Certified Ethical Hacker (CEH) Practice Question

During a cloud security assessment, you discover that a public Amazon S3 bucket is configured for static-website hosting and is reachable only through plain HTTP. Company policy mandates that all web content must be delivered over HTTPS, but the development team cannot update application code or URLs. Which AWS-provided control offers the simplest way to meet the HTTPS-only requirement while keeping the existing site structure intact?

  • Enable server-side encryption with a customer-managed KMS key on the bucket.

  • Attach a bucket policy that denies access whenever the request's aws:SecureTransport condition evaluates to false.

  • Activate S3 versioning and enforce MFA Delete on the bucket.

  • Deploy an Amazon CloudFront distribution in front of the bucket, enable Origin Access Control, and set the viewer protocol policy to redirect HTTP to HTTPS.

Certified Ethical Hacker (CEH)
Cloud Computing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot