CV0-004 Troubleshooting Practice Question
A cloud administrator manages a three-tier application in a public cloud. Users report that API calls from the web tier to the database tier fail with connection timeouts, but the database tier responds normally when queried from a bastion host on the same subnet. The web tier instances reside in a different subnet. Which of the following is the MOST likely cause?
⚠ Common exam trap
The trap here is assuming that because the bastion can reach the database, the database is healthy and the problem must be in the web tier, when in fact source-scoped security group rules commonly differ by subnet.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The database's security group inbound rules do not allow traffic from the web tier's subnet CIDR range on the database port.
The bastion host succeeds from its own subnet while web tier instances in a separate subnet time out, which isolates the problem to source-based filtering rather than routing or the database engine itself. Security groups and network ACLs evaluate the source address, so a rule scoped to the bastion's range blocks the web tier. Allowing the web tier subnet CIDR on the database port restores connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The web tier instances are using an outdated database client library that cannot negotiate the TLS version required by the database.
Why it's wrong here
A TLS negotiation failure would surface as a handshake or certificate error after TCP connectivity is established, not as a connection timeout. The bastion host may use a different client, but the symptom described is a timeout, which points to packets being dropped before the TLS layer. Client library mismatches rarely manifest as silent timeouts across an entire subnet.
- ✓
The database's security group inbound rules do not allow traffic from the web tier's subnet CIDR range on the database port.
Why this is correct
Security groups are stateful and evaluated per source. Because the bastion host on the same subnet succeeds while web tier instances in a different subnet time out, the database's inbound rule likely scopes the permitted source to the bastion's subnet or IP rather than the web tier CIDR. Adding the web tier subnet on the correct database port resolves the timeout.
- ✗
The database engine's max_connections parameter is set too low for the incoming web tier connections.
Why it's wrong here
A connection limit would produce errors such as 'too many connections' or refused connections after the database accepts the TCP handshake, not silent network timeouts. Also, the bastion query succeeds, showing the engine is reachable. Connection exhaustion is a plausible but incorrect hypothesis because the symptom is a network-level timeout rather than a database-level rejection.
- ✗
The web tier's route table lacks a route to the database subnet's CIDR range.
Why it's wrong here
If the web tier had no route to the database subnet, the failure would typically be immediate and affect all destinations in that range, not just the database port. Since routing inside a VPC or virtual network is handled by the platform and the bastion reaches the database, the route is present. A missing route would also break traffic to any other host in that subnet.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.