Courseiva
hardMultiple Choice

CCSP Practice Question: Is reviewing a Terraform configuration and wants…

A security engineer is reviewing a Terraform configuration and wants to prevent deployment of an S3 bucket with public read access. Which IaC scanning tool is best suited for this task?

⚠ Common exam trap

The trap is confusing secrets scanning (GitGuardian) or dependency scanning (Snyk, Dependabot) with IaC misconfiguration scanning — only Checkov is designed to evaluate Terraform resource attributes like S3 ACLs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Checkov

Checkov is a static analysis tool purpose-built for scanning Infrastructure-as-Code (Terraform, CloudFormation, Kubernetes) against security and compliance policies. It has built-in policies that flag S3 buckets with public ACLs or policies, making it the right fit for preventing public-read S3 deployments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Checkov

    Why this is correct

    Checkov is a static analysis tool that parses Terraform plans and flags misconfigured resources, including S3 buckets permitting public read access. This satisfies the stem's requirement to block deployment of publicly readable buckets before apply, unlike runtime or cloud-native posture tools.

  • ✗

    GitGuardian

    Why it's wrong here

    GitGuardian scans commits and repositories for exposed secrets such as API keys and tokens; it performs no static analysis of Terraform resource arguments, so a public-read ACL would pass unnoticed. It is the correct choice when detecting leaked credentials in source history.

  • ✗

    Snyk

    Why it's wrong here

    Snyk focuses on dependency vulnerabilities, though it has some IaC scanning; Checkov is more specialized.

  • ✗

    Dependabot

    Why it's wrong here

    Dependabot raises pull requests to patch vulnerable dependency versions in repositories; it parses package manifests, not Terraform HCL, so it cannot evaluate aws_s3_bucket_acl or public-access settings. It would be the right tool for keeping npm, pip or Maven libraries current against known CVEs.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.