mediumMultiple Select
CISSP Practice Question: An access control policy grants Read and Write…
Exhibit
Refer to the exhibit.
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Action": ["s3:GetObject", "s3:PutObject"],
"Resource": "arn:aws:s3:::example-bucket/*",
"Condition": {
"IpAddress": {
"aws:SourceIp": "10.0.0.0/8"
}
}
}
]
}An access control policy grants Read and Write permissions on a specific target object and includes a network source condition restricting access to a trusted IP range. Which TWO statements about this policy are true?
⚠ Common exam trap
Do not assume a policy grants more than it explicitly states; explicit permissions and conditions define the authorized scope.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The policy implicitly denies access to subjects outside the specified IP range.
Option B is correct because an access control policy that includes a network source condition restricting access to a trusted IP range will not match requests originating from outside that range, so those subjects are implicitly denied access under the default-deny model of access control. Option E is correct because the policy explicitly grants Read and Write permissions on the specific target object, meaning read and write operations on that object are allowed for subjects that also satisfy the network source condition. Option A is incorrect because Read and Write permissions do not constitute full administrative access, which would require broader privileges such as ownership, permission management, or delete rights. Option C is incorrect because the policy only grants Read and Write, not all possible actions on the object. Option D is incorrect because the policy targets a specific object rather than all resources in the organization.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The policy grants full administrative access to the target object.
Why it's wrong here
Full administrative access to an S3 bucket typically implies the ability to perform all S3 actions, including management operations like s3:DeleteObject, s3:PutBucketPolicy, or the wildcard s3:*. This policy explicitly lists only s3:GetObject and s3:PutObject under its Action element. Therefore, it grants only specific data plane access for object manipulation, not comprehensive administrative control over the bucket itself or its lifecycle.
- ✓
The policy implicitly denies access to subjects outside the specified IP range.
Why this is correct
The Condition element specifies that the Allow effect is only active when the source IP address of the request is within the 10.0.0.0/8 range. For any request originating from an IP address outside this specified range, the condition evaluates to false, causing the Allow statement to not apply. In AWS IAM, if no explicit Allow statement applies and no explicit Deny statement exists, the default behavior is an implicit deny, effectively blocking access.
- ✗
The policy allows all actions on the target object.
Why it's wrong here
The policy's Action element explicitly lists s3:GetObject and s3:PutObject. These are specific data plane operations for retrieving and storing objects, respectively. Granting "all S3 actions" would require specifying s3:* or exhaustively listing every possible S3 action, which this policy clearly does not do. Many other S3 actions, such as s3:DeleteObject, s3:ListBucket, or s3:GetBucketPolicy, are not permitted by this statement.
- ✗
The policy applies to all resources in the organization.
Why it's wrong here
The Resource element in this policy is explicitly defined as arn:aws:s3:::example-bucket/*. This ARN (Amazon Resource Name) precisely scopes the permissions to all objects *within* the example-bucket only. It does not apply to the bucket itself (e.g., arn:aws:s3:::example-bucket) nor to any other S3 buckets, services, or resources across the entire AWS account.
- ✓
The policy allows read and write operations on the target object.
Why this is correct
The Action element of the policy explicitly includes s3:GetObject and s3:PutObject. s3:GetObject is the specific S3 API call used to retrieve (read) an new object or an existing object from a bucket. Conversely, s3:PutObject is the API call used to upload (write) a new object or overwrite an existing one. Therefore, the policy grants permissions for both reading and writing objects within the specified example-bucket.
Go deeper
Related to this question
Learn chapter
Security Operations Foundations
Key term
Access control
Access control is the security practice of determining who or what is allowed to view, use, or enter a resource, and under what conditions.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.