Courseiva
Cloud Data Security →easyMultiple Choice

CCSP Cloud Data Security Practice Question

A cloud security analyst is reviewing access logs and notices that a pre-signed URL for an object was used after its expiration time. What should be the outcome of such an access attempt?

⚠ Common exam trap

The trap here is assuming that valid credentials or an active IAM identity can override an expired pre-signed URL — candidates conflate credential validity with signature validity and pick the 'allowed' option.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The request is denied with an access denied error

Pre-signed URLs embed an expiration timestamp (the X-Amz-Expires parameter, capped at 7 days for SigV4) that the storage service validates on every request. Once the current time exceeds that expiry, the signature is treated as invalid and the service returns HTTP 403 AccessDenied. The credentials used to generate the URL are irrelevant at access time — only the signed expiry governs validity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The request is redirected to a new URL automatically

    Why it's wrong here

    Expired pre-signed URLs return an access-denied error; no redirect mechanism exists, since the signature and expiry are validated at request time. It is tempting because URL redirection is common in web applications, and redirection would be correct where a legitimate endpoint has moved, not where a credential has expired.

  • ✗

    The request is allowed because the URL was generated with valid credentials

    Why it's wrong here

    The signature's expiry is validated against the request time, so valid credentials do not extend the URL's lifetime; the request is rejected. It is tempting because the URL was legitimately generated, and credential validity would be the deciding factor where no expiry parameter had been embedded in the signature.

  • ✓

    The request is denied with an access denied error

    Why this is correct

    A pre-signed URL carries a cryptographic signature embedding its expiry timestamp. Once that time passes, the storage service validates the signature and rejects the request, returning an access denied error rather than serving the object.

  • ✗

    The request is logged but still granted

    Why it's wrong here

    Expiry is enforced before authorisation, so the request is denied rather than granted; logging occurs alongside the rejection. It is tempting because audit logging of failed attempts is expected, and log-and-grant would be correct where the control is monitoring rather than access enforcement.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.