hardMultiple Choice
CCSP Practice Question: Is reviewing a Terraform configuration and wants…
A security engineer is reviewing a Terraform configuration and wants to prevent deployment of an S3 bucket with public read access. Which IaC scanning tool is best suited for this task?
⚠ Common exam trap
The trap is confusing secrets scanning (GitGuardian) or dependency scanning (Snyk, Dependabot) with IaC misconfiguration scanning — only Checkov is designed to evaluate Terraform resource attributes like S3 ACLs.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Checkov
Checkov is a static analysis tool purpose-built for scanning Infrastructure-as-Code (Terraform, CloudFormation, Kubernetes) against security and compliance policies. It has built-in policies that flag S3 buckets with public ACLs or policies, making it the right fit for preventing public-read S3 deployments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Checkov
Why this is correct
Checkov is a static analysis tool that parses Terraform plans and flags misconfigured resources, including S3 buckets permitting public read access. This satisfies the stem's requirement to block deployment of publicly readable buckets before apply, unlike runtime or cloud-native posture tools.
- ✗
GitGuardian
Why it's wrong here
GitGuardian scans commits and repositories for exposed secrets such as API keys and tokens; it performs no static analysis of Terraform resource arguments, so a public-read ACL would pass unnoticed. It is the correct choice when detecting leaked credentials in source history.
- ✗
Snyk
Why it's wrong here
Snyk focuses on dependency vulnerabilities, though it has some IaC scanning; Checkov is more specialized.
- ✗
Dependabot
Why it's wrong here
Dependabot raises pull requests to patch vulnerable dependency versions in repositories; it parses package manifests, not Terraform HCL, so it cannot evaluate aws_s3_bucket_acl or public-access settings. It would be the right tool for keeping npm, pip or Maven libraries current against known CVEs.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.