How to Enable Directory Index Access in CloudFront with Private S3 Origin?
A developer creates a static website for their department. The developer deploys the static assets for the website to an Amazon S3 bucket and serves the assets with Amazon CloudFront. The developer uses origin access control (OAC) on the CloudFront distribution to access the S3 bucket. The developer notices users can access the root URL and specific pages but cannot access directories without specifying a file name. For example, /products/index.html works, but /products/ returns an error. The developer needs to enable accessing directories without specifying a file name without exposing the S3 bucket publicly. Which solution will meet these requirements?
Community Votes
78% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the understanding that CloudFront's default root object only applies to the root path (/), and that enabling S3 static website hosting to get index document behavior would require exposing the bucket publicly, violating the security constraint.
When using Amazon CloudFront with a private S3 origin via OAC, CloudFront does not natively serve index documents for subdirectories. The correct solution is to use a CloudFront function to append 'index.html' to directory requests, preserving bucket privacy.
Many candidates choose Option B (enable S3 static website hosting) because it natively supports index documents for subdirectories, but they overlook that this requires changing the origin to the S3 website endpoint, which necessitates making the bucket publicly accessible, violating the requirement.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Understanding the Problem
The developer has a static website hosted on Amazon S3 with Amazon CloudFront as the CDN. They are using Origin Access Control (OAC) to ensure the S3 bucket remains private. The issue is that while /products/index.html works, accessing /products/ returns an error because CloudFront does not automatically look for an index.html file inside subdirectories.
Why Option C is Correct
Option C proposes creating a CloudFront function that intercepts viewer requests and appends index.html when the URL ends with a / (indicating a directory request). This is the AWS-recommended approach for implementing default directory indexes when using a private S3 origin with OAC. The function runs at the edge (viewer request phase), rewrites the URI, and forwards the corrected request to S3 via OAC — all without exposing the bucket.
As noted in the [AWS blog post](https://aws.amazon.com/blogs/networking-and-content-delivery/implementing-default-directory-indexes-in-amazon-s3-backed-amazon-cloudfront-origins-using-cloudfront-functions/) referenced by community members, this is the standard pattern.
Why Other Options Are Wrong
- Option A: Setting the default root object in CloudFront only applies to the root path (
/). It does not handle subdirectories like/products/. This is a common misconception. - Option B: Enabling S3 static website hosting and switching the origin to the S3 website endpoint would indeed provide index document behavior. However, the S3 website endpoint does not support OAC. You would need to make the bucket publicly accessible via a bucket policy, which directly violates the requirement to keep the S3 bucket private.
- Option D: A custom error response mapping 404 to
/index.htmlwould serve the rootindex.htmlfor any missing file, not the correctindex.htmlwithin the requested subdirectory. This breaks the site's navigation entirely.
Community Consensus
The community strongly supports Option C (73%), recognizing that it is the only solution that maintains bucket privacy while enabling directory index access. Those who voted for Option B overlooked the critical constraint that the S3 website endpoint cannot be used with OAC without exposing the bucket.
Official Reference
- https://aws.amazon.com/blogs/networking-and-content-delivery/implementing-default-directory-indexes-in-amazon-s3-backed-amazon-cloudfront-origins-using-cloudfront-functions/
- https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-restricting-access-to-s3.html
- https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/cloudfront-functions.html
Exam Strategy
When a question specifies that an S3 bucket must remain private and CloudFront is using OAC, immediately eliminate any option that involves enabling S3 static website hosting or using the S3 website endpoint, as these are incompatible with OAC and require public bucket access.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →