hardMultiple Select
CV0-004 Practice Question: A cloud operations team needs to implement a…
A cloud operations team needs to implement a monitoring solution for a microservices architecture. The solution must provide centralized logging, metrics, and alerting, and must be able to correlate data from multiple services. Which THREE of the following components should the team include?
⚠ Common exam trap
CompTIA often tests the distinction between specialized tools (SIEM, APM) and the core triad of centralized logging, metrics, and correlation/alerting, leading candidates to over-select security or tracing tools that do not fulfill the requirement for correlating data from multiple services at the log and metric level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A centralized logging system (e.g., ELK stack).
Option B is correct because a centralized logging system such as the ELK stack (Elasticsearch, Logstash, Kibana) aggregates logs from all microservices into one searchable store, which is essential for centralized logging and for correlating events across services. Option C is correct because a correlation engine and alerting system is what ties together logs and metrics from multiple services, detects patterns or thresholds, and generates alerts, directly satisfying the alerting and correlation requirements. Option D is correct because a metrics collection agent and dashboard such as Prometheus with Grafana provides time-series metrics collection, storage, and visualization, fulfilling the metrics and dashboarding needs of the monitoring solution. Option A is not required here because a SIEM focuses on security event management and compliance rather than general operational monitoring, metrics, and service correlation. Option E is not required because APM is a specialized tool for tracing application performance and, while useful, is not one of the three core components needed for centralized logging, metrics, and alerting in this scenario.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A security information and event management (SIEM) system.
Why it's wrong here
A SIEM correlates security events and generates threat alerts, but it does not aggregate application logs or service metrics for operational monitoring across microservices. It is tempting because SIEM genuinely centralises and correlates data, and would be correct if the requirement were security incident detection rather than operational observability.
- ✓
A centralized logging system (e.g., ELK stack).
Why this is correct
Centralised logging aggregates log streams from every microservice into one searchable store, satisfying the stem's centralised logging requirement. Without it, correlating events across services is impossible, since each container's logs remain isolated on its own host and are lost when instances are recycled.
- ✓
A correlation engine and alerting system (e.g., event correlation).
Why this is correct
The correlation engine consumes events from logging and metrics pipelines, applying rules to link related signals across services and trigger alerts. This directly satisfies the stem's alerting and multi-service correlation requirements, which raw log storage and dashboards alone cannot deliver.
- ✓
A metrics collection agent and dashboard (e.g., Prometheus+Grafana).
Why this is correct
Metrics collection agents scrape time-series data such as request rates and latency from each service, and the dashboard visualises them centrally. This satisfies the stem's metrics requirement, complementing logs by exposing quantitative trends needed to correlate behaviour across microservices.
- ✗
An application performance monitoring (APM) tool.
Why it's wrong here
APM tools trace application transactions and latency within instrumented services, but they do not provide the centralised log aggregation or cross-service log correlation the solution demands. They are tempting because APM genuinely covers metrics and alerting for service performance, and would be correct if distributed tracing alone were required.
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.