Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 526–600

834 questions total · 12pages · All types, answers revealed

Page 7

Page 8 of 12

Page 9
526
MCQhard

A cloud administrator is troubleshooting a web application hosted on a cloud virtual machine (VM) that is experiencing intermittent high latency during peak traffic hours. The application is deployed on a single VM instance with 4 vCPUs and 8 GB RAM, running a Linux OS. The VM is connected to a virtual network with a public IP. The administrator has verified that the application code is optimized and there are no memory leaks. CPU utilization remains below 50% during peaks, but network outbound traffic shows periodic spikes up to 500 Mbps. The VM's network interface is configured with a 1 Gbps bandwidth cap. The administrator suspects that the issue is related to network throttling or packet loss. Which of the following actions should the administrator take to resolve the issue?

A.Increase the VM's vCPU count to 8 to improve processing capacity.
B.Upgrade the VM to a larger instance size with higher network bandwidth cap (e.g., 2 Gbps).
C.Configure the firewall to allow all traffic to reduce processing overhead.
D.Enable DDoS protection on the public IP to filter malicious traffic.
AnswerB

The 1 Gbps interface cap is the bottleneck: periodic 500 Mbps outbound spikes plus burst overhead can saturate it, causing throttling and packet loss. A larger instance size raises the network bandwidth cap to 2 Gbps, removing that ceiling so peak traffic no longer queues at the interface.

Why this answer

The VM's network bandwidth cap of 1 Gbps is being saturated during peak traffic (spikes up to 500 Mbps, but with overhead and burst behavior, the cap can cause throttling and packet loss). Upgrading to a larger instance size with a higher network bandwidth cap (e.g., 2 Gbps) directly addresses the bottleneck by providing more headroom for outbound traffic, reducing latency caused by queueing and drops. The administrator has already ruled out CPU and memory issues, so the network cap is the likely culprit.

Exam trap

The trap here is that candidates may assume CPU or memory is the bottleneck because latency is intermittent, but the question explicitly states CPU is below 50% and memory is fine, so the real issue is the network bandwidth cap, which is a common cloud-specific limitation tied to instance size.

How to eliminate wrong answers

Option A is wrong because increasing vCPUs does not increase network bandwidth capacity; the bottleneck is network throughput, not compute, and CPU utilization is already below 50%. Option C is wrong because configuring the firewall to allow all traffic would not reduce processing overhead in a meaningful way and could actually increase security risks; firewall processing overhead is negligible compared to the bandwidth cap limitation. Option D is wrong because DDoS protection is designed to filter malicious traffic, not to resolve throttling or packet loss caused by legitimate peak traffic exceeding the bandwidth cap.

527
MCQeasy

In the shared responsibility model, which of the following is the cloud customer responsible for?

A.Operating system patching on virtual machines
B.Network infrastructure under the hypervisor
C.Hypervisor security
D.Physical hardware maintenance
AnswerA

In IaaS, the provider secures the physical hosts, hypervisor and network fabric, while the customer retains control of guest operating systems. Patching those VMs is therefore the customer's responsibility, satisfying the shared responsibility split at the OS layer.

Why this answer

In the shared responsibility model, the cloud customer is responsible for security 'in' the cloud, which includes the operating system, applications, and data. For IaaS, the customer manages the guest OS, including patching, while the cloud provider manages the hypervisor, network infrastructure, and physical hardware. Therefore, operating system patching on virtual machines is the customer's responsibility.

Exam trap

The trap here is confusing the responsibilities across service models. Candidates might think the provider handles OS patching in IaaS, but that's only true for PaaS or SaaS. Always remember: in IaaS, you patch the OS.

How to eliminate wrong answers

Option B is wrong because network infrastructure under the hypervisor is managed by the cloud provider. Option C is wrong because hypervisor security is the cloud provider's responsibility. Option D is wrong because physical hardware maintenance is handled by the cloud provider.

528
MCQmedium

A cloud architect is designing a highly available web application on AWS. The application must continue serving traffic even if an entire AWS Availability Zone fails. Which architecture should the architect implement?

A.Active-passive in a single Availability Zone
B.Active-active across two Availability Zones
C.Vertical scaling on a single instance
D.Active-passive across two regions
AnswerB

Active-active across two Availability Zones runs identical workloads in both, so each AZ handles traffic independently. When one AZ fails, the surviving AZ absorbs the load, satisfying the requirement to keep serving traffic through a full AZ outage.

Why this answer

Active-active architecture across multiple Availability Zones ensures that if one zone fails, traffic is routed to the remaining healthy zones, providing high availability.

529
MCQeasy

A cloud operations team is using AWS and needs to monitor the CPU utilization of a fleet of Amazon EC2 instances. The team wants to receive an alert when the average CPU utilization exceeds 80% for 5 consecutive minutes. Which AWS service should they use to create the alarm?

A.AWS CloudTrail
B.AWS Trusted Advisor
C.Amazon CloudWatch
D.AWS Config
AnswerC

Amazon CloudWatch collects and tracks metrics such as CPU utilization for EC2 instances. It allows the creation of alarms that trigger when a metric breaches a threshold for a specified number of evaluation periods. In this scenario, an alarm can be set to fire when average CPU utilization exceeds 80% for 5 consecutive minutes, directly meeting the team's requirement for monitoring and alerting.

Why this answer

Amazon CloudWatch is the AWS service designed for monitoring metrics and creating alarms. It collects CPU utilization data from EC2 instances and allows alarms to be configured with thresholds and evaluation periods. Setting an alarm for average CPU utilization greater than 80% for 5 consecutive minutes meets the team's requirement to be alerted when the condition is met.

Exam trap

The trap here is confusing AWS CloudTrail, which logs API activity, with Amazon CloudWatch, which monitors performance metrics and triggers alarms.

530
MCQhard

A company wants to implement a disaster recovery strategy with an RTO of 15 minutes and an RPO of 1 minute for a critical database. Which approach should be used?

A.Scheduled snapshots every hour
B.Daily snapshots copied to another region
C.Weekly full backups to tape stored offsite
D.Cross-region continuous replication with automatic failover
AnswerD

Continuous cross-region replication keeps a standby copy within seconds of the primary, satisfying the one-minute RPO, while automatic failover redirects traffic without manual intervention, meeting the fifteen-minute RTO. Neither scheduled snapshots nor single-region backups can achieve both targets.

Why this answer

The requirement is an RTO of 15 minutes and an RPO of 1 minute. Cross-region continuous replication with automatic failover provides near-zero RPO (often seconds) and rapid RTO (minutes) by continuously replicating data and automatically promoting a standby in another region. This is the only option that can meet both the 1-minute RPO and 15-minute RTO.

Exam trap

CV0-004 often tests the misconception that frequent snapshots can achieve a low RPO, but snapshots are point-in-time and cannot meet sub-minute RPO; candidates must recognize that continuous replication is required for very low RPO.

How to eliminate wrong answers

Option A is wrong because hourly snapshots yield an RPO of up to 60 minutes, far exceeding the 1-minute requirement. Option B is wrong because daily snapshots yield an RPO of up to 24 hours, and cross-region copy adds delay, failing both RPO and likely RTO. Option C is wrong because weekly tape backups have an RPO of up to 7 days and restoration from tape is slow, failing both objectives.

531
MCQhard

A cloud administrator is troubleshooting connectivity issues between two virtual networks in a public cloud. The networks are in the same region but different VPCs. Both VPCs have route tables and security groups configured. Instances in VPC A cannot ping instances in VPC B. Which of the following is the most likely cause?

A.VPC peering is not established between the two VPCs.
B.The instances are not assigned public IP addresses.
C.Security groups are blocking ICMP traffic.
D.Network ACLs are not configured to allow the traffic.
AnswerA

Without VPC peering, no route exists between the two VPCs, so traffic is dropped regardless of route table or security group configuration. Establishing peering creates the private connectivity path required for instances in VPC A to reach VPC B.

Why this answer

VPC peering is a direct network connection between two VPCs that enables routing of traffic using private IPv4 or IPv6 addresses. Without an established VPC peering connection, instances in different VPCs cannot communicate, even if they are in the same region. Since the question states the VPCs are separate and no peering is mentioned, this is the most likely root cause of the connectivity failure.

Exam trap

The trap here is that candidates often focus on security groups or ACLs as the default answer for connectivity issues, but the fundamental prerequisite for cross-VPC communication is the existence of a VPC peering connection or a transit gateway, not just network access controls.

How to eliminate wrong answers

Option B is wrong because public IP addresses are not required for VPC-to-VPC communication; private IP routing via VPC peering or transit gateway is the standard method. Option C is wrong because while security groups can block ICMP, they are stateful and would not prevent all traffic unless explicitly configured to deny ICMP; the question does not indicate any such rule. Option D is wrong because network ACLs are stateless and must allow both inbound and outbound traffic, but they are not the primary enabler of cross-VPC connectivity; without VPC peering, no amount of ACL configuration will establish the link.

532
MCQmedium

A company uses Azure and wants to connect its on-premises data center to Azure with a dedicated, private, and high-bandwidth connection. Which service should the company use?

A.Azure ExpressRoute
B.Site-to-Site VPN
C.Azure Front Door
D.Azure VPN Gateway
AnswerA

Azure ExpressRoute provides a dedicated, private circuit through a connectivity provider, bypassing the public internet entirely. This satisfies the stem's requirement for private, high-bandwidth connectivity between the on-premises data centre and Azure, unlike VPN gateways which traverse the public internet and offer variable bandwidth.

Why this answer

Azure ExpressRoute provides a dedicated private connection from on-premises to Azure, offering higher bandwidth and reliability than VPN.

533
Multi-Selectmedium

A cloud administrator is responsible for a Microsoft Azure environment. The administrator needs to ensure that virtual machine (VM) disks are backed up daily and that backups are retained for 30 days. The administrator also needs to be able to restore individual files from the backups. Which TWO actions should the administrator take to meet these requirements? (Choose two.)

Select 2 answers
A.Install the Microsoft Azure Recovery Services (MARS) agent on each VM and configure a backup schedule.
B.Create an Azure Storage account with blob versioning enabled and configure lifecycle management.
C.Configure Azure Backup for the VMs using the Azure VM backup extension and associate them with the backup policy.
D.Create a Recovery Services vault and configure a backup policy with a daily schedule and 30-day retention.
E.Enable Azure Site Recovery for the VMs and configure a replication policy.
AnswersC, D

Azure Backup for VMs uses an extension installed on the VM to take snapshot-based backups of the OS and data disks. Associating the VMs with the backup policy created in the Recovery Services vault ensures the daily schedule and 30-day retention are applied. This, combined with the vault and policy, enables file-level recovery from the VM backups, fully meeting the administrator's requirements.

Why this answer

To back up Azure VM disks daily with 30-day retention and file-level restore, the administrator must create a Recovery Services vault and configure a backup policy with the desired schedule and retention. Then, the VMs must be configured for Azure Backup using the VM backup extension and associated with that policy. Together, these actions provide the required backup and restore capabilities.

Exam trap

The trap here is confusing Azure Site Recovery, which is for disaster recovery replication, with Azure Backup, which provides scheduled backups and file-level restore.

534
MCQeasy

A cloud operations team uses a configuration management tool to apply patches to hundreds of Linux servers. Recently, the automation script that applies security patches has been failing with an error: 'Package not found.' The administrator verifies that the patch repository URL is correct and that the servers have internet access. The script runs every Sunday at 2:00 AM and the failures started two weeks ago. The failed patches are all for the latest kernel update. What should the administrator check FIRST?

A.Verify that the package cache is being updated before the installation step.
B.Ensure the patch repository is reachable via DNS.
C.Check if the servers have sufficient disk space for the patch download.
D.Roll back to an earlier version of the patch script.
AnswerA

Stale package metadata causes 'Package not found' when the repository has published a newer kernel; refreshing the cache with the package manager's update step before installation lets the script resolve the latest kernel package name.

Why this answer

The error 'Package not found' typically indicates that the repository metadata is outdated. On many Linux systems, the local package cache (e.g., apt or yum) needs to be updated before installing new packages. The script likely needs to run an update command before attempting to install the patch.

535
MCQmedium

A cloud engineer is deploying a web application on AWS and needs to ensure that the application is fault-tolerant across multiple Availability Zones. The engineer plans to use an Auto Scaling group with a launch template. What should the engineer configure to ensure that instances are launched in multiple Availability Zones?

A.Specify multiple subnets, each in a different Availability Zone, in the Auto Scaling group configuration.
B.Create multiple Auto Scaling groups, each with a single subnet in a different Availability Zone.
C.Use a single subnet and enable cross-zone load balancing on the load balancer.
D.Configure the launch template to specify multiple Availability Zones.
AnswerA

An Auto Scaling group can be configured with multiple subnets across different Availability Zones. When the group scales, it launches instances evenly across the specified subnets, providing fault tolerance. This directly meets the requirement for multi-AZ deployment without additional complexity.

Why this answer

Configuring the Auto Scaling group with multiple subnets in different Availability Zones ensures that instances are launched across those AZs, providing fault tolerance. This is the standard and simplest method to achieve multi-AZ deployment for an Auto Scaling group, unlike using a single subnet or multiple groups.

Exam trap

The trap here is thinking that the launch template defines Availability Zones, but actually the subnets specified in the Auto Scaling group determine the AZ placement of instances.

536
MCQhard

An organization uses CloudFormation to manage resources across multiple AWS accounts. They need to deploy a common set of resources (e.g., logging configuration) to all accounts in an AWS Organization. Which CloudFormation feature should they use?

A.Change sets
B.StackSets
C.Drift detection
D.Nested stacks
AnswerB

StackSets deploy a single CloudFormation template across multiple accounts and Regions from one administration account, satisfying the requirement to roll out shared logging configuration organisation-wide. Unlike ordinary stacks, which are scoped to one account and Region, StackSets use service-managed or self-managed permissions to target every account in the AWS Organization automatically.

Why this answer

CloudFormation StackSets allow you to deploy stacks across multiple accounts and regions in a single operation, ideal for multi-account governance.

537
Multi-Selectmedium

A cloud administrator is configuring a notification channel for critical alerts. Which TWO of the following are commonly used notification channels in cloud monitoring systems? (Select TWO.)

Select 2 answers
A.Amazon CloudWatch Logs
B.Amazon Simple Notification Service (SNS)
C.Slack webhooks
D.AWS Organizations
E.AWS CloudTrail
AnswersB, C

Amazon SNS delivers alerts by fanning messages out to email, SMS, HTTP endpoints and Lambda subscribers, satisfying the notification channel requirement. It integrates natively with CloudWatch alarms, so critical threshold breaches reach operators without custom polling infrastructure.

Why this answer

Amazon Simple Notification Service (SNS) (B) is correct because it is a fully managed pub/sub messaging service that supports topics with email, SMS, HTTP/S, and Lambda subscribers, making it a standard notification channel for CloudWatch alarms. Slack webhooks (C) are correct because an incoming webhook URL lets monitoring services POST JSON messages directly to a Slack channel, a widely used integration for critical alert delivery. Amazon CloudWatch Logs (A) is a log storage and query service, not a notification channel, so it does not deliver alerts to people.

AWS Organizations (D) is an account governance and consolidated billing service, and AWS CloudTrail (E) is an API activity auditing service; neither is designed to send alert notifications.

Exam trap

CV0-004 often tests whether candidates confuse data/logging services (CloudWatch Logs, CloudTrail) with actual notification delivery channels (SNS, Slack webhooks).

538
MCQmedium

An organization needs to connect its on-premises data center to a public cloud with a dedicated, low-latency, and consistent network connection. Which connectivity option should they use?

A.Direct Connect
B.Internet gateway
C.VPC peering
D.Site-to-site VPN
AnswerA

Direct Connect provides a dedicated private connection with consistent performance.

Why this answer

Direct Connect (AWS) or ExpressRoute (Azure) provides dedicated private connectivity from on-premises to cloud.

539
Multi-Selecthard

A company is deploying a cloud-native application that uses containers orchestrated by Kubernetes. The security team wants to enforce the principle of least privilege at the Kubernetes level. Which THREE measures should be implemented? (Choose three.)

Select 3 answers
A.Apply Pod Security Standards (e.g., restricted policy)
B.Implement Kubernetes RBAC to restrict permissions to namespaces and resources
C.Implement network policies to restrict pod-to-pod communication
D.Create service accounts with only the necessary permissions for each application
E.Use namespaces to separate environments
AnswersA, B, D

Pod Security Standards enforce security contexts that limit pod capabilities.

Why this answer

Pod Security Standards (PSS) define security contexts for pods, with the 'restricted' policy enforcing the principle of least privilege by disallowing privileged containers, host network access, and other high-risk capabilities. This directly prevents pods from running with unnecessary permissions, aligning with the security team's goal at the pod level.

Exam trap

The CV0-004 exam often tests the distinction between network-level controls (network policies) and identity/privilege controls (RBAC, Pod Security Standards), leading candidates to mistakenly select network policies as a least-privilege measure when they only restrict traffic, not permissions.

540
Multi-Selecthard

A company is performing a disaster recovery test for a critical application. The test reveals that the application's RTO of 1 hour is not being met due to slow database restoration. Which THREE actions could help improve the restoration time? (Select THREE.)

Select 3 answers
A.Implement continuous replication to a standby database
B.Pre-warm standby database instances in the recovery region
C.Disable encryption on the database to reduce overhead
D.Increase the retention period of automated backups
E.Use provisioned IOPS storage for the database volumes
AnswersA, B, E

Continuous replication to a standby database keeps a near-current copy available, so failover avoids restoring from backup and removes the slow restoration step. This directly reduces database recovery time, helping the application meet its one-hour RTO.

Why this answer

Option A (Implement continuous replication to a standby database) is correct because continuous replication keeps a standby copy nearly in sync with the primary, so failover requires little or no data restoration, drastically cutting the time to recover within the 1-hour RTO. Option B (Pre-warm standby database instances in the recovery region) is correct because pre-warming keeps compute, cache, and database processes already running and initialized, eliminating the startup and warm-up latency that would otherwise delay recovery. Option E (Use provisioned IOPS storage for the database volumes) is correct because restoring or replaying data is I/O-bound, and provisioned IOPS delivers guaranteed, higher disk throughput and lower latency, directly accelerating database restoration.

Option C is not appropriate because disabling encryption weakens security and encryption overhead is not the primary bottleneck in slow restores. Option D is not appropriate because increasing backup retention only keeps backups longer; it does not make restoring any single backup faster.

Exam trap

CV0-004 often tests the confusion between backup retention and restoration speed; candidates may think more backups help RTO, but retention only affects RPO and available restore points.

541
Multi-Selectmedium

A company is designing stateless application tiers to support horizontal scaling. Which TWO design principles support statelessness? (Select TWO.)

Select 2 answers
A.Persist all application state in a shared database
B.Store configuration files on each instance locally
C.Store session state in a shared external cache (e.g., Redis)
D.Use local instance storage for session data
E.Use sticky sessions (session affinity) on the load balancer
AnswersA, C

A shared database externalises all session and user state, so any instance can serve any request without relying on local memory. This satisfies the horizontal-scaling constraint, since instances remain interchangeable and can be added or removed freely.

Why this answer

Option A is correct because persisting all application state in a shared database externalizes state from the compute instances, so any instance can serve any request and instances can be added or replaced freely for horizontal scaling. Option C is correct because storing session state in a shared external cache such as Redis keeps session data outside the instance, allowing any instance to read the session and remain interchangeable, which is the essence of statelessness. Option B is not correct because storing configuration files locally on each instance creates per-instance state that must be synchronized and makes instances non-interchangeable.

Option D is not correct because local instance storage for session data ties a user's session to a specific instance, preventing free horizontal scaling. Option E is not correct because sticky sessions (session affinity) on the load balancer deliberately pin a client to one instance, which is the opposite of stateless design and hinders horizontal scaling.

Exam trap

CV0-004 often tests whether candidates recognize that sticky sessions and local session storage are anti-patterns for statelessness — the distractor 'use sticky sessions' sounds like a load-balancing best practice but directly contradicts stateless design.

542
Multi-Selectmedium

A cloud engineer is migrating a legacy application to AWS. The application requires minimal downtime during the database migration from SQL Server to Aurora MySQL. Which TWO AWS services should the engineer use to achieve this?

Select 2 answers
A.AWS Snowball
B.AWS Schema Conversion Tool (SCT)
C.AWS Direct Connect
D.AWS DataSync
E.AWS Database Migration Service (DMS)
AnswersB, E

SCT converts the SQL Server schema and stored procedures into Aurora MySQL-compatible DDL, which is essential because the two engines use different syntax. Without this conversion the migrated schema would fail on Aurora, so it satisfies the heterogeneous-engine requirement underpinning the minimal-downtime cutover.

Why this answer

The AWS Schema Conversion Tool (SCT) is used to convert the source SQL Server database schema and code to be compatible with Aurora MySQL, handling differences in data types, stored procedures, and other database objects. The AWS Database Migration Service (DMS) then performs the actual data migration with minimal downtime by continuously replicating changes from the source to the target database until a cutover is performed. Together, SCT and DMS enable a heterogeneous migration with near-zero downtime.

Exam trap

CompTIA often tests the distinction between data migration services (DMS) and data transfer services (DataSync, Snowball), where candidates mistakenly choose DataSync for database migrations because it sounds similar to 'data synchronization' but it lacks schema conversion and live database replication capabilities.

543
MCQhard

A company wants to implement automated patching for their Windows and Linux servers in AWS. They need to schedule patching during a maintenance window and have a rollback plan. Which service should they use?

A.AWS OpsWorks
B.AWS Config
C.AWS Systems Manager Patch Manager
D.Amazon Inspector
AnswerC

AWS Systems Manager Patch Manager applies OS patches to Windows and Linux instances on a schedule, using maintenance windows and patch baselines. It supports compliance reporting and controlled rollback through baseline approval rules, meeting the maintenance-window and rollback requirements.

Why this answer

AWS Systems Manager Patch Manager automates the process of patching fleets of Windows and Linux servers. It allows you to define patch baselines, schedule patching during maintenance windows, and even roll back patches if needed, making it the ideal service for this requirement.

Exam trap

The trap is confusing Patch Manager with other AWS services that have overlapping capabilities. For example, Amazon Inspector finds vulnerabilities but does not patch, and AWS Config can check compliance but not remediate. Candidates might also think OpsWorks is still the go-to for patching, but it's not.

How to eliminate wrong answers

Option A is wrong because AWS OpsWorks is a configuration management service that uses Chef and Puppet, but it is not specifically designed for automated patching and is being deprecated. Option B is wrong because AWS Config is for assessing, auditing, and evaluating configurations, not for applying patches. Option D is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and network exposures, but it does not perform patching.

544
MCQhard

A cloud engineer is responsible for a fleet of Amazon EC2 instances running a stateless web application. The engineer needs to ensure that if an instance fails a status check, it is automatically replaced without manual intervention. Which AWS feature should be used to meet this requirement?

A.AWS OpsWorks for Chef Automate with auto-healing policies
B.EC2 Auto Recovery feature enabled on each instance
C.EC2 Auto Scaling group with health checks set to EC2 and a launch template
D.AWS Elastic Beanstalk with rolling updates and immutable deployments
AnswerC

An Auto Scaling group can be configured to use EC2 status checks as health checks. When an instance fails a status check, the Auto Scaling group terminates it and launches a new instance from the launch template. This provides automatic replacement and maintains the desired capacity, meeting the requirement for unattended recovery.

Why this answer

The requirement is to automatically replace instances that fail status checks. An EC2 Auto Scaling group with EC2 health checks monitors instance status and replaces unhealthy instances. The launch template defines the instance configuration.

This is the standard AWS pattern for self-healing fleets of stateless instances.

Exam trap

The trap here is confusing EC2 Auto Recovery, which recovers an existing instance onto new hardware, with Auto Scaling, which replaces the instance entirely.

545
MCQeasy

Which cloud deployment model connects an on-premises data center to a public cloud using VPN or dedicated connections like AWS Direct Connect?

A.Private cloud
B.Multi-cloud
C.Hybrid cloud
D.Public cloud
AnswerC

Hybrid cloud joins on-premises infrastructure to a public cloud through VPN tunnels or dedicated private links such as AWS Direct Connect, keeping workloads split across both environments. That connectivity mechanism is exactly what the stem describes.

Why this answer

A hybrid cloud deployment model combines on-premises infrastructure with public cloud services, connected via VPN or dedicated connections like AWS Direct Connect. This allows workloads to span both environments, providing flexibility and scalability. It is the standard term for such integrated architectures.

Exam trap

The trap is confusing hybrid cloud with multi-cloud or private cloud; candidates must remember that hybrid specifically involves on-premises to public cloud integration.

How to eliminate wrong answers

Option A is wrong because a private cloud is dedicated to a single organization and does not inherently connect to a public cloud. Option B is wrong because multi-cloud refers to using multiple public cloud providers, not connecting on-premises to a public cloud. Option D is wrong because a public cloud is a shared, multi-tenant environment without the on-premises integration.

546
Matchingmedium

Match each disaster recovery term to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Maximum time to restore services after outage

Maximum acceptable data loss in time

Automatic switch to standby system

Copy of data for restoration

Documented plan for disaster recovery

Why these pairings

Key disaster recovery terms: RTO focuses on downtime, RPO on data loss, failover is automatic, and cold site has minimal setup. Common confusions involve swapping RTO and RPO definitions or mischaracterizing failover as manual.

547
Multi-Selecthard

A company is deploying a web application on Google Cloud that requires low-latency access to static content (images, CSS) for global users. The application also needs to handle SSL termination to reduce load on backend instances. Which TWO services should the architect use? (Select TWO.)

Select 2 answers
A.Compute Engine with enhanced network
B.Cloud Functions
C.Cloud CDN
D.Cloud Load Balancing
E.Cloud Storage
AnswersC, D

Cloud CDN caches static assets at Google's global edge points of presence, cutting latency for images and CSS by serving users from nearby locations rather than the origin. It directly satisfies the stem's low-latency static-content constraint. SSL termination, however, is handled separately by the external Application Load Balancer, not Cloud CDN itself.

Why this answer

Cloud CDN (Option C) is correct because it uses Google's global edge cache to deliver static content (images, CSS) with low latency by caching content at points of presence (PoPs) close to users. Cloud Load Balancing (Option D) is correct because it provides global anycast-based load balancing with integrated SSL termination, offloading the SSL/TLS handshake from backend instances and reducing their CPU load.

Exam trap

The CV0-004 exam often tests the misconception that Cloud Storage alone can serve static content globally with low latency, but it lacks edge caching and SSL termination, requiring Cloud CDN and Cloud Load Balancing to meet the requirements.

548
MCQmedium

A cloud architect is selecting a storage solution for a database that requires low-latency reads and writes. The database will run on a single VM and must support consistent performance. Which storage type is most appropriate?

A.Archive storage
B.Object storage
C.File storage
D.Block storage
AnswerD

Block storage presents a raw volume directly to the VM, giving the database low-latency, consistent read/write performance on a single host. File and object storage add network protocol overhead and are unsuitable for database workloads needing predictable IOPS, so block satisfies the single-VM, consistent-performance constraint.

Why this answer

Block storage (e.g., EBS, Azure Disk) provides low-latency, consistent performance suitable for databases running on a single VM.

549
MCQmedium

A cloud operations team runs a fleet of Amazon EC2 instances behind an Application Load Balancer. During a load test, the team notices that healthy targets are being marked unhealthy and removed from rotation whenever a deployment briefly pushes CPU utilization above 90 percent. The team wants the load balancer to remove an instance only when the application stops responding to HTTP requests, not when it is merely busy. Which action should the team take?

A.Enable sticky sessions on the load balancer so that clients remain bound to the same instance throughout the deployment.
B.Create a CloudWatch alarm on the CPUUtilization metric and attach it to an Auto Scaling group scaling policy to replace instances above 90 percent.
C.Configure the target group health check to use the HTTP protocol on the application's health endpoint with a matcher for 200 and increase the unhealthy threshold.
D.Change the target group health check to TCP on the instance port and raise the healthy threshold so instances rejoin faster.
AnswerC

An HTTP health check against a dedicated application health endpoint evaluates whether the application is actually serving requests, which is the behavior the team wants. Setting a matcher of 200 confirms a valid response, and raising the unhealthy threshold prevents a single slow response from ejecting a target. Because CPU pressure alone does not affect an HTTP health check, busy-but-responsive instances stay in rotation during deployments.

Why this answer

Health checks should reflect the actual availability of the application, not incidental resource pressure. Switching the target group to an HTTP check against a dedicated health endpoint, expecting a 200 response, and lengthening the unhealthy threshold lets the load balancer distinguish a genuinely unresponsive target from one that is simply handling heavy load. This keeps instances in service during short CPU spikes, which is exactly the deployment behavior the team wants to preserve.

Exam trap

The trap here is assuming that a busy instance is an unhealthy instance, when load balancer health checks are meant to verify application responsiveness rather than resource utilization.

550
MCQhard

A DevOps engineer is designing a CI/CD pipeline for a microservices application. The team wants to isolate each build job to avoid interference. Which cloud concept should be utilized?

A.Dedicated hosts
B.Containerization with orchestration
C.Virtual private cloud (VPC)
D.Serverless functions
AnswerB

Containerisation with orchestration gives each build job its own isolated runtime with dedicated filesystem and resource limits, so concurrent jobs cannot interfere. Orchestration schedules these ephemeral containers across nodes, directly satisfying the stem's requirement to isolate each build job.

Why this answer

Containerization with orchestration (e.g., Docker and Kubernetes) provides isolated runtime environments for each build job by packaging the application and its dependencies into lightweight containers. This ensures that build processes do not interfere with each other, as each container runs in its own isolated user space with dedicated resources, and orchestration manages scheduling, scaling, and lifecycle. This approach is ideal for CI/CD pipelines in microservices architectures where build isolation is critical.

Exam trap

CompTIA often tests the misconception that network-level isolation (VPC) or physical isolation (dedicated hosts) is required for build job isolation, when in fact containerization provides sufficient and more efficient isolation at the process level.

How to eliminate wrong answers

Option A is wrong because dedicated hosts provide physical server isolation but are overkill for build job isolation; they do not offer per-job isolation within the same host and incur higher cost and management overhead. Option C is wrong because a Virtual Private Cloud (VPC) is a network-level isolation construct for cloud resources, not a mechanism to isolate individual build jobs; it cannot prevent interference between processes running on the same compute instance. Option D is wrong because serverless functions (e.g., AWS Lambda) are stateless and ephemeral, but they are not designed for running CI/CD build jobs that require persistent storage, longer execution times, or custom runtime environments; they also lack the fine-grained resource isolation needed for concurrent builds.

551
Multi-Selecthard

Which THREE of the following are common causes of VM migration failures in a cloud environment? (Choose three.)

Select 3 answers
A.Expired software licenses on the target host
B.Incompatible CPU instruction sets or features between source and target hosts
C.Stale DNS records for the VM's hostname
D.Insufficient storage space on the target host
E.Network connectivity issues between the source and target hypervisors
AnswersB, D, E

Incompatible CPU instruction sets or features between source and target hosts directly cause migration failures because the target hypervisor cannot execute instructions the guest VM requires. This satisfies the stem's constraint of identifying common migration failure causes: live migration demands CPU feature parity, and mismatched instruction sets (for example, differing SSE or AVX support) halt the transfer.

Why this answer

Option B is correct because live or cold migration requires the target host's CPU to expose the same instruction set extensions (e.g., SSE4.2, AVX, VT-x/AMD-V) that the VM's configuration and guest OS expect; a mismatch causes the migration to fail or be blocked by compatibility checks such as those in vSphere EVC or Hyper-V processor compatibility mode. Option D is correct because the target datastore must have enough free capacity to hold the VM's disks, snapshots, swap, and memory files; if provisioning the destination files exceeds available space, the migration aborts with an out-of-space error. Option E is correct because migration traffic (e.g., vMotion over TCP 8000, or shared storage access over iSCSI/NFS) depends on reliable, adequately provisioned network links between source and target hypervisors; packet loss, MTU mismatch, or blocked ports will break the transfer.

Option A is not a typical migration failure cause because hypervisor and guest licensing is generally checked at power-on or activation time, not during the migration operation itself. Option C is not a typical cause because stale DNS records for the VM's hostname affect name resolution and connectivity after migration, but they do not prevent the hypervisor-level migration process from completing.

552
MCQeasy

A security administrator needs to store database credentials and API keys securely in AWS. The credentials must be automatically rotated every 90 days. Which service should the administrator use?

A.AWS Systems Manager Parameter Store
B.AWS KMS
C.AWS Secrets Manager
D.AWS Certificate Manager
AnswerC

AWS Secrets Manager natively stores and encrypts secrets, and its built-in rotation schedules Lambda functions to change credentials automatically. This directly satisfies the stem's 90-day rotation requirement, which AWS Systems Manager Parameter Store cannot perform without custom automation.

Why this answer

AWS Secrets Manager is designed to store secrets and provides built-in rotation capabilities.

553
Multi-Selecthard

A cloud security team is reviewing a Google Cloud environment. They need to ensure that data stored in Cloud Storage buckets is protected with customer-managed encryption keys and that access to those keys is tightly controlled. Which TWO actions should the team take? (Choose two.)

Select 2 answers
A.Enable uniform bucket-level access on the bucket.
B.Use customer-supplied encryption keys (CSEK) by providing the key with each upload request.
C.Create a Cloud KMS key ring and key, then grant the storage service account the cryptoKeyEncrypterDecrypter role on the key.
D.Configure the bucket's default encryption to use the Cloud KMS key.
E.Create a service account with the Cloud KMS Admin role and use it to encrypt all objects manually.
AnswersC, D

To use customer-managed encryption keys (CMEK) with Cloud Storage, you must create a Cloud KMS key and grant the Cloud Storage service account permission to use it. The cryptoKeyEncrypterDecrypter role allows the service to encrypt and decrypt data with the key. This is a required step for enabling CMEK on buckets.

Why this answer

Enabling CMEK for Cloud Storage requires creating a Cloud KMS key and granting the Cloud Storage service account the cryptoKeyEncrypterDecrypter role on that key. Then, the bucket's default encryption must be set to use that key. These two actions ensure that objects are encrypted with customer-managed keys and that access to the keys is controlled via IAM.

Exam trap

The trap here is confusing customer-managed encryption keys (CMEK) with customer-supplied encryption keys (CSEK), which are provided per request and not managed in Cloud KMS.

554
Multi-Selecthard

Which TWO design patterns can help a cloud architect achieve a Recovery Time Objective (RTO) of less than 5 minutes for a critical application?

Select 2 answers
A.Warm standby
B.Multi-site active-active
C.Backup and restore
D.Pilot light
E.Hot standby (active/passive) with automatic failover
AnswersB, E

Multi-site active-active runs identical workloads concurrently in separate regions, so traffic fails over instantly via global load balancing with no cold-start or data-restore delay. This satisfies the sub-5-minute RTO constraint, since recovery becomes near-immediate rather than requiring redeployment or backup restoration.

Why this answer

Multi-site active-active (B) is correct because traffic is served simultaneously from two or more independent regions, so if one site fails, the remaining site already runs at full capacity and can absorb the load immediately, yielding an RTO near zero (well under 5 minutes). Hot standby (active/passive) with automatic failover (E) is correct because the passive environment is fully provisioned and continuously running, so automated health checks and DNS/load-balancer failover can redirect traffic in seconds to a few minutes, meeting an RTO under 5 minutes. Warm standby (A) keeps a scaled-down but running copy that must be scaled up and validated before cutover, and pilot light (D) keeps only core services running so the full stack must be provisioned at failover, both typically exceeding 5 minutes.

Backup and restore (C) requires restoring data and rebuilding infrastructure from backups, giving the longest RTO (hours), so it cannot meet the target.

Exam trap

CompTIA often tests the misconception that warm standby or pilot light can achieve sub-5-minute RTO, but candidates forget that these patterns require manual scaling or provisioning steps that add significant delay, unlike the fully pre-provisioned and automated failover in active-active or hot standby.

555
MCQmedium

A cloud engineer notices that an auto-scaling group is adding and removing instances too frequently, causing instability. Which configuration parameter should be adjusted to reduce this behavior?

A.Increase the health check grace period
B.Disable lifecycle hooks
C.Increase the cooldown period
D.Lower the scaling metric thresholds
AnswerC

Increasing the cooldown period forces the auto-scaling group to wait after each scaling activity before triggering another, directly damping the rapid add-remove oscillation described. This satisfies the stability constraint by preventing consecutive scale-out and scale-in events from chasing transient metric spikes.

Why this answer

Increasing the cooldown period is the correct adjustment because cooldown is the waiting time after a scaling activity before the auto-scaling group can perform another scaling action. A longer cooldown lets newly launched instances stabilize and metrics to reflect the new capacity, preventing the rapid add/remove oscillation known as thrashing. This directly reduces the instability described.

Exam trap

CV0-004 often tests the confusion between cooldown (dampening scaling frequency) and health check grace period (delaying health evaluation), causing candidates to pick the wrong stabilization control.

How to eliminate wrong answers

Option A is wrong because the health check grace period controls how long the group waits before checking a new instance's health; extending it delays unhealthy-instance replacement but does not stop rapid scale-in/scale-out flapping. Option B is wrong because lifecycle hooks pause instances in a wait state during launch or termination for custom actions; disabling them removes that control and does not address scaling oscillation. Option D is wrong because lowering scaling metric thresholds makes the group more sensitive to metric changes, which would increase — not reduce — the frequency of scaling actions.

556
MCQhard

A security administrator is configuring a Web Application Firewall (WAF) to protect a public-facing web application. The application experiences a high volume of traffic from certain geographic regions that are not serving customers. Which WAF feature should be used to block this traffic?

A.Rate limiting
B.OWASP rule set
C.Geo-blocking
D.IP reputation lists
AnswerC

Geo-blocking inspects the source IP's geographic origin and denies requests from specified countries or regions, directly satisfying the requirement to drop traffic from regions that generate no customers. It filters at the WAF layer before requests reach the application, unlike rate limiting or signature-based rules.

Why this answer

Geo-blocking allows the WAF to block or allow traffic based on geographic location, reducing unwanted traffic and potential attacks.

557
Multi-Selectmedium

A cloud engineer is troubleshooting a VM that is experiencing high latency. The VM is hosted on a hypervisor with other VMs. Which TWO metrics should the engineer review to identify if resource contention is occurring?

Select 2 answers
A.Memory ballooning
B.CPU ready time
C.Network packet drops
D.Swap usage
E.Disk queue length
AnswersA, B

Memory ballooning reveals host memory pressure: the hypervisor reclaims guest pages via the balloon driver, forcing the VM to swap and stall. Rising ballooning indicates the host is overcommitted on RAM, making it a direct contention signal alongside CPU ready time.

Why this answer

Memory ballooning (A) is correct because it directly indicates that the hypervisor is reclaiming guest memory under host-level memory pressure, which is a classic sign of memory contention among co-hosted VMs and can cause latency from paging or reduced cache. CPU ready time (B) is correct because it measures the time a vCPU is runnable but waiting for a physical CPU, which is the definitive metric for CPU contention on an oversubscribed hypervisor. Network packet drops (C) reflect network congestion or NIC issues rather than hypervisor resource contention.

Swap usage (D) is a guest-OS symptom that can result from memory pressure but does not itself identify contention between VMs. Disk queue length (E) indicates storage latency or an overloaded datastore, not contention for hypervisor CPU or memory resources.

Exam trap

CompTIA often tests the distinction between guest-level metrics (swap usage, disk queue length) and hypervisor-level metrics (ballooning, ready time), and the trap here is that candidates confuse swap usage (guest OS paging) with memory ballooning (hypervisor reclaim), or assume network packet drops indicate VM contention rather than network issues.

558
MCQmedium

A company wants to implement a tagging strategy for their cloud resources to track costs by department and project. Tags must be applied to resources such as virtual machines and storage buckets. Which of the following is a best practice for cost attribution using tags?

A.Apply tags to resources only after creation to avoid governance issues.
B.Define a set of mandatory tag keys such as CostCenter, Project, and Environment with standardized values.
C.Use a single tag key 'Environment' with values 'Production' or 'Development'.
D.Use free-form text for tag values to allow flexibility.
AnswerB

Mandatory, standardised tag keys with controlled values ensure every resource is attributable to a department and project, preventing untagged or inconsistently labelled resources from skewing cost reports. This enforces consistent cost attribution across the estate.

Why this answer

Standardized, mandatory tag keys with controlled values (e.g., CostCenter, Project, Environment) ensure consistent cost allocation across all resources and prevent drift. This enables reliable grouping in billing reports and enforces governance via policies like AWS Tag Policies or Azure Policy. Without a defined schema, cost attribution becomes unreliable and reports fragment.

Exam trap

CV0-004 often tests the misconception that flexible or post-hoc tagging is acceptable, when the exam expects recognition that standardized, mandatory tags applied at creation are the only reliable basis for cost attribution.

How to eliminate wrong answers

Option A is wrong because applying tags only after creation creates a window where resources are untagged, breaking cost attribution and violating governance best practices; tags should be applied at provisioning time via IaC or policies. Option C is wrong because a single 'Environment' tag only tracks one dimension and cannot attribute costs by department or project, which is the stated requirement. Option D is wrong because free-form text values lead to inconsistent spellings, typos, and case variations (e.g., 'Prod', 'production', 'PROD'), making aggregation and reporting impossible.

559
MCQmedium

A company is migrating a large Oracle database (2 TB) from on-premises to AWS RDS for Oracle. They require minimal downtime and need to keep the source database running during migration. Which AWS service should they use to achieve continuous replication?

A.AWS DataSync
B.AWS DMS with CDC
C.AWS S3 Transfer Acceleration
D.AWS Snowball Edge
AnswerB

AWS DMS with change data capture continuously replicates ongoing changes from the live Oracle source to RDS, so the source stays running and cutover downtime is limited to final catch-up. Native tools like Data Pump require quiescing the database, which the minimal-downtime constraint rules out.

Why this answer

AWS DMS with Change Data Capture (CDC) is the correct choice because it enables continuous replication of ongoing changes from the source Oracle database to the target RDS for Oracle instance, allowing the source to remain fully operational during migration. CDC captures incremental changes (inserts, updates, deletes) from the source's redo logs, minimizing downtime to a brief cutover window. This meets the requirement of a 2 TB database with minimal downtime while keeping the source running.

Exam trap

The trap here is that candidates confuse AWS DataSync or S3 Transfer Acceleration as suitable for database replication, but they lack CDC capabilities and are designed for file or object transfers, not transactional database synchronization.

How to eliminate wrong answers

Option A is wrong because AWS DataSync is designed for one-time bulk data transfers between on-premises storage and AWS, not for continuous database replication or CDC. Option C is wrong because AWS S3 Transfer Acceleration speeds up uploads to S3 buckets over the internet but does not support database replication or CDC for Oracle to RDS. Option D is wrong because AWS Snowball Edge is a physical device for offline bulk data transfer, which cannot provide continuous replication and would require taking the source database offline to transfer data.

560
MCQhard

An organization uses a cloud-based infrastructure with multiple VPCs peered together. The security team notices that traffic between VPCs is not being inspected by the central firewall. What design change should be implemented to ensure all inter-VPC traffic passes through a centralized firewall?

A.Use VPC endpoints for all inter-VPC communication
B.Apply network ACLs to all subnets in each VPC
C.Set up a transit VPC with a firewall appliance and route traffic through it
D.Implement VPC peering between all VPCs and attach a firewall to each VPC
AnswerC

VPC peering creates direct, non-transitive routes between VPCs, so traffic bypasses any central inspection point. A transit VPC acts as a hub: spokes peer only with it, and route tables direct inter-VPC traffic through the firewall appliance hosted there, restoring centralised inspection.

Why this answer

A transit VPC architecture uses a centralized hub VPC containing a firewall appliance (e.g., a next-generation firewall) and routes all inter-VPC traffic through it via VPC peering or VPN connections. By configuring route tables in each spoke VPC to point the destination CIDR of other VPCs to the transit VPC's firewall, every packet between VPCs is forced through the firewall for inspection, ensuring compliance with security policies.

Exam trap

The trap here is that candidates confuse VPC peering (which allows direct, non-inspected traffic) with a transit VPC (which forces traffic through a central inspection point), or they mistakenly think network ACLs or VPC endpoints can provide centralized traffic inspection.

How to eliminate wrong answers

Option A is wrong because VPC endpoints (e.g., Gateway or Interface endpoints) are designed for private connectivity to AWS services (like S3 or DynamoDB) without traversing the internet, not for routing general inter-VPC traffic through a central firewall. Option B is wrong because network ACLs are stateless, subnet-level filters that control inbound/outbound traffic at the subnet boundary but do not force traffic through a centralized inspection point; they only allow or deny traffic based on rules, not route it. Option D is wrong because implementing VPC peering between all VPCs creates a full mesh, but attaching a firewall to each VPC would require managing multiple firewalls and does not guarantee centralized inspection; traffic would flow directly between peered VPCs without passing through a single firewall, defeating the goal of centralized inspection.

561
MCQhard

A company uses Azure RBAC to manage access to resources. A user is assigned a Contributor role at the subscription scope. Which of the following is true regarding the scope of this role?

A.The user will have Contributor permissions only on resources created after the assignment.
B.The user will have Contributor permissions on the subscription itself but not its resources.
C.The user will have Contributor permissions only on resource groups within the subscription.
D.The user will have Contributor permissions on all resources within the subscription.
AnswerD

Azure RBAC assignments are inherited by every child scope, so a Contributor role granted at subscription level flows down to all resource groups and resources inside that subscription. This satisfies the stem's subscription-scope constraint, rather than limiting access to a single resource group or resource.

Why this answer

RBAC roles in Azure are inherited from higher scopes to lower scopes (management group → subscription → resource group → resource).

562
MCQeasy

A cloud engineer is troubleshooting a serverless function that is intermittently failing with timeout errors. The function is triggered by an HTTP API and processes data from an external database. The function's timeout is set to 30 seconds. Which of the following is the MOST likely cause of the timeouts?

A.The HTTP API gateway is throttling requests to the function.
B.The external database is experiencing high latency or connection issues.
C.The function's memory allocation is too low, causing it to run slowly.
D.The function's timeout value is set too high for the workload.
AnswerB

Serverless functions that call external databases are highly sensitive to network latency and database responsiveness. If the database is slow to respond or connections are timing out, the function will exceed its timeout. This is a common cause of intermittent timeouts in serverless architectures, especially when the database is outside the cloud provider's network or under heavy load.

Why this answer

Intermittent timeouts in a serverless function that accesses an external database are most commonly caused by database latency or connection problems. The function's execution time is dominated by the database call, so any slowness there can push it over the timeout limit. Addressing database performance or connection pooling is the key to resolving the issue.

Exam trap

The trap here is focusing on the function's configuration (memory, timeout) rather than the external dependency, which is the likely bottleneck in this scenario.

563
MCQhard

A financial services company is deploying a critical application on AWS. The security team requires that all data stored in Amazon S3 be encrypted at rest using keys managed by the company, with the ability to audit key usage and rotate keys annually. The company also wants to minimize operational overhead. Which S3 encryption option should the cloud engineer implement?

A.SSE-S3 with AWS managed keys
B.SSE-KMS with AWS managed keys
C.SSE-KMS with customer managed keys
D.SSE-C with customer-provided keys
AnswerC

SSE-KMS with customer managed keys allows the company to create and manage their own KMS keys, control key policies, enable automatic key rotation, and audit key usage via AWS CloudTrail. This meets all requirements: customer-managed keys, auditing, rotation, and minimal operational overhead since KMS handles the encryption/decryption.

Why this answer

SSE-KMS with customer managed keys provides the necessary control and auditing. The company can create KMS keys, set key policies, enable rotation, and track key usage through CloudTrail. This option balances security requirements with operational efficiency, as AWS manages the encryption and decryption process, but the customer retains control over the keys.

Exam trap

The trap here is confusing SSE-KMS with AWS managed keys and customer managed keys, or assuming SSE-C provides auditing when it does not.

564
MCQeasy

A cloud administrator needs to grant a developer read-only access to a specific storage bucket in AWS. Which IAM component should the administrator modify?

A.IAM policy
B.Security group
C.AWS WAF
D.Network ACL
AnswerA

An IAM policy is the JSON document that defines which actions are allowed or denied on specified resources, and attaching a read-only policy to the developer's identity or the bucket grants exactly that scoped access. Roles, groups and ACLs alone cannot express this permission set.

Why this answer

To grant a developer read-only access to a specific S3 bucket, the administrator must modify an IAM policy. IAM policies are JSON documents that define permissions (Allow/Deny) for actions on AWS resources, and they can be attached to IAM users, groups, or roles. By creating a policy that allows s3:GetObject, s3:ListBucket, etc., on the specific bucket ARN, the administrator can grant least-privilege read-only access.

Exam trap

The trap is confusing network-level controls (security groups, NACLs, WAF) with identity and access management (IAM). Candidates may think that a security group can restrict S3 access, but S3 is not a VPC resource and security groups do not apply to it.

How to eliminate wrong answers

Option B is wrong because security groups act as virtual firewalls for EC2 instances and other resources at the network layer; they control inbound and outbound traffic based on IP, port, and protocol, not IAM permissions for S3. Option C is wrong because AWS WAF is a web application firewall that protects web applications from common exploits; it does not manage identity-based access to S3 buckets. Option D is wrong because network ACLs are stateless subnet-level firewalls that control traffic in and out of subnets; they do not grant or deny IAM permissions to S3.

565
MCQhard

A financial services firm runs containerized workloads on a managed Kubernetes service. Auditors require that no container can run as root, that privilege escalation is blocked, and that the policy is enforced at admission time without modifying existing deployment manifests. Which control best meets these requirements?

A.Deploy a runtime security agent that kills containers detected running with root privileges.
B.Configure a Pod Security Admission policy with the restricted profile applied to the target namespace.
C.Enable the Kubernetes audit log and forward events to a SIEM for alerting on privileged containers.
D.Apply a network policy that denies egress traffic from containers running in the target namespace.
AnswerB

Pod Security Admission enforces pod security standards at admission time and the restricted profile blocks root execution, privilege escalation, and other unsafe capabilities. Applying it to the namespace enforces the policy without editing individual deployment manifests, and violations are rejected before the pod is created. This directly satisfies the auditor's enforcement and non-modification requirements.

Why this answer

Pod Security Admission enforces pod security standards when a pod is admitted, so the restricted profile prevents root execution and privilege escalation before the container starts. It applies at the namespace level, requiring no changes to deployment manifests. Logging, network policy, and runtime termination either observe or react rather than block, so they cannot satisfy a preventive admission-time mandate.

Exam trap

The trap here is treating runtime detection or audit logging as equivalent to admission-time enforcement, when only an admission controller can reject a non-compliant pod before it runs.

566
MCQeasy

A cloud engineer is responsible for securing a multi-tier application deployed on IaaS. The application consists of web servers, application servers, and database servers. The engineer needs to implement network segmentation to minimize the attack surface. Which of the following is the BEST approach?

A.Use a single security group for all instances and define rules to allow traffic between tiers.
B.Create separate subnets for each tier and configure security groups to allow only required traffic between them.
C.Place web servers in a public subnet and application and database servers in the same private subnet with a common security group.
D.Place all instances in the same subnet and use network ACLs to restrict traffic between tiers.
AnswerB

Separate subnets per tier let security groups enforce least-privilege traffic flows between web, application, and database layers, directly minimising the attack surface as the stem requires. Because security groups filter at the instance level, lateral movement after a web-tier compromise is contained, unlike flat-network alternatives that expose every tier to every other.

Why this answer

Creating separate subnets for each tier enforces network segmentation at the IP layer, which is a fundamental security best practice for multi-tier applications. By configuring security groups (stateful firewalls) to allow only the specific required traffic (e.g., HTTP/HTTPS from web to app, SQL from app to database), the engineer minimizes the attack surface by preventing lateral movement if one tier is compromised. This approach aligns with the principle of least privilege and is the most effective method in IaaS environments like AWS, Azure, or GCP.

Exam trap

The trap here is that candidates often confuse security groups with network ACLs or assume that placing servers in the same subnet with restrictive rules is sufficient, but CompTIA tests the understanding that true network segmentation requires separate subnets (or VLANs) to prevent layer-2 adjacency and lateral movement.

How to eliminate wrong answers

Option A is wrong because using a single security group for all instances violates network segmentation; any instance can potentially communicate with any other if rules are too permissive, and it does not isolate tiers, increasing the blast radius. Option C is wrong because placing application and database servers in the same private subnet with a common security group fails to isolate the database tier from the application tier, allowing an attacker who compromises the app server to directly access the database without additional network-level controls. Option D is wrong because placing all instances in the same subnet and relying solely on network ACLs (stateless) is insufficient; network ACLs evaluate rules in order and require explicit allow rules for return traffic, making them more complex to manage and easier to misconfigure, and they do not provide the same granular, stateful control as security groups.

567
MCQhard

A cloud architect is designing a solution to store and retrieve large volumes of unstructured data for a media company. The data must be highly durable, available, and accessible from multiple AWS Regions with low latency. The company also wants to minimize costs for data that is infrequently accessed but must be retained for years. Which AWS service and feature combination should the architect use?

A.Amazon FSx for Lustre with data repository integration
B.Amazon S3 with Cross-Region Replication and S3 Lifecycle policies to transition to S3 Glacier Deep Archive
C.Amazon EBS with snapshots copied to multiple regions
D.Amazon EFS with replication to multiple regions
AnswerB

Amazon S3 provides high durability and availability for unstructured data. Cross-Region Replication automatically replicates objects to another region, enabling low-latency access from multiple regions. S3 Lifecycle policies can transition infrequently accessed data to S3 Glacier Deep Archive for long-term retention at low cost. This combination meets all requirements.

Why this answer

Amazon S3 with Cross-Region Replication and lifecycle policies to S3 Glacier Deep Archive provides a durable, highly available, and globally accessible solution for unstructured data. Cross-Region Replication ensures low-latency access from multiple regions, while lifecycle policies automatically transition infrequently accessed data to a low-cost archival storage class. The other services are either block or file storage and do not offer the same global accessibility and cost-effective archival.

Exam trap

The trap here is confusing block or file storage services with object storage for global, multi-region access, or overlooking the need for a lifecycle policy to reduce costs for infrequently accessed data.

568
MCQhard

A company uses Azure and wants to enforce multi-factor authentication (MFA) for all administrative users. The solution must be centrally managed and apply to all Azure subscriptions. Which approach should be used?

A.Create a Conditional Access policy in Azure AD requiring MFA for all cloud apps
B.Configure MFA on each individual Azure subscription
C.Assign MFA to each user individually in Azure AD
D.Use Azure Policy to require MFA for admin roles
AnswerA

Conditional Access in Microsoft Entra ID evaluates sign-in signals and enforces MFA tenant-wide, covering every Azure subscription because subscriptions inherit directory-level authentication. This satisfies the central management constraint: one policy applies to all administrative users across all cloud apps, rather than per-subscription configuration.

Why this answer

Conditional Access policies in Azure AD are centrally managed and can enforce MFA for all cloud apps across all Azure subscriptions by targeting the 'Microsoft Azure Management' cloud app. This approach applies to all administrative users regardless of subscription, as Azure AD is the identity provider for Azure resources.

Exam trap

The trap here is confusing Azure Policy (resource compliance) with Azure AD Conditional Access (identity security), leading candidates to select Option D, even though Azure Policy cannot enforce authentication requirements.

How to eliminate wrong answers

Option B is wrong because MFA cannot be configured on individual Azure subscriptions; MFA is an Azure AD feature, not a subscription-level setting. Option C is wrong because assigning MFA per user is not centrally managed and does not scale to apply to all subscriptions automatically; it also lacks the granularity of Conditional Access policies. Option D is wrong because Azure Policy is used for resource compliance (e.g., tagging, encryption) and cannot enforce MFA, which is an identity-level control managed by Azure AD.

569
MCQmedium

A cloud architect is designing a deployment strategy for a web application that must handle unpredictable traffic spikes. The application runs in containers on a Kubernetes cluster. The architect wants to minimize costs while ensuring that the cluster can scale out rapidly during spikes. Which deployment strategy best meets these requirements?

A.Pre-provision a fixed number of pods to handle peak load at all times.
B.Manually scale the deployment when monitoring alerts indicate high traffic.
C.Implement horizontal pod autoscaling based on CPU utilization.
D.Use vertical pod autoscaling to increase resource limits on existing pods.
AnswerC

Horizontal pod autoscaling adds or removes pod replicas based on CPU utilisation, matching capacity to demand so the cluster scales out rapidly during spikes and shrinks afterwards. This pay-for-what-you-use elasticity minimises cost compared with over-provisioning static nodes.

Why this answer

Horizontal Pod Autoscaling (HPA) automatically adjusts the number of pod replicas based on observed CPU utilization (or custom metrics), enabling rapid scale-out during traffic spikes without manual intervention. This minimizes costs by running only the necessary pods during low traffic while ensuring the cluster can react quickly to increased demand, which aligns with the requirement for unpredictable spikes.

Exam trap

CompTIA often tests the distinction between horizontal and vertical scaling in the context of cost and rapid elasticity; the trap here is that candidates may choose vertical autoscaling (Option D) thinking it is cheaper, but it cannot scale out quickly enough for unpredictable spikes and is limited by node resources.

How to eliminate wrong answers

Option A is wrong because pre-provisioning a fixed number of pods to handle peak load at all times results in over-provisioning and higher costs, as resources are wasted during low-traffic periods. Option B is wrong because manually scaling the deployment when monitoring alerts indicate high traffic introduces latency and cannot react quickly enough to unpredictable spikes, risking performance degradation. Option D is wrong because vertical pod autoscaling increases resource limits on existing pods, which does not provide rapid scale-out; it is limited by node capacity and cannot handle sudden traffic surges as effectively as adding more pod replicas.

570
MCQmedium

A DevOps team wants to deploy a containerized application to a Kubernetes cluster with zero downtime. The team needs to gradually shift traffic from the old version to the new version, monitoring error rates and automatically rolling back if errors exceed a threshold. Which deployment strategy should the team implement?

A.Blue/green deployment
B.Rolling deployment
C.Recreate deployment
D.Canary deployment
AnswerD

Canary deployment routes a small percentage of traffic to the new version first, then gradually shifts the remainder while monitoring error rates. If errors exceed the threshold, traffic reverts to the old version, delivering the gradual shift, monitoring and automatic rollback the team requires.

Why this answer

Canary deployment is correct because it introduces the new version to a small subset of users/traffic first, allowing the team to monitor error rates and metrics in production before progressively shifting more traffic. If error thresholds are breached, traffic can be instantly routed back to the stable version, achieving zero-downtime with automated rollback. This matches the requirement for gradual traffic shifting with monitoring and automatic rollback.

Exam trap

The trap here is confusing rolling deployment with canary deployment — both are gradual, but only canary provides percentage-based traffic control with automated metric-driven rollback, which is what the question explicitly requires.

How to eliminate wrong answers

Option A is wrong because blue/green deployment switches all traffic at once between two identical environments, which does not provide gradual traffic shifting or fine-grained monitoring of a small user subset before full cutover. Option B is wrong because rolling deployment replaces pods incrementally but does not offer precise traffic-percentage control or the ability to route a defined slice of users to the new version for canary-style metric comparison. Option C is wrong because recreate deployment tears down the old version before starting the new one, causing downtime and offering no rollback automation.

571
MCQhard

A company uses Google Cloud Platform (GCP) and wants to enforce that all service accounts used by applications have only the permissions necessary to perform their tasks. Which IAM concept should the administrator apply?

A.Separation of duties
B.Privileged access management (PAM)
C.Role-based access control (RBAC)
D.Least privilege
AnswerD

Least privilege grants each service account only the IAM roles its task requires, nothing broader. Applied through predefined or custom roles on GCP, it directly satisfies the stem's constraint that service accounts hold only the permissions necessary for their work.

Why this answer

The principle of least privilege dictates granting only the required permissions. In GCP, this is achieved by assigning predefined roles that are narrowly scoped to specific services, and by using conditions to further restrict access.

572
MCQeasy

A cloud engineer is configuring a web application on AWS and needs to ensure that only HTTP and HTTPS traffic from the internet is allowed to reach the EC2 instances. Which AWS service should be used to control inbound traffic at the instance level?

A.Security Group
B.AWS Shield
C.AWS WAF
D.Network ACL
AnswerA

Security groups are stateful virtual firewalls attached directly to EC2 elastic network interfaces, so rules are evaluated per instance rather than per subnet. Allowing only TCP ports 80 and 443 inbound satisfies the instance-level constraint, with return traffic automatically permitted regardless of outbound rules.

Why this answer

Security groups are stateful virtual firewalls that control inbound and outbound traffic at the instance level. Network ACLs operate at the subnet level and are stateless.

573
MCQmedium

A cloud architect is designing an auto-scaling policy for a web application. The application's traffic spikes predictably every weekday at 9 AM and decreases after 5 PM. Which scaling policy is most cost-effective?

A.Step scaling policy that adds instances when CPU > 70%
B.Simple scaling policy with a cooldown of 300 seconds
C.Scheduled scaling policy that increases capacity at 8:45 AM and decreases at 5:15 PM
D.Target tracking policy with a target CPU of 50%
AnswerC

Scheduled scaling provisions capacity at fixed times, matching the predictable weekday 9 AM spike and 5 PM decline without relying on reactive metrics. This avoids over-provisioning during known idle periods, directly satisfying the cost-effectiveness constraint in the stem.

Why this answer

Scheduled scaling is designed for predictable, time-based traffic patterns. Scaling up at 8:45 AM and down at 5:15 PM pre-provisions capacity before the 9 AM spike and removes it after the 5 PM decline, avoiding the lag and over-provisioning inherent in reactive policies. This is the most cost-effective approach for a known weekly pattern.

Exam trap

CV0-004 often tests the misconception that target tracking is always best, when predictable time-based patterns are more cost-effectively handled by scheduled scaling.

How to eliminate wrong answers

Option A is wrong because step scaling reacts to CPU after the spike has already begun, causing latency during ramp-up and leaving capacity idle during predictable lulls. Option B is wrong because simple scaling with a cooldown is reactive and slow, and the 300-second cooldown can delay necessary scale-out during rapid morning ramps. Option D is wrong because target tracking, while effective for variable load, still reacts to metrics rather than anticipating the known 9 AM spike, so it over-provisions during the ramp and under-provisions briefly at onset.

574
MCQmedium

A company uses a public cloud PaaS service to run a custom application. They need to ensure the application can handle increased load without downtime. Which action should they take?

A.Deploy a load balancer in front of the application
B.Move to IaaS to gain more control over scaling
C.Configure auto-scaling for the PaaS service
D.Upgrade the underlying virtual machines manually
AnswerC

Configuring auto-scaling lets the PaaS platform add and remove compute instances automatically as demand rises, directly meeting the no-downtime requirement under increased load. Because the provider manages the underlying infrastructure, scaling occurs without manual intervention or service interruption, unlike vertical resizing, which typically needs a restart.

Why this answer

In a PaaS environment, the cloud provider manages the underlying infrastructure, so the customer cannot manually upgrade VMs. Auto-scaling is a built-in feature of many PaaS services that automatically adjusts resources based on demand, ensuring the application can handle increased load without downtime. This is the most appropriate action.

Exam trap

The trap is thinking that manual VM upgrades or moving to IaaS are necessary for scaling, when in fact PaaS provides auto-scaling as a managed feature.

How to eliminate wrong answers

Option A is wrong because while a load balancer can distribute traffic, it does not automatically scale resources; auto-scaling is needed to handle increased load. Option B is wrong because moving to IaaS would require the company to manage scaling themselves, which is not the goal. Option D is wrong because in PaaS, the underlying VMs are managed by the provider and cannot be manually upgraded by the customer.

575
Multi-Selectmedium

Which TWO of the following are benefits of a multi-cloud strategy? (Select exactly two.)

Select 2 answers
A.Reduces data transfer costs
B.Ensures regulatory compliance in all regions
C.Avoids vendor lock-in
D.Improves disaster recovery by allowing failover across providers
E.Simplifies management by using a single cloud provider
AnswersC, D

Using multiple providers reduces dependence on one vendor's proprietary services, pricing and roadmap, so workloads can be moved or rebalanced. This directly addresses the lock-in constraint by keeping architectures portable across providers rather than tied to a single platform's APIs.

Why this answer

Option C is correct because a multi-cloud strategy spreads workloads across two or more independent providers (e.g., AWS, Azure, GCP), so applications are not tied to one vendor's proprietary APIs, services, or pricing model, which reduces vendor lock-in and increases negotiating leverage. Option D is correct because running workloads on multiple providers enables cross-provider failover: if one cloud's region or service suffers an outage, traffic and workloads can be redirected to another provider, improving resilience and disaster recovery beyond what a single provider's multi-AZ or multi-region setup offers. Option A is not necessarily true — data transfer costs often increase in multi-cloud architectures because egress fees apply when moving data between providers.

Option B is not guaranteed — regulatory compliance depends on configuring each provider's regions, data residency, and controls correctly, not merely on adopting multi-cloud. Option E is incorrect because multi-cloud actually complicates management by requiring separate tools, IAM models, and operational processes for each provider.

Exam trap

The CompTIA Cloud+ exam often tests the misconception that multi-cloud reduces costs or simplifies management, when in reality it increases complexity and data transfer expenses, while the primary benefits are avoiding vendor lock-in and improving disaster recovery resilience.

576
MCQhard

A cloud engineer is responsible for a set of Amazon EC2 instances that run a stateless web application. The engineer must ensure that the application can automatically recover from instance-level failures and that new instances are launched in multiple Availability Zones to maintain high availability. Which combination of AWS services should the engineer use?

A.An Auto Scaling group with a launch template and an Application Load Balancer
B.An Auto Scaling group with a launch template and a Network Load Balancer
C.An EC2 Auto Recovery alarm and a Network Load Balancer
D.A placement group with a spread strategy and an Application Load Balancer
AnswerA

An Auto Scaling group with a launch template can span multiple Availability Zones, automatically replacing unhealthy instances and launching new ones to meet demand. An Application Load Balancer operates at Layer 7, supports HTTP/HTTPS health checks, and can route traffic based on path or host. Together, they provide automatic recovery and high availability for a stateless web application, directly satisfying the engineer's requirements.

Why this answer

The engineer needs both automatic instance recovery and multi-AZ high availability. An Auto Scaling group with a launch template automatically replaces unhealthy instances and can launch instances across multiple Availability Zones. An Application Load Balancer performs HTTP/HTTPS health checks and distributes traffic only to healthy instances.

Together they provide the required resilience and availability for the stateless web application.

Exam trap

The trap here is confusing EC2 Auto Recovery, which recovers a single impaired instance in place, with an Auto Scaling group that replaces instances and scales across Availability Zones.

577
MCQmedium

A security administrator is configuring a web application firewall (WAF) to protect against SQL injection attacks. Which WAF feature should be enabled?

A.Geo-blocking
B.Rate limiting
C.OWASP rule set
D.DDoS protection
AnswerC

The OWASP rule set supplies preconfigured signatures that detect and block SQL injection patterns in inbound requests, directly satisfying the requirement to protect the web application. Unlike generic rate limiting or IP reputation, these rules inspect payload syntax against known injection techniques, so enabling the OWASP core rule set on the WAF mitigates the attack class named in the stem.

Why this answer

The OWASP rule set (also called OWASP Core Rule Set, CRS) is a collection of generic attack detection rules specifically designed to protect web applications against the OWASP Top 10, including SQL injection, cross-site scripting, and command injection. Enabling it on a WAF provides immediate, well-tested signatures for SQLi patterns. This directly addresses the requirement to protect against SQL injection.

Exam trap

CV0-004 often tests WAF feature selection, and the trap is choosing rate limiting or geo-blocking because they sound like security controls, when only the OWASP rule set actually inspects request payloads for SQL injection patterns.

How to eliminate wrong answers

Option A is wrong because geo-blocking restricts traffic based on geographic origin and does nothing to detect or block SQL injection payloads in HTTP requests. Option B is wrong because rate limiting controls request volume to mitigate brute-force or DoS attacks but does not inspect request content for SQLi syntax. Option D is wrong because DDoS protection mitigates volumetric and protocol-layer attacks, not application-layer injection attacks like SQLi.

578
Multi-Selectmedium

A company is migrating a legacy stateful application to the cloud. The application currently runs on a single server and stores session data locally. To enable horizontal scaling, which two design changes should the architect recommend? (Select TWO.)

Select 2 answers
A.Add more storage to the existing instance
B.Implement sticky sessions on the load balancer
C.Move session state to a shared database or cache
D.Use a larger instance type for the application server
E.Refactor the application to be stateless
AnswersC, E

Moving session state to a shared database or cache externalises it from individual instances, so any server behind the load balancer can serve any request. This directly satisfies the horizontal scaling requirement, since locally stored sessions would otherwise pin users to one server and break scaling.

Why this answer

Option C is correct because moving session state to a shared database or cache (e.g., Redis, Memcached, or DynamoDB) externalizes the state so any instance behind the load balancer can serve any request, which is essential for horizontal scaling. Option E is correct because refactoring the application to be stateless removes local session dependencies entirely, allowing instances to be added or removed freely and making the tier truly horizontally scalable. Options A and D are incorrect because adding storage or using a larger instance are vertical scaling approaches that do not enable horizontal scaling and leave the stateful single-server bottleneck in place.

Option B is incorrect because sticky sessions only pin a client to one instance, which preserves the stateful coupling, can cause uneven load, and does not solve the underlying need to share or eliminate session state.

Exam trap

The trap is treating sticky sessions as a scaling solution — they preserve session continuity but actually inhibit horizontal scaling and are the opposite of the stateless design the question is asking for.

579
MCQmedium

An organization uses multiple cloud providers and wants to centralize secrets management. Which solution would best meet this requirement?

A.Azure Key Vault
B.AWS Secrets Manager
C.HashiCorp Vault
D.Google Cloud Secret Manager
AnswerC

HashiCorp Vault is cloud-agnostic, running centrally to issue and audit secrets across AWS, Azure and Google Cloud through one API. This satisfies the multi-cloud centralisation constraint, whereas native secret managers such as Azure Key Vault remain scoped to their own provider.

Why this answer

HashiCorp Vault is a multi-cloud secrets management solution that can store and rotate secrets across different providers.

580
MCQeasy

A cloud architect is designing a serverless application on AWS Lambda. The function needs to process messages from an SQS queue. Which event trigger should be configured for the Lambda function?

A.API Gateway
B.SQS trigger
C.S3 bucket event
D.EventBridge rule
AnswerB

An SQS trigger uses event source mapping, letting Lambda poll the queue and invoke the function with batched messages. This pull-based integration handles scaling and failed-message handling natively, matching the requirement to process queue messages.

Why this answer

AWS Lambda can be triggered by SQS messages. By configuring an SQS trigger, Lambda automatically polls the queue and invokes the function with each message.

581
MCQmedium

An organization uses a cloud-based monitoring service to track CPU utilization across a fleet of virtual machines. The administrator notices that one VM consistently shows 100% CPU utilization at the same time each day. Which of the following should the administrator do NEXT?

A.Add the VM to an auto scaling group to distribute the load
B.Immediately increase the VM size to accommodate the peak
C.Check the VM's local task scheduler for any jobs running during the peak times
D.Scan the VM for malware that might be causing the activity
AnswerC

A repeating daily 100% CPU spike at a fixed time points to a scheduled workload rather than organic demand. Inspecting the VM's local task scheduler identifies recurring jobs triggering the load, confirming the cause before any capacity or monitoring changes are made.

Why this answer

The consistent daily spike in CPU utilization at the same time strongly suggests a scheduled task or cron job is triggering the load. Checking the VM's local task scheduler (e.g., Task Scheduler on Windows or cron on Linux) is the logical first step to identify the specific process causing the spike before taking any remediation actions.

Exam trap

The trap here is that candidates may jump to scaling or security responses (auto scaling, resizing, malware scan) without first performing basic troubleshooting to identify the predictable, recurring process causing the CPU spike.

How to eliminate wrong answers

Option A is wrong because adding the VM to an auto scaling group does not distribute the load within a single VM; auto scaling adds or removes instances horizontally, which would not address a local process consuming 100% CPU on one VM. Option B is wrong because immediately increasing the VM size (vertical scaling) is a reactive, costly approach that does not identify the root cause; the administrator should first investigate what is causing the spike. Option D is wrong because while malware can cause high CPU usage, the predictable daily pattern at the same time is more indicative of a scheduled job than malware, which typically exhibits random or persistent activity.

582
Multi-Selectmedium

A cloud operations team runs a three-tier application on Amazon EC2 instances behind an Application Load Balancer. During a peak-traffic event, users report intermittent 503 errors, and the operations team wants to automatically add capacity when the average CPU utilization of the Auto Scaling group exceeds 70 percent for five consecutive minutes, then remove capacity when it drops below 30 percent. Which TWO configuration elements must the team define to accomplish this? (Choose two.)

Select 2 answers
A.A second CloudWatch alarm that enters the ALARM state when CPU utilization is less than 30 percent for the same evaluation window.
B.An AWS Budgets alarm set to notify when EC2 spending exceeds 70 percent of the monthly forecast.
C.A CloudWatch alarm that enters the ALARM state when CPU utilization is greater than 70 percent for five consecutive evaluation periods.
D.An Application Load Balancer health check configured with a 70 percent healthy threshold.
E.A target tracking scaling policy attached to the Auto Scaling group with a target value of 70 percent.
AnswersA, C

Scale-in requires its own trigger because the threshold differs from scale-out. A separate CloudWatch alarm with a less-than-30-percent condition, evaluated over the same period, provides the discrete signal the Auto Scaling group needs to remove capacity only after utilization genuinely drops, matching the scenario's stated scale-in condition.

Why this answer

Dynamic scaling in an Auto Scaling group is driven by CloudWatch alarms that translate metric thresholds into scaling actions. Because the scenario specifies different thresholds for scaling out and scaling in, two separate alarms are needed: one for CPU above 70 percent and one for CPU below 30 percent, each evaluated over the stated five-minute window. Target tracking and budget alarms cannot express this asymmetric behavior.

Exam trap

The trap here is assuming a single target tracking policy can enforce two different thresholds, when target tracking maintains one target value and cannot express separate scale-out and scale-in conditions.

583
MCQmedium

A cloud architect is designing a containerized microservices platform for a retail company. The company requires that individual services scale independently, that failed containers be replaced automatically without manual intervention, and that the platform abstract away the underlying compute hosts. The operations team has limited experience with cluster management. Which cloud-native orchestration approach BEST meets these requirements?

A.Deploy the microservices to a managed Kubernetes service and define Deployments and Horizontal Pod Autoscalers.
B.Deploy each microservice on a dedicated virtual machine with an autoscaling group per service.
C.Package all microservices into a single monolithic container and run it on one large virtual machine.
D.Use serverless functions for every service and rely on the provider to manage all scaling and placement.
AnswerA

A managed Kubernetes service provides a control plane that schedules containers, restarts failed pods through the ReplicaSet controller, and abstracts the worker nodes. Horizontal Pod Autoscalers adjust replica counts per service based on metrics, so each microservice scales independently. Because the provider manages the control plane, the operations team's limited cluster expertise is less of an obstacle.

Why this answer

A managed Kubernetes service supplies the orchestration features the scenario demands: scheduling across hosts, self-healing of failed containers via controllers, and per-service scaling through Horizontal Pod Autoscalers. It also removes control-plane administration from a team lacking deep cluster skills. The other approaches either fail to abstract hosts, prevent independent scaling, or impose execution-model limits.

Exam trap

The trap here is assuming that autoscaling groups of virtual machines provide the same host abstraction and self-healing as a container orchestrator.

584
MCQmedium

A cloud administrator is responsible for a Microsoft Azure environment with a hub-and-spoke network topology. The administrator needs to ensure that all traffic from the spoke virtual networks to the internet is routed through a network virtual appliance (NVA) in the hub virtual network for inspection. Which Azure feature should the administrator configure?

A.Azure Private Link to connect the spokes to the hub
B.Virtual network peering with gateway transit enabled
C.User-defined routes (UDRs) on the spoke subnets pointing to the NVA's private IP address
D.Azure Firewall in the hub virtual network with forced tunneling
AnswerC

User-defined routes allow the administrator to override Azure's default system routes. By creating a UDR on the spoke subnets with the next hop type set to 'Virtual appliance' and specifying the NVA's private IP address, all traffic destined for the internet or other networks can be forced through the NVA for inspection. This directly satisfies the requirement to route spoke traffic through the NVA in the hub.

Why this answer

To force traffic from spoke virtual networks through a network virtual appliance in the hub, the administrator must configure user-defined routes on the spoke subnets. The UDR sets the next hop type to 'Virtual appliance' and specifies the NVA's private IP address. This overrides Azure's default system routes and ensures traffic is sent to the NVA for inspection before reaching the internet.

Exam trap

The trap here is assuming that virtual network peering or Azure Firewall automatically routes traffic through an NVA, when in fact user-defined routes are required to override default routing.

585
MCQeasy

A cloud administrator needs to centrally collect, search, and retain application and system logs from hundreds of Amazon EC2 instances and AWS services for troubleshooting and compliance. The administrator wants a managed service that stores logs in durable storage and allows ad hoc queries using a query language. Which AWS service should the administrator use?

A.AWS CloudTrail
B.AWS Trusted Advisor
C.AWS Config
D.Amazon CloudWatch Logs
AnswerD

Amazon CloudWatch Logs is a managed service that ingests log data from EC2 instances via the CloudWatch agent, from AWS services, and from custom sources. It stores logs durably in log groups and supports querying with CloudWatch Logs Insights, a query language for searching and analyzing log events, which matches the central collection and ad hoc query requirements.

Why this answer

Amazon CloudWatch Logs is the managed AWS service for centralizing log data from EC2 instances and AWS services. The CloudWatch agent ships instance logs to log groups, and CloudWatch Logs Insights provides a purpose-built query language to search and analyze events. CloudTrail captures API activity, Config tracks resource configuration, and Trusted Advisor offers recommendations, none of which provide general log ingestion and querying.

Exam trap

The trap here is confusing CloudTrail, which records API calls for auditing, with a service that ingests and queries application and operating system logs.

586
Multi-Selectmedium

A cloud operations team is setting up log-based alerting for security events. They want to use structured logging to facilitate querying. Which TWO practices support effective log-based alerting? (Choose TWO.)

Select 2 answers
A.Enable verbose logging for all services
B.Centralize logs in a log management system
C.Use random log formats for different applications
D.Send all logs to syslog servers
E.Output logs in JSON format
AnswersB, E

Centralising logs in a log management system aggregates entries from all sources into one queryable store, enabling correlation and consistent alert rules across services. Without centralisation, security events scattered across hosts cannot be searched or alerted on reliably, undermining structured log-based detection.

Why this answer

Option B is correct because centralizing logs in a log management system (such as a SIEM, ELK/Elasticsearch, or cloud-native service like CloudWatch Logs or Cloud Logging) aggregates events from multiple sources into one queryable store, which is essential for correlating security events and defining alert rules across services. Option E is correct because outputting logs in JSON format produces structured, machine-parseable records with consistent key-value fields, enabling precise queries and filters (e.g., level:ERROR AND event:login_failure) that drive reliable log-based alerts. Option A is not appropriate because enabling verbose logging for all services generates excessive noise and cost, obscuring the security events that alerts should target.

Option C is wrong because random, inconsistent log formats break parsing and make querying and alerting unreliable. Option D is not the best practice here because blindly sending all logs to syslog servers lacks the structured, centralized querying and alerting capabilities required, and syslog alone does not provide the structured format needed for effective log-based alerting.

Exam trap

CV0-004 often tests the confusion between logging volume and logging quality, tempting candidates to choose 'verbose logging' or 'random formats' when the exam expects recognition that structured, centralized logs are what enable effective alerting.

587
MCQmedium

A cloud load balancer is not distributing traffic evenly to backend servers. All servers pass health checks. Which of the following is the most likely cause?

A.The health check interval is set too long.
B.One of the backend servers has reached its connection limit.
C.Session persistence is enabled and directing traffic to specific servers.
D.The health check path is incorrect.
AnswerC

Session persistence pins each client to the backend that first served it, so subsequent requests bypass normal distribution algorithms. With all servers healthy, this stickiness explains the uneven spread described in the stem rather than any health-check or capacity issue.

Why this answer

Session persistence (sticky sessions) binds a client to a specific backend server for the duration of a session, typically via a cookie or source IP hash. When enabled, the load balancer deliberately routes repeat requests from the same client to the same backend, which skews the distribution and makes traffic appear uneven even though all servers are healthy. This is the most likely cause because the scenario explicitly states all servers pass health checks, ruling out availability-based causes.

Exam trap

CV0-004 often tests the misconception that uneven distribution always indicates a backend problem; candidates overlook that session persistence is a deliberate configuration that intentionally skews traffic, and the 'all servers pass health checks' clue is the key differentiator.

How to eliminate wrong answers

Option A is wrong because the health check interval only controls how frequently the load balancer probes backend health — it does not influence how traffic is distributed among healthy servers. Option B is wrong because if a backend server had reached its connection limit, it would typically fail health checks or be marked unhealthy, contradicting the premise that all servers pass health checks; connection limits affect capacity, not the balancing algorithm's distribution logic. Option D is wrong because an incorrect health check path would cause health checks to fail, marking servers unhealthy — again contradicting the stated condition that all servers pass health checks.

588
MCQeasy

A cloud administrator notices that a storage bucket in a cloud object storage service is publicly accessible. The bucket contains sensitive customer data. What is the most likely cause of this issue?

A.The bucket policy or ACL was set to allow public access.
B.The bucket has versioning enabled.
C.The bucket has a lifecycle policy to transition objects to archival storage.
D.The bucket is using server-side encryption with customer-provided keys.
AnswerA

Public accessibility arises when the bucket policy or object ACL grants read permission to AllUsers or AuthenticatedUsers. That explicit grant overrides default private settings, exposing the sensitive customer data. Misconfigured permissions, not encryption or versioning, are the direct cause of anonymous access.

Why this answer

The most likely cause is that the bucket policy or ACL was misconfigured to allow public access. Option A correctly identifies this. Option B is incorrect because versioning does not affect access permissions.

Option C is incorrect because lifecycle policies manage object transitions, not access. Option D is incorrect because server-side encryption does not control public access.

589
MCQhard

A cloud administrator runs the `iostat` command on a Linux VM experiencing slow performance. Based on the exhibit, what is the most likely bottleneck?

A.Disk I/O is saturated.
B.Network bandwidth is limited.
C.CPU is overloaded.
D.Memory is insufficient.
AnswerA

High %util with elevated await and queue depth on the device confirms the disk subsystem is saturated, so requests queue faster than they complete. This matches the slow VM symptom, since CPU and memory metrics remain normal while I/O wait dominates.

Why this answer

The `iostat` command reports CPU and I/O statistics. The exhibit shows high `%util` (e.g., 99.9%) and elevated `await` or `svctm` values, indicating that the disk device is operating at or near its maximum capacity. This means the disk I/O subsystem is saturated, causing requests to queue and slowing overall VM performance.

Exam trap

The trap here is that candidates may misinterpret high `%util` as a CPU bottleneck because `iostat` also displays CPU stats, but the question specifically asks about the bottleneck indicated by the exhibit, which clearly points to disk I/O saturation.

How to eliminate wrong answers

Option B is wrong because `iostat` does not measure network bandwidth; network issues would be diagnosed with tools like `netstat`, `ss`, or `iperf`. Option C is wrong because `iostat` shows CPU statistics (e.g., `%user`, `%system`), and if the CPU were overloaded, those values would be high while disk `%util` might remain low; the exhibit indicates disk saturation, not CPU exhaustion. Option D is wrong because insufficient memory would manifest as high swap usage or out-of-memory (OOM) events, not as high disk `%util`; memory issues are diagnosed with `free`, `vmstat`, or `top`.

590
MCQmedium

A cloud engineer is sizing a relational database for an application with unpredictable read volume that spikes sharply during business hours. The database must scale read capacity without downtime and without changing the application's connection string. Which approach should the engineer use?

A.Vertically scale the primary database instance to a larger size during peak hours.
B.Enable a multi-AZ standby and direct read queries to the standby instance.
C.Add read replicas behind a database-aware proxy or reader endpoint so reads are distributed across replicas.
D.Increase the database's storage volume size to improve read throughput.
AnswerC

Read replicas offload read traffic from the primary and can be added or removed while the database stays online. A reader endpoint or proxy presents a stable address, so the application keeps the same connection string while read capacity scales horizontally. This directly addresses unpredictable read spikes without downtime or application changes.

Why this answer

Read replicas let a relational database scale read capacity horizontally while the primary continues handling writes. Because replicas can be added or removed online and a reader endpoint or proxy keeps a stable address, the application does not need a new connection string and experiences no downtime during scaling.

Exam trap

The trap here is confusing a multi-AZ standby, which is passive and used only for failover, with a read replica, which actively serves read queries.

591
Multi-Selectmedium

A cloud engineer is planning a database migration from an on-premises Oracle database to Amazon RDS for PostgreSQL. The migration must minimize downtime and preserve ongoing changes. Which TWO services should the engineer consider using together? (Choose two.)

Select 2 answers
A.AWS DataSync
B.AWS Snowball
C.AWS Database Migration Service (DMS)
D.Amazon S3 Transfer Acceleration
E.AWS Schema Conversion Tool (SCT)
AnswersC, E

AWS DMS performs the actual data migration and continuous replication, capturing ongoing changes from the source Oracle database so the target stays synchronised. This change data capture capability minimises downtime during cutover to Amazon RDS for PostgreSQL.

Why this answer

Option C, AWS Database Migration Service (DMS), is correct because DMS is purpose-built for migrating databases to AWS with minimal downtime, supporting ongoing replication (change data capture) from the source Oracle database to the target RDS for PostgreSQL so that changes made during the migration are continuously applied. Option E, AWS Schema Conversion Tool (SCT), is correct because migrating from Oracle to PostgreSQL involves heterogeneous engine conversion, and SCT automatically converts the source schema, stored procedures, and other database objects into a PostgreSQL-compatible format that DMS can then use for the data migration. The unmarked options do not belong: AWS DataSync (A) is for transferring file and object data, not for database replication; AWS Snowball (B) is a physical device for bulk offline data transfer; and Amazon S3 Transfer Acceleration (D) only speeds up uploads to S3 and has no role in database migration or schema conversion.

592
MCQeasy

A cloud administrator wants to troubleshoot network connectivity issues between two VPCs. Which AWS feature provides detailed logs of IP traffic for analysis?

A.AWS CloudTrail
B.VPC Route Tables
C.AWS CloudWatch Logs
D.VPC Flow Logs
AnswerD

VPC Flow Logs capture accepted and rejected IP traffic metadata for elastic network interfaces, subnets or VPCs, including source, destination, port and action. Publishing them to CloudWatch Logs or S3 satisfies the troubleshooting requirement, since the records reveal whether traffic between the two VPCs is reaching its destination.

Why this answer

VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, action) for network interfaces in a VPC, and can be published to CloudWatch Logs or S3 for analysis. This is the specific AWS feature designed for troubleshooting connectivity and analyzing traffic patterns at the network layer.

Exam trap

CV0-004 often tests the confusion between CloudTrail (API auditing) and VPC Flow Logs (network traffic), causing candidates to pick CloudTrail when the question asks about IP traffic analysis.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and management events, not IP traffic; it cannot show packet-level connectivity issues. Option B is wrong because VPC Route Tables define routing paths but do not log traffic; they are configuration objects, not diagnostic logs. Option C is wrong because AWS CloudWatch Logs is a log storage/analysis service, not a traffic capture feature; it can receive Flow Logs but does not generate them itself.

593
MCQmedium

A company wants to optimize cloud costs by identifying underutilized EC2 instances. Which AWS service provides rightsizing recommendations?

A.AWS Trusted Advisor
B.AWS Cost Explorer
C.AWS Budgets
D.AWS Compute Optimizer
AnswerD

AWS Compute Optimizer analyses CloudWatch metrics and resource configuration to generate rightsizing recommendations for EC2 instances, identifying over-provisioned or underutilised capacity. This directly satisfies the goal of finding underutilised instances, unlike billing or inventory tools that only report spend.

Why this answer

AWS Compute Optimizer is the dedicated service that analyzes historical utilization metrics (CPU, memory, network, disk) from CloudWatch to generate rightsizing recommendations for EC2 instances, Auto Scaling groups, EBS volumes, and Lambda functions. It uses machine learning to identify over-provisioned or under-provisioned resources and provides specific instance type recommendations. Unlike other cost tools, Compute Optimizer is purpose-built for resource optimization and rightsizing, making it the correct choice for identifying underutilized EC2 instances.

Exam trap

CV0-004 often tests the distinction between cost visibility tools (Cost Explorer, Budgets) and cost optimization tools (Compute Optimizer, Trusted Advisor), so candidates must remember that only Compute Optimizer provides detailed rightsizing recommendations for EC2.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides best-practice checks across cost, security, fault tolerance, performance, and service limits, but its cost optimization checks are high-level (e.g., idle load balancers, unassociated Elastic IPs) and do not generate detailed rightsizing recommendations for EC2 instances. Option B is wrong because AWS Cost Explorer is a cost visualization and analysis tool that shows spending trends and forecasts, but it does not provide rightsizing recommendations; it may show cost anomalies but not specific instance type changes. Option C is wrong because AWS Budgets is used to set custom cost and usage budgets and receive alerts when thresholds are exceeded, but it does not analyze resource utilization or recommend rightsizing actions.

594
Multi-Selectmedium

Which TWO factors should be considered when choosing a cloud deployment model (public, private, hybrid)? (Select TWO.)

Select 2 answers
A.Number of monitors connected to the server
B.Data sensitivity and classification
C.Compliance requirements (e.g., GDPR, HIPAA)
D.Brand of physical servers used
E.Color of server racks in the data center
AnswersB, C

Data sensitivity and classification directly constrain where workloads may reside, since regulated or confidential data often mandates private or hybrid placement rather than public multitenancy. Classification therefore determines the deployment model's compliance boundary, satisfying the stem's requirement to weigh factors shaping the public, private or hybrid choice.

Why this answer

Option B (Data sensitivity and classification) is correct because the sensitivity of the data directly drives the choice of deployment model — highly sensitive or regulated data may require a private or hybrid model to keep it under organizational control, while less sensitive workloads can run in a public cloud. Option C (Compliance requirements such as GDPR, HIPAA) is correct because legal and regulatory mandates dictate where data may reside and how it must be protected, often forcing private or hybrid deployments to satisfy data-residency, audit, and security obligations. In contrast, option A (number of monitors connected to the server) is irrelevant, as display peripherals have no bearing on cloud deployment architecture.

Option D (brand of physical servers) does not determine the deployment model, since public, private, and hybrid clouds can all be built on various hardware vendors. Option E (color of server racks) is purely cosmetic and has no technical or compliance impact on deployment model selection.

Exam trap

CompTIA often tests the misconception that physical hardware attributes (brand, color, monitor count) influence cloud deployment decisions, when in fact the choice is driven solely by data governance, compliance, and operational requirements.

595
Matchingmedium

Match each high-availability concept to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Distribute traffic across multiple servers

Isolated location within a region

One node active, one standby

All nodes serve traffic simultaneously

Why these pairings

Correct matches: Failover (auto-switch to standby), Load Balancing (distribute workload), Clustering (group as one system), Redundancy (duplicate components). Common confusions: swapping failover and load balancing definitions.

596
MCQmedium

A cloud administrator needs to apply security patches to a fleet of 50 Linux servers running on AWS without interrupting business hours. Which approach should the administrator use to schedule patching during a maintenance window?

A.Use AWS Systems Manager Patch Manager with a maintenance window
B.Create a Lambda function that stops instances, patches them, and restarts
C.Manually SSH into each server and run yum update
D.Use AWS Config to apply patch baselines
AnswerA

AWS Systems Manager Patch Manager with a maintenance window satisfies the no-business-hours constraint by targeting the 50 Linux instances via tags and running patch baselines only within a defined schedule, using an IAM service role rather than SSH. This avoids manual intervention and prevents patching outside the approved window.

Why this answer

AWS Systems Manager Patch Manager is designed to automate the process of patching fleets of instances. It integrates with Maintenance Windows, allowing administrators to define a schedule (e.g., outside business hours) during which patching tasks run. This approach is scalable, auditable, and does not require manual intervention or custom scripting, making it the correct choice for patching 50 Linux servers without interrupting business hours.

Exam trap

CV0-004 often tests the misconception that AWS Config can enforce or apply patches, when it only assesses compliance; candidates may confuse Config's role with Patch Manager's active patching capabilities.

How to eliminate wrong answers

Option B is wrong because creating a Lambda function to stop, patch, and restart instances is a custom, error-prone solution that lacks built-in patch compliance reporting and scheduling; stopping instances causes downtime and patching offline instances is inefficient. Option C is wrong because manually SSHing into each server and running yum update is not scalable, lacks scheduling, and is prone to human error, plus it doesn't guarantee patching during a maintenance window. Option D is wrong because AWS Config is a configuration assessment service, not a patching tool; it can detect patch compliance but cannot apply patches or schedule patching.

597
MCQeasy

An organization wants to audit all API calls made in their AWS account. Which AWS service should be enabled to capture these logs?

A.Amazon CloudWatch
B.AWS Trusted Advisor
C.AWS CloudTrail
D.AWS Config
AnswerC

CloudTrail records API activity in an AWS account, capturing the identity of the caller, timestamp, source IP and request parameters for every call. Enabling it satisfies the requirement to audit all API calls, since CloudWatch monitors metrics and Config tracks resource state rather than API events.

Why this answer

AWS CloudTrail records API activity for governance, compliance, and auditing.

598
MCQmedium

A cloud architect is designing a landing zone in AWS Organizations. The security team mandates that all member accounts must centrally log API activity and that individual account administrators must not be able to disable or alter the log destination. The architect needs to enforce this across every current and future account with minimal operational overhead. Which combination of actions should the architect take?

A.Enable CloudTrail in each member account individually, and use AWS Config rules to detect when a trail is stopped so the security team can be notified.
B.Enable AWS CloudTrail Lake in the management account and configure an event data store that ingests events from all member accounts through a resource-based policy.
C.Create an organization trail in CloudTrail from the management account with an S3 bucket in a dedicated log archive account, and attach a service control policy (SCP) denying cloudtrail:StopLogging and cloudtrail:DeleteTrail to all member accounts.
D.Configure AWS Control Tower with a detective guardrail that monitors CloudTrail configuration drift and sends findings to Security Hub for remediation.
AnswerC

An organization trail automatically applies to all accounts in the organization, including accounts added later, and delivers events to a central S3 bucket. The SCP then removes the ability of member account principals to stop or delete the trail, satisfying the tamper-resistance requirement without per-account configuration.

Why this answer

Centralized, tamper-resistant logging across an entire AWS Organization is achieved with an organization trail created from the management account that delivers to a log archive account, combined with an SCP that denies the trail-stopping and trail-deletion actions to member accounts. This design automatically covers future accounts and prevents local administrators from disabling logging.

Exam trap

The trap here is assuming that a detective control such as AWS Config or Control Tower guardrails prevents an account administrator from stopping logging, when only a preventive control like an SCP actually blocks the action.

599
MCQmedium

A DevOps team sets up a CI/CD pipeline for a containerized application on Kubernetes. They want to test a new version with a small subset of users before full rollout. Which deployment method should they use?

A.Canary
B.Recreate
C.Rolling update
D.Blue/green
AnswerA

Canary releases route a small percentage of live traffic to the new container version while the majority still hits the stable version, enabling validation with real users before full rollout. Blue-green would shift all traffic at once, failing the small-subset requirement.

Why this answer

A canary deployment releases the new version to a small subset of users (e.g., 5-10% of traffic) while the rest continue using the stable version. This allows the team to monitor performance, errors, and user feedback before gradually increasing the rollout. Kubernetes supports canary deployments natively through techniques like multiple Deployments with shared labels and service mesh traffic splitting (e.g., Istio or Linkerd).

Exam trap

CompTIA often tests the distinction between canary and rolling update by implying that rolling updates can also target a subset of users, but rolling updates replace pods gradually across the entire cluster without user-based traffic splitting.

How to eliminate wrong answers

Option B (Recreate) is wrong because it terminates all existing pods before creating new ones, causing full downtime and no ability to test with a subset of users. Option C (Rolling update) is wrong because it gradually replaces pods but does not allow fine-grained traffic splitting to a specific user subset; all users eventually receive the new version during the update. Option D (Blue/green) is wrong because it runs two full environments and switches all traffic at once, which does not provide a gradual, user-subset testing phase.

600
MCQmedium

A cloud operations team runs a three-tier web application on AWS. During a recent incident, the on-call engineer received hundreds of Amazon CloudWatch alarms within minutes and could not identify the root cause. The team wants to reduce alarm fatigue while still capturing meaningful signals. Which action should the team take FIRST?

A.Increase each alarm's evaluation period from 1 minute to 60 minutes so that fewer state transitions occur during an incident.
B.Delete all metric alarms and rely solely on AWS Health Dashboard notifications for operational awareness.
C.Configure the SNS topic to buffer notifications and deliver them as a single daily digest email to the operations team.
D.Create composite alarms that combine related metric and state alarms using AND/OR logic, and route only the composite alarm to the notification topic.
AnswerD

Composite alarms evaluate the state of multiple child alarms and fire only when the Boolean expression is true, which directly suppresses the storm of individual notifications. Routing only the composite alarm to the SNS topic means the on-call engineer receives one actionable alert that represents the correlated condition, preserving the underlying child alarms for diagnostics.

Why this answer

Composite alarms exist specifically to reduce noise by evaluating multiple child alarms with Boolean operators and firing a single notification only when the combined condition is met. This preserves granular child alarms for troubleshooting while giving on-call engineers one correlated, actionable signal, which is the fastest way to reduce alarm fatigue without losing observability.

Exam trap

The trap here is assuming alarm fatigue is solved by slowing evaluation periods or batching notifications, when the actual mechanism is correlating multiple alarms into a single composite condition.

Page 7

Page 8 of 12

Page 9