ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
An organization hosts an encrypted S3 bucket named medical-records in the same AWS account as its development team. To enforce least-privilege, you must grant developers the ability to upload new objects to that bucket while preventing them from deleting objects, listing the bucket's contents, or accessing any other bucket. Which IAM policy configuration best satisfies this requirement?
Allow the s3:PutObject and s3:GetObject actions on the resource arn:aws:s3:::medical-records/*.
Allow the s3:PutObject action on the resource arn:aws:s3:::*.
Allow the s3:PutObject action on the resource arn:aws:s3:::medical-records/* and do not include any other S3 actions.
Allow the s3:* action on the resource arn:aws:s3:::medical-records/*.
Least-privilege dictates granting only the permissions required to perform a task. Uploading an object requires s3:PutObject on the object ARN (arn:aws:s3:::medical-records/). No additional S3 actions need to be allowed, and excluding them implicitly denies deletion, listing, or access to other buckets. Allowing GetObject, PutObject on all buckets, or the broad s3: action would grant unnecessary privileges that violate least-privilege principles.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is AWS S3 and its primary use?
Open an interactive chat with Bash
What does implementing least-privilege mean in AWS IAM policies?
Open an interactive chat with Bash
How does the s3:PutObject permission work in the bucket policy?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Access Controls
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .