Refer to the exhibit. A cloud administrator applies this IAM policy to a user. What is the security impact of this specific policy?
Exhibit
{"Version": "2012-10-17", "Statement": [{"Effect": "Allow", "Action": ["s3:GetObject", "s3:ListBucket"], "Resource": ["arn:aws:s3:::company-data/*", "arn:aws:s3:::company-data"]}]}Trap 1: The policy restricts the user to read-only access for files inside…
The inclusion of the wildcard character on the resource arn:aws:s3:::company-data/* explicitly grants access to all objects within the bucket, not just the root directory. This allows the user to traverse and access any file located within the entire bucket structure, representing a potential security risk.
Trap 2: The policy permits the user to delete data from the bucket because…
The s3:ListBucket permission is limited to viewing the metadata of the bucket contents; it does not authorize deletion. Deletion requires the s3:DeleteObject or s3:DeleteBucket permissions, which are absent from this policy. Therefore, the user cannot modify or destroy the data based on these specific permissions.
Trap 3: The policy is invalid because the resource ARN formatting is…
S3 resource ARNs do not require an account ID to be valid. The format provided in the exhibit is syntactically correct for AWS IAM policies. The security issue is not with the syntax or the format, but rather with the excessive scope defined by the resource wildcards.
- A
The policy restricts the user to read-only access for files inside the root directory only.
Why it fails: The inclusion of the wildcard character on the resource arn:aws:s3:::company-data/* explicitly grants access to all objects within the bucket, not just the root directory. This allows the user to traverse and access any file located within the entire bucket structure, representing a potential security risk.
- B
The policy permits the user to delete data from the bucket because s3:ListBucket is present.
Why it fails: The s3:ListBucket permission is limited to viewing the metadata of the bucket contents; it does not authorize deletion. Deletion requires the s3:DeleteObject or s3:DeleteBucket permissions, which are absent from this policy. Therefore, the user cannot modify or destroy the data based on these specific permissions.
- C
The user gains excessive access to all objects in the bucket, potentially violating least privilege.
The policy grants broad read access to the entire contents of the bucket. If the business requirement was for access to a specific sub-folder, this policy is overly permissive. This common misconfiguration allows users to access sensitive data they do not need, increasing the risk of data leakage.
- D
The policy is invalid because the resource ARN formatting is missing the account ID.
Why it fails: S3 resource ARNs do not require an account ID to be valid. The format provided in the exhibit is syntactically correct for AWS IAM policies. The security issue is not with the syntax or the format, but rather with the excessive scope defined by the resource wildcards.