Courseiva

CS0-003 Incident Response and Management Practice Question

During a post-incident activity, the CSIRT performs a root cause analysis for a data breach. They discover that the breach originated from a misconfigured S3 bucket that allowed public read access. Which of the following actions should be included in the lessons learned to prevent recurrence?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement automated compliance checks for cloud storage configurations

Implementing automated compliance checks using tools like AWS Config ensures that storage configurations are continuously monitored and misconfigurations are flagged or corrected.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Rotate all access keys for the affected account

    Why it's wrong here

    While rotating compromised IAM access keys is a critical containment and recovery step to prevent unauthorized API access, it does not address the underlying root cause of the misconfiguration itself. If the storage bucket remains publicly accessible due to flawed policies, rotating access keys will not secure the exposed data from anonymous internet access.

  • ✗

    Disable public access to all S3 buckets permanently

    Why it's wrong here

    Implementing a blanket, permanent block on all public access can disrupt legitimate business operations, such as hosting public assets, static websites, or distribution media. Security teams should avoid blunt-force configurations that break application workflows, opting instead for granular, policy-based controls that align with the principle of least privilege.

  • ✗

    Conduct a penetration test on the cloud environment

    Why it's wrong here

    Penetration testing provides a valuable point-in-time assessment of security posture, but it is too infrequent to detect or prevent rapid configuration drift. To address the root cause of recurring misconfigurations, the organization requires continuous, real-time monitoring and automated enforcement rather than periodic manual assessments.

  • ✓

    Implement automated compliance checks for cloud storage configurations

    Why this is correct

    Implementing automated compliance checks, such as Cloud Security Posture Management (CSPM) tools, directly addresses the root cause by continuously auditing resource configurations against security baselines. These tools provide real-time detection and automated remediation of drift, ensuring that unauthorized public access is blocked immediately upon misconfiguration.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.