ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 184 - SCS-C01 discussion

Report
Export

In response to the past DDoS attack experiences, a Security Engineer has set up an Amazon CloudFront distribution for an Amazon S3 bucket. There is concern that some users may bypass the CloudFront distribution and access the S3 bucket directly.

What must be done to prevent users from accessing the S3 objects directly by using URLs?

A.
Change the S3 bucket/object permission so that only the bucket owner has access.
Answers
A.
Change the S3 bucket/object permission so that only the bucket owner has access.
B.
Set up a CloudFront origin access identity (OAI), and change the S3 bucket/object permission so that only the OAI has access.
Answers
B.
Set up a CloudFront origin access identity (OAI), and change the S3 bucket/object permission so that only the OAI has access.
C.
Create IAM roles for CloudFront, and change the S3 bucket/object permission so that only the IAM role has access.
Answers
C.
Create IAM roles for CloudFront, and change the S3 bucket/object permission so that only the IAM role has access.
D.
Redirect S3 bucket access to the corresponding CloudFront distribution.
Answers
D.
Redirect S3 bucket access to the corresponding CloudFront distribution.
Suggested answer: B

Explanation:

https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-contentrestricting-access-to-s3.html

asked 16/09/2024
ben ebrahimi
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first