Courseiva
easyMultiple Choice

CV0-004 Practice Question: Wants to ensure that only authorized personnel…

An organization wants to ensure that only authorized personnel can access the cloud management console. Which of the following is the BEST method to achieve this?

⚠ Common exam trap

A common mix-up: candidates choose strong password policies (Option B) as the best method, overlooking that MFA is the industry-standard defense against credential compromise, not just password complexity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable multi-factor authentication (MFA) for all console users.

Multi-factor authentication (MFA) is the best method because it adds an additional layer of security beyond just a password, requiring a second factor (e.g., a time-based one-time password from an authenticator app or a hardware token). This significantly reduces the risk of unauthorized access even if credentials are compromised, as the attacker would also need the second factor. In cloud environments like AWS, Azure, or GCP, MFA is a fundamental security best practice for protecting the management console.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Enable multi-factor authentication (MFA) for all console users.

    Why this is correct

    MFA adds a second authentication factor beyond the password, so a compromised credential alone cannot grant console access. This directly satisfies the requirement that only authorised personnel reach the management console, blocking credential-stuffing and phishing-driven logins.

  • ✗

    Implement strong password policies with complex passwords.

    Why it's wrong here

    Complex password policies strengthen one authentication factor but do not confirm that the person holding the credential is authorised, and shared or stolen passwords still grant access. They suit baseline credential hygiene, whereas the scenario demands identity-bound authorisation such as federated authentication with MFA.

  • ✗

    Disable the web console and require API access only.

    Why it's wrong here

    Disabling the console and mandating API access removes the human interface rather than verifying identity, and API keys still require authentication and authorisation. It would suit automation-only environments, but the scenario asks how to authenticate administrators, which identity-based access control handles.

  • ✗

    Restrict console access to a specific IP address range.

    Why it's wrong here

    An IP range restricts where connections originate, not who is connecting; anyone on that network segment could still reach the console. It suits hardening against untrusted networks, but the requirement is authorising specific personnel, which per-user identity verification satisfies.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.