A company stores website images in an Amazon S3 bucket and uses Amazon CloudFront to distribute them. The company has discovered access from countries where it does not have distribution rights. Which actions should the company take to secure the images and limit distribution? (Choose two.)
Choose an answer
Tap an option to check your answer.
Correct answer: Update the S3 bucket policy to allow access only through a CloudFront origin access control (OAC)., Add a CloudFront geo restriction deny list for the countries where the company does not have a license..
Why this is the answer
To secure the images and limit distribution, two actions are necessary. First, updating the S3 bucket policy to allow access only through a CloudFront Origin Access Control (OAC) ensures that users cannot bypass CloudFront and directly access the S3 bucket. This prevents unauthorized direct downloads of images. Second, adding a CloudFront geo restriction deny list for unlicensed countries prevents users in those specific geographic locations from accessing the content through CloudFront. Using an Amazon Route 53 geolocation record with a deny list would only affect DNS resolution, not direct access to the content via CloudFront or S3. Updating the S3 bucket policy with a deny list for countries is less effective because CloudFront's geo-restriction is designed for this purpose and operates at the edge, blocking requests before they reach S3. Enabling "Restrict Viewer Access" in CloudFront is for signed URLs/cookies, not for geo-restrictions, which are handled separately.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed