mediumMultiple Select
CCSP Practice Question: A cloud application uses IAM roles with wildcard…
A cloud application uses IAM roles with wildcard permissions (e.g., iam:* or *:*). Which TWO risks are directly associated with such over-permissive IAM policies?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Privilege escalation to administrative roles
Option B is correct because wildcard IAM policies such as iam:* or *:* allow an identity to perform sensitive IAM actions like CreatePolicyVersion, AttachRolePolicy, or PutRolePolicy, which an attacker can abuse to grant themselves administrative privileges and escalate beyond their intended role. Option E is correct because *:* or broad service wildcards (for example s3:* or rds:*) permit actions like s3:GetObject, s3:ListBucket, or rds:DownloadDBLogFilePortion, enabling unauthorized reading and exfiltration of data from S3 buckets or databases. Option A is not directly tied to over-permissive IAM policies; denial of service typically stems from resource exhaustion, throttling, or destructive actions rather than the breadth of permissions alone. Option C is a possible side effect of misuse but is not a direct risk of wildcard permissions themselves. Option D is incorrect because wildcard policies reduce audit clarity by obscuring which actions are actually granted, not because of logging overhead.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Denial of service against other cloud services
Why it's wrong here
Wildcard IAM policies grant excessive permissions; they do not throttle or exhaust other cloud services, so denial of service is not a direct consequence. It is tempting because compromised credentials could be abused to disrupt services, but that is an indirect effect of broader privilege misuse, not of over-permissiveness itself.
- ✓
Privilege escalation to administrative roles
Why this is correct
Wildcard actions such as iam:* let a compromised principal create policies, attach roles, or pass roles to resources, granting itself full administrative rights. This satisfies the stem's over-permissive IAM role constraint, where the absence of least privilege permits direct escalation to administrative access.
- ✗
Increased cost due to unnecessary resource usage
Why it's wrong here
Wildcard IAM policies grant excessive permissions, enabling privilege escalation and unauthorised data access, not higher billing. Cost growth stems from resource consumption, so this distractor misattributes the risk. Least-privilege scoping addresses the actual exposure; cost controls are a separate concern entirely.
- ✗
Difficulty in auditing permissions due to logging overhead
Why it's wrong here
Logging overhead is not a direct risk of wildcard permissions; the real auditing difficulty is that broad grants obscure which actions are genuinely required and used. It is tempting because verbose CloudTrail logs complicate review, but that stems from log volume, not from the policy's wildcard scope.
- ✓
Unauthorized data exfiltration from S3 buckets or databases
Why this is correct
Wildcard permissions spanning s3:* or database actions let a compromised identity read and copy objects or records to an external location. This directly satisfies the stem's over-permissive IAM policy constraint, since unrestricted read actions enable unauthorised exfiltration of bucket and database data.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.