ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 185 - SAA-C03 discussion

Report
Export

A solutions architect must design a solution that uses Amazon CloudFront with an Amazon S3 origin to store a static website. The company's security policy requires that all website traffic be inspected by AWS WAR How should the solutions architect comply with these requirements?

A.
Configure an S3 bucket policy lo accept requests coming from the AWS WAF Amazon Resource Name (ARN) only.
Answers
A.
Configure an S3 bucket policy lo accept requests coming from the AWS WAF Amazon Resource Name (ARN) only.
B.
Configure Amazon CloudFront to forward all incoming requests to AWS WAF before requesting content from the S3 origin.
Answers
B.
Configure Amazon CloudFront to forward all incoming requests to AWS WAF before requesting content from the S3 origin.
C.
Configure a security group that allows Amazon CloudFront IP addresses to access Amazon S3 only.Associate AWS WAF to CloudFront.
Answers
C.
Configure a security group that allows Amazon CloudFront IP addresses to access Amazon S3 only.Associate AWS WAF to CloudFront.
D.
Configure Amazon CloudFront and Amazon S3 to use an origin access identity (OAI) to restrict access to the S3 bucket. Enable AWS WAF on the distribution.
Answers
D.
Configure Amazon CloudFront and Amazon S3 to use an origin access identity (OAI) to restrict access to the S3 bucket. Enable AWS WAF on the distribution.
Suggested answer: D

Explanation:

https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-contentrestricting-access-to-s3.html

https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/distribution-webawswaf.html

asked 16/09/2024
Yuwadee Srisathan
40 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first