Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 1–75

834 questions total · 12pages · All types, answers revealed

Page 1 of 12

Page 2
1
MCQmedium

A company uses a cloud-based load balancer to distribute traffic to web servers. Recently, a new security policy was applied that restricts traffic to certain geographic regions. Users from an allowed region report they cannot access the website. The load balancer status shows health checks are passing. What should the administrator check?

A.The DNS resolution for the website
B.The SSL certificate expiration
C.The web server logs for application errors
D.The load balancer's access control lists (ACLs)
AnswerD

Geographic restrictions are enforced through load balancer ACLs, which filter client source IP ranges independently of backend health. Since health checks pass, the backend is fine; the ACL is the layer silently dropping traffic from the supposedly allowed region.

Why this answer

Geographic restrictions on a load balancer are typically implemented via access control lists (ACLs). Since health checks are passing, the web servers are functional, so the issue lies in the load balancer's ACLs blocking traffic from the allowed region. Option A is wrong: DNS resolution would affect all users similarly, not just those from a specific region.

Option B is wrong: SSL certificate issues would generate browser warnings or errors, not complete inaccessibility. Option C is wrong: web server logs are irrelevant as the traffic is not reaching the servers due to the ACL block.

2
MCQmedium

A cloud administrator is configuring a web application hosted on a public cloud VM. The application must be accessible over HTTPS, and the administrator needs to ensure that all traffic between the client and the server is encrypted. The cloud provider offers a managed certificate service. Which of the following is the BEST practice for securing the application?

A.Use the cloud provider's managed certificate service to provision and attach the certificate to the load balancer.
B.Generate a self-signed certificate and configure the web server to use it.
C.Disable HTTPS and rely on network-level encryption provided by the cloud provider.
D.Create a certificate signing request (CSR) and submit it to a public CA, then install the certificate and private key on the VM.
AnswerA

A managed certificate attached to the load balancer terminates TLS at the provider's edge, encrypting client-to-server traffic without exposing private keys on the VM. This satisfies the HTTPS encryption requirement while automating renewal and reducing operational overhead.

Why this answer

The cloud provider's managed certificate service automatically handles certificate provisioning, renewal, and attachment to the load balancer, ensuring HTTPS traffic is encrypted with a trusted certificate from a public CA. This is the best practice because it offloads TLS termination to the load balancer, reducing the VM's CPU overhead and centralizing certificate management. It also ensures the certificate is automatically renewed before expiry, preventing service disruptions.

Exam trap

The trap here is that candidates may think manually installing a certificate from a public CA (Option D) is more secure or gives more control, but the cloud provider's managed service is the best practice because it automates lifecycle management and offloads TLS termination to the load balancer, reducing attack surface and operational burden.

How to eliminate wrong answers

Option B is wrong because a self-signed certificate is not trusted by client browsers, causing security warnings and breaking the trust model required for public HTTPS. Option C is wrong because disabling HTTPS removes application-layer encryption, leaving traffic vulnerable to interception even if network-level encryption (like IPsec) is used, as it does not protect against man-in-the-middle attacks at the application layer. Option D is wrong because manually installing a certificate and private key on the VM increases management overhead, risks exposing the private key, and does not leverage the cloud provider's automated renewal and load balancer integration.

3
MCQeasy

A company is migrating its on-premises database to a cloud-managed database service. The database contains sensitive financial data. Which of the following is the MOST important security configuration to implement after migration?

A.Enable encryption at rest using a customer-managed key
B.Configure automated patching schedule
C.Enable public read access for monitoring tools
D.Set up cross-region replication for high availability
AnswerA

Customer-managed keys in the cloud-managed service let the company retain control over the key lifecycle, satisfying the sensitive financial data requirement. Unlike provider-managed keys, revocation or rotation remains under the organisation's governance, so the cloud provider cannot independently decrypt stored data. This directly addresses the compliance constraint for regulated financial records.

Why this answer

Enabling encryption at rest with a customer-managed key is the most important security configuration for sensitive financial data in a cloud-managed database, because it protects data confidentiality even if the underlying storage is compromised and gives the organization control over key lifecycle and access. Customer-managed keys (via KMS or equivalent) allow granular access policies, rotation, and revocation, which are critical for regulatory compliance such as PCI DSS. This directly addresses the protection of data at rest, the primary security concern after migration.

Exam trap

CV0-004 often tests the distinction between confidentiality controls (encryption with customer-managed keys) and availability/operational controls (patching, replication), luring candidates toward operational answers when the question asks for the most important security configuration for sensitive data.

How to eliminate wrong answers

Option B is wrong because automated patching, while important for vulnerability management, addresses software flaws rather than protecting the confidentiality of data at rest and is not the most critical control for sensitive financial data. Option C is wrong because enabling public read access for monitoring tools is a severe security anti-pattern that exposes sensitive financial data to unauthorized parties and violates virtually every compliance framework. Option D is wrong because cross-region replication improves availability and disaster recovery, not confidentiality; it may even expand the attack surface and complicate data residency compliance.

4
MCQeasy

A company is migrating a legacy application to the cloud. The application uses a relational database and requires strong consistency and ACID transactions. Which cloud service model is most appropriate?

A.Infrastructure as a Service (IaaS) with self-managed database servers.
B.Function as a Service (FaaS) with a serverless database.
C.Software as a Service (SaaS) with a built-in database.
D.Platform as a Service (PaaS) with a managed relational database.
AnswerD

PaaS with a managed relational database provides a platform that handles infrastructure management while supporting relational databases with ACID compliance and strong consistency. This allows the company to focus on the application while ensuring the database meets its transactional requirements, making it the most appropriate model.

Why this answer

PaaS with a managed relational database is ideal because it provides a platform for the application while the managed database ensures ACID compliance and strong consistency. The company benefits from reduced operational overhead and can focus on the application, aligning with the migration goals.

Exam trap

The trap here is assuming that IaaS with self-managed databases is necessary for ACID compliance, when in fact managed PaaS databases also provide strong consistency and transactional support.

5
MCQmedium

A cloud architect is designing a solution that requires a shared, POSIX-compliant file system that can be mounted concurrently by hundreds of Linux EC2 instances across multiple Availability Zones in the same AWS Region. The workload is read-heavy, and the file system must scale storage capacity automatically as data grows. Which AWS service should the architect choose?

A.AWS Storage Gateway in File Gateway mode
B.Amazon Elastic Block Store (Amazon EBS) with Multi-Attach enabled
C.Amazon FSx for Windows File Server
D.Amazon Elastic File System (Amazon EFS)
AnswerD

Amazon EFS is a fully managed, elastic NFS file system that supports the POSIX interface and can be mounted concurrently by thousands of EC2 instances across multiple Availability Zones within a Region. It automatically scales storage capacity up and down as files are added or removed, making it ideal for read-heavy shared workloads that require cross-AZ access.

Why this answer

Amazon EFS is the correct choice because it is a managed NFS file system that supports POSIX semantics, can be mounted by many Linux instances simultaneously across multiple Availability Zones, and elastically scales storage capacity. The other services either provide block storage, Windows-oriented SMB file storage, or hybrid gateway functionality that does not meet the cross-AZ shared file system requirement.

Exam trap

The trap here is assuming that Amazon EBS Multi-Attach provides a shared file system for multiple instances across Availability Zones, when it actually only supports block-level attachment within a single Availability Zone.

6
Multi-Selecthard

Which THREE are common reasons why a cloud database instance may become unreachable?

Select 3 answers
A.Firewall rules blocking the database port
B.Incorrect connection string in the application
C.Storage volume is full on the database server
D.Database service not started
E.Hypervisor maintenance causing VM reboot
AnswersA, B, D

Security groups and network ACLs act as stateful or stateless packet filters; if the database listener port (for example 3306 or 5432) is not permitted inbound from the client subnet, connection attempts time out even though the instance itself is healthy and running.

Why this answer

Option A is correct because a cloud database instance listens on a specific port (e.g., 3306 for MySQL, 5432 for PostgreSQL, 1433 for SQL Server), and security group or firewall rules that fail to allow inbound traffic on that port will make the instance unreachable even though it is running. Option B is correct because an incorrect connection string—wrong hostname/endpoint, port, database name, or credentials—prevents the application from establishing a TCP session to the database, which is one of the most common causes of apparent unreachability. Option D is correct because if the database service/daemon (e.g., mysqld, postgresql, sqlservr) is not started or has crashed, the instance will refuse connections on its listening port.

Option C is not a typical cause of unreachability; a full storage volume usually causes write failures, errors, or degraded performance rather than making the instance completely unreachable. Option E is not a common reason either, since hypervisor maintenance typically triggers live migration or a planned reboot, and even if a VM reboots, the database would normally come back online automatically rather than remain unreachable.

Exam trap

CV0-004 often tests the distinction between 'unreachable' and 'slow' or 'failing writes'; candidates may choose storage full or hypervisor maintenance because they sound like availability issues, but the question specifically asks for reasons the instance cannot be reached at all.

7
Multi-Selectmedium

A cloud administrator is configuring cost management for a multi-account cloud environment. The company wants to allocate costs by department and project. Which TWO steps should the administrator take to achieve this? (Choose two.)

Select 2 answers
A.Enable the cloud provider's cost reporting tools
B.Create separate cloud accounts for each department
C.Activate cost allocation tags in the billing console
D.Use the cloud provider's budgeting tools to set spending limits
E.Apply tags to resources such as Department and Project
AnswersC, E

Activating cost allocation tags in the billing console makes tagged resources' spend visible as separate line items in cost reports, satisfying the requirement to allocate costs by department and project. Without activation, tags exist on resources but are excluded from billing data, so departmental and project breakdowns cannot be produced.

Why this answer

Option C is correct because activating cost allocation tags in the billing console is the required step that makes user-defined tags (such as Department and Project) appear as line items in the cost and usage reports, enabling cost breakdowns by those dimensions. Option E is correct because applying consistent tags like Department and Project to resources is what actually associates each resource's spend with the desired cost center, and without these tags the allocation data cannot be produced. Together, tagging resources and then activating those tags for billing is the standard mechanism for allocating costs by department and project in a multi-account environment.

Option A is not one of the two required steps because enabling cost reporting tools alone provides raw billing data but does not by itself map costs to departments and projects. Option B is unnecessary because separate accounts per department are an isolation/consolidation design choice, not the tagging mechanism needed for cost allocation. Option D is incorrect because budgeting tools set thresholds and alerts on spend; they do not allocate or attribute costs to departments and projects.

Exam trap

The trap is thinking that creating separate accounts or enabling reporting alone achieves allocation, when the exam requires both tag activation and actual tagging of resources.

8
MCQmedium

A cloud engineer is troubleshooting a connectivity issue between two virtual networks in different regions. The engineer has verified that the virtual networks are peered and the routing tables are correct. Which of the following is the MOST likely cause of the issue?

A.Incorrect route tables on the virtual network gateway
B.A physical cable disconnection in the datacenter
C.A network security group blocking the traffic
D.Incorrect DNS resolution
AnswerC

Network security groups filter traffic at the subnet or NIC level independently of peering and routing, so a deny rule silently drops packets even when connectivity paths are correct. Inspecting NSG rules on both virtual networks is therefore the most likely explanation for the blocked cross-region traffic.

Why this answer

Network security groups (NSGs) operate at the subnet or NIC level and can filter traffic between peered virtual networks even when routing is correctly configured. Since the engineer has verified peering and routing tables, the most likely remaining cause is an NSG rule explicitly or implicitly denying the traffic, as NSGs are stateful and evaluated after routing decisions.

Exam trap

The trap here is that candidates often overlook NSGs and jump to routing or gateway issues, but in a peered VNet scenario with correct routing, NSGs are the primary layer-4 filter that can silently drop traffic.

How to eliminate wrong answers

Option A is wrong because virtual network gateways are used for VPN or ExpressRoute connections, not for VNet peering; VNet peering uses the Azure backbone without a gateway, so incorrect route tables on a gateway are irrelevant. Option B is wrong because physical cable disconnections in a datacenter are abstracted away by the cloud provider's software-defined networking; the engineer has no access to physical infrastructure, and such issues would manifest as broader outages, not isolated inter-VNet connectivity. Option D is wrong because DNS resolution affects name-to-IP mapping, not IP-level connectivity; if the engineer can ping or test connectivity via IP address, DNS is not the bottleneck.

9
MCQeasy

Which of the following is a stateless network access control that requires explicit allow rules for both inbound and outbound traffic?

A.Security group
B.Network ACL
C.DDoS protection
D.Web application firewall
AnswerB

NACLs are stateless and require rules for both directions.

Why this answer

Network ACLs (NACLs) are stateless; security groups are stateful.

10
MCQhard

A cloud operations team is investigating suspicious activity in a production subscription. Logs show that a service principal authenticated successfully from an unexpected country and then enumerated storage accounts. The team needs to shorten the window in which a stolen credential remains usable and receive an alert when anomalous sign-ins occur. Which combination of controls should the team prioritize?

A.Shorten the credential lifetime for the service principal and configure risk-based sign-in alerting that triggers on anomalous locations.
B.Grant the service principal contributor rights at the subscription scope and enable multi-factor authentication for all interactive users.
C.Increase the password length for the service principal and enable verbose application logging on the storage accounts.
D.Rotate the service principal secret annually and rely on monthly manual review of stored sign-in logs to identify anomalies.
AnswerA

Reducing the credential lifetime limits how long a stolen secret remains valid, directly shrinking the exposure window. Risk-based sign-in detection flags authentications from atypical locations or impossible travel and can alert or block in near real time, addressing the unexpected-country enumeration. Together these controls target both the duration of exposure and timely detection of the anomaly.

Why this answer

Reducing credential lifetime is the most direct way to bound how long a stolen service principal secret can be abused, since every token issued from it expires on a short schedule. Risk-based sign-in alerting detects unusual locations and impossible travel, delivering the timely notification the team needs. Together they address both the exposure window and the detection gap revealed by the incident.

Exam trap

The trap here is thinking that stronger passwords or broader permissions improve security for a non-interactive service principal, when credential lifetime and anomaly detection are the real levers.

11
MCQmedium

A cloud administrator needs to audit all API calls made in a GCP project for compliance purposes. Which service should be enabled to log these actions?

A.GCP Cloud Audit Logs
B.Azure Monitor
C.GCP Security Command Center
D.AWS CloudTrail
AnswerA

Cloud Audit Logs records Admin Activity, Data Access and System Event entries for every API call in the project, giving the compliance audit trail required. Enabling it satisfies the stem's need to capture all API actions, since these logs are generated automatically per project, folder and organisation.

Why this answer

GCP Cloud Audit Logs is the correct service because it records all API calls and administrative actions in a GCP project, including Admin Activity, Data Access, System Event, and Policy Denied logs. Enabling and exporting these logs to a SIEM or log bucket satisfies the compliance audit requirement for API call visibility.

Exam trap

CV0-004 often tests multi-cloud service recognition, causing candidates to pick a service from the wrong cloud provider (Azure Monitor, AWS CloudTrail) or a security posture tool (SCC) instead of the actual audit logging service.

How to eliminate wrong answers

Option B is wrong because Azure Monitor is a Microsoft Azure service and does not audit GCP API calls. Option C is wrong because Security Command Center is a security posture and threat detection service — it consumes audit logs but is not the logging service that records API calls. Option D is wrong because AWS CloudTrail is the AWS equivalent and does not log GCP activity.

12
MCQeasy

A cloud engineer is implementing a tagging strategy for cost allocation. Which tags should be applied to resources to track costs by business unit and environment?

A.BusinessUnit and Environment
B.Owner and Department
C.Project and Application
D.Location and Region
AnswerA

BusinessUnit and Environment map spend to the two required dimensions: which part of the organisation owns the resource and whether it runs in production or non-production. These tags enable cost allocation reporting by both business unit and environment.

Why this answer

BusinessUnit and Environment are the two dimensions explicitly required to track costs by business unit and environment, so tagging resources with these keys directly enables cost allocation reports filtered on those values. Cloud providers' cost explorers and billing dashboards group spend by tag key/value, making these the correct tag pair.

Exam trap

The trap here is confusing organizational cost dimensions (business unit, environment) with other common tag keys like Owner, Project, or Region, which are useful but do not satisfy the stated allocation requirement.

How to eliminate wrong answers

Option B is wrong because Owner and Department do not map to the requested business unit and environment dimensions; Department is a different organizational axis and Owner is an individual, not a cost center. Option C is wrong because Project and Application track workload or product, not business unit or environment. Option D is wrong because Location and Region are geographic/physical attributes, not the organizational and lifecycle dimensions requested.

13
MCQmedium

A cloud architect is designing a stateless containerized workload that must remain available even if an entire data center fails. The workload has no persistent local state and must be able to scale horizontally across regions. Which design decision BEST meets these requirements?

A.Deploy the containers on a single large virtual machine with a snapshot-based backup taken every hour.
B.Deploy identical container clusters in two or more regions and use a global load balancer with health checks to route traffic to healthy regions.
C.Deploy the containers in a single region across multiple availability zones and rely on the orchestrator to reschedule failed tasks.
D.Deploy the containers in one region and configure a DNS failover record that points to a cold standby environment in another region.
AnswerB

This directly satisfies the requirement to survive a full data center failure. A global load balancer continuously probes regional endpoints and redirects user traffic to a healthy region when one fails. Because the workload is stateless and horizontally scalable, identical clusters can run in parallel without data synchronization concerns, providing both high availability and geographic redundancy.

Why this answer

The workload is stateless, so it can be replicated across regions without data consistency concerns. Running identical clusters in multiple regions behind a global load balancer with health checks ensures that traffic is automatically redirected away from a failed region, meeting the requirement to survive a full data center failure. This design also supports horizontal scaling by adding capacity in any region.

Exam trap

The trap here is assuming that multi-AZ deployment within a single region is sufficient for data center failure, when a regional outage requires a multi-region design.

14
Drag & Dropmedium

Arrange the steps to implement a cloud security group that allows only specific IPs to access an application.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The correct sequence ensures that the security group is properly configured with the known allowed IPs before being attached to the resource, and then tested. Identifying IPs first prevents misconfiguration, and setting the source within the rule during creation ensures the rule is complete before association.

15
MCQmedium

An organization uses AWS CloudFormation to deploy resources across multiple AWS accounts. They need to manage a common set of resources in several accounts from a single template. Which CloudFormation feature should they use?

A.Change sets
B.Nested stacks
C.Drift Detection
D.StackSets
AnswerD

StackSets deploy a single CloudFormation template across multiple AWS accounts and regions from one administration account, satisfying the requirement to manage common resources in several accounts centrally. Stack policies, change sets, and nested stacks operate within one account, so they cannot span accounts.

Why this answer

StackSets allow deploying stacks across multiple accounts and regions. Change sets show changes before execution; Drift Detection detects configuration drift; Nested stacks are for reusability within a single account.

16
Multi-Selecthard

A company is deploying a new application on AWS and needs to ensure that the infrastructure is defined as code. The team wants to use AWS CloudFormation to provision resources. They require that the template can be reused across multiple environments (dev, test, prod) with different configurations, such as instance types and subnet IDs. The team also needs to ensure that changes to the infrastructure are applied in a controlled manner. Which two features should the team use to meet these requirements? (Choose two.)

Select 2 answers
A.Use CloudFormation drift detection to identify resources that have been modified outside of CloudFormation.
B.Use CloudFormation parameters to pass environment-specific values into the template.
C.Use CloudFormation stack policies to prevent updates to specific resources.
D.Use CloudFormation change sets to preview how proposed changes will impact running resources before executing them.
E.Use CloudFormation nested stacks to modularize the template into smaller, reusable components.
AnswersB, D

CloudFormation parameters allow you to input custom values when creating or updating a stack, such as instance types, key pairs, and subnet IDs. This enables template reuse across environments without modifying the template itself. Parameters can have default values, allowed values, and descriptions, making them ideal for environment-specific configurations. This directly addresses the requirement for different configurations per environment.

Why this answer

Parameters enable the same CloudFormation template to be used across multiple environments by supplying different values at stack creation or update time. Change sets allow you to preview the effects of updates before applying them, ensuring controlled changes. Together, they satisfy the need for reusable templates with environment-specific configurations and safe, controlled updates.

The other features address different concerns such as modularity, resource protection, and drift detection.

Exam trap

The trap here is confusing features that improve template organization or safety with those that directly enable environment-specific customization and controlled change preview.

17
MCQhard

A company runs a stateless web application on auto-scaling EC2 instances behind an Application Load Balancer. The application experiences sudden traffic spikes. Which scaling approach will handle the spikes most efficiently while minimizing cost?

A.Horizontal scaling with auto-scaling based on CPU utilization
B.Vertical scaling of existing instances
C.Using reserved instances for all capacity
D.Pre-provisioning a large number of instances
AnswerA

Horizontal scaling adds EC2 instances, and CPU-based auto-scaling triggers new capacity only when load rises, then removes it afterwards. This matches spiky, stateless traffic efficiently and keeps cost low, unlike vertical scaling or always-on over-provisioning.

Why this answer

Horizontal scaling (adding instances) combined with auto-scaling based on metrics is best for handling spikes cost-effectively in a stateless app.

18
Multi-Selecteasy

Which TWO of the following are best practices for securing access to a cloud management console?

Select 2 answers
A.Use complex passwords and rotate them every 30 days
B.Restrict access based on IP address ranges
C.Use the root account for daily administration
D.Enable multi-factor authentication (MFA)
E.Enable guest access for external auditors
AnswersB, D

IP restrictions reduce attack surface.

Why this answer

Restricting access based on IP address ranges (B) is a best practice because it limits the attack surface by allowing only trusted network sources to reach the management console. This is often implemented via security group rules, network ACLs, or cloud provider-specific features like AWS Security Groups or Azure NSGs, reducing exposure to brute-force and unauthorized access attempts.

Exam trap

This question tests the misconception that frequent password rotation is still a security best practice, but the CompTIA Cloud+ exam emphasizes NIST-aligned guidance that prioritizes MFA and IP restrictions over arbitrary password expiry.

19
MCQmedium

An organization is subject to PCI DSS compliance and must demonstrate that it is meeting security requirements. Which cloud service can aggregate compliance findings and provide a dashboard?

A.AWS CloudTrail
B.AWS Security Hub
C.AWS Shield
D.AWS Config
AnswerB

AWS Security Hub aggregates findings across AWS accounts and services, mapping them to standards including PCI DSS, then surfaces compliance status in a single dashboard. This directly satisfies the requirement to demonstrate adherence to PCI DSS security controls through consolidated, continuously updated evidence rather than manual reporting.

Why this answer

AWS Security Hub aggregates security findings from multiple AWS services and provides a compliance dashboard.

20
MCQmedium

A cloud engineer needs to store database backups that must be retained for seven years. The backups are rarely accessed. Which storage type is most cost-effective for this use case?

A.Object storage
B.Block storage
C.Archive storage
D.File storage
AnswerC

Archive storage offers the lowest per-gigabyte cost of Azure's blob tiers, designed for data retained for long periods and rarely accessed. It meets the seven-year retention requirement at minimal expense, unlike hot or cool tiers.

Why this answer

Archive storage (also called cold or archival tier) is purpose-built for data that is rarely accessed and must be retained for long periods, offering the lowest per-gigabyte storage cost among storage classes. It trades off higher retrieval costs and longer retrieval times (minutes to hours) for minimal storage cost, which is exactly the profile of seven-year database backups that are rarely accessed. Object storage is a storage architecture, not a cost tier, and standard object storage tiers are more expensive than archive.

Exam trap

CV0-004 often tests the confusion between storage architecture (object, block, file) and storage cost tier (hot, cool, archive), causing candidates to pick 'object storage' when the question is really about the cheapest retention tier.

How to eliminate wrong answers

Option A is wrong because object storage is a data organization model (flat namespace with metadata and unique IDs) rather than a cost-optimized retention tier; while archive storage is often implemented as an object storage class, choosing 'object storage' generically does not address the cost-effectiveness requirement for rarely accessed long-term data. Option B is wrong because block storage presents raw volumes to a single host, is typically the most expensive per GB, and is designed for active workloads like databases and boot volumes — not for seven-year cold retention. Option D is wrong because file storage provides shared hierarchical file systems (e.g., NFS/SMB) for active collaboration and is not cost-optimized for long-term archival retention.

21
MCQmedium

A cloud operations team manages a containerized microservices application running on an Amazon EKS cluster. During peak hours, the team observes that pods are frequently being terminated and restarted, and node CPU utilization is consistently above 90 percent. The team wants to automatically scale the number of pods based on CPU utilization while ensuring the cluster has enough nodes to schedule the pods. Which combination of actions should the team take to meet these requirements?

A.Enable the Kubernetes Horizontal Pod Autoscaler with a target CPU utilization and configure an AWS Auto Scaling group with a target tracking scaling policy based on the average CPU utilization of the nodes.
B.Configure a Horizontal Pod Autoscaler (HPA) to scale pods based on CPU utilization, and enable the Kubernetes Cluster Autoscaler to adjust the number of nodes in the node group.
C.Create an Amazon CloudWatch alarm that triggers an AWS Lambda function to call the EKS UpdateNodegroupConfig API to increase the desired size of the node group when CPU exceeds a threshold.
D.Deploy a Vertical Pod Autoscaler (VPA) to adjust CPU and memory requests for each pod, and use AWS Application Auto Scaling to add more nodes to the node group.
AnswerB

The Horizontal Pod Autoscaler automatically adjusts the number of pod replicas based on observed CPU utilization, directly addressing the pod scaling requirement. The Cluster Autoscaler adjusts the desired capacity of the node group when pods cannot be scheduled due to insufficient resources, ensuring nodes are added during peak load. Together they provide both pod-level and node-level elasticity, which is the correct operational approach for this scenario.

Why this answer

The Horizontal Pod Autoscaler scales the number of pod replicas based on CPU utilization, directly handling increased application load. The Cluster Autoscaler adjusts the node group size when pods cannot be scheduled due to resource constraints, ensuring sufficient compute capacity. Using both together provides a complete scaling solution for the EKS cluster, addressing both pod and node levels.

Other options either scale only one dimension or use less integrated mechanisms that do not respond correctly to pod scheduling needs.

Exam trap

The trap here is confusing pod-level scaling with node-level scaling, or assuming that a generic Auto Scaling group policy can replace the Kubernetes Cluster Autoscaler for EKS node management.

22
Drag & Dropmedium

Sequence the steps to set up a cloud storage bucket with versioning and lifecycle policies.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Create bucket, enable versioning, add lifecycle rules for transitions and deletions, then test.

23
MCQhard

A healthcare company runs a patient portal on virtual machines in a single on-premises datacenter. Regulatory requirements mandate that data must remain on-premises, but the company wants to burst to a public cloud during seasonal peaks and maintain a consistent operational model. The architect must design a hybrid solution that supports workload portability and centralized identity. Which approach BEST meets these requirements?

A.Deploy Azure Arc-enabled servers to project the on-premises VMs into Azure, use Azure Arc-enabled Kubernetes for burst workloads, and integrate Microsoft Entra ID for centralized identity.
B.Establish a site-to-site VPN between the datacenter and the cloud, then manage each environment with its own native tools and separate identity stores.
C.Use a third-party backup appliance to copy VM images to the cloud and restore them as cloud instances during peak periods, keeping separate credentials in each environment.
D.Replicate all patient data to the public cloud and run the portal entirely there, using the cloud provider's identity service for authentication.
AnswerA

Azure Arc projects on-premises servers and Kubernetes clusters into Azure Resource Manager, enabling consistent management, policy, and monitoring across both environments while keeping data on-premises. Burst workloads can run in Azure connected to the same identity plane through Microsoft Entra ID, satisfying portability and centralized identity.

Why this answer

Azure Arc extends Azure management, policy, and monitoring to on-premises servers and Kubernetes clusters, so the company keeps patient data local while gaining a consistent operational model. Arc-enabled Kubernetes supports bursting workloads to Azure, and Microsoft Entra ID provides centralized identity across both environments, meeting portability and identity requirements.

Exam trap

The trap here is equating a site-to-site VPN with hybrid cloud management; connectivity alone does not deliver consistent tooling, policy, or identity across environments.

24
Multi-Selecthard

A cloud operations team is responsible for a multi-tier application on AWS. They need to improve observability by correlating metrics, logs, and traces to diagnose performance issues across services. The team wants to use AWS services that natively support this correlation. Which TWO actions should the team take? (Choose two.)

Select 2 answers
A.Publish custom application metrics to Amazon CloudWatch using the PutMetricData API
B.Configure AWS Config rules to evaluate resource compliance on a schedule
C.Instrument the application with AWS X-Ray SDKs and enable X-Ray tracing on the services
D.Enable AWS CloudTrail data events for all S3 buckets in the account
E.Store all application logs in an Amazon S3 bucket with versioning enabled
AnswersA, C

Publishing custom metrics with PutMetricData lets the team record application-specific measurements alongside standard metrics in CloudWatch. These metrics can be visualized and alarmed on, and they can be correlated with logs and traces to build a fuller picture of application behavior, which directly supports the observability requirement.

Why this answer

Correlating metrics, logs, and traces for performance diagnosis requires instrumenting the application with X-Ray for distributed tracing and publishing custom application metrics to CloudWatch. Together, traces and metrics can be related to log data to isolate latency and errors across services. S3 versioning, CloudTrail data events, and Config rules address storage durability, API auditing, and compliance, not observability correlation.

Exam trap

The trap here is equating auditing services such as CloudTrail and Config with observability, when they record API activity and configuration state rather than performance telemetry.

25
MCQhard

A company uses Google Cloud Platform and wants to enforce that all Compute Engine instances use a specific Customer-Managed Encryption Key (CMEK) for disk encryption. Which GCP service should be used to enforce this policy?

A.IAM Conditions
B.Organization Policies
C.Cloud Security Command Center
D.Cloud Key Management Service
AnswerB

Organization policies can enforce that only CMEK-protected disks are allowed.

Why this answer

Organization Policies (formerly known as 'Constraints') allow administrators to define and enforce guardrails for Google Cloud resources at the hierarchy level. The specific constraint `compute.requireCsekEncryption` (or the newer CMEK-based equivalent) can be applied to a folder or project to mandate that all Compute Engine disks use a Customer-Managed Encryption Key, rejecting any instance creation or disk attachment that does not comply.

Exam trap

The trap here is that candidates often confuse the key management service (which creates keys) with the policy enforcement service (which enforces their usage).

How to eliminate wrong answers

Option A is wrong because IAM Conditions control access to resources based on attributes like time or resource tags, but they cannot enforce encryption key requirements on Compute Engine instances. Option C is wrong because Cloud Security Command Center is a security and risk dashboard that provides visibility and threat detection, not a policy enforcement mechanism for resource configuration. Option D is wrong because Cloud Key Management Service is the service that creates, manages, and stores encryption keys, but it does not enforce policies that require their use on Compute Engine disks.

26
MCQeasy

Refer to the exhibit. A cloud administrator runs the command to inspect an instance and notices that it is running, but the web application hosted on it is unreachable from the internet. The instance is in a public subnet with an internet gateway attached to the VPC. Which of the following is the most likely cause?

A.The instance type t2.medium does not support public IP addresses.
B.The instance's security group does not allow inbound HTTP/HTTPS traffic from 0.0.0.0/0.
C.The subnet subnet-abc is not associated with a route table that has a route to the internet gateway.
D.The volume vol-111 is not encrypted.
AnswerB

A public subnet and internet gateway only provide a route; the security group acts as a stateful virtual firewall at the instance's elastic network interface. With no inbound rule permitting HTTP/HTTPS from 0.0.0.0/0, the web application stays unreachable despite the instance running.

Why this answer

The most likely cause is that the instance's security group does not allow inbound HTTP/HTTPS traffic from 0.0.0.0/0. Even if the instance is running and in a public subnet with an internet gateway, security groups act as virtual firewalls that must permit the traffic. Without the appropriate inbound rules, the web application is unreachable.

Exam trap

CV0-004 often tests the misconception that a public subnet and internet gateway alone guarantee reachability, ignoring the need for security group inbound rules.

How to eliminate wrong answers

Option A is wrong because t2.medium instances do support public IP addresses; instance type does not restrict public IP assignment. Option C is wrong because the scenario states the subnet is public and has a route to the internet gateway, so this is not the issue. Option D is wrong because volume encryption has no bearing on network reachability of the web application.

27
Multi-Selecthard

A cloud engineer is troubleshooting a performance issue in a microservices application. Which THREE tools can help with distributed tracing and latency diagnosis?

Select 3 answers
A.AWS CloudTrail
B.GCP Cloud Trace
C.Azure Application Insights
D.AWS X-Ray
E.VPC Flow Logs
AnswersB, C, D

GCP Cloud Trace captures distributed traces across microservices and reports per-span latency, satisfying the need to pinpoint slow service hops. Its trace-to-log correlation and latency distribution analysis directly expose bottlenecks in request paths, making it valid for diagnosing the performance issue described.

Why this answer

GCP Cloud Trace (B) is correct because it is Google Cloud's native distributed tracing service, capturing latency data across microservices and rendering span waterfalls that pinpoint slow calls. Azure Application Insights (C) is correct because it provides distributed tracing via correlation IDs and the Application Map, showing end-to-end request latency across services and dependencies. AWS X-Ray (D) is correct because it traces requests through AWS-hosted microservices, building service maps and segment/subsegment timing to isolate latency bottlenecks.

AWS CloudTrail (A) is not a tracing tool; it records API activity for auditing and governance, not request latency. VPC Flow Logs (E) capture IP-level network traffic metadata for connectivity and security analysis, not per-request distributed traces.

28
MCQeasy

A cloud administrator needs to monitor CPU utilization for a fleet of EC2 instances and receive notifications when utilization exceeds 80%. Which AWS service should be used to create a metric alarm that triggers an SNS notification?

A.AWS Config
B.AWS Trusted Advisor
C.Amazon CloudWatch
D.AWS CloudTrail
AnswerC

Amazon CloudWatch ingests EC2 hypervisor-level metrics, including CPUUtilization, without agents, and its alarms evaluate thresholds against configurable periods. An alarm set above 80% transitions to ALARM and invokes an SNS topic action, satisfying the notification requirement directly. CloudTrail records API activity, and Trusted Advisor offers recommendations, neither providing metric threshold alarms.

Why this answer

Amazon CloudWatch is the AWS service for monitoring metrics and creating alarms. CloudWatch Alarms can be configured to trigger SNS notifications when a metric crosses a threshold.

29
Matchingmedium

Match each storage type to its characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Data stored as objects with metadata

Data divided into blocks; used in SAN

Data stored in a hierarchical file system

Temporary storage tied to instance lifecycle

Why these pairings

Object storage uses objects with metadata (scalable for unstructured data), block storage uses fixed blocks (low-latency for databases), file storage uses hierarchical files (shared access), and SAN provides block-level access over a high-speed network. Common confusions swap object and block definitions.

30
MCQmedium

A cloud administrator is troubleshooting an issue where a user in the finance department cannot access a critical application hosted on a private cloud. The user can access other applications in the same subnet. The security team recently implemented a new network security policy. Which of the following is MOST likely causing the issue?

A.The user's VM is isolated from the subnet due to a misconfigured VLAN.
B.The user's account has been disabled due to a failed login attempt.
C.The hypervisor is denying access to the application due to a resource quota violation.
D.A host-based firewall rule is blocking the specific application port on the user's VM.
AnswerD

Since the user reaches other applications in the same subnet, routing and network ACLs are functioning. A host-based firewall rule on the user's VM blocking the specific application port is the most likely cause of this single-application failure.

Why this answer

The user can access other applications in the same subnet, indicating network connectivity is intact, but a specific application is blocked. A host-based firewall rule on the user's VM (e.g., Windows Firewall or iptables) can filter traffic by port or protocol, and a newly implemented security policy likely added a rule blocking the port used by the critical application. This explains why only that application is inaccessible while others work.

Exam trap

The trap here is that candidates often assume network-level issues (like VLAN misconfiguration) or account problems, but the key clue is that other applications in the same subnet are accessible, pointing to a host-based filter rather than a network-wide or authentication issue.

How to eliminate wrong answers

Option A is wrong because a misconfigured VLAN would isolate the entire VM from the subnet, preventing access to all applications, not just one. Option B is wrong because a disabled account would prevent authentication to the application or network, but the user can still access other applications, indicating the account is active. Option C is wrong because a hypervisor resource quota violation would affect all VMs or applications on that host, not a single user's access to one application, and would typically cause performance issues or VM failure, not selective port blocking.

31
MCQmedium

A cloud engineer receives an alert that the root filesystem (/) is at 93% usage. The /data volume has plenty of free space. The application stores logs in /var/log/app/ on the root filesystem. Which of the following is the BEST long-term solution?

A.Move the /var/log/app directory to the /data partition and create a symlink
B.Increase the size of the root filesystem
C.Delete the /data partition and merge it with root
D.Configure log rotation to delete logs more frequently
AnswerA

Relocating /var/log/app onto the /data partition and symlinking it back frees the root filesystem permanently, since logs then consume /data's capacity instead. This satisfies the long-term requirement, unlike log rotation or deletion, which only delay reoccurrence as logs regrow.

Why this answer

Moving the /var/log/app directory to the /data partition and creating a symlink is the best long-term solution because it permanently relocates the log data to a volume with ample free space without requiring application reconfiguration. The symlink (/var/log/app -> /data/app) makes the application continue to write to the same logical path, while the actual storage is on the /data filesystem. This resolves the root filesystem capacity issue without altering the application's logging behavior or risking data loss.

Exam trap

CompTIA often tests the misconception that increasing filesystem size or deleting partitions is a valid long-term fix, when in reality the correct approach is to relocate data to a separate volume using a symlink or mount bind.

How to eliminate wrong answers

Option B is wrong because increasing the size of the root filesystem only provides a temporary fix and does not address the underlying issue of log growth; it may also be impractical if the underlying disk or LVM has no free extents. Option C is wrong because deleting the /data partition and merging it with root is destructive, risks data loss on /data, and violates the principle of separating application data from the OS filesystem. Option D is wrong because configuring log rotation to delete logs more frequently reduces historical data needed for troubleshooting and compliance, and does not prevent future root filesystem exhaustion if log volume continues to grow.

32
MCQeasy

A cloud administrator needs to automate the process of patching multiple virtual machines in a private cloud. Which of the following is the best tool for this purpose?

A.Virtual machine templates
B.Ansible playbook
C.SSH with manual commands
D.Scheduled tasks in the hypervisor management console
AnswerB

Ansible playbooks are agentless, connecting over SSH or WinRM to run idempotent patch tasks across many VMs simultaneously. This satisfies the agentless, multi-VM automation constraint, unlike manual patching or single-host scripting, and requires no persistent agent installation on each target.

Why this answer

An Ansible playbook is the best tool for automating patching across multiple VMs because it is agentless, uses SSH for Linux or WinRM for Windows, and supports idempotent execution. This allows the administrator to define the desired patch state declaratively and apply it consistently across the entire fleet without manual intervention.

Exam trap

The trap here is that candidates confuse hypervisor-level automation (scheduled tasks in the console) with guest OS automation, forgetting that patching requires executing commands inside the VM, which hypervisor tools cannot do natively.

How to eliminate wrong answers

Option A is wrong because virtual machine templates are used to create new VMs from a golden image, not to patch existing running VMs. Option C is wrong because SSH with manual commands requires the administrator to connect to each VM individually, which does not scale and is not automated. Option D is wrong because scheduled tasks in the hypervisor management console typically handle hypervisor-level operations (e.g., VM snapshots or power actions) and lack the ability to run OS-level patch commands inside guest VMs.

33
MCQmedium

A company is deploying a web application on AWS using an Application Load Balancer (ALB) and an Auto Scaling group. The application must handle sudden traffic spikes without manual intervention. The engineer needs to configure the Auto Scaling group to scale based on the number of requests per target. Which CloudWatch metric should be used as the basis for the scaling policy?

A.ALB ActiveConnectionCount
B.Auto Scaling Group DesiredCapacity
C.ALB RequestCountPerTarget
D.EC2 CPUUtilization
AnswerC

RequestCountPerTarget is a metric emitted by the Application Load Balancer that measures the average number of requests received per target (e.g., EC2 instance) over a specified period. Scaling based on this metric directly ties capacity to actual demand, allowing the Auto Scaling group to add instances when request load increases, ensuring responsive scaling during traffic spikes.

Why this answer

The ALB RequestCountPerTarget metric directly measures the average request load per instance, making it the most appropriate for scaling based on request volume. It allows the Auto Scaling group to add or remove instances proportionally to traffic, ensuring the application can handle spikes. Other metrics like CPU or connections may not accurately reflect request rate.

Exam trap

The trap here is assuming that CPU utilization is always the best scaling metric, when in fact request-based metrics can be more directly tied to demand for web applications.

34
MCQhard

A financial services firm runs a latency-sensitive trading application in a public cloud. The security team requires that traffic between the application tier and the database tier never traverse the public internet, that both tiers reside in the same virtual network, and that access to the database be restricted to specific application subnet addresses. Which combination of cloud networking controls should the architect implement?

A.Place the tiers in separate virtual networks and connect them with a site-to-site VPN tunnel over the internet.
B.Assign public IP addresses to the database nodes and use a host-based firewall to allow only the application servers.
C.Put both tiers in the same virtual network and rely on the default allow-all rules provided by the cloud platform.
D.Place both tiers in the same virtual network and attach a network security group rule to the database subnet allowing only the application subnet CIDR.
AnswerD

Keeping both tiers in one virtual network means traffic stays on the provider's private backbone and never crosses the public internet. A network security group or firewall rule scoped to the database subnet that permits only the application subnet's CIDR enforces least-privilege access at the subnet boundary, satisfying both the private-path and restricted-access requirements.

Why this answer

Hosting both tiers in a single virtual network guarantees east-west traffic remains on the provider's private network, and a network security group scoped to the database subnet that allows only the application subnet CIDR enforces least-privilege access. Together these controls satisfy the private-path and restricted-access mandates without introducing internet routing or unnecessary tunnel overhead.

Exam trap

The trap here is assuming that encryption via a VPN makes traffic private, when it still traverses the public internet and adds latency.

35
MCQeasy

Which cloud characteristic allows a user to provision additional resources automatically without requiring human intervention?

A.Measured service
B.Resource pooling
C.Rapid elasticity
D.Broad network access
AnswerC

Rapid elasticity provisions and releases resources automatically as demand changes, satisfying the stem's requirement for scaling without human intervention. Measured service and on-demand self-service cover metering and user-initiated provisioning, but only rapid elasticity delivers the automatic, dynamic capacity adjustment described.

Why this answer

Rapid elasticity is the cloud characteristic that allows resources to be automatically provisioned and released to scale rapidly with demand, often without human intervention. This is enabled by auto-scaling policies and APIs that respond to metrics like CPU utilization or request count. It directly matches the description of automatic provisioning without human intervention.

Exam trap

The trap is confusing rapid elasticity with resource pooling or measured service — candidates often pick 'resource pooling' because both involve shared infrastructure, but only rapid elasticity describes automatic, demand-driven provisioning without human intervention.

How to eliminate wrong answers

Option A is wrong because measured service refers to the pay-as-you-go billing model where resource usage is metered and charged, not automatic provisioning. Option B is wrong because resource pooling describes the multi-tenant model where physical resources are shared among customers, not the automatic scaling behavior. Option D is wrong because broad network access means services are available over the network via standard mechanisms, which is about accessibility, not automatic scaling.

36
MCQmedium

A company runs a stateless web application on virtual machines. To handle increased traffic, they add more virtual machines and distribute incoming requests among them. What is this scaling method called?

A.Right-sizing
B.Vertical scaling
C.Auto-scaling
D.Horizontal scaling
AnswerD

Horizontal scaling adds more VM instances to the pool and spreads requests across them, matching the stem's stateless web tier. Vertical scaling would instead resize a single existing VM, which cannot distribute load across multiple hosts.

Why this answer

Horizontal scaling (scaling out) adds more instances — in this case, more virtual machines — and distributes incoming requests among them, typically via a load balancer. This increases capacity by adding parallel resources rather than making a single resource larger. The scenario explicitly describes adding more VMs and distributing requests, which is the definition of horizontal scaling.

Exam trap

CV0-004 often tests the confusion between horizontal scaling (adding instances) and auto-scaling (the automation that adjusts capacity), causing candidates to pick auto-scaling when the question describes the scaling method itself.

How to eliminate wrong answers

Option A is wrong because right-sizing means adjusting the size of an existing instance to match its workload (e.g., downsizing an over-provisioned VM), not adding more instances to handle traffic. Option B is wrong because vertical scaling (scaling up) increases the resources of a single instance — more CPU, RAM, or storage on one VM — which has a hardware ceiling and often requires downtime; the scenario adds multiple VMs, not a bigger one. Option C is wrong because auto-scaling is the automation mechanism that adjusts capacity based on demand; it can perform horizontal scaling, but the question asks for the scaling method itself, which is horizontal scaling, not the automation policy.

37
MCQmedium

A cloud architect is designing a disaster recovery plan. The application requires a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 1 hour. Which strategy best meets these requirements?

A.Daily snapshots replicated to another region
B.Scheduled cross-region snapshots every 6 hours
C.Backup to tape and store offsite
D.Continuous replication to a warm standby site
AnswerD

Continuous replication satisfies the one-hour RPO by shipping every write to the standby, while the warm standby's pre-provisioned, running-but-idle capacity enables promotion within the 15-minute RTO. Unlike pilot light or backup/restore, no rebuild or data reload delay is incurred, meeting both targets simultaneously.

Why this answer

Continuous replication to a warm standby site best meets the RTO of 15 minutes and RPO of 1 hour. Warm standby maintains a scaled-down but functional copy of the environment that can be quickly scaled up, and continuous replication ensures data loss is within minutes, satisfying the RPO.

Exam trap

CV0-004 often tests the trade-offs between RTO and RPO; candidates may choose daily snapshots thinking they are sufficient, but they fail to meet the 1-hour RPO.

How to eliminate wrong answers

Option A is wrong because daily snapshots replicated to another region would result in an RPO of up to 24 hours, exceeding the 1-hour requirement. Option B is wrong because cross-region snapshots every 6 hours would have an RPO of up to 6 hours, also exceeding 1 hour. Option C is wrong because backup to tape and offsite storage is slow to restore, likely exceeding the 15-minute RTO and 1-hour RPO.

38
MCQmedium

A cloud engineer is designing a disaster recovery plan with an RTO of 2 hours and RPO of 15 minutes. Which strategy best meets these requirements?

A.Pilot light with hourly snapshots
B.Warm standby with continuous replication
C.Cold standby with daily backups
D.Active-active across regions
AnswerB

Warm standby with continuous replication keeps a scaled-down environment running and replicates data continuously, giving an RPO near zero and failover well within two hours. This satisfies both the 15-minute RPO and 2-hour RTO at lower cost than active-active.

Why this answer

A warm standby with continuous replication keeps a scaled-down but fully functional copy of the environment running in a secondary region, with data replicated continuously. This allows failover within minutes, easily meeting the 15-minute RPO, and the standby can be scaled up to full capacity within the 2-hour RTO. It balances cost and recovery speed better than the other options for these specific targets.

Exam trap

The trap is that candidates focus only on RTO and pick pilot light or cold standby as 'cheaper,' ignoring that the 15-minute RPO rules out hourly or daily backups — the RPO requirement is the deciding constraint here.

How to eliminate wrong answers

Option A is wrong because hourly snapshots yield an RPO of up to 60 minutes, which exceeds the 15-minute requirement, even though a pilot light could meet the 2-hour RTO. Option C is wrong because daily backups produce an RPO of up to 24 hours and a cold standby requires provisioning infrastructure from scratch, likely exceeding the 2-hour RTO. Option D is wrong because active-active across regions exceeds the requirements and is significantly more expensive and complex than necessary; it is over-engineering for a 2-hour RTO.

39
MCQhard

A cloud database cluster is experiencing replication lag. The primary node shows high write activity, and the replicas are on different availability zones. Which of the following is the most likely cause?

A.Replication is configured as synchronous.
B.Network latency between the primary and replica zones is high.
C.The replica nodes have insufficient storage.
D.The primary node's vCPU is over-allocated.
AnswerB

High inter-zone network latency directly delays log shipping from primary to replica, so each replica applies writes later than the primary commits them. Since the replicas sit in different availability zones, cross-zone round-trip time is the bottleneck driving the observed replication lag, not write volume alone.

Why this answer

Network latency between availability zones is a common cause of replication lag in asynchronous replication setups, especially when the primary has high write activity. Option A is incorrect because synchronous replication would cause the primary to wait for acknowledgment from replicas, leading to write slowdown rather than lag on replicas. Option C is incorrect because insufficient storage on replicas would typically cause disk-full errors, not replication lag.

Option D is incorrect because vCPU over-allocation on the primary primarily affects compute performance, not the replication process which is more sensitive to network and disk I/O.

40
Multi-Selecteasy

A hybrid cloud deployment connects an on-premises data center to a public cloud. Which TWO components are typically required to establish this connectivity? (Select TWO.)

Select 2 answers
A.Load balancer in the cloud
B.Direct peering or dedicated connection (e.g., AWS Direct Connect)
C.Virtual private network (VPN) gateway
D.Public internet with HTTPS
E.Cloud-based DNS resolver
AnswersB, C

A dedicated connection or direct peering provides private, consistent bandwidth between the on-premises data centre and the public cloud, bypassing the public internet. This satisfies the hybrid connectivity requirement for predictable latency and throughput that a standard VPN over the internet cannot guarantee.

Why this answer

Option B is correct because a hybrid cloud requires a private, high-bandwidth, low-latency link between the on-premises data center and the public cloud, which is exactly what a dedicated connection such as AWS Direct Connect (or Azure ExpressRoute, or direct peering) provides, bypassing the public internet. Option C is correct because a VPN gateway (e.g., an IPsec site-to-site VPN terminating on an AWS virtual private gateway or Azure VPN gateway) is the other standard mechanism for securely extending the on-premises network into the cloud over an encrypted tunnel. Together, dedicated connections and VPN gateways are the two canonical connectivity components for hybrid cloud architectures.

Option A is not required for connectivity itself; a load balancer distributes traffic to workloads but does not establish the hybrid link. Option D is incorrect because plain public internet with HTTPS is not the typical secure hybrid connectivity method and lacks the private/encrypted tunnel characteristics of a VPN or dedicated circuit. Option E is incorrect because a DNS resolver only resolves names and plays no role in establishing network connectivity between the data center and the cloud.

Exam trap

The trap here is that candidates confuse application-layer components (like load balancers or DNS) with network-layer connectivity components, or mistakenly think that public internet with HTTPS alone is sufficient for site-to-site hybrid cloud connectivity.

41
MCQmedium

A cloud architect is designing a multi-tier application on a public cloud. To minimize costs while maintaining performance for variable workloads, the architect decides to use a mix of reserved and spot instances. Which design principle is being applied?

A.Scalability
B.High availability
C.Cost optimization
D.Security
AnswerC

Mixing reserved instances for steady baseline capacity with spot instances for interruptible, variable demand directly satisfies the stem's constraint of minimising cost while sustaining performance. This is cost optimisation: matching each workload's tolerance for interruption to the cheapest suitable purchasing model, rather than over-provisioning on-demand capacity.

Why this answer

Using a mix of reserved and spot instances directly reduces compute costs by committing to predictable workloads with reserved instances (which offer significant discounts over on-demand) and using spot instances for fault-tolerant, flexible workloads at steep discounts (often 60-90% off on-demand). This hybrid approach is a core cost optimization strategy in public cloud design, as it balances upfront commitment with opportunistic savings without sacrificing performance for variable workloads.

Exam trap

CompTIA often tests the distinction between cost optimization and scalability, where candidates mistakenly think that using spot instances alone is a scalability strategy, but the key is that mixing reserved and spot instances is a financial optimization, not an architectural scaling mechanism.

How to eliminate wrong answers

Option A is wrong because scalability refers to the ability to automatically increase or decrease resources based on demand (e.g., using auto-scaling groups), not specifically to the financial strategy of mixing instance purchasing options. Option B is wrong because high availability focuses on ensuring application uptime through redundancy across availability zones or regions, not on minimizing costs via instance pricing models. Option D is wrong because security involves protecting data and resources via IAM policies, encryption, and network controls, not on selecting instance types or pricing models to reduce expenditure.

42
Multi-Selecteasy

A company is considering using a public cloud provider. Which TWO characteristics are typical of a public cloud deployment? (Select TWO.)

Select 2 answers
A.The customer has full control over the physical infrastructure
B.The deployment is isolated to a single organization
C.Resources are shared among multiple customers
D.The customer pays only for the resources they use
E.Resources are hosted on-premises
AnswersC, D

Multi-tenancy is the defining trait: the provider pools compute, storage and networking across customers, isolating tenants logically rather than physically. This shared-resource model satisfies the stem's public cloud characteristic, contrasting with single-tenant private deployments where hardware is dedicated to one organisation.

Why this answer

A public cloud is characterized by multi-tenancy (resources shared among multiple customers) and pay-as-you-go pricing, where the customer pays only for the resources they use. Options C and D describe these typical characteristics. Option A is incorrect because the cloud provider manages the physical infrastructure, not the customer.

Option B describes a private cloud, which is isolated to a single organization. Option E describes on-premises deployment, not public cloud.

43
Multi-Selectmedium

A cloud architect is designing a disaster recovery plan for a critical application. Which TWO metrics should be defined to establish recovery objectives?

Select 2 answers
A.RPO (Recovery Point Objective)
B.MTBF (Mean Time Between Failures)
C.RTO (Recovery Time Objective)
D.SLA (Service Level Agreement)
E.MTTR (Mean Time to Repair)
AnswersA, C

RPO defines the maximum tolerable data loss measured in time, determining how frequently backups or replication must occur. It directly satisfies the stem's requirement to establish recovery objectives by quantifying the acceptable gap between the last recoverable data point and the failure moment.

Why this answer

RPO (Recovery Point Objective) is correct because it defines the maximum acceptable amount of data loss measured in time, establishing how far back the recovery must restore data and thus driving backup frequency. RTO (Recovery Time Objective) is correct because it defines the maximum acceptable downtime, i.e., how quickly the application must be restored after a disruption, which directly shapes the DR architecture and failover strategy. Together, RPO and RTO are the two standard recovery objectives used to design and validate a disaster recovery plan.

MTBF (Mean Time Between Failures) is a reliability metric describing expected time between hardware/component failures, not a recovery objective. SLA (Service Level Agreement) is a contractual document that may reference RPO/RTO but is not itself a recovery metric. MTTR (Mean Time to Repair) measures average time to fix a failed component, which is an operational metric rather than a defined recovery objective.

Exam trap

CV0-004 often tests the confusion between recovery metrics (RPO/RTO) and reliability metrics (MTBF/MTTR), or the misconception that an SLA itself defines recovery objectives rather than being a document that references them.

44
Drag & Dropmedium

Sequence the steps to configure a cloud monitoring alert for high memory usage on a virtual machine.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Go to monitoring, create alarm, set threshold, configure notification, then test.

45
Multi-Selecteasy

Which TWO steps should be performed to ensure that a new cloud user has only the minimum required permissions to perform their job? (Choose two.)

Select 2 answers
A.Assign the user to a group with broad administrator access for flexibility.
B.Provide permissions based on the user's specific job functions.
C.Remove the user's account immediately after granting access.
D.Create a custom role that includes all possible permissions.
E.Review and remove unnecessary permissions periodically.
AnswersB, E

Granting permissions mapped to the user's actual job functions enforces least privilege, since each role receives only the actions their duties require. This satisfies the stem's minimum-permissions constraint rather than assigning broad default or inherited access.

Why this answer

Option B is correct because implementing least privilege means granting permissions that map precisely to the user's job functions, so the user receives only the access needed to perform their role and nothing more. Option E is correct because least privilege is not a one-time configuration; permissions tend to accumulate over time (role changes, project assignments), so periodic access reviews and removal of unnecessary permissions keep the account at the minimum required level. Option A is wrong because assigning broad administrator access for flexibility directly violates least privilege by over-provisioning rights.

Option C is wrong because deleting the account right after granting access makes the account unusable and does not relate to limiting permissions. Option D is wrong because a custom role containing all possible permissions is the opposite of least privilege and grants excessive access.

Exam trap

CV0-004 often tests the principle of least privilege. Candidates might choose options that grant broad access for flexibility or create custom roles with all permissions, misunderstanding that least privilege requires minimal access.

46
MCQhard

A cloud administrator is troubleshooting why a newly launched VM did not complete its initialization. According to the exhibit, what is the most likely cause?

A.Cloud-init is not installed on the VM
B.The package repository is not configured correctly
C.The cloud-init user data script contains a syntax error
D.The VM does not have internet access
AnswerB

A misconfigured package repository prevents the cloud-init script from installing required packages, so initialisation halts before completion. This directly satisfies the stem's constraint: the VM launched but never finished bootstrapping, indicating a dependency fetch failure rather than a provisioning or networking fault.

Why this answer

The error 'E: Unable to locate package python3-pip' indicates that the package repository is not configured correctly or the package does not exist in the configured sources. This prevents cloud-init from installing the specified package, so the most likely cause is an incorrect repository configuration. Therefore, option B is correct.

Option A is incorrect because cloud-init is executing commands, showing it is installed. Option C is incorrect because the error is about a missing package, not a syntax error. Option D is incorrect because the command ran successfully, indicating no network issues; the problem is repository configuration.

47
MCQhard

A web application is deployed across multiple availability zones behind a load balancer. The administrator notices that all traffic is being routed to instances in only one availability zone, causing performance issues. The load balancer is configured to distribute traffic across all zones evenly. What is the most likely cause?

A.The firewall rules for the load balancer only allow traffic from one zone.
B.The instances in the other zones are marked as unhealthy due to failing health checks.
C.The route table for the subnets in the other zones is missing a default route.
D.The listener rules are configured to forward traffic to a single backend pool.
AnswerB

When cross-zone load balancing is enabled, the load balancer should distribute traffic across all availability zones. However, if instances in other zones fail health checks, they are marked as unhealthy and removed from the target group's rotation, causing all traffic to go to healthy instances in only one zone.

Why this answer

If the load balancer is configured to distribute traffic evenly across all availability zones but traffic only reaches one zone, the most likely cause is that instances in the other zones are failing health checks and are marked unhealthy. Load balancers only route to healthy backends, so unhealthy instances in other zones are excluded, concentrating traffic in the one healthy zone. This matches the symptom of uneven distribution despite even configuration.

Exam trap

CV0-004 often tests the assumption that even load balancer configuration guarantees even traffic distribution — candidates overlook that health check status dynamically removes backends, so runtime health, not configuration, explains uneven routing.

How to eliminate wrong answers

Option A is wrong because firewall rules typically apply to the load balancer's frontend or the backend subnet as a whole, not per-availability-zone in a way that would selectively block one zone while the LB config says even distribution; also, if the firewall blocked a zone, health checks would fail there too, but the question points to health status as the differentiator. Option C is wrong because a missing default route in other zones' subnets would prevent outbound traffic but would not necessarily cause the load balancer to stop routing to them — and again, health check failures would be the observable cause. Option D is wrong because if listener rules forwarded to a single backend pool, the question's premise that the LB is configured to distribute across all zones evenly would be contradicted; the scenario states the configuration is correct, so the cause must be runtime health state.

48
MCQeasy

A cloud administrator is troubleshooting a failed deployment of a new application version using a continuous integration/continuous deployment (CI/CD) pipeline. The pipeline fails at the 'test' stage. What is the first step the administrator should take?

A.Re-run the pipeline
B.Increase the timeout of the test stage
C.Roll back to the previous version
D.Check the test logs for specific errors
AnswerD

The pipeline halts at the test stage, so the failure detail resides in that stage's output. Reviewing the test logs reveals the specific assertion, dependency or environment error before any remediation, avoiding speculative changes to code or pipeline configuration that could mask the actual fault.

Why this answer

When a CI/CD pipeline fails at the test stage, the first diagnostic step is to examine the test logs to identify the specific error — whether it is a failed assertion, a missing dependency, a timeout, or an environment issue. Logs provide the evidence needed to determine root cause before taking any corrective action. Jumping to re-runs or rollbacks without understanding the failure wastes time and may mask a recurring defect.

Exam trap

CV0-004 often tests the temptation to jump to remediation (re-run, rollback, increase timeout) before performing the fundamental troubleshooting step of reading logs to identify the actual error.

How to eliminate wrong answers

Option A is wrong because re-running the pipeline without diagnosing the failure is a blind action; if the failure is deterministic (e.g., a broken test or code defect), it will simply fail again. Option B is wrong because increasing the test stage timeout assumes the failure is due to slow execution, which is only one of many possible causes and is not supported by evidence yet. Option C is wrong because rolling back to the previous version is a remediation step, not a diagnostic step, and it discards the new version's changes without understanding why the tests failed.

49
Multi-Selecteasy

A company uses AWS CloudFormation to manage infrastructure. The operations team needs to be alerted when a stack update fails. Which TWO methods can be used to send notifications? (Choose two.)

Select 2 answers
A.Use AWS Trusted Advisor to monitor CloudFormation
B.Enable CloudTrail to log stack updates and send logs to CloudWatch Logs
C.Configure CloudFormation to send events to an SNS topic
D.Use AWS Config to detect stack failures
E.Create a CloudWatch Events rule that matches CloudFormation stack update failure events
AnswersC, E

CloudFormation publishes stack lifecycle events, including update failures, to an SNS topic specified in the stack's notification configuration. Subscribers then receive alerts, directly satisfying the requirement to notify the operations team when a stack update fails.

Why this answer

Option C is correct because CloudFormation natively supports associating an SNS topic with stack events, so when a stack update fails CloudFormation publishes the event to that topic and subscribers (email, SMS, Lambda, etc.) receive the notification. Option E is correct because CloudFormation emits stack state-change events to Amazon EventBridge (CloudWatch Events), and a rule matching the StackStatus value UPDATE_FAILED (or UPDATE_ROLLBACK_COMPLETE with failure) can trigger an SNS topic, Lambda, or other target to alert the operations team. Option A is not correct because AWS Trusted Advisor checks cost, security, fault tolerance, performance, and service limits — it does not monitor CloudFormation stack update failures.

Option B is not correct because CloudTrail records API calls for auditing, and while its logs can be sent to CloudWatch Logs, this does not by itself generate failure notifications for stack updates. Option D is not correct because AWS Config evaluates resource configuration compliance and does not detect or notify on CloudFormation stack update failures.

50
MCQeasy

A cloud administrator notices that a virtual machine in a public cloud is running slower than expected. The VM is part of a production web application. The administrator has verified that the VM's CPU and memory utilization are below 50%. What should the administrator check next?

A.Check the network bandwidth and I/O throttling limits.
B.Migrate the VM to a different availability zone.
C.Increase the VM's vCPU count.
D.Reboot the VM.
AnswerA

With CPU and memory below 50%, the bottleneck lies elsewhere. Network bandwidth saturation or storage IOPS throttling limits imposed by the cloud provider commonly degrade VM performance despite adequate compute, so these should be examined next.

Why this answer

When CPU and memory are well below capacity, performance degradation in a public cloud VM is often caused by resource throttling at the network or storage layer. Cloud providers enforce bandwidth caps and I/O limits per VM size, and hitting those limits can cause packet loss, queuing, and high latency even when compute resources are idle. Checking network bandwidth and I/O throttling limits is the correct next step to identify if the VM is being rate-limited.

Exam trap

CompTIA often tests the misconception that low CPU/memory always means the VM is underutilized, when in fact network or I/O throttling can cause severe performance issues without affecting compute metrics.

How to eliminate wrong answers

Option B is wrong because migrating to a different availability zone addresses physical infrastructure failures or zone-level outages, not performance throttling caused by resource caps. Option C is wrong because increasing vCPU count does not resolve network or I/O throttling and may actually increase cost without fixing the bottleneck. Option D is wrong because rebooting the VM clears transient software issues but does not change the underlying resource limits or throttling policies that are causing the slowdown.

51
MCQmedium

A DevOps team is implementing a CI/CD pipeline using Jenkins. They want to ensure that code is automatically built, tested, and deployed to a staging environment before manual approval for production. Which stage should include the deployment to staging?

A.Build
B.Deploy
C.Source
D.Verify
AnswerB

The Deploy stage performs the actual release of built artefacts to the staging environment, so it is where staging deployment belongs. Build compiles, test validates, and manual approval gates production, matching the pipeline's required sequence.

Why this answer

In a Jenkins CI/CD pipeline, the Deploy stage is responsible for taking the built and verified artifact and releasing it to an environment — in this case, the staging environment. The pipeline flow is typically Source → Build → Test/Verify → Deploy (staging) → Manual Approval → Deploy (production). Placing staging deployment in the Deploy stage correctly separates it from build and test activities.

Exam trap

CV0-004 often tests whether candidates conflate 'Verify' (testing) with 'Deploy' (releasing to an environment), causing them to place staging deployment in the Verify stage because staging is used for verification.

How to eliminate wrong answers

Option A is wrong because the Build stage compiles code and produces artifacts; it does not deploy to any environment. Option C is wrong because the Source stage is where Jenkins checks out code from the SCM (Git, SVN) — it is the entry point, not a deployment stage. Option D is wrong because the Verify stage runs tests (unit, integration, static analysis) against the built artifact; it validates quality but does not push code to staging.

Deployment to any environment, including staging, belongs in the Deploy stage.

52
Multi-Selectmedium

Which THREE design principles are fundamental to building a highly available cloud architecture?

Select 3 answers
A.Eliminate single points of failure
B.Deploy across multiple availability zones
C.Implement health checks and auto-recovery
D.Scale vertically to increase capacity
E.Use a single, powerful database instance
AnswersA, B, C

Removing single points of failure ensures no individual component outage halts the service, since redundancy lets traffic fail over. This underpins availability by eliminating the components whose failure would cause total loss of the application.

Why this answer

Option A (Eliminate single points of failure) is correct because high availability requires that no individual component's failure can take down the whole system, so redundant components (multiple instances, load balancers, redundant network paths) must be designed in. Option B (Deploy across multiple availability zones) is correct because AZs are isolated failure domains within a region; distributing workloads across at least two AZs ensures that the loss of one data center does not cause an outage. Option C (Implement health checks and auto-recovery) is correct because health checks detect unhealthy instances and auto-recovery/auto-scaling mechanisms replace or restart them automatically, maintaining service continuity without manual intervention.

Option D (Scale vertically) is not a high-availability principle because increasing the size of a single resource still leaves a single point of failure and often requires downtime to resize. Option E (Use a single, powerful database instance) is not correct because a single database instance is itself a single point of failure; high availability instead calls for replication, multi-AZ failover, or clustering.

Exam trap

CompTIA often tests the misconception that vertical scaling (Option D) is a valid high-availability strategy, when in reality it only addresses capacity and not fault tolerance, and that a single powerful database (Option E) can be made highly available through backups alone, ignoring the need for real-time replication and automatic failover.

53
MCQhard

A cloud architect is designing a microservices-based application that requires inter-service communication. The services must be loosely coupled, and the architecture must handle service failures gracefully. Which communication pattern is most appropriate?

A.Asynchronous messaging using a message queue or pub/sub system.
B.Remote procedure calls (RPC) with timeouts.
C.Shared database with direct reads and writes.
D.Synchronous HTTP/REST calls between services.
AnswerA

Asynchronous messaging decouples services by allowing them to communicate via messages without waiting for immediate responses. If a service fails, messages can be queued and processed later, providing graceful failure handling. This pattern promotes loose coupling and resilience, making it the most appropriate for the scenario.

Why this answer

Asynchronous messaging decouples services and allows them to operate independently, with messages buffered during failures. This ensures that a service outage does not immediately impact others, providing resilience and loose coupling, which are critical for microservices architectures.

Exam trap

The trap here is thinking that synchronous calls with retries or timeouts provide sufficient decoupling, when they still create runtime dependencies that can propagate failures.

54
MCQmedium

A cloud engineer is configuring a web application that must comply with PCI DSS. The application runs on virtual machines in a public cloud. Which of the following security responsibilities falls under the customer's scope according to the shared responsibility model?

A.Replacing failed physical drives in the storage array
B.Patching the guest operating system of the virtual machines
C.Configuring the physical network firewall
D.Applying hypervisor patches
AnswerB

Patching the guest operating system falls to the customer because infrastructure-as-a-service places OS-level maintenance squarely on the tenant, not the provider. PCI DSS requires timely security updates on systems handling cardholder data, and the hypervisor, physical hosts and network fabric remain the provider's responsibility under this model.

Why this answer

In the shared responsibility model, the customer is responsible for patching the guest OS, while the cloud provider manages the physical infrastructure and hypervisor.

55
Multi-Selecthard

A cloud security team is implementing a zero-trust security model for a microservices application deployed on Azure Kubernetes Service (AKS). The team needs to ensure that all service-to-service communication is authenticated and encrypted, and that access policies are enforced based on service identity rather than network location. Which TWO components should the team implement to achieve these goals? (Choose two.)

Select 2 answers
A.Open Service Mesh (OSM) with mutual TLS (mTLS) enabled
B.Azure Active Directory (Azure AD) workload identities
C.Network Security Groups (NSGs) with service tags
D.Azure Bastion for secure remote access to AKS nodes
E.Azure Firewall with network rules based on IP addresses
AnswersA, B

Open Service Mesh (OSM) is a lightweight service mesh that provides mTLS for service-to-service communication, encrypting traffic and authenticating service identities. It enforces access policies based on service accounts, aligning with zero-trust principles. OSM integrates natively with AKS and can leverage Azure AD workload identities for certificate management, making it essential for encrypted and authenticated communication.

Why this answer

A zero-trust model for microservices requires strong service identities and encrypted, authenticated communication. Azure AD workload identities provide the identity plane, allowing services to authenticate using Azure AD tokens. Open Service Mesh with mTLS provides the data plane encryption and enforces access policies based on those identities.

Together, they ensure that service-to-service communication is both authenticated and encrypted, independent of network location.

Exam trap

The trap here is assuming that network-layer controls like firewalls or NSGs can provide identity-based authentication and encryption for microservices.

56
MCQeasy

A cloud administrator is setting up monitoring for a web application. The application must be highly available across multiple availability zones. Which of the following metrics should be monitored to ensure that the application meets its service level agreement (SLA) for uptime?

A.Network throughput per minute.
B.The result of the load balancer health check for each instance.
C.Percentage of disk space used on each instance.
D.Average CPU utilization across all instances.
AnswerB

Load balancer health checks report whether each instance behind the balancer is serving traffic. Monitoring these results across availability zones detects instance or zone failures immediately, directly measuring the uptime component of the SLA rather than inferring it from CPU or request counts.

Why this answer

The load balancer health check result directly indicates whether each instance is reachable and responding correctly to application traffic. Monitoring these results allows the administrator to detect instance failures and verify that the application remains available across multiple availability zones, which is the core requirement for meeting an uptime SLA. Other metrics like throughput, disk space, or CPU utilization are performance indicators but do not directly confirm application availability.

Exam trap

The trap here is that candidates confuse performance metrics (CPU, disk, throughput) with availability metrics, assuming that high resource usage or low throughput directly indicates an outage, when in fact only the load balancer health check result provides a definitive binary signal of instance availability for SLA compliance.

How to eliminate wrong answers

Option A is wrong because network throughput per minute measures data transfer volume, not application availability; high throughput does not guarantee the application is serving requests correctly. Option C is wrong because percentage of disk space used is a capacity metric that can affect performance but does not directly indicate whether the application is up and responding to user requests. Option D is wrong because average CPU utilization across all instances is a performance metric that can be high even when the application is fully available, and it does not detect individual instance failures that would violate an uptime SLA.

57
MCQhard

A company is migrating on-premises workloads to a public cloud. The disaster recovery plan requires an RTO of 15 minutes and an RPO of 5 minutes. Which replication strategy should be used for a critical database?

A.Weekly full backups with daily incrementals stored in the same region
B.Continuous replication to a standby instance in another region
C.Scheduled snapshots every hour with cross-region copy
D.Daily snapshots replicated cross-region
AnswerB

Continuous replication ships every transaction to a standby in another region, giving an RPO of seconds and enabling failover well inside the 15-minute RTO. Snapshot or scheduled replication cannot meet a 5-minute RPO, since data written between intervals would be lost.

Why this answer

Continuous replication to a standby instance in another region provides an RPO of near-zero (often seconds) and an RTO of minutes, as the standby can be promoted quickly. This meets the required RPO of 5 minutes and RTO of 15 minutes. Continuous replication ensures that data changes are replicated asynchronously or synchronously, depending on configuration, minimizing data loss.

Exam trap

CV0-004 often tests RTO/RPO requirements and candidates may underestimate the frequency needed for backups, choosing snapshot intervals that are too long, thus failing to meet the RPO.

How to eliminate wrong answers

Option A is wrong because weekly full backups with daily incrementals result in an RPO of up to 24 hours, far exceeding the 5-minute requirement. Option C is wrong because hourly snapshots give an RPO of up to 1 hour, which is greater than 5 minutes. Option D is wrong because daily snapshots give an RPO of up to 24 hours, also exceeding the requirement.

58
MCQhard

A multinational company uses Google Cloud and needs to ensure that its data cannot be exfiltrated to unauthorized networks even if an attacker obtains valid IAM credentials. The security team wants to define a boundary around specific projects and restrict access to only approved VPC networks and services. Which GCP feature should they implement?

A.VPC firewall rules with egress deny
B.Cloud Armor security policies
C.VPC Service Controls
D.Cloud Identity-Aware Proxy (IAP)
AnswerC

VPC Service Controls create a service perimeter around Google Cloud projects and resources, restricting access to only approved VPC networks and preventing data exfiltration even with valid credentials. This directly addresses the requirement to block exfiltration despite compromised IAM credentials, because the perimeter enforces context-aware access independent of IAM permissions.

Why this answer

VPC Service Controls establish a security perimeter around Google Cloud projects and services, restricting access to authorized VPC networks and preventing data exfiltration even when IAM credentials are compromised. The other options protect application access, VM egress, or edge traffic, none of which create the service-level boundary needed to stop API-based data movement.

Exam trap

The trap here is assuming that IAM and firewall rules are sufficient to stop exfiltration, when an attacker with valid credentials can use service APIs that bypass VPC-level controls unless a service perimeter is in place.

59
MCQeasy

Which of the following is a best practice for managing secrets in cloud applications?

A.Embed secrets in application code
B.Store secrets in environment variables
C.Use a cloud secrets manager with automatic rotation
D.Share secrets via email
AnswerC

A cloud secrets manager with automatic rotation satisfies the core requirement by storing credentials outside application code and rotating them on a defined schedule, limiting exposure if leaked. This removes hardcoded secrets from repositories and configuration files, which is the primary risk the question targets.

Why this answer

Using a cloud secrets manager with automatic rotation is the best practice because it centralizes secret storage, encrypts secrets at rest and in transit, and automates rotation to reduce the risk of credential leakage. Services like AWS Secrets Manager, Azure Key Vault, and Google Secret Manager provide fine-grained access control and audit logging, ensuring secrets are not exposed in code or configuration files.

Exam trap

CV0-004 often tests the misconception that environment variables are secure; candidates may choose them over a dedicated secrets manager, not realizing that environment variables can be exposed and lack rotation.

How to eliminate wrong answers

Option A is wrong because embedding secrets in application code exposes them in source control, build artifacts, and logs, making them vulnerable to unauthorized access. Option B is wrong because environment variables can be inadvertently exposed through debugging interfaces, process listings, or logs, and they lack encryption and rotation capabilities. Option D is wrong because sharing secrets via email is insecure, as email is often unencrypted and can be intercepted or accessed by unauthorized parties.

60
MCQeasy

A cloud administrator needs to monitor CPU utilization of a group of virtual machines and automatically add more instances when utilization exceeds 80% for 5 minutes. Which cloud service should the administrator use to define this scaling policy?

A.Configuration management service
B.Audit logging service
C.Auto scaling service
D.Systems management service
AnswerC

Auto scaling service continuously evaluates metrics such as CPU utilisation against thresholds you define, then adds instances when the 80%-for-5-minutes condition is met. It satisfies the stem's requirement for automatic horizontal scaling driven by monitored performance data, unlike monitoring-only or load-balancing services.

Why this answer

An auto scaling service is purpose-built to define scaling policies based on metrics such as CPU utilization, with thresholds and duration windows (e.g., >80% for 5 minutes) that trigger adding or removing instances. It integrates with CloudWatch-style alarms and launch templates to automatically adjust capacity.

Exam trap

The trap is selecting a monitoring or systems management service because it 'watches' metrics, when the question requires a service that actually acts on those metrics to change capacity.

How to eliminate wrong answers

Option A is wrong because configuration management services enforce desired-state configuration (e.g., Ansible, AWS Systems Manager State Manager) and do not perform metric-driven capacity scaling. Option B is wrong because audit logging services record API activity for compliance and forensics; they do not react to utilization metrics. Option D is wrong because systems management services handle patching, inventory, and remote administration, not dynamic capacity adjustment based on performance thresholds.

61
MCQhard

An organization uses AWS and wants to control inbound traffic to its EC2 instances. They need a solution that automatically allows response traffic for any permitted inbound request. Which of the following should they use?

A.DDoS protection
B.Web Application Firewall
C.Security groups
D.Network ACLs
AnswerC

Security groups are stateful: they automatically permit return traffic for any inbound connection you allow, so no separate outbound rule is needed. This satisfies the requirement that response traffic be allowed automatically. Network ACLs are stateless and would require explicit inbound and outbound rules.

Why this answer

AWS security groups are stateful virtual firewalls that automatically allow return traffic for any permitted inbound request, regardless of outbound rules. This stateful behavior means that if an inbound request is allowed, the response is automatically permitted, satisfying the requirement. Network ACLs, by contrast, are stateless and require explicit rules for both directions.

Exam trap

The trap is confusing security groups with network ACLs; candidates often pick NACLs because they sound like firewalls, but only security groups are stateful and automatically allow return traffic for permitted inbound requests.

How to eliminate wrong answers

Option A is wrong because DDoS protection (e.g., AWS Shield) mitigates volumetric attacks and does not control per-instance inbound traffic or manage return traffic. Option B is wrong because a Web Application Firewall (AWS WAF) filters HTTP/HTTPS requests at layer 7 based on web exploit patterns, not general inbound traffic with automatic return traffic handling. Option D is wrong because Network ACLs are stateless — they require separate inbound and outbound rules, so return traffic is not automatically allowed unless explicitly configured.

62
MCQmedium

A cloud administrator is deploying a containerized workload to Google Kubernetes Engine. The workload must automatically scale based on the number of incoming HTTP requests per second rather than CPU utilization. Which GKE feature should the administrator configure to meet this requirement?

A.GKE Autopilot mode with burst scaling enabled
B.Vertical Pod Autoscaler in recommendation mode
C.Cluster Autoscaler with node pool autoscaling enabled
D.Horizontal Pod Autoscaler with a custom metric from Cloud Monitoring
AnswerD

The Horizontal Pod Autoscaler supports autoscaling based on custom and external metrics, not just CPU or memory. By exporting requests-per-second to Cloud Monitoring and referencing it as a custom metric in the HPA specification, the administrator can scale pods directly on HTTP request rate, which matches the stated requirement.

Why this answer

The Horizontal Pod Autoscaler is the GKE mechanism that changes replica counts in response to metrics. By supplying a custom metric sourced from Cloud Monitoring that represents HTTP requests per second, the administrator can scale on request rate rather than CPU, which is exactly the workload signal described.

Exam trap

The trap here is assuming the Cluster Autoscaler scales application replicas, when it only adjusts the underlying node count in response to scheduling pressure.

63
MCQhard

A financial services company is subject to strict compliance requirements. They need to ensure that all cloud storage objects are written to a write-once-read-many (WORM) state for a defined retention period. Which feature should be enabled?

A.Versioning
B.Object lock
C.Replication
D.Lifecycle policies
AnswerB

Object lock enforces WORM protection by preventing object modification or deletion for a defined retention period, meeting the compliance requirement. It satisfies the write-once-read-many constraint directly at the storage-object level, unlike versioning or lifecycle rules.

Why this answer

Object Lock is the correct feature for WORM compliance because it enforces a write-once-read-many (WORM) state on objects, preventing modification or deletion until the specified retention period expires. Lifecycle policies manage data transitions and deletions but do not provide immutability guarantees required for strict compliance.

Exam trap

CompTIA often tests the distinction between features that manage object versions (versioning) versus those that enforce legal holds or retention (Object Lock). Candidates may incorrectly choose Lifecycle policies for compliance, but only Object Lock provides true WORM immutability.

How to eliminate wrong answers

Option A is wrong because versioning preserves multiple versions of an object but does not prevent deletion or overwrite of any version, so it cannot enforce a WORM state. Option B is wrong because object lock is the actual feature that enforces WORM, but it is not listed as an option; the question asks which feature should be enabled, and lifecycle policies are used to apply object lock settings automatically. Option C is wrong because replication copies objects to another bucket or region but does not impose any write-once-read-many restrictions on the source or destination objects.

64
MCQeasy

A cloud operations team is reviewing the shared responsibility model for a SaaS customer relationship management application. The team wants to document which security tasks remain the customer's responsibility. Which task is the customer responsible for under the shared responsibility model?

A.Patching the hypervisor that hosts the SaaS application's virtual machines.
B.Managing user identities, access permissions, and authentication policies within the SaaS application.
C.Maintaining the physical security controls at the data center hosting the SaaS platform.
D.Applying firmware updates to the storage arrays that back the SaaS application's database.
AnswerB

Identity and access management for the customer's own users remains a customer responsibility in every cloud service model, including SaaS. The provider secures the application infrastructure, but the customer decides who can log in, what roles they hold, and how authentication is enforced. Weak access controls on the customer side are a leading cause of SaaS data breaches.

Why this answer

Under the shared responsibility model, the provider secures the cloud infrastructure while the customer secures what they put in the cloud. For SaaS, that means the customer owns data classification, user identity, access management, and authentication configuration. Physical security, hypervisor patching, and hardware firmware all fall to the provider because they sit below the customer's reach.

Exam trap

The trap here is conflating infrastructure-layer duties such as hypervisor or firmware patching with customer duties, which in SaaS are limited to data and identity governance.

65
MCQhard

A cloud engineer is troubleshooting a containerized application deployed on a managed Kubernetes service. Pods are repeatedly failing to start with the status 'CrashLoopBackOff'. The engineer has confirmed that the container image exists and the pod specification is valid. Which command should the engineer use to view the most recent logs from the previous instance of the crashing container?

A.kubectl logs <pod-name> --previous
B.kubectl exec -it <pod-name> -- /bin/sh
C.kubectl describe pod <pod-name>
D.kubectl get events --field-selector involvedObject.name=<pod-name>
AnswerA

The --previous flag retrieves logs from the previous instance of a container in a pod that has restarted. In a CrashLoopBackOff scenario, the current container may not have produced logs yet, but the previous instance likely contains the error that caused the crash. This command is essential for diagnosing why the container is failing to start.

Why this answer

In a CrashLoopBackOff situation, the container is restarting repeatedly, so the current logs may be empty or incomplete. The --previous flag allows the engineer to access logs from the last terminated instance, which typically contains the error that led to the crash. This is the most direct way to diagnose application-level failures in Kubernetes.

Exam trap

The trap here is relying on kubectl describe or events for application logs, when the previous container instance's logs are the key to understanding the crash cause.

66
MCQeasy

A company needs to deploy a web application quickly and reliably. Which approach is best?

A.FTP the application to each server individually
B.Perform a blue-green deployment manually
C.Use a CI/CD pipeline with automated deployment
D.Manually copy the application files to the server
AnswerC

A CI/CD pipeline automates build, test and release stages, so each change is validated and deployed consistently with minimal manual intervention. This delivers the speed and reliability the scenario demands, unlike manual or ad hoc deployment methods.

Why this answer

A CI/CD pipeline with automated deployment is the best approach because it integrates code changes, runs tests, and deploys to production in a repeatable, auditable manner. This ensures speed, consistency, and rollback capability, which are critical for reliable web application deployment in a cloud or on-premises environment.

Exam trap

CompTIA Cloud+ emphasizes that while manual or semi-automated methods (like manual blue-green) may seem quick, they lack the repeatability, audit trails, and automated rollback that a full CI/CD pipeline provides. Candidates often overlook that 'quick and reliable' in the exam context specifically requires automation and consistency.

How to eliminate wrong answers

Option A is wrong because FTP is an unencrypted, manual file transfer protocol that lacks automation, version control, and rollback mechanisms, making it slow and error-prone for reliable deployment. Option B is wrong because performing a blue-green deployment manually introduces human error risk, lacks automated health checks, and does not provide the consistency of an automated pipeline. Option D is wrong because manually copying files to the server is error-prone, lacks versioning, and cannot ensure consistent configuration across environments, leading to configuration drift and deployment failures.

67
MCQhard

A financial services firm stores regulated customer records in an Amazon S3 bucket. Auditors require that every object be encrypted at rest with a customer-managed key, that key usage be logged, and that the firm be able to revoke access to the data by disabling the key. Which configuration meets these requirements?

A.Configure default bucket encryption with SSE-S3 and enable S3 server access logging on the bucket.
B.Configure default bucket encryption with SSE-KMS using an AWS-managed key and enable KMS key rotation every year.
C.Enable S3 Object Lock in compliance mode and require SSE-C headers on every PUT request.
D.Configure default bucket encryption with SSE-KMS using a customer-managed AWS KMS key and enable CloudTrail data events for the bucket.
AnswerD

SSE-KMS with a customer-managed key gives the firm control over the key, and disabling that key immediately blocks decryption of all objects, satisfying revocation. AWS KMS logs every cryptographic operation to CloudTrail, and enabling CloudTrail data events captures object-level API activity on the bucket, providing the required usage evidence for auditors.

Why this answer

The scenario demands a customer-managed key that the firm can disable to revoke access, plus logging of key usage. SSE-KMS with a customer-managed AWS KMS key satisfies the key control because disabling the key blocks decryption, and CloudTrail captures KMS cryptographic operations as well as S3 data events. AWS-managed keys, SSE-S3, and SSE-C all lack the customer-controlled revocation and audit characteristics required.

Exam trap

The trap here is treating any server-side encryption as equivalent, when only a customer-managed KMS key can be disabled to revoke data access and is fully logged.

68
MCQeasy

A company is migrating a legacy application to the cloud. The application uses a fixed IP address that is hard-coded in several clients. The company needs to ensure the IP address remains the same even if the underlying virtual machine is replaced. Which cloud networking feature should be used?

A.A content delivery network (CDN) distribution with a custom domain.
B.A dynamic host configuration protocol (DHCP) reservation.
C.A static private IP address assigned manually to the virtual machine.
D.An elastic IP address that can be associated with a different virtual machine.
AnswerD

An elastic IP address is a static public IPv4 address designed for dynamic cloud computing. It can be associated with any virtual machine in the account and moved between instances if a failure occurs. This allows clients that use the hard-coded IP to continue reaching the application even after the underlying virtual machine is replaced, satisfying the requirement for a stable public endpoint.

Why this answer

An elastic IP address is a static public IP that can be reassigned to another virtual machine. This allows the application to keep the same public endpoint even when the underlying instance is replaced, which is essential when clients have the IP hard-coded. DHCP reservations and static private IPs are limited to private networks and do not provide a movable public address.

Exam trap

The trap here is assuming that a static private IP or a DHCP reservation provides a public IP that can be moved, when only an elastic IP offers that capability.

69
MCQmedium

An organization is designing a disaster recovery plan with a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 1 hour. Which disaster recovery strategy best meets these requirements while minimizing cost?

A.Cold standby
B.Backup and restore
C.Warm standby
D.Hot standby
AnswerC

Warm standby satisfies the 4-hour RTO through pre-provisioned, scaled-down infrastructure that can be promoted quickly, while continuous data replication keeps the 1-hour RPO. It costs less than hot standby's fully mirrored active environment, avoiding the expense of duplicate capacity the RTO does not demand.

Why this answer

Warm standby maintains a partially running environment that can be fully activated quickly, meeting an RTO of 4 hours and RPO of 1 hour at a lower cost than hot standby.

70
MCQmedium

A company wants to reduce costs by identifying underutilized EC2 instances and receiving recommendations to downsize them. Which AWS service provides rightsizing recommendations based on historical utilization metrics?

A.AWS Cost Explorer
B.AWS Trusted Advisor
C.AWS Auto Scaling
D.AWS Compute Optimizer
AnswerD

AWS Compute Optimizer analyses historical utilisation metrics—such as CPU, memory, and network throughput—from Amazon CloudWatch to generate rightsizing recommendations for EC2 instances. This directly satisfies the company’s requirement to identify underutilised instances and receive downsizing suggestions, as the service uses machine learning to compare observed usage against instance family specifications and outputs specific instance type changes.

Why this answer

AWS Compute Optimizer analyzes historical utilization metrics of EC2 instances and provides rightsizing recommendations to downsize underutilized instances, helping reduce costs. It uses machine learning to generate recommendations based on CPU, memory, and other metrics.

Exam trap

CV0-004 often tests cost optimization tools, and candidates might confuse Compute Optimizer with Trusted Advisor or Cost Explorer, especially regarding rightsizing recommendations.

How to eliminate wrong answers

Option A is wrong because AWS Cost Explorer is for visualizing and managing costs, but it does not provide rightsizing recommendations. Option B is wrong because AWS Trusted Advisor offers best practice checks, including cost optimization, but its rightsizing recommendations are limited and not as detailed as Compute Optimizer's. Option C is wrong because AWS Auto Scaling automatically adjusts capacity based on demand, but it does not provide recommendations to downsize instances.

71
MCQhard

A multinational enterprise uses Amazon Route 53 for public DNS. A recent incident showed that an attacker changed a registrar's nameserver delegation and redirected traffic to a malicious site. The security team wants to detect unauthorized changes to DNS records and receive alerts when records are modified outside the change-management process. Which combination should the team implement?

A.Enable Route 53 query logging and create a CloudWatch alarm on the number of NXDOMAIN responses.
B.Create a Route 53 Resolver query log configuration and export logs to Amazon S3 for long-term retention.
C.Enable AWS CloudTrail and create an EventBridge rule that matches Route 53 ChangeResourceRecordSets API calls and routes them to an alerting target.
D.Configure DNSSEC signing on the hosted zone and publish the DS record with the registrar.
AnswerC

Route 53 record changes are control-plane operations recorded by CloudTrail, including the caller identity, source IP, and request parameters. An EventBridge rule that matches the ChangeResourceRecordSets event pattern can trigger an SNS topic or ticketing system immediately, giving the team detection and alerting for out-of-process modifications.

Why this answer

Detecting unauthorized record modification requires visibility into the Route 53 control plane. CloudTrail records ChangeResourceRecordSets calls with the identity and parameters, and an EventBridge rule matching that event pattern can alert the team in near real time. Query logging, Resolver logs, and DNSSEC address resolution behavior or response integrity rather than change detection and alerting.

Exam trap

The trap here is equating DNS query logging with change monitoring, when only CloudTrail captures the API calls that actually modify records.

72
Multi-Selecthard

A company is deploying a web application on GCP and needs to protect against OWASP Top 10 threats and DDoS attacks. Which THREE services should be combined to provide comprehensive protection?

Select 3 answers
A.Cloud Load Balancing
B.Cloud NAT
C.Cloud CDN
D.Cloud VPN
E.Cloud Armor
AnswersA, C, E

Distributes traffic and integrates with Cloud Armor.

Why this answer

Cloud Load Balancing (A) is correct because it distributes incoming traffic across multiple backend instances, providing inherent DDoS resilience by absorbing and scaling with attack traffic. It also integrates directly with Cloud Armor to enforce OWASP Top 10 web application firewall (WAF) rules, such as SQL injection and XSS protections, at the edge before traffic reaches the application.

Exam trap

The trap here is that candidates often confuse similar network services (like NAT gateways or VPN gateways) as security services for inbound traffic, but they are designed for outbound connectivity and encrypted tunnels, not for application-layer threat detection or DDoS mitigation.

73
MCQeasy

An administrator is configuring a backup policy for a critical application database. The policy must allow point-in-time recovery up to the last 5 minutes. The database is updated continuously throughout the day. Which of the following backup strategies BEST meets the requirement?

A.Weekly full backups with daily differential backups.
B.Hourly snapshots of the virtual machine.
C.Daily full backups plus transaction log backups every 5 minutes.
D.Daily full backups of the database.
AnswerC

Transaction log backups capture every committed change, so replaying them after a full restore achieves recovery to within five minutes. Continuous database updates demand this log-based approach; full backups alone leave up to a day of data loss, failing the point-in-time requirement.

Why this answer

It combines daily full backups with transaction log backups every 5 minutes, which is the only strategy that supports point-in-time recovery (PITR) to within 5 minutes for a continuously updated database. Transaction log backups capture every committed transaction, allowing restoration to any specific point in time by replaying logs from the last full backup.

Exam trap

The trap here is that candidates often confuse crash-consistent snapshots (Option B) with application-consistent backups, failing to realize that VM snapshots do not capture transaction log details needed for precise point-in-time recovery of a database.

How to eliminate wrong answers

Option A is wrong because weekly full backups with daily differential backups only allow recovery to the state at the time of the last differential backup, not to arbitrary points within the last 5 minutes. Option B is wrong because hourly snapshots of the virtual machine are crash-consistent, not application-consistent, and cannot guarantee point-in-time recovery of the database to within 5 minutes due to the snapshot interval and lack of transaction log granularity. Option D is wrong because daily full backups alone provide no granularity for recovery between backup intervals, making point-in-time recovery to the last 5 minutes impossible.

74
MCQmedium

A cloud engineer is deploying a web application that requires SSL termination and content-based routing. Which type of load balancer should be used?

A.Gateway Load Balancer
B.Classic Load Balancer
C.Application Load Balancer
D.Network Load Balancer
AnswerC

An Application Load Balancer operates at layer 7, terminating TLS and routing requests by URL path, host header or content. Network load balancers work at layer 4, forwarding packets by IP and port only, so they cannot inspect content or terminate SSL.

Why this answer

An Application Load Balancer (layer 7) can perform SSL termination and route based on content such as URL paths or host headers.

75
MCQeasy

An organization requires that all cloud resources be tagged with the cost center and environment (e.g., production, development). A compliance checker runs weekly to report untagged resources. The cloud administrator notices that newly created resources are often missing tags. What is the most effective long-term solution?

A.Configure a cloud governance policy that prevents resource creation without required tags.
B.Create a custom dashboard to show untagged resources.
C.Run a script daily to tag any untagged resources.
D.Send an email reminder to all users about tagging policies.
AnswerA

A governance policy enforcing tag requirements at creation time prevents untagged resources from ever existing, satisfying the compliance checker's requirement rather than detecting violations after the fact. Weekly reporting only identifies drift retrospectively; blocking creation addresses the root cause, ensuring cost center and environment tags are present on all resources long term.

Why this answer

The most effective long-term solution is to prevent non-compliant resource creation in the first place, which is what a governance policy (e.g., AWS Organizations SCP, Azure Policy, or GCP Org Policy) does by denying creation of resources without required tags. Detection and remediation after the fact are reactive and leave gaps. Prevention enforces the standard at the control plane, so untagged resources never exist.

Exam trap

CV0-004 often tests the difference between detective controls (dashboards, reports, scripts) and preventive controls (policies that block creation); candidates who focus on 'fixing' untagged resources pick C or B instead of the preventive policy in A.

How to eliminate wrong answers

Option B is wrong because a dashboard only visualizes the problem — it detects untagged resources but does nothing to prevent them, so the weekly compliance report will keep showing violations. Option C is wrong because a daily tagging script is reactive remediation: it leaves a window (up to 24 hours) where resources are untagged and non-compliant, and it may tag resources incorrectly if the script guesses values. Option D is wrong because email reminders rely on human behavior and have no enforcement mechanism; awareness campaigns reduce but do not eliminate violations, so they are not a long-term solution.

Page 1 of 12

Page 2