CompTIA Cloud+ (CV0-004)TroubleshootingHard

A cloud security engineer is conducting an audit and discovers that several critical S3 buckets (or equivalent object storage) containing sensitive logs are publicly accessible. The bucket policies explicitly deny public access, and there are no public ACLs on the buckets. What is the MOST likely reason for this public accessibility?

  1. AThe cloud provider's default bucket policy implicitly overrides explicit denials.
  2. BA cross-account IAM role with excessive permissions is granting unintended access.
  3. CThe objects within the buckets have individual ACLs set to public read.
  4. DThe VPC endpoint policy for S3 is misconfigured, allowing public access.
Show answer & explanation

Correct answer: C. The objects within the buckets have individual ACLs set to public read.

If bucket policies deny public access and bucket ACLs are private, but the bucket is still publicly accessible, it's highly probable that individual objects within the bucket have their own ACLs set to public read, which can override bucket-level policies for specific objects.

Why the other options are wrong

  • A. Cloud providers prioritize explicit denials; default policies typically do not override explicit security configurations.
  • B. Cross-account IAM roles would grant access to another AWS account, not necessarily public internet access.
  • D. VPC endpoint policies control access from within the VPC to S3, not public internet access to S3 buckets.

Object Storage ACLs

Access Control Lists (ACLs) applied at the individual object level within object storage services, granting specific permissions to users or groups.

  • Can grant public read/write access to individual objects.
  • Can potentially override bucket policies for specific objects.
  • Often a source of unintended public data exposure if not managed carefully.

Memory trick: Object ACLs Can Open Private Buckets.

More Troubleshooting questions