Courseiva
Operations and Support →easyMultiple Choice

CV0-004 Operations and Support Practice Question

A cloud administrator needs to grant a third-party auditing firm read-only access to compliance reports in an Amazon S3 bucket for a limited period. The firm's identity provider supports SAML 2.0. Which approach best meets the requirement with least administrative overhead?

⚠ Common exam trap

The trap here is choosing IAM users for external parties out of habit, when identity federation with temporary role sessions is the lower-overhead, time-limited method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure an IAM identity provider for SAML 2.0 and use role-based federation with a time-limited session

Federating the firm's SAML 2.0 identity provider with IAM lets auditors authenticate with existing credentials and assume a scoped role that returns temporary credentials with automatic expiry. This avoids creating and later removing IAM users and keys, minimizes administrative effort, and enforces least privilege for the engagement period. Presigned URLs and public policies lack identity integration and durable auditability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Configure an IAM identity provider for SAML 2.0 and use role-based federation with a time-limited session

    Why this is correct

    SAML 2.0 federation with an IAM identity provider lets the firm's existing directory authenticate auditors, and AWS issues temporary credentials through AssumeRoleWithSAML. No long-lived IAM users or keys are created, sessions expire automatically, and permissions come from a role scoped to S3 read-only. This satisfies limited duration and least overhead precisely.

  • ✗

    Generate a presigned URL for each compliance report and email it to the auditors

    Why it's wrong here

    Presigned URLs grant temporary access to individual objects, so each report would need its own URL and re-issuance as objects change. This does not scale for a set of compliance reports and provides no identity-based audit trail of who accessed what. It also lacks the directory-integrated authentication the firm already supports.

  • ✗

    Create IAM users for each auditor and attach an S3 read-only managed policy

    Why it's wrong here

    Creating long-lived IAM users for external auditors increases credential management overhead and violates least-privilege time-boxing. These credentials persist beyond the engagement unless manually removed, and distributing access keys to a third party expands the attack surface. This approach meets the access need but not the least-overhead and limited-duration requirements.

  • ✗

    Enable S3 Block Public Access and share the bucket through a public bucket policy restricted by source IP

    Why it's wrong here

    A source-IP-restricted public policy exposes the bucket to anyone from those addresses and defeats Block Public Access intent. It provides no per-user identity, no session expiry, and no meaningful audit trail. This is riskier than the required read-only, time-limited, identity-federated access and does not use the firm's SAML capability.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.