mediumMultiple Choice
CV0-004 Practice Question: During a security assessment, a cloud auditor…
During a security assessment, a cloud auditor discovers that a virtual machine has a publicly accessible SSH port (22) open to the entire internet (0.0.0.0/0). The VM is a bastion host intended for administration. What should be done to reduce risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Remove the network security group rule allowing SSH from 0.0.0.0/0 and add a rule allowing only the corporate VPN's public IP range.
A bastion host should only be accessible from trusted IPs, typically the corporate VPN or a specific IP range, to minimize exposure. Option A is incorrect because removing the security group rule and relying solely on the OS firewall does not address the network-level exposure and may not be as manageable in a cloud environment. Option B is incorrect because disabling SSH entirely would prevent necessary administrative access; serial console is not a scalable alternative. Option C is incorrect because while SSH key authentication improves security, it does not restrict the IP addresses that can attempt to connect, leaving the host exposed to brute-force attacks from the entire internet.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the security group rule for SSH and rely on the operating system firewall.
Why it's wrong here
Removing the security group rule while relying on the host firewall leaves the port reachable at the network layer, and host rules can be misconfigured or bypassed. It is tempting because defence in depth favours layered controls, but the security group is the boundary that must actually restrict 0.0.0.0/0.
- ✗
Disable SSH and use a serial console for administration.
Why it's wrong here
Disabling SSH removes the administrative channel the bastion exists to provide, so the host can no longer serve its purpose. Serial console access is tempting as an out-of-band recovery path, but it is not a substitute for the SSH administration the bastion is deployed to broker.
- ✗
Enable SSH key authentication and disable password login.
Why it's wrong here
Key authentication hardens the login method but leaves port 22 reachable from 0.0.0.0/0, so the exposure itself remains. It is tempting because disabling password login is a genuine hardening step, yet the requirement here is restricting source addresses, which key authentication does not address.
- ✓
Remove the network security group rule allowing SSH from 0.0.0.0/0 and add a rule allowing only the corporate VPN's public IP range.
Why this is correct
Restricting SSH to the corporate VPN's public IP range removes exposure to the entire internet while preserving administrative access for authorised staff. This directly satisfies the stem's requirement to reduce risk on a bastion host, since 0.0.0.0/0 permits brute-force and exploitation attempts from any source.
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.