Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 226–300

834 questions total · 12pages · All types, answers revealed

Page 3

Page 4 of 12

Page 5
226
MCQmedium

An organization wants to automate patching of their EC2 instances running Windows Server. They need to schedule patching during a maintenance window and ensure minimal downtime. Which AWS service should they use?

A.AWS OpsWorks
B.Amazon Inspector
C.AWS CloudFormation
D.AWS Systems Manager Patch Manager
AnswerD

AWS Systems Manager Patch Manager automates Windows Server patching through patch baselines and maintenance windows, applying approved updates and reporting compliance. It minimises downtime by controlling reboot timing and concurrency, satisfying the scheduled maintenance-window requirement for EC2 instances.

Why this answer

AWS Systems Manager Patch Manager automates patching and can be scheduled via maintenance windows.

227
MCQhard

During a scheduled DR drill, the cloud team fails over a critical application to the secondary region. After the drill, the application is failed back. The application's RTO was 2 hours, but the actual failover took 2.5 hours. Which action should be taken to improve future failover times?

A.Increase the frequency of DR drills
B.Increase the bandwidth between regions for data replication
C.Automate the failover process using infrastructure as code and runbooks
D.Reduce the RTO to 1 hour to force faster execution
AnswerC

Automating failover with infrastructure as code and runbooks removes manual steps that inflated the 2.5-hour failover beyond the 2-hour RTO. Codified, repeatable orchestration provisions the secondary region and redirects traffic faster, directly cutting recovery time during future DR drills.

Why this answer

The failover exceeded RTO because manual steps introduced delay; automating the failover with infrastructure as code (IaC) and pre-defined runbooks removes human latency, ensures consistent execution order, and reduces the time to bring up the secondary region. Automation directly attacks the root cause of the 30-minute overrun — manual coordination and decision-making — and is the standard DR improvement after a drill reveals timing gaps. This aligns with the DR principle of 'test, measure, improve' by codifying the recovery process.

Exam trap

CV0-004 often tests the confusion between RTO/RPO tuning and process improvement, tempting candidates to pick 'reduce the RTO' or 'add bandwidth' when the real fix is automation of the failover workflow.

How to eliminate wrong answers

Option A is wrong because more frequent drills improve familiarity and reveal issues but do not inherently reduce failover time — the same manual steps still take the same duration. Option B is wrong because bandwidth affects data replication lag, not the failover orchestration time; the RTO overrun is about process, not pipe size. Option D is wrong because arbitrarily lowering the RTO target does not make the process faster — it only changes the goal and could create false compliance reporting without addressing the actual delay.

228
MCQeasy

A company wants to migrate its on-premises workload to the cloud and needs to maintain full control over the operating system, middleware, and applications. Which cloud service model should the company choose?

A.PaaS
B.FaaS
C.SaaS
D.IaaS
AnswerD

IaaS delivers raw compute, storage and networking while the customer retains control of the guest OS, middleware and applications. This satisfies the requirement for full control, unlike PaaS or SaaS, which abstract the operating system layer away from the customer.

Why this answer

IaaS provides the highest level of control among cloud service models, giving the customer direct management of the operating system, middleware, runtime, and applications while the provider manages the underlying virtualization, servers, storage, and networking. Because the company explicitly requires full control over OS, middleware, and applications, IaaS is the only model that grants this level of responsibility. AWS EC2, Azure VMs, and GCP Compute Engine are canonical IaaS examples.

Exam trap

The trap is equating 'control over applications' with PaaS or assuming any cloud migration implies managed services — candidates must recognize that full OS and middleware control is the defining characteristic of IaaS.

How to eliminate wrong answers

Option A is wrong because PaaS abstracts away the operating system and middleware, so the customer cannot maintain full control over those layers. Option B is wrong because FaaS (Function-as-a-Service) abstracts even more — the customer only supplies function code, with no OS or middleware control whatsoever. Option C is wrong because SaaS delivers a fully managed application where the customer controls only configuration and data, not the OS, middleware, or application code.

229
MCQhard

A company deploys a multi-tier application in a public cloud. The web tier uses an auto scaling group across multiple availability zones. The database tier runs on a single large VM. The application experiences intermittent slowdowns during peak load. Which of the following is the BEST long-term solution?

A.Migrate the database to a managed database service with read replicas
B.Add a load balancer in front of the database tier
C.Upgrade the database VM to a larger instance type
D.Increase the number of web servers in the auto scaling group
AnswerA

A managed database service with read replicas offloads read traffic from the single large VM, removing the database tier as the bottleneck during peak load. Auto scaling already handles the web tier, so the persistent constraint is the non-scalable database, which this migration addresses long term.

Why this answer

The database tier is a single point of failure and a performance bottleneck during peak load. Migrating to a managed database service with read replicas offloads read-heavy traffic, improves scalability, and provides automatic failover, addressing both performance and availability issues. This is a long-term solution that aligns with cloud best practices for multi-tier applications.

Exam trap

The trap here is that candidates often assume scaling the web tier (Option D) or vertically scaling the database (Option C) is sufficient, but CompTIA tests the understanding that the database tier is the bottleneck and requires a horizontally scalable, managed solution for long-term reliability and performance.

How to eliminate wrong answers

Option B is wrong because adding a load balancer in front of the database tier does not solve the underlying performance bottleneck; databases typically use connection pooling or direct connections, and a load balancer adds latency without addressing read scalability or write contention. Option C is wrong because upgrading the database VM to a larger instance type is a vertical scaling approach that has a hard limit and does not provide high availability or fault tolerance; it also incurs downtime during resizing and does not handle read-heavy workloads efficiently. Option D is wrong because increasing the number of web servers in the auto scaling group only addresses the web tier's capacity, not the database tier's inability to handle increased read/write requests, so the database remains the bottleneck.

230
Multi-Selectmedium

A cloud administrator is configuring network ACLs (NACLs) for a VPC subnet. The subnet hosts a web server that must accept HTTP (port 80) and HTTPS (port 443) from the internet, and the server needs to respond to clients. Which TWO rules are required?

Select 2 answers
A.Inbound rule: allow all ICMP from 0.0.0.0/0
B.Outbound rule: allow TCP port 80 and 443 to 0.0.0.0/0
C.Inbound rule: allow TCP ports 1024-65535 from 0.0.0.0/0
D.Outbound rule: allow TCP ports 1024-65535 to 0.0.0.0/0
E.Inbound rule: allow TCP port 80 and 443 from 0.0.0.0/0
AnswersD, E

Responses from the web server leave via ephemeral source ports 1024-65535, so the NACL needs an outbound rule permitting that range to 0.0.0.0/0. Without it, return traffic to internet clients is blocked and connections fail.

Why this answer

Option E is correct because the web server must accept inbound HTTP and HTTPS traffic from the internet, so the NACL needs an inbound rule permitting TCP ports 80 and 443 from 0.0.0.0/0. Option D is correct because NACLs are stateless, meaning return traffic is not automatically allowed; the server's responses to clients use ephemeral source ports in the 1024-65535 range, so an outbound rule allowing TCP ports 1024-65535 to 0.0.0.0/0 is required for the responses to reach clients. Option A is not required because ICMP is not needed for HTTP/HTTPS web service and is unrelated to the stated requirement.

Option B is wrong because outbound traffic from the server does not originate from ports 80/443; those are the listening ports, while responses use ephemeral ports. Option C is wrong because inbound client requests target destination ports 80/443, not the ephemeral range, so allowing 1024-65535 inbound would not satisfy the requirement.

Exam trap

CV0-004 often tests the stateless nature of NACLs — candidates incorrectly assume that allowing inbound 80/443 automatically permits return traffic, confusing NACLs with stateful security groups.

231
MCQmedium

A company uses GCP and wants to implement alerting based on anomaly detection for their Compute Engine instances. Which GCP service should they use?

A.Cloud Logging
B.Cloud Functions
C.Cloud Audit Logs
D.Cloud Monitoring
AnswerD

Cloud Monitoring provides alerting policies driven by anomaly-detection metrics, including forecast and outlier-based conditions, which satisfy the requirement for Compute Engine instance alerting. Unlike Cloud Logging, which handles log-based events, it evaluates time-series performance data directly, making it the appropriate service for detecting anomalous instance behaviour.

Why this answer

GCP's Cloud Monitoring (formerly Stackdriver) includes alerting policies that support anomaly detection. Cloud Logging is for logs. Cloud Audit Logs for auditing.

Cloud Functions can be triggered but not directly for anomaly detection.

232
MCQeasy

A cloud engineer is deploying a new web application on Google Cloud. The application must be reachable from the internet on HTTP and HTTPS, and the engineer wants Google's global edge network to terminate TLS and route users to the closest healthy backend. The backend instances should not be directly exposed to the internet. Which Google Cloud service should the engineer use?

A.Cloud CDN with a signed URL configuration pointing directly at the backend instance group.
B.A regional external passthrough Network Load Balancer with backend VMs that have public IP addresses.
C.Cloud Load Balancing with an external Application Load Balancer and a managed SSL certificate.
D.Cloud NAT with a regional external IP address, allowing backend instances to serve traffic directly.
AnswerC

An external Application Load Balancer is a global Layer 7 service that terminates TLS at Google's edge, routes requests to the nearest healthy backend, and supports managed certificates. Backends can be private instances, so they are not directly exposed to the internet, matching all stated requirements.

Why this answer

An external Application Load Balancer is the Google Cloud service that provides global Layer 7 load balancing, TLS termination with managed certificates, health-checked routing to the nearest backend, and private backends. Cloud NAT, passthrough network load balancing, and Cloud CDN each address different concerns and cannot fulfill the full set of requirements.

Exam trap

The trap here is confusing Cloud NAT, which handles outbound-only traffic, with a load balancer that accepts inbound client connections.

233
MCQmedium

A company wants to ensure that logs from their application are easily searchable and structured for analysis. Which logging format should be recommended?

A.JSON format
B.CSV format
C.Binary format
D.Plain text format
AnswerA

JSON stores each log entry as structured key-value pairs, so fields are parsed natively by log analytics platforms without regex extraction. This satisfies the searchability and structured-analysis requirement, whereas plain-text or syslog formats leave messages as unstructured strings that are harder to query reliably.

Why this answer

JSON is a structured, self-describing format with key-value pairs that log aggregation tools (Splunk, ELK, CloudWatch Logs Insights) can parse natively without custom regex. This makes logs easily searchable by field name and enables structured queries, filtering, and aggregation across large volumes.

Exam trap

CV0-004 often tests whether candidates confuse 'human-readable' (plain text) with 'machine-searchable' (JSON) — the trap is picking plain text because it looks simpler, missing that structured searchability is the requirement.

How to eliminate wrong answers

Option B is wrong because CSV is tabular and lacks nesting or schema flexibility — it cannot represent hierarchical log data (like nested error objects) and requires strict column alignment, making it brittle for evolving log schemas. Option C is wrong because binary format is not human-readable and requires specialized decoders, making ad-hoc searching and troubleshooting impractical. Option D is wrong because plain text is unstructured — while human-readable, it requires regex parsing to extract fields, which is error-prone and slow at scale, defeating the goal of easy searchability.

234
MCQmedium

A company is migrating a legacy monolithic application to the cloud. The application currently runs on a single server with 16 vCPUs and 64 GB RAM. The cloud architect recommends redesigning the application to be stateless and horizontally scalable. What is the primary benefit of this approach?

A.Lower storage costs
B.Simpler licensing costs
C.Improved fault tolerance and elasticity
D.Reduced network latency
AnswerC

Stateless, horizontally scalable designs let the platform add or replace instances independently, so a failed node does not lose session state and traffic redistributes automatically. This satisfies the fault tolerance and elasticity benefit, unlike the single-server monolith's fixed capacity and single point of failure.

Why this answer

Redesigning a monolithic application to be stateless and horizontally scalable primarily improves fault tolerance and elasticity. Stateless components can be replicated across multiple instances, so if one fails, others continue to serve requests. Horizontal scaling allows the application to handle varying loads by adding or removing instances dynamically.

Exam trap

CV0-004 often tests the benefits of stateless design, and candidates may choose reduced network latency or lower storage costs, which are not primary benefits; the key is fault tolerance and elasticity.

How to eliminate wrong answers

Option A is wrong because lower storage costs are not the primary benefit of statelessness; storage costs depend on data volume and type. Option B is wrong because simpler licensing costs are not directly related to stateless design; licensing may become more complex with more instances. Option D is wrong because reduced network latency is not guaranteed by horizontal scaling; in fact, distributing instances may increase latency due to network hops.

235
MCQmedium

A cloud engineer is deploying a containerized application on Kubernetes. The security team requires that containers run with reduced privileges and that certain capabilities are dropped. Which Kubernetes feature should be used to enforce these requirements?

A.Pod Security Standards
B.Network policies
C.ConfigMap
D.Horizontal Pod Autoscaler
AnswerA

Pod Security Standards define the Privileged, Baseline and Restricted profiles, with Restricted enforcing reduced privileges and dropped capabilities such as NET_RAW. Applying these via namespace labels or admission control satisfies the security team's container hardening requirement.

Why this answer

Pod Security Standards (PSS) define three levels (Privileged, Baseline, Restricted) that enforce security controls, including running containers with reduced privileges and dropping capabilities. The Restricted policy specifically requires dropping all capabilities and running as non-root, among other restrictions. Therefore, PSS is the correct feature to enforce these requirements.

Exam trap

The trap is confusing Pod Security Standards with other Kubernetes features like Network Policies or RBAC; candidates might think Network Policies control container privileges, but they only control network traffic.

How to eliminate wrong answers

Option B is wrong because Network policies control network traffic between pods, not container privileges or capabilities. Option C is wrong because ConfigMaps are used to store configuration data, not to enforce security policies. Option D is wrong because Horizontal Pod Autoscaler automatically scales the number of pods based on metrics, not security settings.

236
MCQmedium

A cloud administrator needs to centralize logs from multiple cloud provider accounts and on-premises servers for security analysis. Which approach should be used?

A.Create a serverless function that copies logs from each account to a central storage bucket in a management account
B.Enable virtual network flow logs in each account and store them locally
C.Use configuration compliance rules to aggregate logs into a single account
D.Configure each account's API activity logging to deliver logs to a central storage bucket, and use a log collection agent on on-premises servers to send logs to a central log service
AnswerD

Delivering each account's API activity logs to a central storage bucket, plus a collection agent forwarding on-premises server logs to a central log service, unifies cloud and on-premises sources. This hybrid aggregation satisfies the requirement to centralise logs across multiple accounts and on-premises servers for security analysis.

Why this answer

The correct approach is to configure each cloud account's API activity logging (e.g., AWS CloudTrail, Azure Activity Log, GCP Audit Logs) to deliver logs to a central storage bucket, and use a log collection agent on on-premises servers to forward logs to a central log service. This centralizes logs from both cloud and on-premises sources for unified security analysis.

Exam trap

CV0-004 often tests whether candidates confuse local log storage or configuration compliance with true centralized log aggregation — the trap is picking an option that sounds like it collects logs but actually stores them locally or does not cover on-premises sources.

How to eliminate wrong answers

Option A is wrong because a serverless function copying logs is a custom, point-to-point solution that does not scale well and lacks native delivery guarantees; it also does not address on-premises servers. Option B is wrong because enabling virtual network flow logs and storing them locally in each account does not centralize logs — it fragments them, defeating the purpose of centralized security analysis. Option C is wrong because configuration compliance rules evaluate resource configurations; they do not aggregate logs into a single account.

237
MCQhard

A company uses a cloud-based load balancer to distribute traffic to a fleet of web servers. Users report intermittent timeouts. The administrator reviews the load balancer logs and notices that one backend server has a significantly higher error rate than the others. Which of the following is the BEST course of action?

A.Immediately add two more backend servers to distribute the load.
B.Drain connections to the unhealthy server and troubleshoot its configuration.
C.Enable sticky sessions on the load balancer to maintain user sessions.
D.Increase the health check interval for all servers to reduce false positives.
AnswerB

Draining gracefully stops new sessions reaching the failing backend while allowing in-flight requests to complete, then isolates it for configuration troubleshooting. This removes the error source without dropping active user connections, satisfying the requirement to resolve intermittent timeouts.

Why this answer

Draining connections from the unhealthy server allows the load balancer to stop sending new traffic to it while existing sessions complete, preventing further timeouts. Troubleshooting the server's configuration addresses the root cause of the high error rate, such as misconfigured web server software, resource exhaustion, or application bugs. This approach follows the principle of isolating and resolving the faulty component rather than masking the issue with workarounds.

Exam trap

CompTIA often tests the misconception that adding more servers or increasing health check intervals will solve performance issues, but the trap here is that the problem is a specific faulty backend server, not a capacity or health check sensitivity issue, so the correct action is to isolate and troubleshoot that server.

How to eliminate wrong answers

Option A is wrong because adding more backend servers does not fix the underlying problem with the unhealthy server; it only distributes load away from it temporarily, and the faulty server will continue to serve errors to any traffic it receives. Option C is wrong because enabling sticky sessions (session persistence) would lock users to the unhealthy server, worsening the timeouts for those users and increasing error rates. Option D is wrong because increasing the health check interval makes the load balancer less responsive to failures, allowing the unhealthy server to remain in the pool longer and serve more errors before being marked down.

238
Multi-Selecthard

A cloud administrator is reviewing the security posture of a cloud deployment. The company has a policy of least privilege and must ensure that only authorized services can access storage buckets. Which THREE mechanisms should the administrator configure to enforce this policy? (Choose three.)

Select 3 answers
A.Network ACLs that block unauthorized IP ranges
B.Bucket policies that restrict access to specific cloud services
C.Organizational policies that restrict permissions at the account level
D.IAM roles that grant permissions to services requiring access
E.Security groups that allow traffic from authorized services
AnswersB, C, D

Bucket policies are resource-based JSON documents attached directly to the bucket, letting you scope access to named service principals. This enforces least privilege at the storage layer itself, satisfying the requirement that only authorised services reach the buckets, independent of any IAM role attached to a compute resource.

Why this answer

Bucket policies (B) are resource-based policies attached directly to the storage bucket that can explicitly allow or deny access to specific cloud services or principals, enforcing least privilege at the bucket level. Organizational policies (C) apply service control policies (SCPs) or similar guardrails at the account/organization level, restricting the maximum permissions any principal can have, which prevents unauthorized services from ever gaining bucket access. IAM roles (D) grant scoped, temporary credentials to the specific services that need access, so only those services receive the permissions required, aligning with least privilege.

Network ACLs (A) and security groups (E) are network-layer controls that filter IP traffic; they do not govern identity-based or resource-based authorization to storage buckets, so they cannot enforce which services are authorized to access the buckets.

Exam trap

The trap here is that candidates often confuse network-level controls (ACLs and security groups) with identity-based controls, assuming they can restrict service access to storage buckets, but these mechanisms cannot enforce service identity and are not applicable to cloud storage services.

239
MCQmedium

A DevOps team is setting up a CI/CD pipeline using GitHub Actions. They want the pipeline to automatically deploy a containerized application to a Kubernetes cluster only when changes are pushed to the main branch. Which GitHub Actions component should they use to trigger the deployment?

A.A cron job that checks the repository every hour
B.A GitHub webhook configured in the repository settings
C.A pull request review requirement
D.A workflow with an on.push trigger for the main branch
AnswerD

The on.push trigger with a main branch filter causes the workflow to run only when commits are pushed to main, satisfying the conditional deployment requirement. This event-driven trigger is the GitHub Actions component that initiates the pipeline at the correct moment.

Why this answer

GitHub Actions workflows are defined in YAML and can include an 'on' trigger specifying events such as push to a branch. This allows automation of the deployment when code is pushed to main.

240
MCQmedium

A company is experiencing increased traffic to its web application. They want to handle the load by adding more web server instances behind a load balancer. This approach is known as:

A.Stateless design
B.Horizontal scaling
C.Auto-scaling
D.Vertical scaling
AnswerB

Horizontal scaling adds more server instances to the pool behind the load balancer, distributing increased traffic across them. Vertical scaling instead increases the CPU, memory or other resources of an existing instance, which does not match adding instances.

Why this answer

Horizontal scaling (scaling out) means adding more instances of a resource — here, additional web servers behind a load balancer — to distribute increased traffic across multiple nodes. This increases capacity by adding parallel units rather than making a single server more powerful, which is exactly what the scenario describes.

Exam trap

The trap is conflating horizontal scaling (adding instances) with auto-scaling (the automation that performs it) or vertical scaling (adding resources to one host) — the question asks for the approach, not the trigger mechanism.

How to eliminate wrong answers

Option A is wrong because stateless design is an architectural property that makes horizontal scaling easier (no session affinity needed), but it is not the act of adding servers itself. Option C is wrong because auto-scaling is the automation mechanism that triggers scaling actions based on metrics; the question describes the scaling approach, not the automation policy. Option D is wrong because vertical scaling means adding CPU, RAM, or other resources to a single existing server (scaling up), which does not involve adding more instances behind a load balancer.

241
MCQmedium

A security team needs to enforce multi-factor authentication (MFA) for all users accessing the cloud management console. Which IAM feature should be configured?

A.IAM role
B.Condition in IAM policy requiring MFA
C.Resource-based policy
D.Password policy
AnswerB

An IAM policy condition evaluating the MFA claim denies console access unless the principal authenticated with a second factor, satisfying the requirement to enforce MFA for all management-console users. The condition is evaluated at request time, so unauthenticated sessions are blocked before any action is permitted.

Why this answer

A condition in an identity policy can require the presence of multi-factor authentication, enforcing MFA for access to the cloud management console. This is a standard mechanism to mandate MFA at the policy level, ensuring users must authenticate with a second factor before accessing the console.

Exam trap

A common misconception is that password policies can enforce MFA, but password policies only control password attributes, not the second authentication factor required by MFA.

How to eliminate wrong answers

Option A is wrong because an IAM role is used to delegate permissions to entities (like EC2 instances or federated users) and does not inherently enforce MFA; it can be assumed without MFA unless a condition is added. Option C is wrong because a resource-based policy (e.g., an S3 bucket policy) controls access to specific resources, not the cloud management console itself, and cannot enforce MFA for console login. Option D is wrong because a password policy only governs password complexity and rotation rules, not multi-factor authentication; MFA enforcement requires a separate IAM policy condition.

242
MCQhard

A company's cloud environment uses Azure Active Directory for identity management. They want to allow employees to sign in using their existing on-premises Active Directory credentials without synchronizing passwords to the cloud. Which federation protocol should they use?

A.LDAP
B.Kerberos
C.OAuth 2.0
D.SAML 2.0
AnswerD

SAML 2.0 federates identity so Microsoft Entra ID trusts authentication assertions from on-premises Active Directory, letting employees sign in with existing credentials. This satisfies the stem's no-password-synchronisation constraint, unlike password hash synchronisation, which replicates credentials to the cloud.

Why this answer

SAML 2.0 is the correct choice because it is a federation protocol designed for web-based single sign-on (SSO), allowing Azure AD to trust authentication assertions issued by on-premises Active Directory Federation Services (AD FS) without replicating password hashes to the cloud. Azure AD supports SAML 2.0 as a federated identity provider, so users authenticate on-premises and receive a signed token that Azure AD accepts. This satisfies the requirement of using existing AD credentials without password synchronization.

Exam trap

CV0-004 often tests the confusion between authentication protocols (Kerberos, LDAP) and federation protocols (SAML, WS-Federation, OpenID Connect), tricking candidates into picking Kerberos because it is the native AD protocol.

How to eliminate wrong answers

Option A is wrong because LDAP is a directory access protocol used for querying and modifying directory data, not for federated web SSO between identity providers. Option B is wrong because Kerberos is a ticket-based authentication protocol used within a domain (or with cross-realm trusts), not a federation protocol for cloud SSO with Azure AD. Option C is wrong because OAuth 2.0 is an authorization framework for delegated access to APIs, not an authentication/federation protocol for signing users into Azure AD with on-premises credentials.

243
MCQmedium

A cloud administrator needs to ensure that a set of AWS EC2 instances can only be accessed via SSH from the corporate office IP range 203.0.113.0/24. Which configuration should the administrator implement?

A.Create a security group with an inbound rule allowing TCP port 22 from 203.0.113.0/24
B.Deploy a VPN and require all SSH traffic to go through it
C.Configure a network ACL with an inbound allow rule for TCP port 22 from 203.0.113.0/24
D.Use AWS WAF to block SSH traffic except from 203.0.113.0/24
AnswerA

Security groups are stateful, instance-level virtual firewalls whose inbound rules filter by protocol, port and source CIDR. Allowing TCP 22 solely from 203.0.113.0/24 restricts SSH to the corporate range, satisfying the stated access constraint without affecting other traffic.

Why this answer

A security group acts as a stateful virtual firewall for EC2 instances. By specifying the source IP range 203.0.113.0/24 on the inbound SSH rule, only traffic from that range is allowed. Security groups are stateful, so return traffic is automatically permitted.

244
MCQmedium

A cloud administrator needs to deploy a web application in a public cloud. The application must automatically scale out based on CPU utilization and scale in during low demand. Which of the following is the BEST approach?

A.Configure an auto scaling group with a scaling policy based on average CPU utilization
B.Use a script to increase the instance size when CPU exceeds 80%
C.Implement scheduled scaling to add instances during business hours
D.Create a load balancer and manually add instances during peak hours
AnswerA

Auto scaling with CPU metric provides automated horizontal scaling.

Why this answer

An auto scaling group with a scaling policy based on average CPU utilization is the best approach because it dynamically adjusts the number of instances in response to real-time demand. This method uses CloudWatch metrics to trigger scale-out when CPU exceeds a threshold (e.g., 70%) and scale-in when it drops, ensuring the application remains responsive while minimizing cost during low usage.

Exam trap

CompTIA often tests the distinction between horizontal scaling (adding/removing instances) and vertical scaling (resizing instances), where candidates mistakenly choose vertical scaling (Option B) because it seems simpler, but it does not provide the elasticity required for cloud-native applications.

How to eliminate wrong answers

Option B is wrong because increasing the instance size (vertical scaling) does not provide the horizontal scaling required for distributed load handling and can cause downtime during resizing; it also does not automatically scale in. Option C is wrong because scheduled scaling assumes predictable traffic patterns and cannot adapt to unexpected spikes or lulls in CPU utilization, which is the specified trigger. Option D is wrong because manually adding instances during peak hours is not automated and defeats the purpose of elastic scaling, leading to potential delays and human error.

245
Multi-Selectmedium

Which TWO of the following are common causes of performance degradation in a cloud-based application?

Select 2 answers
A.Over-provisioned virtual machines
B.Resource contention from other tenants on the same hypervisor (noisy neighbor)
C.Load balancer distributing traffic evenly
D.Insufficient IOPS on the storage volume
E.Insufficient bandwidth to the cloud provider
AnswersB, D

Noisy neighbor is a classic cloud performance issue.

Why this answer

Resource contention, commonly known as the 'noisy neighbor' effect, occurs when multiple virtual machines (VMs) on the same hypervisor compete for shared physical resources such as CPU caches, memory bandwidth, and disk I/O. This contention can cause unpredictable performance degradation in a cloud-based application, as one tenant's heavy workload starves others of resources. Cloud providers often mitigate this using CPU pinning, I/O throttling, or dedicated instances, but without such controls, noisy neighbors remain a common cause of performance issues.

Exam trap

CompTIA often tests the misconception that over-provisioning (Option A) causes performance degradation, but in cloud environments, over-provisioning leads to cost inefficiency, not performance loss, while under-provisioning is the actual performance risk.

246
MCQhard

A cloud engineer is investigating why an application hosted on Amazon EC2 cannot connect to an Amazon RDS for MySQL database in the same VPC. The database security group allows traffic on port 3306 from the application's security group. The engineer confirms the application is using the correct endpoint and credentials. Which action should the engineer take NEXT to identify the cause?

A.Modify the RDS security group to allow 0.0.0.0/0 on port 3306 to rule out a security group issue.
B.Verify the network ACLs on the database subnet allow inbound and outbound traffic on the required ephemeral ports.
C.Reboot the RDS instance to clear any stale connection state and retest connectivity.
D.Check whether the EC2 instance has a public IP address and attach an Elastic IP to ensure outbound connectivity.
AnswerB

Network ACLs are stateless and evaluate inbound and outbound rules separately, so return traffic to the client uses ephemeral ports that must be explicitly allowed on the outbound side. A common cause of a blocked connection, even when security groups permit it, is an NACL that denies the response traffic or the database port. Checking NACLs is the logical next diagnostic step.

Why this answer

Because the security group already permits the database port from the application's security group, the remaining likely culprit is a stateless network ACL that blocks the request or the ephemeral return traffic. Network ACLs require explicit rules in both directions, unlike stateful security groups. Verifying NACL rules on the database subnet is the correct next step before making any disruptive or risky changes.

Exam trap

The trap here is overlooking that network ACLs are stateless, so the ephemeral return traffic must be explicitly permitted, unlike stateful security group behavior.

247
MCQhard

A company uses Azure DevOps to deploy a critical application. They need to implement a deployment strategy that ensures zero downtime by directing all traffic to the new environment after validation, while keeping the old environment as a fallback. Which deployment strategy should be configured in the Azure Pipelines release pipeline?

A.Canary deployment
B.In-place deployment
C.Blue/green deployment
D.Rolling deployment
AnswerC

Blue/green deployment keeps the existing environment live while the new one is validated, then switches all traffic at once. The old environment remains available for rollback, delivering the zero-downtime cutover with fallback that the release pipeline requires.

Why this answer

Blue/green deployment is the correct strategy because it maintains two identical environments (blue and green) and switches the router or load balancer to direct all traffic to the new (green) environment only after validation is complete. The old (blue) environment remains untouched and can serve as an immediate fallback if issues arise, ensuring zero downtime during the cutover.

Exam trap

CompTIA often tests the distinction between canary and blue/green by emphasizing 'gradual traffic shift' versus 'instant full cutover with fallback,' leading candidates to confuse canary's incremental rollout with the zero-downtime fallback requirement.

How to eliminate wrong answers

Option A is wrong because canary deployment gradually shifts a small percentage of traffic to the new version before full rollout, which does not guarantee zero downtime for all users during the initial validation phase and does not keep the old environment as a full fallback. Option B is wrong because in-place deployment updates the existing environment directly, causing downtime during the update process and no fallback environment is preserved. Option D is wrong because rolling deployment replaces instances incrementally, which can cause temporary capacity reduction or version mismatch during the update, and it does not maintain a complete fallback environment.

248
Multi-Selecthard

A cloud team uses Azure Bicep for deploying resources. They need to create a modular deployment that includes a virtual network and a subnet. Which THREE best practices should they follow when authoring Bicep files? (Choose three.)

Select 3 answers
A.Use hard-coded resource names to ensure consistency.
B.Use modules to encapsulate and reuse resource definitions.
C.Use symbolic names for resources to reference them elsewhere in the file.
D.Use parameters for configurable values like address prefixes.
E.Define all resources in a single file for simplicity.
AnswersB, C, D

Modules let the virtual network and subnet definitions be encapsulated into reusable files, so the parent deployment references them rather than duplicating code. This directly satisfies the modular deployment requirement, keeping each resource definition scoped and independently maintainable.

Why this answer

Using parameters for configurable values, using modules for reuse, and using symbolic names for resource references are best practices.

249
MCQeasy

A cloud application returns HTTP 503 errors during high traffic. The application runs on VMs behind a load balancer. Which action is most likely to resolve the issue?

A.Restart the web server service on one VM.
B.Change the DNS TTL to a lower value.
C.Increase the health check interval on the load balancer.
D.Add additional VMs to the backend pool.
AnswerD

HTTP 503 signals backend capacity exhaustion, so the load balancer has healthy targets but insufficient compute. Adding VMs to the backend pool increases aggregate capacity to absorb the traffic spike, directly addressing the overload causing the errors.

Why this answer

HTTP 503 Service Unavailable during high traffic indicates that the backend servers cannot handle the current load, often because all VMs are saturated or the load balancer has no healthy backends. Adding additional VMs to the backend pool increases capacity and distributes the load, directly addressing the root cause. This is the standard horizontal scaling response to traffic-induced 503 errors.

Exam trap

CV0-004 often tests whether candidates confuse DNS or health-check tuning with actual capacity scaling — the trap is picking a 'quick fix' like restarting a server instead of addressing the root cause of insufficient backend capacity.

How to eliminate wrong answers

Option A is wrong because restarting the web server on one VM may temporarily clear the error but does not increase capacity — the remaining VMs will still be overwhelmed under high traffic. Option B is wrong because lowering DNS TTL affects how quickly DNS changes propagate, but it does not add capacity or resolve backend overload. Option C is wrong because increasing the health check interval makes the load balancer check backends less frequently, which could actually delay detection of unhealthy nodes and worsen the situation — it does not add capacity.

250
Multi-Selecteasy

Which TWO of the following are best practices when configuring a cloud-based virtual private cloud (VPC) for a multi-tier application?

Select 2 answers
A.Place each application tier in a separate subnet.
B.Disable VPC flow logs to reduce costs.
C.Use the default security group for all instances.
D.Place all instances in the same subnet for simplicity.
E.Restrict SSH access to management IP addresses using security groups.
AnswersA, E

Separate subnets per tier let you apply distinct firewall rules and routing between web, application and database layers, enforcing least-privilege segmentation. This directly satisfies the multi-tier isolation requirement rather than leaving all tiers sharing one flat subnet.

Why this answer

Option A is correct because placing each application tier (e.g., web, application, and database tiers) in a separate subnet enables proper network segmentation, allowing you to apply distinct routing, NACLs, and security group rules per tier, which limits lateral movement if one tier is compromised. Option E is correct because restricting SSH (TCP port 22) access to specific management IP addresses via security groups follows the principle of least privilege, preventing brute-force and unauthorized access from the public internet. Options B, C, and D are not best practices: disabling VPC flow logs removes valuable audit and troubleshooting visibility into accepted and rejected traffic; using the default security group for all instances typically allows overly permissive intra-group traffic and violates least privilege; and placing all instances in a single subnet eliminates tier isolation and exposes all components to the same network-level access, increasing blast radius.

Exam trap

CompTIA often tests the misconception that simplicity (placing all instances in one subnet) is a best practice, when in fact proper segmentation is critical for security and compliance in multi-tier architectures.

251
MCQhard

A financial services company runs a multi-tenant SaaS application on AWS. Each tenant has dedicated Amazon RDS for MySQL databases. The security team must ensure that data at rest is encrypted with keys that are unique per tenant and that the company can independently audit key usage. Which approach should be used?

A.Use a single customer managed key (CMK) in AWS KMS for all RDS instances
B.Use client-side encryption with a per-tenant key stored in the application
C.Use a separate customer managed key (CMK) in AWS KMS for each tenant's RDS instance
D.Use AWS managed keys (aws/rds) for each RDS instance
AnswerC

Creating a unique CMK per tenant in AWS KMS allows each RDS instance to be encrypted with its own key. The company can audit key usage separately through CloudTrail, meeting the audit requirement. This provides strong isolation: compromise of one key does not affect other tenants. It also enables per-tenant key rotation and access policies.

Why this answer

Using a separate AWS KMS customer managed key for each tenant's RDS instance provides unique encryption keys per tenant, enabling strong isolation and independent auditability. CloudTrail logs each key's usage, so the security team can track which key encrypted which database and when. This meets both the security and compliance requirements without application-level complexity.

Exam trap

The trap here is assuming that a single CMK or AWS managed keys provide sufficient isolation, when the requirement explicitly demands unique keys per tenant and independent auditing.

252
MCQmedium

An automated snapshot of a cloud VM is failing with the error 'Quota exceeded for resource snapshots'. What is the most likely cause?

A.The snapshot is being created during a backup window.
B.The maximum number of snapshots allowed has been reached.
C.The snapshot retention policy is set too high.
D.The VM's disk is too full to create a snapshot.
AnswerB

The subscription's snapshot quota has been exhausted, meaning the maximum number of snapshots permitted for that region or resource group is already allocated. The error explicitly names the quota for the snapshots resource, so the limit itself is the blocker. Deleting unused snapshots or requesting a quota increase resolves the failure.

Why this answer

The error 'Quota exceeded for resource snapshots' directly indicates that the cloud provider's limit on the number of snapshots for that resource (e.g., per volume, per region, or per account) has been reached. Cloud platforms enforce quotas to prevent resource exhaustion, and once the maximum count is hit, further snapshot creation fails until older snapshots are deleted or a quota increase is requested. This is a hard limit, not a transient condition like a backup window or disk fullness.

Exam trap

CV0-004 often tests the distinction between quota limits and other snapshot failure causes, so candidates may confuse retention policies or disk space with the actual quota error.

How to eliminate wrong answers

Option A is wrong because backup windows are scheduling constructs and do not cause quota errors; snapshots can be taken at any time unless restricted by policy, but the error explicitly mentions quota. Option C is wrong because a retention policy controls how long snapshots are kept, not how many can exist at once; a high retention policy could indirectly lead to hitting the quota, but the error itself is about the quota limit, not the policy setting. Option D is wrong because a full disk might cause snapshot failures due to lack of space for delta changes, but the error message would indicate insufficient space or I/O errors, not a quota exceeded condition.

253
Multi-Selectmedium

A cloud engineer is deploying a new application on AWS and needs to ensure that the deployment is highly available and can withstand the failure of a single Availability Zone. The application uses an Application Load Balancer (ALB) and an Auto Scaling group. Which two configurations should the engineer implement to meet these requirements? (Choose two.)

Select 2 answers
A.Attach an Elastic IP address to each instance in the Auto Scaling group.
B.Enable cross-zone load balancing on the ALB.
C.Configure the Auto Scaling group to span at least two Availability Zones.
D.Set the Auto Scaling group to use a single instance type.
E.Configure the ALB to use a single Availability Zone for simplicity.
AnswersB, C

Cross-zone load balancing allows the ALB to distribute traffic evenly across all registered targets in all enabled Availability Zones. Without it, traffic is distributed only to targets in the same AZ as the load balancer node, which can lead to uneven load and reduced fault tolerance. Enabling cross-zone load balancing ensures that if one AZ fails, the remaining AZs handle the full load.

Why this answer

To achieve high availability and withstand an AZ failure, the Auto Scaling group must span multiple Availability Zones, and the ALB should have cross-zone load balancing enabled. These two configurations ensure that if one AZ becomes unavailable, the remaining AZs continue to serve traffic and the load balancer distributes requests evenly across all healthy targets.

Exam trap

The trap here is thinking that assigning Elastic IPs or using a single instance type improves availability, when the real requirements are multi-AZ distribution and cross-zone load balancing.

254
MCQmedium

A cloud engineer needs to implement a solution to automatically scale an application based on the number of messages in an SQS queue. The goal is to keep the queue length short. Which Auto Scaling policy type should the engineer use?

A.Step scaling
B.Simple scaling
C.Scheduled scaling
D.Target tracking scaling
AnswerD

Target tracking scaling adjusts capacity to hold a chosen metric, such as queue length, at a specified target value. This directly keeps the SQS queue short, unlike simple or step scaling, which react only to fixed thresholds.

Why this answer

Target tracking scaling is ideal when you want to maintain a metric at a target value — here, keeping SQS queue length (ApproximateNumberOfMessagesVisible) at a low target. Auto Scaling automatically adjusts capacity to keep the metric near the target, which directly satisfies the goal of keeping the queue short. It's the recommended policy for queue-depth-driven scaling.

Exam trap

CV0-004 often tests the mapping of 'keep a metric at a target' to target tracking, so candidates who see 'SQS queue' and reach for step scaling because it's 'more granular' pick the wrong policy.

How to eliminate wrong answers

Option A is wrong because step scaling requires you to define explicit threshold ranges and adjustments, which is more manual and less suited to the dynamic, continuous goal of 'keep the queue short.' Option B is wrong because simple scaling only supports a single adjustment per alarm with a cooldown, making it too coarse for queue-depth control. Option C is wrong because scheduled scaling is time-based and cannot react to real-time queue length changes.

255
MCQhard

A cloud engineer is investigating why a nightly batch job on Amazon EC2 takes far longer than expected. CloudWatch shows the instance's CPU and memory usage are low throughout the run, but the job performs many small reads against an Amazon EBS gp3 volume. The engineer wants to reduce the time the job spends waiting on storage. Which action should the engineer take?

A.Resize the instance to a larger instance type with more vCPUs so the job can issue more concurrent read requests.
B.Move the volume to an instance store device so reads are served from local NVMe storage.
C.Increase the provisioned IOPS and throughput settings of the gp3 volume to match the job's small-read workload.
D.Create a snapshot of the volume and restore it as a new volume, then reattach it to the instance.
AnswerC

gp3 volumes have independently configurable IOPS and throughput, and a workload dominated by many small reads is limited by IOPS rather than capacity. Raising provisioned IOPS lets the volume service more read operations per second, directly reducing the storage wait that is stretching the batch job's runtime while CPU and memory remain idle.

Why this answer

The job is storage-bound, not compute-bound, and the read pattern is dominated by many small operations. On gp3, IOPS and throughput are provisioned separately from capacity, so raising the provisioned IOPS increases the rate of read operations the volume can sustain, cutting the wait time. Instance resizing, snapshot restore, and instance store do not correct the volume's operation rate.

Exam trap

The trap here is seeing low CPU and assuming the fix is a bigger instance, when low CPU with high storage wait points to a volume IOPS limit instead.

256
MCQeasy

A company hosts its critical applications on a cloud provider's virtual machines within a virtual private cloud. The security team receives an alert from the intrusion detection system indicating that one of the VMs is exhibiting signs of a ransomware infection. The administrator connects to the VM via a bastion host and observes that several important files have been encrypted and a ransom note has been left. The incident response plan is still being developed, but the administrator knows the immediate priority is to contain the threat and prevent it from spreading to other VMs and storage resources. The company has daily backups stored in a separate cloud storage service that is not directly accessible from the production network. Which of the following actions should the administrator take FIRST to contain the incident and minimize further damage?

A.Restore the VM from the most recent backup.
B.Notify law enforcement about the ransomware attack.
C.Run a full antivirus scan on the infected VM.
D.Immediately disconnect the network interface of the infected VM.
AnswerD

Disconnecting the network interface severs all inbound and outbound traffic at the virtual NIC level, immediately halting lateral movement to other VMs and mounted storage. This satisfies the stem's containment priority, isolating the ransomware before it can encrypt shared resources, while preserving the VM's disk state for later forensic analysis.

Why this answer

The FIRST action in ransomware containment is to isolate the infected VM from the network by disconnecting its network interface. This immediately stops the malware from spreading laterally to other VMs, shared storage, or command-and-control servers. Restoring from backup, notifying law enforcement, or scanning come after containment, because the infection could continue to spread while those actions are performed.

Exam trap

CV0-004 often tests incident response ordering — candidates pick 'restore from backup' or 'scan' because they sound productive, but the exam expects containment FIRST, before eradication or recovery.

How to eliminate wrong answers

Option A is wrong because restoring from backup before isolating the VM would leave the infected VM online, allowing ransomware to continue encrypting files and potentially re-infect the restored VM or spread to other systems. Option B is wrong because notifying law enforcement is a post-containment step — it does not stop the spread and delays the critical isolation action. Option C is wrong because running an antivirus scan on an actively infected VM does not contain the threat; the malware may disable or evade the scanner, and the VM remains connected to the network, enabling lateral movement.

257
MCQmedium

A cloud architect is designing a highly available web application. The application must remain available even if an entire AWS Availability Zone fails. The architect decides to deploy identical application instances in two separate Availability Zones and distribute traffic equally. Which architecture is being implemented?

A.Fault tolerance
B.Warm standby
C.Active-active
D.Active-passive
AnswerC

Active-active runs both Availability Zone instances concurrently, each serving traffic, so the loss of one zone leaves the other handling requests without failover delay. This satisfies the stem's requirement that the application remain available through a complete Availability Zone failure.

Why this answer

An active-active architecture runs identical application instances in multiple Availability Zones simultaneously, with traffic distributed across all of them. Because both AZs are actively serving requests, the failure of one AZ results in the remaining AZ seamlessly absorbing the full load, maintaining availability. This is the defining characteristic described in the scenario — identical instances in two AZs with equal traffic distribution.

Exam trap

The trap is conflating high availability patterns — candidates often pick 'fault tolerance' as a generic term or 'active-passive' because they miss the phrase 'distribute traffic equally,' which specifically signals active-active.

How to eliminate wrong answers

Option A is wrong because fault tolerance implies the system continues operating without any degradation during a component failure, often through redundant hardware or error-correcting mechanisms — it is a broader design goal, not the specific two-AZ active-active pattern described. Option B is wrong because warm standby involves a secondary environment that is running but not actively serving traffic, requiring a failover step to become active. Option D is wrong because active-passive has one AZ actively serving while the other remains idle until failover, which does not match the 'distribute traffic equally' requirement.

258
MCQhard

A company uses AWS and wants to analyze cost trends and identify the top services contributing to monthly spending. Which AWS tool provides a pre-built dashboard for this purpose?

A.AWS Trusted Advisor
B.AWS Cost Explorer
C.AWS Compute Optimizer
D.AWS Budgets
AnswerB

AWS Cost Explorer supplies a pre-built dashboard with cost trend graphs and service-level breakdowns, directly satisfying the requirement to analyse monthly spending and identify top contributing services. It visualises up to 12 months of historical data, whereas Budgets only alerts on thresholds and Cost and Usage Reports deliver raw data.

Why this answer

AWS Cost Explorer is the native cost analysis tool that includes pre-built reports and dashboards for visualizing spend over time, forecasting, and identifying top cost-driving services by filtering on dimensions like service, linked account, or tag. It aggregates Cost and Usage Report data and presents it through a console UI with default views such as 'Cost by Service' and 'Monthly Costs by Linked Account'. This directly matches the requirement for a pre-built dashboard to analyze trends and top contributing services.

Exam trap

CV0-004 often tests the distinction between cost visibility tools (Cost Explorer, CUR) and cost governance tools (Budgets, Trusted Advisor), so candidates pick Budgets thinking 'cost management' means alerts rather than analysis.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides best-practice checks across cost optimization, security, fault tolerance, performance, and service limits — it flags idle resources and savings opportunities but does not offer trend dashboards or service-level spend breakdowns. Option C is wrong because AWS Compute Optimizer analyzes CloudWatch metrics to right-size EC2, EBS, Lambda, and ASG resources; it recommends instance types, not cost trends or top-spending services. Option D is wrong because AWS Budgets is for setting thresholds and alerts on spend/usage against a budget, not for exploratory trend analysis or identifying which services drive monthly costs.

259
MCQmedium

A cloud operations team manages a multi-account AWS environment. Auditors require that every API call made in all accounts be logged to a central location, that logs be immutable for 90 days, and that the logs capture the identity of the caller, the source IP, and the request time. The team wants minimal custom development. Which combination should the team implement?

A.Amazon CloudWatch Logs with subscription filters forwarding application logs to a central account.
B.AWS Config recording all resource configurations in each account and aggregating them into a central aggregator account.
C.AWS CloudTrail organization trail delivering to a central S3 bucket with S3 Object Lock in compliance mode and a bucket policy denying deletes.
D.AWS Security Hub aggregating findings from GuardDuty and Inspector into a central administrator account.
AnswerC

An organization trail in CloudTrail automatically logs management events from all accounts in AWS Organizations to a single S3 bucket. CloudTrail records caller identity, source IP, and event time. S3 Object Lock in compliance mode with a deny-delete bucket policy makes the logs immutable for the retention period. This meets all requirements with minimal custom code.

Why this answer

A CloudTrail organization trail is the AWS-native way to capture API activity across all accounts in AWS Organizations into one central S3 bucket. CloudTrail events include caller identity, source IP, and event time. Applying S3 Object Lock in compliance mode plus a bucket policy that denies deletion provides the required 90-day immutability.

The other services handle configuration, application logs, or findings, none of which produce the required centralized, immutable API audit trail.

Exam trap

The trap here is selecting a monitoring or configuration service such as AWS Config, CloudWatch, or Security Hub when the requirement is specifically an immutable record of every API call with caller identity and source IP.

260
Multi-Selecthard

A cloud administrator is troubleshooting an application that fails to connect to a database. The application and database are in the same VPC. Which THREE steps should the administrator take to diagnose the issue?

Select 3 answers
A.Check the routing table for a route to the internet.
B.Test connectivity to the database using a telnet or netcat command from the application server.
C.Verify that the security group associated with the database instance allows inbound traffic from the application's security group on the database port.
D.Check the DNS resolution of the database endpoint in the application's subnet.
E.Verify that the network ACL for the database subnet allows inbound traffic on the database port.
AnswersB, C, E

Testing with telnet or netcat from the application server isolates whether the database port is reachable across the VPC, distinguishing network or security-group blocking from application-layer faults. It directly satisfies the stem's same-VPC constraint, confirming layer-4 reachability before investigating credentials, driver configuration, or query errors.

Why this answer

Option B is correct because using telnet or netcat from the application server to the database endpoint and port is a direct way to test whether the TCP connection is being established or blocked, which immediately narrows down whether the issue is network-level or application-level. Option C is correct because security groups are stateful virtual firewalls, and if the database's security group does not permit inbound traffic from the application's security group on the database port (e.g., 3306 for MySQL, 5432 for PostgreSQL), the connection will be refused or time out. Option E is correct because network ACLs are stateless subnet-level filters, and the database subnet's NACL must allow inbound traffic on the database port (and the corresponding ephemeral return traffic) for the connection to succeed.

Option A is not relevant because the application and database are in the same VPC, so no internet route is required for internal communication. Option D is not the best diagnostic step here because the scenario specifies both resources are in the same VPC and the focus is on connectivity to the database; DNS resolution of the endpoint is less likely to be the root cause than security group or NACL misconfiguration, and it is not among the marked correct answers.

Exam trap

CompTIA often tests the distinction between stateful security groups and stateless network ACLs, and candidates mistakenly assume that allowing inbound traffic in the security group alone is sufficient, forgetting that network ACLs must also permit the traffic.

261
Multi-Selectmedium

An organization is using Azure and wants to implement a patch management strategy with minimal disruption. Which TWO actions should they take? (Select TWO.)

Select 2 answers
A.Implement rollback procedures
B.Define maintenance windows for patching
C.Use only manual patching
D.Patch all servers simultaneously
E.Disable automatic updates on all VMs
AnswersA, B

Rollback procedures directly satisfy the minimal-disruption constraint: if a patch breaks a workload, reverting to the pre-patch state restores service quickly rather than waiting for a vendor fix. Combined with staged deployment, this limits blast radius across Azure VMs, making recovery a planned, tested step rather than an outage.

Why this answer

Option A (Implement rollback procedures) is correct because a rollback plan allows the organization to revert a patch that causes regressions or outages, directly supporting minimal disruption by limiting the blast radius and downtime of a failed update. Option B (Define maintenance windows for patching) is correct because scheduling patches during controlled, low-traffic periods prevents unexpected reboots and performance impacts during business hours, which is the core of a minimal-disruption patch management strategy. Option C is incorrect because relying solely on manual patching is error-prone, does not scale, and increases the risk of missed or inconsistently applied updates.

Option D is incorrect because patching all servers simultaneously maximizes the chance of a widespread outage and removes the ability to validate patches on a subset first. Option E is incorrect because disabling automatic updates on all VMs leaves systems unpatched and exposed to known vulnerabilities, contradicting a sound patch management strategy.

Exam trap

CV0-004 often tests the misconception that patching all servers at once or disabling automatic updates is acceptable for minimal disruption, when in fact controlled scheduling and rollback capabilities are key.

262
MCQmedium

A cloud administrator manages a Microsoft Azure subscription. The security team requires that all virtual machines in a resource group be protected by a host-based firewall that filters traffic by port and protocol, independent of any network security group rules. The administrator needs a solution that can be applied directly to the operating system of each VM. Which solution should the administrator implement?

A.Enable Azure DDoS Protection Standard on the virtual network.
B.Configure Azure Firewall in the virtual network.
C.Apply a network security group (NSG) to each VM's network interface.
D.Install and configure a host-based firewall such as Windows Defender Firewall or iptables on each VM.
AnswerD

A host-based firewall runs inside the guest operating system and filters traffic by port, protocol, and application, independent of Azure network controls. Windows Defender Firewall and iptables are examples that satisfy the requirement to protect each VM directly at the OS level. This approach provides the granular, per-VM filtering the security team requested.

Why this answer

The requirement is for a host-based firewall that filters traffic by port and protocol directly on each VM's operating system. Only a firewall installed inside the guest OS, such as Windows Defender Firewall or iptables, meets this need. Azure-native services like Firewall, NSGs, and DDoS Protection operate at the network layer and cannot enforce OS-level filtering.

Exam trap

The trap here is assuming that Azure network security controls such as NSGs or Azure Firewall provide host-based protection, when they actually operate at the network layer and cannot filter traffic inside the VM operating system.

263
MCQmedium

A DevOps team uses Ansible to automate cloud resource provisioning. Which of the following best describes Ansible's architecture?

A.It uses a declarative language similar to Terraform.
B.It uses a master-server architecture with a central controller.
C.It requires an agent installed on each managed node.
D.It is agentless and uses SSH or WinRM to execute tasks.
AnswerD

Ansible pushes modules over SSH on Linux and WinRM on Windows, so managed hosts need no installed agent or persistent daemon. This agentless push model is the architectural axis distinguishing it from agent-based configuration tools such as Puppet or Chef.

Why this answer

Ansible is agentless and uses SSH (for Linux/Unix) or WinRM (for Windows) to execute tasks on managed nodes. The control node pushes modules to target hosts over these standard protocols, executes them, and removes them — no persistent agent or daemon is required on managed nodes.

Exam trap

CV0-004 often tests the distinction between agentless tools (Ansible) and agent-based tools (Puppet, Chef, SaltStack) — candidates confuse Ansible's YAML declarative syntax with Terraform's declarative IaC model.

How to eliminate wrong answers

Option A is wrong because while Ansible playbooks are declarative in style, Ansible is fundamentally a procedural/imperative automation tool using YAML playbooks, and it is not 'similar to Terraform' — Terraform is a declarative infrastructure-as-code tool with state files, whereas Ansible is configuration management/orchestration. Option B is wrong because Ansible uses an agentless push architecture from a control node; it does not have a master-server model with agents like Puppet or Chef. Option C is wrong because requiring an agent on each node describes Puppet, Chef, or SaltStack in agent mode — Ansible explicitly does not require agents.

264
MCQmedium

A deployment fails with a message about missing dependencies. What should the administrator check first?

A.Change the instance type to one with more memory
B.Review the deployment logs to identify missing packages
C.Reinstall the operating system
D.Restart the server and retry the deployment
AnswerB

Reviewing the deployment logs directly exposes which dependency resolution failed, satisfying the need to identify the missing packages before remediation. Logs record the exact package names and versions the installer could not locate, so the administrator gains the specific evidence required rather than guessing at causes.

Why this answer

When a deployment fails with a 'missing dependencies' message, the first step is to review the deployment logs. Logs will contain specific error messages indicating which packages or libraries are absent, allowing the administrator to install them directly. This aligns with standard troubleshooting methodology: identify the root cause from logs before taking corrective action.

Exam trap

The trap here is that candidates may assume a generic 'fix' like restarting or resizing the instance will resolve the issue, when the specific error message about missing dependencies demands log inspection to identify and install the exact missing packages.

How to eliminate wrong answers

Option A is wrong because changing the instance type to one with more memory addresses resource constraints (e.g., out-of-memory errors), not missing dependencies, which are package or library absences. Option C is wrong because reinstalling the operating system is an extreme, time-consuming measure that would likely resolve the dependency issue only if the OS image already includes the required packages, but it bypasses the need to identify the specific missing dependencies from logs. Option D is wrong because restarting the server and retrying the deployment does not install missing packages; it merely re-executes the same failing process without addressing the root cause.

265
MCQeasy

A company wants to protect data in transit between its on-premises data center and a public cloud environment. Which technology should be used to create a secure encrypted tunnel over the internet?

A.SSH
B.Firewall
C.TLS
D.VPN
AnswerD

A VPN establishes an encrypted tunnel between the on-premises gateway and the cloud endpoint across the public internet, encapsulating traffic with protocols such as IPsec or TLS. This satisfies the requirement to protect data in transit between the data centre and public cloud.

Why this answer

A VPN (Virtual Private Network) creates an encrypted tunnel over the internet. TLS is used for web traffic, not for site-to-site tunnels. SSH is for remote admin, and a firewall is for filtering, not encrypting tunnels.

266
MCQeasy

A cloud architect is selecting a deployment model for a workload that has strict data sovereignty requirements; data must remain within the company's on-premises data center. Which cloud deployment model should be chosen?

A.Private cloud
B.Community cloud
C.Hybrid cloud
D.Public cloud
AnswerA

A private cloud places all infrastructure and data within the organisation's own data centre, with no multi-tenant or third-party hosting. This directly satisfies the strict data sovereignty constraint requiring data to remain on-premises, unlike public, hybrid or community models.

Why this answer

A private cloud deployment model is the correct choice because it provides dedicated infrastructure that is exclusively used by a single organization, ensuring that all data and workloads remain within the company's on-premises data center. This model meets strict data sovereignty requirements by allowing full control over data residency, network boundaries, and physical security, unlike shared or public environments where data may cross jurisdictional lines.

Exam trap

CompTIA often tests the misconception that a hybrid cloud can satisfy data sovereignty by keeping sensitive data on-premises, but the trap is that the hybrid model inherently involves public cloud integration, which may still expose data to off-premises processing or storage, failing the strict 'must remain within the on-premises data center' requirement.

How to eliminate wrong answers

Option B (Community cloud) is wrong because it is shared among several organizations with common concerns (e.g., compliance or security), but data may still be processed or stored across multiple participants' sites, potentially violating strict on-premises data sovereignty. Option C (Hybrid cloud) is wrong because it combines private and public cloud resources, and while it can keep some data on-premises, the public cloud component introduces the risk of data leaving the data center, which conflicts with the requirement that data must remain within the on-premises data center. Option D (Public cloud) is wrong because it uses shared infrastructure owned and operated by a third-party provider, with data stored in off-premises data centers that may be located in different geographic regions, directly violating data sovereignty constraints.

267
MCQmedium

A cloud administrator receives an alert that a virtual machine is unresponsive. The hypervisor shows the VM status as 'running'. Which of the following should the administrator check FIRST to diagnose the issue?

A.Access the VM's console to view the operating system screen.
B.Verify the security group rules for the VM's subnet.
C.Review the hypervisor's CPU and memory utilization for the VM.
D.Check the virtual network interface for disconnection.
AnswerA

The hypervisor reports the VM as running, so the fault lies inside the guest rather than at the host layer. Opening the console reveals the operating system's actual state — kernel panic, boot hang or frozen services — which remote access cannot show when the OS is unresponsive.

Why this answer

When a VM is unresponsive but the hypervisor shows its status as 'running', the most direct way to determine if the guest OS has crashed or is stuck in a boot loop is to access the VM's console. This provides a direct view of the OS screen, allowing the administrator to see if the OS is hung, at a login prompt, or displaying an error, which is the first step in isolating the issue before checking network or resource configurations.

Exam trap

CompTIA often tests the distinction between 'VM status' (hypervisor-level) and 'guest OS responsiveness' (OS-level), and the trap here is that candidates assume a 'running' VM is fully operational and immediately check network or resource issues, ignoring the need to verify the OS state via console.

How to eliminate wrong answers

Option B is wrong because security group rules control network traffic at the subnet level; if the VM is unresponsive due to an OS crash, security groups would not affect the VM's ability to respond, and checking them first would be premature without confirming the OS is operational. Option C is wrong because reviewing hypervisor CPU and memory utilization for the VM would help identify resource contention, but the VM is already marked as 'running', meaning the hypervisor is allocating resources; the issue is likely within the guest OS, not resource starvation. Option D is wrong because checking the virtual network interface for disconnection would only be relevant if the VM were unreachable over the network, but the alert states the VM is unresponsive, which could be due to an OS-level hang; network disconnection would not cause the VM to be unresponsive from the hypervisor's perspective.

268
MCQmedium

A cloud administrator manages an AWS environment where developers require temporary, least-privilege access to specific S3 buckets. The administrator wants to avoid creating long-term IAM user credentials and needs the ability to audit who assumed which role and when. Which AWS service should be used to issue short-lived credentials for these developers?

A.AWS Security Token Service (STS)
B.AWS Key Management Service (KMS) data keys
C.AWS Organizations service control policies (SCPs)
D.AWS Identity and Access Management (IAM) access keys
AnswerA

AWS STS issues temporary, limited-privilege credentials that expire after a defined duration. By calling AssumeRole, developers receive short-lived credentials tied to an IAM role, and AWS CloudTrail logs the AssumeRole event for auditing. This directly satisfies the need for temporary access without long-term IAM user credentials and provides the required audit trail.

Why this answer

The requirement is for temporary credentials that expire automatically and can be audited. AWS STS provides exactly that through mechanisms like AssumeRole, which returns short-lived credentials associated with an IAM role. CloudTrail records the AssumeRole call, giving the administrator visibility into who assumed which role and when.

Other options either provide long-term credentials or do not issue credentials at all.

Exam trap

The trap here is confusing IAM access keys with temporary credentials, assuming that any IAM-issued key is short-lived when in fact access keys are long-term unless explicitly rotated.

269
MCQmedium

A cloud administrator is troubleshooting a web application that uses a cloud load balancer. Users report intermittent 502 Bad Gateway errors. The administrator checks the load balancer's target group and sees that some targets are marked as unhealthy. The application runs on virtual machines behind the load balancer. Which action should the administrator take to resolve the issue?

A.Increase the load balancer's idle timeout to match the application's response time.
B.Add more targets to the target group to distribute the load.
C.Verify that the health check path and port are correctly configured for the application.
D.Enable sticky sessions on the load balancer to maintain user sessions.
AnswerC

502 errors occur when the load balancer cannot establish a connection to a healthy target. If health checks are misconfigured (e.g., wrong path or port), targets are marked unhealthy and removed from rotation. When all targets are unhealthy, the load balancer returns 502. Correcting health check settings ensures only healthy targets receive traffic.

Why this answer

502 Bad Gateway errors from a load balancer indicate it cannot reach healthy backend targets. If targets are marked unhealthy, the health check configuration is likely incorrect. Verifying the health check path and port ensures the load balancer correctly assesses target health.

Increasing timeout, enabling sticky sessions, or adding targets do not fix misconfigured health checks.

Exam trap

The trap here is assuming that adding more targets or adjusting timeouts will fix 502 errors, when the real issue is often misconfigured health checks.

270
MCQmedium

An organization is implementing a CI/CD pipeline for a critical application. The team wants to deploy a new version to a small subset of users initially to validate performance and functionality before rolling out to the entire user base. Which deployment strategy best fits this requirement?

A.Rolling deployment
B.Blue/green deployment
C.Immutable deployment
D.Canary deployment
AnswerD

Canary deployment routes a small percentage of live traffic to the new version while the majority continues using the stable release, directly satisfying the requirement to validate performance and functionality with a subset of users before full rollout. Unlike blue-green, which switches all traffic at once, canary limits blast radius incrementally.

Why this answer

Canary deployment releases the new version to a small percentage of users, monitors its performance, and gradually increases traffic if successful.

271
MCQhard

A company is designing a VPC in AWS. They need to host a web application with a public-facing load balancer, web servers in private subnets, and a database in a separate private subnet. Which network architecture is most secure and aligns with best practices?

A.Public subnet for load balancer, private subnet for web servers and database together
B.Public subnet for load balancer, private subnet for web servers, separate private subnet for database
C.All resources in public subnets with security groups restricting access
D.All resources in private subnets with a VPN connection
AnswerB

Placing the load balancer in a public subnet exposes only it to the internet, while web servers and database sit in private subnets without inbound internet routing. This tiered separation limits lateral movement and satisfies least-exposure best practise.

Why this answer

A three-tier architecture with a public subnet for the load balancer, private subnets for web servers, and a separate private subnet for the database provides security and isolation.

272
MCQmedium

A company is deploying a containerized application using Kubernetes on a public cloud. The development team has created a Docker image and pushed it to a private container registry. The deployment YAML points to the registry. However, when the deployment is applied, the pods fail to start with an 'ImagePullBackOff' error. The cloud administrator verifies that the registry is reachable from the cluster nodes and that the image exists. What is the most likely reason for the failure?

A.The deployment lacks a secret for registry authentication.
B.The cluster nodes are out of disk space.
C.The image tag is incorrect.
D.The pod does not have sufficient CPU resources.
AnswerA

The private registry requires authentication, and Kubernetes pulls images using credentials supplied via an imagePullSecret referenced in the pod spec. Without that secret, the kubelet receives an authorisation denial from the registry, producing ImagePullBackOff despite the image existing and the registry being reachable.

Why this answer

The most likely reason for the ImagePullBackOff error is that the deployment lacks a Kubernetes secret for registry authentication. Since the image is stored in a private container registry, the kubelet must authenticate with the registry to pull the image. Without a properly configured imagePullSecret in the pod spec, the kubelet cannot obtain credentials, resulting in a failed pull and the ImagePullBackOff status.

Exam trap

CompTIA often tests the distinction between image existence and registry authentication, trapping candidates who assume that because the image is present and the registry is reachable, the pull should succeed without considering the need for explicit credentials.

How to eliminate wrong answers

Option B is wrong because if the cluster nodes were out of disk space, the error would typically be 'Evicted' or 'OutOfDisk', not ImagePullBackOff, and the administrator would see disk pressure events. Option C is wrong because an incorrect image tag would cause a 'ErrImagePull' or 'ImagePullBackOff' error, but the administrator has already verified that the image exists; the issue is authentication, not a missing tag. Option D is wrong because insufficient CPU resources would cause a 'Pending' state with 'Insufficient cpu' events, not an ImagePullBackOff error, which is specific to image retrieval failures.

273
MCQeasy

A company wants to ensure high availability for a stateless web application. Which architecture should be recommended?

A.Two VMs in the same availability zone with a load balancer
B.One VM in each of two availability zones with a load balancer
C.Single VM with daily backups
D.A single large VM with auto-recovery
AnswerB

Two availability zones give independent power and network failure domains, and the load balancer health-checks and routes around a failed instance. Because the application is stateless, either VM can serve any request, so no session state is lost during failover.

Why this answer

Deploying one VM in each of two availability zones with a load balancer ensures high availability by eliminating a single point of failure. If one availability zone fails, the load balancer automatically routes traffic to the healthy VM in the other zone, keeping the stateless web application accessible. This architecture aligns with the principle of fault tolerance for stateless applications, where no session state is lost during failover.

Exam trap

The trap here is that candidates often confuse high availability with redundancy within a single zone, failing to recognize that true high availability requires geographic or zone-level separation to survive infrastructure failures.

How to eliminate wrong answers

Option A is wrong because placing two VMs in the same availability zone still creates a single point of failure at the zone level; if that zone goes down, both VMs become unavailable. Option C is wrong because a single VM with daily backups does not provide high availability — backups only aid recovery after a failure, not automatic failover, and the application will experience downtime. Option D is wrong because a single large VM with auto-recovery still represents a single point of failure; auto-recovery only restarts the VM after a crash, but it does not prevent downtime during the recovery period and cannot protect against zone-level failures.

274
MCQmedium

A company has a requirement to enforce least privilege for its cloud resources. The cloud engineer is configuring IAM policies. Which of the following best describes least privilege?

A.Granting permissions based on the user's job title rather than specific needs
B.Granting permissions only to senior managers
C.Granting only the permissions necessary to perform specific tasks
D.Granting full administrator access to all users to simplify management
AnswerC

Granting only the permissions necessary to perform specific tasks directly satisfies the least-privilege requirement by scoping each identity to the minimum actions its role demands. Unlike broad or standing access, this limits the blast radius of compromised credentials, aligning with Microsoft Entra ID role assignments and just-in-time access patterns that enforce task-specific authorisation.

Why this answer

Least privilege means granting each user or service only the minimum permissions required to perform their specific job functions, and nothing more. This limits the blast radius of compromised credentials and reduces accidental or malicious damage. In cloud IAM, this is implemented through fine-grained policies scoped to specific resources and actions.

Exam trap

CV0-004 often tests the difference between least privilege and role-based access control, and candidates incorrectly pick job-title-based granting thinking it satisfies least privilege when it does not.

How to eliminate wrong answers

Option A is wrong because granting permissions based on job title rather than actual tasks is role-based but not least-privilege — job titles often imply broader access than needed, and two people with the same title may need different permissions. Option B is wrong because restricting permissions to senior managers is not least privilege; it is a hierarchical access model that ignores actual task requirements and may over-privilege managers while under-privileging others. Option D is wrong because granting full administrator access to everyone is the opposite of least privilege and dramatically increases risk.

275
MCQhard

A global company runs a SaaS application in multiple cloud regions. They use DNS-based global load balancing to route users to the nearest region. Recently, users in Asia are experiencing high latency and timeouts. The administrator checks the health of the Asian region's resources and finds everything operational. Latency measurements from a monitoring tool show that traffic from Asian users is being routed to the European region. What should the administrator investigate first?

A.The latency-based routing policy
B.The DNS TTL settings
C.The geo-location records in the DNS provider
D.The load balancer configuration in the Asian region
AnswerA

Latency-based routing selects the region with the lowest measured latency, so a misconfigured or stale policy would explain Asian users being sent to Europe despite healthy Asian resources. Investigating this policy first satisfies the stem's routing anomaly, since resource health and DNS resolution are already confirmed working.

Why this answer

The symptom — Asian users being routed to the European region despite healthy Asian resources — points directly to a misconfigured or misbehaving latency-based routing policy. Latency-based routing relies on measured latency between the user's resolver and each regional endpoint, so if the policy is misconfigured or the measurements are stale, traffic will be sent to the wrong region.

Exam trap

The trap is blaming DNS TTL or geo-location records when the observed behavior — healthy target region but wrong routing — specifically implicates the latency-based routing policy's measurements or configuration.

How to eliminate wrong answers

Option B is wrong because DNS TTL settings affect how long resolvers cache records, but a TTL issue would cause stale routing to any region, not a consistent misroute of Asian users to Europe. Option C is wrong because geo-location records route based on the user's geographic location; if they were the mechanism in use, Asian users would be sent to Asia, so the observed behavior contradicts a geo-routing problem. Option D is wrong because the Asian region's resources are confirmed operational, and a load balancer misconfiguration would cause failures within the region, not redirect users to Europe.

276
MCQmedium

A company is deploying a new web application in a hybrid cloud environment. The application must be able to scale out automatically during peak usage and scale in during low usage. The deployment must also ensure that the application remains available if a single Availability Zone fails. Which deployment strategy should the architect recommend?

A.Deploy a cluster of instances in a single Availability Zone with a load balancer.
B.Create an auto-scaling group spanning multiple Availability Zones.
C.Use a single large instance and manually resize during peak periods.
D.Deploy a load balancer in front of a single instance.
AnswerB

An auto-scaling group spanning multiple Availability Zones adds or removes instances against demand while distributing them across isolated zones, so losing one zone leaves capacity elsewhere. This satisfies both the elastic scaling and single-zone-failure availability constraints.

Why this answer

An auto-scaling group spanning multiple Availability Zones ensures both automatic scaling based on demand and high availability. If one Availability Zone fails, the load balancer distributes traffic to healthy instances in the remaining zones, meeting the requirement for continuous availability during a zone failure.

Exam trap

Candidates often mistakenly believe that a load balancer alone ensures high availability. However, without multiple instances across zones and auto-scaling, the application remains vulnerable to a single zone failure.

How to eliminate wrong answers

Option A is wrong because deploying instances in a single Availability Zone creates a single point of failure; if that zone fails, the entire application becomes unavailable, violating the availability requirement. Option C is wrong because manually resizing a single large instance does not provide automatic scaling and still results in a single point of failure; it also lacks the elasticity needed for peak usage. Option D is wrong because a load balancer in front of a single instance does not provide automatic scaling or fault tolerance; if the instance or its Availability Zone fails, the application goes down.

277
MCQmedium

A cloud administrator is troubleshooting a web application hosted on a cloud VM that is experiencing intermittent high latency. The administrator reviews the cloud provider's monitoring metrics and sees that the VM's CPU utilization is consistently around 30%, memory usage is 40%, and network throughput is well below the instance's limit. Which factor is the most likely cause of the latency?

A.Network packet loss between the client and the VM
B.Disk I/O latency on the VM's volume
C.Insufficient CPU credits on a burstable instance
D.Memory swapping due to insufficient RAM
AnswerB

High latency with low CPU, memory, and network utilization often points to storage I/O bottlenecks. If the application performs frequent disk reads/writes, slow disk I/O can cause delays. Cloud monitoring may not show disk latency by default, so it is a prime suspect when other metrics are normal.

Why this answer

When CPU, memory, and network metrics are all well within normal ranges, storage I/O latency is a frequent hidden cause of application latency. Disk operations may be slow due to volume type, IOPS limits, or contention, and this may not be reflected in default monitoring dashboards.

Exam trap

The trap here is focusing on CPU or memory because they are common causes of latency, but the metrics show they are not saturated, so the bottleneck must be elsewhere, likely storage.

278
MCQmedium

A cloud administrator is configuring a Linux virtual machine in Google Cloud. The security policy requires that all administrative access to the VM use short-lived SSH certificates issued by an internal certificate authority, rather than static SSH keys. Which GCP feature should be used to meet this requirement?

A.OS Login with SSH certificate authority
B.OS Login with two-factor authentication
C.Google Cloud IAP TCP forwarding with SSH
D.IAM roles with SSH key metadata
AnswerA

OS Login can be configured to use an SSH certificate authority. When enabled, the organization's CA issues short-lived SSH certificates to users, and OS Login validates them against the CA's public key. This eliminates static SSH keys and meets the requirement for short-lived, certificate-based administrative access to the Linux VM in Google Cloud.

Why this answer

OS Login with an SSH certificate authority allows the organization to issue short-lived SSH certificates from an internal CA. Users authenticate with these certificates, and OS Login validates them, removing the need for static SSH keys. This directly fulfills the security policy requiring short-lived certificate-based administrative access.

Exam trap

The trap here is assuming that OS Login or IAP alone provides certificate-based authentication, when only the SSH certificate authority integration issues short-lived certificates.

279
MCQhard

A company wants to migrate a stateful application to the cloud but needs to ensure it can scale horizontally. What architectural change is required?

A.Deploy in multiple availability zones
B.Move session state to a shared database or cache
C.Implement sticky sessions on the load balancer
D.Use larger instance types
AnswerB

Horizontal scaling requires any instance to handle any request, but locally stored session state ties a user to one instance. Relocating session state to a shared database or cache externalises it, so additional instances can serve subsequent requests without affinity, enabling true horizontal scale-out.

Why this answer

For a stateful application to scale horizontally, session state must be externalized from individual instances into a shared store such as a database, Redis, or Memcached. This allows any instance behind the load balancer to serve any user request, enabling true horizontal scaling and failover.

Exam trap

The trap is choosing sticky sessions as a 'fix' for stateful scaling — sticky sessions mask the problem but actively prevent horizontal scalability, which is the opposite of what the question asks.

How to eliminate wrong answers

Option A is wrong because deploying across multiple AZs improves availability and fault tolerance but does not by itself enable horizontal scaling of a stateful app — instances would still hold local session state. Option C is wrong because sticky sessions pin a user to a specific instance, which is the opposite of horizontal scalability: it creates hotspots, prevents even load distribution, and breaks when an instance fails. Option D is wrong because larger instance types are vertical scaling, which has a hard ceiling and does not address the architectural barrier to horizontal scaling.

280
MCQmedium

A cloud operations engineer is responsible for a fleet of Amazon EC2 instances that run a stateless web application behind an Application Load Balancer. The engineer needs to perform a rolling replacement of the instances with a new AMI while ensuring that the application remains available and that the deployment automatically rolls back if a specified Amazon CloudWatch alarm enters the ALARM state. Which AWS deployment service should the engineer use?

A.AWS CodeDeploy
B.AWS OpsWorks Stacks
C.AWS CloudFormation
D.AWS Elastic Beanstalk
AnswerA

CodeDeploy is the AWS service purpose-built for automating application deployments to EC2 instances, on-premises servers, Lambda, and ECS. It supports rolling deployments, configurable deployment configurations, and automatic rollback when a specified CloudWatch alarm enters the ALARM state, which directly satisfies the scenario's requirements for availability and safe rollback.

Why this answer

AWS CodeDeploy is designed for automated application deployments to EC2 instances and supports rolling deployment configurations. It integrates with CloudWatch alarms so that if a specified alarm enters the ALARM state during a deployment, CodeDeploy automatically rolls back to the last known good revision, keeping the application available and meeting the rollback requirement.

Exam trap

The trap here is assuming that any AWS service that can deploy code, such as Elastic Beanstalk or CloudFormation, also provides native CloudWatch alarm-based automatic rollback for an existing EC2 fleet.

281
Multi-Selecteasy

A company is adopting a shared responsibility model for a PaaS cloud deployment. Which THREE responsibilities belong to the customer?

Select 3 answers
A.Management of the runtime environment
B.Physical security of data centers
C.Data classification and encryption
D.Application code security
E.User access and identity management
AnswersC, D, E

The customer decides how to classify and encrypt data.

Why this answer

In a PaaS shared responsibility model, the customer is responsible for data classification and encryption of data at rest and in transit. The cloud provider manages the underlying infrastructure, but the customer must classify data according to sensitivity and apply encryption mechanisms, such as using TLS 1.2/1.3 for data in transit and AES-256 for data at rest, as the provider cannot access or classify customer data.

Exam trap

The CV0-004 exam often tests the misconception that the customer manages the runtime environment in PaaS, but the trap here is that PaaS abstracts the runtime, so the provider handles it, while the customer's responsibilities are limited to data, application code, and access control.

282
MCQeasy

Which GCP service provides centralized log management and analysis with the ability to create log-based metrics and alerts?

A.GCP Cloud Monitoring
B.GCP Cloud Audit Logs
C.GCP Cloud Trace
D.GCP Cloud Logging
AnswerD

GCP Cloud Logging centralises log ingestion, storage and analysis, and its log-based metrics convert matching log entries into alerting signals, satisfying the stem's requirement for centralised management plus metric and alert creation. Cloud Monitoring alone lacks native log ingestion, so it cannot derive metrics directly from log content.

Why this answer

Cloud Logging is Google Cloud's centralized log management service, providing ingestion, storage, search, and analysis of logs from all GCP services and custom sources. It supports log-based metrics that convert log entries into time-series data, which can then be used by Cloud Monitoring to create alerts and dashboards. This makes Cloud Logging the correct answer for centralized log management with metric and alert creation capabilities.

Exam trap

CV0-004 often tests the confusion between Cloud Logging (log ingestion and log-based metrics) and Cloud Monitoring (metric visualization and alerting), causing candidates to pick Monitoring when the question emphasizes log management.

How to eliminate wrong answers

Option A is wrong because Cloud Monitoring focuses on metrics, dashboards, and alerting policies, but it does not ingest or store raw log data. Option B is wrong because Cloud Audit Logs is a subset of logs (Admin Activity, Data Access, System Event, Policy Denied) rather than a full log management platform with analysis and metric creation. Option C is wrong because Cloud Trace is a distributed tracing service for latency analysis, not a log management or alerting tool.

283
MCQmedium

A cloud administrator wants to analyze network traffic to troubleshoot connectivity issues between VMs. Which feature should be enabled?

A.Audit logging service
B.Network flow logs
C.Distributed tracing service
D.Configuration compliance service
AnswerB

Network flow logs capture metadata about IP traffic traversing the network — source, destination, port, protocol and accept/reject decisions — without inspecting payloads. This record lets the administrator trace whether packets reach their destination, pinpointing security group, NACL or routing problems between VMs.

Why this answer

Network flow logs capture metadata about IP traffic (source/destination IP, ports, protocol, bytes, packets, accept/reject) flowing through cloud network interfaces, subnets, or VPCs. This data is exactly what an administrator needs to troubleshoot connectivity issues between VMs, such as identifying blocked ports or asymmetric routing. Flow logs are available in AWS VPC Flow Logs, Azure NSG Flow Logs, and GCP VPC Flow Logs.

Exam trap

CV0-004 often tests the confusion between control-plane audit logs (CloudTrail) and data-plane network flow logs, causing candidates to pick audit logging for connectivity troubleshooting.

How to eliminate wrong answers

Option A is wrong because audit logging services (e.g., AWS CloudTrail) record API control-plane actions, not packet-level network traffic between VMs. Option C is wrong because distributed tracing tracks request paths across microservices for latency analysis, not raw network connectivity. Option D is wrong because configuration compliance services evaluate resource settings against policies, not live traffic flows.

284
MCQhard

A cloud engineer must ensure that a critical Azure virtual machine automatically restarts if the guest operating system becomes unresponsive, even when the Azure host is healthy. Which Azure feature should be configured?

A.Azure Monitor autoscale on the virtual machine scale set
B.Azure Availability Zones for the virtual machine
C.Azure Site Recovery replication to a secondary region
D.Azure virtual machine application health monitoring with automatic repair
AnswerD

Azure VM application health monitoring uses a health extension probe to detect an unresponsive guest and, when configured with automatic repair, can restart or recreate the VM if the probe fails. Because it evaluates guest-level responsiveness rather than host health, it addresses the exact scenario where the host is healthy but the OS is hung.

Why this answer

Azure virtual machine application health monitoring probes the guest and, with automatic repair enabled, restarts the VM when the probe reports an unhealthy guest. This targets the specific case of an unresponsive operating system on a healthy host. Availability Zones, autoscale, and Site Recovery address infrastructure redundancy, capacity, and cross-region failover respectively, none of which restart a hung guest.

Exam trap

The trap here is confusing host-level redundancy features such as Availability Zones with guest-level health remediation, when only application health monitoring with automatic repair restarts an unresponsive guest OS.

285
Multi-Selectmedium

A cloud operations team is configuring cost anomaly detection for a multi-account AWS organization. They want to be notified proactively when spending deviates from expected patterns and to attribute the deviation to the right team. Which TWO actions should they take? (Choose two.)

Select 2 answers
A.Deploy a third-party agent on every EC2 instance to report hourly spend to a central dashboard
B.Create a cost allocation report and apply a consistent tag taxonomy across all accounts
C.Set a hard AWS Budgets limit that automatically terminates EC2 instances when exceeded
D.Enable AWS Trusted Advisor cost optimization checks and rely on their weekly emails
E.Enable AWS Cost Anomaly Detection with a monitor scoped to each linked account and configure an alert subscription
AnswersB, E

Consistent cost allocation tags across accounts let Cost Explorer and Cost Anomaly Detection group and filter spend by team, application, or environment. Without a shared tag taxonomy, anomalies cannot be reliably attributed to an owner. Tagging plus per-account monitors together provide both detection and attribution, which is exactly what the scenario requires.

Why this answer

Cost Anomaly Detection with per-account monitors and alert subscriptions provides proactive, machine-learning-based notification of abnormal spend, while a consistent cost allocation tag taxonomy enables attribution of those anomalies to the correct team. Trusted Advisor, Budgets thresholds, and in-instance agents do not provide the combination of learned baselines and team-level attribution required here.

Exam trap

The trap here is assuming AWS Budgets provides anomaly detection, when Budgets only compares actual spend to a static threshold and cannot learn expected patterns or attribute deviations by tag.

286
MCQeasy

A DevOps team uses Terraform to manage cloud infrastructure. They want to store the state file in a remote backend to enable team collaboration. Which backend configuration stores Terraform state in an S3 bucket?

A.backend 'consul'
B.backend 'azurerm'
C.backend 's3'
D.backend 'gcs'
AnswerC

Configuring `backend "s3"` writes the Terraform state file directly to an Amazon S3 bucket, satisfying the remote-backend requirement for shared team access. Terraform's S3 backend also supports state locking via DynamoDB, preventing concurrent runs from corrupting state. Other backend types target different storage services, so they cannot store state in S3.

Why this answer

Terraform's 's3' backend is specifically designed to store state files in an AWS S3 bucket, enabling team collaboration through remote state locking and versioning. This backend uses the AWS SDK to interact with S3, supporting features like DynamoDB-based state locking and encryption with KMS.

Exam trap

The CompTIA Cloud+ exam often tests the specific backend names mapped to cloud providers, and the trap here is that candidates may confuse 's3' with a generic storage term or assume 'azurerm' or 'gcs' are interchangeable, when each is tied to a distinct cloud platform.

How to eliminate wrong answers

Option A is wrong because the 'consul' backend stores state in HashiCorp Consul, a service mesh and key-value store, not in an S3 bucket. Option B is wrong because the 'azurerm' backend stores state in Azure Blob Storage, not in AWS S3. Option D is wrong because the 'gcs' backend stores state in Google Cloud Storage, not in AWS S3.

287
MCQmedium

A company uses a cloud object storage service to store backup data. The cloud provider charges for storage and retrieval. The operations team wants to minimize costs while ensuring data is available within 24 hours of a restore request. Which storage tier should they use?

A.Archive storage tier with retrieval time of 48 hours
B.Hot storage tier
C.Cold storage tier with retrieval time of 12 hours
D.Infrequent access tier with retrieval time of 1 hour
AnswerC

Cold storage's 12-hour retrieval sits comfortably within the 24-hour restore window, and its lower storage and access pricing directly satisfies the cost-minimisation constraint. Warmer tiers would restore faster but charge more for storage and retrieval, exceeding what the 24-hour availability requirement actually demands.

Why this answer

The cold storage tier offers a retrieval time of 12 hours, which meets the requirement of making data available within 24 hours while minimizing costs compared to hotter tiers. Cold storage is designed for infrequently accessed data with longer retrieval times, providing a cost-effective balance between availability and expense for backup data that does not need immediate access.

Exam trap

The trap here is that candidates may confuse 'cold storage' with 'archive storage' or assume that any tier with a retrieval time under 24 hours is equally cost-effective, overlooking that cold storage specifically balances cost and retrieval time for infrequent access needs.

How to eliminate wrong answers

Option A is wrong because the archive storage tier with a 48-hour retrieval time exceeds the 24-hour availability requirement, making it unsuitable for the stated restore window. Option B is wrong because the hot storage tier, while providing immediate retrieval, incurs higher storage costs that are unnecessary for backup data that does not require real-time access, thus failing to minimize costs. Option D is wrong because the infrequent access tier with a 1-hour retrieval time, though cheaper than hot storage, still costs more than cold storage and provides faster retrieval than needed, leading to higher expenses without operational benefit.

288
MCQmedium

A cloud architect is designing a VPC with multiple tiers. The web servers must be accessible from the internet, but the database servers must not be directly accessible. Which subnet design should the architect implement?

A.Place all servers in public subnets and restrict access via security groups
B.Place web servers in a private subnet and database servers in a public subnet
C.Place all servers in private subnets and use a bastion host for access
D.Place web servers in a public subnet and database servers in a private subnet
AnswerD

Public subnets route to an internet gateway, so web servers placed there remain reachable from the internet. Private subnets have no such route, keeping database servers unreachable directly; outbound access via NAT still permits patching and updates without exposing them.

Why this answer

Option D is correct because it follows the standard multi-tier VPC architecture: public subnets host internet-facing resources (web servers) with a route to an Internet Gateway (IGW), while private subnets host sensitive resources (database servers) with no direct route to the internet. This ensures the database tier is not directly reachable from the internet, satisfying the requirement. Security groups and network ACLs can further restrict traffic, but the subnet placement itself provides the first layer of isolation.

Exam trap

CV0-004 often tests the misconception that security groups alone can secure a database in a public subnet, but the exam expects you to recognize that subnet placement (public vs. private) is the primary control for direct internet accessibility.

How to eliminate wrong answers

Option A is wrong because placing all servers in public subnets exposes the database servers to the internet, even if security groups restrict access; a misconfiguration or overly permissive rule could lead to direct exposure. Option B is wrong because it reverses the tiers: web servers in a private subnet would not be directly accessible from the internet without additional components like a load balancer or NAT, and database servers in a public subnet would be directly accessible, violating the requirement. Option C is wrong because placing all servers in private subnets would make the web servers inaccessible from the internet without a bastion host or load balancer, and a bastion host is typically for administrative access, not for serving public web traffic.

289
MCQmedium

A company is migrating a legacy application to the cloud using a replatforming strategy. The application uses a proprietary logging framework that writes logs to local disk. The cloud architecture uses ephemeral storage for the application servers. The operations team notices that logs are lost when servers are replaced during auto-scaling events. What is the best solution to ensure logs are preserved?

A.Increase the size of the ephemeral storage.
B.Use memory-only logging to speed up disk I/O.
C.Disable auto-scaling for the application servers.
D.Configure the logging framework to write to a central log server over the network.
AnswerD

Ephemeral storage is destroyed when auto-scaling replaces instances, so local log files vanish. Redirecting the proprietary framework to write over the network to a central log server decouples log retention from instance lifecycle, preserving all entries.

Why this answer

The core issue is that ephemeral storage is lost when instances are terminated or replaced during auto-scaling events. By configuring the logging framework to write to a central log server over the network (e.g., using syslog, HTTP, or a dedicated log aggregation service), logs are persisted independently of the application server's lifecycle. This decouples log storage from compute resources, ensuring logs survive scaling events.

Exam trap

The trap here is that candidates may think increasing storage or optimizing local I/O solves the persistence problem, but the exam tests understanding that ephemeral storage is inherently non-persistent and that logs must be sent off-instance to survive instance replacement.

How to eliminate wrong answers

Option A is wrong because increasing the size of ephemeral storage does not solve the fundamental problem that ephemeral storage is non-persistent and is destroyed when the instance is terminated or replaced. Option B is wrong because memory-only logging would cause logs to be lost even more quickly on instance termination or crash, and it does not address the persistence requirement; it also introduces performance and capacity constraints. Option C is wrong because disabling auto-scaling defeats the purpose of cloud elasticity and scalability, and it does not address the logging persistence issue—logs would still be lost if a server fails or is manually replaced.

290
MCQmedium

A company is moving a 10 TB SQL Server database to Azure SQL Database. They need to migrate with minimal downtime while keeping the source database operational. Which service should they use?

A.Azure Database Migration Service (DMS)
B.Azure Data Sync
C.Azure Import/Export Service
D.Azure Data Box
AnswerA

Azure Database Migration Service performs online migrations, continuously replicating ongoing transactions from the source SQL Server to Azure SQL Database until cutover. This satisfies the minimal-downtime constraint, since the source stays operational and readable throughout. Offline approaches such as backup-and-restore or BACPAC export would require pausing writes for the full 10 TB transfer.

Why this answer

Azure Database Migration Service supports online migrations with minimal downtime using continuous sync (CDC) from SQL Server to Azure SQL Database.

291
MCQhard

A company is migrating a 50 TB on-premises SQL Server database to Amazon RDS for MySQL with minimal downtime. The schema must be converted from SQL Server to MySQL. Which combination of AWS services should the cloud architect use?

A.AWS DMS and AWS Schema Conversion Tool (SCT)
B.AWS Database Migration Service (DMS) only
C.AWS Snowball and AWS DMS
D.AWS DataSync and AWS Schema Conversion Tool (SCT)
AnswerA

AWS Schema Conversion Tool converts the SQL Server schema and objects to MySQL-compatible definitions, while AWS DMS performs the ongoing data replication. Together they satisfy the heterogeneous engine migration with minimal downtime that the scenario demands.

Why this answer

AWS DMS can migrate data with minimal downtime using CDC. Schema Conversion Tool (SCT) converts the schema from SQL Server to MySQL. DMS then performs the ongoing replication.

292
MCQmedium

A cloud administrator is configuring an alert for an Azure virtual machine. The alert should trigger when the average CPU percentage exceeds 90% for more than 10 minutes. Which Azure service should be used to create this metric alert?

A.Azure Advisor
B.Azure Log Analytics
C.Azure Security Center
D.Azure Monitor Alerts
AnswerD

Azure Monitor Alerts evaluates metric rules against platform metrics such as CPU percentage, supporting the average aggregation over a ten-minute window and the 90% threshold. It is the native alerting engine for Azure virtual machines, so no agent-side scripting is needed.

Why this answer

Azure Monitor Alerts allow you to create metric alerts based on conditions like CPU percentage thresholds and evaluation periods.

293
Multi-Selectmedium

A cloud team is implementing a CI/CD pipeline for a containerized application. They want to automatically build a Docker image, push it to a registry, and deploy it to a Kubernetes cluster. Which TWO tools from the options below are commonly used as part of this pipeline? (Select 2)

Select 2 answers
A.Jenkins
B.CloudFormation
C.GitLab CI
D.Terraform
E.Docker Compose
AnswersA, C

Jenkins orchestrates the pipeline stages: it triggers builds, runs Docker commands to build and push images to a registry, then applies Kubernetes manifests to deploy. Its extensive plugin ecosystem integrates each of these steps, satisfying the stem's requirement for automated build, push and deployment tooling.

Why this answer

Jenkins and GitLab CI are both CI/CD tools that can build Docker images, push to registries, and deploy to Kubernetes. Terraform and CloudFormation are IaC tools, not CI/CD. Docker Compose is for local development.

294
MCQeasy

A small business hosts a web application on a single cloud server. The server has 2 vCPUs and 4 GB RAM. Recently, the application crashes when the number of concurrent users exceeds 50. The administrator checks the system logs and finds out-of-memory (OOM) errors. What is the best course of action to resolve this issue without redesigning the application?

A.Add a load balancer and another server
B.Reduce the application's memory footprint by code optimization
C.Increase the server's RAM to 8 GB
D.Enable swap space on the server
AnswerC

Increasing memory directly resolves OOM errors without application changes.

Why this answer

The best course of action is to increase the server's RAM to 8 GB (Option C). The OOM errors indicate that the current 4 GB RAM is insufficient for 50+ concurrent users. Increasing RAM directly addresses the memory shortage without requiring application changes or redesign.

Option A (load balancer and another server) adds complexity and cost, and may not resolve the memory issue on the single server if the application is not stateless. Option B (code optimization) is a redesign effort that may not be feasible as a quick fix. Option D (enabling swap space) can lead to severe performance degradation because swapping is much slower than RAM, and may still cause crashes under high load.

295
MCQhard

A cloud administrator manages an Amazon EC2 Auto Scaling group behind an Application Load Balancer. Users report intermittent 502 errors during scale-in events. Logs show that instances are terminated while still serving in-flight requests. Which configuration change should the administrator make to resolve this?

A.Increase the Auto Scaling group's cooldown period so that scale-in events occur less frequently throughout the day.
B.Enable sticky sessions on the load balancer so that each user's requests are consistently routed to the same backend instance.
C.Enable connection draining on the load balancer and increase the deregistration delay to allow in-flight requests to complete before instance termination.
D.Change the health check type from ELB to EC2 so that the Auto Scaling group relies on instance status checks instead of load balancer health.
AnswerC

Connection draining, implemented as deregistration delay on the target group, keeps the target in a draining state while existing connections finish. Auto Scaling waits for the load balancer to report the target as unused before terminating the instance, which prevents in-flight requests from being cut off and eliminates the 502 errors observed during scale-in.

Why this answer

The 502 errors occur because instances are terminated while still processing requests. Enabling connection draining with an appropriate deregistration delay makes Auto Scaling wait until the load balancer confirms the target is no longer receiving traffic before terminating it, allowing in-flight requests to complete and eliminating the error condition.

Exam trap

The trap here is confusing scale-in tuning knobs like cooldown or health check type with the actual graceful-drain mechanism that controls when an instance is removed from service.

296
MCQeasy

A company plans to use a public cloud to host a static website with minimal configuration. The website content is stored in an object storage bucket. Users access the site via a custom domain name. Which cloud service should the company use to serve the content with low latency globally?

A.Reverse proxy server in each region
B.DNS-based round-robin to multiple storage buckets
C.Load balancer distributing traffic to multiple object storage endpoints
D.Content delivery network (CDN) with the object storage as origin
AnswerD

A CDN caches the bucket's objects at globally distributed edge locations, so users fetch content from the nearest point of presence rather than the origin region. This directly satisfies the low-latency global access requirement while the object storage remains the origin, and it needs minimal configuration compared with running compute or a web server.

Why this answer

A CDN caches static content at edge locations worldwide, reducing latency for global users. By configuring the object storage bucket as the origin, the CDN pulls content on cache miss and serves it from the nearest edge node. This meets the requirement of minimal configuration while providing low-latency delivery via a custom domain.

Exam trap

CompTIA often tests the misconception that a load balancer or DNS round-robin alone can provide global low-latency delivery, when in fact they lack caching and edge distribution, which are essential for static content performance.

How to eliminate wrong answers

Option A is wrong because deploying a reverse proxy server in each region requires manual provisioning and maintenance, contradicting the 'minimal configuration' requirement and not leveraging the public cloud's managed services. Option B is wrong because DNS-based round-robin to multiple storage buckets does not cache content; each request still hits the origin bucket, and DNS alone cannot provide low-latency global delivery or handle traffic spikes efficiently. Option C is wrong because a load balancer distributing traffic to multiple object storage endpoints does not cache content; it only distributes requests across buckets, still requiring each request to reach the origin, and adds complexity without reducing latency for geographically distributed users.

297
MCQhard

A cloud engineer is deploying a containerized workload to Google Kubernetes Engine. The security team requires that the container run as a non-root user, that the root filesystem be mounted read-only, and that privilege escalation be disallowed. The engineer wants to enforce these controls at the pod level so that any violating pod is rejected during admission. Which action should the engineer take?

A.Enable Binary Authorization on the GKE cluster and require attestations for the workload images.
B.Create a PodSecurityPolicy with runAsNonRoot, readOnlyRootFilesystem, and allowPrivilegeEscalation set to false, then bind it to the service account.
C.Apply a Pod Security Admission label of restricted to the namespace.
D.Create a NetworkPolicy that denies ingress to the namespace and set the pod's runAsUser field to 1000.
AnswerC

Pod Security Admission is the built-in replacement for PodSecurityPolicy and enforces the restricted profile through a namespace label. The restricted profile requires runAsNonRoot, disallows privilege escalation, and mandates a read-only root filesystem through the securityContext, so labeling the namespace rejects noncompliant pods at admission exactly as the security team requires.

Why this answer

Pod Security Admission is the current Kubernetes mechanism for enforcing pod security standards and is enabled by default in modern GKE releases. Labeling the namespace with the restricted profile causes the admission controller to reject any pod that fails the non-root, read-only root filesystem, and no-privilege-escalation requirements, satisfying the security team's enforcement goal without deprecated APIs.

Exam trap

The trap here is reaching for PodSecurityPolicy, which looks correct because it names the exact fields, but it was removed from Kubernetes and is no longer available in current GKE clusters.

298
MCQmedium

A company is deploying a containerized application on Amazon ECS using the Fargate launch type. The application must be highly available and able to handle sudden increases in traffic. The operations team wants to ensure that the service automatically adjusts the number of running tasks based on CPU utilization. Which ECS service configuration should the team implement?

A.Set up a CloudWatch alarm that triggers an AWS Lambda function to call the UpdateService API to change the desired count.
B.Enable ECS cluster auto scaling by associating the cluster with a capacity provider that manages EC2 Auto Scaling groups.
C.Configure an Application Auto Scaling target tracking scaling policy for the ECS service using the ECSServiceAverageCPUUtilization metric.
D.Use the ECS deployment circuit breaker to automatically roll back and scale the service when CPU utilization exceeds a threshold.
AnswerC

Application Auto Scaling for ECS supports target tracking scaling policies that can automatically adjust the desired count of tasks based on a specified metric. The ECSServiceAverageCPUUtilization metric is a predefined metric that represents the average CPU utilization across all tasks in the service. This directly meets the requirement to scale based on CPU utilization.

Why this answer

Application Auto Scaling with a target tracking policy using the ECSServiceAverageCPUUtilization metric is the native AWS solution for automatically scaling ECS services based on CPU usage. It dynamically adjusts the desired task count to maintain the target utilization, ensuring high availability and responsiveness to traffic changes without manual intervention or custom code.

Exam trap

The trap here is assuming that cluster auto scaling or custom Lambda solutions are needed for Fargate task scaling, when Application Auto Scaling directly supports it.

299
MCQmedium

An organization uses GCP and wants to implement a tagging strategy to track costs by project and environment. Which GCP feature should be used to assign metadata to resources for cost attribution?

A.Annotations
B.Tags
C.Metadata
D.Labels
AnswerD

GCP labels are key-value pairs attached to resources that flow into billing exports, enabling cost breakdown by project and environment. Unlike network tags, which control firewall and routing behaviour, labels exist specifically for metadata and cost attribution.

Why this answer

Labels are the correct GCP feature for cost attribution because they are key-value pairs that can be attached to most GCP resources and are directly integrated with Cloud Billing. They allow you to filter and group costs in billing reports by dimensions like project and environment. Unlike other metadata mechanisms, labels are specifically designed for organization and cost management.

Exam trap

CV0-004 often tests the confusion between labels and tags in GCP, where candidates mistakenly choose tags for cost tracking because they are familiar with tags from other cloud providers, but in GCP, tags are for access control and labels are for cost attribution.

How to eliminate wrong answers

Option A is wrong because annotations are used for non-identifying metadata, such as descriptions or timestamps, and are not supported for cost filtering in billing. Option B is wrong because Tags in GCP are used for access control and policy enforcement (e.g., IAM conditions), not for cost attribution. Option C is wrong because metadata refers to the broader concept of attaching arbitrary information to resources, but it is not a specific feature for cost tracking; the actual feature is labels.

300
MCQhard

An organization wants to minimize costs for a batch processing workload that runs nightly for 2 hours and can tolerate interruptions. Which pricing model is most cost-effective?

A.On-demand instances
B.Reserved instances
C.Dedicated hosts
D.Spot instances
AnswerD

Spot instances exploit unused cloud capacity at steep discounts, satisfying the workload's tolerance for interruptions and its short nightly runtime. Because the batch job can resume after eviction, the risk of sudden reclamation is acceptable, making spot pricing markedly cheaper than on-demand or reserved capacity for this intermittent, fault-tolerant scenario.

Why this answer

Spot instances offer significant discounts but can be terminated; suitable for fault-tolerant, interruptible workloads.

Page 3

Page 4 of 12

Page 5