Courseiva

GSEC Virtualization, Cloud, and AI Essentials Practice Question

A security engineer is configuring a new AWS S3 bucket to store sensitive PII. Which combination of settings best adheres to the principle of least privilege for the bucket policy?

⚠ Common exam trap

Candidates often choose broad bucket policies granting open access to all principals or omit Secure Transport requirements, confusing general bucket creation with strict least-privilege principles.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Restrict access to specific IAM roles and require Secure Transport.

Proper S3 configuration requires a defense-in-depth approach that prevents public access while explicitly restricting actions to necessary services. By blocking public access, enforcing TLS for transit, and using explicit IAM roles, the organization minimizes the attack surface. This is vital because S3 buckets are frequent targets for misconfiguration that leads to data exposure, making granular policy control an essential defensive requirement for protecting cloud-based sensitive information.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable public access and rely on bucket ACLs for granular object permission.

    Why it's wrong here

    Public access should never be enabled for buckets containing sensitive data, as it creates an immediate risk of mass exfiltration. Relying solely on ACLs is an outdated practice that often leads to inconsistent security postures; IAM policies are the preferred method for managing modern cloud permissions.

  • ✓

    Restrict access to specific IAM roles and require Secure Transport.

    Why this is correct

    Restricting access to specific IAM roles ensures that only authorized entities can interact with the bucket. Requiring Secure Transport (HTTPS) ensures that data in transit is encrypted, protecting against interception. This combination adheres to the principle of least privilege and robust data protection standards.

  • ✗

    Assign full administrative rights to the bucket root user for ease of management.

    Why it's wrong here

    Assigning full administrative rights to any user, especially for routine bucket access, violates the principle of least privilege. This creates excessive risk if credentials are compromised, as the attacker would have full authority to delete data, modify policies, or change encryption settings across the bucket.

  • ✗

    Use a wildcard principal in the bucket policy to allow internal cross-account access.

    Why it's wrong here

    Using wildcard principals in IAM policies is dangerous because it grants permissions to unauthorized accounts or identities. Cross-account access should always be explicitly scoped to specific, trusted AWS account IDs to prevent privilege escalation or unauthorized data access by external entities within the cloud environment.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official GIAC exam blueprint

This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.