Courseiva
mediumMultiple Select

CCSP Access control lists (ACLs) Practice Question

Which THREE of the following are effective measures to prevent unauthorized access to cloud storage buckets? (Select THREE)

⚠ Common exam trap

CCSP often tests the difference between access control measures and data protection measures — candidates select encryption or versioning because they sound security-related, missing that the question asks specifically about preventing unauthorized access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enabling 'Block all public access' settings

Option B is correct because enabling 'Block all public access' settings on a cloud storage bucket prevents any anonymous or public read/write access, which is a primary vector for unauthorized access. Option D is correct because requiring IAM authentication for all access ensures every request is evaluated against identity-based policies, so only authenticated and authorized principals can reach the bucket. Option E is correct because setting bucket ACLs to 'private' removes grants to AllUsers and AuthenticatedUsers, restricting access to the bucket owner and explicitly authorized accounts. Option A does not belong because bucket versioning only preserves object versions for recovery and does not control who can access the bucket. Option C does not belong because server-side encryption protects data at rest from disclosure but does not prevent unauthorized users from accessing the bucket if permissions are misconfigured.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enabling bucket versioning

    Why it's wrong here

    Versioning preserves prior object versions for recovery; it does not evaluate or restrict who may access a bucket. It is tempting because versioning supports resilience, and it would be correct for accidental deletion or ransomware recovery, but preventing unauthorised access requires bucket policies, IAM restrictions, or public-access blocks.

  • ✓

    Enabling 'Block all public access' settings

    Why this is correct

    Blocking all public access overrides bucket policies and ACLs that would otherwise expose objects, preventing anonymous or unintended internet reads. This directly satisfies the requirement by closing the most common unauthorised access path to cloud storage.

  • ✗

    Enabling server-side encryption

    Why it's wrong here

    Server-side encryption protects data at rest after access is granted; it does not authenticate or authorise the requester. It is tempting because encryption is a core cloud control, and it would be correct for meeting confidentiality or compliance requirements, but blocking unauthorised access needs bucket policies, IAM least privilege, or public-access blocks.

  • ✓

    Requiring identity and access management (IAM) authentication for all access

    Why this is correct

    Requiring IAM authentication for every request eliminates anonymous public access, the primary cause of bucket exposure. It satisfies the stem's constraint by enforcing verified identity before any object read or write, and integrates with Microsoft Entra ID for conditional access and role-based scoping, ensuring no unauthenticated principal reaches stored data.

  • ✓

    Setting bucket access control lists (ACLs) to 'private'

    Why this is correct

    Setting bucket ACLs to 'private' removes public read or write grants, so only explicitly authorised identities can reach the objects. This directly satisfies the stem's constraint of preventing unauthorised access, since anonymous principals are denied by default. It is a foundational control, though it must be paired with identity policies and monitoring for defence in depth.

Visual reference

Source Router + ACL permit 10.0.0.0/8 deny any Server 10.0.0.5 ✓ 192.168.1.1 ✗ dropped ACLs evaluate top-down; first match wins — implicit deny all at end

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.