Courseiva

CompTIA Cloud+ CV0-004 (CV0-004) — Questions 601–675

834 questions total · 12pages · All types, answers revealed

Page 8

Page 9 of 12

Page 10
601
MCQmedium

A company is deploying a containerized microservices application on a cloud platform. The operations team needs to manage secrets, such as database credentials and API keys, securely without embedding them in container images. Which solution should they use?

A.Include secrets in the container image at build time and encrypt the image
B.Use a cloud-native secrets management service to inject secrets at runtime
C.Encrypt secrets and store them in a cloud storage bucket
D.Store secrets as environment variables in the container orchestration platform
AnswerB

A cloud-native secrets management service stores credentials outside the image and injects them into containers at runtime, satisfying the requirement to avoid embedding secrets in images. This keeps secrets centralised, auditable and rotatable without rebuilding or redeploying container artefacts.

Why this answer

A cloud-native secrets management service (e.g., AWS Secrets Manager, GCP Secret Manager, Azure Key Vault) injects secrets at runtime via API calls or sidecar/mounted volumes, so credentials never live in the image or the orchestrator's static config. This enables rotation, fine-grained IAM access, and audit trails without rebuilding images when a credential changes.

Exam trap

CV0-004 often tests the misconception that encrypting an image or using environment variables is 'secure enough' — candidates pick environment variables because they are easy, ignoring that they are readable from the container runtime and logs.

How to eliminate wrong answers

Option A is wrong because baking secrets into the image at build time means anyone who pulls the image can extract them — encryption at rest does not protect secrets from a running container or a registry reader. Option C is wrong because storing encrypted secrets in a cloud storage bucket still requires the application to fetch and decrypt them, and it lacks rotation, versioning, and per-secret access control; it is essentially a DIY secrets store. Option D is wrong because environment variables in the orchestrator are visible via the container runtime (e.g., docker inspect, /proc/1/environ) and are often logged or exposed in crash dumps — they are not a secure secrets store.

602
MCQmedium

A company uses AWS and wants to optimize costs by receiving recommendations to downsize over-provisioned EC2 instances. Which tool provides rightsizing recommendations?

A.AWS Budgets
B.AWS Trusted Advisor
C.AWS Cost Explorer
D.AWS Compute Optimizer
AnswerD

AWS Compute Optimizer analyses CloudWatch metrics against instance families and returns rightsizing recommendations for over-provisioned EC2 instances, directly meeting the cost-optimisation requirement. Cost Explorer and Trusted Advisor do not produce instance-level downsizing guidance of this kind.

Why this answer

AWS Compute Optimizer is the service specifically designed to analyze resource utilization metrics (such as CPU, memory, network, and disk) and generate rightsizing recommendations for EC2 instances, Auto Scaling groups, EBS volumes, and Lambda functions. It uses machine learning to identify over-provisioned or under-provisioned resources and provides actionable recommendations to downsize or upsize, directly addressing the goal of cost optimization. Unlike other tools that focus on billing or budgets, Compute Optimizer delivers instance-type-level guidance based on actual usage patterns.

Exam trap

CV0-004 often tests the distinction between cost visibility tools (Cost Explorer, Budgets) and cost optimization recommendation engines (Compute Optimizer, Trusted Advisor), so candidates must remember that only Compute Optimizer provides detailed EC2 rightsizing recommendations based on utilization metrics.

How to eliminate wrong answers

Option A is wrong because AWS Budgets is used to set custom spending limits and receive alerts when costs or usage exceed thresholds, but it does not analyze resource utilization or provide instance rightsizing recommendations. Option B is wrong because AWS Trusted Advisor offers best-practice checks across cost optimization, security, fault tolerance, and performance, but its cost optimization checks are high-level (e.g., idle load balancers, unassociated Elastic IPs) and do not generate detailed EC2 rightsizing recommendations based on utilization metrics. Option C is wrong because AWS Cost Explorer visualizes and analyzes historical cost and usage data, allowing you to see spending trends and forecast costs, but it does not provide specific rightsizing recommendations for EC2 instances.

603
Matchingmedium

Match each acronym to its definition.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Software as a Service

Platform as a Service

Infrastructure as a Service

Function as a Service

Desktop as a Service

Why these pairings

IaaS, PaaS, SaaS, and FaaS are common cloud service models. IaaS provides virtualized hardware, PaaS provides a development platform, SaaS provides ready-to-use software, and FaaS provides event-driven code execution. Common confusions include swapping IaaS and PaaS definitions.

604
MCQeasy

A company has a policy that all cloud resources must be tagged with 'CostCenter' and 'Project' tags. The cloud operations team uses a monitoring tool to alert when untagged resources are created. The team receives an alert for a new EC2 instance that lacks the required tags. The instance was launched two hours ago by a DevOps engineer who is on leave. The instance is critical for production. What should the administrator do to resolve the compliance violation?

A.Terminate the instance immediately and launch a new one with proper tags.
B.Apply the required tags to the existing instance using the cloud provider's console or CLI.
C.Ignore the alert because the instance is critical and the engineer will fix it when back.
D.Modify the tag policy to exempt instances launched by senior engineers.
AnswerB

Applying the missing CostCenter and Project tags directly to the running EC2 instance via the console or CLI remediates the violation without disrupting the production workload. Tagging is a metadata operation on the resource, requiring no restart or redeployment, so the critical instance stays available while satisfying the policy's tagging requirement.

Why this answer

The compliance violation is the absence of required tags, not a problem with the instance itself. The administrator can use the AWS Management Console, CLI (e.g., `aws ec2 create-tags`), or SDK to apply the 'CostCenter' and 'Project' tags to the existing EC2 instance without disrupting its operation. This resolves the alert and maintains production continuity.

Exam trap

A common mistake is to assume that a compliance violation due to missing tags requires terminating and recreating the resource. In reality, tags can be applied to existing instances without disruption, as they are metadata.

How to eliminate wrong answers

Option A is wrong because terminating a critical production instance causes unnecessary downtime and data loss; tagging is a metadata operation that does not require recreation. Option C is wrong because ignoring the alert violates the company's tagging policy and leaves the resource non-compliant, which could affect cost allocation and auditing. Option D is wrong because modifying the policy to exempt certain users undermines the governance objective and sets a dangerous precedent; the policy should be enforced uniformly.

605
MCQmedium

An organization uses Azure and wants to ensure that only authenticated users from its on-premises Active Directory can access cloud resources. The company has Azure AD Connect set up and wants to enable single sign-on (SSO) for cloud applications. Which federation standard should be used?

A.Kerberos
B.OAuth 2.0
C.SAML
D.OpenID Connect
AnswerC

SAML is the federation standard that Microsoft Entra ID uses to exchange authentication assertions with cloud applications, enabling SSO for users synced from on-premises Active Directory via Azure AD Connect. It satisfies the requirement for authenticated on-premises users accessing cloud resources without separate credentials.

Why this answer

SAML (Security Assertion Markup Language) is the correct federation standard because it enables browser-based single sign-on (SSO) by exchanging authentication and authorization assertions between an identity provider (on-premises Active Directory via Azure AD Connect) and a service provider (cloud applications). SAML 2.0 is specifically designed for federated identity scenarios where users authenticate on-premises and gain access to cloud resources without re-entering credentials.

Exam trap

The trap here is that candidates confuse OAuth 2.0 or OpenID Connect as the default for all SSO scenarios, but the question specifically describes a traditional on-premises AD federation with browser-based cloud applications, which is the classic SAML use case.

How to eliminate wrong answers

Option A is wrong because Kerberos is a network authentication protocol that uses tickets and is designed for on-premises environments, not for federated SSO across cloud boundaries; it cannot pass assertions to cloud applications. Option B is wrong because OAuth 2.0 is an authorization framework, not an authentication protocol; it does not provide identity assertions or user authentication information by itself. Option D is wrong because OpenID Connect is built on top of OAuth 2.0 for authentication but is primarily used for modern web and mobile applications with RESTful APIs, not for the traditional browser-based SAML federation pattern that Azure AD Connect uses for SSO with on-premises AD.

606
Multi-Selecteasy

Which TWO are advantages of using containers over virtual machines? (Select TWO.)

Select 2 answers
A.Better hardware isolation
B.Less overhead because they share the host OS kernel
C.Requires a hypervisor to run
D.Larger resource consumption
E.Faster startup time
AnswersB, E

Containers share the host operating system kernel rather than each bundling a full guest OS, so they consume far less CPU, memory and disk than equivalent virtual machines. This reduced overhead is the defining resource-efficiency advantage over hypervisor-based virtualisation.

Why this answer

Option B is correct because containers share the host operating system kernel rather than each running a full guest OS, so they avoid the CPU, memory, and storage overhead of duplicating an OS per instance. Option E is correct because a container starts as a process on the already-running host kernel, so it can launch in milliseconds to seconds, whereas a VM must boot an entire guest OS through a hypervisor. Options A, C, and D are not advantages: VMs provide stronger hardware-level isolation than containers, containers do not require a hypervisor (that is a VM characteristic), and containers consume fewer, not larger, resources than VMs.

Exam trap

CompTIA often tests the misconception that containers provide stronger isolation than VMs, when in fact VMs offer better security boundaries due to hardware-level virtualization.

607
MCQeasy

A cloud engineer needs to troubleshoot network connectivity issues between two subnets. Which feature can help capture and analyze network traffic metadata?

A.Amazon Inspector
B.AWS Config
C.VPC Flow Logs
D.AWS CloudTrail
AnswerC

VPC Flow Logs capture IP traffic metadata at the network interface level, recording source/destination IPs, ports, protocols, and packet accept/reject decisions without inspecting packet payloads. This satisfies the stem’s requirement to *analyse traffic metadata* between subnets, as the logs are published to Amazon CloudWatch Logs or S3 for querying with tools like Athena, enabling identification of blocked flows or asymmetric routing.

Why this answer

VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, bytes, packets, action) for traffic flowing through ENIs, subnets, or VPCs. This metadata is exactly what's needed to diagnose connectivity issues between subnets, since it shows whether traffic is being accepted or rejected by security groups and NACLs. It can be published to CloudWatch Logs or S3 for analysis.

Exam trap

The trap here is confusing observability services — candidates often pick CloudTrail because it sounds like it 'logs everything,' but CloudTrail logs API calls, not network flows.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure — it does not capture traffic metadata. Option B is wrong because AWS Config records resource configuration changes and evaluates them against compliance rules; it has no packet or flow-level visibility. Option D is wrong because AWS CloudTrail records API activity and management events (who did what, when, from where), not network traffic between subnets.

608
MCQmedium

A cloud operations team runs a containerized API on Amazon ECS with the Fargate launch type. During peak hours, CPU utilization on the tasks regularly reaches 95 percent and response latency doubles. The team wants the service to add tasks automatically before users notice degradation, and to remove them when demand drops. Which action should the team take?

A.Increase the task definition CPU reservation from 1024 to 4096 CPU units and redeploy the service so each task can process more requests.
B.Create an EC2 Auto Scaling group with a launch configuration that runs the container image, and attach the group to the ECS cluster as a capacity provider.
C.Configure an Application Auto Scaling target tracking scaling policy on the ECS service using the ECSServiceAverageCPUUtilization metric with a target value and a scale-out cooldown.
D.Enable burstable performance mode on the ECS cluster so tasks can consume additional CPU credits during peak hours.
AnswerC

Application Auto Scaling for ECS services supports target tracking policies that watch the ECSServiceAverageCPUUtilization metric and adjust the desired task count to hold utilization near the target. Because the metric reflects the whole service, Fargate tasks scale out before saturation and scale in when load falls, which directly addresses the latency spike.

Why this answer

Target tracking scaling on the ECS service is the native mechanism for elastic task capacity. It monitors the service-level average CPU metric and adjusts the desired count toward the configured target, scaling out ahead of user-visible degradation and scaling in afterward. Adjusting task size, cluster-level settings, or EC2 capacity providers does not change the number of running Fargate tasks in response to demand.

Exam trap

The trap here is assuming that giving each task more CPU, or enabling a cluster-wide performance setting, will scale capacity, when only a service scaling policy changes the number of running tasks.

609
MCQeasy

A development team uses AWS CodePipeline to deploy a web application. They need to insert a manual approval step so that a release manager can review the build before it is deployed to production. Which action should the team take?

A.Use AWS CodeDeploy to create a deployment group that requires manual approval.
B.Add an approval action in the pipeline between the build and deploy stages.
C.Configure an AWS Lambda function to send an email and wait for a response before continuing.
D.Enable AWS CloudTrail logging on the pipeline and review logs before each deployment.
AnswerB

AWS CodePipeline supports manual approval actions that pause the pipeline until an authorized user approves or rejects. Placing the approval action after the build stage and before the deploy stage ensures that a release manager can review the build artifacts before they reach production. This directly satisfies the requirement without custom scripting.

Why this answer

AWS CodePipeline includes a built-in manual approval action that halts the pipeline until a designated approver responds. By inserting this action between the build and deploy stages, the team ensures that a release manager can inspect the build artifacts and approve or reject the release. This is the standard, least-effort method to implement a human gate without custom code.

Exam trap

The trap here is assuming that CodeDeploy or CloudTrail can provide manual approval, when only CodePipeline has a native approval action.

610
Matchingmedium

Match each troubleshooting command to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Test network connectivity

Trace path to destination

Query DNS records

Display network connections and ports

Transfer data using various protocols

Why these pairings

Common CLI tools for network troubleshooting: ping tests reachability, traceroute shows the path, nslookup resolves DNS names. Confusing these functions is a typical mistake.

611
MCQmedium

A cloud administrator manages a fleet of Linux virtual machines on Google Cloud. A compliance rule requires that an interactive SSH session to any of these instances be brokered through an identity-aware proxy so that sessions are authenticated and auditable, and that no external IP addresses be assigned to the instances. Which solution should the administrator implement?

A.Configure a Cloud VPN tunnel from the corporate network and allow SSH from the corporate address range only.
B.Assign external IP addresses to each instance and restrict ingress to the administrator's source IP range with firewall rules.
C.Deploy a bastion host with an external IP and have administrators SSH to the bastion before connecting to each instance.
D.Use Identity-Aware Proxy TCP forwarding to reach each instance over its internal IP, with firewall rules allowing the IAP range.
AnswerD

IAP TCP forwarding tunnels SSH over the internal IP through Google's infrastructure, authenticating the user's identity and IAM role before the connection is allowed. Because the instance needs no external address and the firewall permits only the IAP source range, the compliance rule is satisfied. Access is also logged per session, giving the auditability the rule demands.

Why this answer

The rule has two parts: identity-aware brokering of interactive sessions and no external addresses on the instances. Identity-Aware Proxy TCP forwarding satisfies both because it authenticates the user's identity and IAM permissions before tunneling SSH over the internal address, and the firewall only needs to allow the IAP source range. External IPs, bastion hosts, and VPN-only access all authenticate network location rather than user identity.

Exam trap

The trap here is treating a network-location control such as a VPN or firewall range as equivalent to identity-aware session brokering.

612
MCQhard

An organization is designing a VPC with public and private subnets. The web servers must be accessible from the internet, but database servers must not. The architecture also requires high availability across two Availability Zones. What is the minimum number of public subnets and private subnets needed?

A.Two public, two private
B.One public, two private
C.Two public, one private
D.One public, one private
AnswerA

High availability across two Availability Zones requires each subnet tier duplicated per AZ, giving two public and two private subnets. Public subnets host the internet-facing web servers via an internet gateway, while private subnets hold the databases without inbound internet routing, satisfying both the accessibility and isolation constraints.

Why this answer

High availability across two Availability Zones requires at least one subnet per AZ for each tier. Since the architecture needs both public-facing web servers and private database servers in each AZ, the minimum is two public subnets and two private subnets — one of each per AZ.

Exam trap

CV0-004 often tests subnet-to-AZ mapping, and candidates incorrectly assume a single subnet can serve multiple AZs or that one public subnet suffices for HA.

How to eliminate wrong answers

Option B is wrong because one public subnet cannot span two AZs, so the web tier would not be highly available. Option C is wrong because one private subnet cannot span two AZs, so the database tier would not be highly available. Option D is wrong because a single public and single private subnet each reside in one AZ, providing no cross-AZ redundancy for either tier.

613
MCQmedium

A company is designing a disaster recovery plan for its cloud infrastructure. The primary site is in US-East, and the DR site is in US-West. The RPO is 15 minutes, and the RTO is 2 hours. Which replication strategy best meets these requirements at the lowest cost?

A.Scheduled nightly backups to DR
B.Asynchronous replication from primary to DR
C.Synchronous replication between sites
D.No replication; manual failover
AnswerB

Asynchronous replication meets the 15-minute RPO because changes are copied after commit, with typical lag well under that threshold, while avoiding the cost and bandwidth of synchronous replication across US-East to US-West. Synchronous would satisfy RPO but add cross-country latency and expense.

Why this answer

Asynchronous replication sends data changes from the primary site to the DR site with minimal delay, typically within seconds to minutes, which meets the 15-minute RPO. It does not require the low-latency link that synchronous replication demands, making it more cost-effective for geographically separated sites. The 2-hour RTO is achievable because the DR site can be activated quickly from the replicated data, without the overhead of restoring from backups.

Exam trap

CompTIA often tests the misconception that synchronous replication is always better for DR, but the trap here is that the 15-minute RPO allows asynchronous replication, which is far more cost-effective across long distances than the expensive low-latency links required for synchronous replication.

How to eliminate wrong answers

Option A is wrong because scheduled nightly backups cannot achieve a 15-minute RPO; the backup window is too long, and recovery from backups would likely exceed the 2-hour RTO due to restore time. Option C is wrong because synchronous replication requires very low latency between sites (typically under 5-10 ms round-trip) to avoid application performance impact, and the distance between US-East and US-West introduces latency that makes this impractical and expensive (dedicated high-bandwidth circuits). Option D is wrong because no replication means no data is copied to the DR site, so manual failover would result in data loss exceeding the RPO and recovery time far beyond the RTO.

614
MCQmedium

A cloud administrator is troubleshooting slow performance on a managed relational database. Read queries against a read replica are fast, but write operations on the primary node take far longer than during testing. Monitoring shows the primary's CPU is moderate, disk queue depth is high, and provisioned IOPS are consistently saturated. Which action should the administrator take to resolve the bottleneck?

A.Move the primary node to a different availability zone to reduce storage latency.
B.Increase the provisioned IOPS and throughput of the primary's storage volume to match the write workload.
C.Increase the primary instance's memory so more of the working set can be cached.
D.Add another read replica to distribute the write load across more nodes.
AnswerB

Sustained high disk queue depth together with saturated provisioned IOPS points directly to a storage throughput ceiling, not to CPU or query logic. Write operations depend on durable storage commits, so they stall when the volume cannot absorb the write rate, while reads served from a replica with its own volume stay fast. Raising provisioned IOPS addresses the measured constraint.

Why this answer

High disk queue depth combined with saturated provisioned IOPS identifies the storage layer as the limiting factor for writes. Because write latency depends on durable commits to the volume, the fix is to raise provisioned IOPS and throughput so the primary can absorb the write rate. CPU is moderate and reads are healthy, so instance sizing, replica count, and zone placement are not the causes.

Exam trap

The trap here is focusing on CPU or instance class because the symptom is slowness, when the metrics already point to storage throughput saturation.

615
MCQmedium

A company is deploying a stateful application that requires persistent storage. They are using Kubernetes. Which resource should they create to ensure data persists across pod restarts?

A.Deployment
B.Secret
C.PersistentVolumeClaim
D.ConfigMap
AnswerC

A PersistentVolumeClaim requests storage with specific capacity and access modes, binding to a PersistentVolume. Pods reference the claim, so the underlying volume and its data survive pod restarts, rescheduling and replacement, satisfying the persistence requirement.

Why this answer

A PersistentVolumeClaim (PVC) is the correct resource because it abstracts the underlying storage details and allows a pod to request persistent storage that survives pod restarts. When a pod is recreated, the PVC ensures the same volume is reattached, preserving application state. This is essential for stateful applications in Kubernetes, as pods are ephemeral by default.

Exam trap

The trap here is that candidates confuse a Deployment's ability to manage replicas with data persistence, overlooking that a Deployment alone does not guarantee storage survival across pod restarts without an explicit PVC.

How to eliminate wrong answers

Option A is wrong because a Deployment manages stateless replicas and does not inherently provide persistent storage; it can use PVCs but is not a storage resource itself. Option B is wrong because a Secret is used to store sensitive data like passwords or tokens, not for persistent application data. Option D is wrong because a ConfigMap is designed for non-sensitive configuration data (e.g., environment variables or config files) and does not persist across pod restarts as a volume.

616
MCQeasy

Which cloud deployment model involves using services from multiple public cloud providers to avoid vendor lock-in and leverage best-of-breed solutions?

A.Public cloud
B.Hybrid cloud
C.Private cloud
D.Multi-cloud
AnswerD

Multi-cloud means consuming services from two or more public cloud providers simultaneously, distributing workloads across them. This avoids dependence on a single vendor and lets each workload use the strongest provider service, directly matching the stated vendor lock-in and best-of-breed requirements.

Why this answer

Multi-cloud is the use of multiple public cloud providers to gain flexibility and avoid dependency on a single vendor.

617
MCQmedium

A company wants to minimize cloud costs for a batch processing job that runs for a few hours each night and can be interrupted. Which pricing model is most appropriate?

A.Dedicated hosts
B.On-demand instances
C.Spot instances
D.Reserved instances
AnswerC

Spot instances use spare capacity priced far below on-demand rates, and their interruptible nature suits a nightly batch job that can tolerate eviction and resume. This directly satisfies the stem's cost-minimisation and interruption-tolerance constraints, unlike reserved or on-demand pricing.

Why this answer

Spot instances are ideal for batch processing jobs that can tolerate interruptions because they offer significant cost savings (up to 90% off on-demand) by utilizing spare cloud capacity. Since the job runs for a few hours each night and can be interrupted, spot instances provide the most cost-effective solution. They can be terminated by the cloud provider if capacity is needed, but for interruptible workloads, this is acceptable.

Exam trap

CV0-004 often tests the misconception that reserved instances are always cheapest, but for interruptible, short-term workloads, spot instances provide greater savings.

How to eliminate wrong answers

Option A is wrong because Dedicated hosts are physical servers dedicated to a single tenant, which are the most expensive option and provide no cost savings for interruptible workloads. Option B is wrong because On-demand instances are pay-as-you-go but lack the deep discounts of spot instances, making them less cost-effective for interruptible batch jobs. Option D is wrong because Reserved instances require a 1- or 3-year commitment and are best for steady-state workloads, not for short, nightly batch jobs that can be interrupted.

618
Multi-Selectmedium

Which TWO of the following are valid considerations when deploying a virtual machine in a cloud environment? (Choose two.)

Select 2 answers
A.The log retention policy
B.The password complexity requirements
C.The instance size and family
D.The number of virtual CPUs assigned to the hypervisor
E.The type of storage (SSD or HDD)
AnswersC, E

Instance size and family determine vCPU count, memory and hardware acceleration profile, directly constraining performance and cost. Selecting them correctly is a prerequisite for any cloud VM deployment, since the choice cannot be changed without a resize.

Why this answer

Option C (the instance size and family) is correct because in cloud environments the VM's compute capacity is selected from predefined instance types (e.g., general purpose, compute-optimized, memory-optimized), which determine vCPU count, memory, and network bandwidth, directly affecting performance and cost. Option E (the type of storage, SSD or HDD) is correct because cloud providers offer different volume types with distinct IOPS, throughput, and latency characteristics, and choosing SSD-backed versus HDD-backed storage materially impacts application performance and pricing. Option A (log retention policy) is a governance/compliance setting rather than a VM deployment sizing or configuration consideration.

Option B (password complexity requirements) is an identity/security policy concern, not a factor in provisioning the VM itself. Option D (the number of virtual CPUs assigned to the hypervisor) is not a valid consideration because the hypervisor's physical CPU resources are managed by the cloud provider, not selected by the customer deploying a VM.

Exam trap

CompTIA often tests the distinction between VM-level deployment decisions (instance size, storage type) and post-deployment or hypervisor-level configurations (log retention, password policies, hypervisor vCPU assignment) to catch candidates who confuse operational settings with provisioning choices.

619
MCQmedium

A company is adopting a CI/CD pipeline using Jenkins to deploy a web application. The pipeline must include steps to compile code, run unit tests, package the application, deploy to a test environment, and then deploy to production. Which pipeline stage should be configured immediately after the build stage?

A.Verify
B.Test
C.Deploy to production
D.Source
AnswerB

Unit tests validate the compiled artefact before it is packaged or promoted, so the test stage must follow build. Running tests immediately after compilation catches defects earliest, satisfying the pipeline's requirement to verify code before deploying to the test environment.

Why this answer

In a typical CI/CD pipeline, after build (compile) comes test (e.g., unit tests) to validate the code before proceeding to deploy.

620
MCQeasy

A company's cloud environment has experienced a sudden spike in network traffic, causing a critical application to become unresponsive. Which of the following is the FIRST step the cloud administrator should take to address this issue?

A.Restart the application server to restore service.
B.Analyze the network traffic logs to identify the source of the spike.
C.Contact the cloud provider to report the issue.
D.Increase the bandwidth for the affected application.
AnswerB

Analysing network traffic logs first identifies the spike's source, distinguishing a genuine demand surge from a denial-of-service attack or misconfiguration. That evidence determines the appropriate mitigation, avoiding premature actions such as scaling or blocking traffic that could waste resources or disrupt legitimate users.

Why this answer

The first step in troubleshooting a traffic spike is to analyze network traffic logs to identify the source, whether it is a DDoS attack, a misconfigured application, or a legitimate surge. Diagnosis must precede remediation so the fix addresses the actual cause. Restarting, contacting the provider, or adding bandwidth without diagnosis may mask the symptom or waste resources.

Exam trap

CV0-004 often tests the troubleshooting sequence — candidates jump to remediation (restart, scale up) because it feels urgent, but the exam expects diagnosis before action.

How to eliminate wrong answers

Option A is wrong because restarting the application server treats the symptom without identifying the cause and may briefly restore service while the underlying traffic spike continues, causing recurrence. Option C is wrong because contacting the cloud provider before internal analysis wastes time and the provider will typically ask for diagnostic evidence first; it is also premature if the spike is caused by the customer's own workload. Option D is wrong because increasing bandwidth without diagnosing the source may simply absorb malicious or misdirected traffic, increasing cost without resolving the root cause.

621
MCQmedium

A cloud engineer is investigating a sudden increase in egress charges. The engineer suspects that a misconfigured Amazon S3 bucket is being read frequently from the internet. Which tool should the engineer use to identify the source IP addresses and request patterns for that bucket?

A.AWS Budgets
B.S3 server access logging
C.AWS Cost Explorer
D.Amazon S3 Storage Lens
AnswerB

S3 server access logs capture detailed records for every request made to a bucket, including the requester's IP address, the operation, and the response code. Analyzing these logs lets the engineer identify which sources are generating the traffic that drives the egress charges.

Why this answer

S3 server access logging records each request to a bucket with fields including the requester's IP address, the operation performed, and the response. That request-level detail is what allows the engineer to trace the egress charges back to specific clients and patterns, which the aggregated cost and metrics tools cannot provide.

Exam trap

The trap here is relying on cost or usage dashboards that aggregate data when the scenario needs per-request attribution.

622
Multi-Selecthard

A cloud security team is investigating a potential data breach. Which THREE actions should be taken immediately?

Select 3 answers
A.Delete all logs to prevent further evidence exposure
B.Isolate the affected systems from the network
C.Capture a forensic snapshot of the affected storage
D.Notify all users via email
E.Preserve logs and system state
AnswersB, C, E

Isolation halts ongoing exfiltration and lateral movement, containing the breach before eradication. It satisfies the immediate containment constraint, since live systems must be severed from the network while evidence is still volatile and the attacker may retain access.

Why this answer

Option B is correct because isolating the affected systems from the network (e.g., by disabling NICs, changing security group rules, or moving instances to a quarantine VLAN) contains the breach and prevents lateral movement or further data exfiltration. Option C is correct because capturing a forensic snapshot of the affected storage preserves volatile and non-volatile evidence in a forensically sound manner, enabling later analysis without altering the original media. Option E is correct because preserving logs and system state (memory dumps, running processes, audit trails) maintains the chain of custody and provides the evidence needed for root-cause analysis and potential legal proceedings.

Option A is wrong because deleting logs destroys evidence and may violate legal/regulatory retention requirements. Option D is wrong because mass-emailing all users immediately can tip off the attacker, cause panic, and is not a containment or evidence-preservation step; notifications should follow incident response and legal guidance.

Exam trap

CompTIA often tests the misconception that deleting logs or notifying all users immediately is a valid first response, when in fact containment and evidence preservation are the top priorities.

623
MCQmedium

A load balancer log entry shows the above for a request. What is the MOST likely cause of the 504 error?

A.The DNS resolution for the domain name has failed.
B.The backend server took too long to respond to the request.
C.The requested resource does not exist on the backend server.
D.The load balancer's health check is misconfigured.
AnswerB

A 504 Gateway Timeout occurs when the load balancer's upstream connection to the backend exceeds its configured timeout window, so the proxy abandons the request. This matches the stem's constraint: the log records a 504, which specifically indicates backend response latency rather than connection refusal or DNS failure.

Why this answer

A 504 Gateway Timeout error from a load balancer indicates that the load balancer sent the request to a backend server but did not receive a timely response. The load balancer has a configured timeout value (often 30-120 seconds), and if the backend server fails to respond within that window, the load balancer terminates the connection and returns a 504. This is the most common cause of 504 errors in load-balanced environments.

Exam trap

CompTIA often tests the distinction between 502 (bad gateway, often DNS or upstream connection failure) and 504 (gateway timeout, upstream response delay), and candidates mistakenly attribute 504 errors to health check failures or DNS issues.

How to eliminate wrong answers

Option A is wrong because a DNS resolution failure would typically result in a 502 Bad Gateway error (the load balancer cannot resolve the backend server's hostname) or a 503 Service Unavailable, not a 504 timeout. Option C is wrong because a missing resource on the backend server would return a 404 Not Found response from the backend itself, which the load balancer would forward to the client; the load balancer does not generate a 504 for missing resources. Option D is wrong because a misconfigured health check would cause the load balancer to mark the backend as unhealthy and stop sending traffic to it, resulting in a 503 Service Unavailable error, not a 504 timeout.

624
MCQeasy

A cloud administrator runs a deployment script that creates multiple resources using Infrastructure as Code (IaC). The script fails with a "400 Bad Request" error when attempting to create a storage account. Which troubleshooting step should the administrator take first?

A.Check the network connectivity to the cloud API endpoint.
B.Increase the timeout value for the API call.
C.Review the error message details for a specific validation error.
D.Verify that the script has the correct region parameter.
AnswerC

A 400 response signals client-side request rejection, and the response body carries the precise validation failure, such as an invalid name, unsupported region, or SKU mismatch. Reading those details identifies the offending property before any retry or script change is attempted.

Why this answer

A '400 Bad Request' from a cloud API indicates a client-side validation error, such as an invalid parameter, missing required property, or malformed request body. The fastest and most accurate first step is to read the error message details, which typically name the exact field or constraint that failed. This avoids guessing at network, timeout, or region issues that would produce different error codes.

Exam trap

CV0-004 often tests whether candidates jump to infrastructure causes (network, timeout, region) for any API failure — the trap is ignoring that a 400 is a client-side validation error whose details should be read first.

How to eliminate wrong answers

Option A is wrong because network connectivity problems would typically manifest as timeouts, DNS failures, or connection refused errors, not a 400 Bad Request returned by the API. Option B is wrong because increasing the timeout addresses slow responses (e.g., 408 or timeout errors), not a validation rejection that returns immediately. Option D is wrong because an incorrect region parameter would usually produce a 404 or a region-specific error, and the 400 already points to a request validation issue that the error detail will clarify.

625
MCQhard

A cloud engineer is configuring an auto-scaling group with a lifecycle hook to run a custom script when instances are launched. The script installs software and registers the instance with a load balancer. The engineer wants to ensure the instance does not receive traffic until the script completes successfully. What should the engineer do?

A.Set the lifecycle hook to 'terminating:wait' to delay termination.
B.Use a lifecycle hook with a 'pending:wait' state and then send a 'complete-lifecycle-action' signal after the script succeeds.
C.Configure the load balancer health check to fail until the script runs.
D.Configure the launch configuration with a user-data script that runs after the instance is in service.
AnswerB

The pending:wait lifecycle state holds the instance in service-pending until the script signals complete-lifecycle-action, so the load balancer never routes traffic to an unconfigured instance. This satisfies the constraint that traffic must wait for successful script completion.

Why this answer

Option B is correct because using a lifecycle hook with a 'pending:wait' state allows you to pause the instance launch process until the custom script completes. After the script succeeds, you send a 'complete-lifecycle-action' signal to the auto-scaling group, which then proceeds to put the instance into service. This ensures the instance does not receive traffic until the script is done.

Exam trap

CV0-004 often tests the misconception that user data or health checks can delay traffic until a script completes; candidates must remember that lifecycle hooks with 'pending:wait' and explicit 'complete-lifecycle-action' signals are required to pause the instance launch process.

How to eliminate wrong answers

Option A is wrong because a 'terminating:wait' lifecycle hook is used during instance termination, not launch; it would not prevent traffic during launch. Option C is wrong because configuring the load balancer health check to fail until the script runs would cause the instance to be marked unhealthy and potentially terminated, and it does not guarantee the script completes before traffic is routed; it's a reactive approach. Option D is wrong because user-data scripts run during launch but do not inherently delay the instance from being put into service; the instance could receive traffic before the script finishes.

626
MCQhard

A cloud engineer is deploying a stateful application on Amazon EC2 that requires a persistent block storage volume with the highest possible IOPS and lowest latency for a database. The database will run on a single instance in one Availability Zone, and the engineer needs to choose the appropriate Amazon EBS volume type. Which volume type should the engineer select?

A.Amazon EBS Cold HDD (sc1)
B.Amazon EBS Provisioned IOPS SSD (io2 Block Express)
C.Amazon EBS General Purpose SSD (gp3)
D.Amazon EBS Throughput Optimized HDD (st1)
AnswerB

Amazon EBS Provisioned IOPS SSD (io2 Block Express) is designed for critical, I/O-intensive database workloads that require the highest levels of IOPS and consistently low latency. It supports up to 256,000 IOPS and 4,000 MB/s per volume with sub-millisecond latency, and offers 99.999% durability. It is the best choice for a single-instance database requiring maximum performance.

Why this answer

Amazon EBS Provisioned IOPS SSD (io2 Block Express) delivers the highest IOPS and lowest latency among EBS volume types, making it the correct choice for a performance-critical single-instance database. The other options are either throughput-oriented HDDs for sequential workloads or a general-purpose SSD that, while cost-effective, does not provide the extreme performance required in this scenario.

Exam trap

The trap here is assuming that General Purpose SSD (gp3) can be scaled to meet any performance requirement, when in fact it has a maximum IOPS limit far below what Provisioned IOPS SSD (io2 Block Express) can deliver.

627
MCQmedium

A company is deploying a global web application and wants to reduce latency for users around the world. The application serves static content (images, CSS) and dynamic API responses. Which combination of services should the architect use?

A.CDN for static content and a global load balancer with latency-based routing for dynamic content
B.CDN for all content without backend routing
C.A single load balancer in one region with a CDN
D.DNS round-robin for both static and dynamic content
AnswerA

A CDN caches static assets at edge locations, cutting latency for images and CSS. Dynamic API responses cannot be cached, so a global load balancer with latency-based routing directs each user to the nearest healthy regional endpoint, satisfying the worldwide latency constraint.

Why this answer

CDN caches static content at edge locations, reducing latency. For dynamic content, a global load balancer with latency-based routing directs users to the closest region. DNS alone cannot reduce latency for dynamic content.

A single load balancer does not provide global distribution.

628
MCQmedium

A cloud architect is designing a globally distributed application on Google Cloud. The application must serve users from the closest possible point of presence with minimal latency while using a single anycast IP address. Which load balancing solution should the architect choose?

A.Internal passthrough Network Load Balancer
B.External passthrough Network Load Balancer
C.Regional external Application Load Balancer
D.Global external Application Load Balancer
AnswerD

A global external Application Load Balancer uses a single anycast IP address and routes user traffic to the closest healthy backend based on Google's global network. It operates at layer 7, supports HTTP(S) workloads, and is designed for global low-latency distribution. This matches the requirement for a single IP and proximity-based routing across regions.

Why this answer

The global external Application Load Balancer is the only option that provides a single anycast IP address and automatically routes users to the closest healthy backend across Google Cloud regions. It is purpose-built for global, layer 7 applications that require minimal latency and high availability, making it the correct choice for this scenario.

Exam trap

The trap here is assuming that any load balancer with 'external' in its name can provide global anycast routing, when in fact regional and passthrough network load balancers are scoped to a single region and operate at layer 4.

629
MCQeasy

Which of the following is the cloud provider's responsibility under the shared responsibility model?

A.Encrypting data stored in cloud resources
B.Configuring identity and access management policies
C.Securing the physical data center
D.Patching guest operating systems
AnswerC

Securing the physical data centre falls entirely to the cloud provider, satisfying the shared responsibility model's division where the provider always owns physical security. Customers cannot access or harden buildings, racks, or hardware, so this control never transfers to them, unlike patching, identity, or data classification.

Why this answer

Under the shared responsibility model, the cloud provider is responsible for security 'of' the cloud, which includes the physical data center, hardware, and infrastructure. Securing the physical data center is solely the provider's responsibility. The customer is responsible for security 'in' the cloud, such as data encryption, IAM policies, and guest OS patching.

Exam trap

The trap is confusing responsibilities that are always the customer's (like encryption and IAM) with those that are the provider's (physical security); candidates may overestimate the provider's role in data security.

How to eliminate wrong answers

Option A is wrong because encrypting data stored in cloud resources is a customer responsibility, as the customer controls encryption keys and data classification. Option B is wrong because configuring IAM policies is a customer responsibility, as the customer manages access to their resources. Option D is wrong because patching guest operating systems is a customer responsibility, as the customer controls the OS and its updates.

630
MCQeasy

A startup is deploying a web application on a public cloud and expects variable traffic throughout the day. The team wants to minimize costs while ensuring that the application can handle sudden spikes in demand. Which scaling strategy best meets these requirements?

A.Auto scaling based on CPU utilization thresholds
B.Horizontal scaling using a fixed schedule
C.Vertical scaling during off-peak hours
D.Manual scaling based on historical data
AnswerA

Auto scaling on CPU utilisation thresholds adds and removes instances dynamically, matching capacity to the variable daily demand while avoiding spend during troughs. It satisfies both the cost minimisation and sudden-spike requirements, unlike fixed or scheduled provisioning.

Why this answer

Auto scaling based on CPU utilization thresholds is the correct strategy because it dynamically adjusts the number of compute instances in response to real-time demand, ensuring the application can handle sudden spikes while minimizing costs during low-traffic periods. This approach aligns with the startup's requirement for variable traffic and cost efficiency, as it only provisions resources when needed, unlike fixed schedules or manual interventions that cannot react to unpredictable spikes.

Exam trap

CompTIA often tests the misconception that vertical scaling is more cost-effective than horizontal scaling, but the trap here is that vertical scaling requires downtime and has a hard limit on instance size, making it unsuitable for handling sudden, unpredictable spikes in a cost-minimizing, variable-traffic scenario.

How to eliminate wrong answers

Option B is wrong because horizontal scaling using a fixed schedule cannot handle sudden spikes that occur outside the scheduled times, leading to either over-provisioning during low demand or under-provisioning during unexpected surges. Option C is wrong because vertical scaling during off-peak hours involves resizing an existing instance (e.g., increasing vCPUs or RAM), which requires downtime and cannot react to real-time spikes, plus it is limited by the maximum size of a single instance. Option D is wrong because manual scaling based on historical data relies on human intervention, which introduces latency and cannot respond to sudden, unpredictable spikes in demand, making it unsuitable for a startup needing automated, cost-effective scaling.

631
Multi-Selecteasy

A cloud engineer is using Terraform to manage infrastructure. They need to store the state file remotely for team collaboration and to enable state locking. Which THREE of the following backends support state locking? (Select THREE.)

Select 3 answers
A.Consul backend
B.Local file system
C.HTTP backend
D.Azure Blob Storage with blob lease
E.Amazon S3 with DynamoDB for locking
AnswersA, D, E

The Consul backend stores state in Consul's key-value store and uses Consul's session mechanism to acquire a lock, preventing concurrent Terraform runs from corrupting state. This satisfies the stem's state-locking requirement alongside remote storage for team collaboration.

Why this answer

The Consul backend (A) supports state locking natively through Consul's session and key-value store mechanisms, so Terraform can acquire a lock before modifying state. Azure Blob Storage with blob lease (D) supports locking because Terraform uses Azure's blob lease feature to prevent concurrent state writes. Amazon S3 with DynamoDB for locking (E) supports locking by using a DynamoDB table to coordinate and hold the lock while state is stored in S3.

The local file system (B) does not provide remote locking suitable for team collaboration, and the HTTP backend (C) does not support state locking, so neither belongs among the correct answers.

Exam trap

CV0-004 often tests the misconception that any remote backend supports locking — candidates pick HTTP or local because they 'store state remotely' and forget that locking requires a backend with a locking API.

632
MCQhard

Refer to the exhibit. A cloud administrator sees this log after a nightly backup job. Which of the following is the most likely cause of the timeout?

A.The volume has a high I/O load during the snapshot.
B.The volume is attached to an instance that is powered off.
C.The snapshot target region is unreachable.
D.The backup agent is not installed.
AnswerA

Snapshot creation contends with concurrent writes, so sustained I/O pressure delays completion until the job exceeds its timeout window. The log timing aligns with the backup overlapping peak disk activity rather than a network or credential fault.

Why this answer

The log indicates a timeout during a nightly backup job that involves creating a snapshot. A high I/O load on the volume during the snapshot process can cause the snapshot to take longer than the configured timeout threshold, as the snapshot must capture a consistent point-in-time state while the volume is actively being written to. This is a common issue in cloud environments where the snapshot process competes for disk resources, leading to delays that exceed the timeout limit.

Exam trap

CompTIA Cloud+ often tests the misconception that a powered-off instance or missing backup agent is the root cause of snapshot timeouts, when in reality the most common cause is high I/O load on the volume during the snapshot operation.

How to eliminate wrong answers

Option B is wrong because if the volume is attached to an instance that is powered off, the snapshot would typically complete quickly without I/O contention, not cause a timeout. Option C is wrong because the snapshot target region being unreachable would result in a connectivity error (e.g., 'unreachable' or 'access denied'), not a generic timeout during the snapshot creation phase. Option D is wrong because the backup agent is not required for native cloud snapshot operations; snapshots are initiated by the cloud provider's API, not an agent installed on the instance.

633
MCQmedium

A company is migrating a legacy application to AWS. The application requires a shared file system that can be mounted on multiple Linux-based EC2 instances simultaneously. The file system must be highly available and scalable, and it must support POSIX permissions. Which AWS service should be used?

A.Amazon S3
B.Amazon EBS
C.Amazon FSx for Windows File Server
D.Amazon EFS
AnswerD

Amazon EFS is a fully managed, scalable, and highly available file storage service for Linux-based workloads. It supports the NFS protocol, can be mounted on multiple EC2 instances concurrently, and supports POSIX permissions. This meets all the requirements for a shared file system.

Why this answer

Amazon EFS is the correct choice because it is a managed NFS file system that can be mounted on multiple Linux EC2 instances, supports POSIX permissions, and is highly available and scalable. EBS is block storage for single-instance attachment, S3 is object storage, and FSx for Windows is for Windows workloads.

Exam trap

The trap here is confusing block storage (EBS) with file storage (EFS), as EBS is often used for instance storage but does not support shared file access.

634
MCQmedium

A company uses a multi-cloud environment with AWS and Azure. They want to centralize log collection and enable advanced querying for troubleshooting. Which combination of services should they use?

A.AWS CloudTrail and Azure Monitor
B.AWS CloudWatch Logs and Azure Log Analytics
C.AWS S3 and Azure Blob Storage
D.AWS CloudWatch and Azure Application Insights
AnswerB

AWS CloudWatch Logs ingests and stores logs from AWS workloads, while Azure Log Analytics provides the centralised workspace and Kusto queries for advanced troubleshooting. Together they satisfy the multi-cloud constraint by covering both providers and enabling cross-environment querying.

Why this answer

AWS CloudWatch Logs and Azure Log Analytics are the native log aggregation and querying services in their respective clouds. CloudWatch Logs centralizes logs from AWS resources and supports Logs Insights for querying, while Azure Log Analytics provides a powerful KQL-based query engine over data collected in a Log Analytics workspace. Using both together gives centralized collection and advanced querying across the multi-cloud environment.

Exam trap

CV0-004 often tests whether candidates confuse monitoring/APM tools (Azure Monitor, Application Insights) with the actual log storage and query engine (Log Analytics), leading them to pick a service that cannot perform advanced log querying.

How to eliminate wrong answers

Option A is wrong because CloudTrail records API activity (audit trail) rather than application or system logs, and Azure Monitor is an umbrella monitoring platform, not a log query engine — the querying component is Log Analytics. Option C is wrong because S3 and Blob Storage are object storage services for retention, not log collection or querying platforms. Option D is wrong because CloudWatch (without specifying Logs) is a broader monitoring service and Application Insights is an APM tool focused on application performance telemetry, not centralized log querying across infrastructure.

635
MCQmedium

A cloud engineer is troubleshooting an issue where users cannot connect to a web application hosted on a cloud VM. The VM's security group allows HTTP (port 80) from 0.0.0.0/0, and the VM's OS firewall is disabled. The engineer can ping the VM's public IP from the internet. What is the most likely cause of the issue?

A.OS firewall is blocking port 80
B.Incorrect routing table on the VM
C.Security group rule is applied to the wrong subnet
D.Web server service is not running on the VM
AnswerD

Ping succeeding proves the network path, security group rule and routing are functional, so the fault lies above layer 3. A stopped or crashed web server process means nothing listens on port 80, producing connection refusals despite reachable IP connectivity.

Why this answer

Since the OS firewall is disabled and the security group allows HTTP from 0.0.0.0/0, the only remaining layer that could block connectivity is the application itself. If the web server service (e.g., Apache, Nginx, IIS) is not running on the VM, it will not listen on TCP port 80, so HTTP requests will be refused even though network-level access is permitted. The ability to ping the VM confirms IP-level reachability, isolating the issue to the application layer.

Exam trap

The trap here is that candidates assume a ping success implies all services are reachable, but ICMP (ping) operates at the network layer (Layer 3) and does not test TCP port availability, so a running web server is required for HTTP connectivity.

How to eliminate wrong answers

Option A is wrong because the OS firewall is explicitly stated as disabled, so it cannot be blocking port 80. Option B is wrong because routing tables on the VM control outbound traffic, not inbound connections to the VM; inbound traffic is handled by the cloud provider's virtual network and security groups. Option C is wrong because security groups are stateful and applied at the VM network interface level, not to subnets; even if the rule were misapplied, the VM's security group explicitly allows HTTP from 0.0.0.0/0, so this is not the cause.

636
MCQmedium

A cloud engineer is deploying a web application to a Kubernetes cluster. The application requires zero downtime during updates, and the team wants to test new versions with a small percentage of users before full rollout. Which deployment strategy should the engineer use?

A.Rolling deployment
B.Blue/green deployment
C.Canary deployment
D.Immutable deployment
AnswerC

Canary deployment routes a small percentage of live traffic to the new version while the remainder continues to the stable release, then gradually shifts traffic. This satisfies both constraints: zero downtime during updates and validating new versions with a limited user subset before full rollout.

Why this answer

A canary deployment routes a small percentage of traffic to the new version, allowing monitoring and automatic rollback if issues arise, meeting the requirements.

637
MCQmedium

A cloud engineer is deploying a serverless application that processes images uploaded to an object storage bucket. The application must automatically resize each image and store the resized version in a second bucket. The engineer wants to minimize operational overhead and ensure the processing runs only when new images are added. Which AWS service should the engineer use to trigger the processing?

A.Amazon EC2 Auto Scaling group with a custom application
B.AWS Batch with a job queue
C.AWS Lambda with an S3 event trigger
D.AWS Step Functions with a polling loop
AnswerC

AWS Lambda natively integrates with Amazon S3 events, allowing the function to execute automatically when an object is created. This serverless approach eliminates server management and scales with the number of uploads, matching the requirement for minimal operational overhead and event-driven processing.

Why this answer

AWS Lambda with an S3 event trigger is the correct choice because it directly responds to object creation events in Amazon S3 without requiring any server management. The integration is native, so the function runs only when new images are uploaded, aligning with the need for minimal operational overhead and automatic processing. Other options involve more management or are not event-driven.

Exam trap

The trap here is assuming that any compute service can be triggered by S3 events, when actually only AWS Lambda provides native, direct event integration with S3 without additional infrastructure.

638
MCQmedium

A cloud operations team manages a fleet of Amazon EC2 instances running a stateless web tier behind an Application Load Balancer. The team wants to replace instances automatically when an instance fails an Elastic Load Balancing health check, without manual intervention, while keeping the desired capacity constant. Which AWS feature should the team configure to meet this requirement?

A.EC2 Auto Scaling group with health check type set to ELB
B.EC2 Auto Scaling group with health check type set to EC2
C.AWS Lambda function triggered by Amazon CloudWatch alarms on CPU utilization
D.AWS Elastic Beanstalk environment with rolling updates
AnswerA

An Auto Scaling group configured with the ELB health check type uses the load balancer's health status to determine instance health. When an instance fails the ELB health check, Auto Scaling terminates it and launches a replacement to maintain the desired capacity, providing the automatic recovery the team needs without manual intervention.

Why this answer

Automatic replacement of instances that fail load balancer health checks requires an Auto Scaling group whose health check type is set to ELB. In that mode, the group treats an instance as unhealthy when the load balancer reports it as unhealthy, terminates it, and launches a replacement to preserve desired capacity. Other options either react to metrics rather than health checks or only evaluate EC2-level status.

Exam trap

The trap here is assuming that EC2 status checks and ELB health checks are equivalent, when an instance can pass EC2 checks yet still be removed from load balancer rotation.

639
MCQhard

A cloud administrator is deploying a critical application that requires the lowest possible latency between compute instances. The instances will be running in a private subnet and must communicate with each other using their private IP addresses. Which of the following deployment configurations would best meet these requirements?

A.Deploy instances in different Availability Zones within the same region.
B.Deploy instances in the same subnet behind a NAT gateway.
C.Deploy instances in different regions and use inter-region peering.
D.Deploy instances in a placement group within the same Availability Zone.
AnswerD

A placement group packs instances onto closely coupled hardware within one Availability Zone, minimising network hops and delivering the lowest inter-instance latency. Private IP communication within the same subnet is preserved, meeting the private-subnet constraint.

Why this answer

Deploying instances in a placement group within the same Availability Zone ensures they are physically close together, often in the same rack or cluster, which minimizes network hops and achieves the lowest possible latency. This configuration is ideal for latency-sensitive applications because it leverages non-blocking, high-bandwidth inter-instance communication without traversing additional network infrastructure.

Exam trap

The trap here is that candidates often assume distributing instances across Availability Zones improves performance due to high availability, but for latency-sensitive workloads, the physical proximity of a placement group within a single AZ is the correct choice, not fault tolerance.

How to eliminate wrong answers

Option A is wrong because deploying instances in different Availability Zones introduces additional network latency due to the physical separation and the need to traverse Availability Zone boundaries, even within the same region. Option B is wrong because placing instances behind a NAT gateway adds a network hop and processing overhead, which increases latency and is unnecessary for private subnet communication using private IPs. Option C is wrong because deploying instances in different regions and using inter-region peering incurs significant latency due to long-distance data transfer and is not suitable for low-latency requirements.

640
MCQhard

A security administrator needs to enforce least privilege for a Kubernetes cluster in a cloud environment. Which approach should be used to restrict permissions for pods that need to access the cloud provider's API?

A.Assign the pod a static cloud IAM user credential
B.Disable cloud API access for all pods
C.Use a service account with a role that has only the required permissions
D.Grant the pod cluster-admin privileges in Kubernetes
AnswerC

A Kubernetes service account mapped to a cloud role grants pods only the permissions that role defines, satisfying least privilege for API access. Unlike node-wide instance profiles, which expose every pod on that node to the same credentials, this binds permissions to the workload identity itself, so each pod receives solely its required scope.

Why this answer

In Kubernetes, pods assume a Kubernetes service account, and cloud providers support mapping that service account to a cloud IAM role via workload identity (for example, IRSA on EKS or Workload Identity on GKE/AKS). This lets the pod obtain short-lived credentials scoped to only the permissions in the role, enforcing least privilege without embedding static credentials.

Exam trap

CV0-004 often tests the misconception that assigning a static IAM user to a pod is acceptable, when least privilege requires short-lived, role-based workload identity.

How to eliminate wrong answers

Option A is wrong because a static cloud IAM user credential embedded in the pod is a long-lived secret that violates least privilege and is hard to rotate. Option B is wrong because disabling cloud API access for all pods is overly restrictive and breaks legitimate workloads that need scoped access. Option D is wrong because cluster-admin privileges grant full control over the Kubernetes cluster, which is the opposite of least privilege and does not scope cloud API permissions.

641
MCQmedium

A company uses AWS and wants to centralize security monitoring across multiple accounts. Which service should they use to aggregate security findings and check compliance against standards like CIS AWS Foundations?

A.AWS CloudTrail
B.Amazon GuardDuty
C.AWS Security Hub
D.AWS Config
AnswerC

AWS Security Hub aggregates findings from GuardDuty, Inspector, Macie and other accounts into one view, and runs automated compliance checks against standards including CIS AWS Foundations Benchmark. This satisfies the requirement to centralise security monitoring and compliance across multiple accounts.

Why this answer

AWS Security Hub is a centralized security and compliance service that aggregates findings from multiple AWS services (like GuardDuty, Inspector, Macie) and third-party tools across accounts, and it runs automated compliance checks against standards such as CIS AWS Foundations, AWS Foundational Security Best Practices, and PCI DSS. It is purpose-built for cross-account security aggregation and compliance monitoring, making it the correct choice.

Exam trap

CV0-004 often tests whether candidates confuse Security Hub (aggregation and compliance) with GuardDuty (threat detection) or Config (configuration assessment) — each serves a distinct role in the AWS security ecosystem.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and account events for auditing, but it does not aggregate security findings or check compliance against standards — it is a logging service, not a security posture service. Option B is wrong because Amazon GuardDuty is a threat detection service that identifies malicious activity and unauthorized behavior, but it does not aggregate findings across services or perform compliance checks against standards like CIS. Option D is wrong because AWS Config assesses, audits, and evaluates the configurations of AWS resources against desired configurations, but it does not aggregate security findings from other services or provide a centralized compliance dashboard across accounts.

642
MCQeasy

A cloud administrator notices that a cloud-based application is running slowly. The administrator checks the cloud monitoring dashboard and sees that CPU utilization is at 95% for the application server. Which of the following should the administrator do first?

A.Add an additional network interface.
B.Scale out by adding another instance.
C.Reboot the server.
D.Increase the memory allocation.
AnswerB

Scaling out adds another instance to distribute the application load, directly relieving the sustained 95% CPU utilisation on the existing server. Horizontal scaling suits this stateless cloud application, spreading demand across multiple instances rather than resizing a single host. It addresses the immediate bottleneck identified on the monitoring dashboard.

Why this answer

With CPU utilization at 95% on the application server, the bottleneck is compute capacity, so the first remediation step is to scale out by adding another instance to distribute the load. Horizontal scaling directly addresses sustained high CPU by adding parallel processing capacity. This is the least disruptive and most appropriate first action before considering vertical scaling or restarts.

Exam trap

CV0-004 often tests the reflex to reboot or add memory when CPU is high — candidates must match the resource bottleneck (CPU) to the correct scaling action (scale out), not a different resource.

How to eliminate wrong answers

Option A is wrong because adding a network interface increases network throughput capacity, which does nothing to relieve CPU saturation. Option C is wrong because rebooting the server is a disruptive action that may temporarily clear the symptom but does not add capacity and risks an outage. Option D is wrong because increasing memory allocation addresses memory pressure, not CPU utilization, and would not resolve a compute-bound workload.

643
MCQmedium

A cloud engineer is deploying a serverless function using AWS Lambda. The function needs to process messages from an SQS queue. Which event source should be configured to trigger the Lambda function?

A.Amazon S3
B.Amazon SQS
C.Amazon API Gateway
D.Amazon EventBridge
AnswerB

Amazon SQS is a supported Lambda event source; configuring it lets Lambda poll the queue and invoke the function with batched messages. This matches the requirement to process queue messages, unlike push-based sources such as API Gateway or S3.

Why this answer

Lambda can be triggered by SQS, S3, API Gateway, etc. For SQS, the trigger is SQS. S3 triggers on object events; API Gateway for HTTP; EventBridge for events.

644
MCQeasy

A cloud administrator needs to automate the patching of operating systems on a fleet of EC2 instances. Which AWS service should be used?

A.AWS Update Manager
B.AWS Config
C.Amazon Inspector
D.AWS Systems Manager Patch Manager
AnswerD

AWS Systems Manager Patch Manager automates OS patching across EC2 fleets using patch baselines and maintenance windows. It scans for missing patches and applies them at scale, satisfying the fleet-wide automation requirement without manual intervention.

Why this answer

AWS Systems Manager Patch Manager automates the process of patching managed nodes with both security-related and other types of updates. It uses a patch baseline to define which patches should be installed and can schedule patching across a fleet of EC2 instances, making it the correct service for this task.

Exam trap

The trap here is that candidates may confuse Amazon Inspector (which only identifies vulnerabilities) with a patching solution, or assume 'AWS Update Manager' is a real service because it sounds plausible, when in fact the correct service is AWS Systems Manager Patch Manager.

How to eliminate wrong answers

Option A is wrong because AWS Update Manager is not a real AWS service; the correct service for update management is AWS Systems Manager Patch Manager. Option B is wrong because AWS Config is a service for evaluating, auditing, and assessing the configurations of your resources against desired policies, not for automating patch installation. Option C is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and unintended network exposure, but it does not perform patching itself.

645
MCQhard

A cloud engineer manages a Kubernetes cluster on Google Kubernetes Engine. A production Deployment repeatedly enters CrashLoopBackOff after a configuration change, and the engineer needs to inspect why the container is terminating without modifying the running workload. Which action should the engineer take?

A.Enable GKE node auto-repair to replace the node hosting the failing pod
B.Run kubectl logs on the failing pod with the --previous flag to retrieve logs from the prior container instance
C.Delete the Deployment and recreate it with a higher restart backoff limit
D.Scale the Deployment to zero replicas and then back to the original count
AnswerB

When a container crashes and restarts, the current container may not yet have produced logs. The --previous flag retrieves logs from the terminated instance, which is exactly where the crash reason appears. This is a non-disruptive read-only action that satisfies the requirement to inspect without modifying the running workload, making it the correct diagnostic step.

Why this answer

Retrieving logs from the previous container instance surfaces the actual termination error without altering the Deployment or node configuration. Because CrashLoopBackOff restarts containers, the current instance may not have logged anything yet, so the --previous flag is essential. Disruptive actions like deleting, scaling, or replacing nodes neither reveal the cause nor respect the constraint of not modifying the running workload.

Exam trap

The trap here is assuming the current container's logs will show the crash, when a restarted container often has no output yet and the prior instance's logs are required.

646
MCQmedium

A company uses Azure and needs shared file storage accessible from multiple Linux VMs using standard file sharing protocols. Which storage type should they choose?

A.Azure Files
B.Azure Archive Storage
C.Azure Disk Storage
D.Azure Blob Storage
AnswerA

Azure Files provides fully managed SMB and NFS file shares, so multiple Linux VMs can mount the same share concurrently using standard protocols. This directly satisfies the stem's requirement for shared storage across Linux VMs, unlike blob storage or single-VM managed disks, which lack native multi-attach file sharing.

Why this answer

Azure Files provides fully managed file shares in the cloud that are accessible via the industry-standard SMB and NFS protocols, making it the correct choice for shared file storage across multiple Linux VMs. Linux VMs can mount Azure Files shares using SMB 3.0 or NFS 4.1, enabling concurrent access from multiple instances. The other storage types do not support standard file-sharing protocols for multi-VM access.

Exam trap

CV0-004 often tests the confusion between Azure Files (SMB/NFS file shares) and Azure Blob Storage (object storage), tricking candidates into choosing Blob Storage when the scenario explicitly requires standard file-sharing protocols like SMB or NFS.

How to eliminate wrong answers

Option B is wrong because Azure Archive Storage is a blob access tier designed for long-term archival of rarely accessed data with high retrieval latency — it is not a file share and cannot be mounted by VMs. Option C is wrong because Azure Disk Storage provides block-level virtual hard disks attached to a single VM (or shared disks with limitations); it does not offer a network file share accessible via SMB/NFS from multiple Linux VMs. Option D is wrong because Azure Blob Storage is object storage accessed via REST APIs or SDKs, not via standard file-sharing protocols like SMB or NFS, and cannot be mounted natively as a shared file system without additional services like BlobFuse or NFS 3.0 (which has limitations).

647
MCQeasy

A cloud engineer notices that an application is running slower than expected. Monitoring shows that the CPU utilization is consistently below 30%, but memory usage is at 95%. Which of the following is the most likely cause of the performance issue?

A.Insufficient disk space for application logs
B.Insufficient memory causing swapping to disk
C.Network bandwidth saturation
D.CPU contention due to overprovisioning
AnswerB

Insufficient memory forces the operating system to page data from RAM to disk, and that swapping introduces severe latency because disk access is orders of magnitude slower than memory. With memory at 95% while CPU sits below 30%, the bottleneck is memory pressure, not processing capacity, so adding RAM resolves the slowdown.

Why this answer

When memory usage is at 95% and CPU utilization is low, the system is likely thrashing—the operating system is forced to page memory to disk (swap) to free RAM. Disk I/O is orders of magnitude slower than RAM, so even with idle CPU, the application stalls waiting for swap operations. This explains the performance degradation despite low CPU load.

Exam trap

The trap here is that candidates often associate performance issues solely with CPU or network bottlenecks, overlooking the severe impact of memory exhaustion and disk swapping, which can masquerade as a slow application with ample CPU headroom.

How to eliminate wrong answers

Option A is wrong because insufficient disk space for logs would cause write failures or application crashes, not a gradual slowdown with high memory and low CPU. Option C is wrong because network bandwidth saturation would manifest as high latency or packet loss, not as high memory usage with low CPU. Option D is wrong because CPU contention due to overprovisioning would show high CPU ready times or steal time, not consistently low CPU utilization; overprovisioning typically leads to CPU starvation, not memory exhaustion.

648
MCQmedium

A cloud administrator is reviewing a security audit report that shows an instance has been sending outbound traffic to a known malicious IP address. The instance hosts a production application. Which action should the administrator take first?

A.Run an antivirus scan on the instance.
B.Immediately shut down the instance.
C.Isolate the instance by modifying the security group to deny all traffic.
D.Review the application logs to understand the traffic.
AnswerC

Isolating the instance via its security group immediately halts outbound traffic to the malicious IP, containing potential exfiltration or command-and-control activity while preserving the instance for forensic investigation. This satisfies the stem's requirement to act first on a production host, since termination would destroy evidence.

Why this answer

The first priority in a confirmed security incident is containment. Modifying the security group to deny all traffic immediately stops the outbound communication to the malicious IP, preventing data exfiltration or further compromise while preserving the instance for forensic analysis. This aligns with the incident response process, where isolation precedes investigation.

Exam trap

The trap here is that candidates may choose immediate shutdown (Option B) thinking it is the fastest containment method, but the exam emphasizes preserving forensic evidence and using network-level isolation (security groups) as the correct first step in incident response.

How to eliminate wrong answers

Option A is wrong because running an antivirus scan is a remediation step that should occur after containment; it does not stop ongoing malicious outbound traffic and may be ineffective against advanced threats. Option B is wrong because immediately shutting down the instance destroys volatile data (e.g., running processes, memory contents) that could be critical for forensic investigation, and it may cause unnecessary downtime for the production application. Option D is wrong because reviewing application logs is a post-containment investigative action; delaying containment to first review logs risks continued data exfiltration or lateral movement.

649
MCQmedium

During a security assessment, a cloud auditor discovers that a virtual machine has a publicly accessible SSH port (22) open to the entire internet (0.0.0.0/0). The VM is a bastion host intended for administration. What should be done to reduce risk?

A.Remove the security group rule for SSH and rely on the operating system firewall.
B.Disable SSH and use a serial console for administration.
C.Enable SSH key authentication and disable password login.
D.Remove the network security group rule allowing SSH from 0.0.0.0/0 and add a rule allowing only the corporate VPN's public IP range.
AnswerD

Restricting SSH to the corporate VPN's public IP range removes exposure to the entire internet while preserving administrative access for authorised staff. This directly satisfies the stem's requirement to reduce risk on a bastion host, since 0.0.0.0/0 permits brute-force and exploitation attempts from any source.

Why this answer

A bastion host should only be accessible from trusted IPs, typically the corporate VPN or a specific IP range, to minimize exposure. Option A is incorrect because removing the security group rule and relying solely on the OS firewall does not address the network-level exposure and may not be as manageable in a cloud environment. Option B is incorrect because disabling SSH entirely would prevent necessary administrative access; serial console is not a scalable alternative.

Option C is incorrect because while SSH key authentication improves security, it does not restrict the IP addresses that can attempt to connect, leaving the host exposed to brute-force attacks from the entire internet.

650
MCQmedium

A company has a hybrid cloud environment with an on-premises data center and Microsoft Azure. The on-premises infrastructure includes a VPN gateway connected to an Azure virtual network via site-to-site VPN. The network team reports that traffic from on-premises to Azure is experiencing high latency and packet loss. The VPN tunnel status shows as connected. The team has verified that the on-premises firewall is not dropping packets. The Azure administrator checks the virtual network gateway metrics and sees high inbound packet drops and a high number of VPN tunnel rekeys. What is the MOST likely cause of the issue?

A.The on-premises VPN device does not support the same encryption algorithms.
B.The Azure virtual network has overlapping address space with on-premises.
C.There is a misconfiguration in the local network gateway address space.
D.The VPN gateway SKU is too small for the traffic volume.
AnswerD

High inbound packet drops alongside frequent VPN tunnel rekeys indicate the gateway is saturating its throughput and tunnel capacity. An undersized SKU cannot sustain the traffic volume, so the tunnel stays connected but drops packets and renegotiates repeatedly, producing latency and loss.

Why this answer

The high inbound packet drops and frequent VPN tunnel rekeys indicate that the VPN gateway is overwhelmed by traffic. A VPN gateway SKU that is too small for the traffic volume cannot handle the throughput, leading to packet drops and forcing the tunnel to rekey more often as it struggles to maintain the connection. This explains the high latency and packet loss despite the tunnel showing as connected.

Option A (incorrect encryption algorithms) would prevent tunnel establishment or cause constant renegotiation, not just increased rekeys and drops. Option B (overlapping address space) would cause routing conflicts, not specifically packet drops and rekeys. Option C (misconfigured local network gateway address space) would result in connectivity failure or traffic not being routed correctly, not packet drops and rekeys within a functioning tunnel.

651
MCQmedium

A company is using Azure VMs and wants to centralize logs from multiple applications for security analysis. The logs must be retained for 2 years. Which Azure service should they use?

A.Azure Activity Log
B.Azure Application Insights
C.Azure Log Analytics
D.Azure Storage Analytics
AnswerC

Azure Log Analytics ingests application logs from multiple sources into a single workspace, then supports KQL queries for security analysis and configurable retention extending to two years. This directly meets the centralisation and long-retention constraints in the stem.

Why this answer

Azure Log Analytics is the service designed to collect, store, and query log data from multiple sources, including applications, VMs, and Azure resources. It supports configurable retention (including long-term retention beyond the default 30 days) and provides KQL-based querying for security analysis. This makes it the correct choice for centralizing logs with a 2-year retention requirement.

Exam trap

CV0-004 often tests the confusion between Application Insights (APM telemetry) and Log Analytics (centralized log store), tricking candidates into choosing Application Insights when the requirement is broad log centralization and retention.

How to eliminate wrong answers

Option A is wrong because Azure Activity Log records subscription-level control plane operations (who created/deleted resources) and is not a general-purpose application log store. Option B is wrong because Application Insights is an APM service for application performance telemetry (requests, dependencies, exceptions) and is not intended as a centralized multi-application log repository. Option D is wrong because Azure Storage Analytics provides metrics and logs specifically for Azure Storage accounts, not for application logs across VMs and services.

652
Multi-Selecthard

A cloud administrator is troubleshooting a performance issue in a virtualized environment. Which TWO metrics should be monitored to identify CPU contention on the hypervisor?

Select 2 answers
A.Swap rate
B.CPU ready time
C.Memory ballooning
D.CPU utilization per core
E.CPU co-stopping time
AnswersB, E

CPU ready time records how long a virtual machine waits in the run queue before the hypervisor schedules its vCPUs. Elevated values directly indicate physical CPU oversubscription and contention, satisfying the stem's requirement to identify CPU contention on the hypervisor.

Why this answer

CPU ready time (B) measures the time a virtual machine is ready to execute but must wait for the hypervisor to schedule it on a physical core. High ready time directly indicates CPU contention, as the VM is being starved of CPU cycles. CPU co-stopping time (E) occurs when multiple vCPUs in a single VM must wait to be scheduled simultaneously, which also signals CPU overcommitment and contention on the hypervisor.

Exam trap

The trap here is that candidates confuse CPU utilization per core (which shows how busy the CPU is) with CPU ready time (which shows how long VMs are waiting), but high utilization alone does not prove contention—only ready and co-stop times directly measure scheduling delays.

653
MCQhard

A cloud security engineer is responsible for an AWS environment that stores regulated data in Amazon S3 buckets. An audit finding states that data at rest in S3 is not encrypted with a customer-managed key, and the organization must retain control over key rotation and access policies. The engineer must implement encryption that satisfies the audit while minimizing changes to existing applications. Which approach should the engineer take?

A.Enable SSE-C by providing encryption keys in each S3 API request.
B.Enable S3 default encryption using SSE-S3 (AES-256) on all buckets.
C.Implement client-side encryption in each application before uploading objects to S3.
D.Configure SSE-KMS with a customer-managed AWS KMS key and set the bucket default encryption to use that key.
AnswerD

SSE-KMS with a customer-managed key lets the organization define key policies, control rotation, and audit key usage via CloudTrail. Setting it as the bucket default ensures new objects are encrypted automatically without application changes. This satisfies the audit requirement for customer-managed keys while minimizing disruption.

Why this answer

SSE-KMS with a customer-managed key gives the organization control over key policies, rotation, and usage auditing while allowing S3 to handle encryption transparently. Setting it as the bucket default means applications do not need modification to encrypt new objects. Other options either leave key control with AWS or require significant application changes.

Exam trap

The trap here is equating any S3 encryption with compliance, when the audit specifically demands customer-managed keys and control over rotation, which only SSE-KMS with a customer-managed key provides.

654
MCQeasy

An organization needs to store archival data for 7 years to meet compliance requirements. The data is rarely accessed, and retrieval time is not critical. Which cloud storage type is most cost-effective?

A.Block storage
B.File storage
C.Object storage
D.Archive storage
AnswerD

Archive storage offers the lowest per-gigabyte cost of the tiers, designed for data retained for years with infrequent access. The stem states retrieval time is not critical, so the slower, pricier-retrieval trade-off is acceptable for seven-year compliance retention.

Why this answer

Archive storage (e.g., AWS Glacier, Azure Archive) is designed for long-term, infrequently accessed data at the lowest cost. Block storage is for VMs. Object storage is for frequent access.

File storage is for shared file systems.

655
MCQhard

A team is developing a serverless application on AWS Lambda. The application uses several third-party libraries that are large in size. To reduce deployment package size and enable reuse across functions, the team wants to include these libraries as a separate layer. However, the total unzipped size of all layers exceeds the Lambda limits. What should the team do to resolve this?

A.Increase the Lambda function's reserved concurrency
B.Use a container image for the Lambda function instead of layers
C.Reduce the number of layers by combining libraries into fewer custom layers
D.Request a service limit increase from AWS for layer size
AnswerB

Container images bypass the layer unzipped-size ceiling entirely, since Lambda permits images up to 10 GB. Packaging the large third-party libraries into the image satisfies the stem's constraint that combined layer size exceeds the limit, while still allowing reuse across functions via a shared image base.

Why this answer

AWS Lambda has a hard limit of 250 MB unzipped for the combined deployment package and all layers. When layers exceed this, packaging the function as a container image (up to 10 GB) is the supported workaround. Container images can include large third-party libraries directly in the image, bypassing the layer size limit while still allowing reuse via shared base images.

Exam trap

CV0-004 often tests the misconception that layer size limits can be raised via support tickets or that consolidating layers reduces total size — candidates must recognize the 250 MB unzipped hard limit and the container image escape hatch.

How to eliminate wrong answers

Option A is wrong because reserved concurrency controls how many concurrent invocations a function can handle; it has no effect on deployment package or layer size limits. Option C is wrong because combining libraries into fewer layers does not reduce the total unzipped size — the 250 MB limit applies to the sum of all layers plus the function package, so consolidation does not help. Option D is wrong because AWS does not offer a service limit increase for Lambda layer size; the 250 MB unzipped limit is a hard quota.

656
MCQhard

A cloud engineer manages an application running on Amazon ECS with the Fargate launch type. The application occasionally experiences task failures during deployment. The engineer wants to inspect the container's standard output and standard error to determine why a task stopped, without modifying the application to write to a file. Which action should the engineer take?

A.Connect to the Fargate task using SSH to read the container's console output
B.Retrieve the task's output from the Amazon ECR repository where the image is stored
C.Configure the task definition to use the awslogs log driver and view the logs in CloudWatch Logs
D.Enable ECS Exec on the service and run docker logs inside the container to retrieve output
AnswerC

Configuring the task definition's container to use the awslogs log driver sends the container's stdout and stderr streams to a specified CloudWatch Logs log group and stream. This captures the output the engineer needs to diagnose why a task stopped, and it requires no application changes because Docker's logging mechanism handles the capture.

Why this answer

For ECS tasks on Fargate, container stdout and stderr must be directed to a logging destination through a log driver in the task definition. The awslogs driver forwards those streams to CloudWatch Logs, where the engineer can review output from both running and stopped tasks. SSH is unavailable, ECS Exec only works on running tasks, and ECR stores images rather than runtime logs.

Exam trap

The trap here is assuming that a stopped Fargate task can be inspected interactively, when Fargate provides no host access and stopped tasks cannot be entered.

657
MCQhard

A company is migrating an on-premises Oracle database to Amazon RDS for MySQL. The migration must have minimal downtime and must handle ongoing changes during migration. The schema needs to be converted to MySQL-compatible format. Which combination of AWS services should the team use?

A.AWS SCT alone
B.AWS DMS with AWS Schema Conversion Tool (SCT)
C.AWS DataSync
D.AWS DMS alone
AnswerB

AWS DMS performs continuous replication using change data capture (CDC) from the Oracle redo logs, satisfying the minimal-downtime and ongoing-changes constraints. AWS SCT converts the Oracle schema to MySQL-compatible DDL, addressing the schema conversion requirement. Together they cover both migration phases without extended outage.

Why this answer

AWS DMS can perform ongoing replication using CDC, and SCT converts schemas between different database engines.

658
MCQmedium

A financial services company runs a critical application on Google Cloud. The security team requires that all data at rest in Cloud Storage buckets be encrypted with customer-managed encryption keys (CMEK) that are rotated every 90 days. The company also needs to maintain full control over key lifecycle and revoke access immediately if a key is compromised. Which GCP service should be used to manage these keys?

A.Cloud Identity and Access Management (IAM)
B.Cloud Hardware Security Module (Cloud HSM)
C.Cloud Data Loss Prevention (DLP)
D.Cloud Key Management Service (Cloud KMS)
AnswerD

Cloud KMS allows organizations to create and manage customer-managed encryption keys (CMEK) for Cloud Storage and other services. It supports automatic rotation schedules (e.g., every 90 days) and provides granular IAM controls to revoke access instantly. The key material is stored in a hardware security module (HSM) or software, and the customer retains full control, meeting all requirements.

Why this answer

Cloud KMS is the centralized key management service in GCP. It enables the creation of CMEK, supports automatic rotation schedules, and integrates with Cloud Storage to encrypt data at rest. Access to keys is controlled via IAM, allowing immediate revocation.

This provides the required control over key lifecycle and meets the 90-day rotation policy.

Exam trap

The trap here is assuming that Cloud HSM alone provides key management, when it is actually a key storage option within Cloud KMS.

659
MCQhard

A DevOps team uses infrastructure as code to deploy cloud resources. Security policy requires that all storage buckets have versioning enabled and are not publicly accessible. How can these requirements be enforced automatically?

A.Add pre-commit hooks to check the IAC templates for compliance.
B.Use security group rules to restrict access to the storage buckets.
C.Implement a cloud policy that disallows public access and requires versioning on all storage resources.
D.Configure a manual approval gate in the deployment pipeline for any storage changes.
AnswerC

A cloud policy enforces both controls at the control plane: it denies creation of publicly accessible buckets and requires versioning, so non-compliant resources fail deployment regardless of the IaC template used. This satisfies the stem's automatic enforcement requirement, unlike scanning or manual review, which detect drift only after provisioning.

Why this answer

Using a cloud policy service (e.g., AWS Service Control Policy, Azure Policy, or GCP Organization Policy) can enforce rules like 'deny public access' and 'require versioning' at the account or organizational level, automatically applying to all storage resources. Option A is wrong because pre-commit hooks check templates but do not enforce at deployment; they can be bypassed. Option B is wrong because security groups apply to network resources like VMs, not storage buckets.

Option D is wrong because a manual approval gate adds human review but does not automatically enforce the security requirements.

660
MCQmedium

A cloud administrator is responsible for an application hosted on Amazon EC2 that stores session data in memory. The business requires that, in the event of an instance failure, a replacement instance can resume serving users with the existing session data intact and with minimal interruption. Which action should the administrator take to meet this requirement?

A.Create an Amazon Machine Image of the instance after each user session is established.
B.Move session state to an external store such as Amazon ElastiCache for Redis and configure the application to use it.
C.Enable detailed monitoring on the EC2 instances to capture session data in Amazon CloudWatch.
D.Configure an Auto Scaling group with a minimum and maximum size of one to replace failed instances automatically.
AnswerB

Externalizing session state to ElastiCache for Redis decouples the session data from any single instance. If an instance fails, a replacement instance can read the same session data from the shared store, allowing users to continue without losing their sessions. This directly satisfies the requirement for session continuity with minimal interruption.

Why this answer

Session data held only in instance memory is lost when that instance fails. Storing sessions in a shared external service such as Amazon ElastiCache for Redis lets any replacement instance retrieve the same session data. This decouples session state from compute, so failover restores both capacity and user continuity with minimal disruption.

Exam trap

The trap here is assuming that Auto Scaling or monitoring restores application session data, when those features only restore or observe compute capacity.

661
Multi-Selectmedium

A cloud administrator wants to choose an auto-scaling policy that can respond to changing demand patterns. Which TWO policy types support dynamic adjustments based on real-time metrics? (Choose TWO)

Select 2 answers
A.Predictive scaling
B.Target tracking scaling
C.Step scaling
D.Scheduled scaling
E.Simple scaling
AnswersB, C

Target tracking scaling continuously adjusts capacity to hold a chosen metric, such as average CPU utilisation, at a target value. It reacts to real-time metric changes automatically, satisfying the requirement for dynamic adjustment without manually defined thresholds.

Why this answer

Target tracking scaling (B) is correct because it continuously adjusts capacity to keep a chosen metric (such as average CPU utilization or ALB request count per target) at a specified target value, reacting dynamically to real-time metric fluctuations. Step scaling (C) is also correct because it adds or removes capacity in defined step adjustments when a CloudWatch alarm breaches a threshold, allowing graduated responses to real-time metric changes. Predictive scaling (A) is not correct here because it forecasts future demand from historical patterns and provisions capacity ahead of time rather than reacting to real-time metrics.

Scheduled scaling (D) is not correct because it scales based on a defined date/time schedule, not on live metrics. Simple scaling (E) is not correct because it performs a single fixed adjustment when an alarm triggers and then enforces a cooldown, so it does not provide the dynamic, metric-driven responsiveness described.

Exam trap

CV0-004 often tests the distinction between reactive policies (target tracking, step scaling) and proactive policies (predictive, scheduled), tricking candidates into selecting predictive scaling when the question emphasizes real-time metric response.

662
MCQmedium

A cloud administrator is managing a multi-tier application in a public cloud. The database tier is hosted on a VM with a persistent disk. Users report that the application is slow, and the administrator notices that disk I/O latency is high. The VM's disk is a standard network-attached storage volume. Which action should the administrator take to improve disk performance?

A.Enable read caching on the VM's operating system.
B.Change the disk type to a higher-performance SSD-based volume.
C.Increase the size of the disk volume to get higher IOPS.
D.Move the database to a VM with more memory.
AnswerB

Standard network-attached storage often has lower IOPS and higher latency compared to SSD-based volumes. Upgrading to a provisioned IOPS SSD or general-purpose SSD volume can significantly reduce latency and increase throughput. This directly addresses the performance bottleneck by providing faster storage media and potentially higher IOPS limits, which is the most effective solution for high disk I/O latency.

Why this answer

High disk I/O latency on a standard network-attached volume indicates that the storage tier is the bottleneck. Upgrading to an SSD-based volume, such as a provisioned IOPS SSD, provides lower latency and higher throughput. This is the most direct and effective way to improve disk performance for a database workload that is sensitive to I/O latency.

Exam trap

The trap here is assuming that increasing disk size or adding memory will solve I/O latency, when the real fix is to change the storage type to a higher-performance option.

663
MCQeasy

Which of the following compliance frameworks is specifically designed for handling healthcare information in the United States?

A.SOC 2 Type II
B.ISO 27001
C.PCI DSS
D.HIPAA
AnswerD

HIPAA, the Health Insurance Portability and Accountability Act, governs protected health information held by US covered entities and business associates. It specifies administrative, physical and technical safeguards plus breach notification, making it the framework specifically designed for US healthcare data handling.

Why this answer

HIPAA (Health Insurance Portability and Accountability Act) sets standards for protecting sensitive patient data. PCI DSS is for payment card data, SOC 2 is for service organizations, ISO 27001 is for information security management.

664
MCQmedium

A cloud administrator is deploying a virtual machine (VM) in a public cloud and must ensure that the VM can be recovered quickly in case of failure. The administrator configures the VM to use a managed disk. What additional deployment step should be taken to meet the recovery objective with minimal cost?

A.Set the VM's boot diagnostics to store logs in a storage account.
B.Configure automated snapshots of the managed disk on a schedule.
C.Deploy a second VM in a different region as a pilot light.
D.Attach the VM to multiple managed disks in an availability set.
AnswerB

Scheduled automated snapshots capture point-in-time copies of the managed disk, enabling rapid restoration after failure or corruption. Snapshots are incremental and cheap, meeting the recovery objective at minimal cost, unlike continuous replication or a full standby VM.

Why this answer

Configuring automated snapshots of the managed disk provides a cost-effective, incremental backup mechanism that enables rapid recovery of the VM in case of failure. Snapshots capture point-in-time copies of the disk and can be used to create a new managed disk or restore the VM quickly, meeting the recovery objective without the expense of maintaining a separate, always-on replica.

Exam trap

The trap here is that candidates often confuse high availability (e.g., availability sets or pilot light deployments) with backup and recovery, assuming that redundancy alone satisfies the recovery objective, when in fact snapshots provide a lower-cost, backup-focused solution for quick recovery after failure.

How to eliminate wrong answers

Option A is wrong because boot diagnostics store logs for troubleshooting boot failures, not for recovering the VM itself; they do not provide a recoverable copy of the VM's disk. Option C is wrong because deploying a second VM in a different region as a pilot light incurs ongoing compute and storage costs for a standby instance, which is more expensive than using snapshots for recovery. Option D is wrong because attaching multiple managed disks in an availability set provides high availability within a single region but does not create recoverable backups; it protects against hardware failure but not against data corruption or accidental deletion, and it increases cost without meeting the recovery objective.

665
MCQmedium

A company wants to deploy a containerized application to a Kubernetes cluster using a rolling update strategy. They have defined a Kubernetes Deployment manifest. Which field controls the number of pods that can be unavailable during the update?

A.spec.strategy.rollingUpdate.maxSurge
B.spec.template.spec.containers[].readinessProbe
C.spec.strategy.rollingUpdate.maxUnavailable
D.spec.replicas
AnswerC

The `maxUnavailable` field, nested under `spec.strategy.rollingUpdate`, directly caps how many pods may be simultaneously unavailable while a rolling update proceeds. This satisfies the stem's requirement to control unavailability during the rollout, whereas `maxSurge` governs extra pods created above the desired replica count instead.

Why this answer

The `spec.strategy.rollingUpdate.maxUnavailable` field in a Kubernetes Deployment manifest explicitly controls the maximum number of Pods that can be unavailable during a rolling update. This field can be set as an absolute number or a percentage of the desired Pod count, ensuring that the update proceeds without dropping below a specified availability threshold.

Exam trap

In CompTIA Cloud+ exams, candidates often confuse `maxSurge` and `maxUnavailable`. While `maxSurge` controls the number of extra Pods created above the target, `maxUnavailable` specifically governs how many Pods can be taken down during a rolling update.

How to eliminate wrong answers

Option A is wrong because `spec.strategy.rollingUpdate.maxSurge` controls the maximum number of Pods that can be created above the desired replica count during an update, not the number of unavailable Pods. Option B is wrong because `spec.template.spec.containers[].readinessProbe` defines a health check that determines when a container is ready to serve traffic, but it does not control the number of Pods that can be unavailable during a rolling update. Option D is wrong because `spec.replicas` sets the desired number of Pod replicas for the Deployment, but it has no direct role in managing the availability constraints during a rolling update.

666
Multi-Selecthard

A cloud security team is implementing encryption for data at rest using customer-managed keys in a cloud KMS. Which THREE practices should be followed?

Select 3 answers
A.Use IAM policies to restrict who can use and manage the keys.
B.Enable automatic key rotation.
C.Store the key material in plaintext in the application code.
D.Use a default cloud provider key to simplify management.
E.Back up the key material securely in a separate location.
AnswersA, B, E

IAM controls access to KMS keys.

Why this answer

IAM policies are essential for enforcing the principle of least privilege in cloud KMS. By restricting who can use (encrypt/decrypt) and manage (rotate/disable/destroy) customer-managed keys, the security team ensures that only authorized principals can access the key material. This prevents unauthorized users or services from compromising data at rest, which is a core requirement for compliance frameworks like PCI DSS or HIPAA.

Exam trap

The CV0-004 exam often tests the misconception that storing keys in code is acceptable if the code is in a private repository, but the trap here is that any plaintext key in code is a critical vulnerability, regardless of repository access controls.

667
MCQmedium

A company uses CloudFormation to manage infrastructure across multiple AWS accounts. They want to deploy a common set of resources (e.g., VPC, IAM roles) to all accounts in their organization. Which CloudFormation feature should they use?

A.Change sets
B.Nested stacks
C.Stack sets
D.Drift detection
AnswerC

Stack sets extend a single CloudFormation template across multiple accounts and regions from one operation, using organisational or administrator accounts as targets. This directly satisfies the requirement to deploy common VPC and IAM resources to every account in the organisation.

Why this answer

CloudFormation StackSets allow you to deploy a single template across multiple AWS accounts and regions in one operation, using either self-managed permissions or AWS Organizations integration. This is the designed feature for organization-wide resource deployment like VPCs and IAM roles. StackSets handle the orchestration, rollback, and drift detection across all target accounts.

Exam trap

CV0-004 often tests the confusion between nested stacks (modularization within one account) and StackSets (multi-account/multi-region deployment), so candidates who see 'common set of resources' and pick nested stacks miss the multi-account requirement.

How to eliminate wrong answers

Option A is wrong because change sets only preview how a stack update will affect a single existing stack; they do not deploy across accounts. Option B is wrong because nested stacks are used to modularize a single stack into reusable child stacks within one account, not to deploy across multiple accounts. Option D is wrong because drift detection identifies configuration differences between the template and actual resources; it does not deploy resources.

668
MCQeasy

A cloud architect is designing a multi-tenant SaaS application on AWS. Which of the following security responsibilities is the CUSTOMER responsible for under the shared responsibility model?

A.Global network infrastructure
B.Patching the hypervisor
C.Physical security of data centers
D.Configuring security groups
AnswerD

Security groups are a customer-configurable network security control.

Why this answer

Under the shared responsibility model, the customer is responsible for data encryption, OS patching, and IAM configuration, while the provider secures the physical infrastructure.

669
MCQhard

A cloud administrator is investigating a sudden increase in latency for a microservices application. Distributed traces show that a single downstream service's response time grew from 20 ms to 2 seconds, and its CPU utilization remains low at 15 percent. The service makes calls to an external third-party API. Which of the following is the MOST likely cause?

A.The service's container CPU limit is throttling it during request bursts.
B.The service is blocked waiting on the third-party API, and its thread pool is saturating under the increased wait time.
C.The service's memory limit is too low, causing the kernel to swap pages to disk.
D.The service's network interface is experiencing packet loss, causing TCP retransmissions.
AnswerB

When a downstream dependency slows from milliseconds to seconds, worker threads spend most of their time waiting, so the pool fills and queued requests wait even longer. CPU stays low because threads are blocked on I/O, not computing. The growing external API latency is the trigger, and the thread pool saturation amplifies it across the service.

Why this answer

A slowdown in an external dependency pushes worker threads into long waits, so a fixed-size thread pool saturates and requests queue behind blocked workers. CPU remains low because the threads are waiting on I/O, not executing. The trace data localizing latency to the third-party call identifies the trigger, and the service's concurrency model explains the amplification.

Exam trap

The trap here is assuming low CPU utilization means the service is healthy, when blocked threads waiting on an external dependency are the classic signature of this pattern.

670
MCQmedium

A cloud administrator needs to centralize logs from multiple AWS services, including VPC flow logs and application logs, to enable searching and querying. Which solution should be used?

A.AWS CloudTrail
B.Amazon S3 with Athena
C.AWS Config
D.Amazon CloudWatch Logs
AnswerD

Amazon CloudWatch Logs ingests VPC flow logs and application logs into log groups, then supports CloudWatch Logs Insights for searching and querying across them. This satisfies the centralisation requirement directly, since both log types converge in one service without additional infrastructure, unlike S3-based aggregation that lacks native querying.

Why this answer

Amazon CloudWatch Logs is the native centralized log management service that ingests logs from EC2, Lambda, VPC Flow Logs, CloudTrail, and application sources, and provides Logs Insights for searching and querying. It supports metric filters, alarms, and subscription filters for downstream processing, making it the correct choice for centralized search and query across multiple AWS services.

Exam trap

CV0-004 often tests the confusion between CloudTrail (API audit), AWS Config (configuration compliance), and CloudWatch Logs (operational log aggregation and search), tempting candidates to pick CloudTrail for log centralization.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and management events for auditing, not application or VPC flow log content, and it is not a search/query engine for arbitrary logs. Option B is wrong because Amazon S3 with Athena can query logs stored in S3, but it requires you to first deliver logs to S3 and does not provide the centralized ingestion, real-time search, or native integration that CloudWatch Logs offers. Option C is wrong because AWS Config evaluates resource configuration compliance and does not centralize or search application or flow logs.

671
Multi-Selecthard

A cloud operations team manages a three-tier application on Google Cloud. After a deployment, users report intermittent 503 errors from the HTTP(S) load balancer, and backend health checks are flapping between healthy and unhealthy. The team suspects the backend instances are being overwhelmed during health check bursts. Which TWO actions should the team take to stabilize the health checks and reduce false failures? (Choose two.)

Select 2 answers
A.Increase the health check's check interval and timeout settings so probes are less frequent and tolerate brief slowdowns.
B.Reduce the number of backend instances in the instance group so each instance receives fewer health check probes.
C.Enable Cloud CDN on the backend service so cached responses absorb the health check traffic.
D.Switch the backend service to use a network load balancer instead of the HTTP(S) load balancer.
E.Configure a longer healthy threshold and unhealthy threshold on the health check to require more consecutive successes and failures.
AnswersA, E

Lengthening the interval and timeout gives backends more time to respond and reduces the probe rate that may be contributing to the flapping. It does not mask a truly failed instance, because consecutive failures are still required, but it prevents transient latency spikes from marking healthy instances as unhealthy during bursts.

Why this answer

Health check flapping during bursts is addressed by tuning the probe itself: a longer interval and timeout reduce probe intensity and tolerate brief slowdowns, while higher healthy and unhealthy thresholds require more consistent evidence before an instance's state changes. Together these settings distinguish transient latency from genuine failure. Caching, changing load balancer type, or removing instances do not reduce false health check failures.

Exam trap

The trap here is treating health check flapping as a capacity or caching problem, when the direct fix is adjusting probe interval, timeout, and consecutive-result thresholds.

672
MCQhard

A cloud architect is designing a multi-account AWS environment and wants to deploy CloudFormation stacks consistently across many accounts. The architect needs a solution that can manage stack instances across multiple accounts and Regions from a single administrator account. Which AWS feature should be used?

A.Stack sets
B.Drift detection
C.Nested stacks
D.Change sets
AnswerA

Stack sets allow a single administrator account to deploy and manage CloudFormation stacks across multiple target accounts and Regions, satisfying the requirement for centralised, consistent multi-account deployment. The specific mechanism is the stack set’s ability to define a template and parameters once, then automatically create and update stack instances in specified accounts and Regions, handling permissions via service-linked roles.

Why this answer

AWS CloudFormation StackSets allow you to deploy stacks across multiple accounts and Regions from a single administrator account. They are designed for consistent, scalable deployments, enabling you to create, update, or delete stacks in many accounts simultaneously using a single CloudFormation template and set of parameters.

Exam trap

CV0-004 often tests the confusion between StackSets and nested stacks; candidates might think nested stacks can span accounts, but they are limited to a single account and Region.

How to eliminate wrong answers

Option B is wrong because drift detection only identifies differences between the actual stack resources and the expected template, it does not deploy stacks. Option C is wrong because nested stacks are used to modularize a single stack by referencing other stacks as resources, but they do not span multiple accounts or Regions. Option D is wrong because change sets preview how changes will affect running resources, but they do not facilitate multi-account deployment.

673
Multi-Selectmedium

A company is designing a hybrid cloud storage solution. Which TWO storage services are suitable for a shared file system accessible from both on-premises and cloud VMs? (Select TWO.)

Select 2 answers
A.Azure Blob
B.Azure Files
C.Amazon S3
D.Amazon EBS
E.Amazon EFS
AnswersB, E

Azure Files exposes SMB and NFS shares, so on-premises servers and cloud VMs mount the same file system concurrently. This satisfies the hybrid shared-file-system constraint without replication or application changes, unlike object storage such as Blob.

Why this answer

Azure Files (B) is correct because it provides fully managed SMB and NFS file shares that can be mounted simultaneously from on-premises Windows/Linux machines and Azure VMs, making it a true shared file system for hybrid scenarios. Amazon EFS (E) is correct because it is a managed NFS file system that supports mounting from on-premises servers via AWS Direct Connect or VPN as well as from EC2 instances in multiple Availability Zones. Azure Blob (A) is object storage accessed via HTTP/REST rather than a mountable shared file system, so it does not meet the requirement.

Amazon S3 (C) is also object storage with a REST API, not a POSIX/NFS/SMB file system. Amazon EBS (D) provides block storage volumes attached to a single EC2 instance and cannot be shared across on-premises and cloud VMs.

Exam trap

The trap is confusing object storage (Blob, S3) with file storage (Files, EFS) — candidates must remember that shared file systems require SMB/NFS protocols, not REST APIs.

674
MCQhard

A DevOps team deploys a containerized application on Amazon EKS. The security team wants to ensure that containers do not run as root and that read-only root filesystems are enforced. Which Kubernetes mechanism should be used?

A.Pod Security Standards
B.Kubernetes RBAC
C.Network Policies
D.Secrets management
AnswerA

Pod Security Standards enforce security constraints at the pod level.

Why this answer

Pod Security Standards (formerly PSP) define security contexts, including runAsNonRoot and readOnlyRootFilesystem, to enforce these policies.

675
MCQhard

During a penetration test, a cloud security engineer discovers that a storage bucket is publicly accessible because of a misconfigured block public access setting. The bucket contains encrypted data. Which of the following is the primary risk?

A.The bucket name is exposed to enumeration.
B.Data is unreadable because it is encrypted.
C.The encryption key is exposed.
D.Unauthorized users can list and download objects, but encryption at rest protects content if the key is also not accessible.
AnswerD

This accurately describes the primary risk: data exfiltration is possible, but encryption provides a layer of protection if the key is secure.

Why this answer

Unauthorized users can list and download encrypted objects, even if the data is encrypted at rest. The primary risk is data exfiltration if the encryption key is compromised or the data is not properly encrypted.

Page 8

Page 9 of 12

Page 10