ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
A DevOps team assigned an IAM role to a fleet of Amazon EC2 instances so an application can store logs in an existing S3 bucket. The role currently uses the AWS-managed policy AmazonS3FullAccess. To meet the organization's least-privilege requirements without disrupting log uploads, which action should the security administrator take?
Replace AmazonS3FullAccess with the AWS-managed AmazonS3ReadOnlyAccess policy.
Detach AmazonS3FullAccess and attach an inline policy that allows s3:PutObject (and related write actions) only on the specified bucket ARN.
Keep AmazonS3FullAccess but add an explicit deny for s3:DeleteObject on all buckets.
Move the bucket to a separate AWS account and add a bucket policy that allows the role to perform s3:* on the bucket.
Least privilege means granting only the permissions required for a task. The application must write objects to one specific S3 bucket, so the role needs only the s3:PutObject action (and any necessary permissions such as s3:AbortMultipartUpload) on that bucket's ARN. Replacing the broad AmazonS3FullAccess policy with a tightly scoped inline policy meets the requirement. Granting read-only access breaks functionality, while cross-account full access or merely denying DeleteObject still over-provisions permissions, violating least-privilege principles.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is an IAM role in AWS?
Open an interactive chat with Bash
What is an inline policy in AWS IAM?
Open an interactive chat with Bash
What does ARN mean in AWS?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Security Concepts and Practices
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .