hardMultiple Select
CV0-004 Practice Question: A cloud administrator is reviewing the security…
A cloud administrator is reviewing the security posture of a cloud deployment. The company has a policy of least privilege and must ensure that only authorized services can access storage buckets. Which THREE mechanisms should the administrator configure to enforce this policy? (Choose three.)
⚠ Common exam trap
Candidates often confuse network-level controls (ACLs and security groups) with identity-based controls, assuming they can restrict service access to storage buckets, but these mechanisms cannot enforce service identity and are not applicable to cloud storage services.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Bucket policies that restrict access to specific cloud services
Bucket policies (B) are resource-based policies attached directly to the storage bucket that can explicitly allow or deny access to specific cloud services or principals, enforcing least privilege at the bucket level. Organizational policies (C) apply service control policies (SCPs) or similar guardrails at the account/organization level, restricting the maximum permissions any principal can have, which prevents unauthorized services from ever gaining bucket access. IAM roles (D) grant scoped, temporary credentials to the specific services that need access, so only those services receive the permissions required, aligning with least privilege. Network ACLs (A) and security groups (E) are network-layer controls that filter IP traffic; they do not govern identity-based or resource-based authorization to storage buckets, so they cannot enforce which services are authorized to access the buckets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Network ACLs that block unauthorized IP ranges
Why it's wrong here
Network ACLs filter traffic by IP range at the subnet boundary, so they cannot distinguish which service or identity is calling a storage bucket, nor grant per-bucket read or write permissions. They suit blocking known-bad CIDR ranges, not enforcing least privilege over object storage access.
- ✓
Bucket policies that restrict access to specific cloud services
Why this is correct
Bucket policies are resource-based JSON documents attached directly to the bucket, letting you scope access to named service principals. This enforces least privilege at the storage layer itself, satisfying the requirement that only authorised services reach the buckets, independent of any IAM role attached to a compute resource.
- ✓
Organizational policies that restrict permissions at the account level
Why this is correct
Organisational policies apply guardrails at the account level, restricting which identities and services may access storage buckets regardless of individual IAM grants. This enforces least privilege across the whole account, satisfying the stem's authorisation constraint.
- ✓
IAM roles that grant permissions to services requiring access
Why this is correct
IAM roles grant temporary credentials to workloads, so each service receives only the permissions it requires, satisfying least privilege. Unlike long-lived access keys, roles avoid embedded secrets and scope access precisely to authorised services, ensuring only those services can reach the storage buckets.
- ✗
Security groups that allow traffic from authorized services
Why it's wrong here
Security groups are stateful instance-level firewalls controlling inbound and outbound traffic to compute resources; they do not govern requests made directly to a storage bucket endpoint. Bucket policies and IAM roles do that. Security groups are correct for restricting which ports and sources may reach a virtual machine.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.