Courseiva
Security →mediumMultiple Select

CV0-004 Security Practice Question

A cloud security team is hardening a Linux virtual machine that hosts a public-facing API in a public cloud. The team wants to reduce the attack surface at the operating system layer and detect unauthorized file changes. Which TWO measures should the team implement? (Choose two.)

⚠ Common exam trap

The trap here is treating cloud security group rules as a complete substitute for host-level hardening and monitoring.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove or disable unnecessary services, packages, and listening ports that the API does not require.

Reducing the attack surface means removing unnecessary services, packages, and listening ports so fewer exploitable components remain on the host. Detecting unauthorized changes requires a host-based intrusion detection system that monitors file integrity and alerts on tampering. Together these cover both the reduction and detection goals, while the remaining options either expand privileges, weaken layered filtering, or expose trust material insecurely.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store the virtual machine's SSH host keys in a publicly readable object storage bucket for easy distribution to clients.

    Why it's wrong here

    Publishing SSH host keys does not reduce attack surface or detect file changes, and it can facilitate man-in-the-middle scenarios if clients trust keys fetched from an unauthenticated source. Host keys are public by design, but distributing them insecurely undermines their trust value. This option is irrelevant to both stated objectives and introduces a trust weakness rather than a hardening benefit.

  • ✗

    Grant the API service account full administrative privileges on the virtual machine to simplify troubleshooting and deployment.

    Why it's wrong here

    Granting full administrative privileges violates least privilege and dramatically expands the blast radius if the API is compromised. An attacker exploiting the API would inherit root-level control of the host, enabling persistence and lateral movement. This increases rather than reduces attack surface and provides no detection capability, so it contradicts the team's hardening goals on both counts.

  • ✓

    Remove or disable unnecessary services, packages, and listening ports that the API does not require.

    Why this is correct

    Eliminating unneeded services, packages, and open ports directly shrinks the attack surface of the operating system, which is exactly the first goal. Every extra daemon is a potential entry point and patch burden, so removing them reduces exploitable vulnerabilities. This is a foundational hardening step that pairs well with integrity monitoring to cover both reduction and detection objectives.

  • ✓

    Enable a host-based intrusion detection system that monitors critical system files and alerts on unexpected modifications.

    Why this is correct

    A host-based intrusion detection system watches file integrity on the virtual machine itself, hashing critical binaries and configuration files and alerting when they change unexpectedly. This directly satisfies the requirement to detect unauthorized file changes at the operating system layer, and it complements perimeter controls by catching tampering that network defenses cannot see, such as a modified SSH daemon or injected cron job.

  • ✗

    Disable the local firewall and rely solely on the cloud provider's security group rules for all traffic filtering.

    Why it's wrong here

    Relying only on security group rules removes defense in depth, because any misconfiguration or instance reached from within the virtual network bypasses that single layer. Disabling the host firewall increases the attack surface rather than reducing it, and it does nothing to detect unauthorized file changes. This option works against both goals the team stated, making it incorrect for this hardening scenario.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.