Question: Question 6 You are working as a Cloud Security Engineer in your company, and they asked you to ensure that all confidential files shared via

Question 6
You are working as a Cloud Security Engineer in your company, and they asked you to ensure that all confidential files shared via S3 cannot be accessed directly. Which of these options could satisfy this requirement?
1.Assign an IAM user access to objects in the S3 bucket used with CloudFront
2.Create an Origin Access Identity (OAI) and associate it with your CloudFront distribution. Change the permissions on your Amazon 53 bucket so th only the origin access identity has read permissions.
Write an S3 bucket policy that assigns the CloudFront distribution ID as the Principal and the target bucket as the ARN
Enable CORS for the $3 bucket.

Step by Step Solution

There are 3 Steps involved in it

1 Expert Approved Answer
Step: 1 Unlock blur-text-image
Question Has Been Solved by an Expert!

Get step-by-step solutions from verified subject matter experts

Step: 2 Unlock
Step: 3 Unlock

Students Have Also Explored These Related Programming Questions!