CS0-003 Incident Response and Management Practice Question
During a post-incident activity, the CSIRT performs a root cause analysis for a data breach. They discover that the breach originated from a misconfigured S3 bucket that allowed public read access. Which of the following actions should be included in the lessons learned to prevent recurrence?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement automated compliance checks for cloud storage configurations
Implementing automated compliance checks using tools like AWS Config ensures that storage configurations are continuously monitored and misconfigurations are flagged or corrected.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Rotate all access keys for the affected account
Why it's wrong here
While rotating compromised IAM access keys is a critical containment and recovery step to prevent unauthorized API access, it does not address the underlying root cause of the misconfiguration itself. If the storage bucket remains publicly accessible due to flawed policies, rotating access keys will not secure the exposed data from anonymous internet access.
- ✗
Disable public access to all S3 buckets permanently
Why it's wrong here
Implementing a blanket, permanent block on all public access can disrupt legitimate business operations, such as hosting public assets, static websites, or distribution media. Security teams should avoid blunt-force configurations that break application workflows, opting instead for granular, policy-based controls that align with the principle of least privilege.
- ✗
Conduct a penetration test on the cloud environment
Why it's wrong here
Penetration testing provides a valuable point-in-time assessment of security posture, but it is too infrequent to detect or prevent rapid configuration drift. To address the root cause of recurring misconfigurations, the organization requires continuous, real-time monitoring and automated enforcement rather than periodic manual assessments.
- ✓
Implement automated compliance checks for cloud storage configurations
Why this is correct
Implementing automated compliance checks, such as Cloud Security Posture Management (CSPM) tools, directly addresses the root cause by continuously auditing resource configurations against security baselines. These tools provide real-time detection and automated remediation of drift, ensuring that unauthorized public access is blocked immediately upon misconfiguration.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
Learn chapter
Ransomware Incident Response
Key term
Lessons learned
Lessons learned is the process of capturing, analyzing, and documenting knowledge gained from past incidents or projects to improve future security operations and prevent recurrence of problems.
Key term
Root cause analysis
Root cause analysis is a systematic process used to identify the fundamental underlying cause of a problem, rather than just treating its symptoms.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.