DOP-C02 Security and Compliance Practice Question
Exhibit
Refer to the exhibit.
CloudTrail log entry:
{
"eventVersion": "1.08",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012"
},
"eventTime": "2024-03-15T14:30:00Z",
"eventSource": "s3.amazonaws.com",
"eventName": "PutBucketPolicy",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "[S3Console]",
"requestParameters": {
"bucketPolicy": {
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::my-bucket/*"
}
]
}
},
"responseElements": null,
"eventType": "AwsApiCall"
}Refer to the exhibit. A security engineer finds this CloudTrail log entry. What is the most likely security concern?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The bucket is now publicly accessible
The CloudTrail log entry shows a PutBucketPolicy action that sets a bucket policy with principal '*', granting public read access to all objects in the bucket. This is a security concern because the bucket becomes publicly accessible, allowing anyone on the internet to read objects. Option A is correct because the bucket policy makes the bucket publicly accessible. Option B is incorrect because the bucket policy does not grant the root user full access; it grants public access. Option C is incorrect because the action is performed by an IAM user (the user field shows 'arn:aws:iam::123456789012:user/admin'), not the root user. Option D is incorrect because the policy allows all principals (public) to read objects, not just authenticated users.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The bucket is now publicly accessible
Why this is correct
The CloudTrail event shows an s3:PutBucketPolicy call containing 'Principal': '*' and 'Effect': 'Allow' for 's3:GetObject'. That statement explicitly permits anonymous, unauthenticated access to all objects in the bucket. Since no condition restricts the requester and S3 object ownership permits the bucket owner to apply the policy, the bucket is now publicly accessible and every object is readable by anyone with the URL.
- ✗
The bucket policy grants the root user full access
Why it's wrong here
The bucket policy does not name the root user as a principal; the Principal element is '*' which matches every principal, including anonymous users, all IAM users and roles, and every AWS account. The root user already has full administrative access to resources in its account, but this policy is not about granting root anything—it is an open allow statement for the general public.
- ✗
The root user performed an action that should have been done by an IAM user
Why it's wrong here
Whether the change was made by the root user is a governance concern, but it is not the security defect that matters. The bucket becomes public because of the policy's Principal and Action, not because of who called PutBucketPolicy; if an IAM user had applied the same policy, the exposure would be identical. Therefore, emphasizing the root identity distracts from the actual public-access vulnerability.
- ✗
The bucket policy allows only authenticated users to read objects
Why it's wrong here
The statement 'Principal': '*' cannot be read as 'only authenticated users' because in S3 bucket policies the wildcard principal explicitly includes unauthenticated anonymous callers. To restrict access to authenticated AWS identities, you would need to use an AWS account principal such as 'AWS': 'arn:aws:iam::123456789012:root' or a specific condition like aws:userid, and you would also have to deny anonymous requests. Here, no such limitation exists, so the policy grants read access to the general public, not just signed-in users.
Go deeper
Related to this question
About these practice questions
This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on DOP-C02
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Refer to the exhibit. A security engineer sees this CloudTrail event. What action did the user 'admin' perform?
medium- A.Encrypted data with a KMS key.
- B.Rotated a KMS key.
- ✓ C.Created a new KMS key.
- D.Deleted a KMS key.
Why C: The CloudTrail event shows the API call CreateKey, which is the KMS operation that provisions a brand-new customer managed key. The event name in CloudTrail directly maps to the KMS API action, and CreateKey returns a new key ID with key state 'Enabled' and no key material yet until first use. This is distinct from Encrypt, RotateKey, or ScheduleKeyDeletion, each of which produces a different eventName.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.