Courseiva
hardMultiple Choice

CS0-003 Practice Question: Refer to the exhibit

Exhibit

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Action": "s3:*",
      "Resource": "*"
    }
  ]
}

Refer to the exhibit. A security auditor finds this IAM policy attached to a user account. Which of the following describes the primary security concern?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The policy allows all S3 actions, which can lead to data exposure

The policy allows all S3 actions (s3:*) on all resources (Resource "*"), which means the user can read, write, delete, and modify any S3 bucket. This extreme level of access can lead to data exposure or deletion. The wildcard resource (option C) is part of the problem, but the combination of all actions is the core issue. Options A and B are incorrect; a NotAction element is not relevant here, and read-only access would be less permissive.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The policy is missing a NotAction element

    Why it's wrong here

    The NotAction element is an optional IAM policy component used to specify explicit exceptions to a list of allowed actions. Its absence does not constitute a policy defect or misconfiguration, as the primary security flaw is the overly permissive use of the wildcard action on all resources.

  • ✗

    The policy allows read-only access

    Why it's wrong here

    This statement is incorrect because the policy specifies s3:* as the action, which grants full administrative control over the S3 service. This includes highly destructive and modification-based privileges such as DeleteBucket, PutBucketPolicy, and DeleteObject, rather than restricting permissions to read-only actions like GetObject.

  • ✗

    The policy uses a wildcard resource

    Why it's wrong here

    Although specifying a wildcard resource is a significant security concern that violates the principle of least privilege, it is not the primary driver of the critical risk in isolation. The critical vulnerability stems from combining this broad resource scope with unrestricted S3 actions, which elevates the policy from a broad resource target to a catastrophic data exposure risk.

  • ✓

    The policy allows all S3 actions, which can lead to data exposure

    Why this is correct

    By utilizing the s3:* wildcard action, the policy grants unrestricted administrative permissions across the entire Simple Storage Service. This allows unauthorized users or compromised roles to perform destructive operations like deleting entire buckets, modifying access control lists, or exfiltrating sensitive data, directly leading to severe data exposure.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.