PK0-005 Principal Practice Question
Exhibit
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::example-bucket/*",
"Principal": "*"
}
]
}Refer to the exhibit. A project manager is reviewing the security configuration of a project's cloud storage. Which of the following is the MOST significant security risk?
⚠ Common exam trap
Candidates often focus on missing encryption or overly permissive actions, but the most critical flaw is the unrestricted principal, which makes the storage publicly accessible regardless of other settings.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy allows any user
The policy statement with an unrestricted principal allows any user (authenticated or unauthenticated) to access the cloud storage. This is the most significant security risk as it effectively makes the storage publicly accessible, allowing anyone to read, write, or delete objects without restriction. Even if other settings like encryption are missing, a wide-open principal is a direct and immediate exposure.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy lacks encryption
Why it's wrong here
Missing encryption leaves data readable at rest if the storage medium or backups are accessed, but it does not grant an attacker the permissions needed to reach that data. Encryption is tempting because it is a headline control in most cloud security baselines and is frequently the first gap auditors report.
- ✗
The policy allows all actions
Why it's wrong here
A policy allowing all actions grants every principal unrestricted access to the storage, so any compromised credential yields full read, write and delete capability; encryption and version currency cannot compensate for that. It is tempting because broad policies are convenient during development, where permissive access speeds up testing.
- ✓
The policy allows any user
Why this is correct
A policy granting access to any user removes identity-based restriction entirely, exposing the stored data to anonymous or unintended principals. This is the most significant risk because it nullifies authentication and authorisation controls, unlike narrower misconfigurations that still limit who can reach the resource.
- ✗
The policy uses an outdated version
Why it's wrong here
An outdated policy version is a governance and maintenance concern; it does not by itself expose stored data, whereas a policy granting every action removes all access restriction. Version currency is tempting because compliance frameworks and audits routinely flag deprecated policy syntax, and remediating it is a standard hardening step.
Go deeper
Related to this question
About these practice questions
This PK0-005 question is part of Courseiva's 954-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PK0-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PK0-005 exam.