CompTIA · Free Practice Questions · Last reviewed May 2026
30real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
A company is migrating a 50 TB on-premises database to AWS RDS MySQL. The migration must have minimal downtime and support ongoing replication during the cutover. The database schema is standard MySQL. Which combination of services should the company use?
AWS DMS with schema conversion tool to convert to MySQL
AWS Database Migration Service (DMS) with Change Data Capture (CDC) replication
DMS performs the initial full load while Change Data Capture continuously replicates ongoing inserts, updates and deletes from the source MySQL binlog, keeping the target in sync until cutover. This satisfies the minimal-downtime and ongoing-replication constraints for the 50 TB migration.
AWS Snowball Edge to transfer database dump, then import to RDS
AWS DataSync to transfer database files to S3, then restore to RDS
An organization uses CloudFormation to manage infrastructure across multiple AWS accounts. The team wants to deploy a common set of resources, such as VPCs and security groups, to all accounts in a consistent manner. Which CloudFormation feature should they use?
Change sets
Drift detection
StackSets
StackSets extend a single CloudFormation template across multiple AWS accounts and regions from one administrator account, provisioning identical VPCs and security groups consistently. This directly meets the stem's requirement to deploy a common resource set to all accounts without duplicating stacks manually.
Nested stacks
A cloud engineer is designing a deployment strategy for a web application that requires zero downtime. The engineer has set up two identical production environments, one active and one idle. After deploying the new version to the idle environment, the engineer switches the DNS record to point to the idle environment. This deployment method is known as:
Blue/green deployment
Blue/green deployment maintains two identical environments, routing traffic via DNS cutover from the active (blue) to the idle (green) once the new version is verified. This satisfies the zero-downtime constraint, since the switch is near-instantaneous and rollback simply reverts DNS to the original environment.
Rolling deployment
A/B testing deployment
Canary deployment
A team is developing a serverless application on AWS Lambda. The application uses several third-party libraries that are large in size. To reduce deployment package size and enable reuse across functions, the team wants to include these libraries as a separate layer. However, the total unzipped size of all layers exceeds the Lambda limits. What should the team do to resolve this?
Increase the Lambda function's reserved concurrency
Use a container image for the Lambda function instead of layers
Container images bypass the layer unzipped-size ceiling entirely, since Lambda permits images up to 10 GB. Packaging the large third-party libraries into the image satisfies the stem's constraint that combined layer size exceeds the limit, while still allowing reuse across functions via a shared image base.
Reduce the number of layers by combining libraries into fewer custom layers
Request a service limit increase from AWS for layer size
An organization is using Azure DevOps to implement a CI/CD pipeline. In which stage of the pipeline would automated unit tests typically be executed?
Deploy
Build
Automated unit tests run during the Build stage, immediately after compilation and before artefacts are published. Executing them here fails fast on broken code, satisfying the stem's CI/CD requirement by gating later Release and Deploy stages on passing tests.
Verify
Source
A company is migrating 100 TB of data from an on-premises NAS to Amazon S3. The network bandwidth is limited to 100 Mbps, and the transfer must complete within 30 days. Which service should the company use to meet the deadline?
AWS DataSync
Amazon S3 Transfer Acceleration
AWS Snowball
At 100 Mbps, transferring 100 TB would take roughly 100 days, far exceeding the 30-day deadline. AWS Snowball ships data physically on a rugged appliance, bypassing the bandwidth constraint entirely, so the migration completes within the required window.
AWS Direct Connect
Want more Deployment practice?
Practice this domain23% of exam · 6 sample questions below
A company wants to migrate its on-premises workload to the cloud and needs to maintain full control over the operating system, middleware, and applications. Which cloud service model should the company choose?
PaaS
FaaS
SaaS
IaaS
IaaS delivers raw compute, storage and networking while the customer retains control of the guest OS, middleware and applications. This satisfies the requirement for full control, unlike PaaS or SaaS, which abstract the operating system layer away from the customer.
Which cloud deployment model connects an on-premises data center to a public cloud using VPN or dedicated connections like AWS Direct Connect?
Private cloud
Multi-cloud
Hybrid cloud
Hybrid cloud joins on-premises infrastructure to a public cloud through VPN tunnels or dedicated private links such as AWS Direct Connect, keeping workloads split across both environments. That connectivity mechanism is exactly what the stem describes.
Public cloud
A cloud architect is designing a highly available web application. The application must remain available even if an entire AWS Availability Zone fails. The architect decides to deploy identical application instances in two separate Availability Zones and distribute traffic equally. Which architecture is being implemented?
Fault tolerance
Warm standby
Active-active
Active-active runs both Availability Zone instances concurrently, each serving traffic, so the loss of one zone leaves the other handling requests without failover delay. This satisfies the stem's requirement that the application remain available through a complete Availability Zone failure.
Active-passive
A company runs a stateless web application on virtual machines. To handle increased traffic, they add more virtual machines and distribute incoming requests among them. What is this scaling method called?
Right-sizing
Vertical scaling
Auto-scaling
Horizontal scaling
Horizontal scaling adds more VM instances to the pool and spreads requests across them, matching the stem's stateless web tier. Vertical scaling would instead resize a single existing VM, which cannot distribute load across multiple hosts.
A cloud engineer needs to store database backups that must be retained for seven years. The backups are rarely accessed. Which storage type is most cost-effective for this use case?
Object storage
Block storage
Archive storage
Archive storage offers the lowest per-gigabyte cost of Azure's blob tiers, designed for data retained for long periods and rarely accessed. It meets the seven-year retention requirement at minimal expense, unlike hot or cool tiers.
File storage
A company uses AWS and Azure for redundancy. They deploy the same application on both clouds to avoid vendor lock-in and improve disaster recovery. Which cloud deployment model is this?
Community cloud
Hybrid cloud
Private cloud
Multi-cloud
Multi-cloud means deliberately using two or more distinct public cloud providers, here AWS and Azure, for the same workload. This satisfies the redundancy, lock-in avoidance and disaster recovery constraints, unlike hybrid cloud, which pairs public cloud with private infrastructure.
Want more Cloud Architecture and Design practice?
Practice this domainA cloud engineer is configuring a web application on AWS and needs to ensure that only HTTP and HTTPS traffic from the internet is allowed to reach the EC2 instances. Which AWS service should be used to control inbound traffic at the instance level?
Security Group
Security groups are stateful virtual firewalls attached directly to EC2 elastic network interfaces, so rules are evaluated per instance rather than per subnet. Allowing only TCP ports 80 and 443 inbound satisfies the instance-level constraint, with return traffic automatically permitted regardless of outbound rules.
AWS Shield
AWS WAF
Network ACL
A company is migrating to a public cloud and wants to understand security responsibilities. According to the shared responsibility model, which of the following is the customer responsible for in an IaaS deployment?
Patching the guest operating system
In IaaS the provider secures the physical hosts, network and hypervisor, while the customer retains control of everything from the guest operating system upward. Patching the guest OS therefore remains the customer's responsibility, unlike PaaS or SaaS where the provider handles it.
Network infrastructure security
Physical security of data centers
Hypervisor security
A security administrator needs to enforce least privilege for a Kubernetes cluster in a cloud environment. Which approach should be used to restrict permissions for pods that need to access the cloud provider's API?
Assign the pod a static cloud IAM user credential
Disable cloud API access for all pods
Use a service account with a role that has only the required permissions
A Kubernetes service account mapped to a cloud role grants pods only the permissions that role defines, satisfying least privilege for API access. Unlike node-wide instance profiles, which expose every pod on that node to the same credentials, this binds permissions to the workload identity itself, so each pod receives solely its required scope.
Grant the pod cluster-admin privileges in Kubernetes
An organization is moving sensitive data to the cloud and must ensure it is encrypted while stored on disk. Which type of encryption should be implemented?
Encryption in transit
Encryption at rest
Encryption at rest protects data written to persistent storage, such as cloud disks and object stores, by encrypting it before it is saved. This directly satisfies the requirement that sensitive data remain encrypted while stored on disk.
Hashing
Tokenization
A cloud administrator needs to provide external partners with access to a cloud application using their existing corporate credentials. Which federation protocol should be used?
RADIUS
Kerberos
SAML
SAML exchanges signed assertions between the partner's identity provider and the cloud application, letting partners authenticate with existing corporate credentials. It is the established browser-based federation standard for external access, avoiding separate accounts for each partner.
LDAP
A company is using a SaaS application and wants to gain visibility into user activity and enforce data loss prevention policies. Which technology should be deployed?
Intrusion Detection System (IDS)
Web Application Firewall (WAF)
Cloud Access Security Broker (CASB)
A CASB sits between users and the SaaS provider, providing API and proxy-based visibility into user activity plus inline DLP enforcement. It satisfies the stem's SaaS visibility and policy requirement, unlike SWG or firewall approaches that cannot inspect sanctioned SaaS traffic.
Network Access Control (NAC)
Want more Security practice?
Practice this domain27% of exam · 6 sample questions below
A cloud engineer is setting up automated patching for Linux instances in AWS. They need to define a maintenance window during which patches are applied. Which service should they use?
AWS Config
AWS OpsWorks
AWS Systems Manager Patch Manager
AWS Systems Manager Patch Manager defines patch baselines and maintenance windows, then applies patches to Linux instances via the SSM Agent during those windows. It satisfies the stem's requirement for scheduled automated patching, unlike services lacking native patch orchestration or Linux package support.
Amazon Inspector
A cloud administrator is troubleshooting a network connectivity issue between two subnets. They suspect a security group or NACL is blocking traffic. Which tool should they use to analyze the traffic flow?
AWS X-Ray
AWS CloudTrail
AWS Config
VPC Flow Logs
VPC Flow Logs capture accepted and rejected IP traffic metadata for elastic network interfaces, letting the administrator confirm whether a security group or NACL is dropping packets between the subnets. It records the actual allow or deny decision, which configuration review alone cannot prove.
A cloud engineer needs to ensure that an auto-scaling group does not launch new instances immediately after a scale-in event to allow metrics to stabilize. Which feature should they configure?
Health checks
Scheduled scaling
Lifecycle hooks
Cooldown periods
Cooldown periods pause further scaling actions after a scale-in, letting metrics stabilise before the auto-scaling group launches replacement instances. This directly satisfies the stem's requirement to prevent immediate launches, as the cooldown timer blocks new scaling activity until it expires.
A company wants to reduce costs by identifying underutilized EC2 instances. Which tool should they use to get rightsizing recommendations?
AWS Cost Explorer
AWS Trusted Advisor
AWS Compute Optimizer
AWS Compute Optimizer analyses CloudWatch metrics to generate rightsizing recommendations for EC2 instances, identifying over-provisioned or underutilised capacity. This directly satisfies the company's cost-reduction goal by surfacing specific instance-type downsizing opportunities, unlike tools that only report utilisation data without actionable sizing guidance.
AWS Budgets
A cloud operations team is implementing structured logging for better querying. They have decided to use JSON format. What is a key benefit of structured logging over unstructured logging?
Easier to read for humans
Enables querying specific fields
JSON logging stores each attribute as a named key-value pair, so the logging platform parses and indexes individual fields. That lets operators filter and aggregate on specific fields, such as status or user ID, rather than grepping raw text lines.
Reduced storage costs
Faster log ingestion
A cloud architect is designing a disaster recovery plan that includes testing. Which TWO activities are commonly performed as part of DR testing?
Reserved Instance planning
Rightsizing recommendations
Chaos engineering
Chaos engineering deliberately injects failures such as instance termination or network latency to verify that failover and recovery actually work under realistic conditions. It validates DR readiness beyond documentation, exposing gaps in automation and dependencies that tabletop exercises alone cannot reveal.
Scheduled DR drills
Scheduled DR drills rehearse the failover and recovery runbook at planned intervals, measuring actual recovery time and recovery point against the defined objectives. They satisfy the testing requirement by proving that personnel, automation and dependencies function together during a real invocation.
Tagging resources
Want more Operations and Support practice?
Practice this domainA cloud administrator receives an alert that a virtual machine (VM) is unresponsive. The VM is hosted on a hypervisor that shows high CPU ready time. Which of the following is the most likely cause?
Insufficient memory allocated to the VM
Network latency between the VM and storage
Disk I/O contention from other VMs
Over-provisioning of vCPUs on the hypervisor
High CPU ready time means vCPUs wait in the hypervisor's run queue before receiving physical CPU cycles. Over-provisioning vCPUs across guests on the same host oversubscribes physical cores, so each VM waits longer, presenting as an unresponsive guest.
A cloud engineer notices that an application is running slower than expected. Monitoring shows that the CPU utilization is consistently below 30%, but memory usage is at 95%. Which of the following is the most likely cause of the performance issue?
Insufficient disk space for application logs
Insufficient memory causing swapping to disk
Insufficient memory forces the operating system to page data from RAM to disk, and that swapping introduces severe latency because disk access is orders of magnitude slower than memory. With memory at 95% while CPU sits below 30%, the bottleneck is memory pressure, not processing capacity, so adding RAM resolves the slowdown.
Network bandwidth saturation
CPU contention due to overprovisioning
A company is implementing a cloud governance strategy. They need to ensure that all resources are tagged with cost center and environment, and any untagged resources are automatically remediated. Which of the following best practices should be applied?
Implement role-based access control to restrict resource creation
Set up budget alerts to notify when costs exceed thresholds
Create a manual audit process to check tags weekly
Use policy-as-code to enforce tagging and automatically apply tags to untagged resources
Policy-as-code evaluates resource definitions against tagging rules and triggers automatic remediation, applying missing cost centre and environment tags. This enforces the governance requirement continuously rather than relying on manual audits, satisfying the automatic remediation constraint.
A cloud engineer is troubleshooting a VM that is experiencing high latency. The VM is hosted on a hypervisor with other VMs. Which TWO metrics should the engineer review to identify if resource contention is occurring?
Memory ballooning
Memory ballooning reveals host memory pressure: the hypervisor reclaims guest pages via the balloon driver, forcing the VM to swap and stall. Rising ballooning indicates the host is overcommitted on RAM, making it a direct contention signal alongside CPU ready time.
CPU ready time
CPU ready time measures how long a VM's vCPUs sat in the host run queue waiting for a physical core. Elevated values confirm CPU oversubscription on the hypervisor, directly explaining the latency the VM is experiencing.
Network packet drops
Swap usage
Disk queue length
A company is migrating on-premises workloads to the cloud. They need to ensure high availability for a stateless web application across two availability zones. Which THREE components should be configured to meet this requirement?
An auto scaling group spanning both availability zones
An auto scaling group spanning both availability zones maintains capacity when one zone fails, replacing unhealthy instances in the surviving zone. This directly satisfies the high-availability constraint for the stateless web tier, since no session state pins users to a single instance.
A load balancer in front of the web tier
A load balancer distributes incoming traffic across web instances in both availability zones, so the failure of one zone does not take the application offline. This directly satisfies the high-availability requirement for the stateless web tier, since no session state needs persisting and any healthy instance can serve any request.
A read replica database in a different AZ
A single large compute instance to handle all traffic
Multiple subnets, each in a different availability zone
Multiple subnets, each in a different availability zone, provide the fault-isolated network placement the stateless web tier requires. Distributing instances across these subnets ensures that the loss of one availability zone does not take down the application, satisfying the cross-zone high availability constraint.
A company runs a critical e-commerce application on a cloud platform. The architecture includes a load balancer in front of an auto scaling group of compute instances across two availability zones. The instances are in a private subnet and use a NAT gateway for outbound internet access. The application stores session data in a managed Redis cache cluster. During a flash sale, users report that the site is extremely slow and some requests time out. Monitoring shows the load balancer's latency metric is high, and the number of healthy hosts fluctuates. The CPU utilization on the compute instances averages 60% and memory averages 70%. The Redis cluster's CPU utilization is 90%, and its memory usage is 95%. The NAT gateway's metrics show high BytesOutToSource but no errors. Which of the following is the most likely cause of the performance issue?
The NAT gateway is throttling traffic due to bandwidth limits
The managed Redis cache cluster is overloaded and becoming a bottleneck for session lookups
Redis CPU at 90% and memory at 95% indicate the cache cluster is saturated, so session lookups slow or fail, cascading into high load balancer latency and fluctuating healthy hosts. This satisfies the observed bottleneck, since compute CPU and memory remain moderate.
The auto scaling group is not scaling quickly enough due to cooldown periods
The load balancer's idle timeout setting is too low, causing premature connection drops
Want more Troubleshooting practice?
Practice this domainThe CV0-004 exam has 90 questions and must be completed in 90 minutes. The passing score is 750/1000.
Scenario questions on cloud architecture, deployment, security, operations, and troubleshooting across major cloud platforms. Some questions are performance-based (PBQs), asking you to complete tasks in a simulated environment.
The exam covers 5 domains: Deployment, Cloud Architecture and Design, Security, Operations and Support, Troubleshooting. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official CompTIA CV0-004 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.