CompTIA Cloud+ CV0-004 (V4) Practice Question

A cloud operations engineer receives a high-severity alert from the SIEM showing multiple failed and then successful root-level SSH logins to several Linux jump hosts at 03:15 local time, well outside normal maintenance hours. The organization's incident-response runbook states that any suspected compromise must be contained within 15 minutes while evidence is preserved for later investigation. Which immediate action BEST meets these requirements?

  • Disable multi-factor authentication on the jump hosts to simplify administrator access during investigation

  • Add the suspicious IP addresses to a temporary firewall deny list and start packet capture on the affected hosts

  • Snapshot the affected VMs and power them off to prevent further damage

  • Increase the SIEM threshold for failed logins to reduce alert noise while gathering more data

CompTIA Cloud+ CV0-004 (V4)
Operations
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $47
$390.00 $343.00
SAVE $53
CompTIA Cloud+ Voucher with Retake
v4 / CV0-004
Includes Retake
$439.00 $386.00
Bash, the Crucial Exams Chat Bot
AI Bot