GSEC Virtualization, Cloud, and AI Essentials Practice Question
A security engineer is configuring a new AWS S3 bucket to store sensitive PII. Which combination of settings best adheres to the principle of least privilege for the bucket policy?
⚠ Common exam trap
Candidates often choose broad bucket policies granting open access to all principals or omit Secure Transport requirements, confusing general bucket creation with strict least-privilege principles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Restrict access to specific IAM roles and require Secure Transport.
Proper S3 configuration requires a defense-in-depth approach that prevents public access while explicitly restricting actions to necessary services. By blocking public access, enforcing TLS for transit, and using explicit IAM roles, the organization minimizes the attack surface. This is vital because S3 buckets are frequent targets for misconfiguration that leads to data exposure, making granular policy control an essential defensive requirement for protecting cloud-based sensitive information.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Enable public access and rely on bucket ACLs for granular object permission.
Why it's wrong here
Public access should never be enabled for buckets containing sensitive data, as it creates an immediate risk of mass exfiltration. Relying solely on ACLs is an outdated practice that often leads to inconsistent security postures; IAM policies are the preferred method for managing modern cloud permissions.
- ✓
Restrict access to specific IAM roles and require Secure Transport.
Why this is correct
Restricting access to specific IAM roles ensures that only authorized entities can interact with the bucket. Requiring Secure Transport (HTTPS) ensures that data in transit is encrypted, protecting against interception. This combination adheres to the principle of least privilege and robust data protection standards.
- ✗
Assign full administrative rights to the bucket root user for ease of management.
Why it's wrong here
Assigning full administrative rights to any user, especially for routine bucket access, violates the principle of least privilege. This creates excessive risk if credentials are compromised, as the attacker would have full authority to delete data, modify policies, or change encryption settings across the bucket.
- ✗
Use a wildcard principal in the bucket policy to allow internal cross-account access.
Why it's wrong here
Using wildcard principals in IAM policies is dangerous because it grants permissions to unauthorized accounts or identities. Cross-account access should always be explicitly scoped to specific, trusted AWS account IDs to prevent privilege escalation or unauthorized data access by external entities within the cloud environment.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
About these practice questions
Courseiva writes every GSEC question from scratch — 351 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official GIAC exam blueprint
This GSEC practice question is part of Courseiva's free GIAC certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the GSEC exam.