CV0-004 Security Practice Question
A cloud operations team is investigating suspicious activity in a production subscription. Logs show that a service principal authenticated successfully from an unexpected country and then enumerated storage accounts. The team needs to shorten the window in which a stolen credential remains usable and receive an alert when anomalous sign-ins occur. Which combination of controls should the team prioritize?
⚠ Common exam trap
The trap here is thinking that stronger passwords or broader permissions improve security for a non-interactive service principal, when credential lifetime and anomaly detection are the real levers.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Shorten the credential lifetime for the service principal and configure risk-based sign-in alerting that triggers on anomalous locations.
Reducing credential lifetime is the most direct way to bound how long a stolen service principal secret can be abused, since every token issued from it expires on a short schedule. Risk-based sign-in alerting detects unusual locations and impossible travel, delivering the timely notification the team needs. Together they address both the exposure window and the detection gap revealed by the incident.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Shorten the credential lifetime for the service principal and configure risk-based sign-in alerting that triggers on anomalous locations.
Why this is correct
Reducing the credential lifetime limits how long a stolen secret remains valid, directly shrinking the exposure window. Risk-based sign-in detection flags authentications from atypical locations or impossible travel and can alert or block in near real time, addressing the unexpected-country enumeration. Together these controls target both the duration of exposure and timely detection of the anomaly.
- ✗
Grant the service principal contributor rights at the subscription scope and enable multi-factor authentication for all interactive users.
Why it's wrong here
Expanding the service principal to subscription-wide contributor rights increases the blast radius of the compromise rather than containing it. Multi-factor authentication applies to interactive human sign-ins and does not protect a non-interactive service principal using a client secret. This option worsens the impact and provides no reduction in credential lifetime or anomaly detection for the service principal itself.
- ✗
Increase the password length for the service principal and enable verbose application logging on the storage accounts.
Why it's wrong here
A longer password does not shorten the usable lifetime of an already-stolen credential, and service principals typically authenticate with secrets or certificates rather than interactive passwords. Verbose storage logging captures data-plane activity but does not alert on anomalous identity sign-ins or limit credential validity. This option misses both the detection and the exposure-window reduction the team needs.
- ✗
Rotate the service principal secret annually and rely on monthly manual review of stored sign-in logs to identify anomalies.
Why it's wrong here
Annual rotation leaves a stolen secret usable for up to a year, which is far too long a window for a production subscription. Monthly manual log review is retrospective and slow, so enumeration and data exfiltration could complete long before anyone notices. This option fails to shorten the exposure window and fails to provide timely alerting on anomalous sign-ins.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.