ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A development team is launching an application on Amazon EC2 that must read configuration files stored in a single Amazon S3 bucket. The team should NOT be able to list other buckets, write new objects, or delete existing ones. Which IAM policy attached to the EC2 instance profile best enforces the principle of least privilege for this requirement?
The principle of least privilege requires granting only the permissions necessary to perform the required task. Reading objects from one specific S3 bucket needs the s3:GetObject action on that bucket's ARN. Listing all buckets (s3:ListAllMyBuckets) or allowing PutObject/DeleteObject exceeds the stated requirement, while a wildcard resource could expose additional buckets. The correct policy grants only s3:GetObject on the named bucket, satisfying the requirement without unnecessary permissions.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What does the IAM role attached to an EC2 instance profile do?
Open an interactive chat with Bash
What is the principle of least privilege in AWS IAM policies?
Open an interactive chat with Bash
What is the significance of an Amazon Resource Name (ARN) in IAM policies?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .