Courseiva

GCFA Enterprise Environment Incident Response Practice Question

Exhibit

Policy: {
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": "s3:GetObject",
    "Resource": "arn:aws:s3:::sensitive-data/*"
  }]
}

Refer to the exhibit. An attacker attempts to use a compromised identity with this policy to modify a file in the 'sensitive-data' bucket. What is the expected outcome?

⚠ Common exam trap

Candidates often assume that if a user has access to a bucket, they can modify its contents. They overlook that specific IAM actions are granular and must be explicitly permitted.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The request is denied by the service.

The IAM policy explicitly grants the 's3:GetObject' permission, which allows reading files but not modifying them. Because IAM policies follow the principle of least privilege and default to deny, any action not explicitly granted—such as 's3:PutObject' or 's3:DeleteObject'—will be denied. This is crucial for responders to understand, as it confirms that the attacker's write-based actions were blocked, potentially limiting the impact to data exfiltration rather than data tampering.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    The request is denied by the service.

    Why this is correct

    The policy only contains 's3:GetObject', which is a read-only permission. Any attempt to modify data requires 's3:PutObject' or similar write permissions. Since the policy does not include these, the AWS service will return an 'Access Denied' error for the unauthorized modification attempt, preventing the attacker from altering the files.

  • ✗

    The request is successful due to default wide permissions.

    Why it's wrong here

    IAM policies do not have default wide permissions. If an action is not explicitly listed in the 'Action' field, it is automatically denied. The policy provided is clearly restricted to 's3:GetObject' only, ensuring that no unauthorized modification or deletion actions can be performed by the identity assuming this role.

  • ✗

    The request is successful because the resource is a bucket wildcard.

    Why it's wrong here

    The wildcard in the resource field ('/*') applies to objects within the bucket, but it only applies to the specific action defined in the 'Action' block. Since the action is limited to read operations, the wildcard does not grant write access to those objects, regardless of the bucket name structure.

  • ✗

    The request is denied only if MFA is enabled.

    Why it's wrong here

    MFA is an authentication factor and does not change the authorization logic of an IAM policy. Even with MFA enabled, the policy specifically restricts the identity to read-only actions. Authorization is determined by the policy statement, not by the authentication method used to gain access to the role.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This GCFA question is part of Courseiva's 292-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GCFA practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GCFA exam.