Courseiva

SOA-C02 Networking and Content Delivery Practice Question

Network Topology
$ aws cloudfront get-distribution-configid E1A2B3C4D5E6F7Refer to the exhibit.```"ETag": "E3QEXAMPLE","DistributionConfig": {"CallerReference": "my-distribution","Aliases": {"Quantity": 1,"Items": ["www.example.com"]},"Origins": {"Items": ["Id": "my-origin","DomainName": "my-bucket.s3.us-east-1.amazonaws.com","S3OriginConfig": {"OriginAccessIdentity": """DefaultCacheBehavior": {"TargetOriginId": "my-origin","ViewerProtocolPolicy": "redirect-to-https","AllowedMethods": {"Quantity": 2,"Items": ["GET", "HEAD"],"CachedMethods": {"Items": ["GET", "HEAD"]"Compress": true"Enabled": true

Refer to the exhibit. A SysOps administrator is troubleshooting a CloudFront distribution that serves content from an S3 bucket. Users are receiving 'Access Denied' errors when trying to access objects. The exhibit shows the distribution configuration. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The CloudFront distribution is not using an Origin Access Identity (OAI) to authenticate with the S3 bucket.

The exhibit shows that the Origin Access Identity (OAI) field is empty, meaning CloudFront is not using an OAI to authenticate with the S3 bucket. Without an OAI, CloudFront relies on the bucket being publicly accessible, but by default S3 buckets are private. Therefore, CloudFront cannot access the objects, resulting in 'Access Denied' errors. Option A is not evident from the exhibit; the bucket policy is not shown. Option B is incorrect because the distribution status is 'Enabled' in the exhibit. Option D is incorrect because the viewer protocol policy 'Redirect HTTP to HTTPS' would redirect users, not cause Access Denied.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The S3 bucket policy does not grant read access to CloudFront.

    Why it's wrong here

    Even if a bucket policy grants read access to CloudFront, CloudFront cannot authenticate as CloudFront unless the distribution uses an Origin Access Identity (OAI). Without an OAI, CloudFront forwards requests to S3 as an anonymous principal, so the bucket policy has no way to map the request to the distribution. Consequently, a private bucket will return 403 Access Denied regardless of how permissive the policy is; the missing OAI is the root cause.

  • ✗

    The distribution is not enabled.

    Why it's wrong here

    The exhibit indicates that the distribution is in the Enabled state, which means it is active and serving requests. A disabled distribution would return an error such as 'Distribution Not Found' or a 403 from CloudFront itself, not an Access Denied from the S3 origin. Since the configuration clearly shows Enabled: true and presumably a Deployed status, this cannot be the source of the problem.

  • ✓

    The CloudFront distribution is not using an Origin Access Identity (OAI) to authenticate with the S3 bucket.

    Why this is correct

    This is the correct diagnosis: for a private S3 bucket, CloudFront must use an Origin Access Identity to authenticate its requests. Without an OAI, CloudFront does not sign the origin request with a recognized AWS identity, so S3 treats it as anonymous and denies access. The fix involves creating an OAI, associating it with the distribution's S3 origin, and updating the bucket policy to allow that OAI the `s3:GetObject` permission.

  • ✗

    The viewer protocol policy is set to 'redirect-to-https', but users are using HTTP.

    Why it's wrong here

    The `redirect-to-https` viewer protocol policy makes CloudFront return an HTTP 301 redirect to the HTTPS version of any requested URL. This redirection is handled entirely by CloudFront's edge servers before any origin request is made, so it has no bearing on whether S3 issues an Access Denied. If users are accessing over HTTP, they would be redirected to HTTPS and the request would proceed; the Access Denied indicates an origin authentication failure, not a protocol mismatch.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This SOA-C02 question is part of Courseiva's 1,169-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SOA-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SOA-C02 exam.