How to Enable Directory Index Access in CloudFront with Private S3 Origin?

A developer creates a static website for their department. The developer deploys the static assets for the website to an Amazon S3 bucket and serves the assets with Amazon CloudFront. The developer uses origin access control (OAC) on the CloudFront distribution to access the S3 bucket. The developer notices users can access the root URL and specific pages but cannot access directories without specifying a file name. For example, /products/index.html works, but /products/ returns an error. The developer needs to enable accessing directories without specifying a file name without exposing the S3 bucket publicly. Which solution will meet these requirements?

  1. Update the CloudFront distribution's settings to index.html as the default root object is set.
  2. Update the Amazon S3 bucket settings and enable static website hosting. Specify index.html as the Index document. Update the S3 bucket policy to enable access. Update the CloudFront distribution's origin to use the S3 website endpoint.
  3. Create a CloudFront function that examines the request URL and appends index.html when directories are being accessed. Add the function as a viewer request CloudFront function to the CloudFront distribution's behavior. Source Reference Answer
  4. Create a custom error response on the CloudFront distribution with the HTTP error code set to the HTTP 404 Not Found response code and the response page path to /index.html. Set the HTTP response code to the HTTP 200 OK response code.

Community Votes

C
78%
B
22%

78% of anonymous learners picked answer C. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the understanding that CloudFront's default root object only applies to the root path (/), and that enabling S3 static website hosting to get index document behavior would require exposing the bucket publicly, violating the security constraint.

When using Amazon CloudFront with a private S3 origin via OAC, CloudFront does not natively serve index documents for subdirectories. The correct solution is to use a CloudFront function to append 'index.html' to directory requests, preserving bucket privacy.

Many candidates choose Option B (enable S3 static website hosting) because it natively supports index documents for subdirectories, but they overlook that this requires changing the origin to the S3 website endpoint, which necessitates making the bucket publicly accessible, violating the requirement.

Community Discussion (9 comments)

examuserss 👍 1 Selected: A
The best solution is Option A: Update the CloudFront distribution's settings to index.html as the default root object. This is the simplest and most operationally efficient way to ensure that CloudFront automatically serves the index.html file when a user requests a directory, without needing to expose the S3 bucket publicly or implement complex logic.
Saurabh04 👍 1 Selected: B
Enable static website hosting on the S3 bucket. Specify index.html as the Index document. Update the S3 bucket policy to allow access. Configure the CloudFront distribution’s origin to use the S3 website endpoint. Pros: Handles both root and subdirectories. Keeps the S3 bucket private. Cons: Requires S3 bucket policy adjustments.
65703c1 👍 2 Selected: C
C is the correct answer.
KarBiswa 👍 4 Selected: C
https://aws.amazon.com/blogs/networking-and-content-delivery/implementing-default-directory-indexes-in-amazon-s3-backed-amazon-cloudfront-origins-using-cloudfront-functions/
Abdullah22 👍 2
going with B.
SerialiDr 👍 3 Selected: C
This solution allows for the dynamic handling of requests to directories by automatically appending index.html to the path when a directory is requested. This approach does not require exposing the S3 bucket publicly or modifying S3 bucket settings for static website hosting. It leverages CloudFront's capabilities to manipulate the request at the edge location before it reaches the origin, ensuring that users can access directories without specifying a file name in the most secure and efficient manner.
HD98 👍 1
C is the right option
ANDRES715 👍 2 Selected: B
Al habilitar el alojamiento de sitios web estáticos en el depósito de Amazon S3 y especificar index.html como documento de índice, se permite el acceso a los directorios sin especificar un nombre de archivo. Al mismo tiempo, al actualizar la política del depósito S3 para habilitar el acceso y el origen de la distribución de CloudFront para utilizar el punto final del sitio web de S3, se garantiza que el acceso se gestione de manera segura sin exponer públicamente el depósito de S3.
CrescentShared 👍 2 Selected: C
When you enable static website hosting on an S3 bucket, you can specify an index document, which S3 automatically returns when a user requests a directory. However, changing the CloudFront origin to the S3 website endpoint would expose the S3 bucket publicly, which contradicts the requirement to keep the S3 bucket private.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Understanding the Problem

The developer has a static website hosted on Amazon S3 with Amazon CloudFront as the CDN. They are using Origin Access Control (OAC) to ensure the S3 bucket remains private. The issue is that while /products/index.html works, accessing /products/ returns an error because CloudFront does not automatically look for an index.html file inside subdirectories.

Why Option C is Correct

Option C proposes creating a CloudFront function that intercepts viewer requests and appends index.html when the URL ends with a / (indicating a directory request). This is the AWS-recommended approach for implementing default directory indexes when using a private S3 origin with OAC. The function runs at the edge (viewer request phase), rewrites the URI, and forwards the corrected request to S3 via OAC — all without exposing the bucket.

As noted in the [AWS blog post](https://aws.amazon.com/blogs/networking-and-content-delivery/implementing-default-directory-indexes-in-amazon-s3-backed-amazon-cloudfront-origins-using-cloudfront-functions/) referenced by community members, this is the standard pattern.

Why Other Options Are Wrong

  • Option A: Setting the default root object in CloudFront only applies to the root path (/). It does not handle subdirectories like /products/. This is a common misconception.
  • Option B: Enabling S3 static website hosting and switching the origin to the S3 website endpoint would indeed provide index document behavior. However, the S3 website endpoint does not support OAC. You would need to make the bucket publicly accessible via a bucket policy, which directly violates the requirement to keep the S3 bucket private.
  • Option D: A custom error response mapping 404 to /index.html would serve the root index.html for any missing file, not the correct index.html within the requested subdirectory. This breaks the site's navigation entirely.

Community Consensus

The community strongly supports Option C (73%), recognizing that it is the only solution that maintains bucket privacy while enabling directory index access. Those who voted for Option B overlooked the critical constraint that the S3 website endpoint cannot be used with OAC without exposing the bucket.

Official Reference

Exam Strategy

When a question specifies that an S3 bucket must remain private and CloudFront is using OAC, immediately eliminate any option that involves enabling S3 static website hosting or using the S3 website endpoint, as these are incompatible with OAC and require public bucket access.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide