Courseiva
Vulnerability Management →hardMultiple Choice

CS0-003 Vulnerability Management Practice Question

A cloud security analyst is reviewing a misconfiguration in an AWS S3 bucket that allows public read access. The bucket contains sensitive customer data. Which of the following CIS AWS Foundations Benchmark checks would most likely identify this issue?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Ensure S3 buckets do not allow public read access

CIS AWS Foundations Benchmark includes a control for ensuring S3 buckets do not allow public read access. The control is typically '1.5 Ensure S3 bucket policy restricts public read access'. 'Enable S3 bucket logging' is about logging, not access. 'Enable default encryption' is about encryption. 'Enable versioning' is about data protection.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable default encryption for S3 buckets

    Why it's wrong here

    Default encryption protects data at rest from unauthorized read at the storage layer if an attacker somehow obtains the underlying object, but it does nothing to stop a publicly readable bucket policy from serving objects openly over HTTPS to anyone.

  • ✗

    Enable S3 bucket logging

    Why it's wrong here

    Bucket access logging records who requested which objects and when, which supports forensic investigation after the fact, but enabling logging does not restrict the bucket's access control list or policy, so public exposure would continue unchanged.

  • ✗

    Enable versioning on S3 buckets

    Why it's wrong here

    Versioning preserves prior object states so accidental deletions or overwrites can be recovered, addressing data durability and integrity concerns, but it has no relationship to whether the bucket's ACL or policy grants public read permissions.

  • ✓

    Ensure S3 buckets do not allow public read access

    Why this is correct

    This CIS control checks bucket ACLs and bucket policies for statements granting access to 'Everyone' or 'AuthenticatedUsers' groups, which is precisely the misconfiguration exposing sensitive customer data, making it the check that flags and drives remediation of the finding.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.