Courseiva
Network Attacks And Defense StrategiesmediumMultiple ChoiceObjective-mapped

CND Network Attacks And Defense Strategies Practice Question

An organization is implementing cloud security posture management (CSPM) for its multi-cloud environment. The security team needs to ensure that Amazon S3 storage buckets are not publicly accessible due to misconfigurations. Which automated preventive control should be enforced?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable Amazon S3 Block Public Access settings across all AWS accounts and buckets.

AWS S3 Block Public Access is a global or bucket-level setting that ensures public ACLs and bucket policies cannot be applied, preventing accidental data exposure via S3 misconfigurations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Enable Amazon S3 Block Public Access settings across all AWS accounts and buckets.

    Why this is correct

    S3 Block Public Access overrides policies and ACLs to prevent public exposure.

  • Deploy an AWS WAF web access control list on Amazon CloudFront distributions.

    Why it's wrong here

    CloudFront WAF inspects HTTP web traffic, not direct S3 bucket permissions.

  • Configure AWS Security Hub with CIS AWS Foundations Benchmark compliance standards.

    Why it's wrong here

    Security Hub provides visibility and compliance reporting, but S3 Block Public Access is the preventive control.

  • Install a host-based antivirus agent on all EC2 virtual machine instances.

    Why it's wrong here

    Antivirus agents protect EC2 operating systems, not S3 object storage configurations.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CND question from scratch — 323 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.