Examtopics

AWS Certified Solutions Architect - Associate
  • Topic 1 Question 165

    A solutions architect must design a solution that uses Amazon CloudFront with an Amazon S3 origin to store a static website. The company’s security policy requires that all website traffic be inspected by AWS WAF.

    How should the solutions architect comply with these requirements?

    • Configure an S3 bucket policy to accept requests coming from the AWS WAF Amazon Resource Name (ARN) only.

    • Configure Amazon CloudFront to forward all incoming requests to AWS WAF before requesting content from the S3 origin.

    • Configure a security group that allows Amazon CloudFront IP addresses to access Amazon S3 only. Associate AWS WAF to CloudFront.

    • Configure Amazon CloudFront and Amazon S3 to use an origin access identity (OAI) to restrict access to the S3 bucket. Enable AWS WAF on the distribution.


    シャッフルモード