You must deliver protected digital assets to authorized users via Amazon CloudFront while preventing public access. Which configuration satisfies this requirement?
Choose an answer
Tap an option to check your answer.
Correct answer: Place the objects in an S3 bucket with public access blocked. Use an Origin Access Identity (OAI) for CloudFront and enforce access via CloudFront signed URLs to the bucket..
Why this is the answer
The correct configuration involves storing objects in an S3 bucket with public access blocked to ensure they are not directly accessible. An Origin Access Identity (OAI) for CloudFront then grants CloudFront permission to retrieve objects from this private S3 bucket. Finally, CloudFront signed URLs are used to provide time-limited access to authorized users, fulfilling the requirement for protected digital assets. The first incorrect option fails because allowing public S3 access defeats the purpose of protecting assets. The third incorrect option incorrectly mentions field-level encryption, which is unrelated to restricting access to the S3 origin. The fourth option is incorrect because while signed cookies can restrict delivery, the S3 bucket allowing public access still leaves the assets vulnerable to direct access, bypassing CloudFront.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed