Courseiva
Security →mediumMultiple Choice

CV0-004 Security Practice Question

A cloud security team is implementing a key management strategy for workloads spread across AWS and Azure. The team wants a single system of record for cryptographic keys, with the ability to import existing keys from on-premises HSMs, enforce automatic annual rotation, and produce immutable audit logs of every key use. Which approach best satisfies these requirements?

⚠ Common exam trap

The trap here is assuming that a multi-Region KMS key or a replicated key vault entry creates a single multi-cloud key authority, when replication stays inside one provider.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement a centralized external key manager with cloud-native integrations, using BYOK import, policy-driven rotation, and tamper-evident logging.

Centralizing key custody in an external manager that integrates with both AWS KMS and Azure Key Vault meets the single-system-of-record goal while preserving BYOK import, policy-driven rotation, and tamper-evident audit trails. Provider-native replication or object storage cannot deliver unified control, and per-region HSM silos reintroduce fragmentation. The centralized approach also keeps key material under organizational control across clouds.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy a dedicated FIPS 140-2 Level 3 HSM cluster in each cloud region and use the provider's native key management to front the cluster.

    Why it's wrong here

    Running separate HSM clusters in each cloud creates two independent systems of record, defeating the centralized requirement. Key material would need to be synchronized manually, audit logs would not be unified, and automatic annual rotation of imported keys is not guaranteed by native provider key management when the underlying cluster is customer-managed. This adds operational overhead without meeting the single-source goal.

  • ✗

    Use AWS KMS with a multi-Region customer managed key and replicate key metadata to Azure Key Vault.

    Why it's wrong here

    AWS KMS multi-Region keys replicate key material only within AWS Regions, not into Azure. There is no native metadata replication into Azure Key Vault, and imported keys in KMS are not automatically rotated, so the annual rotation requirement fails. The immutable audit requirement would also be split across two control planes, breaking the single system of record goal.

  • ✗

    Store all keys in an encrypted S3 bucket with Object Lock and grant both clouds access through cross-account IAM roles.

    Why it's wrong here

    S3 Object Lock provides immutability for stored objects but does not perform cryptographic operations, so it cannot serve as a key management system. Keys stored as objects would be exposed to any principal with bucket access, and Azure workloads cannot use S3 keys natively. Automatic rotation and usage audit logging for cryptographic operations are absent, making this unsuitable.

  • ✓

    Implement a centralized external key manager with cloud-native integrations, using BYOK import, policy-driven rotation, and tamper-evident logging.

    Why this is correct

    A centralized external key manager integrated with both AWS KMS and Azure Key Vault provides one authoritative system of record. It supports BYOK import from on-premises HSMs, enforces rotation policies centrally, and emits tamper-evident audit logs for every cryptographic operation. This directly satisfies the single-source, import, rotation, and immutable-audit requirements across the multi-cloud environment.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.