Certified Ethical Hacker (CEH) Practice Question

During a cloud security assessment you learn that an Amazon S3 bucket storing nightly database dumps is publicly readable because an Everyone ACL was applied. Operations want a rapid fix that stops anonymous downloads without touching application code or existing IAM roles. What is the most appropriate action?

  • Activate S3 server access logging and CloudTrail data event logging for the bucket.

  • Turn on server-side encryption with AWS KMS for all objects in the bucket.

  • Enable object versioning and require MFA delete on the bucket.

  • Enable S3 Block Public Access for the bucket and block public access granted through ACLs.

Certified Ethical Hacker (CEH)
Cloud Computing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot