Courseiva
Operations and Support →hardMultiple Select

CV0-004 Operations and Support Practice Question

A company uses AWS and wants to implement structured logging for their applications to improve queryability. Which THREE practices should they follow? (Select THREE.)

⚠ Common exam trap

CV0-004 often tests the confusion between security practices (like encryption) and operational practices (like structured logging), leading candidates to select encryption as a logging best practice when it does not address queryability.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Include timestamp, severity, and request ID in each log entry

Option B is correct because including timestamp, severity, and request ID in each log entry provides the essential contextual fields needed for filtering, correlating, and troubleshooting requests across distributed services. Option C is correct because a consistent schema across all services ensures that queries, dashboards, and log-processing pipelines can reliably parse and aggregate logs without per-service custom logic. Option D is correct because writing logs in JSON format produces machine-readable, structured events with named fields, which is the foundation for queryability in tools like Amazon CloudWatch Logs Insights or Athena. Option A is not appropriate because dumping all logs into a single unpartitioned S3 bucket hurts query performance and increases scan costs, since partitioning by date or service is a best practice. Option E is not part of structured logging; KMS encryption at rest is a security control and does not improve the structure or queryability of log data.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Send all logs to a single S3 bucket without partitioning

    Why it's wrong here

    A single unpartitioned S3 bucket prevents efficient pruning, so queries scan everything and cost and latency rise. Partitioning by date or service is tempting to skip for simplicity, but structured logging relies on partitioned prefixes so tools such as Athena can prune scanned data.

  • ✓

    Include timestamp, severity, and request ID in each log entry

    Why this is correct

    Timestamp, severity and request ID are discrete, machine-parseable fields that let queries filter by time window, log level or trace a single request across services. This satisfies the queryability goal by replacing free-text scanning with indexed field lookups.

  • ✓

    Use a consistent schema across all services

    Why this is correct

    A consistent schema means every service emits the same field names and types, so one query works across all logs without per-service parsing rules. This satisfies the queryability requirement by making cross-service correlation and aggregation reliable.

  • ✓

    Write logs in JSON format

    Why this is correct

    JSON encodes each field as an explicit key-value pair, so log processors and query engines parse entries structurally rather than by regex. This satisfies the queryability goal by enabling precise field-level filtering, projection and aggregation across services.

  • ✗

    Encrypt log files at rest using AWS KMS

    Why it's wrong here

    KMS encryption at rest protects confidentiality but adds no structure or queryability, so it does not satisfy the stated goal. It is tempting because security is a logging best practice, yet the question asks specifically for practices that improve queryability, such as JSON formatting and partitioning.

Quick reference

AWS S3 Storage Class Comparison

Storage ClassMin DurationRetrievalUse Case
S3 StandardNoneImmediateFrequently accessed data
S3 Standard-IA30 daysImmediateInfrequent access, rapid retrieval
S3 One Zone-IA30 daysImmediateNon-critical infrequent data
S3 Intelligent-TieringNoneImmediate–hoursUnknown or changing access patterns
S3 Glacier Instant90 daysMillisecondsArchive with instant retrieval
S3 Glacier Flexible90 daysMinutes–hoursArchive, flexible retrieval
S3 Glacier Deep Archive180 daysHoursLong-term compliance archive

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.