Which solution will meet these requirements?

A company has a website with an Amazon CloudFront HTTPS distribution an Application Load Balancer (ALB) with multipleweb instances for dynamic websitecontent, and an Amazon S3 bucket for static website content. The company’s securityengineer recently updated the website security requirements:
HTTPS needs to be enforced for all data in transit with specific ciphers.
The CloudFront distribution needs to be accessible from the internet only.
Which solution will meet these requirements?
A. Set up an S3 bucket policy with the aws:securetransport key. Configure the CloudFront origin access identity (OAI) with the S3 bucket. Configure CloudFront to use specific ciphers. Enforce the ALB with an HTTPS listener only and select the appropriate security policy for the ciphers. Link the ALB with AWS WAF to allow access from the CloudFront IP ranges.
B. Set up an S3 bucket policy with the aws:securetransport key. Configure the CloudFront origin access identity (OAI) with the S3 bucket. Enforce the ALB with an HTTPS listener only and select the appropriate security policy for the ciphers.
C. Modify the CloudFront distribution to use AWS WAF. Force HTTPS on the S3 bucket with specific ciphers in the bucketpolicy. Configure an HTTPS listeneronly for the ALB. Set up a security group to limit access to the ALB from the CloudFrontIP ranges.
D. Modify the CloudFront distribution to use the ALB as the origin. Enforce an HTTP listener on the ALB. Create a pathbasedrouting rule on the ALB with proxiesthat connect to Amazon S3. Create a bucket policy to allow access from theseproxies only.

amazon-exams

Leave a Reply

Your email address will not be published. Required fields are marked *


The reCAPTCHA verification period has expired. Please reload the page.