CV0-004 Security Practice Question
A cloud administrator needs to grant a developer read-only access to a specific storage bucket in AWS. Which IAM component should the administrator modify?
⚠ Common exam trap
The trap is confusing network-level controls (security groups, NACLs, WAF) with identity and access management (IAM). Candidates may think that a security group can restrict S3 access, but S3 is not a VPC resource and security groups do not apply to it.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IAM policy
To grant a developer read-only access to a specific S3 bucket, the administrator must modify an IAM policy. IAM policies are JSON documents that define permissions (Allow/Deny) for actions on AWS resources, and they can be attached to IAM users, groups, or roles. By creating a policy that allows s3:GetObject, s3:ListBucket, etc., on the specific bucket ARN, the administrator can grant least-privilege read-only access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
IAM policy
Why this is correct
An IAM policy is the JSON document that defines which actions are allowed or denied on specified resources, and attaching a read-only policy to the developer's identity or the bucket grants exactly that scoped access. Roles, groups and ACLs alone cannot express this permission set.
- ✗
Security group
Why it's wrong here
Security groups are stateful instance-level packet filters keyed on ports and CIDR ranges; they contain no user identity or bucket permission statements, so they cannot grant read-only access. They tempt when controlling which hosts may reach an instance, which is a connectivity control, not an authorisation one.
- ✗
AWS WAF
Why it's wrong here
AWS WAF inspects HTTP requests against web exploit signatures at the application layer; it holds no IAM principals or bucket policies, so it cannot grant read-only access. It tempts when protecting a web application from injection or bot traffic, not when authorising a user to a storage resource.
- ✗
Network ACL
Why it's wrong here
Network ACLs filter IP traffic at the subnet boundary; they carry no identity or resource-permission model, so they cannot grant a developer read-only bucket access. They tempt when the requirement is subnet-level allow or deny rules, which is a network control rather than an authorisation decision.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.