mediumMultiple Choice
CV0-004 Practice Question: An organization's cloud environment has a policy…
An organization's cloud environment has a policy that all administrative access must be logged and recorded. Which of the following is the best method to enforce this policy?
⚠ Common exam trap
Many exam-takers confuse logging (e.g., syslog) with session recording, failing to recognize that syslog only captures discrete events, not the full interactive session required by the policy.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Use a bastion host with session recording.
A bastion host with session recording provides a centralized, auditable gateway for administrative access. It logs all commands and keystrokes, directly meeting the policy requirement that all administrative access must be logged and recorded. This method captures the full session activity, not just connection metadata.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Require multifactor authentication.
Why it's wrong here
Multifactor authentication verifies an administrator's identity at sign-in; it generates authentication events, not a record of the administrative actions performed afterwards. It is tempting because MFA is the standard control for protecting privileged accounts, and would be correct if the policy demanded stronger proof of who is accessing the environment.
- ✓
Use a bastion host with session recording.
Why this is correct
A bastion host centralises administrative connections through one hardened jump point, and its session-recording capability captures full keystroke and command logs per session. This directly satisfies the policy that all administrative access must be logged and recorded, which network-level logging alone cannot guarantee.
- ✗
Implement a VPN connection for all administrators.
Why it's wrong here
A VPN encrypts the transport path but records nothing about the commands administrators issue once connected, so the logging policy remains unmet. It is tempting because VPNs are the standard way to secure remote administrative access, and would be the right choice if the requirement were confidentiality of admin traffic rather than audit.
- ✗
Configure syslog forwarding for all devices.
Why it's wrong here
Syslog forwarding ships log data to a collector, but it does not itself generate the administrative session records the policy requires; without an auditing mechanism producing those events, nothing is captured to forward. It is tempting because centralised log aggregation is a genuine compliance building block, and would be correct once administrative session logging is already enabled.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.