Courseiva
mediumMultiple Choice

CV0-004 Practice Question: A cloud administrator is troubleshooting an issue…

A cloud administrator is troubleshooting an issue where a user in the finance department cannot access a critical application hosted on a private cloud. The user can access other applications in the same subnet. The security team recently implemented a new network security policy. Which of the following is MOST likely causing the issue?

⚠ Common exam trap

It's easy for candidates to assume network-level issues (like VLAN misconfiguration) or account problems, but the key clue is that other applications in the same subnet are accessible, pointing to a host-based filter rather than a network-wide or authentication issue.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A host-based firewall rule is blocking the specific application port on the user's VM.

The user can access other applications in the same subnet, indicating network connectivity is intact, but a specific application is blocked. A host-based firewall rule on the user's VM (e.g., Windows Firewall or iptables) can filter traffic by port or protocol, and a newly implemented security policy likely added a rule blocking the port used by the critical application. This explains why only that application is inaccessible while others work.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user's VM is isolated from the subnet due to a misconfigured VLAN.

    Why it's wrong here

    VLAN isolation would sever all subnet connectivity, but the user still reaches other applications in that subnet, so the VLAN path is intact. A misconfigured VLAN is the correct diagnosis when a host cannot reach anything on its own segment.

  • ✗

    The user's account has been disabled due to a failed login attempt.

    Why it's wrong here

    A disabled account would block all authentication, yet the user reaches other applications in the same subnet, so credentials are valid. Disabling accounts is the right response to repeated failed logins, which is why it appears plausible here.

  • ✗

    The hypervisor is denying access to the application due to a resource quota violation.

    Why it's wrong here

    A hypervisor quota violation would degrade or stop the VM itself, yet the user reaches other applications, so the VM is running normally. Resource quotas are the right suspect when a workload is throttled or fails to start, not when one application is blocked.

  • ✓

    A host-based firewall rule is blocking the specific application port on the user's VM.

    Why this is correct

    Since the user reaches other applications in the same subnet, routing and network ACLs are functioning. A host-based firewall rule on the user's VM blocking the specific application port is the most likely cause of this single-application failure.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.