Courseiva
Security and Compliance →mediumMultiple Choice

DOP-C02 Security and Compliance Practice Question

Exhibit

Refer to the exhibit.

CloudTrail log entry:
{
    "eventVersion": "1.08",
    "userIdentity": {
        "type": "Root",
        "principalId": "123456789012",
        "arn": "arn:aws:iam::123456789012:root",
        "accountId": "123456789012"
    },
    "eventTime": "2024-03-15T14:30:00Z",
    "eventSource": "s3.amazonaws.com",
    "eventName": "PutBucketPolicy",
    "awsRegion": "us-east-1",
    "sourceIPAddress": "203.0.113.5",
    "userAgent": "[S3Console]",
    "requestParameters": {
        "bucketPolicy": {
            "Version": "2012-10-17",
            "Statement": [
                {
                    "Effect": "Allow",
                    "Principal": "*",
                    "Action": "s3:GetObject",
                    "Resource": "arn:aws:s3:::my-bucket/*"
                }
            ]
        }
    },
    "responseElements": null,
    "eventType": "AwsApiCall"
}

Refer to the exhibit. A security engineer finds this CloudTrail log entry. What is the most likely security concern?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The bucket is now publicly accessible

The CloudTrail log entry shows a PutBucketPolicy action that sets a bucket policy with principal '*', granting public read access to all objects in the bucket. This is a security concern because the bucket becomes publicly accessible, allowing anyone on the internet to read objects. Option A is correct because the bucket policy makes the bucket publicly accessible. Option B is incorrect because the bucket policy does not grant the root user full access; it grants public access. Option C is incorrect because the action is performed by an IAM user (the user field shows 'arn:aws:iam::123456789012:user/admin'), not the root user. Option D is incorrect because the policy allows all principals (public) to read objects, not just authenticated users.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The bucket is now publicly accessible

    Why this is correct

    The CloudTrail event shows an s3:PutBucketPolicy call containing 'Principal': '*' and 'Effect': 'Allow' for 's3:GetObject'. That statement explicitly permits anonymous, unauthenticated access to all objects in the bucket. Since no condition restricts the requester and S3 object ownership permits the bucket owner to apply the policy, the bucket is now publicly accessible and every object is readable by anyone with the URL.

  • ✗

    The bucket policy grants the root user full access

    Why it's wrong here

    The bucket policy does not name the root user as a principal; the Principal element is '*' which matches every principal, including anonymous users, all IAM users and roles, and every AWS account. The root user already has full administrative access to resources in its account, but this policy is not about granting root anything—it is an open allow statement for the general public.

  • ✗

    The root user performed an action that should have been done by an IAM user

    Why it's wrong here

    Whether the change was made by the root user is a governance concern, but it is not the security defect that matters. The bucket becomes public because of the policy's Principal and Action, not because of who called PutBucketPolicy; if an IAM user had applied the same policy, the exposure would be identical. Therefore, emphasizing the root identity distracts from the actual public-access vulnerability.

  • ✗

    The bucket policy allows only authenticated users to read objects

    Why it's wrong here

    The statement 'Principal': '*' cannot be read as 'only authenticated users' because in S3 bucket policies the wildcard principal explicitly includes unauthenticated anonymous callers. To restrict access to authenticated AWS identities, you would need to use an AWS account principal such as 'AWS': 'arn:aws:iam::123456789012:root' or a specific condition like aws:userid, and you would also have to deny anonymous requests. Here, no such limitation exists, so the policy grants read access to the general public, not just signed-in users.

About these practice questions

This DOP-C02 question is part of Courseiva's 1,298-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on DOP-C02

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Refer to the exhibit. A security engineer sees this CloudTrail event. What action did the user 'admin' perform?

medium
  • A.Encrypted data with a KMS key.
  • B.Rotated a KMS key.
  • ✓ C.Created a new KMS key.
  • D.Deleted a KMS key.

Why C: The CloudTrail event shows the API call CreateKey, which is the KMS operation that provisions a brand-new customer managed key. The event name in CloudTrail directly maps to the KMS API action, and CreateKey returns a new key ID with key state 'Enabled' and no key material yet until first use. This is distinct from Encrypt, RotateKey, or ScheduleKeyDeletion, each of which produces a different eventName.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DOP-C02 practice question is part of Courseiva's free Amazon Web Services certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DOP-C02 exam.