Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 376–450

834 questions total · 12pages · All types, answers revealed

Page 5

Page 6 of 12

Page 7
376
Multi-Selecthard

A cloud engineer is troubleshooting a performance issue where a web server cluster experiences high latency during peak hours. The cluster uses an auto-scaling group behind a load balancer. Which THREE steps should the engineer take to identify the root cause?

Select 3 answers
A.Monitor CPU and memory utilization on the web servers
B.Analyze web server access logs for slow requests
C.Check the load balancer's backend instance health status
D.Reduce the number of instances in the auto-scaling group
E.Review security group rules for the load balancer
AnswersA, B, C

High latency during peak hours may stem from CPU or memory saturation on the web servers themselves. Monitoring both metrics reveals whether instances are resource-constrained, which would prevent the auto-scaling group from serving requests promptly behind the load balancer.

Why this answer

Option A is correct because monitoring CPU and memory utilization on the web servers reveals whether the instances are resource-saturated during peak hours, which is a common cause of high latency in an auto-scaling cluster. Option B is correct because analyzing web server access logs for slow requests helps pinpoint which endpoints, queries, or upstream dependencies are contributing to the latency, providing concrete evidence of the bottleneck. Option C is correct because checking the load balancer's backend instance health status verifies whether unhealthy or failing instances are being served or whether health checks are flapping, which directly impacts response times.

Option D is incorrect because reducing the number of instances in the auto-scaling group would decrease capacity and likely worsen latency rather than help diagnose the root cause. Option E is incorrect because reviewing security group rules for the load balancer addresses connectivity and access control, not performance degradation during peak hours.

Exam trap

The trap here is that candidates may think reducing instances (Option D) is a valid troubleshooting step, but it is a remediation action that can mask the root cause and potentially crash the application under load.

377
MCQmedium

A company uses a SaaS application for customer relationship management (CRM). The security team wants to monitor user activities and enforce data loss prevention (DLP) policies. Which type of security tool should be deployed?

A.Intrusion Detection System (IDS)
B.Security Information and Event Management (SIEM)
C.Cloud Access Security Broker (CASB)
D.Web Application Firewall (WAF)
AnswerC

A CASB sits between users and the SaaS CRM, providing activity monitoring and enforcing DLP policies on cloud traffic. It satisfies the stem's constraint of governing a SaaS application, which endpoint or network tools cannot inspect directly.

Why this answer

A Cloud Access Security Broker (CASB) provides visibility into SaaS usage, monitors user activities, and can enforce DLP policies across cloud applications.

378
MCQeasy

What is the primary benefit of using Infrastructure as Code (IaC)?

A.Improved network performance
B.Full manual control over resources
C.Consistent and repeatable deployments
D.Lower cloud service costs
AnswerC

IaC defines infrastructure declaratively in version-controlled templates, so Microsoft Entra ID-integrated pipelines provision identical environments on every run. This eliminates configuration drift and manual error, directly satisfying the stem's demand for the primary benefit: consistent, repeatable deployments across environments.

Why this answer

The primary benefit of Infrastructure as Code (IaC) is that it enables consistent and repeatable deployments by defining infrastructure in code, which can be version-controlled, tested, and automatically provisioned. This reduces human error and ensures identical environments across stages. Improved network performance, full manual control, and lower costs are not the primary benefits; IaC may indirectly affect costs but not as its main purpose.

Exam trap

CV0-004 often tests the core purpose of IaC; candidates might confuse it with configuration management or think it's about cost savings, but the key is consistency and repeatability.

How to eliminate wrong answers

Option A is wrong because IaC does not directly improve network performance; it's about provisioning and management. Option B is wrong because IaC reduces manual control by automating provisioning, not enhancing manual control. Option D is wrong because while IaC can lead to cost savings through efficient resource use, it is not the primary benefit; consistency and repeatability are the core advantages.

379
MCQeasy

Which of the following is the best practice for securely storing secrets such as database passwords in a cloud environment?

A.Hard-code the secrets in the application code.
B.Store secrets in a configuration file in the repository.
C.Encrypt secrets and store them in a shared storage.
D.Use a dedicated secrets management service.
AnswerD

A dedicated secrets management service stores credentials encrypted at rest, enforces fine-grained access policies, and supports rotation and auditing. This removes hard-coded passwords from code and configuration, satisfying the requirement for secure secret storage rather than relying on weaker alternatives such as environment variables or vault-less files.

Why this answer

A dedicated secrets management service (e.g., Azure Key Vault, AWS Secrets Manager, HashiCorp Vault) is the best practice because it centralizes secret storage, enforces access control, provides audit logging, and supports automatic rotation. Applications retrieve secrets at runtime via managed identities or short-lived tokens, so secrets never persist in code or repositories. This minimizes the blast radius if a repository or configuration file is compromised.

Exam trap

CV0-004 often tests the misconception that encrypting secrets in shared storage is sufficient, but the exam expects recognition that centralized secrets management with access control and rotation is the true best practice.

How to eliminate wrong answers

Option A is wrong because hard-coding secrets in application code exposes them to anyone with source access and makes rotation extremely difficult. Option B is wrong because storing secrets in a configuration file in the repository—even if the repo is private—risks accidental exposure through commits, forks, or CI logs. Option C is wrong because encrypting secrets and storing them in shared storage still requires managing the encryption key and access permissions, and it lacks the centralized auditing and rotation capabilities of a dedicated service.

380
Multi-Selecteasy

Which TWO of the following are common security concerns specific to a public cloud infrastructure?

Select 2 answers
A.Exposure of insecure application programming interfaces (APIs).
B.Physical theft of servers from data centers.
C.Packet sniffing on the provider's internal network.
D.Misconfiguration of cloud resources leading to data exposure.
E.Hypervisor-level malware.
AnswersA, D

Public cloud APIs are internet-facing management interfaces, so misconfiguration or weak authentication exposes them to unauthorised access. This concern is specific to public cloud because the provider's control plane is reachable externally, unlike isolated private infrastructure.

Why this answer

Option A is correct because public cloud services are managed and automated through publicly reachable REST APIs (e.g., AWS EC2, S3, IAM endpoints), and insecure or unauthenticated APIs are a leading cloud-specific attack vector, as seen in breaches like the 2019 Capital One incident. Option D is correct because cloud resources are provisioned via declarative templates and consoles, and a single misconfigured S3 bucket ACL, security group, or IAM policy can expose data to the internet, making misconfiguration one of the most common causes of cloud data breaches. Option B is not a cloud-specific concern because physical server theft is mitigated by the provider's data center controls and is a general on-premises risk, not unique to public cloud.

Option C is not cloud-specific because packet sniffing on internal networks applies to any shared network environment and is largely mitigated by encryption (TLS) and virtual network isolation. Option E is not cloud-specific because hypervisor-level malware affects any virtualization platform, including private and on-premises environments, not just public cloud.

Exam trap

CV0-004 often tests the shared responsibility model — candidates pick provider-side concerns like physical theft or hypervisor malware, forgetting those are the cloud provider's responsibility, not the customer's.

381
MCQhard

A cloud architect is designing a VPC with three tiers: web, application, and database. Which subnet design provides the best security posture?

A.Web in public subnet, app and database in private subnets with appropriate routing
B.Web and app in public subnets, database in private subnet
C.All tiers in private subnets with a VPN
D.All tiers in the same public subnet with security groups
AnswerA

Placing only the web tier in a public subnet limits internet exposure to the presentation layer, while application and database tiers remain unreachable directly. Routing through NAT gateways or load balancers enforces tiered segmentation, satisfying least-privilege network access.

Why this answer

It follows the principle of least privilege and network segmentation. Placing the web tier in a public subnet allows it to receive internet traffic, while the application and database tiers reside in private subnets with no direct internet access. This design ensures that only the web tier is exposed, and the database is isolated, accessible only via the application tier through controlled routing, significantly reducing the attack surface.

Exam trap

The CV0-004 exam often tests the misconception that security groups alone are sufficient for network segmentation, leading candidates to choose Option D, but security groups are stateful firewalls at the instance level and do not replace the need for subnet-level isolation and controlled routing paths.

How to eliminate wrong answers

Option B is wrong because placing the application tier in a public subnet exposes it to the internet, increasing the risk of direct attacks on application logic and potentially compromising the database. Option C is wrong because placing all tiers in private subnets with a VPN is overly restrictive and impractical for a web-facing application; it would require all users to have VPN access, which is not typical for public web services. Option D is wrong because placing all tiers in the same public subnet violates network segmentation best practices; security groups alone cannot prevent lateral movement between tiers if an attacker compromises one instance, as they share the same network broadcast domain and routing path.

382
MCQeasy

Which storage type is most suitable for hosting a shared file system accessible by multiple virtual machines in a cloud environment?

A.Archive storage
B.Object storage
C.Block storage
D.File storage
AnswerD

File storage exposes SMB or NFS shares, so several virtual machines can mount the same file system concurrently. Block storage attaches to a single instance, and object storage lacks the shared hierarchical file semantics required.

Why this answer

File storage (option D) is the correct choice because it provides a hierarchical, shared file system that multiple virtual machines can mount simultaneously using standard protocols like NFS (Network File System) or SMB/CIFS. This allows concurrent read/write access with file-level locking, making it ideal for shared workloads such as home directories, content management, or collaboration tools in a cloud environment.

Exam trap

The CV0-004 exam often tests the misconception that block storage can be shared by multiple VMs, but the trap here is that block storage is a single-attach device unless you implement a complex clustered file system (e.g., GFS2 or OCFS2), which is not the default or simplest solution for shared access.

How to eliminate wrong answers

Option A is wrong because archive storage is designed for long-term, infrequently accessed data with high retrieval latency, not for active, concurrent file sharing by multiple VMs. Option B is wrong because object storage uses a flat namespace with HTTP-based APIs (e.g., S3) and lacks native file system semantics like hierarchical directories and file-level locking, making it unsuitable for shared file system access. Option C is wrong because block storage presents raw volumes (e.g., iSCSI or NVMe-oF) that can only be attached to a single VM at a time; it does not support concurrent multi-VM access without a clustered file system overlay, which adds complexity and is not a native feature.

383
MCQeasy

A cloud administrator is asked to give the security team read-only visibility into all objects stored in an Amazon S3 bucket used for application logs, without granting the ability to delete or overwrite any object. The security team authenticates as an IAM role. Which action should the administrator take?

A.Apply an S3 bucket policy that allows s3:* for the security team's role principal on the bucket.
B.Enable S3 Block Public Access on the bucket and share the object URLs with the security team.
C.Attach an IAM policy granting s3:GetObject and s3:ListBucket on the bucket and its objects to the security team's role.
D.Create a presigned URL for each object and distribute the URLs to the security team.
AnswerC

Granting s3:GetObject on the object ARN and s3:ListBucket on the bucket ARN gives exactly the read and enumerate permissions needed, and nothing more. Delete and overwrite operations require s3:DeleteObject and s3:PutObject, which are not included, so the team cannot modify the logs. This is the least-privilege way to satisfy the request using IAM.

Why this answer

The request is for ongoing, role-based read access limited to viewing and listing log objects. An IAM policy naming s3:GetObject on the objects and s3:ListBucket on the bucket delivers precisely that, while omitting the write and delete actions that would breach the constraint. Broad wildcards, public sharing, and per-object presigned URLs either over-grant, fail to authenticate the role, or cannot cover future objects.

Exam trap

The trap here is treating a broad s3:* bucket policy as equivalent to read-only access when it also permits destructive actions.

384
MCQeasy

A company recently migrated its on-premises backup server to a cloud virtual machine running Windows Server with a dedicated data disk for backups. The backup software is configured to write to a folder on the data disk. After two weeks, the backup jobs start failing with 'disk full' errors. The cloud engineer logs into the VM and verifies that the data disk has 500 GB of total space and the backup folder shows only 300 GB used. However, the operating system reports the disk as 100% full. The engineer also notices that the recycle bin on the data disk appears to be empty. Which of the following is the MOST likely cause of the discrepancy?

A.Shadow copies (Volume Shadow Copies) are consuming space on the data disk
B.The cloud provider has imposed a quota on the disk's storage capacity that is lower than the provisioned size
C.The recycle bin on the data disk contains deleted backup files that are not counted
D.The backup software is compressing data, causing the disk to appear full due to index fragmentation
AnswerA

Volume Shadow Copies store previous versions on the same volume, consuming space invisible to folder-size checks and the recycle bin. With 300 GB of 500 GB visible, shadow storage accounts for the hidden remainder, explaining the 100% full report despite an apparently empty recycle bin.

Why this answer

Volume Shadow Copies (VSS snapshots) on the data disk are consuming the missing ~200 GB. When backup software or Windows features create shadow copies, the space is reserved in the System Volume Information folder and is not visible in Explorer or counted against the backup folder's reported usage. The disk therefore shows 100% full even though the backup folder only reports 300 GB.

Exam trap

The trap here is assuming that 'used space in the backup folder' equals 'used space on the disk' — candidates forget that hidden system artifacts like VSS shadow copies, pagefile, and System Volume Information consume space invisibly.

How to eliminate wrong answers

Option B is wrong because cloud providers do not silently impose quotas below the provisioned disk size — the OS would see the full provisioned capacity, not a phantom 200 GB loss. Option C is wrong because the recycle bin was verified as empty, and even if it contained files, they would be counted as used space in Explorer. Option D is wrong because compression reduces on-disk usage rather than inflating it, and index fragmentation does not cause a disk to report 100% full.

385
Drag & Dropmedium

Arrange the steps to configure auto-scaling for a group of virtual machines based on CPU utilization.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First define the template, then the group, then the scaling policy, attach it, and test.

386
Multi-Selectmedium

Which THREE of the following are common causes of application performance degradation in a cloud environment? (Choose three.)

Select 3 answers
A.Insufficient number of security groups
B.Network latency and bandwidth limitations
C.Application code that is poorly optimized
D.Resource exhaustion (CPU, memory, disk I/O)
E.Overprovisioned storage
AnswersB, C, D

Cloud workloads depend on shared network paths, so latency and constrained bandwidth directly delay request and response cycles between tiers and services. This is a recognised degradation cause, distinct from code or host resource issues, and applies regardless of provider.

Why this answer

Option B (Network latency and bandwidth limitations) is correct because in cloud environments traffic often traverses multiple network hops, availability zones, or regions, and high round-trip latency or constrained throughput directly slows request/response times for distributed applications. Option C (Application code that is poorly optimized) is correct because inefficient algorithms, unindexed database queries, memory leaks, or excessive synchronous calls consume more CPU, memory, and I/O than necessary, degrading performance regardless of how much infrastructure is provisioned. Option D (Resource exhaustion (CPU, memory, disk I/O)) is correct because when an instance or container saturates its vCPU credits, RAM, or IOPS/throughput limits, requests queue and latency rises sharply, a very common cloud scaling failure mode.

Option A is not a cause of performance degradation: security groups are stateful firewalls that filter traffic, and having too few of them affects access control and manageability, not application speed. Option E is not correct because overprovisioned storage provides excess capacity and typically does not degrade performance; performance issues more often stem from underprovisioned IOPS or throughput, not from having more storage than needed.

Exam trap

CV0-004 often tests the distinction between performance degradation causes and security/configuration issues, so candidates may incorrectly select security groups or overprovisioned storage as performance problems.

387
MCQhard

An organization is deploying a multi-tier application in the cloud. The web tier uses auto scaling, and the database tier uses a managed database service. During a load test, the web tier scales up correctly, but the database performance degrades significantly, causing timeout errors. The administrator reviews the database metrics and finds that CPU and memory are normal, but the number of connections is high. Which of the following is the BEST action to resolve the issue?

A.Add read replicas to offload read traffic from the primary database.
B.Increase the maximum number of web servers in the auto scaling group.
C.Increase the compute size of the database instance.
D.Implement connection pooling on the web servers to limit database connections.
AnswerD

Database CPU and memory are normal while connection count is high, so the bottleneck is connection overhead, not compute. Connection pooling on the web servers caps and reuses database connections, directly reducing the connection count that causes the timeouts.

Why this answer

The issue is that the database is overwhelmed by a high number of connections, not by CPU or memory pressure. Connection pooling on the web servers reuses a fixed set of database connections, reducing the connection overhead and preventing the database from hitting its maximum connection limit. This directly addresses the symptom of high connection count without changing the database's compute capacity or the web tier's scaling behavior.

Exam trap

The trap here is that candidates confuse high connection count with high CPU/memory load and choose to scale the database vertically (Option C), when the real issue is connection exhaustion that is solved by pooling.

How to eliminate wrong answers

Option A is wrong because read replicas only offload read queries, but the problem is connection count, not read load; the database is likely experiencing connection exhaustion from both reads and writes. Option B is wrong because increasing the maximum number of web servers would increase the number of concurrent database connections, worsening the problem. Option C is wrong because CPU and memory are normal, so increasing compute size does not address the connection limit; the bottleneck is the maximum number of allowed connections, not resource saturation.

388
MCQeasy

A cloud administrator is configuring a Linux VM as a router. The iptables rules are shown. The administrator can SSH into the VM from the network but cannot forward traffic between interfaces. What is the most likely cause?

A.The INPUT chain has a rule dropping invalid packets
B.The INPUT chain is missing a rule to allow forwarded traffic
C.The FORWARD chain's default policy is DROP and no rules allow forwarding
D.The NAT table is misconfigured
AnswerC

SSH works because INPUT accepts it, but forwarding relies on the FORWARD chain. A default DROP policy with no ACCEPT rules silently discards packets traversing the VM, so inter-interface traffic never passes despite routing being enabled.

Why this answer

The FORWARD chain in iptables controls traffic that passes through the VM (i.e., traffic not destined for the VM itself). If its default policy is DROP and no explicit ACCEPT rules exist for forwarding, the kernel will drop all forwarded packets, preventing the VM from acting as a router. SSH access works because it uses the INPUT chain, which is separate from FORWARD.

Exam trap

The trap here is that candidates confuse the INPUT chain (for local traffic) with the FORWARD chain (for transit traffic), assuming that allowing SSH implies forwarding is also allowed, when in fact they are handled by completely separate chains.

How to eliminate wrong answers

Option A is wrong because the INPUT chain dropping invalid packets affects only traffic destined for the VM itself, not forwarded traffic; SSH connectivity proves INPUT is functional. Option B is wrong because forwarded traffic is governed by the FORWARD chain, not the INPUT chain; the INPUT chain has no role in forwarding decisions. Option D is wrong because the NAT table is used for source/destination NAT (e.g., masquerading) and does not control basic IP forwarding; even with correct NAT, packets will be dropped if the FORWARD chain blocks them.

389
MCQeasy

An organization is migrating its on-premises virtualization environment to a public cloud. The current environment uses VMware vSphere with VM templates. The cloud provider supports importing VMs in OVF format. Which step should the cloud administrator take to prepare the VMs for migration?

A.Take a snapshot of each VM and copy the snapshot files.
B.Export each VM as an OVF template.
C.Convert each VM to an ISO image.
D.Copy the VM's VMDK files and import them as VHDX.
AnswerB

Exporting each VM as an OVF template produces the Open Virtualization Format package the cloud provider accepts for import. This satisfies the migration constraint by converting vSphere VMs into a portable format the target platform can ingest.

Why this answer

The cloud provider supports importing VMs in OVF format, which is an open standard for packaging and distributing virtual appliances. Exporting each VM as an OVF template from VMware vSphere creates the necessary .ovf descriptor file and accompanying disk files (e.g., .vmdk) that the provider can directly import. This is the correct preparation step because it produces the exact format required by the target cloud platform.

Exam trap

The trap here is that candidates may confuse 'export as OVF' with other common VMware operations like taking snapshots or copying VMDK files, not realizing that OVF is the specific format required by the cloud provider for direct import.

How to eliminate wrong answers

Option A is wrong because a snapshot captures a point-in-time state of the VM but does not produce a portable, importable format like OVF; snapshot files are tied to the original VM and cannot be directly imported into a cloud provider. Option C is wrong because an ISO image is used for OS installation media or data discs, not for virtual machine disk images; converting a VM to ISO would lose the VM's configuration, snapshots, and file system structure. Option D is wrong because VMDK files are VMware's native disk format, but the provider expects OVF format, not raw VMDK or VHDX; importing VMDK files directly would require additional conversion steps and the provider's import process specifically requires the OVF package.

390
Multi-Selectmedium

A cloud operations team is hardening a Microsoft Azure subscription that hosts production virtual machines. The security lead wants to ensure that only approved operating system images can be deployed and that any drift from the baseline configuration is automatically detected. Which TWO Azure services should be implemented to meet these goals? (Choose two.)

Select 2 answers
A.Azure Policy with a custom definition restricting allowed image publishers and offers
B.Azure Policy with the built-in 'Allowed virtual machine size SKUs' initiative
C.Azure Automation State Configuration (DSC)
D.Azure Advisor security recommendations
E.Microsoft Defender for Cloud regulatory compliance dashboard
AnswersA, C

Azure Policy can enforce that VMs may only be created from approved image publishers, offers, and SKUs by evaluating the imageReference property. This directly prevents deployment of unapproved operating system images. Combined with a drift-detection service, it fulfills the requirement to restrict images to an approved set.

Why this answer

Azure Policy with a custom image restriction definition enforces that only approved OS images can be deployed, directly satisfying the image control requirement. Azure Automation State Configuration continuously evaluates VMs against a DSC baseline and reports drift, satisfying the drift detection requirement. Together they provide both preventive and detective controls for the production subscription.

Exam trap

The trap here is selecting broad posture or advisory tools like Defender for Cloud or Advisor, which report on compliance but do not enforce image approval or continuously detect configuration drift.

391
MCQhard

Which deployment strategy minimizes risk by gradually shifting a small percentage of traffic to a new version before full rollout?

A.Canary deployment
B.In-place deployment
C.Rolling deployment
D.Blue-green deployment
AnswerA

A canary deployment routes a small, controlled percentage of live traffic to the new version while the majority continues to the stable release. Monitoring that subset exposes defects with limited blast radius, allowing rollback before full rollout, which is precisely the gradual, risk-minimising shift the question describes.

Why this answer

A canary deployment minimizes risk by routing a small percentage of traffic (e.g., 5-10%) to the new version while the majority continues to use the stable version. This allows real-world validation of the new version under production load before a full rollout, and if issues are detected, traffic can be instantly redirected back to the old version. The strategy is named after the 'canary in a coal mine' concept, where early detection of problems prevents widespread impact.

Exam trap

CompTIA often tests the distinction between canary and rolling deployments, where candidates mistakenly think rolling deployment also uses a small traffic percentage, but rolling updates instances sequentially without the deliberate traffic-splitting and validation phase that defines a canary.

How to eliminate wrong answers

Option B (In-place deployment) is wrong because it directly replaces the existing version on the same infrastructure without any traffic shifting or gradual rollout, meaning any failure affects all users immediately. Option C (Rolling deployment) is wrong because it gradually replaces instances one by one (or in batches) but does not intentionally isolate a small traffic percentage for validation; it updates all instances over time without a canary's targeted risk assessment. Option D (Blue-green deployment) is wrong because it maintains two identical environments (blue and green) and switches all traffic at once from the old to the new version, which does not involve a gradual traffic shift or small percentage testing.

392
MCQeasy

A cloud administrator receives reports that a newly deployed application stack fails health checks and is repeatedly replaced by the orchestrator. Logs show the container starts, then exits after a few seconds with no error. The container image runs a process that daemonizes and returns control to the shell. Which of the following is the MOST likely cause?

A.The orchestrator's restart policy is set to Always, causing healthy containers to be restarted.
B.The container image was built for the wrong CPU architecture and the kernel is killing the process.
C.The container's main process forks into the background, so the runtime sees the foreground process exit and stops the container.
D.The container's health check endpoint is returning 500 errors because the application is not fully initialized.
AnswerC

Container runtimes tie the container lifecycle to the foreground process. When an entrypoint script launches a daemon that backgrounds itself, the foreground process exits, the runtime treats the container as complete, and the orchestrator restarts it. The fix is to run the process in the foreground or use a supervisor that keeps a foreground process alive.

Why this answer

Container lifecycle is bound to the foreground process. When the entrypoint backgrounds the application and returns, the runtime sees the main process complete and stops the container, so the orchestrator repeatedly recreates it. Running the server in the foreground or using a process supervisor keeps the container alive and allows health checks to succeed.

Exam trap

The trap here is focusing on the health check configuration when the container is exiting before health checks even matter, because the foreground process ends.

393
MCQhard

A cloud operations team is troubleshooting a performance issue with a database that is running on a virtual machine. The database is experiencing high latency during peak hours. Metrics show that CPU and memory usage are below 50%, but disk I/O latency spikes. The database is hosted on a cloud provider's virtual machine with premium SSDs. Which of the following is the MOST likely cause of the disk I/O latency?

A.The OS is paging memory to disk due to insufficient RAM.
B.The virtual machine's network bandwidth is saturated.
C.The disk IOPS limit is being exceeded during peak loads.
D.The database application is CPU-bound.
AnswerC

Premium SSDs cap provisioned IOPS, and once peak database demand exceeds that ceiling, the storage layer queues requests, producing latency spikes while CPU and memory remain under 50%. The bottleneck is storage throughput, not compute.

Why this answer

Premium SSDs have defined IOPS limits that, when exceeded during peak loads, cause disk I/O latency spikes. Since CPU and memory are below 50%, the bottleneck is at the storage layer, not compute or memory. The high latency indicates the disk queue depth is growing as requests exceed the provisioned IOPS cap, leading to queuing delays.

Exam trap

A common trap is to attribute high disk I/O latency to memory pressure (paging), but since memory usage is low, the real cause is hitting the disk's IOPS ceiling.

How to eliminate wrong answers

Option A is wrong because the OS paging memory to disk would show high memory usage (near 100%) and increased disk reads/writes, but metrics show memory usage below 50%, ruling out insufficient RAM. Option B is wrong because network bandwidth saturation would manifest as network latency or packet loss, not disk I/O latency spikes; the issue is specifically with disk performance, not network throughput. Option D is wrong because the database being CPU-bound would show CPU usage at or near 100%, but metrics indicate CPU usage is below 50%, so the CPU is not the bottleneck.

394
Multi-Selecthard

A company is migrating to AWS and needs to meet PCI DSS compliance. Which THREE of the following should be implemented? (Choose three.)

Select 3 answers
A.Encrypting cardholder data at rest and in transit
B.Using single-factor authentication for all administrative access
C.Implementing a vulnerability management program
D.Enabling audit logging for all access to cardholder data
E.Using default VPC settings without changes
AnswersA, C, D

Encrypting cardholder data at rest and in transit directly satisfies PCI DSS Requirement 4, which mandates strong cryptography for cardholder data during transmission over open, public networks and while stored. This controls the core constraint of protecting sensitive authentication data throughout its lifecycle, a mandatory baseline for any PCI DSS compliant AWS migration.

Why this answer

PCI DSS requires encryption of cardholder data, regular security testing (like vulnerability scanning), and audit logging. Using default VPC settings may not be secure. Single-factor authentication is insufficient.

395
Multi-Selecteasy

Which TWO of the following are benefits of using a content delivery network (CDN) with cloud-hosted applications? (Choose two.)

Select 2 answers
A.Reduces load on the origin server
B.Simplifies application architecture
C.Eliminates the need for HTTPS encryption
D.Reduces latency for end users by caching content at edge locations
E.Lowers overall infrastructure cost
AnswersA, D

Edge nodes serve cached copies of content, so a large share of user requests never reach the origin. This offloads bandwidth and compute from the origin server, satisfying the stem's benefit of reducing load on the cloud-hosted application's backend.

Why this answer

Option A is correct because a CDN serves cached copies of content from edge nodes, so a large share of user requests never reach the origin server, directly reducing CPU, bandwidth, and concurrent-connection load on the origin. Option D is correct because CDNs cache content at edge locations geographically close to end users, shortening the network round-trip distance and thus reducing latency compared with fetching every request from a distant origin region. Option B is not a CDN benefit, since integrating a CDN typically adds a distribution and cache-invalidation layer rather than simplifying the application architecture.

Option C is wrong because CDNs do not remove the need for HTTPS; they usually require TLS between clients and edge nodes and often between the edge and origin. Option E is not guaranteed, as CDN usage adds service charges that may or may not be offset by reduced origin costs.

Exam trap

A common misconception is that a CDN simplifies application architecture or reduces costs, but in reality, it adds operational overhead and incurs additional service fees, while HTTPS remains mandatory for secure communication.

396
MCQmedium

A cloud administrator is troubleshooting network connectivity issues between two VPCs in AWS. The administrator wants to examine traffic flow logs to identify dropped packets. Which AWS feature provides detailed network traffic logs for VPCs?

A.AWS X-Ray
B.AWS CloudTrail
C.VPC Flow Logs
D.Amazon CloudWatch Logs
AnswerC

VPC Flow Logs capture IP traffic metadata for elastic network interfaces, subnets and VPC peering connections, recording accepted and rejected packets with source, destination and port details. This directly satisfies the administrator's requirement to examine traffic flow records and identify where packets are being dropped between the two VPCs.

Why this answer

VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, action) for network interfaces in a VPC, and can be published to CloudWatch Logs or S3. They are the correct tool for diagnosing dropped packets and connectivity issues between VPCs, showing ACCEPT and REJECT records. CloudTrail, X-Ray, and CloudWatch Logs serve different observability purposes.

Exam trap

CV0-004 often tests the confusion between CloudTrail (API audit) and VPC Flow Logs (network traffic) — candidates pick CloudTrail because it 'logs everything,' but it does not capture packet-level flow data.

How to eliminate wrong answers

Option A is wrong because AWS X-Ray traces application requests through distributed services; it does not log network-layer packet flows. Option B is wrong because CloudTrail records API calls and account activity (who did what), not network traffic. Option D is wrong because CloudWatch Logs is a general log storage/query service; it can receive Flow Logs but is not itself the feature that generates network traffic logs.

397
MCQmedium

A cloud architect is designing a new application that must be highly available across multiple geographic regions. The application uses a relational database that must be writable in the primary region and readable in a secondary region with minimal replication lag. Which AWS database feature should the architect implement to meet these requirements?

A.Amazon DynamoDB global tables
B.Amazon RDS Multi-AZ deployment
C.Amazon Aurora Global Database
D.Amazon RDS read replicas in a secondary region
AnswerC

Amazon Aurora Global Database is designed for multi-region applications, providing a primary region that is writable and secondary regions that are read-only with typical replication lag under one second. It uses dedicated replication infrastructure for low latency and supports fast failover. This meets the requirements for a writable primary and low-lag readable secondary region.

Why this answer

The requirement is for a relational database that is writable in one region and readable in another with minimal replication lag. Amazon Aurora Global Database provides exactly this: a primary region for writes and secondary regions for reads with sub-second replication lag. Other options either do not support cross-region replication or do not provide the required low lag and relational capabilities.

Exam trap

The trap here is confusing Multi-AZ with multi-region; Multi-AZ is for high availability within a region, not for cross-region read scaling.

398
MCQmedium

A security analyst is reviewing logs and finds that an unauthorized user accessed a storage blob in a cloud environment. The analyst needs to determine which permissions allowed the access. Which cloud feature provides a detailed view of effective permissions for a user?

A.Privileged Identity Management (PIM)
B.Role-Based Access Control (RBAC) with effective permissions analysis
C.Blueprints/Service Catalog
D.Policy Enforcement
AnswerB

RBAC with effective permissions analysis aggregates every role assignment, including inherited and group-derived ones, into a single evaluated view, revealing exactly which permission granted the blob access. This directly satisfies the analyst's need to trace the specific authorisation path rather than inspecting raw role definitions individually.

Why this answer

Role-Based Access Control (RBAC) systems often provide an 'effective permissions' or 'check access' feature that allows an administrator to evaluate the cumulative permissions assigned to a specific user, group, or service principal for a given resource scope. This feature calculates the net effect of all role assignments, including inherited permissions from higher-level scopes such as management groups, subscriptions, and resource groups, enabling the analyst to pinpoint exactly which role granted the unauthorized access.

Exam trap

The trap here is that candidates often confuse RBAC's effective permissions feature with Privileged Identity Management (PIM), assuming PIM shows current permissions, when in fact PIM only manages role activation and does not compute the cumulative effective permissions across multiple role assignments.

How to eliminate wrong answers

Option A is wrong because Azure AD Privileged Identity Management (PIM) manages just-in-time activation and oversight of privileged roles, but it does not provide a detailed view of effective permissions for a specific user on a resource. Option C is wrong because Azure Blueprints is used for defining and deploying repeatable sets of Azure resources and policies (like compliance templates), not for evaluating effective user permissions. Option D is wrong because Azure Policy enforces rules and effects (e.g., deny, audit) on resource configurations, but it does not evaluate or display the effective RBAC permissions assigned to a user.

399
MCQhard

During a security audit, it is discovered that a cloud application can be accessed using a shared service account that has elevated privileges. The audit recommends implementing a just-in-time (JIT) access model. What is the primary benefit of JIT access in this scenario?

A.Automates auditing of third-party access.
B.Allows for easier management of user identities.
C.Reduces the attack surface by minimizing persistent privileged access.
D.Eliminates the need for user authentication.
AnswerC

JIT access grants privileged permissions only for a defined, approved window, then revokes them automatically. This eliminates the standing elevated privileges of the shared service account, directly shrinking the attack surface available to an attacker who compromises those credentials.

Why this answer

Just-in-time (JIT) access grants privileged permissions only for a limited, approved window and revokes them automatically afterward, rather than leaving standing elevated privileges in place. In this scenario, replacing the shared always-privileged service account with JIT access removes persistent high-privilege credentials that attackers could abuse, directly shrinking the attack surface. This is the core security benefit JIT is designed to deliver.

Exam trap

CV0-004 often tests the misconception that JIT 'eliminates' authentication or 'automates' auditing — the actual benefit is reducing persistent privileged access, so watch for answers that overstate what JIT does.

How to eliminate wrong answers

Option A is wrong because JIT access is about time-bound privilege elevation, not auditing third-party access — auditing is a separate control (and JIT can complement it, but it isn't the primary benefit). Option B is wrong because JIT actually adds approval workflows and complexity to identity management; easier identity management is a benefit of SSO/federation, not JIT. Option D is wrong because JIT still requires authentication — it adds authorization constraints on top of authentication, it does not remove it.

400
MCQhard

A cloud security team is implementing a secrets management solution for applications running on AWS. They need to automatically rotate database credentials every 30 days and avoid hardcoding secrets. Which service should they use?

A.AWS Identity and Access Management (IAM) roles
B.AWS Key Management Service (KMS)
C.AWS Secrets Manager
D.AWS Systems Manager Parameter Store
AnswerC

AWS Secrets Manager natively performs scheduled rotation of database credentials via Lambda rotation functions, satisfying the 30-day rotation requirement, and applications retrieve secrets through API calls at runtime rather than embedding them in code, eliminating hardcoded credentials.

Why this answer

AWS Secrets Manager allows automatic rotation of secrets (e.g., database credentials) and integration with AWS services. Parameter Store can store secrets but does not natively support automatic rotation. KMS is for encryption keys.

IAM roles are for AWS service permissions.

401
Multi-Selecthard

A large enterprise is migrating multiple applications to the cloud. They need to ensure compliance with industry regulations and maintain security during the transition. Which THREE best practices should they follow?

Select 3 answers
A.Use a single cloud provider for simplicity
B.Disable logging to reduce data exposure
C.Encrypt data in transit and at rest
D.Conduct vulnerability assessments on migrated applications
E.Implement identity and access management (IAM)
AnswersC, D, E

Encrypting data in transit (TLS) and at rest (KMS or SSE) protects confidentiality throughout migration, directly satisfying the stem's regulatory compliance and security requirements. Encryption is a foundational control mandated by standards such as PCI DSS, HIPAA and GDPR for data moving to cloud environments.

Why this answer

Option C is correct because encrypting data in transit (e.g., TLS 1.2/1.3) and at rest (e.g., AES-256) protects sensitive information from interception and unauthorized access, which is a core requirement of regulations such as HIPAA, PCI DSS, and GDPR. Option D is correct because conducting vulnerability assessments on migrated applications identifies misconfigurations, unpatched software, and exploitable weaknesses introduced during the transition, enabling remediation before attackers can leverage them. Option E is correct because implementing identity and access management (IAM) enforces least privilege, role-based access control, and strong authentication, which are essential for maintaining security and meeting compliance audit requirements in a multi-application cloud environment.

Option A is not correct because relying on a single cloud provider increases vendor lock-in and concentration risk rather than being a security or compliance best practice. Option B is not correct because disabling logging reduces data exposure but destroys the audit trails and monitoring evidence required for regulatory compliance and incident detection.

Exam trap

CompTIA often tests the misconception that simplifying the migration by using a single provider or reducing logging is a valid security strategy, when in fact these actions undermine compliance and visibility.

402
MCQmedium

An organization uses multiple SaaS applications and wants to enforce data loss prevention policies and gain visibility into user activity. Which technology should they implement?

A.Security information and event management (SIEM)
B.Web Application Firewall (WAF)
C.Virtual private network (VPN)
D.Cloud Access Security Broker (CASB)
AnswerD

A CASB sits between users and SaaS providers, giving visibility into sanctioned and unsanctioned application usage while enforcing data loss prevention policies inline. That API and proxy-based inspection satisfies both the visibility and DLP requirements across multiple SaaS applications.

Why this answer

A Cloud Access Security Broker (CASB) sits between users and SaaS applications to enforce DLP policies, provide visibility into shadow IT, and monitor user activity across multiple cloud services. CASB is specifically designed for the SaaS visibility and control use case described, offering API-based and proxy-based modes. It can inspect data in transit and at rest in sanctioned SaaS apps, apply DLP rules, and generate audit trails.

Exam trap

CV0-004 often tests the distinction between CASB and SIEM — candidates confuse visibility (SIEM) with policy enforcement and control over SaaS (CASB), picking SIEM when the requirement includes DLP enforcement.

How to eliminate wrong answers

Option A is wrong because SIEM aggregates and correlates log data for security monitoring and incident response, but it does not enforce DLP policies or provide inline control over SaaS user activity — it is a detection and analysis tool, not a policy enforcement point. Option B is wrong because a WAF protects web applications from HTTP-layer attacks (SQLi, XSS) and does not govern SaaS usage or data flows to third-party cloud apps. Option C is wrong because a VPN provides encrypted remote access to a corporate network but does not inspect or control SaaS application usage or enforce DLP.

403
MCQeasy

A cloud administrator is deploying a new virtual machine in a public cloud. The administrator needs to ensure that the VM can be accessed remotely for management purposes. The security group associated with the VM currently allows only outbound traffic. Which inbound rule should be added to allow SSH access from the administrator's corporate network?

A.Allow inbound TCP port 443 from the corporate network's CIDR block.
B.Allow inbound UDP port 22 from the corporate network's CIDR block.
C.Allow inbound TCP port 3389 from the corporate network's CIDR block.
D.Allow inbound TCP port 22 from the corporate network's CIDR block.
AnswerD

SSH uses TCP port 22 by default. To allow remote management, an inbound rule permitting TCP port 22 from the specific corporate network CIDR is necessary. This restricts access to known IP addresses, enhancing security. Without this rule, the VM would be unreachable via SSH, preventing management. This is a fundamental step in securing remote access to cloud instances.

Why this answer

SSH access requires an inbound rule allowing TCP port 22 from the administrator's network. This ensures that only trusted sources can connect, reducing the attack surface. Port 3389 is for RDP, UDP 22 is not used by SSH, and port 443 is for HTTPS.

Therefore, the rule allowing TCP 22 from the corporate CIDR is the correct choice for secure remote management.

Exam trap

The trap here is confusing SSH with RDP or using the wrong protocol; SSH is TCP port 22, not 3389 or UDP.

404
MCQmedium

A cloud architect is designing a multi-tier application that must be resilient to the failure of an entire availability zone. Which of the following strategies BEST meets this requirement?

A.Place all instances behind a single load balancer in one zone
B.Implement auto-scaling within the same availability zone
C.Use larger instance types to handle more load
D.Deploy application instances across three availability zones with a load balancer
AnswerD

Spreading instances across three availability zones means a single zone outage leaves two zones serving traffic, and the load balancer health checks route around the failed zone. This satisfies the requirement for resilience to the failure of an entire availability zone, which a single-zone or two-zone design cannot guarantee.

Why this answer

Deploying application instances across three availability zones behind a load balancer ensures that the failure of any single AZ does not take down the application. The load balancer distributes traffic to healthy instances in the remaining AZs, providing true AZ-level fault tolerance. Three AZs also satisfy the common cloud best practice of N+1 or 2N redundancy.

Exam trap

CV0-004 often tests whether candidates confuse 'high availability' (auto-scaling, larger instances) with 'fault tolerance' (multi-AZ) — the question specifically requires resilience to an entire AZ failure, which only multi-AZ satisfies.

How to eliminate wrong answers

Option A is wrong because placing all instances in one zone creates a single point of failure — an AZ outage takes down the entire application. Option B is wrong because auto-scaling within a single AZ does not protect against AZ failure; it only handles load fluctuations. Option C is wrong because larger instance types address capacity, not resilience — a single large instance in one AZ still fails if that AZ goes down.

405
Multi-Selectmedium

A cloud security team is hardening a Microsoft Azure subscription that hosts production virtual machines. The team must ensure that administrative access to the VMs requires multi-factor authentication and that privileged role assignments are reviewed on a recurring basis. (Choose two.)

Select 2 answers
A.Enable Microsoft Entra multifactor authentication and enforce it through a Conditional Access policy scoped to the Azure portal and VM management.
B.Assign the Owner role at the subscription scope to all administrators so they can manage access reviews themselves.
C.Configure Microsoft Entra Privileged Identity Management access reviews for privileged Azure resource roles on a recurring schedule.
D.Create a custom Azure Policy that audits virtual machines lacking the latest OS patches.
E.Enable just-in-time VM access in Microsoft Defender for Cloud and rely on it as the sole authentication control.
AnswersA, C

Conditional Access is the policy engine that evaluates signals such as user, device, and location, then enforces controls like multifactor authentication. Scoping the policy to the Azure portal and VM management ensures administrators must satisfy MFA before reaching privileged VM operations. This directly satisfies the requirement that administrative access require MFA.

Why this answer

The two requirements are MFA for administrative access and recurring review of privileged role assignments. Conditional Access enforces MFA for the portal and VM management paths, while Privileged Identity Management access reviews provide scheduled attestation of privileged roles and can revoke access automatically. The other choices either weaken privilege boundaries, address network reachability, or focus on patching rather than identity controls.

Exam trap

The trap here is conflating network-level controls like just-in-time VM access with identity-level MFA enforcement, when only Conditional Access actually requires a second authentication factor.

406
MCQmedium

A company has a cloud-based application that uses an auto-scaling group across multiple Availability Zones (AZs). The application experiences periodic spikes in traffic. The auto-scaling policy uses a step scaling policy based on CPU utilization. The operations team notices that during a traffic spike, new instances are launched but take over five minutes to become healthy and begin serving traffic. During this time, existing instances are overloaded and some requests fail. The team wants to reduce the time it takes for new instances to handle traffic. Which action would be most effective?

A.Increase the instance type to a larger size so each instance can handle more traffic.
B.Use a pre-warmed, customized AMI with the application pre-installed and caches preloaded.
C.Reduce the cooldown period in the scaling policy to launch instances faster.
D.Move all instances to a single AZ to avoid cross-AZ latency.
AnswerB

A pre-warmed AMI with the application installed and caches preloaded removes the lengthy bootstrap and warm-up phase, so new instances pass health checks and serve traffic far sooner. This directly satisfies the stem's goal of reducing time-to-serve during CPU-driven traffic spikes.

Why this answer

The bottleneck is instance warm-up time: new instances must boot the OS, install/patch the application, and populate caches before passing health checks, which takes over five minutes. A pre-warmed, customized AMI with the application pre-installed and caches preloaded eliminates most of that bootstrapping, so new instances pass health checks and serve traffic in a fraction of the time. This directly addresses the root cause — slow time-to-healthy — rather than scaling capacity or tuning policy timing.

Exam trap

CV0-004 often tests the confusion between scaling speed (how fast new instances launch) and instance readiness (how fast they become healthy) — candidates pick cooldown reduction thinking it speeds up warm-up, when it only affects policy reaction timing.

How to eliminate wrong answers

Option A is wrong because a larger instance type increases per-instance capacity but does not reduce the five-minute warm-up; new instances still take just as long to become healthy, so the overload window persists. Option C is wrong because the cooldown period controls how long the scaling policy waits before collecting new metrics or launching additional instances — reducing it can cause thrashing and does not speed up instance initialization. Option D is wrong because consolidating into a single AZ reduces resilience and does not affect instance boot time; cross-AZ latency is negligible compared to application warm-up.

407
MCQmedium

A cloud administrator runs the command shown in the exhibit on a storage node in a hyper-converged cluster. The node is experiencing intermittent I/O errors and degraded performance. Based on the SMART data, what is the most likely cause of the issue?

A.The storage network is experiencing high latency.
B.The filesystem is corrupted and requires a repair.
C.The disk has developed bad sectors and is likely failing.
D.A RAID array is rebuilding, causing performance degradation.
AnswerC

SMART attributes such as reallocated sector count and pending sector count directly evidence physical media degradation. Rising reallocated sectors confirm the drive has remapped bad sectors, matching the intermittent I/O errors and degraded performance described. This satisfies the stem's requirement to identify the most likely cause from the SMART data.

Why this answer

The SMART data from the storage node shows attributes such as Reallocated_Sector_Count, Current_Pending_Sector, and Offline_Uncorrectable with non-zero values, which are definitive indicators of physical bad sectors on the disk. These bad sectors cause intermittent I/O errors and degraded performance because the disk must retry reads/writes or remap sectors, increasing latency. Option C is correct because this pattern directly points to a failing disk, not a network, filesystem, or RAID issue.

Exam trap

The trap here is that candidates confuse SMART disk failure indicators with filesystem corruption or network issues, because intermittent I/O errors can superficially resemble symptoms of a corrupt filesystem or a flapping network link, but the SMART data provides direct hardware-level evidence that eliminates those possibilities.

How to eliminate wrong answers

Option A is wrong because high storage network latency would manifest as consistent packet loss or jitter across all nodes, not as SMART attributes indicating physical disk errors; the command shown is a SMART query, not a network diagnostic. Option B is wrong because filesystem corruption typically produces errors like 'structure needs cleaning' or 'input/output error' on specific files, not the SMART counters for reallocated or pending sectors, which are hardware-level indicators. Option D is wrong because a RAID array rebuilding would show a degraded or rebuilding state in the RAID controller status (e.g., mdadm or megaraid output), not in SMART data, and performance would be consistently slow during rebuild, not intermittent.

408
MCQhard

An organization has a hybrid cloud environment with resources in both a private cloud and a public cloud. The operations team reports that the cloud management platform cannot collect monitoring data from the public cloud instances. The security team recently updated firewall rules. Which of the following is the MOST likely cause?

A.The load balancer in front of the management platform is misconfigured
B.The public cloud instances cannot reach the management platform's IP address due to firewall changes
C.The SNMP community string was modified on the instances
D.The management platform's NAT IP address was changed
AnswerB

Monitoring agents push data outbound to the management platform, so newly tightened firewall rules blocking that destination IP would halt collection. The private cloud path is unaffected, isolating the public cloud instances as the failing source.

Why this answer

The security team's recent firewall rule update is the most likely cause because the cloud management platform typically uses specific ports and protocols (e.g., HTTPS on TCP 443, SSH on TCP 22, or WinRM on TCP 5985/5986) to collect monitoring data from public cloud instances. If the firewall rules block outbound traffic from the public cloud instances to the management platform's IP address, or block inbound traffic from those instances at the platform's side, the data collection will fail. This directly aligns with the reported symptom of the management platform being unable to collect monitoring data after a firewall change.

Exam trap

CompTIA often tests the candidate's ability to correlate a specific operational change (firewall rule update) with the most direct impact on network connectivity for monitoring, rather than distracting with unrelated configuration changes like SNMP strings or load balancer settings.

How to eliminate wrong answers

Option A is wrong because a misconfigured load balancer in front of the management platform would affect all traffic to the platform, not just monitoring data from public cloud instances, and the issue is specifically tied to the recent firewall rule update. Option C is wrong because while SNMP community string changes could disrupt monitoring, the question explicitly states the security team updated firewall rules, not SNMP configurations, and SNMP is not the only monitoring protocol used in hybrid cloud environments. Option D is wrong because changing the management platform's NAT IP address would require corresponding updates in routing and firewall rules; if this had occurred, the operations team would likely have reported a broader connectivity failure, not just a monitoring data collection issue, and the firewall rule update is the more immediate and likely cause.

409
Multi-Selecthard

A cloud administrator is troubleshooting a containerized application deployed on a managed Kubernetes cluster. Pods are failing to start, and the events show 'FailedMount' errors for a persistent volume claim (PVC). The PVC is bound to a persistent volume (PV) that uses a storage class with a reclaim policy of Delete. Which two actions should the administrator take to resolve the issue? (Choose two.)

Select 2 answers
A.Restart the kubelet service on the node to clear stale mount points.
B.Verify that the PV's storage class supports the access mode requested by the PVC.
C.Check that the node's kubelet has the necessary permissions to attach and mount the volume.
D.Change the reclaim policy to Retain to prevent data loss.
E.Increase the PVC's requested storage size to match the PV's capacity.
AnswersB, C

If the PVC requests an access mode (e.g., ReadWriteMany) that the underlying storage class does not support, the mount will fail. Checking compatibility ensures the volume can be attached to the pod. This is a common cause of FailedMount errors, especially with different storage backends like block vs. file storage.

Why this answer

FailedMount errors often stem from incompatible access modes or insufficient node permissions. The storage class must support the PVC's access mode, and the node's kubelet needs permissions to attach and mount the volume. Increasing size or changing reclaim policy does not affect mountability.

Restarting kubelet is a temporary measure, not a root-cause fix.

Exam trap

The trap here is focusing on storage size or reclaim policy, which are provisioning concerns, rather than mount-time issues like access modes and permissions.

410
MCQeasy

A cloud administrator is designing a multi-tier application. The database tier must not be directly accessible from the internet, but the web tier must be able to connect to it. Which of the following should the administrator implement?

A.Implement an application load balancer in front of the database.
B.Place the database servers in a public subnet and restrict the security group.
C.Use a VPN connection for the web tier to access the database.
D.Place the database servers in a private subnet and configure the security group to allow inbound traffic from the web tier's security group.
AnswerD

Private subnets have no route to the internet gateway, so the database tier cannot be reached directly. Referencing the web tier's security group as the inbound source restricts database access to those instances alone, satisfying both the isolation and connectivity requirements.

Why this answer

Placing the database servers in a private subnet ensures they have no direct internet route, meeting the security requirement. By configuring the security group to allow inbound traffic only from the web tier's security group, you enable the web tier to connect to the database while blocking all other traffic, including from the internet. This leverages AWS security group referencing (or similar cloud provider feature) to create a trusted, internal communication path.

Exam trap

The trap here is that candidates often confuse 'restricting the security group' with 'placing in a private subnet,' failing to realize that a public subnet inherently provides internet accessibility regardless of security group rules, which only filter traffic but do not remove the public route.

How to eliminate wrong answers

Option A is wrong because an application load balancer is designed to distribute traffic to web or application servers, not to provide secure database access; placing a load balancer in front of the database would expose it to the internet and add unnecessary complexity without preventing direct internet access. Option B is wrong because placing the database servers in a public subnet, even with a restrictive security group, still exposes them to potential internet-based attacks and violates the requirement that the database must not be directly accessible from the internet. Option C is wrong because a VPN connection is typically used for site-to-site or remote user access, not for internal web-to-database communication within the same cloud environment; it would add latency and overhead without addressing the core need for private subnet isolation.

411
MCQhard

A cloud operations team must ensure that a critical workload continues to run even if an entire AWS Region becomes unavailable. The workload's data is stored in Amazon S3, and the team wants the data available in a second Region with minimal operational effort and automatic replication. Which action should the team take?

A.Enable S3 Versioning on the bucket and rely on it for regional failover.
B.Apply an S3 Lifecycle policy to transition objects to a second Region.
C.Use S3 Transfer Acceleration to speed up access from the secondary Region.
D.Configure S3 Cross-Region Replication on the source bucket.
AnswerD

Cross-Region Replication automatically copies objects to a bucket in another Region as they are written, providing a maintained copy with minimal operational effort. If the primary Region is lost, the replica bucket can serve the data, supporting the requirement for regional resilience.

Why this answer

Cross-Region Replication continuously copies objects to a destination bucket in another Region, so a current copy exists without manual intervention. That automatically maintained replica is what allows the workload to recover if the primary Region becomes unavailable, which the other options cannot deliver.

Exam trap

The trap here is confusing features that improve durability or performance within a Region with actual cross-Region data replication.

412
Multi-Selecthard

A company is migrating on-premises workloads to the cloud. They need to ensure high availability for a stateless web application across two availability zones. Which THREE components should be configured to meet this requirement?

Select 3 answers
A.An auto scaling group spanning both availability zones
B.A load balancer in front of the web tier
C.A read replica database in a different AZ
D.A single large compute instance to handle all traffic
E.Multiple subnets, each in a different availability zone
AnswersA, B, E

An auto scaling group spanning both availability zones maintains capacity when one zone fails, replacing unhealthy instances in the surviving zone. This directly satisfies the high-availability constraint for the stateless web tier, since no session state pins users to a single instance.

Why this answer

Option A is correct because an auto scaling group spanning both availability zones ensures that instances are distributed across AZs and can automatically replace failed instances, maintaining high availability for the stateless web tier. Option B is correct because a load balancer in front of the web tier distributes incoming traffic across healthy instances in multiple AZs, providing fault tolerance and a single point of entry. Option E is correct because multiple subnets, each in a different availability zone, are required to place the load balancer and auto scaling group across distinct AZs, which is the foundation for AZ-level redundancy.

Option C is not correct because a read replica database is a data-tier concern and is not required for a stateless web application's high availability. Option D is not correct because a single large compute instance is a single point of failure and cannot provide high availability across two availability zones.

Exam trap

The trap here is that candidates often confuse database-level high availability (like read replicas or multi-AZ database replication) with application-tier high availability, leading them to select a database option (C) when the question explicitly targets the stateless web tier.

413
MCQmedium

A cloud engineer is tasked with deploying a containerized application on Kubernetes. The application must handle varying loads, and the deployment should automatically replace failed containers. Which Kubernetes object should the engineer use to achieve self-healing and scalability?

A.ConfigMap
B.Service
C.Deployment
D.Pod
AnswerC

A Deployment manages ReplicaSets, which maintain the desired pod count and automatically replace failed containers, satisfying the self-healing requirement. Its Horizontal Pod Autoscaler integration adjusts replica counts as load varies, delivering the scalability the stem demands. Bare pods or DaemonSets cannot reschedule failed replicas or scale dynamically in this manner.

Why this answer

A Deployment is the correct Kubernetes object because it manages ReplicaSets to provide declarative updates, self-healing (automatic replacement of failed pods), and scalability (adjusting replica counts). Unlike a standalone Pod, a Deployment ensures the desired state is maintained, automatically rescheduling containers if they fail.

Exam trap

CompTIA Cloud+ often tests the misconception that a Pod alone provides self-healing, but in Kubernetes, a Pod is a non-self-healing atomic unit; only controllers like Deployment (or StatefulSet/DaemonSet) provide automatic replacement and scaling.

How to eliminate wrong answers

Option A (ConfigMap) is wrong because it is used to inject configuration data (e.g., environment variables, files) into pods, not to manage pod lifecycle, self-healing, or scaling. Option B (Service) is wrong because it provides a stable network endpoint and load balancing for a set of pods, but does not handle pod replacement or scaling of replicas. Option D (Pod) is wrong because a single Pod lacks self-healing capabilities; if the Pod fails, it is not automatically replaced unless managed by a higher-level controller like a Deployment.

414
MCQmedium

An organization's cloud environment has a policy that all administrative access must be logged and recorded. Which of the following is the best method to enforce this policy?

A.Require multifactor authentication.
B.Use a bastion host with session recording.
C.Implement a VPN connection for all administrators.
D.Configure syslog forwarding for all devices.
AnswerB

A bastion host centralises administrative connections through one hardened jump point, and its session-recording capability captures full keystroke and command logs per session. This directly satisfies the policy that all administrative access must be logged and recorded, which network-level logging alone cannot guarantee.

Why this answer

A bastion host with session recording provides a centralized, auditable gateway for administrative access. It logs all commands and keystrokes, directly meeting the policy requirement that all administrative access must be logged and recorded. This method captures the full session activity, not just connection metadata.

Exam trap

The trap here is that candidates often confuse logging (e.g., syslog) with session recording, failing to recognize that syslog only captures discrete events, not the full interactive session required by the policy.

How to eliminate wrong answers

Option A is wrong because multifactor authentication (MFA) strengthens authentication but does not log or record administrative sessions; it only verifies identity. Option C is wrong because a VPN connection encrypts traffic and authenticates users but does not inherently log or record the commands or actions performed during the administrative session. Option D is wrong because syslog forwarding collects system logs (e.g., authentication events, errors) but does not capture interactive session content like keystrokes or command output, which is required for full session recording.

415
MCQmedium

A cloud engineer deployed the infrastructure shown. The load balancer's health checks are failing for the EC2 instance. Which of the following is the MOST likely cause?

A.The web server is not running HTTP.
B.The health check endpoint /health does not exist on the web server.
C.The EC2 instance is in the wrong subnet.
D.The security group does not allow traffic from the load balancer.
AnswerB

Health checks probe a specific path and port; if /health is absent, the web server returns 404 or resets, marking the instance unhealthy despite the application running. This is the most likely cause, not security groups or instance state, which would produce different symptoms.

Why this answer

The health check is failing because the load balancer is configured to check the /health endpoint, but the web server does not have that endpoint defined. Without a matching route or file for /health, the server returns a non-2xx/3xx status code (e.g., 404 Not Found), causing the load balancer to mark the instance as unhealthy.

Exam trap

The trap here is that candidates often assume a security group or subnet misconfiguration is the root cause, but the question specifically describes health checks failing (not timing out), which points to an application-layer issue like a missing endpoint rather than a network-layer problem.

How to eliminate wrong answers

Option A is wrong because the health check failure is not due to the web server not running HTTP; the server could be running HTTP on the correct port but still fail if the specific /health endpoint is missing. Option C is wrong because the EC2 instance being in the wrong subnet would prevent the load balancer from routing traffic at all, but the question states health checks are failing, implying the instance is reachable but not responding correctly to the health check request. Option D is wrong because if the security group did not allow traffic from the load balancer, the health check requests would be dropped entirely, resulting in a timeout rather than a specific endpoint failure; the scenario points to a missing endpoint, not a network access issue.

416
MCQmedium

An organization is migrating a MySQL database to Amazon RDS using AWS DMS. They want to minimize downtime by using ongoing replication from the source. Which DMS feature should they enable to capture changes as they occur on the source database?

A.Data validation
B.Change Data Capture (CDC)
C.Full load
D.Schema conversion
AnswerB

Change Data Capture reads the source's transaction logs and streams ongoing inserts, updates and deletes to the target, so RDS stays synchronised after the initial full load. This satisfies the requirement to minimise downtime during cutover.

Why this answer

Change Data Capture (CDC) in AWS DMS captures ongoing changes from the source database by reading the transaction logs (e.g., binary log for MySQL) and applying them to the target. This enables near-zero downtime migration because after the initial full load, CDC continuously replicates inserts, updates, and deletes.

Exam trap

CV0-004 often tests the difference between full load and CDC; the trap is choosing Full load when the requirement is to capture ongoing changes to minimize downtime.

How to eliminate wrong answers

Option A is wrong because Data validation compares source and target data to ensure consistency; it does not capture changes. Option C is wrong because Full load only performs the initial bulk copy of existing data, not ongoing changes. Option D is wrong because Schema conversion is a feature of AWS SCT (Schema Conversion Tool) that converts schemas between different database engines; it does not capture ongoing changes.

417
MCQhard

A cloud engineer is deploying a containerized application on Amazon ECS using the Fargate launch type. The application requires persistent storage for a shared cache that must be accessible by multiple tasks across different Availability Zones. The cache data must survive task restarts. Which storage solution should the engineer use?

A.Amazon FSx for Windows File Server
B.Amazon S3 bucket mounted as a file system using s3fs
C.Amazon EBS volume attached to each task
D.Amazon EFS file system mounted to each task
AnswerD

Amazon EFS is a shared, elastic file system that can be mounted by multiple ECS tasks across different Availability Zones. It provides persistent storage that survives task restarts. Fargate tasks support EFS mounts, making it suitable for a shared cache that requires concurrent access and durability.

Why this answer

Amazon EFS provides a shared, durable, and scalable file system that can be mounted by multiple ECS tasks across Availability Zones. It supports the POSIX interface, making it ideal for shared cache storage that requires concurrent access and persistence. Fargate tasks can mount EFS file systems, ensuring the cache data remains available even if tasks are restarted or replaced.

Exam trap

The trap here is assuming that Amazon EBS can be shared across multiple tasks or that S3 can serve as a low-latency file system for a shared cache.

418
MCQmedium

A company is using a SaaS application and wants to gain visibility into user activity and enforce data loss prevention policies. Which technology should be deployed?

A.Intrusion Detection System (IDS)
B.Web Application Firewall (WAF)
C.Cloud Access Security Broker (CASB)
D.Network Access Control (NAC)
AnswerC

A CASB sits between users and the SaaS provider, providing API and proxy-based visibility into user activity plus inline DLP enforcement. It satisfies the stem's SaaS visibility and policy requirement, unlike SWG or firewall approaches that cannot inspect sanctioned SaaS traffic.

Why this answer

A Cloud Access Security Broker (CASB) is a security policy enforcement point placed between cloud service consumers and cloud service providers to combine and interject enterprise security policies as cloud-based resources are accessed. It provides visibility into user activity, enforces data loss prevention (DLP) policies, and ensures compliance for SaaS applications.

Exam trap

CV0-004 often tests the confusion between network security tools (IDS, WAF, NAC) and cloud-specific security controls (CASB), so candidates must recognize that only CASB provides SaaS visibility and DLP.

How to eliminate wrong answers

Option A is wrong because an Intrusion Detection System (IDS) monitors network traffic for malicious activity but does not provide granular visibility into SaaS user activity or enforce DLP policies. Option B is wrong because a Web Application Firewall (WAF) protects web applications from attacks like SQL injection and XSS, but it does not govern SaaS usage or data loss. Option D is wrong because Network Access Control (NAC) controls device access to the network based on compliance, not SaaS application activity or DLP.

419
MCQhard

A company is migrating a legacy application that requires static public IP addresses for licensing. The cloud provider assigns public IPs dynamically by default. Which solution should the administrator recommend while minimizing cost?

A.Use a NAT gateway with a static IP.
B.Assign elastic IP addresses (or static public IPs) to the instances.
C.Use static private IPs.
D.Use a VPN connection.
AnswerB

Elastic IP addresses are statically allocated public addresses that persist across instance stop/start, satisfying the licensing requirement for fixed public IPs while remaining cheaper than reserving dedicated public IP ranges or running a NAT gateway.

Why this answer

Elastic IP addresses (or static public IPs) provide persistent public IPv4 addresses that can be associated with instances, meeting the licensing requirement for static public IPs. This is the most cost-effective solution as it only incurs charges for allocated but unused Elastic IPs, whereas other options introduce additional infrastructure costs or fail to address the requirement.

Exam trap

The trap here is that candidates may choose a NAT gateway (Option A) thinking it provides a static public IP for the instance, but a NAT gateway only translates outbound traffic and does not assign a public IP to the instance for inbound licensing checks, while also incurring higher costs.

How to eliminate wrong answers

Option A is wrong because a NAT gateway with a static IP provides outbound internet access but does not assign a static public IP directly to the instance for inbound licensing validation; it also incurs hourly and data processing costs, increasing expenses unnecessarily. Option C is wrong because static private IPs are not publicly routable and cannot satisfy the licensing requirement for static public IP addresses. Option D is wrong because a VPN connection creates an encrypted tunnel to a remote network but does not provide a static public IP address for the instance; it adds complexity and cost without meeting the core requirement.

420
MCQhard

A company is deploying a containerized microservices architecture on Azure Kubernetes Service (AKS). The security team requires that all container images are scanned for vulnerabilities before deployment. Which deployment approach should the DevOps team implement to ensure only approved images are used?

A.Store all images in a private registry without any scanning.
B.Use Docker Content Trust to sign images and verify signatures during deployment.
C.Enable Azure Container Registry tasks for automatic vulnerability scanning and enforce with Azure Policy.
D.Deploy an admission controller that checks image signatures only.
AnswerC

Azure Container Registry tasks scan images automatically on push, while Azure Policy for AKS enforces admission control, blocking any image lacking a passing scan before it reaches a node. This combination satisfies the requirement that only approved, vulnerability-scanned images are deployed, rather than merely alerting after deployment.

Why this answer

Azure Container Registry (ACR) Tasks can automatically scan images for vulnerabilities using Microsoft Defender for Cloud, and Azure Policy can enforce that only images from approved registries or with passing scan results are deployed to AKS. This ensures that all container images are scanned before deployment and that only compliant images are used, meeting the security team's requirement.

Exam trap

The trap here is that candidates often confuse image signing (e.g., Docker Content Trust or Notary) with vulnerability scanning, assuming that signing alone ensures security, but signing only verifies image origin and integrity, not the presence of vulnerabilities.

How to eliminate wrong answers

Option A is wrong because storing images in a private registry without scanning does not enforce vulnerability scanning or approval, leaving the system exposed to known vulnerabilities. Option B is wrong because Docker Content Trust only signs images and verifies signatures during deployment, but it does not perform vulnerability scanning; it ensures image integrity and provenance, not security compliance. Option D is wrong because an admission controller that checks image signatures only verifies cryptographic signatures, not vulnerability scan results, so it does not ensure images are free of vulnerabilities.

421
Multi-Selectmedium

A cloud security engineer is hardening a Kubernetes cluster. Which TWO measures should be implemented to improve container security? (Choose two.)

Select 2 answers
A.Implement runtime security monitoring
B.Store secrets in ConfigMaps
C.Disable audit logging to reduce overhead
D.Use default service accounts for all pods
E.Enable image scanning for vulnerabilities
AnswersA, E

Runtime security detects suspicious container behavior.

Why this answer

A is correct because runtime security monitoring (e.g., using Falco, Sysdig, or Aqua Security) detects and alerts on anomalous behavior within running containers, such as unexpected system calls, privilege escalations, or file system changes. This is a critical layer of defense that complements image scanning by catching threats that bypass static checks, such as zero-day exploits or compromised containers. Without runtime monitoring, malicious activity inside a container can go undetected until significant damage occurs.

Exam trap

A common misconception is that ConfigMaps are a secure place for secrets, but ConfigMaps lack encryption and access control features, making them unsuitable for sensitive data.

422
MCQmedium

A company is deploying a global web application that serves static content (images, CSS, JavaScript) to users worldwide. They want to reduce latency and offload traffic from the origin servers. Which service should they implement?

A.Auto-scaling group
B.VPN connection
C.Load balancer
D.Content Delivery Network (CDN)
AnswerD

CDN caches content at edge locations, reducing latency.

Why this answer

A Content Delivery Network (CDN) caches static content at edge locations worldwide, reducing latency and offloading origin servers.

423
MCQmedium

A security team discovers that a container image used in production contains a known vulnerability in one of its base image layers. Which action should be taken to remediate this issue?

A.Rebuild the container image using an updated base image
B.Delete the container and recreate it from the same image
C.Apply a security patch to the running container
D.Enable runtime security monitoring to detect exploitation attempts
AnswerA

Rebuilding with an updated base image replaces the vulnerable layer, removing the inherited flaw while preserving application code. Patching the running container alone would not remediate the image itself, so rebuilding is the correct action.

Why this answer

When a vulnerability is found in a base image layer, the correct remediation is to rebuild the container image using an updated base image that includes the patched version of the affected component. Containers are immutable, so patching a running container does not persist and does not fix the image. Rebuilding ensures the new image is free of the vulnerability and can be redeployed across the environment.

Exam trap

CV0-004 often tests the misconception that you can patch a running container to fix a vulnerability, when containers are immutable and the fix must be applied to the image and redeployed.

How to eliminate wrong answers

Option B is wrong because deleting and recreating a container from the same image reproduces the same vulnerable layer, so the vulnerability remains. Option C is wrong because applying a patch to a running container is a temporary, non-persistent change that is lost on restart and does not fix the underlying image used for future deployments. Option D is wrong because runtime security monitoring only detects exploitation attempts; it does not remediate the vulnerability itself and leaves the production environment exposed.

424
MCQmedium

A cloud security team is implementing a key management strategy for workloads spread across AWS and Azure. The team wants a single system of record for cryptographic keys, with the ability to import existing keys from on-premises HSMs, enforce automatic annual rotation, and produce immutable audit logs of every key use. Which approach best satisfies these requirements?

A.Deploy a dedicated FIPS 140-2 Level 3 HSM cluster in each cloud region and use the provider's native key management to front the cluster.
B.Use AWS KMS with a multi-Region customer managed key and replicate key metadata to Azure Key Vault.
C.Store all keys in an encrypted S3 bucket with Object Lock and grant both clouds access through cross-account IAM roles.
D.Implement a centralized external key manager with cloud-native integrations, using BYOK import, policy-driven rotation, and tamper-evident logging.
AnswerD

A centralized external key manager integrated with both AWS KMS and Azure Key Vault provides one authoritative system of record. It supports BYOK import from on-premises HSMs, enforces rotation policies centrally, and emits tamper-evident audit logs for every cryptographic operation. This directly satisfies the single-source, import, rotation, and immutable-audit requirements across the multi-cloud environment.

Why this answer

Centralizing key custody in an external manager that integrates with both AWS KMS and Azure Key Vault meets the single-system-of-record goal while preserving BYOK import, policy-driven rotation, and tamper-evident audit trails. Provider-native replication or object storage cannot deliver unified control, and per-region HSM silos reintroduce fragmentation. The centralized approach also keeps key material under organizational control across clouds.

Exam trap

The trap here is assuming that a multi-Region KMS key or a replicated key vault entry creates a single multi-cloud key authority, when replication stays inside one provider.

425
Multi-Selecthard

A cloud architect is designing a multi-tier application on a public cloud. The application must be highly available and fault-tolerant within a single region. Which three items should be included in the architecture? (Select THREE.)

Select 3 answers
A.Deploy resources in multiple availability zones
B.Place a load balancer in front of the web tier
C.Use a single instance in one availability zone
D.Use a single database instance without replication
E.Implement health checks for all instances
AnswersA, B, E

Spreading resources across multiple availability zones within one region gives fault isolation: a single zone failure leaves the application running elsewhere. This directly satisfies the stem's fault-tolerance and high-availability constraint while remaining inside a single region.

Why this answer

High availability within a region requires distributing resources across availability zones, using load balancers for traffic distribution, and implementing health checks for automatic failover.

426
MCQmedium

A company is running a stateless web application on a public cloud. They expect traffic to spike during certain hours. Which scaling strategy would be most cost-effective and efficient?

A.Using a larger instance type and scheduling scaling actions
B.Pre-provisioning double capacity permanently
C.Horizontal scaling using auto-scaling groups based on CPU utilization
D.Vertical scaling with manual adjustments before anticipated spikes
AnswerC

Auto-scaling groups add or remove identical stateless instances horizontally as CPU utilisation rises and falls, matching capacity to demand. This satisfies the cost-effectiveness constraint because instances are billed only while running, unlike vertical scaling, which requires permanently larger, pricier instances.

Why this answer

Horizontal scaling with auto-scaling groups based on CPU utilization is the most cost-effective and efficient strategy for a stateless web application with variable traffic. Auto-scaling groups automatically adjust the number of instances in response to real-time demand, ensuring you only pay for the capacity you need. Because the application is stateless, any instance can handle any request, making horizontal scaling seamless and highly available.

This approach eliminates manual intervention and optimizes costs by scaling in during low-traffic periods.

Exam trap

CV0-004 often tests the misconception that vertical scaling is more efficient for spiky traffic, but the exam expects you to recognize that horizontal scaling with auto-scaling groups is the most cost-effective and efficient for stateless applications.

How to eliminate wrong answers

Option A is wrong because using a larger instance type (vertical scaling) and scheduling scaling actions still requires manual capacity planning and does not automatically respond to unexpected traffic spikes; it also often leads to over-provisioning during off-peak hours. Option B is wrong because pre-provisioning double capacity permanently is highly cost-inefficient, as you pay for idle resources during normal and low-traffic periods. Option D is wrong because vertical scaling with manual adjustments is reactive, labor-intensive, and limited by the maximum size of an instance; it cannot handle sudden spikes efficiently and may cause downtime during resizing.

427
MCQeasy

Which of the following storage types is most suitable for hosting a shared file system that multiple virtual machines need to access concurrently using NFS?

A.Archive storage
B.File storage
C.Block storage
D.Object storage
AnswerB

File storage exposes SMB or NFS shares, letting multiple VMs mount the same file system concurrently. Block storage attaches to a single instance, and object storage lacks a POSIX NFS interface. NFS concurrency is therefore satisfied only by file storage.

Why this answer

File storage (e.g., EFS, Azure Files) provides a shared file system accessible via NFS or SMB.

428
MCQmedium

A mid-sized company is migrating its on-premises applications to a public cloud. The security team has implemented a cloud access security broker (CASB) to monitor and enforce policies for sensitive data. The company uses a multi-cloud environment with both AWS and Azure. After deployment, the security team receives alerts that a developer accidentally exposed a set of credentials in a public GitHub repository. The credentials were associated with a service account that has read-write access to an AWS S3 bucket containing customer PII (personally identifiable information). The team immediately revokes the credentials and rotates the access keys. The security team wants to prevent such incidents in the future and ensure that any exposed credentials are promptly detected without relying solely on manual GitHub scans. The company also wants to maintain a least-privilege model for all cloud resources. Given this scenario, which of the following actions should the security team take FIRST to reduce the risk of credential exposure and improve detection?

A.Implement a periodic secret scanning tool that runs every 24 hours and reports any found credentials to the security team.
B.Configure the CASB to integrate with the GitHub API to continuously scan for exposed secrets and automatically trigger alerts.
C.Disable all public repositories and require all code to be stored in private repositories with strict branch protection rules.
D.Require all developers to use a password manager to store secrets and set up a process to manually review GitHub commits.
AnswerB

Integrating the CASB with the GitHub API gives continuous, automated secret scanning across repositories, replacing manual checks and satisfying the stem's detection requirement. Alerts fire immediately when credentials appear, enabling prompt revocation before the exposed service account's read-write S3 access can be abused.

Why this answer

A CASB is designed to integrate with cloud services like GitHub via APIs to provide continuous monitoring and policy enforcement. By configuring the CASB to scan GitHub repositories in real-time, the security team can detect exposed credentials immediately upon commit, rather than relying on periodic scans or manual reviews. This aligns with the requirement for prompt detection without manual intervention and leverages the existing CASB investment for multi-cloud environments.

Exam trap

CompTIA often tests the distinction between periodic and continuous detection mechanisms, where candidates may choose a periodic scanning tool (Option A) because it seems simpler, but the question explicitly requires prompt detection without relying solely on manual scans, making real-time CASB integration the correct first action.

How to eliminate wrong answers

Option A is wrong because a periodic secret scanning tool that runs every 24 hours introduces a detection delay, which contradicts the requirement for prompt detection of exposed credentials; real-time detection is needed to minimize the window of exposure. Option C is wrong because disabling all public repositories and requiring private repositories with branch protection rules reduces the attack surface but does not address the detection of already-exposed credentials or prevent accidental commits of secrets to private repositories; it also ignores the need for continuous monitoring. Option D is wrong because requiring developers to use a password manager and manually review commits is a procedural control that lacks automation and scalability, failing to meet the requirement for prompt detection without relying solely on manual scans.

429
MCQhard

A financial services company stores regulated data in Amazon S3 buckets. A security architect must ensure that objects are encrypted at rest using keys that the company controls, can be rotated on a schedule, and can be audited independently of AWS-managed keys. The keys must not leave AWS hardware security modules in plaintext. Which encryption option should the architect choose?

A.SSE-KMS with a customer managed key in AWS KMS
B.SSE-S3 with bucket default encryption
C.SSE-C with customer-provided keys
D.Client-side encryption before uploading to S3
AnswerA

SSE-KMS with a customer managed key lets the company define key policies, enable automatic rotation, and audit every use through CloudTrail and KMS key usage logs. The key material is protected by AWS KMS HSMs and never leaves them in plaintext. This satisfies control, scheduled rotation, and independent auditability for the regulated data.

Why this answer

SSE-KMS with a customer managed key gives the company ownership of the key policy, scheduled rotation, and an audit trail via CloudTrail and KMS logs, while the key material remains protected inside AWS KMS HSMs. This matches the control, rotation, and auditability requirements.

Exam trap

The trap here is confusing customer-controlled keys with customer-provided keys, assuming SSE-C provides the same audit and rotation benefits as a KMS customer managed key.

430
MCQmedium

A cloud architect is designing a system that must durably store an unlimited amount of unstructured data, such as images and videos, with 99.999999999% (11 nines) durability. The data will be accessed infrequently, but when accessed, it must be available within milliseconds. The architect wants the most cost-effective storage class for this access pattern. Which Amazon S3 storage class should the architect choose?

A.Amazon S3 Glacier Deep Archive
B.Amazon S3 Standard
C.Amazon S3 Intelligent-Tiering
D.Amazon S3 Standard-Infrequent Access (S3 Standard-IA)
AnswerD

Amazon S3 Standard-IA is designed for data that is accessed less frequently but requires rapid access when needed. It offers the same low latency and high throughput as S3 Standard, with 11 nines of durability, and has a lower storage price. It is the most cost-effective choice for infrequently accessed data that must be immediately available, though it has a minimum storage duration charge of 30 days.

Why this answer

Amazon S3 Standard-IA is the correct choice because it provides low-latency access and 11 nines of durability at a lower storage cost than S3 Standard, making it ideal for infrequently accessed data that requires immediate availability. The other options are either too expensive for infrequent access, incur monitoring fees, or have retrieval times that are too slow.

Exam trap

The trap here is assuming that S3 Intelligent-Tiering is always the most cost-effective for infrequent access, when in fact it adds a per-object monitoring fee that can make it more expensive than a static infrequent access class for known access patterns.

431
Multi-Selecteasy

Which TWO of the following are effective methods to protect data in transit within a cloud environment? Select two.

Select 2 answers
A.Object-level ACLs
B.Server-side encryption with AES-256
C.Data masking
D.VPN overlay networks
E.TLS/SSL encryption
AnswersD, E

VPN overlay networks encapsulate traffic within encrypted tunnels, such as IPsec or TLS, protecting data as it crosses untrusted networks between cloud and on-premises resources. This directly satisfies the "in transit" requirement by securing the transmission path itself, rather than data at rest or endpoint authentication.

Why this answer

Options D and E are correct because VPN overlay networks and TLS/SSL encryption both protect data in transit by encrypting the communication channel. Option A (object-level ACLs) controls access to data but does not encrypt it in transit. Option B (server-side encryption with AES-256) protects data at rest.

Option C (data masking) obscures data but does not protect it during transmission.

432
MCQhard

A company runs a stateless web application on AWS EC2 instances behind an Application Load Balancer. To reduce costs, they want to use the most cost-effective compute option that can handle variable traffic and be interrupted. Which pricing model should they use for the EC2 instances?

A.Dedicated hosts
B.Spot instances
C.Reserved instances
D.On-demand instances
AnswerB

Spot instances exploit spare EC2 capacity at steep discounts, suiting the stateless, interruptible workload described. The Application Load Balancer distributes traffic across instances, so a reclaimed Spot instance causes no data loss, and variable demand is met elastically. This satisfies the stem's cost-effectiveness and tolerance-for-interruption constraints better than On-Demand or Reserved pricing.

Why this answer

Spot instances are the most cost-effective EC2 option for stateless, interruption-tolerant workloads. They leverage unused AWS capacity at discounts up to 90% off On-Demand, and since the application is stateless and sits behind an ALB, instances can be terminated and replaced without data loss or session disruption. This matches the requirement for variable traffic handling with cost reduction.

Exam trap

CV0-004 often tests the misconception that Reserved Instances are always the cheapest option, but they require commitment and are unsuitable for variable or interruptible workloads; the key is recognizing that 'interrupted' and 'stateless' point directly to Spot.

How to eliminate wrong answers

Option A is wrong because Dedicated Hosts are physical servers fully dedicated to a single customer, designed for licensing and compliance needs, and are the most expensive option—not cost-effective for variable, interruptible workloads. Option C is wrong because Reserved Instances require a 1- or 3-year commitment and provide savings only for steady-state, predictable usage; they do not handle variable traffic well and cannot be interrupted for savings. Option D is wrong because On-Demand instances offer no discount and are billed per second with no interruption capability, making them the least cost-effective choice for a workload that can tolerate interruptions.

433
MCQmedium

A security team wants to implement host-based intrusion detection on their virtual machines in a public cloud. Which approach provides the most effective detection while minimizing performance impact?

A.Install an antivirus agent on each VM.
B.Enable network traffic logging at the hypervisor level.
C.Enable VPC flow logs and analyze them.
D.Use a cloud-native security service that deploys an agent to monitor system logs and file integrity.
AnswerD

A cloud-native agent monitors system logs and file integrity directly on each VM, satisfying the host-based detection requirement. Agent-based collection captures OS-level events that network inspection cannot see, while lightweight log and integrity checks limit CPU and memory overhead compared with full packet capture or continuous file scanning.

Why this answer

Cloud-native security services that deploy agents on each VM provide host-based intrusion detection by monitoring system logs and file integrity, which is the most effective method for host-level threats. Options A, B, and C are incorrect: A (antivirus) focuses on malware, not intrusion detection; B and C are network-based, not host-based, and may not capture host-level events.

434
MCQhard

A company uses GitHub Actions to build and deploy a microservices application. They want to automate the deployment to a Kubernetes cluster only when changes are pushed to the main branch. Which GitHub Actions event trigger should be used in the workflow?

A.on: workflow_dispatch:
B.on: push: branches: [ main ]
C.on: schedule: - cron: '0 0 * * *'
D.on: pull_request: branches: [ main ]
AnswerB

The push event with a branches filter limited to main triggers the workflow only when commits land on that branch, ignoring pushes to feature branches. This precisely matches the requirement to deploy solely on main-branch changes.

Why this answer

The 'push' event with branch filters triggers on pushes to main. 'pull_request' triggers on PR events; 'schedule' triggers on a cron; 'workflow_dispatch' triggers manually.

435
MCQmedium

A company wants to connect its on-premises data center to a public cloud provider with a dedicated, high-bandwidth, low-latency connection. The connection must be private and not traverse the internet. Which connectivity option should be used?

A.Site-to-Site VPN
B.Internet gateway
C.VPC peering
D.Direct Connect or ExpressRoute
AnswerD

Direct Connect and ExpressRoute provide dedicated private circuits between on-premises infrastructure and cloud providers, bypassing the public internet entirely. This satisfies the stem's requirements for high bandwidth, low latency, and privacy. Unlike site-to-site VPNs, which tunnel over the internet, these services deliver consistent performance through a direct physical link.

Why this answer

AWS Direct Connect and Azure ExpressRoute are dedicated private connectivity services that establish a physical cross-connect between the on-premises data center and the cloud provider's network via a colocation facility, bypassing the public internet entirely. They deliver high bandwidth (up to 100 Gbps with LAG) and consistent low latency, satisfying the private, non-internet requirement.

Exam trap

CV0-004 often tests whether candidates distinguish dedicated private interconnect (Direct Connect/ExpressRoute) from internet-based VPNs, trapping them into selecting Site-to-Site VPN because it is also 'private' via encryption — but it still traverses the public internet.

How to eliminate wrong answers

Option A is wrong because a Site-to-Site VPN tunnels traffic over the public internet (IPsec), so it does traverse the internet and offers variable latency and bandwidth — it fails the 'not traverse the internet' requirement. Option B is wrong because an Internet gateway is the cloud-side component that enables VPC resources to communicate with the internet; it is the opposite of a private dedicated connection. Option C is wrong because VPC peering connects two VPCs within (or across) cloud accounts/regions — it is cloud-to-cloud connectivity and does not connect an on-premises data center to the cloud.

436
Multi-Selectmedium

A cloud administrator is troubleshooting a connectivity issue between two VPCs in the same region. Which TWO actions should the administrator verify? (Choose two.)

Select 2 answers
A.VPC peering connection status
B.Route table entries
C.Security group rules
D.VPN tunnel configuration
E.Internet gateway attachment
AnswersA, B

VPC peering provides a direct private route between two VPCs, so its connection status must be Active before traffic can flow. A Pending, Rejected or Expired state blocks all routing regardless of route tables or security groups, directly satisfying the stem's same-region VPC-to-VPC connectivity requirement.

Why this answer

Option A (VPC peering connection status) is correct because a peering connection must be in the 'active' state for traffic to flow between the two VPCs; if it is 'pending-acceptance', 'rejected', or 'deleted', connectivity will fail regardless of routing. Option B (Route table entries) is correct because each VPC's route tables must contain routes pointing the destination CIDR of the peer VPC to the peering connection (pcx-xxxx), and missing or incorrect routes are a common cause of peering failures. Option C (Security group rules) is not the primary check here because security groups are stateful and typically evaluated after routing works, and the question targets VPC-to-VPC connectivity rather than instance-level filtering.

Option D (VPN tunnel configuration) does not apply because VPC peering does not use VPN tunnels; VPNs are used for site-to-site or remote-access connections. Option E (Internet gateway attachment) is irrelevant because traffic between peered VPCs in the same region does not traverse an internet gateway.

Exam trap

CV0-004 often tests the misconception that security groups or IGWs are the first thing to check for VPC-to-VPC connectivity, when in fact peering status and route tables are the prerequisites that must exist before any security control matters.

437
MCQhard

A company is migrating a legacy monolithic application to a microservices architecture on the cloud. The application has tight coupling and shared database schemas. Which migration strategy should the company adopt to reduce risk and enable iterative migration?

A.Re-platform to a managed service and rewrite later
B.Use the strangler fig pattern to gradually replace components
C.Containerize the monolithic application and run it on a cluster
D.Lift and shift the entire application, then refactor in-place
AnswerB

The strangler fig pattern incrementally routes traffic from legacy components to new microservices via a facade, letting you peel away tightly coupled modules and shared schemas piece by piece. This satisfies the requirement to reduce risk and enable iterative migration rather than a risky big-bang rewrite.

Why this answer

The strangler fig pattern is the correct migration strategy because it allows the company to incrementally replace specific functionalities of the legacy monolithic application with new microservices, reducing risk by keeping the existing system operational during the transition. This approach directly addresses the tight coupling and shared database schema issues by enabling gradual decomposition without requiring a complete rewrite or a risky big-bang migration.

Exam trap

The trap here is that candidates often confuse the strangler fig pattern with containerization or lift-and-shift, mistakenly believing that simply moving the monolith to containers or a managed service constitutes a migration strategy, when in fact those approaches do not break the tight coupling or enable iterative decomposition.

How to eliminate wrong answers

Option A is wrong because re-platforming to a managed service and rewriting later does not address the tight coupling and shared database schema issues; it merely shifts the monolithic application to a different hosting environment without breaking dependencies, and the deferred rewrite introduces significant technical debt and risk. Option C is wrong because containerizing the monolithic application and running it on a cluster (e.g., Kubernetes) preserves the tight coupling and shared database schema, offering no architectural decomposition and failing to enable iterative migration to microservices. Option D is wrong because lift and shift followed by in-place refactoring is a high-risk, big-bang approach that attempts to refactor the entire monolith at once, which is prone to extended downtime and regression issues, and does not support the iterative, low-risk migration required.

438
MCQhard

A cloud security engineer is implementing a data loss prevention (DLP) strategy for sensitive data stored in Amazon S3. The company must detect and prevent accidental exposure of personally identifiable information (PII) in objects uploaded by users. The engineer needs a solution that automatically scans new objects, identifies PII, and can trigger alerts or block access. Which AWS service should the engineer use?

A.AWS GuardDuty
B.Amazon Inspector
C.Amazon Macie
D.AWS Config
AnswerC

Amazon Macie is a fully managed data security and privacy service that uses machine learning to automatically discover, classify, and protect sensitive data in S3. It continuously evaluates buckets for PII and other sensitive data, providing detailed findings and alerting via EventBridge. It can also be configured to automatically remediate issues, such as blocking public access, making it the appropriate choice for this scenario.

Why this answer

Amazon Macie is purpose-built to discover and protect sensitive data in S3. It uses pattern matching and machine learning to identify PII, financial data, and credentials. It provides findings that can be integrated with Security Hub and EventBridge for automated responses.

This directly addresses the need to scan new objects, detect PII, and trigger alerts or remediation actions.

Exam trap

The trap here is confusing threat detection (GuardDuty) or configuration auditing (AWS Config) with data classification and DLP capabilities.

439
MCQeasy

A cloud engineer wants to receive real-time notifications when a CloudWatch Alarm enters the ALARM state. Which notification channel can be configured directly within the CloudWatch Alarm action?

A.PagerDuty
B.AWS Chatbot
C.Amazon Simple Notification Service (SNS)
D.Slack webhook
AnswerC

CloudWatch Alarm actions natively support Amazon SNS topics as a notification target, so publishing to an SNS topic delivers real-time ALARM-state notifications to subscribers. Lambda, SQS and EventBridge require separate wiring rather than direct alarm configuration.

Why this answer

Amazon CloudWatch Alarms natively support Amazon SNS topics as an alarm action — when the alarm transitions to ALARM state, CloudWatch publishes a message to the configured SNS topic, which then fans out to email, SMS, Lambda, SQS, or HTTP endpoints. SNS is the only notification channel that can be configured directly in the alarm's action list without additional integration services.

Exam trap

CV0-004 often tests whether candidates know that CloudWatch Alarms can only directly invoke SNS (plus a few AWS-native actions) — candidates incorrectly assume third-party tools like PagerDuty or Slack can be configured as native alarm actions.

How to eliminate wrong answers

Option A is wrong because PagerDuty is a third-party incident-management platform; it is not a native CloudWatch alarm action and requires integration via SNS, Lambda, or EventBridge. Option B is wrong because AWS Chatbot is a separate service that bridges SNS/EventBridge to Slack or Microsoft Teams — it is not selectable directly as a CloudWatch alarm action. Option D is wrong because a Slack webhook is an external HTTPS endpoint; CloudWatch cannot call it directly and requires SNS plus a Lambda function (or AWS Chatbot) to relay the notification.

440
MCQeasy

Which cloud service model provides the customer with the most control over the operating system and software stack?

A.FaaS
B.SaaS
C.PaaS
D.IaaS
AnswerD

IaaS delivers virtualised compute, storage and networking while leaving the guest operating system, middleware and applications to the customer. This satisfies the requirement for maximum control, since the customer patches, hardens and configures the OS and software stack themselves.

Why this answer

IaaS (Infrastructure as a Service) provides the customer with the highest level of control over the operating system and software stack among the cloud service models. In IaaS, the provider manages the physical infrastructure, but the customer is responsible for the OS, middleware, runtime, and applications. This allows for maximum customization and control.

Exam trap

CV0-004 often tests the understanding of the shared responsibility model and which model offers the most control. The trap is to confuse PaaS with IaaS, thinking PaaS gives more control because it includes a platform, but actually IaaS gives more control over the OS.

How to eliminate wrong answers

Option A is wrong because FaaS (Function as a Service) abstracts away the OS and runtime, giving the customer only control over the function code. Option B is wrong because SaaS (Software as a Service) provides a complete application managed by the provider, with minimal customer control. Option C is wrong because PaaS (Platform as a Service) provides a platform for deploying applications, but the OS and runtime are managed by the provider, so the customer has less control than with IaaS.

441
MCQhard

A cloud architect is designing a shared file system for a machine learning cluster where multiple Linux virtual machines must read and write the same training data concurrently with POSIX semantics. The workload runs for several weeks and needs high aggregate throughput. Which storage solution should the architect select?

A.An object storage bucket accessed through a REST API for all training data reads and writes.
B.A local SSD on each virtual machine with a scheduled rsync job to synchronize data.
C.A managed network file system that supports concurrent POSIX access and scales throughput with provisioned capacity.
D.A block storage volume attached to each virtual machine individually.
AnswerC

A managed network file system designed for concurrent access provides the shared POSIX namespace the cluster needs, and its throughput often scales with provisioned capacity, which suits a multi-week, high-throughput training job. It supports many clients mounting the same file system simultaneously, so all virtual machines see consistent file metadata and can read and write in parallel.

Why this answer

A managed network file system is purpose-built for many clients mounting the same POSIX namespace concurrently. It provides shared file locking and metadata, and its throughput commonly scales with provisioned capacity, making it suitable for a long-running, high-throughput machine learning workload that requires consistent concurrent access.

Exam trap

The trap here is assuming that fast local SSDs or object storage can substitute for a shared POSIX file system, when neither provides concurrent file semantics across many nodes.

442
MCQeasy

A cloud administrator needs to design a storage solution that provides block-level access for a database server and must be highly durable. Which storage type should be used?

A.File storage
B.Block storage
C.Archive storage
D.Object storage
AnswerB

Block storage presents raw volumes over protocols such as iSCSI or NVMe, which a database server formats and mounts directly, giving the low-latency block-level access databases demand. Cloud block volumes replicate within the availability zone, delivering the required durability.

Why this answer

Block storage is the correct choice because it provides raw, low-latency block-level access that database servers require for high-performance read/write operations. It also supports features like RAID, snapshots, and replication to achieve high durability, making it ideal for transactional databases.

Exam trap

CompTIA often tests the misconception that object storage can serve as a high-performance block store, but candidates must remember that object storage lacks the low-latency, block-level access and filesystem semantics required for transactional databases.

How to eliminate wrong answers

Option A is wrong because file storage uses a hierarchical file system with network protocols like NFS or SMB, which introduces overhead and is not optimized for the low-latency, block-level I/O patterns of a database server. Option C is wrong because archive storage is designed for long-term retention of infrequently accessed data, with high latency and no block-level access, making it unsuitable for active database workloads. Option D is wrong because object storage uses a flat namespace with HTTP-based APIs (e.g., S3) and is optimized for unstructured data, not for the block-level, random read/write operations required by databases.

443
MCQhard

A company is migrating its on-premises application to a public cloud. The application requires low-latency access to a legacy database that cannot be moved to the cloud. The cloud deployment must use a hybrid architecture. Which network connectivity solution should the cloud architect recommend to minimize latency and provide secure, reliable communication?

A.Use a dedicated private connection via a cloud provider's direct connect service.
B.Route traffic through the public internet with encryption.
C.Deploy a CloudFront distribution to cache database queries.
D.Establish a site-to-site VPN over the internet.
AnswerA

A dedicated private interconnect bypasses the public internet, providing deterministic paths and low jitter to the on-premises legacy database. This satisfies the hybrid architecture's latency-minimisation and reliability constraints better than site-to-site VPN over shared internet links.

Why this answer

A dedicated private connection via a cloud provider's direct connect service (e.g., AWS Direct Connect, Azure ExpressRoute, or Google Cloud Interconnect) establishes a private, physical link between the on-premises data center and the cloud VPC. This bypasses the public internet entirely, providing consistent low-latency performance, higher bandwidth, and a more reliable connection for hybrid architectures where the legacy database remains on-premises.

Exam trap

CompTIA often tests the misconception that a site-to-site VPN is sufficient for low-latency hybrid connectivity, but the trap here is that VPNs over the internet cannot guarantee consistent latency or bandwidth, whereas a dedicated private connection provides a Service Level Agreement (SLA) for performance and reliability.

How to eliminate wrong answers

Option B is wrong because routing traffic through the public internet with encryption (e.g., HTTPS or IPsec) introduces variable latency, potential packet loss, and security risks from exposure to internet-based threats, making it unsuitable for low-latency requirements. Option C is wrong because CloudFront (or any CDN) is a content delivery service for caching static or dynamic web content at edge locations; it cannot cache database queries or provide a network path to an on-premises database, and it adds unnecessary complexity without addressing the hybrid connectivity need. Option D is wrong because a site-to-site VPN over the internet, while encrypted and secure, relies on the public internet's best-effort routing, which introduces jitter and higher latency compared to a dedicated private connection, failing the low-latency requirement.

444
MCQmedium

A company is designing a disaster recovery (DR) plan for a critical application hosted in a public cloud. The application requires a recovery time objective (RTO) of 1 hour and a recovery point objective (RPO) of 15 minutes. Which of the following DR strategies BEST meets these requirements?

A.Backup and restore with daily backups.
B.Cold standby with nightly backups.
C.Pilot light with hourly snapshots.
D.Warm standby with continuous data replication.
AnswerD

Warm standby with continuous replication keeps a running scaled-down environment and replicates data continuously, giving an RPO near zero and rapid failover within the one-hour RTO. This satisfies both the 15-minute RPO and one-hour RTO constraints.

Why this answer

Warm standby with continuous data replication meets the RTO of 1 hour and RPO of 15 minutes because it maintains a partially scaled-down replica of the production environment that can be quickly scaled up, and continuous replication (e.g., using asynchronous replication or Change Block Tracking) ensures data loss is limited to seconds or minutes, well within the 15-minute RPO.

Exam trap

CompTIA often tests the distinction between 'pilot light' and 'warm standby' — the trap here is that candidates confuse hourly snapshots (pilot light) with continuous replication, failing to recognize that hourly snapshots cannot achieve a 15-minute RPO.

How to eliminate wrong answers

Option A is wrong because daily backups provide an RPO of up to 24 hours, far exceeding the required 15 minutes, and the restore process would take much longer than 1 hour, failing the RTO. Option B is wrong because cold standby involves no pre-provisioned resources, requiring manual provisioning and configuration that typically takes hours, exceeding the 1-hour RTO, and nightly backups provide an RPO of up to 24 hours. Option C is wrong because pilot light with hourly snapshots provides an RPO of up to 1 hour, which exceeds the 15-minute requirement, and the snapshots are not continuous, so data loss could be significant.

445
Drag & Dropmedium

Arrange the steps to configure a VPN connection between an on-premises network and a cloud VPC.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Start with cloud-side gateway, on-premises gateway representation, configure on-prem device, create connection, then routing.

446
MCQeasy

A cloud administrator needs to give the security team read-only visibility into all API activity across an AWS account, including who made each call, when, and from which IP address. The records must be retained for 365 days for compliance. Which service should the administrator use?

A.Amazon CloudWatch Logs
B.AWS Trusted Advisor
C.AWS Config
D.AWS CloudTrail
AnswerD

CloudTrail records API activity in an account, capturing the identity of the caller, the time, the source IP, and the request details. Creating a trail that delivers events to an S3 bucket with a 365-day lifecycle or retention policy satisfies the compliance requirement for long-term audit visibility.

Why this answer

CloudTrail is the service purpose-built to record API activity in an AWS account, including caller identity, timestamp, and source address. Delivering those events to durable storage with a retention policy of 365 days meets both the visibility and compliance needs described.

Exam trap

The trap here is confusing configuration-change tracking or log aggregation with full API audit logging.

447
MCQeasy

A cloud user is unable to connect to a web server VM from the internet after a security group rule was modified. The VM is running and can be pinged from other VMs in the same subnet. What is the most likely cause?

A.The VM's local firewall is blocking the traffic.
B.The VM's routing table is missing a default gateway.
C.The inbound rule for HTTP/HTTPS was removed or misconfigured.
D.The VM's DNS settings are incorrect.
AnswerC

Intra-subnet pings succeeding proves the VM, OS and network path are healthy, isolating the fault to the security group. Modifying that group most likely removed or misconfigured the inbound HTTP/HTTPS rule, blocking internet clients while internal traffic continues.

Why this answer

The most likely cause is that the inbound security group rule for HTTP/HTTPS was removed or misconfigured, as security groups act as virtual firewalls controlling traffic to the VM. Since the VM can be pinged from other VMs in the same subnet, the network path and VM's OS are functional, isolating the issue to the security group's inbound rules. Modifying the security group likely removed the rule allowing HTTP/HTTPS traffic from the internet.

Exam trap

CV0-004 often tests the confusion between security group rules and network ACLs, or between local firewall and cloud firewall; candidates may overlook that successful pings indicate the issue is specific to the port/protocol, not general connectivity.

How to eliminate wrong answers

Option A is wrong because if the VM's local firewall were blocking traffic, it would also block pings from other VMs, but pings are successful. Option B is wrong because a missing default gateway would prevent communication with other subnets, but the VM can be pinged from VMs in the same subnet, indicating local routing works. Option D is wrong because DNS settings affect name resolution, not connectivity; the user is unable to connect, which is a connectivity issue, not a name resolution issue.

448
MCQeasy

A company wants to centralize logs from multiple AWS services and analyze them using SQL-like queries. Which service should they use?

A.AWS CloudTrail
B.Amazon S3
C.Amazon CloudWatch Logs Insights
D.AWS Config
AnswerC

CloudWatch Logs Insights runs SQL-like queries against log groups aggregated from multiple AWS services, returning results without exporting data elsewhere. This satisfies the centralised collection and query requirement directly, since logs remain in CloudWatch and are analysed in place rather than piped to Athena or OpenSearch.

Why this answer

Amazon CloudWatch Logs Insights provides an interactive query language that supports SQL-like commands (fields, filter, stats, sort, limit, parse) to analyze log data stored in CloudWatch Logs. It can query across multiple log groups from different AWS services, making it the right choice for centralized log analysis with SQL-like queries.

Exam trap

CV0-004 often tests the difference between log storage/collection services and log analytics services — candidates pick S3 or CloudTrail for querying, not realizing that SQL-like analysis requires CloudWatch Logs Insights (or Athena on S3).

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and delivers it to S3 or CloudWatch Logs, but it does not provide a SQL-like query engine for analyzing logs. Option B is wrong because Amazon S3 is object storage — it can store logs but does not natively offer SQL-like querying (Athena would be needed on top of S3). Option D is wrong because AWS Config evaluates resource configuration compliance and records configuration changes; it is not a log analytics engine and does not support SQL-like queries over arbitrary logs.

449
MCQmedium

A cloud engineer manages a Kubernetes cluster on Google Kubernetes Engine (GKE). An application team reports that a compromised container in the 'payments' namespace attempted to read secrets belonging to the 'analytics' namespace, but the request was denied. The engineer wants to enforce a policy that restricts pod-to-pod traffic so that only pods labeled 'app=frontend' can reach pods labeled 'app=api' on TCP port 8080, while denying all other ingress to the api pods. Which mechanism should the engineer implement?

A.A Kubernetes Service of type ClusterIP exposing the api pods, combined with a PodDisruptionBudget to limit access.
B.A GKE firewall rule (VPC firewall) that allows ingress to the node pool on TCP 8080 from the frontend node pool's IP range only.
C.An Istio sidecar with mTLS STRICT mode enabled in the payments and analytics namespaces.
D.A Kubernetes NetworkPolicy applied in the api namespace selecting pods with label app=api, with an ingress rule allowing only pods labeled app=frontend on TCP 8080.
AnswerD

NetworkPolicy is the native Kubernetes object that controls pod-level ingress and egress. Selecting app=api and permitting only app=frontend on TCP 8080 enforces the least-privilege requirement directly. On GKE, NetworkPolicy enforcement requires a policy-capable CNI (Calico or the built-in GKE Dataplane V2), which the cluster already has since the cross-namespace read was denied by a policy.

Why this answer

Kubernetes NetworkPolicy is the correct tool because it provides label-selector-based ingress control at the pod level. Selecting pods labeled app=api and allowing ingress only from app=frontend on TCP 8080 implements the required least-privilege traffic rule. Node-level VPC firewalls, Services, and mTLS alone cannot express or enforce this pod-label restriction, so the NetworkPolicy is the only option that meets the stated requirement.

Exam trap

The trap here is assuming VPC-level firewall rules or service mesh mTLS alone can restrict traffic between individual pods, when only a Kubernetes NetworkPolicy object can enforce label-based pod ingress.

450
MCQmedium

A cloud administrator is designing network security for a three-tier application. The web tier must be accessible from the internet, but the application and database tiers should only be reachable from the web tier. Which security group configuration should be used?

A.Use separate security groups: web allows HTTP/HTTPS from 0.0.0.0/0; app allows traffic from web security group; db allows traffic from app security group
B.Assign the same security group to all tiers and use a single inbound rule
C.Place all tiers in the same subnet and use a network ACL to permit all traffic
D.Configure a network ACL for each subnet with allow rules for the required traffic
AnswerA

Security groups act as stateful virtual firewalls referencing each other as sources. Chaining web-to-app and app-to-db rules restricts the application and database tiers to traffic originating from the preceding tier, satisfying the isolation constraint while exposing only the web tier publicly.

Why this answer

It uses separate security groups for each tier, implementing the principle of least privilege. The web tier security group allows HTTP/HTTPS from 0.0.0.0/0 for internet access, while the app tier security group references the web tier security group as its source, ensuring only traffic from the web tier can reach the application tier. Similarly, the database tier security group references the app tier security group, restricting access exclusively to the application tier.

This configuration enforces strict east-west traffic control and prevents direct internet access to the internal tiers.

Exam trap

A common trap is confusing the functionality of stateful security groups with stateless network ACLs. Candidates may choose network ACLs (Option D) thinking they provide similar control, not realizing that security groups support logical references to other security groups, which is essential for dynamic tier-to-tier access in a three-tier architecture.

How to eliminate wrong answers

Option B is wrong because assigning the same security group to all tiers with a single inbound rule would allow all tiers to communicate with each other without restriction, violating the principle of least privilege and potentially exposing the database tier to the web tier or the internet. Option C is wrong because placing all tiers in the same subnet and using a network ACL to permit all traffic eliminates subnet-level segmentation, allowing any instance in the subnet to reach any other instance, and network ACLs are stateless, requiring explicit return rules, which adds complexity and risk. Option D is wrong because while network ACLs can provide subnet-level filtering, they are stateless and do not support security group references as sources; they require manual IP address management and cannot dynamically reference the web tier's security group, making them less precise and harder to maintain for tier-to-tier access control.

Page 5

Page 6 of 12

Page 7