CV0-004 Security Practice Question
A cloud administrator notices that an AWS IAM user has more permissions than necessary. Which principle should be applied to correct this?
⚠ Common exam trap
CV0-004 often tests the distinction between least privilege and zero trust, so candidates pick zero trust because it sounds modern, missing that the question is specifically about trimming excess IAM permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Least privilege
Least privilege means granting an identity only the permissions required to perform its task, and nothing more. When an IAM user has excessive permissions, the correct remediation is to scope the attached policies down to the minimum necessary, which is the definition of least privilege. The other principles address different security concerns and do not directly describe trimming excess permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Separation of duties
Why it's wrong here
Separation of duties splits critical tasks across different identities to prevent fraud, which does not reduce one user's excessive permissions. It is tempting because it also limits blast radius, and it would be correct when designing approval workflows where no single person can both request and authorise a change.
- ✗
Defense in depth
Why it's wrong here
Defense in depth layers independent controls so one failure does not compromise the system, but it does not trim an individual identity's over-broad permissions. It would be the correct principle when adding network, host and data controls around an already least-privileged identity.
- ✗
Zero trust
Why it's wrong here
Zero trust removes implicit trust based on network location and verifies every request, but it does not itself scope an IAM user's granted actions. It would be the correct principle when redesigning access so on-premises and VPN traffic is authenticated and authorised like external traffic.
- ✓
Least privilege
Why this is correct
Least privilege grants only the permissions required for a user's tasks, directly removing the excessive access the AWS IAM user currently holds. Unlike broader controls such as separation of duties, it targets permission scope itself, satisfying the stem's constraint of more permissions than necessary.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.