Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 826–834

834 questions total · 12pages · All types, answers revealed

Page 11

Page 12 of 12

826
MCQeasy

A cloud administrator cannot deploy a new VM from a custom image. The deployment fails with an error stating 'Incompatible hypervisor version'. What is the most likely cause?

A.The image was created on a newer hypervisor than the current host.
B.The VM's virtual hardware version is too old.
C.The image file is corrupt.
D.The storage backend does not support the image format.
AnswerA

A custom image carries a hypervisor compatibility level set by the host that created it. If that level exceeds the destination host's hypervisor version, the platform rejects deployment, producing exactly this incompatibility error. The image must be recreated on an equal or older hypervisor.

Why this answer

The error 'Incompatible hypervisor version' indicates that the custom image was created on a hypervisor version that is newer than the one on the host where deployment is attempted. Hypervisors like VMware ESXi, Hyper-V, or KVM have version-specific features and virtual hardware compatibility; an image from a newer version may not be supported on an older host.

Exam trap

CV0-004 often tests the direction of compatibility: candidates might think an older image is incompatible with a newer hypervisor, but the error specifically indicates the image is from a newer hypervisor than the host.

How to eliminate wrong answers

Option B is wrong because if the VM's virtual hardware version is too old, it would typically still be compatible (newer hypervisors support older versions), and the error would not mention hypervisor version. Option C is wrong because a corrupt image would produce a different error, such as checksum failure or invalid format. Option D is wrong because an unsupported image format would yield an error about format, not hypervisor version.

827
MCQhard

A company needs to connect its on-premises data center to a public cloud provider with a dedicated, consistent network connection that bypasses the internet. Which connectivity method should be used?

A.VPC peering
B.Internet gateway
C.Site-to-Site VPN
D.Direct Connect or ExpressRoute
AnswerD

Direct Connect (AWS) and ExpressRoute (Azure) provision private, dedicated circuits from an on-premises data centre to the provider's edge, bypassing the public internet entirely. This satisfies the requirement for a consistent, dedicated connection rather than an IPsec VPN tunnel over internet links.

Why this answer

Direct Connect (AWS) and ExpressRoute (Azure) are dedicated private network connections from on-premises infrastructure to a cloud provider that bypass the public internet entirely. They provide consistent latency, higher bandwidth, and more predictable performance than internet-based options, which is exactly what the scenario requires.

Exam trap

The trap is assuming that because a Site-to-Site VPN is encrypted it must be the 'secure dedicated' answer — but VPNs still traverse the public internet, so they fail the 'bypasses the internet' and 'consistent' criteria.

How to eliminate wrong answers

Option A is wrong because VPC peering connects two virtual private clouds (VPCs) to each other — it does not connect an on-premises data center to a cloud provider and does not provide a dedicated physical link. Option B is wrong because an internet gateway is the component that enables VPC resources to communicate with the public internet — it is the opposite of bypassing the internet. Option C is wrong because a Site-to-Site VPN traverses the public internet (encrypted via IPsec), so it does not provide the dedicated, consistent path the scenario demands, even though it is encrypted.

828
MCQeasy

A cloud administrator needs to protect a web application from common attacks such as SQL injection and cross-site scripting (XSS). Which cloud service should be implemented?

A.DDoS protection service
B.Network ACL
C.Security group
D.Web Application Firewall (WAF)
AnswerD

A Web Application Firewall inspects HTTP/S requests at layer 7 and blocks signatures matching SQL injection and XSS payloads before they reach the application. Network firewalls and load balancers operate at lower layers and cannot parse request content to detect these attacks.

Why this answer

A Web Application Firewall (WAF) is specifically designed to filter and monitor HTTP traffic, blocking common web exploits like SQL injection and XSS. Cloud providers offer WAF services (e.g., AWS WAF, Azure WAF, Cloud Armor).

829
MCQeasy

A cloud engineer is tasked with automating the deployment of a new web application. Which of the following tools is BEST suited for managing infrastructure as code in a hybrid cloud environment?

A.AWS CloudFormation
B.Ansible
C.Terraform
D.Docker
AnswerC

Terraform's declarative HCL and provider plugins manage resources across on-premises and multiple public clouds from one state file, satisfying the hybrid constraint. Unlike cloud-native tools tied to a single vendor, it provisions both environments consistently, making it best suited for automating this deployment.

Why this answer

Terraform is the best choice because it is a cloud-agnostic Infrastructure as Code (IaC) tool that uses a declarative configuration language (HCL) to manage resources across multiple providers, including AWS, Azure, and on-premises systems. This makes it ideal for hybrid cloud environments where consistent provisioning and state management are required across disparate platforms.

Exam trap

The CompTIA Cloud+ exam often tests the distinction between IaC tools (Terraform, CloudFormation) and configuration management tools (Ansible, Puppet) or containerization tools (Docker), leading candidates to choose Ansible because it also supports multi-cloud, but missing that Terraform is purpose-built for declarative infrastructure provisioning in hybrid clouds.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation is a proprietary IaC tool that only works within the AWS ecosystem, making it unsuitable for managing resources in a hybrid cloud that includes non-AWS providers. Option B is wrong because Ansible is primarily a configuration management and automation tool that uses imperative playbooks and push-based execution, not a dedicated IaC tool for declarative resource provisioning across hybrid clouds. Option D is wrong because Docker is a containerization platform that packages applications and dependencies into containers, not an IaC tool for managing cloud infrastructure resources like VMs, networks, or storage.

830
MCQmedium

A cloud administrator is responsible for a set of Amazon EC2 instances that must be patched on a recurring schedule. The administrator wants to define a maintenance window, register the target instances, and have the system apply operating system patches automatically with a defined baseline. Which AWS service should the administrator use to accomplish this with the least operational overhead?

A.Amazon Inspector
B.AWS Config conformance packs
C.AWS Trusted Advisor
D.AWS Systems Manager Patch Manager
AnswerD

AWS Systems Manager Patch Manager uses patch baselines and maintenance windows to scan and install operating system patches on registered managed nodes automatically. It supports approval rules, compliance reporting, and scheduled execution, which matches the requirement to patch on a recurring schedule with a defined baseline and minimal manual effort.

Why this answer

AWS Systems Manager Patch Manager is purpose-built for automated patch management. It combines patch baselines, which define approved patches, with maintenance windows that schedule when patching runs, and it registers target instances as managed nodes. This delivers recurring, baseline-driven patching with low operational overhead.

Exam trap

The trap here is confusing a vulnerability assessment service such as Amazon Inspector with a patch deployment service.

831
Multi-Selectmedium

A cloud architect is designing a disaster recovery plan that includes testing. Which TWO activities are commonly performed as part of DR testing?

Select 2 answers
A.Reserved Instance planning
B.Rightsizing recommendations
C.Chaos engineering
D.Scheduled DR drills
E.Tagging resources
AnswersC, D

Chaos engineering deliberately injects failures such as instance termination or network latency to verify that failover and recovery actually work under realistic conditions. It validates DR readiness beyond documentation, exposing gaps in automation and dependencies that tabletop exercises alone cannot reveal.

Why this answer

Chaos engineering (C) is a valid DR testing activity because it deliberately injects failures—such as terminating instances, blocking network paths, or simulating AZ outages—to verify that failover, replication, and recovery mechanisms actually work under real fault conditions. Scheduled DR drills (D) are also a core DR testing practice, as they exercise documented runbooks and recovery procedures (for example, promoting a standby database or failing over to a secondary region) on a planned cadence to validate RTO and RPO targets. The remaining options are not DR testing activities: Reserved Instance planning (A) is a cost-optimization/billing exercise, rightsizing recommendations (B) are about matching instance capacity to utilization for efficiency, and tagging resources (E) is a governance and metadata practice that supports organization and cost allocation but does not itself test recovery.

Exam trap

CV0-004 often tests whether candidates can distinguish DR validation activities (drills, chaos engineering) from cost or governance activities (reserved instances, rightsizing, tagging) that are unrelated to recovery testing.

832
MCQmedium

A cloud administrator is configuring a new virtual private cloud (VPC) for a three-tier application. The web tier must be accessible from the internet, the application tier should only be accessible from the web tier, and the database tier should only be accessible from the application tier. Which network architecture should be used?

A.Use one subnet with network ACLs to restrict traffic between tiers.
B.Place all tiers in the same subnet and use host-based firewalls.
C.Place each tier in a separate subnet with appropriate security group rules controlling traffic.
D.Deploy each tier in a different VPC and peer them.
AnswerC

Separate subnets per tier, combined with security group rules referencing source security groups, enforce that only the web tier reaches the application tier and only the application tier reaches the database, satisfying the stated isolation requirement.

Why this answer

Placing each tier in a separate subnet and using security group rules provides stateful, instance-level traffic control. Security groups act as virtual firewalls at the hypervisor layer, allowing you to specify inbound rules that restrict the application tier to only accept traffic from the web tier's security group, and the database tier to only accept traffic from the application tier's security group. This aligns with the principle of least privilege and ensures that each tier is isolated within the VPC while maintaining necessary connectivity.

Exam trap

The trap here is that candidates often confuse network ACLs (stateless, subnet-level) with security groups (stateful, instance-level) and assume a single subnet with ACLs can achieve the same isolation, but ACLs cannot filter based on source security group IDs and require manual IP management, making them unsuitable for this multi-tier access control requirement.

How to eliminate wrong answers

Option A is wrong because using a single subnet with network ACLs (stateless) would require complex, bidirectional rule management for each tier, and network ACLs cannot filter traffic based on source security group IDs, making it impossible to restrict traffic to only the web tier or application tier without exposing other resources. Option B is wrong because placing all tiers in the same subnet with host-based firewalls violates the security best practice of network segmentation; host-based firewalls are not managed centrally and can be bypassed if the host is compromised, plus they do not provide the same level of isolation as separate subnets with security groups. Option D is wrong because deploying each tier in a different VPC and peering them introduces unnecessary complexity, latency, and cost; VPC peering does not support transitive routing, so you would need additional routing configurations or a transit gateway, and it violates the typical three-tier architecture pattern where all tiers reside within the same VPC for low-latency communication.

833
Multi-Selectmedium

A cloud administrator is configuring an Azure environment for a healthcare application that must comply with HIPAA. Which TWO configurations are required to meet HIPAA security and privacy rules? (Choose two.)

Select 2 answers
A.Implement audit logging for access to ePHI
B.Configure network security groups to allow only HTTPS traffic
C.Enable multi-factor authentication for all administrative accounts
D.Configure automatic patching for all virtual machines
E.Enable encryption at rest for all storage accounts containing ePHI
AnswersA, E

HIPAA requires audit controls to record access to ePHI.

Why this answer

Audit logging for access to ePHI is required by HIPAA to track who accessed, modified, or deleted protected health information. In Azure, this is implemented through Azure Monitor and Log Analytics, which capture detailed audit trails for storage accounts, databases, and applications. Without audit logs, the organization cannot demonstrate compliance with the HIPAA Security Rule's requirement for activity monitoring and accountability.

Exam trap

The trap here is that candidates often confuse 'best practices' (like MFA and automatic patching) with 'required configurations' under HIPAA, leading them to select options that are recommended but not explicitly mandated by the Security Rule.

834
MCQeasy

A company wants to automate the deployment of cloud resources using code. Which tool is BEST suited for this purpose?

A.SSH
B.An IP address management tool
C.Infrastructure as Code (IaC) templates
D.A configuration management database
AnswerC

Infrastructure as Code templates define cloud resources declaratively in version-controlled files, enabling repeatable, automated deployments without manual portal configuration. This directly satisfies the requirement to automate resource provisioning through code, unlike monitoring or scripting tools that lack declarative state management.

Why this answer

Infrastructure as Code (IaC) templates (Option C) are the best tool for automating cloud resource deployment because they allow you to define, version, and provision infrastructure through machine-readable definition files. Tools like Terraform, AWS CloudFormation, or Azure Resource Manager templates enable repeatable, consistent deployments without manual intervention, directly aligning with the goal of automating cloud resource deployment using code.

Exam trap

The trap here is that candidates may confuse SSH (a remote access tool) with automation scripts (like Ansible playbooks) or think that a CMDB can automate deployments, but the question specifically asks for a tool that uses code to deploy resources, which is the core definition of IaC.

How to eliminate wrong answers

Option A is wrong because SSH (Secure Shell) is a network protocol for secure remote access to systems, not a tool for automating the deployment of cloud resources; it lacks the declarative or imperative infrastructure definition capabilities needed for IaC. Option B is wrong because an IP address management (IPAM) tool is used for planning, tracking, and managing IP address spaces, not for provisioning or orchestrating cloud resources via code. Option D is wrong because a configuration management database (CMDB) is a repository that stores information about IT assets and their relationships; it does not automate deployment but rather serves as a reference for configuration items.

Page 11

Page 12 of 12