Courseiva
hardMultiple Select

CS0-003 Practice Question: A cloud security posture tool reports public…

A cloud security posture tool reports public access on object storage. Which follow-up checks matter? (Choose two.)

⚠ Common exam trap

The trap here is that candidates often focus on the misconfiguration itself (public access) rather than the necessary forensic step of verifying actual data exposure, leading them to pick irrelevant options like account name length or UI settings.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Whether sensitive objects were accessed or downloaded

The primary concern with public access to object storage is data exposure. Checking whether sensitive objects were accessed or downloaded determines if a breach actually occurred, which is a critical follow-up step in vulnerability management. Without this check, you cannot assess the real-world impact of the misconfiguration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Whether the storage account name is short

    Why it's wrong here

    The length or specific naming convention of a storage account provides no inherent security or protection against public exposure. Public access is determined by explicit access control lists (ACLs), bucket policies, or account-level settings, not by the arbitrary string used for identification. A short name does not make an object more or less vulnerable to misconfiguration, as security relies on proper policy enforcement.

  • ✓

    Whether sensitive objects were accessed or downloaded

    Why this is correct

    Once a Cloud Security Posture Management (CSPM) tool identifies potential public access, determining whether sensitive objects were actually accessed or downloaded is critical for incident response and impact assessment. This moves beyond a misconfiguration alert to evidence of potential data exfiltration or unauthorized access, directly informing the severity of the incident and necessary remediation steps. It helps quantify the actual damage and regulatory reporting requirements.

  • ✗

    Whether the administrator uses dark mode

    Why it's wrong here

    An administrator's personal user interface preferences, such as enabling dark mode, are purely aesthetic and have no bearing on the underlying security posture or public accessibility of cloud resources. Security configurations are managed through specific IAM policies, bucket policies, and network access controls, which operate independently of how the console is visually rendered. UI settings do not influence effective permissions or resource exposure.

  • ✓

    Whether public access is effectively allowed by bucket and account policies

    Why this is correct

    Understanding whether public access is *effectively* allowed requires evaluating the cumulative effect of all applicable policies, including bucket policies, IAM user/role policies, and organizational service control policies. A CSPM tool must analyze these layers to determine the true permissions, as a seemingly private bucket might still be publicly accessible due to an overly permissive IAM policy or a misconfigured ACL. This comprehensive evaluation reveals the actual security posture.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.