CV0-004 Security Practice Question
A healthcare organization must protect electronic protected health information stored in a public cloud object storage bucket. Compliance requires encryption at rest with customer-controlled keys and verifiable evidence that data has not been altered. Which TWO controls should be implemented to meet these requirements? (Choose two.)
⚠ Common exam trap
The trap here is treating versioning or replication as tamper-evidence, when only compliance-mode object lock prevents modification by any principal including the account root.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Enable object lock in compliance mode with a retention period aligned to the records retention policy.
Encryption at rest with a customer-managed key keeps cryptographic control with the organization, while object lock in compliance mode guarantees immutability that even privileged accounts cannot override. Together they deliver confidentiality and verifiable integrity for regulated health records. Versioning, restrictive bucket policies, and cross-region replication improve durability or reduce risk but cannot prove that data remains unaltered.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply a bucket policy that denies delete operations to all principals except a designated break-glass role.
Why it's wrong here
A restrictive bucket policy reduces the risk of accidental or malicious deletion but remains mutable by any principal with policy-editing rights. It does not create cryptographic immutability or provide verifiable proof of integrity to an auditor. A privileged administrator could change the policy and then delete data, so this control is weaker than object lock in compliance mode.
- ✗
Enable object versioning on the bucket to retain prior versions of every object.
Why it's wrong here
Versioning preserves historical copies of objects, which helps with recovery from accidental deletion or overwrite, but it does not provide cryptographic proof that data has not been altered. An attacker with write access could still modify the current version, and versioning alone offers no tamper-evidence. It is a durability control, not an integrity attestation control.
- ✓
Enable object lock in compliance mode with a retention period aligned to the records retention policy.
Why this is correct
Object lock in compliance mode makes objects immutable for the retention period, and even the root account cannot delete or alter them. This provides verifiable evidence that stored records have not been changed, which satisfies the tamper-evidence requirement. Combined with customer-managed encryption keys, it delivers both confidentiality and integrity assurance for regulated health data.
- ✓
Configure server-side encryption using a customer-managed key stored in the cloud provider's key management service.
Why this is correct
Server-side encryption with a customer-managed key satisfies the requirement for encryption at rest under customer control. The organization owns the key policy and can revoke access, rotate the key, and audit its use independently of the provider. This meets the compliance expectation that key custody remains with the covered entity rather than the provider's default managed keys.
- ✗
Enable cross-region replication so that a second copy of every object exists in another region.
Why it's wrong here
Cross-region replication improves availability and disaster recovery by maintaining a geographically separate copy, but both copies remain mutable. If an object is altered or deleted, the change propagates to the replica. This control addresses durability and regional resilience, not the requirement for customer-controlled encryption keys or verifiable immutability of records.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.