CertyRush
Đang tải...
C CertyRush
Câu hỏi free preview

Câu 55: AWS Certified Security - Specialty(Old)

In response to the past DDoS attack experiences, a Security Engineer has set up an Amazon CloudFront distribution for an Amazon S3 bucket. There is concern that some users may bypass the CloudFront distribution and access the S3 bucket directly. What must be done to prevent users from accessing the S3 objects directly…

Nội dung câu hỏi

In response to the past DDoS attack experiences, a Security Engineer has set up an Amazon CloudFront distribution for an Amazon S3 bucket. There is concern that some users may bypass the CloudFront distribution and access the S3 bucket directly. What must be done to prevent users from accessing the S3 objects directly by using URLs?

Các lựa chọn

Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.

  1. A. Change the S3 bucket/object permission so that only the bucket owner has access.
  2. B. Set up a CloudFront origin access identity (OAI), and change the S3 bucket/object permission so that only the OAI has access. — đáp án hiện tại
  3. C. Create IAM roles for CloudFront, and change the S3 bucket/object permission so that only the IAM role has access.
  4. D. Redirect S3 bucket access to the corresponding CloudFront distribution.

Cộng đồng

0 bình luận công khai. Tên thành viên được ẩn một phần.

Chưa có bình luận. Mở giao diện tương tác để bắt đầu thảo luận.

Câu hỏi liền kề