Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 676–750

834 questions total · 12pages · All types, answers revealed

Page 9

Page 10 of 12

Page 11
676
MCQmedium

An organization is designing a cloud architecture that must be fault-tolerant within a single region. The architect decides to deploy application instances in multiple Availability Zones (AZs). Which cloud characteristic is being leveraged?

A.Resource pooling
B.Measured service
C.Elasticity
D.On-demand self-service
AnswerA

Resource pooling allows the provider to serve multiple customers and distribute resources across AZs for fault tolerance.

Why this answer

Deploying application instances across multiple Availability Zones (AZs) within a single region leverages resource pooling, a key cloud characteristic. Resource pooling allows the cloud provider to aggregate compute, storage, and network resources from multiple physical locations (AZs) into a shared pool that can be dynamically allocated to tenants. By distributing instances across AZs, the architect ensures that if one AZ fails, the application remains available using resources from other AZs, directly utilizing the provider's pooled infrastructure.

Exam trap

CompTIA often tests the distinction between resource pooling and elasticity, where candidates mistakenly think distributing across AZs is about scaling (elasticity) rather than leveraging the provider's shared physical infrastructure (resource pooling).

How to eliminate wrong answers

Option B (Measured service) is wrong because it refers to the metering and billing of cloud resource usage (e.g., per-hour or per-GB charges), not the architectural placement of instances across AZs for fault tolerance. Option C (Elasticity) is wrong because elasticity describes the ability to automatically scale resources up or down based on demand, not the geographic or fault-isolated distribution of instances. Option D (On-demand self-service) is wrong because it describes the ability to provision resources without human interaction via a web portal or API, not the multi-AZ deployment strategy for high availability.

677
MCQmedium

A cloud administrator needs to provide external partners with access to a cloud application using their existing corporate credentials. Which federation protocol should be used?

A.RADIUS
B.Kerberos
C.SAML
D.LDAP
AnswerC

SAML exchanges signed assertions between the partner's identity provider and the cloud application, letting partners authenticate with existing corporate credentials. It is the established browser-based federation standard for external access, avoiding separate accounts for each partner.

Why this answer

SAML (Security Assertion Markup Language) is the standard federation protocol for web-based single sign-on, allowing external partners to authenticate with their own corporate identity provider and access a cloud application via trust relationships. It exchanges XML-based assertions between an identity provider and a service provider. This matches the requirement of using existing corporate credentials for external access.

Exam trap

The trap is selecting LDAP or Kerberos because they are familiar authentication technologies; candidates overlook that federation across organizational boundaries to a cloud app specifically requires SAML (or OIDC), not directory or network authentication protocols.

How to eliminate wrong answers

Option A is wrong because RADIUS is an AAA protocol used primarily for network access authentication (VPN, Wi-Fi, dial-up), not for web application federation or cross-domain SSO. Option B is wrong because Kerberos is a ticket-based authentication protocol designed for intra-domain use within a trusted realm (e.g., Active Directory), not for federating identities across organizational boundaries to cloud apps. Option D is wrong because LDAP is a directory access protocol for querying and modifying directory services; it does not provide the federated trust and assertion exchange needed for cross-organization SSO.

678
MCQmedium

A cloud engineer is deploying a new version of an application to an Amazon ECS cluster using the rolling update deployment type. The engineer wants to ensure that the new version is deployed without downtime and that the old tasks are terminated only after the new tasks are healthy. Which parameter should the engineer configure?

A.Set the task placement strategy to spread across Availability Zones.
B.Set the minimum healthy percent to 100 and the maximum percent to 200.
C.Set the deployment circuit breaker to enabled with rollback.
D.Set the minimum healthy percent to 50 and the maximum percent to 100.
AnswerB

With a minimum healthy percent of 100, ECS ensures that the number of running tasks never drops below the desired count during deployment. The maximum percent of 200 allows ECS to launch additional tasks beyond the desired count, enabling new tasks to start and become healthy before old ones are stopped. This achieves zero-downtime deployment.

Why this answer

For a rolling update on Amazon ECS, the deployment configuration's minimum healthy percent and maximum percent control how many tasks must remain running and how many extra tasks can be launched. Setting minimum healthy percent to 100 and maximum percent to 200 ensures that the desired number of tasks is always running while allowing new tasks to start and become healthy before old tasks are terminated, thus achieving zero downtime.

Exam trap

The trap here is confusing the deployment circuit breaker with the parameters that control the rolling update strategy; the circuit breaker only handles rollbacks on failure.

679
MCQhard

A cloud engineer is designing a CI/CD pipeline using Azure DevOps. They need to ensure that code changes are automatically built, tested, and deployed to a staging environment, and then after manual approval, deployed to production. Which pipeline configuration should they use?

A.Multi-stage pipeline with environment approvals on the production stage
B.Single stage pipeline with conditional deployment
C.Release pipeline with continuous deployment trigger
D.Build pipeline only
AnswerA

A multi-stage pipeline separates build, test, staging and production into discrete stages, and environment approvals gate the production stage so deployment waits for manual sign-off. This satisfies both the automated staging deployment and the approval-before-production constraint.

Why this answer

Azure DevOps multi-stage pipelines allow defining stages such as build, test, and deploy, with gates and approvals. An approval gate on the production stage ensures manual review before deployment.

680
MCQmedium

A cloud engineer is troubleshooting a network connectivity issue between two VPCs in AWS. To analyze traffic patterns and identify dropped packets, which feature should be enabled?

A.VPC Flow Logs
B.AWS CloudTrail
C.Amazon Inspector
D.AWS X-Ray
AnswerA

VPC Flow Logs capture IP traffic metadata for network interfaces, subnets or VPCs, recording accepted and rejected packets. Enabling them on the affected interfaces lets the engineer analyse traffic patterns and pinpoint where packets are dropped between the two VPCs.

Why this answer

VPC Flow Logs capture information about IP traffic going to and from network interfaces in a VPC, useful for troubleshooting connectivity and security issues.

681
MCQhard

A cloud engineer is deploying a containerized application on Amazon EKS. The application pods need to access an Amazon RDS database. The security team wants to avoid storing database credentials in the container image or environment variables and prefers short-lived credentials. Which mechanism should be used?

A.AWS Secrets Manager with IAM roles for service accounts (IRSA)
B.Kubernetes Secrets mounted as environment variables
C.AWS Systems Manager Parameter Store with SecureString parameters
D.Amazon RDS IAM database authentication with a static master password
AnswerA

IAM roles for service accounts (IRSA) allows Kubernetes pods to assume an IAM role and obtain temporary credentials. The pod can then retrieve the database secret from AWS Secrets Manager using those credentials, avoiding hardcoded secrets. This provides short-lived credentials and fine-grained access control, directly meeting the security team's requirements for the EKS application.

Why this answer

IAM roles for service accounts (IRSA) enables EKS pods to assume an IAM role and receive temporary credentials. The pod can then access AWS Secrets Manager to retrieve the database secret dynamically, eliminating hardcoded credentials. This approach provides short-lived credentials and adheres to the security team's preference for avoiding static secrets in the container environment.

Exam trap

The trap here is believing that Kubernetes Secrets or Parameter Store alone solve credential management, when they still require a secure, short-lived identity to access them.

682
MCQeasy

After deploying a new cloud application, users report that they cannot connect to the application. The cloud administrator checks the security group rules and finds that the inbound rule for HTTP traffic is missing. What is the best practice to prevent this issue in future deployments?

A.Create a checklist for manual review before each deployment.
B.Use an Infrastructure as Code (IaC) template to define security group rules.
C.Clone a security group that already has the correct rules.
D.Configure the security group to allow all traffic by default.
AnswerB

An IaC template declares security group rules as version-controlled code, so required inbound HTTP rules are provisioned consistently and repeatably with every deployment. This eliminates the manual omission that caused the outage, satisfying the best-practice requirement to prevent missing rules in future deployments.

Why this answer

Using an Infrastructure as Code (IaC) template to define security group rules ensures that the required inbound HTTP rule is codified, version-controlled, and automatically applied in every deployment. This eliminates human error and enforces consistency across environments. IaC tools like Terraform, CloudFormation, or ARM templates allow you to declare the desired state, so missing rules are caught during deployment or CI/CD validation.

Exam trap

CV0-004 often tests the confusion between reactive manual fixes (checklists, cloning) and proactive automated solutions (IaC), expecting candidates to recognize that IaC is the best practice for preventing configuration drift and human error.

How to eliminate wrong answers

Option A is wrong because a manual checklist still relies on human review and is prone to oversight, especially under time pressure or across many deployments; it does not prevent the issue, only attempts to catch it. Option C is wrong because cloning an existing security group may work for a one-off, but it is not a repeatable best practice and can propagate stale or overly permissive rules; it lacks the declarative, versioned nature of IaC. Option D is wrong because allowing all traffic by default violates the principle of least privilege and creates a severe security risk, far worse than the original missing rule.

683
MCQmedium

A cloud administrator is designing a backup strategy for a critical database. The recovery point objective (RPO) is 15 minutes, and the recovery time objective (RTO) is 1 hour. Which backup approach BEST meets these objectives?

A.Take a full backup once a day and store it in a different region.
B.Enable continuous transaction log shipping to a standby database in another availability zone.
C.Take a snapshot every hour and copy it to object storage.
D.Rely on the cloud provider's built-in redundancy within a single availability zone.
AnswerB

Continuous transaction log shipping replicates every committed transaction to a standby database, achieving an RPO of near zero or within minutes. If the primary fails, the standby can be promoted, and recovery time is typically well under an hour. This meets both the 15-minute RPO and the 1-hour RTO, providing a robust disaster recovery solution.

Why this answer

Continuous transaction log shipping provides near-real-time replication, ensuring that the standby database is always up to date. This achieves an RPO of minutes or less, well within the 15-minute requirement. In the event of a failure, the standby can be promoted quickly, meeting the 1-hour RTO.

Daily or hourly backups are too infrequent for the RPO, and single-zone redundancy does not provide disaster recovery.

Exam trap

The trap here is confusing high availability within a zone with disaster recovery, when only continuous replication to a separate location can meet a tight RPO.

684
MCQmedium

A company runs a web application on three virtual machines behind a load balancer. During a traffic spike, one VM becomes unresponsive. The load balancer continues sending traffic to it, causing errors. Which configuration change would prevent this issue in the future?

A.Set a longer connection timeout on the load balancer.
B.Configure health checks on the load balancer.
C.Increase the number of VMs to five.
D.Change the load balancing algorithm to round-robin.
AnswerB

Health checks probe each backend and remove failing instances from rotation, so an unresponsive VM stops receiving traffic. This directly addresses the stem's constraint that the load balancer kept sending traffic to the failed VM.

Why this answer

Health checks allow the load balancer to periodically probe the status of each backend VM (e.g., via HTTP GET or TCP SYN). If a VM fails a configurable number of consecutive checks, the load balancer automatically marks it as unhealthy and stops routing traffic to it, preventing errors during a spike. This is the standard mechanism in AWS ELB, Azure Load Balancer, and HAProxy to detect and isolate failed instances.

Exam trap

CompTIA often tests the misconception that simply adding more servers or changing the algorithm solves availability issues, when in fact without health checks the load balancer has no mechanism to detect and avoid failed instances.

How to eliminate wrong answers

Option A is wrong because a longer connection timeout would only delay the detection of an unresponsive VM, not prevent traffic from being sent to it; the load balancer would still forward new requests and wait longer for a response, increasing user-facing errors. Option C is wrong because simply increasing the number of VMs does not address the root cause—the load balancer will still blindly send traffic to an unresponsive VM, so errors persist regardless of pool size. Option D is wrong because changing the algorithm to round-robin does not include any failure detection; it merely distributes requests evenly, so an unresponsive VM will still receive its share of traffic and cause errors.

685
MCQmedium

A company is designing a disaster recovery plan for its critical application. The application must be recovered within 4 hours (RTO) and can tolerate up to 1 hour of data loss (RPO). Which replication strategy is most cost-effective?

A.No replication; rely on backups restored from archive
B.Asynchronous replication
C.Synchronous replication
D.Daily snapshots with no replication
AnswerB

Asynchronous replication copies changes after acknowledgement, so a site can lag by up to an hour — matching the one-hour RPO — while costing far less than synchronous replication, which would need low-latency links to meet a near-zero RPO the business does not require.

Why this answer

Asynchronous replication meets the RPO of 1 hour (data loss up to 1 hour) and can be lower cost than synchronous replication, which requires high bandwidth. Synchronous replication would be more expensive and unnecessary. No replication would not meet RPO.

Daily backups would exceed RPO.

686
MCQhard

A cloud engineer is deploying a stateful application on Amazon EKS. The application requires persistent storage that must be highly available and automatically replicated across multiple Availability Zones. The engineer needs to define the storage class in Kubernetes. Which storage class provisioner should be used?

A.fsx.csi.aws.com with Lustre
B.efs.csi.aws.com
C.ebs.csi.aws.com with volume type io1
D.local.csi.aws.com
AnswerB

Amazon EFS is a managed file system that provides shared, elastic storage across multiple Availability Zones. The EFS CSI driver allows Kubernetes to dynamically provision persistent volumes backed by EFS, which is automatically replicated across AZs within a region. This makes it ideal for stateful applications requiring high availability and multi-AZ resilience.

Why this answer

Amazon EFS, accessed via the EFS CSI driver, is the correct choice for persistent storage that is automatically replicated across multiple Availability Zones. It provides a shared file system that can be mounted by multiple pods across AZs, ensuring high availability. Other options either are single-AZ, not replicated, or ephemeral.

Exam trap

The trap here is assuming that high-performance block storage like EBS or FSx automatically provides multi-AZ replication, when in fact they are typically tied to a single AZ unless configured otherwise.

687
Multi-Selectmedium

A company is designing an auto-scaling solution for a stateless application. Which TWO features are essential for the application to scale horizontally without issues? (Select TWO.)

Select 2 answers
A.Stateless application design
B.Stateful session management
C.Use of local storage for application data
D.Vertical scaling on the existing instances
E.A load balancer to distribute traffic
AnswersA, E

Stateless application design ensures no session or local data persists on individual instances, so any instance can handle any request. This removes the need for sticky sessions or instance-specific state, directly enabling horizontal scaling and safe termination during scale-in events.

Why this answer

Horizontal scaling requires that the application is stateless, meaning no session data is stored locally on instances, so any instance can handle any request. A load balancer is essential to distribute incoming traffic across multiple instances, ensuring no single instance is overwhelmed and that requests can be sent to any available instance. In contrast, stateful session management (B) and local storage (C) would tie data to specific instances, preventing seamless scaling.

Vertical scaling (D) is about increasing resources of existing instances, not adding more instances horizontally.

688
MCQmedium

A company is migrating an on-premises MySQL database to Azure SQL Database using Azure Database Migration Service. They want minimal downtime. Which migration mode should they choose?

A.Bulk copy
B.Offline migration
C.Online migration with continuous sync
D.Schema conversion only
AnswerC

Online migration with continuous sync keeps the source MySQL database available whilst replicating ongoing changes to Azure SQL Database, then performs a brief cutover. This directly satisfies the minimal-downtime constraint, unlike offline migration, which requires the source to be taken offline for the entire data copy.

Why this answer

Azure DMS offers online migration mode that uses CDC to replicate ongoing changes, allowing near-zero downtime. Offline mode requires stopping writes during migration.

689
MCQeasy

An organization wants to deploy a new application with zero downtime by switching traffic between two identical production environments. Which deployment strategy should be used?

A.Rolling deployment
B.Canary deployment
C.In-place deployment
D.Blue/green deployment
AnswerD

Blue/green deployment maintains two identical production environments and switches traffic at the load balancer or DNS layer once the new version is verified. Because cutover is atomic and rollback is immediate, users experience no downtime during release.

Why this answer

Blue/green deployment maintains two identical production environments (blue and green) and switches traffic from one to the other, typically via a load balancer or DNS cutover. This provides near-zero downtime and instant rollback by simply redirecting traffic back to the previous environment if issues arise.

Exam trap

CV0-004 often tests the confusion between blue/green and canary — candidates pick canary because both reduce risk, but only blue/green provides an instant full cutover and rollback via environment switching.

How to eliminate wrong answers

Option A is wrong because rolling deployment replaces instances incrementally within the same environment, which can cause version skew and does not provide an instant rollback path. Option B is wrong because canary deployment routes a small percentage of traffic to the new version for validation, which is gradual rather than a full cutover and does not guarantee zero downtime during the ramp. Option C is wrong because in-place deployment updates the existing environment directly, causing downtime and offering no easy rollback.

690
MCQeasy

A cloud administrator needs to provide a shared file system that can be accessed by multiple Linux-based virtual machines in the same VPC. Which storage type should be used?

A.Object storage
B.Archive storage
C.Block storage
D.File storage
AnswerD

File storage provides a shared, POSIX-compliant file system mountable concurrently by multiple Linux instances within the same VPC, matching the requirement. Block storage attaches to a single instance, and object storage lacks native shared-mount semantics.

Why this answer

File storage provides a shared, hierarchical file system (e.g., NFS, SMB) that multiple Linux VMs in the same VPC can mount simultaneously, making it ideal for shared access. In AWS, this is Amazon EFS (Elastic File System), which supports concurrent NFS mounts across EC2 instances. Block and object storage do not natively provide a shared POSIX file system for multiple Linux hosts.

Exam trap

The trap is assuming block storage (EBS) can be shared like a file system, or that object storage (S3) is a drop-in shared file system — the exam expects recognition that 'shared file system across multiple Linux VMs' maps to file storage (EFS/NFS).

How to eliminate wrong answers

Option A is wrong because object storage (e.g., S3) uses a flat namespace with HTTP APIs and is not mountable as a standard POSIX file system across multiple Linux VMs without additional layers (e.g., s3fs), which is not the intended shared file system solution. Option B is wrong because archive storage (e.g., S3 Glacier) is for long-term, infrequent access with high retrieval latency, not shared active file access. Option C is wrong because block storage (e.g., EBS) attaches to a single EC2 instance (or cluster-aware setups) and does not natively provide a shared file system across multiple VMs.

691
Multi-Selectmedium

Which TWO factors should be considered when selecting a cloud region for deploying a globally distributed application to minimize latency?

Select 2 answers
A.Geographic proximity to target user base
B.Number of available virtual machine sizes
C.Presence of multiple Availability Zones
D.Local tax rate for cloud services
E.Availability of edge caching services (CDN)
AnswersA, E

Placing resources in a region geographically close to the target user base shortens the physical network path, directly reducing round-trip latency. This satisfies the stem's latency-minimisation goal for a globally distributed application, since propagation delay scales with distance.

Why this answer

Option A is correct because network round-trip time is dominated by physical distance; placing the region geographically close to the target user base reduces propagation delay and thus latency for those users. Option E is correct because edge caching services (CDN) push content to points of presence near end users, so the availability of such services in or around a region lets static and cacheable content be served from the edge rather than traversing back to the origin region, further minimizing perceived latency. Options B, C, and D do not belong: the number of available VM sizes (B) affects compute flexibility and cost, not network latency; multiple Availability Zones (C) provide fault tolerance and high availability within a region, not latency reduction; and the local tax rate (D) is a cost/compliance consideration with no bearing on network performance.

Exam trap

Candidates often incorrectly assume that multiple Availability Zones reduce latency, but AZs primarily provide high availability and disaster recovery, not latency reduction.

692
MCQhard

An organization must comply with a regulation requiring that all data stored in the cloud be encrypted at rest using a cloud provider's native encryption service. The company also needs to maintain control over the encryption keys. Which solution should the architect recommend?

A.Use the cloud provider's native encryption service with customer-managed keys
B.Encrypt the data on-premises before uploading to the cloud
C.Use the cloud provider's default encryption with provider-managed keys
D.Use a third-party hardware security module (HSM) hosted on-premises
AnswerA

The provider's native encryption service satisfies the mandate for cloud-native encryption at rest, while customer-managed keys retain organisational control over key material. This combination meets both the regulatory encryption requirement and the key-ownership constraint without relying on provider-held keys.

Why this answer

The regulation requires cloud-native encryption at rest with customer-controlled keys. Cloud providers offer services like AWS KMS with customer-managed keys (CMKs) or Azure Key Vault with customer-managed keys, which allow the organization to create, rotate, and disable keys independently while the provider handles the underlying encryption of data at rest using envelope encryption. This satisfies both the 'native encryption service' and 'maintain control over the encryption keys' requirements.

Exam trap

CompTIA often tests the distinction between 'native encryption service' and 'encryption at rest'—candidates mistakenly think any encryption (like client-side or third-party HSM) satisfies the requirement, but the question explicitly demands the cloud provider's native service with customer-managed keys.

How to eliminate wrong answers

Option B is wrong because encrypting data on-premises before upload does not use the cloud provider's native encryption service, violating the explicit requirement to use the provider's service. Option C is wrong because provider-managed keys mean the cloud provider controls the encryption keys, which fails the requirement that the company maintain control over the keys. Option D is wrong because a third-party HSM hosted on-premises is not a cloud provider's native encryption service, and it introduces additional complexity and latency without meeting the 'native service' mandate.

693
MCQeasy

A cloud administrator is tasked with monitoring CPU utilization across a fleet of virtual machines. Which cloud service should be used to collect and visualize this metric?

A.Cloud monitoring service
B.Audit logging service
C.Configuration management service
D.Advisor or optimization service
AnswerA

A cloud monitoring service ingests metrics such as CPU utilisation from VM agents and hypervisor APIs, then stores and visualises them in dashboards. It satisfies the requirement to collect and visualise CPU metrics across the fleet, unlike compute or storage services that do not provide metric aggregation.

Why this answer

A cloud monitoring service is specifically designed to collect, aggregate, and visualize performance metrics like CPU utilization from virtual machines and other resources. It provides time-series data storage, dashboards, and alerting capabilities, making it the correct tool for this task. Other services focus on different operational aspects such as logging, configuration, or recommendations, not real-time metric collection and visualization.

Exam trap

CV0-004 often tests the distinction between monitoring (metrics) and logging (events), so candidates may confuse audit logging with performance monitoring, especially when both are used for operational visibility.

How to eliminate wrong answers

Option B is wrong because an audit logging service records API activity and user actions for compliance and security analysis, not performance metrics like CPU utilization. Option C is wrong because a configuration management service automates the deployment and management of resource configurations, but does not collect or visualize runtime performance data. Option D is wrong because an advisor or optimization service analyzes resource usage to provide recommendations, but it does not directly collect or visualize raw metrics; it relies on monitoring data.

694
MCQeasy

A company wants to move its on-premises web application to the cloud with minimal code changes to reduce risk. Which deployment strategy is most appropriate?

A.Refactor
B.Rehost
C.Replatform
D.Rebuild
AnswerB

Rehosting lifts the application onto cloud infrastructure unchanged, satisfying the minimal-code-change constraint. Unlike replatforming or refactoring, which demand modification, rehosting preserves the existing codebase and configuration, reducing migration risk and effort. This makes it the most appropriate strategy when code changes must be avoided.

Why this answer

The Rehost (lift-and-shift) strategy is most appropriate because it moves the on-premises web application to the cloud with minimal code changes, directly reducing risk. By migrating the existing virtual machines or physical servers to cloud instances (e.g., AWS EC2 or Azure VMs) without modifying the application architecture, the company preserves the current codebase and operational behavior. This approach avoids the complexity and potential errors associated with rewriting or refactoring code, making it the safest choice for a risk-averse migration.

Exam trap

The trap here is that candidates often confuse 'Replatform' with 'Rehost' because both involve moving to the cloud, but Replatform requires code changes to leverage managed services (e.g., replacing a self-managed database with Amazon RDS), which increases risk and violates the 'minimal code changes' constraint.

How to eliminate wrong answers

Option A (Refactor) is wrong because it involves modifying the application code to optimize it for cloud-native features (e.g., using serverless functions or microservices), which contradicts the requirement for minimal code changes and increases risk. Option C (Replatform) is wrong because it requires some code changes to adapt the application to a managed cloud service (e.g., moving from a self-hosted database to Amazon RDS), which still introduces risk beyond a pure lift-and-shift. Option D (Rebuild) is wrong because it entails completely rewriting the application from scratch using cloud-native architectures (e.g., containers or serverless), which maximizes code changes and risk, directly opposing the stated goal.

695
MCQhard

After deploying a new application version, users get 503 errors. The application runs on Kubernetes in a private cloud. What is the most likely cause?

A.Application health check failing
B.Incorrect ingress configuration
C.Insufficient pod resources
D.Node port exhaustion
AnswerA

A failing readiness or liveness probe causes Kubernetes to remove pods from Service endpoints or restart them, leaving no healthy backends to serve traffic, so the ingress returns 503. This directly matches the scenario: a new version deployed, private-cloud Kubernetes, and users receiving 503 errors.

Why this answer

After deploying a new application version, users get 503 errors. In Kubernetes, a 503 Service Unavailable error often indicates that the service has no healthy endpoints. The most likely cause is that the application's health check (readiness probe) is failing, causing Kubernetes to remove the pod from the service's endpoints.

This can happen if the new version has a bug, misconfiguration, or takes longer to start than the probe's thresholds allow.

Exam trap

CV0-004 often tests Kubernetes troubleshooting; candidates may jump to ingress or resource issues, but 503 errors specifically point to health check failures or no available endpoints.

How to eliminate wrong answers

Option B is wrong because an incorrect ingress configuration would typically result in 404 errors or routing issues, not 503, unless the ingress cannot reach the service, but that is less direct. Option C is wrong because insufficient pod resources might cause pods to crash or be evicted, leading to 503 if no pods are available, but health check failure is more specific to a new deployment. Option D is wrong because node port exhaustion would affect all services on the node, not just the new application, and is less likely in a private cloud with proper planning.

696
MCQmedium

A company wants to migrate its existing on-premises web application to the cloud to reduce operational overhead. The application runs on a custom Linux distribution with specific kernel modules. Which cloud deployment model would best minimize the need to refactor the application while still reducing maintenance of the underlying infrastructure?

A.Container as a Service (CaaS)
B.Platform as a Service (PaaS)
C.Software as a Service (SaaS)
D.Infrastructure as a Service (IaaS)
AnswerD

IaaS supplies virtualised compute, storage and networking while leaving the guest OS and kernel modules under the customer's control, so the custom Linux distribution runs unmodified. The provider maintains the physical infrastructure, reducing operational overhead without refactoring.

Why this answer

IaaS (Infrastructure as a Service) provides virtualized compute resources where you retain full control over the operating system, including custom Linux distributions and kernel modules. This allows you to migrate the application as-is without refactoring, while the cloud provider handles the underlying physical infrastructure maintenance, such as hardware failures and network cabling.

Exam trap

The trap here is that candidates often choose PaaS or CaaS thinking they reduce operational overhead more, but they overlook the critical requirement for custom kernel modules, which only IaaS can support without refactoring.

How to eliminate wrong answers

Option A is wrong because CaaS (e.g., Kubernetes, Docker Swarm) requires the application to be containerized, which would necessitate refactoring to package the custom kernel modules into the container image or use host-level kernel sharing, potentially breaking compatibility. Option B is wrong because PaaS abstracts the OS layer entirely, preventing you from installing custom kernel modules or using a non-standard Linux distribution, forcing significant refactoring. Option C is wrong because SaaS delivers a fully managed application with no control over the underlying OS or runtime, making it impossible to migrate a custom web application without complete redevelopment.

697
MCQeasy

A company wants to track cloud spending by department and project. Which strategy should be implemented to enable cost attribution?

A.Use a single account for all workloads
B.Enable detailed billing reports
C.Implement a resource tagging strategy
D.Use AWS Organizations only
AnswerC

Tagging resources with department and project keys lets cost management tools group and filter spend along those dimensions. This enables accurate cost attribution, which untagged resources cannot support because billing data lacks the metadata needed to map charges to owners.

Why this answer

Resource tagging is the foundational mechanism for cost attribution in cloud environments. By applying consistent key-value tags (e.g., Department=Finance, Project=Alpha) to every resource, billing systems can group and filter costs along those dimensions. AWS Cost Explorer, Azure Cost Management, and GCP Billing all support grouping by tag, which directly answers the requirement to track spending by department and project.

Exam trap

CV0-004 often tests the misconception that enabling billing reports or Organizations alone provides cost attribution, when in reality tags are the prerequisite for any meaningful cost grouping.

How to eliminate wrong answers

Option A is wrong because a single account collapses all workloads into one billing boundary, making per-department or per-project attribution impossible without tags anyway. Option B is wrong because detailed billing reports only provide granular line-item data — they do not by themselves create the logical grouping needed for attribution. Option D is wrong because AWS Organizations provides account-level consolidated billing and governance, but without tags on resources, costs still cannot be split by department or project within an account.

698
MCQhard

A cloud engineer is troubleshooting a containerized application deployed on a managed Kubernetes cluster. The application pods are repeatedly restarting with 'OOMKilled' status. The engineer reviews the pod specification and sees that the memory request is 512Mi and the memory limit is 1Gi. The application is a Java-based service with a heap size set to 768Mi. Node metrics show that nodes have 8Gi of memory with 2Gi available. Which of the following is the MOST likely cause of the OOMKilled events?

A.The Java heap size exceeds the container memory limit when accounting for JVM overhead.
B.The container is being killed by the Kubernetes liveness probe due to high memory usage.
C.The Java application has a memory leak that causes it to exceed the heap size.
D.The memory request is too low, causing the pod to be scheduled on a node with insufficient memory.
AnswerA

The container memory limit is 1Gi, but the Java heap is set to 768Mi. The JVM requires additional memory beyond the heap for metaspace, thread stacks, code cache, and native memory. This overhead can easily exceed 256Mi, pushing total memory usage above the 1Gi limit. When the container exceeds its limit, the kernel OOM killer terminates the process, resulting in 'OOMKilled' status. The node has available memory, so the issue is the container limit, not node pressure.

Why this answer

The container memory limit is 1Gi, but the Java heap is 768Mi. The JVM requires additional native memory for metaspace, thread stacks, and other structures. When the total memory usage exceeds the 1Gi limit, the kernel OOM killer terminates the container, resulting in 'OOMKilled'.

Although the node has available memory, the container's cgroup limit is the constraint. Increasing the memory limit or reducing the heap size would resolve the issue.

Exam trap

The trap here is focusing on node-level memory availability and overlooking the container's cgroup limit, which is the actual constraint triggering the OOM killer.

699
MCQhard

A cloud administrator is managing a Microsoft Azure environment. The administrator needs to enforce a policy that prevents the creation of any Azure Storage account without HTTPS-only traffic enabled and without a minimum TLS version of 1.2. The policy must apply to all current and future subscriptions in the tenant and must be evaluated when resources are created or updated. Which Azure feature should the administrator use?

A.Azure Role-Based Access Control (RBAC)
B.Azure Blueprints
C.Azure Policy
D.Microsoft Defender for Cloud
AnswerC

Azure Policy is the governance service that evaluates resources against business rules and can deny noncompliant resource creation or updates. By assigning a built-in or custom policy definition that requires HTTPS-only traffic and a minimum TLS version, the administrator can enforce the requirement across all subscriptions in the tenant, including future ones, at deployment time.

Why this answer

Azure Policy is the correct choice because it evaluates resource properties during create and update operations and can deny noncompliant resources. Assigning a policy that requires HTTPS-only traffic and TLS 1.2 at a management group scope ensures the rule applies to all current and future subscriptions in the tenant, satisfying both the enforcement and scope requirements.

Exam trap

The trap here is confusing a security posture or reporting service, such as Microsoft Defender for Cloud, with an enforcement mechanism that can block noncompliant resource creation.

700
Multi-Selectmedium

A cloud administrator is setting up auto-scaling for a web application that uses an SQS queue for incoming requests. The administrator wants to scale the number of EC2 instances based on the queue depth. Which two metrics are appropriate for this auto-scaling policy? (Choose TWO.)

Select 2 answers
A.CPU utilization of instances
B.ApproximateNumberOfMessagesVisible (queue depth)
C.Memory utilization of instances
D.Network throughput
E.BacklogPerInstance (queue depth per instance)
AnswersB, E

ApproximateNumberOfMessagesVisible reports the count of messages awaiting retrieval, directly reflecting backlog depth. Scaling on this metric adds EC2 capacity precisely when consumer throughput lags behind incoming demand, satisfying the requirement to scale on queue depth rather than CPU or network statistics.

Why this answer

Option B, ApproximateNumberOfMessagesVisible (queue depth), is correct because it is the native CloudWatch metric that reports how many messages are available in the SQS queue, directly reflecting the incoming workload that the EC2 fleet must process. Option E, BacklogPerInstance (queue depth per instance), is correct because it is a custom metric that divides the queue backlog by the number of running instances, giving a per-instance workload signal that is ideal for target-tracking scaling policies on an SQS-backed web tier. Options A (CPU utilization) and C (memory utilization) are not appropriate here because the workload is driven by queue depth rather than instance-level compute or memory pressure, and memory utilization is not even a default CloudWatch EC2 metric.

Option D (network throughput) is also unsuitable because it measures data transfer volume, not the amount of pending work in the queue, so it would not reliably track the backlog the application must drain.

Exam trap

CV0-004 often tests the temptation to scale on CPU or memory for queue-based workloads, when the correct signal is queue depth or backlog per instance.

701
MCQeasy

A cloud administrator is tasked with ensuring that all API requests to the cloud management plane are encrypted. Which protocol should be enforced to meet this requirement?

A.TLS
B.IPsec
C.SSL
D.SSH
AnswerA

TLS encrypts data in transit, directly satisfying the requirement that management-plane API requests be encrypted. Management-plane endpoints, including Microsoft Entra ID and Azure Resource Manager, require TLS for confidentiality and integrity. Enforcing TLS 1.2 or higher prevents interception or tampering of administrative API traffic.

Why this answer

TLS (Transport Layer Security) is the protocol that encrypts API requests to cloud management planes, securing data in transit over HTTPS. All major cloud providers expose their management APIs exclusively over TLS, and enforcing TLS 1.2 or higher is the standard requirement for encrypted control-plane traffic. TLS is the successor to SSL and is the correct modern answer.

Exam trap

CV0-004 often tests the SSL-versus-TLS distinction, baiting candidates who remember the older 'SSL' terminology instead of the correct modern protocol, TLS.

How to eliminate wrong answers

Option B is wrong because IPsec operates at the network layer to secure VPN tunnels between networks, not individual HTTPS API calls to a management plane. Option C is wrong because SSL is the deprecated predecessor to TLS; modern cloud APIs use TLS, and citing SSL would be technically outdated. Option D is wrong because SSH provides encrypted remote shell access, not the HTTPS transport used by REST management APIs.

702
MCQeasy

Which encryption standard is most commonly used for data at rest in cloud storage services?

A.Blowfish
B.DES
C.AES-256
D.RSA
AnswerC

AES-256 is the symmetric block cipher overwhelmingly adopted for cloud data-at-rest encryption, offering 256-bit keys resistant to brute force. It satisfies the stem's requirement for the encryption standard most commonly used by cloud storage services.

Why this answer

AES-256 is the de facto standard for data-at-rest encryption in cloud storage services such as Amazon S3, Azure Blob Storage, and Google Cloud Storage. It provides strong symmetric encryption with a 256-bit key, is FIPS 140-2/3 validated, and is widely supported by hardware acceleration. Cloud providers default to AES-256 (or AES-128 in some cases) for server-side encryption.

Exam trap

CV0-004 often tests the confusion between symmetric encryption algorithms (AES) used for bulk data-at-rest and asymmetric algorithms (RSA) used for key exchange or signatures — candidates may pick RSA thinking 'stronger equals better' for storage.

How to eliminate wrong answers

Option A is wrong because Blowfish is a legacy symmetric cipher with a 64-bit block size that is considered outdated and is not used as a cloud storage default. Option B is wrong because DES (and 3DES) has a 56-bit effective key and is cryptographically broken for modern use; no major cloud provider uses it for data-at-rest. Option D is wrong because RSA is an asymmetric algorithm used for key exchange and digital signatures, not for bulk data-at-rest encryption — it is far too slow for encrypting large datasets.

703
MCQeasy

A cloud engineer is deploying a new application on AWS and needs to ensure that the application's environment variables are securely stored and not exposed in the source code or CloudFormation templates. Which AWS service should be used to store and retrieve these secrets?

A.AWS Systems Manager Parameter Store (String type)
B.AWS Secrets Manager
C.AWS CloudFormation parameters with the NoEcho attribute
D.Amazon S3 bucket with default encryption
AnswerB

AWS Secrets Manager is designed to securely store and manage secrets such as database credentials, API keys, and environment variables. It provides encryption at rest using KMS, automatic rotation, and fine-grained access control via IAM. Applications can retrieve secrets at runtime using the AWS SDK, keeping them out of source code and templates, which meets the requirement.

Why this answer

AWS Secrets Manager is the appropriate service for securely storing and retrieving secrets like environment variables. It encrypts secrets at rest, supports automatic rotation, and integrates with IAM for access control. Other options either store plaintext, only mask values, or lack secret management features, making them unsuitable for secure secret storage.

Exam trap

The trap here is thinking that CloudFormation NoEcho or Parameter Store String type provides secure secret storage, when they either only hide values or store them unencrypted.

704
MCQeasy

A cloud engineer is configuring an Azure Storage account that holds regulated customer data. The compliance team requires that data is encrypted at rest with customer-managed keys stored in Azure Key Vault, and that key usage is auditable. Which configuration should the engineer apply?

A.Configure a customer-managed key in Azure Key Vault and assign it as the encryption key for the storage account.
B.Set the storage account encryption key source to Microsoft-managed keys and enable soft delete.
C.Enable infrastructure encryption and store keys in a managed HSM.
D.Enable Azure Disk Encryption on the storage account and store the KEK in Key Vault.
AnswerA

Azure Storage supports customer-managed keys by referencing a key in Key Vault or Managed HSM. Setting the account's encryption key source to the Key Vault key makes the customer control rotation and revocation, and Key Vault diagnostic logs record key operations for audit, satisfying the regulated-data requirement.

Why this answer

Azure Storage encryption supports customer-managed keys by referencing a key stored in Azure Key Vault or Managed HSM. Setting the account's encryption key source to that key gives the customer control over rotation and revocation, while Key Vault logging records every key operation. Microsoft-managed keys and disk encryption do not provide the same customer control or auditability for storage account data.

Exam trap

The trap here is applying Azure Disk Encryption, which protects VM disks, to an Azure Storage account that stores blobs and files.

705
Multi-Selecthard

A company is experiencing intermittent performance issues in a microservices application. Which TWO tools can help diagnose latency problems through distributed tracing? (Choose TWO)

Select 2 answers
A.AWS CloudWatch Logs
B.Azure Monitor
C.Azure Application Insights
D.AWS CloudTrail
E.AWS X-Ray
AnswersC, E

Azure Application Insights satisfies the distributed tracing requirement by correlating requests across microservices through its telemetry model, using operation IDs to stitch spans into an end-to-end transaction view. This exposes per-hop latency, letting you pinpoint which service introduces delay during intermittent performance issues.

Why this answer

Azure Application Insights (C) is correct because it provides distributed tracing across microservices, correlating requests with dependency calls and showing end-to-end latency breakdowns via the Application Map and transaction diagnostics. AWS X-Ray (E) is correct because it natively performs distributed tracing for microservices, using trace IDs and segments/subsegments to visualize latency bottlenecks across services, including integrations with Lambda, API Gateway, and ECS. AWS CloudWatch Logs (A) only aggregates log data and does not by itself provide distributed trace correlation across services.

Azure Monitor (B) is a broader monitoring platform whose distributed tracing capability comes specifically through Application Insights, so it is not the precise tracing tool here. AWS CloudTrail (D) records API activity for auditing and governance, not request-level latency tracing.

Exam trap

CV0-004 often tests the distinction between monitoring/logging tools and true distributed tracing tools; candidates may incorrectly select CloudWatch Logs or Azure Monitor because they are familiar monitoring services.

706
Multi-Selectmedium

A cloud administrator is optimizing costs for a batch processing workload that runs nightly for 2 hours. The workload can tolerate interruptions. Which THREE purchasing options should the administrator consider? (Choose three.)

Select 3 answers
A.Preemptible VMs
B.Spot instances
C.Dedicated hosts
D.Reserved instances
E.On-demand instances
AnswersA, B, E

Preemptible VMs are cost-effective and can be interrupted, ideal for batch jobs.

Why this answer

Correct answer: Preemptible VMs, Spot instances, and On-demand instances. For a batch processing workload that runs nightly for only 2 hours and can tolerate interruptions, cost optimization favors using interruptible instances like Preemptible VMs (Google Cloud) or Spot instances (AWS/Azure) because they offer significant discounts and are suitable for fault-tolerant workloads. On-demand instances are also an option to consider when interruptible instances are not available or if the workload requires guaranteed capacity, though they are more expensive.

Reserved instances or dedicated hosts are not cost-effective for such short, periodic workloads because they require long-term commitments (1 or 3 years) and are designed for steady-state usage. Therefore, the three options to consider are Preemptible VMs, Spot instances, and On-demand instances.

707
MCQhard

A company is deploying a containerized application on Amazon EKS. The security team requires that the application pods use an IAM role to access AWS services without storing credentials in the container images or environment variables. Which approach should the team use?

A.Use the AWS SDK for Java with a custom credential provider that reads from the pod's environment variables.
B.Attach an IAM role to the EC2 worker nodes and rely on the instance metadata service for pod credentials.
C.Create a Kubernetes service account and associate it with an IAM role using IAM Roles for Service Accounts (IRSA).
D.Store AWS credentials in a Kubernetes secret and mount it as a volume in the pod.
AnswerC

IAM Roles for Service Accounts (IRSA) allows Kubernetes pods to assume an IAM role via a service account. The EKS cluster's OIDC provider is used to federate the service account to IAM, and the pod receives temporary credentials through a projected service account token. This eliminates the need to store credentials in images or environment variables, meeting the security requirement.

Why this answer

IAM Roles for Service Accounts (IRSA) is the AWS-recommended method to grant AWS permissions to individual pods in an EKS cluster. By associating a Kubernetes service account with an IAM role, the pod can obtain temporary credentials via the cluster's OIDC provider. This approach adheres to least privilege and eliminates the need to store or manage long-term credentials in images or environment variables.

Exam trap

The trap here is assuming that node-level IAM roles or Kubernetes secrets are sufficient, but they either grant excessive permissions or still involve stored credentials.

708
MCQmedium

A financial services firm requires a cloud deployment that keeps sensitive customer data on-premises while bursting compute-intensive risk analysis workloads to a public cloud during peak times. Which deployment model best meets this requirement?

A.Hybrid cloud
B.Public cloud
C.Multi-cloud
D.Private cloud
AnswerA

Hybrid cloud keeps sensitive customer data on-premises under the firm's control while connecting to public cloud resources for peak risk-analysis bursts. This directly satisfies both constraints: data residency on-premises and elastic compute scaling during peak demand.

Why this answer

A hybrid cloud model combines on-premises infrastructure (private cloud) with public cloud services, allowing data and applications to be shared between them. This exactly matches the requirement to keep sensitive customer data on-premises while bursting compute-intensive workloads to a public cloud during peak times. Hybrid cloud provides the necessary integration, orchestration, and security controls to move workloads securely between environments.

Exam trap

The trap is confusing hybrid cloud with multi-cloud; candidates may pick multi-cloud because it sounds more flexible, but the requirement specifically mentions on-premises data and bursting to a public cloud, which is the definition of hybrid cloud.

How to eliminate wrong answers

Option B is wrong because a public cloud deployment would place all resources in a public cloud provider, which does not meet the requirement to keep sensitive data on-premises. Option C is wrong because multi-cloud involves using two or more public cloud providers, which does not address the need for on-premises data residency. Option D is wrong because a private cloud alone would not provide the elasticity to burst compute-intensive workloads to a public cloud during peak times.

709
MCQmedium

A cloud engineer is investigating intermittent latency in a three-tier application hosted in Google Cloud. The engineer suspects that a specific Compute Engine instance is experiencing packet loss to its database backend. The engineer needs to capture and analyze the traffic at the packet level on the instance without installing third-party agents on the instance and without disrupting production traffic. Which Google Cloud feature should the engineer use?

A.Cloud NAT logging
B.Firewall Rules Logging
C.Packet Mirroring
D.VPC Flow Logs
AnswerC

Packet Mirroring clones traffic from a specified instance or subnet and sends it to a collector instance for analysis. It operates at the VPC level, requires no agent on the monitored instance, and does not disrupt production traffic. This allows the engineer to capture and analyze packet-level details to diagnose the suspected packet loss.

Why this answer

Packet Mirroring is the correct choice because it clones traffic at the VPC level and forwards it to a collector without requiring an agent on the source instance and without affecting production traffic. This gives the engineer full packet-level visibility to analyze retransmissions, dropped packets, and TCP behavior between the instance and the database.

Exam trap

The trap here is assuming that VPC Flow Logs, which capture flow metadata, provide the same packet-level detail as an actual packet capture mechanism.

710
Multi-Selecthard

Which THREE of the following are essential components of a cloud incident response plan? Select three.

Select 3 answers
A.Data backup schedule
B.Cost optimization strategies
C.Root cause analysis
D.Communication plan
E.Containment procedures
AnswersC, D, E

Root cause analysis is essential because it determines why the incident occurred, enabling remediation of the underlying weakness rather than only the symptom. Without it, the plan cannot prevent recurrence, which is a core objective of any incident response lifecycle.

Why this answer

Root cause analysis (C) is essential because a cloud incident response plan must include a post-incident phase that determines the underlying cause of the event to prevent recurrence and improve controls. A communication plan (D) is essential because incident response requires defined notification paths and escalation procedures for stakeholders, customers, regulators, and internal teams, especially given cloud shared-responsibility and breach-notification obligations. Containment procedures (E) are essential because the plan must specify how to limit the scope and impact of an incident, such as isolating compromised instances, revoking credentials, or restricting network access, before eradication and recovery.

Data backup schedule (A) is a recovery or business continuity concern rather than a core incident response component, and cost optimization strategies (B) relate to financial management of cloud resources, not incident handling.

Exam trap

CV0-004 often tests the distinction between incident response components and broader operational or financial practices, tempting candidates to select backup schedules or cost optimization as part of IR.

711
MCQmedium

A cloud engineer is designing a VPC for a web application that requires a public subnet for a load balancer and a private subnet for application servers. The application servers must access the internet for software updates without being directly accessible from the internet. Which configuration should the engineer implement?

A.Create a NAT Gateway in the public subnet and update the private subnet's route table to point to the NAT Gateway.
B.Attach an Internet Gateway to the VPC and configure the private subnet's route table to point to the Internet Gateway.
C.Set up a VPN connection between the VPC and the on-premises data center and route all internet traffic through the VPN.
D.Assign Elastic IP addresses to the application servers and configure security groups to allow outbound traffic only.
AnswerA

A NAT Gateway allows instances in a private subnet to initiate outbound traffic to the internet while preventing inbound traffic from reaching them. Placing the NAT Gateway in a public subnet gives it internet access via the Internet Gateway. Updating the private subnet's route table to point to the NAT Gateway enables the application servers to download updates without being directly accessible.

Why this answer

A NAT Gateway in a public subnet allows private subnet instances to initiate outbound internet traffic while remaining inaccessible from the internet. The private subnet's route table must direct outbound traffic to the NAT Gateway. This is the standard AWS design pattern for enabling updates and patches for private instances without exposing them publicly.

Exam trap

The trap here is assuming that an Internet Gateway can be used directly by private subnet instances, but private instances lack public IPs and would require a NAT device for outbound internet access.

712
MCQeasy

A systems administrator needs to apply a critical security patch to a set of application servers running in a cloud environment. The administrator wants to minimize downtime and ensure that if the patch causes issues, the servers can be rolled back quickly. Which of the following is the BEST approach?

A.Patch all servers at once during a maintenance window.
B.Take a snapshot of each server, apply the patch, and if issues occur, restore from snapshot.
C.Use an automated configuration management tool to apply the patch gradually.
D.Use a blue-green deployment, patch the green environment, then switch traffic.
AnswerD

Blue-green deployment keeps the current blue environment serving traffic while the green environment is patched and validated. Switching traffic only after verification, and reverting by redirecting back to blue, satisfies the stem's requirements for minimal downtime and rapid rollback.

Why this answer

Blue-green deployment allows zero-downtime patching by switching traffic from the current (blue) environment to the patched (green) environment, and if issues occur, traffic can be switched back instantly, providing immediate rollback. Option A is incorrect because patching all servers at once causes downtime and no quick rollback. Option B is incorrect because taking snapshots before patching and restoring if needed incurs downtime during restore and is not as quick as switching traffic.

Option C is incorrect because using an automated configuration management tool to apply patches gradually may not provide instant rollback and could still cause partial downtime.

713
MCQeasy

A company uses AWS CloudFormation to manage its infrastructure. After updating a stack, a developer notices that the actual infrastructure differs from the expected template. Which CloudFormation feature should be used to identify these differences?

A.Drift detection
B.Stack sets
C.Change sets
D.Rollback triggers
AnswerA

Drift detection compares the actual deployed resource configuration against the expected stack template and reports any divergence. It directly identifies where live infrastructure no longer matches the template, satisfying the developer's need to locate differences after the update.

Why this answer

Drift detection allows you to detect whether a stack's actual configuration differs from its expected template configuration.

714
Multi-Selecteasy

A cloud administrator is deploying a new application in a cloud environment. The application requires high availability and fault tolerance. Which two design principles should the administrator implement? (Select TWO).

Select 2 answers
A.Place a load balancer in front of the application.
B.Use an auto-scaling group across multiple availability zones.
C.Deploy all instances in a single availability zone.
D.Use a single instance to reduce costs.
E.Store all data on a single volume without replication.
AnswersA, B

A load balancer distributes incoming requests across healthy instances and removes failed ones from rotation, eliminating the application tier as a single point of failure. This directly delivers the required high availability and fault tolerance.

Why this answer

Option A is correct because placing a load balancer in front of the application distributes incoming traffic across multiple healthy backend instances, eliminating a single point of failure and enabling continued service if one instance fails, which directly supports high availability. Option B is correct because an auto-scaling group spanning multiple availability zones automatically replaces failed instances and balances capacity across physically separate data centers, providing both fault tolerance against an AZ outage and elasticity for demand changes. Option C is incorrect because confining all instances to a single availability zone means an AZ-level failure takes down the entire application, defeating fault tolerance.

Option D is incorrect because a single instance is a single point of failure with no redundancy, so any instance or host failure causes an outage. Option E is incorrect because a single unreplicated volume is a single point of failure for data, risking permanent data loss and preventing recovery from storage failure.

Exam trap

The trap here is that candidates often think cost-saving strategies (single instance, single volume) are acceptable for high availability, but the exam requires understanding that fault tolerance demands redundancy at every layer—compute, storage, and network—across multiple failure domains.

715
MCQmedium

A cloud administrator needs to detect unusual spikes in CPU usage across a fleet of EC2 instances. Which AWS service should be used to create an alarm that triggers when CPU utilization exceeds an expected baseline?

A.AWS Config
B.AWS CloudTrail
C.AWS CloudWatch Alarms with anomaly detection
D.AWS Systems Manager
AnswerC

CloudWatch anomaly detection builds a learned baseline from historical CPU patterns and alarms on deviations, catching unusual spikes rather than fixed thresholds. Static thresholds would either miss subtle spikes or fire constantly on normal variation.

Why this answer

Amazon CloudWatch Alarms supports anomaly detection bands, which use machine learning to establish a normal baseline for a metric such as CPUUtilization and then alarm when the metric falls outside the expected band. This is the correct service for detecting unusual spikes relative to a learned baseline across a fleet of EC2 instances.

Exam trap

CV0-004 often tests whether candidates pick a monitoring-adjacent service like CloudTrail or Config for metric-based alerting, confusing activity logging with performance monitoring.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration compliance and recording service — it tracks resource configuration changes, not performance metrics like CPU utilization. Option B is wrong because AWS CloudTrail records API activity and management events, not runtime performance metrics. Option D is wrong because AWS Systems Manager is used for operational tasks such as patching, inventory, and run commands, not for creating metric-based alarms.

716
MCQmedium

A cloud architect is deploying a web application across multiple availability zones within a single region to achieve high availability. The application requires that if one availability zone fails, traffic should automatically be rerouted to the remaining zones without manual intervention. Which configuration is required?

A.Active-passive with a standby instance in a different region
B.Active-active across availability zones with a load balancer
C.Vertical scaling of instances in a single availability zone
D.Cold standby with daily backups
AnswerB

Active-active across availability zones with a load balancer satisfies the automatic failover constraint: the load balancer health-checks each zone's endpoints and reroutes traffic to surviving zones when one fails, with no manual intervention. Running identical instances in every zone also preserves capacity, unlike active-passive, which requires failover orchestration.

Why this answer

Deploying an active-active configuration across multiple availability zones with a load balancer ensures that traffic is automatically distributed to healthy instances. If one availability zone fails, the load balancer's health checks detect the failure and reroute traffic to the remaining zones without manual intervention, meeting the high availability requirement.

Exam trap

The trap here is that candidates often confuse high availability with disaster recovery, mistakenly choosing a cross-region active-passive setup (Option A) when the question explicitly specifies a single region and automatic rerouting.

How to eliminate wrong answers

Option A is wrong because active-passive with a standby instance in a different region introduces cross-region latency and requires manual or automated failover mechanisms, not automatic rerouting within a single region. Option C is wrong because vertical scaling in a single availability zone does not provide fault tolerance; if that zone fails, all instances become unavailable regardless of size. Option D is wrong because a cold standby with daily backups involves significant recovery time and manual steps to restore service, not automatic traffic rerouting.

717
Multi-Selectmedium

Which TWO of the following are common vulnerabilities in cloud environments that can lead to unauthorized access? Select two.

Select 2 answers
A.Enabling automatic patching
B.Lack of encryption for data in transit
C.Using multi-factor authentication
D.Properly scoped IAM roles
E.Misconfigured security groups allowing overly permissive inbound rules
AnswersB, E

Unencrypted data in transit can be intercepted or manipulated on the network, enabling credential theft and session hijacking that grant unauthorised access. This satisfies the vulnerability criterion because cloud traffic traverses shared infrastructure and public networks, where absence of TLS leaves authentication tokens and payloads readable to attackers.

Why this answer

Options B and E are correct because lack of encryption for data in transit exposes sensitive data to interception, and misconfigured security groups allowing overly permissive inbound rules can grant unauthorized access. Options A, C, and D are security best practices that help prevent vulnerabilities.

718
MCQeasy

A company is migrating a legacy on-premises application to a public cloud. The application currently uses a single monolithic architecture and relies on a local file system for storage. The cloud architect needs to redesign the application to take advantage of cloud-native features. Which design principle should the architect prioritize to ensure scalability and resilience?

A.Maintain the monolithic architecture and connect via VPN to on-premises storage
B.Use vertical scaling by increasing vCPU and RAM on a single large VM
C.Refactor the application into microservices deployed across multiple instances
D.Deploy the entire application in a single availability zone to reduce latency
AnswerC

Splitting the monolith into microservices across multiple instances removes the single local file system dependency, letting each service scale independently and survive instance failure. This cloud-native decomposition directly delivers the scalability and resilience the migration demands.

Why this answer

Refactoring the monolithic application into microservices enables independent scaling of components, improves fault isolation, and aligns with cloud-native patterns like containerization and orchestration (e.g., Kubernetes). This approach leverages horizontal scaling across multiple instances, which is essential for achieving elasticity and resilience in a public cloud environment, unlike the legacy single-point-of-failure monolithic design.

Exam trap

The trap here is that candidates often confuse vertical scaling (Option B) as a valid cloud-native approach, but the exam emphasizes horizontal scaling and decoupled architectures as the correct principles for scalability and resilience in cloud design.

How to eliminate wrong answers

Option A is wrong because maintaining the monolithic architecture and connecting via VPN to on-premises storage fails to leverage cloud-native features like managed storage services (e.g., Amazon S3 or Azure Blob Storage), introduces latency and bandwidth bottlenecks, and does not address scalability or resilience. Option B is wrong because vertical scaling (increasing vCPU and RAM on a single large VM) has hard limits (e.g., maximum instance size in AWS or Azure), creates a single point of failure, and does not provide the elasticity or fault tolerance required for cloud-native applications. Option D is wrong because deploying the entire application in a single availability zone increases the risk of downtime due to zone-level failures (e.g., power outages or network issues), contradicts the cloud best practice of multi-AZ deployment for high availability, and does not improve scalability.

719
Multi-Selecthard

A company manages a multi-account AWS environment and wants to deploy consistent infrastructure across several accounts using CloudFormation. The solution must support updates to the infrastructure and detect configuration drift. Which TWO CloudFormation features should be used?

Select 2 answers
A.Change sets
B.StackSets
C.Outputs
D.Nested stacks
E.Drift detection
AnswersB, E

StackSets deploy a single CloudFormation template across multiple AWS accounts and Regions from one administrator account, satisfying the multi-account consistency requirement. They also support update operations and drift detection on each stack instance, so infrastructure changes propagate and configuration drift is identified per account.

Why this answer

StackSets (B) is correct because it is the CloudFormation feature designed to deploy and update the same template across multiple AWS accounts and Regions from a single administrator account, which directly satisfies the requirement for consistent infrastructure across several accounts. Drift detection (E) is correct because it lets CloudFormation compare a stack's actual resource configuration against its expected template configuration and report resources that have been modified outside CloudFormation, satisfying the drift-detection requirement. Change sets (A) only preview how proposed changes would affect a single stack before execution, so they do not provide multi-account deployment or drift detection.

Outputs (C) merely export values from a stack for cross-stack references and do not deploy or monitor infrastructure. Nested stacks (D) help organize reusable templates within a single account/stack hierarchy but do not natively roll out stacks across multiple accounts or detect drift.

720
MCQeasy

A company stores sensitive customer data in an Amazon S3 bucket. A security audit reveals that the data is encrypted at rest using SSE-S3. The company now requires that they manage and control the encryption keys themselves, including the ability to rotate and revoke them. Which S3 encryption option should be used?

A.Client-side encryption
B.SSE-S3
C.SSE-KMS with AWS managed keys
D.SSE-KMS with customer managed keys
AnswerD

SSE-KMS with customer managed keys allows the organization to create and control the KMS keys used for S3 encryption. The customer can define key policies, enable automatic rotation, and disable or revoke keys when needed. This satisfies the requirement for full control over key management, including rotation and revocation, while still using S3 server-side encryption.

Why this answer

SSE-KMS with customer managed keys gives the organization ownership and control of the KMS keys used to encrypt S3 objects. This allows key rotation, policy management, and revocation, which aligns with the audit requirement. Other S3 encryption options either lack customer key control or place management outside the S3 server-side encryption model.

Exam trap

The trap here is assuming that any KMS-based encryption gives full customer control, when AWS managed keys do not permit rotation or revocation by the customer.

721
MCQeasy

A cloud customer is deploying a virtual machine (VM) in a public IaaS environment. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

A.Securing the hypervisor
B.Patching the guest operating system
C.Physical security of the data center
D.Network infrastructure integrity
AnswerB

In IaaS, the provider secures the physical hosts, hypervisor and network fabric, while the customer owns everything above it, including the guest operating system. Patching that guest OS therefore falls to the customer, satisfying the shared responsibility split for this deployment.

Why this answer

In the shared responsibility model for IaaS, the cloud provider is responsible for the security 'of' the cloud (physical security, hypervisor, network infrastructure), while the customer is responsible for security 'in' the cloud. Patching the guest operating system is a customer task because the customer has full control over the VM's OS, including updates, configuration, and application security. This aligns with the principle that the customer manages everything from the OS up, while the provider manages the virtualization layer and below.

Exam trap

CV0-004 often tests the misconception that the cloud provider handles all security tasks, leading candidates to incorrectly select physical security or hypervisor protection as customer responsibilities.

How to eliminate wrong answers

Option A is wrong because securing the hypervisor is the cloud provider's responsibility; the hypervisor is part of the virtualization infrastructure that the provider manages and isolates. Option C is wrong because physical security of the data center is always the cloud provider's responsibility, as customers have no access to or control over the physical facilities. Option D is wrong because network infrastructure integrity (e.g., routers, switches, physical network) is managed by the cloud provider; the customer is responsible for logical network security such as security groups and firewalls, but not the underlying infrastructure.

722
MCQeasy

A company uses a cloud provider's key management service to encrypt data at rest. The security team wants to ensure that encryption keys are automatically rotated every 90 days to meet compliance requirements. Which feature should be enabled?

A.Key import scheduling
B.Key automatic rotation
C.Key revocation
D.Key policy enforcement
AnswerB

This automates key replacement at specified intervals.

Why this answer

Key automatic rotation is the KMS feature that schedules and performs periodic key rotation without manual intervention, satisfying a 90-day compliance requirement. In AWS KMS, Azure Key Vault, and OCI Vault, enabling automatic rotation lets the service generate new key material on a defined schedule while retaining old versions for decryption. This directly meets the requirement of automatic rotation every 90 days.

Exam trap

The trap here is confusing key rotation with key revocation or key policy management — candidates may pick 'key revocation' thinking it enforces lifecycle, but revocation destroys access rather than rotating material.

How to eliminate wrong answers

Option A is wrong because key import scheduling refers to importing externally generated key material into the KMS, not rotating existing keys. Option C is wrong because key revocation disables or deletes a key, which would make encrypted data inaccessible rather than satisfy a rotation policy. Option D is wrong because key policy enforcement controls who can use or manage keys via IAM policies, but does not perform rotation.

723
MCQmedium

A cloud administrator is responsible for a Microsoft Azure environment where several production virtual machines must be backed up nightly. The recovery requirements state that backups must be retained for 90 days, that individual files must be restorable without recovering the entire VM, and that the backup data must be encrypted at rest. Which Azure Backup configuration should the administrator implement?

A.Create a Recovery Services vault, enable Azure Backup for the VMs, and set a daily backup policy with 90-day retention.
B.Configure Azure Site Recovery replication with a 90-day retention policy.
C.Configure Azure Files share snapshots with a 90-day retention policy for the VM data.
D.Enable Azure Disk Encryption on each VM and schedule snapshots with a 90-day retention rule.
AnswerA

Azure Backup stores VM backups in a Recovery Services vault, which encrypts data at rest by default. The policy controls the backup schedule and retention, and file-level recovery is supported directly from the recovery point. This combination satisfies the nightly schedule, 90-day retention, file restore, and encryption requirements.

Why this answer

Azure Backup with a Recovery Services vault is the native solution for VM backup in Azure. The vault encrypts backup data at rest, the backup policy defines the nightly schedule and 90-day retention, and file-level recovery lets administrators restore individual files from a recovery point without recovering the entire VM, matching all three requirements in the scenario.

Exam trap

The trap here is confusing replication for disaster recovery, such as Azure Site Recovery, with point-in-time backup that supports file-level restore and long-term retention.

724
Drag & Dropmedium

Arrange the steps to deploy a new virtual machine in a public cloud environment (e.g., AWS, Azure, GCP) in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

VM deployment typically starts with specs, then OS, network, launch, and finally public access configuration.

725
MCQhard

An engineer is deploying a Kubernetes application on EKS and needs to ensure that pods are only considered healthy after a startup delay, and that traffic stops to unhealthy pods. Which two probe types should be configured in the deployment manifest?

A.Startup probe and readiness probe
B.Liveness probe and startup probe
C.Only readiness probe
D.Readiness probe and liveness probe
AnswerA

A startup probe suppresses liveness and readiness checks until the container initialises, preventing premature restarts, while the readiness probe removes the pod from Service endpoints when unhealthy. Together they satisfy both the startup-delay and traffic-stopping requirements.

Why this answer

Startup probes delay health checks until the pod has had time to initialize, which satisfies the startup delay requirement. Readiness probes control when the pod receives traffic, stopping traffic to unhealthy pods. Together, they meet both needs.

Liveness probes restart unhealthy pods but do not handle startup delay or traffic routing.

Exam trap

Candidates often confuse startup probes with liveness probes. Startup probes defer other probes until initialization completes, while liveness probes restart pods that become unresponsive after startup.

726
Multi-Selecthard

A security engineer is designing a data classification policy for a cloud environment. The policy must identify sensitive data, apply appropriate controls, and monitor access. Which THREE of the following should be included in the policy? (Select THREE.)

Select 3 answers
A.Cloud Access Security Broker (CASB) for all data
B.Encryption at rest for classified data
C.Access logging and monitoring for sensitive data
D.Network security groups to isolate data
E.Data discovery and classification tools
AnswersB, C, E

Protects data in storage.

Why this answer

Data classification includes identifying where data resides, encrypting it, and monitoring access. DLP tools help enforce policies. Security groups are network controls, not data classification.

CASB is for SaaS, but not necessarily part of a classification policy.

727
MCQhard

A cloud engineer is designing a disaster recovery strategy for a critical application hosted on Azure. The application uses a SQL Database and must be able to fail over to a secondary region with minimal data loss. The Recovery Point Objective (RPO) is 5 minutes and the Recovery Time Objective (RTO) is 15 minutes. The engineer needs a solution that automatically replicates data and provides a connection endpoint that remains constant during failover. Which Azure feature should be implemented?

A.Azure SQL Database geo-restore
B.Azure SQL Database zone-redundant configuration
C.Azure SQL Database auto-failover groups
D.Azure SQL Database active geo-replication
AnswerC

Auto-failover groups provide a read-write listener endpoint that remains constant during failover, enabling automatic failover of one or more databases to a secondary region. They support automatic replication and can meet low RPO and RTO requirements by handling the failover process seamlessly.

Why this answer

Auto-failover groups provide automatic replication and a stable listener endpoint that enables seamless failover to a secondary region. This meets the low RPO and RTO requirements by automating the failover process and abstracting the underlying database changes from the application.

Exam trap

The trap here is confusing high availability features like zone redundancy with disaster recovery features that span regions, or assuming active geo-replication provides automatic failover without a listener endpoint.

728
MCQeasy

Which of the following is a benefit of using a Cloud Access Security Broker (CASB) for SaaS applications?

A.It encrypts data at rest in cloud storage.
B.It provides a virtual private network (VPN) for remote access.
C.It replaces the need for a web application firewall.
D.It gives visibility and control over Shadow IT and data protection.
AnswerD

A CASB sits between users and SaaS providers, discovering unsanctioned applications and enforcing data-loss prevention, encryption and access policies. This directly delivers the visibility and control over Shadow IT and data protection that the question asks for as the SaaS benefit.

Why this answer

CASBs provide visibility into SaaS usage and enforce security policies, such as data loss prevention (DLP) and access control.

729
MCQeasy

A cloud engineer wants to view a dashboard showing cost breakdown by department. Which tool provides pre-built billing dashboards?

A.AWS CloudWatch
B.AWS Cost Explorer
C.AWS Trusted Advisor
D.AWS Config
AnswerB

AWS Cost Explorer provides pre-built dashboards that visualise cost and usage data, including breakdowns by dimension such as department when costs are tagged accordingly. This directly satisfies the requirement for an existing billing dashboard, unlike raw billing reports or custom-built tooling that would need manual configuration.

Why this answer

AWS Cost Explorer includes pre-built reports and dashboards that break down costs by dimensions such as service, linked account, and tag, which can represent departments. It is the native AWS tool for visualizing and analyzing billing data, including cost by department when tags are used.

Exam trap

CV0-004 often tests whether candidates confuse monitoring tools like CloudWatch with billing tools, or pick Trusted Advisor because it sounds like it would surface cost insights.

How to eliminate wrong answers

Option A is wrong because AWS CloudWatch is a monitoring service for metrics, logs, and alarms — it does not provide billing dashboards or cost breakdowns. Option C is wrong because AWS Trusted Advisor provides best-practice checks and recommendations, not cost breakdown dashboards by department. Option D is wrong because AWS Config records and evaluates resource configurations for compliance, not billing or cost data.

730
Multi-Selectmedium

A company is selecting a cloud deployment model. They require the ability to keep sensitive data on-premises due to regulatory compliance, but want to leverage cloud resources for burst computing capacity. Which THREE characteristics describe this model?

Select 3 answers
A.Uses multiple public cloud providers
B.Resources are exclusively owned by one organization
C.Provides the ability to burst to the cloud for extra capacity
D.Uses a VPN or dedicated connection between on-premises and cloud
E.Data can remain on-premises for compliance
AnswersC, D, E

Bursting to the cloud directly satisfies the stem's requirement to leverage cloud resources for extra capacity while sensitive data stays on-premises. In a hybrid model, workloads scale out to public cloud during demand spikes, then return on-premises, preserving regulatory compliance without over-provisioning internal hardware.

Why this answer

Hybrid cloud connects on-premises with public cloud, enabling data residency and bursting.

731
Multi-Selecthard

A company uses AWS and wants to implement a structured logging format to simplify querying and analysis of application logs. Which three best practices should be followed when implementing structured logging? (Choose THREE.)

Select 3 answers
A.Write logs in plain text to reduce storage costs
B.Include a unique request ID for each transaction
C.Use consistent key names across all services
D.Use JSON format for log entries
E.Embed binary data in log messages for performance
AnswersB, C, D

A unique request ID per transaction lets you correlate every log line belonging to one request across services, which is essential for tracing distributed calls. Without it, entries from concurrent requests interleave and become impossible to reconstruct during analysis.

Why this answer

Option B is correct because including a unique request ID for each transaction enables correlation of log entries across distributed services, making it possible to trace a single request through multiple components during querying and analysis. Option C is correct because using consistent key names across all services ensures that queries and dashboards work uniformly, avoiding the need to map different field names for the same data in tools like CloudWatch Logs Insights or Athena. Option D is correct because JSON is a structured, machine-readable format that supports native parsing and filtering of fields, which directly simplifies querying and analysis compared to unstructured text.

Option A is not appropriate because plain text logs are unstructured, defeating the purpose of structured logging and making querying harder, even if storage costs are lower. Option E is not appropriate because embedding binary data in log messages bloats log size, harms readability, and is not queryable, so it does not support structured logging best practices.

Exam trap

CV0-004 often tests whether candidates pick cost-saving or performance-sounding options like plain text or binary embedding, which contradict the goals of structured logging.

732
MCQeasy

A company wants to reduce cloud costs by identifying underutilized EC2 instances. Which AWS service provides rightsizing recommendations?

A.AWS Budgets
B.AWS Trusted Advisor
C.AWS Cost Explorer
D.AWS Compute Optimizer
AnswerD

AWS Compute Optimizer analyses CloudWatch metrics for EC2 instances and delivers rightsizing recommendations, directly satisfying the requirement to identify underutilised instances and cut cloud spend. It evaluates CPU, memory and network utilisation over time, unlike billing tools that only report cost.

Why this answer

AWS Compute Optimizer analyzes historical utilization metrics of EC2 instances and provides rightsizing recommendations to identify underutilized or overprovisioned instances. It uses machine learning to recommend optimal instance types based on CPU, memory, network, and disk usage, directly addressing the goal of reducing costs by identifying underutilized instances.

Exam trap

CV0-004 often tests the confusion between cost visualization tools (Cost Explorer, Budgets) and cost optimization tools (Compute Optimizer, Trusted Advisor), tricking candidates into choosing a tool that only reports costs rather than recommends rightsizing.

How to eliminate wrong answers

Option A is wrong because AWS Budgets is used to set custom cost and usage budgets and receive alerts when thresholds are exceeded; it does not provide rightsizing recommendations. Option B is wrong because AWS Trusted Advisor offers best-practice checks, including some cost optimization checks (e.g., low utilization EC2 instances), but it does not provide detailed rightsizing recommendations with specific instance type suggestions. Option C is wrong because AWS Cost Explorer visualizes and analyzes cost and usage data, but it does not generate rightsizing recommendations; it helps you understand spending patterns, not optimize instance types.

733
MCQmedium

A company runs a stateful application that maintains session data in memory on the server. The application experiences performance issues during traffic spikes. Which design change would best improve scalability?

A.Increase the memory of each server (vertical scaling)
B.Implement sticky sessions on the load balancer
C.Move session state to a shared cache or database (stateless design)
D.Use a CDN to cache static content
AnswerC

In-memory session state binds each user to one server, preventing horizontal scaling. Moving sessions to a shared cache or database makes application instances stateless, so any instance can serve any request and additional replicas absorb traffic spikes.

Why this answer

Making the application stateless by moving session state to an external store (e.g., Redis or database) allows any instance to handle any request, enabling horizontal scaling.

734
Multi-Selecthard

A cloud security architect is designing a data protection strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores tenant data in object storage and a managed relational database. Regulators require that each tenant's data be cryptographically isolated so that a key compromise for one tenant cannot expose another tenant's data, and that the organization be able to prove key usage is auditable. Which TWO measures should the architect implement? (Choose two.)

Select 2 answers
A.Enable provider-managed encryption at rest on the object storage and database, relying on the provider's default keys.
B.Store all tenant data in a single database schema and rely on application-level row filtering for isolation.
C.Use a separate customer-managed key per tenant in a managed key management service, with key usage logged to an audit trail.
D.Implement envelope encryption where each tenant has a data key wrapped by a tenant-specific master key stored in the KMS.
E.Encrypt backups with a single organization-wide key and rotate it annually to limit exposure.
AnswersC, D

A distinct customer-managed key per tenant provides cryptographic isolation, so a compromised key affects only one tenant. Managed KMS services such as AWS KMS, Azure Key Vault, or Cloud KMS log key usage to CloudTrail, Azure Monitor, or Cloud Audit Logs, giving the auditor the required evidence. This directly satisfies both the isolation and auditability requirements.

Why this answer

Per-tenant customer-managed keys in a managed KMS provide cryptographic isolation, and envelope encryption with tenant-specific master keys ensures data keys are wrapped uniquely per tenant. Both approaches rely on KMS audit logging to prove key usage. Shared provider-managed keys, row-level filtering, and a single organization-wide key fail to create per-tenant cryptographic boundaries or auditable key-usage records.

Exam trap

The trap here is treating logical isolation, such as row filtering or a single shared key, as equivalent to cryptographic isolation with per-tenant keys and auditable usage.

735
MCQeasy

A cloud engineer is writing a Terraform configuration to deploy an AWS EC2 instance. Which file extension is typically used for Terraform configuration files written in HCL?

A..yaml
B..tf
C..json
D..hcl
AnswerB

HCL configuration files that Terraform loads from a working directory use the .tf extension, holding resource, variable and provider blocks. Terraform also reads .tf.json for JSON syntax and .tfvars for variable values, but .tf is the standard for HCL-authored configuration, satisfying the scenario's requirement.

Why this answer

Terraform configuration files written in HCL (HashiCorp Configuration Language) typically use the .tf file extension. This is the standard convention for Terraform modules and configurations, and Terraform automatically loads files with this extension. Other extensions like .tf.json are used for JSON-based configurations, but .tf is the primary one for HCL.

Exam trap

CV0-004 often tests the distinction between .tf and .hcl; candidates may think .hcl is the Terraform extension, but Terraform uses .tf for HCL configurations.

How to eliminate wrong answers

Option A is wrong because .yaml is used for YAML configuration files, not for Terraform HCL; Terraform does not natively parse YAML for configuration. Option C is wrong because .json is used for JSON-based Terraform configurations (with .tf.json extension), but the question specifies HCL, which uses .tf. Option D is wrong because .hcl is a generic extension for HCL files, but Terraform specifically uses .tf for its configuration files; .hcl is not the typical extension for Terraform.

736
MCQmedium

A cloud administrator is investigating a sudden increase in egress charges for an application running on multiple Linux VMs in a public cloud. The application makes frequent calls to a third-party REST API over the public internet. Which action should the administrator take FIRST to identify the source of the unexpected egress traffic?

A.Configure a NAT gateway and route all outbound traffic through it to centralize logging.
B.Install a host-based intrusion detection system (HIDS) on each VM to monitor outbound connections.
C.Enable VPC flow logs and analyze the destination IP addresses and byte counts for outbound traffic.
D.Review the cloud provider's billing dashboard for the previous month to compare costs.
AnswerC

VPC flow logs capture metadata about IP traffic to and from network interfaces in a VPC, including source/destination IPs and bytes transferred. Filtering for outbound traffic to the third-party API's public IPs will reveal which instances are generating the most egress and confirm whether the increase is due to API calls or other traffic. This is the most direct first step to localize the source before deeper packet analysis.

Why this answer

VPC flow logs provide the necessary network-level visibility to identify the source of increased egress traffic. By analyzing flow logs, the administrator can see which instances are communicating with external IPs and the volume of data transferred. This targeted approach quickly narrows down the cause, whether it is a misconfigured application, a compromised instance, or a change in API usage patterns.

Exam trap

The trap here is assuming that billing or host-based tools can provide the granular network traffic details needed to pinpoint egress sources, when in fact flow logs are the correct first step.

737
MCQhard

A DevOps engineer is deploying a containerized application to Amazon ECS using the Fargate launch type. The application must be highly available across multiple Availability Zones and automatically scale based on CPU utilization. The engineer has already created a task definition and an Application Load Balancer. Which additional configuration is required to meet these requirements?

A.Create an ECS service with a desired count of at least two, spread across multiple subnets in different Availability Zones, and configure a target tracking scaling policy.
B.Create an ECS service with a placement constraint to spread tasks evenly across instances and enable service auto scaling based on memory.
C.Configure the task definition to use the EC2 launch type and place instances in an Auto Scaling group across multiple AZs.
D.Deploy the tasks as a standalone task using the RunTask API and enable CloudWatch alarms to trigger Lambda functions for scaling.
AnswerA

An ECS service with a desired count of two or more and tasks spread across multiple subnets in different AZs ensures high availability. A target tracking scaling policy based on CPU utilization automatically adjusts the number of tasks. This combination meets both the high availability and auto-scaling requirements.

Why this answer

To achieve high availability and auto-scaling with Fargate, you need an ECS service that runs multiple tasks across AZs and a target tracking scaling policy. The service ensures tasks are rescheduled if they fail, and the scaling policy adjusts capacity based on CPU. The other options either use the wrong launch type or lack native service management.

Exam trap

The trap here is assuming that Fargate tasks can be spread using placement constraints or that standalone tasks can auto-scale without a service.

738
MCQhard

A company is deploying a multi-tier application in a cloud environment. The application must comply with PCI DSS, which requires encryption of data at rest and in transit. The database tier must be isolated from direct internet access, while the web tier must be accessible from the internet. Which of the following deployment architectures best meets these requirements?

A.Place all tiers in the same subnet and use security groups to restrict traffic.
B.Use a single instance for web and database, and place it behind a load balancer.
C.Use a VPN connection from the web tier to the database tier and disable encryption.
D.Deploy web tier in a public subnet, database tier in a private subnet, and use SSL/TLS for encryption.
AnswerD

Public and private subnets enforce the isolation constraint, keeping the database unreachable from the internet while the web tier remains exposed. SSL/TLS satisfies PCI DSS encryption in transit, and storage-level encryption covers data at rest.

Why this answer

It separates the web tier into a public subnet for internet accessibility and the database tier into a private subnet for isolation, meeting PCI DSS requirements. SSL/TLS encryption ensures data in transit is protected, and encryption at rest can be applied to the database storage. This architecture aligns with cloud best practices for multi-tier applications requiring compliance.

Exam trap

CompTIA often tests the misconception that security groups alone provide sufficient isolation, but network segmentation via separate subnets is required for PCI DSS compliance, and encryption must be explicitly enabled for both data at rest and in transit.

How to eliminate wrong answers

Option A is wrong because placing all tiers in the same subnet with only security groups does not provide network-level isolation for the database tier, violating PCI DSS requirements for data at rest and in transit encryption and exposing the database to potential direct internet access if misconfigured. Option B is wrong because using a single instance for both web and database tiers eliminates isolation, creating a single point of failure and violating PCI DSS segmentation requirements; it also fails to encrypt data in transit between tiers. Option C is wrong because a VPN connection from the web tier to the database tier does not inherently provide encryption for data in transit unless SSL/TLS or IPsec is explicitly configured, and disabling encryption violates PCI DSS; additionally, the web tier in a public subnet still requires encryption for all data in transit.

739
Multi-Selecthard

A company uses a hybrid cloud model with an on-premises data center connected to a public cloud via a VPN. Users report intermittent connectivity issues to cloud applications. Which THREE components should the administrator check to isolate the problem? (Choose three.)

Select 3 answers
A.Rebooting the cloud instances
B.VPN tunnel status and configuration
C.Security group rules in the cloud VPC
D.Route tables in the cloud VPC and on-premises
E.DNS resolution configuration
AnswersB, C, D

The VPN tunnel carries all hybrid traffic, so its status and configuration directly determine whether cloud applications remain reachable. Intermittent drops, rekey failures or mismatched parameters on the tunnel would produce exactly the reported sporadic connectivity loss.

Why this answer

Option B (VPN tunnel status and configuration) is correct because the hybrid connection between the on-premises data center and the public cloud depends on the IPsec VPN tunnel; if the tunnel is down, flapping, or has mismatched encryption parameters, users will experience intermittent connectivity to cloud applications. Option C (Security group rules in the cloud VPC) is correct because security groups act as stateful virtual firewalls at the instance level, and overly restrictive or incorrectly configured inbound/outbound rules can silently drop traffic, causing intermittent or failed access. Option D (Route tables in the cloud VPC and on-premises) is correct because traffic between the data center and cloud subnets must be routed correctly in both directions; missing or incorrect routes (for example, no route to the VPN gateway or the on-premises CIDR) will break connectivity even if the tunnel and security groups are fine.

Option A (Rebooting the cloud instances) is not a diagnostic component and would not isolate the cause; it may temporarily mask symptoms without identifying the underlying network issue. Option E (DNS resolution configuration) can cause name resolution failures, but the scenario describes intermittent connectivity to cloud applications rather than name resolution errors, and DNS is not one of the three marked components to check for isolating this hybrid network problem.

Exam trap

The trap here is that candidates often focus on application-level fixes (like rebooting instances) or DNS, when the real issue is a network-layer problem involving the VPN tunnel, routing, and security group rules that affect the path between on-premises and cloud resources.

740
Multi-Selecthard

A cloud operations team is deploying a three-tier application across multiple availability zones. To meet a strict recovery time objective, they want the application to keep serving traffic if an entire availability zone becomes unavailable. Which TWO design actions should the team take? (Choose two.)

Select 2 answers
A.Increase the instance size to handle the full production load on a single instance.
B.Configure the database with a multi-AZ standby that can be promoted automatically.
C.Distribute application instances across at least two availability zones behind a load balancer.
D.Take nightly snapshots of the database volumes and store them in a separate region.
E.Enable termination protection on all production instances.
AnswersB, C

A multi-AZ database keeps a synchronized standby in a separate zone and promotes it automatically during a zone failure. This removes the need to restore from backup, keeping database downtime within the recovery time objective and allowing the application tier to reconnect with minimal delay.

Why this answer

High availability across zones requires both a resilient application tier and a resilient data tier. Running instances in multiple zones behind a load balancer keeps the application serving traffic, while a multi-AZ database with automatic failover keeps data available without a lengthy restore, together meeting the aggressive recovery time objective.

Exam trap

The trap here is treating backup and protection features, such as snapshots or termination protection, as substitutes for high availability.

741
Multi-Selectmedium

A cloud architect is designing a deployment for a multi-tier application on AWS. The application consists of a web tier, an application tier, and a database tier. The architect needs to ensure that the deployment is highly available and can survive an Availability Zone failure. Which two configurations should be included in the design? (Choose two.)

Select 2 answers
A.Configure the database tier with a Multi-AZ deployment using Amazon RDS.
B.Deploy the web and application tiers across multiple Availability Zones using an Auto Scaling group.
C.Place all tiers in a single Availability Zone to minimize latency.
D.Use a single NAT gateway for all private subnets to reduce cost.
E.Use an Application Load Balancer to distribute traffic only within a single Availability Zone.
AnswersA, B

Amazon RDS Multi-AZ deployments create a standby replica in a different Availability Zone and automatically fail over to it in case of an AZ failure. This ensures database availability and durability. It is a key component for a highly available multi-tier application, as it eliminates the database as a single point of failure.

Why this answer

To achieve high availability and survive an Availability Zone failure, the web and application tiers should be deployed across multiple AZs using an Auto Scaling group, and the database tier should use a Multi-AZ deployment such as Amazon RDS Multi-AZ. These two configurations ensure that no single AZ failure takes down the entire application. The Auto Scaling group maintains capacity, and the Multi-AZ database provides automatic failover.

Exam trap

The trap here is assuming that a single NAT gateway or a single Availability Zone deployment is sufficient for high availability, when in fact they introduce single points of failure.

742
Multi-Selectmedium

Which TWO of the following are key components of a disaster recovery plan in the cloud? (Select TWO.)

Select 2 answers
A.Network performance monitoring
B.Billing alerts
C.Recovery point objective (RPO)
D.Load balancing
E.Cross-region replication
AnswersC, E

The recovery point objective defines the maximum tolerable data loss measured in time, directly determining backup frequency and replication strategy. It is a core disaster recovery plan component because it translates business tolerance for lost transactions into concrete cloud backup and retention configurations.

Why this answer

Option C (Recovery point objective, RPO) is correct because a disaster recovery plan must define the maximum acceptable amount of data loss measured in time, which directly drives backup frequency and replication strategy in the cloud. Option E (Cross-region replication) is correct because replicating data and workloads to a geographically separate region is a core mechanism for surviving a regional outage and meeting the plan's recovery targets. Options A (Network performance monitoring), B (Billing alerts), and D (Load balancing) are not key components of a DR plan: monitoring and load balancing support availability and performance within normal operations, and billing alerts are cost-management controls, none of which define or enable recovery from a disaster.

Exam trap

Many candidates mistakenly think load balancing is part of disaster recovery, but load balancing is for high availability within a single region, not for cross-region DR. Recovery point objective (RPO) and cross-region replication are key DR components.

743
MCQmedium

A cloud operations team supports a latency-sensitive application running on Amazon EC2 instances. Users in a remote region report that responses are slow even though the application's own metrics show normal processing times. The team wants to continuously measure the network path between the users' region and the application endpoint, capturing round-trip latency and packet loss without modifying the application. Which AWS service should they use?

A.Amazon CloudWatch Network Monitor.
B.AWS Network Manager with a global network configured.
C.VPC Flow Logs with a custom metric filter.
D.AWS CloudTrail with data events enabled on the load balancer.
AnswerA

CloudWatch Network Monitor continuously probes network paths between source and destination resources in different regions and reports round-trip latency and packet loss. It works without application changes, which fits the requirement to measure the user-to-endpoint path while leaving the workload untouched, making it the correct monitoring service here.

Why this answer

CloudWatch Network Monitor is purpose-built to probe paths between AWS and external or cross-region endpoints, reporting latency and packet loss continuously. Because it operates at the network layer and requires no agent or code change, it fits the scenario where application metrics look healthy but the user-perceived path is slow, allowing the team to correlate network degradation with the reported slowness.

Exam trap

The trap here is choosing VPC Flow Logs because they sound like network monitoring, when they actually record connection metadata rather than latency or loss measurements.

744
MCQhard

A cloud engineer is designing a VPC in AWS for a three-tier web application. The web servers must be accessible from the internet, the application servers should only be accessible from the web servers, and the database servers should only be accessible from the application servers. What is the most secure VPC design?

A.Public subnet for web and application servers, private subnet for database servers
B.Single public subnet with all servers placed in it, using security groups to restrict traffic
C.Public subnet for web servers, private subnet for application servers, and a separate private subnet for database servers, with proper security group rules
D.Use a single private subnet and a NAT gateway for internet access
AnswerC

Separating web, application and database tiers into public and private subnets, then restricting traffic with security group rules referencing each tier, enforces the required access path. Only web servers are internet-facing, satisfying the constraint that application and database servers remain unreachable directly.

Why this answer

The most secure design places each tier in its own subnet with security groups that restrict traffic: web servers in a public subnet (internet-facing), application servers in a private subnet (only accessible from web servers), and database servers in a separate private subnet (only accessible from application servers). This segmentation limits lateral movement and follows the principle of least privilege.

Exam trap

CV0-004 often tests the misconception that security groups alone are sufficient without subnet segmentation, leading candidates to choose a single public subnet design.

How to eliminate wrong answers

Option A is wrong because placing application servers in a public subnet exposes them to the internet, violating the requirement that they should only be accessible from web servers. Option B is wrong because a single public subnet with all servers exposes all tiers to the internet, relying solely on security groups, which is less secure than network segmentation. Option D is wrong because a single private subnet with a NAT gateway does not allow inbound internet access to web servers, so the web tier would not be accessible from the internet.

745
Multi-Selecthard

A cloud architect is designing a deployment for a multi-tier application that must meet compliance requirements for data residency. The application consists of a web tier, application tier, and database tier. Which TWO deployment strategies should the architect consider to ensure data remains in a specific geographic region while maintaining high availability?

Select 2 answers
A.Set up a VPN to a neighboring region
B.Deploy across multiple availability zones in the same region
C.Deploy in a single availability zone
D.Use regional load balancers
E.Deploy across multiple regions
AnswersB, D

Keeps data in region and provides HA.

Why this answer

Deploying across multiple Availability Zones (AZs) within the same region ensures that application components remain within the geographic boundary required for data residency, while providing high availability through fault isolation. If one AZ fails, traffic is automatically routed to healthy instances in other AZs, maintaining uptime without leaving the region.

Exam trap

CompTIA often tests the distinction between 'high availability' and 'disaster recovery' — candidates mistakenly choose multi-region deployment for high availability, but that violates data residency, while the correct answer uses multiple AZs within a single region to satisfy both constraints.

746
MCQhard

A cloud engineer is designing a serverless application that processes messages from an Amazon SQS queue. The application must scale automatically based on the number of messages in the queue and must handle failures gracefully by retrying failed messages. Which AWS service should the engineer use to run the application code?

A.AWS Step Functions with a state machine
B.AWS Lambda with an SQS trigger
C.Amazon EC2 Auto Scaling group with a custom worker
D.AWS Fargate with an ECS service
AnswerB

AWS Lambda supports SQS as an event source. When configured, Lambda automatically polls the queue and invokes the function with batches of messages. It scales based on the number of messages, and failed invocations can be retried or sent to a dead-letter queue. This meets the requirements for automatic scaling and graceful failure handling.

Why this answer

AWS Lambda with an SQS trigger is the most suitable because it natively integrates with SQS, automatically scales based on the number of messages, and provides built-in retry and dead-letter queue support. Other options require manual scaling configuration or additional components to achieve the same level of integration and simplicity.

Exam trap

The trap here is assuming that any compute service can easily integrate with SQS; only Lambda has native SQS event source mapping that handles scaling and retries automatically.

747
MCQhard

A cloud engineer is troubleshooting a storage performance issue. The storage is backed by a SAN with a mix of SSD and HDD drives. Which of the following metrics would BEST indicate that the storage subsystem is the bottleneck?

A.Low memory usage on the hypervisor
B.High network utilization on storage network links
C.High disk queue depth and latency
D.High CPU utilization on all application servers
AnswerC

Queue depth measures outstanding I/O requests awaiting service, and latency measures response time. Both rising together shows requests are queuing faster than the SSD/HDD mix can serve them, isolating the storage subsystem rather than CPU, network or application as the bottleneck.

Why this answer

High disk queue depth and latency directly indicate that I/O requests are waiting, which is a classic sign of a storage bottleneck. Low memory usage (A) does not indicate a storage issue. High network utilization (B) could be caused by storage traffic but does not confirm the storage subsystem is the bottleneck; it could be normal.

High CPU utilization (D) points to compute, not storage.

748
Multi-Selectmedium

A cloud architect is designing a highly available architecture on AWS for a web application that must survive the failure of an entire Availability Zone. The application uses an Application Load Balancer, web servers, and an Amazon RDS database. Which TWO design actions should the architect take? (Choose two.)

Select 2 answers
A.Configure the Application Load Balancer to route traffic only to a single Availability Zone to reduce latency.
B.Deploy the web servers in an Auto Scaling group that spans at least two Availability Zones.
C.Enable a Multi-AZ deployment for the Amazon RDS database.
D.Place the RDS database in a single Availability Zone and rely on automated backups for failover.
E.Use Amazon S3 to store the database files and point the application to the S3 bucket.
AnswersB, C

An Auto Scaling group spanning multiple Availability Zones ensures that if one AZ fails, instances in the remaining AZ continue to serve traffic. The Auto Scaling group can also replace failed instances automatically. This provides compute-layer high availability and is a fundamental design practice for surviving AZ failures.

Why this answer

To survive an Availability Zone failure, the web tier must be distributed across multiple AZs using an Auto Scaling group, and the database tier must use a Multi-AZ deployment for automatic failover. These two actions together provide high availability for both compute and data layers.

Exam trap

The trap here is believing that automated backups provide high availability; backups are for recovery, not for automatic failover during an AZ outage.

749
MCQhard

A cloud orchestration template fails to deploy resources with the error 'Resource limit exceeded'. The administrator has enough quota for all services. What is the most likely cause?

A.The template has a syntax error in the JSON.
B.A specific resource type has reached its service limit.
C.The custom image used is corrupted.
D.The IAM role used does not have permission to create resources.
AnswerB

Quota is per resource type, not aggregate, so overall headroom can exist while one service limit is exhausted. The deployment fails because that specific resource type has hit its ceiling, satisfying the 'Resource limit exceeded' error.

Why this answer

Certain resource types have service-specific limits that are separate from the overall account quota. Even if the administrator has enough total quota, a specific resource type (e.g., virtual machines, storage accounts) may have reached its maximum allowed count. Option A is incorrect because a syntax error would cause a different error, such as parsing failure.

Option C is incorrect because a corrupted image would typically result in image-related errors. Option D is incorrect because permission issues would generate an access denied error, not 'Resource limit exceeded'.

750
MCQmedium

A cloud administrator manages a three-tier application in a public cloud. Users report that API calls from the web tier to the database tier fail with connection timeouts, but the database tier responds normally when queried from a bastion host on the same subnet. The web tier instances reside in a different subnet. Which of the following is the MOST likely cause?

A.The web tier instances are using an outdated database client library that cannot negotiate the TLS version required by the database.
B.The database's security group inbound rules do not allow traffic from the web tier's subnet CIDR range on the database port.
C.The database engine's max_connections parameter is set too low for the incoming web tier connections.
D.The web tier's route table lacks a route to the database subnet's CIDR range.
AnswerB

Security groups are stateful and evaluated per source. Because the bastion host on the same subnet succeeds while web tier instances in a different subnet time out, the database's inbound rule likely scopes the permitted source to the bastion's subnet or IP rather than the web tier CIDR. Adding the web tier subnet on the correct database port resolves the timeout.

Why this answer

The bastion host succeeds from its own subnet while web tier instances in a separate subnet time out, which isolates the problem to source-based filtering rather than routing or the database engine itself. Security groups and network ACLs evaluate the source address, so a rule scoped to the bastion's range blocks the web tier. Allowing the web tier subnet CIDR on the database port restores connectivity.

Exam trap

The trap here is assuming that because the bastion can reach the database, the database is healthy and the problem must be in the web tier, when in fact source-scoped security group rules commonly differ by subnet.

Page 9

Page 10 of 12

Page 11