hardMultiple Choice
CS0-003 Practice Question: Refer to the exhibit
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:*",
"Resource": "*"
}
]
}Refer to the exhibit. A security auditor finds this IAM policy attached to a user account. Which of the following describes the primary security concern?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy allows all S3 actions, which can lead to data exposure
The policy allows all S3 actions (s3:*) on all resources (Resource "*"), which means the user can read, write, delete, and modify any S3 bucket. This extreme level of access can lead to data exposure or deletion. The wildcard resource (option C) is part of the problem, but the combination of all actions is the core issue. Options A and B are incorrect; a NotAction element is not relevant here, and read-only access would be less permissive.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy is missing a NotAction element
Why it's wrong here
The NotAction element is an optional IAM policy component used to specify explicit exceptions to a list of allowed actions. Its absence does not constitute a policy defect or misconfiguration, as the primary security flaw is the overly permissive use of the wildcard action on all resources.
- ✗
The policy allows read-only access
Why it's wrong here
This statement is incorrect because the policy specifies s3:* as the action, which grants full administrative control over the S3 service. This includes highly destructive and modification-based privileges such as DeleteBucket, PutBucketPolicy, and DeleteObject, rather than restricting permissions to read-only actions like GetObject.
- ✗
The policy uses a wildcard resource
Why it's wrong here
Although specifying a wildcard resource is a significant security concern that violates the principle of least privilege, it is not the primary driver of the critical risk in isolation. The critical vulnerability stems from combining this broad resource scope with unrestricted S3 actions, which elevates the policy from a broad resource target to a catastrophic data exposure risk.
- ✓
The policy allows all S3 actions, which can lead to data exposure
Why this is correct
By utilizing the s3:* wildcard action, the policy grants unrestricted administrative permissions across the entire Simple Storage Service. This allows unauthorized users or compromised roles to perform destructive operations like deleting entire buckets, modifying access control lists, or exfiltrating sensitive data, directly leading to severe data exposure.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
Learn chapter
Memory Forensics and Volatile Data
Key term
IAM policy
An IAM policy is a set of rules that determines who can access specific cloud resources and what actions they are allowed to perform.
Key term
IAM
Identity and Access Management (IAM) is a framework of policies and technologies that ensures the right individuals have the appropriate access to technology resources.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.