Courseiva
Operations and Support →mediumMultiple Choice

CV0-004 Operations and Support Practice Question

A company uses a multi-cloud strategy with workloads in AWS and Azure. The cloud team wants a centralized log management solution to correlate security events across both platforms. Which approach is most suitable?

⚠ Common exam trap

CV0-004 often tests the misconception that a native cloud logging service (CloudWatch, Log Analytics) can serve as a multi-cloud solution — candidates pick the tool they know best, ignoring that the question demands cross-platform correlation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a third-party SIEM solution such as Splunk

A third-party SIEM such as Splunk is the most suitable approach because it is platform-agnostic and can ingest logs from AWS, Azure, and other sources into a centralized correlation engine. It provides cross-cloud security event correlation, alerting, and compliance reporting out of the box. This directly addresses the requirement for centralized log management across multi-cloud environments.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use AWS CloudWatch Logs with cross-account log groups

    Why it's wrong here

    CloudWatch Logs cross-account log groups centralise logs only between AWS accounts; they cannot ingest Azure activity or resource logs, so the Azure half of the estate stays uncorrelated. It is the right approach when every workload and account sits inside AWS and no second cloud provider is involved.

  • ✓

    Deploy a third-party SIEM solution such as Splunk

    Why this is correct

    Splunk ingests and normalises logs from AWS and Azure sources, correlating security events across both platforms through a single pane of glass. This directly satisfies the stem's centralised, cross-cloud correlation requirement, which native tooling such as Microsoft Entra ID or AWS Security Hub cannot deliver for a heterogeneous multi-cloud estate.

  • ✗

    Use GCP Cloud Logging with a log sink to BigQuery

    Why it's wrong here

    GCP Cloud Logging sinks route logs to BigQuery for storage and analysis, but it provides no native ingestion of AWS or Azure control-plane events, so cross-platform correlation requires custom export pipelines. It suits organisations standardising on GCP where all workloads and log sources already sit within Google Cloud.

  • ✗

    Use Azure Log Analytics and forward AWS logs to it via an agent

    Why it's wrong here

    Log Analytics ingests AWS data only through the Azure Monitor agent or custom connectors, so correlation across both clouds depends on that forwarding path rather than native multi-cloud ingestion. It is tempting because Log Analytics is the natural Azure-native choice for KQL queries and workbooks when all workloads already reside in Azure.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.