CV0-004 Operations and Support Practice Question
A company uses AWS and wants to implement structured logging for their applications to improve queryability. Which THREE practices should they follow? (Select THREE.)
⚠ Common exam trap
CV0-004 often tests the confusion between security practices (like encryption) and operational practices (like structured logging), leading candidates to select encryption as a logging best practice when it does not address queryability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Include timestamp, severity, and request ID in each log entry
Option B is correct because including timestamp, severity, and request ID in each log entry provides the essential contextual fields needed for filtering, correlating, and troubleshooting requests across distributed services. Option C is correct because a consistent schema across all services ensures that queries, dashboards, and log-processing pipelines can reliably parse and aggregate logs without per-service custom logic. Option D is correct because writing logs in JSON format produces machine-readable, structured events with named fields, which is the foundation for queryability in tools like Amazon CloudWatch Logs Insights or Athena. Option A is not appropriate because dumping all logs into a single unpartitioned S3 bucket hurts query performance and increases scan costs, since partitioning by date or service is a best practice. Option E is not part of structured logging; KMS encryption at rest is a security control and does not improve the structure or queryability of log data.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Send all logs to a single S3 bucket without partitioning
Why it's wrong here
A single unpartitioned S3 bucket prevents efficient pruning, so queries scan everything and cost and latency rise. Partitioning by date or service is tempting to skip for simplicity, but structured logging relies on partitioned prefixes so tools such as Athena can prune scanned data.
- ✓
Include timestamp, severity, and request ID in each log entry
Why this is correct
Timestamp, severity and request ID are discrete, machine-parseable fields that let queries filter by time window, log level or trace a single request across services. This satisfies the queryability goal by replacing free-text scanning with indexed field lookups.
- ✓
Use a consistent schema across all services
Why this is correct
A consistent schema means every service emits the same field names and types, so one query works across all logs without per-service parsing rules. This satisfies the queryability requirement by making cross-service correlation and aggregation reliable.
- ✓
Write logs in JSON format
Why this is correct
JSON encodes each field as an explicit key-value pair, so log processors and query engines parse entries structurally rather than by regex. This satisfies the queryability goal by enabling precise field-level filtering, projection and aggregation across services.
- ✗
Encrypt log files at rest using AWS KMS
Why it's wrong here
KMS encryption at rest protects confidentiality but adds no structure or queryability, so it does not satisfy the stated goal. It is tempting because security is a logging best practice, yet the question asks specifically for practices that improve queryability, such as JSON formatting and partitioning.
Quick reference
AWS S3 Storage Class Comparison
| Storage Class | Min Duration | Retrieval | Use Case |
|---|---|---|---|
| S3 Standard | None | Immediate | Frequently accessed data |
| S3 Standard-IA | 30 days | Immediate | Infrequent access, rapid retrieval |
| S3 One Zone-IA | 30 days | Immediate | Non-critical infrequent data |
| S3 Intelligent-Tiering | None | Immediate–hours | Unknown or changing access patterns |
| S3 Glacier Instant | 90 days | Milliseconds | Archive with instant retrieval |
| S3 Glacier Flexible | 90 days | Minutes–hours | Archive, flexible retrieval |
| S3 Glacier Deep Archive | 180 days | Hours | Long-term compliance archive |
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.