mediumMultiple Select
CV0-004 Practice Question: Experiencing intermittent connectivity issues…
A company is experiencing intermittent connectivity issues between its on-premises data center and a public cloud environment over a VPN connection. Which TWO of the following should the administrator check to troubleshoot the problem?
⚠ Common exam trap
CompTIA often tests the misconception that intermittent VPN issues are always bandwidth-related, but the real culprit is usually routing misconfiguration or tunnel instability, which is why route validation and log/packet-loss analysis are the correct pair.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Validate the route tables on both sides of the VPN.
Option B is correct because intermittent VPN connectivity is frequently caused by asymmetric or missing routes, so validating the route tables on both the on-premises and cloud sides ensures traffic is being forwarded to the correct tunnel and subnet. Option E is correct because reviewing VPN logs and monitoring packet loss reveals tunnel renegotiation failures, IKE/IPsec errors, or dropped packets that directly explain intermittent connectivity. Options A, C, and D are not the best choices: bandwidth may affect performance but not intermittent drops, cloud storage performance is unrelated to VPN transport, and DNS resolution issues would typically cause name resolution failures rather than intermittent tunnel connectivity.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Verify that the internet bandwidth is sufficient.
Why it's wrong here
Sufficient internet bandwidth is a prerequisite for the VPN, but intermittent drops stem from tunnel, routing or MTU issues rather than raw capacity. It is tempting because bandwidth saturation degrades VPN throughput, and verifying it would be the correct choice when sustained congestion, not intermittent loss, is the reported symptom.
- ✓
Validate the route tables on both sides of the VPN.
Why this is correct
Route tables determine whether traffic from each subnet reaches the VPN gateway and the remote network. Asymmetric or missing routes cause packets to drop intermittently, matching the reported connectivity symptoms, so verifying both sides confirms path symmetry.
- ✗
Ensure the cloud storage performance is adequate.
Why it's wrong here
Storage performance does not affect VPN tunnel establishment or packet flow, so it cannot explain intermittent connectivity. It is tempting because storage latency and IOPS matter in cloud workloads, and checking them would be the correct choice when an application on cloud storage is slow rather than the VPN link itself.
- ✗
Check the DNS resolution of cloud endpoints.
Why it's wrong here
DNS resolution of cloud endpoints affects name lookups, not the VPN tunnel's data path, so it cannot cause intermittent tunnel drops. It is tempting because DNS failures do produce connectivity symptoms, and checking resolution would be the correct choice when on-premises clients cannot resolve cloud service hostnames.
- ✓
Review the VPN logs and monitor packet loss.
Why this is correct
VPN logs expose tunnel renegotiation, IKE failures and disconnects, while packet-loss monitoring reveals whether traffic degrades in transit. Together they pinpoint whether the intermittency originates in the tunnel itself rather than in routing or application layers.
Visual reference
Quick reference
VPN Protocol Comparison
| Protocol | Port | Encryption | Authentication | Use Case |
|---|---|---|---|---|
| IKEv2 / IPsec | UDP 500 / 4500 | AES-256 | Certificates / PSK | Site-to-site & remote access |
| SSL / TLS VPN | TCP 443 | TLS 1.3 | Certificates / MFA | Clientless remote access |
| L2TP / IPsec | UDP 1701 | AES (IPsec) | PSK / Certificates | Legacy remote access |
| WireGuard | UDP 51820 | ChaCha20 | Public keys | Modern high-performance VPN |
| PPTP | TCP 1723 | MPPE (weak) | MS-CHAPv2 | Legacy — avoid in production |
PPTP is considered insecure. IKEv2/IPsec and SSL VPN are the current recommended options.
Go deeper
Related to this question
About these practice questions
This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.