mediumMultiple Select
CCSP Practice Question: A cloud security engineer is reviewing an AWS IAM…
A cloud security engineer is reviewing an AWS IAM policy that includes the following statement: 'Effect: Allow, Action: iam:*, Resource: *'. Which two security concerns does this configuration create? (Choose TWO.)
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Over-permissive IAM role
Option A (Over-permissive IAM role) is correct because Action: iam:* with Resource: * grants every IAM action on every IAM resource, far exceeding what any single role should hold and violating least privilege. Option E (Privilege escalation risk) is correct because iam:* includes actions like iam:CreatePolicyVersion, iam:AttachUserPolicy, iam:PutRolePolicy, and iam:PassRole, which let an identity grant itself or others broader permissions and effectively escalate to administrator. Option B is wrong because S3 bucket exposure depends on S3 bucket policies, ACLs, or Block Public Access settings, not an IAM statement. Option C is wrong because hardcoded credentials are a code/secret-management issue, not something created by an IAM policy statement. Option D is wrong because SSRF is an application-layer vulnerability, not a property of an IAM policy.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Over-permissive IAM role
Why this is correct
Granting iam:* on Resource:* lets the principal create users, attach policies and modify roles across the whole account, far beyond any legitimate task. This violates least privilege, the specific concern the wildcard action and resource combination creates.
- ✗
Exposed S3 bucket
Why it's wrong here
An exposed S3 bucket concerns bucket ACLs or policies permitting public access; this statement governs IAM actions, not S3 resource exposure. It tempts because iam:* with Resource:* looks broadly dangerous, yet the concrete risk is unrestricted identity management, not public object storage.
- ✗
Hardcoded credentials
Why it's wrong here
Hardcoded credentials are secrets embedded in code or configuration; this policy contains no credential material, only an Allow statement. It tempts because over-permissive IAM often accompanies poor secret hygiene, but the wildcard itself creates privilege escalation, not embedded secrets.
- ✗
SSRF vulnerability
Why it's wrong here
SSRF is an application-layer flaw where attacker-supplied URLs make a server issue requests; an IAM policy grants API permissions and cannot introduce request forgery. It tempts because wildcard permissions widen blast radius, but SSRF belongs to web app testing, not IAM policy review.
- ✓
Privilege escalation risk
Why this is correct
Because iam:* includes CreatePolicyVersion, AttachRolePolicy and PassRole, a holder can grant themselves or a service broader permissions, escalating from limited access to full administrative control. That self-elevation path is the privilege escalation concern the wildcard statement creates.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.