Courseiva
Security →easyMultiple Choice

CV0-004 Security Practice Question

An administrator is configuring access to a cloud management console for a large team. The organization wants to require a second authentication factor for all users and centralize the identity source so that disabling an account in the corporate directory immediately removes cloud access. Which approach should the administrator implement?

⚠ Common exam trap

The trap here is believing that strong local passwords provide the same control as directory-backed federation with enforced multi-factor authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Federate the cloud provider with the corporate directory using SAML or OIDC and enforce multi-factor authentication at the identity provider.

Identity federation with the corporate directory through SAML or OIDC establishes one authoritative identity source, so deactivating a directory account instantly prevents new cloud sessions. Enforcing multi-factor authentication at the identity provider applies the second factor consistently to every federated sign-in, meeting both the centralization and the stronger-authentication goals without maintaining duplicate cloud identities.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Federate the cloud provider with the corporate directory using SAML or OIDC and enforce multi-factor authentication at the identity provider.

    Why this is correct

    Federation makes the corporate directory the single source of truth, so disabling an account there immediately blocks cloud sign-in because the identity provider no longer issues assertions. Enforcing multi-factor authentication at the identity provider applies the second factor uniformly across every federated application, satisfying both requirements without duplicating identities in the cloud.

  • ✗

    Issue each user a long-lived cloud API access key and require them to use it when signing in to the management console.

    Why it's wrong here

    Long-lived access keys are intended for programmatic access, not interactive console sign-in, and they bypass the corporate directory entirely. If a key leaks it remains valid until manually revoked, and there is no second factor. This option fails both the centralized revocation requirement and the multi-factor authentication requirement while increasing credential sprawl.

  • ✗

    Share a single privileged cloud account among the team and rotate its password on a weekly schedule.

    Why it's wrong here

    Shared accounts destroy individual accountability, make audit trails useless, and cannot be disabled per person when someone leaves. Multi-factor authentication on a shared account still does not identify which human performed an action. Rotating the password weekly is operationally disruptive and does not achieve centralized, per-user revocation as required.

  • ✗

    Create separate local cloud accounts for each user and enforce a strong password complexity policy on each one.

    Why it's wrong here

    Local cloud accounts are independent identities that are not tied to the corporate directory, so disabling a user in the directory would not revoke cloud access. Strong passwords alone do not provide a second factor. This approach multiplies administrative overhead and leaves orphaned accounts, failing both the centralized identity and the multi-factor requirements.

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.