Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 76–150

834 questions total · 12pages · All types, answers revealed

Page 1

Page 2 of 12

Page 3
76
MCQmedium

A cloud engineer is designing a microservices architecture on AWS. The services must communicate asynchronously and decouple producers from consumers. The engineer needs a fully managed message queuing service that supports dead-letter queues and message retention up to 14 days. Which AWS service should be used?

A.Amazon SQS
B.AWS Step Functions
C.Amazon EventBridge
D.Amazon SNS
AnswerA

Amazon SQS is a fully managed message queuing service that enables asynchronous communication and decoupling of microservices. It supports standard and FIFO queues, dead-letter queues for handling failed messages, and message retention configurable from 1 minute to 14 days. This directly matches the requirements for a managed queuing service with dead-letter queue support.

Why this answer

Amazon SQS is the only fully managed message queuing service among the options. It provides asynchronous decoupling, supports dead-letter queues for isolating problematic messages, and allows message retention up to 14 days. SNS is pub/sub, EventBridge is an event bus, and Step Functions is an orchestrator, so they do not meet the specific queuing and retention requirements.

Exam trap

The trap here is confusing pub/sub messaging with queuing, or assuming that EventBridge or Step Functions can replace a dedicated message queue for asynchronous decoupling.

77
MCQmedium

A cloud administrator manages a fleet of Amazon EC2 instances hosting a stateless web tier. The security team requires that any administrative SSH access is logged to a tamper-evident, centralized location, and that the private keys never leave a hardware device. Which approach should the administrator implement?

A.Store SSH private keys in AWS Secrets Manager and retrieve them at instance boot via user data.
B.Use AWS Systems Manager Session Manager with an EC2 instance profile and log sessions to Amazon CloudWatch Logs and S3.
C.Deploy a bastion host with SSH certificate authority and forward all session logs to a syslog server.
D.Configure EC2 key pairs and rotate them every 30 days using AWS Lambda and EventBridge.
AnswerB

Session Manager provides shell access through the Systems Manager agent without opening inbound SSH ports or distributing private keys. Sessions can be recorded and streamed to CloudWatch Logs and S3 with object lock for tamper evidence, satisfying both the hardware-key and centralized-logging requirements.

Why this answer

Session Manager uses the Systems Manager agent and IAM instance profiles to broker shell access, so no inbound SSH port or private key distribution is required. Session logging to CloudWatch Logs and S3 with retention controls provides the tamper-evident, centralized audit trail. Together these meet both the key custody and logging requirements without exposing credentials.

Exam trap

The trap here is assuming that storing SSH keys in a managed secret store or rotating them satisfies a requirement that private keys never leave a hardware device.

78
MCQhard

A cloud administrator is troubleshooting a database performance issue in a cloud environment. The database is hosted on a virtual machine with a high-performance SSD. Users report slow query responses. Monitoring shows high disk I/O wait and low CPU utilization. Which action should the administrator take to improve performance?

A.Check the VM's disk queue depth and consider increasing provisioned IOPS.
B.Migrate the database to a VM with a larger memory allocation.
C.Enable read caching on the database to reduce disk reads.
D.Increase the VM's CPU count to handle more concurrent queries.
AnswerA

High disk I/O wait with low CPU indicates the storage subsystem is the bottleneck. Cloud VMs have limits on IOPS and throughput. If the disk queue is saturated, increasing provisioned IOPS (if using a cloud disk like AWS EBS or Azure Disk) can improve performance. Checking queue depth helps confirm the bottleneck before making changes.

Why this answer

High disk I/O wait with low CPU utilization points to storage as the bottleneck. Cloud disks have IOPS limits; if the workload exceeds provisioned IOPS, performance degrades. Checking queue depth confirms saturation, and increasing provisioned IOPS or upgrading the disk type resolves the issue.

CPU and memory changes do not address the storage bottleneck, and read caching may not help if the workload is write-intensive.

Exam trap

The trap here is assuming that more CPU or memory will fix slow queries, when the metrics clearly indicate a disk I/O bottleneck.

79
MCQmedium

A cloud architect is designing a web application that must remain available during a full region outage. They plan to deploy identical resources in two separate geographical regions. Which high availability architecture is described?

A.Cold standby
B.Active-passive
C.Active-active
D.Warm standby
AnswerC

Active-active runs identical workloads concurrently in both regions, each serving traffic, so a full region outage leaves the surviving region already handling production load. This differs from active-passive, where the standby region only takes over after failover, incurring downtime.

Why this answer

Active-active is the correct architecture because it deploys identical resources in two or more regions simultaneously, with both regions actively serving traffic. This provides high availability and load distribution, and if one region fails, the other continues to handle requests without interruption. This is the only option that describes both regions actively running and serving users at the same time.

Exam trap

CV0-004 often tests the distinction between active-active and active-passive/warm standby, where candidates confuse 'both regions running' with 'both regions serving traffic'; only active-active has both regions actively serving.

How to eliminate wrong answers

Option A is wrong because cold standby involves a secondary region that is not running and must be provisioned and started after a failure, resulting in significant downtime. Option B is wrong because active-passive has one region actively serving traffic while the other is on standby (often running but not serving), which does not provide immediate failover without some delay. Option D is wrong because warm standby involves a scaled-down but running secondary environment that requires scaling up before it can handle full production load, introducing a delay.

80
MCQeasy

A cloud administrator is deploying a new application to a Kubernetes cluster using a Deployment manifest. The application requires persistent storage that must survive pod restarts and be accessible by a single pod at a time. Which Kubernetes resource should be used to define the storage?

A.ConfigMap mounted as a volume
B.emptyDir volume mounted in the pod spec
C.hostPath volume pointing to a directory on the node
D.PersistentVolumeClaim with accessMode ReadWriteOnce
AnswerD

A PersistentVolumeClaim (PVC) with ReadWriteOnce allows a single node to mount the volume for read-write access, which is suitable for a single pod. It provides persistent storage that survives pod restarts. This is the standard way to request durable storage in Kubernetes and meets the requirement.

Why this answer

A PersistentVolumeClaim with ReadWriteOnce provides durable storage accessible by a single node, which is appropriate for a single pod. It decouples storage from the pod lifecycle, ensuring data persists across restarts. The other options are either ephemeral, node-specific, or meant for configuration, not persistent storage.

Exam trap

The trap here is confusing configuration or ephemeral volumes with persistent storage, especially when the application needs data to survive pod restarts.

81
Multi-Selectmedium

A cloud operations team runs a three-tier application on Google Cloud and wants to reduce the mean time to recovery for incidents. They want automated actions to run when a Cloud Monitoring alert fires, and they want to capture the exact configuration state at the moment of the incident for later analysis. Which TWO approaches should the team implement? (Choose two.)

Select 2 answers
A.Configure a Cloud Monitoring uptime check that pings the frontend every minute and emails the on-call engineer.
B.Increase the Cloud Monitoring alert threshold so that fewer alerts fire during normal traffic fluctuations.
C.Create an alerting policy in Cloud Monitoring that publishes to a Pub/Sub topic, and trigger a Cloud Run function to run remediation steps.
D.Set a Cloud Monitoring log-based alert that writes matching log entries into a BigQuery dataset for dashboards.
E.Enable Cloud Asset Inventory and schedule exports of resource metadata to a Cloud Storage bucket for later comparison.
AnswersC, E

Cloud Monitoring alerting policies can send notifications to a Pub/Sub topic, and a subscriber such as a Cloud Run function can execute automated remediation. This closes the loop from detection to action without human latency, which directly reduces recovery time. It is the supported event-driven pattern for automated response in Google Cloud and scales with alert volume.

Why this answer

Automated remediation requires an event path from detection to action, which the alerting policy to Pub/Sub to Cloud Run function pattern provides. Capturing configuration state requires a service that records resource configuration over time, which Cloud Asset Inventory exports deliver. Uptime checks, log-to-BigQuery pipelines, and threshold changes improve visibility or reduce noise but neither act automatically nor preserve the deployed configuration at incident time.

Exam trap

The trap here is confusing better monitoring and alerting with actual automated remediation and configuration capture.

82
Multi-Selectmedium

Which THREE of the following are best practices for deploying applications in a cloud environment? (Choose three.)

Select 3 answers
A.Use immutable infrastructure patterns.
B.Design for horizontal scaling rather than vertical.
C.Open all ports in security groups to simplify connectivity.
D.Keep unused resources to avoid reprovisioning delays.
E.Implement blue/green deployment to minimize downtime.
AnswersA, B, E

Immutable infrastructure replaces servers rather than mutating them in place, so every deployment ships a freshly built, identically configured image. This eliminates configuration drift, makes rollbacks deterministic, and ensures environments remain reproducible across scaling events and regions.

Why this answer

Option A is correct because immutable infrastructure patterns replace servers rather than patching them in place, which makes cloud deployments reproducible, eliminates configuration drift, and allows rollback by simply redeploying a known-good image. Option B is correct because designing for horizontal scaling (adding/removing instances behind a load balancer) matches the elastic, distributed nature of cloud platforms and avoids the single-instance ceiling and downtime of vertical scaling. Option E is correct because blue/green deployment runs two identical environments and shifts traffic (e.g., via DNS or a load balancer) only after the new version is validated, minimizing downtime and enabling instant rollback.

Option C is not a best practice because opening all ports in security groups violates least-privilege network access and exposes resources to attack. Option D is not a best practice because retaining unused resources wastes cost and increases the attack surface; cloud provisioning is fast enough that resources should be released and recreated as needed.

Exam trap

CompTIA often tests the misconception that 'keeping unused resources avoids delays' (D) is a valid cost-saving strategy, when in fact cloud environments are designed for rapid provisioning from images or snapshots, making idle resources an unnecessary expense and security risk.

83
MCQmedium

A company's cloud environment uses a shared responsibility model. The security team notices that a data breach occurred due to misconfigured storage buckets in the public cloud. Which party is primarily responsible for this misconfiguration according to the shared responsibility model?

A.The cloud service provider
B.The cloud auditor
C.A third-party security vendor
D.The customer
AnswerD

Under the shared responsibility model, the cloud provider secures the infrastructure, but the customer owns configuration of their own resources. Storage bucket permissions and access policies are customer-controlled, so the misconfiguration and resulting breach rest with the customer.

Why this answer

Under the shared responsibility model, the cloud customer is always responsible for securing their own data and configuring their own resources, including storage bucket permissions. Misconfigured storage buckets are a customer-side configuration error, not a provider failure. The provider secures the infrastructure, but the customer secures what they put in it and how they configure access.

Exam trap

CV0-004 often tests the shared responsibility model by presenting a misconfiguration scenario — candidates may incorrectly blame the provider, but the exam expects recognition that configuration is always the customer's responsibility.

How to eliminate wrong answers

Option A is wrong because the cloud service provider is responsible for security OF the cloud (physical, network, hypervisor), not security IN the cloud (customer data, configurations). Option B is wrong because a cloud auditor is an independent assessor, not an operational party responsible for configuration. Option C is wrong because a third-party security vendor may assist but does not bear primary responsibility — the customer owns the configuration.

84
MCQmedium

A cloud administrator is responsible for a production account and needs to ensure that an Amazon S3 bucket containing sensitive data cannot be made public, even by an administrator. The administrator wants a preventive control that blocks public access at the bucket and account level. Which action should the administrator take?

A.Create an AWS Config rule that detects public S3 buckets and sends an alert to the operations team when one is found.
B.Enable S3 server access logging and review the logs for public read requests to detect unauthorized exposure.
C.Attach an IAM policy to all users denying s3:PutBucketPolicy to prevent anyone from adding a public bucket policy.
D.Enable S3 Block Public Access at both the bucket and account levels and verify that no bucket policy grants public access.
AnswerD

S3 Block Public Access provides preventive controls that override bucket policies and ACLs that would otherwise grant public access. Enabling it at both the account and bucket levels ensures the setting applies broadly and cannot be bypassed by individual bucket configuration changes. This is the correct preventive control for preventing accidental or intentional public exposure of sensitive data.

Why this answer

S3 Block Public Access is the preventive control that overrides policies and ACLs granting public access, and applying it at both the account and bucket levels ensures comprehensive protection. Detective controls such as AWS Config rules or access logging only reveal exposure after the fact, and narrow IAM denials do not cover all paths to public access. The preventive setting is the correct choice for blocking public exposure.

Exam trap

The trap here is choosing a detective control such as AWS Config or access logging when the requirement explicitly calls for a preventive control that blocks public access.

85
MCQmedium

A cloud application is experiencing intermittent high latency. The operations team has enabled distributed tracing using AWS X-Ray but is unable to pinpoint the source. Which additional step should the team take to identify the root cause of the latency?

A.Enable VPC Flow Logs to analyze network traffic patterns.
B.Increase the auto-scaling group size to handle the load.
C.Analyze traces in X-Ray to identify which service segment has the highest duration.
D.Examine application logs on each virtual machine.
AnswerC

X-Ray traces already capture per-segment timing, so comparing segment durations isolates the subcomponent responsible for latency. Ranking segments by duration pinpoints the slow service or downstream call driving the intermittent spikes, which aggregate tracing alone cannot reveal.

Why this answer

AWS X-Ray provides distributed tracing that captures latency data for each segment of a request. To pinpoint the source of intermittent high latency, the team should analyze the traces to identify which service segment has the highest duration. This directly reveals the bottleneck, whether it's a database call, external API, or compute-intensive operation.

Other steps like VPC Flow Logs or application logs may provide additional context but are not as directly actionable for latency root cause.

Exam trap

CV0-004 often tests the confusion between network-level monitoring (VPC Flow Logs) and application-level tracing (X-Ray), leading candidates to choose network tools for application latency issues.

How to eliminate wrong answers

Option A is wrong because VPC Flow Logs capture IP traffic metadata, not application-level latency; they are useful for network troubleshooting but cannot identify which service segment is slow. Option B is wrong because increasing auto-scaling group size addresses capacity issues but does not help identify the root cause of latency; it may mask the problem or increase cost. Option D is wrong because examining application logs on each VM is time-consuming and may not correlate events across services; X-Ray traces already aggregate and correlate this data.

86
MCQmedium

A cloud administrator manages a hybrid cloud environment where on-premises servers connect to a VPC in AWS via a VPN connection. The on-premises network uses IP range 10.0.0.0/16. The VPC uses 172.16.0.0/16. The VPN is established and the tunnel status is UP. However, on-premises hosts cannot ping EC2 instances in the VPC. The administrator logs into an EC2 instance and can ping the on-premises VPN gateway IP. The security groups and network ACLs are configured to allow all traffic. The route tables in the VPC have a route to the on-premises network via the virtual private gateway. The on-premises firewall logs show that packets from the VPC are being dropped. What is the most likely cause?

A.The VPN tunnel is misconfigured and not passing traffic.
B.The on-premises firewall is blocking traffic from the VPC CIDR range.
C.The security group attached to the EC2 instance is blocking inbound ICMP.
D.The VPC route table does not have a route to the on-premises network.
AnswerB

The EC2 instance can reach the on-premises VPN gateway, proving the tunnel and VPC routing work. Since on-premises firewall logs show dropped packets from the VPC CIDR, the firewall is filtering that range, blocking return traffic to EC2 instances.

Why this answer

The on-premises firewall logs explicitly show that packets from the VPC are being dropped, indicating the firewall is filtering traffic from the VPC CIDR range (172.16.0.0/16). Since the VPN tunnel is UP, the EC2 instance can ping the on-premises VPN gateway IP, and security groups/network ACLs allow all traffic, the only remaining point of failure is the on-premises firewall blocking the return traffic.

Exam trap

The trap here is that candidates assume a UP VPN tunnel guarantees end-to-end connectivity, ignoring that on-premises firewalls often require explicit allow rules for the VPC CIDR, even when the tunnel is established.

How to eliminate wrong answers

Option A is wrong because the VPN tunnel status is UP and the EC2 instance can ping the on-premises VPN gateway IP, proving the tunnel is passing traffic correctly. Option C is wrong because the security group is configured to allow all traffic, and the issue is on the on-premises side as shown by firewall logs. Option D is wrong because the VPC route table already has a route to the on-premises network via the virtual private gateway, as stated in the scenario.

87
MCQhard

A company uses a cloud storage service with versioning enabled. An employee accidentally deleted a critical file. The administrator attempts to restore the file from the version history, but the file does not appear in the list of versions. What is the most likely reason?

A.The file was created before versioning was enabled.
B.Versioning was suspended after the file was created.
C.The file was overwritten, not deleted.
D.The file was deleted using a lifecycle policy.
AnswerA

Files created before versioning was enabled have no prior versions recorded, so they never appear in the version history list. Microsoft Entra ID is unrelated here; the constraint is that versioning only captures objects written after it was switched on, leaving pre-existing files unrestorable via version history.

Why this answer

When versioning is enabled on a cloud storage service (such as Amazon S3), only objects created or modified after the versioning feature is turned on are assigned a version ID. Any objects that existed before versioning was enabled are not tracked in the version history. Therefore, if the file was created prior to enabling versioning, it will not appear in the list of versions, and the administrator cannot restore it via version history.

Exam trap

The trap here is that candidates assume versioning retroactively protects all objects in the bucket, but in reality, versioning only applies to objects created or modified after it is enabled, and objects with a null version ID are not recoverable through version history.

How to eliminate wrong answers

Option B is wrong because suspending versioning does not remove existing version history; it only stops new versions from being created, and the file would still appear in the version list. Option C is wrong because overwriting a file creates a new version, and the previous version remains accessible in the version history; the file would still appear. Option D is wrong because lifecycle policies can delete noncurrent versions, but they operate on objects that already have version IDs; a file created before versioning was enabled would not have a version ID and thus would not be affected by a lifecycle policy.

88
MCQhard

A cloud engineer is responsible for a Kubernetes cluster on AWS EKS. The cluster runs a stateful application that requires persistent storage. The engineer must ensure that storage volumes are automatically provisioned when persistent volume claims are created, and that the storage remains available if the pod is rescheduled to a different node. Which solution should the engineer implement?

A.Use hostPath volumes in the pod specification to provide local storage on each node.
B.Configure a PersistentVolume manually for each pod and use node affinity to pin the pod to the node where the volume is located.
C.Use an emptyDir volume with a persistent volume claim template to provide storage that survives pod restarts.
D.Create a StorageClass that uses the AWS EBS CSI driver with the WaitForFirstConsumer volume binding mode, and reference it in a PersistentVolumeClaim.
AnswerD

The AWS EBS CSI driver enables dynamic provisioning of EBS volumes. Using WaitForFirstConsumer ensures the volume is provisioned in the same availability zone as the pod, allowing the pod to attach the volume after rescheduling within the same zone. This meets both dynamic provisioning and persistence requirements.

Why this answer

The AWS EBS CSI driver with a StorageClass and WaitForFirstConsumer binding mode enables dynamic provisioning of persistent EBS volumes. It ensures the volume is created in the correct availability zone and can be reattached when the pod is rescheduled, satisfying both automatic provisioning and data persistence.

Exam trap

The trap here is confusing hostPath or emptyDir with persistent storage solutions, when they are node-local and ephemeral, respectively.

89
MCQeasy

Which of the following is a key benefit of using object storage like Amazon S3 over block storage?

A.Unlimited scalability for unstructured data
B.Direct attachment to a single VM
C.Supports file-level locking
D.Lower latency for database workloads
AnswerA

Object storage addresses the stem's scalability constraint by using a flat namespace with HTTP-accessible objects, so capacity grows without provisioning volumes. Block storage requires pre-sized LUNs and a filesystem, capping practical scale. This makes S3 suitable for unstructured data such as media and logs.

Why this answer

Amazon S3 is designed for unlimited scalability, allowing you to store and retrieve any amount of unstructured data (e.g., images, videos, backups) without provisioning storage in advance. Unlike block storage, which has fixed size limits per volume, S3 automatically scales to accommodate petabytes of data, making it ideal for modern cloud-native applications.

Exam trap

The CV0-004 exam often tests the misconception that object storage is suitable for low-latency transactional workloads, but the trap here is that candidates confuse scalability with performance, forgetting that block storage (e.g., EBS) is optimized for low latency via direct attachment and NVMe protocols, while object storage prioritizes scale and cost over speed.

How to eliminate wrong answers

Option B is wrong because direct attachment to a single VM is a characteristic of block storage (e.g., Amazon EBS), not object storage like S3, which is accessed via HTTP/HTTPS APIs over the network. Option C is wrong because object storage typically does not support file-level locking; it uses eventual consistency or strong consistency for objects, not file locks like NFS or SMB. Option D is wrong because object storage has higher latency compared to block storage (e.g., EBS or local SSD) due to its HTTP-based API and distributed architecture, making it unsuitable for low-latency database workloads.

90
MCQhard

A cloud engineer needs to ensure that an auto-scaling group does not launch new instances immediately after a scale-in event to allow metrics to stabilize. Which feature should they configure?

A.Health checks
B.Scheduled scaling
C.Lifecycle hooks
D.Cooldown periods
AnswerD

Cooldown periods pause further scaling actions after a scale-in, letting metrics stabilise before the auto-scaling group launches replacement instances. This directly satisfies the stem's requirement to prevent immediate launches, as the cooldown timer blocks new scaling activity until it expires.

Why this answer

Cooldown periods are specifically designed to prevent an Auto Scaling group from launching or terminating additional instances immediately after a scaling activity. This allows metrics to stabilize and prevents rapid, unnecessary scaling actions. By configuring a cooldown period, the engineer ensures that new instances are not launched until the cooldown expires, giving the system time to reflect the effect of the previous scaling event.

Exam trap

CV0-004 often tests the confusion between cooldown periods and lifecycle hooks, as both involve timing and instance management, but only cooldown periods directly prevent immediate scaling after a scale-in event.

How to eliminate wrong answers

Option A is wrong because health checks determine instance health and replace unhealthy instances, but they do not control the timing of scaling actions. Option B is wrong because scheduled scaling is used to scale based on predictable time patterns, not to delay scaling after an event. Option C is wrong because lifecycle hooks allow you to perform custom actions before an instance is put into service or terminated, but they do not inherently prevent immediate scaling after a scale-in event.

91
MCQmedium

A cloud administrator receives an alert that a virtual machine (VM) is unresponsive. The VM is hosted on a hypervisor that shows high CPU ready time. Which of the following is the most likely cause?

A.Insufficient memory allocated to the VM
B.Network latency between the VM and storage
C.Disk I/O contention from other VMs
D.Over-provisioning of vCPUs on the hypervisor
AnswerD

High CPU ready time means vCPUs wait in the hypervisor's run queue before receiving physical CPU cycles. Over-provisioning vCPUs across guests on the same host oversubscribes physical cores, so each VM waits longer, presenting as an unresponsive guest.

Why this answer

High CPU ready time indicates that the VM is ready to execute instructions but is waiting for the hypervisor to schedule physical CPU time. This is a classic symptom of over-provisioning vCPUs, where the total number of vCPUs assigned to all VMs exceeds the available physical cores, causing contention at the hypervisor scheduler level.

Exam trap

The trap here is that candidates confuse high CPU ready time with high CPU usage or memory pressure, but ready time is a hypervisor-level scheduling delay, not a guest OS metric, and is directly tied to vCPU over-provisioning.

How to eliminate wrong answers

Option A is wrong because insufficient memory would typically cause swapping or ballooning, not high CPU ready time, which is a CPU scheduling metric. Option B is wrong because network latency between the VM and storage affects storage I/O latency, not CPU scheduling, and would manifest as high disk latency or queue depth. Option C is wrong because disk I/O contention from other VMs would result in high disk queue length or latency, not CPU ready time, which is a measure of CPU starvation.

92
MCQhard

A cloud administrator is configuring auto-scaling for a batch processing application that uses an SQS queue. The number of jobs varies unpredictably. Which metric is most appropriate for scaling the worker instances?

A.Memory utilization of workers
B.SQS queue depth (ApproximateNumberOfMessages)
C.Network throughput
D.CPU utilization of workers
AnswerB

Queue depth directly reflects pending work, so workers scale with actual backlog rather than a proxy. Because job volume varies unpredictably, ApproximateNumberOfMessages lets auto-scaling add instances when messages accumulate and remove them when the queue drains, matching capacity to demand.

Why this answer

SQS queue depth (ApproximateNumberOfMessages) is the most appropriate metric because it directly reflects the backlog of work. For a batch processing application with unpredictable job volumes, scaling based on queue depth ensures that worker instances are added when there are many messages waiting and removed when the queue is empty. This provides responsive scaling that matches the actual workload.

Exam trap

CV0-004 often tests the tendency to choose CPU utilization as a default scaling metric, but for queue-based workloads, the queue depth is a more direct and effective metric.

How to eliminate wrong answers

Option A is wrong because memory utilization may not correlate with the number of pending jobs; workers could be idle but using memory. Option C is wrong because network throughput is not a direct indicator of pending work; it could be high due to other traffic. Option D is wrong because CPU utilization may be low if workers are waiting for I/O or if the job is not CPU-intensive, leading to under-scaling.

93
MCQhard

A cloud administrator is responsible for ensuring the availability of a critical application that runs on a virtual machine. The administrator needs to implement a solution that can automatically restart the virtual machine if it becomes unresponsive due to an operating system crash. Which of the following should the administrator configure?

A.A snapshot-based backup policy
B.A load balancer with a health probe
C.A VM group configured with automatic recovery
D.A custom script that sends a heartbeat to a monitoring service
AnswerC

A VM group with automatic recovery monitors guest health and restarts the virtual machine when the operating system stops responding, satisfying the requirement to recover automatically from an OS crash. Unlike host-level HA, which only reacts to physical host failure, this detects in-guest unresponsiveness and triggers the restart.

Why this answer

Configuring automatic recovery for the VM (or a group of VMs) allows the cloud platform to detect a VM failure and automatically restart it. This is a feature provided by most cloud providers to ensure high availability.

Exam trap

The trap here is that candidates often confuse a load balancer's health probe (which only reroutes traffic) with automatic VM recovery, or they assume a custom heartbeat script alone is sufficient without understanding that it lacks the built-in execution engine to perform the restart.

How to eliminate wrong answers

Option A is wrong because a snapshot-based backup policy is designed for data protection and recovery from corruption or accidental deletion, not for detecting and automatically restarting an unresponsive VM due to an OS crash. Option B is wrong because a load balancer with a health probe distributes traffic and removes unhealthy instances from the pool, but it does not automatically restart the VM; it only reroutes traffic, leaving the VM in a failed state. Option D is wrong because a custom script that sends a heartbeat to a monitoring service can detect unresponsiveness but requires an external automation mechanism (e.g., Azure Automation, Logic Apps) to trigger the restart; it is not a built-in, self-contained solution for automatic VM restart.

94
MCQeasy

A cloud engineer is writing a Terraform configuration to provision an AWS EC2 instance. They need to pass the AMI ID as a variable to make the configuration reusable. Which Terraform block should be used to define the variable?

A.output
B.provider
C.variable
D.resource
AnswerC

The variable block declares an input variable, letting the AMI ID be supplied at plan or apply time rather than hard-coded, which makes the configuration reusable across environments. Output exposes values, locals compute intermediates, and provider configures the AWS plugin.

Why this answer

Variables are defined using the 'variable' block. 'resource' declares resources; 'provider' configures providers; 'output' defines outputs.

95
MCQmedium

A healthcare company must ensure that patient records stored in a public cloud are encrypted at rest and that the company alone controls the keys used for encryption, including the ability to revoke access immediately if an employee leaves. Which key management approach BEST satisfies these requirements?

A.Enable transport layer security for all connections and rely on it to protect stored patient records.
B.Use provider-managed encryption keys that the cloud vendor generates and rotates automatically.
C.Use customer-managed keys stored in a cloud key management service with granular access policies.
D.Encrypt data with a symmetric key hardcoded in the application source code stored in the repository.
AnswerC

Customer-managed keys in a key management service let the organization own the key material and define access through policies. Revoking a user's permission to the key immediately removes their ability to decrypt data, and the company can rotate or disable keys itself. This meets both the encryption-at-rest and exclusive-control requirements.

Why this answer

Customer-managed keys in a cloud key management service give the healthcare company ownership of the key material and policy-based control over who may use it. Revoking a departing employee's key permissions blocks decryption immediately, and the organization can rotate or disable keys on its own schedule, satisfying both encryption-at-rest and exclusive key custody.

Exam trap

The trap here is treating encryption in transit as equivalent to encryption at rest, when they protect data in different states.

96
Multi-Selecthard

A cloud team is planning a disaster recovery drill for their application running in a public cloud. They want to validate that the recovery process meets the defined RTO and RPO. Which THREE activities should be included in the DR drill? (Select THREE.)

Select 3 answers
A.Review cost optimization recommendations for the DR environment.
B.Measure the time taken to restore services from backups.
C.Run chaos engineering experiments to introduce random failures.
D.Perform a failover to the DR site and verify application functionality.
E.Check the timestamp of the most recent backup or replica to ensure data is within RPO.
AnswersB, D, E

Measuring restore duration directly validates the recovery time objective, confirming services return within the agreed RTO. Timing restoration from backups exercises the actual recovery mechanism, exposing whether backup retrieval, data transfer and service start-up collectively satisfy the RTO constraint defined in the stem.

Why this answer

The drill must validate the two key recovery objectives, so option B is correct because measuring the time taken to restore services from backups directly tests whether the actual recovery time meets the defined RTO. Option D is correct because performing a failover to the DR site and verifying application functionality proves that the recovery environment works end-to-end and that services can actually be resumed at the DR location. Option E is correct because checking the timestamp of the most recent backup or replica confirms the data loss window, which is exactly what RPO measures.

Option A is not part of validating RTO/RPO; cost optimization is a separate FinOps activity. Option C, chaos engineering, tests resilience to random failures but is not a required DR drill activity for validating recovery time and data currency against RTO and RPO.

Exam trap

CV0-004 often tests the distinction between DR drill activities and other operational tasks like cost optimization or chaos engineering, and candidates may incorrectly include activities that do not directly validate RTO/RPO.

97
MCQmedium

A cloud engineer is deploying a containerized application using Kubernetes. The application consists of a frontend, a backend API, and a database. The engineer needs to ensure that the backend API can be reached by the frontend but not from outside the cluster. Which Kubernetes resource should the engineer use to expose the backend API?

A.NodePort service
B.ClusterIP service
C.Ingress resource
D.LoadBalancer service
AnswerB

ClusterIP assigns a virtual IP reachable only inside the cluster network, so frontend pods can reach the backend API while external clients cannot. This satisfies the stem's requirement that the backend be unreachable from outside the cluster.

Why this answer

A ClusterIP service exposes the backend API on a cluster-internal IP address, making it reachable only from within the Kubernetes cluster. This meets the requirement that the frontend can communicate with the backend API, but external traffic is blocked. ClusterIP is the default service type and is ideal for internal service-to-service communication.

Exam trap

The trap here is that candidates often confuse Ingress as a method to expose services internally, but Ingress is specifically designed for external HTTP/HTTPS traffic and does not restrict access to cluster-internal communication.

How to eliminate wrong answers

Option A is wrong because a NodePort service exposes the backend API on a static port on each node's IP address, allowing external traffic to reach the service from outside the cluster, which violates the requirement. Option C is wrong because an Ingress resource is not a service type; it provides HTTP/HTTPS routing to services from outside the cluster and typically requires an Ingress controller, thus exposing the backend externally. Option D is wrong because a LoadBalancer service provisions an external load balancer (e.g., from a cloud provider) with a public IP, making the backend API accessible from outside the cluster, which contradicts the requirement.

98
MCQeasy

A developer wants to deploy an application using Azure Bicep. What is a key benefit of using Bicep over ARM templates?

A.Bicep has simpler, more readable syntax than ARM JSON
B.Bicep can be used to manage any cloud provider
C.Bicep eliminates the need for resource providers
D.Bicep supports imperative scripting
AnswerA

Bicep's declarative DSL compiles directly to ARM JSON, so it provides identical resource coverage while replacing verbose JSON brackets, quotes and nested expressions with concise, readable syntax. This directly satisfies the stem's requirement for a key benefit over ARM templates: reduced authoring complexity without losing any deployment capability.

Why this answer

Bicep is a domain-specific language that provides a cleaner, more readable, and more concise syntax than ARM JSON templates. It abstracts away much of the JSON boilerplate, such as parameters, variables, and resource declarations, while still compiling to ARM JSON for deployment. This makes authoring and maintaining infrastructure-as-code easier.

Exam trap

CV0-004 often tests the misconception that Bicep is multi-cloud or imperative; it is Azure-specific and declarative, compiling to ARM JSON.

How to eliminate wrong answers

Option B is wrong because Bicep is specific to Azure; it cannot manage other cloud providers like AWS or GCP. Option C is wrong because Bicep still relies on Azure resource providers to deploy resources; it does not eliminate them. Option D is wrong because Bicep is declarative, not imperative; it describes the desired end state, and Azure Resource Manager handles the deployment orchestration.

99
MCQmedium

A cloud operations team runs a containerized payroll application on Amazon EKS. Compliance requires that the application pod retrieve database credentials at runtime without embedding them in the container image, and that the credentials be rotated automatically every 30 days. Which approach BEST meets these requirements?

A.Create an IAM role for the service account and let the application call the database with IAM authentication credentials that never expire.
B.Mount the credentials as a Kubernetes Secret created from a base64-encoded manifest stored in the Git repository.
C.Store the credentials in AWS Secrets Manager and use the AWS Secrets Manager and Config Provider for Secrets Store CSI Driver to inject them into the pod.
D.Inject the credentials as environment variables through the pod spec, referencing values held in an encrypted Amazon S3 bucket.
AnswerC

The Secrets Store CSI Driver with the AWS provider mounts Secrets Manager values directly into the pod as files, so nothing is baked into the image. Secrets Manager supports native rotation schedules, including every 30 days, and the auto-rotate feature refreshes the mounted files without a pod restart. This satisfies both the runtime retrieval and automatic rotation requirements.

Why this answer

The requirement is runtime retrieval of database credentials plus automatic 30-day rotation without embedding secrets in the image. A secrets manager with native rotation integrated into the pod through the Secrets Store CSI Driver delivers both, mounting values as files and refreshing them on schedule. Base64 secrets, environment variables, and IAM role credentials each miss either the rotation or the runtime-injection aspect of the scenario.

Exam trap

The trap here is assuming that base64-encoded Kubernetes Secrets or environment variables provide secure secret handling, when they actually expose plaintext credentials and offer no rotation.

100
MCQeasy

A company is migrating a legacy application to Google Cloud. The application requires a relational database with automatic failover and replication across multiple zones within a region. Which Google Cloud service should the company use?

A.Cloud Spanner
B.Firestore
C.Cloud Bigtable
D.Cloud SQL with high availability configuration
AnswerD

Cloud SQL offers a high availability configuration that creates a standby instance in a different zone within the same region. It provides automatic failover and synchronous replication to the standby. This meets the requirement for a relational database with automatic failover and multi-zone replication within a region.

Why this answer

Cloud SQL with high availability configuration is the correct choice because it provides a relational database with automatic failover and synchronous replication to a standby instance in a different zone. This matches the requirement for multi-zone replication within a region for a legacy relational application.

Exam trap

The trap here is assuming that any highly available database service will work; Cloud SQL HA is specifically designed for regional multi-zone failover, while other services are either NoSQL or globally distributed.

101
MCQhard

A cloud architect is designing a VPC for a three-tier web application. The web servers must be accessible from the internet, the application servers should only be reachable from the web tier, and the database servers should not have any public IP addresses and should be isolated. Which subnet design meets these requirements?

A.Web tier in public subnet, app tier in private subnet, database tier in a separate private subnet with no internet gateway
B.Web tier in public subnet, app and database tiers in the same private subnet
C.All servers in private subnets with a NAT gateway for inbound traffic
D.All servers in the same public subnet with security groups
AnswerA

This design satisfies every stated constraint: the public subnet exposes web servers to the internet, the private app subnet is reachable only from the web tier via security groups, and the isolated database subnet lacks a route to an internet gateway, so no public IPs are needed.

Why this answer

A three-tier architecture requires strict network segmentation: the web tier in a public subnet with a route to an Internet Gateway for inbound traffic, the app tier in a private subnet reachable only from the web tier (via security groups or NACLs), and the database tier in a separate private subnet with no route to an Internet Gateway or NAT Gateway, ensuring complete isolation. This design enforces least-privilege network access and satisfies the stated requirements.

Exam trap

CV0-004 often tests the misconception that security groups alone can isolate tiers within a single public subnet — candidates must recognize that subnet-level routing (public vs. private, presence of IGW/NAT) is the primary segmentation control.

How to eliminate wrong answers

Option B is wrong because placing the app and database tiers in the same private subnet violates the isolation requirement — the database would share a subnet with the app tier, allowing lateral movement and broader reachability than intended. Option C is wrong because a NAT gateway provides outbound internet access for private subnets, not inbound access; putting all servers in private subnets would make the web tier unreachable from the internet. Option D is wrong because placing all servers in a single public subnet exposes the app and database tiers to the internet and relies solely on security groups, violating the requirement that the database have no public IP and be isolated.

102
Multi-Selectmedium

Which THREE of the following are common causes of cloud resource provisioning failures?

Select 3 answers
A.Insufficient service quotas.
B.Policy restrictions (e.g., organization policies).
C.Exceeded resource limits (e.g., vCPU, memory).
D.Disk encryption settings.
E.Incorrect resource tagging.
AnswersA, B, C

Insufficient service quotas directly block provisioning because the cloud platform enforces per-subscription or per-region limits on resources such as vCPUs, public IP addresses, and storage accounts. When a deployment requests capacity beyond the allotted quota, the API rejects the request, making quota exhaustion a frequent and well-documented cause of provisioning failure.

Why this answer

Insufficient service quotas (A) are a common cause of provisioning failures because cloud providers cap the number of resources or capacity per region/project, and requests beyond the quota are rejected until an increase is approved. Policy restrictions such as organization policies (B) block resource creation when the request violates constraints (for example, allowed regions, machine types, or public IP rules), causing the provisioning operation to fail. Exceeded resource limits like vCPU or memory (C) also cause failures when the requested instance size or aggregate capacity surpasses the account's or region's available limits.

Disk encryption settings (D) and incorrect resource tagging (E) are not typical causes of provisioning failure; encryption is usually a configuration choice that is supported, and tagging is generally optional metadata that does not prevent resource creation.

Exam trap

CompTIA often tests the distinction between hard failures (quotas, policies, limits) and soft failures (tagging, encryption), where candidates mistakenly think metadata or encryption misconfigurations prevent provisioning when they actually only cause post-deployment issues.

103
MCQmedium

A DevOps team is deploying containerized applications on Kubernetes. They want to ensure containers do not run with root privileges and that host filesystem access is restricted. Which Kubernetes feature should they use?

A.Service accounts
B.ConfigMaps
C.Network policies
D.Pod Security Standards
AnswerD

Pod Security Standards define restricted, baseline and privileged profiles enforced via Pod Security Admission. The restricted profile blocks root execution and host filesystem mounts, directly satisfying both the non-root and host-access constraints without custom policy authoring.

Why this answer

Pod Security Standards (PSS) define three profiles — Privileged, Baseline, and Restricted — that control whether pods can run as root, use host namespaces, access the host filesystem, or use privileged capabilities. Enforcing the Restricted profile via Pod Security Admission (PSA) directly prevents root execution and restricts hostPath/host filesystem access. This is the native Kubernetes mechanism for pod-level security hardening.

Exam trap

The trap is conflating network-level controls (Network Policies) or identity controls (Service Accounts) with workload security controls — candidates pick Network Policies because 'restricting access' sounds security-related, but it does not address root privileges or host filesystem mounts.

How to eliminate wrong answers

Option A is wrong because Service Accounts provide an identity for pods to authenticate to the Kubernetes API and access resources — they do not restrict root privileges or host filesystem access. Option B is wrong because ConfigMaps store non-sensitive configuration data as key-value pairs and have no security enforcement capability. Option C is wrong because Network Policies control ingress/egress traffic between pods at the network layer (L3/L4) and do not govern process privileges or filesystem mounts.

104
MCQmedium

A cloud engineer is deploying a containerized workload to a Kubernetes cluster running in a public cloud. The security team requires that the application pods never use long-lived static credentials to access the cloud provider's object storage service. The cluster already runs an OpenID Connect (OIDC) identity provider that the cloud provider trusts. Which approach should the engineer implement to meet this requirement?

A.Configure an IAM role with a trust policy scoped to the cluster's OIDC provider and annotate the Kubernetes service account so pods receive short-lived tokens.
B.Enable basic authentication on the Kubernetes API server and issue each pod a static service account token stored in a durable Secret.
C.Deploy a sidecar container that holds a username and password for the object storage service and proxies all requests from the application container.
D.Store the object storage access key and secret key in a Kubernetes Secret and mount it into the pod as environment variables.
AnswerA

This is exactly what IRSA-style workload identity federation provides: the cloud IAM role trusts the cluster's OIDC issuer, and the annotated service account lets pods exchange a projected service account token for temporary cloud credentials. No static keys exist anywhere, tokens expire automatically, and access is scoped per service account, satisfying the no-long-lived-credentials requirement cleanly.

Why this answer

Federating the Kubernetes service account with the cloud IAM role through the cluster's OIDC provider lets pods obtain short-lived, automatically rotated credentials scoped to a single workload. Because no secret key material is ever stored in the cluster, the requirement that pods never use long-lived static credentials is met, and least privilege is enforced per service account rather than shared cluster-wide.

Exam trap

The trap here is assuming that storing credentials in a Kubernetes Secret makes them safe, when Secrets are merely base64-encoded and remain long-lived static credentials.

105
MCQhard

A company uses Azure AD for identity federation with an on-premises Active Directory. They want to enable single sign-on (SSO) for cloud applications using an open standard. Which protocol should they use?

A.OAuth 2.0
B.SAML 2.0
C.LDAP
D.Kerberos
AnswerB

SAML 2.0 is an open OASIS standard for exchanging authentication and authorisation data, letting Microsoft Entra ID act as identity provider and issue signed assertions to cloud applications. This satisfies the stem's federation requirement with on-premises Active Directory, delivering browser-based SSO without exposing credentials to each application.

Why this answer

SAML (Security Assertion Markup Language) and OIDC (OpenID Connect) are open standards for federation. SAML is commonly used for SSO with Azure AD. OAuth is for authorization, not authentication.

LDAP is a directory protocol. Kerberos is for on-premises.

106
MCQmedium

A financial services company runs a containerized payment application on Google Kubernetes Engine (GKE). A compliance auditor requires that all container images deployed to the cluster be cryptographically verified for integrity and provenance before admission. The security team wants to enforce this at the cluster level without modifying each application's deployment pipeline. Which GKE feature should they implement?

A.VPC Service Controls
B.Container Analysis
C.Shielded GKE Nodes
D.Binary Authorization
AnswerD

Binary Authorization is a GKE-native admission controller that enforces attestation-based policies on container images at deploy time. It verifies cryptographic signatures produced by trusted attestors before allowing a pod to be created. This satisfies the auditor's requirement for integrity and provenance verification without touching individual pipelines, since enforcement happens centrally on the cluster's admission webhook.

Why this answer

Binary Authorization is the GKE feature purpose-built to enforce that only images signed by trusted attestors can be deployed. Because enforcement occurs through the cluster admission controller, the policy applies centrally without requiring changes to each pipeline. The other options address network perimeters, image metadata scanning, or node hardening, none of which cryptographically verify image provenance at admission time.

Exam trap

The trap here is confusing image scanning tools like Container Analysis with admission enforcement mechanisms — scanning reports findings, while Binary Authorization actually blocks non-compliant images.

107
Multi-Selecteasy

Which TWO characteristics are essential for a cloud service to be considered as a true Infrastructure as a Service (IaaS) offering?

Select 2 answers
A.Customer has control over the guest operating system
B.Provider automatically applies OS security patches
C.Customer manages the underlying hypervisor
D.Provider performs automated backups of all customer data
E.On-demand self-service provisioning of virtual machines
AnswersA, E

IaaS leaves guest OS patching, configuration and administration to the customer, distinguishing it from PaaS, where the provider manages the runtime. This control over the guest operating system is the defining characteristic separating IaaS from higher-level managed offerings.

Why this answer

Option A is correct because a defining trait of IaaS is that the consumer, not the provider, controls the guest operating system, including choosing the OS, installing patches, and managing middleware and applications running on the provisioned compute resources. Option E is correct because IaaS must deliver on-demand self-service provisioning, typically through APIs or portals, allowing consumers to unilaterally spin up virtual machines and other resources without human interaction from the provider. Option B is incorrect because automatic OS patching is a provider-managed responsibility typical of PaaS or managed services, not a required IaaS characteristic.

Option C is incorrect because in IaaS the provider, not the customer, manages the underlying hypervisor and virtualization layer. Option D is incorrect because automated backups of all customer data are not an essential IaaS characteristic; data backup is generally the consumer's responsibility in the IaaS shared responsibility model.

Exam trap

CompTIA often tests the misconception that IaaS includes provider-managed OS patching or backups, confusing it with PaaS or managed services, but the core distinction is customer control over the guest OS and on-demand self-service provisioning.

108
MCQmedium

A cloud administrator is configuring a new virtual private cloud (VPC) and needs to ensure that traffic between web servers and database servers is restricted to only the necessary ports. Which security approach should the administrator implement?

A.Enable VPC flow logs to detect and block malicious traffic.
B.Configure a security group with inbound rules for the web tier and outbound rules for the database tier.
C.Create an IAM policy to restrict access between subnets.
D.Implement network ACLs with rules that allow only database-specific ports (e.g., 3306) from web to database and block all other traffic.
AnswerB

Correct. Configuring security groups with inbound rules on the database tier to allow only the necessary database port from the web tier's security group, and outbound rules on the web tier, effectively restricts traffic to required ports.

Why this answer

Security groups are stateful firewalls that operate at the instance level. By configuring a security group for the database tier with an inbound rule that allows traffic only from the web tier's security group on the necessary database port (e.g., 3306 for MySQL), and a corresponding outbound rule on the web tier's security group, the administrator can restrict traffic to only the required ports. Network ACLs are stateless and require explicit rules for return traffic, making them more complex and error-prone.

IAM policies manage permissions, not traffic. Flow logs only monitor traffic, they do not block it.

Exam trap

Candidates often confuse security groups with network ACLs. Security groups are stateful and operate at the instance level, while NACLs are stateless and operate at the subnet level. For restricting traffic between specific instances (like web and database servers), security groups are the more appropriate and granular control.

109
MCQmedium

A company deploys a stateless web application across two AWS Availability Zones behind a load balancer. This design primarily improves which characteristic?

A.Cost efficiency
B.High availability
C.Scalability
D.Security
AnswerB

Spreading the stateless application across two Availability Zones behind a load balancer removes a single point of failure. If one zone fails, the load balancer routes traffic to the surviving zone, so the design primarily improves high availability rather than scalability, elasticity or durability.

Why this answer

Deploying a stateless web application across two AWS Availability Zones behind a load balancer primarily improves high availability. If one AZ fails, the load balancer routes traffic to the healthy AZ, ensuring the application remains accessible. This design eliminates a single point of failure.

Exam trap

The trap here is confusing high availability with scalability; multi-AZ improves availability, while scalability is about handling growth, often achieved via Auto Scaling.

How to eliminate wrong answers

Option A is wrong because deploying across multiple AZs may increase costs due to duplicate resources and data transfer charges. Option C is wrong because scalability is about handling increased load, which can be achieved within a single AZ using Auto Scaling; multi-AZ is for availability. Option D is wrong because security is enhanced through other measures like security groups, IAM, and encryption, not by multi-AZ deployment itself.

110
MCQeasy

A cloud engineer is configuring object storage for a media company that stores video archives accessed a few times per year but must retain them for seven years for compliance. Retrieval latency of several hours is acceptable, and cost must be minimized. Which storage tier characteristic should the engineer select?

A.An archive tier with long retrieval times and the lowest storage cost.
B.A local SSD volume attached to a virtual machine that stores the archives.
C.A standard tier with millisecond access and no retrieval fee.
D.A high-performance tier with low latency and frequent-access pricing.
AnswerA

Archive tiers are engineered for long-term retention of data that is rarely accessed, offering the lowest storage price per gigabyte in exchange for retrieval times measured in hours. The scenario permits several hours of retrieval latency and prioritizes cost, so an archive tier aligns exactly with both the access pattern and the compliance retention period.

Why this answer

Archive-class object storage is purpose-built for data retained for years but read only occasionally, trading retrieval latency for the lowest storage cost per gigabyte. Since the media company accepts hours of retrieval delay and emphasizes cost, the archive tier satisfies both the compliance retention period and the budget constraint better than any frequently accessed or block-based option.

Exam trap

The trap here is equating durability and compliance retention with frequent-access storage, when archive tiers provide equal durability at much lower cost.

111
MCQmedium

A cloud operations team is implementing a tagging strategy for cost attribution. They need to track costs by environment (dev, test, prod), project, and team. Which approach should they use?

A.Use resource groups to organize resources by environment
B.Apply tags such as Environment, Project, and Team to all resources
C.Use resource naming conventions to encode environment and project
D.Create separate cloud accounts for each environment
AnswerB

Applying Environment, Project and Team tags to all resources creates the three attribution dimensions the stem requires, enabling cost reports grouped by deployment stage, initiative and owning group. Consistent tagging across resources is what makes allocation accurate.

Why this answer

Tags are key-value pairs that can be applied to resources and used for cost allocation, filtering, and reporting across environments, projects, and teams. Applying Environment, Project, and Team tags to all resources enables granular cost attribution in billing reports and supports chargeback/showback models.

Exam trap

The trap here is confusing naming conventions or account separation with tagging — candidates often think a well-structured name or separate accounts is sufficient for cost attribution, but only tags provide the queryable metadata needed for billing reports.

How to eliminate wrong answers

Option A is wrong because resource groups are an Azure construct for lifecycle management, not a cost-attribution mechanism in a multi-cloud context, and they do not provide the flexible key-value metadata needed for cross-cutting dimensions. Option C is wrong because naming conventions are not machine-readable metadata — they cannot be used directly in billing filters or cost reports without parsing, and they are error-prone. Option D is wrong because creating separate accounts per environment is an isolation strategy, not a tagging strategy, and it does not address tracking by project or team within an environment.

112
MCQhard

A cloud architect is designing a DDoS protection strategy for a web application hosted on AWS. The application uses an Application Load Balancer (ALB). Which service provides automatic, always-on DDoS protection at no additional cost?

A.AWS WAF
B.AWS Network Firewall
C.AWS Shield Standard
D.AWS Shield Advanced
AnswerC

AWS Shield Standard is enabled automatically on all AWS accounts and protects against common network and transport layer DDoS attacks at no extra charge. It defends the ALB without configuration, satisfying the always-on, zero-cost constraint.

Why this answer

AWS Shield Standard provides automatic protection against common DDoS attacks for all AWS customers at no additional cost.

113
MCQeasy

A company wants to migrate its on-premises workloads to the cloud but must keep sensitive customer data on-premises due to regulatory compliance. Which cloud deployment model should they use?

A.Public cloud
B.Hybrid cloud
C.Multi-cloud
D.Private cloud
AnswerB

Hybrid cloud keeps sensitive customer data on-premises while extending workloads to the public cloud, directly satisfying the regulatory constraint. Unlike public or private cloud alone, it connects on-premises infrastructure with cloud services, letting the company migrate non-sensitive workloads without breaching data-residency rules.

Why this answer

A hybrid cloud model combines on-premises infrastructure with public cloud services, allowing sensitive data to remain on-premises while other workloads leverage cloud scalability. This meets regulatory compliance by keeping data local while enabling cloud benefits for non-sensitive components.

Exam trap

The trap is confusing hybrid cloud with multi-cloud. Multi-cloud uses multiple public clouds but does not address on-premises data residency requirements.

How to eliminate wrong answers

Option A is wrong because public cloud alone cannot keep sensitive data on-premises. Option C is wrong because multi-cloud involves multiple public cloud providers, not on-premises integration. Option D is wrong because private cloud is solely on-premises and does not provide the flexibility of public cloud for other workloads.

114
MCQeasy

A cloud administrator needs to transfer 50 TB of data from an on-premises NAS to Amazon S3. The office has limited bandwidth (50 Mbps). Which service is most suitable for this offline transfer?

A.AWS VPN
B.AWS DataSync
C.AWS Snowball
D.S3 Transfer Acceleration
AnswerC

AWS Snowball provides a physical appliance for offline bulk data transfer, bypassing the 50 Mbps bandwidth constraint that would make 50 TB take months to upload. Data is shipped to AWS and imported into S3.

Why this answer

AWS Snowball is a physical petabyte-scale data transport device designed for offline data migration when network bandwidth is insufficient. With 50 TB of data and only 50 Mbps bandwidth, transferring over the network would take months (roughly 100+ days), making Snowball the appropriate choice for offline transfer to S3.

Exam trap

CV0-004 often tests whether candidates pick online transfer services (DataSync, Transfer Acceleration) for scenarios where bandwidth makes network transfer impractical, missing the cue that 'offline' and 'limited bandwidth' point to Snowball.

How to eliminate wrong answers

Option A is wrong because AWS VPN establishes an encrypted network tunnel over the internet — it does not solve the bandwidth limitation and would still require transferring 50 TB over a 50 Mbps link. Option B is wrong because AWS DataSync is an online data transfer service that moves data over the network (or via Direct Connect); it is not an offline solution and would be bottlenecked by the 50 Mbps link. Option D is wrong because S3 Transfer Acceleration uses AWS edge locations to speed up uploads over the internet — it improves throughput but cannot overcome a 50 Mbps origin uplink for 50 TB of data.

115
Multi-Selectmedium

Which TWO metrics should be monitored to determine if a cloud database is experiencing a memory bottleneck?

Select 2 answers
A.Network bytes sent
B.Swap usage
C.Average disk queue length
D.Disk latency
E.Page faults per second
AnswersB, E

Swap usage rises when physical memory is exhausted and the database pages memory to disk. Sustained swap activity signals a memory bottleneck, since the instance is compensating for insufficient RAM by moving pages to slower storage.

Why this answer

Swap usage (B) is a direct indicator of memory pressure: when the database's working set exceeds available RAM, the OS pages memory out to swap, so sustained or rising swap activity signals a memory bottleneck. Page faults per second (E) is also a core memory metric, since a high rate of hard page faults means the database is repeatedly fetching pages from disk instead of RAM, confirming insufficient memory. By contrast, network bytes sent (A) reflects throughput/bandwidth rather than memory contention, and average disk queue length (C) and disk latency (D) measure storage subsystem performance, which may be affected by paging but do not by themselves identify a memory bottleneck.

Exam trap

CompTIA often tests the distinction between memory-specific metrics (swap usage, page faults) and storage-related metrics (disk queue length, latency), trapping candidates who confuse high disk activity with memory pressure.

116
Multi-Selecthard

A company uses AWS and wants to implement structured logging for their applications to improve queryability. Which THREE practices should they follow? (Select THREE.)

Select 3 answers
A.Send all logs to a single S3 bucket without partitioning
B.Include timestamp, severity, and request ID in each log entry
C.Use a consistent schema across all services
D.Write logs in JSON format
E.Encrypt log files at rest using AWS KMS
AnswersB, C, D

Timestamp, severity and request ID are discrete, machine-parseable fields that let queries filter by time window, log level or trace a single request across services. This satisfies the queryability goal by replacing free-text scanning with indexed field lookups.

Why this answer

Option B is correct because including timestamp, severity, and request ID in each log entry provides the essential contextual fields needed for filtering, correlating, and troubleshooting requests across distributed services. Option C is correct because a consistent schema across all services ensures that queries, dashboards, and log-processing pipelines can reliably parse and aggregate logs without per-service custom logic. Option D is correct because writing logs in JSON format produces machine-readable, structured events with named fields, which is the foundation for queryability in tools like Amazon CloudWatch Logs Insights or Athena.

Option A is not appropriate because dumping all logs into a single unpartitioned S3 bucket hurts query performance and increases scan costs, since partitioning by date or service is a best practice. Option E is not part of structured logging; KMS encryption at rest is a security control and does not improve the structure or queryability of log data.

Exam trap

CV0-004 often tests the confusion between security practices (like encryption) and operational practices (like structured logging), leading candidates to select encryption as a logging best practice when it does not address queryability.

117
MCQmedium

A company uses GitLab CI for its CI/CD pipeline. The pipeline includes a 'deploy' job that runs only when a tag is pushed. Which GitLab CI keyword should be used to control job execution based on tags?

A.stage
B.except
C.only
D.needs
AnswerC

The only keyword restricts a job to specified conditions, such as only: tags, so the deploy job runs solely when a tag is pushed. This satisfies the stem's requirement to control execution based on tags rather than branches or merge requests.

Why this answer

The 'only' keyword in GitLab CI controls when a job runs based on conditions such as tags, branches, or changes. Using 'only: tags' ensures the deploy job executes only when a tag is pushed, which matches the requirement.

Exam trap

CV0-004 often tests the distinction between 'only' and 'except' (inverse conditions) and between 'only' and 'rules' (legacy vs modern syntax) — candidates who pick 'except' or 'needs' misunderstand the direction of the condition.

How to eliminate wrong answers

Option A is wrong because 'stage' defines the pipeline stage a job belongs to (e.g., build, test, deploy) and does not control execution based on tags. Option B is wrong because 'except' is the inverse of 'only' — it excludes jobs from running under specified conditions, which is the opposite of what is needed. Option D is wrong because 'needs' defines job dependencies for out-of-order execution (DAG), not tag-based execution conditions.

118
MCQeasy

A company is designing a disaster recovery plan for a critical database that requires a recovery point objective (RPO) of 1 minute and a recovery time objective (RTO) of 15 minutes. The database runs on a cloud virtual machine. Which backup strategy should the administrator implement to meet these requirements?

A.Take daily snapshots and store them in the same region.
B.Perform weekly backups to tape and store offsite.
C.Use cross-region snapshot replication with hourly snapshots.
D.Implement continuous replication to a standby instance in a different region.
AnswerD

Continuous replication to a standby instance in another region satisfies the one-minute RPO by shipping every transaction asynchronously, and meets the fifteen-minute RTO because the standby is already running and can be promoted immediately, avoiding restore-from-backup delays.

Why this answer

Continuous replication to a standby instance in a different region provides an RPO of near-zero (often seconds) and an RTO of minutes, as the standby can be promoted quickly. This meets the 1-minute RPO and 15-minute RTO requirements. It also provides cross-region disaster recovery, which is essential for critical databases.

Exam trap

CV0-004 often tests the difference between RPO and RTO, and candidates may choose snapshot-based solutions thinking they are sufficient, but snapshots typically have higher RPO.

How to eliminate wrong answers

Option A is wrong because daily snapshots have an RPO of up to 24 hours, far exceeding the 1-minute requirement, and storing in the same region does not protect against regional failures. Option B is wrong because weekly backups have an RPO of up to 7 days and tape offsite may have long recovery times, not meeting RTO. Option C is wrong because hourly snapshots have an RPO of up to 1 hour, which exceeds the 1-minute requirement, and cross-region replication of snapshots may still take time to restore, potentially exceeding RTO.

119
MCQeasy

A user reports that they cannot connect to a RDS database instance from their application. The security group for the RDS instance allows inbound traffic on port 3306 from the application server's security group. What should the administrator check NEXT?

A.IAM policy attached to the RDS instance
B.Network ACL rules for the RDS subnet
C.Route table entries for the RDS subnet
D.Outbound security group rules on the RDS instance
AnswerB

Security groups are stateful and already permit port 3306, so the next layer to verify is the stateless network ACL on the RDS subnet, which must allow inbound 3306 and outbound ephemeral return traffic. This satisfies the requirement to check the next likely blocker.

Why this answer

The security group for the RDS instance allows inbound traffic on port 3306 from the application server's security group, which is correct. However, network ACLs (NACLs) are stateless and can block traffic even if security groups allow it. The administrator should check the NACL rules for the RDS subnet to ensure that inbound and outbound rules permit traffic on port 3306 and the ephemeral ports for return traffic.

This is the next logical step after verifying security group rules.

Exam trap

CV0-004 often tests the difference between stateful security groups and stateless NACLs; candidates may forget that NACLs require explicit outbound rules for return traffic, leading them to overlook NACL checks.

How to eliminate wrong answers

Option A is wrong because IAM policies control access to RDS management APIs, not network connectivity to the database. Option C is wrong because route table entries affect routing between subnets; if the application server and RDS are in the same VPC, the default route exists, and if they are in different VPCs, peering or other connectivity would be needed, but the scenario implies they are in the same VPC or already connected. Option D is wrong because outbound security group rules on the RDS instance are not relevant for inbound connections; security groups are stateful, so return traffic is automatically allowed if inbound is allowed.

120
MCQeasy

A company wants to migrate its on-premises virtualized workloads to the cloud while maintaining control over the operating system and middleware. Which cloud service model should they choose?

A.SaaS
B.FaaS
C.PaaS
D.IaaS
AnswerD

IaaS delivers virtualised compute, storage and networking while leaving the guest OS, patching and middleware entirely under the customer's control. That directly satisfies the stem's requirement to retain control over the operating system and middleware, unlike PaaS or SaaS, which abstract those layers away.

Why this answer

IaaS (Infrastructure as a Service) provides virtualized compute, storage, and networking where the customer retains control over the operating system, middleware, and runtime, while the provider manages the underlying physical infrastructure. This matches the requirement to migrate virtualized workloads while keeping OS and middleware control.

Exam trap

CV0-004 often tests the boundary between IaaS and PaaS — candidates pick PaaS thinking 'managed' means less work, but PaaS removes the OS/middleware control the question explicitly requires.

How to eliminate wrong answers

Option A (SaaS) is wrong because SaaS delivers fully managed applications where the customer controls neither the OS nor middleware — the provider owns the entire stack. Option B (FaaS) is wrong because Function-as-a-Service abstracts away the OS entirely, running event-driven code snippets with no server or OS management by the customer. Option C (PaaS) is wrong because PaaS manages the OS and runtime for the customer, leaving only application code and data under customer control — the opposite of maintaining OS/middleware control.

121
Multi-Selecthard

A cloud administrator is troubleshooting a network connectivity issue between two VPCs connected via a VPC peering connection. The administrator has verified that the route tables are correct and that the security groups allow traffic. However, instances in VPC A cannot ping instances in VPC B. Which TWO of the following could be causing the issue? (Choose TWO.)

Select 2 answers
A.Network ACLs in VPC B are blocking inbound ICMP
B.Security groups in VPC A are blocking inbound ICMP
C.Host-based firewall on the target instance is blocking ping
D.VPC peering connection does not support ICMP
E.Route tables are misconfigured
AnswersA, C

Network ACLs are stateless subnet-level filters separate from security groups. Even with security groups allowing traffic, an inbound rule in VPC B's NACL denying ICMP would silently drop echo requests, explaining why instances in VPC A cannot ping VPC B.

Why this answer

Option A is correct because network ACLs are stateless subnet-level filters that must explicitly allow inbound ICMP (for IPv4, protocol 1, type 8 echo request) and outbound ICMP echo reply (type 0); even though the administrator verified security groups, a restrictive NACL in VPC B would silently drop ping traffic. Option C is correct because a host-based firewall (e.g., iptables, Windows Firewall, or firewalld) running on the target instance operates above the VPC layer and can block ICMP echo requests regardless of correct route tables and security group rules. Option B is not correct because the scenario states security groups already allow traffic, and security groups are stateful, so inbound ICMP would be permitted if configured.

Option D is not correct because VPC peering fully supports ICMP traffic between peered VPCs; it is not a protocol limitation. Option E is not correct because the administrator has already verified that the route tables are correct.

Exam trap

CV0-004 often tests the layered nature of cloud networking — candidates fixate on route tables and security groups and forget that network ACLs and host-based firewalls are separate, independent layers that can block traffic.

122
MCQmedium

A cloud architect is designing a multi-tier web application that must handle sudden traffic spikes. The application layer is stateless, and the database layer is read-heavy with occasional writes. Which design best meets the requirement for elasticity and cost efficiency?

A.Use auto-scaling for the application tier and read replicas for the database
B.Implement auto-scaling for the database tier and use a larger application instance
C.Use a load balancer to distribute traffic to multiple database instances
D.Deploy large application and database instances to handle peak load
AnswerA

Auto-scaling matches capacity to demand for the stateless application tier, satisfying elasticity without over-provisioning. Read replicas offload read-heavy traffic from the primary database, improving throughput while writes remain on the primary. Together they deliver horizontal scaling and cost efficiency, since resources track actual load rather than peak estimates.

Why this answer

Auto-scaling the stateless application tier dynamically adds or removes instances based on CPU or request metrics, directly handling traffic spikes without over-provisioning. For the read-heavy database tier, read replicas offload SELECT queries from the primary database, improving read throughput and cost efficiency by scaling horizontally only when needed, while the primary handles occasional writes.

Exam trap

CompTIA often tests the misconception that auto-scaling applies equally to all tiers, but the trap here is that databases are stateful and require careful replication strategies (like read replicas) rather than simple instance scaling, and candidates may confuse load balancers with database replication mechanisms.

How to eliminate wrong answers

Option B is wrong because auto-scaling a database tier is complex and rarely used; databases are stateful and scaling them horizontally requires sharding or replication, not simple instance count changes, and using a larger application instance alone fails to handle spikes cost-effectively as it leads to over-provisioning. Option C is wrong because a load balancer distributing traffic to multiple database instances assumes all instances can handle writes, which breaks consistency unless a distributed database with consensus (e.g., Raft) is used; for a traditional RDBMS, this would cause split-brain or stale reads. Option D is wrong because deploying large instances to handle peak load is the opposite of elasticity—it wastes resources during low traffic and does not scale down, increasing costs without dynamic adjustment.

123
MCQmedium

A cloud engineer is deploying a containerized application on Amazon ECS using the Fargate launch type. The application requires persistent storage for a database container. The engineer needs to ensure that the data persists even if the task is stopped and restarted. Which storage option should the engineer use?

A.Amazon S3 bucket mounted as a file system using s3fs
B.Docker volume on the host instance
C.Amazon EBS volume attached to the Fargate task
D.Amazon EFS file system mounted as a volume in the task definition
AnswerD

Amazon EFS provides a shared, elastic file system that can be mounted by multiple Fargate tasks simultaneously. It supports persistent storage that survives task restarts and can be used for database containers that require a file system. EFS is the recommended solution for persistent storage with Fargate because it integrates natively and supports the required durability and scalability.

Why this answer

Amazon EFS is the only storage option that provides persistent, shared file storage that can be mounted by Fargate tasks. It survives task restarts and can be used for database containers that require a file system. EBS volumes cannot be attached to Fargate tasks, Docker volumes on the host are not accessible, and S3 is not suitable for database storage due to performance and consistency limitations.

Exam trap

The trap here is assuming that any AWS storage service can be used with Fargate, when in fact Fargate has specific supported storage integrations, and EFS is the primary persistent file storage option.

124
MCQmedium

A cloud operations team deploys a containerized workload to a Kubernetes cluster managed by Amazon EKS. The application pods intermittently fail during peak traffic hours, and the team suspects that the pods are being terminated because they exceed their configured resource limits. Which action should the team take FIRST to confirm this suspicion?

A.Increase the CPU and memory limits for the deployment immediately and observe whether failures stop.
B.Enable AWS CloudTrail data events on the EKS cluster and search for DeletePod API calls.
C.Configure a Horizontal Pod Autoscaler with a target CPU utilization of 50 percent and wait for the next peak.
D.Review the pod events and container status using kubectl describe pod and check for OOMKilled or Evicted reasons.
AnswerD

Using kubectl describe pod surfaces Kubernetes events and the last termination reason for each container, including OOMKilled when a container exceeds its memory limit or Evicted when the node reclaims resources. This is the most direct, low-cost diagnostic step before changing any configuration, and it aligns with the operations task of identifying why pods are being terminated under load.

Why this answer

The fastest way to confirm whether pods are hitting resource limits is to inspect Kubernetes events and container termination reasons. The kubectl describe pod output reports OOMKilled, Evicted, and related statuses that directly indicate whether limits or node pressure caused the failures. This evidence-based step avoids premature scaling or limit changes and keeps the investigation focused on the actual cause.

Exam trap

The trap here is assuming that AWS-level logging such as CloudTrail captures in-cluster pod terminations, when those events are handled by the Kubernetes control plane and kubelet.

125
MCQmedium

A cloud administrator is deploying a new Amazon EC2 instance that must run a custom application. The application requires a specific IAM role to access an S3 bucket. The administrator wants to avoid embedding AWS credentials in the instance. What should the administrator do?

A.Configure the application to use the AWS SDK's default credential provider chain with environment variables set on the instance.
B.Generate an access key and secret key for an IAM user, then store them in a configuration file on the instance.
C.Use AWS Systems Manager Parameter Store to store the credentials and retrieve them at runtime.
D.Create an IAM role with the necessary S3 permissions and attach it to the EC2 instance using an instance profile.
AnswerD

AWS recommends using IAM roles for EC2 instances to grant permissions without embedding long-term credentials. An instance profile is a container for an IAM role that can be attached to an EC2 instance at launch or later. The instance then retrieves temporary credentials from the instance metadata service, which are automatically rotated. This method is secure and aligns with best practices.

Why this answer

The most secure and recommended way to grant an EC2 instance access to AWS services like S3 is to create an IAM role with the required permissions and attach it to the instance via an instance profile. The instance can then obtain temporary credentials from the instance metadata service, eliminating the need for hardcoded credentials and enabling automatic rotation.

Exam trap

The trap here is believing that storing credentials in Parameter Store or environment variables is equally secure, when they still require an IAM role or introduce static credentials.

126
Multi-Selectmedium

A company is designing a hybrid cloud architecture connecting their on-premises data center to AWS. Which TWO options provide dedicated, private network connectivity? (Select TWO.)

Select 2 answers
A.Internet gateway
B.VPC peering
C.NAT gateway
D.Site-to-Site VPN
E.AWS Direct Connect
AnswersD, E

VPN creates a private encrypted tunnel over the internet.

Why this answer

AWS Direct Connect provides dedicated private connection, and VPN over the internet can also be private if encrypted, but it's not dedicated. Site-to-Site VPN is a valid private connectivity option. Internet gateway is public, VPC peering is between VPCs, not on-premises.

127
MCQmedium

A security engineer is reviewing IAM policies and notices a policy that allows all actions on all resources for a user. Which principle of security is being violated?

A.Least privilege
B.Separation of duties
C.Need to know
D.Defense in depth
AnswerA

Least privilege requires granting only the permissions needed for a user's tasks. A policy allowing all actions on all resources grants unrestricted access, directly violating that principle by exceeding any legitimate job function's required scope.

Why this answer

The principle of least privilege states that users should be granted only the minimum permissions necessary to perform their job functions. A policy allowing all actions on all resources grants far more access than needed, directly violating this principle. This is a classic example of an overly permissive IAM policy.

Exam trap

The trap is confusing least privilege with need to know — both limit access, but least privilege is about the minimum permissions to do the job, while need to know is about limiting information access. The wildcard policy is a textbook least-privilege violation.

How to eliminate wrong answers

Option B is wrong because separation of duties requires dividing critical tasks among multiple people to prevent fraud or error — it is not about the scope of a single user's permissions. Option C is wrong because need to know is about limiting access to information on a need-to-know basis, which is related but distinct from the broader permission scope addressed by least privilege. Option D is wrong because defense in depth is about layering multiple security controls (e.g., firewalls, IDS, encryption) so that no single failure compromises the system — it does not describe the over-permissioning of a single identity.

128
Multi-Selecteasy

A cloud architect is designing identity and access management (IAM) for a multi-cloud environment. The architect wants to enforce least privilege and support federation with an on-premises Active Directory. Which TWO of the following should be implemented? (Select TWO).

Select 2 answers
A.Storing shared credentials in application code
B.Assigning full administrator roles to all users
C.Disabling multi-factor authentication (MFA)
D.Using service accounts for application authentication
E.Federation using SAML
AnswersD, E

Service accounts provide dedicated identities with minimal permissions for apps.

Why this answer

Federation with SAML allows SSO from on-prem AD, and service accounts provide non-human identities for applications, both supporting least privilege by granting only necessary permissions.

129
MCQeasy

A healthcare company runs a web application on Google Cloud. A security analyst notices that attackers are submitting crafted SQL statements through the application's search form and reading data from the backend database. The company wants to block these requests before they reach the application servers while keeping false positives low for legitimate search traffic. Which service should be implemented?

A.Cloud Armor security policy with a preconfigured WAF rule for SQL injection attached to the backend service.
B.Cloud IDS endpoint deployed in the application subnet to detect intrusion attempts.
C.VPC Service Controls perimeter around the database project to restrict data exfiltration.
D.Private Service Connect endpoint that exposes the database only to the application's VPC.
AnswerA

Cloud Armor inspects incoming requests at the edge and can apply preconfigured WAF rules, including the SQL injection signature set, before traffic reaches the backend. Rules can run in preview mode first so the team tunes sensitivity and reduces false positives on legitimate search strings. This directly blocks the crafted statements at the perimeter.

Why this answer

The attack arrives as HTTP requests carrying SQL syntax, so the control must inspect request content at the edge. Cloud Armor with a preconfigured WAF rule for SQL injection evaluates requests against the backend service and can block matching traffic, with preview mode available to tune sensitivity. VPC Service Controls, Cloud IDS, and Private Service Connect operate at network or detection layers and cannot stop the payload.

Exam trap

The trap here is assuming that any Google Cloud network security service inspects application payloads, when only Cloud Armor evaluates HTTP request content for SQL injection signatures.

130
Multi-Selecteasy

Which TWO of the following are characteristics of a hybrid cloud deployment? (Select exactly two.)

Select 2 answers
A.Combines on-premises private cloud with public cloud resources
B.Allows data and application portability between environments
C.Simplifies data governance across environments
D.Typically uses a single public cloud provider
E.Uses only community cloud services
AnswersA, B

Hybrid cloud is defined by integrating an on-premises private cloud with public cloud services, joined by secure connectivity so workloads span both. That combination of private and public infrastructure is precisely the characteristic the question asks for.

Why this answer

Option A is correct because a hybrid cloud by definition combines an on-premises private cloud with public cloud resources, integrating the two environments so workloads can span both. Option B is correct because hybrid cloud architectures are designed to allow data and application portability between the private and public environments, enabling workloads to move as needs change. Option C is not correct because hybrid cloud actually complicates data governance, since data resides in multiple environments with differing policies, compliance requirements, and controls.

Option D is not correct because hybrid cloud involves both private and public environments, not a single public cloud provider. Option E is not correct because community cloud services are shared by organizations with common concerns and are a separate deployment model, not a defining characteristic of hybrid cloud.

Exam trap

The trap here is that candidates often confuse 'hybrid cloud' with 'multi-cloud' or assume it simplifies governance, but CompTIA tests the specific definition of hybrid cloud as a combination of private and public cloud environments with portability, not a single-provider or community-only model.

131
Multi-Selectmedium

A cloud administrator is troubleshooting a performance issue in a virtualized environment. Which TWO metrics should the administrator monitor to identify CPU contention? (Choose two.)

Select 2 answers
A.CPU usage percentage
B.CPU ready time
C.CPU co-stop time
D.CPU frequency
E.CPU load average
AnswersB, C

CPU ready time measures the milliseconds a virtual machine waits for a physical core, directly exposing contention. This satisfies the troubleshooting requirement by quantifying scheduling delay, unlike utilisation percentages that show demand but not competition.

Why this answer

CPU ready time (B) is the correct metric because it measures the amount of time a virtual machine was ready to run but could not be scheduled on a physical CPU, which directly indicates CPU contention or overcommitment on the host. CPU co-stop time (C) is also correct because it reflects the time a vCPU was ready but had to wait for other vCPUs in the same virtual machine to be co-scheduled, a symptom of CPU contention in multi-vCPU VMs. CPU usage percentage (A) only shows how busy a CPU is and can be high without contention, so it does not specifically identify contention.

CPU frequency (D) is a hardware characteristic and does not indicate scheduling delays or contention. CPU load average (E) is a host-level metric that may suggest demand but does not isolate per-VM scheduling latency like ready and co-stop times do.

Exam trap

The trap here is that candidates often confuse CPU usage percentage with CPU contention, but usage measures consumption while ready time and co-stop time directly measure waiting caused by resource competition.

132
MCQmedium

A company wants to deploy a Kubernetes application across multiple AWS accounts using a single set of manifests. The team needs to manage the deployment centrally while allowing each account to have its own configuration values (e.g., environment-specific variables). Which approach should the team use?

A.Use Terraform workspaces with Kubernetes provider
B.Use Helm charts with per-environment values files
C.Use CloudFormation StackSets with Kubernetes resources
D.Create separate manifests for each account
AnswerB

Helm charts separate templated manifests from environment-specific values, so one chart deploys across accounts while each account supplies its own values file. This satisfies the requirement for a single set of manifests with per-account configuration, since overrides are injected at render time rather than duplicated per account.

Why this answer

Helm charts with per-environment values files allow a single set of Kubernetes manifests (templated) to be deployed across multiple AWS accounts, with each account providing its own configuration values (e.g., environment-specific variables) via separate values files. This enables centralized management of the deployment logic while allowing per-account customization.

Exam trap

CV0-004 often tests the difference between infrastructure-as-code tools; candidates may choose Terraform workspaces because they think it can template Kubernetes manifests, but Helm is specifically designed for parameterized Kubernetes deployments.

How to eliminate wrong answers

Option A is wrong because Terraform workspaces are used to manage multiple instances of the same configuration with different state files, but they are not designed for templating Kubernetes manifests; the Kubernetes provider in Terraform is for managing Kubernetes resources, not for packaging and parameterizing manifests. Option C is wrong because CloudFormation StackSets are for deploying AWS resources across accounts, but they do not natively manage Kubernetes resources; you would need custom resources or nested stacks, which is not the intended use. Option D is wrong because creating separate manifests for each account leads to duplication and drift, defeating the goal of a single set of manifests.

133
MCQhard

A company runs a critical e-commerce application on a cloud platform. The architecture includes a load balancer in front of an auto scaling group of compute instances across two availability zones. The instances are in a private subnet and use a NAT gateway for outbound internet access. The application stores session data in a managed Redis cache cluster. During a flash sale, users report that the site is extremely slow and some requests time out. Monitoring shows the load balancer's latency metric is high, and the number of healthy hosts fluctuates. The CPU utilization on the compute instances averages 60% and memory averages 70%. The Redis cluster's CPU utilization is 90%, and its memory usage is 95%. The NAT gateway's metrics show high BytesOutToSource but no errors. Which of the following is the most likely cause of the performance issue?

A.The NAT gateway is throttling traffic due to bandwidth limits
B.The managed Redis cache cluster is overloaded and becoming a bottleneck for session lookups
C.The auto scaling group is not scaling quickly enough due to cooldown periods
D.The load balancer's idle timeout setting is too low, causing premature connection drops
AnswerB

Redis CPU at 90% and memory at 95% indicate the cache cluster is saturated, so session lookups slow or fail, cascading into high load balancer latency and fluctuating healthy hosts. This satisfies the observed bottleneck, since compute CPU and memory remain moderate.

Why this answer

The managed Redis cache cluster is the most likely bottleneck because its CPU utilization is at 90% and memory usage at 95%, indicating it is near capacity. Since the application stores session data in Redis, high latency and timeouts during a flash sale are consistent with an overloaded session store that cannot keep up with request volume, causing the load balancer to experience increased latency and healthy host fluctuations as sessions fail to be retrieved or written.

Exam trap

The trap here is that candidates may focus on the NAT gateway or auto scaling group because they are common bottlenecks, but the key clue is the Redis cluster's high CPU and memory metrics, which directly correlate with session store performance issues in a stateful application.

How to eliminate wrong answers

Option A is wrong because the NAT Gateway shows high BytesOutToSource but no errors, and NAT Gateway bandwidth limits are typically high (up to 10 Gbps per AZ) and would cause packet drops or errors if throttled, not just high latency. Option C is wrong because the Auto Scaling group's cooldown periods could delay scaling, but the EC2 instances are only at 60% CPU and 70% memory, which are not saturated, so scaling is not the primary issue. Option D is wrong because the ALB's idle timeout setting (default 60 seconds) controls how long the ALB keeps a connection open without data; premature connection drops would manifest as immediate disconnects, not high latency and timeouts.

134
MCQhard

A cloud architect is designing a disaster recovery plan for a critical application with an RTO of 15 minutes and an RPO of 1 minute. The application runs on AWS EC2 instances with data stored on EBS volumes. Which replication strategy best meets these requirements?

A.EBS snapshots replicated to another region every hour
B.Continuous replication using AWS Elastic Disaster Recovery
C.Daily AMI backups stored in a different region
D.Cross-region replication of S3 buckets
AnswerB

AWS Elastic Disaster Recovery replicates block-level changes continuously from source EC2 instances and EBS volumes to a staging area, giving sub-second RPO and rapid recovery. This satisfies the 1-minute RPO and 15-minute RTO, unlike snapshot-based or scheduled replication, which cannot meet such tight recovery targets.

Why this answer

An RPO of 1 minute requires near-continuous data replication, which AWS Elastic Disaster Recovery (DRS) provides by continuously replicating block-level changes from source EC2/EBS to a staging area in the target region. Snapshots every hour (RPO up to 60 min) and daily AMIs (RPO up to 24 h) cannot meet a 1-minute RPO. S3 CRR is irrelevant because the data lives on EBS, not S3.

Exam trap

The trap is matching backup frequency to RPO loosely — candidates pick 'hourly snapshots' thinking it's frequent enough, but a 1-minute RPO demands continuous block-level replication, not scheduled snapshots.

How to eliminate wrong answers

Option A is wrong because hourly EBS snapshots yield an RPO of up to 60 minutes, far exceeding the 1-minute requirement. Option C is wrong because daily AMI backups give an RPO of up to 24 hours and are also slower to restore, failing both RPO and likely RTO. Option D is wrong because S3 Cross-Region Replication only replicates S3 objects; the application data is on EBS volumes, so it does not protect the workload at all.

135
MCQhard

A cloud security team is reviewing audit logs and notices that a service account has been used to launch several high-risk API calls that are not part of its normal behavior. Which security control should be implemented to detect such anomalies in real time?

A.Enable API audit logging
B.Implement an anomaly detection service
C.Use a static IAM policy
D.Configure a network ACL
AnswerB

Anomaly detection establishes behavioural baselines for service accounts and flags deviations, such as unusual high-risk API calls, in real time. This satisfies the requirement to detect abnormal activity as it occurs rather than relying on static rules or periodic review.

Why this answer

Anomaly detection services (such as Amazon GuardDuty, Azure Defender, or Google Cloud Security Command Center) use machine learning and behavioral baselines to identify unusual API activity from service accounts in near real time. Since the question specifies detecting deviations from normal behavior, a behavioral analytics control is required rather than passive logging or static policy enforcement.

Exam trap

CV0-004 often tests the distinction between detective controls that merely log (audit logging) and those that actively analyze behavior (anomaly detection) — candidates pick logging because it sounds like 'detection.'

How to eliminate wrong answers

Option A is wrong because API audit logging (e.g., CloudTrail, Activity Log) only records events for later review — it does not analyze or alert on anomalous patterns in real time. Option C is wrong because a static IAM policy defines permitted actions but cannot detect misuse of legitimately granted permissions or behavioral drift. Option D is wrong because a network ACL is a stateless subnet-level packet filter that operates at Layers 3/4 and has no visibility into API semantics or user behavior.

136
MCQmedium

An organization uses CloudFormation to manage infrastructure across multiple AWS accounts. The team wants to deploy a common set of resources, such as VPCs and security groups, to all accounts in a consistent manner. Which CloudFormation feature should they use?

A.Change sets
B.Drift detection
C.StackSets
D.Nested stacks
AnswerC

StackSets extend a single CloudFormation template across multiple AWS accounts and regions from one administrator account, provisioning identical VPCs and security groups consistently. This directly meets the stem's requirement to deploy a common resource set to all accounts without duplicating stacks manually.

Why this answer

StackSets allow deploying stacks across multiple accounts and regions. Change sets preview changes, drift detection checks for manual changes, and nested stacks organize templates within a single account.

137
MCQmedium

A cloud engineer is deploying a three-tier web application using AWS CloudFormation. The application requires a relational database that must be encrypted at rest and support automated backups. The engineer wants to minimize management overhead. Which AWS CloudFormation resource should be used for the database tier?

A.AWS::RDS::DBInstance with the Engine property set to mysql and StorageEncrypted set to true
B.AWS::ElastiCache::CacheCluster with the Engine property set to redis and automatic backups enabled
C.AWS::EC2::Instance with a MySQL AMI and an EBS volume encrypted using AWS::EC2::Volume
D.AWS::DynamoDB::Table with the SSESpecification property and point-in-time recovery enabled
AnswerA

AWS::RDS::DBInstance is the correct resource for deploying a managed relational database. Setting StorageEncrypted to true ensures encryption at rest, and RDS automatically handles backups and patching, minimizing management overhead. This matches the requirements exactly and is the standard way to provision RDS via CloudFormation.

Why this answer

The AWS::RDS::DBInstance resource is designed for managed relational databases, offering encryption at rest via StorageEncrypted and automated backups. It reduces operational burden by handling patching, backups, and replication. The other options either require manual management, use a non-relational engine, or provide caching rather than a primary database.

Exam trap

The trap here is assuming that any encrypted storage or backup-capable service can serve as the database tier, overlooking the need for a managed relational database.

138
MCQhard

A DevOps team is deploying a new version of a microservice to a Kubernetes cluster on AWS. They want to minimize the risk of introducing errors by gradually shifting traffic to the new version while monitoring key metrics. They also need the ability to automatically roll back if the new version does not perform well. Which deployment strategy should they use?

A.Canary deployment
B.Recreate deployment
C.Rolling update
D.Blue/green deployment
AnswerA

Canary deployment involves releasing the new version to a small subset of users or traffic, then gradually increasing the traffic while monitoring metrics. If issues are detected, the deployment can be automatically rolled back. This strategy minimizes risk by limiting exposure and allows for data-driven decisions based on real-time performance. It aligns perfectly with the requirements for gradual traffic shifting and automated rollback.

Why this answer

Canary deployment is designed to reduce risk by gradually shifting a small percentage of traffic to the new version, monitoring its performance, and then progressively increasing traffic if metrics are satisfactory. It supports automated rollback if anomalies are detected. Recreate causes downtime, rolling update lacks fine-grained traffic control and automated rollback based on metrics, and blue/green switches all traffic at once, which is riskier.

Exam trap

The trap here is confusing rolling updates with canary deployments, as both are gradual, but only canary provides controlled traffic shifting and automated rollback based on custom metrics.

139
MCQhard

A cloud engineer is designing a storage solution for a high-performance database that requires consistent low-latency access to block-level storage. The database runs on a single virtual machine and must support frequent random read/write operations. Which storage type should the engineer choose?

A.A block storage volume attached to the virtual machine, provisioned with high IOPS.
B.A managed file share using the SMB protocol.
C.A content delivery network (CDN) edge cache.
D.Object storage with a hierarchical namespace and eventual consistency.
AnswerA

Block storage presents raw volumes that can be formatted with a file system and used by the database. It supports low-latency random read/write operations and allows the engineer to provision IOPS based on performance needs. Attaching the volume directly to the virtual machine ensures dedicated access and consistent performance, which is exactly what a high-performance database requires.

Why this answer

A high-performance database requires block-level storage with consistent low latency and the ability to handle frequent random read/write operations. Block storage volumes attached to the virtual machine provide dedicated, high-IOPS storage that can be formatted and used directly by the database. Object storage, file shares, and CDNs do not offer the necessary block-level access or performance characteristics.

Exam trap

The trap here is confusing shared file storage with block storage, when databases typically require dedicated block-level volumes for performance.

140
MCQhard

During a security audit, a cloud engineer discovers that a container image used in production has a known critical vulnerability in a base layer. Which practice should be implemented to prevent this in the future?

A.Enable Kubernetes pod security policies
B.Use only official images from Docker Hub
C.Perform container image scanning during CI/CD
D.Implement network segmentation
AnswerC

Scanning images in CI/CD catches vulnerable base layers before deployment, so the pipeline fails the build rather than letting the flaw reach production. This directly satisfies the stem's requirement to prevent known critical vulnerabilities recurring in future container images.

Why this answer

Container image scanning during CI/CD integrates security checks into the build pipeline, automatically detecting vulnerabilities in base layers and dependencies before deployment. This shift-left approach prevents vulnerable images from reaching production by failing the build or alerting teams. It is the most effective practice to prevent known vulnerabilities in base layers from being deployed.

Exam trap

CV0-004 often tests the confusion between runtime security controls (like pod security policies) and build-time security practices (like image scanning), leading candidates to choose runtime measures for preventing vulnerable images.

How to eliminate wrong answers

Option A is wrong because Kubernetes pod security policies (now deprecated in favor of Pod Security Admission) control runtime privileges and access, not image vulnerabilities. Option B is wrong because using only official Docker Hub images does not guarantee they are vulnerability-free; official images can still contain vulnerable base layers or outdated packages. Option D is wrong because network segmentation limits lateral movement but does not prevent the deployment of vulnerable images; it addresses runtime network isolation, not image security.

141
MCQmedium

A company is migrating its on-premises applications to a public cloud. The security team wants to ensure that the cloud provider is responsible for physical security of data centers, while the company remains responsible for securing guest operating systems. Which concept does this describe?

A.Least privilege principle
B.Zero Trust architecture
C.Shared responsibility model
D.Defense in depth
AnswerC

The shared responsibility model splits security duties by layer: the provider secures the physical data centres, hardware and hypervisor, while the customer secures everything above, including guest operating systems, patches and identity. This directly satisfies the stem's requirement that the company retains guest OS responsibility while the provider handles physical security.

Why this answer

The shared responsibility model defines the division of security responsibilities between the cloud provider and the customer. The provider is responsible for security 'of' the cloud (e.g., physical data centers), while the customer is responsible for security 'in' the cloud (e.g., guest OS, applications). This matches the scenario where the provider handles physical security and the company secures guest operating systems.

Exam trap

CV0-004 often tests the confusion between the shared responsibility model and other security concepts like least privilege or defense in depth, expecting candidates to identify the model that explicitly divides responsibilities.

How to eliminate wrong answers

Option A is wrong because least privilege is about granting minimal permissions, not about dividing responsibilities between provider and customer. Option B is wrong because Zero Trust is a security model that assumes no implicit trust, focusing on continuous verification, not on responsibility division. Option D is wrong because defense in depth involves multiple layers of security controls, not the specific split of responsibilities between cloud provider and customer.

142
MCQmedium

An e-commerce application experiences variable traffic with sudden spikes during flash sales. The application is designed to be stateless. Which scaling approach should the cloud architect implement to handle these spikes efficiently?

A.Vertical scaling on a single large instance
B.Horizontal auto-scaling based on CPU utilization
C.Using a load balancer with active-passive failover
D.Pre-provisioning a fixed cluster of instances
AnswerB

Horizontal auto-scaling adds or removes stateless instances in response to CPU thresholds, matching capacity to flash-sale demand without manual intervention. Because the application holds no session state, new instances can serve traffic immediately, satisfying the sudden-spike constraint efficiently. Vertical scaling would require restarts and hit fixed instance-size ceilings.

Why this answer

Horizontal auto-scaling based on CPU utilization allows the application to dynamically add or remove instances in response to traffic spikes. Since the application is stateless, new instances can be added seamlessly behind a load balancer, providing efficient scaling during flash sales.

Exam trap

The trap is assuming that vertical scaling or fixed clusters can handle sudden spikes; candidates must recognize that only horizontal auto-scaling provides elastic capacity for variable traffic.

How to eliminate wrong answers

Option A is wrong because vertical scaling on a single large instance has limits and cannot handle sudden spikes efficiently; it also requires downtime for resizing. Option C is wrong because a load balancer with active-passive failover is for high availability, not for scaling; it does not add capacity during spikes. Option D is wrong because pre-provisioning a fixed cluster cannot handle variable traffic efficiently; it may be over-provisioned during low traffic and under-provisioned during spikes.

143
MCQeasy

Which cloud service model provides the customer with the most control over the operating system and applications?

A.IaaS
B.FaaS
C.PaaS
D.SaaS
AnswerA

IaaS delivers only virtualised compute, storage and networking, leaving the guest operating system, middleware and applications entirely under customer management. PaaS and SaaS abstract the OS away, so IaaS uniquely satisfies the requirement for maximum control over both operating system and applications.

Why this answer

IaaS provides virtualized computing resources where customers manage OS and above.

144
MCQhard

A cloud administrator is standardizing infrastructure provisioning across teams and wants to enforce that all deployed resources carry a mandatory cost-center tag. The administrator needs non-compliant deployments to be rejected automatically across multiple accounts in an AWS Organization. Which control should be implemented?

A.An Amazon EventBridge rule that triggers a Lambda function to delete untagged resources
B.An AWS Config rule using the required-tags managed rule
C.A service control policy applied at the organization root that denies resource creation without the cost-center tag
D.An IAM permissions boundary attached to each developer role
AnswerC

Service control policies set the maximum permissions for accounts in an AWS Organization and can include conditions such as aws:RequestTag to deny create operations lacking the required tag. Applied at the root, the policy covers all accounts and blocks non-compliant deployments at the API layer. This provides preventive, organization-wide enforcement matching the requirement.

Why this answer

Service control policies define the permission ceiling for accounts in an AWS Organization and support condition keys such as aws:RequestTag, so a deny statement can block create operations that omit the cost-center tag. Applying it at the root enforces the rule across every account preventively. Config rules, permissions boundaries, and EventBridge remediation act after the fact or per principal and do not block the deployment.

Exam trap

The trap here is treating tag detection tools like AWS Config as preventive controls, when only service control policies can deny the create request outright.

145
MCQeasy

A cloud engineer needs to apply security patches to a group of Linux VMs running in Azure. The engineer wants to automate the patching process and ensure that patches are applied during a predefined maintenance window. Which Azure service should be used?

A.Azure Security Center
B.Azure Policy
C.Azure Backup
D.Azure Update Management
AnswerD

Azure Update Manager orchestrates OS patching for Azure and Arc-connected Linux VMs, scheduling assessments and deployments inside a defined maintenance window. It satisfies the automation and windowing constraints directly, unlike manual SSH patching or image rebuilds. Note that Update Management in Azure Automation is retired; Update Manager is the current service.

Why this answer

Azure Update Management (now part of Azure Automation) is the purpose-built service for orchestrating OS patch deployment across Windows and Linux VMs, including Azure VMs, on-premises machines, and other clouds via the Log Analytics agent. It lets you define a maintenance window, schedule recurring patch deployments, and produce compliance reports showing which patches are missing or installed. This directly satisfies the requirement to automate patching during a predefined window.

Exam trap

CV0-004 often tests the confusion between governance/assessment services (Azure Policy, Defender for Cloud) and the actual remediation service (Update Management) — candidates pick Policy because it sounds like it 'enforces' patching.

How to eliminate wrong answers

Option A is wrong because Azure Security Center (now Microsoft Defender for Cloud) provides security posture assessment, recommendations, and threat protection — it can flag missing patches but does not schedule or apply them. Option B is wrong because Azure Policy enforces governance and compliance rules (e.g., 'require a tag' or 'audit OS updates') but does not perform patch installation. Option C is wrong because Azure Backup handles data protection and recovery, not OS patch deployment.

146
MCQhard

An organization is migrating a legacy application to the cloud. The application writes logs to a local file system. The cloud architect recommends using a centralized logging service. Which of the following BEST explains why this change is important?

A.To meet regulatory compliance requirements for log retention
B.To reduce storage costs by using object storage for logs
C.Because cloud instances are ephemeral and local logs would be lost if instances terminate
D.To encrypt log data at rest and in transit
AnswerC

Cloud instances are ephemeral: a local log file resides only on that instance's disk and disappears when the instance terminates or is replaced. Centralised logging persists entries independently of instance lifecycle, satisfying the durability requirement the legacy local-file approach cannot meet.

Why this answer

Cloud instances are ephemeral, meaning they can be terminated, replaced, or scaled down at any time, and any logs stored only on the local file system are lost when the instance goes away. Centralized logging ensures logs persist independently of instance lifecycle, which is critical for troubleshooting, auditing, and compliance. This is the most direct and fundamental reason to move logs off local storage in the cloud.

Exam trap

CV0-004 often tests the misconception that compliance or cost is the primary reason for centralized logging, when the fundamental cloud-native reason is instance ephemerality and the need for durable, externalized log storage.

How to eliminate wrong answers

Option A is wrong because while regulatory compliance may require log retention, it is not the primary reason for centralized logging in this scenario; the immediate technical risk is log loss due to ephemerality. Option B is wrong because reducing storage costs by using object storage is a secondary benefit, not the main reason; centralized logging may actually increase costs depending on volume and retention. Option D is wrong because encryption of logs at rest and in transit is a security control that can be applied regardless of whether logs are local or centralized, and it is not the primary driver for centralization.

147
Multi-Selecthard

Which THREE of the following are key considerations when designing a cloud-native application for high availability? (Select exactly three.)

Select 3 answers
A.Use multithreading for all components
B.Use synchronous replication for databases
C.Implement loose coupling between services
D.Use stateless application components
E.Design for horizontal scaling using auto-scaling groups
AnswersC, D, E

Loose coupling lets each service fail or scale independently, so one component's outage does not cascade across the application. This directly supports the high availability goal by containing faults and permitting graceful degradation rather than total service loss.

Why this answer

Option C is correct because loose coupling between services—typically achieved through asynchronous messaging (e.g., queues, event buses) or well-defined APIs—ensures that the failure of one service does not cascade to others, which is fundamental to high availability in cloud-native designs. Option D is correct because stateless application components store no session data locally, allowing any instance to handle any request and enabling failed instances to be replaced seamlessly by load balancers or orchestrators. Option E is correct because designing for horizontal scaling with auto-scaling groups lets the application add or remove instances dynamically in response to demand or instance failure, maintaining availability across Availability Zones.

Option A is not a key HA consideration because multithreading is an implementation-level concurrency technique, not a cloud-native availability pattern, and can even introduce complexity or contention. Option B is not appropriate because synchronous replication can increase latency and couple database nodes tightly, whereas asynchronous or quorum-based replication is generally preferred for resilient, distributed cloud databases.

Exam trap

CompTIA often tests the misconception that high availability requires synchronous replication or multithreading, when in fact these can introduce tight coupling and single points of failure; the trap is confusing performance optimization with architectural resilience.

148
MCQhard

A cloud engineer is designing a solution for a financial application that requires strict data residency in a specific country. The application must also be highly available across multiple data centers within that country. Which design consideration is most critical?

A.Deploying resources in multiple availability zones within the same region.
B.Using a content delivery network (CDN) to cache data globally.
C.Using a global load balancer to distribute traffic across continents.
D.Implementing a multi-region active-active architecture.
AnswerA

Deploying across multiple availability zones within a single region ensures high availability while keeping data within the country's borders, satisfying data residency. Availability zones are isolated data centers within a region, providing fault tolerance without crossing legal boundaries, making this the most critical design consideration.

Why this answer

Deploying across multiple availability zones within the same region keeps data within the country while providing high availability through fault isolation. This satisfies both data residency and availability requirements without introducing cross-border data flows that could violate regulations.

Exam trap

The trap here is equating high availability with multi-region deployments, overlooking that availability zones within a region can provide sufficient redundancy while complying with data residency laws.

149
MCQeasy

Which cloud service model provides the customer with the ability to deploy and manage custom applications without managing the underlying operating system or runtime environment?

A.SaaS
B.PaaS
C.IaaS
D.FaaS
AnswerB

PaaS delivers managed runtimes and middleware, so customers deploy code and manage applications while the provider handles the operating system, patching and runtime. That matches the constraint of no OS or runtime management, unlike IaaS, which leaves those layers to the customer.

Why this answer

PaaS provides a managed platform where customers deploy their code while the provider manages the OS, runtime, and infrastructure.

150
MCQmedium

A developer is deploying a serverless application using AWS Lambda. They want to reuse common code (e.g., database connection logic) across multiple functions without duplicating it. Which Lambda feature should they use?

A.Lambda versions
B.Lambda aliases
C.Lambda layers
D.Lambda environment variables
AnswerC

Lambda layers package shared libraries and dependencies separately from function code, so database connection logic is referenced by multiple functions rather than duplicated in each deployment package. This directly satisfies the requirement to reuse common code across functions while keeping individual deployment artefacts small.

Why this answer

Lambda Layers allow you to package and share code across multiple functions, enabling code reuse and reducing deployment package size.

Page 1

Page 2 of 12

Page 3