CCSP Cloud Data Security Practice Question
A cloud security analyst is reviewing access logs and notices that a pre-signed URL for an object was used after its expiration time. What should be the outcome of such an access attempt?
⚠ Common exam trap
The trap here is assuming that valid credentials or an active IAM identity can override an expired pre-signed URL — candidates conflate credential validity with signature validity and pick the 'allowed' option.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The request is denied with an access denied error
Pre-signed URLs embed an expiration timestamp (the X-Amz-Expires parameter, capped at 7 days for SigV4) that the storage service validates on every request. Once the current time exceeds that expiry, the signature is treated as invalid and the service returns HTTP 403 AccessDenied. The credentials used to generate the URL are irrelevant at access time — only the signed expiry governs validity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The request is redirected to a new URL automatically
Why it's wrong here
Expired pre-signed URLs return an access-denied error; no redirect mechanism exists, since the signature and expiry are validated at request time. It is tempting because URL redirection is common in web applications, and redirection would be correct where a legitimate endpoint has moved, not where a credential has expired.
- ✗
The request is allowed because the URL was generated with valid credentials
Why it's wrong here
The signature's expiry is validated against the request time, so valid credentials do not extend the URL's lifetime; the request is rejected. It is tempting because the URL was legitimately generated, and credential validity would be the deciding factor where no expiry parameter had been embedded in the signature.
- ✓
The request is denied with an access denied error
Why this is correct
A pre-signed URL carries a cryptographic signature embedding its expiry timestamp. Once that time passes, the storage service validates the signature and rejects the request, returning an access denied error rather than serving the object.
- ✗
The request is logged but still granted
Why it's wrong here
Expiry is enforced before authorisation, so the request is denied rather than granted; logging occurs alongside the rejection. It is tempting because audit logging of failed attempts is expected, and log-and-grant would be correct where the control is monitoring rather than access enforcement.
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.