hardMultiple Choice
CV0-004 Practice Question: During a security audit, an organization…
During a security audit, an organization discovers their cloud-based database is accessible from any public IP address due to a firewall rule allowing 0.0.0.0/0 on port 3306 (MySQL). The database must remain accessible to remote developers working from home. What is the most effective remediation?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Change the firewall rule to allow only specific known developer IP ranges.
Restricting to specific trusted IP ranges reduces exposure while maintaining remote access.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the firewall rule entirely and rely on database IAM authentication.
Why it's wrong here
Removing the rule blocks the remote developers the stem requires to keep working, since IAM authentication governs identity, not network reachability. Removing public exposure entirely is correct only when no external access is needed, such as an internal-only database.
- ✗
Enable encryption in transit using TLS and keep the rule as is.
Why it's wrong here
TLS encrypts traffic but leaves port 3306 reachable from every internet address, so the exposure the audit flagged persists. Encryption suits protecting data crossing untrusted networks, yet the requirement is restricting who can connect; the rule must be scoped to developer source addresses or a VPN/bastion instead.
- ✓
Change the firewall rule to allow only specific known developer IP ranges.
Why this is correct
Restricting the rule to known developer IP ranges removes anonymous public exposure on port 3306 while preserving remote access. Unlike disabling the rule or VPN-only alternatives, it directly satisfies the constraint that developers working from home must retain connectivity.
- ✗
Move the database to a private subnet without a NAT gateway.
Why it's wrong here
A private subnet without a NAT gateway has no outbound path, so remote developers cannot reach the database at all, breaking the stated requirement. This isolation suits databases with no external connectivity needs, such as backend-only stores accessed from within the VPC.
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.