Courseiva
hardMultiple SelectObjective-mapped

CV0-004 Practice Question: A cloud administrator is reviewing the security…

A cloud administrator is reviewing the security posture of a cloud deployment. The company has a policy of least privilege and must ensure that only authorized services can access storage buckets. Which THREE mechanisms should the administrator configure to enforce this policy? (Choose three.)

⚠ Common exam trap

Candidates often confuse network-level controls (ACLs and security groups) with identity-based controls, assuming they can restrict service access to storage buckets, but these mechanisms cannot enforce service identity and are not applicable to cloud storage services.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Bucket policies that restrict access to specific cloud services

Bucket policies can explicitly grant or deny access to specific cloud services (e.g., logging or auditing services) using the principal element with a service principal. This aligns with the least privilege policy by ensuring only authorized services can access the storage buckets, without relying on network-level controls. Option C is correct because organizational policies enforce rules across accounts, restricting permissions at the account level to ensure only authorized services have access. Option D is correct because IAM roles can be used to grant granular permissions to services that require access, following the principle of least privilege.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Network ACLs that block unauthorized IP ranges

    Why it's wrong here

    Network ACLs control traffic at the subnet level, not service-level access.

  • Bucket policies that restrict access to specific cloud services

    Why this is correct

    Bucket policies define who can access the bucket and under what conditions.

  • Organizational policies that restrict permissions at the account level

    Why this is correct

    SCPs set permission boundaries for accounts, enforcing least privilege across services.

  • IAM roles that grant permissions to services requiring access

    Why this is correct

    IAM roles provide temporary credentials for services to access resources.

  • Security groups that allow traffic from authorized services

    Why it's wrong here

    Security groups apply to compute instances, not storage buckets.

About these practice questions

One of 977 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.