Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 151–225

834 questions total · 12pages · All types, answers revealed

Page 2

Page 3 of 12

Page 4
151
MCQmedium

A cloud engineer needs to deploy a containerized application on Amazon EKS. The application requires a persistent storage volume that can be dynamically provisioned. Which Kubernetes resource should be used to request storage?

A.PersistentVolume
B.PersistentVolumeClaim
C.StorageClass
D.ConfigMap
AnswerB

A PersistentVolumeClaim requests storage from a StorageClass, which triggers dynamic provisioning of a PersistentVolume. This satisfies the stem's requirement for dynamically provisioned persistent storage on Amazon EKS, unlike a PersistentVolume, which represents already-provisioned capacity, or a StorageClass, which only defines the provisioning template.

Why this answer

A PersistentVolumeClaim (PVC) is the correct Kubernetes resource to request storage because it acts as a request for storage by a pod, specifying size, access modes, and optionally a StorageClass. In Amazon EKS, a PVC can trigger dynamic provisioning of an EBS or EFS volume via a StorageClass, decoupling the storage request from the underlying PersistentVolume. This allows the cloud engineer to deploy the containerized application without manually pre-provisioning storage.

Exam trap

The exam often tests the distinction between a PersistentVolume (the actual storage resource) and a PersistentVolumeClaim (the request for storage), leading candidates to mistakenly select PV when the question asks for the resource that 'requests' storage.

How to eliminate wrong answers

Option A is wrong because a PersistentVolume (PV) is a cluster resource representing pre-provisioned storage, not a request for storage; it is the backend volume that a PVC binds to. Option C is wrong because a StorageClass defines the storage type and provisioner (e.g., 'ebs.csi.aws.com') but does not itself request storage; it is referenced by a PVC to enable dynamic provisioning. Option D is wrong because a ConfigMap is used to inject configuration data (key-value pairs) into pods, not for persistent storage requests.

152
MCQeasy

Which cloud service model provides the customer with the highest level of control over the operating system and middleware?

A.PaaS
B.FaaS
C.IaaS
D.SaaS
AnswerC

IaaS delivers virtual machines, storage and networking while the customer manages the guest operating system, patching and middleware. That leaves the greatest control over the OS layer, unlike PaaS or SaaS, which abstract it away.

Why this answer

IaaS provides virtualized computing resources where the customer manages the OS, middleware, and applications, offering the highest control among the three main service models.

153
MCQmedium

A developer deployed a new version of a cloud function, but the function is returning 500 errors. The previous version worked fine. What is the most likely cause?

A.The function is using an outdated runtime.
B.The new code contains a runtime error.
C.The function's memory allocation is too low.
D.The function's timeout is set too short.
AnswerB

A 500 error indicates server-side execution failure. Since the previous version worked, the newly deployed code most likely throws an unhandled exception or runtime error during execution, which the platform surfaces as an internal server error.

Why this answer

The most likely cause of 500 errors after deploying a new version of a cloud function is a runtime error in the new code. A 500 Internal Server Error indicates that the function's code executed but threw an unhandled exception or logic error, which did not exist in the previous working version. Since the environment (runtime, memory, timeout) remained unchanged, the introduction of faulty code is the primary suspect.

Exam trap

CompTIA often tests the distinction between code-level errors (500) and resource/configuration errors (memory, timeout, runtime), tempting candidates to blame environment settings when the actual cause is a bug introduced in the new code.

How to eliminate wrong answers

Option A is wrong because an outdated runtime would cause deployment failures or compatibility warnings, not a sudden 500 error after a code change; the runtime version is typically fixed during deployment. Option C is wrong because memory allocation being too low would manifest as out-of-memory (OOM) errors or timeouts, not a generic 500 error, and the previous version worked with the same allocation. Option D is wrong because a timeout set too short would produce a 504 Gateway Timeout or a specific timeout error, not a 500 Internal Server Error, and the previous version succeeded with the same timeout value.

154
MCQeasy

A company has a cloud-based application that uses a relational database. The database team performs daily backups to an on-premises storage system using a VPN connection. Recently, backups have been failing with timeout errors. The network team confirms the VPN is up and stable. Which of the following is the MOST likely cause?

A.The database service is not responding
B.The VPN bandwidth is insufficient for the backup data volume
C.The VPN tunnel is not properly configured
D.The on-premises firewall is blocking the backup port
AnswerB

Insufficient VPN bandwidth saturates the tunnel during large backup transfers, causing TCP retransmissions and eventual timeout errors despite the VPN remaining up and stable. A relational database's daily full or incremental backup volume can exceed the tunnel's throughput, so the constraint of a stable-but-limited VPN link is satisfied by this explanation.

Why this answer

The VPN connection is confirmed stable, so tunnel configuration and firewall issues are unlikely. Backup timeout errors with large data volumes typically indicate insufficient bandwidth, causing the transfer to exceed the timeout threshold. The database service itself is responding (backups are attempted), ruling out service unavailability.

Exam trap

The trap here is that candidates assume a stable VPN means the link has sufficient capacity, but CompTIA often tests the distinction between connectivity (layer 3) and throughput (layer 4/performance), where a stable tunnel can still be too slow for large data transfers.

How to eliminate wrong answers

Option A is wrong because if the database service were not responding, backups would fail immediately with a connection error, not a timeout after data transfer begins. Option C is wrong because the network team confirmed the VPN is up and stable, meaning the tunnel is properly configured and operational. Option D is wrong because a firewall block would cause a consistent failure (e.g., connection refused), not intermittent timeouts, and the VPN tunnel encrypts traffic, making port-specific blocking less likely.

155
MCQmedium

Refer to the exhibit. The auto scaling group is fluctuating between 2 and 3 instances every few minutes. What is the most likely cause?

A.The instances are taking too long to become healthy.
B.The launch configuration has incorrect user data.
C.The load balancer is not properly distributing traffic.
D.The scaling policies are based on metrics that are too sensitive.
AnswerD

Scaling policies react to metric thresholds; if those metrics fluctuate naturally around the target, the group adds and removes instances repeatedly. Overly sensitive thresholds or short cooldowns cause this rapid oscillation between two and three instances, matching the exhibit.

Why this answer

The auto scaling group fluctuating between 2 and 3 instances every few minutes indicates a scaling policy that is too sensitive, likely based on a metric such as CPU utilization or request count per target that oscillates rapidly. When the metric crosses the scale-out threshold, a new instance launches, causing the metric to drop below the scale-in threshold, which then terminates an instance, creating a cycle. This is a classic symptom of thrashing due to overly aggressive or poorly configured scaling policies.

Exam trap

CompTIA often tests the concept of scaling thrashing, and the trap here is that candidates may incorrectly attribute the oscillation to load balancer misconfiguration or instance health delays, rather than recognizing it as a direct symptom of overly sensitive scaling policies with insufficient cooldown or threshold margins.

How to eliminate wrong answers

Option A is wrong because instances taking too long to become healthy would cause the auto scaling group to launch additional instances while waiting, but it would not cause rapid fluctuation between 2 and 3 instances; instead, it would lead to a sustained higher count or failed health checks. Option B is wrong because incorrect user data in the launch configuration would cause instances to fail to initialize properly, leading to unhealthy instances and potential replacement, but not the specific 2-to-3 oscillation pattern. Option C is wrong because the load balancer not properly distributing traffic would cause uneven load but would not directly cause the auto scaling group to scale in and out every few minutes; the scaling policies are based on aggregated metrics, not load balancer distribution issues.

156
MCQmedium

A healthcare organization uses a cloud-based virtual private cloud (VPC) to host a web application that processes protected health information (PHI). The application consists of a public-facing load balancer, a web server tier in a public subnet, and a database tier in a private subnet. The database runs on a managed relational database service with encryption at rest enabled using a cloud provider-managed key. The security auditor requires that the database encryption key must be controlled by the organization and rotated every 90 days. Additionally, the database must only be accessible from the web server tier. The database is currently accessible from the entire VPC CIDR block. What should the cloud administrator do to meet these requirements?

A.Export the database, disable encryption, and import into a new database with a customer-managed key.
B.Enable encryption with a provider-managed key and restrict database access using a network ACL.
C.Re-encrypt the database using a customer-managed key in the cloud provider's key management service, and update the database security group to only allow traffic from the web server security group.
D.Encrypt the web server's storage with a customer-managed key and keep the database encryption as is.
AnswerC

A customer-managed key in the cloud KMS satisfies the auditor's control and 90-day rotation requirement, unlike provider-managed keys. Replacing the CIDR-wide rule with a security group reference restricts database access to the web server tier only.

Why this answer

It addresses both requirements: re-encrypting the database with a customer-managed key in the cloud provider's KMS allows the organization to control and rotate the key every 90 days, and updating the database security group to only allow traffic from the web server security group restricts access to only the web server tier. Option A is incorrect because exporting and re-importing the database is unnecessary and disabling encryption is not recommended; re-encrypting in place is the proper approach. Option B is incorrect because provider-managed keys do not give the organization control or the ability to rotate the key as required.

Option D is incorrect because encrypting the web server's storage does not address database encryption or access control requirements.

157
Multi-Selectmedium

A healthcare organization must protect electronic protected health information stored in a public cloud object storage bucket. Compliance requires encryption at rest with customer-controlled keys and verifiable evidence that data has not been altered. Which TWO controls should be implemented to meet these requirements? (Choose two.)

Select 2 answers
A.Apply a bucket policy that denies delete operations to all principals except a designated break-glass role.
B.Enable object versioning on the bucket to retain prior versions of every object.
C.Enable object lock in compliance mode with a retention period aligned to the records retention policy.
D.Configure server-side encryption using a customer-managed key stored in the cloud provider's key management service.
E.Enable cross-region replication so that a second copy of every object exists in another region.
AnswersC, D

Object lock in compliance mode makes objects immutable for the retention period, and even the root account cannot delete or alter them. This provides verifiable evidence that stored records have not been changed, which satisfies the tamper-evidence requirement. Combined with customer-managed encryption keys, it delivers both confidentiality and integrity assurance for regulated health data.

Why this answer

Encryption at rest with a customer-managed key keeps cryptographic control with the organization, while object lock in compliance mode guarantees immutability that even privileged accounts cannot override. Together they deliver confidentiality and verifiable integrity for regulated health records. Versioning, restrictive bucket policies, and cross-region replication improve durability or reduce risk but cannot prove that data remains unaltered.

Exam trap

The trap here is treating versioning or replication as tamper-evidence, when only compliance-mode object lock prevents modification by any principal including the account root.

158
Multi-Selectmedium

A cloud administrator is troubleshooting a performance degradation issue on a database server hosted in a public cloud. The server is experiencing high disk I/O wait times. The administrator suspects that the storage volume type is not optimized for the workload. Which two actions should the administrator take to address the issue? (Choose two.)

Select 2 answers
A.Increase the size of the existing volume to automatically improve IOPS.
B.Change the storage volume to a higher-performance SSD-based volume type.
C.Increase the instance type to one with more memory.
D.Move the database to a volume with a higher IOPS provisioned.
E.Enable detailed monitoring for the volume to analyze I/O patterns.
AnswersB, D

Upgrading to a higher-performance SSD volume type, such as provisioned IOPS SSD, can significantly reduce disk I/O wait times by providing more IOPS and lower latency. This is a direct solution when the current volume type is the bottleneck. The administrator should evaluate the workload's IOPS requirements and choose an appropriate volume type. This action addresses the root cause of high I/O wait.

Why this answer

High disk I/O wait times indicate that the storage volume cannot keep up with the workload's demand. The most effective solutions are to change to a higher-performance volume type or provision a volume with higher IOPS. Both actions directly increase the storage's ability to handle I/O operations, reducing wait times.

Diagnostic steps like monitoring are useful but do not resolve the issue.

Exam trap

The trap here is assuming that increasing volume size automatically scales IOPS linearly, which is not true for all volume types and may not meet performance needs.

159
MCQhard

A company recently migrated its database to a cloud-managed database service. After the migration, the application team reports that some queries are returning stale data. The database is configured with read replicas. What is the most likely reason for the stale data?

A.The database parameter group is misconfigured.
B.The application is reading from a read replica that has replication lag.
C.The network latency between the application and database is high.
D.The database’s backup and restore process has corrupted the data.
AnswerB

Read replicas replicate asynchronously from the primary database, so a replica can lag behind by seconds or more. When the application queries that replica, it reads data committed before the lag interval elapsed, returning stale results until replication catches up.

Why this answer

The most likely reason for stale data is that the application is reading from a read replica that has not yet applied all changes from the primary database. In cloud-managed database services like Amazon RDS or Azure SQL, read replicas use asynchronous replication, which introduces replication lag. If the application directs read queries to a replica that is behind, it will return data that is not current.

Exam trap

CompTIA Cloud+ often tests the concept of asynchronous replication lag in read replicas, and the trap here is that candidates may confuse stale data with network latency or misconfiguration, overlooking the fundamental behavior of read replicas returning data that is not yet fully synchronized.

How to eliminate wrong answers

Option A is wrong because a misconfigured database parameter group affects settings like memory, timeouts, or character sets, but it does not cause stale data from read replicas. Option C is wrong because high network latency would slow query response times but would not cause the database to return outdated data; the data itself would still be current. Option D is wrong because backup and restore processes are separate from live read replicas and would not cause stale data in ongoing operations; corruption would typically cause errors or missing data, not stale data.

160
MCQhard

A company has deployed a containerized application on a Kubernetes cluster. The security team wants to ensure that containers cannot run as the root user and that the container's root filesystem is read-only. Which Kubernetes security mechanism should be used?

A.Pod Security Standards
B.Network policies
C.Seccomp profiles
D.Resource quotas
AnswerA

Pod Security Standards define the restricted profile, which sets runAsNonRoot and readOnlyRootFilesystem enforcement via the securityContext, satisfying both constraints. Applied through namespace labels or admission control, they block root execution and writable root filesystems at pod admission.

Why this answer

Pod Security Standards (PSS) are the built-in Kubernetes mechanism for enforcing pod-level security policies, including the 'restricted' profile which requires runAsNonRoot and readOnlyRootFilesystem. PSS replaced the deprecated PodSecurityPolicy and is enforced via namespace labels (pod-security.kubernetes.io/enforce). This directly addresses both requirements: preventing root execution and enforcing a read-only root filesystem.

Exam trap

CV0-004 often tests the confusion between Pod Security Standards (which govern pod security context like runAsNonRoot) and Network Policies (which govern traffic), so candidates who focus on 'security' generically may pick the wrong control.

How to eliminate wrong answers

Option B is wrong because Network policies only control ingress/egress traffic between pods and do not govern container user IDs or filesystem mount options. Option C is wrong because Seccomp profiles restrict which system calls a container can make, not the user identity or filesystem writability. Option D is wrong because Resource quotas limit CPU, memory, and object counts within a namespace, having no bearing on security context settings like runAsNonRoot or readOnlyRootFilesystem.

161
MCQeasy

A cloud administrator notices that a virtual machine (VM) is running slowly. The hypervisor shows high CPU ready time for that VM. Which of the following is the most likely cause?

A.High disk I/O latency on the datastore
B.Insufficient memory allocated to the VM
C.Overcommitted physical CPU resources on the host
D.Misconfigured virtual switch
AnswerC

High CPU ready time means the VM waited for physical cores while the scheduler ran other vCPUs. That occurs when the host's physical CPU is overcommitted, so the hypervisor cannot grant cycles promptly, directly explaining the slow VM.

Why this answer

High CPU ready time indicates that the VM is ready to execute instructions but is waiting for the physical CPU to become available. This is a classic symptom of CPU overcommitment, where the host has more virtual CPUs (vCPUs) assigned to VMs than physical cores, causing contention. Option C correctly identifies this as the most likely cause.

Exam trap

CompTIA often tests the distinction between CPU ready time and other performance metrics, trapping candidates who confuse high CPU ready time with memory pressure or storage latency.

How to eliminate wrong answers

Option A is wrong because high disk I/O latency would manifest as high disk queue depth or high kernel latency, not as CPU ready time. Option B is wrong because insufficient memory would cause ballooning or swapping, not CPU ready time. Option D is wrong because a misconfigured virtual switch would cause network connectivity issues or packet loss, not CPU scheduling delays.

162
MCQeasy

An architect is designing a cloud application that must handle unpredictable spikes in traffic. The application should automatically add resources during peak demand and remove them when demand decreases to minimize costs. Which scaling strategy should be used?

A.Scheduled scaling based on historical patterns
B.Vertical scaling of existing instances
C.Manual scaling by operations team
D.Horizontal auto-scaling based on CPU utilization
AnswerD

Horizontal auto-scaling adds or removes instances, and CPU utilisation is the trigger metric that reflects load. This matches unpredictable spikes by scaling out at peak and in during lulls, minimising cost, whereas vertical scaling requires restarts and has fixed ceilings.

Why this answer

Horizontal auto-scaling based on CPU utilization is the correct strategy because it dynamically adds or removes instances in response to real-time demand, ensuring the application can handle unpredictable traffic spikes while minimizing costs. This approach aligns with cloud elasticity principles, where resources scale out (add instances) during high CPU load and scale in (remove instances) when load decreases, without manual intervention.

Exam trap

The trap here is that candidates often confuse vertical scaling (scaling up) with horizontal scaling (scaling out), assuming resizing existing instances is more cost-effective, but vertical scaling has hard limits and cannot match the elasticity required for unpredictable spikes.

How to eliminate wrong answers

Option A is wrong because scheduled scaling relies on predefined historical patterns, which cannot adapt to unpredictable spikes that deviate from those patterns. Option B is wrong because vertical scaling (resizing existing instances) has hardware limits and often requires downtime, making it unsuitable for handling sudden, unpredictable demand changes. Option C is wrong because manual scaling by the operations team introduces latency and human error, failing to provide the automatic, real-time response needed for unpredictable traffic.

163
MCQmedium

A cloud administrator notices that an IAM role in a public cloud environment has permissions to perform all actions on all resources. The principle of least privilege should be applied. What is the best first step to reduce the security risk?

A.Delete the role and create a new one with minimal permissions immediately.
B.Create a new role with fewer permissions and ask users to switch roles.
C.Review the role's attached policies and identify unused or unnecessary permissions.
D.Modify the role's trust policy to restrict which users can assume it.
AnswerC

Reviewing attached policies exposes exactly which actions the role grants, letting the administrator identify unused or unnecessary permissions before editing anything. This directly satisfies the least-privilege constraint by scoping permissions to what the workload actually requires, rather than deleting the role or revoking access blindly, which could break dependent services.

Why this answer

The best first step is to review the role's attached policies and identify unused or unnecessary permissions (Option C). This aligns with the principle of least privilege by allowing the administrator to understand which permissions are actually needed before making changes, minimizing the risk of disrupting legitimate access. Deleting the role immediately (Option A) could cause service disruptions.

Creating a new role and asking users to switch (Option B) is time-consuming and may not address the root issue. Modifying the trust policy (Option D) restricts who can assume the role but does not reduce the permissions granted.

164
MCQeasy

A cloud administrator needs to set up a centralized logging solution to collect logs from multiple projects. Which cloud service should be used?

A.Monitoring service
B.Logging service
C.Serverless function service
D.Audit logs service
AnswerB

A dedicated logging service aggregates log streams from multiple projects into a single centralised repository, removing the need to query each project separately. It provides unified retention, search and access control, which is precisely the centralisation the administrator requires across disparate projects.

Why this answer

A centralized logging service is designed to aggregate, store, and analyze log data from multiple sources, including multiple projects. In cloud environments, this is typically a dedicated logging service (such as Google Cloud Logging, AWS CloudWatch Logs, or Azure Monitor Logs) that can collect logs across projects and provide querying and retention. Option B is the correct choice.

Exam trap

CV0-004 often tests the distinction between logging and monitoring services — candidates who equate 'collect logs' with 'monitoring' pick the monitoring service, but monitoring is about metrics and alerts, not log aggregation.

How to eliminate wrong answers

Option A is wrong because a monitoring service focuses on metrics, dashboards, and alerting rather than centralized log aggregation and storage. Option C is wrong because a serverless function service executes code in response to events; it does not store or aggregate logs. Option D is wrong because audit logs are a specific type of log (recording administrative activity) and are not a general-purpose centralized logging solution for application logs across projects.

165
MCQhard

A cloud administrator is designing an auto-scaling policy for a web application that experiences predictable traffic spikes during business hours. The administrator wants to ensure that the application scales out before the start of business hours to avoid performance degradation. Which scaling policy type should be used?

A.Manual scaling
B.Dynamic scaling
C.Scheduled scaling
D.Predictive scaling
AnswerC

Scheduled scaling triggers scale-out actions at predefined times, so capacity increases before the predictable business-hours spike begins. This satisfies the requirement to scale out ahead of the traffic increase, which dynamic or reactive policies cannot guarantee.

Why this answer

Scheduled scaling allows scaling actions at specific times (e.g., before business hours).

166
MCQhard

A security team runs workloads in Microsoft Azure and must ensure that all data stored in Azure SQL Database and Azure Storage accounts is encrypted with customer-managed keys (CMK) rather than platform-managed keys. The compliance officer requires that the organization be able to revoke access to the data by disabling the key, and that key rotation be controlled internally. Which Azure service should the team configure to meet these requirements?

A.Azure Information Protection labels applied to the database and storage resources to classify the data.
B.Azure Confidential Computing with SGX-enabled virtual machines hosting the SQL and storage workloads.
C.Azure Key Vault, storing the RSA keys and granting the SQL and Storage resources access via managed identities.
D.Azure Disk Encryption with BitLocker and DM-Crypt extensions applied to the underlying VM disks.
AnswerC

Azure Key Vault holds customer-managed RSA keys and integrates with Azure SQL Database and Azure Storage through Transparent Data Encryption and storage service encryption with CMK. Granting the resources access via managed identities lets the team disable or rotate the key to revoke access. This satisfies the requirement for internal key control and revocation capability.

Why this answer

Azure Key Vault is the service that stores customer-managed RSA keys and integrates with Azure SQL Database and Azure Storage to encrypt data at rest with keys the organization controls. By granting the PaaS resources access through managed identities, the team can rotate or disable the key to revoke access. Disk Encryption, Information Protection labels, and Confidential Computing address other layers and cannot satisfy the CMK and revocation requirements.

Exam trap

The trap here is confusing encryption-in-use or disk-level encryption features with the key-management service that actually supplies customer-managed keys for Azure PaaS data services.

167
MCQmedium

During a cloud migration, a database server is moved from on-premises to a cloud-managed database service. After migration, the application team reports that some queries are running slower than before. The database CPU utilization is low. What is the most likely cause?

A.The network latency between the application and the database has increased
B.The database is not indexed properly
C.The database connection pooling is misconfigured
D.The cloud database instance type has insufficient memory
AnswerA

Low CPU indicates the database itself is not the bottleneck, so the added round-trip latency between application and cloud-managed database is the likely cause. Moving off-premises lengthens the network path, slowing query response even when processing is idle.

Why this answer

When a database is moved to a cloud-managed service and queries slow down while CPU utilization is low, the most likely cause is increased network latency between the application and the database. Low CPU indicates the database is not compute-bound, so the delay is likely in the round-trip time for queries. This is common when the application and database are in different regions or availability zones.

Exam trap

CV0-004 often tests the correlation between low CPU and slow queries; candidates may blame indexing or instance size, but low CPU points to a non-compute bottleneck like network latency, which is common in cloud migrations.

How to eliminate wrong answers

Option B is wrong because improper indexing would typically cause high CPU utilization due to full table scans, not low CPU. Option C is wrong because misconfigured connection pooling would cause connection errors or overhead, but not necessarily slower queries with low CPU; it might cause timeouts. Option D is wrong because insufficient memory would lead to swapping or disk I/O, often increasing CPU or causing out-of-memory errors, not low CPU with slow queries.

168
MCQeasy

A cloud architect is designing a system that requires a durable, highly available object storage solution for storing backups and media files. The data must be accessible from anywhere via HTTP/HTTPS. Which AWS service should be used?

A.Amazon EFS
B.Amazon RDS
C.Amazon EBS
D.Amazon S3
AnswerD

Amazon S3 is a durable, highly available object storage service designed for storing and retrieving any amount of data. It provides HTTP/HTTPS access and is ideal for backups and media files. S3 offers 99.999999999% durability and can be accessed globally, meeting the requirements.

Why this answer

Amazon S3 is the correct choice because it is a durable, highly available object storage service that supports HTTP/HTTPS access and is designed for backups and media files. EBS, EFS, and RDS serve different storage needs: block, file, and database respectively, and do not meet the object storage and accessibility requirements.

Exam trap

The trap here is confusing block or file storage with object storage, as EBS and EFS are often used for similar workloads but lack HTTP accessibility.

169
MCQhard

A security administrator is deploying a web application firewall (WAF) to protect a public-facing web application. The application experiences a high volume of traffic from a specific geographic region that is not part of the target customer base. Which WAF feature would best reduce the attack surface without impacting legitimate users?

A.IP whitelisting
B.Rate limiting
C.OWASP rule set
D.Geo-blocking
AnswerD

Geo-blocking filters traffic by source country, dropping requests from the unwanted region at the WAF before they reach the application. Legitimate users elsewhere remain unaffected, reducing the attack surface from that region's hostile traffic without disrupting the target customer base.

Why this answer

Geo-blocking allows the administrator to block traffic from specific regions, reducing the attack surface by eliminating traffic from non-target areas.

170
MCQmedium

A company has a three-tier application in a cloud VPC: web servers in a public subnet, application servers in a private subnet, and database servers in a private subnet. The web servers can connect to the application servers, but the application servers cannot connect to the database servers. The security groups are configured as follows: - Web SG: inbound HTTP from 0.0.0.0/0, outbound all - App SG: inbound HTTP from Web SG, outbound all - DB SG: inbound MySQL from App SG, outbound all What is the most likely cause of the connectivity issue?

A.The database security group is missing an inbound rule for MySQL.
B.The application security group is missing an outbound rule for MySQL.
C.The network access control list (NACL) on the database subnet is blocking inbound traffic from the application subnet.
D.The web security group is blocking traffic to the database.
AnswerC

Security groups are stateful and already permit MySQL from the App SG, so the block must come from the stateless layer: the database subnet's NACL. Its inbound rules are evaluated independently of outbound, and a missing allow for the application subnet's CIDR on port 3306 drops the traffic.

Why this answer

The most likely cause is a network ACL (NACL) on the database subnet blocking inbound traffic from the application subnet. Security groups are stateful and allow return traffic, but NACLs are stateless and must explicitly allow both inbound and outbound traffic on ephemeral ports. If the NACL denies inbound MySQL (port 3306) from the app subnet's CIDR, the connection fails even though the security groups are correctly configured.

Exam trap

The trap is focusing only on security groups because they are commonly misconfigured; the exam tests whether you remember that NACLs are stateless and can block traffic even when security groups are correct.

How to eliminate wrong answers

Option A is wrong because the DB security group already has an inbound rule for MySQL from the App SG, as stated in the scenario. Option B is wrong because the App SG has outbound 'all', which includes MySQL traffic to the DB. Option D is wrong because the Web SG is not involved in the app-to-database connection path; the web tier only talks to the app tier.

171
MCQmedium

An Azure administrator needs to deploy a cloud-native application using Azure DevOps. The team wants to define the entire Azure infrastructure as code using a declarative language that is concise and integrated with Azure. Which tool should the administrator use?

A.Terraform
B.Bicep
C.Ansible
D.ARM templates (JSON)
AnswerB

Bicep is a declarative domain-specific language that compiles to Azure Resource Manager templates, offering concise syntax with native Azure integration. It satisfies the stem's requirement for infrastructure as code in a declarative, concise form, unlike imperative scripting or JSON-based ARM templates.

Why this answer

Bicep is a domain-specific language for deploying Azure resources that provides a simpler syntax than ARM templates while being fully integrated with Azure.

172
Multi-Selectmedium

A company is considering a multi-cloud deployment to avoid vendor lock-in. Which TWO factors should they consider? (Select TWO.)

Select 2 answers
A.Unified management tools support
B.Consistent security policies across clouds
C.Data egress costs between clouds
D.Performance differences between providers
E.Software licensing compatibility
AnswersB, C

Multi-cloud spans providers with differing IAM models, logging formats and encryption defaults. A single consistent security policy framework, applied uniformly across every cloud, prevents fragmented controls and audit gaps that vendor lock-in avoidance would otherwise introduce.

Why this answer

Option B is correct because in a multi-cloud deployment the company must enforce consistent security policies (e.g., IAM, encryption, network segmentation) across all providers; otherwise, gaps between clouds create vulnerabilities and compliance failures. Option C is correct because data egress costs between clouds are a major hidden expense in multi-cloud architectures — providers charge for outbound data transfer, and inter-cloud traffic can quickly erode the cost benefits of avoiding vendor lock-in. Option A is not essential since unified management tools are helpful but not a defining factor for multi-cloud success.

Option D is not a primary consideration because performance differences are typically minor and can be managed through workload placement. Option E is not specific to multi-cloud; software licensing compatibility matters in any environment and does not directly address the vendor lock-in goal.

Exam trap

The trap here is that candidates often confuse operational benefits (like unified management or performance tuning) with strategic lock-in avoidance, leading them to select options A or D instead of focusing on cost and security consistency as the key differentiators.

173
Multi-Selectmedium

A cloud operations team is preparing for a disaster recovery drill for a multi-tier application. Which TWO activities are essential for verifying the effectiveness of the DR plan? (Select TWO.)

Select 2 answers
A.Verify the RTO and RPO are achieved
B.Review the incident response plan
C.Update the asset inventory
D.Perform a failover test to the DR site
E.Conduct a security audit
AnswersA, D

Verifying RTO and RPO confirms the DR plan meets its defined recovery targets, directly satisfying the drill's purpose of validating effectiveness. RTO measures restoration time; RPO measures tolerable data loss. Achieving both proves the failover actually works within business constraints, rather than merely documenting procedures that may fail under real conditions.

Why this answer

Option A is correct because the Recovery Time Objective (RTO) and Recovery Point Objective (RPO) are the measurable targets that define how quickly and how much data the DR plan must restore, so verifying they are actually achieved during the drill is the core proof that the plan meets business requirements. Option D is correct because a failover test to the DR site exercises the real recovery procedures—bringing up the standby environment, redirecting traffic, and validating application functionality—which is the only way to confirm the plan works end to end rather than just on paper. The remaining options, while valuable in other contexts, are not essential DR effectiveness checks: reviewing the incident response plan (B) addresses incident handling rather than recovery validation, updating the asset inventory (C) is a documentation/hygiene task, and conducting a security audit (E) assesses security controls, not recovery capability.

Exam trap

The trap is choosing documentation or audit activities (incident response review, asset inventory, security audit) that support DR governance but do not actually verify recovery effectiveness.

174
MCQhard

A company is deploying a microservices architecture that must scale dynamically based on traffic. Which technology should be used?

A.Manually add more virtual machines during peak hours
B.Deploy a monolithic application on a single large instance
C.Kubernetes with Horizontal Pod Autoscaler
D.Use a single large instance with a load balancer
AnswerC

The Horizontal Pod Autoscaler adjusts replica counts from observed metrics such as CPU or request rate, letting microservices scale elastically with traffic. Kubernetes supplies the orchestration and scheduling layer, satisfying the dynamic-scaling requirement without manual intervention.

Why this answer

Kubernetes with Horizontal Pod Autoscaler (HPA) is purpose-built for microservices that must scale dynamically: HPA watches metrics (CPU, memory, or custom metrics via the metrics API) and automatically adjusts the number of pod replicas in a Deployment, ReplicaSet, or StatefulSet. This delivers elastic, policy-driven scaling without human intervention, which is exactly what a traffic-driven microservices architecture requires.

Exam trap

The trap here is confusing load balancing (distributing existing capacity) with autoscaling (adding capacity on demand) — candidates who pick the load balancer option mistake traffic distribution for elastic scaling.

How to eliminate wrong answers

Option A is wrong because manually adding VMs during peak hours is reactive, human-dependent, and cannot respond to sudden traffic spikes in real time. Option B is wrong because a monolithic application on a single large instance contradicts the microservices requirement and creates a single point of failure with no horizontal elasticity. Option D is wrong because a single large instance with a load balancer still has a fixed capacity ceiling — a load balancer distributes traffic but does not add compute capacity when demand grows.

175
MCQmedium

During a CI/CD pipeline for a web application, the team wants to reduce risk by deploying a new version to a small percentage of users initially, monitoring for errors, and automatically rolling back if issues are detected. Which deployment strategy should they implement?

A.Blue/green deployment
B.Rolling deployment
C.In-place deployment
D.Canary deployment
AnswerD

Canary deployment routes a small percentage of traffic to the new version while the majority still hits the stable release, enabling error monitoring and automatic rollback. This directly satisfies the requirement to limit initial user exposure and revert on detected issues.

Why this answer

Canary deployment routes a small percentage of production traffic to the new version while the majority continues to hit the stable version, allowing the team to monitor error rates and latency in real time. If metrics degrade, traffic can be shifted back automatically, limiting blast radius. This matches the requirement of exposing only a small subset of users, monitoring, and auto-rolling back.

Exam trap

CV0-004 often tests the distinction between canary and blue/green — candidates pick blue/green because both reduce risk, but only canary exposes a small percentage of users with gradual traffic shifting.

How to eliminate wrong answers

Option A is wrong because blue/green deployment shifts 100% of traffic from the old environment to the new one after validation, so all users are exposed simultaneously rather than a small percentage. Option B is wrong because rolling deployment replaces instances in batches across the entire fleet, gradually increasing exposure to all users rather than isolating a small canary cohort. Option C is wrong because in-place deployment updates the existing instances directly, causing downtime or full-fleet exposure with no traffic-splitting mechanism for gradual risk reduction.

176
MCQmedium

A cloud administrator receives an alert that a virtual machine's disk usage is at 95%. The VM hosts a database. Which of the following troubleshooting steps should the administrator take FIRST?

A.Expand the virtual disk by resizing the volume in the cloud console
B.Reboot the virtual machine to free up temporary files
C.Query the database for active connections to determine if there are long-running transactions
D.Check the disk to identify which files are consuming space
AnswerD

Identifying which files consume the space reveals whether the growth is database data, logs or orphaned files, directing the remedy. This diagnostic step precedes deletion or expansion, satisfying the requirement to act first without risking data loss on a production database.

Why this answer

When a VM's disk usage reaches 95%, the first step is to identify what is consuming the space. Checking the disk to identify which files are consuming space (Option D) allows the administrator to determine whether the issue is caused by database logs, temporary files, or other data, and to plan an appropriate remediation without unnecessary risk or downtime.

Exam trap

The trap here is that candidates may assume high disk usage is always caused by temporary files or transactions, leading them to reboot or query the database first, rather than performing a simple disk space analysis to identify the actual culprit.

How to eliminate wrong answers

Option A is wrong because expanding the virtual disk without first identifying the cause of high usage may lead to uncontrolled growth and does not address the root cause; it also risks exceeding storage quotas or costs. Option B is wrong because rebooting the VM to free temporary files is a disruptive action that may not resolve the issue if the space is consumed by database logs or persistent data, and it could cause unnecessary downtime for a production database. Option C is wrong because querying for long-running transactions addresses performance issues, not disk space consumption; high disk usage is typically caused by data files, logs, or temporary files, not by active connections.

177
MCQhard

An organization is migrating a MySQL database to Amazon Aurora with minimal downtime. The migration must capture ongoing changes from the source database and apply them to the target during the cutover. Which AWS Database Migration Service (DMS) feature should be used?

A.Validation
B.Change data capture (CDC)
C.Full load only
D.Schema conversion
AnswerB

Change data capture reads ongoing inserts, updates and deletes from the source's transaction log and applies them to Aurora, keeping the target synchronised until cutover. This satisfies the minimal-downtime constraint by replicating changes continuously rather than requiring a stop-and-copy migration.

Why this answer

Change data capture (CDC) in AWS DMS continuously reads the source database's transaction log (binary log for MySQL) and applies ongoing changes to the target, enabling near-zero-downtime cutover. It is the specific DMS feature designed to replicate changes that occur after the initial full load.

Exam trap

CV0-004 often tests the misconception that 'full load' or 'validation' handles ongoing changes, when only CDC (also called 'replication' or 'ongoing replication') captures and applies changes made after the initial load.

How to eliminate wrong answers

Option A is wrong because Validation compares source and target data to confirm consistency — it does not capture or apply ongoing changes. Option C is wrong because Full load only performs a one-time bulk copy of existing data and does not replicate subsequent changes, which would cause data loss during cutover. Option D is wrong because Schema conversion is an AWS SCT (Schema Conversion Tool) function that translates DDL between engines; it does not handle ongoing data replication.

178
MCQmedium

A cloud engineer is deploying a containerized application to a Kubernetes cluster. The application requires a configuration file that contains database credentials and API keys. The engineer wants to avoid hardcoding sensitive information in the container image or in the deployment manifest. Which Kubernetes resource should be used to store and manage this sensitive data securely?

A.Secret
B.ConfigMap
C.PersistentVolumeClaim
D.ServiceAccount
AnswerA

Kubernetes Secrets are designed to hold sensitive information such as passwords, tokens, and keys. They are stored in etcd and can be encrypted at rest if configured. Secrets can be mounted as files or exposed as environment variables, and they are only distributed to nodes running pods that require them. Using a Secret avoids hardcoding credentials in the image or manifest and follows security best practices.

Why this answer

Kubernetes Secrets are the appropriate resource for storing sensitive configuration data such as database credentials and API keys. They keep secrets separate from the container image and deployment manifest, and they can be encrypted at rest. Secrets can be consumed as environment variables or mounted as files, providing flexibility while maintaining security.

This approach aligns with the principle of least privilege and avoids exposing sensitive data in source control.

Exam trap

The trap here is assuming ConfigMaps are sufficient for secrets because they are easy to use, but they lack the security controls of Secrets.

179
MCQmedium

An organization is using CloudFormation to manage AWS infrastructure. They need to detect if any manual changes have been made to resources outside of CloudFormation. Which CloudFormation feature should they use?

A.Change sets
B.Drift detection
C.Stack sets
D.Resource signals
AnswerB

Drift detection compares each stack resource's actual configuration against its expected template-defined state, reporting any divergence. This directly satisfies the requirement to identify manual changes made outside CloudFormation, since it flags resources whose live properties no longer match the stack's declared configuration.

Why this answer

CloudFormation drift detection compares the current state of resources with the expected state defined in the stack template. It identifies resources that have been modified manually, known as drift.

180
MCQhard

A cloud administrator receives an alert that a virtual machine has unexpectedly shut down. The administrator checks the hypervisor logs and finds an entry "Out of memory: killed process" in the VM's OS logs. Which of the following is the most likely cause?

A.The hypervisor memory overcommitment is too high.
B.The VM has a memory leak in its application.
C.The VM's memory balloon driver is not installed.
D.The VM's swap space is insufficient.
AnswerB

The hypervisor log shows the guest OS out-of-memory killer terminating a process, which points to memory exhaustion inside the VM rather than a host or hypervisor fault. An application memory leak steadily consumes guest RAM until the kernel kills processes, shutting the VM down.

Why this answer

The log entry 'Out of memory: killed process' indicates that the Linux kernel's Out-Of-Memory (OOM) killer terminated a process to free memory. This is typically triggered when the system runs out of available memory, often due to a memory leak in an application consuming memory over time without releasing it. While hypervisor-level issues can cause VM instability, the specific OOM killer message points to a guest OS-level memory exhaustion problem, making a memory leak the most likely cause.

Exam trap

CompTIA Cloud+ often tests the distinction between guest OS-level memory exhaustion (e.g., memory leak) and hypervisor-level memory management (e.g., overcommitment or ballooning), leading candidates to incorrectly attribute the OOM killer message to hypervisor issues rather than the application inside the VM.

How to eliminate wrong answers

Option A is wrong because hypervisor memory overcommitment can cause the hypervisor to reclaim memory from VMs (e.g., via ballooning or swapping), but it does not directly cause the guest OS's OOM killer to fire; the guest OS would see its memory shrink but not necessarily run out unless the balloon driver forces it. Option C is wrong because the memory balloon driver not being installed would prevent the hypervisor from reclaiming unused memory from the VM, potentially leading to wasted resources, but it does not cause the guest OS to run out of memory and trigger the OOM killer; in fact, without ballooning, the VM retains all its allocated memory. Option D is wrong because insufficient swap space can lead to the OOM killer if memory is exhausted and no swap is available, but the OOM killer message itself does not indicate a swap insufficiency; it indicates that the system ran out of both physical RAM and swap, and the root cause is often a memory leak consuming all available memory, not just a lack of swap.

181
MCQhard

A cloud engineer runs the commands shown in the exhibit. Based on the output, which security issue is present?

A.The bastion host is not used for SSH access.
B.The web servers are not running.
C.The firewall rule allows SSH access from any source IP.
D.There are too many firewall rules allowing SSH.
AnswerC

The exhibit shows an inbound rule permitting TCP port 22 with a source of 0.0.0.0/0, meaning any internet host can reach SSH. That violates the least-privilege constraint in the stem, since administrative access should be restricted to known management addresses rather than exposed globally.

Why this answer

The exhibit shows a firewall rule permitting TCP/22 (SSH) with source 0.0.0.0/0, meaning any host on the internet can attempt SSH to the web servers. This violates least privilege and exposes the instances to brute-force and exploitation attempts. The correct remediation is to restrict the source to a bastion host or corporate CIDR.

Exam trap

CV0-004 often tests whether candidates focus on the actual misconfiguration shown (0.0.0.0/0 on SSH) rather than plausible-sounding but unsupported options like 'no bastion host' or 'too many rules'.

How to eliminate wrong answers

Option A is wrong because the exhibit does not show whether a bastion host exists or is used — the visible issue is the overly permissive source range, not the absence of a bastion. Option B is wrong because the exhibit shows firewall rules, not instance health checks or service status, so there is no evidence the web servers are down. Option D is wrong because the problem is not the quantity of SSH rules but the overly broad source CIDR in the rule that is present; adding or removing rules does not fix the 0.0.0.0/0 exposure.

182
Multi-Selectmedium

A cloud architect is designing a highly available two-tier web application. The database tier must remain available if a single Availability Zone fails. Which TWO design decisions should the architect make? (Choose two.)

Select 2 answers
A.Configure the database with a standby replica in a different Availability Zone and automatic failover.
B.Place all application servers in one Availability Zone to reduce network latency between tiers.
C.Deploy the application tier across multiple Availability Zones behind a load balancer.
D.Route all database traffic through a NAT gateway in the primary Availability Zone.
E.Use a single large database instance with daily snapshots stored in the same Availability Zone.
AnswersA, C

A standby replica in another Availability Zone receives synchronous replication and can be promoted automatically when the primary zone fails. This provides a low recovery point and low recovery time because the standby is already in sync. It directly addresses the requirement that the database tier survive the loss of a single Availability Zone without manual intervention.

Why this answer

High availability across Availability Zones requires removing single points of failure in every tier. A database with a standby in another zone and automatic failover keeps data available, while application servers distributed across zones behind a load balancer keep the web tier serving requests. Together they prevent one zone failure from taking down the application.

Exam trap

The trap here is focusing only on the database tier and forgetting that the application tier must also be spread across zones to avoid a single point of failure.

183
MCQeasy

A cloud architect is designing a deployment pipeline using GitHub Actions. They want to automatically run tests on every push to the main branch. Which GitHub Actions component defines the automation workflow?

A.Job
B.Step
C.Action
D.Workflow
AnswerD

A workflow is the YAML-defined automation unit in GitHub Actions, containing the triggers and jobs that run. Defining it with an on: push trigger scoped to the main branch executes the test jobs automatically on every push, meeting the stated requirement.

Why this answer

A GitHub Actions workflow is the top-level YAML file (in .github/workflows) that defines when automation runs and what jobs it contains. It is the component that binds triggers (like push to main) to jobs and steps, so it is the correct answer for 'defines the automation workflow.'

Exam trap

CV0-004 often tests the confusion between the workflow (top-level YAML) and its sub-components (job, step, action); candidates must identify the workflow as the automation definition.

How to eliminate wrong answers

Option A is wrong because a job is a set of steps that runs on a runner within a workflow; it is a sub-component, not the top-level definition. Option B is wrong because a step is a single task within a job (a shell command or an action), the smallest unit. Option C is wrong because an action is a reusable unit of code invoked by a step, not the workflow definition itself.

184
MCQmedium

A cloud administrator manages a three-tier application in a public cloud. After a change window, users can reach the web front end, but every request to the API tier returns HTTP 504 Gateway Timeout. The web tier and API tier are in different subnets, and the API instances report healthy in the load balancer target group. Which action should the administrator take FIRST to isolate the fault?

A.Lower the web tier's idle timeout value so slow API responses are terminated sooner.
B.Reboot all API instances because the target group reports them healthy but the application process may have hung.
C.Verify the network ACL and security group rules that govern traffic from the web subnet to the API tier's listener port.
D.Increase the API tier's autoscaling maximum because the timeout indicates the tier is saturated with requests.
AnswerC

A 504 from the front end while API instances are healthy points to connectivity between tiers rather than an application crash. A security group or network ACL that silently drops the web-to-API flow would let the target group health check pass (if it originates inside the API subnet) while user requests time out. Checking these rules first is the fastest way to confirm or eliminate a network path fault.

Why this answer

Healthy API targets plus front-end 504s isolate the fault to the path between tiers, not to the API application itself. Security groups and network ACLs are the components that can silently drop traffic on the listener port while still allowing health checks, so reviewing those rules first is the correct diagnostic step. Reboots, scaling, and timeout tuning all act on the wrong layer and would delay identification of the real cause.

Exam trap

The trap here is assuming a 504 always means the backend application is overloaded, when it can equally mean traffic never reaches the backend at all.

185
MCQhard

A DevOps engineer is configuring a Kubernetes deployment for a microservices application. The application requires that new pods receive traffic only after a health check endpoint returns HTTP 200. Which Kubernetes feature should be configured on the pods?

A.Startup probe
B.Liveness probe
C.Resource limits
D.Readiness probe
AnswerD

A readiness probe checks the health endpoint and only adds the pod to the Service endpoints once it returns HTTP 200. This directly satisfies the requirement that new pods receive traffic only after the health check passes, unlike a liveness probe, which restarts containers.

Why this answer

A readiness probe determines whether a pod is ready to receive traffic. If the readiness probe fails, the pod is removed from the endpoints of the service, preventing traffic from being sent to it until it passes. This matches the requirement that new pods receive traffic only after a health check endpoint returns HTTP 200.

Exam trap

The trap is confusing readiness probes with liveness probes; candidates must remember that readiness controls traffic, while liveness controls restarts.

How to eliminate wrong answers

Option A is wrong because a startup probe is used to determine when a container has started, and it disables other probes until it succeeds; it does not control traffic routing. Option B is wrong because a liveness probe checks if the container is still running and restarts it if not, but it does not affect traffic routing. Option C is wrong because resource limits control CPU and memory allocation, not traffic routing based on health checks.

186
MCQmedium

A company is deploying a web application on AWS using an Auto Scaling group of Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores user session data locally on each instance. During a scaling event, users are being logged out because their sessions are not available on new instances. The company wants to implement a solution that allows sessions to persist across all instances without modifying the application code. Which approach should be used?

A.Enable sticky sessions (session affinity) on the ALB.
B.Store session data in an Amazon ElastiCache for Redis cluster.
C.Configure the Auto Scaling group to use a launch template with a pre-baked AMI that includes session data.
D.Use an Amazon RDS database to store session data.
AnswerB

Amazon ElastiCache for Redis provides a centralized, in-memory data store that can be used to store session data. By configuring the application to use Redis as the session store, sessions become available to all instances in the Auto Scaling group. This requires no application code changes if the application already supports external session stores, or minimal configuration changes. It ensures sessions persist even if instances are added or removed.

Why this answer

Amazon ElastiCache for Redis is a fully managed in-memory data store that is ideal for session management. It provides sub-millisecond latency and can scale to handle high request rates. By externalizing session state to Redis, all instances in the Auto Scaling group can access the same session data, so users remain logged in even when instances are added or removed.

This is a common pattern for stateless web applications.

Exam trap

The trap here is assuming that sticky sessions on the load balancer are sufficient for session persistence during scaling events, when in fact they only tie a user to a single instance and do not share session data across instances.

187
MCQhard

A cloud administrator is troubleshooting a database failover issue. The database is a managed service with a primary and standby replica in different availability zones. The application uses a read-write endpoint. During a recent maintenance event, the primary database failed over automatically, but the application experienced a 10-minute outage. The administrator checks the failover logs and sees that it completed within 2 minutes. What is the most likely cause of the extended outage?

A.The application's database connection pool does not retry DNS resolution
B.The application was not configured to use multiple availability zones
C.The standby replica was not in sync
D.The failover triggered a change in the endpoint DNS record
AnswerA

After failover the read-write endpoint's DNS record points to the new primary, but a connection pool caching the old address keeps reconnecting to the failed node until its entries expire. This explains the outage far exceeding the two-minute failover time.

Why this answer

The most likely cause is that the application's connection pool caches the DNS resolution of the read-write endpoint. After failover, the DNS record points to the new primary, but the pool continues to use the old IP until the TTL expires or the connection is refreshed. This causes a prolonged outage beyond the actual failover time.

Exam trap

The trap is blaming the failover mechanism or replication; candidates overlook application-side DNS caching in connection pools as the cause of extended downtime.

How to eliminate wrong answers

Option B is wrong because the application uses a read-write endpoint, which is inherently multi-AZ; the issue is not lack of AZ configuration. Option C is wrong because the failover logs show it completed in 2 minutes, implying the standby was in sync. Option D is wrong because a DNS change is expected during failover; the problem is the application not picking up the change, not the change itself.

188
MCQeasy

A cloud administrator needs to grant a third-party auditing firm read-only access to compliance reports in an Amazon S3 bucket for a limited period. The firm's identity provider supports SAML 2.0. Which approach best meets the requirement with least administrative overhead?

A.Configure an IAM identity provider for SAML 2.0 and use role-based federation with a time-limited session
B.Generate a presigned URL for each compliance report and email it to the auditors
C.Create IAM users for each auditor and attach an S3 read-only managed policy
D.Enable S3 Block Public Access and share the bucket through a public bucket policy restricted by source IP
AnswerA

SAML 2.0 federation with an IAM identity provider lets the firm's existing directory authenticate auditors, and AWS issues temporary credentials through AssumeRoleWithSAML. No long-lived IAM users or keys are created, sessions expire automatically, and permissions come from a role scoped to S3 read-only. This satisfies limited duration and least overhead precisely.

Why this answer

Federating the firm's SAML 2.0 identity provider with IAM lets auditors authenticate with existing credentials and assume a scoped role that returns temporary credentials with automatic expiry. This avoids creating and later removing IAM users and keys, minimizes administrative effort, and enforces least privilege for the engagement period. Presigned URLs and public policies lack identity integration and durable auditability.

Exam trap

The trap here is choosing IAM users for external parties out of habit, when identity federation with temporary role sessions is the lower-overhead, time-limited method.

189
MCQeasy

A cloud architect needs to choose a compute service for a batch processing job that runs once a day and takes about 30 minutes. The job is CPU-intensive and can tolerate interruptions. Which compute option is the most cost-effective?

A.Reserved instances
B.Spot (preemptible) instances
C.Dedicated hosts
D.On-demand instances
AnswerB

Spot instances offer substantial discounts over on-demand pricing and can be reclaimed with little notice, which suits a CPU-intensive batch job that tolerates interruptions. The 30-minute daily runtime means reclamation risk is low and cost savings are maximised.

Why this answer

(Spot/preemptible instances) is the most cost-effective for this interruptible batch job. Reserved instances (A) require a long-term commitment, on-demand instances (D) are more expensive, and dedicated hosts (C) are costly and unnecessary.

190
MCQmedium

A company's compliance team must provide evidence that their cloud environment meets PCI DSS requirements. Which AWS service can aggregate security findings and automate compliance checks?

A.AWS Config
B.AWS Security Hub
C.Amazon Inspector
D.AWS CloudTrail
AnswerB

AWS Security Hub aggregates findings from GuardDuty, Inspector, Macie and Config, then runs automated compliance checks against standards including PCI DSS. This centralised aggregation and automated assessment satisfies the compliance team's evidence requirement, unlike standalone services.

Why this answer

AWS Security Hub aggregates security findings from multiple AWS services and third-party tools, and it can run automated compliance checks against standards like PCI DSS. It provides a central dashboard for security posture. AWS Config records resource configurations but does not aggregate findings or automate compliance checks in the same way.

Amazon Inspector is for vulnerability assessment, and CloudTrail logs API activity.

Exam trap

CV0-004 often tests the confusion between AWS Config (configuration recording) and Security Hub (aggregation and compliance), expecting candidates to know that Security Hub is the aggregator for compliance.

How to eliminate wrong answers

Option A is wrong because AWS Config evaluates resource configurations against desired rules but does not aggregate findings from other services or provide automated compliance checks for standards like PCI DSS. Option C is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and network exposures, not a compliance aggregation tool. Option D is wrong because AWS CloudTrail records API calls for auditing but does not aggregate security findings or automate compliance checks.

191
MCQmedium

A company migrated to a hybrid cloud and users report slow access to files stored in the cloud. The on-premises network is 100 Mbps. What troubleshooting step should be taken?

A.Enable compression on the cloud storage gateway
B.Check VPN bandwidth and latency
C.Increase cloud storage performance tier
D.Move files to on-premises storage
AnswerB

Checking VPN bandwidth and latency directly addresses the hybrid cloud bottleneck: the 100 Mbps on-premises link and any tunnel overhead cap throughput for cloud file access. Measuring both reveals whether encryption, routing or congestion is throttling transfers, satisfying the stem's constraint of diagnosing slow cloud file access across the hybrid connection.

Why this answer

The most likely bottleneck in a hybrid cloud scenario where users access cloud-stored files over a 100 Mbps on-premises connection is the VPN tunnel used to connect to the cloud. VPN bandwidth and latency directly affect file access speed, and issues such as insufficient tunnel capacity, high latency, or packet loss can cause slow transfers. Checking these metrics is the logical first troubleshooting step to identify whether the network path is the limiting factor.

Exam trap

CV0-004 often tests the misconception that slow cloud file access is always due to cloud storage performance, leading candidates to choose increasing the performance tier instead of first diagnosing the network path.

How to eliminate wrong answers

Option A is wrong because enabling compression on the cloud storage gateway may improve effective throughput but does not address the underlying network bottleneck; it is a optimization step, not a troubleshooting step, and may not be supported or effective if the data is already compressed. Option C is wrong because increasing the cloud storage performance tier addresses storage IOPS or throughput limits on the cloud side, but the on-premises network at 100 Mbps is a more immediate constraint, and the scenario does not indicate storage performance is the issue. Option D is wrong because moving files to on-premises storage defeats the purpose of the hybrid cloud migration and does not troubleshoot the slow access; it is a workaround, not a diagnostic step.

192
Multi-Selectmedium

A cloud architect is designing a multi-tier application that must be resilient to the failure of a single availability zone. The application consists of a web tier, an application tier, and a database tier. Which TWO design decisions will help achieve this resilience? (Choose two.)

Select 2 answers
A.Use a single, large database instance in one availability zone with frequent snapshots.
B.Place all tiers in a single availability zone to reduce network latency between components.
C.Deploy the web and application tiers across multiple availability zones and use a load balancer to distribute traffic.
D.Configure the database tier with a multi-AZ standby replica that can be promoted in the event of a failure.
E.Store all session state on the local disk of each web server to improve performance.
AnswersC, D

Distributing the web and application tiers across multiple availability zones ensures that if one zone fails, the remaining zones can continue to serve requests. A load balancer health-checks instances and routes traffic only to healthy targets. This eliminates single points of failure at the compute layer and is a fundamental practice for zone-resilient architectures.

Why this answer

To be resilient to a single availability zone failure, both the stateless tiers and the stateful database tier must be distributed. Deploying the web and application tiers across multiple zones behind a load balancer ensures continued service if one zone fails. Configuring the database with a multi-AZ standby replica provides automatic failover for the data layer.

Together, these decisions eliminate single points of failure across all tiers.

Exam trap

The trap here is focusing only on the compute tiers and forgetting that the database tier also needs a multi-AZ strategy to achieve full resilience.

193
MCQhard

An organization needs to recover its critical database within 15 minutes and lose at most 1 minute of data. Which configuration meets these requirements?

A.Active-active with asynchronous replication
B.Warm standby with hourly backups
C.Hot standby with synchronous replication
D.Cold standby with daily backups
AnswerC

Synchronous replication commits each transaction on both primary and standby before acknowledgement, so a failover loses zero committed data — comfortably inside the one-minute RPO. The hot standby is already running and current, allowing promotion within the 15-minute RTO. Asynchronous replication could not guarantee that one-minute data-loss limit.

Why this answer

Hot standby with synchronous replication ensures that every write to the primary database is also written to the standby before the transaction is acknowledged. This guarantees zero data loss (RPO=0) and, combined with automatic failover, can achieve a recovery time of under 15 minutes (RTO<15 min).

Exam trap

A common trap is confusing 'asynchronous replication' (which can lose data) with 'synchronous replication' (which preserves data), leading candidates to incorrectly choose active-active with async replication despite its inability to meet the 1-minute RPO.

How to eliminate wrong answers

Option A is wrong because active-active with asynchronous replication can cause data loss of more than 1 minute if a failure occurs before the async replication completes, violating the RPO of ≤1 minute. Option B is wrong because warm standby with hourly backups has an RPO of up to 1 hour (not ≤1 minute) and an RTO that typically exceeds 15 minutes due to the need to restore from backup. Option D is wrong because cold standby with daily backups has an RPO of up to 24 hours and an RTO measured in hours or days, far exceeding the 15-minute RTO requirement.

194
MCQeasy

A cloud engineer is troubleshooting a performance issue in a virtualized environment. A critical application is running slowly, and the engineer suspects resource contention. The host server has 32 vCPUs and 256 GB of RAM, running four VMs. Which tool should the engineer use to determine if CPU ready time is causing the performance degradation?

A.Run the 'top' command inside the affected VM
B.Deploy a network analyzer to capture traffic between VMs
C.Check the performance monitor in the guest operating system
D.Use the hypervisor's monitoring console to view CPU ready time
AnswerD

CPU ready time measures how long a vCPU waited in the hypervisor's run queue for a physical core, which is the precise metric for CPU contention on an overcommitted host. Only the hypervisor console exposes it; guest tools cannot see scheduling delay.

Why this answer

CPU ready time is a hypervisor-level metric that measures the time a VM is ready to execute but must wait for a physical CPU core to become available. Since the engineer suspects resource contention among VMs on the same host, the hypervisor's monitoring console is the only tool that can expose this metric directly. Guest OS tools like 'top' or Performance Monitor cannot see CPU ready time because it occurs at the virtualization layer, not inside the VM.

Exam trap

The trap here is that candidates assume guest OS tools like 'top' or Performance Monitor can detect all CPU-related bottlenecks, but they cannot see hypervisor-level metrics like CPU ready time, which requires the hypervisor's own monitoring console.

How to eliminate wrong answers

Option A is wrong because the 'top' command inside the affected VM shows guest-level CPU utilization, not hypervisor-level CPU ready time, which is invisible to the guest OS. Option B is wrong because a network analyzer captures traffic between VMs and is used for network latency or packet loss issues, not CPU scheduling contention. Option C is wrong because the guest OS performance monitor reports CPU usage from the guest's perspective, but CPU ready time is a hypervisor metric that the guest cannot measure or report.

195
MCQmedium

An organization is subject to PCI DSS compliance and must ensure that all data transmitted between its cloud application and users is encrypted. Which encryption method should be enforced?

A.AES-256
B.TLS 1.2 or higher
C.SHA-256
D.IPsec VPN
AnswerB

TLS 1.2 or higher encrypts data in transit between the cloud application and users, satisfying the PCI DSS requirement for protecting cardholder data over public networks. Earlier protocol versions contain known weaknesses, so enforcing TLS 1.2 as the minimum cipher suite baseline is mandatory.

Why this answer

PCI DSS requires that cardholder data transmitted over open, public networks be protected with strong cryptography. TLS 1.2 or higher is the transport-layer protocol that provides encryption, integrity, and authentication for data in transit between the cloud application and users, satisfying the requirement. AES-256 is the underlying cipher TLS uses, but it is not itself a transmission method.

Exam trap

CV0-004 often tests the confusion between an encryption algorithm (AES-256, SHA-256) and a transport protocol (TLS), so candidates pick the cipher name instead of the protocol that actually secures data in transit.

How to eliminate wrong answers

Option A is wrong because AES-256 is a symmetric block cipher used to encrypt data at rest or as the bulk cipher inside TLS, not a protocol for securing data in transit between a server and users. Option C is wrong because SHA-256 is a cryptographic hash function used for integrity and signatures, not encryption, so it cannot protect confidentiality. Option D is wrong because IPsec VPN encrypts site-to-site or client-to-site tunnels at the network layer, which is not the standard method for securing public web/API traffic to end users and is not what PCI DSS expects for browser-based access.

196
Multi-Selecthard

A company wants to ensure fault tolerance for a critical application by deploying across multiple availability zones. Which THREE design decisions contribute to fault tolerance? (Select THREE.)

Select 3 answers
A.Using a single database instance without replication
B.Placing a load balancer in front of the instances to distribute traffic
C.Deploying application instances in at least two availability zones
D.Implementing duplicate components (N+1 redundancy) in each tier
E.Using a single large instance in one AZ
AnswersB, C, D

A load balancer distributes incoming traffic across instances in multiple availability zones and health-checks them, routing around a failed zone. This directly delivers the fault tolerance the scenario demands by removing any single instance or zone as a point of failure.

Why this answer

Deploying across multiple AZs, using load balancers to distribute traffic, and having redundant components in each AZ contribute to fault tolerance. Single instance and same AZ do not provide fault tolerance.

197
MCQmedium

A cloud administrator manages a SaaS-based CRM application integrated with an on-premises Active Directory via SAML 2.0. Users report intermittent authentication failures during peak hours (09:00-11:00), with error messages indicating 'SAML assertion validation failed'. The IdP logs show successful authentications, but the SP logs show signature validation errors. The IdP's signing certificate was rotated 30 days ago, and the SP metadata was updated 45 days ago. Which of the following is the MOST likely cause?

A.The IdP is not including the correct NameID format in the SAML assertion.
B.The SP's SAML assertion consumer service (ACS) URL is misconfigured.
C.The SP's metadata contains an outdated IdP signing certificate.
D.The IdP's clock is skewed relative to the SP, causing timestamp validation to fail.
AnswerC

The SP metadata was updated 45 days ago, but the IdP rotated its signing certificate 30 days ago. SAML signature validation relies on the certificate in the SP's trusted metadata; if it still holds the old certificate, assertions signed with the new key fail validation. This matches the symptom of successful IdP authentication but SP-side signature errors, and the timing discrepancy confirms the metadata is stale.

Why this answer

The IdP rotated its signing certificate 30 days ago, but the SP metadata was last updated 45 days ago, meaning the SP still trusts the old certificate. SAML signature validation requires the SP to use the current IdP signing certificate. The successful IdP authentications and SP signature errors confirm the SP cannot validate assertions signed with the new key.

Updating the SP metadata with the new certificate resolves the issue.

Exam trap

The trap here is assuming that because the IdP logs show successful authentications, the problem must be on the IdP side, when in fact the SP's stale metadata is the root cause.

198
MCQhard

A cloud administrator is troubleshooting a VM whose performance metrics show high 'CPU ready' (or 'CPU steal') time, even though the VM's own CPU utilization is only 20%. The VM runs a latency-sensitive database and is hosted on a shared hypervisor. Which action is the MOST appropriate first step to resolve the performance issue?

A.Configure CPU affinity to pin the VM to a specific physical core.
B.Enable CPU hot-add and dynamically add more cores during peak hours.
C.Increase the number of vCPUs assigned to the VM.
D.Migrate the VM to a dedicated host or a host with lower oversubscription.
AnswerD

High CPU ready time indicates the VM is waiting for physical CPU resources because the hypervisor is oversubscribed. Moving the VM to a dedicated host or a host with lower oversubscription reduces contention, directly addressing the root cause. This is the most appropriate first step because it targets the resource bottleneck without unnecessary changes to the VM's configuration.

Why this answer

High CPU ready time indicates the VM is waiting for physical CPU resources due to host oversubscription. The most effective first step is to reduce contention by moving the VM to a dedicated host or a host with lower oversubscription. Increasing vCPUs or enabling hot-add does not address the host-level bottleneck and can worsen scheduling delays.

CPU affinity is not a reliable fix for oversubscription.

Exam trap

The trap here is assuming that high CPU ready time means the VM needs more vCPUs, when it actually indicates the VM is waiting for physical CPU time due to host contention.

199
MCQhard

A company hosts a web application on AWS and wants to improve latency for global users. Which service should they use to cache static content at edge locations?

A.Application Load Balancer
B.AWS CloudFront
C.AWS Global Accelerator
D.Amazon Route 53
AnswerB

AWS CloudFront caches static content at edge locations worldwide, directly satisfying the global low-latency requirement. Requests terminate at the nearest point of presence rather than the origin region, cutting round-trip time. Unlike regional services such as S3 alone, CloudFront's distributed edge network is purpose-built for this caching scenario.

Why this answer

AWS CloudFront is a content delivery network (CDN) that caches static content at edge locations worldwide, reducing latency for global users. It integrates with AWS services like S3 and EC2, and supports dynamic content acceleration. The other options do not provide edge caching for static content.

Exam trap

CV0-004 often tests the distinction between services that improve performance (CloudFront for caching, Global Accelerator for network path optimization) and those that don't (ALB for load balancing, Route 53 for DNS).

How to eliminate wrong answers

Option A is wrong because Application Load Balancer distributes incoming traffic across multiple targets in a single region, not caching content at edge locations. Option C is wrong because AWS Global Accelerator improves availability and performance by routing traffic over the AWS global network, but it does not cache static content. Option D is wrong because Amazon Route 53 is a DNS service that routes end users to internet applications, but it does not cache content at edge locations.

200
MCQmedium

A cloud engineer is deploying a multi-tier web application on AWS. The web tier must be able to scale out during traffic spikes, but the database tier should remain on a fixed set of instances. The engineer wants to define the infrastructure as code using AWS CloudFormation. Which CloudFormation feature should be used to automatically adjust the number of web tier instances based on CPU utilization?

A.Use a CloudFormation stack policy to allow scaling actions.
B.Use a CloudFormation change set to modify the desired capacity.
C.Use an Auto Scaling group with a scaling policy based on the CPUUtilization metric.
D.Use a CloudFormation update policy with AutoScalingRollingUpdate.
AnswerC

An Auto Scaling group with a scaling policy that references the Amazon CloudWatch CPUUtilization metric automatically adjusts the desired capacity of the web tier instances when average CPU crosses defined thresholds. This is the standard, declarative way to implement dynamic scaling in CloudFormation, ensuring the application can handle traffic spikes without manual intervention.

Why this answer

The correct approach is to define an Auto Scaling group with a scaling policy that uses the CPUUtilization metric. This allows CloudFormation to manage the group and its scaling behavior declaratively, automatically increasing or decreasing instances as needed. Other options either handle updates, protect resources, or preview changes, but none provide dynamic scaling based on metrics.

Exam trap

The trap here is confusing update policies or change sets with actual scaling mechanisms; only a scaling policy tied to a metric enables dynamic capacity adjustments.

201
MCQmedium

A cloud engineer is deploying a multi-tier web application on AWS using AWS Elastic Beanstalk. The application requires a relational database and must be able to scale automatically based on demand. The engineer wants to minimize management overhead. Which deployment approach should the engineer use?

A.Deploy the application as a container on Amazon ECS with an Amazon RDS database, and configure Application Auto Scaling.
B.Create a new Elastic Beanstalk environment with a web server tier and configure an Amazon RDS database instance using the Elastic Beanstalk console.
C.Use AWS CloudFormation to create an EC2 instance with a user data script that installs the application and a MySQL database.
D.Launch an Amazon EC2 instance, install the application and database software, and configure an Auto Scaling group manually.
AnswerB

Elastic Beanstalk supports integrating an RDS database directly through the console, which automates the creation of the database and configures the necessary security groups and environment properties. This minimizes management overhead because Beanstalk handles provisioning, scaling, and monitoring of both the application and the database lifecycle. The web server tier handles HTTP requests and can scale automatically based on load.

Why this answer

Elastic Beanstalk is designed to simplify deployment by handling capacity provisioning, load balancing, scaling, and application health monitoring. Integrating an RDS database through the Elastic Beanstalk console automates database setup and lifecycle management, reducing administrative tasks. The other options require manual configuration of scaling or database management, which increases overhead and does not leverage Beanstalk's integrated features.

Exam trap

The trap here is assuming that any automated deployment service reduces management overhead equally, when Elastic Beanstalk specifically provides integrated database provisioning and automatic scaling with minimal configuration.

202
MCQmedium

A cloud architect is designing a solution that must automatically provision and configure compute, storage, and networking resources in a repeatable manner across multiple cloud providers. The solution must minimize manual intervention and ensure consistent configurations. Which approach best meets these requirements?

A.Implementing a hybrid cloud with a single management portal.
B.Infrastructure as Code (IaC) with cloud-agnostic tools like Terraform.
C.Manually creating resources through each cloud provider's web console.
D.Using provider-specific CLI scripts that are executed manually.
AnswerB

IaC with Terraform allows defining infrastructure in declarative configuration files that can be version-controlled and applied consistently across multiple providers. This automates provisioning and configuration, reduces manual errors, and ensures repeatability, directly addressing the requirement for automated, consistent multi-cloud deployments.

Why this answer

Infrastructure as Code with a cloud-agnostic tool like Terraform enables automated, repeatable, and consistent provisioning across multiple cloud providers. It treats infrastructure as software, allowing version control and collaboration, which minimizes manual intervention and ensures configurations are applied uniformly. This directly satisfies the scenario's requirements.

Exam trap

The trap here is assuming that a single management portal or provider-specific scripts provide the same level of automation and consistency as cloud-agnostic Infrastructure as Code.

203
MCQeasy

A cloud engineer is troubleshooting performance issues in a virtualized environment. Which of the following tools would BEST help identify CPU contention on a hypervisor?

A.iperf
B.esxtop
C.ping
D.nslookup
AnswerB

esxtop runs on the ESXi host itself, exposing per-world CPU scheduling metrics such as %RDY, which directly quantifies the time a vCPU waits for physical cores. This satisfies the stem's requirement to identify CPU contention at the hypervisor layer, unlike guest-level tools that cannot see host scheduling pressure.

Why this answer

esxtop is VMware's real-time performance monitoring tool for ESXi hosts, and it exposes CPU metrics such as %RDY (ready time), which directly indicates CPU contention when VMs are waiting for physical CPU cycles. It is the standard tool for diagnosing hypervisor-level CPU scheduling issues.

Exam trap

CV0-004 often tests tool-to-purpose mapping — candidates confuse network tools (iperf, ping, nslookup) with hypervisor performance tools, so recognizing esxtop as the VMware-specific CPU contention tool is the key discriminator.

How to eliminate wrong answers

Option A is wrong because iperf measures network throughput and bandwidth, not CPU scheduling or contention. Option C is wrong because ping tests basic network reachability and round-trip latency, which is unrelated to hypervisor CPU contention. Option D is wrong because nslookup is a DNS query tool used to resolve names to IP addresses, with no visibility into CPU performance.

204
Matchingmedium

Match each networking concept to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Isolated private network in the cloud

Logical subdivision of a VPC

Enables private instances to access internet

Secure tunnel over public internet

Distributed network for content delivery

Why these pairings

Correct matches: VPC (isolated network), VPN (secure tunnel). Common confusions involve swapping Subnet and CDN, or Load Balancer and CDN. Understanding each component's role in cloud networking is key.

205
MCQmedium

An organization needs to store database credentials and API keys securely in the cloud, with automatic rotation every 90 days. Which service should be used?

A.AWS CloudHSM
B.AWS Key Management Service (KMS)
C.AWS Systems Manager Parameter Store
D.AWS Secrets Manager
AnswerD

Secrets Manager stores secrets and supports automatic rotation.

Why this answer

AWS Secrets Manager is purpose-built to store database credentials, API keys, and other secrets, and it natively supports automatic rotation on a schedule (for example, every 90 days) using Lambda rotation functions. That combination of secure storage plus managed rotation is exactly what the scenario requires. KMS and Parameter Store do not provide built-in secret rotation for database credentials.

Exam trap

CV0-004 often tests the overlap between KMS, Parameter Store, and Secrets Manager, so candidates pick KMS for 'secure storage' and miss that only Secrets Manager provides native automatic rotation.

How to eliminate wrong answers

Option A is wrong because AWS CloudHSM provides dedicated hardware security modules for key operations and compliance, but it does not store or rotate application secrets like database credentials. Option B is wrong because KMS manages encryption keys and can encrypt secrets, but it has no native secret-rotation feature for credentials. Option C is wrong because Systems Manager Parameter Store can hold SecureString values, but it lacks built-in automatic rotation and lifecycle management for database credentials, so rotation would have to be custom-built.

206
MCQeasy

A cloud administrator is responsible for a set of Linux virtual machines in AWS. The administrator needs to run a script on all of the instances at a scheduled time each night to rotate application logs. The script must run without the administrator logging in to each instance, and the administrator wants to avoid managing SSH keys for this task. Which AWS service should the administrator use?

A.AWS Trusted Advisor
B.AWS CloudTrail
C.AWS Systems Manager Run Command
D.AWS Config
AnswerC

Run Command is part of AWS Systems Manager and allows the administrator to run scripts or commands on managed instances without SSH access. It uses the Systems Manager agent and IAM permissions, so no SSH keys are needed. It can be scheduled through a maintenance window or EventBridge, satisfying the nightly execution requirement.

Why this answer

AWS Systems Manager Run Command is designed to run commands and scripts on managed instances at scale without requiring SSH access. It uses the Systems Manager agent and IAM roles for authentication, and it can be scheduled through maintenance windows or EventBridge rules, which matches the nightly log rotation requirement without SSH key management.

Exam trap

The trap here is assuming that any AWS service that observes or audits instances, such as CloudTrail or Config, can also execute operational tasks on them.

207
MCQeasy

A cloud engineer needs to deploy a stateless application across multiple availability zones. The application must scale horizontally based on CPU utilization. Which of the following is the BEST configuration?

A.Deploy a single large instance and increase its size as needed
B.Create an auto-scaling group spanning multiple zones with a load balancer
C.Use a managed container service and manually add containers
D.Deploy instances in one zone using spot instances to reduce cost
AnswerB

An auto-scaling group spanning multiple availability zones with a load balancer directly satisfies both constraints: horizontal scaling driven by CPU utilisation and resilience across zones. The load balancer distributes traffic to healthy instances, while the scaling group adds or removes capacity as demand changes.

Why this answer

An auto-scaling group spanning multiple availability zones ensures high availability and fault tolerance by distributing instances across zones, while the load balancer distributes traffic and the scaling policy adjusts capacity based on CPU utilization. This configuration meets the requirements for a stateless, horizontally scalable application without manual intervention.

Exam trap

A common trap is choosing vertical scaling (Option A) because it seems simpler, but it does not meet the requirement for multi-AZ distribution and automated horizontal scaling.

How to eliminate wrong answers

Option A is wrong because scaling vertically (increasing instance size) does not provide horizontal scalability or multi-AZ resilience, and it introduces a single point of failure. Option C is wrong because manually adding containers lacks automation and does not leverage auto-scaling based on CPU utilization, making it inefficient for dynamic workloads. Option D is wrong because deploying instances in a single zone with spot instances does not ensure multi-AZ fault tolerance, and spot instances can be terminated at any time, risking application availability.

208
MCQhard

A company is deploying a stateful application on AWS that requires a shared, POSIX-compliant file system that can be mounted on multiple Amazon EC2 instances simultaneously. The application also needs to support high throughput and must be durable across multiple Availability Zones. Which AWS storage service should the company use?

A.Amazon FSx for Windows File Server
B.Amazon EFS
C.Amazon EBS with Multi-Attach
D.Amazon S3
AnswerB

Amazon EFS is a fully managed, POSIX-compliant file system that can be mounted on multiple EC2 instances simultaneously. It is durable across multiple Availability Zones and supports high throughput with Bursting or Provisioned Throughput modes. EFS is designed for shared access and automatically scales. This matches the requirements for a shared file system with multi-AZ durability and high throughput.

Why this answer

Amazon EFS is the correct choice because it provides a POSIX-compliant, shared file system that can be mounted on multiple EC2 instances across multiple Availability Zones. It offers high throughput and durability, making it ideal for stateful applications requiring shared storage. Other options either do not support POSIX semantics or do not span multiple AZs.

Exam trap

The trap here is assuming that EBS Multi-Attach provides a shared file system, but it is block storage limited to a single AZ and requires a cluster file system.

209
MCQhard

A security analyst is investigating a potential data exfiltration from a cloud environment. The analyst finds that an instance IAM role was assumed by a compromised user, and the role has permissions to read from a sensitive database. What is the BEST way to prevent this type of attack in the future?

A.Enforce MFA for all users and require MFA when assuming the role.
B.Add a resource-based policy to the database to deny access from the role.
C.Rotate the IAM role's access keys every 30 days.
D.Remove the IAM role and use a service account instead.
AnswerA

Requiring MFA at role assumption adds a second authentication factor, so a compromised user's stolen credentials alone cannot assume the instance IAM role. This directly blocks the credential-based privilege escalation path that granted database read access, satisfying the prevention requirement.

Why this answer

The best because enforcing MFA for all users and requiring MFA when assuming roles ensures that even if a user's credentials are compromised, the attacker cannot assume the IAM role without also having access to the user's MFA device. This directly addresses the scenario. Option B is not the best because adding a resource-based policy to deny access from the role would break legitimate access and does not prevent the compromised user from assuming the role.

Option C is not the best because rotating the role's access keys every 30 days does not prevent an attacker from using the role's temporary credentials if they have already assumed the role; also, IAM roles do not have access keys; they issue temporary credentials. Option D is not the best because removing the IAM role and using a service account would not solve the underlying issue and could introduce other security risks.

210
MCQeasy

A cloud administrator needs to ensure that an Amazon S3 bucket containing regulated data logs every object-level access attempt, including reads and writes, for audit purposes. Which action should the administrator take?

A.Configure an S3 event notification to publish to Amazon SNS whenever an object is created in the bucket.
B.Enable S3 server access logging on the bucket and deliver the logs to a separate logging bucket.
C.Enable S3 Object Lock in governance mode on the bucket to prevent deletion of audit records.
D.Enable AWS CloudTrail data events for the S3 bucket and configure the trail to deliver to a log archive account.
AnswerD

CloudTrail data events capture object-level API activity such as GetObject and PutObject for the specified bucket, providing a reliable, structured audit record of every access attempt. Delivering the trail to a separate log archive account supports immutability and separation of duties, which is the expected pattern for regulated data.

Why this answer

AWS CloudTrail data events are the designated mechanism for recording object-level S3 API activity, including reads and writes, in a structured and reliable manner. Sending the trail to a dedicated log archive account strengthens the audit posture by separating log custody from the account being monitored.

Exam trap

The trap here is treating S3 server access logging or event notifications as equivalent to CloudTrail data events, when only the latter provides reliable object-level audit records.

211
Multi-Selectmedium

A company is using a PaaS offering to host a web application. Which THREE management responsibilities are retained by the customer? (Select THREE.)

Select 3 answers
A.Runtime environment
B.Application code
C.Operating system patches
D.Data and its security
E.Access and identity management
AnswersB, D, E

In PaaS, the provider manages the runtime, middleware, and operating system, but the customer still writes, deploys, and patches the application code itself. This retained responsibility satisfies the scenario's requirement to identify what the customer still manages.

Why this answer

In a PaaS model, the provider manages the platform stack (runtime, middleware, OS, virtualization), while the customer retains responsibility for what they deploy and control on top of it. Option B (Application code) is correct because the customer writes, deploys, and maintains the application itself, including its logic, dependencies, and updates. Option D (Data and its security) is correct because the customer owns the data, controls classification, encryption, backup, and access policies, even though the provider secures the underlying storage infrastructure.

Option E (Access and identity management) is correct because the customer manages user accounts, roles, authentication, and authorization for their application and data, typically via the provider's IAM tooling or federation. Option A (Runtime environment) is not retained by the customer, as the PaaS provider manages the language runtime, libraries, and execution environment. Option C (Operating system patches) is not retained by the customer, since the provider handles OS-level patching and maintenance in a PaaS offering.

Exam trap

CV0-004 often tests the shared responsibility model, and candidates frequently confuse provider-managed components (like runtime and OS) with customer-managed ones, leading them to incorrectly select options that are actually the provider's responsibility.

212
MCQmedium

A cloud administrator notices that an AWS IAM user has more permissions than necessary. Which principle should be applied to correct this?

A.Separation of duties
B.Defense in depth
C.Zero trust
D.Least privilege
AnswerD

Least privilege grants only the permissions required for a user's tasks, directly removing the excessive access the AWS IAM user currently holds. Unlike broader controls such as separation of duties, it targets permission scope itself, satisfying the stem's constraint of more permissions than necessary.

Why this answer

Least privilege means granting an identity only the permissions required to perform its task, and nothing more. When an IAM user has excessive permissions, the correct remediation is to scope the attached policies down to the minimum necessary, which is the definition of least privilege. The other principles address different security concerns and do not directly describe trimming excess permissions.

Exam trap

CV0-004 often tests the distinction between least privilege and zero trust, so candidates pick zero trust because it sounds modern, missing that the question is specifically about trimming excess IAM permissions.

How to eliminate wrong answers

Option A is wrong because separation of duties splits critical functions across different people to prevent fraud, which is about role design rather than reducing an individual's excess permissions. Option B is wrong because defense in depth layers multiple controls (network, host, application) and does not by itself describe removing unnecessary IAM permissions. Option C is wrong because zero trust is an architectural model that verifies every request regardless of network location; it is broader than the specific act of reducing an over-permissioned IAM user.

213
Multi-Selecthard

A cloud architect is evaluating a multi-cloud strategy to improve resilience. Which THREE factors should be considered when designing multi-cloud architecture? (Select THREE.)

Select 3 answers
A.Increased vendor lock-in
B.Data transfer costs between clouds
C.Ability to manage all clouds with a single API
D.Application portability and interoperability
E.Consistent security and compliance policies across clouds
AnswersB, D, E

Egress charges apply whenever data leaves a provider's network, so cross-cloud replication and failover traffic incur fees that single-cloud designs avoid. This directly addresses the resilience-versus-cost trade-off the architect must weigh, since continuous synchronisation between clouds multiplies billable egress volume.

Why this answer

Option B (Data transfer costs between clouds) is correct because multi-cloud designs frequently move data across provider boundaries, and egress charges plus inter-cloud transfer fees can significantly erode the cost benefits of a multi-cloud strategy, so they must be modeled during design. Option D (Application portability and interoperability) is correct because resilience in a multi-cloud architecture depends on workloads being able to run on more than one provider, which requires avoiding proprietary APIs and using portable formats such as containers, Kubernetes, and open standards. Option E (Consistent security and compliance policies across clouds) is correct because each provider implements identity, encryption, and logging differently, so a unified policy framework and controls such as federated IAM and centralized logging are needed to maintain a consistent security posture.

Option A (Increased vendor lock-in) is not a valid factor because multi-cloud is generally adopted to reduce dependence on a single vendor, not to increase lock-in. Option C (Ability to manage all clouds with a single API) is not a required design factor because no single universal API natively manages AWS, Azure, and GCP; management is typically achieved through abstraction layers, IaC tools like Terraform, or multi-cloud platforms rather than one provider API.

Exam trap

CV0-004 often tests multi-cloud design factors; candidates may incorrectly select vendor lock-in as a benefit or overlook the importance of data transfer costs and portability.

214
Multi-Selectmedium

Which TWO of the following are best practices for securing an API gateway in a cloud environment?

Select 2 answers
A.Implement rate limiting to control the number of requests per client.
B.Expose the API endpoints without authentication for ease of integration.
C.Return detailed error messages including stack traces to help developers.
D.Use API keys or OAuth for authentication and authorization.
E.Disable HTTPS to reduce latency.
AnswersA, D

Rate limiting caps requests per client within a defined window, mitigating brute-force credential stuffing, enumeration and denial-of-service floods that would otherwise exhaust gateway and backend capacity. It satisfies the stem's cloud constraint, where internet-exposed gateways face untrusted, high-volume traffic that must be throttled before reaching origin services.

Why this answer

Option A is correct because rate limiting throttles the number of requests a client can make in a given time window, mitigating brute-force attacks, credential stuffing, and denial-of-service abuse against the gateway. Option D is correct because API keys or OAuth 2.0 tokens enforce authentication and authorization, ensuring only verified and properly scoped clients can invoke backend services. Option B is wrong because exposing endpoints without authentication allows anonymous abuse and data exposure, which is never a best practice.

Option C is wrong because returning stack traces and detailed internal errors leaks implementation details useful to attackers; generic error messages should be returned instead. Option E is wrong because disabling HTTPS removes TLS encryption, exposing credentials and payloads to interception, and latency reduction does not justify that risk.

Exam trap

CompTIA often tests the misconception that 'detailed error messages help developers debug faster'—but in a cloud environment, exposing stack traces is a critical security flaw, not a best practice.

215
MCQhard

A cloud engineer is deploying a containerized microservices application on Google Kubernetes Engine. The team wants each pod to authenticate to Google Cloud APIs without embedding long-lived service account keys, and they want per-workload identity that can be granted least-privilege IAM roles. Which approach should the engineer implement?

A.Create a service account key JSON file and mount it as a Kubernetes Secret in each pod
B.Grant the Compute Engine default service account broad roles and let all pods share it
C.Enable Workload Identity and bind a Kubernetes service account to a Google service account
D.Store the service account credentials in Secret Manager and inject them at pod startup
AnswerC

Workload Identity federates Kubernetes service accounts with Google Cloud IAM, allowing pods to obtain short-lived access tokens through the metadata server without any static key files. Each Kubernetes service account maps to a Google service account, so IAM roles can be scoped per workload, satisfying the keyless authentication and least-privilege requirements for the microservices deployment.

Why this answer

Workload Identity is the GKE-native mechanism that lets pods impersonate a Google service account through short-lived federated tokens, eliminating static key files and enabling per-workload IAM bindings. The alternatives either reintroduce long-lived credentials or collapse identity to the node level, neither of which provides keyless, least-privilege access for individual microservices.

Exam trap

The trap here is treating secret storage or rotation as equivalent to eliminating long-lived credentials entirely.

216
MCQhard

A company is implementing a cloud governance strategy. They need to ensure that all resources are tagged with cost center and environment, and any untagged resources are automatically remediated. Which of the following best practices should be applied?

A.Implement role-based access control to restrict resource creation
B.Set up budget alerts to notify when costs exceed thresholds
C.Create a manual audit process to check tags weekly
D.Use policy-as-code to enforce tagging and automatically apply tags to untagged resources
AnswerD

Policy-as-code evaluates resource definitions against tagging rules and triggers automatic remediation, applying missing cost centre and environment tags. This enforces the governance requirement continuously rather than relying on manual audits, satisfying the automatic remediation constraint.

Why this answer

Policy-as-code (e.g., Azure Policy, AWS Config Rules, or Open Policy Agent) allows you to define tagging requirements declaratively and automatically remediate non-compliant resources. This approach enforces governance in real-time without manual intervention, ensuring all resources are tagged with cost center and environment as specified.

Exam trap

The trap here is that candidates often confuse manual audit processes (Option C) with automated governance, failing to recognize that policy-as-code provides the required automatic remediation in real-time.

How to eliminate wrong answers

Option A is wrong because role-based access control (RBAC) restricts who can create resources but does not automatically tag or remediate untagged resources. Option B is wrong because budget alerts notify when costs exceed thresholds but do not enforce tagging or remediate untagged resources. Option C is wrong because a manual audit process is reactive, time-consuming, and does not provide automatic remediation, which is required by the question.

217
MCQhard

A cloud operations team manages a multi-account AWS environment with AWS Organizations. They need a centralized, near-real-time view of security findings across all accounts and want the ability to automatically suppress findings that match approved exceptions. Which service should they use to aggregate and manage these findings?

A.AWS Config with a central aggregator in the delegated administrator account
B.AWS Security Hub with the organization-wide aggregation feature enabled
C.Amazon Detective with cross-account data ingestion from member accounts
D.AWS Trusted Advisor with organizational view enabled in the management account
AnswerB

Security Hub supports designating a delegated administrator account and aggregating findings from all member accounts into a single pane. It integrates findings from services like GuardDuty and Inspector and supports automation rules and suppression filters to mute findings matching approved exceptions, which directly satisfies the centralized visibility and suppression requirements described.

Why this answer

Security Hub is designed to aggregate and normalize findings from multiple AWS security services across an organization, and its automation rules and suppression filters allow approved exceptions to be muted. This combination of centralized aggregation with automated suppression matches the operational requirement precisely.

Exam trap

The trap here is confusing configuration compliance aggregation from AWS Config with runtime security findings aggregation, which are handled by different services.

218
MCQmedium

A cloud engineer wants to be notified when the average CPU utilization of an auto-scaling group exceeds 80% for 5 minutes. Which alerting mechanism should be used?

A.AWS Systems Manager OpsCenter
B.AWS Config rule
C.AWS Trusted Advisor
D.AWS CloudWatch Alarm
AnswerD

AWS CloudWatch Alarm evaluates metric thresholds over defined evaluation periods, so it directly satisfies the five-minute sustained average CPU condition. It monitors the auto-scaling group's aggregate metric and triggers notification actions when the 80% threshold is breached, unlike log-based or event-driven mechanisms that cannot assess rolling metric averages.

Why this answer

AWS CloudWatch Alarms are purpose-built to watch a metric (like the Average CPUUtilization of an Auto Scaling group) and trigger actions when a threshold is breached for a defined number of evaluation periods. Configuring an alarm with a threshold of 80%, a period of 300 seconds, and the appropriate statistic/datapoints-to-alarm directly satisfies the 'exceeds 80% for 5 minutes' requirement. Alarms can then notify via SNS, trigger Auto Scaling, or invoke actions.

Exam trap

CV0-004 often tests the distinction between monitoring/alerting services (CloudWatch) and configuration/compliance services (Config, Trusted Advisor), so candidates who see 'notify' and reach for a governance tool pick the wrong answer.

How to eliminate wrong answers

Option A is wrong because Systems Manager OpsCenter is an operational work-item aggregator for investigating and remediating issues, not a metric-threshold alerting engine. Option B is wrong because AWS Config rules evaluate resource configuration compliance (e.g., 'is encryption enabled?'), not real-time performance metrics like CPU utilization. Option C is wrong because Trusted Advisor provides best-practice checks and recommendations across cost, security, and fault tolerance — it does not monitor custom metric thresholds or send threshold-based alerts.

219
MCQhard

After reviewing the Terraform plan, a cloud administrator notices that the instance will be created with a public IP address. However, the company policy requires that all instances in this subnet remain private. What should the administrator do to meet the policy before applying the plan?

A.Add a shell command in user_data to remove the public IP after boot.
B.Use a different AMI that does not require public access.
C.Change the 'associate_public_ip_address' argument to 'false' in the resource block.
D.Modify the subnet_id to point to a private subnet with no internet gateway.
AnswerC

Setting `associate_public_ip_address` to `false` directly removes the public IP assignment from the instance's network interface, satisfying the policy that all instances in this subnet remain private. This argument controls the instance-level public addressing behaviour, so the plan no longer provisions a public address before apply.

Why this answer

Setting 'associate_public_ip_address' to false in the Terraform resource block explicitly prevents the instance from receiving a public IP address, directly adhering to the policy. Option A is wrong: using user_data to remove the public IP after boot is unreliable, creates a temporary exposure, and violates the principle of declarative infrastructure. Option B is wrong: the AMI choice does not control public IP assignment; that is determined by subnet settings and resource arguments.

Option D is wrong: changing to a private subnet might work if it disables auto-assign public IP, but it is unnecessary and could have other implications; the direct fix is to set the argument to false.

220
MCQmedium

A company is deploying a new version of a microservice on Amazon EKS. The deployment must ensure that new pods are created and become healthy before old pods are terminated. The current deployment uses a ReplicaSet. Which Kubernetes resource and strategy should be used?

A.ReplicaSet with RollingUpdate strategy
B.DaemonSet with RollingUpdate
C.Deployment with RollingUpdate strategy
D.StatefulSet with OnDelete strategy
AnswerC

RollingUpdate replaces pods incrementally, honouring maxSurge and maxUnavailable so new pods reach readiness before old ones terminate. A bare ReplicaSet cannot orchestrate this ordering during updates, so the Deployment controller is required to satisfy the zero-downtime constraint.

Why this answer

A Deployment manages ReplicaSets and supports a RollingUpdate strategy that creates new pods and waits for them to become ready before terminating old ones.

221
MCQeasy

A cloud administrator is deploying a new containerized workload on Google Kubernetes Engine in Google Cloud. The security team requires that the containers run with a non-root user, have a read-only root filesystem where possible, and are prevented from gaining additional Linux capabilities. Which GKE feature should the administrator enable to enforce these restrictions at the pod level?

A.Pod Security Admission with the restricted profile
B.Shielded GKE Nodes
C.Binary Authorization
D.Network Policy in GKE
AnswerA

Pod Security Admission with the restricted profile enforces hardened pod settings, including running as non-root, disallowing privilege escalation, dropping capabilities, and requiring a seccomp profile. Applying it at the namespace level ensures every pod meets the security team's baseline. It directly maps to the non-root, read-only, and no-new-capabilities requirements.

Why this answer

Pod Security Admission with the restricted profile enforces the exact pod-level controls requested: non-root execution, disallowing privilege escalation, dropping Linux capabilities, and requiring stricter seccomp and filesystem settings. Enabling it on the namespace applies the policy consistently across the workload.

Exam trap

The trap here is selecting a node-hardening or image-provenance feature when the requirement is specifically about runtime pod security context enforcement.

222
MCQmedium

A company wants to implement a disaster recovery strategy with an RTO of 15 minutes and an RPO of 1 hour for a critical application running on AWS. Which approach would best meet these requirements?

A.Continuous replication to a warm standby environment with automated failover
B.Backup to AWS S3 and restore using AWS CloudFormation
C.Cross-region replication with a read replica and manual promotion
D.Daily snapshots of EBS volumes to another region
AnswerA

Continuous replication to a warm standby keeps a running scaled-down copy current, so automated failover recovers within the 15-minute RTO while replication lag under one hour satisfies the RPO. Pilot light or backup-restore approaches cannot meet that recovery time.

Why this answer

Continuous replication to a standby environment with automatic failover provides the lowest RTO and RPO, meeting the requirements.

223
MCQeasy

A cloud engineer needs to deploy a serverless function that runs when a new object is uploaded to an S3 bucket. Which AWS service event trigger should be configured?

A.API Gateway
B.EventBridge
C.S3
D.SQS
AnswerC

S3 emits event notifications when objects are created, so configuring an S3 event trigger invokes the serverless function on upload. This directly satisfies the requirement that the function runs when a new object lands in the bucket, without polling.

Why this answer

Amazon S3 can directly invoke AWS Lambda when a new object is uploaded by configuring an S3 event notification on the bucket. This native integration allows the S3 service to trigger the function without any intermediary service, making option C the correct choice for a serverless function triggered by an S3 upload event.

Exam trap

Candidates often confuse direct service integrations (S3 → Lambda) with event bus patterns (EventBridge), where they may overcomplicate by choosing EventBridge when the native S3 trigger is simpler and sufficient.

How to eliminate wrong answers

Option A is wrong because API Gateway is a service for creating RESTful or WebSocket APIs to front-end applications or services, not for directly triggering functions from S3 events; it would require an additional integration layer. Option B is wrong because EventBridge is a serverless event bus for routing events between AWS services and custom applications, but S3 can send events directly to Lambda without needing EventBridge as an intermediary. Option D is wrong because SQS is a message queue service that decouples components, not a direct trigger for Lambda from S3; while S3 can send events to SQS, the queue would then need to be polled by a consumer, adding latency and complexity.

224
MCQhard

A cloud administrator is troubleshooting connectivity to a web server running on a Linux VM. The web server is configured to listen on ports 80 (HTTP) and 443 (HTTPS). The administrator runs the iptables command shown in the exhibit. Based on the output, what is the MOST likely reason that external users cannot access the web server on port 443?

A.The web server is not configured to listen on port 443, so iptables rules are irrelevant.
B.The iptables default policy is ACCEPT, but the rule for port 443 explicitly drops traffic from external sources.
C.The rule for port 80 is placed before the rule for port 443, causing all HTTPS traffic to be evaluated as HTTP and dropped.
D.The iptables rule for port 443 only allows traffic from the 10.0.0.0/8 subnet, which does not include external IP addresses.
AnswerD

The INPUT chain rule for port 443 specifies source 10.0.0.0/8, a private range covering only internal addresses. External users' public source IPs never match this criterion, so the packet is dropped before reaching the web server. Port 80 lacks this restriction, explaining why only HTTPS fails.

Why this answer

The iptables rule for port 443 specifies a source IP range of 10.0.0.0/8, which is a private RFC 1918 address space. External users have public IP addresses that do not fall within this subnet, so their HTTPS traffic is implicitly dropped by the rule's match condition. The default policy being ACCEPT does not override the explicit rule that only permits traffic from the 10.0.0.0/8 subnet.

Exam trap

The trap here is that candidates assume a default ACCEPT policy means all traffic is allowed, overlooking that an explicit rule with a restrictive source match will only permit traffic from that source, effectively denying all others by not matching.

How to eliminate wrong answers

Option A is wrong because the question states the web server is configured to listen on port 443, so the issue is not a misconfigured web server. Option B is wrong because the iptables output does not show an explicit DROP rule for port 443; instead, it shows an ACCEPT rule restricted to a specific source subnet, which implicitly drops all other traffic. Option C is wrong because iptables processes rules sequentially, but the rule for port 80 (HTTP) does not affect HTTPS traffic on port 443; each rule is evaluated independently based on protocol and port match.

225
MCQeasy

A cloud administrator notices that a load balancer is marking all instances as unhealthy. The health check is configured to check a specific URL path. Which of the following is the MOST likely cause?

A.The health check path does not exist on the instances.
B.The auto scaling group's minimum size is too low.
C.The security group for the instances blocks traffic from the load balancer.
D.The instances are under high CPU load.
AnswerA

The health check queries a specific URL path; if that path returns 404 or is absent, every instance fails the check and is marked unhealthy. The load balancer's probe therefore reports all instances down despite the instances themselves running.

Why this answer

The health check is configured to check a specific URL path. If that path does not exist on the instances (e.g., returns a 404 or 403 status), the load balancer will consider the instances unhealthy. This is the most direct cause because the health check relies on a successful HTTP response (typically 200 OK) from that exact path.

Exam trap

CompTIA often tests the distinction between connectivity issues (security groups, network ACLs) and application-level health check failures, leading candidates to incorrectly choose security group misconfiguration when the real issue is a missing or misconfigured health check endpoint.

How to eliminate wrong answers

Option B is wrong because the auto scaling group's minimum size affects the number of instances running, not the health check status of individual instances; a low minimum size could cause scaling issues but does not cause all instances to be marked unhealthy. Option C is wrong because if the security group blocked traffic from the load balancer, the instances would be unreachable entirely (e.g., connection timeout), not just fail a specific URL path health check. Option D is wrong because high CPU load might degrade performance but does not inherently cause the health check to fail unless the application crashes or the web server stops responding; the load balancer's health check is a simple HTTP request that typically succeeds even under moderate load.

Page 2

Page 3 of 12

Page 4