Courseiva
Troubleshooting →easyMultiple Choice

CV0-004 Troubleshooting Practice Question

A cloud administrator is troubleshooting a newly deployed web application on a cloud VM. Users cannot access the application via its public IP address, but the administrator can SSH into the VM and access the application locally using curl http://localhost:8080. The VM's security group allows inbound traffic on port 22 and port 80. The application is listening on port 8080. Which of the following is the MOST likely cause of the issue?

⚠ Common exam trap

The trap here is assuming that because local access works, the application is correctly configured, and overlooking that the security group only permits specific ports.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The security group does not allow inbound traffic on port 8080.

The security group allows inbound traffic only on ports 22 and 80, but the application listens on port 8080. External users cannot reach port 8080 because the security group blocks it. Local access via localhost:8080 works because it does not traverse the security group. To resolve the issue, the administrator should either add an inbound rule for port 8080 or reconfigure the application to listen on port 80.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The application is configured to use HTTPS instead of HTTP.

    Why it's wrong here

    If the application were using HTTPS, local curl to http://localhost:8080 would likely fail or return an error, but the administrator successfully accessed it via HTTP. Moreover, the security group allows port 80, not 443, so even if the application used HTTPS on 8080, the security group would still block external access. The issue is not the protocol but the port and security group rules.

  • ✗

    The application is bound to the loopback interface instead of all interfaces.

    Why it's wrong here

    If the application were bound only to 127.0.0.1, local curl would work, but external access would fail even if the security group allowed port 8080. However, the security group does not allow port 8080, so even if the application were bound to all interfaces, external access would still be blocked. The security group restriction is a more fundamental issue; binding is a possible cause but is secondary. The question asks for the most likely cause given the security group configuration.

  • ✓

    The security group does not allow inbound traffic on port 8080.

    Why this is correct

    The security group allows inbound traffic on ports 22 and 80, but the application is listening on port 8080. Since users are trying to access the application via its public IP, they are likely using a URL without specifying port 8080 (e.g., http://public-ip), which defaults to port 80. However, even if they specified port 8080, the security group would block it because only ports 22 and 80 are allowed. The local curl to localhost:8080 works because it bypasses the security group. Thus, the security group is the most likely cause.

  • ✗

    The VM's operating system firewall is blocking port 8080.

    Why it's wrong here

    If the OS firewall were blocking port 8080, the local curl to localhost:8080 would also fail, because the firewall would filter traffic on the loopback interface as well (depending on configuration, but typically it would). Since local access works, the OS firewall is not blocking the port. The issue is more likely at the cloud security group level, which only affects external traffic.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

Courseiva writes every CV0-004 question from scratch — 834 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.