A company delivers its website using CloudFront and needs to store access logs centrally with encryption at rest. Which solution satisfies these requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Create an S3 bucket configured with default server-side encryption using AES-256. Configure CloudFront to store logs in that S3 bucket..
Why this is the answer
The correct solution is to create an S3 bucket configured with default server-side encryption using AES-256 and configure CloudFront to store logs in that S3 bucket. CloudFront natively supports delivering access logs directly to an S3 bucket. S3 provides robust, scalable, and cost-effective storage with built-in encryption options like AES-256, satisfying the requirement for encryption at rest. The options involving Amazon OpenSearch Service are incorrect because CloudFront does not directly integrate with OpenSearch Service for log delivery. While you could potentially stream logs from S3 to OpenSearch, it adds unnecessary complexity and is not the direct log destination for CloudFront. The option to create an S3 bucket with no default encryption and enable encryption on the CloudFront distribution is incorrect because CloudFront encryption settings apply to content delivery, not to the encryption of the access logs stored in S3. The S3 bucket itself must be configured for encryption at rest.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed