted origins, making it the current best practice over the legacy origin access identity (OAI).

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.