CV0-004 Troubleshooting Practice Question
A company uses a cloud-based load balancer to distribute traffic to web servers. Recently, a new security policy was applied that restricts traffic to certain geographic regions. Users from an allowed region report they cannot access the website. The load balancer status shows health checks are passing. What should the administrator check?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The load balancer's access control lists (ACLs)
Geographic restrictions on a load balancer are typically implemented via access control lists (ACLs). Since health checks are passing, the web servers are functional, so the issue lies in the load balancer's ACLs blocking traffic from the allowed region. Option A is wrong: DNS resolution would affect all users similarly, not just those from a specific region. Option B is wrong: SSL certificate issues would generate browser warnings or errors, not complete inaccessibility. Option C is wrong: web server logs are irrelevant as the traffic is not reaching the servers due to the ACL block.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The DNS resolution for the website
Why it's wrong here
DNS resolution determines which address clients reach; since health checks pass, the load balancer already resolves and reaches the servers, so DNS does not explain region-blocked users. It is tempting because DNS faults cause widespread access failures, and would be correct if the hostname resolved incorrectly or not at all.
- ✗
The SSL certificate expiration
Why it's wrong here
Certificate expiry would break TLS for all users, not only those in one permitted region, and health checks would typically still pass. It is tempting because expired certificates commonly cause HTTPS failures, and checking them is valid when every client reports browser trust warnings.
- ✗
The web server logs for application errors
Why it's wrong here
Application errors would affect all users regardless of geography, and the geo-restriction policy was applied immediately before the outage. Server logs are the right place to look when a single application function misbehaves while network and health checks remain normal.
- ✓
The load balancer's access control lists (ACLs)
Why this is correct
Geographic restrictions are enforced through load balancer ACLs, which filter client source IP ranges independently of backend health. Since health checks pass, the backend is fine; the ACL is the layer silently dropping traffic from the supposedly allowed region.
Visual reference
Go deeper
Related to this question
About these practice questions
One of 834 original CV0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.