Use CloudFront OAC plus a bucket policy that allows only the OAC, and a WAF IP-set ACL

Answer Correct answer: B — CloudFront OAC with a bucket policy allowing only the OAC, plus a WAF IP-set web ACL on the distribution.

A security engineer needs to set up an Amazon CloudFront distribution for an Amazon S3 bucket that hosts a static website. The security engineer must allow only specified IP addresses to access the website. The security engineer also must prevent users from accessing the website directly by using S3 URLs. Which solution will meet these requirements?

  1. Generate an S3 bucket policy. Specify cloudfront.amazonaws.com as the principal. Use the aws:SourceIp condition key to allow access only if the request comes from the specified IP addresses.
  2. Create a CloudFront origin access control (OAC). Create the S3 bucket policy so that only the OAC has access. Create an AWS WAF web ACL, and add an IP set rule. Associate the web ACL with the CloudFront distribution. Correct Answer
  3. Implement security groups to allow only the specified IP addresses access and to restrict S3 bucket access by using the CloudFront distribution.
  4. Create an S3 bucket access point to allow access from only the CloudFront distribution. Create an AWS WAF web ACL and add an IP set rule. Associate the web ACL with the CloudFront distribution.

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

OAC (the modern successor to OAI) lets the bucket policy grant access exclusively to CloudFront, preventing direct S3-URL access. WAF IP-set rules filter by source IP at the distribution. A bucket policy using cloudfront.amazonaws.com with aws:SourceIp (A) does not guarantee traffic came via CloudFront and is not the recommended pattern; security groups (C) do not apply to S3; S3 access points (D) do not enforce IP allowlists at the edge like WAF. B is correct.

To serve an S3 static site only to specified IPs and block direct S3-URL access, create a CloudFront Origin Access Control (OAC) and set the bucket policy to allow access solely from that OAC—closing direct S3 access. Then attach an AWS WAF web ACL with an IP-set rule to the distribution to permit only the specified source IPs. This satisfies both requirements: private origin and IP restriction at the edge.

Using a bucket policy with cloudfront.amazonaws.com principal + aws:SourceIp (A)—that grants by service principal and does not truly lock access to only your distribution, and SourceIp there is unreliable for ensuring CloudFront-only. Using security groups (C)—S3 is not in a VPC and has no security groups. D's access point does not provide IP-set filtering like WAF.

Community Discussion (3 comments)

5409b91 👍 7 Selected: B
Why Not Other Options? Option A: Specifying cloudfront.amazonaws.com as the principal with aws:SourceIp condition key in the bucket policy does not ensure that access is only through CloudFront, as it does not tie the access to a specific CloudFront distribution. Option C: Security groups cannot be used to control access to S3 buckets; they are used for controlling access to EC2 instances, among other resources. This approach would not meet the requirement. Option D: Using an S3 bucket access point is unnecessary when OACs and bucket policies can effectively manage the access requirements. Also, access points are more relevant for complex access control scenarios and do not inherently solve the issue of restricting direct S3 access via CloudFront.
navid1365 👍 1 Selected: B
B is the correct answer
Certified101 👍 2 Selected: B
B is correct

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Origin Access Control lets the S3 bucket policy grant access exclusively to the specific CloudFront distribution, eliminating direct S3-URL access. A WAF web ACL with an IP-set rule attached to the distribution then restricts who can reach the site to the specified IP addresses. Together they meet both constraints at the edge and origin.

Why the Other Options Are Wrong

A uses a bucket policy with the cloudfront.amazonaws.com service principal plus aws:SourceIp, which does not guarantee requests arrived via your distribution and is not the recommended lock pattern. C proposes security groups, but S3 is not VPC-resident and has no security groups. D uses an S3 access point, which does not provide edge IP-set filtering like WAF. B is correct.

Community Comment Notes

Community voted B (100). Commenters explained why A fails (service-principal + SourceIp does not ensure CloudFront-only access). B was confirmed as OAC + bucket policy restricted to OAC + WAF IP set.

Official Reference

Related Analysis

← Back to SCS-C02 Study Guide