Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 451–525

834 questions total · 12pages · All types, answers revealed

Page 6

Page 7 of 12

Page 8
451
MCQeasy

A cloud administrator needs to ensure that log data is retained for one year to meet compliance requirements. Which action should be taken for the log group in CloudWatch Logs?

A.Set the log group's retention policy to 365 days
B.Create a CloudWatch Events rule to delete logs after one year
C.Increase the log group's data durability by enabling encryption
D.Export logs to Amazon S3 and delete the log group
AnswerA

Setting the log group's retention policy to 365 days directly satisfies the one-year compliance requirement, since CloudWatch Logs deletes events automatically once the configured retention period elapses. Configuring this at the log group level applies uniformly to every log stream within it, avoiding per-stream management and preventing indefinite storage costs.

Why this answer

CloudWatch Logs log groups have a retention setting that controls how long log events are kept before automatic deletion. Setting the retention policy to 365 days ensures logs are retained for exactly one year, meeting the compliance requirement without manual intervention.

Exam trap

CV0-004 often tests whether candidates know that retention is a native log group setting — candidates pick workarounds like EventBridge deletion rules or S3 export, missing the simple built-in retention policy configuration.

How to eliminate wrong answers

Option B is wrong because CloudWatch Events (now EventBridge) rules trigger actions based on events or schedules, but using a rule to delete logs after one year is an indirect, error-prone approach — the native retention setting already handles this. Option C is wrong because enabling encryption increases data durability and security but does not affect retention duration; encryption and retention are independent settings. Option D is wrong because exporting logs to S3 and deleting the log group removes the logs from CloudWatch and requires managing retention in S3 separately — it does not set retention on the log group as the question asks.

452
MCQeasy

A cloud administrator manages workloads in Microsoft Azure. The security team requires that all virtual machines apply operating system updates automatically during a defined window without the administrator logging in to each machine. Which Azure feature should the administrator use to meet this requirement?

A.Microsoft Defender for Cloud, with the regulatory compliance dashboard enabled for the subscription.
B.Azure Update Manager, with a maintenance configuration that schedules update assessments and installations on the target virtual machines.
C.Azure Policy, with a built-in initiative that audits whether the Guest Configuration extension is installed.
D.Azure Automation State Configuration, with a DSC configuration that declares the Windows Update service as running.
AnswerB

Azure Update Manager provides agentless assessment and scheduled patching for Azure and Arc-enabled machines. By assigning a maintenance configuration, the administrator defines the recurrence and maintenance window, and the service installs approved updates automatically, satisfying the requirement without interactive logon to each VM.

Why this answer

Azure Update Manager is the service purpose-built for assessing and installing operating system updates on Azure virtual machines and Arc-connected servers. A maintenance configuration defines the schedule and window, and the service performs assessment and installation automatically, which is exactly what the security team requires without per-machine administrator logon.

Exam trap

The trap here is confusing posture assessment or configuration enforcement services, which only report or enforce settings, with the service that actually schedules and installs operating system updates.

453
MCQhard

A company is deploying a containerized application on AWS Fargate. The application requires a persistent, shared storage volume that can be accessed by multiple tasks simultaneously and must survive task restarts. The storage must be highly available and scalable. Which storage solution should the company use?

A.Amazon Elastic File System (EFS)
B.Amazon Elastic Block Store (EBS) volumes
C.Amazon S3 bucket mounted as a file system
D.AWS Fargate ephemeral storage
AnswerA

Amazon EFS is a fully managed, scalable, elastic file system that can be mounted by multiple EC2 instances and Fargate tasks simultaneously. It provides shared storage that persists independently of task lifecycle, meeting the requirements for high availability and scalability in a multi-task Fargate deployment.

Why this answer

Amazon EFS is designed for shared, elastic file storage that can be mounted by multiple Fargate tasks concurrently. It provides the persistent, highly available, and scalable storage needed for the application, unlike EBS volumes which are not shared, ephemeral storage which is temporary, or S3 which is not a file system.

Exam trap

The trap here is assuming that EBS volumes can be shared across multiple Fargate tasks, but EBS is block storage that supports only single-attach for Fargate, and multi-attach is limited to specific EC2 instances.

454
Multi-Selectmedium

A company is experiencing intermittent connectivity issues between its on-premises data center and a public cloud environment over a VPN connection. Which TWO of the following should the administrator check to troubleshoot the problem?

Select 2 answers
A.Verify that the internet bandwidth is sufficient.
B.Validate the route tables on both sides of the VPN.
C.Ensure the cloud storage performance is adequate.
D.Check the DNS resolution of cloud endpoints.
E.Review the VPN logs and monitor packet loss.
AnswersB, E

Route tables determine whether traffic from each subnet reaches the VPN gateway and the remote network. Asymmetric or missing routes cause packets to drop intermittently, matching the reported connectivity symptoms, so verifying both sides confirms path symmetry.

Why this answer

Option B is correct because intermittent VPN connectivity is frequently caused by asymmetric or missing routes, so validating the route tables on both the on-premises and cloud sides ensures traffic is being forwarded to the correct tunnel and subnet. Option E is correct because reviewing VPN logs and monitoring packet loss reveals tunnel renegotiation failures, IKE/IPsec errors, or dropped packets that directly explain intermittent connectivity. Options A, C, and D are not the best choices: bandwidth may affect performance but not intermittent drops, cloud storage performance is unrelated to VPN transport, and DNS resolution issues would typically cause name resolution failures rather than intermittent tunnel connectivity.

Exam trap

CompTIA often tests the misconception that intermittent VPN issues are always bandwidth-related, but the real culprit is usually routing misconfiguration or tunnel instability, which is why route validation and log/packet-loss analysis are the correct pair.

455
MCQeasy

Which of the following is a characteristic of serverless computing (FaaS)?

A.You pay for allocated resources regardless of usage
B.You are charged per execution or compute time
C.You must manage the underlying servers
D.You have to provision capacity in advance
AnswerB

Serverless computing (FaaS) bills only for actual invocation and execution duration, measured in milliseconds, rather than for idle provisioned capacity. This consumption-based model directly satisfies the characteristic sought: no charges accrue while code sits dormant, unlike always-on virtual machines or containers.

Why this answer

Serverless computing (FaaS) abstracts all infrastructure management and bills based on actual consumption — typically per invocation and per GB-second of compute time. This means you pay only when your function executes, not for idle capacity. This consumption-based model is the defining economic characteristic of FaaS platforms like AWS Lambda, Azure Functions, and Google Cloud Functions.

Exam trap

CV0-004 often tests the confusion between serverless (consumption-based, no server management) and IaaS (pre-provisioned, pay-for-allocated) — candidates who conflate 'no servers to manage' with 'no servers involved' or who pick reserved-capacity answers get tripped up.

How to eliminate wrong answers

Option A is wrong because paying for allocated resources regardless of usage describes traditional IaaS or reserved-instance pricing, not serverless — FaaS scales to zero and charges nothing when idle. Option C is wrong because managing underlying servers is the opposite of serverless; the cloud provider fully manages the runtime, OS patching, and scaling. Option D is wrong because provisioning capacity in advance describes EC2-style pre-provisioned compute; FaaS automatically provisions and scales per request without any advance capacity planning.

456
MCQeasy

A company is migrating to the cloud and needs to transfer 200 TB of data from an on-premises data center to GCP. The network bandwidth is limited, so they want to use a physical appliance for offline transfer. Which GCP service should they use?

A.Azure Data Box
B.Transfer Appliance
C.AWS DataSync
D.Storage Transfer Service
AnswerB

Transfer Appliance is Google's physical, rackable device shipped to the customer, loaded with data, then returned for ingestion into GCP. It bypasses the limited-bandwidth constraint by moving 200 TB offline rather than over the network.

Why this answer

Storage Transfer Service is for online transfers; Transfer Appliance is Google's offline physical device; DataSync is AWS; Azure Data Box is Microsoft's offline device.

457
MCQeasy

A cloud administrator notices that a virtual machine is unresponsive. The VM is running on a hypervisor host that shows high CPU utilization. What should the administrator do first?

A.Reboot the hypervisor host
B.Increase the VM's vCPU count
C.Migrate the VM to another host
D.Check the VM console for OS-level issues
AnswerD

High host CPU utilisation may be caused by the guest OS itself, so checking the VM console first distinguishes an OS-level hang or runaway process from genuine hypervisor contention. This is the least disruptive diagnostic step before migrating or restarting the VM.

Why this answer

The first step in troubleshooting an unresponsive VM is to check the VM console for OS-level issues. This allows the administrator to see if the OS is hung, has a kernel panic, or is waiting for input. Option A is wrong because rebooting the hypervisor host would affect all VMs and is a drastic measure that should only be taken after other diagnostics.

Option B is wrong because increasing the VM's vCPU count does not address the root cause of unresponsiveness and could worsen resource contention on an already overloaded host. Option C is wrong because migrating the VM to another host is premature without first determining if the issue is OS-related; also, migration might not be possible if the VM is completely unresponsive.

458
MCQeasy

A cloud administrator is tasked with reducing costs for a development environment that runs 24/7. The environment consists of several virtual machines and a load balancer. Which action would most effectively reduce costs without affecting developer access during business hours?

A.Implement auto-scaling to run only one instance during off-hours.
B.Schedule the VMs to shut down during nights and weekends.
C.Use reserved instances for all VMs.
D.Change all VMs to burstable instance types.
AnswerB

Scheduling virtual machines to shut down outside business hours eliminates compute charges during nights and weekends while preserving developer access when needed. Because the environment runs 24/7 unnecessarily, this addresses the stem's cost constraint directly; the load balancer's minimal cost remains largely unchanged.

Why this answer

Scheduling VMs to shut down during nights and weekends directly reduces compute costs by eliminating runtime charges when the development environment is not needed. This approach preserves full availability during business hours without requiring architectural changes, and it is the most straightforward way to cut costs for a 24/7-running environment that only needs daytime access.

Exam trap

The trap here is that candidates often choose auto-scaling or burstable instances because they focus on reducing per-unit cost rather than eliminating runtime, missing the fact that shutting down VMs entirely during off-hours yields the greatest savings for a development environment with predictable idle periods.

How to eliminate wrong answers

Option A is wrong because auto-scaling to run only one instance during off-hours still keeps that instance running and incurring costs, and it does not address the load balancer's cost; moreover, auto-scaling is designed for variable demand, not for eliminating runtime entirely. Option C is wrong because reserved instances require a 1- or 3-year commitment and are intended for steady-state workloads, not for a development environment that can be shut down; they would lock in costs rather than reduce them for intermittent usage. Option D is wrong because changing to burstable instance types (e.g., AWS T-series) reduces per-hour cost but still charges for every hour the VMs run, so it does not eliminate the cost of running 24/7; it only lowers the rate, not the runtime.

459
MCQhard

A company runs a containerized application on a Kubernetes cluster. The application logs indicate occasional 'CrashLoopBackOff' errors. The developer says the application works fine locally. What is the most likely cause in the cloud environment?

A.The readiness probe is misconfigured and returning false.
B.The memory limit set in the pod spec is too low, causing the container to be OOMKilled.
C.The container image is not being pulled correctly from the registry.
D.The persistent volume claim is not bound to a storage class.
AnswerB

Locally the container likely had no cgroup memory cap, so it never triggered the kernel OOM killer. In Kubernetes, exceeding the pod spec's memory limit causes the kubelet to report OOMKilled, and the restart backoff loop produces CrashLoopBackOff. Raising the limit resolves it.

Why this answer

The 'CrashLoopBackOff' error indicates that the container is repeatedly crashing after startup. Since the application works locally, the issue is likely environmental. A memory limit set too low in the pod spec causes the container to exceed its allowed memory, triggering an OOMKill (Out of Memory Kill) by the kubelet.

The container restarts, fails again, and enters CrashLoopBackOff, which is a common cloud-specific resource constraint not present in local development.

Exam trap

CompTIA often tests the distinction between pod statuses: candidates confuse 'CrashLoopBackOff' (container crashes after starting) with 'ImagePullBackOff' (image pull failure) or 'Pending' (resource unavailability), so they incorrectly attribute the error to image or volume issues rather than resource limits.

How to eliminate wrong answers

Option A is wrong because a misconfigured readiness probe returning false would cause the pod to be marked as not ready and removed from service endpoints, but it would not cause the container to crash or enter CrashLoopBackOff; the container would continue running. Option C is wrong because if the container image were not being pulled correctly, the pod would show an 'ImagePullBackOff' or 'ErrImagePull' status, not 'CrashLoopBackOff'. Option D is wrong because an unbound persistent volume claim would cause the pod to remain in 'Pending' state, not crash after starting; the container would never run to begin with.

460
MCQmedium

A cloud administrator receives an alert that the CPU utilization on a production web server has exceeded 90% for the past hour. The administrator checks the metrics and sees that the request rate has increased. Which of the following is the MOST appropriate action to resolve the issue in the short term?

A.Increase the memory allocation for the virtual machine.
B.Implement rate limiting to reduce incoming requests.
C.Increase the number of vCPUs or add additional instances behind a load balancer.
D.Optimize the application code to reduce CPU usage.
AnswerC

Adding vCPUs or instances behind a load balancer directly addresses the capacity shortfall causing sustained high CPU from increased request volume. Horizontal scaling via the load balancer distributes load immediately, resolving the short-term constraint without code changes or architectural redesign.

Why this answer

Increasing the number of vCPUs or adding additional instances behind a load balancer directly addresses the high CPU utilization caused by increased request rate. This scales the compute resources horizontally or vertically to handle the load, which is the most immediate and effective short-term action for a production web server under sustained high traffic.

Exam trap

The trap here is that candidates often confuse high CPU utilization with a memory bottleneck or incorrectly assume that rate limiting is the only way to handle increased traffic, failing to recognize that scaling compute resources is the standard operational response to sustained high load.

How to eliminate wrong answers

Option A is wrong because increasing memory allocation does not reduce CPU utilization; CPU and memory are separate resources, and high CPU usage is not resolved by adding RAM. Option B is wrong because implementing rate limiting would drop or delay legitimate user requests, degrading the user experience and potentially violating SLAs, rather than resolving the capacity issue. Option D is wrong because optimizing application code is a long-term solution that requires development cycles, testing, and deployment, and is not appropriate for an immediate short-term fix in a production environment.

461
MCQmedium

A cloud operations team manages a fleet of Amazon EC2 instances behind an Application Load Balancer. During a recent incident, several instances stopped passing their ELB health checks but the Auto Scaling group did not replace them. The team wants the Auto Scaling group to automatically terminate and replace instances that fail ELB health checks, not just EC2 status checks. Which action should the team take?

A.Increase the health check grace period on the Auto Scaling group.
B.Configure a lifecycle hook to terminate instances that fail health checks.
C.Lower the unhealthy threshold on the target group health check.
D.Enable ELB health checks as an additional health check type on the Auto Scaling group.
AnswerD

By default an Auto Scaling group only uses EC2 status checks, so an instance that is running but failing the load balancer health check stays in service. Adding ELB as a health check type makes the group treat unhealthy ELB targets as unhealthy instances and replace them, which is exactly the behavior the team needs.

Why this answer

Auto Scaling groups by default rely only on EC2 status checks, which do not detect application-level failures seen by the load balancer. Adding ELB as a health check type lets the group treat targets failing the load balancer check as unhealthy and replace them automatically, restoring capacity without manual intervention.

Exam trap

The trap here is assuming that configuring the load balancer health check alone causes the Auto Scaling group to replace unhealthy instances.

462
Multi-Selectmedium

A cloud architect is designing a highly available three-tier application on AWS. The web tier must survive the loss of a single Availability Zone, and the database tier must support automatic failover with minimal administrative intervention. Which TWO design decisions should the architect implement? (Choose two.)

Select 2 answers
A.Use a Multi-AZ deployment for Amazon RDS so a standby is maintained in a second Availability Zone
B.Configure Amazon RDS as a Single-AZ instance with automated snapshots every hour
C.Attach an Elastic IP address to each web server instance and update DNS manually during an outage
D.Place all web servers in a single Availability Zone and use larger instance types
E.Deploy web servers in an Auto Scaling group spanning at least two Availability Zones behind an Application Load Balancer
AnswersA, E

RDS Multi-AZ maintains a synchronous standby in another Availability Zone and automatically promotes it during a failure, updating the DNS endpoint so the application reconnects without manual intervention. This satisfies the database requirement for automatic failover with minimal administration.

Why this answer

Zone-level resilience for the web tier comes from distributing instances across zones behind a load balancer, and database resilience with automatic failover comes from a Multi-AZ standby that is promoted without manual steps. The remaining choices either concentrate risk in one zone, rely on slow manual restoration, or depend on human intervention during an outage.

Exam trap

The trap here is equating backups or larger instances with high availability, when neither provides automatic failover during a zone outage.

463
MCQmedium

Refer to the exhibit. A cloud load balancer is returning 502 Bad Gateway errors to clients. What is the most likely cause?

A.The load balancer's SSL certificate is invalid.
B.The security group allows inbound traffic from the load balancer.
C.The DNS record points to the wrong IP.
D.The backend web servers are not responding correctly.
AnswerD

A 502 Bad Gateway means the load balancer received an invalid or incomplete response from an upstream backend. Since the balancer itself and client connectivity are functioning, the fault lies with the backend web servers failing to respond correctly, matching this option.

Why this answer

A 502 Bad Gateway error indicates that the load balancer (acting as a proxy or gateway) received an invalid or no response from the upstream backend web servers. This typically occurs when the backend servers are overloaded, have crashed, or are misconfigured (e.g., incorrect health check path, application pool failure). The load balancer successfully forwards the request but fails to get a valid HTTP response, triggering the 502 error.

Exam trap

CompTIA often tests the distinction between HTTP status codes (502 vs. 504 vs. 503) and their root causes, trapping candidates who confuse a backend response failure (502) with a timeout (504) or an overload condition (503).

How to eliminate wrong answers

Option A is wrong because an invalid SSL certificate on the load balancer would cause SSL/TLS handshake failures (e.g., 525 or 526 errors in Cloudflare, or certificate warnings), not a 502 Bad Gateway, which is a proxy-level error unrelated to certificate validity. Option B is wrong because allowing inbound traffic from the load balancer in the security group is actually a correct configuration; if it were blocked, the load balancer would receive connection timeouts or 504 errors, not 502 errors. Option C is wrong because a DNS record pointing to the wrong IP would cause clients to reach an incorrect server or no server at all, resulting in connection failures or 404 errors, not a 502 Bad Gateway from the load balancer.

464
Multi-Selectmedium

A cloud administrator is investigating a sudden increase in cost for a production environment. The administrator wants to identify the sources of the cost increase and implement a tagging strategy for cost allocation. Which TWO actions should the administrator take? (Choose two.)

Select 2 answers
A.Implement a rightsizing recommendation report.
B.Use the cloud provider's cost explorer to analyze cost drivers.
C.Enable detailed billing reports with resource tags.
D.Purchase Reserved Instances for all resources.
E.Create a budget alert for the total monthly cost.
AnswersB, C

The cloud provider's cost explorer aggregates spend by service, region and account, revealing which resources drive the sudden increase. This satisfies the investigation requirement, providing the cost-driver visibility needed before tags can be applied for allocation.

Why this answer

Option B is correct because the cloud provider's cost explorer (e.g., AWS Cost Explorer or Azure Cost Management) lets the administrator visualize and filter spending by service, account, region, and tag, which directly identifies the sources of the sudden cost increase. Option C is correct because enabling detailed billing reports (such as AWS Cost and Usage Report or Azure detailed usage data) with resource tags activated provides granular, per-resource cost and usage data that is required to build and validate a tag-based cost allocation strategy. Option A is not correct because a rightsizing recommendation report only suggests instance size or type changes and does not analyze cost drivers or enable tag-based allocation.

Option D is not correct because purchasing Reserved Instances for all resources is a commitment-based discount action, not an investigation or tagging strategy, and could increase risk if usage changes. Option E is not correct because a budget alert only notifies when total monthly cost crosses a threshold; it does not identify cost sources or implement tagging for allocation.

Exam trap

CV0-004 often tests the confusion between cost analysis tools (cost explorer, detailed billing) and cost optimization actions (rightsizing, reserved instances); candidates must select actions that directly address identification and tagging.

465
MCQmedium

A cloud engineer is tasked with setting up a disaster recovery (DR) plan for a critical application that runs on virtual machines in a private cloud. The DR site is a public cloud. The application requires low recovery time objective (RTO) of less than 15 minutes and recovery point objective (RPO) of less than 5 minutes. Which of the following replication strategies BEST meets these requirements?

A.Replicate virtual machine images to the DR site daily.
B.Use synchronous replication to keep data identical.
C.Configure agent-based backup to the DR site every 5 minutes.
D.Use continuous asynchronous replication to the DR site.
AnswerD

Continuous asynchronous replication ships every write to the public cloud DR site within seconds, keeping data loss inside the five-minute RPO while virtual machines stay powered off until failover. Recovery completes well under fifteen minutes because replicas are already current, satisfying both the low RTO and RPO constraints.

Why this answer

Continuous asynchronous replication replicates data changes to the DR site with minimal lag (often seconds), meeting an RPO of under 5 minutes while allowing recovery within the 15-minute RTO. It is the standard approach for cross-cloud DR where synchronous replication is impractical due to WAN latency. This strategy balances low RPO/RTO with the realities of replicating from a private cloud to a public cloud.

Exam trap

The trap is choosing synchronous replication for the lowest RPO without considering WAN latency and performance impact — the exam expects recognition that synchronous replication is unsuitable for cross-cloud DR.

How to eliminate wrong answers

Option A is wrong because daily VM image replication yields an RPO of up to 24 hours, far exceeding the 5-minute requirement. Option B is wrong because synchronous replication requires low-latency links and would severely impact application performance across a private-to-public cloud WAN; it is typically used within a single data center or metro area, not for cross-cloud DR. Option C is wrong because agent-based backup every 5 minutes meets RPO but does not provide the rapid failover and continuous replication needed to meet a 15-minute RTO — backups require restore time, which often exceeds 15 minutes for critical VMs.

466
MCQmedium

A company uses AWS and Azure for redundancy. They deploy the same application on both clouds to avoid vendor lock-in and improve disaster recovery. Which cloud deployment model is this?

A.Community cloud
B.Hybrid cloud
C.Private cloud
D.Multi-cloud
AnswerD

Multi-cloud means deliberately using two or more distinct public cloud providers, here AWS and Azure, for the same workload. This satisfies the redundancy, lock-in avoidance and disaster recovery constraints, unlike hybrid cloud, which pairs public cloud with private infrastructure.

Why this answer

Multi-cloud uses multiple public cloud providers for redundancy and best-of-breed services.

467
MCQeasy

A company wants to be notified when their monthly AWS spending exceeds $10,000. Which AWS service should they use to set up this alert?

A.AWS Trusted Advisor
B.AWS Budgets
C.AWS Cost Explorer
D.AWS CloudWatch Alarms
AnswerB

AWS Budgets lets you define a monthly cost budget with a threshold and configure alerts when actual or forecast spend exceeds it. This directly satisfies the $10,000 notification requirement, whereas CloudWatch alarms track metrics rather than billing amounts.

Why this answer

AWS Budgets allows you to set custom cost budgets and configure alerts when actual or forecasted spending exceeds a defined threshold, such as $10,000 per month. It sends notifications via email or SNS when the threshold is breached, directly satisfying the requirement to be notified about monthly spending exceeding a specific amount.

Exam trap

CV0-004 often tests the difference between cost visibility tools and cost alerting tools — candidates pick Cost Explorer or Trusted Advisor for notifications, when only AWS Budgets is designed to alert on spending thresholds.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides recommendations on cost optimization, security, and performance but does not send threshold-based spending alerts for a specific dollar amount. Option C is wrong because AWS Cost Explorer visualizes and analyzes historical cost and usage data but does not natively send alerts when spending exceeds a threshold. Option D is wrong because CloudWatch Alarms monitor metrics, and while the AWS/Billing metric EstimatedCharges exists in us-east-1, it is a less direct and less flexible mechanism than AWS Budgets for setting a $10,000 monthly spending alert.

468
MCQhard

A cloud engineer is deploying a containerized application on Amazon ECS using the Fargate launch type. The application requires a persistent shared storage volume that can be accessed by multiple tasks simultaneously. The engineer needs to ensure that the storage is highly available and can be mounted to multiple ECS tasks across different Availability Zones. Which storage solution should the engineer use?

A.Amazon S3 bucket
B.Amazon EFS file system
C.Amazon FSx for Windows File Server
D.Amazon EBS volume
AnswerB

Amazon EFS is a fully managed, highly available, and scalable file storage service that can be mounted to multiple ECS tasks across different Availability Zones simultaneously. It supports the Network File System (NFS) protocol and is designed for shared access, making it ideal for this requirement.

Why this answer

Amazon EFS is the correct choice because it provides shared, highly available file storage that can be mounted to multiple ECS tasks across Availability Zones. It uses NFS and is designed for concurrent access. EBS is single-attach, S3 is object storage, and FSx for Windows is for Windows workloads, so they do not meet the requirements.

Exam trap

The trap here is assuming that Amazon EBS can be shared across multiple tasks like a network file system; EBS is block storage with single-attach limitations.

469
MCQeasy

A cloud security team needs to ensure that all API calls made to the cloud provider are logged and monitored for suspicious activity. Which service should be enabled?

A.Deploy a web application firewall (WAF).
B.Configure an intrusion detection system (IDS) on the network.
C.Enable cloud audit logging for the management console and API calls.
D.Implement a security information and event management (SIEM) system.
AnswerC

Cloud audit logging captures management console actions and API calls, recording who did what, when, and from where. This satisfies the requirement to log and monitor all API calls for suspicious activity, feeding into security monitoring and alerting tools.

Why this answer

Cloud audit logging (e.g., AWS CloudTrail, Azure Activity Log, GCP Cloud Audit Logs) is the native service that records every management console action and API call made against the cloud provider, capturing identity, source IP, timestamp, and request parameters. This directly satisfies the requirement to log and monitor API activity for suspicious behavior. WAF, IDS, and SIEM are complementary controls but do not themselves generate the authoritative API audit trail.

Exam trap

The trap here is confusing detective controls (audit logging) with preventive or network-layer controls (WAF, IDS) and with aggregation tools (SIEM); candidates often pick SIEM because it 'monitors' activity, but the question asks which service must be enabled to generate the API log data in the first place.

How to eliminate wrong answers

Option A is wrong because a WAF inspects and filters HTTP/S application traffic at layer 7 to block exploits like SQLi or XSS; it does not record control-plane API calls or console actions. Option B is wrong because an IDS monitors network packets for known attack signatures or anomalies and has no visibility into authenticated cloud provider API calls or IAM-level events. Option D is wrong because a SIEM aggregates and correlates logs from many sources, but it is a consumer of logs — without cloud audit logging enabled there is no API event source for the SIEM to ingest.

470
MCQmedium

A company uses a cloud-based logging service to aggregate logs from multiple servers. Suddenly, the logging service stops receiving logs from several servers. The administrator checks the logging agent status on those servers and finds that the agents are running but not sending data. The network connectivity between the servers and the logging service is verified as working. Which of the following is the MOST likely cause?

A.The logging service has reached its storage quota.
B.The logging endpoint configuration on the agents is incorrect.
C.The logging agent is out of memory.
D.A firewall is blocking the outbound traffic from the servers.
AnswerB

Agents running but silent, with verified network connectivity, points to misconfiguration rather than transport failure. If the endpoint address or port the agent sends to is wrong, logs never reach the service, satisfying the stem's constraint that connectivity works while data flow does not.

Why this answer

The logging agents are running but not sending data, and network connectivity is verified as working. This points to a configuration issue where the agents are pointing to an incorrect logging endpoint (e.g., wrong URL, port, or API key). Even if the service is healthy, misconfigured agents will fail to transmit logs, which matches the symptom of agents running but idle.

Exam trap

The trap here is that candidates assume a running agent implies correct configuration, but agents can run idle if they cannot reach or authenticate to the configured endpoint, even when network connectivity is fine.

How to eliminate wrong answers

Option A is wrong because if the logging service had reached its storage quota, the service would typically reject new logs or return an error, but the agents would still attempt to send data (and likely log the rejection). Option C is wrong because an out-of-memory agent would likely crash, hang, or produce errors, not remain in a running state without sending data. Option D is wrong because network connectivity between the servers and the logging service is verified as working, which directly rules out a firewall blocking outbound traffic.

471
MCQeasy

A DevOps team wants to deploy a Kubernetes application using a package manager that simplifies the deployment process by bundling all Kubernetes resources into a single package. Which tool should the team use?

A.Kustomize
B.Helm
C.Ansible
D.Terraform
AnswerB

Helm packages Kubernetes manifests into versioned charts, letting the team install, upgrade and roll back the whole application as one unit. It bundles Deployments, Services and ConfigMaps into a single release, satisfying the requirement for a package manager.

Why this answer

Helm is the package manager for Kubernetes that uses charts to define, install, and upgrade even the most complex Kubernetes applications.

472
MCQeasy

Which storage type is most appropriate for a shared file system that multiple virtual machines need to mount simultaneously with read/write access?

A.Archive storage
B.File storage
C.Object storage
D.Block storage
AnswerB

File storage exposes SMB or NFS shares that many VMs can mount concurrently with read/write access, satisfying the simultaneous multi-mount constraint. Block storage attaches to a single instance, and object storage uses HTTP APIs rather than mountable file protocols.

Why this answer

File storage (e.g., NFS, SMB, or a shared file system like Azure Files) is designed to be mounted simultaneously by multiple clients with read/write access, providing a shared namespace and file-level locking. Block storage typically attaches to a single VM at a time (unless using shared disks with cluster-aware file systems), and object storage is accessed via HTTP APIs, not mounted as a traditional file system. Archive storage is for long-term retention and is not suitable for active shared read/write workloads.

Exam trap

CV0-004 often tests the confusion between block and file storage for shared access; candidates may pick block storage because it is common for VM disks, but block storage is not natively shared read/write across multiple VMs without a cluster file system.

How to eliminate wrong answers

Option A is wrong because archive storage is optimized for low-cost, infrequent access and long retrieval times, not for active shared read/write mounting by multiple VMs. Option C is wrong because object storage exposes data via REST APIs and is not natively mountable as a POSIX-compliant shared file system for simultaneous read/write by multiple VMs. Option D is wrong because block storage presents raw volumes that are typically attached to one VM at a time; simultaneous read/write from multiple VMs requires a cluster file system and is not the default or most appropriate choice for a shared file system.

473
Multi-Selecthard

Which THREE of the following are best practices when deploying a cloud application using Infrastructure as Code (IaC)? (Choose three.)

Select 3 answers
A.Store IaC templates in a version control system.
B.Break down complex deployments into reusable modules.
C.Embed credentials directly in the IaC templates.
D.Manually modify resources after deployment to tune performance.
E.Use immutable infrastructure patterns where possible.
AnswersA, B, E

Version control gives every template change an auditable history and enables rollback, peer review and branching. This directly satisfies the reproducibility and traceability that Infrastructure as Code demands, since environments can be rebuilt from a known, reviewed commit rather than undocumented manual edits.

Why this answer

Option A is correct because storing IaC templates in a version control system (e.g., Git) provides change history, peer review via pull requests, rollback capability, and auditability, which are foundational to reliable, repeatable deployments. Option B is correct because decomposing complex deployments into reusable modules (e.g., Terraform modules or CloudFormation nested stacks) reduces duplication, enforces consistency, and makes templates easier to test and maintain. Option E is correct because immutable infrastructure patterns—replacing rather than mutating running resources, often via new machine images or fresh stack deployments—eliminate configuration drift and make rollbacks deterministic.

Option C is not appropriate because embedding credentials directly in templates exposes secrets in version control and logs; secrets should be referenced from a secrets manager or parameter store. Option D is not appropriate because manually modifying resources after deployment creates configuration drift, breaks reproducibility, and means the IaC templates no longer reflect the actual environment.

Exam trap

CompTIA often tests the distinction between mutable and immutable infrastructure, and the trap here is that candidates may think manual tuning (Option D) is acceptable for performance optimization, but it violates the core IaC principle of idempotent, automated deployments.

474
MCQmedium

A cloud engineer deploys the Kubernetes manifest shown in the exhibit. After deployment, the frontend pods are in CrashLoopBackOff state. The engineer checks the logs and finds 'OOMKilled' errors. Which of the following changes would resolve the issue?

A.Increase the memory limit to 1Gi.
B.Increase the number of replicas to 5.
C.Reduce the CPU limit to 250m.
D.Change the service type to ClusterIP.
AnswerA

OOMKilled means the container exceeded its memory limit and the kernel terminated it. Raising the limit to 1Gi gives the frontend pods sufficient headroom, preventing the kubelet from killing them and ending the CrashLoopBackOff cycle.

Why this answer

The 'OOMKilled' error indicates the container's memory usage exceeded its configured limit, causing the kernel's Out-Of-Memory (OOM) killer to terminate the process. Increasing the memory limit to 1Gi provides the container with more memory headroom, preventing the OOM kill and allowing the pod to run without crashing.

Exam trap

CompTIA often tests the distinction between resource limits (memory vs. CPU) and scaling strategies, trapping candidates who confuse horizontal scaling (replicas) with vertical scaling (resource limits).

How to eliminate wrong answers

Option B is wrong because increasing the number of replicas does not address the per-pod memory exhaustion; it only distributes traffic across more pods, each still subject to the same insufficient memory limit. Option C is wrong because reducing the CPU limit does not affect memory allocation; OOM kills are triggered by memory, not CPU, and lowering CPU could cause throttling but not resolve the memory shortage. Option D is wrong because changing the service type to ClusterIP only alters network exposure (internal vs. external) and has no impact on container resource limits or OOM behavior.

475
MCQmedium

A cloud engineer is using Ansible to automate the configuration of cloud resources. The engineer needs to ensure that the automation does not require any agent software to be installed on the target nodes. Which characteristic of Ansible makes this possible?

A.It uses PowerShell Desired State Configuration
B.It uses a master-agent architecture
C.It is agentless
D.It requires a pull-based model
AnswerC

Ansible connects to target nodes over standard SSH or WinRM, pushing modules at runtime rather than relying on a persistent agent. This agentless architecture satisfies the constraint that no software be pre-installed on managed hosts.

Why this answer

Ansible is agentless because it communicates with managed nodes over standard SSH (Linux/Unix) or WinRM (Windows) rather than requiring a persistent agent daemon to be installed and maintained on each target. The control node pushes Python-based modules to the target at runtime, executes them, and removes them afterward. This is why option C directly answers the requirement that no agent software be installed on target nodes.

Exam trap

The trap here is confusing 'agentless' with 'no dependencies' — candidates may pick the pull-based option assuming Ansible works like Puppet, but Ansible is push-based by default and its agentless nature comes from SSH/WinRM, not from a pull model.

How to eliminate wrong answers

Option A is wrong because PowerShell Desired State Configuration is a Microsoft push/pull configuration platform used by tools like Ansible's win_dsc module, not the mechanism that makes Ansible agentless. Option B is wrong because a master-agent architecture is the opposite of agentless — it describes tools like Puppet, Chef, or Salt in agent mode, which require a persistent agent on each managed node. Option D is wrong because Ansible's default mode is push-based (the control node initiates SSH connections), not pull-based; pull mode (ansible-pull) is an optional pattern and does not explain agentless operation.

476
MCQmedium

During a disaster recovery test, a cloud administrator discovers that the standby database in a different region is not synchronized with the primary. The primary database uses asynchronous replication. What is the MOST likely reason for the sync failure?

A.License expiration on the standby database
B.Network latency causing replication lag
C.Firewall rules blocking port 3306 between regions
D.Incorrect replication configuration using a read replica instead of a standby
AnswerB

Asynchronous replication commits on the primary without waiting for the standby, so inter-region network latency directly manifests as replication lag. Sustained latency prevents the standby from ever catching up, which is the expected failure mode for cross-region async setups.

Why this answer

Asynchronous replication does not wait for the standby to acknowledge each write, so the standby can lag behind the primary. Cross-region replication is especially sensitive to network latency, which directly increases replication lag and can cause the standby to fall out of sync during a DR test. This is the most likely cause given the asynchronous, cross-region setup.

Exam trap

CV0-004 often tests the distinction between synchronous and asynchronous replication — candidates pick 'firewall blocking port' because it sounds like a concrete failure, but a blocked port would cause total replication failure, not a lag/sync gap, which is the hallmark of async replication under latency.

How to eliminate wrong answers

Option A is wrong because license expiration would typically stop the database service entirely or produce explicit license errors, not a gradual synchronization gap. Option C is wrong because if firewall rules blocked port 3306, replication would fail completely and immediately — there would be no partial sync, and the standby would show no recent transactions at all. Option D is wrong because a read replica is a valid replication target; the question states the primary uses asynchronous replication, and a read replica configured for async replication would still sync (just with lag), so misconfiguration is less likely than the inherent latency of async cross-region replication.

477
MCQmedium

An administrator is writing an Ansible playbook to provision cloud resources across multiple cloud providers. The playbook must manage instances in AWS, Azure, and GCP. Which Ansible concept should the administrator use to interact with each cloud provider's API?

A.Modules
B.Roles
C.Inventories
D.Playbooks
AnswerA

Ansible modules are provider-specific plugins that translate playbook tasks into each cloud API's native calls, so AWS, Azure and GCP each expose dedicated modules covering compute, networking and storage. This satisfies the stem's multi-cloud requirement, since a single playbook can invoke the appropriate module per provider without custom API scripting.

Why this answer

Ansible modules are the units of code that perform specific tasks, such as interacting with cloud provider APIs. For multi-cloud provisioning, the administrator would use modules like `amazon.aws.ec2_instance`, `azure.azcollection.azure_rm_virtualmachine`, and `google.cloud.gcp_compute_instance` to manage resources in AWS, Azure, and GCP respectively. Modules abstract the underlying API calls, allowing the playbook to execute tasks across providers.

Exam trap

CV0-004 often tests the confusion between Ansible roles and modules, where candidates might think roles handle API interactions, but roles are just a structural organization method.

How to eliminate wrong answers

Option B is wrong because roles are a way to organize playbooks and tasks into reusable components, not to interact with APIs directly. Option C is wrong because inventories define the hosts or nodes that playbooks target, not the API interactions. Option D is wrong because playbooks are the orchestration files that call modules; they do not themselves interact with cloud APIs.

478
MCQhard

A company operates a multi-tier web application on AWS. The web tier runs on EC2 instances behind an Application Load Balancer. The application tier runs on EC2 instances that connect to an RDS MySQL database. Recently, users have reported slow page load times. The cloud administrator investigates and finds the following: CPU utilization on web and app tier instances is below 50%, memory usage is normal, but the RDS instance's CPU utilization is consistently above 80% and the number of database connections is at the maximum. The administrator also notices that the application code opens a new database connection for each HTTP request and does not close them properly. Which action should the administrator take to resolve the performance issue?

A.Scale the RDS instance vertically to a larger instance class.
B.Implement a connection pooling mechanism in the application tier.
C.Increase the timeout for idle database connections.
D.Increase the maximum number of database connections on RDS.
AnswerB

The stem shows RDS CPU above 80% and connections at maximum, caused by the app opening a new connection per request without closing it. Connection pooling reuses a bounded set of persistent connections, cutting connection churn and RDS CPU load, directly relieving the saturated database tier.

Why this answer

The performance issue is caused by the application opening a new database connection for each HTTP request and not closing them properly, which exhausts the maximum connections on RDS. Implementing a connection pooling mechanism in the application tier reuses existing connections, reduces connection overhead, and prevents connection exhaustion without requiring a larger instance or increasing the connection limit. This directly addresses the root cause—inefficient connection management—rather than treating symptoms like high CPU or connection limits.

Exam trap

CompTIA often tests the misconception that scaling resources (vertical scaling or increasing limits) is the primary fix for performance issues, when the real problem is inefficient resource usage like connection leaks that require architectural changes such as connection pooling.

How to eliminate wrong answers

Option A is wrong because vertically scaling the RDS instance would increase CPU and memory capacity but does not fix the underlying connection leak; the application would still exhaust connections, leading to the same bottleneck. Option C is wrong because increasing the timeout for idle database connections would keep more connections open longer, exacerbating the connection exhaustion problem rather than resolving it. Option D is wrong because increasing the maximum number of database connections on RDS would allow more concurrent connections but does not address the application's failure to close connections, leading to eventual resource exhaustion and potential instability.

479
MCQeasy

A cloud administrator is deploying a microservices application on Kubernetes in a public cloud. The services must be able to discover each other dynamically and route traffic without hardcoded IP addresses. Which Kubernetes resource should the administrator use to provide a stable network endpoint for a set of pods?

A.ConfigMap
B.NetworkPolicy
C.Service
D.Ingress
AnswerC

A Kubernetes Service provides a stable virtual IP and DNS name that abstracts a set of pods. It enables dynamic discovery and load balancing across pods, even as they are created or destroyed. This matches the requirement for a stable network endpoint without hardcoded IPs.

Why this answer

A Kubernetes Service is the correct resource for providing a stable network endpoint and enabling dynamic service discovery. It abstracts pod IPs and offers load balancing, which is essential for microservices communication without hardcoded addresses.

Exam trap

The trap here is confusing Ingress with Service; Ingress is for external access and HTTP routing, not for internal service discovery.

480
MCQeasy

A cloud administrator needs to ensure that application logs are retained for three years to comply with regulatory requirements. Which of the following is the MOST cost-effective solution?

A.Configure log rotation so only the last 30 days of logs are kept in the instance
B.Store all logs in block storage for three years
C.Use a lifecycle policy to transition logs to archive storage after 90 days and delete after three years
D.Compress old logs manually and store them in a separate volume
AnswerC

A lifecycle policy transitioning logs to archive storage after 90 days and deleting at three years meets the retention requirement at the lowest cost, since archive tiers are cheaper than hot storage and deletion prevents indefinite charges.

Why this answer

The most cost-effective solution because it uses a lifecycle policy to automatically transition logs from hot storage to cheaper archive storage (e.g., Amazon S3 Glacier or Azure Blob Archive tier) after 90 days, then deletes them after three years. This minimizes storage costs by moving infrequently accessed data to lower-cost tiers while still meeting the three-year retention requirement without manual intervention or unnecessary use of expensive block storage.

Exam trap

The trap here is that candidates may choose block storage (Option B) because they assume all storage is equal, failing to recognize that block storage is optimized for low-latency I/O, not long-term archival, and incurs significantly higher costs than object storage with lifecycle management.

How to eliminate wrong answers

Option A is wrong because retaining only the last 30 days of logs fails to meet the three-year regulatory retention requirement, making it non-compliant. Option B is wrong because storing all logs in block storage (e.g., EBS volumes) for three years is prohibitively expensive due to high per-GB costs and lack of lifecycle tiering, and block storage is designed for high-performance workloads, not long-term archival. Option D is wrong because manually compressing logs and storing them in a separate volume still incurs block storage costs and requires ongoing manual effort, which is neither scalable nor cost-effective compared to automated lifecycle policies.

481
Multi-Selecteasy

A cloud administrator is investigating why a virtual machine is running slowly. The administrator checks the hypervisor performance metrics. Which TWO of the following metrics indicate CPU contention? (Choose TWO.)

Select 2 answers
A.High CPU ready time
B.High disk queue depth
C.High CPU co-stop time
D.High memory ballooning
E.High CPU usage percentage
AnswersA, C

High CPU ready time measures the percentage of time a virtual machine was ready to run but waited for a physical core. Sustained high values directly indicate CPU contention on the host, satisfying the stem's requirement for a metric evidencing contention.

Why this answer

CPU ready time (option A) and co-stop time (option C) are both indicators of CPU contention. Ready time is time a VM is ready to run but waiting for CPU; co-stop time is time a VM is stopped because another vCPU in the same VM is contending. Option E (High CPU usage percentage) is normal utilization, not contention.

Option B (High disk queue depth) is storage-related. Option D (High memory ballooning) is memory-related.

482
Multi-Selecthard

A company is designing a highly available architecture for a critical application. The solution must tolerate the failure of an entire availability zone. Which TWO design principles should be implemented? (Choose two.)

Select 2 answers
A.Deploy instances in a single availability zone
B.Use RAID 0 for all instance storage
C.Use a single load balancer without health checks
D.Use a load balancer with health checks and cross-zone load balancing
E.Deploy instances across multiple availability zones
AnswersD, E

Cross-zone load balancing distributes traffic evenly across healthy targets in every availability zone, and health checks withdraw targets in a failed zone automatically. This satisfies the stem's zone-failure tolerance constraint by removing the failed zone from rotation without manual intervention.

Why this answer

To tolerate an AZ failure, deploy across multiple AZs and use active-active or active-passive with failover. So deploying across multiple AZs and using a load balancer with health checks to route traffic away from failed AZ are correct.

483
Matchingmedium

Match each cloud deployment model to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Shared infrastructure over the internet

Dedicated to a single organization

Combination of public and private

Shared by several organizations with common concerns

Why these pairings

Deployment models define ownership and access scope. Public is third-party multi-tenant; private is single-tenant; hybrid combines models; community is shared by like-minded organizations. Common errors include swapping definitions between hybrid and community.

484
MCQhard

A cloud administrator notices that an auto-scaling group is frequently adding and removing instances due to brief spikes in CPU usage. What should be adjusted to stabilize the scaling activity?

A.Increase the cooldown period
B.Increase the maximum instance count
C.Decrease the minimum instance count
D.Decrease the cooldown period
AnswerA

The cooldown period enforces a waiting interval after each scaling activity before another can begin. Extending it prevents the auto-scaling group from reacting to brief CPU spikes, stabilising instance additions and removals as the stem requires.

Why this answer

Increasing the cooldown period prevents the auto-scaling group from launching or terminating additional instances immediately after a scaling activity, which smooths out reactions to brief CPU spikes. A longer cooldown gives metrics time to stabilize before another scaling decision is made, reducing thrashing. This directly addresses the frequent add/remove behavior described.

Exam trap

CV0-004 often tests whether candidates confuse cooldown with capacity limits — increasing max size or decreasing min size changes the bounds, but only the cooldown period controls how quickly the group reacts to metric fluctuations.

How to eliminate wrong answers

Option B is wrong because increasing the maximum instance count only raises the ceiling — it does not stop the group from rapidly scaling in and out in response to short spikes. Option C is wrong because decreasing the minimum instance count lowers the floor and can actually make the group less stable, not more. Option D is wrong because decreasing the cooldown period makes the group react faster and more aggressively, worsening the thrashing.

485
MCQmedium

A company uses a cloud load balancer to distribute traffic to a group of web servers. After a recent update, some users report being redirected to a maintenance page when the application is actually available. What is the most likely cause?

A.The load balancer health check is misconfigured and marking healthy instances as unhealthy.
B.The load balancer's SSL certificate has expired.
C.The DNS record for the load balancer has a short TTL.
D.The web servers are not configured with the same security group.
AnswerA

A misconfigured health check probes the wrong port, path, or protocol, so the load balancer marks functioning web servers as unhealthy and removes them from the pool. Users hitting those instances are redirected to the maintenance page despite the application running, directly satisfying the stem's symptom of false unavailability after an update.

Why this answer

The most likely cause is that the load balancer's health check is misconfigured, causing it to incorrectly mark healthy web servers as unhealthy. When all instances are marked unhealthy, the load balancer has no available targets and may route traffic to a fallback maintenance page or return an error. This explains why users see a maintenance page despite the application being available.

Exam trap

CompTIA often tests the distinction between health check misconfiguration and other common issues like SSL or DNS, so candidates may mistakenly choose an expired SSL certificate because they associate 'maintenance page' with security errors, but the correct cause is the load balancer's health check marking healthy instances as unhealthy.

How to eliminate wrong answers

Option B is wrong because an expired SSL certificate would cause TLS handshake errors (e.g., certificate warnings or connection failures), not a redirect to a maintenance page. Option C is wrong because a short TTL on the DNS record affects how quickly DNS changes propagate, but it does not cause the load balancer to redirect traffic to a maintenance page. Option D is wrong because mismatched security groups would block traffic at the network level, resulting in timeouts or connection refused errors, not a maintenance page redirect.

486
MCQmedium

A cloud engineer is setting up automated patching for Linux instances in AWS. They need to define a maintenance window during which patches are applied. Which service should they use?

A.AWS Config
B.AWS OpsWorks
C.AWS Systems Manager Patch Manager
D.Amazon Inspector
AnswerC

AWS Systems Manager Patch Manager defines patch baselines and maintenance windows, then applies patches to Linux instances via the SSM Agent during those windows. It satisfies the stem's requirement for scheduled automated patching, unlike services lacking native patch orchestration or Linux package support.

Why this answer

AWS Systems Manager Patch Manager is specifically designed to automate the process of patching managed nodes, including defining maintenance windows during which patches are applied. It allows you to create patch baselines, specify approved patches, and schedule patching within a maintenance window. This meets the requirement of automated patching with a defined maintenance window.

Exam trap

CV0-004 often tests the confusion between vulnerability scanning (Amazon Inspector) and patch management (Systems Manager Patch Manager), or between configuration management (OpsWorks) and patching.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for assessing, auditing, and evaluating configurations, not for applying patches. Option B is wrong because AWS OpsWorks is a configuration management service that uses Chef and Puppet, but it is not the primary service for automated patching; Patch Manager is more direct and integrated. Option D is wrong because Amazon Inspector is a vulnerability management service that scans for vulnerabilities but does not apply patches.

487
MCQeasy

A media company stores finished video masters in Amazon S3. Regulators require that each master be retained unaltered for exactly seven years, and that no user, including the root account, be able to delete or overwrite it during that period. Which S3 capability should the administrator implement?

A.S3 Lifecycle rules that transition objects to S3 Glacier Deep Archive after 30 days and expire them after 2555 days.
B.S3 Cross-Region Replication with S3 Inventory reports sent to a separate account for audit purposes.
C.S3 Object Lock in compliance mode with a retention period of 2555 days applied to the bucket.
D.S3 Versioning combined with a bucket policy that denies s3:DeleteObject to all principals.
AnswerC

S3 Object Lock in compliance mode enforces a write-once-read-many retention period that even the root user cannot shorten or bypass, and objects cannot be overwritten or deleted until the date passes. Setting a 2555-day retention on the bucket satisfies the exact seven-year, tamper-proof requirement for every stored video master.

Why this answer

Object Lock in compliance mode is the only S3 mechanism that enforces immutability against every principal, including the account root user, for a fixed retention period. Applying a 2555-day retention to the bucket covers all video masters automatically. Lifecycle rules, versioning with deny policies, and replication all offer durability or auditing benefits but remain reversible by privileged users, so none guarantees regulatory immutability.

Exam trap

The trap here is assuming that a deny-based bucket policy or versioning is tamper-proof, when both can be changed or bypassed by a privileged principal.

488
MCQhard

A cloud engineer is troubleshooting a Microsoft Azure virtual machine that becomes unresponsive under sustained load. The engineer suspects a storage performance bottleneck but needs to confirm whether the issue is IOPS throttling or throughput throttling on the managed disk. Which Azure Monitor metrics should the engineer examine to distinguish between these two causes?

A.Disk IOPS Consumed Percentage and Disk Bandwidth Consumed Percentage
B.Disk Latency and Disk Transactions per second from Azure Monitor
C.OS Disk Queue Depth and OS Disk Read Operations/sec from the guest OS
D.VM CPU Credits Remaining and VM Network In Total
AnswerA

These two platform metrics express consumed IOPS and consumed bandwidth as percentages of the disk's provisioned limits. If IOPS Consumed Percentage approaches 100 while bandwidth remains low, the disk is IOPS-throttled; if bandwidth percentage saturates first, it is throughput-throttled. This directly distinguishes the two causes described.

Why this answer

Azure Monitor exposes Disk IOPS Consumed Percentage and Disk Bandwidth Consumed Percentage as platform metrics for managed disks. Comparing which percentage approaches saturation reveals whether the workload is being limited by the provisioned IOPS ceiling or the throughput ceiling, which is the exact distinction the engineer needs.

Exam trap

The trap here is relying on guest OS queue depth to identify throttling, when only platform consumption percentages reveal which provisioned limit is actually being reached.

489
Multi-Selectmedium

A cloud administrator is planning a migration of on-premises workloads to a public cloud. Which THREE factors should the administrator consider to ensure minimal downtime? (Choose three.)

Select 3 answers
A.Application compatibility
B.Data compression
C.Network bandwidth
D.Transfer time window
E.Cost of data transfer
AnswersA, C, D

Application compatibility determines whether workloads can run unchanged in the public cloud or need refactoring, which directly affects migration sequencing and cutover duration. Incompatible applications force remediation or re-platforming work, extending the migration window and increasing downtime risk.

Why this answer

Application compatibility (A) is correct because the administrator must verify that each on-premises workload can run in the target public cloud environment (OS versions, hypervisor/instance types, dependencies, and licensing) so that cutover does not stall on unsupported software and cause extended downtime. Network bandwidth (C) is correct because the available throughput between the on-premises site and the cloud directly determines how quickly data can be replicated or transferred; insufficient bandwidth stretches the migration window and forces longer outages unless offline seeding or continuous replication is used. Transfer time window (D) is correct because the administrator must schedule the bulk data movement and final cutover within an acceptable maintenance period, accounting for replication lag and delta synchronization, to keep the actual service interruption as short as possible.

Data compression (B) and cost of data transfer (E) are not among the required factors: compression can reduce payload size and egress/ingress charges can affect budget, but neither is a primary determinant of achieving minimal downtime in the migration plan.

Exam trap

CompTIA Cloud+ often tests the distinction between factors that directly affect downtime duration (bandwidth, transfer window, compatibility) versus operational or cost-related factors (compression, cost) that do not inherently minimize downtime.

490
MCQmedium

A cloud architect is designing a multi-tier application. The application tier needs to access a database, but the database should not be reachable from the internet. Which network security control should be used?

A.Place the database in a private subnet and use a security group to allow traffic only from the application tier
B.Encrypt the database connection using TLS
C.Use a VPN to connect the application tier to the database
D.Place the database in a public subnet with restrictive security groups
AnswerA

A private subnet removes the database from internet routing, while a security group referencing the application tier as source enforces least-privilege access at the instance level. Together they satisfy the constraint that only the application tier may reach the database.

Why this answer

Placing the database in a private subnet with no direct internet route ensures it is not reachable from the internet. Security groups can then allow inbound traffic only from the application tier's security group.

491
Multi-Selecteasy

A company is adopting Infrastructure as Code (IaC) to manage its cloud resources. Which THREE statements are true about IaC? (Select THREE.)

Select 3 answers
A.IaC allows for automated provisioning of infrastructure
B.IaC eliminates the need for manual configuration changes
C.IaC is only applicable for immutable infrastructure
D.IaC configurations are typically stored in version control
E.IaC ensures that deployments are repeatable and consistent
AnswersA, D, E

IaC codifies infrastructure definitions, so provisioning happens through automated pipelines rather than manual console work. This directly satisfies the scenario's adoption goal: repeatable, version-controlled deployment of cloud resources. Templates or configuration files drive the automation, removing human error and enabling consistent environments across deployments.

Why this answer

Option A is correct because IaC tools such as Terraform, AWS CloudFormation, and Ansible automate the provisioning of infrastructure by declaring resources in code and applying them through APIs, removing manual click-through provisioning. Option D is correct because IaC configuration files (e.g., .tf, YAML templates, playbooks) are text-based and are normally committed to a version control system like Git, enabling change tracking, peer review, and rollback. Option E is correct because the same declarative or idempotent IaC code produces the same resulting infrastructure state on every run, giving repeatable and consistent deployments across environments.

Option B is not marked correct because IaC does not eliminate manual configuration changes entirely; out-of-band or drift changes can still occur and must be detected and reconciled. Option C is not marked correct because IaC supports both mutable and immutable infrastructure models, so it is not limited to immutable infrastructure.

Exam trap

CV0-004 often tests the misconception that IaC eliminates all manual changes or is only for immutable infrastructure — candidates may overstate its scope and pick incorrect statements.

492
MCQhard

During a security audit, an organization discovers their cloud-based database is accessible from any public IP address due to a firewall rule allowing 0.0.0.0/0 on port 3306 (MySQL). The database must remain accessible to remote developers working from home. What is the most effective remediation?

A.Remove the firewall rule entirely and rely on database IAM authentication.
B.Enable encryption in transit using TLS and keep the rule as is.
C.Change the firewall rule to allow only specific known developer IP ranges.
D.Move the database to a private subnet without a NAT gateway.
AnswerC

Restricting the rule to known developer IP ranges removes anonymous public exposure on port 3306 while preserving remote access. Unlike disabling the rule or VPN-only alternatives, it directly satisfies the constraint that developers working from home must retain connectivity.

Why this answer

Restricting to specific trusted IP ranges reduces exposure while maintaining remote access.

493
MCQmedium

An organization wants to deploy a new microservice to a Kubernetes cluster with zero downtime. The deployment should update pods gradually by replacing old pods with new ones, and if the new pods fail health checks, the rollout should stop. Which Kubernetes deployment strategy meets these requirements?

A.Canary
B.Recreate
C.Rolling update
D.Blue/green
AnswerC

A rolling update replaces pods incrementally, keeping the service available throughout. Its maxUnavailable and maxSurge settings control the gradual replacement, and the rollout halts automatically when new pods fail readiness probes, satisfying the zero-downtime and health-check constraints.

Why this answer

A rolling update strategy in Kubernetes replaces pods incrementally and can be configured to pause on failed health checks.

494
MCQeasy

Which cloud service model gives the customer the most control over the operating system and applications, while the provider manages the physical hardware, network, and storage?

A.FaaS
B.PaaS
C.SaaS
D.IaaS
AnswerD

IaaS leaves the customer managing the guest operating system, middleware and applications, while the provider handles physical hardware, networking and storage virtualisation. This split gives more control than PaaS or SaaS, which abstract the OS layer away.

Why this answer

IaaS (Infrastructure as a Service) provides virtualized compute, storage, and networking resources, but the customer is responsible for managing the guest operating system, middleware, runtime, and applications. The provider only manages the physical hardware, network fabric, and storage infrastructure. This gives the customer the highest level of control among the listed models without owning the physical data center.

Exam trap

CV0-004 often tests the misconception that PaaS gives more control than IaaS because it includes development tools, but the key differentiator is that IaaS leaves OS management to the customer, while PaaS abstracts it away.

How to eliminate wrong answers

Option A is wrong because FaaS (Function as a Service) abstracts away the operating system, runtime, and even the application server, leaving the customer responsible only for function code and configuration. Option B is wrong because PaaS (Platform as a Service) manages the OS, runtime, and middleware, so the customer only controls deployed applications and some configuration settings. Option C is wrong because SaaS (Software as a Service) delivers a fully managed application where the customer has no control over the underlying OS, runtime, or infrastructure.

495
MCQeasy

A company decides to use AWS for compute and Azure for storage to leverage best-of-breed services. This is an example of which cloud deployment model?

A.Multi-cloud
B.Community cloud
C.Public cloud
D.Hybrid cloud
AnswerA

Multi-cloud means deliberately using two or more distinct public cloud providers for different workloads. AWS for compute plus Azure for storage spans separate providers, satisfying the best-of-breed requirement rather than a hybrid or single-provider model.

Why this answer

Using AWS for compute and Azure for storage means the organization is consuming services from two different public cloud providers simultaneously, which is the definition of a multi-cloud deployment. Multi-cloud is about using multiple providers, regardless of whether workloads are integrated. Hybrid cloud, by contrast, combines public cloud with private infrastructure.

Exam trap

CV0-004 often tests the confusion between multi-cloud and hybrid cloud, so candidates must anchor on whether the mix involves two public providers (multi-cloud) or public plus private/on-premises (hybrid).

How to eliminate wrong answers

Option B is wrong because a community cloud is shared infrastructure among organizations with common concerns (e.g., government agencies), not multiple commercial providers. Option C is wrong because public cloud refers to a single provider's shared infrastructure; using two providers is not 'public cloud' as a model. Option D is wrong because hybrid cloud combines public cloud with private cloud or on-premises infrastructure, not two public providers.

496
MCQeasy

A cloud engineer needs to deploy a Lambda function that processes objects uploaded to an S3 bucket. The function code is stored in a .zip file. Which event trigger should the engineer configure to invoke the function automatically?

A.S3 event notification
B.API Gateway
C.SQS
D.EventBridge
AnswerA

S3 event notifications publish ObjectCreated events to Lambda, invoking the function whenever an object lands in the bucket. This satisfies the automatic invocation requirement for uploaded objects, avoiding polling and needing no manual trigger configuration.

Why this answer

S3 event notifications can be configured on a bucket to invoke a Lambda function when objects are created (e.g., s3:ObjectCreated:*), which directly satisfies the requirement to process uploaded objects automatically. This is the native, serverless integration between S3 and Lambda. API Gateway, SQS, and EventBridge are not triggered by S3 PUT events without additional configuration.

Exam trap

The trap is overcomplicating the trigger — candidates pick EventBridge or SQS thinking they are more 'event-driven,' but the simplest native S3-to-Lambda trigger is an S3 event notification.

How to eliminate wrong answers

Option B is wrong because API Gateway invokes Lambda in response to HTTP/REST requests, not S3 object uploads — it would require the uploader to call an API instead of using S3 directly. Option C is wrong because SQS is a queue that Lambda polls; S3 does not natively enqueue messages to SQS without an event notification or Lambda in between, so it does not directly trigger on upload. Option D is wrong because EventBridge can receive S3 events, but that requires S3 event notifications to be enabled first and an EventBridge rule to route them — it is an indirect path, not the direct trigger the question asks for.

497
MCQeasy

A company is experiencing latency issues when accessing a cloud-based application. The cloud administrator runs a traceroute and notices high latency at the ISP's edge router. Which of the following is the MOST likely cause?

A.An internet service provider (ISP) issue is degrading the WAN connection
B.A misconfigured firewall rule is dropping packets
C.The load balancer is sending traffic to unhealthy instances
D.The virtual machine hosting the application is under-provisioned
AnswerA

Traceroute showing high latency at the ISP's edge router localises the delay to the provider's network, outside the company's control. The WAN connection is degraded there, so the application itself and internal infrastructure are not the bottleneck.

Why this answer

High latency at the ISP's edge router indicates that the bottleneck is occurring on the WAN link between the company's network and the cloud provider, which is under the ISP's control. This is a classic symptom of an ISP issue, such as congestion, routing problems, or a degraded physical link, directly impacting the WAN connection. The traceroute output localizes the latency to the ISP's infrastructure, not to the company's internal network or the cloud application's resources.

Exam trap

CompTIA often tests the distinction between latency caused by network infrastructure (ISP) versus application or server performance issues, and the trap here is that candidates may attribute high latency to internal misconfigurations (like firewalls or load balancers) when the traceroute clearly isolates the problem to an external hop.

How to eliminate wrong answers

Option B is wrong because a misconfigured firewall rule dropping packets would cause packet loss or connectivity failures, not consistently high latency at a specific hop; dropped packets would result in retransmissions and timeouts, not a steady latency increase. Option C is wrong because a load balancer sending traffic to unhealthy instances would cause application errors or timeouts, but the latency would appear at the application layer or after the load balancer, not at the ISP's edge router. Option D is wrong because an under-provisioned virtual machine would cause high CPU or memory utilization leading to application slowness, but the latency would be observed at the VM or within the cloud provider's network, not at the ISP's edge router.

498
MCQmedium

A cloud administrator notices that an Auto Scaling group is launching and terminating instances too frequently, causing instability. What should the administrator adjust to reduce this flapping behavior?

A.Disable the cooldown period
B.Decrease the cooldown period
C.Increase the scale-out threshold
D.Increase the cooldown period
AnswerD

The cooldown period prevents the Auto Scaling group from launching or terminating additional instances immediately after a scaling activity, damping rapid oscillation. Increasing it forces the group to wait longer between actions, directly reducing the flapping instability described.

Why this answer

Increasing the cooldown period gives instances time to stabilize before additional scaling actions, reducing flapping.

499
MCQmedium

A cloud engineer is deploying a new version of a web application to a Kubernetes cluster. The application must remain available during the update, and the team wants to minimize the risk of exposing users to a faulty version. They decide to use a deployment strategy that gradually shifts traffic to the new version while monitoring for errors. Which Kubernetes resource should they configure to achieve this?

A.A Deployment with a RollingUpdate strategy and maxSurge/maxUnavailable parameters.
B.A StatefulSet with ordered pod management.
C.A Service of type LoadBalancer with session affinity enabled.
D.A DaemonSet that runs a pod on every node.
AnswerA

A Deployment with RollingUpdate strategy gradually replaces old pods with new ones while maintaining availability. By setting maxSurge and maxUnavailable, the engineer controls the pace of the rollout. This allows monitoring and, if needed, pausing or rolling back the deployment. It is the standard way to achieve zero-downtime updates in Kubernetes without additional tools.

Why this answer

A Deployment with a RollingUpdate strategy is the native Kubernetes mechanism for gradually updating application instances while preserving availability. By configuring maxSurge and maxUnavailable, the engineer can control how many extra pods are created and how many old pods are taken down at once. This enables monitoring and, if necessary, pausing or rolling back the update to avoid exposing users to a faulty version.

Exam trap

The trap here is confusing a Service's traffic distribution with a Deployment's rollout control; a Service balances traffic but does not manage version updates.

500
Multi-Selecthard

Which THREE of the following are valid methods to manage identity and access in a multi-cloud environment?

Select 3 answers
A.Set up a site-to-site VPN between the on-premises network and each cloud.
B.Implement a federation using SAML 2.0 between the corporate identity provider and each cloud.
C.Assign resource tags and use them in attribute-based access control (ABAC) policies.
D.Use a single shared API key for all clouds to simplify automation.
E.Deploy a cloud access security broker (CASB) to enforce access policies across clouds.
AnswersB, C, E

Federation allows SSO and centralized identity management.

Why this answer

Option B is correct because SAML 2.0 federation lets the corporate identity provider act as the authoritative IdP, issuing signed assertions that each cloud provider's STS trusts, enabling single sign-on and centralized identity lifecycle management across clouds. Option C is correct because tagging resources and referencing those tags in ABAC policies allows a single, consistent authorization model (for example, 'allow if resource tag owner == user.department') to be evaluated across heterogeneous cloud IAM engines. Option E is correct because a CASB sits between users and multiple cloud services to enforce authentication, authorization, DLP, and shadow-IT policies uniformly, which is a recognized way to govern access in multi-cloud environments.

Option A is not an identity or access management method; a site-to-site VPN only provides encrypted network connectivity between on-premises and cloud networks. Option D is not valid because a single shared API key is a static, non-attributable credential that cannot be scoped per user or cloud, breaks least privilege and auditability, and is an anti-pattern for identity management.

Exam trap

The trap is that candidates may think network connectivity (VPN) or simple API keys are sufficient for IAM, but the question asks for identity and access management methods, which require authentication, authorization, and policy enforcement.

501
Multi-Selecthard

Which THREE of the following are valid considerations when selecting a cloud deployment model (public, private, hybrid)? (Choose three.)

Select 3 answers
A.Regulatory compliance requirements.
B.Budget and total cost of ownership.
C.Developers' preferred programming languages.
D.Latency sensitivity of the application.
E.Cloud provider's marketing claims.
AnswersA, B, D

Regulatory compliance dictates where data may reside and which controls apply, directly determining whether public, private or hybrid tenancy is permissible. This satisfies the selection criteria by ruling out deployment models that cannot meet mandated data-sovereignty or certification obligations.

Why this answer

Option A (Regulatory compliance requirements) is correct because data-residency, sovereignty, and industry regulations (e.g., HIPAA, GDPR, PCI DSS) often dictate whether workloads can run in a public cloud, must stay in a private cloud, or require a hybrid model to keep sensitive data on-premises. Option B (Budget and total cost of ownership) is correct because deployment models differ significantly in CapEx versus OpEx: public cloud shifts spend to operational pay-as-you-go costs, private cloud requires capital investment in hardware and staffing, and hybrid blends both, so TCO analysis directly drives model selection. Option D (Latency sensitivity of the application) is correct because real-time or low-latency workloads may need private or hybrid placement near users or data sources, since public cloud network round-trip times can violate strict latency SLAs.

Option C is not a valid consideration because programming language preference is an application development concern independent of where the infrastructure is deployed. Option E is not a valid consideration because marketing claims are not a technical or business criterion for evaluating deployment models.

Exam trap

CompTIA often tests that candidates confuse operational preferences (like programming languages) with architectural constraints, leading them to select C as a valid consideration when it is irrelevant to the deployment model decision.

502
Multi-Selectmedium

A cloud administrator is troubleshooting a web application that is hosted on a VM in a public cloud. Users report that the application is intermittently unavailable. The administrator checks the cloud provider's status page and sees no ongoing incidents. Which two actions should the administrator take to diagnose the issue? (Choose two.)

Select 2 answers
A.Reboot the VM to clear any transient issues.
B.Enable detailed monitoring on the VM and wait for the next occurrence.
C.Increase the VM's CPU and memory resources to handle potential spikes.
D.Review the VM's system logs for errors or warnings around the times of unavailability.
E.Check the cloud provider's network ACLs and security group rules for the VM.
AnswersD, E

System logs on the VM can reveal application crashes, kernel panics, or resource exhaustion events that correlate with the unavailability. Checking logs around the reported times is a fundamental troubleshooting step to identify patterns or specific errors. This action is non-intrusive and can quickly point to the root cause, such as a service restarting or running out of memory.

Why this answer

To diagnose intermittent unavailability without a provider incident, the administrator should examine the VM's system logs for errors and verify network ACLs and security group rules. These actions directly investigate the VM's health and network configuration, which are common causes of intermittent accessibility. They are immediate, non-destructive steps that can reveal misconfigurations or application faults.

Exam trap

The trap here is jumping to resource scaling or rebooting before gathering diagnostic data, which can mask the root cause and lead to unnecessary changes.

503
MCQhard

A company uses GCP and wants to ensure that log entries from Compute Engine instances are automatically exported to BigQuery for analysis. The logs must include structured JSON data. Which GCP service should be configured to route logs?

A.Cloud Audit Logs
B.Cloud Functions
C.Cloud Monitoring
D.Cloud Logging using sinks
AnswerD

Sinks define inclusion filters and a destination, letting Cloud Logging route matching entries to a BigQuery dataset. This satisfies the requirement to automatically export Compute Engine logs while preserving their structured JSON payloads for analysis.

Why this answer

Cloud Logging can route logs to BigQuery using sinks. It accepts structured logs in JSON format.

504
MCQeasy

A cloud administrator needs to apply a critical security patch to a virtual machine that is part of a production application. The application must remain available during patching. Which of the following is the BEST approach?

A.Postpone the patch until the next scheduled update cycle
B.Remove the VM from the load balancer, apply the patch, then return it to service during a maintenance window
C.Patch all VMs simultaneously to minimize the time to full deployment
D.Apply the patch during peak usage hours to ensure immediate deployment
AnswerB

Draining the VM from the load balancer first stops new sessions reaching it while peers absorb traffic, so the application stays available. Patching the isolated instance then returning it to service avoids the downtime inherent in in-place patching of a live production node.

Why this answer

Removing the VM from the load balancer ensures that no new traffic is sent to it while the patch is applied, maintaining application availability for users. After the patch is applied and the VM is verified as healthy, it can be returned to the load balancer pool. This approach aligns with a rolling update strategy, which is the standard method for applying patches to production VMs without downtime.

Exam trap

The trap here is that candidates may think patching all VMs simultaneously is faster and therefore better, but they overlook the critical requirement of maintaining application availability, which is explicitly stated in the question.

How to eliminate wrong answers

Option A is wrong because postponing a critical security patch leaves the application vulnerable to exploitation, which violates security best practices and compliance requirements. Option C is wrong because patching all VMs simultaneously would cause a complete application outage, as no VM would be available to serve traffic during the patching process. Option D is wrong because applying the patch during peak usage hours increases the risk of performance degradation or service disruption, and contradicts the standard practice of scheduling maintenance during low-traffic periods.

505
MCQmedium

A cloud engineer is writing a Bicep file to deploy Azure resources. Bicep is a domain-specific language (DSL) that transpiles to ARM templates. Which of the following is a benefit of using Bicep over ARM JSON templates?

A.Bicep automatically manages state
B.Bicep reduces code verbosity and supports modules
C.Bicep is natively executed by Azure Resource Manager
D.Bicep supports imperative scripting
AnswerB

Bicep's declarative syntax removes much of ARM JSON's boilerplate, such as repeated parameters and nested resource declarations, and supports modules for reusable, composable deployments. This directly satisfies the stem's requirement for a benefit over ARM JSON templates.

Why this answer

Bicep provides a simpler syntax with less boilerplate, modularity, and reusable modules. It reduces complexity compared to raw ARM JSON.

506
MCQmedium

A cloud operations team runs a Kubernetes cluster on Google Kubernetes Engine (GKE). They need to ensure that a critical payment microservice is automatically restarted if its container process fails, and that a new Pod is created if the node hosting it becomes unhealthy. Which Kubernetes object should they configure to meet these requirements?

A.A standalone Pod
B.A DaemonSet
C.A Deployment with a ReplicaSet
D.A CronJob
AnswerC

A Deployment manages a ReplicaSet, which ensures the desired number of Pod replicas are running. If a container process fails, the kubelet restarts it according to the Pod's restartPolicy (default Always). If a node becomes unhealthy, the ReplicaSet controller creates replacement Pods on healthy nodes. This directly satisfies both automatic container restart and Pod rescheduling requirements for the payment microservice.

Why this answer

A Deployment with a ReplicaSet is the correct Kubernetes controller for stateless, long-running microservices. The ReplicaSet ensures the desired number of Pod replicas are running, and the kubelet restarts failed containers. If a node becomes unhealthy, the ReplicaSet controller creates replacement Pods on healthy nodes.

This provides both container-level and node-level self-healing, which the payment microservice requires.

Exam trap

The trap here is assuming that a standalone Pod or DaemonSet provides the same self-healing and rescheduling guarantees as a Deployment-managed ReplicaSet.

507
MCQmedium

A company is deploying a containerized application on Amazon ECS. The operations team needs to ensure that the application can scale automatically based on CPU utilization and that the underlying container instances are managed without manual intervention. They also want to minimize the operational overhead of managing the container host infrastructure. Which ECS launch type should they use?

A.EKS launch type
B.AWS Batch launch type
C.Fargate launch type
D.EC2 launch type
AnswerC

AWS Fargate is a serverless compute engine for containers that eliminates the need to manage EC2 instances. It automatically scales based on CPU utilization when used with ECS service auto scaling. The team only defines task definitions and services, and Fargate handles the infrastructure. This directly reduces operational overhead and meets the requirement for automatic scaling without manual host management.

Why this answer

The Fargate launch type for Amazon ECS removes the need to manage EC2 instances, allowing the team to focus on the application. It supports service auto scaling based on CPU utilization and other metrics. By using Fargate, the operations team minimizes infrastructure management and achieves automatic scaling, which aligns with the stated requirements for reduced operational overhead.

Exam trap

The trap here is confusing ECS launch types with other AWS container services like EKS or Batch, which serve different purposes.

508
Multi-Selectmedium

A cloud architect is reviewing costs for a production environment. The environment uses a mix of EC2 instances and RDS databases. Which THREE of the following are effective cost optimization strategies?

Select 3 answers
A.Use reserved instances for baseline capacity
B.Implement storage lifecycle policies to move old data to cheaper storage tiers
C.Use all SSD storage for all data to maximize performance
D.Rightsize instances based on actual utilization metrics
E.Run all instances 24/7 to ensure availability
AnswersA, B, D

Reserved instances apply a one- or three-year commitment to steady-state capacity, cutting hourly rates substantially versus on-demand. This satisfies the cost optimisation requirement by discounting the predictable baseline load while on-demand or spot covers peaks.

Why this answer

Reserved instances provide discounts for steady-state usage. Storage lifecycle policies move data to cheaper tiers over time. Rightsizing ensures resources match workload requirements, reducing waste.

Using all SSD even for cold data is expensive. Running instances 24/7 when not needed increases costs unnecessarily.

509
MCQhard

A cloud engineer is troubleshooting a performance issue in a multi-tier application on AWS. The web tier shows high latency, but the application logs indicate no errors. The engineer wants to trace a request end-to-end across services. Which AWS service should be used?

A.VPC Flow Logs
B.Amazon CloudWatch Logs
C.AWS CloudTrail
D.AWS X-Ray
AnswerD

AWS X-Ray traces requests across distributed services, building a service map that pinpoints latency between tiers. Since logs show no errors, the bottleneck is performance rather than failure, and X-Ray's segment and subsegment timing exposes exactly where the web tier's downstream calls stall.

Why this answer

AWS X-Ray provides distributed tracing, allowing you to trace requests as they travel through your application and identify performance bottlenecks.

510
MCQeasy

A virtual machine in a cloud environment is experiencing high disk I/O latency. The administrator checks the performance metrics and sees that the disk queue length is consistently above 100. What is the best immediate action?

A.Attach an additional disk and stripe the data
B.Upgrade the VM's network bandwidth
C.Migrate the VM to a host with faster disks
D.Increase the VM's memory
AnswerA

Stripping adds parallelism, reducing queue depth and improving latency.

Why this answer

Attach an additional disk and stripe the data. A high disk queue length indicates that the disk is overwhelmed with I/O requests. Stripping data across multiple disks (e.g., RAID 0) distributes the I/O load, reducing queue length and latency.

Option B is wrong because network bandwidth does not affect disk I/O. Option C is wrong because migrating to a host with faster disks may help but is not the immediate action; adding disks is quicker and more direct. Option D is wrong because increasing memory does not directly improve disk I/O performance.

511
MCQmedium

A cloud administrator notices that an application's latency has increased. The application is distributed across multiple microservices. Which tool can help trace requests across services to identify the bottleneck?

A.Centralized logging service
B.Vulnerability assessment tool
C.Distributed tracing tool
D.Audit logging service
AnswerC

Distributed tracing propagates a shared trace context across service boundaries, letting the administrator visualise each span's duration and pinpoint the microservice causing increased latency. Unlike metrics or logs, which show isolated per-service data, it reconstructs the full request path, directly satisfying the requirement to trace requests across distributed microservices.

Why this answer

A distributed tracing tool is designed to follow a single request as it propagates through multiple microservices, capturing spans, timing, and parent-child relationships. This lets the administrator pinpoint which service or call in the chain is adding latency. Centralized logging aggregates logs but does not natively reconstruct cross-service request paths with timing.

Exam trap

CV0-004 often tests the confusion between logging and tracing, so candidates pick centralized logging when the scenario explicitly requires following a request across services.

How to eliminate wrong answers

Option A is wrong because centralized logging collects and indexes log events but does not correlate a single request's journey across services with timing breakdowns. Option B is wrong because a vulnerability assessment tool scans for security weaknesses, not performance bottlenecks. Option D is wrong because audit logging records security-relevant events for compliance, not request latency across microservices.

512
MCQhard

A cloud engineer is troubleshooting an issue where a virtual machine (VM) in a VPC cannot communicate with an on-premises database server through a site-to-site VPN. The VPN tunnel status shows 'UP' and the on-premises firewall logs show packets from the VM's public IP (but the VM is in a private subnet with no public IP). What is the MOST likely cause?

A.The on-premises firewall is blocking the VM's private IP address.
B.The VM's security group is blocking outbound traffic to the on-premises subnet.
C.The route table for the subnet is missing a route to the on-premises network via the VPN.
D.The VPN tunnel is misconfigured with mismatched pre-shared keys.
AnswerC

The subnet's route table lacks a path to the on-premises CIDR via the VPN gateway, so traffic from the private-subnet VM is dropped before reaching the tunnel, despite the tunnel showing UP and the on-premises firewall logging packets.

Why this answer

The VPN tunnel status is 'UP' and the on-premises firewall sees packets from the VM's public IP, but the VM is in a private subnet with no public IP. This indicates that the VM's traffic is being sent to the internet instead of through the VPN tunnel. The most likely cause is that the subnet's route table lacks a specific route directing traffic destined for the on-premises network to the virtual private gateway (VGW) or VPN connection, causing the traffic to be routed to the internet gateway (IGW) and source-NATed to the public IP.

Exam trap

The trap here is that candidates see 'VPN tunnel UP' and assume the VPN is fully functional, overlooking that routing (the route table) is a separate layer that must direct traffic into the tunnel; the tunnel being up does not guarantee traffic is being sent through it.

How to eliminate wrong answers

Option A is wrong because the on-premises firewall logs show packets from the VM's public IP, not its private IP, so the firewall is not blocking the private IP; the issue is that the private IP is not being used for the VPN traffic. Option B is wrong because security groups are stateful and, by default, allow all outbound traffic; even if outbound rules were restrictive, the traffic would still be dropped at the VM level, not appear at the on-premises firewall with a public IP. Option D is wrong because mismatched pre-shared keys would prevent the VPN tunnel from establishing, but the tunnel status is 'UP', indicating the Phase 1 and Phase 2 negotiations succeeded.

513
Multi-Selecteasy

A cloud architect is designing a multi-tier application that must remain available during a single Availability Zone failure. Which TWO design principles should the architect apply?

Select 2 answers
A.Implement synchronous replication between the primary site and a DR site.
B.Deploy resources across multiple Availability Zones.
C.Use a single load balancer to distribute traffic across instances.
D.Place all application servers in the same subnet for low latency.
E.Use an auto-scaling group with a minimum of two instances spread across zones.
AnswersB, E

Spreading resources across multiple Availability Zones means a single zone outage leaves instances in surviving zones serving traffic, satisfying the availability requirement. Combined with load balancing and health checks, this removes the single point of failure.

Why this answer

Option B is correct because deploying resources across multiple Availability Zones ensures that if one AZ fails, the application continues running from the remaining AZs, which is the fundamental high-availability design principle for surviving a single-AZ failure. Option E is correct because an Auto Scaling group with a minimum of two instances spread across zones maintains capacity and automatically replaces failed instances, providing both redundancy and resilience against an AZ outage. Option A is not appropriate here because synchronous replication to a DR site addresses regional disaster recovery, not single-AZ fault tolerance, and synchronous replication across regions introduces latency.

Option C is insufficient because a single load balancer is itself a single point of failure unless it is also made multi-AZ, and it does not by itself distribute resources across zones. Option D is wrong because placing all servers in one subnet confines them to a single AZ, which directly violates the requirement to survive an AZ failure.

Exam trap

CompTIA often tests the distinction between high availability (within a region across AZs) and disaster recovery (across regions), leading candidates to mistakenly choose synchronous replication (Option A) for AZ failure scenarios when it is actually designed for regional outages.

514
MCQmedium

A company uses Azure and wants to set up an alert that triggers when the average CPU of a virtual machine exceeds 90% for the past 15 minutes. The alert should send an email to the operations team. Which Azure resources are needed?

A.Azure Log Analytics and Logic App
B.Azure Monitor metric alert and action group with email
C.Azure Advisor recommendation
D.Azure Service Health alert
AnswerB

Azure Monitor metric alerts evaluate platform metrics such as Percentage CPU against a threshold over a defined aggregation window, satisfying the 15-minute average above 90% condition. The action group then delivers the email notification to the operations team, fulfilling the alerting requirement without needing Log Analytics queries.

Why this answer

Azure Monitor metric alerts evaluate metrics like CPU percentage against thresholds, and action groups define the notification channels (e.g., email). To alert when average CPU exceeds 90% for 15 minutes, you create a metric alert rule with a 15-minute aggregation window and attach an action group configured to send email to the operations team. This is the native, minimal-resource approach.

Exam trap

The trap is overcomplicating the solution by choosing Log Analytics or Logic Apps, when a simple metric alert with an action group is sufficient and is the intended answer.

How to eliminate wrong answers

Option A is wrong because Log Analytics and Logic Apps are not required for simple metric alerts; they add unnecessary complexity and cost. Option C is wrong because Azure Advisor provides recommendations, not real-time alerting on metrics. Option D is wrong because Azure Service Health alerts are for platform-wide service issues, not VM-level performance metrics.

515
MCQmedium

A company wants to reduce costs by identifying underutilized EC2 instances. Which tool should they use to get rightsizing recommendations?

A.AWS Cost Explorer
B.AWS Trusted Advisor
C.AWS Compute Optimizer
D.AWS Budgets
AnswerC

AWS Compute Optimizer analyses CloudWatch metrics to generate rightsizing recommendations for EC2 instances, identifying over-provisioned or underutilised capacity. This directly satisfies the company's cost-reduction goal by surfacing specific instance-type downsizing opportunities, unlike tools that only report utilisation data without actionable sizing guidance.

Why this answer

AWS Compute Optimizer is specifically designed to analyze resource utilization and provide rightsizing recommendations for EC2 instances, among other resources. It uses machine learning to identify underutilized instances and suggests optimal instance types, helping reduce costs.

Exam trap

CV0-004 often tests the confusion between cost management tools like Cost Explorer and rightsizing tools like Compute Optimizer; candidates may think Cost Explorer provides rightsizing, but it only shows costs.

How to eliminate wrong answers

Option A is wrong because AWS Cost Explorer is for visualizing and managing costs, but it does not provide rightsizing recommendations. Option B is wrong because AWS Trusted Advisor offers best practice checks, including cost optimization, but its rightsizing recommendations are limited and not as comprehensive as Compute Optimizer. Option D is wrong because AWS Budgets is for setting custom cost and usage budgets and alerts, not for rightsizing.

516
MCQeasy

A company is deploying a new application on AWS and wants to automate the creation of infrastructure using infrastructure as code. The team needs to define resources such as Amazon VPC, subnets, and security groups in a template that can be version-controlled and reused across multiple environments. Which AWS service should they use?

A.AWS CodeDeploy
B.AWS CloudFormation
C.AWS OpsWorks
D.AWS Elastic Beanstalk
AnswerB

AWS CloudFormation allows you to define infrastructure as code using JSON or YAML templates. It supports version control, parameterization, and reuse across environments. It can create and manage a wide range of AWS resources, including VPCs, subnets, and security groups, making it ideal for this scenario.

Why this answer

AWS CloudFormation is the correct choice because it enables infrastructure as code, allowing the team to define and version AWS resources such as VPCs, subnets, and security groups in templates. It supports reuse across environments through parameters and mappings. Elastic Beanstalk, OpsWorks, and CodeDeploy serve different purposes and do not provide the same level of infrastructure definition and version control.

Exam trap

The trap here is confusing infrastructure as code with application deployment services; Elastic Beanstalk and CodeDeploy automate deployments but do not define infrastructure resources like VPCs and subnets.

517
MCQhard

A company is migrating a 50 TB on-premises database to AWS RDS MySQL. The migration must have minimal downtime and support ongoing replication during the cutover. The database schema is standard MySQL. Which combination of services should the company use?

A.AWS DMS with schema conversion tool to convert to MySQL
B.AWS Database Migration Service (DMS) with Change Data Capture (CDC) replication
C.AWS Snowball Edge to transfer database dump, then import to RDS
D.AWS DataSync to transfer database files to S3, then restore to RDS
AnswerB

DMS performs the initial full load while Change Data Capture continuously replicates ongoing inserts, updates and deletes from the source MySQL binlog, keeping the target in sync until cutover. This satisfies the minimal-downtime and ongoing-replication constraints for the 50 TB migration.

Why this answer

AWS DMS with Change Data Capture (CDC) performs the initial full load and then continuously replicates ongoing changes from the source MySQL to RDS MySQL, enabling minimal-downtime cutover. Because the schema is standard MySQL, no schema conversion is needed, and CDC keeps the target in sync until the application is switched over.

Exam trap

CV0-004 often tests the distinction between schema conversion (SCT, needed only for heterogeneous migrations) and data replication (DMS/CDC) — candidates pick SCT even when the schema is already the target engine.

How to eliminate wrong answers

Option A is wrong because the AWS Schema Conversion Tool (SCT) is used when converting from a different database engine (e.g., Oracle to MySQL); since the schema is already standard MySQL, SCT is unnecessary and adds complexity. Option C is wrong because Snowball Edge is an offline bulk-transfer appliance — it cannot support ongoing replication or minimal downtime during cutover. Option D is wrong because DataSync transfers files to S3, not database-native replication to RDS; restoring database files from S3 to RDS MySQL is not a supported or practical migration path for a live 50 TB database.

518
MCQmedium

A cloud administrator needs to apply security patches to a group of Windows servers during a maintenance window to minimize disruption. Which type of service should be used?

A.Vulnerability assessment service
B.Configuration compliance service
C.Configuration management and automation service
D.Patch automation service with maintenance window scheduling
AnswerD

A patch automation service inventories missing OS patches and applies them to tagged Windows servers only within the defined maintenance window, preventing disruption outside approved hours. This satisfies the requirement to patch a server group while minimising disruption, unlike manual patching or always-on update schedules.

Why this answer

The administrator needs to apply security patches to a group of Windows servers during a specific maintenance window to minimize disruption. A patch automation service with maintenance window scheduling is designed exactly for this purpose: it automates the deployment of patches and allows scheduling within defined windows, ensuring updates occur only during approved times. This directly addresses the requirement to apply patches while controlling when they happen to avoid service interruptions.

Exam trap

CV0-004 often tests the distinction between tools that identify issues (vulnerability assessment, configuration compliance) and those that remediate them (patch automation), so candidates may incorrectly choose a monitoring or assessment service when the requirement is to apply patches.

How to eliminate wrong answers

Option A is wrong because a vulnerability assessment service identifies and reports vulnerabilities but does not apply patches. Option B is wrong because a configuration compliance service monitors and enforces configuration settings against baselines, but it does not deploy patches. Option C is wrong because a configuration management and automation service can automate tasks but lacks the specific patch management and maintenance window scheduling features needed for controlled patch deployment.

519
MCQmedium

A containerized application deployment fails with an 'ImagePullBackOff' error. What should the administrator verify?

A.The CPU utilization on the node
B.The cluster's DNS configuration
C.The firewall rules between nodes and registry
D.The container registry credentials and image tag
AnswerD

ImagePullBackOff means the kubelet cannot fetch the image, so the registry credentials and image tag must be checked. Invalid authentication secrets or a non-existent tag both cause pull failures, making these the direct causes of the error.

Why this answer

ImagePullBackOff means the container runtime cannot pull the image, which is almost always caused by invalid registry credentials, a wrong image tag, or an image that does not exist. Verifying the registry credentials and the exact image tag/name is the correct first troubleshooting step.

Exam trap

CV0-004 often tests the misconception that ImagePullBackOff is a networking or resource issue, when the error specifically indicates an image retrieval failure most often due to credentials or tag errors.

How to eliminate wrong answers

Option A is wrong because high CPU on the node would cause scheduling or performance issues, not an image pull failure. Option B is wrong because DNS misconfiguration would typically manifest as name resolution errors for the registry, but the specific ImagePullBackOff error points to authentication or image reference problems first. Option C is wrong because firewall rules are a possible cause but are secondary to verifying credentials and tag, which are the most common root causes and the direct meaning of the error.

520
MCQeasy

A cloud administrator is troubleshooting a web application that is hosted on multiple virtual machines behind a load balancer. Users report that the application is occasionally slow, but the load balancer health checks show all instances as healthy. The administrator suspects that one of the virtual machines is performing poorly. Which of the following should the administrator do to confirm this suspicion?

A.Restart each virtual machine one at a time to see if performance improves.
B.Review the load balancer's access logs for response times per backend instance.
C.Check the CPU utilization of each virtual machine using the cloud provider's console.
D.Enable detailed monitoring on all virtual machines and wait for new metrics.
AnswerB

Load balancer access logs typically include the backend instance that handled each request and the response time. By analyzing these logs, the administrator can identify if a particular instance has higher response times than others. This is a direct way to confirm which virtual machine is performing poorly without disrupting the service. Other methods may require more invasive actions or may not provide per-instance data.

Why this answer

Load balancer access logs are a valuable source of per-instance performance data. They record which backend handled each request and how long it took to respond. By examining these logs, the administrator can quickly identify if one instance is consistently slower.

This method is non-intrusive and uses existing data, making it the most efficient first step.

Exam trap

The trap here is assuming that CPU utilization is the definitive indicator of performance, when response time from logs is more directly tied to user experience.

521
Multi-Selecthard

A cloud administrator is investigating a performance issue with a cloud-based application. The application's response time has increased significantly. Monitoring shows low CPU and memory, but high network latency. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Review the security group rules for any restrictive outbound rules.
B.Check the load balancer's connection draining settings.
C.Use a trace tool to identify network hops and bottlenecks.
D.Verify that the instances are in the same placement group.
E.Check for packet drops in the VPC flow logs.
AnswersC, E

Traceroute helps pinpoint where network delays occur.

Why this answer

Using a trace tool (such as traceroute or MTR) allows the administrator to identify each network hop between the application and its users, revealing where latency is introduced. This directly addresses the symptom of high network latency by pinpointing congested or failing routers, misconfigured firewalls, or suboptimal routing paths.

Exam trap

The trap here is that candidates may confuse high latency with connectivity failures and incorrectly choose security group or load balancer settings, when in fact the correct approach is to use network diagnostic tools (trace tool and flow logs) to isolate the source of the delay.

522
MCQmedium

An organization wants to ensure that only authenticated users from their corporate Active Directory can access cloud resources. Which federation protocol is most commonly used for this purpose?

A.LDAP
B.OAuth 2.0
C.RADIUS
D.SAML
AnswerD

SAML exchanges signed assertions between the corporate identity provider and the cloud service, so Active Directory credentials authenticate users without replicating accounts. This satisfies the requirement that only authenticated corporate AD users reach cloud resources, unlike OAuth, which handles authorisation delegation rather than federated authentication.

Why this answer

SAML (Security Assertion Markup Language) is the standard federation protocol used to enable single sign-on (SSO) between an identity provider (like Active Directory Federation Services) and a service provider (cloud resources). It exchanges authentication and authorization data in XML assertions, allowing users authenticated against corporate AD to access cloud applications without separate credentials. SAML is specifically designed for web-based federated identity scenarios, making it the most common choice for enterprise cloud SSO.

Exam trap

CV0-004 often tests the confusion between authentication and authorization protocols — candidates may pick OAuth 2.0 thinking it handles login, but OAuth is for delegated authorization, while SAML is the federation standard for SSO.

How to eliminate wrong answers

Option A is wrong because LDAP is a directory access protocol used for querying and modifying directory services, not a federation protocol for cross-domain authentication; it does not support web SSO assertions. Option B is wrong because OAuth 2.0 is an authorization framework for delegated access (e.g., allowing an app to access resources on a user's behalf), not an authentication or federation protocol for verifying user identity across domains. Option C is wrong because RADIUS is a network access authentication protocol used for VPNs, Wi-Fi, and dial-up, not for federating identities to cloud applications.

523
Multi-Selectmedium

A company is planning to migrate a 200 TB on-premises file server to AWS S3. The network link is 1 Gbps and cannot be saturated due to other traffic. The migration must be completed within two weeks. Which TWO services or features should the cloud engineer consider to accelerate the transfer? (Choose two.)

Select 2 answers
A.AWS Direct Connect
B.AWS DMS
C.AWS DataSync
D.AWS Snowball
E.AWS Storage Gateway
AnswersC, D

DataSync can accelerate transfers over the network and is designed for large datasets.

Why this answer

AWS DataSync is correct because it is designed to efficiently migrate large datasets to AWS by using parallel multi-threaded transfers and incremental syncs, which can optimize the use of the available 1 Gbps link without saturating it. It can handle the 200 TB file server migration by automating the transfer and reducing the time required compared to manual copying, though the 1 Gbps link alone may still be insufficient for the two-week window, making it a partial solution.

Exam trap

The trap here is that candidates often assume AWS DataSync alone can handle any large transfer over a network link, but they overlook the bandwidth calculation—200 TB at 1 Gbps takes over 18 days, so a physical transport like Snowball is necessary to meet the two-week deadline.

524
MCQmedium

A cloud architect is choosing a compute pricing model for a batch processing job that runs for 2 hours every night. The job can be interrupted. Which option is most cost-effective?

A.Reserved instances for 1 year
B.Spot instances
C.On-demand instances
D.Dedicated hosts
AnswerB

Spot instances price capacity at steep discounts because workloads are evictable, matching the job's interruptibility. Reserved or on-demand pricing would charge for guaranteed availability the batch job does not require, so spot satisfies the nightly two-hour, interruption-tolerant constraint most cheaply.

Why this answer

Spot instances are the most cost-effective option because the batch processing job is fault-tolerant (can be interrupted) and runs for a fixed, short duration (2 hours nightly). Spot instances offer significant discounts (often 60-90% off on-demand pricing) by leveraging unused cloud capacity, which can be reclaimed with a 2-minute warning. This aligns perfectly with the workload's tolerance for interruption and its predictable but non-critical schedule.

Exam trap

The CV0-004 exam often tests the misconception that Reserved instances are always cheaper for any recurring workload, but the trap here is that the short, interruptible nature of the job makes spot instances far more cost-effective than committing to a long-term reservation.

How to eliminate wrong answers

Option A is wrong because Reserved instances require a 1-year or 3-year commitment and are designed for steady-state, always-on workloads; paying upfront for a full year to cover only 2 hours per night is wasteful and not cost-effective. Option C is wrong because On-demand instances charge per hour with no discount, making them more expensive than spot instances for a batch job that can tolerate interruptions. Option D is wrong because Dedicated hosts are physical servers dedicated to a single customer, incurring high costs for full server capacity regardless of usage; they are intended for compliance or licensing needs, not for cost optimization on an interruptible batch job.

525
MCQhard

A cloud administrator is managing a hybrid cloud environment where on-premises servers connect to a public cloud VPC via a site-to-site VPN. Users report intermittent connectivity issues to cloud resources. The administrator examines the VPN tunnel logs and sees 'Phase 2 negotiation failed' errors. Which of the following is the MOST likely cause?

A.Dead Peer Detection (DPD) is disabled on one side.
B.Incorrect pre-shared key used for the VPN tunnel.
C.Packet loss due to high latency on the internet link.
D.Mismatched encryption domain definitions (traffic selectors) between on-premises and cloud VPN gateways.
AnswerD

Phase 2 (Quick Mode) negotiates IPsec security associations, including the traffic selectors defining which subnets each peer encrypts. If the on-premises and cloud gateways define mismatched encryption domains, the proposed selectors never align, so Phase 2 negotiation fails and the tunnel drops intermittently.

Why this answer

Phase 2 negotiation failures in IPsec VPNs indicate that the two gateways cannot agree on the security associations (SAs) for encrypting data traffic. This is most commonly caused by mismatched encryption domain definitions (traffic selectors), such as differing local/remote subnets, protocols, or ports. When the on-premises and cloud VPN gateways define the allowed traffic differently, they cannot establish the Phase 2 SA, leading to intermittent connectivity.

Exam trap

The trap here is that candidates often confuse Phase 1 and Phase 2 failures, incorrectly attributing the error to pre-shared key mismatches (Phase 1) instead of traffic selector mismatches (Phase 2).

How to eliminate wrong answers

Option A is wrong because Dead Peer Detection (DPD) is used to detect loss of a peer during Phase 1 or Phase 2, but disabling DPD does not cause Phase 2 negotiation failures; it only delays failure detection. Option B is wrong because an incorrect pre-shared key would cause Phase 1 (IKE) authentication to fail, not Phase 2 negotiation. Option C is wrong because packet loss or high latency can cause timeouts or retransmissions but does not directly cause a 'Phase 2 negotiation failed' error, which is a protocol-level mismatch.

Page 6

Page 7 of 12

Page 8