Courseiva
mediumMultiple Select

CCSP Practice Question: A cloud application uses IAM roles with wildcard…

A cloud application uses IAM roles with wildcard permissions (e.g., iam:* or *:*). Which TWO risks are directly associated with such over-permissive IAM policies?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Privilege escalation to administrative roles

Option B is correct because wildcard IAM policies such as iam:* or *:* allow an identity to perform sensitive IAM actions like CreatePolicyVersion, AttachRolePolicy, or PutRolePolicy, which an attacker can abuse to grant themselves administrative privileges and escalate beyond their intended role. Option E is correct because *:* or broad service wildcards (for example s3:* or rds:*) permit actions like s3:GetObject, s3:ListBucket, or rds:DownloadDBLogFilePortion, enabling unauthorized reading and exfiltration of data from S3 buckets or databases. Option A is not directly tied to over-permissive IAM policies; denial of service typically stems from resource exhaustion, throttling, or destructive actions rather than the breadth of permissions alone. Option C is a possible side effect of misuse but is not a direct risk of wildcard permissions themselves. Option D is incorrect because wildcard policies reduce audit clarity by obscuring which actions are actually granted, not because of logging overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Denial of service against other cloud services

    Why it's wrong here

    Wildcard IAM policies grant excessive permissions; they do not throttle or exhaust other cloud services, so denial of service is not a direct consequence. It is tempting because compromised credentials could be abused to disrupt services, but that is an indirect effect of broader privilege misuse, not of over-permissiveness itself.

  • ✓

    Privilege escalation to administrative roles

    Why this is correct

    Wildcard actions such as iam:* let a compromised principal create policies, attach roles, or pass roles to resources, granting itself full administrative rights. This satisfies the stem's over-permissive IAM role constraint, where the absence of least privilege permits direct escalation to administrative access.

  • ✗

    Increased cost due to unnecessary resource usage

    Why it's wrong here

    Wildcard IAM policies grant excessive permissions, enabling privilege escalation and unauthorised data access, not higher billing. Cost growth stems from resource consumption, so this distractor misattributes the risk. Least-privilege scoping addresses the actual exposure; cost controls are a separate concern entirely.

  • ✗

    Difficulty in auditing permissions due to logging overhead

    Why it's wrong here

    Logging overhead is not a direct risk of wildcard permissions; the real auditing difficulty is that broad grants obscure which actions are genuinely required and used. It is tempting because verbose CloudTrail logs complicate review, but that stems from log volume, not from the policy's wildcard scope.

  • ✓

    Unauthorized data exfiltration from S3 buckets or databases

    Why this is correct

    Wildcard permissions spanning s3:* or database actions let a compromised identity read and copy objects or records to an external location. This directly satisfies the stem's over-permissive IAM policy constraint, since unrestricted read actions enable unauthorised exfiltration of bucket and database data.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.