Question: Question 6 You are working as a Cloud Security Engineer in your company, and they asked you to ensure that all confidential files shared via
Question
You are working as a Cloud Security Engineer in your company, and they asked you to ensure that all confidential files shared via S cannot be accessed directly. Which of these options could satisfy this requirement?
Assign an IAM user access to objects in the S bucket used with CloudFront
Create an Origin Access Identity OAI and associate it with your CloudFront distribution. Change the permissions on your Amazon bucket so th only the origin access identity has read permissions.
Write an S bucket policy that assigns the CloudFront distribution ID as the Principal and the target bucket as the ARN
Enable CORS for the $ bucket.
Step by Step Solution
There are 3 Steps involved in it
1 Expert Approved Answer
Step: 1 Unlock
Question Has Been Solved by an Expert!
Get step-by-step solutions from verified subject matter experts
Step: 2 Unlock
Step: 3 Unlock
