easyMultiple Choice
CV0-004 Practice Question: A cloud administrator is tasked with ensuring…
A cloud administrator is tasked with ensuring that all API requests to the cloud management plane are encrypted. Which protocol should be enforced to meet this requirement?
⚠ Common exam trap
CV0-004 often tests the SSL-versus-TLS distinction, baiting candidates who remember the older 'SSL' terminology instead of the correct modern protocol, TLS.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
TLS
TLS (Transport Layer Security) is the protocol that encrypts API requests to cloud management planes, securing data in transit over HTTPS. All major cloud providers expose their management APIs exclusively over TLS, and enforcing TLS 1.2 or higher is the standard requirement for encrypted control-plane traffic. TLS is the successor to SSL and is the correct modern answer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
TLS
Why this is correct
TLS encrypts data in transit, directly satisfying the requirement that management-plane API requests be encrypted. Management-plane endpoints, including Microsoft Entra ID and Azure Resource Manager, require TLS for confidentiality and integrity. Enforcing TLS 1.2 or higher prevents interception or tampering of administrative API traffic.
- ✗
IPsec
Why it's wrong here
IPsec encrypts network traffic at the IP layer, typically for VPN tunnels between sites, not individual HTTPS API calls to a management plane. It is tempting because it provides strong encryption, and it would be correct for securing site-to-site connectivity, but management-plane APIs require TLS.
- ✗
SSL
Why it's wrong here
SSL is the obsolete predecessor of TLS; modern management-plane APIs enforce TLS 1.2 or higher, and SSL versions carry known vulnerabilities. It is tempting because SSL historically encrypted web traffic, and it would be correct only for legacy systems, but current API encryption requires TLS.
- ✗
SSH
Why it's wrong here
SSH secures interactive shell sessions and file transfer, not REST or SOAP API requests to a cloud management plane. It is tempting because it encrypts administrative access, and it would be correct for remote command-line administration, but API endpoints are protected with TLS rather than SSH.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.