exam questions

Exam AWS Certified SysOps Administrator - Associate All Questions

View all questions & answers for the AWS Certified SysOps Administrator - Associate exam

Exam AWS Certified SysOps Administrator - Associate topic 1 question 176 discussion

A SysOps administrator is reviewing AWS Trusted Advisor warnings and encounters a warning for an S3 bucket policy that has open access permissions. While discussing the issue with the bucket owner, the administrator realizes the S3 bucket is an origin for an Amazon CloudFront web distribution.

Which action should the administrator take to ensure that users access objects in Amazon S3 by using only CloudFront URLs?

  • A. Encrypt the S3 bucket content with Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3).
  • B. Create an origin access identity and grant it permissions to read objects in the S3 bucket.
  • C. Assign an IAM user to the CloudFront distribution and grant the user permissions in the S3 bucket policy.
  • D. Assign an IAM role to the CloudFront distribution and grant the role permissions in the S3 bucket policy.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
r2c3po
10 months ago
Selected Answer: B
Option B is the correct choice: #B. Create an origin access identity and grant it permissions to read objects in the S3 bucket. When using Amazon CloudFront as a content delivery network with an S3 bucket as the origin, it's a best practice to restrict direct access to the S3 bucket and require users to access objects only through CloudFront URLs. This can be achieved by creating an Origin Access Identity (OAI) and granting it permission to read objects in the S3 bucket.
upvoted 3 times
...
Saibal9
10 months, 1 week ago
It is actually Origin Access Control now.
upvoted 2 times
...
Christina666
1 year, 3 months ago
Selected Answer: B
OAI--------------only Cloudfront get objects from S3
upvoted 4 times
jipark
1 year, 2 months ago
got it, OAI is used for CloudFront
upvoted 2 times
...
...
michaldavid
1 year, 10 months ago
Selected Answer: B
bbbbbb
upvoted 3 times
...
Liongeek
1 year, 11 months ago
Ans: B I just had a class on that in CloudGuru :p
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago