A SysOps admin hosts a static website in an Amazon S3 bucket and wants to ensure visitors can only reach the site through a single CloudFront distribution. Users must not be able to bypass CloudFront and access the S3 website endpoint directly. Which AWS feature should the admin use to enforce that requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: An Origin Access Identity (OAI) attached to the CloudFront distribution.
Why this is the answer
An Origin Access Identity (OAI) is the correct choice because it creates a special CloudFront user that S3 can recognize. When you configure your S3 bucket policy to grant read permissions only to this OAI, CloudFront can fetch content from S3, but direct access attempts to the S3 website endpoint will be denied. An S3 bucket ACL that restricts public access would prevent all public access, including CloudFront, unless specific CloudFront IPs were whitelisted, which is not scalable or secure. AWS Firewall Manager is for managing WAF rules across accounts and is not designed for restricting direct S3 endpoint access in this manner. An Amazon Route 53 private hosted zone is for DNS resolution within a VPC and does not control access to public S3 endpoints.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed