CompTIA · Free Practice Questions · Last reviewed May 2026
24real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
An administrator needs to ensure that cloud resources are geographically separated to maintain availability during a regional disaster. Which feature should they configure?
Availability Zone replication
Load Balancer
Multi-Region deployment
This ensures regional fault tolerance.
Auto Scaling Group
An organization needs to extend its on-premises data center to a VPC while ensuring private connectivity that avoids the public internet. Which connectivity option is best?
Site-to-Site VPN
Client VPN
Direct Connect
This is a private, dedicated network link.
Public IP peering
A startup is looking for a cloud deployment model where they pay only for resources used and share underlying hardware with other tenants. What model is this?
Public Cloud
Public cloud is multi-tenant and consumption-based.
Hybrid Cloud
Community Cloud
Private Cloud
You are troubleshooting a connectivity issue where an application in a private subnet cannot reach the internet to download updates. Which component is missing?
Internet Gateway
NAT Gateway
NAT allows private instances to access the internet.
VPC Endpoint
Route Table
A company is moving from a capital expenditure model to an operational expenditure model. What is the primary benefit?
Increased control over hardware
Removal of upfront capital costs
OpEx removes the need for hardware procurement capital.
Predictable monthly billing
No hardware maintenance
A developer needs to host a static website on AWS S3. Which configuration is required to make the objects publicly accessible?
Enable Static Website Hosting
This allows S3 to serve content as a website.
Configure a NAT Gateway
Attach an Elastic IP
Create an EC2 instance
Want more Cloud Concepts practice?
Practice this domainYou are managing a multi-cloud environment using Terraform. You need to ensure that the infrastructure state is locked to prevent concurrent modifications during CI/CD pipeline runs. Which backend component should you implement to achieve state locking?
DynamoDB table
DynamoDB is the required service for state locking when using S3 as a Terraform backend.
S3 Versioning
Terraform Cloud Workspaces
IAM Policy
A system administrator needs to automatically replace unhealthy EC2 instances in an AWS Auto Scaling group. Which component must be configured?
CloudWatch Alarms
Elastic Load Balancer
IAM Role
Auto Scaling Health Checks
Auto Scaling monitors instance health and replaces those that fail checks.
A cloud administrator is tasked with reducing idle resource costs in AWS. Which tool should be configured to provide specific rightsizing recommendations for EC2 instances based on historical utilization data?
AWS Cost Explorer
AWS Trusted Advisor
AWS Budgets
AWS Compute Optimizer
Compute Optimizer is the specific service designed for rightsizing recommendations.
A developer needs to monitor real-time CPU utilization across a fleet of virtual machines in Azure. Which service should be used to capture and visualize these metrics?
Azure Advisor
Azure Monitor
Azure Monitor provides the infrastructure to collect and visualize VM metrics.
Azure Policy
Azure Resource Graph
An organization is migrating to a hybrid cloud model. They require a dedicated, private connection between their on-premises data center and the cloud provider to reduce latency. Which service should be provisioned?
Direct Connect
Direct Connect establishes a private, physical connection from the data center to the cloud.
Software-Defined Networking
Content Delivery Network
Site-to-Site VPN
Which cloud operation task is primarily responsible for ensuring that the cloud environment adheres to corporate security and regulatory standards?
Cost optimization
Load balancing
Compliance management
Compliance management specifically manages regulatory and policy adherence.
Capacity planning
Want more Management And Technical Operations practice?
Practice this domainAn enterprise is deploying a hybrid cloud model and must ensure that data moving between the on-premises data center and the cloud provider is encrypted. Which mechanism is most appropriate?
VPC Peering
IGW (Internet Gateway)
Direct Connect
Site-to-Site VPN
Site-to-Site VPN creates an encrypted IPsec tunnel for secure hybrid traffic.
A security analyst notices unauthorized changes to cloud infrastructure. Which service should be analyzed to identify which IAM user made the changes?
AWS IAM Access Analyzer
AWS CloudWatch
AWS CloudTrail
CloudTrail logs every API request made in the AWS account.
AWS Security Hub
To ensure that all virtual machines in a cloud environment comply with corporate security standards (e.g., specific OS versions), which tool should be used to enforce configuration policies automatically?
Azure Backup
Azure Policy
Azure Policy is designed to enforce rules and effects over resources to ensure compliance.
Azure Resource Manager templates
Azure Monitor
A project manager is reviewing cloud resource usage to ensure compliance with a budget governance policy. Which cloud service dashboard provides the most direct view of current resource costs and budget alerts?
AWS Cost Explorer
Cost Explorer allows for detailed visualization and budget monitoring.
AWS Trusted Advisor
AWS CloudTrail
AWS Config
A company is migrating sensitive financial data to AWS and needs to ensure that all data is encrypted at rest using customer-managed keys. Which service should the administrator configure to manage these keys while maintaining audit logs for compliance?
AWS Secrets Manager
AWS CloudHSM
AWS Key Management Service (KMS)
KMS allows for the creation and management of customer-managed keys with integrated auditing.
AWS Certificate Manager (ACM)
An organization is subject to GDPR and needs to ensure that personal data stored in an Azure SQL Database is protected against unauthorized access. Which feature should be enabled to identify potential vulnerabilities and anomalies?
Azure Information Protection
Azure AD Conditional Access
Azure Firewall
Azure SQL Advanced Data Security
This feature includes vulnerability assessments and threat detection specific to database security.
Want more Governance Risk Compliance And Security practice?
Practice this domainWhen performing a TCO analysis for migrating a legacy on-premises database to Azure SQL, which hidden cost is most likely to be overlooked?
Power and cooling
Data egress fees
Egress fees for transferring data out of the cloud provider to on-premises systems are often underestimated.
Software licensing
Hardware maintenance
Which cloud service model would best suit a company that needs complete control over the network configuration and operating system but wants to avoid physical server maintenance?
PaaS
SaaS
IaaS
IaaS offers the most flexibility for network and OS control while abstracting physical hardware.
Serverless
A healthcare company must comply with HIPAA. When selecting a cloud provider, which document provides the best assurance of compliance?
Vendor marketing brochure
SOC 2 Type II report
SOC 2 reports provide independent assurance regarding security, availability, and processing integrity.
Service Level Agreement (SLA)
Public pricing catalog
A project manager is calculating the cloud adoption strategy using a 'Re-platform' approach. What is the expected outcome?
Moving VMs without any changes
Replacing the application with a third-party service
Optimize application performance by migrating to managed services
Re-platforming allows for leveraging managed services like RDS or Azure SQL while maintaining the original application architecture.
Complete rewrite of the application code
An organization wants to use AWS Cost Explorer to identify cost-saving opportunities. Which filter should the administrator apply to find idle resources?
API Activity Log
Usage Type Group
Usage Type Group allows you to aggregate costs for specific service components to identify idle or underutilized instances.
Service Quotas
Resource Tagging
A cloud architect is choosing between IaaS and SaaS for a new CRM system. What is the primary business advantage of selecting SaaS?
Lower initial implementation cost
Full control over the operating system
Reduced administrative overhead
SaaS provides a managed application environment where the vendor handles updates and security patching.
Customizable hardware configuration
Want more Business Principles OF Cloud Environments practice?
Practice this domainThe CLO-002 exam has 200 questions and must be completed in 120 minutes. The passing score is 700/1000.
Multiple-choice and performance-based questions covering IT security, networking, and operations. Some questions are performance-based (PBQs), asking you to complete tasks in a simulated environment.
The exam covers 4 domains: Cloud Concepts, Management And Technical Operations, Governance Risk Compliance And Security, Business Principles OF Cloud Environments. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official CompTIA CLO-002 exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.