Courseiva
Security →easyMultiple Choice

CV0-004 Security Practice Question

A cloud administrator needs to grant a developer read-only access to a specific storage bucket in AWS. Which IAM component should the administrator modify?

⚠ Common exam trap

The trap is confusing network-level controls (security groups, NACLs, WAF) with identity and access management (IAM). Candidates may think that a security group can restrict S3 access, but S3 is not a VPC resource and security groups do not apply to it.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IAM policy

To grant a developer read-only access to a specific S3 bucket, the administrator must modify an IAM policy. IAM policies are JSON documents that define permissions (Allow/Deny) for actions on AWS resources, and they can be attached to IAM users, groups, or roles. By creating a policy that allows s3:GetObject, s3:ListBucket, etc., on the specific bucket ARN, the administrator can grant least-privilege read-only access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    IAM policy

    Why this is correct

    An IAM policy is the JSON document that defines which actions are allowed or denied on specified resources, and attaching a read-only policy to the developer's identity or the bucket grants exactly that scoped access. Roles, groups and ACLs alone cannot express this permission set.

  • ✗

    Security group

    Why it's wrong here

    Security groups are stateful instance-level packet filters keyed on ports and CIDR ranges; they contain no user identity or bucket permission statements, so they cannot grant read-only access. They tempt when controlling which hosts may reach an instance, which is a connectivity control, not an authorisation one.

  • ✗

    AWS WAF

    Why it's wrong here

    AWS WAF inspects HTTP requests against web exploit signatures at the application layer; it holds no IAM principals or bucket policies, so it cannot grant read-only access. It tempts when protecting a web application from injection or bot traffic, not when authorising a user to a storage resource.

  • ✗

    Network ACL

    Why it's wrong here

    Network ACLs filter IP traffic at the subnet boundary; they carry no identity or resource-permission model, so they cannot grant a developer read-only bucket access. They tempt when the requirement is subnet-level allow or deny rules, which is a network control rather than an authorisation decision.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.