Courseiva

CV0-004 Cloud Architecture and Design Practice Question

A financial services firm runs a latency-sensitive trading application in a public cloud. The security team requires that traffic between the application tier and the database tier never traverse the public internet, that both tiers reside in the same virtual network, and that access to the database be restricted to specific application subnet addresses. Which combination of cloud networking controls should the architect implement?

⚠ Common exam trap

The trap here is assuming that encryption via a VPN makes traffic private, when it still traverses the public internet and adds latency.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Place both tiers in the same virtual network and attach a network security group rule to the database subnet allowing only the application subnet CIDR.

Hosting both tiers in a single virtual network guarantees east-west traffic remains on the provider's private network, and a network security group scoped to the database subnet that allows only the application subnet CIDR enforces least-privilege access. Together these controls satisfy the private-path and restricted-access mandates without introducing internet routing or unnecessary tunnel overhead.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Place the tiers in separate virtual networks and connect them with a site-to-site VPN tunnel over the internet.

    Why it's wrong here

    A site-to-site VPN encrypts traffic but still carries it across the public internet, which the security team explicitly forbids for this latency-sensitive application. Separate virtual networks also add encryption and tunneling overhead that increases latency. Although the tunnel restricts access somewhat, it violates the requirement that traffic never traverse the public internet.

  • ✗

    Assign public IP addresses to the database nodes and use a host-based firewall to allow only the application servers.

    Why it's wrong here

    Public IP addresses expose the database tier to internet-routable paths and broaden the attack surface, contradicting the mandate that database traffic stay off the public internet. A host-based firewall filters traffic but does not change the fact that packets are routable from the internet. This approach fails the primary private-path requirement regardless of filtering.

  • ✗

    Put both tiers in the same virtual network and rely on the default allow-all rules provided by the cloud platform.

    Why it's wrong here

    Placing tiers in one virtual network does keep traffic private, but default allow-all rules permit any workload in the network to reach the database, violating the requirement to restrict access to specific application subnet addresses. Least privilege demands an explicit rule limiting database access to the application subnet CIDR rather than trusting platform defaults.

  • ✓

    Place both tiers in the same virtual network and attach a network security group rule to the database subnet allowing only the application subnet CIDR.

    Why this is correct

    Keeping both tiers in one virtual network means traffic stays on the provider's private backbone and never crosses the public internet. A network security group or firewall rule scoped to the database subnet that permits only the application subnet's CIDR enforces least-privilege access at the subnet boundary, satisfying both the private-path and restricted-access requirements.

Visual reference

192.168.1.0 /24 256 addresses (254 usable) 192.168.1.0 /25 Subnet A 128 addr (126 usable) 192.168.1.128 /25 Subnet B 128 addr (126 usable) Borrowing 1 bit from host portion creates 2 subnets (/25)

About these practice questions

This CV0-004 question is part of Courseiva's 834-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CV0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CV0-004 exam.