An application is served globally via Amazon CloudFront, with an Amazon S3 bucket as its origin. Users are reporting occasional '403 Access Denied' errors when trying to access specific objects. The S3 bucket policy allows public read access. What is the MOST likely cause of these errors?
- AThe objects in the S3 bucket are encrypted with a customer-managed key (CMK) in AWS KMS.
- BThe S3 bucket policy explicitly denies access to CloudFront.
- CThe CloudFront distribution's cache behavior is not set to forward query strings.
- DThe CloudFront distribution is not configured with an Origin Access Control (OAC) or Origin Access Identity (OAI).
Show answer & explanationAnswer & explanation
Correct answer: D. The CloudFront distribution is not configured with an Origin Access Control (OAC) or Origin Access Identity (OAI).
If the S3 bucket policy allows public read access, CloudFront can fetch objects. However, a common best practice (and often the default for new S3 buckets) is to have 'Block public access' enabled, even if the bucket policy tries to grant public access. The most secure way for CloudFront to access a private S3 bucket (or one with 'Block public access' enabled) is by using an Origin Access Control (OAC) or the older Origin Access Identity (OAI). Without OAC/OAI, CloudFront might not have permission to fetch objects, leading to 403 errors, especially if S3's 'Block Public Access' settings are enabled, overriding the bucket policy.
Why the other options are wrong
- A. S3 objects encrypted with CMK can be served by CloudFront, provided the CloudFront service principal has permission to use the CMK. This is a separate permission issue rather than a fundamental access denial.
- B. The question states the S3 bucket policy allows public read access, making an explicit denial less likely, though not impossible. However, OAC/OAI is a more common configuration issue.
- C. Forwarding query strings affects caching and how CloudFront serves different versions of an object, but not the fundamental access permission to the origin itself, which would cause a 403.
CloudFront Origin Access Control (OAC)
A CloudFront feature that enables you to restrict access to your Amazon S3 bucket origins, allowing only CloudFront to retrieve content from the bucket.
- Replaces the older Origin Access Identity (OAI).
- Ensures S3 content is only accessible via CloudFront URLs.
- Protects S3 buckets from direct public access while allowing CloudFront to serve content.
Memory trick: CloudFront needs its own key (OAC) to unlock S3's treasure chest.