Courseiva
Operations and Support →mediumMultiple Choice

CV0-004 Operations and Support Practice Question

A cloud administrator is responsible for a production account and needs to ensure that an Amazon S3 bucket containing sensitive data cannot be made public, even by an administrator. The administrator wants a preventive control that blocks public access at the bucket and account level. Which action should the administrator take?

⚠ Common exam trap

The trap here is choosing a detective control such as AWS Config or access logging when the requirement explicitly calls for a preventive control that blocks public access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable S3 Block Public Access at both the bucket and account levels and verify that no bucket policy grants public access.

S3 Block Public Access is the preventive control that overrides policies and ACLs granting public access, and applying it at both the account and bucket levels ensures comprehensive protection. Detective controls such as AWS Config rules or access logging only reveal exposure after the fact, and narrow IAM denials do not cover all paths to public access. The preventive setting is the correct choice for blocking public exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create an AWS Config rule that detects public S3 buckets and sends an alert to the operations team when one is found.

    Why it's wrong here

    An AWS Config rule is a detective control that reports noncompliance after the fact. It does not prevent a bucket from being made public, and an attacker or misconfigured change could expose data before remediation occurs. The requirement is for a preventive control that blocks public access, which Config alone does not provide.

  • ✗

    Enable S3 server access logging and review the logs for public read requests to detect unauthorized exposure.

    Why it's wrong here

    Access logging records requests for auditing and forensics but does not block public access. It is a detective measure that reveals exposure only after requests have occurred, which is too late for sensitive data. The requirement calls for a preventive control, so logging alone does not satisfy the objective.

  • ✗

    Attach an IAM policy to all users denying s3:PutBucketPolicy to prevent anyone from adding a public bucket policy.

    Why it's wrong here

    Denying s3:PutBucketPolicy restricts one API action but does not prevent public access granted through bucket ACLs, access point policies, or existing policies. An administrator could still enable public access through other means, and the control is not comprehensive. A preventive control must block public access broadly, which this narrow IAM denial does not achieve.

  • ✓

    Enable S3 Block Public Access at both the bucket and account levels and verify that no bucket policy grants public access.

    Why this is correct

    S3 Block Public Access provides preventive controls that override bucket policies and ACLs that would otherwise grant public access. Enabling it at both the account and bucket levels ensures the setting applies broadly and cannot be bypassed by individual bucket configuration changes. This is the correct preventive control for preventing accidental or intentional public exposure of sensitive data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.