Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 301–375

834 questions total · 12pages · All types, answers revealed

Page 4

Page 5 of 12

Page 6
301
MCQhard

A cloud engineer is troubleshooting a performance issue in a Microsoft Azure environment. The application runs on an Azure Virtual Machine Scale Set (VMSS) behind an Azure Load Balancer. Users report intermittent slow response times. The engineer suspects that the VMSS instances are experiencing high CPU utilization due to uneven traffic distribution. The engineer needs to collect and analyze performance data to identify the root cause. Which Azure feature should the engineer use to gain deep visibility into the performance of the VMSS instances and the load balancer?

A.Azure Network Watcher with connection monitor and packet capture
B.Azure Monitor with VM insights and Load Balancer insights
C.Azure Log Analytics with custom Kusto queries on VMSS diagnostic logs
D.Azure Service Health and Azure Advisor
AnswerB

Azure Monitor provides a unified platform for collecting and analyzing telemetry from Azure resources. VM insights specifically monitors the performance and health of virtual machines, including CPU, memory, and disk metrics, and can be applied to VMSS instances. Load Balancer insights provides detailed metrics and logs for the load balancer, such as traffic distribution and backend health. Together, they offer comprehensive visibility into both the VMSS and the load balancer, enabling the engineer to identify uneven traffic distribution and high CPU usage.

Why this answer

The engineer should use Azure Monitor with VM insights and Load Balancer insights. VM insights provides performance monitoring for VMSS instances, including CPU utilization, and Load Balancer insights offers detailed traffic distribution metrics. This combination allows the engineer to correlate high CPU usage with uneven traffic patterns, pinpointing the root cause.

Other options focus on network diagnostics, service health, or require manual log analysis, which are less direct and comprehensive for this performance troubleshooting scenario.

Exam trap

The trap here is choosing network-focused tools like Network Watcher when the issue involves CPU performance and traffic distribution, or assuming that Log Analytics alone can provide the same integrated insights as VM insights and Load Balancer insights.

302
Multi-Selectmedium

Which TWO of the following are best practices for managing cloud costs? (Select TWO.)

Select 2 answers
A.Implementing resource tagging for cost allocation
B.Consolidating all environments into a single subscription
C.Using reserved instances for predictable workloads
D.Overprovisioning resources to ensure high performance
E.Manually stopping idle virtual machines
AnswersA, C

Tagging resources with metadata such as owner, project and environment enables cost allocation, chargeback and identification of untagged or orphaned spend. This satisfies the stem's cost-management best practice by making consumption attributable, which underpins budgeting, forecasting and anomaly detection across cloud accounts.

Why this answer

Option A is correct because resource tagging attaches metadata (such as cost center, owner, project, or environment) to cloud resources, which enables accurate cost allocation, chargeback/showback reporting, and identification of untagged or wasteful spending in cost management tools. Option C is correct because reserved instances (or equivalent commitment-based discounts like savings plans) provide significant discounts—often up to 72% versus pay-as-you-go—for steady-state, predictable workloads, making them a core cost-optimization practice. Option B is not a best practice because consolidating all environments into a single subscription reduces cost visibility, complicates access control and budgeting, and can prevent applying environment-specific policies or discounts.

Option D is wrong because overprovisioning wastes money on unused capacity and directly contradicts cost optimization, even if it may boost performance. Option E is not a recommended best practice because manually stopping idle VMs is error-prone, unscalable, and inconsistent; automated scheduling, auto-scaling, or rightsizing should be used instead.

Exam trap

Cloud+ often tests the misconception that manual actions (like stopping VMs by hand) are a best practice, when in fact automation and right-sizing are the recommended approaches for consistent cost management.

303
Multi-Selectmedium

Which TWO of the following are advantages of using a configuration management tool (e.g., Ansible, Chef, Puppet) in cloud deployments? (Choose two.)

Select 2 answers
A.Automatically configure network devices.
B.Enable idempotent infrastructure changes.
C.Ensure consistent software configurations across multiple instances.
D.Provide dynamic auto-scaling of resources.
E.Monitor application performance in real-time.
AnswersB, C

Configuration management tools converge a target to a declared desired state, so reapplying the same playbook or manifest produces no further changes. This idempotence satisfies the stem's advantage, preventing repeated runs from duplicating or corrupting configuration.

Why this answer

Option B is correct because configuration management tools such as Ansible, Chef, and Puppet are designed around idempotency: applying the same playbook, recipe, or manifest repeatedly converges the target system to the declared state without duplicating changes, which is essential for safe, repeatable cloud infrastructure updates. Option C is correct because these tools enforce a single source of truth for package versions, files, and service settings, so every instance provisioned from the same configuration ends up with an identical software configuration, eliminating configuration drift across a fleet. Option A is not correct because configuring network devices (routers, switches, firewalls) is the domain of dedicated network automation tools and protocols rather than general-purpose host configuration management.

Option D is not correct because dynamic auto-scaling is provided by cloud platform services such as AWS Auto Scaling or Azure Virtual Machine Scale Sets, not by configuration management tools themselves. Option E is not correct because real-time application performance monitoring is handled by APM and observability tools such as CloudWatch, Datadog, or New Relic, not by configuration management.

Exam trap

The trap here is that candidates confuse configuration management tools with broader cloud management or monitoring services, mistakenly attributing capabilities like auto-scaling or real-time monitoring to tools that are strictly focused on state-based configuration and idempotent provisioning.

304
MCQhard

A company has a hybrid cloud environment where on-premises servers communicate with cloud resources via a VPN connection. The network team notices intermittent connectivity issues and packet loss. The VPN tunnel is established, but performance is degraded. Which step should the team take first to diagnose the issue?

A.Restart the VPN tunnel and monitor logs
B.Use traceroute and ping to measure latency and packet loss
C.Increase the MTU size on the VPN tunnel
D.Check the CPU utilization of the on-premises VPN appliance
AnswerB

traceroute and ping measure hop-by-hop latency and packet loss across the VPN path, isolating whether degradation sits in the tunnel, the ISP, or an endpoint. This satisfies the stem's need for a first diagnostic step before changing configuration or escalating.

Why this answer

B is correct because traceroute and ping are the foundational diagnostic tools to measure latency and packet loss across a VPN tunnel. Intermittent connectivity and packet loss often stem from path issues, MTU mismatches, or routing problems that these tools can isolate. Since the tunnel is established, the first step is to quantify the performance degradation before making configuration changes.

Exam trap

The trap here is that candidates assume the VPN tunnel is fully healthy because it is established, and they jump to restarting the tunnel or tweaking MTU without first using basic network diagnostics to isolate the performance issue.

How to eliminate wrong answers

Option A is wrong because restarting the VPN tunnel is a disruptive action that should only be taken after gathering diagnostic data; it may temporarily mask the issue without identifying the root cause. Option C is wrong because increasing the MTU size could worsen fragmentation or cause packet drops if the underlying path has a lower MTU; the correct first step is to test with ping to determine the optimal MTU. Option D is wrong because checking CPU utilization of the on-premises VPN appliance is a secondary step; while high CPU could cause performance issues, it is not the first diagnostic step when the tunnel is established and the primary symptom is packet loss.

305
MCQhard

A cloud administrator is troubleshooting a network connectivity issue between two subnets. They suspect a security group or NACL is blocking traffic. Which tool should they use to analyze the traffic flow?

A.AWS X-Ray
B.AWS CloudTrail
C.AWS Config
D.VPC Flow Logs
AnswerD

VPC Flow Logs capture accepted and rejected IP traffic metadata for elastic network interfaces, letting the administrator confirm whether a security group or NACL is dropping packets between the subnets. It records the actual allow or deny decision, which configuration review alone cannot prove.

Why this answer

VPC Flow Logs capture IP traffic information to and from network interfaces in a VPC. They can be used to analyze traffic flow and determine whether security groups or NACLs are blocking traffic by showing accepted and rejected traffic. This makes them the appropriate tool for troubleshooting connectivity issues between subnets.

Exam trap

CV0-004 often tests the distinction between logging services, and candidates may confuse CloudTrail (API activity) with Flow Logs (network traffic).

How to eliminate wrong answers

Option A is wrong because AWS X-Ray is used for tracing requests in distributed applications, not for analyzing network traffic at the VPC level. Option B is wrong because AWS CloudTrail logs API activity, not network traffic; it cannot show whether a security group blocked a packet. Option C is wrong because AWS Config records resource configurations and changes, not live traffic flow; it is not suitable for real-time network troubleshooting.

306
Multi-Selectmedium

A cloud architect is designing a container security strategy. Which TWO of the following should be implemented to secure containers? (Choose two.)

Select 2 answers
A.Runtime security monitoring for anomalous behavior
B.Disabling all security contexts in Kubernetes
C.Image scanning for vulnerabilities
D.Using the latest base images without scanning
E.Implementing network ACLs at the hypervisor level
AnswersA, C

Runtime security monitoring detects anomalous behaviour in running containers, such as unexpected process execution or privilege escalation, which static image scanning cannot catch. It satisfies the requirement to secure containers throughout their lifecycle, not only at build time.

Why this answer

Option A (Runtime security monitoring for anomalous behavior) is correct because containers can be compromised after deployment, and runtime monitoring detects suspicious activity such as unexpected process execution, privilege escalation, or unauthorized file access, enabling rapid response to threats that static controls miss. Option C (Image scanning for vulnerabilities) is correct because container images often include outdated OS packages and libraries with known CVEs; scanning images in the CI/CD pipeline and registry before deployment prevents vulnerable artifacts from reaching production. Option B is wrong because disabling all security contexts removes controls like runAsNonRoot, readOnlyRootFilesystem, and dropped capabilities, weakening rather than strengthening container isolation.

Option D is wrong because using the latest base images without scanning provides no assurance that known vulnerabilities are absent and can introduce unreviewed changes. Option E is wrong because network ACLs at the hypervisor level do not address container-specific risks such as image vulnerabilities or runtime compromise, and container network policy is typically enforced via Kubernetes NetworkPolicy or service mesh rather than hypervisor ACLs.

Exam trap

CV0-004 often tests the misconception that hypervisor-level network ACLs secure containers, but containers require orchestration-aware policies like Kubernetes NetworkPolicies; also, candidates may think disabling security contexts simplifies management, but it removes essential isolation.

307
Multi-Selecteasy

A cloud administrator is planning a migration of on-premises workloads to the cloud. Which TWO factors should be considered when selecting the appropriate cloud service model (IaaS, PaaS, SaaS)?

Select 2 answers
A.The scalability requirements of the application.
B.The level of control required over the operating system and runtime environment.
C.The security compliance requirements for data at rest.
D.The compatibility of the application with managed database or middleware services.
E.The total cost of ownership compared to on-premises.
AnswersB, D

Control over the operating system and runtime environment decreases as you move from IaaS through PaaS to SaaS. This axis determines which service model suits workloads needing patching, custom runtimes, or administrative access, satisfying the migration planning requirement.

Why this answer

Option B is correct because the cloud service model is fundamentally chosen based on how much control the organization needs over the OS and runtime: IaaS gives full OS/runtime control, PaaS abstracts the OS and runtime, and SaaS abstracts nearly everything, so this factor directly drives the IaaS/PaaS/SaaS decision. Option D is correct because PaaS suitability hinges on whether the application can run on managed databases, middleware, and runtime services without modification; if it depends on custom or unsupported components, IaaS may be required instead. Option A is not the deciding factor for service model selection, since scalability can be achieved across IaaS, PaaS, and SaaS and is more a design/architecture concern.

Option C is important for overall cloud security and compliance, but data-at-rest protections can be implemented in all three models and do not by themselves determine the service model. Option E is a business-case consideration that applies regardless of model and does not specifically differentiate IaaS, PaaS, and SaaS selection.

Exam trap

CompTIA often tests the misconception that security compliance or scalability are primary factors for service model selection, when in fact they are operational requirements that apply across all models, while control over the OS and runtime is the key differentiator.

308
MCQmedium

A cloud administrator is configuring an auto-scaling group for a web application. The application experiences predictable traffic spikes every weekday at 9 AM. Which scaling policy is most appropriate?

A.Step scaling with a cool-down period
B.Simple scaling with a 300-second cooldown
C.Target tracking scaling based on average CPU utilization
D.Scheduled scaling to add instances before 9 AM
AnswerD

Scheduled scaling adds instances ahead of the known 9 AM weekday spike, matching the predictable, time-based demand pattern. Unlike dynamic or reactive policies, it provisions capacity before traffic arrives, avoiding the lag inherent in metric-triggered responses and ensuring sufficient resources are ready when the surge begins.

Why this answer

Option D is correct because the traffic spike is predictable (every weekday at 9 AM), and scheduled scaling pre-provisions capacity before the spike begins, avoiding the lag inherent in reactive policies. This is the canonical use case for scheduled scaling in AWS Auto Scaling, Azure VMSS, and GCP MIG.

Exam trap

CV0-004 often tests the misconception that target tracking or step scaling is 'best' for all workloads — the discriminator is whether the load pattern is predictable (scheduled) or variable (dynamic), and candidates who default to CPU-based target tracking miss the 'predictable spike' keyword.

How to eliminate wrong answers

Option A is wrong because step scaling is reactive — it responds to CloudWatch alarms after the metric breaches a threshold, so instances are added only after the spike has already degraded performance, and the cool-down further delays subsequent adjustments. Option B is wrong because simple scaling with a 300-second cooldown is even slower and less granular than step scaling, and it still reacts after the fact rather than anticipating the known 9 AM load. Option C is wrong because target tracking based on average CPU is reactive and can be fooled by a fast ramp — by the time CPU crosses the target, users are already experiencing latency; it is better suited to unpredictable or steady-state workloads.

309
MCQmedium

A cloud operations team runs a fleet of Amazon EC2 instances behind an Application Load Balancer. During a recent incident, the team discovered that a single unhealthy instance continued to receive traffic for several minutes before being removed. The team wants to reduce the time it takes for the load balancer to detect and stop routing traffic to unhealthy targets. Which action should the administrator take to meet this requirement?

A.Increase the deregistration delay so connections drain gracefully before instances are removed.
B.Reduce the health check interval and unhealthy threshold in the target group health check settings.
C.Change the load balancer scheme from internet-facing to internal to reduce probe latency.
D.Enable sticky sessions on the target group so clients remain bound to a single healthy instance.
AnswerB

The target group health check settings control how frequently the load balancer probes targets and how many consecutive failures mark a target unhealthy. Shortening the interval and lowering the unhealthy threshold reduces detection latency, so unhealthy instances are removed from rotation faster. This directly addresses the scenario where an unhealthy instance kept receiving traffic for several minutes.

Why this answer

Health check behavior for an Application Load Balancer target group is governed by the interval, timeout, healthy threshold, and unhealthy threshold. Lowering the interval and reducing the number of consecutive failures required to mark a target unhealthy shortens detection time, which directly addresses the requirement to remove unhealthy instances from rotation faster.

Exam trap

The trap here is assuming that connection draining or session affinity settings control how quickly the load balancer notices an unhealthy target.

310
MCQeasy

A developer is deploying a serverless function that processes images uploaded to an S3 bucket. The function should be triggered automatically whenever a new object is created in the bucket. Which event source should be configured to invoke the Lambda function?

A.Amazon SQS
B.Amazon EventBridge
C.Amazon S3
D.API Gateway
AnswerC

Amazon S3 event notifications invoke Lambda directly when objects are created, satisfying the automatic trigger requirement. Configuring the bucket's `s3:ObjectCreated:*` event type with the function as destination removes polling entirely. This is the native push integration for object-creation events, unlike pull-based sources such as Kinesis or DynamoDB Streams.

Why this answer

Amazon S3 is the correct event source because it natively supports event notifications that can directly invoke AWS Lambda functions when objects are created, deleted, or modified in a bucket. This integration is built into the S3 service and requires no additional services or polling. The developer simply configures an S3 bucket notification to trigger the Lambda function on 's3:ObjectCreated:*' events, which is the standard serverless pattern for processing uploaded files.

Exam trap

CV0-004 often tests the misconception that any AWS service that can invoke Lambda is a valid event source for S3 events, but the key is that S3 itself must be configured as the event source for direct, automatic triggering.

How to eliminate wrong answers

Option A is wrong because Amazon SQS is a message queue service, not an event source for S3 object creation; while SQS can be used as a Lambda event source, it would require an intermediary process to poll S3 and enqueue messages, adding unnecessary complexity. Option B is wrong because Amazon EventBridge can receive S3 events, but it is not the direct event source for S3 object creation; using EventBridge would involve configuring S3 to send events to EventBridge and then routing them to Lambda, which is an indirect and more complex approach than native S3 triggers. Option D is wrong because API Gateway is used for synchronous HTTP requests, not for reacting to S3 object creation events; it would require an external system to call the API upon upload, which is not automatic.

311
MCQeasy

A company needs to migrate 50 TB of data from an on-premises file server to a cloud storage service. The network bandwidth is limited and the migration must be completed within one week. Which cloud service is specifically designed for offline data transfer of large datasets?

A.Online data transfer service
B.Offline data transfer via physical device
C.Batch processing service
D.Data transfer acceleration
AnswerB

Offline data transfer via a physical device ships data on encrypted disks to the cloud provider, bypassing limited network bandwidth. This satisfies the 50 TB volume and one-week deadline that online upload over the constrained link cannot meet.

Why this answer

Offline data transfer via physical device is specifically designed for offline data transfer of large datasets, such as 50 TB, when network bandwidth is limited. It provides physical storage devices that are shipped to the customer, loaded with data, and returned to the cloud provider for ingestion into the cloud storage service, bypassing network constraints entirely. This makes it the ideal choice for completing a 50 TB migration within one week over a limited bandwidth connection.

Exam trap

The trap here is that candidates often confuse online data transfer services with offline transfer solutions, overlooking that the physical device service is the only option designed for moving large data when bandwidth is insufficient.

How to eliminate wrong answers

Option A is wrong because AWS DataSync is an online data transfer service that requires network connectivity and is not designed for offline transfer; it would be impractical for 50 TB over limited bandwidth within one week. Option C is wrong because Amazon S3 Batch Operations is used for managing bulk actions on existing S3 objects (e.g., copying, tagging) and does not handle initial data ingestion from on-premises sources. Option D is wrong because S3 Transfer Acceleration is a network optimization feature that speeds up uploads over the internet but still relies on available bandwidth and cannot overcome severe bandwidth limitations for large datasets.

312
MCQmedium

A company stores sensitive customer data in an S3 bucket and must encrypt the data at rest using a key managed by the company (not AWS). Which encryption option should the company use?

A.Client-side encryption
B.SSE-C
C.SSE-KMS
D.SSE-S3
AnswerB

SSE-C lets the company supply and retain its own encryption key, which AWS never stores, satisfying the requirement for customer-managed keys. SSE-S3 and SSE-KMS use AWS-managed or AWS-held key material, so neither meets the constraint of company-managed keys.

Why this answer

SSE-C (Server-Side Encryption with Customer-Provided Keys) allows the company to provide their own encryption key with each request, and AWS uses that key to encrypt the object at rest but does not store the key. This meets the requirement that the key is managed by the company, not AWS.

Exam trap

The trap here is confusing SSE-KMS with customer-managed keys: candidates may think 'customer managed key' in KMS means the company manages the key, but the question explicitly says 'not AWS', and SSE-KMS still involves AWS KMS managing the key material, whereas SSE-C requires the customer to provide the key.

How to eliminate wrong answers

Option A is wrong because client-side encryption means the company encrypts data before uploading, but the question specifies encryption at rest in S3 and a key managed by the company; client-side encryption is a valid approach but SSE-C is the specific S3 server-side option where the customer manages the key. Option C is wrong because SSE-KMS uses AWS KMS-managed keys (though customer master keys can be customer-managed, the key material is still managed by AWS KMS, and the question says 'not AWS'). Option D is wrong because SSE-S3 uses AWS-managed keys entirely, so the company does not manage the key.

313
MCQmedium

A company wants to reduce cloud costs for a stateless batch processing workload that runs nightly for about 3 hours. The workload can tolerate interruptions. Which pricing model is most cost-effective?

A.Reserved instances
B.Dedicated hosts
C.Spot instances
D.On-demand instances
AnswerC

Spot instances draw from spare capacity at steep discounts and can be reclaimed with little notice, which suits a stateless nightly batch job that tolerates interruptions. Reserved or on-demand pricing would bill for idle hours, failing the cost-reduction constraint.

Why this answer

Spot instances offer up to 90% discounts compared to on-demand and are ideal for interruptible, stateless batch workloads. Since the workload runs nightly for about 3 hours and can tolerate interruptions, spot instances provide the lowest cost without requiring long-term commitments. This matches the cost-effectiveness requirement precisely.

Exam trap

CV0-004 often tests the misconception that reserved instances are always cheapest — candidates must recognize that for short, interruptible workloads, spot instances deliver the greatest savings.

How to eliminate wrong answers

Option A is wrong because reserved instances require a 1- or 3-year commitment and are better for steady-state, always-on workloads, not short nightly batches. Option B is wrong because dedicated hosts are the most expensive option and are used for licensing or compliance requirements, not cost reduction for interruptible batch jobs. Option D is wrong because on-demand instances are more expensive than spot for the same interruptible workload.

314
Multi-Selecteasy

A cloud administrator wants to ensure that patches are applied to cloud workloads with minimal risk. Which TWO practices should the administrator follow? (Choose two.)

Select 2 answers
A.Automate patch deployment using orchestration tools.
B.Skip patches for legacy systems to avoid regression.
C.Patch in production during peak hours to save time.
D.Always apply patches manually to ensure control.
E.Test patches in a staging environment first.
AnswersA, E

Automating patch deployment through orchestration tools enforces consistent, repeatable updates across cloud workloads, eliminating manual drift and human error that introduce risk. This directly satisfies the stem's minimal-risk constraint by applying patches uniformly at scale, with controlled scheduling and rollback capability, rather than relying on ad hoc manual intervention across distributed instances.

Why this answer

Automating patch deployment using orchestration tools ensures consistent, repeatable, and scheduled patching across cloud workloads, reducing human error and manual overhead. Option E is correct because testing patches in a staging environment first validates compatibility and identifies regressions before production deployment, which is a critical risk mitigation practice in cloud operations.

Exam trap

A common misconception is that manual control is safer than automation, but in cloud operations, automation with orchestration tools reduces risk by ensuring consistency and audit trails, while manual patching introduces human error and scalability issues.

315
MCQhard

An organization runs a batch processing job that runs for 2 hours every night. The job can tolerate interruptions and can resume from the last checkpoint. Which cloud purchasing option minimizes cost?

A.Reserved instances
B.Spot instances
C.Dedicated hosts
D.On-demand instances
AnswerB

Spot instances use spare cloud capacity priced far below on-demand rates, and they can be reclaimed with little notice. The job tolerates interruptions and resumes from checkpoints, so eviction causes no data loss. This fault tolerance is exactly the constraint that makes spot pricing the cheapest viable option.

Why this answer

Spot instances are the correct choice because they offer the largest discount (up to 90% off on-demand) for workloads that can tolerate interruptions and resume from checkpoints. The batch job's ability to be interrupted and restart from the last checkpoint aligns perfectly with spot instance behavior, where instances can be reclaimed by the cloud provider with a two-minute warning. This makes spot instances the most cost-effective option for this fault-tolerant, time-flexible workload.

Exam trap

The trap here is assuming that reserved instances are always the cheapest for long-running jobs, but the key differentiator is the workload's tolerance for interruptions—spot instances win for fault-tolerant, checkpointable batch jobs.

How to eliminate wrong answers

Option A is wrong because reserved instances require a 1- or 3-year commitment and are best for steady-state, always-on workloads, not interruptible nightly batch jobs. Option C is wrong because dedicated hosts are the most expensive option, used for licensing or compliance requirements, and provide no cost benefit for interruptible batch processing. Option D is wrong because on-demand instances are the most expensive pay-as-you-go option and offer no discount for the workload's tolerance of interruptions.

316
MCQmedium

A cloud engineer is writing a Terraform configuration to deploy an AWS EC2 instance. The engineer wants to pass the AMI ID and instance type into the configuration at runtime without hardcoding them. Which Terraform feature should be used?

A.Locals
B.Outputs
C.Variables
D.Data sources
AnswerC

Input variables let the configuration accept the AMI ID and instance type at runtime via CLI flags, variable files, or environment variables, rather than hardcoding values. This satisfies the requirement to pass values in without editing the configuration.

Why this answer

Variables in Terraform allow you to define parameters that can be supplied at runtime, making configurations reusable and flexible.

317
MCQeasy

A cloud administrator is troubleshooting a virtual machine (VM) in a public cloud that has become unresponsive. The administrator cannot SSH into the VM, and the cloud provider's console shows the VM is running. The administrator suspects the VM's OS has hung. Which action should the administrator take to regain access to the VM with minimal data loss?

A.Delete the VM's network interface and recreate it.
B.Detach the VM's disk and attach it to another VM for repair.
C.Terminate the VM and create a new one from a snapshot.
D.Reboot the VM from the cloud provider's console.
AnswerD

A soft reboot (if supported) or hard reboot from the console can restart the OS without losing the VM's persistent disk data. This is the least disruptive action to regain access when the OS is hung but the VM is still running. It avoids data loss on attached volumes.

Why this answer

When a VM's OS is hung but the instance is still running, a reboot from the cloud console is the quickest way to restore access. It preserves the instance and its persistent storage, minimizing data loss and downtime compared to termination or disk detachment.

Exam trap

The trap here is assuming that because SSH fails, the VM must be terminated or the disk detached, when a simple reboot often resolves a hung OS without data loss.

318
Multi-Selecthard

A cloud administrator is troubleshooting a performance issue in a virtualized environment. Which THREE of the following metrics should the administrator analyze to identify potential resource contention? (Select THREE.)

Select 3 answers
A.CPU ready time
B.Disk queuing
C.Swap file usage
D.Network latency
E.Memory ballooning
AnswersA, B, E

CPU ready time measures how long a vCPU waited in the queue for a physical core, expressed as a percentage of elapsed time. Elevated values directly indicate host CPU overcommitment and contention, making it a primary metric for diagnosing virtualised performance degradation.

Why this answer

CPU ready time (A) is correct because it measures the percentage of time a vCPU is ready to run but is waiting for a physical CPU to become available, which directly indicates CPU overcommitment and contention in a virtualized host. Disk queuing (B) is correct because queue depth and latency on the storage path reveal contention for shared datastore or LUN IOPS, showing when VMs are waiting on storage resources. Memory ballooning (E) is correct because the balloon driver reclaims guest memory when the host is under memory pressure, so active ballooning signals memory contention and overcommitment on the ESXi host.

Swap file usage (C) is not the best indicator of contention since it reflects paging activity that may occur for reasons other than host-level resource contention, and network latency (D) points to network path or congestion issues rather than contention for CPU, memory, or storage resources.

Exam trap

The trap here is that candidates often select network latency or swap file usage as signs of resource contention, but these metrics are not direct indicators of hypervisor-level contention for CPU, memory, or storage in a virtualized environment.

319
MCQeasy

A developer wants to deploy a containerized application on a Kubernetes cluster using a package manager that simplifies deployment and management. Which tool should be used?

A.Docker Compose
B.Helm
C.Terraform
D.Ansible
AnswerB

Helm is the Kubernetes package manager, bundling manifests into charts with templating, versioning and release tracking. It simplifies deploying and managing the containerised application across cluster environments, which is precisely the package-manager capability the developer requires.

Why this answer

Helm is the package manager for Kubernetes. It uses charts to define, install, and upgrade complex Kubernetes applications.

320
MCQhard

A cloud architect is designing a disaster recovery strategy for a critical application with a Recovery Time Objective of 15 minutes and a Recovery Point Objective of 5 minutes. The secondary Region must be able to take over with minimal manual effort. Which strategy should the architect implement?

A.A warm standby in the secondary Region with continuous data replication and automated failover orchestration.
B.A pilot light strategy with only the database replicated and all application servers provisioned on demand during a disaster.
C.A backup-and-restore strategy that copies nightly snapshots to the secondary Region.
D.A multi-site active-active deployment with both Regions serving production traffic simultaneously.
AnswerA

A warm standby keeps a scaled-down but functional copy of the environment running in the secondary Region, and continuous replication keeps data within the five-minute recovery point. Automated failover orchestration promotes the standby and redirects traffic with minimal human action, meeting the fifteen-minute recovery time. This balances cost and speed better than hotter or colder options.

Why this answer

A warm standby keeps a functional, scaled-down environment in the secondary Region with continuous replication, so data loss stays within the five-minute recovery point. Automated failover orchestration promotes resources and redirects traffic without lengthy manual steps, satisfying the fifteen-minute recovery time while costing less than a fully active second Region.

Exam trap

The trap here is choosing the cheapest backup-and-restore option, which cannot meet a five-minute recovery point or a fifteen-minute recovery time.

321
MCQmedium

A cloud operations team runs a containerized workload on Amazon ECS with tasks spread across an Auto Scaling group of EC2 instances. During a peak-traffic event, the team observes that a single task repeatedly restarts with an out-of-memory error while the host instance still shows 40% free memory. The team wants the scheduler to stop placing new tasks on that host when its committed memory is exhausted. Which action should the team take?

A.Set a task memory reservation in the task definition so ECS accounts for that memory when placing tasks on the instance.
B.Increase the EC2 instance type size in the Auto Scaling group launch template and recycle the instances.
C.Enable ECS managed scaling on the service and lower the target capacity utilization threshold.
D.Raise the container memory hard limit in the task definition so the task can use the host's remaining free memory.
AnswerA

A task memory reservation informs the ECS scheduler how much memory each task needs, so tasks are only placed on instances with enough unreserved capacity. The hard limit caps a container's usage, but the reservation is what prevents over-commitment across tasks. Setting it makes the scheduler leave the host alone once committed memory is exhausted, which is exactly the observed failure.

Why this answer

The restart loop happens because the scheduler lacks information about committed memory, so it keeps packing tasks onto a host that cannot actually hold them. Declaring a memory reservation per task gives the scheduler the data it needs to refuse placement on an exhausted instance. The hard limit only caps a single container and does not influence placement decisions, and scaling or resizing does not correct the underlying bin-packing logic.

Exam trap

The trap here is assuming that the container memory hard limit controls scheduling, when it only caps a single container's usage.

322
MCQmedium

A company uses a multi-cloud strategy with workloads in AWS and Azure. The cloud team wants a centralized log management solution to correlate security events across both platforms. Which approach is most suitable?

A.Use AWS CloudWatch Logs with cross-account log groups
B.Deploy a third-party SIEM solution such as Splunk
C.Use GCP Cloud Logging with a log sink to BigQuery
D.Use Azure Log Analytics and forward AWS logs to it via an agent
AnswerB

Splunk ingests and normalises logs from AWS and Azure sources, correlating security events across both platforms through a single pane of glass. This directly satisfies the stem's centralised, cross-cloud correlation requirement, which native tooling such as Microsoft Entra ID or AWS Security Hub cannot deliver for a heterogeneous multi-cloud estate.

Why this answer

A third-party SIEM such as Splunk is the most suitable approach because it is platform-agnostic and can ingest logs from AWS, Azure, and other sources into a centralized correlation engine. It provides cross-cloud security event correlation, alerting, and compliance reporting out of the box. This directly addresses the requirement for centralized log management across multi-cloud environments.

Exam trap

CV0-004 often tests the misconception that a native cloud logging service (CloudWatch, Log Analytics) can serve as a multi-cloud solution — candidates pick the tool they know best, ignoring that the question demands cross-platform correlation.

How to eliminate wrong answers

Option A is wrong because AWS CloudWatch Logs with cross-account log groups only centralizes AWS logs, not Azure logs, so it cannot correlate across both clouds. Option C is wrong because GCP Cloud Logging with a BigQuery sink is GCP-centric and does not natively ingest AWS or Azure logs without additional tooling. Option D is wrong because Azure Log Analytics can ingest AWS logs via an agent, but it is still Azure-centric and not designed as a neutral multi-cloud correlation platform.

323
MCQmedium

A cloud operations team wants to analyze application performance and identify slow database queries. They need a distributed tracing solution. Which service should they use?

A.Amazon Inspector
B.AWS CloudTrail
C.Amazon CloudWatch Logs Insights
D.AWS X-Ray
AnswerD

AWS X-Ray traces requests across distributed components, capturing subsegments for downstream calls such as database queries. This satisfies the requirement to identify slow queries by exposing per-query latency within the trace timeline, letting the team pinpoint which database operations delay application performance.

Why this answer

AWS X-Ray is a distributed tracing service that traces requests as they travel through microservices, Lambda functions, and database calls, producing a service map and segment timelines. It can pinpoint slow database queries by showing subsegment durations for SQL and NoSQL calls. This makes X-Ray the correct tool for identifying performance bottlenecks across a distributed application.

Exam trap

CV0-004 often tests the overlap between logging (CloudWatch Logs Insights) and tracing (X-Ray), causing candidates to choose log querying when the question explicitly asks for distributed tracing of slow database queries.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances and container images for software vulnerabilities and network exposure, not application tracing. Option B is wrong because AWS CloudTrail records API activity for auditing and governance, not request-level performance tracing. Option C is wrong because CloudWatch Logs Insights queries log data for patterns and errors but does not provide distributed trace context or service maps.

324
MCQhard

A company is migrating a legacy monolithic application to AWS. The application requires a relational database and must support read-heavy workloads with minimal latency for users across North America and Europe. The database must be highly available and provide automatic failover. Which AWS database solution should the architect recommend?

A.Amazon Aurora Global Database with a primary cluster in one region and secondary clusters in another region.
B.Amazon DynamoDB with global tables enabled and provisioned throughput in both regions.
C.Amazon Redshift with a multi-node cluster and cross-region snapshot copy.
D.Amazon RDS for MySQL with a Multi-AZ deployment and read replicas in both regions.
AnswerA

Aurora Global Database is designed for global applications. It consists of a primary cluster in one region and up to five secondary clusters in other regions. Replication is storage-based and typically has less than one second of latency. Secondary clusters can serve read traffic with low latency, and failover to a secondary region can be performed quickly. This meets the requirements for read-heavy workloads, low latency, and high availability.

Why this answer

Amazon Aurora Global Database provides a relational database with global replication, low-latency reads, and fast failover. It is ideal for read-heavy workloads distributed across multiple regions. The storage-based replication ensures minimal lag, and secondary clusters can serve read traffic locally.

This solution meets the requirements for high availability, automatic failover, and global low-latency access.

Exam trap

The trap here is assuming that any multi-AZ or read replica configuration will provide low-latency global reads, but only Aurora Global Database offers a managed cross-region replication with a unified global endpoint and fast failover.

325
MCQeasy

An organization wants to migrate its on-premises virtual machines to the cloud with minimal changes. Which deployment model is most appropriate?

A.Re-platform to PaaS
B.Refactor into SaaS
C.Lift-and-shift to IaaS
D.Re-architect as containerized applications
AnswerC

Lift-and-shift to IaaS satisfies the minimal-change constraint by replicating existing virtual machines on cloud infrastructure, preserving the operating system, applications and configuration unchanged. Unlike PaaS or SaaS, which demand refactoring or replacement, IaaS supplies raw compute, storage and networking, so migration requires no application redesign.

Why this answer

The lift-and-shift (rehost) model migrates on-premises virtual machines to IaaS with minimal changes, preserving the OS, applications, and configurations. This approach avoids refactoring or re-architecting, making it the most appropriate for minimizing modifications during cloud migration.

Exam trap

CompTIA often tests the misconception that 'minimal changes' means using a fully managed service (PaaS or SaaS), but the correct answer is IaaS because it preserves the existing VM architecture without requiring code or configuration modifications.

How to eliminate wrong answers

Option A is wrong because re-platforming to PaaS requires modifying the application to use platform-managed services (e.g., replacing a database with a cloud-native DB), which introduces changes beyond minimal. Option B is wrong because refactoring into SaaS involves rewriting the application as a multi-tenant service, which is a fundamental architectural change and not minimal. Option D is wrong because re-architecting as containerized applications requires packaging the VM workloads into containers, altering the deployment model and often requiring orchestration (e.g., Kubernetes), which is not minimal.

326
MCQhard

A team is using Kubernetes for container orchestration. They want to ensure that a new deployment does not cause downtime by gradually updating pods with a rolling update strategy. Which parameter in a Deployment manifest controls the number of pods that can be unavailable during the update?

A.spec.minReadySeconds
B.spec.replicas
C.spec.strategy.rollingUpdate.maxSurge
D.spec.strategy.rollingUpdate.maxUnavailable
AnswerD

maxUnavailable caps how many pods may be taken offline simultaneously during a rolling update, directly satisfying the no-downtime constraint. Setting it to 0 with maxSurge above 0 keeps full capacity while new pods start, so the deployment never drops below the desired replica count.

Why this answer

The `spec.strategy.rollingUpdate.maxUnavailable` parameter in a Kubernetes Deployment manifest specifies the maximum number of pods that can be unavailable during a rolling update. This ensures that a controlled number of pods are taken down at a time, preventing downtime by maintaining a minimum number of available pods throughout the update process.

Exam trap

The trap here is that candidates often confuse `maxSurge` (which controls extra pods created above the desired count) with `maxUnavailable` (which controls pods that can be taken down), leading them to select option C instead of D.

How to eliminate wrong answers

Option A is wrong because `spec.minReadySeconds` controls how long a newly created pod must be ready before it is considered available, not the number of pods that can be unavailable during an update. Option B is wrong because `spec.replicas` defines the desired number of pod replicas, not the availability constraints during a rolling update. Option C is wrong because `spec.strategy.rollingUpdate.maxSurge` controls the maximum number of pods that can be created above the desired replica count during an update, not the number that can be unavailable.

327
Multi-Selecteasy

A cloud administrator is designing a backup strategy for a virtual machine running a critical application. The application stores data on a separate data disk. Which TWO of the following practices should the administrator include to ensure a reliable backup?

Select 2 answers
A.Ensure the backup includes the system state and data disk.
B.Encrypt the backup files before storing them off-site.
C.Use file-level backups for the data disk only.
D.Perform guest-level backups with application-aware processing.
E.Rely solely on hypervisor-level snapshots.
AnswersA, D

Capturing both the system state and the separate data disk ensures the VM's OS configuration and the application's stored data are recoverable together. Omitting either leaves a gap: a restored VM without its data disk, or data without a bootable, configured system.

Why this answer

Option A is correct because a reliable backup of a VM hosting a critical application must capture both the operating system/system state and the separate data disk, so the VM can be fully restored and the application's data is not lost. Option D is correct because guest-level backups with application-aware processing use VSS (or equivalent) to quiesce the application and flush pending writes, ensuring transactionally consistent backups of the critical application. Option B is a good security practice but is not required for backup reliability, so it is not one of the two best answers.

Option C is insufficient because file-level backups of only the data disk omit the system state and may not capture application-consistent data. Option E is incorrect because hypervisor-level snapshots alone are not a complete backup strategy and do not provide application-aware consistency or long-term retention.

Exam trap

CV0-004 often tests backup best practices; candidates might choose encryption or hypervisor snapshots as reliability measures, but the key is application consistency and including all necessary components (system state and data disk).

328
MCQeasy

A company stores sensitive data in a cloud object storage. They want to ensure that data is automatically deleted after a retention period of 7 years to comply with legal requirements. Which feature should be used?

A.Versioning with delete markers.
B.Object lock with retention mode.
C.Lifecycle policy with expiration.
D.Compliance policy rules.
AnswerC

Lifecycle policies automate object expiration based on age.

Why this answer

Lifecycle policies can automatically expire objects after a specified number of days.

329
Multi-Selecthard

A company is implementing a secrets management solution. The security team wants to ensure that secrets are protected and rotated regularly. Which THREE of the following are best practices for secrets management?

Select 3 answers
A.Audit access to secrets to detect unauthorized usage.
B.Hard-code secrets in application source code for simplicity.
C.Use a dedicated secrets management service like AWS Secrets Manager or Azure Key Vault.
D.Enable automatic rotation of secrets on a regular schedule.
E.Store secrets in environment variables for easy access by applications.
AnswersA, C, D

Auditing secret access produces an immutable record of who read or modified each credential, exposing misuse, stale integrations or compromised identities. It satisfies the stem's protection goal by enabling detection of unauthorised usage before rotation alone would reveal it.

Why this answer

Best practices include using a dedicated vault, rotating secrets, avoiding hard-coded secrets, and auditing access.

330
MCQmedium

Refer to the exhibit. What is the effect of this bucket policy?

A.It requires users to authenticate with AWS IAM before accessing the bucket.
B.It allows anyone to read objects in example-bucket only if they come from the specified IP range.
C.It allows only the specified IP range to write objects.
D.It denies all access to the bucket except from the specified IP range.
AnswerB

The bucket policy's Condition block restricts the Allow effect to requests originating from the named CIDR range, so anonymous read access succeeds only for source addresses inside that range. All other IPs are denied, satisfying the stem's constraint of limiting public reads to a specified network.

Why this answer

The bucket policy shown grants s3:GetObject (read) permission to Principal '*' (everyone) but wraps it in a Condition that restricts access to requests originating from the specified IP range using the aws:SourceIp condition key. Because the action is GetObject and the condition limits the source addresses, only readers coming from that CIDR block can retrieve objects. This is a classic allow-with-condition policy, not a deny or authentication requirement.

Exam trap

The trap here is confusing an Allow-with-Condition policy for a Deny policy — candidates see an IP restriction and assume everything else is blocked, when in fact the policy only grants read access from that range and says nothing about other principals or actions.

How to eliminate wrong answers

Option A is wrong because the policy uses Principal '*' with no aws:PrincipalArn or IAM authentication requirement — anonymous requests from the allowed IP range would still succeed. Option C is wrong because the policy grants s3:GetObject (read), not s3:PutObject (write), so it does not authorize writes. Option D is wrong because the policy is an Allow statement scoped by a condition, not a Deny statement — traffic outside the IP range is simply not granted access by this policy, not explicitly denied by it.

331
Multi-Selecteasy

A cloud engineer is deploying a new application that requires high availability. The solution must include automated failover and load balancing. Which TWO of the following should the engineer implement?

Select 2 answers
A.Configure an auto scaling group with a minimum of two instances across two availability zones.
B.Take daily snapshots of the instance and store them in a different region.
C.Configure a read replica in a different region for failover.
D.Deploy the application on a single large instance with more resources.
E.Place the instances behind an application load balancer with health checks.
AnswersA, E

An auto scaling group spanning two availability zones provides both required capabilities: the load balancer distributes traffic across healthy instances, while automated failover occurs when the group replaces failed instances in the surviving zone. This directly satisfies the high availability, automated failover and load balancing constraints in the stem.

Why this answer

Option A is correct because an Auto Scaling group spanning two Availability Zones ensures the application runs on at least two instances in separate failure domains, and Auto Scaling can automatically replace unhealthy instances, providing automated failover and high availability. Option E is correct because an Application Load Balancer distributes incoming traffic across the instances and uses health checks to detect and route around failed targets, delivering both load balancing and automated failover at the traffic layer. Together, A and E satisfy the stated requirements of high availability, automated failover, and load balancing.

Option B is incorrect because daily snapshots only provide backup and recovery, not automated failover or load balancing. Option C is incorrect because a cross-region read replica addresses database read scaling and disaster recovery, not application-level failover or load balancing. Option D is incorrect because a single large instance is a single point of failure and provides neither automated failover nor load balancing.

Exam trap

The trap here is that candidates often confuse data backup or database replication (options B and C) with application-level high availability and load balancing, failing to recognize that automated failover and load balancing require multiple active compute instances and a traffic distributor, not just data redundancy.

332
MCQhard

A company uses AWS and needs to enforce that all S3 buckets are encrypted at rest with customer-managed keys stored in AWS KMS. Which IAM policy condition would ensure this?

A.s3:x-amz-server-side-encryption-aws-kms-key-id
B.s3:x-amz-server-side-encryption with value AES256
C.aws:SourceVpce
D.s3:versioning
AnswerA

This condition allows requiring a specific KMS key ARN for encryption.

Why this answer

The 'aws:RequestTag' condition (or similar) can enforce that resources are created with specific tags, but to enforce encryption key usage, the condition 's3:x-amz-server-side-encryption-aws-kms-key-id' is used.

333
MCQmedium

A cloud architect is designing a containerized microservices application that must handle unpredictable traffic spikes and scale rapidly. The architect wants to minimize operational overhead while ensuring high availability across multiple Availability Zones. Which solution best meets these requirements?

A.Deploy the application on a cluster of EC2 instances managed by an Auto Scaling group, with a Classic Load Balancer distributing traffic.
B.Create an AWS Lambda function for each microservice and expose them through an API Gateway with caching enabled.
C.Deploy the application on a single large EC2 instance with an Elastic IP address and use Route 53 latency-based routing to direct traffic.
D.Use AWS Fargate with an Application Load Balancer and configure an ECS service that spans multiple Availability Zones.
AnswerD

AWS Fargate is a serverless compute engine for containers that eliminates the need to manage servers. An Application Load Balancer provides advanced routing and integrates with ECS. Configuring the ECS service across multiple Availability Zones ensures high availability. This solution scales rapidly and reduces operational overhead, directly addressing the requirements.

Why this answer

AWS Fargate with an Application Load Balancer and a multi-AZ ECS service provides a serverless container platform that scales rapidly and eliminates server management. The Application Load Balancer offers advanced routing for microservices, and spanning multiple Availability Zones ensures high availability. This combination directly satisfies the need for minimal operational overhead and resilience.

Exam trap

The trap here is assuming that serverless functions like AWS Lambda are always the best choice for microservices, but Lambda has runtime and execution duration limits that may not suit all microservices.

334
MCQhard

A company is deploying a multi-tier application on AWS using AWS CloudFormation. The application consists of an Auto Scaling group, an RDS instance, and an Application Load Balancer. The team needs to ensure that the RDS instance is created before the Auto Scaling group and that the Auto Scaling group is updated only after the load balancer is ready. Which CloudFormation feature should be used to define these dependencies?

A.Metadata section
B.DependsOn attribute
C.UpdatePolicy attribute
D.CreationPolicy attribute
AnswerB

The DependsOn attribute in CloudFormation explicitly defines that a resource creation or update depends on another resource. By specifying DependsOn, you can ensure that the RDS instance is created before the Auto Scaling group, and the Auto Scaling group waits for the load balancer. This controls the order of resource provisioning and updates, meeting the requirement.

Why this answer

The DependsOn attribute explicitly defines dependencies between CloudFormation resources, ensuring that the RDS instance is created before the Auto Scaling group and that the Auto Scaling group waits for the load balancer. CreationPolicy and UpdatePolicy control signaling and update behavior, not creation order, and Metadata is for informational purposes only.

Exam trap

The trap here is confusing CreationPolicy with dependency management; CreationPolicy waits for signals but does not enforce that one resource is created before another.

335
MCQmedium

A cloud administrator is reviewing cost reports and notices that a development environment is incurring high costs due to idle compute resources. The environment is used only during business hours on weekdays. Which of the following actions would MOST effectively reduce costs?

A.Implement an auto-scaling schedule to shut down instances during off-hours.
B.Move the development environment to a different region with lower costs.
C.Change all instances to smaller instance types.
D.Use spot instances for all development servers.
AnswerA

Scheduled auto-scaling stops instances outside weekday business hours, eliminating charges for idle compute during nights and weekends. This directly matches the usage pattern described, unlike rightsizing or reserved capacity, which reduce rates but leave instances running.

Why this answer

An auto-scaling schedule allows you to define time-based rules to automatically scale in (terminate) instances during off-hours and scale out (launch) them during business hours. This directly addresses the idle compute waste by ensuring resources are only running when needed, which is the most effective cost reduction strategy for a predictable usage pattern like weekdays 9-to-5.

Exam trap

CompTIA often tests the distinction between reducing per-unit cost (e.g., smaller instances, spot, different region) versus reducing total runtime cost, and the trap here is that candidates choose a cost-reduction method that still leaves resources running 24/7 instead of aligning compute with actual usage patterns.

How to eliminate wrong answers

Option B is wrong because moving to a different region may reduce per-hour costs but does not eliminate the idle time waste; instances would still run 24/7, just at a lower rate. Option C is wrong because downsizing instance types reduces per-instance cost but still leaves instances running idle during off-hours, failing to address the core issue of unnecessary runtime. Option D is wrong because spot instances can be interrupted at any time and are not suitable for a development environment that requires consistent availability during business hours; they also do not automatically stop during off-hours.

336
MCQeasy

A company uses AWS and wants to receive alerts when CPU utilization of an EC2 instance exceeds 90% for 10 minutes. Which AWS service should be used to create this alarm?

A.Amazon CloudWatch Alarms
B.AWS CloudTrail
C.AWS Config
D.AWS Trusted Advisor
AnswerA

CloudWatch Alarms evaluate metric thresholds over defined periods; a CPUUtilization alarm with a 90% threshold and ten-minute evaluation period triggers the required alert. It is the native AWS mechanism for threshold-based EC2 metric alerting, matching the stem's duration and percentage constraints exactly.

Why this answer

CloudWatch Alarms monitor metrics and trigger actions based on thresholds and duration.

337
MCQeasy

A cloud engineer needs to ensure that a web application can scale out automatically during traffic spikes. Which design best practice should be implemented?

A.Deploy a larger instance size.
B.Use a single powerful VM with more vCPUs.
C.Manually provision additional VMs during peak times.
D.Configure an auto scaling group with a load balancer.
AnswerD

An auto scaling group provisions and terminates instances based on demand metrics, while the load balancer distributes incoming traffic across those instances. Together they satisfy the stem's requirement for automatic scale-out during traffic spikes, since the group adjusts capacity horizontally and the balancer ensures new instances receive traffic immediately.

Why this answer

An auto scaling group combined with a load balancer automatically adds or removes VM instances based on predefined metrics (e.g., CPU utilization, request count), ensuring the web application scales out horizontally during traffic spikes without manual intervention. This aligns with cloud elasticity best practices for handling variable workloads.

Exam trap

CompTIA often tests the distinction between vertical scaling (scaling up) and horizontal scaling (scaling out), where candidates mistakenly choose a larger instance size or a single powerful VM because they think 'more resources' is the solution, ignoring the need for automatic, elastic scaling and fault tolerance.

How to eliminate wrong answers

Option A is wrong because deploying a larger instance size (vertical scaling) has a hard limit based on the maximum available instance type and does not provide true elasticity; it also incurs downtime during resizing and cannot handle sudden spikes beyond the single instance's capacity. Option B is wrong because using a single powerful VM with more vCPUs is also vertical scaling, creating a single point of failure and a scalability ceiling; it cannot distribute traffic across multiple instances. Option C is wrong because manually provisioning additional VMs during peak times is reactive, error-prone, and introduces latency, failing to meet the requirement for automatic scaling during traffic spikes.

338
MCQmedium

A cloud administrator is deploying a web application on Azure. The application requires a shared, highly available file storage that can be mounted simultaneously by multiple virtual machines across different availability zones. Which Azure storage solution should the administrator choose?

A.Azure Files
B.Azure Queue Storage
C.Azure Blob Storage
D.Azure Managed Disks
AnswerA

Azure Files offers fully managed file shares in the cloud that are accessible via SMB and NFS protocols. It supports simultaneous mounting by multiple VMs, including across different availability zones when using zone-redundant storage. This makes it suitable for lift-and-shift applications that need shared file storage.

Why this answer

Azure Files is the correct choice because it provides fully managed file shares that can be mounted by multiple VMs simultaneously using standard protocols like SMB and NFS. It supports high availability and can be configured with zone-redundant storage to ensure accessibility across availability zones, meeting the requirement for shared, highly available file storage.

Exam trap

The trap here is confusing Blob Storage with file storage; Blob is object storage and does not support native file system protocols for shared access.

339
MCQeasy

An administrator is configuring access to a cloud management console for a large team. The organization wants to require a second authentication factor for all users and centralize the identity source so that disabling an account in the corporate directory immediately removes cloud access. Which approach should the administrator implement?

A.Federate the cloud provider with the corporate directory using SAML or OIDC and enforce multi-factor authentication at the identity provider.
B.Issue each user a long-lived cloud API access key and require them to use it when signing in to the management console.
C.Share a single privileged cloud account among the team and rotate its password on a weekly schedule.
D.Create separate local cloud accounts for each user and enforce a strong password complexity policy on each one.
AnswerA

Federation makes the corporate directory the single source of truth, so disabling an account there immediately blocks cloud sign-in because the identity provider no longer issues assertions. Enforcing multi-factor authentication at the identity provider applies the second factor uniformly across every federated application, satisfying both requirements without duplicating identities in the cloud.

Why this answer

Identity federation with the corporate directory through SAML or OIDC establishes one authoritative identity source, so deactivating a directory account instantly prevents new cloud sessions. Enforcing multi-factor authentication at the identity provider applies the second factor consistently to every federated sign-in, meeting both the centralization and the stronger-authentication goals without maintaining duplicate cloud identities.

Exam trap

The trap here is believing that strong local passwords provide the same control as directory-backed federation with enforced multi-factor authentication.

340
Multi-Selectmedium

A financial services firm is moving a regulated trading application to a public cloud. The security team must prove that data is encrypted in transit between the application tier and the database tier, and that only the application tier can reach the database port. Which two controls should the cloud architect implement? (Choose two.)

Select 2 answers
A.Create a network ACL on the database subnet that denies all traffic except the application subnet CIDR range.
B.Configure the database to accept connections only over TLS and require certificate validation from the application tier.
C.Deploy the database into a private subnet with a NAT gateway so it can initiate outbound updates.
D.Attach a security group to the database that allows the database port only from the application tier's security group.
E.Enable encryption at rest on the database volume using a customer-managed key stored in the cloud provider's key management service.
AnswersB, D

Enforcing TLS on the database listener with mandatory certificate validation ensures the channel between application and database is encrypted and that the application verifies the database identity, preventing interception or spoofing. This directly produces the cryptographic evidence auditors require for encryption in transit between the two tiers.

Why this answer

Encryption in transit and least-privilege reachability are distinct controls that must be paired. Requiring TLS with certificate validation on the database listener proves the channel is cryptographically protected, and a security group rule that names the application tier's security group as the only permitted source enforces role-based access to the database port. Encryption at rest, private subnets with NAT, and subnet-level ACLs address other concerns and do not satisfy either requirement.

Exam trap

The trap here is accepting encryption at rest as proof of encryption in transit, when the two protect entirely different states of the data.

341
MCQhard

A cloud administrator sees the output above when troubleshooting a virtual machine that is unresponsive. The VM is critical and must be restored quickly. What should the administrator do first?

A.Resume the VM using the virsh resume command.
B.Restart the libvirtd service on the host.
C.Increase the memory allocation for the host to free resources.
D.Migrate the VM to another host in the cluster.
AnswerA

Resuming with `virsh resume` restores a paused domain without rebooting, preserving memory state and avoiding downtime. The stem's constraint—a critical VM requiring rapid restoration—favours this over restarting, which would discard in-memory data and lengthen recovery. Paused VMs remain intact, so resumption is the fastest safe first action.

Why this answer

The output from `virsh list --all` shows the VM is in a 'paused' state, which means it is still resident in memory but not executing. The fastest way to restore a paused VM is to resume it with `virsh resume <vm-name>`, which immediately continues CPU execution without requiring a reboot or migration. This directly addresses the unresponsive behavior while preserving the VM's current memory state.

Exam trap

The trap here is that candidates assume a paused VM requires a full restart or host-level intervention, but the CV0-004 exam expects you to recognize that `virsh resume` is the immediate, low-risk recovery action for a paused domain.

How to eliminate wrong answers

Option B is wrong because restarting the libvirtd service would disrupt all VMs on the host and is unnecessary when only a single VM is paused; the issue is at the VM level, not the hypervisor daemon. Option C is wrong because increasing host memory allocation does not affect a paused VM—pausing is triggered by storage I/O errors, disk full conditions, or host memory overcommitment, not by insufficient host memory. Option D is wrong because migrating a paused VM requires resuming it first or using `virsh migrate --live` which cannot work on a paused domain; migration adds unnecessary complexity and downtime when a simple resume command will restore service immediately.

342
MCQmedium

A company is planning to migrate to AWS and wants to achieve the lowest possible compute costs for a steady-state workload that will run 24/7. Which purchasing option should be recommended?

A.Spot Instances
B.Reserved Instances
C.On-Demand Instances
D.Dedicated Hosts
AnswerB

Reserved Instances suit steady-state, 24/7 workloads by exchanging a one- or three-year term commitment for a significant discount against On-Demand pricing, directly satisfying the lowest-possible-compute-cost constraint. Unlike Spot Instances, capacity is not interruptible, so continuous availability is preserved without the premium of On-Demand rates.

Why this answer

Reserved Instances provide a significant discount (up to 72%) compared to On-Demand pricing in exchange for a one- or three-year commitment, making them ideal for steady-state workloads that run 24/7. Because the workload is predictable and continuous, the commitment is easily justified and the effective hourly cost is minimized. This is the standard AWS recommendation for long-running, stable compute.

Exam trap

CV0-004 often tests the trade-off between cost and reliability, tempting candidates to choose Spot Instances for their low price while ignoring the interruption risk for a 24/7 steady-state workload.

How to eliminate wrong answers

Option A is wrong because Spot Instances can be reclaimed by AWS with a two-minute warning, making them unsuitable for a steady-state 24/7 workload that cannot tolerate interruption. Option C is wrong because On-Demand pricing is the most expensive option and is intended for short-term, unpredictable, or spiky workloads. Option D is wrong because Dedicated Hosts are for licensing and compliance requirements (BYOL, tenancy isolation) and are more expensive than Reserved Instances for general steady-state compute.

343
MCQhard

During a disaster recovery test, a cloud administrator finds that the replicated VMs in the secondary site fail to start because they are assigned to a resource pool that does not exist in the secondary site. Which of the following should the administrator have done to prevent this issue?

A.Map the resource pools between primary and secondary sites.
B.Use storage snapshot replication instead.
C.Ensure the secondary site has identical hardware.
D.Configure the replication job to use a different datastore.
AnswerA

Replication copied VMs but not the resource-pool mapping, so the secondary site lacked the referenced pool and VMs failed to start. Mapping resource pools between primary and secondary sites ensures replicated VMs land in an existing pool, satisfying the DR test's startup requirement.

Why this answer

The issue stems from the replicated VMs being assigned to a resource pool that doesn't exist on the secondary site. By mapping resource pools between primary and secondary sites during replication setup, the administrator ensures that the destination resource pool is created or mapped correctly, allowing the VMs to start without dependency errors. This is a common prerequisite in vSphere Replication or similar disaster recovery tools where resource pool configurations must be mirrored to avoid startup failures.

Exam trap

The trap here is that candidates often assume the issue is storage-related or hardware-related, overlooking the fact that logical constructs like resource pools must be explicitly mapped in a disaster recovery configuration, even when using replication technologies.

How to eliminate wrong answers

Option B is wrong because storage snapshot replication replicates the storage-level data but does not address the mapping of virtual infrastructure objects like resource pools; the VMs would still fail to start if the target resource pool is missing. Option C is wrong because identical hardware is not required for resource pool existence; resource pools are logical constructs within a vCenter or hypervisor, not tied to physical hardware specifics. Option D is wrong because configuring the replication job to use a different datastore only changes the storage location, not the resource pool assignment; the VMs would still reference a non-existent resource pool on the secondary site.

344
MCQeasy

A startup wants to run code in response to events without provisioning or managing servers. Which cloud service model should they use?

A.PaaS
B.IaaS
C.FaaS
D.SaaS
AnswerC

FaaS runs event-triggered code without provisioning or managing servers, matching the startup's requirement exactly. The provider handles all infrastructure; the developer deploys only functions. IaaS and PaaS still involve server or runtime management, so they fail the no-server-management constraint.

Why this answer

FaaS (Function-as-a-Service) is the cloud service model where the provider runs code in response to events without requiring the customer to provision or manage servers. The customer deploys functions, and the platform handles scaling, patching, and infrastructure. This exactly matches the requirement to run code on events with no server management.

Exam trap

The trap is confusing FaaS with PaaS — candidates often pick PaaS because both are managed, but the exam tests that FaaS specifically means event-driven functions with no server provisioning or management.

How to eliminate wrong answers

Option A is wrong because PaaS provides a managed platform for deploying applications (e.g., App Engine, Heroku) but still involves running an application environment, not event-driven functions without server management. Option B is wrong because IaaS provides raw virtual machines, storage, and networking where the customer manages the OS and runtime — the opposite of serverless. Option D is wrong because SaaS delivers finished software applications to end users, not a model for running custom code in response to events.

345
MCQmedium

A cloud team wants to automatically scale an application based on the number of pending messages in a message queue. Which scaling policy type should be used?

A.Dynamic scaling (metric-based)
B.Scheduled scaling
C.Manual scaling
D.Static scaling
AnswerA

Dynamic scaling (metric-based) triggers capacity changes from a monitored metric rather than a fixed schedule, so it directly satisfies the stem's requirement to scale on pending message count. The queue depth feeds an autoscaling rule that adds or removes instances as the backlog rises or drains, matching demand automatically.

Why this answer

Dynamic scaling (metric-based) adjusts the number of instances to keep a specific metric, such as queue depth, at a target value. This is the appropriate policy for scaling based on real-time queue depth.

346
MCQeasy

A cloud engineer notices that a virtual machine (VM) in a public cloud environment is consistently running at 90% CPU during business hours. The VM hosts a customer-facing web application. Which of the following is the BEST initial troubleshooting step?

A.Migrate the VM to a different availability zone.
B.Review the VM's performance metrics and application logs.
C.Reboot the VM to reset resource usage.
D.Scale up the VM to a larger instance size.
AnswerB

Sustained 90% CPU during business hours points to a workload or code issue, not necessarily a capacity one. Reviewing performance metrics and application logs first identifies whether the cause is traffic, a runaway process or inefficient code before any resizing decision.

Why this answer

The initial step in troubleshooting high CPU usage is to gather diagnostic data. Reviewing the VM's performance metrics (e.g., CPU utilization, memory, disk I/O) and application logs helps identify whether the issue is caused by a legitimate workload spike, a memory leak, or a misconfiguration. This aligns with the 'identify before act' principle in cloud operations, ensuring the engineer understands the root cause before making changes.

Exam trap

The trap here is that candidates often jump to a 'fix' like scaling up or rebooting, but the CompTIA Cloud+ exam tests the foundational troubleshooting methodology of 'gather data first' to avoid unnecessary changes and ensure the solution is targeted and cost-effective.

How to eliminate wrong answers

Option A is wrong because migrating the VM to a different availability zone does not address high CPU usage; it only changes the physical location, which may introduce latency or availability issues without resolving the performance bottleneck. Option C is wrong because rebooting the VM is a disruptive action that only temporarily resets resource usage; it does not diagnose or fix the underlying cause, and it can lead to application downtime for a customer-facing web app. Option D is wrong because scaling up to a larger instance size is a reactive measure that may mask the problem without investigation; it increases costs and could be unnecessary if the issue is due to a software bug or misconfiguration.

347
MCQmedium

A security engineer is reviewing a cloud storage bucket policy. Which of the following best describes the security issue present in the exhibit?

A.The bucket policy correctly limits access to read-only operations, which is secure by default.
B.The bucket policy should be modified to allow write access for full functionality.
C.The bucket policy should include an IP address restriction to limit access to corporate IPs.
D.The bucket policy allows public read access to all objects, creating a data exposure risk.
AnswerD

Public read access on a bucket policy grants anonymous principals the `s3:GetObject` permission, so anyone on the internet can retrieve every stored object without authentication. This directly satisfies the stem's data exposure risk, since confidentiality is lost for all objects rather than a scoped subset.

Why this answer

The exhibit (a bucket policy granting public read access) exposes all objects in the bucket to anyone on the internet, which is a data exposure risk (D). Public read access on a storage bucket is one of the most common cloud misconfigurations and a leading cause of data breaches, because it allows unauthenticated principals to list and download objects. The correct characterization is that the policy creates an exposure risk, not that it is secure or needs write access.

Exam trap

CV0-004 often tests the misconception that read-only public access is acceptable or 'secure by default' — candidates must recognize that public read on a bucket is a data exposure vulnerability regardless of the operation type.

How to eliminate wrong answers

Option A is wrong because read-only public access is not 'secure by default' — public read on a bucket containing sensitive data is a critical exposure regardless of the operation being read-only; confidentiality is violated. Option B is wrong because adding write access would worsen the vulnerability, enabling data tampering or ransomware-style overwrites, not fix it. Option C is wrong because while an IP restriction would reduce exposure, it does not address the fundamental misconfiguration of public access and is not the best description of the issue present; the policy itself is the problem, not the absence of an IP condition.

348
Multi-Selecthard

A cloud operations team is designing a backup strategy for a set of Amazon RDS for MySQL databases that support a production application. The team needs to be able to restore the database to any point in time within the last 35 days and must also retain a copy of the database for seven years for regulatory compliance. The team wants to minimize operational overhead. Which TWO actions should the team take? (Choose two.)

Select 2 answers
A.Create a manual DB snapshot and retain it for seven years.
B.Enable Multi-AZ deployment for the RDS instance.
C.Configure a read replica in a second region and promote it for recovery.
D.Export automated backups to Amazon S3 and apply a lifecycle policy for seven-year retention.
E.Enable automated backups with a backup retention period of 35 days.
AnswersD, E

RDS supports exporting snapshots to Amazon S3, and S3 lifecycle policies can transition and retain objects for seven years. This provides durable, low-overhead long-term retention for compliance. Combined with automated backups for point-in-time recovery, it satisfies both the short-term and long-term requirements without managing servers.

Why this answer

Automated backups with a 35-day retention period deliver point-in-time recovery within the required window and are fully managed. Exporting backups to Amazon S3 with a seven-year lifecycle policy provides durable, low-overhead long-term retention for regulatory compliance. Together they meet both the short-term recovery and long-term retention requirements.

Exam trap

The trap here is treating high-availability features such as Multi-AZ or read replicas as if they were backup and retention mechanisms.

349
MCQhard

A company uses a hybrid cloud environment with workloads in AWS and on-premises. They want to use a single monitoring dashboard to view metrics from both environments. Which solution should they implement?

A.Deploy a third-party monitoring tool in AWS and replicate all logs to it
B.Set up a VPN connection and use VPC Flow Logs for on-premises traffic
C.Install the CloudWatch agent on on-premises servers and send metrics to CloudWatch, then create a CloudWatch dashboard
D.Use AWS CloudTrail to log on-premises activity
AnswerC

The CloudWatch agent collects on-premises server metrics and publishes them to CloudWatch, letting a single dashboard display hybrid data alongside AWS resource metrics. This satisfies the unified-view constraint without deploying a separate third-party monitoring platform.

Why this answer

The CloudWatch agent can be installed on on-premises servers to collect OS-level and application metrics and push them to CloudWatch over the public internet or a VPN/Direct Connect. Once the metrics are in CloudWatch, they appear alongside AWS-native metrics and can be visualized in a single CloudWatch dashboard, satisfying the hybrid monitoring requirement. This is the native, lowest-friction way to unify metrics from both environments.

Exam trap

CV0-004 often tests whether candidates conflate logging/auditing services (CloudTrail, VPC Flow Logs) with metric monitoring — the key is that only CloudWatch ingests and visualizes metrics, and the agent is what extends it to on-premises.

How to eliminate wrong answers

Option A is wrong because deploying a third-party tool in AWS and replicating logs only addresses logs, not metrics, and introduces unnecessary tooling and cost when CloudWatch already supports hybrid ingestion. Option B is wrong because VPC Flow Logs capture IP traffic metadata for AWS network interfaces — they do not monitor on-premises traffic, and a VPN alone does not produce on-prem metrics. Option D is wrong because CloudTrail records AWS API activity for auditing, not on-premises server activity or performance metrics.

350
Multi-Selectmedium

A cloud architect is designing a deployment pipeline for a multi-tier application. The team wants to automate testing and deployment while ensuring that only healthy code reaches production. Which TWO practices should they implement?

Select 2 answers
A.Infrastructure as Code
B.Immutable infrastructure
C.Blue/green deployment
D.Canary releases
E.Manual approval gates
AnswersC, D

Blue/green deployment maintains two identical environments, shifting traffic only after the new version passes health checks in the staging slot. This satisfies the requirement that only healthy code reaches production, since the live environment stays untouched until verification completes and rollback remains instant.

Why this answer

Blue/green deployment (C) is correct because it maintains two identical environments and shifts traffic only after the new (green) version passes health checks, so unhealthy code never receives production traffic and rollback is instant by reverting the router/load balancer. Canary releases (D) are correct because they route a small percentage of production traffic to the new version and progressively increase it only while health and error-rate metrics stay within thresholds, automatically halting or rolling back on failure. Together these deployment strategies directly enforce the requirement that only verified healthy code reaches full production.

Infrastructure as Code (A) and immutable infrastructure (B) improve provisioning consistency and reproducibility but do not by themselves gate traffic on health, and manual approval gates (E) add human sign-off rather than automated health-based promotion, so they do not satisfy the stated goal.

Exam trap

CompTIA often tests the distinction between deployment strategies (blue/green, canary) and infrastructure management practices (IaC, immutable), so candidates mistakenly select IaC or immutable infrastructure because they associate 'automation' with provisioning rather than traffic management and health gating.

351
MCQhard

A cloud administrator notices that a virtual machine is consuming excessive CPU resources with no apparent workload. Which of the following should the administrator investigate FIRST to determine the cause?

A.A misconfigured load balancer sending traffic to the VM
B.CPU hotplug settings on the hypervisor
C.A runaway process inside the VM
D.Memory overcommitment ratio
AnswerC

Guest-level CPU consumption with no external workload points to something executing inside the operating system. A runaway or looping process is the most direct explanation and is checked first via Task Manager or top before examining host-level metrics or hypervisor scheduling.

Why this answer

A runaway process inside the VM is the most likely cause when a VM exhibits high CPU utilization without an apparent workload. This could be due to a background service, malware, or an application stuck in an infinite loop. Option A is incorrect because a misconfigured load balancer would direct traffic to the VM, which would result in network and CPU activity associated with processing that traffic, not idle high CPU.

Option B is incorrect; CPU hotplug settings affect the ability to add CPUs but do not themselves cause high CPU usage. Option D is incorrect; memory overcommitment affects memory availability, not CPU utilization.

352
MCQhard

A company uses a hybrid cloud model with an on-premises data center and a public cloud. The network team reports that traffic between the cloud and on-premises is experiencing high latency and packet loss. The cloud administrator verifies that the VPN connection is up. What is the most likely cause?

A.A firewall rule is blocking ICMP packets.
B.VMs are placed in different cloud regions.
C.The VPN tunnel has a mismatched MTU size.
D.The cloud provider is throttling bandwidth.
AnswerC

A mismatched MTU causes larger packets to be dropped when the DF flag is set, producing packet loss and retransmission latency while the tunnel itself stays up. This matches the verified-up VPN with high latency and loss.

Why this answer

When a VPN tunnel is up but traffic experiences high latency and packet loss, a mismatched Maximum Transmission Unit (MTU) size is a common cause. This occurs because packets larger than the tunnel's MTU must be fragmented, and if fragmentation is not properly handled (e.g., due to the DF bit being set), packets are dropped, leading to retransmissions and increased latency. The symptoms align with MTU issues rather than simple connectivity or throttling problems.

Exam trap

The trap here is that candidates assume a 'VPN is up' means all traffic flows perfectly, but CompTIA often tests the subtlety that MTU mismatch causes performance degradation without breaking the tunnel itself, leading them to incorrectly blame firewall rules or bandwidth throttling.

How to eliminate wrong answers

Option A is wrong because ICMP packets are not required for VPN tunnel operation; blocking ICMP would cause ping failures but not necessarily high latency and packet loss on data traffic, and the VPN is already verified as up. Option B is wrong because VMs in different cloud regions would affect latency between those VMs, but the question specifies traffic between the cloud and on-premises data center, which is routed through the VPN tunnel regardless of VM placement. Option D is wrong because cloud providers typically throttle bandwidth based on usage limits or burst credits, which would manifest as reduced throughput rather than the combination of high latency and packet loss described.

353
MCQeasy

A cloud administrator is tasked with ensuring that only encrypted connections are used to transfer files to a cloud storage bucket. Which of the following should the administrator enforce?

A.Use HTTP with a custom header.
B.Allow FTP but restrict to specific IPs.
C.Require HTTPS for all uploads.
D.Enable SFTP access to the bucket.
AnswerC

HTTPS wraps uploads in TLS, encrypting data in transit between the client and the storage endpoint. Enforcing it on the bucket rejects plain HTTP PUT requests, satisfying the requirement that only encrypted connections transfer files.

Why this answer

HTTPS (HTTP over TLS) encrypts data in transit using TLS, ensuring that files uploaded to a cloud storage bucket are protected from eavesdropping and tampering. By requiring HTTPS for all uploads, the administrator enforces encrypted connections as mandated by the security policy, which is a standard practice for cloud storage services like AWS S3 or Azure Blob Storage.

Exam trap

The trap here is that candidates may confuse SFTP (which is encrypted) with FTP (which is not), and incorrectly assume that enabling SFTP is the correct answer, but the question specifically targets the standard encrypted protocol for cloud storage bucket uploads, which is HTTPS.

How to eliminate wrong answers

Option A is wrong because HTTP with a custom header does not provide encryption; the data is still transmitted in plaintext, making it vulnerable to interception. Option B is wrong because FTP transmits data and credentials in cleartext, and restricting by IP does not encrypt the connection, leaving it susceptible to packet sniffing. Option D is wrong because SFTP (SSH File Transfer Protocol) encrypts the connection, but the question specifically asks for encrypted connections to transfer files to a cloud storage bucket; while SFTP is encrypted, it is not the standard protocol for cloud storage bucket uploads (which typically use HTTPS), and enabling it may introduce unnecessary complexity or security risks if not properly managed.

354
MCQeasy

A company wants to migrate its on-premises workloads to the cloud and requires full control over the operating system, installed software, and security configurations. Which cloud service model should they choose?

A.FaaS
B.IaaS
C.PaaS
D.SaaS
AnswerB

IaaS provides the raw compute, storage and networking primitives while leaving the guest operating system, middleware and installed software entirely under the customer's administration. That satisfies the stated requirement for full control over the OS, software and security configurations, which PaaS and SaaS abstract away.

Why this answer

IaaS provides virtualized computing resources where the customer manages the OS and above, giving full control.

355
MCQeasy

A company wants to migrate its on-premises workloads to the cloud but must keep sensitive data on-premises due to regulatory requirements. Which cloud deployment model should the company use?

A.Multi-cloud
B.Public cloud
C.Hybrid cloud
D.Private cloud
AnswerC

Hybrid cloud keeps sensitive workloads on-premises while extending other workloads to public cloud, directly satisfying the regulatory constraint that sensitive data must remain on-premises. Neither pure public nor private cloud alone meets both the migration goal and the data-residency requirement.

Why this answer

A hybrid cloud deployment model combines on-premises infrastructure with public cloud services, allowing sensitive data to remain on-premises while other workloads leverage cloud scalability. This directly meets the regulatory requirement to keep sensitive data local while still benefiting from cloud resources for other components.

Exam trap

CV0-004 often tests the distinction between hybrid and private cloud, and candidates may choose private cloud thinking it keeps data on-premises, but private cloud does not inherently provide the public cloud integration that hybrid offers.

How to eliminate wrong answers

Option A is wrong because multi-cloud refers to using multiple public cloud providers, not keeping data on-premises. Option B is wrong because public cloud alone cannot satisfy the requirement to keep sensitive data on-premises. Option D is wrong because a private cloud is dedicated to a single organization but does not inherently include public cloud integration; it may still be on-premises but lacks the hybrid flexibility described.

356
MCQhard

A DevOps engineer is deploying an application on Kubernetes. The exhibit shows the status of pods and a describe output. The frontend pod is stuck in Pending state. Which action should the engineer take to resolve the issue?

A.Reduce the resource requests in the frontend deployment manifest.
B.Add a node affinity rule to schedule on nodes with more memory.
C.Change the service type from ClusterIP to NodePort.
D.Modify the image pull policy to Always.
AnswerA

A pod stuck in Pending with insufficient-resource events means no node satisfies its CPU or memory requests. Lowering those requests lets the scheduler place the pod on existing nodes, resolving the constraint without adding capacity.

Why this answer

The frontend pod is stuck in Pending state because the cluster nodes lack sufficient resources (CPU or memory) to satisfy the pod's resource requests. Reducing the resource requests in the deployment manifest lowers the scheduling threshold, allowing the pod to fit on an available node. This directly addresses the most common cause of Pending pods: insufficient allocatable resources on any node.

Exam trap

CompTIA often tests the misconception that changing service types or image pull policies can resolve scheduling failures, when the root cause is almost always resource insufficiency or taints/tolerations.

How to eliminate wrong answers

Option B is wrong because adding a node affinity rule does not free up resources; it only constrains scheduling to specific nodes, which would likely fail if those nodes already lack capacity. Option C is wrong because changing the service type from ClusterIP to NodePort affects external access, not pod scheduling or resource availability. Option D is wrong because modifying the image pull policy to Always only forces a fresh image pull on pod start; it does not resolve resource constraints that prevent the pod from being scheduled.

357
MCQeasy

A cloud engineer needs to collect and query log data from multiple cloud services in a centralized location. Which cloud service should be used for centralized log management?

A.Audit logging service
B.Monitoring service
C.Logging service
D.Storage service
AnswerC

A dedicated logging service ingests and indexes log data from multiple cloud services into one queryable store, satisfying the centralisation requirement. Unlike raw object storage, it provides native search, filtering and retention across heterogeneous sources, so the engineer queries all services from a single pane rather than correlating separate exports manually.

Why this answer

A dedicated logging service is designed to ingest, store, and query log data from multiple sources in a centralized location, providing search, filtering, and retention capabilities. It is the purpose-built tool for centralized log management, unlike audit logging (which captures specific compliance events) or monitoring (which focuses on metrics and alerts).

Exam trap

The trap here is conflating 'audit logging' with general 'logging' — candidates see 'log' in the audit option and pick it, missing that audit logging is scoped to compliance events rather than centralized aggregation of all service logs.

How to eliminate wrong answers

Option A is wrong because an audit logging service captures compliance and security-relevant events for a specific scope, not general-purpose centralized log aggregation and querying across many services. Option B is wrong because a monitoring service focuses on metrics, dashboards, and alerting rather than ingesting and querying raw log data. Option D is wrong because a storage service only stores objects or files; it does not provide log ingestion pipelines, indexing, or query capabilities needed for centralized log management.

358
Multi-Selecthard

A cloud engineer is planning a disaster recovery drill for a critical application that spans multiple availability zones. The drill must validate RTO and RPO without affecting production. Which THREE actions should the engineer include? (Choose three.)

Select 3 answers
A.Perform a failover to the secondary environment using production data
B.Terminate production instances to simulate a disaster
C.Verify that the recovered data is consistent with the source data at the last replication point
D.Delete all backups to ensure they are not used during the drill
E.Monitor the time taken to complete the failover and recovery
AnswersA, C, E

Failing over to the secondary environment with production data validates the real recovery path, exercising actual RTO and RPO against live datasets rather than synthetic copies. Because the secondary environment is isolated from production, the drill confirms recovery capability without disrupting live workloads, satisfying the requirement to test recovery objectives non-disruptively.

Why this answer

Option A is correct because a DR drill must actually exercise the failover to the secondary environment using production data (or a current copy of it) to realistically validate that the standby environment can take over and meet the target RTO and RPO. Option C is correct because validating RPO requires confirming that the recovered data matches the source data as of the last replication point, proving no data loss beyond the defined objective. Option E is correct because measuring the elapsed time from disaster declaration through failover and recovery is the only way to verify the actual RTO against the target.

Option B is wrong because terminating production instances would cause a real outage, violating the requirement that the drill not affect production. Option D is wrong because deleting backups destroys recovery capability and is a dangerous, non-standard practice that would undermine rather than validate DR readiness.

Exam trap

CV0-004 often tests whether candidates understand that DR drills must not disrupt production, tempting them to select destructive actions like terminating instances or deleting backups as part of the test.

359
MCQhard

A financial services firm stores regulated customer records in an object storage bucket in a public cloud. A compliance auditor requires that every object be encrypted with a customer-managed key so the firm can revoke access instantly and prove key custody, while still allowing the provider to perform envelope encryption for performance. Which configuration meets these requirements?

A.Enable provider-managed default encryption on the bucket using keys the cloud provider generates and rotates automatically.
B.Configure the bucket to use a customer-managed key stored in the cloud key management service, with automatic key rotation and an audit trail of key usage.
C.Encrypt each object client-side with an application-held symmetric key before uploading, and store the ciphertext in the bucket.
D.Apply a bucket policy that denies unencrypted uploads and rely on transport layer security to protect objects at rest.
AnswerB

Customer-managed keys in the provider's key management service keep custody with the organization, allow immediate revocation by disabling or deleting the key, and produce an auditable usage trail. The provider still performs envelope encryption, generating a data key per object that is wrapped by the customer-managed key, so performance and server-side functionality are preserved while compliance evidence is generated.

Why this answer

Customer-managed keys held in the cloud key management service satisfy custody and revocation requirements because the organization controls the key lifecycle and can disable the key to cut off decryption instantly. The provider still performs envelope encryption by generating per-object data keys wrapped by the customer-managed key, which keeps performance high and maintains an auditable record of every cryptographic operation.

Exam trap

The trap here is conflating encryption at rest with key custody, since provider-managed default encryption encrypts data but leaves the organization unable to revoke access.

360
Multi-Selectmedium

A cloud administrator notices that an IAM user has permissions that are not explicitly assigned. The administrator suspects that the user is inheriting permissions through group membership or role assignment. Which TWO methods can the administrator use to identify all effective permissions for this user? (Choose TWO.)

Select 2 answers
A.List the user's group memberships and examine the policies attached to those groups and any roles the user can assume.
B.Review the user's recent access logs to see which actions were allowed.
C.Check the resource-based policies on each resource the user might access.
D.Use a 'simulate principal policy' API call to evaluate the user's effective permissions.
E.Log in as the root user and run a permissions report.
AnswersA, D

This helps in understanding the inherited permissions.

Why this answer

Group memberships and assumable roles are common sources of inherited permissions. By listing the user's groups and examining the policies attached to those groups, as well as any roles the user can assume, the administrator can trace the origin of the unexpected permissions. This method directly identifies the inheritance chain that grants permissions not explicitly assigned to the user.

Exam trap

CompTIA often tests the distinction between inherited permissions (from groups/roles) and explicit permissions, and the trap here is that candidates may confuse reviewing access logs (which show past actions) with evaluating effective permissions (which shows potential actions).

361
MCQeasy

An organization is moving sensitive data to the cloud and must ensure it is encrypted while stored on disk. Which type of encryption should be implemented?

A.Encryption in transit
B.Encryption at rest
C.Hashing
D.Tokenization
AnswerB

Encryption at rest protects data written to persistent storage, such as cloud disks and object stores, by encrypting it before it is saved. This directly satisfies the requirement that sensitive data remain encrypted while stored on disk.

Why this answer

Encryption at rest protects data stored on disk, typically using AES-256.

362
MCQeasy

A cloud administrator needs to deploy a new version of an application to a Kubernetes cluster. The administrator wants to update the application without downtime and ensure that if the new version fails, the deployment automatically rolls back to the previous version. Which Kubernetes resource should the administrator use?

A.Deployment
B.StatefulSet
C.DaemonSet
D.Job
AnswerA

A Kubernetes Deployment manages the rollout of new versions by creating a ReplicaSet and gradually replacing pods. It supports rolling updates and automatic rollback if the new version fails health checks, ensuring zero downtime and safe deployment, which matches the administrator's requirements.

Why this answer

A Kubernetes Deployment is the correct resource because it provides declarative updates for pods and ReplicaSets, enabling rolling updates and automatic rollbacks. It ensures that the application remains available during updates and reverts to the previous version if the new version fails. Other resources are designed for different use cases and do not offer these capabilities.

Exam trap

The trap here is assuming that any workload controller can handle rolling updates and rollbacks, but only Deployments are specifically designed for stateless application version management with automatic rollback.

363
MCQeasy

An organization is using Azure DevOps to implement a CI/CD pipeline. In which stage of the pipeline would automated unit tests typically be executed?

A.Deploy
B.Build
C.Verify
D.Source
AnswerB

Automated unit tests run during the Build stage, immediately after compilation and before artefacts are published. Executing them here fails fast on broken code, satisfying the stem's CI/CD requirement by gating later Release and Deploy stages on passing tests.

Why this answer

In a typical CI/CD pipeline, automated unit tests are executed during the Build stage, immediately after code compilation, to validate that individual components function correctly before any deployment. This early feedback loop catches defects quickly and prevents broken code from progressing to later stages. The Build stage is where code is compiled, packaged, and unit-tested.

Exam trap

CV0-004 often tests the confusion between Build and Verify/Test stages, causing candidates to place unit tests in a later stage when they should be executed during the Build stage for early feedback.

How to eliminate wrong answers

Option A is wrong because the Deploy stage is where the built and tested artifacts are released to an environment; unit tests are not typically run there. Option C is wrong because the Verify stage (or Test stage) usually runs integration, system, or acceptance tests, not unit tests; unit tests belong earlier in the pipeline. Option D is wrong because the Source stage is where code is checked out or triggered, not where tests are executed.

364
MCQeasy

Refer to the exhibit. A cloud administrator runs this command on a VM. Which of the following is most likely causing the high 'wa' value?

A.Disk I/O bottleneck
B.Network congestion
C.High CPU load
D.Insufficient memory
AnswerA

The 'wa' column in top or vmstat measures CPU time spent waiting on I/O completion. A sustained high value indicates processes blocked on storage, so the disk subsystem is the bottleneck. Memory pressure or CPU saturation would raise different counters, such as 'si'/'so' or 'us'/'sy'.

Why this answer

The 'wa' value in the output of the 'top' or 'vmstat' command represents the percentage of time the CPU spends waiting for I/O operations to complete. A high 'wa' value indicates that the CPU is frequently idle because it is waiting for data from storage devices, which is a classic symptom of a disk I/O bottleneck. This occurs when the storage subsystem cannot keep up with the read/write requests from the VM, causing the CPU to stall.

Exam trap

A common trap in CompTIA Cloud+ exams is to misinterpret a high 'wa' value as a symptom of high CPU load or memory pressure, when in fact it specifically indicates the CPU is waiting for disk I/O, not that it is busy processing.

How to eliminate wrong answers

Option B is wrong because network congestion would manifest as high 'si' (softirq) or 'st' (steal time) values, or as packet drops and latency in network-specific metrics, not as CPU wait time for I/O. Option C is wrong because high CPU load is indicated by a high 'us' (user) or 'sy' (system) value, not 'wa'; a high 'wa' actually means the CPU is idle waiting for I/O, not busy processing. Option D is wrong because insufficient memory typically causes high 'si' and 'so' (swap in/out) values in vmstat or high 'wa' only indirectly if swapping causes heavy disk I/O, but the direct cause of a high 'wa' is the disk I/O bottleneck itself, not the memory shortage.

365
MCQeasy

A company wants to deploy a Lambda function that processes objects uploaded to an S3 bucket. Which event trigger should be configured on the Lambda function?

A.API Gateway
B.CloudWatch Events
C.S3 bucket event notification
D.SQS
AnswerC

S3 bucket event notifications push records directly to Lambda when objects are created, satisfying the stem's requirement to process uploads automatically. This native integration invokes the function per object without polling, unlike scheduled or manual triggers. Configuring the notification on the bucket, filtered by event type, delivers the object metadata Lambda needs.

Why this answer

S3 bucket event notifications can be configured to directly invoke a Lambda function when objects are uploaded. This is the native, serverless integration where S3 publishes an event (e.g., s3:ObjectCreated:Put) to Lambda, triggering the function automatically without any intermediary service.

Exam trap

CompTIA Cloud+ often tests the misconception that SQS or CloudWatch Events are required to bridge S3 and Lambda, when in fact S3 can invoke Lambda directly via its event notification feature.

How to eliminate wrong answers

Option A is wrong because API Gateway is used to create RESTful or WebSocket APIs that trigger Lambda functions via HTTP requests, not for S3 object upload events. Option B is wrong because CloudWatch Events (now Amazon EventBridge) is used for scheduling or responding to AWS service events, but it is not the direct trigger for S3 object uploads; S3 can send events directly to Lambda without CloudWatch. Option D is wrong because SQS is a message queue service; while Lambda can poll SQS, S3 can send events directly to Lambda without needing an SQS queue as an intermediary.

366
MCQmedium

A company is migrating to a public cloud and wants to understand security responsibilities. According to the shared responsibility model, which of the following is the customer responsible for in an IaaS deployment?

A.Patching the guest operating system
B.Network infrastructure security
C.Physical security of data centers
D.Hypervisor security
AnswerA

In IaaS the provider secures the physical hosts, network and hypervisor, while the customer retains control of everything from the guest operating system upward. Patching the guest OS therefore remains the customer's responsibility, unlike PaaS or SaaS where the provider handles it.

Why this answer

In an IaaS deployment, the customer is responsible for patching the guest operating system (A). Under the shared responsibility model, the cloud provider manages the physical security, network infrastructure, and hypervisor, while the customer is responsible for the security of everything they deploy on the infrastructure, including the guest OS, applications, and data. Patching the guest OS is a customer task because the customer has control over the OS and its configuration.

Exam trap

The trap is confusing the responsibilities of the cloud provider and customer, often assuming the provider handles more than they do, such as OS patching in IaaS.

How to eliminate wrong answers

Option B is wrong because network infrastructure security (e.g., routers, switches, physical network) is managed by the cloud provider in IaaS. Option C is wrong because physical security of data centers is always the responsibility of the cloud provider. Option D is wrong because hypervisor security is managed by the cloud provider, as the hypervisor is part of the virtualization infrastructure.

367
MCQeasy

A cloud administrator needs to receive real-time notifications when CPU utilization exceeds 90% on a production server. Which AWS service should be used to trigger an alert based on a metric threshold?

A.CloudWatch Alarms
B.Amazon SNS
C.AWS Config
D.AWS CloudTrail
AnswerA

CloudWatch Alarms evaluate metric thresholds against a defined period and trigger actions when breached. Configuring an alarm on the EC2 CPUUtilization metric above 90% delivers the real-time notification the administrator requires, unlike dashboards or logs.

Why this answer

CloudWatch Alarms monitor CloudWatch metrics and trigger actions when a metric crosses a defined threshold, such as CPU utilization exceeding 90% for a specified number of evaluation periods. Alarms can send notifications via Amazon SNS, trigger Auto Scaling, or invoke Lambda functions. This makes CloudWatch Alarms the correct service for threshold-based alerting on metrics.

Exam trap

CV0-004 often tests the confusion between CloudWatch Alarms (which evaluate thresholds) and Amazon SNS (which delivers notifications), tempting candidates to pick SNS when the question asks what triggers the alert.

How to eliminate wrong answers

Option B is wrong because Amazon SNS is a pub/sub notification service that delivers messages, but it does not evaluate metric thresholds on its own; it must be triggered by an alarm or another event source. Option C is wrong because AWS Config evaluates resource configuration compliance against rules, not real-time metric thresholds. Option D is wrong because AWS CloudTrail records API activity for auditing, not performance metrics or threshold-based alerting.

368
MCQmedium

During a deployment using a script, an administrator receives a 'Permission Denied' error. What is the most likely cause?

A.The service account lacks necessary IAM roles
B.Network latency is causing timeouts
C.The deployment is targeting the wrong region
D.The instance has insufficient storage
AnswerA

The deployment script authenticates as a service account, and 'Permission Denied' indicates that identity lacks the IAM roles required for the API calls it makes. Granting the missing roles resolves the authorisation failure, directly addressing the insufficient privileges constraint in the stem.

Why this answer

The 'Permission Denied' error during a scripted deployment most commonly occurs when the identity executing the script (e.g., a service account) lacks the necessary IAM permissions to perform the required actions, such as creating or modifying resources. IAM roles define what actions are allowed, so missing roles directly cause authorization failures. Network latency, wrong region, or insufficient storage would typically produce different errors (timeouts, resource not found, or disk full).

Exam trap

CV0-004 often tests the distinction between authorization errors (permission denied) and other deployment issues like network or configuration errors; candidates may overlook IAM as the root cause.

How to eliminate wrong answers

Option B is wrong because network latency causes timeouts or connection errors, not permission denied. Option C is wrong because targeting the wrong region would result in resource not found or deployment to an unintended location, not an authorization error. Option D is wrong because insufficient storage would lead to disk space errors, not permission issues.

369
Multi-Selectmedium

A cloud operations team needs to reduce the mean time to recovery for a microservices application running on Amazon EKS. They want to detect service degradation earlier and automatically replace unhealthy pods without manual intervention. Which TWO actions should the team take? (Choose two.)

Select 2 answers
A.Deploy the application as a Kubernetes Deployment with a ReplicaSet so that failed pods are automatically recreated to maintain the desired replica count.
B.Increase the node group size and enable cluster autoscaler so that more nodes are available when pods fail.
C.Enable AWS CloudTrail logging for the EKS control plane and create alarms on API error rates to trigger automatic pod replacement.
D.Configure liveness and readiness probes on each container so Kubernetes can detect and restart unhealthy pods and remove them from service endpoints.
E.Set the pod restartPolicy to Always for all containers and rely on the kubelet to recreate the entire pod when a container exits.
AnswersA, D

A Deployment manages a ReplicaSet that continuously reconciles the observed state to the desired replica count. If a pod is deleted or fails, the ReplicaSet creates a replacement automatically. This self-healing behavior is fundamental to reducing manual intervention and recovery time for microservices on EKS.

Why this answer

Reducing recovery time requires both detecting unhealthy containers and replacing them automatically. Liveness and readiness probes give Kubernetes the signals to restart unresponsive containers and to stop sending traffic to pods that are not ready. A Deployment with a ReplicaSet continuously reconciles toward the desired replica count, recreating failed pods.

Together these mechanisms deliver automatic detection and remediation without manual intervention.

Exam trap

The trap here is treating node scaling or audit logging as self-healing mechanisms, when pod-level health probes and controller reconciliation are what actually detect and replace unhealthy pods.

370
MCQeasy

A company uses a cloud load balancer to distribute traffic to web servers. The load balancer health checks are failing for all instances. The instances are running and can be accessed directly via their private IPs from within the VPC. What is the most likely cause?

A.The load balancer's cross-zone load balancing is disabled.
B.The load balancer's listeners are configured on the wrong ports.
C.The security group of the instances is not allowing traffic from the load balancer.
D.The instances are not registered with the target group.
AnswerC

The load balancer's health checks originate from its own nodes, so the instances' security group must permit inbound traffic from the load balancer. Direct private IP access works because that traffic comes from within the VPC, not the load balancer.

Why this answer

The most likely cause is that the security group attached to the web server instances does not include an inbound rule allowing traffic from the load balancer's source IP addresses or the load balancer's security group. Even though the instances are healthy and reachable via private IPs from within the VPC, the load balancer's health check probes (typically HTTP/HTTPS or TCP) are blocked by the instance-level firewall, causing all health checks to fail.

Exam trap

The trap here is that candidates assume that because the instances are reachable via private IP from within the VPC, the load balancer should also be able to reach them, but they forget that the load balancer's health check traffic is subject to the instance's security group rules, which must explicitly permit the load balancer's source.

How to eliminate wrong answers

Option A is wrong because cross-zone load balancing affects how traffic is distributed across instances in different Availability Zones, not the ability of health checks to reach instances. Option B is wrong because listener port misconfiguration would cause client requests to fail, but health checks are sent on the configured health check port, which is independent of the listener port; the question states health checks are failing, not client traffic. Option D is wrong because if instances were not registered with the target group, the load balancer would not even attempt health checks; the question states health checks are failing, implying the instances are registered but unreachable by the health check probes.

371
MCQhard

A company running a critical web application wants to protect against SQL injection and cross-site scripting attacks. The application is behind a load balancer. Which type of service should be deployed to provide this protection?

A.Network firewall
B.DDoS protection service
C.Intrusion detection system
D.Web application firewall (WAF)
AnswerD

A WAF inspects HTTP/HTTPS traffic at layer 7, matching signatures to block SQL injection and cross-site scripting payloads before they reach the application. Deployed behind the load balancer, it satisfies the requirement to filter malicious web requests targeting this critical application.

Why this answer

A web application firewall (WAF) is designed to protect web applications from common web exploits like SQL injection and cross-site scripting. It can be integrated with load balancers to inspect HTTP/HTTPS traffic and filter malicious requests based on customizable rules. This makes it the correct choice for the described threat scenario.

Exam trap

The trap here is that candidates often confuse a web application firewall with a DDoS protection service, thinking the latter provides application-layer attack protection. However, DDoS protection focuses on volumetric attacks while a WAF handles web-specific exploits like SQL injection and XSS.

How to eliminate wrong answers

Option A is wrong because AWS Network Firewall is a stateful managed firewall for VPC network traffic, operating at layers 3-4 and 7 for network protocols, but it does not provide application-layer inspection for SQL injection or XSS payloads in HTTP requests. Option B is wrong because AWS Shield Advanced provides DDoS protection against volumetric and state-exhaustion attacks, not against application-layer threats like SQL injection or XSS. Option C is wrong because AWS GuardDuty is a threat detection service that analyzes VPC flow logs, DNS logs, and CloudTrail events for malicious activity, but it does not actively block or filter web application attacks like SQL injection or XSS.

372
MCQhard

A cloud operations team is implementing structured logging for better querying. They have decided to use JSON format. What is a key benefit of structured logging over unstructured logging?

A.Easier to read for humans
B.Enables querying specific fields
C.Reduced storage costs
D.Faster log ingestion
AnswerB

JSON logging stores each attribute as a named key-value pair, so the logging platform parses and indexes individual fields. That lets operators filter and aggregate on specific fields, such as status or user ID, rather than grepping raw text lines.

Why this answer

Structured logging (e.g., JSON) enables efficient querying and filtering of log data.

373
MCQhard

A company is designing a cloud network architecture for a three-tier application. The web tier must be accessible from the internet, the application tier should only be accessible from the web tier, and the database tier should only be accessible from the application tier. The company uses a single VPC with multiple subnets. The security team requires that all traffic between tiers be encrypted in transit. The architect proposes using security groups and network ACLs. Which combination of security group rules meets these requirements while following the principle of least privilege?

A.Web: inbound 443 from 0.0.0.0/0, outbound to app SG:8443. App: inbound from web SG:8443, outbound to db SG:3306. DB: inbound from app SG:3306.
B.Web: inbound 443 from 0.0.0.0/0, outbound to 0.0.0.0/0:0-65535. App: inbound from web SG:443, outbound to 0.0.0.0/0:0-65535. DB: inbound from app SG:3306, outbound to 0.0.0.0/0:0-65535.
C.Web: inbound 443 from 0.0.0.0/0 and 22 from 0.0.0.0/0, outbound to app SG:443. App: inbound from web SG:443, outbound to db SG:3306. DB: inbound from app SG:3306.
D.Web: inbound 443 from 0.0.0.0/0, outbound to app subnet CIDR:1433. App: inbound from web subnet CIDR:443, outbound to db subnet CIDR:3306. DB: inbound from app subnet CIDR:3306.
AnswerA

Uses security groups for fine-grained control, allows only required traffic, and encrypts traffic (HTTPS on web, database encryption assumed).

Why this answer

It uses security group (SG) references to enforce strict, stateful traffic flow between tiers: the web SG allows inbound HTTPS (443) from the internet and outbound to the app SG on port 8443; the app SG allows inbound only from the web SG on port 8443 and outbound to the DB SG on port 3306; the DB SG allows inbound only from the app SG on port 3306. This follows least privilege by restricting each tier’s communication to only the necessary ports and source/destination SGs, and the use of TLS/SSL on port 443 and 8443 ensures encryption in transit as required.

Exam trap

The trap here is that candidates often confuse security group statefulness with network ACL statelessness, or they mistakenly use broad CIDR ranges (like 0.0.0.0/0) for outbound rules instead of specific SG references, violating least privilege and encryption requirements.

How to eliminate wrong answers

Option B is wrong because it allows overly permissive outbound rules (0.0.0.0/0 on all ports) from each tier, violating least privilege by permitting unnecessary outbound traffic and potentially exposing the app and DB tiers to the internet. Option C is wrong because it includes inbound SSH (port 22) from 0.0.0.0/0 on the web tier, which is not required for the three-tier architecture and introduces an unnecessary attack surface; also, it uses port 443 for web-to-app traffic instead of the specified port 8443, which may not match the application’s encryption requirements. Option D is wrong because it uses subnet CIDR ranges instead of security group references, which is less granular and does not automatically adapt to changes in instance IPs; additionally, it uses port 1433 (SQL Server) instead of the required port 3306 (MySQL) for the database tier, and port 443 for web-to-app traffic instead of 8443.

374
MCQhard

A cloud engineer is troubleshooting an issue where an application running in a container on a Kubernetes cluster is unable to resolve DNS names. The cluster uses CoreDNS. The engineer checks the CoreDNS pod logs and sees no errors. Which of the following should the engineer check next?

A.The Kubernetes DNS service IP address
B.The container's /etc/resolv.conf file
C.The cloud provider's DNS resolver settings
D.The network policy for the namespace
AnswerB

With CoreDNS logging no errors, the fault likely lies in the pod's own DNS configuration. The container's /etc/resolv.conf supplies the nameserver and search domains used for lookups, so an incorrect or missing entry there would break name resolution despite healthy cluster DNS.

Why this answer

The container's /etc/resolv.conf file contains the DNS configuration, including the nameserver IP and search domains. If CoreDNS logs show no errors, the issue may be that the container is not using the correct DNS server or has a misconfigured resolv.conf. Checking this file is the next logical step.

Exam trap

CV0-004 often tests the assumption that DNS issues are always server-side, leading candidates to overlook client-side configuration like resolv.conf.

How to eliminate wrong answers

Option A is wrong because the Kubernetes DNS service IP is typically correct and automatically injected; if it were wrong, CoreDNS logs might show errors or the issue would be widespread. Option C is wrong because the cloud provider's DNS resolver settings are not directly used by pods unless configured, and CoreDNS handles DNS for the cluster. Option D is wrong because a network policy blocking DNS traffic would likely cause timeouts and could be checked, but since CoreDNS logs show no errors, the issue is more likely on the client side.

375
Multi-Selectmedium

A cloud architect is designing a highly available application on AWS. The application must be fault-tolerant and able to withstand the failure of an entire Availability Zone. Which TWO actions should the architect take? (Select TWO.)

Select 2 answers
A.Store application state on the local instance store
B.Deploy EC2 instances in a single Availability Zone
C.Use a single large EC2 instance
D.Deploy EC2 instances across two or more Availability Zones
E.Configure an Auto Scaling group to span multiple Availability Zones
AnswersD, E

Distributing EC2 instances across two or more Availability Zones ensures that an AZ-wide failure only removes part of the fleet, leaving capacity in surviving zones. This directly satisfies the stem's requirement to withstand the failure of an entire Availability Zone.

Why this answer

Deploying across multiple Availability Zones and using an auto scaling group across those zones ensures that if one zone fails, the application continues in the other zones.

Page 4

Page 5 of 12

Page 6