Courseiva
TroubleshootingeasyMultiple ChoiceObjective-mapped

CV0-004 Troubleshooting Practice Question

A cloud user is unable to connect to a web server VM from the internet after a security group rule was modified. The VM is running and can be pinged from other VMs in the same subnet. What is the most likely cause?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

The inbound rule for HTTP/HTTPS was removed or misconfigured.

Modifying a security group rule likely removed or misconfigured the inbound HTTP/HTTPS rule, blocking internet traffic to the web server. The VM is accessible from other VMs in the same subnet (via private IP), indicating the OS and local services are running, but internet connectivity is controlled by the security group. Option A (local firewall) is unlikely because internal ping works. Option B (missing default gateway) would affect all outbound and inbound traffic. Option D (DNS) affects name resolution, not direct IP connectivity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • The VM's local firewall is blocking the traffic.

    Why it's wrong here

    A local firewall would also block internal traffic.

  • The VM's routing table is missing a default gateway.

    Why it's wrong here

    Internal connectivity implies routing is functional.

  • The inbound rule for HTTP/HTTPS was removed or misconfigured.

    Why this is correct

    Security groups control inbound traffic; missing rule blocks internet access.

  • The VM's DNS settings are incorrect.

    Why it's wrong here

    DNS settings control name resolution, not network-layer connectivity; the user’s inability to reach the VM from the internet persists even if DNS is misconfigured, because the security group rule blocks the traffic at the packet level regardless of hostname lookup. This option is tempting because incorrect DNS often prevents users from reaching a resource by name, and in a scenario where the VM is unreachable by FQDN but reachable by IP, DNS would be the correct diagnosis.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 977 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.