Based on the exhibit, what is the security risk of this bucket policy?
Principal: * allows anonymous access.
Why this answer
The bucket policy grants public read access by setting `"Principal": "*"` and `"Effect": "Allow"` with `"Action": "s3:GetObject"`. This means any unauthenticated user on the internet can list and retrieve objects in the bucket, making it publicly readable. The policy does not require any authentication or authorization checks, which is a common misconfiguration leading to data exposure.
Exam trap
ISACA often tests the distinction between read and write permissions in bucket policies, and the trap here is that candidates see `"Principal": "*"` and assume it means full public access (both read and write), but the specific `Action` determines the actual risk—only read access is granted in this case.
How to eliminate wrong answers
Option B is wrong because the policy only allows `s3:GetObject` (read) actions, not `s3:PutObject` or `s3:DeleteObject` (write) actions, so public write access is not granted. Option C is wrong because the policy sets `"Principal": "*"`, which applies to all principals, not restricting access to a specific IAM role; a restricted policy would specify an ARN like `"AWS": "arn:aws:iam::123456789012:role/MyRole"`. Option D is wrong because S3 bucket policies are not individually encrypted; they are stored as JSON documents within AWS IAM and are protected by AWS's infrastructure encryption at rest, and the question asks about a security risk, not a missing encryption feature that does not exist for policies.