Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 751–825

834 questions total · 12pages · All types, answers revealed

Page 10

Page 11 of 12

Page 12
751
MCQhard

A DevOps team deploys a containerized application to a Kubernetes cluster. They need to ensure that containers cannot run with privileged access. Which Kubernetes security mechanism should be applied?

A.Pod Security Standards
B.Network policies
C.ConfigMaps
D.Service accounts
AnswerA

Pod Security Standards define the privileged, baseline and restricted profiles enforced via pod security admission, blocking containers that request privileged mode. This directly satisfies the constraint that containers cannot run with privileged access, unlike RBAC, which governs API permissions rather than pod capabilities.

Why this answer

Pod Security Standards (PSS) define three profiles — Privileged, Baseline, and Restricted — that control whether pods can run with privileged access, host networking, hostPath volumes, and similar elevated capabilities. Enforcing the Restricted or Baseline profile via Pod Security Admission prevents containers from running privileged. This is the native Kubernetes mechanism for restricting pod-level privileges.

Exam trap

CV0-004 often tests the confusion between network-level controls (Network Policies) and workload-level privilege controls (Pod Security Standards) — candidates may pick Network Policies thinking they restrict container capabilities.

How to eliminate wrong answers

Option B is wrong because Network Policies control pod-to-pod network traffic (ingress/egress), not container privilege levels or security contexts. Option C is wrong because ConfigMaps store non-sensitive configuration data as key-value pairs and have no security enforcement role. Option D is wrong because Service Accounts provide identity for pods to authenticate to the Kubernetes API and external services, not runtime privilege restrictions.

752
Multi-Selecteasy

Which TWO of the following are best practices for managing cloud storage in a multi-account environment? (Choose two.)

Select 2 answers
A.Implement bucket policies to restrict cross-account access.
B.Use separate encryption keys for each account.
C.Enable logging and monitoring of all storage operations.
D.Use a single storage bucket/container for all accounts to simplify management.
E.Allow full public access to ensure availability.
AnswersA, C

Bucket policies are resource-based controls attached directly to the storage bucket, letting you define which external account principals may access it and under what conditions. In a multi-account environment, this satisfies the constraint of preventing unintended cross-account access, since identity-based policies in the owning account alone cannot govern requests originating from other accounts.

Why this answer

Option A is correct because implementing bucket policies (e.g., S3 bucket policies or equivalent resource-based policies) lets you explicitly define which accounts, principals, or roles may access a bucket, thereby restricting unintended cross-account access in a multi-account environment. Option C is correct because enabling logging and monitoring of all storage operations (such as S3 server access logging, CloudTrail data events, or equivalent audit logs) provides the visibility needed to detect unauthorized access, verify compliance, and troubleshoot issues across accounts. Option B is not a recognized best practice in the same sense, since key management should follow a deliberate strategy (e.g., KMS key policies, centralized vs. per-account keys) rather than simply mandating separate keys per account.

Option D is wrong because a single shared bucket for all accounts undermines isolation, least privilege, and blast-radius containment. Option E is wrong because full public access violates security best practices and risks data exposure.

Exam trap

CV0-004 often tests the confusion between security best practices and operational convenience, so candidates may choose a single bucket or public access for simplicity, or think separate encryption keys are mandatory.

753
Multi-Selecthard

A cloud engineer is optimizing costs for a data analytics workload that runs periodically. The workload processes large datasets stored in Amazon S3 and runs on EC2 instances. Which THREE strategies should the engineer consider to reduce costs? (Select THREE.)

Select 3 answers
A.Implement S3 Lifecycle policies to transition older data to S3 Glacier
B.Provision large instances to reduce processing time
C.Choose the correct instance type based on resource requirements
D.Use Spot Instances for the compute nodes
E.Use on-demand instances exclusively
AnswersA, C, D

S3 Lifecycle policies automatically transition infrequently accessed datasets to Glacier, whose storage pricing is far lower than S3 Standard. This satisfies the cost-reduction goal for large, ageing analytics data without altering the EC2 compute tier.

Why this answer

Option A is correct because S3 Lifecycle policies can automatically transition aging analytics data to lower-cost storage classes such as S3 Glacier, cutting storage costs for data that is no longer frequently accessed. Option C is correct because right-sizing the EC2 instance type to the workload's actual CPU, memory, and I/O needs avoids paying for over-provisioned capacity. Option D is correct because Spot Instances offer steep discounts (up to ~90% off On-Demand) and are well suited to periodic, interruption-tolerant batch analytics jobs.

Option B is wrong because simply provisioning larger instances increases hourly cost and does not guarantee proportional time savings. Option E is wrong because On-Demand pricing is the most expensive compute option and provides no cost optimization for a periodic workload.

Exam trap

CV0-004 often tests the misconception that bigger instances always reduce cost by finishing faster, when right-sizing plus Spot and lifecycle tiering is the actual cost lever.

754
MCQmedium

A company is migrating 100 TB of data from an on-premises NAS to Amazon S3. The network bandwidth is limited to 100 Mbps, and the transfer must complete within 30 days. Which service should the company use to meet the deadline?

A.AWS DataSync
B.Amazon S3 Transfer Acceleration
C.AWS Snowball
D.AWS Direct Connect
AnswerC

At 100 Mbps, transferring 100 TB would take roughly 100 days, far exceeding the 30-day deadline. AWS Snowball ships data physically on a rugged appliance, bypassing the bandwidth constraint entirely, so the migration completes within the required window.

Why this answer

AWS Snowball is the correct choice because transferring 100 TB over a 100 Mbps link would take far longer than 30 days. At 100 Mbps, the theoretical maximum is about 12.5 MB/s, which over 30 days yields roughly 32 TB, well short of 100 TB. Snowball uses physical devices to ship data, bypassing network bandwidth limitations and meeting the deadline.

Exam trap

CV0-004 often tests the calculation of transfer time versus bandwidth, so candidates who pick DataSync or Direct Connect overlook that the 100 Mbps limit makes network transfer infeasible within the deadline.

How to eliminate wrong answers

Option A is wrong because AWS DataSync transfers data over the network and is subject to the same 100 Mbps bandwidth constraint, making it unable to complete 100 TB in 30 days. Option B is wrong because S3 Transfer Acceleration speeds up transfers over the internet using edge locations, but it cannot overcome a 100 Mbps origin uplink limitation. Option D is wrong because AWS Direct Connect provides a dedicated network connection but still requires sufficient bandwidth; a 100 Mbps Direct Connect link would have the same throughput limitation and would take too long to provision for a 30-day deadline.

755
MCQhard

A company is migrating its on-premises e-commerce application to a public cloud. The application consists of a stateless web tier, a stateful application tier that stores session data in memory, and a relational database. The migration must ensure high availability, scalability, and minimal downtime during cutover. The cloud provider offers load balancers, auto-scaling groups, managed database services, and caching services. The current on-premises architecture uses a single web server, a single application server, and a single database server. The application tier stores session data in local memory, which is lost if the server fails. The team needs to redesign the architecture to be cloud-native. Which of the following is the BEST course of action?

A.Deploy the web tier behind a load balancer with auto-scaling. Keep the application tier as a single instance with session replication to a secondary instance. Use a managed database with a read replica.
B.Deploy the web tier behind a load balancer with auto-scaling. Move session state from the application tier to a distributed caching service. Deploy the application tier behind a separate load balancer with auto-scaling. Migrate the database to a managed Multi-AZ deployment.
C.Use a load balancer for the web tier with auto-scaling. Deploy the application tier as a single large instance with sticky sessions. Migrate the database to a larger single-instance managed database.
D.Deploy both web and application tiers behind a load balancer with auto-scaling. Use sticky sessions to maintain session state. Migrate the database to a managed Multi-AZ deployment.
AnswerB

Distributing session state to a caching service removes the in-memory single point of failure, while load balancers with auto-scaling deliver the required availability and elasticity. Managed Multi-AZ database migration minimises cutover downtime, satisfying every stated cloud-native constraint.

Why this answer

It addresses the key requirements: high availability, scalability, and minimal downtime. By moving session state from local memory to a distributed caching service (e.g., Amazon ElastiCache or Azure Cache for Redis), the application tier becomes stateless and can be auto-scaled behind its own load balancer. The managed Multi-AZ database provides automatic failover and high availability, while the web tier behind a load balancer with auto-scaling ensures scalability and fault tolerance.

This design eliminates single points of failure and allows zero-downtime cutover by scaling out before decommissioning on-premises resources.

Exam trap

CompTIA often tests the misconception that sticky sessions or session replication are sufficient for high availability in a cloud environment, but the correct approach is to externalize session state to a distributed cache to achieve true statelessness and scalability.

How to eliminate wrong answers

Option A is wrong because it keeps the application tier as a single instance with session replication to a secondary instance, which still has a single point of failure during failover and does not provide true horizontal scalability; session replication introduces latency and complexity without the elasticity of auto-scaling. Option C is wrong because deploying the application tier as a single large instance with sticky sessions creates a single point of failure and does not allow auto-scaling, violating high availability and scalability requirements; sticky sessions also couple clients to specific instances, preventing seamless failover. Option D is wrong because using sticky sessions for both web and application tiers ties session state to specific instances, preventing true statelessness and auto-scaling; if an instance fails, its sticky sessions are lost, causing data loss and downtime.

756
MCQmedium

A cloud engineer is deploying a serverless application using AWS Lambda. The application processes files uploaded to an S3 bucket. To minimize cold start latency, which deployment configuration should the engineer use?

A.Set the function timeout to the minimum value.
B.Increase the memory allocation and enable provisioned concurrency.
C.Place the Lambda function in a VPC without any NAT gateway.
D.Configure the function to run in a specific Availability Zone.
AnswerB

Increasing memory allocation proportionally raises allocated vCPU, cutting initialisation time, while provisioned concurrency pre-initialises execution environments so invocations skip the cold start entirely. Together they directly satisfy the stem's requirement to minimise cold start latency for the S3-triggered Lambda function.

Why this answer

Provisioned concurrency pre-warms a specified number of Lambda execution environments, eliminating cold starts for those instances. Increasing memory allocation also proportionally increases CPU and network throughput, which can reduce initialization time. Together, these configurations directly address cold start latency for a serverless application processing S3 uploads.

Exam trap

CompTIA often tests the misconception that reducing timeout or placing Lambda in a VPC improves performance, when in fact these actions either have no effect or increase latency due to network overhead.

How to eliminate wrong answers

Option A is wrong because setting the function timeout to the minimum value (e.g., 1 second) does not reduce cold start latency; it only limits execution duration, potentially causing timeouts for file processing. Option C is wrong because placing the Lambda function in a VPC without a NAT gateway prevents internet access but does not reduce cold start latency; in fact, VPC-enabled Lambda functions often experience increased cold start times due to ENI (Elastic Network Interface) creation overhead. Option D is wrong because Lambda functions are inherently stateless and run across multiple Availability Zones automatically; specifying a single Availability Zone is not a supported configuration and does not affect cold start latency.

757
MCQeasy

An organization wants to reduce cloud costs by identifying underutilized EC2 instances. Which AWS service provides rightsizing recommendations?

A.AWS Budgets
B.AWS Compute Optimizer
C.AWS Trusted Advisor
D.AWS Cost Explorer
AnswerB

AWS Compute Optimizer analyses CloudWatch metrics and resource configuration to generate rightsizing recommendations for EC2 instances, identifying over-provisioned capacity. This directly satisfies the requirement to reduce costs by flagging underutilised instances, unlike billing or cost-explorer tools that report spend without recommending instance-size changes.

Why this answer

AWS Compute Optimizer analyzes CloudWatch metrics and resource configurations to generate rightsizing recommendations for EC2 instances, including whether instances are over-provisioned. It uses machine learning to compare your workload against historical patterns and provides specific instance type recommendations, directly addressing the goal of identifying underutilized EC2 instances.

Exam trap

CV0-004 often tests the confusion between cost visibility tools (Budgets, Cost Explorer) and cost optimization tools (Compute Optimizer, Trusted Advisor), so candidates must distinguish monitoring from rightsizing.

How to eliminate wrong answers

Option A is wrong because AWS Budgets only tracks spending against thresholds and sends alerts — it does not analyze instance utilization or recommend instance sizes. Option C is wrong because AWS Trusted Advisor offers a limited set of cost optimization checks (e.g., idle load balancers, low-utilization EC2) but does not provide detailed rightsizing recommendations with specific instance type alternatives. Option D is wrong because Cost Explorer visualizes and forecasts costs but does not analyze CPU, memory, or network utilization to recommend rightsizing.

758
MCQhard

A cloud architect is designing a multi-tier application in a public cloud that must comply with PCI DSS. The web tier must be accessible from the internet, but the application tier should not have any public IP addresses. Which architecture meets these requirements?

A.Assign public IP addresses to both tiers and use security group rules to restrict traffic.
B.Deploy both tiers in private subnets and use a VPC peering connection to the corporate data center.
C.Use a site-to-site VPN between the cloud VPC and an on-premises network for all traffic.
D.Place the web tier in a public subnet behind an internet-facing load balancer, and the app tier in a private subnet with a NAT gateway for outbound traffic.
AnswerD

Placing the app tier in a private subnet removes all inbound internet reachability, satisfying the PCI DSS isolation requirement, while the NAT gateway permits outbound-only traffic for patching and updates. The internet-facing load balancer fronts the web tier, so only that tier accepts public connections.

Why this answer

It places the web tier in a public subnet with an internet-facing load balancer, allowing internet access, and the app tier in a private subnet with no public IP, meeting the requirement. The NAT gateway enables outbound traffic for the app tier (e.g., for updates) without exposing it inbound. Option A is wrong because it assigns public IPs to both tiers, which violates the requirement that the app tier should not have public IPs.

Option B is wrong because deploying both in private subnets would prevent internet access to the web tier, and VPC peering to a data center does not address internet access. Option C is wrong because a site-to-site VPN would route all traffic through on-premises, which is unnecessary and doesn't provide direct internet access to the web tier as required.

759
MCQmedium

A company uses a hybrid cloud model and experiences intermittent connectivity issues between the on-premises network and the public cloud VPC. The administrator has verified that the VPN connection is established. Which of the following should the administrator check next?

A.Firewall rules for outbound traffic.
B.Public IP address of the VPN gateway.
C.Routing tables on both sides.
D.DNS resolution of cloud endpoints.
AnswerC

With the VPN tunnel established, intermittent failures typically stem from asymmetric or missing routes, so routing tables on both sides must be verified. Mismatched routes cause traffic to traverse incorrect paths or be dropped, matching the intermittent hybrid connectivity symptom described.

Why this answer

Since the VPN connection is established (tunnel is up), the issue is likely with traffic routing rather than basic connectivity. Routing tables on both the on-premises router and the cloud VPC must have correct routes pointing to the VPN gateway and the remote subnets; a missing or misconfigured route (e.g., a missing static route or incorrect VPC route table entry) will cause intermittent connectivity even when the VPN tunnel itself is active.

Exam trap

The trap here is that candidates assume an established VPN tunnel guarantees end-to-end connectivity, but CompTIA often tests that routing misconfigurations (e.g., missing static routes or incorrect VPC route propagation) are the most common cause of intermittent connectivity when the tunnel is up.

How to eliminate wrong answers

Option A is wrong because firewall rules for outbound traffic are typically checked after routing; if the VPN tunnel is up, outbound firewall rules are not the primary cause of intermittent connectivity between two specific networks. Option B is wrong because the public IP address of the VPN gateway is already verified as part of the established VPN connection; changing it would break the tunnel, not cause intermittent issues. Option D is wrong because DNS resolution of cloud endpoints affects name resolution, not the underlying network path; if the VPN is up and routes are correct, DNS issues would manifest as name resolution failures, not intermittent connectivity.

760
MCQhard

A company is deploying a critical financial application on a private cloud. The compliance team requires that all data at rest be encrypted with a key managed by the company's hardware security module (HSM). The cloud architect must select a storage solution that supports customer-managed keys and integrates with the existing HSM. Which storage option should the architect choose?

A.Object storage with server-side encryption using a cloud provider key
B.Instance store volumes on the compute nodes
C.Encrypted volumes on a software-defined storage (SDS) cluster
D.Network-attached storage (NAS) appliance with built-in encryption
AnswerC

Encrypted volumes on an SDS cluster let the company supply its own HSM-backed keys, since the encryption layer is software-controlled and can be bound to an external key manager rather than a provider-held key. This satisfies the compliance constraint that keys remain under company HSM custody, unlike provider-managed encryption.

Why this answer

A software-defined storage (SDS) cluster can be configured to use customer-managed encryption keys that integrate directly with the company's existing hardware security module (HSM) via standard interfaces like PKCS#11 or KMIP. This allows the company to maintain full control over key management and meet the compliance requirement for data-at-rest encryption with HSM-managed keys.

Exam trap

The trap here is that candidates often confuse 'built-in encryption' on a NAS appliance with the ability to integrate with an external HSM, but NAS appliances typically lack native KMIP or PKCS#11 support for HSM-backed key management, making SDS the only option that explicitly supports such integration.

How to eliminate wrong answers

Option A is wrong because object storage with server-side encryption using a cloud provider key means the cloud provider manages the encryption key, not the company's HSM, failing the customer-managed key requirement. Option B is wrong because instance store volumes are ephemeral and do not persist data beyond the instance lifecycle, making them unsuitable for a critical financial application that requires durable, encrypted storage with HSM integration. Option D is wrong because a NAS appliance with built-in encryption typically uses its own internal key management or a simple passphrase, and does not natively integrate with an external HSM for key management without additional complex configuration, which is not a standard feature.

761
MCQeasy

A startup is deploying a web application on AWS and wants to protect it from common Layer 7 attacks such as SQL injection and cross-site scripting. The application runs behind an Application Load Balancer, and the team wants a managed service that can be deployed quickly with minimal configuration. Which AWS service should they use?

A.AWS WAF
B.AWS Shield Advanced
C.Amazon GuardDuty
D.AWS Network Firewall
AnswerA

AWS WAF is a managed web application firewall that inspects HTTP(S) requests at Layer 7 and can block SQL injection and cross-site scripting using AWS Managed Rules. It integrates directly with Application Load Balancer, CloudFront, and API Gateway, and can be deployed quickly with preconfigured rule groups, matching the startup's need for minimal configuration.

Why this answer

AWS WAF is purpose-built to inspect HTTP(S) traffic and block Layer 7 attacks like SQL injection and XSS using managed rule groups. It integrates natively with Application Load Balancer and can be deployed in minutes, satisfying the startup's need for a managed, low-configuration solution. The other services address DDoS, threat detection, or network-layer filtering, not application payload protection.

Exam trap

The trap here is confusing Shield Advanced with WAF — Shield mitigates DDoS at the network layer, while WAF inspects application requests for injection and scripting attacks.

762
MCQeasy

A cloud administrator is tasked with ensuring that a cloud database is backed up daily. The backup must be stored off-site for disaster recovery. Which of the following is the most cost-effective solution?

A.Schedule a backup to an object storage bucket in a different region.
B.Perform a full backup to tape and store off-site.
C.Perform incremental backups to a local network share.
D.Use snapshot replication to a different region.
AnswerA

Object storage in a separate region provides off-site durability at low cost, since object storage pricing is far cheaper than block or file tiers and cross-region replication satisfies the disaster recovery constraint without dedicated infrastructure.

Why this answer

Scheduling a backup to an object storage bucket in a different region leverages cloud-native, pay-per-use storage (e.g., Amazon S3, Azure Blob, or Google Cloud Storage) with geo-redundancy. This eliminates the need for physical media or manual intervention, and cross-region replication provides off-site disaster recovery at minimal cost compared to tape or dedicated replication services.

Exam trap

Many candidates mistakenly believe that snapshot replication is the cheapest DR method, but in reality, scheduled object storage backups are more cost-effective for daily off-site retention because snapshots replicate entire block-level changes and incur higher storage and transfer costs.

How to eliminate wrong answers

Option B is wrong because tape backups require physical media handling, manual transport, and ongoing hardware/operational costs, making them significantly more expensive and slower to restore than cloud object storage. Option C is wrong because storing backups on a local network share does not provide off-site disaster recovery; a local failure or site-wide disaster would destroy both the database and its backup. Option D is wrong because snapshot replication to a different region typically incurs higher egress and storage costs than simple scheduled backups to object storage, and snapshots are often tied to the source region's lifecycle, making them less cost-effective for daily off-site backups.

763
Multi-Selectmedium

A company is designing a hybrid cloud architecture. They need to ensure high availability for a critical application. Which TWO of the following are best practices for achieving high availability in a hybrid cloud environment?

Select 2 answers
A.Rely solely on on-premises infrastructure with cloud as a backup
B.Implement an active-active architecture across on-premises and cloud
C.Use a single load balancer to route all traffic
D.Use multiple availability zones within a cloud region
E.Deploy the application in a single availability zone to reduce complexity
AnswersB, D

Active-active deployment runs workloads simultaneously in both on-premises and cloud, so traffic fails over instantly when one site degrades. This directly satisfies the stem's high-availability requirement for a critical application, unlike active-passive designs that incur downtime during failover. Distributing load across both environments also removes the single point of failure inherent in a single-site deployment.

Why this answer

Using multiple availability zones within a region protects against data center failure. An active-active architecture ensures both on-premises and cloud are handling traffic, providing redundancy. Deploying in a single zone creates a single point of failure.

Using only on-premises does not leverage cloud for HA. A single load balancer is a SPOF.

764
MCQhard

A company uses AWS and Azure to run identical workloads for redundancy. They want to simplify management by using a single set of tools across both clouds. Which architectural approach should they consider?

A.Use each provider's native management tools
B.Single cloud migration to one provider
C.Multi-cloud using a cloud-agnostic orchestration tool
D.Hybrid cloud using VPN between AWS and Azure
AnswerC

A cloud-agnostic orchestration tool such as Terraform or Kubernetes abstracts provider-specific APIs, letting one toolset manage AWS and Azure workloads. This directly satisfies the requirement to simplify management across both clouds while preserving the redundancy architecture.

Why this answer

Multi-cloud with a cloud-agnostic abstraction layer (e.g., using Terraform or Kubernetes) allows managing resources across providers with a unified toolset.

765
MCQmedium

A cloud operations team manages a multi-tier web application on Google Cloud. The application logs are being written to Cloud Logging, and the team needs to be alerted whenever the number of HTTP 500 errors exceeds 50 in a 5-minute window. Which action should the team take to meet this requirement?

A.Enable Cloud Trace on the application and create an alerting policy that triggers when the error rate exceeds 50 per 5 minutes.
B.Create a log-based metric in Cloud Logging that counts HTTP 500 entries, then create a Cloud Monitoring alerting policy based on that metric with a threshold of 50 over 5 minutes.
C.Use Cloud Monitoring uptime checks to monitor the application endpoint and alert when the failure count exceeds 50 in 5 minutes.
D.Configure a Cloud Logging sink to Pub/Sub and create a Cloud Function that counts errors and sends an email when the count exceeds 50.
AnswerB

Log-based metrics in Cloud Logging convert log entries matching a filter into a numeric time series. Creating a metric that counts HTTP 500 entries, then attaching a Cloud Monitoring alerting policy with the specified threshold and window, directly satisfies the requirement. This is the standard Google Cloud pattern for alerting on log content.

Why this answer

The correct approach is to derive a metric from the logs using a log-based metric in Cloud Logging, then use Cloud Monitoring to alert on that metric. This natively supports counting specific log entries and applying a threshold over a time window, which matches the requirement exactly without custom code.

Exam trap

The trap here is assuming that Cloud Trace or uptime checks can alert on application error counts, when they actually measure latency or availability rather than log-derived error volume.

766
MCQeasy

A cloud engineer is using Ansible to automate cloud resource provisioning. Which statement about Ansible is true?

A.Ansible uses JSON for configuration management.
B.Ansible requires an agent to be installed on each managed node.
C.Ansible uses YAML for playbook definitions.
D.Ansible is a cloud-only tool that cannot manage on-premises servers.
AnswerC

Ansible playbooks are written in YAML, a human-readable data serialisation format, and executed over SSH without agents on managed nodes. This is the factual property distinguishing Ansible from agent-based configuration tools that use other definition languages.

Why this answer

Ansible playbooks are written in YAML, a human-readable data serialization format that defines plays, tasks, modules, and variables. This YAML-based syntax is a defining characteristic of Ansible and is why it is popular for configuration management and orchestration.

Exam trap

CV0-004 often tests the misconception that Ansible requires agents or uses JSON, when in fact it is agentless and YAML-based — a common point of confusion with other configuration management tools.

How to eliminate wrong answers

Option A is wrong because Ansible uses YAML, not JSON, for playbook and configuration definitions (though JSON can be used for some data structures, it is not the primary format). Option B is wrong because Ansible is agentless; it connects to managed nodes over SSH (Linux) or WinRM (Windows) without requiring an agent installation. Option D is wrong because Ansible is not cloud-only; it can manage on-premises servers, network devices, and hybrid environments equally well.

767
MCQmedium

A cloud administrator is writing an Ansible playbook to provision cloud resources. The administrator wants to ensure that the playbook can run without requiring any agent software on the target machines. Which Ansible feature enables this agentless operation?

A.Ansible inventory files that list hosts
B.Ansible modules that run on the control node
C.SSH-based connection to managed nodes
D.Pull mode from a central repository
AnswerC

Ansible connects over SSH and pushes Python modules to managed nodes, executing them remotely without installing a persistent agent. This satisfies the agentless requirement, unlike pull-based configuration tools that mandate agent software on every target machine.

Why this answer

Ansible is agentless by design and connects to managed nodes over standard SSH (or WinRM for Windows). This means no Ansible agent or daemon needs to be installed on target machines — the control node pushes modules over SSH, executes them, and removes them. SSH-based connection is the foundational mechanism that enables this agentless architecture.

Exam trap

CV0-004 often tests the misconception that Ansible requires an agent or that modules run on the control node — candidates must remember that Ansible pushes modules over SSH and executes them on the managed node.

How to eliminate wrong answers

Option A is wrong because inventory files simply list and group managed hosts — they define targets but do not enable agentless operation. Option B is wrong because Ansible modules are pushed to and executed on the managed node (not the control node); stating they run on the control node misrepresents how Ansible works. Option D is wrong because pull mode (ansible-pull) is a less common alternative where nodes pull playbooks from a repository, but it still relies on SSH or local execution and is not the feature that enables agentless operation.

768
MCQmedium

A DevOps team uses Jenkins for CI/CD. They want to automatically deploy containerized applications to a Kubernetes cluster. Which Jenkins feature or plugin can integrate with Kubernetes to manage deployments?

A.Jenkins Declarative Pipeline
B.Jenkins Blue Ocean
C.Jenkins Multibranch Pipeline
D.Kubernetes plugin
AnswerD

The Kubernetes plugin provisions dynamic Jenkins agents as pods in the cluster and executes build steps within them, enabling containerised deployments to be orchestrated directly against Kubernetes. It satisfies the requirement to integrate Jenkins pipelines with cluster-managed deployment workloads.

Why this answer

The Kubernetes plugin for Jenkins allows Jenkins agents to be dynamically provisioned as pods within a Kubernetes cluster, enabling automated deployment of containerized applications. It integrates directly with the Kubernetes API to manage deployments, services, and other resources, making it the correct choice for this scenario.

Exam trap

The CompTIA Cloud+ exam often tests the distinction between Jenkins features that define pipeline logic (like Declarative Pipeline) and plugins that provide external integrations (like the Kubernetes plugin), leading candidates to confuse syntax with integration capabilities.

How to eliminate wrong answers

Option A is wrong because Jenkins Declarative Pipeline is a syntax for defining CI/CD pipelines, not a plugin that integrates with Kubernetes for deployment management. Option B is wrong because Jenkins Blue Ocean is a user interface redesign for Jenkins, providing a modern UI but no native Kubernetes integration or deployment capabilities. Option C is wrong because Jenkins Multibranch Pipeline is a feature that automatically creates pipelines for multiple branches in a repository, but it does not provide Kubernetes-specific deployment integration.

769
MCQeasy

A company is migrating its on-premises application to the cloud and needs to ensure high availability. The application requires a stateless web tier and a stateful database tier. Which design approach BEST meets these requirements?

A.Deploy one large web server and one large database server.
B.Deploy web servers behind a load balancer and use a managed database with multi-AZ replication.
C.Use round-robin DNS for web servers and a read replica for the database.
D.Use auto-scaling for web servers and a single database instance.
AnswerB

Stateless web servers behind a load balancer can be replaced or scaled horizontally across availability zones, while a managed multi-AZ database handles failover and replication for the stateful tier. This separation directly satisfies the high-availability requirement for both tiers.

Why this answer

Deploying web servers behind a load balancer provides horizontal scaling and fault tolerance for the stateless web tier, while using a managed database with multi-AZ replication ensures automatic failover and data durability for the stateful database tier. This combination meets high availability requirements by eliminating single points of failure and providing redundancy across Availability Zones.

Exam trap

CompTIA often tests the misconception that round-robin DNS or a single read replica provides high availability, but candidates must recognize that DNS-based load balancing lacks health checking and automatic failover, and a read replica cannot handle write failures, making multi-AZ replication essential for database high availability.

How to eliminate wrong answers

Option A is wrong because deploying one large web server and one large database server creates a single point of failure; if either server fails, the entire application becomes unavailable, violating high availability. Option C is wrong because round-robin DNS does not provide health checking or automatic failover; if a web server goes down, DNS will still direct traffic to it, causing service disruption, and a read replica for the database does not support automatic failover for writes, leaving the database tier without high availability. Option D is wrong because auto-scaling for web servers addresses scaling but not high availability if all instances are in a single Availability Zone, and a single database instance is a single point of failure; without multi-AZ replication, database failure causes complete downtime.

770
MCQeasy

Which cloud deployment model involves connecting an on-premises data center to a public cloud provider using a VPN or dedicated connection?

A.Private cloud
B.Multi-cloud
C.Hybrid cloud
D.Public cloud
AnswerC

A hybrid cloud specifically joins on-premises infrastructure to a public cloud, typically via VPN or dedicated private link. This satisfies the stem's requirement for that on-premises-to-public-cloud connectivity, distinguishing it from purely public, private or community models.

Why this answer

A hybrid cloud is defined by the integration of on-premises infrastructure (private cloud) with a public cloud provider, typically via a secure network connection such as a VPN or dedicated link (e.g., AWS Direct Connect, Azure ExpressRoute). This model allows workloads and data to move between environments, enabling burst capacity, disaster recovery, and gradual migration. The key differentiator is the interconnection between private and public resources, which is exactly what the question describes.

Exam trap

CV0-004 often tests the confusion between hybrid cloud and multi-cloud, where candidates mistakenly select multi-cloud when on-premises integration is mentioned, or assume any public cloud use is hybrid.

How to eliminate wrong answers

Option A is wrong because a private cloud is dedicated solely to one organization and does not inherently include a public cloud connection; it may be on-premises or hosted, but remains isolated. Option B is wrong because multi-cloud refers to using two or more public cloud providers (e.g., AWS and Azure) without necessarily involving on-premises infrastructure; it does not require a VPN or dedicated link to a private data center. Option D is wrong because a public cloud is a shared, multi-tenant environment offered over the internet; it does not include on-premises integration by definition.

771
MCQmedium

A cloud operations team needs to ensure that all Amazon S3 buckets in their AWS account have server access logging enabled. They want to automatically detect and remediate any bucket that does not have logging enabled. Which combination of AWS services should they use?

A.Amazon GuardDuty with S3 protection and AWS Lambda remediation
B.Amazon Inspector with S3 assessment and AWS Systems Manager Automation
C.AWS CloudTrail with Amazon EventBridge and AWS Lambda to enable logging
D.AWS Config rule with automatic remediation using AWS Systems Manager Automation
AnswerD

AWS Config can evaluate S3 bucket configurations against a rule that checks if server access logging is enabled. When a bucket is non-compliant, Config can trigger automatic remediation using an SSM Automation document that enables logging. This provides continuous compliance and automatic correction, meeting the requirement.

Why this answer

The need is to detect and remediate S3 buckets without server access logging. AWS Config provides managed rules that can check for this configuration. When a bucket is non-compliant, Config can automatically run an SSM Automation document to enable logging.

This creates a continuous compliance loop with automatic remediation, which is the most direct and native solution.

Exam trap

The trap here is assuming that security services like GuardDuty or Inspector can enforce configuration compliance, when AWS Config is the service designed for configuration evaluation and remediation.

772
MCQeasy

A cloud engineer is designing a deployment strategy for a web application that requires zero downtime. The engineer has set up two identical production environments, one active and one idle. After deploying the new version to the idle environment, the engineer switches the DNS record to point to the idle environment. This deployment method is known as:

A.Blue/green deployment
B.Rolling deployment
C.A/B testing deployment
D.Canary deployment
AnswerA

Blue/green deployment maintains two identical environments, routing traffic via DNS cutover from the active (blue) to the idle (green) once the new version is verified. This satisfies the zero-downtime constraint, since the switch is near-instantaneous and rollback simply reverts DNS to the original environment.

Why this answer

Blue/green deployment maintains two identical environments: one live (blue) and one idle (green). After deploying the new version to the idle environment and testing it, traffic is switched from the active to the idle environment, typically via DNS or a load balancer. This provides zero downtime and instant rollback because the previous environment remains intact until the switch is validated.

Exam trap

CV0-004 often tests the distinction between deployment strategies that provide zero downtime versus those that reduce risk; candidates confuse blue/green with canary or rolling because all aim to minimize downtime, but only blue/green uses two identical environments with an atomic traffic switch.

How to eliminate wrong answers

Option B is wrong because rolling deployment updates instances in batches within the same environment, so both old and new versions run simultaneously during the rollout, which can cause compatibility issues and does not provide an instant, atomic cutover. Option C is wrong because A/B testing deployment routes a subset of users to a different version to compare behavior or metrics, not to achieve zero-downtime release of a single new version. Option D is wrong because canary deployment gradually shifts a small percentage of traffic to the new version while the majority still uses the old version, requiring monitoring and progressive rollout rather than an immediate full switch.

773
MCQeasy

A company runs a customer-facing web application on Azure virtual machines. During a regional outage, the operations team needs to bring up the same environment in a secondary Azure region. The team wants an automated, repeatable deployment that includes virtual networks, load balancers, and VM configurations. Which Azure capability should the team use to meet this goal?

A.Azure Resource Manager templates (ARM templates)
B.Azure Cost Management budgets
C.Azure Monitor alert rules
D.Azure Advisor recommendations
AnswerA

ARM templates describe the desired infrastructure declaratively, so the same template can be redeployed to a secondary region to recreate virtual networks, load balancers, and VMs consistently. This provides the automated, repeatable regional deployment the team needs and supports parameterization for region-specific values, making it the appropriate choice for this recovery scenario.

Why this answer

Because the requirement is automated, repeatable deployment of a full resource set into another region, an infrastructure-as-code mechanism is required. ARM templates express the environment declaratively and can be redeployed with region parameters, whereas the other services provide monitoring, recommendations, or cost governance and cannot provision the environment.

Exam trap

The trap here is confusing Azure services that observe or advise on resources with services that actually deploy them.

774
Multi-Selectmedium

A cloud architect is designing a Kubernetes deployment for a stateless web application. The application must be highly available and automatically recover from failures. Which THREE components are required to achieve this? (Select 3)

Select 3 answers
A.ConfigMap
B.Deployment resource
C.Service resource
D.StatefulSet
E.Readiness probe
AnswersB, C, E

A Deployment manages a ReplicaSet, maintaining the desired pod count and recreating failed pods automatically. This reconciliation loop delivers the self-healing, highly available behaviour the stem demands for the stateless web application across node or pod failures.

Why this answer

A Deployment manages replicas and supports rolling updates. A Service provides stable networking to the pods. Readiness probes ensure only healthy pods receive traffic.

ConfigMaps and StatefulSets are not required for stateless HA.

775
MCQeasy

Which of the following is a benefit of using a Web Application Firewall (WAF)?

A.Filtering malicious HTTP/HTTPS traffic to a web application
B.Encrypting data at rest in a database
C.Protecting against DDoS attacks at the network layer
D.Managing user identities and access
AnswerA

A WAF inspects inbound HTTP/HTTPS requests at layer 7, applying rule sets to block SQL injection, cross-site scripting and similar payloads before they reach the web server. This directly satisfies the stem's requirement to filter malicious web traffic rather than merely logging or rate-limiting it.

Why this answer

WAFs protect web applications from common attacks like SQL injection, cross-site scripting, and other OWASP Top 10 threats by filtering and monitoring HTTP/HTTPS traffic.

776
MCQhard

A DevOps team is implementing a canary deployment for a microservice running on Amazon ECS. They want to gradually shift 10% of traffic to the new version and automatically roll back if error rates exceed 1% in 5 minutes. Which combination of services should they use?

A.AWS CloudFormation and SSM
B.AWS Lambda and Step Functions
C.AWS CodeDeploy with CloudWatch alarms
D.AWS Elastic Beanstalk and Route 53
AnswerC

CodeDeploy natively supports ECS canary and linear traffic shifting, and its deployment configuration can reference CloudWatch alarms to trigger automatic rollback. This directly satisfies the 10% gradual shift and the 1%-error-rate/5-minute rollback constraint without custom scripting.

Why this answer

AWS CodeDeploy natively supports canary deployments for Amazon ECS, allowing you to specify a traffic shift percentage (e.g., 10%) and integrate with CloudWatch alarms to automatically trigger a rollback when error rates exceed a defined threshold (e.g., 1% over 5 minutes). This combination directly fulfills the gradual traffic shifting and automated rollback requirements without custom scripting.

Exam trap

A common mistake is assuming that any orchestration service (like Step Functions) is equivalent to a native deployment service, but the key is that CodeDeploy provides built-in traffic shifting and alarm-based rollback without custom code, which is exactly the requirement in the question.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation and SSM are infrastructure provisioning and management tools; they do not provide built-in traffic shifting or automated rollback based on error rate thresholds for ECS deployments. Option B is wrong because AWS Lambda and Step Functions can orchestrate custom deployment logic but require significant custom code to implement traffic shifting and alarm-based rollback, whereas CodeDeploy offers this natively. Option D is wrong because AWS Elastic Beanstalk is a PaaS service that does not support canary deployments for ECS microservices, and Route 53 is a DNS service that cannot shift traffic at the application load balancer level for ECS tasks.

777
MCQmedium

A cloud administrator is troubleshooting a Linux virtual machine (VM) in a public cloud that is experiencing packet loss when communicating with another VM in the same subnet. The administrator runs 'ip -s link show eth0' and observes a high number of dropped packets on the receive side. The VM's CPU utilization is low, and the network interface is a paravirtualized driver (virtio). Which of the following is the MOST likely cause of the dropped packets?

A.The receive ring buffer on the network interface is too small, causing packets to be dropped when the buffer overflows.
B.The VM's firewall is dropping packets due to a misconfigured rule.
C.There is a physical network issue, such as a faulty cable or switch port.
D.The VM's CPU is not allocating enough cycles to process network interrupts.
AnswerA

A high number of receive drops on a virtio interface often indicates that the receive ring buffer is full. When packets arrive faster than the guest can process them, the buffer overflows and packets are dropped. This is common in virtualized environments where the virtio driver's ring size may be default and insufficient for high throughput. Increasing the ring buffer size using ethtool -G can mitigate the issue, and low CPU utilization suggests the guest is not overwhelmed, pointing to buffer capacity.

Why this answer

The high number of receive drops on the virtio interface, combined with low CPU utilization, points to receive ring buffer exhaustion. The virtio driver uses a ring buffer to hold incoming packets; if the buffer is too small for the traffic rate, packets are dropped. Increasing the ring buffer size with ethtool -G eth0 rx <size> can resolve the issue.

Physical network issues and firewall drops are less likely in a cloud environment and would not manifest as interface-level receive drops.

Exam trap

The trap here is assuming that packet loss in the cloud is due to physical network problems, when in virtualized environments it is often a driver buffer or configuration issue.

778
MCQeasy

A cloud engineer is managing infrastructure as code using Terraform. Which command should be run to preview changes before applying them to the cloud environment?

A.terraform apply
B.terraform destroy
C.terraform plan
D.terraform init
AnswerC

`terraform plan` performs a dry run that refreshes state and computes the execution plan, showing exactly which resources will be created, modified or destroyed without touching the cloud environment. This satisfies the stem's requirement to preview changes before applying them, unlike `terraform apply`, which executes them.

Why this answer

The terraform plan command creates an execution plan, showing what actions Terraform will take to change the infrastructure. It is used as a dry run before applying changes.

779
MCQmedium

A cloud operations team runs a three-tier web application on Amazon EC2 instances behind an Application Load Balancer. Users report intermittent 502 errors, and the operations team wants to identify whether the issue originates from unhealthy targets before the load balancer removes them. Which AWS feature should the team enable to actively probe target health at a configurable interval?

A.AWS CloudTrail data events on the target instances
B.VPC Flow Logs on the subnet hosting the targets
C.Application Load Balancer health checks with a shortened healthy and unhealthy threshold
D.Amazon Route 53 latency-based routing with failover records
AnswerC

ALB health checks periodically probe each registered target on a configured protocol, port, and path. Reducing healthy and unhealthy thresholds makes the load balancer react faster to failing targets, which directly addresses identifying unhealthy targets before they serve traffic. This is the native mechanism for detecting target health in an ALB and is the correct operational control in this scenario.

Why this answer

Application Load Balancer health checks are the built-in mechanism that actively probes each registered target and removes unhealthy ones from rotation. Tuning the healthy and unhealthy thresholds lets the team detect failing targets faster and correlate the 502 errors with backend health. Logging and DNS-based services operate at different layers and cannot actively determine target health behind an ALB.

Exam trap

The trap here is assuming that logging services like CloudTrail or Flow Logs perform active health probes, when only the load balancer's own health check mechanism evaluates target health.

780
MCQmedium

A DevOps team is deploying a containerized application to Google Kubernetes Engine (GKE). The team wants to automate the deployment of the application along with its dependencies, such as ConfigMaps and Services, using a single package. Which tool should the team use?

A.Helm charts
B.kubectl apply with multiple manifest files
C.Kustomize overlays
D.Docker Compose
AnswerA

Helm charts package Kubernetes manifests into one versioned, parameterised release, bundling Deployments with ConfigMaps and Services so a single `helm install` deploys the application and its dependencies together. This directly satisfies the stem's requirement for one package automating GKE deployment of the app plus its dependencies.

Why this answer

Helm is the de facto package manager for Kubernetes and bundles all related manifests — Deployments, Services, ConfigMaps, Secrets, Ingress — into a single versioned chart that can be installed, upgraded, and rolled back with one command. This directly matches the requirement to deploy an application and its dependencies as a single package. Helm also supports templating and values files for environment-specific configuration.

Exam trap

CV0-004 often tests the distinction between packaging/lifecycle tools (Helm) and customization tools (Kustomize) or raw kubectl, so candidates who pick Kustomize miss that it does not provide single-package install with versioned releases.

How to eliminate wrong answers

Option B is wrong because kubectl apply with multiple manifests is imperative, has no packaging, versioning, or rollback semantics, and requires manually tracking which files belong together. Option C is wrong because Kustomize overlays customize existing manifests for different environments but do not package an application with dependencies into a single installable unit with lifecycle management. Option D is wrong because Docker Compose is a local development tool for Docker, not a GKE/Kubernetes packaging mechanism, and does not deploy native Kubernetes resources.

781
Multi-Selecthard

Which THREE are common tasks in a CI/CD pipeline? (Select THREE.)

Select 3 answers
A.Manual code review by a senior developer
B.Handwritten notes for deployment steps
C.Source code checkout from version control
D.Deployment to a staging or production environment
E.Automated testing (unit, integration, etc.)
AnswersC, D, E

Source code checkout retrieves the repository revision that triggers the pipeline, supplying the artefact for subsequent build and test stages. It is a standard opening task in CI/CD workflows, distinct from deployment, monitoring or infrastructure provisioning activities.

Why this answer

Option C is correct because a CI/CD pipeline begins by checking out source code from a version control system such as Git, which triggers the automated build and test stages. Option D is correct because the CD portion of the pipeline automates deployment to staging or production environments, often using tools like Jenkins, GitLab CI, or Argo CD. Option E is correct because automated testing (unit, integration, and similar tests) is a core CI activity that validates each code change before it progresses further in the pipeline.

Options A and B are not correct: manual code review, while valuable, is a human process rather than an automated pipeline task, and handwritten deployment notes are the opposite of the automation that CI/CD pipelines are designed to provide.

Exam trap

CompTIA often tests the distinction between manual, human-in-the-loop activities (like code review or handwritten notes) and fully automated, scripted steps that are essential to a CI/CD pipeline, leading candidates to mistakenly include manual tasks as pipeline tasks.

782
Multi-Selectmedium

A company's application is unable to connect to a managed cloud database. The database is deployed in a VPC with public accessibility disabled. The application runs on an EC2 instance in the same VPC. Which three troubleshooting steps should the administrator take? (Choose three.)

Select 3 answers
A.Ensure the VPC has an internet gateway attached.
B.Check the network ACL associated with the database subnet for appropriate rules.
C.Verify that the database endpoint is correctly configured in the application.
D.Verify that the EC2 instance has a public IP address.
E.Check the security group for the database to ensure it allows inbound traffic from the EC2 instance's security group.
AnswersB, C, E

Network ACLs are stateless and evaluated per subnet, unlike security groups. The database subnet's ACL must permit inbound traffic on the database port and outbound return traffic to the EC2 subnet's ephemeral range, or packets are dropped before reaching the database.

Why this answer

Option B is correct because network ACLs are stateless subnet-level firewalls; if the database subnet's NACL lacks an inbound rule allowing the database port (e.g., 3306 for MySQL or 5432 for PostgreSQL) from the EC2 instance's subnet CIDR, and a corresponding outbound rule for the return traffic, connectivity will fail even if security groups are correct. Option C is correct because a misconfigured endpoint (wrong hostname, port, or database name) in the application's connection string is a common cause of connection failures and must be verified before deeper network troubleshooting. Option E is correct because the database's security group must have an inbound rule referencing the EC2 instance's security group (or its CIDR) on the database listener port; since the database is not publicly accessible, this security group reference is the primary stateful access control.

Option A is not needed because an internet gateway only enables internet connectivity for public subnets and is irrelevant for instance-to-database traffic within the same VPC. Option D is not needed because a public IP is only required for internet-facing communication, not for private communication between an EC2 instance and a database in the same VPC.

Exam trap

CV0-004 often tests the misconception that private intra-VPC connectivity requires an internet gateway or public IP, when in fact security groups, NACLs, and endpoint configuration are the real determinants.

783
MCQmedium

A cloud administrator needs to apply security patches to a fleet of EC2 instances running Windows Server. The patches must be applied during a maintenance window to minimize downtime. Which AWS service can automate patching?

A.AWS CloudFormation
B.AWS Systems Manager Patch Manager
C.AWS Config
D.Amazon Inspector
AnswerB

Patch Manager, part of AWS Systems Manager, applies OS and security patches to managed EC2 instances on a schedule you define. Configuring a maintenance window satisfies the low-downtime constraint, since patching runs automatically during the specified period rather than requiring manual intervention on each instance.

Why this answer

AWS Systems Manager Patch Manager automates the process of patching EC2 instances, including Windows Server, and supports maintenance windows to control when patches are applied. It can scan for missing patches and install them on a schedule, minimizing downtime.

Exam trap

CV0-004 often tests whether candidates confuse vulnerability assessment tools like Inspector with remediation tools like Patch Manager, or pick CloudFormation because it sounds like automation.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources, not for applying OS patches. Option C is wrong because AWS Config evaluates resource compliance and configuration changes, but it does not install patches. Option D is wrong because Amazon Inspector assesses vulnerabilities and can identify missing patches, but it does not apply them.

784
Multi-Selecthard

A cloud administrator is troubleshooting a performance issue where a web application is responding slowly. The application runs on virtual machines in a private cloud. The administrator has verified that CPU and memory utilization are within normal limits. Which TWO additional metrics should the administrator check to diagnose the issue?

Select 2 answers
A.Number of running processes
B.Network latency between the application and database servers
C.Disk I/O wait time on the hypervisor
D.Virtual machine snapshot size
E.Hypervisor version
AnswersB, C

Network latency directly affects request round-trip time between application and database tiers, a bottleneck CPU and memory metrics cannot reveal. Since the stem confirms compute resources are normal, measuring inter-tier latency isolates transport delay or congestion as the cause of slow responses, satisfying the need to identify non-compute performance constraints.

Why this answer

Network latency between the application and database servers is a critical metric because slow database queries or network congestion can cause the web application to respond slowly even when CPU and memory on the VMs are normal. High latency increases round-trip time for SQL queries, directly impacting page load times. Disk I/O wait time on the hypervisor is also essential because excessive I/O wait indicates storage contention, which can throttle read/write operations for the VMs, leading to application sluggishness.

Exam trap

CompTIA often tests the distinction between VM-level metrics (CPU/memory) and infrastructure-level metrics (network/storage), trapping candidates who overlook that application performance can degrade due to external dependencies even when the VM itself appears healthy.

785
Multi-Selecthard

A cloud architect is designing a disaster recovery strategy for a mission-critical application hosted in a single cloud region. The business requires that the application survive the loss of an entire region and that failover be largely automated with minimal data loss. The budget permits a warm standby environment. Which TWO design elements should the architect include to meet these requirements? (Choose two.)

Select 2 answers
A.Rely on manual runbooks to rebuild the environment after a regional outage is detected.
B.Deploy a warm standby environment in a second region that can be scaled up on failover.
C.Store nightly database backups exclusively in the primary region's object storage.
D.Configure the application to use a single availability zone within the primary region for lowest latency.
E.Replicate application data and configurations to a second region continuously.
AnswersB, E

A warm standby runs a reduced but functional copy of the application in another region, so failover does not require building infrastructure from scratch. It can be scaled to full capacity when the primary region fails, meeting the automated, low-downtime requirement while respecting the budget that rules out a fully active-active deployment. This directly addresses surviving a regional outage.

Why this answer

Surviving a full regional outage with minimal data loss requires both a copy of the data and configuration outside the failed region and a second-region environment ready to take over. Continuous cross-region replication minimizes the recovery point objective, while a warm standby that scales up on failover provides a rapid, largely automated recovery path within the stated budget.

Exam trap

The trap here is assuming that in-region redundancy such as multiple availability zones protects against the loss of an entire region.

786
MCQhard

A company uses a hybrid cloud model with an AWS Direct Connect connection to its on-premises network. Users report intermittent connectivity to cloud resources. A network engineer finds packet loss on the Direct Connect virtual interface. Which of the following should be checked FIRST to resolve the issue?

A.The physical port status of the Direct Connect router
B.The MTU setting on the on-premises firewall
C.The BGP session status between the on-premises router and the AWS Direct Connect endpoint
D.The VPN tunnel status for the Direct Connect link
AnswerC

Packet loss on a Direct Connect virtual interface most commonly stems from a flapping or down BGP session, which withdraws routes and drops traffic. Verifying the BGP session status between the on-premises router and the AWS endpoint is the fastest first diagnostic step.

Why this answer

Intermittent packet loss on a Direct Connect virtual interface is most commonly caused by BGP session flapping or misconfiguration, as BGP is the routing protocol that establishes and maintains connectivity between the on-premises router and the AWS Direct Connect endpoint. Checking the BGP session status first allows the engineer to quickly identify if the issue is due to route advertisement problems, hold timer mismatches, or session resets, which are frequent root causes of intermittent packet loss.

Exam trap

The trap here is that candidates often confuse Direct Connect with VPN-based connections and assume a VPN tunnel is involved, leading them to check VPN status (Option D) instead of the BGP session that actually governs the virtual interface routing.

How to eliminate wrong answers

Option A is wrong because the physical port status of the Direct Connect router would show a hard failure (e.g., link down) rather than intermittent packet loss; intermittent issues are rarely caused by physical port problems unless there is a duplex mismatch or cable fault, but these are less likely to be the first check. Option B is wrong because MTU settings on the on-premises firewall typically cause fragmentation or black-hole issues for large packets, not intermittent packet loss across all traffic; MTU mismatches usually result in consistent packet drops for packets exceeding the MTU, not sporadic loss. Option D is wrong because Direct Connect does not use a VPN tunnel; it is a dedicated physical connection, and VPN tunnels are used for AWS Site-to-Site VPN, not Direct Connect virtual interfaces.

787
MCQeasy

A cloud architect is designing a network to protect a web application from common attacks such as SQL injection and cross-site scripting. Which cloud service should be used?

A.DDoS Protection
B.Network ACL
C.Web Application Firewall (WAF)
D.Security Group
AnswerC

A WAF inspects HTTP/S traffic at the application layer, filtering injection and scripting payloads via managed rule sets. Network firewalls and security groups operate at lower layers and cannot parse request content, so they miss these attacks. This directly satisfies the requirement to protect the web application.

Why this answer

A Web Application Firewall (WAF) is specifically designed to inspect HTTP/HTTPS traffic and block application-layer attacks such as SQL injection, cross-site scripting (XSS), and other OWASP Top 10 threats. It operates at Layer 7 and applies rule sets or signatures to web requests and responses. This makes it the correct cloud service for protecting a web application from these attacks.

Exam trap

CV0-004 often tests the confusion between Layer 3/4 controls (Security Groups, NACLs, DDoS Protection) and Layer 7 controls (WAF) — candidates pick Security Groups or NACLs because they sound like firewalls, but only a WAF inspects application payloads for SQLi/XSS.

How to eliminate wrong answers

Option A is wrong because DDoS Protection mitigates volumetric and protocol-level floods (Layer 3/4), not application-layer injection or scripting attacks. Option B is wrong because a Network ACL is a stateless Layer 3/4 packet filter based on IP, port, and protocol — it cannot inspect HTTP payloads for SQLi or XSS. Option D is wrong because a Security Group is a stateful Layer 3/4 virtual firewall for instances, filtering by IP/port/protocol but not inspecting application content.

788
MCQmedium

A cloud administrator receives an alert that the CPU usage on a virtual machine has spiked to 100% for 10 minutes. The VM hosts a critical application. What is the best first step?

A.Check the VM's performance metrics for the last hour to identify the process causing the spike.
B.Immediately reboot the VM.
C.Move the VM to a different host.
D.Increase the VM's CPU limits.
AnswerA

Reviewing the VM's performance metrics for the preceding hour establishes whether the 100% CPU spike is sustained, transient, or recurring, and identifies the offending process. This evidence-based diagnosis precedes remediation, avoiding disruptive actions on a critical application.

Why this answer

Checking the VM's performance metrics for the last hour is the best first step because it allows the administrator to identify the specific process or application causing the CPU spike without disrupting service. This diagnostic approach aligns with the ITIL problem management framework, which emphasizes root cause analysis before taking corrective action. In a virtualized environment, tools like vCenter Performance Charts or Hyper-V Performance Monitor can pinpoint whether the spike is due to a runaway process, a memory leak, or a scheduled task, enabling a targeted resolution.

Exam trap

The trap here is that candidates often jump to immediate remediation actions like rebooting or migrating the VM, overlooking the fundamental troubleshooting principle of gathering diagnostic data first to avoid recurring issues and unnecessary downtime.

How to eliminate wrong answers

Option B is wrong because immediately rebooting the VM is a reactive measure that may temporarily clear the symptom but does not address the root cause, and it causes unnecessary downtime for a critical application. Option C is wrong because moving the VM to a different host (vMotion) only shifts the resource contention to another physical server without resolving the underlying process issue, and it may not help if the spike is application-specific. Option D is wrong because increasing the VM's CPU limits without first investigating the cause can mask the problem, potentially leading to resource starvation for other VMs and violating capacity planning best practices.

789
MCQmedium

A cloud administrator needs to perform a disaster recovery test for a critical application running in a different AWS region. The RTO is 1 hour, and the RPO is 15 minutes. Which replication strategy should be used to meet the RPO?

A.Hourly snapshot-based replication
B.Daily snapshot-based replication
C.Cross-region replication with eventual consistency
D.Continuous replication
AnswerD

Continuous replication copies every write to the DR region, giving an RPO measured in seconds or minutes, comfortably inside the 15-minute target. Snapshot or batch approaches would leave larger gaps between recovery points, breaching the stated RPO.

Why this answer

Continuous replication replicates data continuously, so the recovery point objective (RPO) — the maximum acceptable data loss — can be as low as seconds or minutes, meeting the 15-minute requirement. Snapshot-based approaches at hourly or daily intervals cannot meet a 15-minute RPO.

Exam trap

CV0-004 often tests whether candidates match snapshot frequency to RPO incorrectly, or pick 'eventual consistency' as a replication strategy when the question demands a specific RPO guarantee.

How to eliminate wrong answers

Option A is wrong because hourly snapshots mean up to 60 minutes of data loss, which exceeds the 15-minute RPO. Option B is wrong because daily snapshots mean up to 24 hours of data loss, far exceeding the RPO. Option C is wrong because cross-region replication with eventual consistency does not guarantee a specific RPO and is not a defined replication strategy for meeting a 15-minute RPO in this context.

790
MCQmedium

A security engineer is configuring a network security group (NSG) in Azure to allow inbound HTTPS traffic to a web server. The engineer creates an inbound rule allowing TCP port 443 from the Internet. What must be done to ensure the web server can respond to clients?

A.Create an outbound rule allowing all traffic to the Internet.
B.Create an inbound rule allowing TCP port 443 from the web server.
C.Create an outbound rule allowing TCP port 443 to the Internet.
D.No additional rule is needed because the NSG is stateful.
AnswerD

Network security groups are stateful, so return traffic for an allowed inbound connection is automatically permitted regardless of outbound rules. Because the inbound TCP 443 rule already establishes the flow, replies from the web server reach clients without any additional outbound rule.

Why this answer

NSGs are stateful; allowing inbound traffic automatically allows the corresponding outbound response traffic.

791
MCQeasy

A cloud administrator needs to deploy a new application that requires a static IP address. The administrator is using a cloud provider that allows the reservation of elastic IP addresses. Which deployment step should be taken to ensure the IP address is not lost when the resource is stopped?

A.Configure the instance to obtain an IP via DHCP.
B.Allocate an elastic IP address and associate it with the resource.
C.Assign a private IP address from a reserved range.
D.Set up an external DNS service to point to the public IP.
AnswerB

Elastic IP addresses are reserved, account-level public addresses that persist independently of any instance lifecycle. Associating one with the resource means stopping or restarting it preserves the same static public IP, satisfying the no-loss constraint.

Why this answer

Elastic IP addresses are static public IPv4 addresses that you can allocate to your account and associate with a resource. When you associate an elastic IP with an instance, it persists even if the instance is stopped, because the IP is reserved in your account until you explicitly release it. This ensures the IP address is not lost when the resource is stopped, unlike ephemeral public IPs that change on stop/start.

Exam trap

CompTIA often tests the distinction between ephemeral public IPs (which are lost on stop/start) and elastic/reserved IPs (which persist), and the trap here is that candidates may confuse a static private IP (Option C) with a static public IP, or think DNS alone (Option D) can prevent IP loss.

How to eliminate wrong answers

Option A is wrong because configuring DHCP only assigns a dynamic private IP address, which does not provide a static public IP and may change on stop/start. Option C is wrong because assigning a private IP from a reserved range gives a static private address, but the question requires a static public IP address for external access. Option D is wrong because setting up an external DNS service only maps a domain name to an IP; it does not prevent the underlying public IP from changing when the instance is stopped.

792
MCQeasy

A cloud administrator manages a fleet of Amazon EC2 instances that must receive operating system patches on a defined schedule. The administrator wants to automate patching, control the maintenance window, and receive compliance reports showing which instances are missing patches. Which AWS service should the administrator use?

A.AWS Config with managed rules for patch compliance
B.Amazon Inspector with automated assessment schedules
C.AWS Trusted Advisor with security category checks
D.AWS Systems Manager Patch Manager
AnswerD

Patch Manager, part of AWS Systems Manager, automates patching of EC2 instances and on-premises managed nodes using patch baselines, maintenance windows, and compliance reporting. It supports scheduled scans and installs, and its compliance dashboard shows which nodes are missing patches. This directly satisfies the requirement for automated, scheduled patching with compliance visibility across the fleet.

Why this answer

AWS Systems Manager Patch Manager is built to automate operating system patching across EC2 and hybrid nodes. It combines patch baselines, maintenance windows, and compliance reporting so the administrator can schedule installs and prove which instances are compliant. Other services either assess configuration or detect vulnerabilities but do not install patches or provide the required scheduling and compliance workflow.

Exam trap

The trap here is confusing vulnerability assessment or configuration tracking services with the service that actually installs operating system patches on a schedule.

793
MCQmedium

A security engineer is configuring an AWS IAM policy for a new application. The policy must allow the application to read objects from a specific S3 bucket. Which IAM policy element determines whether the action is allowed or denied?

A.Effect
B.Action
C.Resource
D.Condition
AnswerA

The Effect element specifies whether a matching statement results in Allow or Deny, making it the axis that determines the policy outcome. With the action and resource already scoped to s3:GetObject on the named bucket, Effect supplies the explicit Allow the stem requires.

Why this answer

The Effect element in an IAM policy specifies whether the statement allows or denies access. It is a required element that can be set to 'Allow' or 'Deny'. In this case, to allow the application to read objects, the Effect must be 'Allow'.

Therefore, the Effect element determines whether the action is allowed or denied.

Exam trap

The trap is confusing the roles of the four elements; candidates might think Action or Resource determines allow/deny, but only Effect explicitly sets the permission outcome.

How to eliminate wrong answers

Option B is wrong because Action specifies the API operations (e.g., s3:GetObject) that the policy applies to, but it does not determine allow/deny by itself. Option C is wrong because Resource specifies the object or objects the policy applies to (e.g., a specific S3 bucket), but it does not determine allow/deny. Option D is wrong because Condition specifies circumstances under which the policy is in effect (e.g., IP range, MFA), but it does not determine allow/deny; it only refines when the statement applies.

794
MCQeasy

A cloud engineer is writing Terraform code to provision AWS resources. They need to define the cloud provider and authentication details. Which block should they use in their HCL configuration?

A.resource block
B.provider block
C.variable block
D.module block
AnswerB

The provider block declares the cloud platform, such as AWS, and supplies authentication details like access keys or region, so Terraform knows which API to call and how to authenticate. Resource blocks then reference that configured provider when provisioning.

Why this answer

In HashiCorp Configuration Language (HCL), the provider block declares which cloud provider Terraform should use (e.g., aws, azure, google) and supplies the configuration needed to authenticate and target the correct region or account. For AWS, this includes region, access keys, or references to credential profiles/roles. Without a provider block, Terraform cannot know which API to call or how to authenticate.

Exam trap

The trap is conflating the block that defines infrastructure (resource) with the block that defines how Terraform authenticates and connects (provider); candidates who focus on 'provisioning AWS resources' may wrongly select the resource block.

How to eliminate wrong answers

Option A is wrong because a resource block defines a specific infrastructure object to create or manage (e.g., aws_instance, aws_s3_bucket); it consumes the provider configuration but does not define it. Option C is wrong because a variable block declares input parameters that make configurations reusable and parameterized — it does not configure provider authentication. Option D is wrong because a module block calls a reusable collection of Terraform configurations; it packages resources but does not itself define provider credentials or endpoints.

795
MCQmedium

A cloud administrator notices that a cloud-based web application is experiencing intermittent latency during peak hours. The application runs on an auto-scaling group of virtual machines behind a load balancer. Which of the following should the administrator investigate FIRST to resolve the issue?

A.Review the auto-scaling group's scaling policies and thresholds
B.Enable SSL offloading on the load balancer
C.Verify the load balancer's health check interval
D.Check DNS resolution times for the application domain
AnswerA

Intermittent peak-hour latency points to insufficient or mistuned scaling, so the scaling policies and thresholds govern whether capacity keeps pace with demand. Verifying them first confirms whether the auto-scaling group adds instances quickly enough before investigating load balancer or instance-level causes.

Why this answer

The intermittent latency during peak hours is most likely caused by the auto-scaling group's scaling policies not reacting quickly enough or being set with thresholds that are too high, leading to insufficient capacity under load. Investigating the scaling policies and thresholds first directly addresses the root cause—whether the group is adding instances too slowly or at too high a utilization trigger—rather than symptoms like health checks or DNS. This aligns with the operational best practice of verifying capacity management before tuning network or load-balancer settings.

Exam trap

The trap here is that candidates confuse load balancer tuning (SSL offloading, health checks) with capacity issues, overlooking that auto-scaling policies directly control the number of instances available to handle peak load.

How to eliminate wrong answers

Option B is wrong because enabling SSL offloading on the load balancer reduces CPU overhead on backend VMs but does not address insufficient capacity during peak hours; it is a performance optimization, not a scaling fix. Option C is wrong because verifying the load balancer's health check interval checks instance health status, not scaling responsiveness; a misconfigured health check might cause traffic misrouting but not intermittent latency from under-provisioning. Option D is wrong because checking DNS resolution times addresses client-side name resolution delays, which are unrelated to backend capacity or auto-scaling behavior; DNS caching typically masks such issues and does not cause intermittent peak-hour latency.

796
MCQeasy

According to the shared responsibility model, which of the following is the cloud provider responsible for?

A.Operating system patching
B.Physical infrastructure security
C.Application code security
D.Identity and access management configuration
AnswerB

Under the shared responsibility model, the cloud provider owns security of the cloud: datacentre facilities, hardware, networking and physical access controls. The customer remains responsible for security in the cloud, covering guest OS patching, application configuration and identity management.

Why this answer

Under the shared responsibility model, the cloud provider is always responsible for the security OF the cloud — the physical facilities, hardware, network fabric, and hypervisor layer that underpin the service. Physical infrastructure security (data center access controls, hardware disposal, environmental controls) is entirely the provider's domain and cannot be delegated to the customer. Customers are responsible for security IN the cloud, which covers their data, configurations, and workloads.

Exam trap

The trap here is confusing 'security OF the cloud' (provider) with 'security IN the cloud' (customer) — candidates often assume the provider patches everything, but OS patching and IAM remain customer duties in most service models.

How to eliminate wrong answers

Option A is wrong because operating system patching is a customer responsibility in IaaS (and shared in PaaS), not the provider's — the customer owns guest OS patching for their instances. Option C is wrong because application code security always belongs to the customer, since the provider has no visibility into or control over the customer's application logic. Option D is wrong because identity and access management configuration is a customer responsibility — the customer defines users, roles, permissions, and MFA policies for their own tenant.

797
MCQhard

A cloud administrator is troubleshooting a performance issue where an application occasionally experiences high latency. The application runs on AWS and uses EC2, ELB, and RDS. Which combination of tools would best help trace the request flow and identify the bottleneck?

A.AWS X-Ray and VPC Flow Logs
B.AWS Trusted Advisor and AWS Personal Health Dashboard
C.Amazon CloudWatch Logs and AWS Shield
D.AWS CloudTrail and AWS Config
AnswerA

X-Ray traces requests across EC2, ELB and RDS, exposing per-segment latency so the bottleneck service is identified. VPC Flow Logs complement this by revealing network-level drops or rejects along the path that tracing alone may not show.

Why this answer

AWS X-Ray traces requests through the application, including calls to downstream services like RDS, and VPC Flow Logs capture IP traffic to and from network interfaces, helping identify network-level bottlenecks. Together, they provide end-to-end visibility from the request entry point to the database and network layer. This combination is best for tracing request flow and pinpointing latency issues.

Exam trap

CV0-004 often tests the confusion between auditing tools (CloudTrail, Config) and performance tracing tools (X-Ray, Flow Logs), leading candidates to choose options that provide compliance or configuration data instead of latency insights.

How to eliminate wrong answers

Option B is wrong because Trusted Advisor provides best practice checks and Personal Health Dashboard shows AWS service health, neither of which trace request flow or identify application bottlenecks. Option C is wrong because CloudWatch Logs can capture application logs but does not trace requests across services, and AWS Shield is for DDoS protection, not performance troubleshooting. Option D is wrong because CloudTrail records API activity for auditing, and AWS Config tracks resource configurations, neither of which helps trace request flow or latency.

798
Multi-Selectmedium

A cloud security team is implementing the principle of least privilege for IAM roles. Which TWO actions are consistent with this principle?

Select 2 answers
A.Grant full administrative access to all users to simplify management
B.Regularly review and revoke unused permissions
C.Create custom roles with only the specific permissions needed for each job function
D.Use wildcard (*) permissions to allow all actions on a resource
E.Assign root user access to all developers
AnswersB, C

Regularly reviewing and revoking unused permissions enforces least privilege by continuously shrinking each IAM role's effective permissions. This satisfies the stem's constraint because stale, unused grants are removed rather than left accumulating, limiting the blast radius if credentials are compromised.

Why this answer

Option B is correct because regularly reviewing and revoking unused permissions enforces least privilege over time, eliminating accumulated or stale entitlements that could be exploited. Option C is correct because creating custom roles scoped to only the specific permissions each job function requires directly embodies least privilege, granting no more access than necessary. Option A is wrong because granting full administrative access to all users violates least privilege by massively over-provisioning rights.

Option D is wrong because wildcard (*) permissions allow all actions on a resource, which is the opposite of narrowly scoped access. Option E is wrong because assigning root user access to all developers grants the most privileged account to many people, directly contradicting least privilege.

Exam trap

CV0-004 often tests the difference between least privilege and convenience — candidates may pick 'full admin to simplify management' because it sounds operationally efficient, but it directly contradicts the principle.

799
MCQeasy

A cloud architect is designing a serverless application using Azure Functions. The function must process messages from an Azure Storage Queue. How should the architect configure the trigger?

A.Blob trigger
B.Event Grid trigger
C.Queue trigger
D.HTTP trigger with queue polling
AnswerC

A queue trigger binds the function to an Azure Storage Queue, so the Functions runtime polls the queue and invokes the function whenever a message arrives. This is the native mechanism for queue-driven, serverless message processing without manual polling code.

Why this answer

Azure Functions natively supports a Queue trigger that automatically polls an Azure Storage Queue for new messages and executes the function code when a message is detected. This is the simplest and most efficient way to process messages from a Storage Queue without custom polling logic.

Exam trap

CompTIA Cloud+ candidates often mistakenly choose Event Grid because it is event-driven, but it does not directly integrate with Storage Queues without custom event subscriptions.

How to eliminate wrong answers

Option A is wrong because a Blob trigger is designed to respond to blob storage events (e.g., new or updated blobs), not queue messages. Option B is wrong because an Event Grid trigger handles events from Azure Event Grid, which is a separate event routing service, not a direct queue message source. Option D is wrong because an HTTP trigger with queue polling would require custom code to poll the queue, which defeats the purpose of using a built-in trigger and adds unnecessary complexity.

800
MCQhard

A company is moving a legacy monolithic application to the cloud. The application has interdependencies that make it difficult to refactor. The architect needs to minimize changes while gaining cloud benefits like elasticity and pay-as-you-go. Which migration strategy is BEST?

A.Retire
B.Repurchase
C.Refactor / Re-architect
D.Rehost (Lift and shift)
AnswerD

Rehost moves the existing application to the cloud with minimal changes, meeting the requirement.

Why this answer

Rehosting (lift and shift) is the best strategy because it moves the monolithic application to the cloud with minimal changes, preserving existing interdependencies. This allows the company to immediately gain cloud benefits like elasticity and pay-as-you-go pricing without refactoring the tightly coupled codebase. The application runs on cloud infrastructure (e.g., EC2 instances) as-is, leveraging auto-scaling and resource optimization.

Exam trap

CompTIA often tests the misconception that 'cloud-native benefits require refactoring,' but the trap here is that rehosting still provides elasticity and pay-as-you-go via infrastructure-level scaling, even without application changes.

How to eliminate wrong answers

Option A is wrong because retiring the application would eliminate it entirely, which does not meet the goal of gaining cloud benefits while keeping the application running. Option B is wrong because repurchasing involves replacing the application with a SaaS product, which requires significant changes and may not support the existing interdependencies. Option C is wrong because refactoring/re-architecting involves modifying the application code to break dependencies, which contradicts the requirement to minimize changes.

801
MCQmedium

A security auditor is reviewing the IAM configuration for a cloud account. The auditor finds that a user has permissions to create and delete resources in all services. Which principle of security is being violated?

A.Need to know
B.Defense in depth
C.Least privilege
D.Separation of duties
AnswerC

Granting a user create and delete permissions across all services exceeds what their role requires, breaching least privilege, which limits rights to the minimum needed. The other principles address separation of duties, defence in depth and need to know, not excessive permission scope.

Why this answer

The principle of least privilege is violated because the user has permissions to create and delete resources in all services, which is far more than necessary for their role. Least privilege requires granting only the minimum permissions needed to perform a task.

Exam trap

CV0-004 often tests security principles, and candidates might confuse least privilege with separation of duties or need to know, especially when the scenario involves broad permissions.

How to eliminate wrong answers

Option A is wrong because 'need to know' is about information access, not resource permissions. Option B is wrong because 'defense in depth' is about layered security controls, not about excessive permissions. Option D is wrong because 'separation of duties' is about dividing tasks among different users to prevent fraud, but the issue here is excessive permissions for a single user.

802
Multi-Selectmedium

A cloud operations team is designing a disaster recovery plan that includes regular testing. Which TWO activities should be part of the DR testing process? (Select TWO.)

Select 2 answers
A.Updating security patches
B.Reviewing billing reports
C.Chaos engineering experiments
D.Scheduled DR drills
E.Performing daily backups
AnswersC, D

Chaos engineering deliberately injects faults to validate resilience and recovery behaviour, satisfying the stem's requirement for regular DR testing. Unlike tabletop exercises, it verifies actual failover mechanisms under controlled failure conditions, exposing gaps between documented recovery procedures and real system responses before a genuine disaster occurs.

Why this answer

Option C (Chaos engineering experiments) is correct because deliberately injecting controlled failures into the environment validates that failover, redundancy, and recovery mechanisms actually work under real-world fault conditions, which is a core goal of DR testing. Option D (Scheduled DR drills) is correct because recurring, planned exercises such as failover/failback tests and tabletop simulations verify that recovery time objectives (RTO) and recovery point objectives (RPO) can be met and that runbooks and personnel are effective. Option A (Updating security patches) is a routine vulnerability-management task, not a DR test, even though patching supports overall resilience.

Option B (Reviewing billing reports) is a cost-management activity unrelated to validating recovery capabilities. Option E (Performing daily backups) is a data-protection prerequisite that DR testing depends on, but the backup operation itself is not a test of recovery readiness.

Exam trap

The trap is conflating routine operational hygiene (patching, backups, billing) with actual DR testing — candidates pick backups because they sound disaster-related, but backups are preparation, not testing.

803
MCQeasy

A cloud architect needs to monitor CPU utilization across a fleet of EC2 instances and receive an alert when the average CPU exceeds 80% for 10 minutes. Which AWS service should be used to collect the metric and trigger the alert?

A.AWS Systems Manager
B.AWS Config
C.AWS CloudTrail
D.Amazon CloudWatch
AnswerD

Amazon CloudWatch collects EC2 CPU metrics via the hypervisor and evaluates them against alarms, using periods and evaluation periods to require the average to exceed 80% across 10 minutes before triggering. This satisfies both the fleet-wide collection and sustained-threshold alerting requirements.

Why this answer

Amazon CloudWatch is the AWS native monitoring service that collects EC2 metrics such as CPUUtilization at one-minute granularity (or finer with detailed monitoring) and supports CloudWatch Alarms with configurable thresholds and evaluation periods. An alarm can be set to trigger when the average CPUUtilization exceeds 80% for 10 minutes (e.g., 2 consecutive 5-minute periods or 10 consecutive 1-minute periods). CloudWatch also integrates with SNS for notifications and Auto Scaling for automated responses.

Exam trap

The trap is confusing monitoring (CloudWatch) with configuration compliance (Config) or API auditing (CloudTrail) — candidates who haven't internalized the 'metrics vs. config vs. API calls' split often pick Config or CloudTrail.

How to eliminate wrong answers

Option A is wrong because AWS Systems Manager is for operational management — patching, run commands, parameter store, session manager — not for metric collection or threshold alerting. Option B is wrong because AWS Config evaluates resource configuration compliance against rules (e.g., 'is this S3 bucket encrypted?'), not runtime performance metrics like CPU utilization. Option C is wrong because AWS CloudTrail records API activity and audit events (who called what API when), not infrastructure performance metrics.

804
MCQhard

A company runs a critical application on a cloud VM that must achieve a 99.99% monthly uptime SLA. The VM is deployed in a single availability zone. The current architecture has no redundancy. What is the most effective design change to meet the SLA requirement?

A.Schedule daily backups to a different region
B.Deploy the application across two availability zones with a load balancer
C.Upgrade the VM to a larger instance type for better reliability
D.Add a second VM in the same availability zone with a load balancer
AnswerB

A single-zone VM cannot reach 99.99% monthly uptime because any zone failure causes total outage. Spreading the application across two availability zones behind a load balancer removes that single point of failure, satisfying the redundancy the SLA demands.

Why this answer

Deploying the application across two availability zones with a load balancer provides high availability by eliminating a single point of failure. A 99.99% monthly uptime SLA requires a design that can withstand an entire availability zone failure, which a single-zone deployment cannot achieve. The load balancer distributes traffic to healthy VMs, automatically failing over if one zone becomes unavailable, thus meeting the SLA target.

Exam trap

CompTIA often tests the distinction between high availability (redundancy across zones) and disaster recovery (backups to another region), leading candidates to mistakenly choose backup solutions for uptime requirements.

How to eliminate wrong answers

Option A is wrong because daily backups to a different region provide disaster recovery, not high availability; they do not prevent downtime during an availability zone failure, as restoring from backup takes significant time and cannot achieve 99.99% uptime. Option C is wrong because upgrading to a larger instance type improves performance and may reduce hardware-related failures, but it does not protect against availability zone outages or other infrastructure failures that cause downtime. Option D is wrong because adding a second VM in the same availability zone with a load balancer still creates a single point of failure at the zone level; if the entire availability zone fails, both VMs become unavailable simultaneously.

805
MCQmedium

A company runs a production application on multiple cloud regions for high availability. They want to minimize latency for global users. Which DNS routing policy should they use?

A.Latency routing
B.Failover routing
C.Geolocation routing
D.Simple routing
AnswerA

Latency routing directs each user to the region responding fastest, measured by actual network round-trip time. This satisfies the minimise-latency constraint for global users, unlike failover or weighted policies which prioritise availability or distribution rather than per-user responsiveness.

Why this answer

Latency routing in DNS directs users to the region with the lowest network latency, which is ideal for minimizing latency for global users. It uses latency measurements between the user's resolver and the various regional endpoints to select the best-performing region. This is distinct from geolocation routing, which routes based on the user's geographic location rather than actual network performance.

Exam trap

CV0-004 often tests the confusion between latency routing and geolocation routing — candidates assume that routing based on geography always minimizes latency, but latency routing uses actual network measurements and can route a user to a different region than their geographic location.

How to eliminate wrong answers

Option B is wrong because failover routing is designed for disaster recovery — it routes to a primary endpoint and only switches to a secondary when the primary fails, not for latency optimization. Option C is wrong because geolocation routing directs users based on their geographic location (e.g., country or continent), which does not always correlate with the lowest latency — a user in a border region might be closer to a different region. Option D is wrong because simple routing returns a single record with no intelligence about latency, failover, or geography.

806
MCQeasy

An organization wants to ensure that only authorized personnel can access the cloud management console. Which of the following is the BEST method to achieve this?

A.Enable multi-factor authentication (MFA) for all console users.
B.Implement strong password policies with complex passwords.
C.Disable the web console and require API access only.
D.Restrict console access to a specific IP address range.
AnswerA

MFA adds a second authentication factor beyond the password, so a compromised credential alone cannot grant console access. This directly satisfies the requirement that only authorised personnel reach the management console, blocking credential-stuffing and phishing-driven logins.

Why this answer

Multi-factor authentication (MFA) is the best method because it adds an additional layer of security beyond just a password, requiring a second factor (e.g., a time-based one-time password from an authenticator app or a hardware token). This significantly reduces the risk of unauthorized access even if credentials are compromised, as the attacker would also need the second factor. In cloud environments like AWS, Azure, or GCP, MFA is a fundamental security best practice for protecting the management console.

Exam trap

The trap here is that candidates often choose strong password policies (Option B) as the best method, overlooking that MFA is the industry-standard defense against credential compromise, not just password complexity.

How to eliminate wrong answers

Option B is wrong because while strong password policies are important, they are insufficient on their own; passwords alone can be phished, guessed, or brute-forced, and MFA provides a critical additional layer. Option C is wrong because disabling the web console and requiring API access only does not inherently improve security—API access still requires authentication and can be just as vulnerable if not protected with MFA or proper IAM roles, and it reduces operational flexibility. Option D is wrong because restricting console access to a specific IP address range can be bypassed by attackers using VPNs or compromised machines within that range, and it does not protect against credential theft or insider threats; it is a network-level control, not an identity-level control.

807
MCQmedium

A cloud architect is deploying a serverless application using AWS Lambda. The application must process messages from an Amazon SQS queue. The messages are expected to be processed in order, and the application must handle failures without losing messages. Which configuration should be used?

A.Use Amazon Kinesis Data Streams as the event source and configure the Lambda function to process records in batches.
B.Configure the Lambda function with an SQS trigger and set the batch size to 10, and enable a dead-letter queue for the source queue.
C.Create an SNS topic and subscribe the Lambda function to it, then publish messages to the topic.
D.Use an SQS FIFO queue as the event source for the Lambda function and configure a dead-letter queue for the source queue.
AnswerD

SQS FIFO queues provide strict message ordering and exactly-once processing. Configuring a dead-letter queue for the source queue ensures that messages that fail processing are moved to a DLQ after a specified number of attempts, preventing message loss. This meets both the ordering and failure handling requirements.

Why this answer

SQS FIFO queues guarantee message order and support dead-letter queues for failed messages. Using a FIFO queue as the Lambda event source ensures ordered processing, and the DLQ captures messages that cannot be processed, preventing loss. The other options either lack ordering guarantees or use the wrong service.

Exam trap

The trap here is assuming that standard SQS queues preserve order or that SNS can provide durable, ordered delivery.

808
MCQmedium

A cloud administrator notices that a virtual machine running a critical application is using 95% CPU consistently. The application is single-threaded and performance is degraded. Which action should the administrator take to resolve the issue?

A.Deploy additional VMs and load balance the application.
B.Increase the RAM allocation to the VM.
C.Migrate the VM to a host with a higher CPU clock speed.
D.Increase the number of vCPUs assigned to the VM.
AnswerC

Because the application is single-threaded, extra cores cannot help; throughput is bound by per-core clock speed. Migrating to a host with a higher CPU clock frequency raises single-thread performance, directly resolving the sustained 95% CPU saturation.

Why this answer

The application is single-threaded, meaning it can only utilize one CPU core at a time. Increasing the CPU clock speed directly improves the processing speed of that single thread, which resolves the performance degradation. Option C is correct because migrating to a host with a higher CPU clock speed provides a faster core for the single-threaded workload.

Exam trap

CompTIA often tests the misconception that adding more vCPUs always improves performance, but for single-threaded workloads, higher clock speed is the correct solution, not vCPU count.

How to eliminate wrong answers

Option A is wrong because deploying additional VMs and load balancing would distribute requests across multiple instances, but a single-threaded application cannot parallelize its work across VMs; this adds complexity without addressing the core bottleneck. Option B is wrong because increasing RAM allocation does not affect CPU utilization or single-threaded performance; the issue is CPU-bound, not memory-bound. Option D is wrong because increasing the number of vCPUs does not help a single-threaded application; the application can only use one vCPU at a time, and additional vCPUs may even cause scheduling overhead or NUMA issues.

809
MCQeasy

A company wants to migrate its on-premises workloads to the cloud while maintaining the ability to run some sensitive applications on-premises. Which cloud deployment model best meets this requirement?

A.Hybrid cloud
B.Multi-cloud
C.Private cloud
D.Public cloud
AnswerA

Hybrid cloud combines on-premises infrastructure with public cloud services, letting sensitive applications remain on local hardware while other workloads migrate. This directly satisfies the stem's dual requirement: cloud migration plus on-premises retention, which neither public nor private cloud alone can deliver.

Why this answer

A hybrid cloud deployment combines on-premises infrastructure with public cloud services, allowing workloads to run in both environments with connectivity between them. This directly matches the requirement to migrate some workloads to the cloud while keeping sensitive applications on-premises. Hybrid cloud is the canonical model for this split-workload scenario.

Exam trap

The trap is confusing hybrid with multi-cloud — candidates see 'multiple environments' and pick multi-cloud, but multi-cloud specifically means multiple public providers, not on-prem plus public.

How to eliminate wrong answers

Option B is wrong because multi-cloud means using two or more public cloud providers (e.g., AWS + Azure) — it says nothing about keeping workloads on-premises. Option C is wrong because a private cloud is dedicated infrastructure (on-prem or hosted) for a single organization, which excludes the public cloud migration the company wants. Option D is wrong because a public cloud model puts everything in a shared provider environment, contradicting the requirement to keep sensitive apps on-premises.

810
MCQhard

An organization uses Azure DevOps for CI/CD. They want to implement a deployment strategy where a new version of an application is deployed to a small subset of users (e.g., 5%) and if no errors are detected, the percentage is gradually increased to 100%. Which deployment strategy should they use?

A.Rolling
B.Recreate
C.Canary
D.Blue/green
AnswerC

Canary releases route a small percentage of live traffic to the new version, then incrementally shift the remainder once health checks pass. This satisfies the gradual 5%-to-100% rollout with error detection that Azure DevOps pipelines can automate.

Why this answer

Canary deployment routes a small percentage of live traffic (e.g., 5%) to the new version while the majority still hits the stable version, then gradually shifts traffic as health metrics remain clean. Azure DevOps supports this natively via deployment rings, traffic-splitting in App Service/Container Apps, or feature flags. The gradual, metric-gated traffic shift is the defining characteristic of canary.

Exam trap

CV0-004 often tests the confusion between canary (percentage-based gradual traffic shift to a subset of users) and blue/green (two full environments with an all-at-once cutover) — candidates pick blue/green because both involve two versions running simultaneously.

How to eliminate wrong answers

Option A is wrong because rolling deployment replaces instances in batches across the entire fleet with no traffic-percentage control or user subsetting — all users eventually hit the new version as instances cycle. Option B is wrong because recreate tears down the old version entirely before bringing up the new one, causing downtime and offering no gradual exposure. Option D is wrong because blue/green runs two full parallel environments and flips 100% of traffic at once (or via a single cutover), not a gradual percentage ramp.

811
Multi-Selecthard

A cloud operations team needs to implement a monitoring solution for a microservices architecture. The solution must provide centralized logging, metrics, and alerting, and must be able to correlate data from multiple services. Which THREE of the following components should the team include?

Select 3 answers
A.A security information and event management (SIEM) system.
B.A centralized logging system (e.g., ELK stack).
C.A correlation engine and alerting system (e.g., event correlation).
D.A metrics collection agent and dashboard (e.g., Prometheus+Grafana).
E.An application performance monitoring (APM) tool.
AnswersB, C, D

Centralised logging aggregates log streams from every microservice into one searchable store, satisfying the stem's centralised logging requirement. Without it, correlating events across services is impossible, since each container's logs remain isolated on its own host and are lost when instances are recycled.

Why this answer

Option B is correct because a centralized logging system such as the ELK stack (Elasticsearch, Logstash, Kibana) aggregates logs from all microservices into one searchable store, which is essential for centralized logging and for correlating events across services. Option C is correct because a correlation engine and alerting system is what ties together logs and metrics from multiple services, detects patterns or thresholds, and generates alerts, directly satisfying the alerting and correlation requirements. Option D is correct because a metrics collection agent and dashboard such as Prometheus with Grafana provides time-series metrics collection, storage, and visualization, fulfilling the metrics and dashboarding needs of the monitoring solution.

Option A is not required here because a SIEM focuses on security event management and compliance rather than general operational monitoring, metrics, and service correlation. Option E is not required because APM is a specialized tool for tracing application performance and, while useful, is not one of the three core components needed for centralized logging, metrics, and alerting in this scenario.

Exam trap

CompTIA often tests the distinction between specialized tools (SIEM, APM) and the core triad of centralized logging, metrics, and correlation/alerting, leading candidates to over-select security or tracing tools that do not fulfill the requirement for correlating data from multiple services at the log and metric level.

812
MCQeasy

Which of the following is a key benefit of using a Cloud Access Security Broker (CASB)?

A.Automates resource provisioning
B.Provides DDoS protection
C.Manages encryption keys for on-premises data
D.Discovers and controls use of unauthorized cloud applications
AnswerD

A CASB provides shadow IT discovery, identifying cloud applications in use that fall outside sanctioned policy. It then enforces controls such as blocking or restricting those unsanctioned services, satisfying the requirement to both discover and control unauthorised cloud application usage.

Why this answer

CASBs provide visibility and control over SaaS applications, including shadow IT discovery.

813
MCQmedium

An organization uses a cloud-based load balancer to distribute traffic to a web application across multiple availability zones. Users report that the application is intermittently unavailable. The cloud administrator finds that the load balancer health checks are failing on instances in one availability zone. What is the most likely cause?

A.The availability zone is experiencing a partial outage.
B.A single instance in the failing AZ has a misconfigured web server.
C.The DNS settings for the application domain are misconfigured.
D.The load balancer's listener configuration is incorrect.
AnswerA

A partial availability zone outage makes instances in that zone fail health checks, so the load balancer removes them and intermittent unavailability follows. This explains failures confined to one zone while other zones remain healthy.

Why this answer

When health checks fail for all instances in a single availability zone (AZ) while other AZs remain healthy, the most likely cause is a partial outage or degradation within that AZ. Cloud providers like AWS, Azure, or GCP isolate AZs to prevent single points of failure, but an AZ can experience issues such as network connectivity loss, power disruption, or hardware failures that affect all instances in that zone. The load balancer's health checks are designed to detect such zone-level failures by probing each instance; if an entire AZ is impaired, all its instances will fail the health check simultaneously.

Exam trap

CompTIA often tests the distinction between instance-level failures and zone-level failures; the trap here is that candidates may assume a single misconfigured instance (Option B) is the cause, but the key clue is that all instances in one AZ are failing health checks, which points to an AZ-wide issue rather than a per-instance configuration problem.

How to eliminate wrong answers

Option B is wrong because a misconfigured web server on a single instance would cause only that instance to fail health checks, not all instances in the AZ; the scenario describes all instances in the AZ failing. Option C is wrong because DNS misconfiguration would affect client resolution to the load balancer's DNS name, not the load balancer's ability to perform health checks on backend instances; health checks operate at the network layer between the load balancer and instances, independent of DNS. Option D is wrong because an incorrect listener configuration (e.g., wrong port or protocol) would cause health checks to fail for all instances across all AZs, not just one AZ; the issue is isolated to a single AZ, pointing to a zone-level problem.

814
Multi-Selectmedium

Which THREE of the following are recommended practices for securing cloud API access? (Choose three.)

Select 3 answers
A.Use role-based access control to limit permissions for each API user
B.Embed API keys directly in application source code for convenience
C.Enable detailed logging of all API calls to a centralized service
D.Expose API endpoints publicly for easy access by all clients
E.Rotate API keys and tokens on a regular schedule
AnswersA, C, E

Role-based access control enforces least privilege by assigning permissions through roles rather than to individual API users, so each caller receives only the scopes its function requires. This directly satisfies the stem's constraint of limiting permissions per API user, reducing blast radius if credentials leak and simplifying revocation at scale.

Why this answer

Option A is correct because role-based access control (RBAC) enforces least privilege by assigning each API user or service only the specific permissions required for its function, reducing the blast radius of a compromised credential. Option C is correct because enabling detailed logging of all API calls to a centralized service (e.g., AWS CloudTrail, Azure Monitor, or GCP Cloud Audit Logs) provides an audit trail for detecting anomalous activity, supporting incident response, and meeting compliance requirements. Option E is correct because regularly rotating API keys and tokens limits the window of exposure if a credential is leaked, and rotation should be automated and paired with revocation of old credentials.

Option B is not recommended because embedding API keys in source code exposes them to anyone with repository access and often leads to leaks in version control history; secrets should be stored in a secrets manager or vault. Option D is not recommended because exposing API endpoints publicly to all clients removes authentication and network controls, increasing attack surface; endpoints should be restricted via authentication, authorization, and network policies such as private endpoints or IP allowlists.

Exam trap

A common trap is the misconception that embedding API keys in source code is acceptable for convenience, but this violates secure coding standards and is a common cause of data breaches in cloud environments.

815
MCQmedium

A cloud architect is designing an auto-scaling policy for a web application that experiences predictable traffic spikes every weekday morning from 8 to 10 AM. The application runs on a group of virtual machines behind a load balancer. Which scaling approach is MOST cost-effective while ensuring performance during the spike?

A.Dynamic scaling based on CPU utilization threshold
B.Proactive scaling using machine learning to predict spikes
C.Manual scaling by the operations team each morning
D.Scheduled scaling to increase capacity before 8 AM and decrease after 10 AM
AnswerD

Traffic spikes are predictable and time-bound, so scheduled scaling adds capacity before 8 AM and removes it after 10 AM, matching supply to demand exactly. Dynamic or reactive scaling would lag the spike and waste spend during idle hours, breaching the cost-effectiveness constraint.

Why this answer

Scheduled scaling is the most cost-effective approach because the traffic pattern is predictable (every weekday 8–10 AM). By configuring the auto-scaling group to add instances before the spike and remove them after, you avoid paying for idle resources during off-peak hours while ensuring capacity is ready when needed. This approach directly matches the known schedule without relying on reactive metrics or manual intervention.

Exam trap

CompTIA often tests the distinction between reactive (dynamic) and proactive (scheduled) scaling, where candidates mistakenly choose dynamic scaling for predictable patterns because they assume it is always the most efficient, ignoring the latency of metric-based triggers.

How to eliminate wrong answers

Option A is wrong because dynamic scaling based on CPU utilization reacts to load after it occurs, which can cause a lag in provisioning and potential performance degradation during the initial spike. Option B is wrong because proactive scaling using machine learning is overkill for a predictable, repeating schedule and introduces unnecessary complexity and cost. Option C is wrong because manual scaling is error-prone, requires human intervention every morning, and cannot guarantee timely scaling for a predictable pattern.

816
Multi-Selectmedium

A cloud administrator is deploying a new three-tier application on Google Cloud. The web tier must be accessible from the internet, the application tier must only accept traffic from the web tier, and the database tier must only accept traffic from the application tier. The administrator needs to implement network security controls to enforce these requirements. Which two Google Cloud features should be used? (Choose two.)

Select 2 answers
A.Hierarchical firewall policies
B.Cloud Armor security policies
C.VPC Service Controls
D.Network tags on instances
E.VPC firewall rules
AnswersD, E

Network tags are used in conjunction with VPC firewall rules to identify source or target instances. By tagging instances in each tier, you can create firewall rules that allow traffic only from specific tags, enabling granular control over which tiers can communicate, thus enforcing the desired segmentation.

Why this answer

VPC firewall rules and network tags work together to enforce tiered network segmentation. Firewall rules define allowed traffic based on tags, and network tags identify instances belonging to each tier. This combination ensures that only the intended traffic flows between tiers, meeting the security requirements.

Exam trap

The trap here is assuming that Cloud Armor or VPC Service Controls can enforce internal tier-to-tier traffic restrictions, when they are designed for edge protection and service perimeters, respectively.

817
MCQmedium

A DevOps team uses CloudFormation to manage multi-account infrastructure. They need to deploy a common set of resources across multiple AWS accounts in an organization. Which CloudFormation feature should they use?

A.Nested stacks
B.Drift detection
C.Stack sets
D.Change sets
AnswerC

Stack sets let a single CloudFormation template deploy identical resources across many AWS accounts and regions from one administrator account. This satisfies the stem's requirement for consistent multi-account deployment, unlike ordinary stacks, which are scoped to a single account.

Why this answer

CloudFormation StackSets allow a single template to be deployed across multiple AWS accounts and regions from a central administrator account, which is exactly what the DevOps team needs for multi-account infrastructure. StackSets support automatic deployment to new accounts as they join the organization and can use service-managed permissions for Organizations integration. This makes it the correct feature for cross-account, multi-region rollouts.

Exam trap

The trap is confusing nested stacks (intra-account template composition) with StackSets (cross-account/cross-region deployment) — both involve 'stacks' but solve entirely different problems.

How to eliminate wrong answers

Option A is wrong because nested stacks are used to decompose a large template into reusable child stacks within a single account and region — they do not span accounts. Option B is wrong because drift detection identifies when actual resource configuration differs from the template, which is a monitoring capability, not a deployment mechanism. Option D is wrong because change sets preview how proposed template changes will affect existing resources before execution, but they operate within a single stack and do not deploy across accounts.

818
Multi-Selectmedium

A cloud administrator is configuring a CASB (Cloud Access Security Broker) for SaaS applications. Which TWO capabilities should the administrator expect from the CASB? (Choose two.)

Select 2 answers
A.Discover and control shadow IT usage
B.Manage on-premises server patches
C.Apply data loss prevention (DLP) policies
D.Provide local DNS resolution
E.Replace the cloud provider's infrastructure
AnswersA, C

CASBs provide discovery of unsanctioned SaaS usage, identifying shadow IT across the organisation, then enforce granular controls such as blocking or restricting those applications. This visibility and control capability directly matches the stem's SaaS-focused CASB deployment.

Why this answer

Option A is correct because a core CASB function is discovery of shadow IT — the CASB uses API connectors, log analysis, and traffic inspection to identify unsanctioned SaaS usage and then apply control (block, coach, or allow) policies. Option C is correct because CASBs enforce data loss prevention policies on cloud traffic and data at rest, inspecting content for sensitive patterns (PII, PCI, credentials) and applying actions such as block, quarantine, or encryption via API or inline proxies. Options B, D, and E are incorrect: patch management of on-premises servers is a configuration management/endpoint tool function, local DNS resolution is provided by DNS servers (e.g., BIND, Windows DNS) rather than a CASB, and a CASB never replaces the cloud provider's infrastructure — it sits alongside SaaS/IaaS to provide visibility, compliance, threat protection, and data security.

Exam trap

CV0-004 often tests the misconception that a CASB is a network security appliance that provides infrastructure services like DNS or patching, when it is actually a policy enforcement point for cloud usage visibility and data protection.

819
Multi-Selectmedium

A cloud security team is hardening a Linux virtual machine that hosts a public-facing API in a public cloud. The team wants to reduce the attack surface at the operating system layer and detect unauthorized file changes. Which TWO measures should the team implement? (Choose two.)

Select 2 answers
A.Store the virtual machine's SSH host keys in a publicly readable object storage bucket for easy distribution to clients.
B.Grant the API service account full administrative privileges on the virtual machine to simplify troubleshooting and deployment.
C.Remove or disable unnecessary services, packages, and listening ports that the API does not require.
D.Enable a host-based intrusion detection system that monitors critical system files and alerts on unexpected modifications.
E.Disable the local firewall and rely solely on the cloud provider's security group rules for all traffic filtering.
AnswersC, D

Eliminating unneeded services, packages, and open ports directly shrinks the attack surface of the operating system, which is exactly the first goal. Every extra daemon is a potential entry point and patch burden, so removing them reduces exploitable vulnerabilities. This is a foundational hardening step that pairs well with integrity monitoring to cover both reduction and detection objectives.

Why this answer

Reducing the attack surface means removing unnecessary services, packages, and listening ports so fewer exploitable components remain on the host. Detecting unauthorized changes requires a host-based intrusion detection system that monitors file integrity and alerts on tampering. Together these cover both the reduction and detection goals, while the remaining options either expand privileges, weaken layered filtering, or expose trust material insecurely.

Exam trap

The trap here is treating cloud security group rules as a complete substitute for host-level hardening and monitoring.

820
MCQeasy

During a cloud deployment, a virtual machine is created from a custom image. After boot, the VM is not accessible via SSH. Which of the following should the administrator check FIRST?

A.The security group rules for inbound SSH
B.The boot volume is encrypted
C.The hypervisor version compatibility
D.The image's OS license activation status
AnswerA

SSH depends on TCP port 22 reaching the instance; a missing or overly restrictive inbound rule in the security group silently drops that traffic before it ever reaches the VM. Since the image itself booted, checking the security group first isolates the most common network-layer cause of connection refusal.

Why this answer

The most common reason a newly deployed VM is inaccessible via SSH is that the security group or network ACL does not permit inbound TCP port 22 traffic. Security groups act as a virtual firewall at the instance level, and if the rule allowing SSH from the administrator's IP is missing or misconfigured, the connection will be refused. This should be the first check because it is a frequent misconfiguration during deployment.

Exam trap

The trap here is that candidates may assume the issue is with the OS or image itself (e.g., licensing or encryption) and overlook the most common and easily verified network-layer misconfiguration of security group rules.

How to eliminate wrong answers

Option B is wrong because boot volume encryption affects data at rest security, not network connectivity; an encrypted volume does not block SSH access. Option C is wrong because hypervisor version compatibility is a pre-deployment concern and would typically cause the VM to fail to boot or run, not just block SSH after boot. Option D is wrong because OS license activation status might cause grace-period warnings or feature restrictions but does not prevent SSH connectivity; SSH is a network service that operates independently of activation state.

821
MCQhard

A cloud administrator is troubleshooting a performance issue where an application running on a VM in a private cloud is experiencing high latency. The VM is connected to a virtual switch that uses SR-IOV. The administrator suspects network bottlenecks. Which of the following is the MOST likely cause of the latency?

A.The physical network interface card (NIC) is saturated.
B.The virtual switch is dropping packets due to buffer exhaustion.
C.The VM's virtual NIC is not using the correct driver.
D.The hypervisor's CPU is overloaded due to SR-IOV emulation.
AnswerA

With SR-IOV the virtual function bypasses the hypervisor's virtual switch, so guest traffic reaches the physical NIC directly and no longer benefits from host-side software queuing or shaping. If that physical NIC's bandwidth is exhausted, latency rises for every virtual function sharing it.

Why this answer

SR-IOV allows a physical NIC to present multiple virtual functions (VFs) directly to VMs, bypassing the virtual switch for data plane traffic. When the physical NIC reaches its bandwidth capacity, all VFs sharing that NIC experience increased latency and packet drops, making NIC saturation the most likely cause of the high latency.

Exam trap

The trap here is that candidates assume SR-IOV eliminates all bottlenecks, but the physical NIC remains a shared resource that can become saturated, causing latency for all VMs using its VFs.

How to eliminate wrong answers

Option B is wrong because SR-IOV bypasses the virtual switch for data plane traffic, so buffer exhaustion on the virtual switch does not affect SR-IOV passthrough traffic. Option C is wrong because SR-IOV requires a specific driver (e.g., ixgbevf or mlx5_core) on the VM; an incorrect driver would prevent the VF from being recognized or cause connectivity failure, not just high latency. Option D is wrong because SR-IOV offloads network processing to the NIC hardware, so the hypervisor's CPU is not involved in emulating the NIC for SR-IOV VFs; CPU overload would affect other components but is not a direct consequence of SR-IOV.

822
MCQhard

A company uses a multi-cloud strategy with both AWS and Azure. The cloud operations team needs to centrally monitor all cloud resources and receive alerts when resource usage exceeds predefined thresholds. Which of the following solutions should the team implement?

A.Azure Monitor with Log Analytics
B.AWS CloudWatch with cross-account monitoring
C.A third-party monitoring tool that supports both AWS and Azure
D.Custom scripts that log to a central syslog server
AnswerC

Third-party tools like Datadog can aggregate metrics from multiple clouds into a single dashboard.

Why this answer

A third-party monitoring tool (e.g., Datadog, Splunk, or Dynatrace) can natively ingest metrics and logs from both AWS and Azure APIs, providing a single pane of glass for alerting across a multi-cloud environment. This avoids the vendor lock-in and integration gaps that arise when using native tools from only one cloud provider.

Exam trap

The trap here is that candidates assume native tools like Azure Monitor or AWS CloudWatch can be extended to monitor other clouds, but they are architecturally limited to their own ecosystems, making a third-party tool the only viable multi-cloud solution.

How to eliminate wrong answers

Option A is wrong because Azure Monitor with Log Analytics is designed to monitor Azure resources only; it cannot natively pull metrics from AWS services without complex, unsupported workarounds. Option B is wrong because AWS CloudWatch with cross-account monitoring is limited to AWS accounts and cannot monitor Azure resources at all. Option D is wrong because custom scripts logging to a central syslog server lack native integration with cloud provider APIs, requiring manual metric collection and failing to provide real-time, threshold-based alerting for dynamic cloud resources.

823
Multi-Selecthard

A cloud operations team supports a microservices application running on Amazon ECS with AWS Fargate tasks. Users report that some requests fail intermittently, and the team suspects that containers are being terminated because they exceed resource limits or fail health checks. The team wants to collect the relevant diagnostic data to confirm the cause. (Choose two.)

Select 2 answers
A.Review the Amazon ECS service event log and task stopped reasons in the Amazon ECS console.
B.Increase the Fargate task CPU and memory allocation and redeploy to observe whether failures stop.
C.Enable and inspect AWS CloudTrail data events for the ECS tasks.
D.Delete and recreate the ECS cluster to force a clean state.
E.Configure the task definition to send container logs to Amazon CloudWatch Logs and review them for error output.
AnswersA, E

The ECS service event log and task stopped reasons record why tasks were stopped, including out-of-memory terminations, failed health checks, and essential container exits. This is the most direct source for confirming that containers were terminated due to resource limits or health check failures, matching the team's diagnostic goal.

Why this answer

Confirming why ECS tasks terminate requires two complementary evidence sources: the ECS service event log and task stopped reasons, which record platform-level termination causes, and container logs delivered to Amazon CloudWatch Logs, which capture application-level errors. Together they distinguish resource-limit kills from health check failures or application crashes.

Exam trap

The trap here is treating a remediation action such as increasing task resources as though it were a diagnostic step.

824
Multi-Selectmedium

A company is implementing a cloud-based SIEM solution. Which TWO of the following are essential data sources that should be integrated to ensure comprehensive security monitoring?

Select 2 answers
A.Physical access logs from the data center.
B.Firewall configuration backup files.
C.Employee vacation schedule.
D.DNS query logs from the cloud DNS service.
E.Network flow logs from virtual network appliances.
AnswersD, E

DNS query logs record every domain resolution request, exposing malicious lookups, DNS tunnelling, and command-and-control beaconing that endpoint or flow data alone may miss. Ingesting them into the SIEM gives visibility into name-resolution activity across the cloud estate.

Why this answer

Option D is correct because DNS query logs from the cloud DNS service provide visibility into domain resolution activity, enabling detection of malicious domains, DNS tunneling, and command-and-control beaconing that other telemetry may miss. Option E is correct because network flow logs from virtual network appliances capture IP-level metadata (source/destination, ports, protocol, bytes) across cloud traffic, which is essential for identifying lateral movement, exfiltration, and anomalous communication patterns in a SIEM. Option A is not essential for a cloud-based SIEM since physical data center access logs pertain to on-premises facility security rather than cloud workload or network activity.

Option B is not a continuous monitoring data source; firewall configuration backups are static artifacts useful for compliance or change auditing, not real-time event correlation. Option C is irrelevant to security monitoring because employee vacation schedules have no bearing on detecting threats or correlating security events.

Exam trap

The trap here is that candidates often mistake static configuration files (like firewall backups) or non-security data (like vacation schedules) as valid SIEM sources, overlooking that a SIEM requires real-time, event-driven logs (e.g., DNS queries and network flows) to perform effective threat detection and correlation.

825
MCQeasy

A cloud administrator is troubleshooting a newly deployed web application on a cloud VM. Users cannot access the application via its public IP address, but the administrator can SSH into the VM and access the application locally using curl http://localhost:8080. The VM's security group allows inbound traffic on port 22 and port 80. The application is listening on port 8080. Which of the following is the MOST likely cause of the issue?

A.The application is configured to use HTTPS instead of HTTP.
B.The application is bound to the loopback interface instead of all interfaces.
C.The security group does not allow inbound traffic on port 8080.
D.The VM's operating system firewall is blocking port 8080.
AnswerC

The security group allows inbound traffic on ports 22 and 80, but the application is listening on port 8080. Since users are trying to access the application via its public IP, they are likely using a URL without specifying port 8080 (e.g., http://public-ip), which defaults to port 80. However, even if they specified port 8080, the security group would block it because only ports 22 and 80 are allowed. The local curl to localhost:8080 works because it bypasses the security group. Thus, the security group is the most likely cause.

Why this answer

The security group allows inbound traffic only on ports 22 and 80, but the application listens on port 8080. External users cannot reach port 8080 because the security group blocks it. Local access via localhost:8080 works because it does not traverse the security group.

To resolve the issue, the administrator should either add an inbound rule for port 8080 or reconfigure the application to listen on port 80.

Exam trap

The trap here is assuming that because local access works, the application is correctly configured, and overlooking that the security group only permits specific ports.

Page 10

Page 11 of 12

Page 12