CPENT Cloud And Hybrid Infrastructure Security Practice Question
An AWS penetration tester identifies an EC2 instance configured with an IAM instance profile that grants broad s3:* permissions across all S3 buckets in the account. What AWS service feature should be recommended to restrict these permissions based on least privilege?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
AWS IAM Access Analyzer and CloudTrail analysis to generate least-privilege IAM policies based on actual usage.
AWS IAM Access Analyzer helps identify unused permissions and allows policy generation based on actual access history.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
AWS Shield Advanced to inspect and block unauthorized S3 API requests at the network layer.
Why it's wrong here
AWS Shield protects against DDoS attacks, not IAM permission scoping.
- ✗
AWS Trusted Advisor to enforce mandatory multi-factor authentication on all S3 API calls.
Why it's wrong here
Trusted Advisor provides best practice checks, not active least-privilege generation.
- ✗
Amazon GuardDuty to automatically quarantine the EC2 instance upon detecting broad S3 access.
Why it's wrong here
GuardDuty detects threats but does not modify IAM permissions.
- ✓
AWS IAM Access Analyzer and CloudTrail analysis to generate least-privilege IAM policies based on actual usage.
Why this is correct
Access Analyzer helps refine permissions based on activity.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
This CPENT question is part of Courseiva's 274-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed August 2026 · checked against the official EC-Council exam blueprint
This CPENT practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CPENT exam.