Courseiva
easyMultiple Select

CV0-004 Practice Question: Which TWO of the following are best practices for…

Which TWO of the following are best practices for managing cloud storage in a multi-account environment? (Choose two.)

⚠ Common exam trap

CV0-004 often tests the confusion between security best practices and operational convenience, so candidates may choose a single bucket or public access for simplicity, or think separate encryption keys are mandatory.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Implement bucket policies to restrict cross-account access.

Option A is correct because implementing bucket policies (e.g., S3 bucket policies or equivalent resource-based policies) lets you explicitly define which accounts, principals, or roles may access a bucket, thereby restricting unintended cross-account access in a multi-account environment. Option C is correct because enabling logging and monitoring of all storage operations (such as S3 server access logging, CloudTrail data events, or equivalent audit logs) provides the visibility needed to detect unauthorized access, verify compliance, and troubleshoot issues across accounts. Option B is not a recognized best practice in the same sense, since key management should follow a deliberate strategy (e.g., KMS key policies, centralized vs. per-account keys) rather than simply mandating separate keys per account. Option D is wrong because a single shared bucket for all accounts undermines isolation, least privilege, and blast-radius containment. Option E is wrong because full public access violates security best practices and risks data exposure.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Implement bucket policies to restrict cross-account access.

    Why this is correct

    Bucket policies are resource-based controls attached directly to the storage bucket, letting you define which external account principals may access it and under what conditions. In a multi-account environment, this satisfies the constraint of preventing unintended cross-account access, since identity-based policies in the owning account alone cannot govern requests originating from other accounts.

  • ✗

    Use separate encryption keys for each account.

    Why it's wrong here

    Separate keys per account is a sound isolation practise, but the question asks for storage management best practices; per-account keys alone do not address lifecycle, access, or cost governance across accounts. It would be correct where regulatory isolation mandates distinct key custody per tenant.

  • ✓

    Enable logging and monitoring of all storage operations.

    Why this is correct

    Enabling logging and monitoring of all storage operations provides the audit trail and anomaly detection that a multi-account environment demands, where activity is scattered across many accounts and cannot be reviewed centrally by default. This directly satisfies the stem's multi-account constraint, since per-account visibility is essential before any cross-account aggregation or alerting can occur.

  • ✗

    Use a single storage bucket/container for all accounts to simplify management.

    Why it's wrong here

    A single shared bucket across accounts collapses the isolation boundary, letting one account's misconfiguration or credential compromise expose every account's objects. Consolidated buckets suit single-account or tightly coupled workloads where centralised management outweighs blast-radius concerns.

  • ✗

    Allow full public access to ensure availability.

    Why it's wrong here

    Full public access removes the access-control layer entirely, exposing stored objects to anyone and breaching least-privilege expectations for multi-account storage. Public access is only appropriate for deliberately published static content, such as a website's public assets, not general account data.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.