Which solution meets these requirements?

2 Comments

  1. Ann
    Author

    I think the answer is:
    Create an origin access identity (OAI) in CloudFront. Modify the S3 bucket policy to allow only the new OAI to access the bucket contents. Associate the ALB with a security group that allows only incoming traffic from the CloudFront service to communicate with the ALB.

  2. Margaret
    Author

    I scheme that the answer is:
    Create an origin access identity (OAI) in CloudFront. Modify the S3 bucket policy to allow only the new OAI to access the bucket contents. Associate the ALB with a security group that allows only incoming traffic from the CloudFront service to communicate with the ALB.

Leave a Reply

Your email address will not be published. Required fields are marked *

5 × 4 =