Courseiva

CCNA Cloud Architecture and Design Questions

75 of 133 questions · Page 1/2 · Cloud Architecture and Design · Answers revealed

1
MCQeasy

A company is migrating a legacy application to the cloud. The application uses a relational database and requires strong consistency and ACID transactions. Which cloud service model is most appropriate?

A.Infrastructure as a Service (IaaS) with self-managed database servers.
B.Function as a Service (FaaS) with a serverless database.
C.Software as a Service (SaaS) with a built-in database.
D.Platform as a Service (PaaS) with a managed relational database.
AnswerD

PaaS with a managed relational database provides a platform that handles infrastructure management while supporting relational databases with ACID compliance and strong consistency. This allows the company to focus on the application while ensuring the database meets its transactional requirements, making it the most appropriate model.

Why this answer

PaaS with a managed relational database is ideal because it provides a platform for the application while the managed database ensures ACID compliance and strong consistency. The company benefits from reduced operational overhead and can focus on the application, aligning with the migration goals.

Exam trap

The trap here is assuming that IaaS with self-managed databases is necessary for ACID compliance, when in fact managed PaaS databases also provide strong consistency and transactional support.

2
MCQmedium

A cloud architect is designing a solution that requires a shared, POSIX-compliant file system that can be mounted concurrently by hundreds of Linux EC2 instances across multiple Availability Zones in the same AWS Region. The workload is read-heavy, and the file system must scale storage capacity automatically as data grows. Which AWS service should the architect choose?

A.AWS Storage Gateway in File Gateway mode
B.Amazon Elastic Block Store (Amazon EBS) with Multi-Attach enabled
C.Amazon FSx for Windows File Server
D.Amazon Elastic File System (Amazon EFS)
AnswerD

Amazon EFS is a fully managed, elastic NFS file system that supports the POSIX interface and can be mounted concurrently by thousands of EC2 instances across multiple Availability Zones within a Region. It automatically scales storage capacity up and down as files are added or removed, making it ideal for read-heavy shared workloads that require cross-AZ access.

Why this answer

Amazon EFS is the correct choice because it is a managed NFS file system that supports POSIX semantics, can be mounted by many Linux instances simultaneously across multiple Availability Zones, and elastically scales storage capacity. The other services either provide block storage, Windows-oriented SMB file storage, or hybrid gateway functionality that does not meet the cross-AZ shared file system requirement.

Exam trap

The trap here is assuming that Amazon EBS Multi-Attach provides a shared file system for multiple instances across Availability Zones, when it actually only supports block-level attachment within a single Availability Zone.

3
MCQmedium

A cloud architect is designing a stateless containerized workload that must remain available even if an entire data center fails. The workload has no persistent local state and must be able to scale horizontally across regions. Which design decision BEST meets these requirements?

A.Deploy the containers on a single large virtual machine with a snapshot-based backup taken every hour.
B.Deploy identical container clusters in two or more regions and use a global load balancer with health checks to route traffic to healthy regions.
C.Deploy the containers in a single region across multiple availability zones and rely on the orchestrator to reschedule failed tasks.
D.Deploy the containers in one region and configure a DNS failover record that points to a cold standby environment in another region.
AnswerB

This directly satisfies the requirement to survive a full data center failure. A global load balancer continuously probes regional endpoints and redirects user traffic to a healthy region when one fails. Because the workload is stateless and horizontally scalable, identical clusters can run in parallel without data synchronization concerns, providing both high availability and geographic redundancy.

Why this answer

The workload is stateless, so it can be replicated across regions without data consistency concerns. Running identical clusters in multiple regions behind a global load balancer with health checks ensures that traffic is automatically redirected away from a failed region, meeting the requirement to survive a full data center failure. This design also supports horizontal scaling by adding capacity in any region.

Exam trap

The trap here is assuming that multi-AZ deployment within a single region is sufficient for data center failure, when a regional outage requires a multi-region design.

4
MCQhard

A company runs a stateless web application on auto-scaling EC2 instances behind an Application Load Balancer. The application experiences sudden traffic spikes. Which scaling approach will handle the spikes most efficiently while minimizing cost?

A.Horizontal scaling with auto-scaling based on CPU utilization
B.Vertical scaling of existing instances
C.Using reserved instances for all capacity
D.Pre-provisioning a large number of instances
AnswerA

Horizontal scaling adds EC2 instances, and CPU-based auto-scaling triggers new capacity only when load rises, then removes it afterwards. This matches spiky, stateless traffic efficiently and keeps cost low, unlike vertical scaling or always-on over-provisioning.

Why this answer

Horizontal scaling (adding instances) combined with auto-scaling based on metrics is best for handling spikes cost-effectively in a stateless app.

5
MCQmedium

A cloud engineer needs to store database backups that must be retained for seven years. The backups are rarely accessed. Which storage type is most cost-effective for this use case?

A.Object storage
B.Block storage
C.Archive storage
D.File storage
AnswerC

Archive storage offers the lowest per-gigabyte cost of Azure's blob tiers, designed for data retained for long periods and rarely accessed. It meets the seven-year retention requirement at minimal expense, unlike hot or cool tiers.

Why this answer

Archive storage (also called cold or archival tier) is purpose-built for data that is rarely accessed and must be retained for long periods, offering the lowest per-gigabyte storage cost among storage classes. It trades off higher retrieval costs and longer retrieval times (minutes to hours) for minimal storage cost, which is exactly the profile of seven-year database backups that are rarely accessed. Object storage is a storage architecture, not a cost tier, and standard object storage tiers are more expensive than archive.

Exam trap

CV0-004 often tests the confusion between storage architecture (object, block, file) and storage cost tier (hot, cool, archive), causing candidates to pick 'object storage' when the question is really about the cheapest retention tier.

How to eliminate wrong answers

Option A is wrong because object storage is a data organization model (flat namespace with metadata and unique IDs) rather than a cost-optimized retention tier; while archive storage is often implemented as an object storage class, choosing 'object storage' generically does not address the cost-effectiveness requirement for rarely accessed long-term data. Option B is wrong because block storage presents raw volumes to a single host, is typically the most expensive per GB, and is designed for active workloads like databases and boot volumes — not for seven-year cold retention. Option D is wrong because file storage provides shared hierarchical file systems (e.g., NFS/SMB) for active collaboration and is not cost-optimized for long-term archival retention.

6
MCQhard

A healthcare company runs a patient portal on virtual machines in a single on-premises datacenter. Regulatory requirements mandate that data must remain on-premises, but the company wants to burst to a public cloud during seasonal peaks and maintain a consistent operational model. The architect must design a hybrid solution that supports workload portability and centralized identity. Which approach BEST meets these requirements?

A.Deploy Azure Arc-enabled servers to project the on-premises VMs into Azure, use Azure Arc-enabled Kubernetes for burst workloads, and integrate Microsoft Entra ID for centralized identity.
B.Establish a site-to-site VPN between the datacenter and the cloud, then manage each environment with its own native tools and separate identity stores.
C.Use a third-party backup appliance to copy VM images to the cloud and restore them as cloud instances during peak periods, keeping separate credentials in each environment.
D.Replicate all patient data to the public cloud and run the portal entirely there, using the cloud provider's identity service for authentication.
AnswerA

Azure Arc projects on-premises servers and Kubernetes clusters into Azure Resource Manager, enabling consistent management, policy, and monitoring across both environments while keeping data on-premises. Burst workloads can run in Azure connected to the same identity plane through Microsoft Entra ID, satisfying portability and centralized identity.

Why this answer

Azure Arc extends Azure management, policy, and monitoring to on-premises servers and Kubernetes clusters, so the company keeps patient data local while gaining a consistent operational model. Arc-enabled Kubernetes supports bursting workloads to Azure, and Microsoft Entra ID provides centralized identity across both environments, meeting portability and identity requirements.

Exam trap

The trap here is equating a site-to-site VPN with hybrid cloud management; connectivity alone does not deliver consistent tooling, policy, or identity across environments.

7
MCQhard

A financial services firm runs a latency-sensitive trading application in a public cloud. The security team requires that traffic between the application tier and the database tier never traverse the public internet, that both tiers reside in the same virtual network, and that access to the database be restricted to specific application subnet addresses. Which combination of cloud networking controls should the architect implement?

A.Place the tiers in separate virtual networks and connect them with a site-to-site VPN tunnel over the internet.
B.Assign public IP addresses to the database nodes and use a host-based firewall to allow only the application servers.
C.Put both tiers in the same virtual network and rely on the default allow-all rules provided by the cloud platform.
D.Place both tiers in the same virtual network and attach a network security group rule to the database subnet allowing only the application subnet CIDR.
AnswerD

Keeping both tiers in one virtual network means traffic stays on the provider's private backbone and never crosses the public internet. A network security group or firewall rule scoped to the database subnet that permits only the application subnet's CIDR enforces least-privilege access at the subnet boundary, satisfying both the private-path and restricted-access requirements.

Why this answer

Hosting both tiers in a single virtual network guarantees east-west traffic remains on the provider's private network, and a network security group scoped to the database subnet that allows only the application subnet CIDR enforces least-privilege access. Together these controls satisfy the private-path and restricted-access mandates without introducing internet routing or unnecessary tunnel overhead.

Exam trap

The trap here is assuming that encryption via a VPN makes traffic private, when it still traverses the public internet and adds latency.

8
MCQeasy

Which cloud characteristic allows a user to provision additional resources automatically without requiring human intervention?

A.Measured service
B.Resource pooling
C.Rapid elasticity
D.Broad network access
AnswerC

Rapid elasticity provisions and releases resources automatically as demand changes, satisfying the stem's requirement for scaling without human intervention. Measured service and on-demand self-service cover metering and user-initiated provisioning, but only rapid elasticity delivers the automatic, dynamic capacity adjustment described.

Why this answer

Rapid elasticity is the cloud characteristic that allows resources to be automatically provisioned and released to scale rapidly with demand, often without human intervention. This is enabled by auto-scaling policies and APIs that respond to metrics like CPU utilization or request count. It directly matches the description of automatic provisioning without human intervention.

Exam trap

The trap is confusing rapid elasticity with resource pooling or measured service — candidates often pick 'resource pooling' because both involve shared infrastructure, but only rapid elasticity describes automatic, demand-driven provisioning without human intervention.

How to eliminate wrong answers

Option A is wrong because measured service refers to the pay-as-you-go billing model where resource usage is metered and charged, not automatic provisioning. Option B is wrong because resource pooling describes the multi-tenant model where physical resources are shared among customers, not the automatic scaling behavior. Option D is wrong because broad network access means services are available over the network via standard mechanisms, which is about accessibility, not automatic scaling.

9
MCQmedium

A company runs a stateless web application on virtual machines. To handle increased traffic, they add more virtual machines and distribute incoming requests among them. What is this scaling method called?

A.Right-sizing
B.Vertical scaling
C.Auto-scaling
D.Horizontal scaling
AnswerD

Horizontal scaling adds more VM instances to the pool and spreads requests across them, matching the stem's stateless web tier. Vertical scaling would instead resize a single existing VM, which cannot distribute load across multiple hosts.

Why this answer

Horizontal scaling (scaling out) adds more instances — in this case, more virtual machines — and distributes incoming requests among them, typically via a load balancer. This increases capacity by adding parallel resources rather than making a single resource larger. The scenario explicitly describes adding more VMs and distributing requests, which is the definition of horizontal scaling.

Exam trap

CV0-004 often tests the confusion between horizontal scaling (adding instances) and auto-scaling (the automation that adjusts capacity), causing candidates to pick auto-scaling when the question describes the scaling method itself.

How to eliminate wrong answers

Option A is wrong because right-sizing means adjusting the size of an existing instance to match its workload (e.g., downsizing an over-provisioned VM), not adding more instances to handle traffic. Option B is wrong because vertical scaling (scaling up) increases the resources of a single instance — more CPU, RAM, or storage on one VM — which has a hardware ceiling and often requires downtime; the scenario adds multiple VMs, not a bigger one. Option C is wrong because auto-scaling is the automation mechanism that adjusts capacity based on demand; it can perform horizontal scaling, but the question asks for the scaling method itself, which is horizontal scaling, not the automation policy.

10
MCQmedium

A cloud engineer is designing a disaster recovery plan with an RTO of 2 hours and RPO of 15 minutes. Which strategy best meets these requirements?

A.Pilot light with hourly snapshots
B.Warm standby with continuous replication
C.Cold standby with daily backups
D.Active-active across regions
AnswerB

Warm standby with continuous replication keeps a scaled-down environment running and replicates data continuously, giving an RPO near zero and failover well within two hours. This satisfies both the 15-minute RPO and 2-hour RTO at lower cost than active-active.

Why this answer

A warm standby with continuous replication keeps a scaled-down but fully functional copy of the environment running in a secondary region, with data replicated continuously. This allows failover within minutes, easily meeting the 15-minute RPO, and the standby can be scaled up to full capacity within the 2-hour RTO. It balances cost and recovery speed better than the other options for these specific targets.

Exam trap

The trap is that candidates focus only on RTO and pick pilot light or cold standby as 'cheaper,' ignoring that the 15-minute RPO rules out hourly or daily backups — the RPO requirement is the deciding constraint here.

How to eliminate wrong answers

Option A is wrong because hourly snapshots yield an RPO of up to 60 minutes, which exceeds the 15-minute requirement, even though a pilot light could meet the 2-hour RTO. Option C is wrong because daily backups produce an RPO of up to 24 hours and a cold standby requires provisioning infrastructure from scratch, likely exceeding the 2-hour RTO. Option D is wrong because active-active across regions exceeds the requirements and is significantly more expensive and complex than necessary; it is over-engineering for a 2-hour RTO.

11
Multi-Selecteasy

A company is considering using a public cloud provider. Which TWO characteristics are typical of a public cloud deployment? (Select TWO.)

Select 2 answers
A.The customer has full control over the physical infrastructure
B.The deployment is isolated to a single organization
C.Resources are shared among multiple customers
D.The customer pays only for the resources they use
E.Resources are hosted on-premises
AnswersC, D

Multi-tenancy is the defining trait: the provider pools compute, storage and networking across customers, isolating tenants logically rather than physically. This shared-resource model satisfies the stem's public cloud characteristic, contrasting with single-tenant private deployments where hardware is dedicated to one organisation.

Why this answer

A public cloud is characterized by multi-tenancy (resources shared among multiple customers) and pay-as-you-go pricing, where the customer pays only for the resources they use. Options C and D describe these typical characteristics. Option A is incorrect because the cloud provider manages the physical infrastructure, not the customer.

Option B describes a private cloud, which is isolated to a single organization. Option E describes on-premises deployment, not public cloud.

12
Multi-Selectmedium

A cloud architect is designing a disaster recovery plan for a critical application. Which TWO metrics should be defined to establish recovery objectives?

Select 2 answers
A.RPO (Recovery Point Objective)
B.MTBF (Mean Time Between Failures)
C.RTO (Recovery Time Objective)
D.SLA (Service Level Agreement)
E.MTTR (Mean Time to Repair)
AnswersA, C

RPO defines the maximum tolerable data loss measured in time, determining how frequently backups or replication must occur. It directly satisfies the stem's requirement to establish recovery objectives by quantifying the acceptable gap between the last recoverable data point and the failure moment.

Why this answer

RPO (Recovery Point Objective) is correct because it defines the maximum acceptable amount of data loss measured in time, establishing how far back the recovery must restore data and thus driving backup frequency. RTO (Recovery Time Objective) is correct because it defines the maximum acceptable downtime, i.e., how quickly the application must be restored after a disruption, which directly shapes the DR architecture and failover strategy. Together, RPO and RTO are the two standard recovery objectives used to design and validate a disaster recovery plan.

MTBF (Mean Time Between Failures) is a reliability metric describing expected time between hardware/component failures, not a recovery objective. SLA (Service Level Agreement) is a contractual document that may reference RPO/RTO but is not itself a recovery metric. MTTR (Mean Time to Repair) measures average time to fix a failed component, which is an operational metric rather than a defined recovery objective.

Exam trap

CV0-004 often tests the confusion between recovery metrics (RPO/RTO) and reliability metrics (MTBF/MTTR), or the misconception that an SLA itself defines recovery objectives rather than being a document that references them.

13
MCQhard

A cloud architect is designing a microservices-based application that requires inter-service communication. The services must be loosely coupled, and the architecture must handle service failures gracefully. Which communication pattern is most appropriate?

A.Asynchronous messaging using a message queue or pub/sub system.
B.Remote procedure calls (RPC) with timeouts.
C.Shared database with direct reads and writes.
D.Synchronous HTTP/REST calls between services.
AnswerA

Asynchronous messaging decouples services by allowing them to communicate via messages without waiting for immediate responses. If a service fails, messages can be queued and processed later, providing graceful failure handling. This pattern promotes loose coupling and resilience, making it the most appropriate for the scenario.

Why this answer

Asynchronous messaging decouples services and allows them to operate independently, with messages buffered during failures. This ensures that a service outage does not immediately impact others, providing resilience and loose coupling, which are critical for microservices architectures.

Exam trap

The trap here is thinking that synchronous calls with retries or timeouts provide sufficient decoupling, when they still create runtime dependencies that can propagate failures.

14
MCQeasy

A company is migrating a legacy application to the cloud. The application uses a fixed IP address that is hard-coded in several clients. The company needs to ensure the IP address remains the same even if the underlying virtual machine is replaced. Which cloud networking feature should be used?

A.A content delivery network (CDN) distribution with a custom domain.
B.A dynamic host configuration protocol (DHCP) reservation.
C.A static private IP address assigned manually to the virtual machine.
D.An elastic IP address that can be associated with a different virtual machine.
AnswerD

An elastic IP address is a static public IPv4 address designed for dynamic cloud computing. It can be associated with any virtual machine in the account and moved between instances if a failure occurs. This allows clients that use the hard-coded IP to continue reaching the application even after the underlying virtual machine is replaced, satisfying the requirement for a stable public endpoint.

Why this answer

An elastic IP address is a static public IP that can be reassigned to another virtual machine. This allows the application to keep the same public endpoint even when the underlying instance is replaced, which is essential when clients have the IP hard-coded. DHCP reservations and static private IPs are limited to private networks and do not provide a movable public address.

Exam trap

The trap here is assuming that a static private IP or a DHCP reservation provides a public IP that can be moved, when only an elastic IP offers that capability.

15
MCQmedium

An organization is designing a disaster recovery plan with a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 1 hour. Which disaster recovery strategy best meets these requirements while minimizing cost?

A.Cold standby
B.Backup and restore
C.Warm standby
D.Hot standby
AnswerC

Warm standby satisfies the 4-hour RTO through pre-provisioned, scaled-down infrastructure that can be promoted quickly, while continuous data replication keeps the 1-hour RPO. It costs less than hot standby's fully mirrored active environment, avoiding the expense of duplicate capacity the RTO does not demand.

Why this answer

Warm standby maintains a partially running environment that can be fully activated quickly, meeting an RTO of 4 hours and RPO of 1 hour at a lower cost than hot standby.

16
MCQmedium

A cloud engineer is deploying a web application that requires SSL termination and content-based routing. Which type of load balancer should be used?

A.Gateway Load Balancer
B.Classic Load Balancer
C.Application Load Balancer
D.Network Load Balancer
AnswerC

An Application Load Balancer operates at layer 7, terminating TLS and routing requests by URL path, host header or content. Network load balancers work at layer 4, forwarding packets by IP and port only, so they cannot inspect content or terminate SSL.

Why this answer

An Application Load Balancer (layer 7) can perform SSL termination and route based on content such as URL paths or host headers.

17
MCQmedium

A cloud engineer is designing a microservices architecture on AWS. The services must communicate asynchronously and decouple producers from consumers. The engineer needs a fully managed message queuing service that supports dead-letter queues and message retention up to 14 days. Which AWS service should be used?

A.Amazon SQS
B.AWS Step Functions
C.Amazon EventBridge
D.Amazon SNS
AnswerA

Amazon SQS is a fully managed message queuing service that enables asynchronous communication and decoupling of microservices. It supports standard and FIFO queues, dead-letter queues for handling failed messages, and message retention configurable from 1 minute to 14 days. This directly matches the requirements for a managed queuing service with dead-letter queue support.

Why this answer

Amazon SQS is the only fully managed message queuing service among the options. It provides asynchronous decoupling, supports dead-letter queues for isolating problematic messages, and allows message retention up to 14 days. SNS is pub/sub, EventBridge is an event bus, and Step Functions is an orchestrator, so they do not meet the specific queuing and retention requirements.

Exam trap

The trap here is confusing pub/sub messaging with queuing, or assuming that EventBridge or Step Functions can replace a dedicated message queue for asynchronous decoupling.

18
MCQmedium

A cloud architect is designing a web application that must remain available during a full region outage. They plan to deploy identical resources in two separate geographical regions. Which high availability architecture is described?

A.Cold standby
B.Active-passive
C.Active-active
D.Warm standby
AnswerC

Active-active runs identical workloads concurrently in both regions, each serving traffic, so a full region outage leaves the surviving region already handling production load. This differs from active-passive, where the standby region only takes over after failover, incurring downtime.

Why this answer

Active-active is the correct architecture because it deploys identical resources in two or more regions simultaneously, with both regions actively serving traffic. This provides high availability and load distribution, and if one region fails, the other continues to handle requests without interruption. This is the only option that describes both regions actively running and serving users at the same time.

Exam trap

CV0-004 often tests the distinction between active-active and active-passive/warm standby, where candidates confuse 'both regions running' with 'both regions serving traffic'; only active-active has both regions actively serving.

How to eliminate wrong answers

Option A is wrong because cold standby involves a secondary region that is not running and must be provisioned and started after a failure, resulting in significant downtime. Option B is wrong because active-passive has one region actively serving traffic while the other is on standby (often running but not serving), which does not provide immediate failover without some delay. Option D is wrong because warm standby involves a scaled-down but running secondary environment that requires scaling up before it can handle full production load, introducing a delay.

19
MCQeasy

Which of the following is a key benefit of using object storage like Amazon S3 over block storage?

A.Unlimited scalability for unstructured data
B.Direct attachment to a single VM
C.Supports file-level locking
D.Lower latency for database workloads
AnswerA

Object storage addresses the stem's scalability constraint by using a flat namespace with HTTP-accessible objects, so capacity grows without provisioning volumes. Block storage requires pre-sized LUNs and a filesystem, capping practical scale. This makes S3 suitable for unstructured data such as media and logs.

Why this answer

Amazon S3 is designed for unlimited scalability, allowing you to store and retrieve any amount of unstructured data (e.g., images, videos, backups) without provisioning storage in advance. Unlike block storage, which has fixed size limits per volume, S3 automatically scales to accommodate petabytes of data, making it ideal for modern cloud-native applications.

Exam trap

The CV0-004 exam often tests the misconception that object storage is suitable for low-latency transactional workloads, but the trap here is that candidates confuse scalability with performance, forgetting that block storage (e.g., EBS) is optimized for low latency via direct attachment and NVMe protocols, while object storage prioritizes scale and cost over speed.

How to eliminate wrong answers

Option B is wrong because direct attachment to a single VM is a characteristic of block storage (e.g., Amazon EBS), not object storage like S3, which is accessed via HTTP/HTTPS APIs over the network. Option C is wrong because object storage typically does not support file-level locking; it uses eventual consistency or strong consistency for objects, not file locks like NFS or SMB. Option D is wrong because object storage has higher latency compared to block storage (e.g., EBS or local SSD) due to its HTTP-based API and distributed architecture, making it unsuitable for low-latency database workloads.

20
MCQmedium

A healthcare company must ensure that patient records stored in a public cloud are encrypted at rest and that the company alone controls the keys used for encryption, including the ability to revoke access immediately if an employee leaves. Which key management approach BEST satisfies these requirements?

A.Enable transport layer security for all connections and rely on it to protect stored patient records.
B.Use provider-managed encryption keys that the cloud vendor generates and rotates automatically.
C.Use customer-managed keys stored in a cloud key management service with granular access policies.
D.Encrypt data with a symmetric key hardcoded in the application source code stored in the repository.
AnswerC

Customer-managed keys in a key management service let the organization own the key material and define access through policies. Revoking a user's permission to the key immediately removes their ability to decrypt data, and the company can rotate or disable keys itself. This meets both the encryption-at-rest and exclusive-control requirements.

Why this answer

Customer-managed keys in a cloud key management service give the healthcare company ownership of the key material and policy-based control over who may use it. Revoking a departing employee's key permissions blocks decryption immediately, and the organization can rotate or disable keys on its own schedule, satisfying both encryption-at-rest and exclusive key custody.

Exam trap

The trap here is treating encryption in transit as equivalent to encryption at rest, when they protect data in different states.

21
MCQeasy

A company is migrating a legacy application to Google Cloud. The application requires a relational database with automatic failover and replication across multiple zones within a region. Which Google Cloud service should the company use?

A.Cloud Spanner
B.Firestore
C.Cloud Bigtable
D.Cloud SQL with high availability configuration
AnswerD

Cloud SQL offers a high availability configuration that creates a standby instance in a different zone within the same region. It provides automatic failover and synchronous replication to the standby. This meets the requirement for a relational database with automatic failover and multi-zone replication within a region.

Why this answer

Cloud SQL with high availability configuration is the correct choice because it provides a relational database with automatic failover and synchronous replication to a standby instance in a different zone. This matches the requirement for multi-zone replication within a region for a legacy relational application.

Exam trap

The trap here is assuming that any highly available database service will work; Cloud SQL HA is specifically designed for regional multi-zone failover, while other services are either NoSQL or globally distributed.

22
MCQhard

A cloud architect is designing a VPC for a three-tier web application. The web servers must be accessible from the internet, the application servers should only be reachable from the web tier, and the database servers should not have any public IP addresses and should be isolated. Which subnet design meets these requirements?

A.Web tier in public subnet, app tier in private subnet, database tier in a separate private subnet with no internet gateway
B.Web tier in public subnet, app and database tiers in the same private subnet
C.All servers in private subnets with a NAT gateway for inbound traffic
D.All servers in the same public subnet with security groups
AnswerA

This design satisfies every stated constraint: the public subnet exposes web servers to the internet, the private app subnet is reachable only from the web tier via security groups, and the isolated database subnet lacks a route to an internet gateway, so no public IPs are needed.

Why this answer

A three-tier architecture requires strict network segmentation: the web tier in a public subnet with a route to an Internet Gateway for inbound traffic, the app tier in a private subnet reachable only from the web tier (via security groups or NACLs), and the database tier in a separate private subnet with no route to an Internet Gateway or NAT Gateway, ensuring complete isolation. This design enforces least-privilege network access and satisfies the stated requirements.

Exam trap

CV0-004 often tests the misconception that security groups alone can isolate tiers within a single public subnet — candidates must recognize that subnet-level routing (public vs. private, presence of IGW/NAT) is the primary segmentation control.

How to eliminate wrong answers

Option B is wrong because placing the app and database tiers in the same private subnet violates the isolation requirement — the database would share a subnet with the app tier, allowing lateral movement and broader reachability than intended. Option C is wrong because a NAT gateway provides outbound internet access for private subnets, not inbound access; putting all servers in private subnets would make the web tier unreachable from the internet. Option D is wrong because placing all servers in a single public subnet exposes the app and database tiers to the internet and relies solely on security groups, violating the requirement that the database have no public IP and be isolated.

23
MCQmedium

A company deploys a stateless web application across two AWS Availability Zones behind a load balancer. This design primarily improves which characteristic?

A.Cost efficiency
B.High availability
C.Scalability
D.Security
AnswerB

Spreading the stateless application across two Availability Zones behind a load balancer removes a single point of failure. If one zone fails, the load balancer routes traffic to the surviving zone, so the design primarily improves high availability rather than scalability, elasticity or durability.

Why this answer

Deploying a stateless web application across two AWS Availability Zones behind a load balancer primarily improves high availability. If one AZ fails, the load balancer routes traffic to the healthy AZ, ensuring the application remains accessible. This design eliminates a single point of failure.

Exam trap

The trap here is confusing high availability with scalability; multi-AZ improves availability, while scalability is about handling growth, often achieved via Auto Scaling.

How to eliminate wrong answers

Option A is wrong because deploying across multiple AZs may increase costs due to duplicate resources and data transfer charges. Option C is wrong because scalability is about handling increased load, which can be achieved within a single AZ using Auto Scaling; multi-AZ is for availability. Option D is wrong because security is enhanced through other measures like security groups, IAM, and encryption, not by multi-AZ deployment itself.

24
MCQeasy

A cloud engineer is configuring object storage for a media company that stores video archives accessed a few times per year but must retain them for seven years for compliance. Retrieval latency of several hours is acceptable, and cost must be minimized. Which storage tier characteristic should the engineer select?

A.An archive tier with long retrieval times and the lowest storage cost.
B.A local SSD volume attached to a virtual machine that stores the archives.
C.A standard tier with millisecond access and no retrieval fee.
D.A high-performance tier with low latency and frequent-access pricing.
AnswerA

Archive tiers are engineered for long-term retention of data that is rarely accessed, offering the lowest storage price per gigabyte in exchange for retrieval times measured in hours. The scenario permits several hours of retrieval latency and prioritizes cost, so an archive tier aligns exactly with both the access pattern and the compliance retention period.

Why this answer

Archive-class object storage is purpose-built for data retained for years but read only occasionally, trading retrieval latency for the lowest storage cost per gigabyte. Since the media company accepts hours of retrieval delay and emphasizes cost, the archive tier satisfies both the compliance retention period and the budget constraint better than any frequently accessed or block-based option.

Exam trap

The trap here is equating durability and compliance retention with frequent-access storage, when archive tiers provide equal durability at much lower cost.

25
MCQeasy

A company wants to migrate its on-premises workloads to the cloud but must keep sensitive customer data on-premises due to regulatory compliance. Which cloud deployment model should they use?

A.Public cloud
B.Hybrid cloud
C.Multi-cloud
D.Private cloud
AnswerB

Hybrid cloud keeps sensitive customer data on-premises while extending workloads to the public cloud, directly satisfying the regulatory constraint. Unlike public or private cloud alone, it connects on-premises infrastructure with cloud services, letting the company migrate non-sensitive workloads without breaching data-residency rules.

Why this answer

A hybrid cloud model combines on-premises infrastructure with public cloud services, allowing sensitive data to remain on-premises while other workloads leverage cloud scalability. This meets regulatory compliance by keeping data local while enabling cloud benefits for non-sensitive components.

Exam trap

The trap is confusing hybrid cloud with multi-cloud. Multi-cloud uses multiple public clouds but does not address on-premises data residency requirements.

How to eliminate wrong answers

Option A is wrong because public cloud alone cannot keep sensitive data on-premises. Option C is wrong because multi-cloud involves multiple public cloud providers, not on-premises integration. Option D is wrong because private cloud is solely on-premises and does not provide the flexibility of public cloud for other workloads.

26
MCQeasy

A company wants to migrate its on-premises virtualized workloads to the cloud while maintaining control over the operating system and middleware. Which cloud service model should they choose?

A.SaaS
B.FaaS
C.PaaS
D.IaaS
AnswerD

IaaS delivers virtualised compute, storage and networking while leaving the guest OS, patching and middleware entirely under the customer's control. That directly satisfies the stem's requirement to retain control over the operating system and middleware, unlike PaaS or SaaS, which abstract those layers away.

Why this answer

IaaS (Infrastructure as a Service) provides virtualized compute, storage, and networking where the customer retains control over the operating system, middleware, and runtime, while the provider manages the underlying physical infrastructure. This matches the requirement to migrate virtualized workloads while keeping OS and middleware control.

Exam trap

CV0-004 often tests the boundary between IaaS and PaaS — candidates pick PaaS thinking 'managed' means less work, but PaaS removes the OS/middleware control the question explicitly requires.

How to eliminate wrong answers

Option A (SaaS) is wrong because SaaS delivers fully managed applications where the customer controls neither the OS nor middleware — the provider owns the entire stack. Option B (FaaS) is wrong because Function-as-a-Service abstracts away the OS entirely, running event-driven code snippets with no server or OS management by the customer. Option C (PaaS) is wrong because PaaS manages the OS and runtime for the customer, leaving only application code and data under customer control — the opposite of maintaining OS/middleware control.

27
Multi-Selectmedium

A company is designing a hybrid cloud architecture connecting their on-premises data center to AWS. Which TWO options provide dedicated, private network connectivity? (Select TWO.)

Select 2 answers
A.Internet gateway
B.VPC peering
C.NAT gateway
D.Site-to-Site VPN
E.AWS Direct Connect
AnswersD, E

VPN creates a private encrypted tunnel over the internet.

Why this answer

AWS Direct Connect provides dedicated private connection, and VPN over the internet can also be private if encrypted, but it's not dedicated. Site-to-Site VPN is a valid private connectivity option. Internet gateway is public, VPC peering is between VPCs, not on-premises.

28
MCQhard

A cloud engineer is designing a storage solution for a high-performance database that requires consistent low-latency access to block-level storage. The database runs on a single virtual machine and must support frequent random read/write operations. Which storage type should the engineer choose?

A.A block storage volume attached to the virtual machine, provisioned with high IOPS.
B.A managed file share using the SMB protocol.
C.A content delivery network (CDN) edge cache.
D.Object storage with a hierarchical namespace and eventual consistency.
AnswerA

Block storage presents raw volumes that can be formatted with a file system and used by the database. It supports low-latency random read/write operations and allows the engineer to provision IOPS based on performance needs. Attaching the volume directly to the virtual machine ensures dedicated access and consistent performance, which is exactly what a high-performance database requires.

Why this answer

A high-performance database requires block-level storage with consistent low latency and the ability to handle frequent random read/write operations. Block storage volumes attached to the virtual machine provide dedicated, high-IOPS storage that can be formatted and used directly by the database. Object storage, file shares, and CDNs do not offer the necessary block-level access or performance characteristics.

Exam trap

The trap here is confusing shared file storage with block storage, when databases typically require dedicated block-level volumes for performance.

29
MCQmedium

An e-commerce application experiences variable traffic with sudden spikes during flash sales. The application is designed to be stateless. Which scaling approach should the cloud architect implement to handle these spikes efficiently?

A.Vertical scaling on a single large instance
B.Horizontal auto-scaling based on CPU utilization
C.Using a load balancer with active-passive failover
D.Pre-provisioning a fixed cluster of instances
AnswerB

Horizontal auto-scaling adds or removes stateless instances in response to CPU thresholds, matching capacity to flash-sale demand without manual intervention. Because the application holds no session state, new instances can serve traffic immediately, satisfying the sudden-spike constraint efficiently. Vertical scaling would require restarts and hit fixed instance-size ceilings.

Why this answer

Horizontal auto-scaling based on CPU utilization allows the application to dynamically add or remove instances in response to traffic spikes. Since the application is stateless, new instances can be added seamlessly behind a load balancer, providing efficient scaling during flash sales.

Exam trap

The trap is assuming that vertical scaling or fixed clusters can handle sudden spikes; candidates must recognize that only horizontal auto-scaling provides elastic capacity for variable traffic.

How to eliminate wrong answers

Option A is wrong because vertical scaling on a single large instance has limits and cannot handle sudden spikes efficiently; it also requires downtime for resizing. Option C is wrong because a load balancer with active-passive failover is for high availability, not for scaling; it does not add capacity during spikes. Option D is wrong because pre-provisioning a fixed cluster cannot handle variable traffic efficiently; it may be over-provisioned during low traffic and under-provisioned during spikes.

30
MCQeasy

Which cloud service model provides the customer with the most control over the operating system and applications?

A.IaaS
B.FaaS
C.PaaS
D.SaaS
AnswerA

IaaS delivers only virtualised compute, storage and networking, leaving the guest operating system, middleware and applications entirely under customer management. PaaS and SaaS abstract the OS away, so IaaS uniquely satisfies the requirement for maximum control over both operating system and applications.

Why this answer

IaaS provides virtualized computing resources where customers manage OS and above.

31
MCQhard

A cloud engineer is designing a solution for a financial application that requires strict data residency in a specific country. The application must also be highly available across multiple data centers within that country. Which design consideration is most critical?

A.Deploying resources in multiple availability zones within the same region.
B.Using a content delivery network (CDN) to cache data globally.
C.Using a global load balancer to distribute traffic across continents.
D.Implementing a multi-region active-active architecture.
AnswerA

Deploying across multiple availability zones within a single region ensures high availability while keeping data within the country's borders, satisfying data residency. Availability zones are isolated data centers within a region, providing fault tolerance without crossing legal boundaries, making this the most critical design consideration.

Why this answer

Deploying across multiple availability zones within the same region keeps data within the country while providing high availability through fault isolation. This satisfies both data residency and availability requirements without introducing cross-border data flows that could violate regulations.

Exam trap

The trap here is equating high availability with multi-region deployments, overlooking that availability zones within a region can provide sufficient redundancy while complying with data residency laws.

32
MCQeasy

Which cloud service model provides the customer with the ability to deploy and manage custom applications without managing the underlying operating system or runtime environment?

A.SaaS
B.PaaS
C.IaaS
D.FaaS
AnswerB

PaaS delivers managed runtimes and middleware, so customers deploy code and manage applications while the provider handles the operating system, patching and runtime. That matches the constraint of no OS or runtime management, unlike IaaS, which leaves those layers to the customer.

Why this answer

PaaS provides a managed platform where customers deploy their code while the provider manages the OS, runtime, and infrastructure.

33
MCQeasy

Which cloud service model provides the customer with the highest level of control over the operating system and middleware?

A.PaaS
B.FaaS
C.IaaS
D.SaaS
AnswerC

IaaS delivers virtual machines, storage and networking while the customer manages the guest operating system, patching and middleware. That leaves the greatest control over the OS layer, unlike PaaS or SaaS, which abstract it away.

Why this answer

IaaS provides virtualized computing resources where the customer manages the OS, middleware, and applications, offering the highest control among the three main service models.

34
MCQeasy

A cloud architect is designing a system that requires a durable, highly available object storage solution for storing backups and media files. The data must be accessible from anywhere via HTTP/HTTPS. Which AWS service should be used?

A.Amazon EFS
B.Amazon RDS
C.Amazon EBS
D.Amazon S3
AnswerD

Amazon S3 is a durable, highly available object storage service designed for storing and retrieving any amount of data. It provides HTTP/HTTPS access and is ideal for backups and media files. S3 offers 99.999999999% durability and can be accessed globally, meeting the requirements.

Why this answer

Amazon S3 is the correct choice because it is a durable, highly available object storage service that supports HTTP/HTTPS access and is designed for backups and media files. EBS, EFS, and RDS serve different storage needs: block, file, and database respectively, and do not meet the object storage and accessibility requirements.

Exam trap

The trap here is confusing block or file storage with object storage, as EBS and EFS are often used for similar workloads but lack HTTP accessibility.

35
Multi-Selectmedium

A cloud architect is designing a highly available two-tier web application. The database tier must remain available if a single Availability Zone fails. Which TWO design decisions should the architect make? (Choose two.)

Select 2 answers
A.Configure the database with a standby replica in a different Availability Zone and automatic failover.
B.Place all application servers in one Availability Zone to reduce network latency between tiers.
C.Deploy the application tier across multiple Availability Zones behind a load balancer.
D.Route all database traffic through a NAT gateway in the primary Availability Zone.
E.Use a single large database instance with daily snapshots stored in the same Availability Zone.
AnswersA, C

A standby replica in another Availability Zone receives synchronous replication and can be promoted automatically when the primary zone fails. This provides a low recovery point and low recovery time because the standby is already in sync. It directly addresses the requirement that the database tier survive the loss of a single Availability Zone without manual intervention.

Why this answer

High availability across Availability Zones requires removing single points of failure in every tier. A database with a standby in another zone and automatic failover keeps data available, while application servers distributed across zones behind a load balancer keep the web tier serving requests. Together they prevent one zone failure from taking down the application.

Exam trap

The trap here is focusing only on the database tier and forgetting that the application tier must also be spread across zones to avoid a single point of failure.

36
Multi-Selectmedium

A cloud architect is designing a multi-tier application that must be resilient to the failure of a single availability zone. The application consists of a web tier, an application tier, and a database tier. Which TWO design decisions will help achieve this resilience? (Choose two.)

Select 2 answers
A.Use a single, large database instance in one availability zone with frequent snapshots.
B.Place all tiers in a single availability zone to reduce network latency between components.
C.Deploy the web and application tiers across multiple availability zones and use a load balancer to distribute traffic.
D.Configure the database tier with a multi-AZ standby replica that can be promoted in the event of a failure.
E.Store all session state on the local disk of each web server to improve performance.
AnswersC, D

Distributing the web and application tiers across multiple availability zones ensures that if one zone fails, the remaining zones can continue to serve requests. A load balancer health-checks instances and routes traffic only to healthy targets. This eliminates single points of failure at the compute layer and is a fundamental practice for zone-resilient architectures.

Why this answer

To be resilient to a single availability zone failure, both the stateless tiers and the stateful database tier must be distributed. Deploying the web and application tiers across multiple zones behind a load balancer ensures continued service if one zone fails. Configuring the database with a multi-AZ standby replica provides automatic failover for the data layer.

Together, these decisions eliminate single points of failure across all tiers.

Exam trap

The trap here is focusing only on the compute tiers and forgetting that the database tier also needs a multi-AZ strategy to achieve full resilience.

37
MCQhard

An organization needs to recover its critical database within 15 minutes and lose at most 1 minute of data. Which configuration meets these requirements?

A.Active-active with asynchronous replication
B.Warm standby with hourly backups
C.Hot standby with synchronous replication
D.Cold standby with daily backups
AnswerC

Synchronous replication commits each transaction on both primary and standby before acknowledgement, so a failover loses zero committed data — comfortably inside the one-minute RPO. The hot standby is already running and current, allowing promotion within the 15-minute RTO. Asynchronous replication could not guarantee that one-minute data-loss limit.

Why this answer

Hot standby with synchronous replication ensures that every write to the primary database is also written to the standby before the transaction is acknowledged. This guarantees zero data loss (RPO=0) and, combined with automatic failover, can achieve a recovery time of under 15 minutes (RTO<15 min).

Exam trap

A common trap is confusing 'asynchronous replication' (which can lose data) with 'synchronous replication' (which preserves data), leading candidates to incorrectly choose active-active with async replication despite its inability to meet the 1-minute RPO.

How to eliminate wrong answers

Option A is wrong because active-active with asynchronous replication can cause data loss of more than 1 minute if a failure occurs before the async replication completes, violating the RPO of ≤1 minute. Option B is wrong because warm standby with hourly backups has an RPO of up to 1 hour (not ≤1 minute) and an RTO that typically exceeds 15 minutes due to the need to restore from backup. Option D is wrong because cold standby with daily backups has an RPO of up to 24 hours and an RTO measured in hours or days, far exceeding the 15-minute RTO requirement.

38
Multi-Selecthard

A company wants to ensure fault tolerance for a critical application by deploying across multiple availability zones. Which THREE design decisions contribute to fault tolerance? (Select THREE.)

Select 3 answers
A.Using a single database instance without replication
B.Placing a load balancer in front of the instances to distribute traffic
C.Deploying application instances in at least two availability zones
D.Implementing duplicate components (N+1 redundancy) in each tier
E.Using a single large instance in one AZ
AnswersB, C, D

A load balancer distributes incoming traffic across instances in multiple availability zones and health-checks them, routing around a failed zone. This directly delivers the fault tolerance the scenario demands by removing any single instance or zone as a point of failure.

Why this answer

Deploying across multiple AZs, using load balancers to distribute traffic, and having redundant components in each AZ contribute to fault tolerance. Single instance and same AZ do not provide fault tolerance.

39
MCQhard

A company hosts a web application on AWS and wants to improve latency for global users. Which service should they use to cache static content at edge locations?

A.Application Load Balancer
B.AWS CloudFront
C.AWS Global Accelerator
D.Amazon Route 53
AnswerB

AWS CloudFront caches static content at edge locations worldwide, directly satisfying the global low-latency requirement. Requests terminate at the nearest point of presence rather than the origin region, cutting round-trip time. Unlike regional services such as S3 alone, CloudFront's distributed edge network is purpose-built for this caching scenario.

Why this answer

AWS CloudFront is a content delivery network (CDN) that caches static content at edge locations worldwide, reducing latency for global users. It integrates with AWS services like S3 and EC2, and supports dynamic content acceleration. The other options do not provide edge caching for static content.

Exam trap

CV0-004 often tests the distinction between services that improve performance (CloudFront for caching, Global Accelerator for network path optimization) and those that don't (ALB for load balancing, Route 53 for DNS).

How to eliminate wrong answers

Option A is wrong because Application Load Balancer distributes incoming traffic across multiple targets in a single region, not caching content at edge locations. Option C is wrong because AWS Global Accelerator improves availability and performance by routing traffic over the AWS global network, but it does not cache static content. Option D is wrong because Amazon Route 53 is a DNS service that routes end users to internet applications, but it does not cache content at edge locations.

40
MCQmedium

A cloud architect is designing a solution that must automatically provision and configure compute, storage, and networking resources in a repeatable manner across multiple cloud providers. The solution must minimize manual intervention and ensure consistent configurations. Which approach best meets these requirements?

A.Implementing a hybrid cloud with a single management portal.
B.Infrastructure as Code (IaC) with cloud-agnostic tools like Terraform.
C.Manually creating resources through each cloud provider's web console.
D.Using provider-specific CLI scripts that are executed manually.
AnswerB

IaC with Terraform allows defining infrastructure in declarative configuration files that can be version-controlled and applied consistently across multiple providers. This automates provisioning and configuration, reduces manual errors, and ensures repeatability, directly addressing the requirement for automated, consistent multi-cloud deployments.

Why this answer

Infrastructure as Code with a cloud-agnostic tool like Terraform enables automated, repeatable, and consistent provisioning across multiple cloud providers. It treats infrastructure as software, allowing version control and collaboration, which minimizes manual intervention and ensures configurations are applied uniformly. This directly satisfies the scenario's requirements.

Exam trap

The trap here is assuming that a single management portal or provider-specific scripts provide the same level of automation and consistency as cloud-agnostic Infrastructure as Code.

41
Multi-Selectmedium

A company is using a PaaS offering to host a web application. Which THREE management responsibilities are retained by the customer? (Select THREE.)

Select 3 answers
A.Runtime environment
B.Application code
C.Operating system patches
D.Data and its security
E.Access and identity management
AnswersB, D, E

In PaaS, the provider manages the runtime, middleware, and operating system, but the customer still writes, deploys, and patches the application code itself. This retained responsibility satisfies the scenario's requirement to identify what the customer still manages.

Why this answer

In a PaaS model, the provider manages the platform stack (runtime, middleware, OS, virtualization), while the customer retains responsibility for what they deploy and control on top of it. Option B (Application code) is correct because the customer writes, deploys, and maintains the application itself, including its logic, dependencies, and updates. Option D (Data and its security) is correct because the customer owns the data, controls classification, encryption, backup, and access policies, even though the provider secures the underlying storage infrastructure.

Option E (Access and identity management) is correct because the customer manages user accounts, roles, authentication, and authorization for their application and data, typically via the provider's IAM tooling or federation. Option A (Runtime environment) is not retained by the customer, as the PaaS provider manages the language runtime, libraries, and execution environment. Option C (Operating system patches) is not retained by the customer, since the provider handles OS-level patching and maintenance in a PaaS offering.

Exam trap

CV0-004 often tests the shared responsibility model, and candidates frequently confuse provider-managed components (like runtime and OS) with customer-managed ones, leading them to incorrectly select options that are actually the provider's responsibility.

42
Multi-Selecthard

A cloud architect is evaluating a multi-cloud strategy to improve resilience. Which THREE factors should be considered when designing multi-cloud architecture? (Select THREE.)

Select 3 answers
A.Increased vendor lock-in
B.Data transfer costs between clouds
C.Ability to manage all clouds with a single API
D.Application portability and interoperability
E.Consistent security and compliance policies across clouds
AnswersB, D, E

Egress charges apply whenever data leaves a provider's network, so cross-cloud replication and failover traffic incur fees that single-cloud designs avoid. This directly addresses the resilience-versus-cost trade-off the architect must weigh, since continuous synchronisation between clouds multiplies billable egress volume.

Why this answer

Option B (Data transfer costs between clouds) is correct because multi-cloud designs frequently move data across provider boundaries, and egress charges plus inter-cloud transfer fees can significantly erode the cost benefits of a multi-cloud strategy, so they must be modeled during design. Option D (Application portability and interoperability) is correct because resilience in a multi-cloud architecture depends on workloads being able to run on more than one provider, which requires avoiding proprietary APIs and using portable formats such as containers, Kubernetes, and open standards. Option E (Consistent security and compliance policies across clouds) is correct because each provider implements identity, encryption, and logging differently, so a unified policy framework and controls such as federated IAM and centralized logging are needed to maintain a consistent security posture.

Option A (Increased vendor lock-in) is not a valid factor because multi-cloud is generally adopted to reduce dependence on a single vendor, not to increase lock-in. Option C (Ability to manage all clouds with a single API) is not a required design factor because no single universal API natively manages AWS, Azure, and GCP; management is typically achieved through abstraction layers, IaC tools like Terraform, or multi-cloud platforms rather than one provider API.

Exam trap

CV0-004 often tests multi-cloud design factors; candidates may incorrectly select vendor lock-in as a benefit or overlook the importance of data transfer costs and portability.

43
MCQhard

A cloud engineer is deploying a containerized microservices application on Google Kubernetes Engine. The team wants each pod to authenticate to Google Cloud APIs without embedding long-lived service account keys, and they want per-workload identity that can be granted least-privilege IAM roles. Which approach should the engineer implement?

A.Create a service account key JSON file and mount it as a Kubernetes Secret in each pod
B.Grant the Compute Engine default service account broad roles and let all pods share it
C.Enable Workload Identity and bind a Kubernetes service account to a Google service account
D.Store the service account credentials in Secret Manager and inject them at pod startup
AnswerC

Workload Identity federates Kubernetes service accounts with Google Cloud IAM, allowing pods to obtain short-lived access tokens through the metadata server without any static key files. Each Kubernetes service account maps to a Google service account, so IAM roles can be scoped per workload, satisfying the keyless authentication and least-privilege requirements for the microservices deployment.

Why this answer

Workload Identity is the GKE-native mechanism that lets pods impersonate a Google service account through short-lived federated tokens, eliminating static key files and enabling per-workload IAM bindings. The alternatives either reintroduce long-lived credentials or collapse identity to the node level, neither of which provides keyless, least-privilege access for individual microservices.

Exam trap

The trap here is treating secret storage or rotation as equivalent to eliminating long-lived credentials entirely.

44
MCQeasy

A company wants to migrate its on-premises workload to the cloud and needs to maintain full control over the operating system, middleware, and applications. Which cloud service model should the company choose?

A.PaaS
B.FaaS
C.SaaS
D.IaaS
AnswerD

IaaS delivers raw compute, storage and networking while the customer retains control of the guest OS, middleware and applications. This satisfies the requirement for full control, unlike PaaS or SaaS, which abstract the operating system layer away from the customer.

Why this answer

IaaS provides the highest level of control among cloud service models, giving the customer direct management of the operating system, middleware, runtime, and applications while the provider manages the underlying virtualization, servers, storage, and networking. Because the company explicitly requires full control over OS, middleware, and applications, IaaS is the only model that grants this level of responsibility. AWS EC2, Azure VMs, and GCP Compute Engine are canonical IaaS examples.

Exam trap

The trap is equating 'control over applications' with PaaS or assuming any cloud migration implies managed services — candidates must recognize that full OS and middleware control is the defining characteristic of IaaS.

How to eliminate wrong answers

Option A is wrong because PaaS abstracts away the operating system and middleware, so the customer cannot maintain full control over those layers. Option B is wrong because FaaS (Function-as-a-Service) abstracts even more — the customer only supplies function code, with no OS or middleware control whatsoever. Option C is wrong because SaaS delivers a fully managed application where the customer controls only configuration and data, not the OS, middleware, or application code.

45
MCQeasy

A cloud engineer is deploying a new web application on Google Cloud. The application must be reachable from the internet on HTTP and HTTPS, and the engineer wants Google's global edge network to terminate TLS and route users to the closest healthy backend. The backend instances should not be directly exposed to the internet. Which Google Cloud service should the engineer use?

A.Cloud CDN with a signed URL configuration pointing directly at the backend instance group.
B.A regional external passthrough Network Load Balancer with backend VMs that have public IP addresses.
C.Cloud Load Balancing with an external Application Load Balancer and a managed SSL certificate.
D.Cloud NAT with a regional external IP address, allowing backend instances to serve traffic directly.
AnswerC

An external Application Load Balancer is a global Layer 7 service that terminates TLS at Google's edge, routes requests to the nearest healthy backend, and supports managed certificates. Backends can be private instances, so they are not directly exposed to the internet, matching all stated requirements.

Why this answer

An external Application Load Balancer is the Google Cloud service that provides global Layer 7 load balancing, TLS termination with managed certificates, health-checked routing to the nearest backend, and private backends. Cloud NAT, passthrough network load balancing, and Cloud CDN each address different concerns and cannot fulfill the full set of requirements.

Exam trap

The trap here is confusing Cloud NAT, which handles outbound-only traffic, with a load balancer that accepts inbound client connections.

46
MCQmedium

A company is migrating a legacy monolithic application to the cloud. The application currently runs on a single server with 16 vCPUs and 64 GB RAM. The cloud architect recommends redesigning the application to be stateless and horizontally scalable. What is the primary benefit of this approach?

A.Lower storage costs
B.Simpler licensing costs
C.Improved fault tolerance and elasticity
D.Reduced network latency
AnswerC

Stateless, horizontally scalable designs let the platform add or replace instances independently, so a failed node does not lose session state and traffic redistributes automatically. This satisfies the fault tolerance and elasticity benefit, unlike the single-server monolith's fixed capacity and single point of failure.

Why this answer

Redesigning a monolithic application to be stateless and horizontally scalable primarily improves fault tolerance and elasticity. Stateless components can be replicated across multiple instances, so if one fails, others continue to serve requests. Horizontal scaling allows the application to handle varying loads by adding or removing instances dynamically.

Exam trap

CV0-004 often tests the benefits of stateless design, and candidates may choose reduced network latency or lower storage costs, which are not primary benefits; the key is fault tolerance and elasticity.

How to eliminate wrong answers

Option A is wrong because lower storage costs are not the primary benefit of statelessness; storage costs depend on data volume and type. Option B is wrong because simpler licensing costs are not directly related to stateless design; licensing may become more complex with more instances. Option D is wrong because reduced network latency is not guaranteed by horizontal scaling; in fact, distributing instances may increase latency due to network hops.

47
MCQmedium

A company is experiencing increased traffic to its web application. They want to handle the load by adding more web server instances behind a load balancer. This approach is known as:

A.Stateless design
B.Horizontal scaling
C.Auto-scaling
D.Vertical scaling
AnswerB

Horizontal scaling adds more server instances to the pool behind the load balancer, distributing increased traffic across them. Vertical scaling instead increases the CPU, memory or other resources of an existing instance, which does not match adding instances.

Why this answer

Horizontal scaling (scaling out) means adding more instances of a resource — here, additional web servers behind a load balancer — to distribute increased traffic across multiple nodes. This increases capacity by adding parallel units rather than making a single server more powerful, which is exactly what the scenario describes.

Exam trap

The trap is conflating horizontal scaling (adding instances) with auto-scaling (the automation that performs it) or vertical scaling (adding resources to one host) — the question asks for the approach, not the trigger mechanism.

How to eliminate wrong answers

Option A is wrong because stateless design is an architectural property that makes horizontal scaling easier (no session affinity needed), but it is not the act of adding servers itself. Option C is wrong because auto-scaling is the automation mechanism that triggers scaling actions based on metrics; the question describes the scaling approach, not the automation policy. Option D is wrong because vertical scaling means adding CPU, RAM, or other resources to a single existing server (scaling up), which does not involve adding more instances behind a load balancer.

48
MCQmedium

A cloud architect is designing a highly available web application. The application must remain available even if an entire AWS Availability Zone fails. The architect decides to deploy identical application instances in two separate Availability Zones and distribute traffic equally. Which architecture is being implemented?

A.Fault tolerance
B.Warm standby
C.Active-active
D.Active-passive
AnswerC

Active-active runs both Availability Zone instances concurrently, each serving traffic, so the loss of one zone leaves the other handling requests without failover delay. This satisfies the stem's requirement that the application remain available through a complete Availability Zone failure.

Why this answer

An active-active architecture runs identical application instances in multiple Availability Zones simultaneously, with traffic distributed across all of them. Because both AZs are actively serving requests, the failure of one AZ results in the remaining AZ seamlessly absorbing the full load, maintaining availability. This is the defining characteristic described in the scenario — identical instances in two AZs with equal traffic distribution.

Exam trap

The trap is conflating high availability patterns — candidates often pick 'fault tolerance' as a generic term or 'active-passive' because they miss the phrase 'distribute traffic equally,' which specifically signals active-active.

How to eliminate wrong answers

Option A is wrong because fault tolerance implies the system continues operating without any degradation during a component failure, often through redundant hardware or error-correcting mechanisms — it is a broader design goal, not the specific two-AZ active-active pattern described. Option B is wrong because warm standby involves a secondary environment that is running but not actively serving traffic, requiring a failover step to become active. Option D is wrong because active-passive has one AZ actively serving while the other remains idle until failover, which does not match the 'distribute traffic equally' requirement.

49
MCQhard

A company is designing a VPC in AWS. They need to host a web application with a public-facing load balancer, web servers in private subnets, and a database in a separate private subnet. Which network architecture is most secure and aligns with best practices?

A.Public subnet for load balancer, private subnet for web servers and database together
B.Public subnet for load balancer, private subnet for web servers, separate private subnet for database
C.All resources in public subnets with security groups restricting access
D.All resources in private subnets with a VPN connection
AnswerB

Placing the load balancer in a public subnet exposes only it to the internet, while web servers and database sit in private subnets without inbound internet routing. This tiered separation limits lateral movement and satisfies least-exposure best practise.

Why this answer

A three-tier architecture with a public subnet for the load balancer, private subnets for web servers, and a separate private subnet for the database provides security and isolation.

50
MCQhard

A company wants to migrate a stateful application to the cloud but needs to ensure it can scale horizontally. What architectural change is required?

A.Deploy in multiple availability zones
B.Move session state to a shared database or cache
C.Implement sticky sessions on the load balancer
D.Use larger instance types
AnswerB

Horizontal scaling requires any instance to handle any request, but locally stored session state ties a user to one instance. Relocating session state to a shared database or cache externalises it, so additional instances can serve subsequent requests without affinity, enabling true horizontal scale-out.

Why this answer

For a stateful application to scale horizontally, session state must be externalized from individual instances into a shared store such as a database, Redis, or Memcached. This allows any instance behind the load balancer to serve any user request, enabling true horizontal scaling and failover.

Exam trap

The trap is choosing sticky sessions as a 'fix' for stateful scaling — sticky sessions mask the problem but actively prevent horizontal scalability, which is the opposite of what the question asks.

How to eliminate wrong answers

Option A is wrong because deploying across multiple AZs improves availability and fault tolerance but does not by itself enable horizontal scaling of a stateful app — instances would still hold local session state. Option C is wrong because sticky sessions pin a user to a specific instance, which is the opposite of horizontal scalability: it creates hotspots, prevents even load distribution, and breaks when an instance fails. Option D is wrong because larger instance types are vertical scaling, which has a hard ceiling and does not address the architectural barrier to horizontal scaling.

51
MCQmedium

A cloud architect is designing a VPC with multiple tiers. The web servers must be accessible from the internet, but the database servers must not be directly accessible. Which subnet design should the architect implement?

A.Place all servers in public subnets and restrict access via security groups
B.Place web servers in a private subnet and database servers in a public subnet
C.Place all servers in private subnets and use a bastion host for access
D.Place web servers in a public subnet and database servers in a private subnet
AnswerD

Public subnets route to an internet gateway, so web servers placed there remain reachable from the internet. Private subnets have no such route, keeping database servers unreachable directly; outbound access via NAT still permits patching and updates without exposing them.

Why this answer

Option D is correct because it follows the standard multi-tier VPC architecture: public subnets host internet-facing resources (web servers) with a route to an Internet Gateway (IGW), while private subnets host sensitive resources (database servers) with no direct route to the internet. This ensures the database tier is not directly reachable from the internet, satisfying the requirement. Security groups and network ACLs can further restrict traffic, but the subnet placement itself provides the first layer of isolation.

Exam trap

CV0-004 often tests the misconception that security groups alone can secure a database in a public subnet, but the exam expects you to recognize that subnet placement (public vs. private) is the primary control for direct internet accessibility.

How to eliminate wrong answers

Option A is wrong because placing all servers in public subnets exposes the database servers to the internet, even if security groups restrict access; a misconfiguration or overly permissive rule could lead to direct exposure. Option B is wrong because it reverses the tiers: web servers in a private subnet would not be directly accessible from the internet without additional components like a load balancer or NAT, and database servers in a public subnet would be directly accessible, violating the requirement. Option C is wrong because placing all servers in private subnets would make the web servers inaccessible from the internet without a bastion host or load balancer, and a bastion host is typically for administrative access, not for serving public web traffic.

52
MCQhard

An organization wants to minimize costs for a batch processing workload that runs nightly for 2 hours and can tolerate interruptions. Which pricing model is most cost-effective?

A.On-demand instances
B.Reserved instances
C.Dedicated hosts
D.Spot instances
AnswerD

Spot instances exploit unused cloud capacity at steep discounts, satisfying the workload's tolerance for interruptions and its short nightly runtime. Because the batch job can resume after eviction, the risk of sudden reclamation is acceptable, making spot pricing markedly cheaper than on-demand or reserved capacity for this intermittent, fault-tolerant scenario.

Why this answer

Spot instances offer significant discounts but can be terminated; suitable for fault-tolerant, interruptible workloads.

53
MCQmedium

A company wants to reduce cloud costs for a stateless batch processing workload that runs nightly for about 3 hours. The workload can tolerate interruptions. Which pricing model is most cost-effective?

A.Reserved instances
B.Dedicated hosts
C.Spot instances
D.On-demand instances
AnswerC

Spot instances draw from spare capacity at steep discounts and can be reclaimed with little notice, which suits a stateless nightly batch job that tolerates interruptions. Reserved or on-demand pricing would bill for idle hours, failing the cost-reduction constraint.

Why this answer

Spot instances offer up to 90% discounts compared to on-demand and are ideal for interruptible, stateless batch workloads. Since the workload runs nightly for about 3 hours and can tolerate interruptions, spot instances provide the lowest cost without requiring long-term commitments. This matches the cost-effectiveness requirement precisely.

Exam trap

CV0-004 often tests the misconception that reserved instances are always cheapest — candidates must recognize that for short, interruptible workloads, spot instances deliver the greatest savings.

How to eliminate wrong answers

Option A is wrong because reserved instances require a 1- or 3-year commitment and are better for steady-state, always-on workloads, not short nightly batches. Option B is wrong because dedicated hosts are the most expensive option and are used for licensing or compliance requirements, not cost reduction for interruptible batch jobs. Option D is wrong because on-demand instances are more expensive than spot for the same interruptible workload.

54
MCQhard

An organization runs a batch processing job that runs for 2 hours every night. The job can tolerate interruptions and can resume from the last checkpoint. Which cloud purchasing option minimizes cost?

A.Reserved instances
B.Spot instances
C.Dedicated hosts
D.On-demand instances
AnswerB

Spot instances use spare cloud capacity priced far below on-demand rates, and they can be reclaimed with little notice. The job tolerates interruptions and resumes from checkpoints, so eviction causes no data loss. This fault tolerance is exactly the constraint that makes spot pricing the cheapest viable option.

Why this answer

Spot instances are the correct choice because they offer the largest discount (up to 90% off on-demand) for workloads that can tolerate interruptions and resume from checkpoints. The batch job's ability to be interrupted and restart from the last checkpoint aligns perfectly with spot instance behavior, where instances can be reclaimed by the cloud provider with a two-minute warning. This makes spot instances the most cost-effective option for this fault-tolerant, time-flexible workload.

Exam trap

The trap here is assuming that reserved instances are always the cheapest for long-running jobs, but the key differentiator is the workload's tolerance for interruptions—spot instances win for fault-tolerant, checkpointable batch jobs.

How to eliminate wrong answers

Option A is wrong because reserved instances require a 1- or 3-year commitment and are best for steady-state, always-on workloads, not interruptible nightly batch jobs. Option C is wrong because dedicated hosts are the most expensive option, used for licensing or compliance requirements, and provide no cost benefit for interruptible batch processing. Option D is wrong because on-demand instances are the most expensive pay-as-you-go option and offer no discount for the workload's tolerance of interruptions.

55
MCQhard

A cloud architect is designing a disaster recovery strategy for a critical application with a Recovery Time Objective of 15 minutes and a Recovery Point Objective of 5 minutes. The secondary Region must be able to take over with minimal manual effort. Which strategy should the architect implement?

A.A warm standby in the secondary Region with continuous data replication and automated failover orchestration.
B.A pilot light strategy with only the database replicated and all application servers provisioned on demand during a disaster.
C.A backup-and-restore strategy that copies nightly snapshots to the secondary Region.
D.A multi-site active-active deployment with both Regions serving production traffic simultaneously.
AnswerA

A warm standby keeps a scaled-down but functional copy of the environment running in the secondary Region, and continuous replication keeps data within the five-minute recovery point. Automated failover orchestration promotes the standby and redirects traffic with minimal human action, meeting the fifteen-minute recovery time. This balances cost and speed better than hotter or colder options.

Why this answer

A warm standby keeps a functional, scaled-down environment in the secondary Region with continuous replication, so data loss stays within the five-minute recovery point. Automated failover orchestration promotes resources and redirects traffic without lengthy manual steps, satisfying the fifteen-minute recovery time while costing less than a fully active second Region.

Exam trap

The trap here is choosing the cheapest backup-and-restore option, which cannot meet a five-minute recovery point or a fifteen-minute recovery time.

56
MCQhard

A company is migrating a legacy monolithic application to AWS. The application requires a relational database and must support read-heavy workloads with minimal latency for users across North America and Europe. The database must be highly available and provide automatic failover. Which AWS database solution should the architect recommend?

A.Amazon Aurora Global Database with a primary cluster in one region and secondary clusters in another region.
B.Amazon DynamoDB with global tables enabled and provisioned throughput in both regions.
C.Amazon Redshift with a multi-node cluster and cross-region snapshot copy.
D.Amazon RDS for MySQL with a Multi-AZ deployment and read replicas in both regions.
AnswerA

Aurora Global Database is designed for global applications. It consists of a primary cluster in one region and up to five secondary clusters in other regions. Replication is storage-based and typically has less than one second of latency. Secondary clusters can serve read traffic with low latency, and failover to a secondary region can be performed quickly. This meets the requirements for read-heavy workloads, low latency, and high availability.

Why this answer

Amazon Aurora Global Database provides a relational database with global replication, low-latency reads, and fast failover. It is ideal for read-heavy workloads distributed across multiple regions. The storage-based replication ensures minimal lag, and secondary clusters can serve read traffic locally.

This solution meets the requirements for high availability, automatic failover, and global low-latency access.

Exam trap

The trap here is assuming that any multi-AZ or read replica configuration will provide low-latency global reads, but only Aurora Global Database offers a managed cross-region replication with a unified global endpoint and fast failover.

57
MCQmedium

A cloud architect is designing a containerized microservices application that must handle unpredictable traffic spikes and scale rapidly. The architect wants to minimize operational overhead while ensuring high availability across multiple Availability Zones. Which solution best meets these requirements?

A.Deploy the application on a cluster of EC2 instances managed by an Auto Scaling group, with a Classic Load Balancer distributing traffic.
B.Create an AWS Lambda function for each microservice and expose them through an API Gateway with caching enabled.
C.Deploy the application on a single large EC2 instance with an Elastic IP address and use Route 53 latency-based routing to direct traffic.
D.Use AWS Fargate with an Application Load Balancer and configure an ECS service that spans multiple Availability Zones.
AnswerD

AWS Fargate is a serverless compute engine for containers that eliminates the need to manage servers. An Application Load Balancer provides advanced routing and integrates with ECS. Configuring the ECS service across multiple Availability Zones ensures high availability. This solution scales rapidly and reduces operational overhead, directly addressing the requirements.

Why this answer

AWS Fargate with an Application Load Balancer and a multi-AZ ECS service provides a serverless container platform that scales rapidly and eliminates server management. The Application Load Balancer offers advanced routing for microservices, and spanning multiple Availability Zones ensures high availability. This combination directly satisfies the need for minimal operational overhead and resilience.

Exam trap

The trap here is assuming that serverless functions like AWS Lambda are always the best choice for microservices, but Lambda has runtime and execution duration limits that may not suit all microservices.

58
MCQmedium

A cloud administrator is deploying a web application on Azure. The application requires a shared, highly available file storage that can be mounted simultaneously by multiple virtual machines across different availability zones. Which Azure storage solution should the administrator choose?

A.Azure Files
B.Azure Queue Storage
C.Azure Blob Storage
D.Azure Managed Disks
AnswerA

Azure Files offers fully managed file shares in the cloud that are accessible via SMB and NFS protocols. It supports simultaneous mounting by multiple VMs, including across different availability zones when using zone-redundant storage. This makes it suitable for lift-and-shift applications that need shared file storage.

Why this answer

Azure Files is the correct choice because it provides fully managed file shares that can be mounted by multiple VMs simultaneously using standard protocols like SMB and NFS. It supports high availability and can be configured with zone-redundant storage to ensure accessibility across availability zones, meeting the requirement for shared, highly available file storage.

Exam trap

The trap here is confusing Blob Storage with file storage; Blob is object storage and does not support native file system protocols for shared access.

59
Multi-Selectmedium

A financial services firm is moving a regulated trading application to a public cloud. The security team must prove that data is encrypted in transit between the application tier and the database tier, and that only the application tier can reach the database port. Which two controls should the cloud architect implement? (Choose two.)

Select 2 answers
A.Create a network ACL on the database subnet that denies all traffic except the application subnet CIDR range.
B.Configure the database to accept connections only over TLS and require certificate validation from the application tier.
C.Deploy the database into a private subnet with a NAT gateway so it can initiate outbound updates.
D.Attach a security group to the database that allows the database port only from the application tier's security group.
E.Enable encryption at rest on the database volume using a customer-managed key stored in the cloud provider's key management service.
AnswersB, D

Enforcing TLS on the database listener with mandatory certificate validation ensures the channel between application and database is encrypted and that the application verifies the database identity, preventing interception or spoofing. This directly produces the cryptographic evidence auditors require for encryption in transit between the two tiers.

Why this answer

Encryption in transit and least-privilege reachability are distinct controls that must be paired. Requiring TLS with certificate validation on the database listener proves the channel is cryptographically protected, and a security group rule that names the application tier's security group as the only permitted source enforces role-based access to the database port. Encryption at rest, private subnets with NAT, and subnet-level ACLs address other concerns and do not satisfy either requirement.

Exam trap

The trap here is accepting encryption at rest as proof of encryption in transit, when the two protect entirely different states of the data.

60
MCQeasy

A startup wants to run code in response to events without provisioning or managing servers. Which cloud service model should they use?

A.PaaS
B.IaaS
C.FaaS
D.SaaS
AnswerC

FaaS runs event-triggered code without provisioning or managing servers, matching the startup's requirement exactly. The provider handles all infrastructure; the developer deploys only functions. IaaS and PaaS still involve server or runtime management, so they fail the no-server-management constraint.

Why this answer

FaaS (Function-as-a-Service) is the cloud service model where the provider runs code in response to events without requiring the customer to provision or manage servers. The customer deploys functions, and the platform handles scaling, patching, and infrastructure. This exactly matches the requirement to run code on events with no server management.

Exam trap

The trap is confusing FaaS with PaaS — candidates often pick PaaS because both are managed, but the exam tests that FaaS specifically means event-driven functions with no server provisioning or management.

How to eliminate wrong answers

Option A is wrong because PaaS provides a managed platform for deploying applications (e.g., App Engine, Heroku) but still involves running an application environment, not event-driven functions without server management. Option B is wrong because IaaS provides raw virtual machines, storage, and networking where the customer manages the OS and runtime — the opposite of serverless. Option D is wrong because SaaS delivers finished software applications to end users, not a model for running custom code in response to events.

61
MCQeasy

A company wants to migrate its on-premises workloads to the cloud and requires full control over the operating system, installed software, and security configurations. Which cloud service model should they choose?

A.FaaS
B.IaaS
C.PaaS
D.SaaS
AnswerB

IaaS provides the raw compute, storage and networking primitives while leaving the guest operating system, middleware and installed software entirely under the customer's administration. That satisfies the stated requirement for full control over the OS, software and security configurations, which PaaS and SaaS abstract away.

Why this answer

IaaS provides virtualized computing resources where the customer manages the OS and above, giving full control.

62
MCQeasy

A company wants to migrate its on-premises workloads to the cloud but must keep sensitive data on-premises due to regulatory requirements. Which cloud deployment model should the company use?

A.Multi-cloud
B.Public cloud
C.Hybrid cloud
D.Private cloud
AnswerC

Hybrid cloud keeps sensitive workloads on-premises while extending other workloads to public cloud, directly satisfying the regulatory constraint that sensitive data must remain on-premises. Neither pure public nor private cloud alone meets both the migration goal and the data-residency requirement.

Why this answer

A hybrid cloud deployment model combines on-premises infrastructure with public cloud services, allowing sensitive data to remain on-premises while other workloads leverage cloud scalability. This directly meets the regulatory requirement to keep sensitive data local while still benefiting from cloud resources for other components.

Exam trap

CV0-004 often tests the distinction between hybrid and private cloud, and candidates may choose private cloud thinking it keeps data on-premises, but private cloud does not inherently provide the public cloud integration that hybrid offers.

How to eliminate wrong answers

Option A is wrong because multi-cloud refers to using multiple public cloud providers, not keeping data on-premises. Option B is wrong because public cloud alone cannot satisfy the requirement to keep sensitive data on-premises. Option D is wrong because a private cloud is dedicated to a single organization but does not inherently include public cloud integration; it may still be on-premises but lacks the hybrid flexibility described.

63
Multi-Selectmedium

A cloud architect is designing a highly available application on AWS. The application must be fault-tolerant and able to withstand the failure of an entire Availability Zone. Which TWO actions should the architect take? (Select TWO.)

Select 2 answers
A.Store application state on the local instance store
B.Deploy EC2 instances in a single Availability Zone
C.Use a single large EC2 instance
D.Deploy EC2 instances across two or more Availability Zones
E.Configure an Auto Scaling group to span multiple Availability Zones
AnswersD, E

Distributing EC2 instances across two or more Availability Zones ensures that an AZ-wide failure only removes part of the fleet, leaving capacity in surviving zones. This directly satisfies the stem's requirement to withstand the failure of an entire Availability Zone.

Why this answer

Deploying across multiple Availability Zones and using an auto scaling group across those zones ensures that if one zone fails, the application continues in the other zones.

64
MCQhard

A cloud architect is designing a VPC with three tiers: web, application, and database. Which subnet design provides the best security posture?

A.Web in public subnet, app and database in private subnets with appropriate routing
B.Web and app in public subnets, database in private subnet
C.All tiers in private subnets with a VPN
D.All tiers in the same public subnet with security groups
AnswerA

Placing only the web tier in a public subnet limits internet exposure to the presentation layer, while application and database tiers remain unreachable directly. Routing through NAT gateways or load balancers enforces tiered segmentation, satisfying least-privilege network access.

Why this answer

It follows the principle of least privilege and network segmentation. Placing the web tier in a public subnet allows it to receive internet traffic, while the application and database tiers reside in private subnets with no direct internet access. This design ensures that only the web tier is exposed, and the database is isolated, accessible only via the application tier through controlled routing, significantly reducing the attack surface.

Exam trap

The CV0-004 exam often tests the misconception that security groups alone are sufficient for network segmentation, leading candidates to choose Option D, but security groups are stateful firewalls at the instance level and do not replace the need for subnet-level isolation and controlled routing paths.

How to eliminate wrong answers

Option B is wrong because placing the application tier in a public subnet exposes it to the internet, increasing the risk of direct attacks on application logic and potentially compromising the database. Option C is wrong because placing all tiers in private subnets with a VPN is overly restrictive and impractical for a web-facing application; it would require all users to have VPN access, which is not typical for public web services. Option D is wrong because placing all tiers in the same public subnet violates network segmentation best practices; security groups alone cannot prevent lateral movement between tiers if an attacker compromises one instance, as they share the same network broadcast domain and routing path.

65
MCQeasy

Which storage type is most suitable for hosting a shared file system accessible by multiple virtual machines in a cloud environment?

A.Archive storage
B.Object storage
C.Block storage
D.File storage
AnswerD

File storage exposes SMB or NFS shares, so several virtual machines can mount the same file system concurrently. Block storage attaches to a single instance, and object storage lacks the shared hierarchical file semantics required.

Why this answer

File storage (option D) is the correct choice because it provides a hierarchical, shared file system that multiple virtual machines can mount simultaneously using standard protocols like NFS (Network File System) or SMB/CIFS. This allows concurrent read/write access with file-level locking, making it ideal for shared workloads such as home directories, content management, or collaboration tools in a cloud environment.

Exam trap

The CV0-004 exam often tests the misconception that block storage can be shared by multiple VMs, but the trap here is that block storage is a single-attach device unless you implement a complex clustered file system (e.g., GFS2 or OCFS2), which is not the default or simplest solution for shared access.

How to eliminate wrong answers

Option A is wrong because archive storage is designed for long-term, infrequently accessed data with high retrieval latency, not for active, concurrent file sharing by multiple VMs. Option B is wrong because object storage uses a flat namespace with HTTP-based APIs (e.g., S3) and lacks native file system semantics like hierarchical directories and file-level locking, making it unsuitable for shared file system access. Option C is wrong because block storage presents raw volumes (e.g., iSCSI or NVMe-oF) that can only be attached to a single VM at a time; it does not support concurrent multi-VM access without a clustered file system overlay, which adds complexity and is not a native feature.

66
MCQmedium

A cloud architect is designing a new application that must be highly available across multiple geographic regions. The application uses a relational database that must be writable in the primary region and readable in a secondary region with minimal replication lag. Which AWS database feature should the architect implement to meet these requirements?

A.Amazon DynamoDB global tables
B.Amazon RDS Multi-AZ deployment
C.Amazon Aurora Global Database
D.Amazon RDS read replicas in a secondary region
AnswerC

Amazon Aurora Global Database is designed for multi-region applications, providing a primary region that is writable and secondary regions that are read-only with typical replication lag under one second. It uses dedicated replication infrastructure for low latency and supports fast failover. This meets the requirements for a writable primary and low-lag readable secondary region.

Why this answer

The requirement is for a relational database that is writable in one region and readable in another with minimal replication lag. Amazon Aurora Global Database provides exactly this: a primary region for writes and secondary regions for reads with sub-second replication lag. Other options either do not support cross-region replication or do not provide the required low lag and relational capabilities.

Exam trap

The trap here is confusing Multi-AZ with multi-region; Multi-AZ is for high availability within a region, not for cross-region read scaling.

67
MCQmedium

A company is deploying a global web application that serves static content (images, CSS, JavaScript) to users worldwide. They want to reduce latency and offload traffic from the origin servers. Which service should they implement?

A.Auto-scaling group
B.VPN connection
C.Load balancer
D.Content Delivery Network (CDN)
AnswerD

CDN caches content at edge locations, reducing latency.

Why this answer

A Content Delivery Network (CDN) caches static content at edge locations worldwide, reducing latency and offloading origin servers.

68
Multi-Selecthard

A cloud architect is designing a multi-tier application on a public cloud. The application must be highly available and fault-tolerant within a single region. Which three items should be included in the architecture? (Select THREE.)

Select 3 answers
A.Deploy resources in multiple availability zones
B.Place a load balancer in front of the web tier
C.Use a single instance in one availability zone
D.Use a single database instance without replication
E.Implement health checks for all instances
AnswersA, B, E

Spreading resources across multiple availability zones within one region gives fault isolation: a single zone failure leaves the application running elsewhere. This directly satisfies the stem's fault-tolerance and high-availability constraint while remaining inside a single region.

Why this answer

High availability within a region requires distributing resources across availability zones, using load balancers for traffic distribution, and implementing health checks for automatic failover.

69
MCQmedium

A company is running a stateless web application on a public cloud. They expect traffic to spike during certain hours. Which scaling strategy would be most cost-effective and efficient?

A.Using a larger instance type and scheduling scaling actions
B.Pre-provisioning double capacity permanently
C.Horizontal scaling using auto-scaling groups based on CPU utilization
D.Vertical scaling with manual adjustments before anticipated spikes
AnswerC

Auto-scaling groups add or remove identical stateless instances horizontally as CPU utilisation rises and falls, matching capacity to demand. This satisfies the cost-effectiveness constraint because instances are billed only while running, unlike vertical scaling, which requires permanently larger, pricier instances.

Why this answer

Horizontal scaling with auto-scaling groups based on CPU utilization is the most cost-effective and efficient strategy for a stateless web application with variable traffic. Auto-scaling groups automatically adjust the number of instances in response to real-time demand, ensuring you only pay for the capacity you need. Because the application is stateless, any instance can handle any request, making horizontal scaling seamless and highly available.

This approach eliminates manual intervention and optimizes costs by scaling in during low-traffic periods.

Exam trap

CV0-004 often tests the misconception that vertical scaling is more efficient for spiky traffic, but the exam expects you to recognize that horizontal scaling with auto-scaling groups is the most cost-effective and efficient for stateless applications.

How to eliminate wrong answers

Option A is wrong because using a larger instance type (vertical scaling) and scheduling scaling actions still requires manual capacity planning and does not automatically respond to unexpected traffic spikes; it also often leads to over-provisioning during off-peak hours. Option B is wrong because pre-provisioning double capacity permanently is highly cost-inefficient, as you pay for idle resources during normal and low-traffic periods. Option D is wrong because vertical scaling with manual adjustments is reactive, labor-intensive, and limited by the maximum size of an instance; it cannot handle sudden spikes efficiently and may cause downtime during resizing.

70
MCQeasy

Which of the following storage types is most suitable for hosting a shared file system that multiple virtual machines need to access concurrently using NFS?

A.Archive storage
B.File storage
C.Block storage
D.Object storage
AnswerB

File storage exposes SMB or NFS shares, letting multiple VMs mount the same file system concurrently. Block storage attaches to a single instance, and object storage lacks a POSIX NFS interface. NFS concurrency is therefore satisfied only by file storage.

Why this answer

File storage (e.g., EFS, Azure Files) provides a shared file system accessible via NFS or SMB.

71
MCQmedium

A cloud architect is designing a system that must durably store an unlimited amount of unstructured data, such as images and videos, with 99.999999999% (11 nines) durability. The data will be accessed infrequently, but when accessed, it must be available within milliseconds. The architect wants the most cost-effective storage class for this access pattern. Which Amazon S3 storage class should the architect choose?

A.Amazon S3 Glacier Deep Archive
B.Amazon S3 Standard
C.Amazon S3 Intelligent-Tiering
D.Amazon S3 Standard-Infrequent Access (S3 Standard-IA)
AnswerD

Amazon S3 Standard-IA is designed for data that is accessed less frequently but requires rapid access when needed. It offers the same low latency and high throughput as S3 Standard, with 11 nines of durability, and has a lower storage price. It is the most cost-effective choice for infrequently accessed data that must be immediately available, though it has a minimum storage duration charge of 30 days.

Why this answer

Amazon S3 Standard-IA is the correct choice because it provides low-latency access and 11 nines of durability at a lower storage cost than S3 Standard, making it ideal for infrequently accessed data that requires immediate availability. The other options are either too expensive for infrequent access, incur monitoring fees, or have retrieval times that are too slow.

Exam trap

The trap here is assuming that S3 Intelligent-Tiering is always the most cost-effective for infrequent access, when in fact it adds a per-object monitoring fee that can make it more expensive than a static infrequent access class for known access patterns.

72
MCQhard

A company runs a stateless web application on AWS EC2 instances behind an Application Load Balancer. To reduce costs, they want to use the most cost-effective compute option that can handle variable traffic and be interrupted. Which pricing model should they use for the EC2 instances?

A.Dedicated hosts
B.Spot instances
C.Reserved instances
D.On-demand instances
AnswerB

Spot instances exploit spare EC2 capacity at steep discounts, suiting the stateless, interruptible workload described. The Application Load Balancer distributes traffic across instances, so a reclaimed Spot instance causes no data loss, and variable demand is met elastically. This satisfies the stem's cost-effectiveness and tolerance-for-interruption constraints better than On-Demand or Reserved pricing.

Why this answer

Spot instances are the most cost-effective EC2 option for stateless, interruption-tolerant workloads. They leverage unused AWS capacity at discounts up to 90% off On-Demand, and since the application is stateless and sits behind an ALB, instances can be terminated and replaced without data loss or session disruption. This matches the requirement for variable traffic handling with cost reduction.

Exam trap

CV0-004 often tests the misconception that Reserved Instances are always the cheapest option, but they require commitment and are unsuitable for variable or interruptible workloads; the key is recognizing that 'interrupted' and 'stateless' point directly to Spot.

How to eliminate wrong answers

Option A is wrong because Dedicated Hosts are physical servers fully dedicated to a single customer, designed for licensing and compliance needs, and are the most expensive option—not cost-effective for variable, interruptible workloads. Option C is wrong because Reserved Instances require a 1- or 3-year commitment and provide savings only for steady-state, predictable usage; they do not handle variable traffic well and cannot be interrupted for savings. Option D is wrong because On-Demand instances offer no discount and are billed per second with no interruption capability, making them the least cost-effective choice for a workload that can tolerate interruptions.

73
MCQmedium

A company wants to connect its on-premises data center to a public cloud provider with a dedicated, high-bandwidth, low-latency connection. The connection must be private and not traverse the internet. Which connectivity option should be used?

A.Site-to-Site VPN
B.Internet gateway
C.VPC peering
D.Direct Connect or ExpressRoute
AnswerD

Direct Connect and ExpressRoute provide dedicated private circuits between on-premises infrastructure and cloud providers, bypassing the public internet entirely. This satisfies the stem's requirements for high bandwidth, low latency, and privacy. Unlike site-to-site VPNs, which tunnel over the internet, these services deliver consistent performance through a direct physical link.

Why this answer

AWS Direct Connect and Azure ExpressRoute are dedicated private connectivity services that establish a physical cross-connect between the on-premises data center and the cloud provider's network via a colocation facility, bypassing the public internet entirely. They deliver high bandwidth (up to 100 Gbps with LAG) and consistent low latency, satisfying the private, non-internet requirement.

Exam trap

CV0-004 often tests whether candidates distinguish dedicated private interconnect (Direct Connect/ExpressRoute) from internet-based VPNs, trapping them into selecting Site-to-Site VPN because it is also 'private' via encryption — but it still traverses the public internet.

How to eliminate wrong answers

Option A is wrong because a Site-to-Site VPN tunnels traffic over the public internet (IPsec), so it does traverse the internet and offers variable latency and bandwidth — it fails the 'not traverse the internet' requirement. Option B is wrong because an Internet gateway is the cloud-side component that enables VPC resources to communicate with the internet; it is the opposite of a private dedicated connection. Option C is wrong because VPC peering connects two VPCs within (or across) cloud accounts/regions — it is cloud-to-cloud connectivity and does not connect an on-premises data center to the cloud.

74
MCQeasy

Which cloud service model provides the customer with the most control over the operating system and software stack?

A.FaaS
B.SaaS
C.PaaS
D.IaaS
AnswerD

IaaS delivers virtualised compute, storage and networking while leaving the guest operating system, middleware and applications to the customer. This satisfies the requirement for maximum control, since the customer patches, hardens and configures the OS and software stack themselves.

Why this answer

IaaS (Infrastructure as a Service) provides the customer with the highest level of control over the operating system and software stack among the cloud service models. In IaaS, the provider manages the physical infrastructure, but the customer is responsible for the OS, middleware, runtime, and applications. This allows for maximum customization and control.

Exam trap

CV0-004 often tests the understanding of the shared responsibility model and which model offers the most control. The trap is to confuse PaaS with IaaS, thinking PaaS gives more control because it includes a platform, but actually IaaS gives more control over the OS.

How to eliminate wrong answers

Option A is wrong because FaaS (Function as a Service) abstracts away the OS and runtime, giving the customer only control over the function code. Option B is wrong because SaaS (Software as a Service) provides a complete application managed by the provider, with minimal customer control. Option C is wrong because PaaS (Platform as a Service) provides a platform for deploying applications, but the OS and runtime are managed by the provider, so the customer has less control than with IaaS.

75
MCQhard

A cloud architect is designing a shared file system for a machine learning cluster where multiple Linux virtual machines must read and write the same training data concurrently with POSIX semantics. The workload runs for several weeks and needs high aggregate throughput. Which storage solution should the architect select?

A.An object storage bucket accessed through a REST API for all training data reads and writes.
B.A local SSD on each virtual machine with a scheduled rsync job to synchronize data.
C.A managed network file system that supports concurrent POSIX access and scales throughput with provisioned capacity.
D.A block storage volume attached to each virtual machine individually.
AnswerC

A managed network file system designed for concurrent access provides the shared POSIX namespace the cluster needs, and its throughput often scales with provisioned capacity, which suits a multi-week, high-throughput training job. It supports many clients mounting the same file system simultaneously, so all virtual machines see consistent file metadata and can read and write in parallel.

Why this answer

A managed network file system is purpose-built for many clients mounting the same POSIX namespace concurrently. It provides shared file locking and metadata, and its throughput commonly scales with provisioned capacity, making it suitable for a long-running, high-throughput machine learning workload that requires consistent concurrent access.

Exam trap

The trap here is assuming that fast local SSDs or object storage can substitute for a shared POSIX file system, when neither provides concurrent file semantics across many nodes.

Page 1 of 2 · 133 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cloud Architecture and Design questions.