Courseiva
mediumMultiple Choice

CV0-004 Practice Question: A cloud administrator notices that an IAM role in…

A cloud administrator notices that an IAM role in a public cloud environment has permissions to perform all actions on all resources. The principle of least privilege should be applied. What is the best first step to reduce the security risk?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Review the role's attached policies and identify unused or unnecessary permissions.

The best first step is to review the role's attached policies and identify unused or unnecessary permissions (Option C). This aligns with the principle of least privilege by allowing the administrator to understand which permissions are actually needed before making changes, minimizing the risk of disrupting legitimate access. Deleting the role immediately (Option A) could cause service disruptions. Creating a new role and asking users to switch (Option B) is time-consuming and may not address the root issue. Modifying the trust policy (Option D) restricts who can assume the role but does not reduce the permissions granted.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Delete the role and create a new one with minimal permissions immediately.

    Why it's wrong here

    Deleting the role outright breaks every workload, instance profile and automation currently assuming it, causing an outage before least privilege is established. Deletion is appropriate for genuinely unused or compromised identities, not for remediating a role that is actively in use.

  • ✗

    Create a new role with fewer permissions and ask users to switch roles.

    Why it's wrong here

    Creating a parallel role and asking users to switch leaves the wildcard role intact and still assumable, so the excessive permissions remain exploitable. This approach suits planned, low-risk migrations where continuity matters, not immediate containment of an over-privileged identity.

  • ✓

    Review the role's attached policies and identify unused or unnecessary permissions.

    Why this is correct

    Reviewing attached policies exposes exactly which actions the role grants, letting the administrator identify unused or unnecessary permissions before editing anything. This directly satisfies the least-privilege constraint by scoping permissions to what the workload actually requires, rather than deleting the role or revoking access blindly, which could break dependent services.

  • ✗

    Modify the role's trust policy to restrict which users can assume it.

    Why it's wrong here

    Restricting the trust policy narrows who may assume the role but leaves its Action:* and Resource:* permissions unchanged, so any remaining principal still gains full account control. Trust-policy edits address federation or cross-account access concerns, not excessive permissions.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.