CV0-004 Troubleshooting Practice Question
A cloud engineer is troubleshooting an issue where users cannot connect to a web application hosted on a cloud VM. The VM's security group allows HTTP (port 80) from 0.0.0.0/0, and the VM's OS firewall is disabled. The engineer can ping the VM's public IP from the internet. What is the most likely cause of the issue?
⚠ Common exam trap
Candidates often assume a ping success implies all services are reachable, but ICMP (ping) operates at the network layer (Layer 3) and does not test TCP port availability, so a running web server is required for HTTP connectivity.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Web server service is not running on the VM
Since the OS firewall is disabled and the security group allows HTTP from 0.0.0.0/0, the only remaining layer that could block connectivity is the application itself. If the web server service (e.g., Apache, Nginx, IIS) is not running on the VM, it will not listen on TCP port 80, so HTTP requests will be refused even though network-level access is permitted. The ability to ping the VM confirms IP-level reachability, isolating the issue to the application layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
OS firewall is blocking port 80
Why it's wrong here
The stem explicitly states the VM's OS firewall is disabled, so it cannot be dropping port 80 traffic. It is tempting because host firewalls commonly block web ports after misconfiguration, and would be the answer if the firewall were enabled and lacked an inbound HTTP allow rule.
- ✗
Incorrect routing table on the VM
Why it's wrong here
The VM's own routing table governs its outbound traffic, not inbound connections reaching its public IP; ping already succeeded, proving inbound reachability. It is tempting because routing errors do break connectivity, but they would typically affect the VM's egress or traffic between subnets rather than inbound HTTP.
- ✗
Security group rule is applied to the wrong subnet
Why it's wrong here
Security groups attach to network interfaces or instances, not subnets; subnet-level filtering is handled by network ACLs. The stem already confirms the group permits port 80 from anywhere, so misapplied subnet scope cannot explain the block. It is tempting because network ACLs and security groups are both stateful-looking filters, but ACLs are the subnet-scoped control.
- ✓
Web server service is not running on the VM
Why this is correct
Ping succeeding proves the network path, security group rule and routing are functional, so the fault lies above layer 3. A stopped or crashed web server process means nothing listens on port 80, producing connection refusals despite reachable IP connectivity.
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.