CV0-004 Operations and Support Practice Question
A cloud administrator needs to grant a third-party auditing firm read-only access to compliance reports in an Amazon S3 bucket for a limited period. The firm's identity provider supports SAML 2.0. Which approach best meets the requirement with least administrative overhead?
⚠ Common exam trap
The trap here is choosing IAM users for external parties out of habit, when identity federation with temporary role sessions is the lower-overhead, time-limited method.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Configure an IAM identity provider for SAML 2.0 and use role-based federation with a time-limited session
Federating the firm's SAML 2.0 identity provider with IAM lets auditors authenticate with existing credentials and assume a scoped role that returns temporary credentials with automatic expiry. This avoids creating and later removing IAM users and keys, minimizes administrative effort, and enforces least privilege for the engagement period. Presigned URLs and public policies lack identity integration and durable auditability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Configure an IAM identity provider for SAML 2.0 and use role-based federation with a time-limited session
Why this is correct
SAML 2.0 federation with an IAM identity provider lets the firm's existing directory authenticate auditors, and AWS issues temporary credentials through AssumeRoleWithSAML. No long-lived IAM users or keys are created, sessions expire automatically, and permissions come from a role scoped to S3 read-only. This satisfies limited duration and least overhead precisely.
- ✗
Generate a presigned URL for each compliance report and email it to the auditors
Why it's wrong here
Presigned URLs grant temporary access to individual objects, so each report would need its own URL and re-issuance as objects change. This does not scale for a set of compliance reports and provides no identity-based audit trail of who accessed what. It also lacks the directory-integrated authentication the firm already supports.
- ✗
Create IAM users for each auditor and attach an S3 read-only managed policy
Why it's wrong here
Creating long-lived IAM users for external auditors increases credential management overhead and violates least-privilege time-boxing. These credentials persist beyond the engagement unless manually removed, and distributing access keys to a third party expands the attack surface. This approach meets the access need but not the least-overhead and limited-duration requirements.
- ✗
Enable S3 Block Public Access and share the bucket through a public bucket policy restricted by source IP
Why it's wrong here
A source-IP-restricted public policy exposes the bucket to anyone from those addresses and defeats Block Public Access intent. It provides no per-user identity, no session expiry, and no meaningful audit trail. This is riskier than the required read-only, time-limited, identity-federated access and does not use the firm's SAML capability.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.