hardMultiple Select
CS0-003 Practice Question: A cloud workload identity begins accessing…
A cloud workload identity begins accessing secrets outside its normal application scope. Which evidence should be reviewed? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the distinction between 'what happened' (audit logs) and 'why it could happen' (policy changes), and the trap here is that candidates may overlook the policy change evidence because they focus only on the direct access logs, missing the root cause of the permission misconfiguration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Cloud audit logs for secret-read operations
Cloud audit logs record all API calls, including secret-read operations. If a workload identity is accessing secrets outside its normal scope, the audit logs will show the specific secret-read API calls (e.g., GetSecretValue in AWS Secrets Manager or accessSecretVersion in Google Cloud Secret Manager) made by that identity. Reviewing these logs directly confirms the anomalous access pattern and identifies which secrets were retrieved, providing the primary evidence of the breach.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Cloud audit logs for secret-read operations
Why this is correct
Cloud audit logs, specifically those tracking data plane operations like secret-read events, provide granular details on which secrets were accessed, by which identity, from what source IP, and at what timestamp. This direct evidence is crucial for identifying unauthorized secret access and understanding the scope of a potential compromise, directly addressing the scenario of a workload identity accessing secrets outside its expected scope.
- ✗
Legacy fax transmission logs
Why it's wrong here
Legacy fax transmission logs record metadata related to documents sent or received via traditional analog fax machines, detailing sender, recipient, and transmission status. These logs operate entirely outside modern cloud infrastructure and have no mechanism to track or provide insights into a cloud workload identity's access patterns or activities related to cloud-based secrets. Therefore, they are completely irrelevant for investigating cloud security incidents.
- ✓
Recent role assignment or policy changes for the workload identity
Why this is correct
Reviewing recent changes to the workload identity's assigned roles, IAM policies, or resource-based policies can reveal if new permissions were inadvertently or maliciously granted, enabling access to previously unauthorized secrets. Such changes, often recorded in control plane audit logs, directly explain *how* the workload gained the capability to access secrets outside its expected scope, even if the access itself is recorded elsewhere.
- ✗
The colour of the application logo
Why it's wrong here
The aesthetic design elements of an application, such as the color of its logo, are purely cosmetic branding choices. These visual attributes have absolutely no technical or operational bearing on the application's security posture, its underlying cloud infrastructure, or the permissions granted to its workload identity. Consequently, examining logo color provides zero actionable intelligence for investigating unauthorized secret access.
Go deeper
Related to this question
Learn chapter
Identity-Based Attack Patterns: Pass-the-Hash, Kerberoasting
Key term
Cloud Audit Logs
Cloud Audit Logs are a record of actions taken by users, services, and resources inside a cloud environment, capturing who did what, when, and from where.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.