Courseiva
Operations and Support →hardMultiple Choice

CV0-004 Operations and Support Practice Question

A cloud administrator is troubleshooting a network connectivity issue between two subnets. They suspect a security group or NACL is blocking traffic. Which tool should they use to analyze the traffic flow?

⚠ Common exam trap

CV0-004 often tests the distinction between logging services, and candidates may confuse CloudTrail (API activity) with Flow Logs (network traffic).

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

VPC Flow Logs

VPC Flow Logs capture IP traffic information to and from network interfaces in a VPC. They can be used to analyze traffic flow and determine whether security groups or NACLs are blocking traffic by showing accepted and rejected traffic. This makes them the appropriate tool for troubleshooting connectivity issues between subnets.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    AWS X-Ray

    Why it's wrong here

    X-Ray traces application requests and latency, not packet flow between subnets, so it cannot show security group or NACL drops. It is tempting because X-Ray analyses request paths, and would be correct for diagnosing latency or errors inside a distributed application.

  • ✗

    AWS CloudTrail

    Why it's wrong here

    CloudTrail records API activity in the account, not network packets, so it cannot reveal whether a security group or NACL is dropping traffic. It is tempting because CloudTrail audits configuration changes, and would be correct for identifying who altered a rule or when.

  • ✗

    AWS Config

    Why it's wrong here

    AWS Config evaluates resource configuration compliance and records changes, but does not capture live traffic flow between subnets. It is tempting because Config tracks security group and NACL rule state, and would be correct for detecting drift or non-compliant rule configurations.

  • ✓

    VPC Flow Logs

    Why this is correct

    VPC Flow Logs capture accepted and rejected IP traffic metadata for elastic network interfaces, letting the administrator confirm whether a security group or NACL is dropping packets between the subnets. It records the actual allow or deny decision, which configuration review alone cannot prove.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.