AWS Certified SysOps Administrator – AssociateNetworking and Content DeliveryMedium

A SysOps administrator needs to configure a new Amazon CloudFront distribution to serve static content from an Amazon S3 bucket. To enhance security, the administrator wants to ensure that users can only access the content through CloudFront and not directly from the S3 bucket URL. Which CloudFront feature should be used?

  1. AS3 bucket policies with IP address restrictions.
  2. BOrigin Access Control (OAC).
  3. CCloudFront signed URLs.
  4. DCloudFront geo-restriction.
Show answer & explanation

Correct answer: B. Origin Access Control (OAC).

Origin Access Control (OAC) is the recommended and more secure method to restrict direct access to an Amazon S3 bucket behind CloudFront. OAC uses a public key infrastructure (PKI) to sign requests, ensuring that only CloudFront can access the S3 origin, and it supports all S3 regions and S3 server-side encryption with AWS KMS (SSE-KMS).

Why the other options are wrong

  • A. S3 bucket policies with IP restrictions are cumbersome to manage for CloudFront's dynamic IP ranges and less secure than OAC.
  • C. Signed URLs are for restricting access to specific content for a limited time, not for restricting direct S3 bucket access generally.
  • D. Geo-restriction controls where content can be viewed from, not how it's accessed from the origin.

CloudFront Origin Access Control (OAC)

Origin Access Control (OAC) is a security feature that prevents users from bypassing CloudFront and accessing content directly from an S3 bucket or other origins.

  • Recommended over Origin Access Identity (OAI).
  • Uses standard PKI for secure communication.
  • Ensures content is only accessible through CloudFront.

Memory trick: For CloudFront to 'own' the S3 content, it needs 'Origin Access Control' to lock out direct access.

More Networking and Content Delivery questions