CompTIA Cloud+ (CV0-004)OperationsMedium

A cloud security engineer is reviewing the access control policies for an object storage bucket containing sensitive customer data. The current policy grants 'Everyone' read access. The engineer needs to restrict access so that only specific authorized applications, running on designated virtual machines, can retrieve data from this bucket, while adhering to the principle of least privilege. Which access control mechanism should be implemented?

  1. AApply a Security Group to the object storage bucket, allowing ingress from the VMs' private IPs.
  2. BUpdate the bucket policy to deny 'Everyone' and explicitly grant public IP addresses of the VMs.
  3. CConfigure IAM roles for the VMs, granting them read access to the bucket, and remove 'Everyone' access.
  4. DImplement a VPN connection from the applications to the object storage service endpoint.
Show answer & explanation

Correct answer: C. Configure IAM roles for the VMs, granting them read access to the bucket, and remove 'Everyone' access.

IAM roles provide a secure and granular way to grant permissions to cloud resources like VMs, allowing them to assume a role and access other services (like object storage) without embedding credentials. Removing 'Everyone' access and using IAM roles adheres to the principle of least privilege and is the recommended cloud-native approach.

Why the other options are wrong

  • A. Security Groups control network traffic to compute instances, not direct access to object storage buckets, which are typically accessed via API endpoints.
  • B. Relying on public IP addresses is insecure and fragile, as IPs can change or be spoofed, violating least privilege.
  • D. VPNs secure network traffic but do not manage authorization for object storage access; IAM is still needed to define what the applications can do.

IAM Roles for Cloud Resources

Identity and Access Management (IAM) roles are used to delegate temporary permissions to cloud resources (like VMs or serverless functions) to access other cloud services securely.

  • Avoids embedding static credentials.
  • Adheres to the principle of least privilege.
  • Permissions are dynamically assumed by the resource.

Memory trick: IAM Roles: Identity Access Made Right for Resources.

More Operations questions