GCFA Enterprise Environment Incident Response Practice Question
Exhibit
Policy: {
"Version": "2012-10-17",
"Statement": [{
"Effect": "Allow",
"Action": "s3:GetObject",
"Resource": "arn:aws:s3:::sensitive-data/*"
}]
}Refer to the exhibit. An attacker attempts to use a compromised identity with this policy to modify a file in the 'sensitive-data' bucket. What is the expected outcome?
⚠ Common exam trap
Candidates often assume that if a user has access to a bucket, they can modify its contents. They overlook that specific IAM actions are granular and must be explicitly permitted.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The request is denied by the service.
The IAM policy explicitly grants the 's3:GetObject' permission, which allows reading files but not modifying them. Because IAM policies follow the principle of least privilege and default to deny, any action not explicitly granted—such as 's3:PutObject' or 's3:DeleteObject'—will be denied. This is crucial for responders to understand, as it confirms that the attacker's write-based actions were blocked, potentially limiting the impact to data exfiltration rather than data tampering.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
The request is denied by the service.
Why this is correct
The policy only contains 's3:GetObject', which is a read-only permission. Any attempt to modify data requires 's3:PutObject' or similar write permissions. Since the policy does not include these, the AWS service will return an 'Access Denied' error for the unauthorized modification attempt, preventing the attacker from altering the files.
- ✗
The request is successful due to default wide permissions.
Why it's wrong here
IAM policies do not have default wide permissions. If an action is not explicitly listed in the 'Action' field, it is automatically denied. The policy provided is clearly restricted to 's3:GetObject' only, ensuring that no unauthorized modification or deletion actions can be performed by the identity assuming this role.
- ✗
The request is successful because the resource is a bucket wildcard.
Why it's wrong here
The wildcard in the resource field ('/*') applies to objects within the bucket, but it only applies to the specific action defined in the 'Action' block. Since the action is limited to read operations, the wildcard does not grant write access to those objects, regardless of the bucket name structure.
- ✗
The request is denied only if MFA is enabled.
Why it's wrong here
MFA is an authentication factor and does not change the authorization logic of an IAM policy. Even with MFA enabled, the policy specifically restricts the identity to read-only actions. Authorization is determined by the policy statement, not by the authentication method used to gain access to the role.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.