Courseiva
mediumMultiple Choice

Least Privilege Principle — Overly Permissive IAM Policy Example

Exhibit

Refer to the exhibit.
Firewall rule:
rule id 10: allow source 203.0.113.0/24 destination 10.0.1.100 service any

Based on the exhibit, what vulnerability is present in the firewall rule?

⚠ Common exam trap

The CASP+ exam often tests the distinction between overly permissive service definitions and broad source IP ranges. Candidates mistakenly focus on the source subnet being 'too broad' when the real flaw is the 'any' service specification.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Overly permissive service specification

The firewall rule permits 'any' as the service, meaning all TCP/UDP ports and protocols are allowed through. This is overly permissive because it bypasses the principle of least privilege, exposing the internal network to unnecessary traffic and potential attacks. A proper rule should specify only required services (e.g., TCP/443 for HTTPS) to minimize the attack surface.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Overly permissive service specification

    Why this is correct

    The rule permits any service on the relevant ports rather than restricting to the specific services required, so the vulnerability is an overly permissive service specification, allowing unnecessary protocols and broadening the exploitable attack surface beyond the intended traffic.

  • ✗

    Source IP range is too broad

    Why it's wrong here

    A broad source range permits traffic from addresses that should never reach the protected service, but the exhibit's rule must be read against its intended scope. It is tempting because wide ranges are a common misconfiguration. Narrowing the range to required hosts is correct where the rule's purpose is host-specific access.

  • ✗

    No logging is enabled

    Why it's wrong here

    Logging absence is a monitoring gap, not the rule's access-control flaw; the exhibit's vulnerability lies in the permissive source, port or action the rule allows. Logging would be the finding where traffic is correctly filtered but activity goes unrecorded for audit or incident response.

  • ✗

    Missing application ID control

    Why it's wrong here

    Application ID control restricts traffic to specific applications; omitting it permits any application on allowed ports. It is tempting because application filtering is a recognised hardening measure, and would be correct where the rule must enforce application-level identification rather than only port and address matching.

About these practice questions

This CAS-005 question is part of Courseiva's 973-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CAS-005

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Based on the exhibit, which security issue does this IAM policy represent?

hard
  • A.No versioning configured
  • ✓ B.Overly permissive resource access
  • C.Missing server-side encryption
  • D.Insufficient logging and monitoring

Why B: The IAM policy in the exhibit uses a wildcard (`*`) in the `Resource` element, granting access to all resources within the account. This violates the principle of least privilege by allowing overly permissive resource access, which could lead to unauthorized data exposure or modification. The correct answer is B because the policy does not restrict actions to specific resources, making it a classic example of excessive permissions.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.