CV0-004 Deployment Practice Question
A cloud administrator is deploying a new virtual machine in a public cloud. The administrator needs to ensure that the VM can be accessed remotely for management purposes. The security group associated with the VM currently allows only outbound traffic. Which inbound rule should be added to allow SSH access from the administrator's corporate network?
⚠ Common exam trap
Test-takers frequently confuse SSH with RDP or using the wrong protocol; SSH is TCP port 22, not 3389 or UDP.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Allow inbound TCP port 22 from the corporate network's CIDR block.
SSH access requires an inbound rule allowing TCP port 22 from the administrator's network. This ensures that only trusted sources can connect, reducing the attack surface. Port 3389 is for RDP, UDP 22 is not used by SSH, and port 443 is for HTTPS. Therefore, the rule allowing TCP 22 from the corporate CIDR is the correct choice for secure remote management.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Allow inbound TCP port 443 from the corporate network's CIDR block.
Why it's wrong here
Port 443 is used for HTTPS, which is for secure web traffic. It does not provide SSH access. Allowing port 443 would not enable remote management via SSH. While HTTPS is important for web applications, it is not relevant to the administrator's need to manage the VM via SSH. The correct port is 22.
- ✗
Allow inbound UDP port 22 from the corporate network's CIDR block.
Why it's wrong here
SSH operates over TCP, not UDP. Allowing UDP port 22 would not permit SSH connections. While some protocols use UDP, SSH requires a reliable, connection-oriented transport provided by TCP. Therefore, this rule would be ineffective. The administrator must specify TCP as the protocol for SSH access.
- ✗
Allow inbound TCP port 3389 from the corporate network's CIDR block.
Why it's wrong here
Port 3389 is used by Remote Desktop Protocol (RDP) for Windows instances. The scenario specifies SSH, which is typically used for Linux instances. Allowing RDP would not enable SSH access and could introduce unnecessary exposure if the VM is Linux. The correct port for SSH is 22, not 3389. Therefore, this rule would not achieve the goal.
- ✓
Allow inbound TCP port 22 from the corporate network's CIDR block.
Why this is correct
SSH uses TCP port 22 by default. To allow remote management, an inbound rule permitting TCP port 22 from the specific corporate network CIDR is necessary. This restricts access to known IP addresses, enhancing security. Without this rule, the VM would be unreachable via SSH, preventing management. This is a fundamental step in securing remote access to cloud instances.
Visual reference
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.