exam questions

Exam AWS Certified Security - Specialty SCS-C02 All Questions

View all questions & answers for the AWS Certified Security - Specialty SCS-C02 exam

Exam AWS Certified Security - Specialty SCS-C02 topic 1 question 91 discussion

A company stores images for a website in an Amazon S3 bucket. The company is using Amazon CloudFront to serve the images to end users. The company recently discovered that the images are being accessed from countries where the company does not have a distribution license.

Which actions should the company take to secure the images to limit their distribution? (Choose two.)

  • A. Update the S3 bucket policy to restrict access to a CloudFront origin access control (OAC).
  • B. Update the website DNS record to use an Amazon Route 53 geolocation record deny list of countries where the company lacks a license.
  • C. Add a CloudFront geo restriction deny list of countries where the company lacks a license.
  • D. Update the S3 bucket policy with a deny list of countries where the company lacks a license.
  • E. Enable the Restrict Viewer Access option in CloudFront to create a deny list of countries where the company lacks a license.
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
[Removed]
Highly Voted 1 year ago
Selected Answer: AC
A so the object requests do not bypass Cloudfront, and C for georestrictions. Careful with this oioi fella 👀
upvoted 7 times
Aamee
1 year ago
Fully agreed on ur 'oioi' feedback :D..
upvoted 1 times
...
...
DSExam
Most Recent 1 month ago
Selected Answer: AC
A and C makes more sense
upvoted 1 times
...
cumzle_com
5 months, 2 weeks ago
Selected Answer: AC
why not E : The "Restrict Viewer Access" option in CloudFront is designed to require signed URLs or signed cookies, which is not directly related to geo-restrictions. Geo-restriction settings in CloudFront should be used instead.
upvoted 1 times
...
sema2232
5 months, 3 weeks ago
why E is incorrect ?
upvoted 2 times
...
Raphaello
9 months, 2 weeks ago
Selected Answer: AC
Restrict access to CF distro through OAC might not directly help with geo-restriction, until you pick option C alongside it. It enforces flow to be only through CF, where the geo-restriction in place. AC are correct.
upvoted 1 times
...
Gafa255
10 months, 2 weeks ago
Selected Answer: AC
AC correct options. https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/georestrictions.html
upvoted 1 times
Gafa255
10 months, 2 weeks ago
https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-restricting-access-to-s3.html
upvoted 1 times
...
...
kejam
1 year ago
Selected Answer: AC
https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/georestrictions.html
upvoted 3 times
...
Aamee
1 year ago
Selected Answer: AC
A describes how to limit the access via the policy to bound the access within OAC. C describes about using the geo restriction based R53 policy you can use to limit the access on the unwanted countries.
upvoted 1 times
Aamee
1 year ago
typo: It's Geo restriction list in CloudFront and not R53 policy, my bad!...
upvoted 1 times
...
...
oioi
1 year ago
Selected Answer: CE
correct
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...