Courseiva
easyMultiple ChoiceObjective-mapped

CV0-004 Practice Question: Refer to the exhibit

Exhibit

Refer to the exhibit.
```
[critical] [security] [user_data] [user_data_1e3b] User credentials stored in user data where they are accessible to all users with read access.
```

Refer to the exhibit. This log message is from a cloud security scanner. Which principle did the scanner likely detect?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Least privilege

The message indicates that user credentials were stored in user data (such as instance metadata) and are accessible to all users with read access to that metadata. This violates the principle of least privilege because credentials should not be widely accessible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Separation of duties

    Why it's wrong here

    Separation of duties involves dividing responsibilities among different people, not about credential storage.

  • Defense in depth

    Why it's wrong here

    Defense in depth is about multiple layers of security, not about storing credentials properly.

  • Fail securely

    Why it's wrong here

    Fail securely means that when an error occurs, the system remains secure; not directly related.

  • Least privilege

    Why this is correct

    Storing credentials where many users can access them gives more privilege than necessary.

About these practice questions

This CV0-004 question is part of Courseiva's 977-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on CV0-004

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. Which TWO steps should be performed to ensure that a new cloud user has only the minimum required permissions to perform their job? (Choose two.)

easy
  • A.Assign the user to a group with broad administrator access for flexibility.
  • B.Provide permissions based on the user's specific job functions.
  • C.Remove the user's account immediately after granting access.
  • D.Create a custom role that includes all possible permissions.
  • E.Review and remove unnecessary permissions periodically.

Why B: The principle of least privilege involves granting only necessary permissions and periodically reviewing them. Using a broad policy is the opposite. Removing the user is not appropriate. Creating a group is good for management but not directly for least privilege.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.