CV0-004 Security Practice Question
An administrator is configuring access to a cloud management console for a large team. The organization wants to require a second authentication factor for all users and centralize the identity source so that disabling an account in the corporate directory immediately removes cloud access. Which approach should the administrator implement?
⚠ Common exam trap
The trap here is believing that strong local passwords provide the same control as directory-backed federation with enforced multi-factor authentication.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Federate the cloud provider with the corporate directory using SAML or OIDC and enforce multi-factor authentication at the identity provider.
Identity federation with the corporate directory through SAML or OIDC establishes one authoritative identity source, so deactivating a directory account instantly prevents new cloud sessions. Enforcing multi-factor authentication at the identity provider applies the second factor consistently to every federated sign-in, meeting both the centralization and the stronger-authentication goals without maintaining duplicate cloud identities.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Federate the cloud provider with the corporate directory using SAML or OIDC and enforce multi-factor authentication at the identity provider.
Why this is correct
Federation makes the corporate directory the single source of truth, so disabling an account there immediately blocks cloud sign-in because the identity provider no longer issues assertions. Enforcing multi-factor authentication at the identity provider applies the second factor uniformly across every federated application, satisfying both requirements without duplicating identities in the cloud.
- ✗
Issue each user a long-lived cloud API access key and require them to use it when signing in to the management console.
Why it's wrong here
Long-lived access keys are intended for programmatic access, not interactive console sign-in, and they bypass the corporate directory entirely. If a key leaks it remains valid until manually revoked, and there is no second factor. This option fails both the centralized revocation requirement and the multi-factor authentication requirement while increasing credential sprawl.
- ✗
Share a single privileged cloud account among the team and rotate its password on a weekly schedule.
Why it's wrong here
Shared accounts destroy individual accountability, make audit trails useless, and cannot be disabled per person when someone leaves. Multi-factor authentication on a shared account still does not identify which human performed an action. Rotating the password weekly is operationally disruptive and does not achieve centralized, per-user revocation as required.
- ✗
Create separate local cloud accounts for each user and enforce a strong password complexity policy on each one.
Why it's wrong here
Local cloud accounts are independent identities that are not tied to the corporate directory, so disabling a user in the directory would not revoke cloud access. Strong passwords alone do not provide a second factor. This approach multiplies administrative overhead and leaves orphaned accounts, failing both the centralized identity and the multi-factor requirements.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.