🔥 40% Off Crucial Exams Memberships — Deal ends today!

9 minutes, 58 seconds remaining!

Certified Ethical Hacker (CEH) Practice Question

During an external penetration test you find an Amazon S3 bucket called corp-app-logs. The bucket policy allows the s3:ListBucket action to the "*" principal, letting anyone on the Internet enumerate object keys. Internal applications that reside in the company's VPC must continue to read and write objects normally. Which single configuration change will most effectively stop external enumeration without breaking the internal workflow?

  • Enable S3 Block Public Access for the bucket to disallow public ACLs and public policy grants

  • Create a lifecycle rule that moves objects to Amazon S3 Glacier after 30 days

  • Turn on default server-side encryption (SSE-S3) for all objects in the bucket

  • Enable S3 Versioning to keep prior revisions of every object in the bucket

Certified Ethical Hacker (CEH)
Cloud Computing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot