How to restrict direct S3 access to CloudFront only?
A developer is creating a publicly accessible enterprise website consisting of only static assets. The developer is hosting the website in Amazon S3 and serving the website to users through an Amazon CloudFront distribution. The users of this application must not be able to access the application content directly from an S3 bucket. All content must be served through the Amazon CloudFront distribution. Which solution will meet these requirements?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests securing S3 origins so that only CloudFront can fetch objects; the trap is granting unnecessary write permissions or misusing bucket conditions.
To serve a static website exclusively through Amazon CloudFront, developers must use Origin Access Control (OAC) with a restrictive S3 bucket policy. Community consensus strongly favors OAC over legacy OAI or incorrect permission models.
Candidates often choose B because it mentions blocking public access, but it wrongly grants CloudFront write access and omits OAC, failing to truly restrict direct S3 access.
Community Discussion (7 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why Option A is Correct
The scenario requires that only CloudFront can read objects from the S3 bucket, while direct public access is forbidden. The modern, AWS-recommended method is to use Origin Access Control (OAC). OAC allows CloudFront to sign requests to S3 using AWS Signature Version 4, and the S3 bucket policy is updated with a condition that only accepts requests signed by the specific CloudFront distribution. Although the option mentions "read and write access," the critical part is that OAC is correctly configured and the bucket policy references the CloudFront service principal, ensuring exclusive access.
Why the Other Options Fail
- Option B enables "Block All Public Access" (good) but then grants CloudFront write access, which is irrelevant for serving static content and does not describe how CloudFront authenticates to S3. Without OAC or OAI, there is no mechanism to prevent direct S3 access.
- Option C enables static website hosting on the S3 bucket. This makes the bucket a public website endpoint, which directly contradicts the requirement that users must not access content directly from S3. CloudFront would then fetch from the public website endpoint, not the secure REST API endpoint.
- Option D attempts to use a custom header and a bucket policy condition based on
aws:RequestTag. However, S3 bucket policies cannot evaluate custom headers sent by CloudFront usingaws:RequestTag; that condition key is for IAM resource tags. This approach does not work for restricting S3 access to CloudFront.
Community Insight
As noted by community members, the only valid ways to restrict S3 access to CloudFront are OAC (recommended) or the legacy OAI. Option A is the only one that correctly implements OAC. Several commenters pointed out that Option B's mention of "write access" is a red herring and does not address the core security requirement.
Official Reference
Exam Strategy
When a question asks to restrict direct S3 access to CloudFront only, immediately look for OAC or OAI in the options. Eliminate any answer that mentions public website endpoints or irrelevant write permissions.
Related Analysis
Practice All DVA-C02 Questions
Access 100 questions with complete answers and detailed explanations.
View Full DVA-C02 Practice Test →