Courseiva
mediumMultiple Select

CCSP Practice Question: A cloud security engineer is reviewing an AWS IAM…

A cloud security engineer is reviewing an AWS IAM policy that includes the following statement: 'Effect: Allow, Action: iam:*, Resource: *'. Which two security concerns does this configuration create? (Choose TWO.)

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Over-permissive IAM role

Option A (Over-permissive IAM role) is correct because Action: iam:* with Resource: * grants every IAM action on every IAM resource, far exceeding what any single role should hold and violating least privilege. Option E (Privilege escalation risk) is correct because iam:* includes actions like iam:CreatePolicyVersion, iam:AttachUserPolicy, iam:PutRolePolicy, and iam:PassRole, which let an identity grant itself or others broader permissions and effectively escalate to administrator. Option B is wrong because S3 bucket exposure depends on S3 bucket policies, ACLs, or Block Public Access settings, not an IAM statement. Option C is wrong because hardcoded credentials are a code/secret-management issue, not something created by an IAM policy statement. Option D is wrong because SSRF is an application-layer vulnerability, not a property of an IAM policy.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Over-permissive IAM role

    Why this is correct

    Granting iam:* on Resource:* lets the principal create users, attach policies and modify roles across the whole account, far beyond any legitimate task. This violates least privilege, the specific concern the wildcard action and resource combination creates.

  • ✗

    Exposed S3 bucket

    Why it's wrong here

    An exposed S3 bucket concerns bucket ACLs or policies permitting public access; this statement governs IAM actions, not S3 resource exposure. It tempts because iam:* with Resource:* looks broadly dangerous, yet the concrete risk is unrestricted identity management, not public object storage.

  • ✗

    Hardcoded credentials

    Why it's wrong here

    Hardcoded credentials are secrets embedded in code or configuration; this policy contains no credential material, only an Allow statement. It tempts because over-permissive IAM often accompanies poor secret hygiene, but the wildcard itself creates privilege escalation, not embedded secrets.

  • ✗

    SSRF vulnerability

    Why it's wrong here

    SSRF is an application-layer flaw where attacker-supplied URLs make a server issue requests; an IAM policy grants API permissions and cannot introduce request forgery. It tempts because wildcard permissions widen blast radius, but SSRF belongs to web app testing, not IAM policy review.

  • ✓

    Privilege escalation risk

    Why this is correct

    Because iam:* includes CreatePolicyVersion, AttachRolePolicy and PassRole, a holder can grant themselves or a service broader permissions, escalating from limited access to full administrative control. That self-elevation path is the privilege escalation concern the wildcard statement creates.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.