Comptia

CV0-004 Free Practice Questions — Page 7

Question 31

A company just learned that the data in its object storage was accessed by an unauthorized party. Which of the following should the company have done to make the data unusable?

A. The company should have switched from object storage to file storage.
B. The company should have hashed the data.
C. The company should have changed the file access permissions.
D. The company should have encrypted the data at rest.
Show Answer
Correct Answer: D
Explanation:
Encrypting data at rest ensures that even if an unauthorized party gains access to the storage, the data remains unreadable without the encryption keys. Changing storage type or permissions does not protect already-accessed data, and hashing is generally for passwords or integrity checks, not for making stored data retrievable yet unusable.

Question 31

Which of the following would a customer most likely be accountable for in a shared responsibility model?

A. Security of data in the data centers
B. Security in the cloud
C. Security of the application
D. Security of the cloud
Show Answer
Correct Answer: B
Explanation:
In the shared responsibility model, the cloud provider secures the cloud (physical data centers, hardware, and underlying infrastructure), while the customer is responsible for security in the cloud. This includes configurations, identities, data, operating systems, and applications they deploy. Therefore, the most accurate choice is security in the cloud, not security of the cloud or data centers.

Question 32

Which of the following provides secure, private communication between cloud environments without provisioning additional hardware or appliances?

A. VPN
B. VPC peering
C. BGP
D. Transit gateway
Show Answer
Correct Answer: B
Explanation:
VPC peering provides direct, private IP connectivity between cloud environments over the provider’s internal network without requiring additional hardware, appliances, or tunnels. VPN requires gateways, BGP is a routing protocol, and a transit gateway is a managed hub service but goes beyond simple direct communication implied by the question.

Question 32

An organization decides to migrate its software source code framework to microservices. Which of the following correctly describes this new approach?

A. Public cloud-managed services
B. Tightly coupled architecture
C. Private cloud-managed services
D. Loosely coupled architecture
Show Answer
Correct Answer: D
Explanation:
Microservices architecture decomposes an application into small, independent services that can be developed, deployed, and scaled separately. This independence minimizes direct dependencies between services, which is the definition of a loosely coupled architecture. The other options describe deployment models (public/private cloud) or the opposite architectural style (tightly coupled).

Question 33

A customer relationship management application, which is hosted in a public cloud IaaS network, is vulnerable to a remote command execution vulnerability. Which of the following is the best solution for the security engineer to implement to prevent the application from being exploited by basic attacks?

A. IPS
B. ACL
C. DLP
D. WAF
Show Answer
Correct Answer: D
Explanation:
The vulnerability is a remote command execution issue in a web-based CRM hosted in public cloud IaaS. Basic exploitation attempts occur at the application (HTTP/HTTPS) layer. A Web Application Firewall (WAF) is specifically designed to inspect and filter web traffic and block common web attacks such as remote command execution, SQL injection, and XSS. IPS is more general and network/protocol focused, ACLs only control network access, and DLP focuses on preventing data exfiltration rather than blocking exploitation. Therefore, WAF is the best solution.

Question 33

A cloud service provider just launched a new serverless service that is compliant with all security regulations. A company deployed its code using the service, and the company’s application was hacked due to leaked credentials. Which of the following is responsible?

A. Customer
B. Cloud service provider
C. Hacker
D. Code repository
Show Answer
Correct Answer: A
Explanation:
Under the shared responsibility model, the cloud provider secures the underlying infrastructure and compliance of the service, while the customer is responsible for security in the cloud, including application code and credential management. Since the breach was due to leaked credentials in the deployed code, responsibility lies with the customer.

Question 34

A cloud engineer is provisioning a new application that requires access to the organization’s public cloud resources. Which of the following is the best way for the cloud engineer to authenticate the application?

A. API key
B. Cookie
C. MFA
D. Username and password
Show Answer
Correct Answer: A
Explanation:
The scenario describes an application (not a human) needing programmatic access to public cloud resources. API keys are designed for non-interactive, application-to-cloud authentication and can be scoped, rotated, and revoked. Cookies are for web sessions, MFA applies to human users, and usernames/passwords are insecure and inappropriate for automated applications.

Question 34

Which of the following technologies can read the contents of a printed memo?

A. Document scanning
B. Sentiment analysis
C. Text recognition
D. Natural language processing
Show Answer
Correct Answer: C
Explanation:
Reading the contents of a printed memo requires converting visual characters into machine-readable text, which is done by text recognition (optical character recognition). The other options analyze text after it is already digitized or serve different purposes.

Question 35

A company experienced a data leak through its website. A security engineer, who is investigating the issue, runs a vulnerability scan against the website and receives the following output: Which of the following is the most likely cause of this leak?

A. RTMP port open
B. SQL injection
C. Privilege escalation
D. Insecure protocol
Show Answer
Correct Answer: D
Explanation:
The most likely cause is use of an insecure protocol (e.g., FTP). FTP transmits credentials and data in cleartext, which can be captured by an attacker via network sniffing or MITM, leading directly to a data leak from the website. The other options do not inherently explain passive leakage of data without additional exploitation details.

Question 35

A public cloud environment customer wants to encrypt the data it puts in the cloud. However, the CSP prohibits customer encryption keys. Which of the following principles is the CSP violating?

A. Data ownership
B. Data sovereignty
C. Data classification
D. Data retention
Show Answer
Correct Answer: A
Explanation:
If the CSP prohibits customer-managed encryption keys, the customer cannot exercise full control over access to their own data. Control of encryption keys is a core mechanism by which a data owner enforces confidentiality and access rights. By retaining exclusive control of the keys, the CSP undermines the customer’s ability to control, access, or restrict use of the data, which violates the principle of data ownership. The other options (sovereignty, classification, retention) do not directly address control over encryption keys.

$19

Get all 179 questions with detailed answers and explanations

  • Instant download HTML + PDF delivered the moment payment clears.
  • Secure Stripe checkout we never see or store your card details.
  • 7-day refund if files are defective see our refund policy.