CND Network Attacks And Defense Strategies Practice Question
An organization is implementing cloud security posture management (CSPM) for its multi-cloud environment. The security team needs to ensure that Amazon S3 storage buckets are not publicly accessible due to misconfigurations. Which automated preventive control should be enforced?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable Amazon S3 Block Public Access settings across all AWS accounts and buckets.
AWS S3 Block Public Access is a global or bucket-level setting that ensures public ACLs and bucket policies cannot be applied, preventing accidental data exposure via S3 misconfigurations.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Enable Amazon S3 Block Public Access settings across all AWS accounts and buckets.
Why this is correct
S3 Block Public Access overrides policies and ACLs to prevent public exposure.
- ✗
Deploy an AWS WAF web access control list on Amazon CloudFront distributions.
Why it's wrong here
CloudFront WAF inspects HTTP web traffic, not direct S3 bucket permissions.
- ✗
Configure AWS Security Hub with CIS AWS Foundations Benchmark compliance standards.
Why it's wrong here
Security Hub provides visibility and compliance reporting, but S3 Block Public Access is the preventive control.
- ✗
Install a host-based antivirus agent on all EC2 virtual machine instances.
Why it's wrong here
Antivirus agents protect EC2 operating systems, not S3 object storage configurations.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva writes every CND question from scratch — 323 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This CND practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CND exam.