A global company needs to distribute sensitive content to its users worldwide while ensuring that only authenticated users can access the content and that all data is encrypted in transit. The solution must also prevent direct access to the origin S3 bucket. Which AWS services and configuration should be used?
- AAmazon CloudFront with signed URLs/cookies and an Origin Access Control (OAC) for an S3 bucket with default encryption.
- BAmazon CloudFront with custom headers for authentication and a private S3 bucket accessed via a VPC endpoint.
- CAmazon S3 with bucket policies to restrict access and KMS encryption, accessed directly by users.
- DAmazon CloudFront with signed URLs/cookies and an Origin Access Identity (OAI) for an S3 bucket with default encryption.
Show answer & explanationAnswer & explanation
Correct answer: A. Amazon CloudFront with signed URLs/cookies and an Origin Access Control (OAC) for an S3 bucket with default encryption.
Amazon CloudFront is essential for global content distribution and in-transit encryption (HTTPS). Signed URLs/cookies enforce authenticated access. An Origin Access Control (OAC) allows CloudFront to securely access a private S3 bucket, preventing direct user access to the origin. S3 default encryption handles data at rest. This combination meets all requirements.
Why the other options are wrong
- B. Custom headers can be used for some authentication, but signed URLs/cookies are purpose-built for time-limited, authenticated access to CloudFront content. A VPC endpoint for S3 is for private *internal* access to S3, not for CloudFront accessing a public-facing S3 origin, nor does it make the S3 bucket directly accessible to users through CloudFront in a secure manner without OAC/OAI.
- C. Direct S3 access by users, even with bucket policies and KMS, lacks the global distribution, performance, and advanced access control (signed URLs/cookies) that CloudFront provides, and it doesn't abstract the origin access.
- D. This is very similar to A, but OAI (Origin Access Identity) is the legacy method. Origin Access Control (OAC) is the recommended and more secure approach, supporting all S3 buckets and also other origins like EC2 or ALB, with more granular control and support for IAM. Therefore, OAC is the better choice.
CloudFront Secure Content Delivery
CloudFront delivers content globally, providing in-transit encryption, and integrates with signed URLs/cookies for authenticated access and Origin Access Control (OAC) for secure, private S3 origin access.
- CloudFront for global distribution and HTTPS.
- Signed URLs/cookies for authenticated, time-limited access.
- Origin Access Control (OAC) securely connects CloudFront to private S3.
- Prevents direct access to the S3 origin bucket.
Memory trick: CloudFront: Caching Content Securely