Courseiva
hardMultiple ChoiceObjective-mapped

CISSP Practice Question: A financial services company has a hybrid cloud…

A financial services company has a hybrid cloud environment with on-premises servers and a public cloud provider. The security team recently discovered that an attacker exfiltrated sensitive customer data from a cloud storage bucket. The investigation reveals that the bucket was configured with a bucket policy that allowed anonymous read access. The security architect must redesign the architecture to prevent such incidents. The company uses AWS for cloud services. The architect proposes the following: (1) Enable AWS CloudTrail and Amazon GuardDuty for monitoring. (2) Implement AWS Identity and Access Management (IAM) roles for applications instead of long-term access keys. (3) Use AWS Key Management Service (KMS) to encrypt data at rest. (4) Configure a VPC with a NAT gateway and private subnets for all compute resources. (5) Implement S3 bucket policies that deny all access unless explicitly allowed by a specific IAM role. During a review, the chief information security officer (CISO) points out that one of these measures does not directly address the root cause of the incident. Which measure is least effective in preventing unauthorized access to S3 buckets?

⚠ Common exam trap

A common mix-up: candidates confuse detective controls (monitoring) with preventive controls (access policies, encryption, network segmentation), leading candidates to think that enabling logging and threat detection directly prevents the root cause of a misconfigured bucket policy.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Enable AWS CloudTrail and Amazon GuardDuty for monitoring

(enabling AWS CloudTrail and Amazon GuardDuty) is a detective control, not a preventive one. The root cause of the incident was a misconfigured bucket policy that allowed anonymous read access. Monitoring tools can detect unauthorized access after it occurs but cannot prevent it. The other options directly address the root cause by enforcing least privilege, encrypting data, or restricting network access.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Use AWS KMS to encrypt data at rest

    Why it's wrong here

    Using AWS Key Management Service (KMS) for data at rest encryption protects the data's confidentiality if the underlying storage is compromised. However, KMS does not control access permissions to the S3 bucket itself. If a bucket policy allows anonymous read access, an unauthorized party can still download the encrypted objects, as decryption happens transparently for any entity authorized by the bucket policy, regardless of their identity.

  • Configure a VPC with private subnets and a NAT gateway

    Why it's wrong here

    Configuring a Virtual Private Cloud (VPC) with private subnets and a Network Address Translation (NAT) gateway primarily secures network traffic for resources *within* the VPC. This network design does not govern access to Amazon S3 buckets, which are global services accessed over the internet or via VPC endpoints. S3 bucket policies and IAM policies dictate who can access the bucket, irrespective of the network configuration of the client attempting access.

  • Enable AWS CloudTrail and Amazon GuardDuty for monitoring

    Why this is correct

    Enabling AWS CloudTrail and Amazon GuardDuty is a critical detective control for identifying security misconfigurations and unauthorized activity. CloudTrail logs all API calls, including changes to S3 bucket policies that could expose data, providing an audit trail. GuardDuty continuously monitors for malicious activity and unusual S3 access patterns, such as anonymous access or data exfiltration attempts, alerting security teams to potential breaches for rapid response.

  • Implement IAM roles for applications instead of long-term access keys

    Why it's wrong here

    Implementing IAM roles for applications instead of long-term access keys is a fundamental security best practice that significantly reduces the risk of credential compromise. Roles provide temporary, dynamically generated credentials, eliminating the need to store static keys. However, this measure secures *internal application access* to AWS resources and does not prevent anonymous public access to an S3 bucket if the bucket's own policy explicitly grants `public read` permissions.

Visual reference

Inside (Private) PC-A 10.0.0.1 PC-B 10.0.0.2 NAT Router Outside (Public) 203.0.113.1 Inside Global Server PAT: many private IPs share one public IP via unique port numbers

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 747 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.