CV0-004 Operations and Support Practice Question
A company uses a multi-cloud strategy with workloads in AWS and Azure. The cloud team wants a centralized log management solution to correlate security events across both platforms. Which approach is most suitable?
⚠ Common exam trap
CV0-004 often tests the misconception that a native cloud logging service (CloudWatch, Log Analytics) can serve as a multi-cloud solution — candidates pick the tool they know best, ignoring that the question demands cross-platform correlation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy a third-party SIEM solution such as Splunk
A third-party SIEM such as Splunk is the most suitable approach because it is platform-agnostic and can ingest logs from AWS, Azure, and other sources into a centralized correlation engine. It provides cross-cloud security event correlation, alerting, and compliance reporting out of the box. This directly addresses the requirement for centralized log management across multi-cloud environments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Use AWS CloudWatch Logs with cross-account log groups
Why it's wrong here
CloudWatch Logs cross-account log groups centralise logs only between AWS accounts; they cannot ingest Azure activity or resource logs, so the Azure half of the estate stays uncorrelated. It is the right approach when every workload and account sits inside AWS and no second cloud provider is involved.
- ✓
Deploy a third-party SIEM solution such as Splunk
Why this is correct
Splunk ingests and normalises logs from AWS and Azure sources, correlating security events across both platforms through a single pane of glass. This directly satisfies the stem's centralised, cross-cloud correlation requirement, which native tooling such as Microsoft Entra ID or AWS Security Hub cannot deliver for a heterogeneous multi-cloud estate.
- ✗
Use GCP Cloud Logging with a log sink to BigQuery
Why it's wrong here
GCP Cloud Logging sinks route logs to BigQuery for storage and analysis, but it provides no native ingestion of AWS or Azure control-plane events, so cross-platform correlation requires custom export pipelines. It suits organisations standardising on GCP where all workloads and log sources already sit within Google Cloud.
- ✗
Use Azure Log Analytics and forward AWS logs to it via an agent
Why it's wrong here
Log Analytics ingests AWS data only through the Azure Monitor agent or custom connectors, so correlation across both clouds depends on that forwarding path rather than native multi-cloud ingestion. It is tempting because Log Analytics is the natural Azure-native choice for KQL queries and workbooks when all workloads already reside in Azure.
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.