Courseiva
Troubleshooting →easyMultiple Choice

CV0-004 Troubleshooting Practice Question

A cloud user is unable to connect to a web server VM from the internet after a security group rule was modified. The VM is running and can be pinged from other VMs in the same subnet. What is the most likely cause?

⚠ Common exam trap

CV0-004 often tests the confusion between security group rules and network ACLs, or between local firewall and cloud firewall; candidates may overlook that successful pings indicate the issue is specific to the port/protocol, not general connectivity.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The inbound rule for HTTP/HTTPS was removed or misconfigured.

The most likely cause is that the inbound security group rule for HTTP/HTTPS was removed or misconfigured, as security groups act as virtual firewalls controlling traffic to the VM. Since the VM can be pinged from other VMs in the same subnet, the network path and VM's OS are functional, isolating the issue to the security group's inbound rules. Modifying the security group likely removed the rule allowing HTTP/HTTPS traffic from the internet.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The VM's local firewall is blocking the traffic.

    Why it's wrong here

    A local firewall would also block internal traffic.

  • ✗

    The VM's routing table is missing a default gateway.

    Why it's wrong here

    Internal connectivity implies routing is functional.

  • ✓

    The inbound rule for HTTP/HTTPS was removed or misconfigured.

    Why this is correct

    Intra-subnet pings succeeding proves the VM, OS and network path are healthy, isolating the fault to the security group. Modifying that group most likely removed or misconfigured the inbound HTTP/HTTPS rule, blocking internet clients while internal traffic continues.

  • ✗

    The VM's DNS settings are incorrect.

    Why it's wrong here

    DNS settings control name resolution, not network-layer connectivity; the user’s inability to reach the VM from the internet persists even if DNS is misconfigured, because the security group rule blocks the traffic at the packet level regardless of hostname lookup. This option is tempting because incorrect DNS often prevents users from reaching a resource by name, and in a scenario where the VM is unreachable by FQDN but reachable by IP, DNS would be the correct diagnosis.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.