CV0-004 Operations and Support Practice Question
A company uses AWS and wants to implement a structured logging format to simplify querying and analysis of application logs. Which three best practices should be followed when implementing structured logging? (Choose THREE.)
⚠ Common exam trap
CV0-004 often tests whether candidates pick cost-saving or performance-sounding options like plain text or binary embedding, which contradict the goals of structured logging.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Include a unique request ID for each transaction
Option B is correct because including a unique request ID for each transaction enables correlation of log entries across distributed services, making it possible to trace a single request through multiple components during querying and analysis. Option C is correct because using consistent key names across all services ensures that queries and dashboards work uniformly, avoiding the need to map different field names for the same data in tools like CloudWatch Logs Insights or Athena. Option D is correct because JSON is a structured, machine-readable format that supports native parsing and filtering of fields, which directly simplifies querying and analysis compared to unstructured text. Option A is not appropriate because plain text logs are unstructured, defeating the purpose of structured logging and making querying harder, even if storage costs are lower. Option E is not appropriate because embedding binary data in log messages bloats log size, harms readability, and is not queryable, so it does not support structured logging best practices.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Write logs in plain text to reduce storage costs
Why it's wrong here
Plain-text lines lack the field names and delimiters that structured formats such as JSON provide, so query engines cannot filter by attribute without brittle regex parsing. It is tempting because plain text reduces storage and write overhead, which suits simple append-only audit trails, not logs requiring structured querying.
- ✓
Include a unique request ID for each transaction
Why this is correct
A unique request ID per transaction lets you correlate every log line belonging to one request across services, which is essential for tracing distributed calls. Without it, entries from concurrent requests interleave and become impossible to reconstruct during analysis.
- ✓
Use consistent key names across all services
Why this is correct
Consistent key names across all services keep field semantics identical, so a single query works against logs from any component. Divergent naming forces per-service query rewrites and breaks aggregation, undermining the structured format's purpose of simplifying analysis.
- ✓
Use JSON format for log entries
Why this is correct
JSON provides a self-describing key-value structure, so each field (timestamp, severity, request ID) becomes independently queryable rather than buried in free text. This directly satisfies the requirement for a structured format that simplifies querying and analysis of application logs.
- ✗
Embed binary data in log messages for performance
Why it's wrong here
Binary payloads are not human-readable and break the key-value structure that query engines parse, defeating the purpose of structured logging. It is tempting because binary encoding shrinks payload size for throughput, but that suits high-volume transport protocols, not logs intended for searching, filtering and analysis in CloudWatch or Athena.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.