Courseiva
easyMultiple Choice

CCSP Practice Question: A cloud security engineer is troubleshooting a…

A cloud security engineer is troubleshooting a failure in automated backups for a production database. The backup job runs nightly but has failed for the past three nights. The logs show permission denied errors when the backup service attempts to write to the storage bucket. Which action should the engineer take first?

⚠ Common exam trap

ISC2 often tests the distinction between authentication (who you are) and authorization (what you can do), leading candidates to mistakenly rotate keys or restart services instead of checking permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Check the IAM roles and bucket ACLs assigned to the service account.

The permission denied errors indicate that the service account used by the backup job lacks the necessary permissions to write to the storage bucket. Checking the IAM roles and bucket ACLs is the first logical step to identify and resolve the misconfiguration, as it directly addresses the root cause without introducing unnecessary changes or escalations.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Open a support ticket with the cloud provider for incident response.

    Why it's wrong here

    Provider support cannot resolve an IAM policy denying the backup service's write, so it delays diagnosis. It is tempting because the failure is cloud-hosted, and would be correct if the bucket or service itself were impaired rather than the identity's permissions.

  • ✓

    Check the IAM roles and bucket ACLs assigned to the service account.

    Why this is correct

    Permission denied errors when writing to the bucket point to identity or resource-policy authorisation, so verifying the service account's IAM roles and bucket ACLs satisfies the stem's access-failure constraint before any retry or code change.

  • ✗

    Restart the backup service and retry the job.

    Why it's wrong here

    Restarting the service cannot alter the bucket's IAM policy, so the permission denied error will recur on retry. Restarts suit transient faults like crashed processes or stale connections, not persistent authorisation denials that require a policy or role correction.

  • ✗

    Rotate the service account keys used for authentication.

    Why it's wrong here

    Rotating keys addresses credential expiry or compromise, but the logs show authorisation failure, not authentication failure — the identity is recognised yet lacks bucket write permission. Key rotation is the right first step when authentication itself fails, such as expired or revoked credentials.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.