AWS Certified SysOps Administrator – AssociateNetworking and Content DeliveryMedium
A SysOps administrator is managing an Amazon CloudFront distribution that serves static content from an Amazon S3 bucket. The company has a strict security policy requiring that users can ONLY access the content through CloudFront and are explicitly prevented from accessing the S3 bucket directly via its public URL. Which CloudFront feature should the administrator implement to enforce this policy?
- AAWS WAF
- BOrigin Access Control (OAC)
- CSigned URLs/Signed Cookies
- DCloudFront Functions
Show answer & explanationAnswer & explanation
Correct answer: B. Origin Access Control (OAC)
Origin Access Control (OAC) is the recommended method to restrict direct access to an S3 bucket when using CloudFront. It grants CloudFront permission to access the S3 bucket, while explicitly blocking all other direct access attempts to the S3 bucket's public URL.
Why the other options are wrong
- A. AWS WAF is a web application firewall that protects against common web exploits, but it does not directly prevent direct S3 bucket access.
- C. Signed URLs/Signed Cookies are used to provide time-limited access to private content through CloudFront, not to prevent direct S3 access itself.
- D. CloudFront Functions allow lightweight JavaScript code execution at the edge but are not designed for restricting direct S3 access.
CloudFront Origin Access Control (OAC)
A CloudFront feature that enhances the security of S3 origins by enabling CloudFront to access the S3 bucket while preventing direct public access to the bucket.
- Replaces and improves upon Origin Access Identity (OAI)
- Supports all S3 buckets, including those with server-side encryption
- Provides more granular permissions for CloudFront to S3
- Ensures content delivery exclusively through CloudFront
Memory trick: OAC is the Only Access Control for CloudFront to S3.