Courseiva
hardMultiple Select

CS0-003 Practice Question: A cloud workload identity begins accessing…

A cloud workload identity begins accessing secrets outside its normal application scope. Which evidence should be reviewed? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the distinction between 'what happened' (audit logs) and 'why it could happen' (policy changes), and the trap here is that candidates may overlook the policy change evidence because they focus only on the direct access logs, missing the root cause of the permission misconfiguration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Cloud audit logs for secret-read operations

Cloud audit logs record all API calls, including secret-read operations. If a workload identity is accessing secrets outside its normal scope, the audit logs will show the specific secret-read API calls (e.g., GetSecretValue in AWS Secrets Manager or accessSecretVersion in Google Cloud Secret Manager) made by that identity. Reviewing these logs directly confirms the anomalous access pattern and identifies which secrets were retrieved, providing the primary evidence of the breach.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Cloud audit logs for secret-read operations

    Why this is correct

    Cloud audit logs, specifically those tracking data plane operations like secret-read events, provide granular details on which secrets were accessed, by which identity, from what source IP, and at what timestamp. This direct evidence is crucial for identifying unauthorized secret access and understanding the scope of a potential compromise, directly addressing the scenario of a workload identity accessing secrets outside its expected scope.

  • ✗

    Legacy fax transmission logs

    Why it's wrong here

    Legacy fax transmission logs record metadata related to documents sent or received via traditional analog fax machines, detailing sender, recipient, and transmission status. These logs operate entirely outside modern cloud infrastructure and have no mechanism to track or provide insights into a cloud workload identity's access patterns or activities related to cloud-based secrets. Therefore, they are completely irrelevant for investigating cloud security incidents.

  • ✓

    Recent role assignment or policy changes for the workload identity

    Why this is correct

    Reviewing recent changes to the workload identity's assigned roles, IAM policies, or resource-based policies can reveal if new permissions were inadvertently or maliciously granted, enabling access to previously unauthorized secrets. Such changes, often recorded in control plane audit logs, directly explain *how* the workload gained the capability to access secrets outside its expected scope, even if the access itself is recorded elsewhere.

  • ✗

    The colour of the application logo

    Why it's wrong here

    The aesthetic design elements of an application, such as the color of its logo, are purely cosmetic branding choices. These visual attributes have absolutely no technical or operational bearing on the application's security posture, its underlying cloud infrastructure, or the permissions granted to its workload identity. Consequently, examining logo color provides zero actionable intelligence for investigating unauthorized secret access.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.