4.0 Security CV0-004 Practice Quiz
232 exam-style questions covering 19% of the CV0-004 exam. Instant feedback on every answer, progress tracking, no signup required.
This domain is part of the CompTIA Cloud+ practice test. Each question is tagged by exam objective and difficulty so you can drill exactly the areas you need.
Sample Questions
What does scanning scope define in a cloud vulnerability management program?
- A. The speed at which vulnerability scans must complete
- B. The boundaries of what is included in vulnerability scans, which cloud resources, networks, applications, and environments are assessed for vulnerabilities
- C. The number of security engineers required to review scan results
- D. The frequency at which vulnerability reports are shared with management
Scanning scope establishes the boundaries of vulnerability assessment, which assets, environments, IP ranges, applications, and cloud services are included or excluded from scans. Without defined scope, critical assets may be missed or scans may violate boundaries. This is the correct answer.
What does vulnerability identification involve in a cloud security program?
- A. Physically inspecting cloud hardware for defects
- B. Discovering and cataloging security weaknesses in cloud resources, including misconfigured services, unpatched software, weak credentials, and insecure network configurations, through automated scanning, manual review, and threat intelligence
- C. Identifying which engineers are responsible for each cloud resource
- D. Determining the monthly cost of each cloud service
Vulnerability identification discovers and catalogs security weaknesses, misconfigurations, outdated software, weak authentication, exposed services, creating the inventory of issues that must be assessed and remediated. This is the correct answer.
A security team runs vulnerability scans on their cloud environment but misses a critical internet-facing API gateway because it was not included in the scan scope. What scanning scope practice would MOST directly prevent this gap?
- A. Run scans more frequently to increase the chance of discovering missed assets
- B. Maintain a comprehensive cloud asset inventory (using cloud-native discovery tools or CSPM) and reconcile it against scan scope to ensure all internet-facing resources are included, particularly those accessible from outside the organization's perimeter
- C. Limit scanning to internal resources only to avoid disrupting external services
- D. Scan only the assets that appear in the CMDB without cloud asset discovery
Cloud asset discovery tools automatically enumerate all cloud resources including dynamically provisioned ones. Reconciling discovered assets against scan scope ensures internet-facing resources are never inadvertently excluded. This is the correct answer.
A cloud security team uses both authenticated and unauthenticated vulnerability scans. Which statement BEST explains why authenticated scanning provides more complete vulnerability identification?
- A. Authenticated scans run faster than unauthenticated scans
- B. Authenticated scans log into target systems with credentials, discovering installed software versions, configuration details, and local vulnerabilities that are only visible from inside the system. Unauthenticated scans only see externally exposed services, missing many internal vulnerabilities that authenticated scans detect
- C. Authenticated scans only check network-level vulnerabilities
- D. Unauthenticated scans provide more accurate results than authenticated scans
Authenticated scanning accesses the system internals with credentials, inspecting installed packages, running services, registry settings, and configuration files. This discovers vulnerabilities that are invisible from outside the system, providing significantly more complete identification. This is the correct answer.
A vulnerability scanner reports 500 vulnerabilities. 50 have CVSS scores above 9.0, 150 score 7.0-8.9, and 300 score below 7.0. A CVE with score 8.5 has a public exploit and affects an internet-facing payment processing server. How should assessment rank this vulnerability relative to others with higher CVSS scores but no public exploits?
- A. Always prioritize by CVSS score alone regardless of exploit availability or system criticality
- B. The CVE 8.5 with a public exploit on an internet-facing payment server should be prioritized above many 9.0+ vulnerabilities without public exploits, exploit availability and system criticality are critical contextual factors that can outweigh raw CVSS score in real-world risk prioritization
- C. CVSS score 8.5 is too low to prioritize before any score 9.0+ vulnerabilities
- D. Vulnerabilities on payment servers are automatically handled by PCI DSS and do not require manual assessment
Risk-based assessment factors in exploit availability (active exploitation possible immediately with public exploit), network exposure (internet-facing), and business impact (payment processing). These factors can elevate a lower CVSS score vulnerability above higher-score theoretical vulnerabilities with no known exploits. This is the correct answer.
A cloud team plans to conduct penetration testing against their production environment. Before beginning, they must define scanning scope. Which elements are MOST critical to include in the scope definition?
- A. Only the IP addresses of servers that have previously experienced incidents
- B. Specific IP ranges, domain names, cloud resource IDs, and services in scope; explicit exclusions (production databases to avoid data corruption, third-party services outside testing authority); testing windows; notification contacts; and cloud provider penetration testing authorization if required
- C. The names of engineers who will review the penetration test report
- D. The budget allocated for penetration testing services
Penetration test scope must precisely define included and excluded targets (to prevent unintended system disruption or testing of systems without authorization), testing windows (to coordinate with operations), notification contacts (for immediate response if critical issues found), and cloud provider authorization (major providers require pre-approval for penetration testing). This is the correct answer.
A vulnerability management program scans on-premises systems thoroughly but only scans cloud resources quarterly due to perceived complexity. A cloud-hosted application is compromised through an unscanned vulnerability. What scanning scope principle was violated?
- A. Cloud resources are inherently more secure than on-premises and require less frequent scanning
- B. Scanning frequency and coverage must be consistent across all environments, cloud resources face the same (or greater) threat exposure as on-premises due to internet accessibility, and must be included in the same continuous or frequent scanning cadence as traditional infrastructure
- C. Cloud providers are responsible for vulnerability scanning all customer cloud resources
- D. Quarterly scanning is sufficient for any environment that uses managed cloud services
Vulnerability scanning scope must treat cloud resources with the same rigor as on-premises, attackers do not distinguish between environments. Quarterly cloud scanning versus continuous on-premises scanning creates a systematic coverage gap that attackers exploit. This is the correct answer.
A CSPM (Cloud Security Posture Management) tool identifies 847 misconfigurations across a cloud environment. 312 are labeled as critical, 285 as high, 150 as medium, and 100 as low. A security analyst must decide how to approach identification reporting to leadership. Which identification reporting approach provides the MOST actionable intelligence?
- A. Report the total count of 847 misconfigurations without prioritization
- B. Present findings segmented by severity with business context, highlighting critical findings by affected business service, exploitation likelihood, and potential impact, rather than raw counts, enabling leadership to understand business risk and prioritize resource allocation accordingly
- C. Report only the 100 low-severity findings to avoid alarming leadership
- D. Wait until all 847 vulnerabilities are remediated before reporting anything
Severity-segmented reporting with business impact context transforms vulnerability identification data into actionable intelligence, leadership understands which vulnerabilities pose the greatest business risk and can prioritize remediation investment accordingly. This is the correct answer.
Link to this quiz
Studying with a group or teaching a class? Send this address or paste the link into your notes, wiki, or course page:
https://quizbuffet.com/comptia-cloud-plus/security/
<a href="https://quizbuffet.com/comptia-cloud-plus/security/">CompTIA Cloud+ Security practice quiz on QuizBuffet</a>
Other CV0-004 Domains
← Back to CV0-004 practice test overview
Questions are written against the published CV0-004 objectives and checked for accuracy and balance before they go live. How QuizBuffet writes and reviews its questions.