A SysOps Administrator is reviewing AWS Trusted Advisor warnings and encounters a warning for an S3 bucket policy that has open access permissions. While discussing the issue the bucket owner, the Administrator realizes the S3 bucket is an origin for an Amazon CloudFront web distribution. Which action should the Administrator take to ensure that users access objects in Amazon S3 by using only CloudFront URLs?
A) Encrypt the S3 bucket content with Server-Side Encryption with Amazon S3-Managed Keys (SSE-S3)
B) Create an origin access identity and grant it permissions to read objects in the S3 bucket
C) Assign an IAM user to the CoudFront distribution and whitelist the IAM user in the S3 bucket policy
D) Assign an IAM role to the CloudFront distribution and whitelist the IAM role in the S3 bucket policy
Correct Answer:
Verified
Q633: A photo-sharing site delivers content worldwide from
Q634: An existing, deployed solution uses Amazon EC2
Q635: A SysOps Administrator has an AWS Direct
Q636: A SysOps Administrator is managing an application
Q637: InfoSec is concerned that an employee may
Q639: A SysOps Administrator has an AWS Lambda
Q640: A company's data retention policy dictates that
Q641: A SysOps Administrator is implementing SSL for
Q642: An Auto Scaling group scales up and
Q643: An HTTP web application is launched on
Unlock this Answer For Free Now!
View this answer and more for free by performing one of the following actions
Scan the QR code to install the App and get 2 free unlocks
Unlock quizzes for free by uploading documents