How to restrict direct S3 access to CloudFront only?

A developer is creating a publicly accessible enterprise website consisting of only static assets. The developer is hosting the website in Amazon S3 and serving the website to users through an Amazon CloudFront distribution. The users of this application must not be able to access the application content directly from an S3 bucket. All content must be served through the Amazon CloudFront distribution. Which solution will meet these requirements?

  1. Create a new origin access control (OAC) in CloudFront. Configure the CloudFront distribution's origin to use the new OAC. Update the S3 bucket policy to allow CloudFront OAC with read and write access to access Amazon S3 as the origin. Source Reference Answer
  2. Update the S3 bucket settings. Enable the block all public access setting in Amazon S3. Configure the CloudFront distribution's with Amazon S3 as the origin. Update the S3 bucket policy to allow CloudFront write access.
  3. Update the S3 bucket's static website settings. Enable static website hosting and specifying index and error documents. Update the CloudFront origin to use the S3 bucket's website endpoint.
  4. Update the CloudFront distribution's origin to send a custom header. Update the S3 bucket policy with a condition by using the aws:RequestTag/tag-key key. Configure the tag-key as the custom header name, and the value being matched is the header's value.

Community Votes

A
100%

100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests securing S3 origins so that only CloudFront can fetch objects; the trap is granting unnecessary write permissions or misusing bucket conditions.

To serve a static website exclusively through Amazon CloudFront, developers must use Origin Access Control (OAC) with a restrictive S3 bucket policy. Community consensus strongly favors OAC over legacy OAI or incorrect permission models.

Candidates often choose B because it mentions blocking public access, but it wrongly grants CloudFront write access and omits OAC, failing to truly restrict direct S3 access.

Community Discussion (7 comments)

Saudis 👍 1 Selected: A
the access to S3 Always by two ways OAC or OAI In cloud front we access by OAC
65703c1 👍 1 Selected: A
A is the correct answer.
DeaconStJohn 👍 3 Selected: A
Think back to every beginner cloud project you have completed/read about/ignored.
Abdullah22 👍 1 Selected: B
why not B
nder 👍 4 Selected: A
https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/private-content-restricting-access-to-s3.html
monishvster 👍 1 Selected: C
We don't want to provide write access to CloudFront since it's a static website. S3 should suffice
CrescentShared 👍 3 Selected: A
While enabling the block all public access setting in Amazon S3 is a good security practice and necessary for this scenario, simply allowing CloudFront "write access" is not relevant since the scenario involves serving static assets, not writing to the S3 bucket. This option also doesn't specify using an OAC or a similar method to ensure exclusive access through CloudFront.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why Option A is Correct

The scenario requires that only CloudFront can read objects from the S3 bucket, while direct public access is forbidden. The modern, AWS-recommended method is to use Origin Access Control (OAC). OAC allows CloudFront to sign requests to S3 using AWS Signature Version 4, and the S3 bucket policy is updated with a condition that only accepts requests signed by the specific CloudFront distribution. Although the option mentions "read and write access," the critical part is that OAC is correctly configured and the bucket policy references the CloudFront service principal, ensuring exclusive access.

Why the Other Options Fail

  • Option B enables "Block All Public Access" (good) but then grants CloudFront write access, which is irrelevant for serving static content and does not describe how CloudFront authenticates to S3. Without OAC or OAI, there is no mechanism to prevent direct S3 access.
  • Option C enables static website hosting on the S3 bucket. This makes the bucket a public website endpoint, which directly contradicts the requirement that users must not access content directly from S3. CloudFront would then fetch from the public website endpoint, not the secure REST API endpoint.
  • Option D attempts to use a custom header and a bucket policy condition based on aws:RequestTag. However, S3 bucket policies cannot evaluate custom headers sent by CloudFront using aws:RequestTag; that condition key is for IAM resource tags. This approach does not work for restricting S3 access to CloudFront.

Community Insight

As noted by community members, the only valid ways to restrict S3 access to CloudFront are OAC (recommended) or the legacy OAI. Option A is the only one that correctly implements OAC. Several commenters pointed out that Option B's mention of "write access" is a red herring and does not address the core security requirement.

Official Reference

Exam Strategy

When a question asks to restrict direct S3 access to CloudFront only, immediately look for OAC or OAI in the options. Eliminate any answer that mentions public website endpoints or irrelevant write permissions.

Related Analysis

Practice All DVA-C02 Questions

Access 100 questions with complete answers and detailed explanations.

View Full DVA-C02 Practice Test →

← Back to DVA-C02 Study Guide