Courseiva

CCNA Cloud Architecture and Design Questions

58 of 133 questions · Page 2/2 · Cloud Architecture and Design · Answers revealed

76
MCQeasy

Which of the following is a characteristic of serverless computing (FaaS)?

A.You pay for allocated resources regardless of usage
B.You are charged per execution or compute time
C.You must manage the underlying servers
D.You have to provision capacity in advance
AnswerB

Serverless computing (FaaS) bills only for actual invocation and execution duration, measured in milliseconds, rather than for idle provisioned capacity. This consumption-based model directly satisfies the characteristic sought: no charges accrue while code sits dormant, unlike always-on virtual machines or containers.

Why this answer

Serverless computing (FaaS) abstracts all infrastructure management and bills based on actual consumption — typically per invocation and per GB-second of compute time. This means you pay only when your function executes, not for idle capacity. This consumption-based model is the defining economic characteristic of FaaS platforms like AWS Lambda, Azure Functions, and Google Cloud Functions.

Exam trap

CV0-004 often tests the confusion between serverless (consumption-based, no server management) and IaaS (pre-provisioned, pay-for-allocated) — candidates who conflate 'no servers to manage' with 'no servers involved' or who pick reserved-capacity answers get tripped up.

How to eliminate wrong answers

Option A is wrong because paying for allocated resources regardless of usage describes traditional IaaS or reserved-instance pricing, not serverless — FaaS scales to zero and charges nothing when idle. Option C is wrong because managing underlying servers is the opposite of serverless; the cloud provider fully manages the runtime, OS patching, and scaling. Option D is wrong because provisioning capacity in advance describes EC2-style pre-provisioned compute; FaaS automatically provisions and scales per request without any advance capacity planning.

77
Multi-Selectmedium

A cloud architect is designing a highly available three-tier application on AWS. The web tier must survive the loss of a single Availability Zone, and the database tier must support automatic failover with minimal administrative intervention. Which TWO design decisions should the architect implement? (Choose two.)

Select 2 answers
A.Use a Multi-AZ deployment for Amazon RDS so a standby is maintained in a second Availability Zone
B.Configure Amazon RDS as a Single-AZ instance with automated snapshots every hour
C.Attach an Elastic IP address to each web server instance and update DNS manually during an outage
D.Place all web servers in a single Availability Zone and use larger instance types
E.Deploy web servers in an Auto Scaling group spanning at least two Availability Zones behind an Application Load Balancer
AnswersA, E

RDS Multi-AZ maintains a synchronous standby in another Availability Zone and automatically promotes it during a failure, updating the DNS endpoint so the application reconnects without manual intervention. This satisfies the database requirement for automatic failover with minimal administration.

Why this answer

Zone-level resilience for the web tier comes from distributing instances across zones behind a load balancer, and database resilience with automatic failover comes from a Multi-AZ standby that is promoted without manual steps. The remaining choices either concentrate risk in one zone, rely on slow manual restoration, or depend on human intervention during an outage.

Exam trap

The trap here is equating backups or larger instances with high availability, when neither provides automatic failover during a zone outage.

78
MCQmedium

A company uses AWS and Azure for redundancy. They deploy the same application on both clouds to avoid vendor lock-in and improve disaster recovery. Which cloud deployment model is this?

A.Community cloud
B.Hybrid cloud
C.Private cloud
D.Multi-cloud
AnswerD

Multi-cloud means deliberately using two or more distinct public cloud providers, here AWS and Azure, for the same workload. This satisfies the redundancy, lock-in avoidance and disaster recovery constraints, unlike hybrid cloud, which pairs public cloud with private infrastructure.

Why this answer

Multi-cloud uses multiple public cloud providers for redundancy and best-of-breed services.

79
MCQeasy

Which storage type is most appropriate for a shared file system that multiple virtual machines need to mount simultaneously with read/write access?

A.Archive storage
B.File storage
C.Object storage
D.Block storage
AnswerB

File storage exposes SMB or NFS shares that many VMs can mount concurrently with read/write access, satisfying the simultaneous multi-mount constraint. Block storage attaches to a single instance, and object storage uses HTTP APIs rather than mountable file protocols.

Why this answer

File storage (e.g., NFS, SMB, or a shared file system like Azure Files) is designed to be mounted simultaneously by multiple clients with read/write access, providing a shared namespace and file-level locking. Block storage typically attaches to a single VM at a time (unless using shared disks with cluster-aware file systems), and object storage is accessed via HTTP APIs, not mounted as a traditional file system. Archive storage is for long-term retention and is not suitable for active shared read/write workloads.

Exam trap

CV0-004 often tests the confusion between block and file storage for shared access; candidates may pick block storage because it is common for VM disks, but block storage is not natively shared read/write across multiple VMs without a cluster file system.

How to eliminate wrong answers

Option A is wrong because archive storage is optimized for low-cost, infrequent access and long retrieval times, not for active shared read/write mounting by multiple VMs. Option C is wrong because object storage exposes data via REST APIs and is not natively mountable as a POSIX-compliant shared file system for simultaneous read/write by multiple VMs. Option D is wrong because block storage presents raw volumes that are typically attached to one VM at a time; simultaneous read/write from multiple VMs requires a cluster file system and is not the default or most appropriate choice for a shared file system.

80
MCQeasy

A cloud administrator is deploying a microservices application on Kubernetes in a public cloud. The services must be able to discover each other dynamically and route traffic without hardcoded IP addresses. Which Kubernetes resource should the administrator use to provide a stable network endpoint for a set of pods?

A.ConfigMap
B.NetworkPolicy
C.Service
D.Ingress
AnswerC

A Kubernetes Service provides a stable virtual IP and DNS name that abstracts a set of pods. It enables dynamic discovery and load balancing across pods, even as they are created or destroyed. This matches the requirement for a stable network endpoint without hardcoded IPs.

Why this answer

A Kubernetes Service is the correct resource for providing a stable network endpoint and enabling dynamic service discovery. It abstracts pod IPs and offers load balancing, which is essential for microservices communication without hardcoded addresses.

Exam trap

The trap here is confusing Ingress with Service; Ingress is for external access and HTTP routing, not for internal service discovery.

81
Multi-Selecthard

A company is designing a highly available architecture for a critical application. The solution must tolerate the failure of an entire availability zone. Which TWO design principles should be implemented? (Choose two.)

Select 2 answers
A.Deploy instances in a single availability zone
B.Use RAID 0 for all instance storage
C.Use a single load balancer without health checks
D.Use a load balancer with health checks and cross-zone load balancing
E.Deploy instances across multiple availability zones
AnswersD, E

Cross-zone load balancing distributes traffic evenly across healthy targets in every availability zone, and health checks withdraw targets in a failed zone automatically. This satisfies the stem's zone-failure tolerance constraint by removing the failed zone from rotation without manual intervention.

Why this answer

To tolerate an AZ failure, deploy across multiple AZs and use active-active or active-passive with failover. So deploying across multiple AZs and using a load balancer with health checks to route traffic away from failed AZ are correct.

82
MCQeasy

A media company stores finished video masters in Amazon S3. Regulators require that each master be retained unaltered for exactly seven years, and that no user, including the root account, be able to delete or overwrite it during that period. Which S3 capability should the administrator implement?

A.S3 Lifecycle rules that transition objects to S3 Glacier Deep Archive after 30 days and expire them after 2555 days.
B.S3 Cross-Region Replication with S3 Inventory reports sent to a separate account for audit purposes.
C.S3 Object Lock in compliance mode with a retention period of 2555 days applied to the bucket.
D.S3 Versioning combined with a bucket policy that denies s3:DeleteObject to all principals.
AnswerC

S3 Object Lock in compliance mode enforces a write-once-read-many retention period that even the root user cannot shorten or bypass, and objects cannot be overwritten or deleted until the date passes. Setting a 2555-day retention on the bucket satisfies the exact seven-year, tamper-proof requirement for every stored video master.

Why this answer

Object Lock in compliance mode is the only S3 mechanism that enforces immutability against every principal, including the account root user, for a fixed retention period. Applying a 2555-day retention to the bucket covers all video masters automatically. Lifecycle rules, versioning with deny policies, and replication all offer durability or auditing benefits but remain reversible by privileged users, so none guarantees regulatory immutability.

Exam trap

The trap here is assuming that a deny-based bucket policy or versioning is tamper-proof, when both can be changed or bypassed by a privileged principal.

83
MCQeasy

Which cloud service model gives the customer the most control over the operating system and applications, while the provider manages the physical hardware, network, and storage?

A.FaaS
B.PaaS
C.SaaS
D.IaaS
AnswerD

IaaS leaves the customer managing the guest operating system, middleware and applications, while the provider handles physical hardware, networking and storage virtualisation. This split gives more control than PaaS or SaaS, which abstract the OS layer away.

Why this answer

IaaS (Infrastructure as a Service) provides virtualized compute, storage, and networking resources, but the customer is responsible for managing the guest operating system, middleware, runtime, and applications. The provider only manages the physical hardware, network fabric, and storage infrastructure. This gives the customer the highest level of control among the listed models without owning the physical data center.

Exam trap

CV0-004 often tests the misconception that PaaS gives more control than IaaS because it includes development tools, but the key differentiator is that IaaS leaves OS management to the customer, while PaaS abstracts it away.

How to eliminate wrong answers

Option A is wrong because FaaS (Function as a Service) abstracts away the operating system, runtime, and even the application server, leaving the customer responsible only for function code and configuration. Option B is wrong because PaaS (Platform as a Service) manages the OS, runtime, and middleware, so the customer only controls deployed applications and some configuration settings. Option C is wrong because SaaS (Software as a Service) delivers a fully managed application where the customer has no control over the underlying OS, runtime, or infrastructure.

84
MCQeasy

A company decides to use AWS for compute and Azure for storage to leverage best-of-breed services. This is an example of which cloud deployment model?

A.Multi-cloud
B.Community cloud
C.Public cloud
D.Hybrid cloud
AnswerA

Multi-cloud means deliberately using two or more distinct public cloud providers for different workloads. AWS for compute plus Azure for storage spans separate providers, satisfying the best-of-breed requirement rather than a hybrid or single-provider model.

Why this answer

Using AWS for compute and Azure for storage means the organization is consuming services from two different public cloud providers simultaneously, which is the definition of a multi-cloud deployment. Multi-cloud is about using multiple providers, regardless of whether workloads are integrated. Hybrid cloud, by contrast, combines public cloud with private infrastructure.

Exam trap

CV0-004 often tests the confusion between multi-cloud and hybrid cloud, so candidates must anchor on whether the mix involves two public providers (multi-cloud) or public plus private/on-premises (hybrid).

How to eliminate wrong answers

Option B is wrong because a community cloud is shared infrastructure among organizations with common concerns (e.g., government agencies), not multiple commercial providers. Option C is wrong because public cloud refers to a single provider's shared infrastructure; using two providers is not 'public cloud' as a model. Option D is wrong because hybrid cloud combines public cloud with private cloud or on-premises infrastructure, not two public providers.

85
Multi-Selectmedium

A cloud architect is reviewing costs for a production environment. The environment uses a mix of EC2 instances and RDS databases. Which THREE of the following are effective cost optimization strategies?

Select 3 answers
A.Use reserved instances for baseline capacity
B.Implement storage lifecycle policies to move old data to cheaper storage tiers
C.Use all SSD storage for all data to maximize performance
D.Rightsize instances based on actual utilization metrics
E.Run all instances 24/7 to ensure availability
AnswersA, B, D

Reserved instances apply a one- or three-year commitment to steady-state capacity, cutting hourly rates substantially versus on-demand. This satisfies the cost optimisation requirement by discounting the predictable baseline load while on-demand or spot covers peaks.

Why this answer

Reserved instances provide discounts for steady-state usage. Storage lifecycle policies move data to cheaper tiers over time. Rightsizing ensures resources match workload requirements, reducing waste.

Using all SSD even for cold data is expensive. Running instances 24/7 when not needed increases costs unnecessarily.

86
MCQmedium

A cloud architect is choosing a compute pricing model for a batch processing job that runs for 2 hours every night. The job can be interrupted. Which option is most cost-effective?

A.Reserved instances for 1 year
B.Spot instances
C.On-demand instances
D.Dedicated hosts
AnswerB

Spot instances price capacity at steep discounts because workloads are evictable, matching the job's interruptibility. Reserved or on-demand pricing would charge for guaranteed availability the batch job does not require, so spot satisfies the nightly two-hour, interruption-tolerant constraint most cheaply.

Why this answer

Spot instances are the most cost-effective option because the batch processing job is fault-tolerant (can be interrupted) and runs for a fixed, short duration (2 hours nightly). Spot instances offer significant discounts (often 60-90% off on-demand pricing) by leveraging unused cloud capacity, which can be reclaimed with a 2-minute warning. This aligns perfectly with the workload's tolerance for interruption and its predictable but non-critical schedule.

Exam trap

The CV0-004 exam often tests the misconception that Reserved instances are always cheaper for any recurring workload, but the trap here is that the short, interruptible nature of the job makes spot instances far more cost-effective than committing to a long-term reservation.

How to eliminate wrong answers

Option A is wrong because Reserved instances require a 1-year or 3-year commitment and are designed for steady-state, always-on workloads; paying upfront for a full year to cover only 2 hours per night is wasteful and not cost-effective. Option C is wrong because On-demand instances charge per hour with no discount, making them more expensive than spot instances for a batch job that can tolerate interruptions. Option D is wrong because Dedicated hosts are physical servers dedicated to a single customer, incurring high costs for full server capacity regardless of usage; they are intended for compliance or licensing needs, not for cost optimization on an interruptible batch job.

87
MCQmedium

A cloud architect is designing a highly available web application on AWS. The application must continue serving traffic even if an entire AWS Availability Zone fails. Which architecture should the architect implement?

A.Active-passive in a single Availability Zone
B.Active-active across two Availability Zones
C.Vertical scaling on a single instance
D.Active-passive across two regions
AnswerB

Active-active across two Availability Zones runs identical workloads in both, so each AZ handles traffic independently. When one AZ fails, the surviving AZ absorbs the load, satisfying the requirement to keep serving traffic through a full AZ outage.

Why this answer

Active-active architecture across multiple Availability Zones ensures that if one zone fails, traffic is routed to the remaining healthy zones, providing high availability.

88
MCQmedium

A company uses Azure and wants to connect its on-premises data center to Azure with a dedicated, private, and high-bandwidth connection. Which service should the company use?

A.Azure ExpressRoute
B.Site-to-Site VPN
C.Azure Front Door
D.Azure VPN Gateway
AnswerA

Azure ExpressRoute provides a dedicated, private circuit through a connectivity provider, bypassing the public internet entirely. This satisfies the stem's requirement for private, high-bandwidth connectivity between the on-premises data centre and Azure, unlike VPN gateways which traverse the public internet and offer variable bandwidth.

Why this answer

Azure ExpressRoute provides a dedicated private connection from on-premises to Azure, offering higher bandwidth and reliability than VPN.

89
MCQmedium

An organization needs to connect its on-premises data center to a public cloud with a dedicated, low-latency, and consistent network connection. Which connectivity option should they use?

A.Direct Connect
B.Internet gateway
C.VPC peering
D.Site-to-site VPN
AnswerA

Direct Connect provides a dedicated private connection with consistent performance.

Why this answer

Direct Connect (AWS) or ExpressRoute (Azure) provides dedicated private connectivity from on-premises to cloud.

90
Multi-Selectmedium

A company is designing stateless application tiers to support horizontal scaling. Which TWO design principles support statelessness? (Select TWO.)

Select 2 answers
A.Persist all application state in a shared database
B.Store configuration files on each instance locally
C.Store session state in a shared external cache (e.g., Redis)
D.Use local instance storage for session data
E.Use sticky sessions (session affinity) on the load balancer
AnswersA, C

A shared database externalises all session and user state, so any instance can serve any request without relying on local memory. This satisfies the horizontal-scaling constraint, since instances remain interchangeable and can be added or removed freely.

Why this answer

Option A is correct because persisting all application state in a shared database externalizes state from the compute instances, so any instance can serve any request and instances can be added or replaced freely for horizontal scaling. Option C is correct because storing session state in a shared external cache such as Redis keeps session data outside the instance, allowing any instance to read the session and remain interchangeable, which is the essence of statelessness. Option B is not correct because storing configuration files locally on each instance creates per-instance state that must be synchronized and makes instances non-interchangeable.

Option D is not correct because local instance storage for session data ties a user's session to a specific instance, preventing free horizontal scaling. Option E is not correct because sticky sessions (session affinity) on the load balancer deliberately pin a client to one instance, which is the opposite of stateless design and hinders horizontal scaling.

Exam trap

CV0-004 often tests whether candidates recognize that sticky sessions and local session storage are anti-patterns for statelessness — the distractor 'use sticky sessions' sounds like a load-balancing best practice but directly contradicts stateless design.

91
MCQeasy

Which cloud deployment model connects an on-premises data center to a public cloud using VPN or dedicated connections like AWS Direct Connect?

A.Private cloud
B.Multi-cloud
C.Hybrid cloud
D.Public cloud
AnswerC

Hybrid cloud joins on-premises infrastructure to a public cloud through VPN tunnels or dedicated private links such as AWS Direct Connect, keeping workloads split across both environments. That connectivity mechanism is exactly what the stem describes.

Why this answer

A hybrid cloud deployment model combines on-premises infrastructure with public cloud services, connected via VPN or dedicated connections like AWS Direct Connect. This allows workloads to span both environments, providing flexibility and scalability. It is the standard term for such integrated architectures.

Exam trap

The trap is confusing hybrid cloud with multi-cloud or private cloud; candidates must remember that hybrid specifically involves on-premises to public cloud integration.

How to eliminate wrong answers

Option A is wrong because a private cloud is dedicated to a single organization and does not inherently connect to a public cloud. Option B is wrong because multi-cloud refers to using multiple public cloud providers, not connecting on-premises to a public cloud. Option D is wrong because a public cloud is a shared, multi-tenant environment without the on-premises integration.

92
Multi-Selecthard

A company is deploying a web application on Google Cloud that requires low-latency access to static content (images, CSS) for global users. The application also needs to handle SSL termination to reduce load on backend instances. Which TWO services should the architect use? (Select TWO.)

Select 2 answers
A.Compute Engine with enhanced network
B.Cloud Functions
C.Cloud CDN
D.Cloud Load Balancing
E.Cloud Storage
AnswersC, D

Cloud CDN caches static assets at Google's global edge points of presence, cutting latency for images and CSS by serving users from nearby locations rather than the origin. It directly satisfies the stem's low-latency static-content constraint. SSL termination, however, is handled separately by the external Application Load Balancer, not Cloud CDN itself.

Why this answer

Cloud CDN (Option C) is correct because it uses Google's global edge cache to deliver static content (images, CSS) with low latency by caching content at points of presence (PoPs) close to users. Cloud Load Balancing (Option D) is correct because it provides global anycast-based load balancing with integrated SSL termination, offloading the SSL/TLS handshake from backend instances and reducing their CPU load.

Exam trap

The CV0-004 exam often tests the misconception that Cloud Storage alone can serve static content globally with low latency, but it lacks edge caching and SSL termination, requiring Cloud CDN and Cloud Load Balancing to meet the requirements.

93
MCQmedium

A cloud architect is selecting a storage solution for a database that requires low-latency reads and writes. The database will run on a single VM and must support consistent performance. Which storage type is most appropriate?

A.Archive storage
B.Object storage
C.File storage
D.Block storage
AnswerD

Block storage presents a raw volume directly to the VM, giving the database low-latency, consistent read/write performance on a single host. File and object storage add network protocol overhead and are unsuitable for database workloads needing predictable IOPS, so block satisfies the single-VM, consistent-performance constraint.

Why this answer

Block storage (e.g., EBS, Azure Disk) provides low-latency, consistent performance suitable for databases running on a single VM.

94
MCQhard

A cloud architect is designing a solution to store and retrieve large volumes of unstructured data for a media company. The data must be highly durable, available, and accessible from multiple AWS Regions with low latency. The company also wants to minimize costs for data that is infrequently accessed but must be retained for years. Which AWS service and feature combination should the architect use?

A.Amazon FSx for Lustre with data repository integration
B.Amazon S3 with Cross-Region Replication and S3 Lifecycle policies to transition to S3 Glacier Deep Archive
C.Amazon EBS with snapshots copied to multiple regions
D.Amazon EFS with replication to multiple regions
AnswerB

Amazon S3 provides high durability and availability for unstructured data. Cross-Region Replication automatically replicates objects to another region, enabling low-latency access from multiple regions. S3 Lifecycle policies can transition infrequently accessed data to S3 Glacier Deep Archive for long-term retention at low cost. This combination meets all requirements.

Why this answer

Amazon S3 with Cross-Region Replication and lifecycle policies to S3 Glacier Deep Archive provides a durable, highly available, and globally accessible solution for unstructured data. Cross-Region Replication ensures low-latency access from multiple regions, while lifecycle policies automatically transition infrequently accessed data to a low-cost archival storage class. The other services are either block or file storage and do not offer the same global accessibility and cost-effective archival.

Exam trap

The trap here is confusing block or file storage services with object storage for global, multi-region access, or overlooking the need for a lifecycle policy to reduce costs for infrequently accessed data.

95
MCQmedium

A company uses a public cloud PaaS service to run a custom application. They need to ensure the application can handle increased load without downtime. Which action should they take?

A.Deploy a load balancer in front of the application
B.Move to IaaS to gain more control over scaling
C.Configure auto-scaling for the PaaS service
D.Upgrade the underlying virtual machines manually
AnswerC

Configuring auto-scaling lets the PaaS platform add and remove compute instances automatically as demand rises, directly meeting the no-downtime requirement under increased load. Because the provider manages the underlying infrastructure, scaling occurs without manual intervention or service interruption, unlike vertical resizing, which typically needs a restart.

Why this answer

In a PaaS environment, the cloud provider manages the underlying infrastructure, so the customer cannot manually upgrade VMs. Auto-scaling is a built-in feature of many PaaS services that automatically adjusts resources based on demand, ensuring the application can handle increased load without downtime. This is the most appropriate action.

Exam trap

The trap is thinking that manual VM upgrades or moving to IaaS are necessary for scaling, when in fact PaaS provides auto-scaling as a managed feature.

How to eliminate wrong answers

Option A is wrong because while a load balancer can distribute traffic, it does not automatically scale resources; auto-scaling is needed to handle increased load. Option B is wrong because moving to IaaS would require the company to manage scaling themselves, which is not the goal. Option D is wrong because in PaaS, the underlying VMs are managed by the provider and cannot be manually upgraded by the customer.

96
Multi-Selectmedium

A company is migrating a legacy stateful application to the cloud. The application currently runs on a single server and stores session data locally. To enable horizontal scaling, which two design changes should the architect recommend? (Select TWO.)

Select 2 answers
A.Add more storage to the existing instance
B.Implement sticky sessions on the load balancer
C.Move session state to a shared database or cache
D.Use a larger instance type for the application server
E.Refactor the application to be stateless
AnswersC, E

Moving session state to a shared database or cache externalises it from individual instances, so any server behind the load balancer can serve any request. This directly satisfies the horizontal scaling requirement, since locally stored sessions would otherwise pin users to one server and break scaling.

Why this answer

Option C is correct because moving session state to a shared database or cache (e.g., Redis, Memcached, or DynamoDB) externalizes the state so any instance behind the load balancer can serve any request, which is essential for horizontal scaling. Option E is correct because refactoring the application to be stateless removes local session dependencies entirely, allowing instances to be added or removed freely and making the tier truly horizontally scalable. Options A and D are incorrect because adding storage or using a larger instance are vertical scaling approaches that do not enable horizontal scaling and leave the stateful single-server bottleneck in place.

Option B is incorrect because sticky sessions only pin a client to one instance, which preserves the stateful coupling, can cause uneven load, and does not solve the underlying need to share or eliminate session state.

Exam trap

The trap is treating sticky sessions as a scaling solution — they preserve session continuity but actually inhibit horizontal scaling and are the opposite of the stateless design the question is asking for.

97
MCQmedium

A cloud architect is designing a containerized microservices platform for a retail company. The company requires that individual services scale independently, that failed containers be replaced automatically without manual intervention, and that the platform abstract away the underlying compute hosts. The operations team has limited experience with cluster management. Which cloud-native orchestration approach BEST meets these requirements?

A.Deploy the microservices to a managed Kubernetes service and define Deployments and Horizontal Pod Autoscalers.
B.Deploy each microservice on a dedicated virtual machine with an autoscaling group per service.
C.Package all microservices into a single monolithic container and run it on one large virtual machine.
D.Use serverless functions for every service and rely on the provider to manage all scaling and placement.
AnswerA

A managed Kubernetes service provides a control plane that schedules containers, restarts failed pods through the ReplicaSet controller, and abstracts the worker nodes. Horizontal Pod Autoscalers adjust replica counts per service based on metrics, so each microservice scales independently. Because the provider manages the control plane, the operations team's limited cluster expertise is less of an obstacle.

Why this answer

A managed Kubernetes service supplies the orchestration features the scenario demands: scheduling across hosts, self-healing of failed containers via controllers, and per-service scaling through Horizontal Pod Autoscalers. It also removes control-plane administration from a team lacking deep cluster skills. The other approaches either fail to abstract hosts, prevent independent scaling, or impose execution-model limits.

Exam trap

The trap here is assuming that autoscaling groups of virtual machines provide the same host abstraction and self-healing as a container orchestrator.

98
MCQmedium

A cloud engineer is sizing a relational database for an application with unpredictable read volume that spikes sharply during business hours. The database must scale read capacity without downtime and without changing the application's connection string. Which approach should the engineer use?

A.Vertically scale the primary database instance to a larger size during peak hours.
B.Enable a multi-AZ standby and direct read queries to the standby instance.
C.Add read replicas behind a database-aware proxy or reader endpoint so reads are distributed across replicas.
D.Increase the database's storage volume size to improve read throughput.
AnswerC

Read replicas offload read traffic from the primary and can be added or removed while the database stays online. A reader endpoint or proxy presents a stable address, so the application keeps the same connection string while read capacity scales horizontally. This directly addresses unpredictable read spikes without downtime or application changes.

Why this answer

Read replicas let a relational database scale read capacity horizontally while the primary continues handling writes. Because replicas can be added or removed online and a reader endpoint or proxy keeps a stable address, the application does not need a new connection string and experiences no downtime during scaling.

Exam trap

The trap here is confusing a multi-AZ standby, which is passive and used only for failover, with a read replica, which actively serves read queries.

99
MCQmedium

A cloud architect is designing a landing zone in AWS Organizations. The security team mandates that all member accounts must centrally log API activity and that individual account administrators must not be able to disable or alter the log destination. The architect needs to enforce this across every current and future account with minimal operational overhead. Which combination of actions should the architect take?

A.Enable CloudTrail in each member account individually, and use AWS Config rules to detect when a trail is stopped so the security team can be notified.
B.Enable AWS CloudTrail Lake in the management account and configure an event data store that ingests events from all member accounts through a resource-based policy.
C.Create an organization trail in CloudTrail from the management account with an S3 bucket in a dedicated log archive account, and attach a service control policy (SCP) denying cloudtrail:StopLogging and cloudtrail:DeleteTrail to all member accounts.
D.Configure AWS Control Tower with a detective guardrail that monitors CloudTrail configuration drift and sends findings to Security Hub for remediation.
AnswerC

An organization trail automatically applies to all accounts in the organization, including accounts added later, and delivers events to a central S3 bucket. The SCP then removes the ability of member account principals to stop or delete the trail, satisfying the tamper-resistance requirement without per-account configuration.

Why this answer

Centralized, tamper-resistant logging across an entire AWS Organization is achieved with an organization trail created from the management account that delivers to a log archive account, combined with an SCP that denies the trail-stopping and trail-deletion actions to member accounts. This design automatically covers future accounts and prevents local administrators from disabling logging.

Exam trap

The trap here is assuming that a detective control such as AWS Config or Control Tower guardrails prevents an account administrator from stopping logging, when only a preventive control like an SCP actually blocks the action.

100
MCQhard

An organization is designing a VPC with public and private subnets. The web servers must be accessible from the internet, but database servers must not. The architecture also requires high availability across two Availability Zones. What is the minimum number of public subnets and private subnets needed?

A.Two public, two private
B.One public, two private
C.Two public, one private
D.One public, one private
AnswerA

High availability across two Availability Zones requires each subnet tier duplicated per AZ, giving two public and two private subnets. Public subnets host the internet-facing web servers via an internet gateway, while private subnets hold the databases without inbound internet routing, satisfying both the accessibility and isolation constraints.

Why this answer

High availability across two Availability Zones requires at least one subnet per AZ for each tier. Since the architecture needs both public-facing web servers and private database servers in each AZ, the minimum is two public subnets and two private subnets — one of each per AZ.

Exam trap

CV0-004 often tests subnet-to-AZ mapping, and candidates incorrectly assume a single subnet can serve multiple AZs or that one public subnet suffices for HA.

How to eliminate wrong answers

Option B is wrong because one public subnet cannot span two AZs, so the web tier would not be highly available. Option C is wrong because one private subnet cannot span two AZs, so the database tier would not be highly available. Option D is wrong because a single public and single private subnet each reside in one AZ, providing no cross-AZ redundancy for either tier.

101
MCQeasy

Which cloud deployment model involves using services from multiple public cloud providers to avoid vendor lock-in and leverage best-of-breed solutions?

A.Public cloud
B.Hybrid cloud
C.Private cloud
D.Multi-cloud
AnswerD

Multi-cloud means consuming services from two or more public cloud providers simultaneously, distributing workloads across them. This avoids dependence on a single vendor and lets each workload use the strongest provider service, directly matching the stated vendor lock-in and best-of-breed requirements.

Why this answer

Multi-cloud is the use of multiple public cloud providers to gain flexibility and avoid dependency on a single vendor.

102
MCQmedium

A company wants to minimize cloud costs for a batch processing job that runs for a few hours each night and can be interrupted. Which pricing model is most appropriate?

A.Dedicated hosts
B.On-demand instances
C.Spot instances
D.Reserved instances
AnswerC

Spot instances use spare capacity priced far below on-demand rates, and their interruptible nature suits a nightly batch job that can tolerate eviction and resume. This directly satisfies the stem's cost-minimisation and interruption-tolerance constraints, unlike reserved or on-demand pricing.

Why this answer

Spot instances are ideal for batch processing jobs that can tolerate interruptions because they offer significant cost savings (up to 90% off on-demand) by utilizing spare cloud capacity. Since the job runs for a few hours each night and can be interrupted, spot instances provide the most cost-effective solution. They can be terminated by the cloud provider if capacity is needed, but for interruptible workloads, this is acceptable.

Exam trap

CV0-004 often tests the misconception that reserved instances are always cheapest, but for interruptible, short-term workloads, spot instances provide greater savings.

How to eliminate wrong answers

Option A is wrong because Dedicated hosts are physical servers dedicated to a single tenant, which are the most expensive option and provide no cost savings for interruptible workloads. Option B is wrong because On-demand instances are pay-as-you-go but lack the deep discounts of spot instances, making them less cost-effective for interruptible batch jobs. Option D is wrong because Reserved instances require a 1- or 3-year commitment and are best for steady-state workloads, not for short, nightly batch jobs that can be interrupted.

103
MCQhard

A cloud engineer is deploying a stateful application on Amazon EC2 that requires a persistent block storage volume with the highest possible IOPS and lowest latency for a database. The database will run on a single instance in one Availability Zone, and the engineer needs to choose the appropriate Amazon EBS volume type. Which volume type should the engineer select?

A.Amazon EBS Cold HDD (sc1)
B.Amazon EBS Provisioned IOPS SSD (io2 Block Express)
C.Amazon EBS General Purpose SSD (gp3)
D.Amazon EBS Throughput Optimized HDD (st1)
AnswerB

Amazon EBS Provisioned IOPS SSD (io2 Block Express) is designed for critical, I/O-intensive database workloads that require the highest levels of IOPS and consistently low latency. It supports up to 256,000 IOPS and 4,000 MB/s per volume with sub-millisecond latency, and offers 99.999% durability. It is the best choice for a single-instance database requiring maximum performance.

Why this answer

Amazon EBS Provisioned IOPS SSD (io2 Block Express) delivers the highest IOPS and lowest latency among EBS volume types, making it the correct choice for a performance-critical single-instance database. The other options are either throughput-oriented HDDs for sequential workloads or a general-purpose SSD that, while cost-effective, does not provide the extreme performance required in this scenario.

Exam trap

The trap here is assuming that General Purpose SSD (gp3) can be scaled to meet any performance requirement, when in fact it has a maximum IOPS limit far below what Provisioned IOPS SSD (io2 Block Express) can deliver.

104
MCQmedium

A company is deploying a global web application and wants to reduce latency for users around the world. The application serves static content (images, CSS) and dynamic API responses. Which combination of services should the architect use?

A.CDN for static content and a global load balancer with latency-based routing for dynamic content
B.CDN for all content without backend routing
C.A single load balancer in one region with a CDN
D.DNS round-robin for both static and dynamic content
AnswerA

A CDN caches static assets at edge locations, cutting latency for images and CSS. Dynamic API responses cannot be cached, so a global load balancer with latency-based routing directs each user to the nearest healthy regional endpoint, satisfying the worldwide latency constraint.

Why this answer

CDN caches static content at edge locations, reducing latency. For dynamic content, a global load balancer with latency-based routing directs users to the closest region. DNS alone cannot reduce latency for dynamic content.

A single load balancer does not provide global distribution.

105
MCQmedium

A cloud architect is designing a globally distributed application on Google Cloud. The application must serve users from the closest possible point of presence with minimal latency while using a single anycast IP address. Which load balancing solution should the architect choose?

A.Internal passthrough Network Load Balancer
B.External passthrough Network Load Balancer
C.Regional external Application Load Balancer
D.Global external Application Load Balancer
AnswerD

A global external Application Load Balancer uses a single anycast IP address and routes user traffic to the closest healthy backend based on Google's global network. It operates at layer 7, supports HTTP(S) workloads, and is designed for global low-latency distribution. This matches the requirement for a single IP and proximity-based routing across regions.

Why this answer

The global external Application Load Balancer is the only option that provides a single anycast IP address and automatically routes users to the closest healthy backend across Google Cloud regions. It is purpose-built for global, layer 7 applications that require minimal latency and high availability, making it the correct choice for this scenario.

Exam trap

The trap here is assuming that any load balancer with 'external' in its name can provide global anycast routing, when in fact regional and passthrough network load balancers are scoped to a single region and operate at layer 4.

106
MCQmedium

A company is migrating a legacy application to AWS. The application requires a shared file system that can be mounted on multiple Linux-based EC2 instances simultaneously. The file system must be highly available and scalable, and it must support POSIX permissions. Which AWS service should be used?

A.Amazon S3
B.Amazon EBS
C.Amazon FSx for Windows File Server
D.Amazon EFS
AnswerD

Amazon EFS is a fully managed, scalable, and highly available file storage service for Linux-based workloads. It supports the NFS protocol, can be mounted on multiple EC2 instances concurrently, and supports POSIX permissions. This meets all the requirements for a shared file system.

Why this answer

Amazon EFS is the correct choice because it is a managed NFS file system that can be mounted on multiple Linux EC2 instances, supports POSIX permissions, and is highly available and scalable. EBS is block storage for single-instance attachment, S3 is object storage, and FSx for Windows is for Windows workloads.

Exam trap

The trap here is confusing block storage (EBS) with file storage (EFS), as EBS is often used for instance storage but does not support shared file access.

107
MCQmedium

A company uses Azure and needs shared file storage accessible from multiple Linux VMs using standard file sharing protocols. Which storage type should they choose?

A.Azure Files
B.Azure Archive Storage
C.Azure Disk Storage
D.Azure Blob Storage
AnswerA

Azure Files provides fully managed SMB and NFS file shares, so multiple Linux VMs can mount the same share concurrently using standard protocols. This directly satisfies the stem's requirement for shared storage across Linux VMs, unlike blob storage or single-VM managed disks, which lack native multi-attach file sharing.

Why this answer

Azure Files provides fully managed file shares in the cloud that are accessible via the industry-standard SMB and NFS protocols, making it the correct choice for shared file storage across multiple Linux VMs. Linux VMs can mount Azure Files shares using SMB 3.0 or NFS 4.1, enabling concurrent access from multiple instances. The other storage types do not support standard file-sharing protocols for multi-VM access.

Exam trap

CV0-004 often tests the confusion between Azure Files (SMB/NFS file shares) and Azure Blob Storage (object storage), tricking candidates into choosing Blob Storage when the scenario explicitly requires standard file-sharing protocols like SMB or NFS.

How to eliminate wrong answers

Option B is wrong because Azure Archive Storage is a blob access tier designed for long-term archival of rarely accessed data with high retrieval latency — it is not a file share and cannot be mounted by VMs. Option C is wrong because Azure Disk Storage provides block-level virtual hard disks attached to a single VM (or shared disks with limitations); it does not offer a network file share accessible via SMB/NFS from multiple Linux VMs. Option D is wrong because Azure Blob Storage is object storage accessed via REST APIs or SDKs, not via standard file-sharing protocols like SMB or NFS, and cannot be mounted natively as a shared file system without additional services like BlobFuse or NFS 3.0 (which has limitations).

108
MCQeasy

An organization needs to store archival data for 7 years to meet compliance requirements. The data is rarely accessed, and retrieval time is not critical. Which cloud storage type is most cost-effective?

A.Block storage
B.File storage
C.Object storage
D.Archive storage
AnswerD

Archive storage offers the lowest per-gigabyte cost of the tiers, designed for data retained for years with infrequent access. The stem states retrieval time is not critical, so the slower, pricier-retrieval trade-off is acceptable for seven-year compliance retention.

Why this answer

Archive storage (e.g., AWS Glacier, Azure Archive) is designed for long-term, infrequently accessed data at the lowest cost. Block storage is for VMs. Object storage is for frequent access.

File storage is for shared file systems.

109
Multi-Selectmedium

A company is designing a hybrid cloud storage solution. Which TWO storage services are suitable for a shared file system accessible from both on-premises and cloud VMs? (Select TWO.)

Select 2 answers
A.Azure Blob
B.Azure Files
C.Amazon S3
D.Amazon EBS
E.Amazon EFS
AnswersB, E

Azure Files exposes SMB and NFS shares, so on-premises servers and cloud VMs mount the same file system concurrently. This satisfies the hybrid shared-file-system constraint without replication or application changes, unlike object storage such as Blob.

Why this answer

Azure Files (B) is correct because it provides fully managed SMB and NFS file shares that can be mounted simultaneously from on-premises Windows/Linux machines and Azure VMs, making it a true shared file system for hybrid scenarios. Amazon EFS (E) is correct because it is a managed NFS file system that supports mounting from on-premises servers via AWS Direct Connect or VPN as well as from EC2 instances in multiple Availability Zones. Azure Blob (A) is object storage accessed via HTTP/REST rather than a mountable shared file system, so it does not meet the requirement.

Amazon S3 (C) is also object storage with a REST API, not a POSIX/NFS/SMB file system. Amazon EBS (D) provides block storage volumes attached to a single EC2 instance and cannot be shared across on-premises and cloud VMs.

Exam trap

The trap is confusing object storage (Blob, S3) with file storage (Files, EFS) — candidates must remember that shared file systems require SMB/NFS protocols, not REST APIs.

110
MCQmedium

A cloud administrator is designing a backup strategy for a critical database. The recovery point objective (RPO) is 15 minutes, and the recovery time objective (RTO) is 1 hour. Which backup approach BEST meets these objectives?

A.Take a full backup once a day and store it in a different region.
B.Enable continuous transaction log shipping to a standby database in another availability zone.
C.Take a snapshot every hour and copy it to object storage.
D.Rely on the cloud provider's built-in redundancy within a single availability zone.
AnswerB

Continuous transaction log shipping replicates every committed transaction to a standby database, achieving an RPO of near zero or within minutes. If the primary fails, the standby can be promoted, and recovery time is typically well under an hour. This meets both the 15-minute RPO and the 1-hour RTO, providing a robust disaster recovery solution.

Why this answer

Continuous transaction log shipping provides near-real-time replication, ensuring that the standby database is always up to date. This achieves an RPO of minutes or less, well within the 15-minute requirement. In the event of a failure, the standby can be promoted quickly, meeting the 1-hour RTO.

Daily or hourly backups are too infrequent for the RPO, and single-zone redundancy does not provide disaster recovery.

Exam trap

The trap here is confusing high availability within a zone with disaster recovery, when only continuous replication to a separate location can meet a tight RPO.

111
MCQmedium

A company is designing a disaster recovery plan for its critical application. The application must be recovered within 4 hours (RTO) and can tolerate up to 1 hour of data loss (RPO). Which replication strategy is most cost-effective?

A.No replication; rely on backups restored from archive
B.Asynchronous replication
C.Synchronous replication
D.Daily snapshots with no replication
AnswerB

Asynchronous replication copies changes after acknowledgement, so a site can lag by up to an hour — matching the one-hour RPO — while costing far less than synchronous replication, which would need low-latency links to meet a near-zero RPO the business does not require.

Why this answer

Asynchronous replication meets the RPO of 1 hour (data loss up to 1 hour) and can be lower cost than synchronous replication, which requires high bandwidth. Synchronous replication would be more expensive and unnecessary. No replication would not meet RPO.

Daily backups would exceed RPO.

112
Multi-Selectmedium

A company is designing an auto-scaling solution for a stateless application. Which TWO features are essential for the application to scale horizontally without issues? (Select TWO.)

Select 2 answers
A.Stateless application design
B.Stateful session management
C.Use of local storage for application data
D.Vertical scaling on the existing instances
E.A load balancer to distribute traffic
AnswersA, E

Stateless application design ensures no session or local data persists on individual instances, so any instance can handle any request. This removes the need for sticky sessions or instance-specific state, directly enabling horizontal scaling and safe termination during scale-in events.

Why this answer

Horizontal scaling requires that the application is stateless, meaning no session data is stored locally on instances, so any instance can handle any request. A load balancer is essential to distribute incoming traffic across multiple instances, ensuring no single instance is overwhelmed and that requests can be sent to any available instance. In contrast, stateful session management (B) and local storage (C) would tie data to specific instances, preventing seamless scaling.

Vertical scaling (D) is about increasing resources of existing instances, not adding more instances horizontally.

113
MCQeasy

A cloud administrator needs to provide a shared file system that can be accessed by multiple Linux-based virtual machines in the same VPC. Which storage type should be used?

A.Object storage
B.Archive storage
C.Block storage
D.File storage
AnswerD

File storage provides a shared, POSIX-compliant file system mountable concurrently by multiple Linux instances within the same VPC, matching the requirement. Block storage attaches to a single instance, and object storage lacks native shared-mount semantics.

Why this answer

File storage provides a shared, hierarchical file system (e.g., NFS, SMB) that multiple Linux VMs in the same VPC can mount simultaneously, making it ideal for shared access. In AWS, this is Amazon EFS (Elastic File System), which supports concurrent NFS mounts across EC2 instances. Block and object storage do not natively provide a shared POSIX file system for multiple Linux hosts.

Exam trap

The trap is assuming block storage (EBS) can be shared like a file system, or that object storage (S3) is a drop-in shared file system — the exam expects recognition that 'shared file system across multiple Linux VMs' maps to file storage (EFS/NFS).

How to eliminate wrong answers

Option A is wrong because object storage (e.g., S3) uses a flat namespace with HTTP APIs and is not mountable as a standard POSIX file system across multiple Linux VMs without additional layers (e.g., s3fs), which is not the intended shared file system solution. Option B is wrong because archive storage (e.g., S3 Glacier) is for long-term, infrequent access with high retrieval latency, not shared active file access. Option C is wrong because block storage (e.g., EBS) attaches to a single EC2 instance (or cluster-aware setups) and does not natively provide a shared file system across multiple VMs.

114
Multi-Selectmedium

A cloud administrator is optimizing costs for a batch processing workload that runs nightly for 2 hours. The workload can tolerate interruptions. Which THREE purchasing options should the administrator consider? (Choose three.)

Select 3 answers
A.Preemptible VMs
B.Spot instances
C.Dedicated hosts
D.Reserved instances
E.On-demand instances
AnswersA, B, E

Preemptible VMs are cost-effective and can be interrupted, ideal for batch jobs.

Why this answer

Correct answer: Preemptible VMs, Spot instances, and On-demand instances. For a batch processing workload that runs nightly for only 2 hours and can tolerate interruptions, cost optimization favors using interruptible instances like Preemptible VMs (Google Cloud) or Spot instances (AWS/Azure) because they offer significant discounts and are suitable for fault-tolerant workloads. On-demand instances are also an option to consider when interruptible instances are not available or if the workload requires guaranteed capacity, though they are more expensive.

Reserved instances or dedicated hosts are not cost-effective for such short, periodic workloads because they require long-term commitments (1 or 3 years) and are designed for steady-state usage. Therefore, the three options to consider are Preemptible VMs, Spot instances, and On-demand instances.

115
MCQmedium

A financial services firm requires a cloud deployment that keeps sensitive customer data on-premises while bursting compute-intensive risk analysis workloads to a public cloud during peak times. Which deployment model best meets this requirement?

A.Hybrid cloud
B.Public cloud
C.Multi-cloud
D.Private cloud
AnswerA

Hybrid cloud keeps sensitive customer data on-premises under the firm's control while connecting to public cloud resources for peak risk-analysis bursts. This directly satisfies both constraints: data residency on-premises and elastic compute scaling during peak demand.

Why this answer

A hybrid cloud model combines on-premises infrastructure (private cloud) with public cloud services, allowing data and applications to be shared between them. This exactly matches the requirement to keep sensitive customer data on-premises while bursting compute-intensive workloads to a public cloud during peak times. Hybrid cloud provides the necessary integration, orchestration, and security controls to move workloads securely between environments.

Exam trap

The trap is confusing hybrid cloud with multi-cloud; candidates may pick multi-cloud because it sounds more flexible, but the requirement specifically mentions on-premises data and bursting to a public cloud, which is the definition of hybrid cloud.

How to eliminate wrong answers

Option B is wrong because a public cloud deployment would place all resources in a public cloud provider, which does not meet the requirement to keep sensitive data on-premises. Option C is wrong because multi-cloud involves using two or more public cloud providers, which does not address the need for on-premises data residency. Option D is wrong because a private cloud alone would not provide the elasticity to burst compute-intensive workloads to a public cloud during peak times.

116
MCQmedium

A cloud engineer is designing a VPC for a web application that requires a public subnet for a load balancer and a private subnet for application servers. The application servers must access the internet for software updates without being directly accessible from the internet. Which configuration should the engineer implement?

A.Create a NAT Gateway in the public subnet and update the private subnet's route table to point to the NAT Gateway.
B.Attach an Internet Gateway to the VPC and configure the private subnet's route table to point to the Internet Gateway.
C.Set up a VPN connection between the VPC and the on-premises data center and route all internet traffic through the VPN.
D.Assign Elastic IP addresses to the application servers and configure security groups to allow outbound traffic only.
AnswerA

A NAT Gateway allows instances in a private subnet to initiate outbound traffic to the internet while preventing inbound traffic from reaching them. Placing the NAT Gateway in a public subnet gives it internet access via the Internet Gateway. Updating the private subnet's route table to point to the NAT Gateway enables the application servers to download updates without being directly accessible.

Why this answer

A NAT Gateway in a public subnet allows private subnet instances to initiate outbound internet traffic while remaining inaccessible from the internet. The private subnet's route table must direct outbound traffic to the NAT Gateway. This is the standard AWS design pattern for enabling updates and patches for private instances without exposing them publicly.

Exam trap

The trap here is assuming that an Internet Gateway can be used directly by private subnet instances, but private instances lack public IPs and would require a NAT device for outbound internet access.

117
MCQmedium

A cloud architect is deploying a web application across multiple availability zones within a single region to achieve high availability. The application requires that if one availability zone fails, traffic should automatically be rerouted to the remaining zones without manual intervention. Which configuration is required?

A.Active-passive with a standby instance in a different region
B.Active-active across availability zones with a load balancer
C.Vertical scaling of instances in a single availability zone
D.Cold standby with daily backups
AnswerB

Active-active across availability zones with a load balancer satisfies the automatic failover constraint: the load balancer health-checks each zone's endpoints and reroutes traffic to surviving zones when one fails, with no manual intervention. Running identical instances in every zone also preserves capacity, unlike active-passive, which requires failover orchestration.

Why this answer

Deploying an active-active configuration across multiple availability zones with a load balancer ensures that traffic is automatically distributed to healthy instances. If one availability zone fails, the load balancer's health checks detect the failure and reroute traffic to the remaining zones without manual intervention, meeting the high availability requirement.

Exam trap

The trap here is that candidates often confuse high availability with disaster recovery, mistakenly choosing a cross-region active-passive setup (Option A) when the question explicitly specifies a single region and automatic rerouting.

How to eliminate wrong answers

Option A is wrong because active-passive with a standby instance in a different region introduces cross-region latency and requires manual or automated failover mechanisms, not automatic rerouting within a single region. Option C is wrong because vertical scaling in a single availability zone does not provide fault tolerance; if that zone fails, all instances become unavailable regardless of size. Option D is wrong because a cold standby with daily backups involves significant recovery time and manual steps to restore service, not automatic traffic rerouting.

118
MCQhard

A cloud engineer is designing a disaster recovery strategy for a critical application hosted on Azure. The application uses a SQL Database and must be able to fail over to a secondary region with minimal data loss. The Recovery Point Objective (RPO) is 5 minutes and the Recovery Time Objective (RTO) is 15 minutes. The engineer needs a solution that automatically replicates data and provides a connection endpoint that remains constant during failover. Which Azure feature should be implemented?

A.Azure SQL Database geo-restore
B.Azure SQL Database zone-redundant configuration
C.Azure SQL Database auto-failover groups
D.Azure SQL Database active geo-replication
AnswerC

Auto-failover groups provide a read-write listener endpoint that remains constant during failover, enabling automatic failover of one or more databases to a secondary region. They support automatic replication and can meet low RPO and RTO requirements by handling the failover process seamlessly.

Why this answer

Auto-failover groups provide automatic replication and a stable listener endpoint that enables seamless failover to a secondary region. This meets the low RPO and RTO requirements by automating the failover process and abstracting the underlying database changes from the application.

Exam trap

The trap here is confusing high availability features like zone redundancy with disaster recovery features that span regions, or assuming active geo-replication provides automatic failover without a listener endpoint.

119
Multi-Selectmedium

A company is selecting a cloud deployment model. They require the ability to keep sensitive data on-premises due to regulatory compliance, but want to leverage cloud resources for burst computing capacity. Which THREE characteristics describe this model?

Select 3 answers
A.Uses multiple public cloud providers
B.Resources are exclusively owned by one organization
C.Provides the ability to burst to the cloud for extra capacity
D.Uses a VPN or dedicated connection between on-premises and cloud
E.Data can remain on-premises for compliance
AnswersC, D, E

Bursting to the cloud directly satisfies the stem's requirement to leverage cloud resources for extra capacity while sensitive data stays on-premises. In a hybrid model, workloads scale out to public cloud during demand spikes, then return on-premises, preserving regulatory compliance without over-provisioning internal hardware.

Why this answer

Hybrid cloud connects on-premises with public cloud, enabling data residency and bursting.

120
MCQmedium

A company runs a stateful application that maintains session data in memory on the server. The application experiences performance issues during traffic spikes. Which design change would best improve scalability?

A.Increase the memory of each server (vertical scaling)
B.Implement sticky sessions on the load balancer
C.Move session state to a shared cache or database (stateless design)
D.Use a CDN to cache static content
AnswerC

In-memory session state binds each user to one server, preventing horizontal scaling. Moving sessions to a shared cache or database makes application instances stateless, so any instance can serve any request and additional replicas absorb traffic spikes.

Why this answer

Making the application stateless by moving session state to an external store (e.g., Redis or database) allows any instance to handle any request, enabling horizontal scaling.

121
MCQhard

A cloud engineer is designing a VPC in AWS for a three-tier web application. The web servers must be accessible from the internet, the application servers should only be accessible from the web servers, and the database servers should only be accessible from the application servers. What is the most secure VPC design?

A.Public subnet for web and application servers, private subnet for database servers
B.Single public subnet with all servers placed in it, using security groups to restrict traffic
C.Public subnet for web servers, private subnet for application servers, and a separate private subnet for database servers, with proper security group rules
D.Use a single private subnet and a NAT gateway for internet access
AnswerC

Separating web, application and database tiers into public and private subnets, then restricting traffic with security group rules referencing each tier, enforces the required access path. Only web servers are internet-facing, satisfying the constraint that application and database servers remain unreachable directly.

Why this answer

The most secure design places each tier in its own subnet with security groups that restrict traffic: web servers in a public subnet (internet-facing), application servers in a private subnet (only accessible from web servers), and database servers in a separate private subnet (only accessible from application servers). This segmentation limits lateral movement and follows the principle of least privilege.

Exam trap

CV0-004 often tests the misconception that security groups alone are sufficient without subnet segmentation, leading candidates to choose a single public subnet design.

How to eliminate wrong answers

Option A is wrong because placing application servers in a public subnet exposes them to the internet, violating the requirement that they should only be accessible from web servers. Option B is wrong because a single public subnet with all servers exposes all tiers to the internet, relying solely on security groups, which is less secure than network segmentation. Option D is wrong because a single private subnet with a NAT gateway does not allow inbound internet access to web servers, so the web tier would not be accessible from the internet.

122
MCQhard

A cloud engineer is designing a serverless application that processes messages from an Amazon SQS queue. The application must scale automatically based on the number of messages in the queue and must handle failures gracefully by retrying failed messages. Which AWS service should the engineer use to run the application code?

A.AWS Step Functions with a state machine
B.AWS Lambda with an SQS trigger
C.Amazon EC2 Auto Scaling group with a custom worker
D.AWS Fargate with an ECS service
AnswerB

AWS Lambda supports SQS as an event source. When configured, Lambda automatically polls the queue and invokes the function with batches of messages. It scales based on the number of messages, and failed invocations can be retried or sent to a dead-letter queue. This meets the requirements for automatic scaling and graceful failure handling.

Why this answer

AWS Lambda with an SQS trigger is the most suitable because it natively integrates with SQS, automatically scales based on the number of messages, and provides built-in retry and dead-letter queue support. Other options require manual scaling configuration or additional components to achieve the same level of integration and simplicity.

Exam trap

The trap here is assuming that any compute service can easily integrate with SQS; only Lambda has native SQS event source mapping that handles scaling and retries automatically.

123
Multi-Selectmedium

A cloud architect is designing a highly available architecture on AWS for a web application that must survive the failure of an entire Availability Zone. The application uses an Application Load Balancer, web servers, and an Amazon RDS database. Which TWO design actions should the architect take? (Choose two.)

Select 2 answers
A.Configure the Application Load Balancer to route traffic only to a single Availability Zone to reduce latency.
B.Deploy the web servers in an Auto Scaling group that spans at least two Availability Zones.
C.Enable a Multi-AZ deployment for the Amazon RDS database.
D.Place the RDS database in a single Availability Zone and rely on automated backups for failover.
E.Use Amazon S3 to store the database files and point the application to the S3 bucket.
AnswersB, C

An Auto Scaling group spanning multiple Availability Zones ensures that if one AZ fails, instances in the remaining AZ continue to serve traffic. The Auto Scaling group can also replace failed instances automatically. This provides compute-layer high availability and is a fundamental design practice for surviving AZ failures.

Why this answer

To survive an Availability Zone failure, the web tier must be distributed across multiple AZs using an Auto Scaling group, and the database tier must use a Multi-AZ deployment for automatic failover. These two actions together provide high availability for both compute and data layers.

Exam trap

The trap here is believing that automated backups provide high availability; backups are for recovery, not for automatic failover during an AZ outage.

124
Multi-Selecthard

A cloud engineer is optimizing costs for a data analytics workload that runs periodically. The workload processes large datasets stored in Amazon S3 and runs on EC2 instances. Which THREE strategies should the engineer consider to reduce costs? (Select THREE.)

Select 3 answers
A.Implement S3 Lifecycle policies to transition older data to S3 Glacier
B.Provision large instances to reduce processing time
C.Choose the correct instance type based on resource requirements
D.Use Spot Instances for the compute nodes
E.Use on-demand instances exclusively
AnswersA, C, D

S3 Lifecycle policies automatically transition infrequently accessed datasets to Glacier, whose storage pricing is far lower than S3 Standard. This satisfies the cost-reduction goal for large, ageing analytics data without altering the EC2 compute tier.

Why this answer

Option A is correct because S3 Lifecycle policies can automatically transition aging analytics data to lower-cost storage classes such as S3 Glacier, cutting storage costs for data that is no longer frequently accessed. Option C is correct because right-sizing the EC2 instance type to the workload's actual CPU, memory, and I/O needs avoids paying for over-provisioned capacity. Option D is correct because Spot Instances offer steep discounts (up to ~90% off On-Demand) and are well suited to periodic, interruption-tolerant batch analytics jobs.

Option B is wrong because simply provisioning larger instances increases hourly cost and does not guarantee proportional time savings. Option E is wrong because On-Demand pricing is the most expensive compute option and provides no cost optimization for a periodic workload.

Exam trap

CV0-004 often tests the misconception that bigger instances always reduce cost by finishing faster, when right-sizing plus Spot and lifecycle tiering is the actual cost lever.

125
Multi-Selectmedium

A company is designing a hybrid cloud architecture. They need to ensure high availability for a critical application. Which TWO of the following are best practices for achieving high availability in a hybrid cloud environment?

Select 2 answers
A.Rely solely on on-premises infrastructure with cloud as a backup
B.Implement an active-active architecture across on-premises and cloud
C.Use a single load balancer to route all traffic
D.Use multiple availability zones within a cloud region
E.Deploy the application in a single availability zone to reduce complexity
AnswersB, D

Active-active deployment runs workloads simultaneously in both on-premises and cloud, so traffic fails over instantly when one site degrades. This directly satisfies the stem's high-availability requirement for a critical application, unlike active-passive designs that incur downtime during failover. Distributing load across both environments also removes the single point of failure inherent in a single-site deployment.

Why this answer

Using multiple availability zones within a region protects against data center failure. An active-active architecture ensures both on-premises and cloud are handling traffic, providing redundancy. Deploying in a single zone creates a single point of failure.

Using only on-premises does not leverage cloud for HA. A single load balancer is a SPOF.

126
MCQhard

A company uses AWS and Azure to run identical workloads for redundancy. They want to simplify management by using a single set of tools across both clouds. Which architectural approach should they consider?

A.Use each provider's native management tools
B.Single cloud migration to one provider
C.Multi-cloud using a cloud-agnostic orchestration tool
D.Hybrid cloud using VPN between AWS and Azure
AnswerC

A cloud-agnostic orchestration tool such as Terraform or Kubernetes abstracts provider-specific APIs, letting one toolset manage AWS and Azure workloads. This directly satisfies the requirement to simplify management across both clouds while preserving the redundancy architecture.

Why this answer

Multi-cloud with a cloud-agnostic abstraction layer (e.g., using Terraform or Kubernetes) allows managing resources across providers with a unified toolset.

127
MCQeasy

Which cloud deployment model involves connecting an on-premises data center to a public cloud provider using a VPN or dedicated connection?

A.Private cloud
B.Multi-cloud
C.Hybrid cloud
D.Public cloud
AnswerC

A hybrid cloud specifically joins on-premises infrastructure to a public cloud, typically via VPN or dedicated private link. This satisfies the stem's requirement for that on-premises-to-public-cloud connectivity, distinguishing it from purely public, private or community models.

Why this answer

A hybrid cloud is defined by the integration of on-premises infrastructure (private cloud) with a public cloud provider, typically via a secure network connection such as a VPN or dedicated link (e.g., AWS Direct Connect, Azure ExpressRoute). This model allows workloads and data to move between environments, enabling burst capacity, disaster recovery, and gradual migration. The key differentiator is the interconnection between private and public resources, which is exactly what the question describes.

Exam trap

CV0-004 often tests the confusion between hybrid cloud and multi-cloud, where candidates mistakenly select multi-cloud when on-premises integration is mentioned, or assume any public cloud use is hybrid.

How to eliminate wrong answers

Option A is wrong because a private cloud is dedicated solely to one organization and does not inherently include a public cloud connection; it may be on-premises or hosted, but remains isolated. Option B is wrong because multi-cloud refers to using two or more public cloud providers (e.g., AWS and Azure) without necessarily involving on-premises infrastructure; it does not require a VPN or dedicated link to a private data center. Option D is wrong because a public cloud is a shared, multi-tenant environment offered over the internet; it does not include on-premises integration by definition.

128
MCQeasy

A company runs a customer-facing web application on Azure virtual machines. During a regional outage, the operations team needs to bring up the same environment in a secondary Azure region. The team wants an automated, repeatable deployment that includes virtual networks, load balancers, and VM configurations. Which Azure capability should the team use to meet this goal?

A.Azure Resource Manager templates (ARM templates)
B.Azure Cost Management budgets
C.Azure Monitor alert rules
D.Azure Advisor recommendations
AnswerA

ARM templates describe the desired infrastructure declaratively, so the same template can be redeployed to a secondary region to recreate virtual networks, load balancers, and VMs consistently. This provides the automated, repeatable regional deployment the team needs and supports parameterization for region-specific values, making it the appropriate choice for this recovery scenario.

Why this answer

Because the requirement is automated, repeatable deployment of a full resource set into another region, an infrastructure-as-code mechanism is required. ARM templates express the environment declaratively and can be redeployed with region parameters, whereas the other services provide monitoring, recommendations, or cost governance and cannot provision the environment.

Exam trap

The trap here is confusing Azure services that observe or advise on resources with services that actually deploy them.

129
Multi-Selecthard

A cloud architect is designing a disaster recovery strategy for a mission-critical application hosted in a single cloud region. The business requires that the application survive the loss of an entire region and that failover be largely automated with minimal data loss. The budget permits a warm standby environment. Which TWO design elements should the architect include to meet these requirements? (Choose two.)

Select 2 answers
A.Rely on manual runbooks to rebuild the environment after a regional outage is detected.
B.Deploy a warm standby environment in a second region that can be scaled up on failover.
C.Store nightly database backups exclusively in the primary region's object storage.
D.Configure the application to use a single availability zone within the primary region for lowest latency.
E.Replicate application data and configurations to a second region continuously.
AnswersB, E

A warm standby runs a reduced but functional copy of the application in another region, so failover does not require building infrastructure from scratch. It can be scaled to full capacity when the primary region fails, meeting the automated, low-downtime requirement while respecting the budget that rules out a fully active-active deployment. This directly addresses surviving a regional outage.

Why this answer

Surviving a full regional outage with minimal data loss requires both a copy of the data and configuration outside the failed region and a second-region environment ready to take over. Continuous cross-region replication minimizes the recovery point objective, while a warm standby that scales up on failover provides a rapid, largely automated recovery path within the stated budget.

Exam trap

The trap here is assuming that in-region redundancy such as multiple availability zones protects against the loss of an entire region.

130
MCQmedium

A company runs a production application on multiple cloud regions for high availability. They want to minimize latency for global users. Which DNS routing policy should they use?

A.Latency routing
B.Failover routing
C.Geolocation routing
D.Simple routing
AnswerA

Latency routing directs each user to the region responding fastest, measured by actual network round-trip time. This satisfies the minimise-latency constraint for global users, unlike failover or weighted policies which prioritise availability or distribution rather than per-user responsiveness.

Why this answer

Latency routing in DNS directs users to the region with the lowest network latency, which is ideal for minimizing latency for global users. It uses latency measurements between the user's resolver and the various regional endpoints to select the best-performing region. This is distinct from geolocation routing, which routes based on the user's geographic location rather than actual network performance.

Exam trap

CV0-004 often tests the confusion between latency routing and geolocation routing — candidates assume that routing based on geography always minimizes latency, but latency routing uses actual network measurements and can route a user to a different region than their geographic location.

How to eliminate wrong answers

Option B is wrong because failover routing is designed for disaster recovery — it routes to a primary endpoint and only switches to a secondary when the primary fails, not for latency optimization. Option C is wrong because geolocation routing directs users based on their geographic location (e.g., country or continent), which does not always correlate with the lowest latency — a user in a border region might be closer to a different region. Option D is wrong because simple routing returns a single record with no intelligence about latency, failover, or geography.

131
MCQeasy

A company wants to migrate its on-premises workloads to the cloud while maintaining the ability to run some sensitive applications on-premises. Which cloud deployment model best meets this requirement?

A.Hybrid cloud
B.Multi-cloud
C.Private cloud
D.Public cloud
AnswerA

Hybrid cloud combines on-premises infrastructure with public cloud services, letting sensitive applications remain on local hardware while other workloads migrate. This directly satisfies the stem's dual requirement: cloud migration plus on-premises retention, which neither public nor private cloud alone can deliver.

Why this answer

A hybrid cloud deployment combines on-premises infrastructure with public cloud services, allowing workloads to run in both environments with connectivity between them. This directly matches the requirement to migrate some workloads to the cloud while keeping sensitive applications on-premises. Hybrid cloud is the canonical model for this split-workload scenario.

Exam trap

The trap is confusing hybrid with multi-cloud — candidates see 'multiple environments' and pick multi-cloud, but multi-cloud specifically means multiple public providers, not on-prem plus public.

How to eliminate wrong answers

Option B is wrong because multi-cloud means using two or more public cloud providers (e.g., AWS + Azure) — it says nothing about keeping workloads on-premises. Option C is wrong because a private cloud is dedicated infrastructure (on-prem or hosted) for a single organization, which excludes the public cloud migration the company wants. Option D is wrong because a public cloud model puts everything in a shared provider environment, contradicting the requirement to keep sensitive apps on-premises.

132
Multi-Selectmedium

A cloud administrator is deploying a new three-tier application on Google Cloud. The web tier must be accessible from the internet, the application tier must only accept traffic from the web tier, and the database tier must only accept traffic from the application tier. The administrator needs to implement network security controls to enforce these requirements. Which two Google Cloud features should be used? (Choose two.)

Select 2 answers
A.Hierarchical firewall policies
B.Cloud Armor security policies
C.VPC Service Controls
D.Network tags on instances
E.VPC firewall rules
AnswersD, E

Network tags are used in conjunction with VPC firewall rules to identify source or target instances. By tagging instances in each tier, you can create firewall rules that allow traffic only from specific tags, enabling granular control over which tiers can communicate, thus enforcing the desired segmentation.

Why this answer

VPC firewall rules and network tags work together to enforce tiered network segmentation. Firewall rules define allowed traffic based on tags, and network tags identify instances belonging to each tier. This combination ensures that only the intended traffic flows between tiers, meeting the security requirements.

Exam trap

The trap here is assuming that Cloud Armor or VPC Service Controls can enforce internal tier-to-tier traffic restrictions, when they are designed for edge protection and service perimeters, respectively.

133
MCQhard

A company needs to connect its on-premises data center to a public cloud provider with a dedicated, consistent network connection that bypasses the internet. Which connectivity method should be used?

A.VPC peering
B.Internet gateway
C.Site-to-Site VPN
D.Direct Connect or ExpressRoute
AnswerD

Direct Connect (AWS) and ExpressRoute (Azure) provision private, dedicated circuits from an on-premises data centre to the provider's edge, bypassing the public internet entirely. This satisfies the requirement for a consistent, dedicated connection rather than an IPsec VPN tunnel over internet links.

Why this answer

Direct Connect (AWS) and ExpressRoute (Azure) are dedicated private network connections from on-premises infrastructure to a cloud provider that bypass the public internet entirely. They provide consistent latency, higher bandwidth, and more predictable performance than internet-based options, which is exactly what the scenario requires.

Exam trap

The trap is assuming that because a Site-to-Site VPN is encrypted it must be the 'secure dedicated' answer — but VPNs still traverse the public internet, so they fail the 'bypasses the internet' and 'consistent' criteria.

How to eliminate wrong answers

Option A is wrong because VPC peering connects two virtual private clouds (VPCs) to each other — it does not connect an on-premises data center to a cloud provider and does not provide a dedicated physical link. Option B is wrong because an internet gateway is the component that enables VPC resources to communicate with the public internet — it is the opposite of bypassing the internet. Option C is wrong because a Site-to-Site VPN traverses the public internet (encrypted via IPsec), so it does not provide the dedicated, consistent path the scenario demands, even though it is encrypted.

← PreviousPage 2 of 2 · 133 questions total

Ready to test yourself?

Try a timed practice session using only Cloud Architecture and Design questions.