Courseiva
Security →mediumMultiple Select

CV0-004 Security Practice Question

A cloud security team is hardening a Microsoft Azure subscription that hosts production virtual machines. The team must ensure that administrative access to the VMs requires multi-factor authentication and that privileged role assignments are reviewed on a recurring basis. (Choose two.)

⚠ Common exam trap

The trap here is conflating network-level controls like just-in-time VM access with identity-level MFA enforcement, when only Conditional Access actually requires a second authentication factor.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable Microsoft Entra multifactor authentication and enforce it through a Conditional Access policy scoped to the Azure portal and VM management.

The two requirements are MFA for administrative access and recurring review of privileged role assignments. Conditional Access enforces MFA for the portal and VM management paths, while Privileged Identity Management access reviews provide scheduled attestation of privileged roles and can revoke access automatically. The other choices either weaken privilege boundaries, address network reachability, or focus on patching rather than identity controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable Microsoft Entra multifactor authentication and enforce it through a Conditional Access policy scoped to the Azure portal and VM management.

    Why this is correct

    Conditional Access is the policy engine that evaluates signals such as user, device, and location, then enforces controls like multifactor authentication. Scoping the policy to the Azure portal and VM management ensures administrators must satisfy MFA before reaching privileged VM operations. This directly satisfies the requirement that administrative access require MFA.

  • ✗

    Assign the Owner role at the subscription scope to all administrators so they can manage access reviews themselves.

    Why it's wrong here

    Granting Owner at subscription scope gives broad control over all resources and access, which violates least privilege and expands the attack surface. It also does not create any recurring review process. Administrators managing their own access reviews introduces a conflict of interest, so this choice weakens rather than strengthens the security posture.

  • ✓

    Configure Microsoft Entra Privileged Identity Management access reviews for privileged Azure resource roles on a recurring schedule.

    Why this is correct

    Privileged Identity Management access reviews let reviewers periodically attest whether users still need privileged roles, and they can be scheduled to recur automatically. This delivers the required recurring review of privileged role assignments and can automatically remove access when a reviewer does not respond or denies continuation.

  • ✗

    Create a custom Azure Policy that audits virtual machines lacking the latest OS patches.

    Why it's wrong here

    Azure Policy evaluates resource properties and can audit or deny configurations, but patch compliance auditing addresses update hygiene, not administrative authentication or role-assignment review. This control is unrelated to MFA enforcement and to periodic attestation of privileged roles, so it does not satisfy either requirement in the scenario.

  • ✗

    Enable just-in-time VM access in Microsoft Defender for Cloud and rely on it as the sole authentication control.

    Why it's wrong here

    Just-in-time VM access locks down management ports and opens them only for approved requests, which reduces exposure, but it governs network reachability rather than proving the administrator's identity with multiple factors. It does not perform recurring access reviews. Treating it as the sole authentication control leaves the MFA requirement unmet.

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.