Courseiva
hardMultiple Choice

CCSP Practice Question: During a security audit, a cloud security…

During a security audit, a cloud security architect discovers that a cloud storage bucket is configured with a bucket policy that allows read access to objects from any principal. What is the most likely risk?

⚠ Common exam trap

The trap is that candidates may focus on secondary effects like cost or logging, but the core risk of a public-read bucket policy is unauthorized data access and exfiltration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Potential for data exfiltration by unauthorized users

A bucket policy allowing read access to objects from any principal means anyone on the internet can list and download objects, leading to potential data exfiltration. This is a classic cloud storage misconfiguration where sensitive data becomes publicly accessible without authentication. The primary risk is unauthorized disclosure of data, not performance or cost issues.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Denial of service from excessive requests

    Why it's wrong here

    Anonymous read access exposes object contents to anyone, so the actual risk is unauthorised data disclosure, not request flooding. It tempts because public buckets can be hammered, but denial of service concerns availability, whereas the bucket policy grants confidentiality loss regardless of request volume.

  • ✓

    Potential for data exfiltration by unauthorized users

    Why this is correct

    A bucket policy granting read access to any principal removes authentication entirely, letting anyone retrieve stored objects. This directly enables data exfiltration by unauthorised users, satisfying the stem's constraint of an unrestricted principal. Unlike identity-based controls, resource policies apply regardless of Microsoft Entra ID membership, so anonymous or external actors can enumerate and download data.

  • ✗

    Insufficient logging of access

    Why it's wrong here

    The policy itself grants anonymous read access, so the exposure exists whether or not logging captures it; missing logs are a separate detective-control gap. It tempts because auditing public buckets matters, but insufficient logging would be the finding if access records were absent, not the primary risk of the open policy.

  • ✗

    Increased cost due to excessive write operations

    Why it's wrong here

    A policy granting read access to any principal exposes object contents to anonymous or unauthorised readers; write operations are unaffected, so cost from excessive writes does not follow. This option confuses the granted action. Cost risk arises from public write access enabling data upload or ransomware.

About these practice questions

Courseiva writes every CCSP question from scratch — 934 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.