A cloud security administrator is auditing the access logs for an object storage bucket containing sensitive customer data. They discover that a specific user account, which should only have read-only access, has successfully performed several 'DeleteObject' operations. The bucket policy explicitly denies 'DeleteObject' to this user. What is the MOST likely reason for this unauthorized action?
- AThe bucket policy has an implicit allow for 'DeleteObject' due to a wildcard statement.
- BThe object storage bucket is publicly accessible, overriding the bucket policy.
- CAn IAM policy directly attached to the user or a group the user belongs to grants 'DeleteObject' permissions.
- DThe user's client-side application is caching outdated credentials.
Show answer & explanationAnswer & explanation
Correct answer: C. An IAM policy directly attached to the user or a group the user belongs to grants 'DeleteObject' permissions.
In cloud IAM, an explicit 'Deny' within a bucket policy can be overridden by an explicit 'Allow' in an identity-based IAM policy (attached to the user or their group). This is a critical aspect of how cloud IAM policies are evaluated, where explicit allows can sometimes trump resource-based denies.
Why the other options are wrong
- A. A bucket policy explicitly denying 'DeleteObject' to a user cannot have an implicit allow for that user within the same policy; explicit denies take precedence over implicit allows within the *same* policy.
- B. If the bucket were publicly accessible, it would be open to anyone, not just a specific user account with read-only intent. Also, a public access setting might be separate from the detailed bucket policy itself.
- D. Caching outdated credentials might lead to access denied errors, not successful unauthorized actions.
Cloud IAM Policy Evaluation Order
The hierarchical process by which cloud providers determine effective permissions, often involving evaluating explicit denies, explicit allows from various policy types (identity-based, resource-based), and implicit denies.
- Explicit 'Deny' generally takes precedence over 'Allow'.
- An 'Explicit Allow' in an identity policy can sometimes override a 'Deny' in a resource policy, depending on the exact cloud provider's evaluation logic.
- Understanding the full set of policies (user, group, role, resource) is crucial for effective permissions management.
Memory trick: The user's personal badge (IAM policy) might be stronger than the building's rules (bucket policy).