Courseiva
hardMultiple ChoiceObjective-mapped

CV0-004 Practice Question: A company uses a public cloud provider and has a…

A company uses a public cloud provider and has a requirement that all data must be encrypted in transit and at rest. The architect notices that the cloud provider's load balancer terminates TLS and forwards traffic to backend instances over HTTP. Which design change should the architect make?

⚠ Common exam trap

Many candidates assume TLS termination at the load balancer is sufficient for encryption in transit, overlooking that the requirement applies to the entire data path, including the segment between the load balancer and backend instances.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Configure end-to-end encryption using HTTPS between load balancer and backend

The requirement mandates encryption in transit for all data paths. By configuring end-to-end HTTPS between the load balancer and backend instances, the architect ensures that traffic is encrypted from the client to the backend, even after the load balancer terminates the initial TLS connection. This prevents plaintext HTTP traffic from flowing over the internal network, satisfying the encryption-at-rest and in-transit compliance needs.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement a web application firewall (WAF) on the backend

    Why it's wrong here

    WAF provides security but does not encrypt traffic; it inspects packets.

  • Enable TLS termination at the backend instances only

    Why it's wrong here

    That would not change the load balancer configuration; traffic to load balancer still terminates TLS.

  • Use a VPN tunnel between the load balancer and backend

    Why it's wrong here

    A VPN tunnel between the load balancer and backend encrypts traffic only across the tunnel link, but the load balancer still terminates TLS and forwards decrypted HTTP to the backend instances. This fails the requirement that data must be encrypted at rest on the backend instances themselves, as the tunnel does not enforce encryption on the stored data. It is tempting because a VPN correctly protects data in transit over a network segment, and would be the right choice if the requirement were solely to encrypt traffic between two specific network endpoints.

  • Configure end-to-end encryption using HTTPS between load balancer and backend

    Why this is correct

    This ensures traffic is encrypted all the way from client to backend instance.

About these practice questions

Courseiva writes every CV0-004 question from scratch — 977 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.