CV0-004 Security Practice Question
An organization uses multiple SaaS applications and wants to enforce data loss prevention policies and gain visibility into user activity. Which technology should they implement?
⚠ Common exam trap
CV0-004 often tests the distinction between CASB and SIEM — candidates confuse visibility (SIEM) with policy enforcement and control over SaaS (CASB), picking SIEM when the requirement includes DLP enforcement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud Access Security Broker (CASB)
A Cloud Access Security Broker (CASB) sits between users and SaaS applications to enforce DLP policies, provide visibility into shadow IT, and monitor user activity across multiple cloud services. CASB is specifically designed for the SaaS visibility and control use case described, offering API-based and proxy-based modes. It can inspect data in transit and at rest in sanctioned SaaS apps, apply DLP rules, and generate audit trails.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Security information and event management (SIEM)
Why it's wrong here
SIEM aggregates and correlates log events for detection and investigation, but it cannot inspect SaaS traffic inline or enforce DLP policy actions. It is tempting because it delivers the visibility requirement, yet visibility alone does not block data exfiltration; a cloud access security broker (CASB) sits between users and SaaS to enforce DLP.
- ✗
Web Application Firewall (WAF)
Why it's wrong here
A WAF inspects inbound HTTP requests to protect a web application from exploits such as SQL injection, but it does not govern outbound user uploads to third-party SaaS services, so DLP enforcement is absent. It is tempting because it filters web traffic, yet its correct scenario is shielding a self-hosted web application, not multi-SaaS data governance.
- ✗
Virtual private network (VPN)
Why it's wrong here
A VPN encrypts transport between endpoints and networks, giving no inspection of SaaS application payloads, user activity or data classification, so DLP policies cannot be enforced. It is tempting because it secures remote access to internal resources, which is its actual purpose; here the requirement is controlling data flows into sanctioned SaaS apps.
- ✓
Cloud Access Security Broker (CASB)
Why this is correct
A CASB sits between users and SaaS providers, giving visibility into sanctioned and unsanctioned application usage while enforcing data loss prevention policies inline. That API and proxy-based inspection satisfies both the visibility and DLP requirements across multiple SaaS applications.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.