Courseiva
Cloud And Hybrid Infrastructure SecurityeasyMultiple ChoiceObjective-mapped

CPENT Cloud And Hybrid Infrastructure Security Practice Question

An AWS penetration tester identifies an EC2 instance configured with an IAM instance profile that grants broad s3:* permissions across all S3 buckets in the account. What AWS service feature should be recommended to restrict these permissions based on least privilege?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

AWS IAM Access Analyzer and CloudTrail analysis to generate least-privilege IAM policies based on actual usage.

AWS IAM Access Analyzer helps identify unused permissions and allows policy generation based on actual access history.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • AWS Shield Advanced to inspect and block unauthorized S3 API requests at the network layer.

    Why it's wrong here

    AWS Shield protects against DDoS attacks, not IAM permission scoping.

  • AWS Trusted Advisor to enforce mandatory multi-factor authentication on all S3 API calls.

    Why it's wrong here

    Trusted Advisor provides best practice checks, not active least-privilege generation.

  • Amazon GuardDuty to automatically quarantine the EC2 instance upon detecting broad S3 access.

    Why it's wrong here

    GuardDuty detects threats but does not modify IAM permissions.

  • AWS IAM Access Analyzer and CloudTrail analysis to generate least-privilege IAM policies based on actual usage.

    Why this is correct

    Access Analyzer helps refine permissions based on activity.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CPENT question is part of Courseiva's 274-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed August 2026 · checked against the official EC-Council exam blueprint

This CPENT practice question is part of Courseiva's free EC-Council certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CPENT exam.