Courseiva

CCNA Operations and Support Questions

75 of 155 questions · Page 2/3 · Operations and Support · Answers revealed

76
MCQeasy

A cloud administrator needs to give the security team read-only visibility into all API activity across an AWS account, including who made each call, when, and from which IP address. The records must be retained for 365 days for compliance. Which service should the administrator use?

A.Amazon CloudWatch Logs
B.AWS Trusted Advisor
C.AWS Config
D.AWS CloudTrail
AnswerD

CloudTrail records API activity in an account, capturing the identity of the caller, the time, the source IP, and the request details. Creating a trail that delivers events to an S3 bucket with a 365-day lifecycle or retention policy satisfies the compliance requirement for long-term audit visibility.

Why this answer

CloudTrail is the service purpose-built to record API activity in an AWS account, including caller identity, timestamp, and source address. Delivering those events to durable storage with a retention policy of 365 days meets both the visibility and compliance needs described.

Exam trap

The trap here is confusing configuration-change tracking or log aggregation with full API audit logging.

77
MCQeasy

A company wants to centralize logs from multiple AWS services and analyze them using SQL-like queries. Which service should they use?

A.AWS CloudTrail
B.Amazon S3
C.Amazon CloudWatch Logs Insights
D.AWS Config
AnswerC

CloudWatch Logs Insights runs SQL-like queries against log groups aggregated from multiple AWS services, returning results without exporting data elsewhere. This satisfies the centralised collection and query requirement directly, since logs remain in CloudWatch and are analysed in place rather than piped to Athena or OpenSearch.

Why this answer

Amazon CloudWatch Logs Insights provides an interactive query language that supports SQL-like commands (fields, filter, stats, sort, limit, parse) to analyze log data stored in CloudWatch Logs. It can query across multiple log groups from different AWS services, making it the right choice for centralized log analysis with SQL-like queries.

Exam trap

CV0-004 often tests the difference between log storage/collection services and log analytics services — candidates pick S3 or CloudTrail for querying, not realizing that SQL-like analysis requires CloudWatch Logs Insights (or Athena on S3).

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and delivers it to S3 or CloudWatch Logs, but it does not provide a SQL-like query engine for analyzing logs. Option B is wrong because Amazon S3 is object storage — it can store logs but does not natively offer SQL-like querying (Athena would be needed on top of S3). Option D is wrong because AWS Config evaluates resource configuration compliance and records configuration changes; it is not a log analytics engine and does not support SQL-like queries over arbitrary logs.

78
MCQeasy

A cloud administrator needs to ensure that log data is retained for one year to meet compliance requirements. Which action should be taken for the log group in CloudWatch Logs?

A.Set the log group's retention policy to 365 days
B.Create a CloudWatch Events rule to delete logs after one year
C.Increase the log group's data durability by enabling encryption
D.Export logs to Amazon S3 and delete the log group
AnswerA

Setting the log group's retention policy to 365 days directly satisfies the one-year compliance requirement, since CloudWatch Logs deletes events automatically once the configured retention period elapses. Configuring this at the log group level applies uniformly to every log stream within it, avoiding per-stream management and preventing indefinite storage costs.

Why this answer

CloudWatch Logs log groups have a retention setting that controls how long log events are kept before automatic deletion. Setting the retention policy to 365 days ensures logs are retained for exactly one year, meeting the compliance requirement without manual intervention.

Exam trap

CV0-004 often tests whether candidates know that retention is a native log group setting — candidates pick workarounds like EventBridge deletion rules or S3 export, missing the simple built-in retention policy configuration.

How to eliminate wrong answers

Option B is wrong because CloudWatch Events (now EventBridge) rules trigger actions based on events or schedules, but using a rule to delete logs after one year is an indirect, error-prone approach — the native retention setting already handles this. Option C is wrong because enabling encryption increases data durability and security but does not affect retention duration; encryption and retention are independent settings. Option D is wrong because exporting logs to S3 and deleting the log group removes the logs from CloudWatch and requires managing retention in S3 separately — it does not set retention on the log group as the question asks.

79
MCQeasy

A cloud administrator manages workloads in Microsoft Azure. The security team requires that all virtual machines apply operating system updates automatically during a defined window without the administrator logging in to each machine. Which Azure feature should the administrator use to meet this requirement?

A.Microsoft Defender for Cloud, with the regulatory compliance dashboard enabled for the subscription.
B.Azure Update Manager, with a maintenance configuration that schedules update assessments and installations on the target virtual machines.
C.Azure Policy, with a built-in initiative that audits whether the Guest Configuration extension is installed.
D.Azure Automation State Configuration, with a DSC configuration that declares the Windows Update service as running.
AnswerB

Azure Update Manager provides agentless assessment and scheduled patching for Azure and Arc-enabled machines. By assigning a maintenance configuration, the administrator defines the recurrence and maintenance window, and the service installs approved updates automatically, satisfying the requirement without interactive logon to each VM.

Why this answer

Azure Update Manager is the service purpose-built for assessing and installing operating system updates on Azure virtual machines and Arc-connected servers. A maintenance configuration defines the schedule and window, and the service performs assessment and installation automatically, which is exactly what the security team requires without per-machine administrator logon.

Exam trap

The trap here is confusing posture assessment or configuration enforcement services, which only report or enforce settings, with the service that actually schedules and installs operating system updates.

80
MCQmedium

A cloud operations team manages a fleet of Amazon EC2 instances behind an Application Load Balancer. During a recent incident, several instances stopped passing their ELB health checks but the Auto Scaling group did not replace them. The team wants the Auto Scaling group to automatically terminate and replace instances that fail ELB health checks, not just EC2 status checks. Which action should the team take?

A.Increase the health check grace period on the Auto Scaling group.
B.Configure a lifecycle hook to terminate instances that fail health checks.
C.Lower the unhealthy threshold on the target group health check.
D.Enable ELB health checks as an additional health check type on the Auto Scaling group.
AnswerD

By default an Auto Scaling group only uses EC2 status checks, so an instance that is running but failing the load balancer health check stays in service. Adding ELB as a health check type makes the group treat unhealthy ELB targets as unhealthy instances and replace them, which is exactly the behavior the team needs.

Why this answer

Auto Scaling groups by default rely only on EC2 status checks, which do not detect application-level failures seen by the load balancer. Adding ELB as a health check type lets the group treat targets failing the load balancer check as unhealthy and replace them automatically, restoring capacity without manual intervention.

Exam trap

The trap here is assuming that configuring the load balancer health check alone causes the Auto Scaling group to replace unhealthy instances.

81
Multi-Selectmedium

A cloud administrator is investigating a sudden increase in cost for a production environment. The administrator wants to identify the sources of the cost increase and implement a tagging strategy for cost allocation. Which TWO actions should the administrator take? (Choose two.)

Select 2 answers
A.Implement a rightsizing recommendation report.
B.Use the cloud provider's cost explorer to analyze cost drivers.
C.Enable detailed billing reports with resource tags.
D.Purchase Reserved Instances for all resources.
E.Create a budget alert for the total monthly cost.
AnswersB, C

The cloud provider's cost explorer aggregates spend by service, region and account, revealing which resources drive the sudden increase. This satisfies the investigation requirement, providing the cost-driver visibility needed before tags can be applied for allocation.

Why this answer

Option B is correct because the cloud provider's cost explorer (e.g., AWS Cost Explorer or Azure Cost Management) lets the administrator visualize and filter spending by service, account, region, and tag, which directly identifies the sources of the sudden cost increase. Option C is correct because enabling detailed billing reports (such as AWS Cost and Usage Report or Azure detailed usage data) with resource tags activated provides granular, per-resource cost and usage data that is required to build and validate a tag-based cost allocation strategy. Option A is not correct because a rightsizing recommendation report only suggests instance size or type changes and does not analyze cost drivers or enable tag-based allocation.

Option D is not correct because purchasing Reserved Instances for all resources is a commitment-based discount action, not an investigation or tagging strategy, and could increase risk if usage changes. Option E is not correct because a budget alert only notifies when total monthly cost crosses a threshold; it does not identify cost sources or implement tagging for allocation.

Exam trap

CV0-004 often tests the confusion between cost analysis tools (cost explorer, detailed billing) and cost optimization actions (rightsizing, reserved instances); candidates must select actions that directly address identification and tagging.

82
MCQeasy

A company wants to be notified when their monthly AWS spending exceeds $10,000. Which AWS service should they use to set up this alert?

A.AWS Trusted Advisor
B.AWS Budgets
C.AWS Cost Explorer
D.AWS CloudWatch Alarms
AnswerB

AWS Budgets lets you define a monthly cost budget with a threshold and configure alerts when actual or forecast spend exceeds it. This directly satisfies the $10,000 notification requirement, whereas CloudWatch alarms track metrics rather than billing amounts.

Why this answer

AWS Budgets allows you to set custom cost budgets and configure alerts when actual or forecasted spending exceeds a defined threshold, such as $10,000 per month. It sends notifications via email or SNS when the threshold is breached, directly satisfying the requirement to be notified about monthly spending exceeding a specific amount.

Exam trap

CV0-004 often tests the difference between cost visibility tools and cost alerting tools — candidates pick Cost Explorer or Trusted Advisor for notifications, when only AWS Budgets is designed to alert on spending thresholds.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides recommendations on cost optimization, security, and performance but does not send threshold-based spending alerts for a specific dollar amount. Option C is wrong because AWS Cost Explorer visualizes and analyzes historical cost and usage data but does not natively send alerts when spending exceeds a threshold. Option D is wrong because CloudWatch Alarms monitor metrics, and while the AWS/Billing metric EstimatedCharges exists in us-east-1, it is a less direct and less flexible mechanism than AWS Budgets for setting a $10,000 monthly spending alert.

83
MCQhard

A cloud administrator notices that an auto-scaling group is frequently adding and removing instances due to brief spikes in CPU usage. What should be adjusted to stabilize the scaling activity?

A.Increase the cooldown period
B.Increase the maximum instance count
C.Decrease the minimum instance count
D.Decrease the cooldown period
AnswerA

The cooldown period enforces a waiting interval after each scaling activity before another can begin. Extending it prevents the auto-scaling group from reacting to brief CPU spikes, stabilising instance additions and removals as the stem requires.

Why this answer

Increasing the cooldown period prevents the auto-scaling group from launching or terminating additional instances immediately after a scaling activity, which smooths out reactions to brief CPU spikes. A longer cooldown gives metrics time to stabilize before another scaling decision is made, reducing thrashing. This directly addresses the frequent add/remove behavior described.

Exam trap

CV0-004 often tests whether candidates confuse cooldown with capacity limits — increasing max size or decreasing min size changes the bounds, but only the cooldown period controls how quickly the group reacts to metric fluctuations.

How to eliminate wrong answers

Option B is wrong because increasing the maximum instance count only raises the ceiling — it does not stop the group from rapidly scaling in and out in response to short spikes. Option C is wrong because decreasing the minimum instance count lowers the floor and can actually make the group less stable, not more. Option D is wrong because decreasing the cooldown period makes the group react faster and more aggressively, worsening the thrashing.

84
MCQmedium

A cloud engineer is setting up automated patching for Linux instances in AWS. They need to define a maintenance window during which patches are applied. Which service should they use?

A.AWS Config
B.AWS OpsWorks
C.AWS Systems Manager Patch Manager
D.Amazon Inspector
AnswerC

AWS Systems Manager Patch Manager defines patch baselines and maintenance windows, then applies patches to Linux instances via the SSM Agent during those windows. It satisfies the stem's requirement for scheduled automated patching, unlike services lacking native patch orchestration or Linux package support.

Why this answer

AWS Systems Manager Patch Manager is specifically designed to automate the process of patching managed nodes, including defining maintenance windows during which patches are applied. It allows you to create patch baselines, specify approved patches, and schedule patching within a maintenance window. This meets the requirement of automated patching with a defined maintenance window.

Exam trap

CV0-004 often tests the confusion between vulnerability scanning (Amazon Inspector) and patch management (Systems Manager Patch Manager), or between configuration management (OpsWorks) and patching.

How to eliminate wrong answers

Option A is wrong because AWS Config is a service for assessing, auditing, and evaluating configurations, not for applying patches. Option B is wrong because AWS OpsWorks is a configuration management service that uses Chef and Puppet, but it is not the primary service for automated patching; Patch Manager is more direct and integrated. Option D is wrong because Amazon Inspector is a vulnerability management service that scans for vulnerabilities but does not apply patches.

85
MCQhard

A cloud engineer is troubleshooting a Microsoft Azure virtual machine that becomes unresponsive under sustained load. The engineer suspects a storage performance bottleneck but needs to confirm whether the issue is IOPS throttling or throughput throttling on the managed disk. Which Azure Monitor metrics should the engineer examine to distinguish between these two causes?

A.Disk IOPS Consumed Percentage and Disk Bandwidth Consumed Percentage
B.Disk Latency and Disk Transactions per second from Azure Monitor
C.OS Disk Queue Depth and OS Disk Read Operations/sec from the guest OS
D.VM CPU Credits Remaining and VM Network In Total
AnswerA

These two platform metrics express consumed IOPS and consumed bandwidth as percentages of the disk's provisioned limits. If IOPS Consumed Percentage approaches 100 while bandwidth remains low, the disk is IOPS-throttled; if bandwidth percentage saturates first, it is throughput-throttled. This directly distinguishes the two causes described.

Why this answer

Azure Monitor exposes Disk IOPS Consumed Percentage and Disk Bandwidth Consumed Percentage as platform metrics for managed disks. Comparing which percentage approaches saturation reveals whether the workload is being limited by the provisioned IOPS ceiling or the throughput ceiling, which is the exact distinction the engineer needs.

Exam trap

The trap here is relying on guest OS queue depth to identify throttling, when only platform consumption percentages reveal which provisioned limit is actually being reached.

86
MCQmedium

A cloud administrator notices that an Auto Scaling group is launching and terminating instances too frequently, causing instability. What should the administrator adjust to reduce this flapping behavior?

A.Disable the cooldown period
B.Decrease the cooldown period
C.Increase the scale-out threshold
D.Increase the cooldown period
AnswerD

The cooldown period prevents the Auto Scaling group from launching or terminating additional instances immediately after a scaling activity, damping rapid oscillation. Increasing it forces the group to wait longer between actions, directly reducing the flapping instability described.

Why this answer

Increasing the cooldown period gives instances time to stabilize before additional scaling actions, reducing flapping.

87
MCQhard

A company uses GCP and wants to ensure that log entries from Compute Engine instances are automatically exported to BigQuery for analysis. The logs must include structured JSON data. Which GCP service should be configured to route logs?

A.Cloud Audit Logs
B.Cloud Functions
C.Cloud Monitoring
D.Cloud Logging using sinks
AnswerD

Sinks define inclusion filters and a destination, letting Cloud Logging route matching entries to a BigQuery dataset. This satisfies the requirement to automatically export Compute Engine logs while preserving their structured JSON payloads for analysis.

Why this answer

Cloud Logging can route logs to BigQuery using sinks. It accepts structured logs in JSON format.

88
MCQmedium

A cloud operations team runs a Kubernetes cluster on Google Kubernetes Engine (GKE). They need to ensure that a critical payment microservice is automatically restarted if its container process fails, and that a new Pod is created if the node hosting it becomes unhealthy. Which Kubernetes object should they configure to meet these requirements?

A.A standalone Pod
B.A DaemonSet
C.A Deployment with a ReplicaSet
D.A CronJob
AnswerC

A Deployment manages a ReplicaSet, which ensures the desired number of Pod replicas are running. If a container process fails, the kubelet restarts it according to the Pod's restartPolicy (default Always). If a node becomes unhealthy, the ReplicaSet controller creates replacement Pods on healthy nodes. This directly satisfies both automatic container restart and Pod rescheduling requirements for the payment microservice.

Why this answer

A Deployment with a ReplicaSet is the correct Kubernetes controller for stateless, long-running microservices. The ReplicaSet ensures the desired number of Pod replicas are running, and the kubelet restarts failed containers. If a node becomes unhealthy, the ReplicaSet controller creates replacement Pods on healthy nodes.

This provides both container-level and node-level self-healing, which the payment microservice requires.

Exam trap

The trap here is assuming that a standalone Pod or DaemonSet provides the same self-healing and rescheduling guarantees as a Deployment-managed ReplicaSet.

89
MCQhard

A cloud engineer is troubleshooting a performance issue in a multi-tier application on AWS. The web tier shows high latency, but the application logs indicate no errors. The engineer wants to trace a request end-to-end across services. Which AWS service should be used?

A.VPC Flow Logs
B.Amazon CloudWatch Logs
C.AWS CloudTrail
D.AWS X-Ray
AnswerD

AWS X-Ray traces requests across distributed services, building a service map that pinpoints latency between tiers. Since logs show no errors, the bottleneck is performance rather than failure, and X-Ray's segment and subsegment timing exposes exactly where the web tier's downstream calls stall.

Why this answer

AWS X-Ray provides distributed tracing, allowing you to trace requests as they travel through your application and identify performance bottlenecks.

90
MCQmedium

A cloud administrator notices that an application's latency has increased. The application is distributed across multiple microservices. Which tool can help trace requests across services to identify the bottleneck?

A.Centralized logging service
B.Vulnerability assessment tool
C.Distributed tracing tool
D.Audit logging service
AnswerC

Distributed tracing propagates a shared trace context across service boundaries, letting the administrator visualise each span's duration and pinpoint the microservice causing increased latency. Unlike metrics or logs, which show isolated per-service data, it reconstructs the full request path, directly satisfying the requirement to trace requests across distributed microservices.

Why this answer

A distributed tracing tool is designed to follow a single request as it propagates through multiple microservices, capturing spans, timing, and parent-child relationships. This lets the administrator pinpoint which service or call in the chain is adding latency. Centralized logging aggregates logs but does not natively reconstruct cross-service request paths with timing.

Exam trap

CV0-004 often tests the confusion between logging and tracing, so candidates pick centralized logging when the scenario explicitly requires following a request across services.

How to eliminate wrong answers

Option A is wrong because centralized logging collects and indexes log events but does not correlate a single request's journey across services with timing breakdowns. Option B is wrong because a vulnerability assessment tool scans for security weaknesses, not performance bottlenecks. Option D is wrong because audit logging records security-relevant events for compliance, not request latency across microservices.

91
MCQmedium

A company uses Azure and wants to set up an alert that triggers when the average CPU of a virtual machine exceeds 90% for the past 15 minutes. The alert should send an email to the operations team. Which Azure resources are needed?

A.Azure Log Analytics and Logic App
B.Azure Monitor metric alert and action group with email
C.Azure Advisor recommendation
D.Azure Service Health alert
AnswerB

Azure Monitor metric alerts evaluate platform metrics such as Percentage CPU against a threshold over a defined aggregation window, satisfying the 15-minute average above 90% condition. The action group then delivers the email notification to the operations team, fulfilling the alerting requirement without needing Log Analytics queries.

Why this answer

Azure Monitor metric alerts evaluate metrics like CPU percentage against thresholds, and action groups define the notification channels (e.g., email). To alert when average CPU exceeds 90% for 15 minutes, you create a metric alert rule with a 15-minute aggregation window and attach an action group configured to send email to the operations team. This is the native, minimal-resource approach.

Exam trap

The trap is overcomplicating the solution by choosing Log Analytics or Logic Apps, when a simple metric alert with an action group is sufficient and is the intended answer.

How to eliminate wrong answers

Option A is wrong because Log Analytics and Logic Apps are not required for simple metric alerts; they add unnecessary complexity and cost. Option C is wrong because Azure Advisor provides recommendations, not real-time alerting on metrics. Option D is wrong because Azure Service Health alerts are for platform-wide service issues, not VM-level performance metrics.

92
MCQmedium

A company wants to reduce costs by identifying underutilized EC2 instances. Which tool should they use to get rightsizing recommendations?

A.AWS Cost Explorer
B.AWS Trusted Advisor
C.AWS Compute Optimizer
D.AWS Budgets
AnswerC

AWS Compute Optimizer analyses CloudWatch metrics to generate rightsizing recommendations for EC2 instances, identifying over-provisioned or underutilised capacity. This directly satisfies the company's cost-reduction goal by surfacing specific instance-type downsizing opportunities, unlike tools that only report utilisation data without actionable sizing guidance.

Why this answer

AWS Compute Optimizer is specifically designed to analyze resource utilization and provide rightsizing recommendations for EC2 instances, among other resources. It uses machine learning to identify underutilized instances and suggests optimal instance types, helping reduce costs.

Exam trap

CV0-004 often tests the confusion between cost management tools like Cost Explorer and rightsizing tools like Compute Optimizer; candidates may think Cost Explorer provides rightsizing, but it only shows costs.

How to eliminate wrong answers

Option A is wrong because AWS Cost Explorer is for visualizing and managing costs, but it does not provide rightsizing recommendations. Option B is wrong because AWS Trusted Advisor offers best practice checks, including cost optimization, but its rightsizing recommendations are limited and not as comprehensive as Compute Optimizer. Option D is wrong because AWS Budgets is for setting custom cost and usage budgets and alerts, not for rightsizing.

93
MCQmedium

A cloud administrator needs to apply security patches to a group of Windows servers during a maintenance window to minimize disruption. Which type of service should be used?

A.Vulnerability assessment service
B.Configuration compliance service
C.Configuration management and automation service
D.Patch automation service with maintenance window scheduling
AnswerD

A patch automation service inventories missing OS patches and applies them to tagged Windows servers only within the defined maintenance window, preventing disruption outside approved hours. This satisfies the requirement to patch a server group while minimising disruption, unlike manual patching or always-on update schedules.

Why this answer

The administrator needs to apply security patches to a group of Windows servers during a specific maintenance window to minimize disruption. A patch automation service with maintenance window scheduling is designed exactly for this purpose: it automates the deployment of patches and allows scheduling within defined windows, ensuring updates occur only during approved times. This directly addresses the requirement to apply patches while controlling when they happen to avoid service interruptions.

Exam trap

CV0-004 often tests the distinction between tools that identify issues (vulnerability assessment, configuration compliance) and those that remediate them (patch automation), so candidates may incorrectly choose a monitoring or assessment service when the requirement is to apply patches.

How to eliminate wrong answers

Option A is wrong because a vulnerability assessment service identifies and reports vulnerabilities but does not apply patches. Option B is wrong because a configuration compliance service monitors and enforces configuration settings against baselines, but it does not deploy patches. Option C is wrong because a configuration management and automation service can automate tasks but lacks the specific patch management and maintenance window scheduling features needed for controlled patch deployment.

94
MCQeasy

A cloud operations team is using AWS and needs to monitor the CPU utilization of a fleet of Amazon EC2 instances. The team wants to receive an alert when the average CPU utilization exceeds 80% for 5 consecutive minutes. Which AWS service should they use to create the alarm?

A.AWS CloudTrail
B.AWS Trusted Advisor
C.Amazon CloudWatch
D.AWS Config
AnswerC

Amazon CloudWatch collects and tracks metrics such as CPU utilization for EC2 instances. It allows the creation of alarms that trigger when a metric breaches a threshold for a specified number of evaluation periods. In this scenario, an alarm can be set to fire when average CPU utilization exceeds 80% for 5 consecutive minutes, directly meeting the team's requirement for monitoring and alerting.

Why this answer

Amazon CloudWatch is the AWS service designed for monitoring metrics and creating alarms. It collects CPU utilization data from EC2 instances and allows alarms to be configured with thresholds and evaluation periods. Setting an alarm for average CPU utilization greater than 80% for 5 consecutive minutes meets the team's requirement to be alerted when the condition is met.

Exam trap

The trap here is confusing AWS CloudTrail, which logs API activity, with Amazon CloudWatch, which monitors performance metrics and triggers alarms.

95
MCQhard

A company wants to implement a disaster recovery strategy with an RTO of 15 minutes and an RPO of 1 minute for a critical database. Which approach should be used?

A.Scheduled snapshots every hour
B.Daily snapshots copied to another region
C.Weekly full backups to tape stored offsite
D.Cross-region continuous replication with automatic failover
AnswerD

Continuous cross-region replication keeps a standby copy within seconds of the primary, satisfying the one-minute RPO, while automatic failover redirects traffic without manual intervention, meeting the fifteen-minute RTO. Neither scheduled snapshots nor single-region backups can achieve both targets.

Why this answer

The requirement is an RTO of 15 minutes and an RPO of 1 minute. Cross-region continuous replication with automatic failover provides near-zero RPO (often seconds) and rapid RTO (minutes) by continuously replicating data and automatically promoting a standby in another region. This is the only option that can meet both the 1-minute RPO and 15-minute RTO.

Exam trap

CV0-004 often tests the misconception that frequent snapshots can achieve a low RPO, but snapshots are point-in-time and cannot meet sub-minute RPO; candidates must recognize that continuous replication is required for very low RPO.

How to eliminate wrong answers

Option A is wrong because hourly snapshots yield an RPO of up to 60 minutes, far exceeding the 1-minute requirement. Option B is wrong because daily snapshots yield an RPO of up to 24 hours, and cross-region copy adds delay, failing both RPO and likely RTO. Option C is wrong because weekly tape backups have an RPO of up to 7 days and restoration from tape is slow, failing both objectives.

96
Multi-Selectmedium

A cloud administrator is responsible for a Microsoft Azure environment. The administrator needs to ensure that virtual machine (VM) disks are backed up daily and that backups are retained for 30 days. The administrator also needs to be able to restore individual files from the backups. Which TWO actions should the administrator take to meet these requirements? (Choose two.)

Select 2 answers
A.Install the Microsoft Azure Recovery Services (MARS) agent on each VM and configure a backup schedule.
B.Create an Azure Storage account with blob versioning enabled and configure lifecycle management.
C.Configure Azure Backup for the VMs using the Azure VM backup extension and associate them with the backup policy.
D.Create a Recovery Services vault and configure a backup policy with a daily schedule and 30-day retention.
E.Enable Azure Site Recovery for the VMs and configure a replication policy.
AnswersC, D

Azure Backup for VMs uses an extension installed on the VM to take snapshot-based backups of the OS and data disks. Associating the VMs with the backup policy created in the Recovery Services vault ensures the daily schedule and 30-day retention are applied. This, combined with the vault and policy, enables file-level recovery from the VM backups, fully meeting the administrator's requirements.

Why this answer

To back up Azure VM disks daily with 30-day retention and file-level restore, the administrator must create a Recovery Services vault and configure a backup policy with the desired schedule and retention. Then, the VMs must be configured for Azure Backup using the VM backup extension and associated with that policy. Together, these actions provide the required backup and restore capabilities.

Exam trap

The trap here is confusing Azure Site Recovery, which is for disaster recovery replication, with Azure Backup, which provides scheduled backups and file-level restore.

97
Multi-Selectmedium

A cloud administrator is configuring a notification channel for critical alerts. Which TWO of the following are commonly used notification channels in cloud monitoring systems? (Select TWO.)

Select 2 answers
A.Amazon CloudWatch Logs
B.Amazon Simple Notification Service (SNS)
C.Slack webhooks
D.AWS Organizations
E.AWS CloudTrail
AnswersB, C

Amazon SNS delivers alerts by fanning messages out to email, SMS, HTTP endpoints and Lambda subscribers, satisfying the notification channel requirement. It integrates natively with CloudWatch alarms, so critical threshold breaches reach operators without custom polling infrastructure.

Why this answer

Amazon Simple Notification Service (SNS) (B) is correct because it is a fully managed pub/sub messaging service that supports topics with email, SMS, HTTP/S, and Lambda subscribers, making it a standard notification channel for CloudWatch alarms. Slack webhooks (C) are correct because an incoming webhook URL lets monitoring services POST JSON messages directly to a Slack channel, a widely used integration for critical alert delivery. Amazon CloudWatch Logs (A) is a log storage and query service, not a notification channel, so it does not deliver alerts to people.

AWS Organizations (D) is an account governance and consolidated billing service, and AWS CloudTrail (E) is an API activity auditing service; neither is designed to send alert notifications.

Exam trap

CV0-004 often tests whether candidates confuse data/logging services (CloudWatch Logs, CloudTrail) with actual notification delivery channels (SNS, Slack webhooks).

98
Multi-Selecthard

A company is performing a disaster recovery test for a critical application. The test reveals that the application's RTO of 1 hour is not being met due to slow database restoration. Which THREE actions could help improve the restoration time? (Select THREE.)

Select 3 answers
A.Implement continuous replication to a standby database
B.Pre-warm standby database instances in the recovery region
C.Disable encryption on the database to reduce overhead
D.Increase the retention period of automated backups
E.Use provisioned IOPS storage for the database volumes
AnswersA, B, E

Continuous replication to a standby database keeps a near-current copy available, so failover avoids restoring from backup and removes the slow restoration step. This directly reduces database recovery time, helping the application meet its one-hour RTO.

Why this answer

Option A (Implement continuous replication to a standby database) is correct because continuous replication keeps a standby copy nearly in sync with the primary, so failover requires little or no data restoration, drastically cutting the time to recover within the 1-hour RTO. Option B (Pre-warm standby database instances in the recovery region) is correct because pre-warming keeps compute, cache, and database processes already running and initialized, eliminating the startup and warm-up latency that would otherwise delay recovery. Option E (Use provisioned IOPS storage for the database volumes) is correct because restoring or replaying data is I/O-bound, and provisioned IOPS delivers guaranteed, higher disk throughput and lower latency, directly accelerating database restoration.

Option C is not appropriate because disabling encryption weakens security and encryption overhead is not the primary bottleneck in slow restores. Option D is not appropriate because increasing backup retention only keeps backups longer; it does not make restoring any single backup faster.

Exam trap

CV0-004 often tests the confusion between backup retention and restoration speed; candidates may think more backups help RTO, but retention only affects RPO and available restore points.

99
MCQhard

A company wants to implement automated patching for their Windows and Linux servers in AWS. They need to schedule patching during a maintenance window and have a rollback plan. Which service should they use?

A.AWS OpsWorks
B.AWS Config
C.AWS Systems Manager Patch Manager
D.Amazon Inspector
AnswerC

AWS Systems Manager Patch Manager applies OS patches to Windows and Linux instances on a schedule, using maintenance windows and patch baselines. It supports compliance reporting and controlled rollback through baseline approval rules, meeting the maintenance-window and rollback requirements.

Why this answer

AWS Systems Manager Patch Manager automates the process of patching fleets of Windows and Linux servers. It allows you to define patch baselines, schedule patching during maintenance windows, and even roll back patches if needed, making it the ideal service for this requirement.

Exam trap

The trap is confusing Patch Manager with other AWS services that have overlapping capabilities. For example, Amazon Inspector finds vulnerabilities but does not patch, and AWS Config can check compliance but not remediate. Candidates might also think OpsWorks is still the go-to for patching, but it's not.

How to eliminate wrong answers

Option A is wrong because AWS OpsWorks is a configuration management service that uses Chef and Puppet, but it is not specifically designed for automated patching and is being deprecated. Option B is wrong because AWS Config is for assessing, auditing, and evaluating configurations, not for applying patches. Option D is wrong because Amazon Inspector is a vulnerability management service that scans for software vulnerabilities and network exposures, but it does not perform patching.

100
MCQhard

A cloud engineer is responsible for a fleet of Amazon EC2 instances running a stateless web application. The engineer needs to ensure that if an instance fails a status check, it is automatically replaced without manual intervention. Which AWS feature should be used to meet this requirement?

A.AWS OpsWorks for Chef Automate with auto-healing policies
B.EC2 Auto Recovery feature enabled on each instance
C.EC2 Auto Scaling group with health checks set to EC2 and a launch template
D.AWS Elastic Beanstalk with rolling updates and immutable deployments
AnswerC

An Auto Scaling group can be configured to use EC2 status checks as health checks. When an instance fails a status check, the Auto Scaling group terminates it and launches a new instance from the launch template. This provides automatic replacement and maintains the desired capacity, meeting the requirement for unattended recovery.

Why this answer

The requirement is to automatically replace instances that fail status checks. An EC2 Auto Scaling group with EC2 health checks monitors instance status and replaces unhealthy instances. The launch template defines the instance configuration.

This is the standard AWS pattern for self-healing fleets of stateless instances.

Exam trap

The trap here is confusing EC2 Auto Recovery, which recovers an existing instance onto new hardware, with Auto Scaling, which replaces the instance entirely.

101
MCQmedium

A cloud operations team runs a fleet of Amazon EC2 instances behind an Application Load Balancer. During a load test, the team notices that healthy targets are being marked unhealthy and removed from rotation whenever a deployment briefly pushes CPU utilization above 90 percent. The team wants the load balancer to remove an instance only when the application stops responding to HTTP requests, not when it is merely busy. Which action should the team take?

A.Enable sticky sessions on the load balancer so that clients remain bound to the same instance throughout the deployment.
B.Create a CloudWatch alarm on the CPUUtilization metric and attach it to an Auto Scaling group scaling policy to replace instances above 90 percent.
C.Configure the target group health check to use the HTTP protocol on the application's health endpoint with a matcher for 200 and increase the unhealthy threshold.
D.Change the target group health check to TCP on the instance port and raise the healthy threshold so instances rejoin faster.
AnswerC

An HTTP health check against a dedicated application health endpoint evaluates whether the application is actually serving requests, which is the behavior the team wants. Setting a matcher of 200 confirms a valid response, and raising the unhealthy threshold prevents a single slow response from ejecting a target. Because CPU pressure alone does not affect an HTTP health check, busy-but-responsive instances stay in rotation during deployments.

Why this answer

Health checks should reflect the actual availability of the application, not incidental resource pressure. Switching the target group to an HTTP check against a dedicated health endpoint, expecting a 200 response, and lengthening the unhealthy threshold lets the load balancer distinguish a genuinely unresponsive target from one that is simply handling heavy load. This keeps instances in service during short CPU spikes, which is exactly the deployment behavior the team wants to preserve.

Exam trap

The trap here is assuming that a busy instance is an unhealthy instance, when load balancer health checks are meant to verify application responsiveness rather than resource utilization.

102
MCQmedium

A cloud engineer notices that an auto-scaling group is adding and removing instances too frequently, causing instability. Which configuration parameter should be adjusted to reduce this behavior?

A.Increase the health check grace period
B.Disable lifecycle hooks
C.Increase the cooldown period
D.Lower the scaling metric thresholds
AnswerC

Increasing the cooldown period forces the auto-scaling group to wait after each scaling activity before triggering another, directly damping the rapid add-remove oscillation described. This satisfies the stability constraint by preventing consecutive scale-out and scale-in events from chasing transient metric spikes.

Why this answer

Increasing the cooldown period is the correct adjustment because cooldown is the waiting time after a scaling activity before the auto-scaling group can perform another scaling action. A longer cooldown lets newly launched instances stabilize and metrics to reflect the new capacity, preventing the rapid add/remove oscillation known as thrashing. This directly reduces the instability described.

Exam trap

CV0-004 often tests the confusion between cooldown (dampening scaling frequency) and health check grace period (delaying health evaluation), causing candidates to pick the wrong stabilization control.

How to eliminate wrong answers

Option A is wrong because the health check grace period controls how long the group waits before checking a new instance's health; extending it delays unhealthy-instance replacement but does not stop rapid scale-in/scale-out flapping. Option B is wrong because lifecycle hooks pause instances in a wait state during launch or termination for custom actions; disabling them removes that control and does not address scaling oscillation. Option D is wrong because lowering scaling metric thresholds makes the group more sensitive to metric changes, which would increase — not reduce — the frequency of scaling actions.

103
MCQmedium

A company wants to implement a tagging strategy for their cloud resources to track costs by department and project. Tags must be applied to resources such as virtual machines and storage buckets. Which of the following is a best practice for cost attribution using tags?

A.Apply tags to resources only after creation to avoid governance issues.
B.Define a set of mandatory tag keys such as CostCenter, Project, and Environment with standardized values.
C.Use a single tag key 'Environment' with values 'Production' or 'Development'.
D.Use free-form text for tag values to allow flexibility.
AnswerB

Mandatory, standardised tag keys with controlled values ensure every resource is attributable to a department and project, preventing untagged or inconsistently labelled resources from skewing cost reports. This enforces consistent cost attribution across the estate.

Why this answer

Standardized, mandatory tag keys with controlled values (e.g., CostCenter, Project, Environment) ensure consistent cost allocation across all resources and prevent drift. This enables reliable grouping in billing reports and enforces governance via policies like AWS Tag Policies or Azure Policy. Without a defined schema, cost attribution becomes unreliable and reports fragment.

Exam trap

CV0-004 often tests the misconception that flexible or post-hoc tagging is acceptable, when the exam expects recognition that standardized, mandatory tags applied at creation are the only reliable basis for cost attribution.

How to eliminate wrong answers

Option A is wrong because applying tags only after creation creates a window where resources are untagged, breaking cost attribution and violating governance best practices; tags should be applied at provisioning time via IaC or policies. Option C is wrong because a single 'Environment' tag only tracks one dimension and cannot attribute costs by department or project, which is the stated requirement. Option D is wrong because free-form text values lead to inconsistent spellings, typos, and case variations (e.g., 'Prod', 'production', 'PROD'), making aggregation and reporting impossible.

104
MCQmedium

A cloud architect is designing an auto-scaling policy for a web application. The application's traffic spikes predictably every weekday at 9 AM and decreases after 5 PM. Which scaling policy is most cost-effective?

A.Step scaling policy that adds instances when CPU > 70%
B.Simple scaling policy with a cooldown of 300 seconds
C.Scheduled scaling policy that increases capacity at 8:45 AM and decreases at 5:15 PM
D.Target tracking policy with a target CPU of 50%
AnswerC

Scheduled scaling provisions capacity at fixed times, matching the predictable weekday 9 AM spike and 5 PM decline without relying on reactive metrics. This avoids over-provisioning during known idle periods, directly satisfying the cost-effectiveness constraint in the stem.

Why this answer

Scheduled scaling is designed for predictable, time-based traffic patterns. Scaling up at 8:45 AM and down at 5:15 PM pre-provisions capacity before the 9 AM spike and removes it after the 5 PM decline, avoiding the lag and over-provisioning inherent in reactive policies. This is the most cost-effective approach for a known weekly pattern.

Exam trap

CV0-004 often tests the misconception that target tracking is always best, when predictable time-based patterns are more cost-effectively handled by scheduled scaling.

How to eliminate wrong answers

Option A is wrong because step scaling reacts to CPU after the spike has already begun, causing latency during ramp-up and leaving capacity idle during predictable lulls. Option B is wrong because simple scaling with a cooldown is reactive and slow, and the 300-second cooldown can delay necessary scale-out during rapid morning ramps. Option D is wrong because target tracking, while effective for variable load, still reacts to metrics rather than anticipating the known 9 AM spike, so it over-provisions during the ramp and under-provisions briefly at onset.

105
MCQhard

A cloud engineer is responsible for a set of Amazon EC2 instances that run a stateless web application. The engineer must ensure that the application can automatically recover from instance-level failures and that new instances are launched in multiple Availability Zones to maintain high availability. Which combination of AWS services should the engineer use?

A.An Auto Scaling group with a launch template and an Application Load Balancer
B.An Auto Scaling group with a launch template and a Network Load Balancer
C.An EC2 Auto Recovery alarm and a Network Load Balancer
D.A placement group with a spread strategy and an Application Load Balancer
AnswerA

An Auto Scaling group with a launch template can span multiple Availability Zones, automatically replacing unhealthy instances and launching new ones to meet demand. An Application Load Balancer operates at Layer 7, supports HTTP/HTTPS health checks, and can route traffic based on path or host. Together, they provide automatic recovery and high availability for a stateless web application, directly satisfying the engineer's requirements.

Why this answer

The engineer needs both automatic instance recovery and multi-AZ high availability. An Auto Scaling group with a launch template automatically replaces unhealthy instances and can launch instances across multiple Availability Zones. An Application Load Balancer performs HTTP/HTTPS health checks and distributes traffic only to healthy instances.

Together they provide the required resilience and availability for the stateless web application.

Exam trap

The trap here is confusing EC2 Auto Recovery, which recovers a single impaired instance in place, with an Auto Scaling group that replaces instances and scales across Availability Zones.

106
Multi-Selectmedium

A cloud operations team runs a three-tier application on Amazon EC2 instances behind an Application Load Balancer. During a peak-traffic event, users report intermittent 503 errors, and the operations team wants to automatically add capacity when the average CPU utilization of the Auto Scaling group exceeds 70 percent for five consecutive minutes, then remove capacity when it drops below 30 percent. Which TWO configuration elements must the team define to accomplish this? (Choose two.)

Select 2 answers
A.A second CloudWatch alarm that enters the ALARM state when CPU utilization is less than 30 percent for the same evaluation window.
B.An AWS Budgets alarm set to notify when EC2 spending exceeds 70 percent of the monthly forecast.
C.A CloudWatch alarm that enters the ALARM state when CPU utilization is greater than 70 percent for five consecutive evaluation periods.
D.An Application Load Balancer health check configured with a 70 percent healthy threshold.
E.A target tracking scaling policy attached to the Auto Scaling group with a target value of 70 percent.
AnswersA, C

Scale-in requires its own trigger because the threshold differs from scale-out. A separate CloudWatch alarm with a less-than-30-percent condition, evaluated over the same period, provides the discrete signal the Auto Scaling group needs to remove capacity only after utilization genuinely drops, matching the scenario's stated scale-in condition.

Why this answer

Dynamic scaling in an Auto Scaling group is driven by CloudWatch alarms that translate metric thresholds into scaling actions. Because the scenario specifies different thresholds for scaling out and scaling in, two separate alarms are needed: one for CPU above 70 percent and one for CPU below 30 percent, each evaluated over the stated five-minute window. Target tracking and budget alarms cannot express this asymmetric behavior.

Exam trap

The trap here is assuming a single target tracking policy can enforce two different thresholds, when target tracking maintains one target value and cannot express separate scale-out and scale-in conditions.

107
MCQmedium

A cloud administrator is responsible for a Microsoft Azure environment with a hub-and-spoke network topology. The administrator needs to ensure that all traffic from the spoke virtual networks to the internet is routed through a network virtual appliance (NVA) in the hub virtual network for inspection. Which Azure feature should the administrator configure?

A.Azure Private Link to connect the spokes to the hub
B.Virtual network peering with gateway transit enabled
C.User-defined routes (UDRs) on the spoke subnets pointing to the NVA's private IP address
D.Azure Firewall in the hub virtual network with forced tunneling
AnswerC

User-defined routes allow the administrator to override Azure's default system routes. By creating a UDR on the spoke subnets with the next hop type set to 'Virtual appliance' and specifying the NVA's private IP address, all traffic destined for the internet or other networks can be forced through the NVA for inspection. This directly satisfies the requirement to route spoke traffic through the NVA in the hub.

Why this answer

To force traffic from spoke virtual networks through a network virtual appliance in the hub, the administrator must configure user-defined routes on the spoke subnets. The UDR sets the next hop type to 'Virtual appliance' and specifies the NVA's private IP address. This overrides Azure's default system routes and ensures traffic is sent to the NVA for inspection before reaching the internet.

Exam trap

The trap here is assuming that virtual network peering or Azure Firewall automatically routes traffic through an NVA, when in fact user-defined routes are required to override default routing.

108
MCQeasy

A cloud administrator needs to centrally collect, search, and retain application and system logs from hundreds of Amazon EC2 instances and AWS services for troubleshooting and compliance. The administrator wants a managed service that stores logs in durable storage and allows ad hoc queries using a query language. Which AWS service should the administrator use?

A.AWS CloudTrail
B.AWS Trusted Advisor
C.AWS Config
D.Amazon CloudWatch Logs
AnswerD

Amazon CloudWatch Logs is a managed service that ingests log data from EC2 instances via the CloudWatch agent, from AWS services, and from custom sources. It stores logs durably in log groups and supports querying with CloudWatch Logs Insights, a query language for searching and analyzing log events, which matches the central collection and ad hoc query requirements.

Why this answer

Amazon CloudWatch Logs is the managed AWS service for centralizing log data from EC2 instances and AWS services. The CloudWatch agent ships instance logs to log groups, and CloudWatch Logs Insights provides a purpose-built query language to search and analyze events. CloudTrail captures API activity, Config tracks resource configuration, and Trusted Advisor offers recommendations, none of which provide general log ingestion and querying.

Exam trap

The trap here is confusing CloudTrail, which records API calls for auditing, with a service that ingests and queries application and operating system logs.

109
Multi-Selectmedium

A cloud operations team is setting up log-based alerting for security events. They want to use structured logging to facilitate querying. Which TWO practices support effective log-based alerting? (Choose TWO.)

Select 2 answers
A.Enable verbose logging for all services
B.Centralize logs in a log management system
C.Use random log formats for different applications
D.Send all logs to syslog servers
E.Output logs in JSON format
AnswersB, E

Centralising logs in a log management system aggregates entries from all sources into one queryable store, enabling correlation and consistent alert rules across services. Without centralisation, security events scattered across hosts cannot be searched or alerted on reliably, undermining structured log-based detection.

Why this answer

Option B is correct because centralizing logs in a log management system (such as a SIEM, ELK/Elasticsearch, or cloud-native service like CloudWatch Logs or Cloud Logging) aggregates events from multiple sources into one queryable store, which is essential for correlating security events and defining alert rules across services. Option E is correct because outputting logs in JSON format produces structured, machine-parseable records with consistent key-value fields, enabling precise queries and filters (e.g., level:ERROR AND event:login_failure) that drive reliable log-based alerts. Option A is not appropriate because enabling verbose logging for all services generates excessive noise and cost, obscuring the security events that alerts should target.

Option C is wrong because random, inconsistent log formats break parsing and make querying and alerting unreliable. Option D is not the best practice here because blindly sending all logs to syslog servers lacks the structured, centralized querying and alerting capabilities required, and syslog alone does not provide the structured format needed for effective log-based alerting.

Exam trap

CV0-004 often tests the confusion between logging volume and logging quality, tempting candidates to choose 'verbose logging' or 'random formats' when the exam expects recognition that structured, centralized logs are what enable effective alerting.

110
MCQeasy

A cloud administrator wants to troubleshoot network connectivity issues between two VPCs. Which AWS feature provides detailed logs of IP traffic for analysis?

A.AWS CloudTrail
B.VPC Route Tables
C.AWS CloudWatch Logs
D.VPC Flow Logs
AnswerD

VPC Flow Logs capture accepted and rejected IP traffic metadata for elastic network interfaces, subnets or VPCs, including source, destination, port and action. Publishing them to CloudWatch Logs or S3 satisfies the troubleshooting requirement, since the records reveal whether traffic between the two VPCs is reaching its destination.

Why this answer

VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, action) for network interfaces in a VPC, and can be published to CloudWatch Logs or S3 for analysis. This is the specific AWS feature designed for troubleshooting connectivity and analyzing traffic patterns at the network layer.

Exam trap

CV0-004 often tests the confusion between CloudTrail (API auditing) and VPC Flow Logs (network traffic), causing candidates to pick CloudTrail when the question asks about IP traffic analysis.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and management events, not IP traffic; it cannot show packet-level connectivity issues. Option B is wrong because VPC Route Tables define routing paths but do not log traffic; they are configuration objects, not diagnostic logs. Option C is wrong because AWS CloudWatch Logs is a log storage/analysis service, not a traffic capture feature; it can receive Flow Logs but does not generate them itself.

111
MCQmedium

A company wants to optimize cloud costs by identifying underutilized EC2 instances. Which AWS service provides rightsizing recommendations?

A.AWS Trusted Advisor
B.AWS Cost Explorer
C.AWS Budgets
D.AWS Compute Optimizer
AnswerD

AWS Compute Optimizer analyses CloudWatch metrics and resource configuration to generate rightsizing recommendations for EC2 instances, identifying over-provisioned or underutilised capacity. This directly satisfies the goal of finding underutilised instances, unlike billing or inventory tools that only report spend.

Why this answer

AWS Compute Optimizer is the dedicated service that analyzes historical utilization metrics (CPU, memory, network, disk) from CloudWatch to generate rightsizing recommendations for EC2 instances, Auto Scaling groups, EBS volumes, and Lambda functions. It uses machine learning to identify over-provisioned or under-provisioned resources and provides specific instance type recommendations. Unlike other cost tools, Compute Optimizer is purpose-built for resource optimization and rightsizing, making it the correct choice for identifying underutilized EC2 instances.

Exam trap

CV0-004 often tests the distinction between cost visibility tools (Cost Explorer, Budgets) and cost optimization tools (Compute Optimizer, Trusted Advisor), so candidates must remember that only Compute Optimizer provides detailed rightsizing recommendations for EC2.

How to eliminate wrong answers

Option A is wrong because AWS Trusted Advisor provides best-practice checks across cost, security, fault tolerance, performance, and service limits, but its cost optimization checks are high-level (e.g., idle load balancers, unassociated Elastic IPs) and do not generate detailed rightsizing recommendations for EC2 instances. Option B is wrong because AWS Cost Explorer is a cost visualization and analysis tool that shows spending trends and forecasts, but it does not provide rightsizing recommendations; it may show cost anomalies but not specific instance type changes. Option C is wrong because AWS Budgets is used to set custom cost and usage budgets and receive alerts when thresholds are exceeded, but it does not analyze resource utilization or recommend rightsizing actions.

112
MCQmedium

A cloud administrator needs to apply security patches to a fleet of 50 Linux servers running on AWS without interrupting business hours. Which approach should the administrator use to schedule patching during a maintenance window?

A.Use AWS Systems Manager Patch Manager with a maintenance window
B.Create a Lambda function that stops instances, patches them, and restarts
C.Manually SSH into each server and run yum update
D.Use AWS Config to apply patch baselines
AnswerA

AWS Systems Manager Patch Manager with a maintenance window satisfies the no-business-hours constraint by targeting the 50 Linux instances via tags and running patch baselines only within a defined schedule, using an IAM service role rather than SSH. This avoids manual intervention and prevents patching outside the approved window.

Why this answer

AWS Systems Manager Patch Manager is designed to automate the process of patching fleets of instances. It integrates with Maintenance Windows, allowing administrators to define a schedule (e.g., outside business hours) during which patching tasks run. This approach is scalable, auditable, and does not require manual intervention or custom scripting, making it the correct choice for patching 50 Linux servers without interrupting business hours.

Exam trap

CV0-004 often tests the misconception that AWS Config can enforce or apply patches, when it only assesses compliance; candidates may confuse Config's role with Patch Manager's active patching capabilities.

How to eliminate wrong answers

Option B is wrong because creating a Lambda function to stop, patch, and restart instances is a custom, error-prone solution that lacks built-in patch compliance reporting and scheduling; stopping instances causes downtime and patching offline instances is inefficient. Option C is wrong because manually SSHing into each server and running yum update is not scalable, lacks scheduling, and is prone to human error, plus it doesn't guarantee patching during a maintenance window. Option D is wrong because AWS Config is a configuration assessment service, not a patching tool; it can detect patch compliance but cannot apply patches or schedule patching.

113
MCQmedium

A cloud operations team runs a three-tier web application on AWS. During a recent incident, the on-call engineer received hundreds of Amazon CloudWatch alarms within minutes and could not identify the root cause. The team wants to reduce alarm fatigue while still capturing meaningful signals. Which action should the team take FIRST?

A.Increase each alarm's evaluation period from 1 minute to 60 minutes so that fewer state transitions occur during an incident.
B.Delete all metric alarms and rely solely on AWS Health Dashboard notifications for operational awareness.
C.Configure the SNS topic to buffer notifications and deliver them as a single daily digest email to the operations team.
D.Create composite alarms that combine related metric and state alarms using AND/OR logic, and route only the composite alarm to the notification topic.
AnswerD

Composite alarms evaluate the state of multiple child alarms and fire only when the Boolean expression is true, which directly suppresses the storm of individual notifications. Routing only the composite alarm to the SNS topic means the on-call engineer receives one actionable alert that represents the correlated condition, preserving the underlying child alarms for diagnostics.

Why this answer

Composite alarms exist specifically to reduce noise by evaluating multiple child alarms with Boolean operators and firing a single notification only when the combined condition is met. This preserves granular child alarms for troubleshooting while giving on-call engineers one correlated, actionable signal, which is the fastest way to reduce alarm fatigue without losing observability.

Exam trap

The trap here is assuming alarm fatigue is solved by slowing evaluation periods or batching notifications, when the actual mechanism is correlating multiple alarms into a single composite condition.

114
MCQmedium

A company uses AWS and wants to optimize costs by receiving recommendations to downsize over-provisioned EC2 instances. Which tool provides rightsizing recommendations?

A.AWS Budgets
B.AWS Trusted Advisor
C.AWS Cost Explorer
D.AWS Compute Optimizer
AnswerD

AWS Compute Optimizer analyses CloudWatch metrics against instance families and returns rightsizing recommendations for over-provisioned EC2 instances, directly meeting the cost-optimisation requirement. Cost Explorer and Trusted Advisor do not produce instance-level downsizing guidance of this kind.

Why this answer

AWS Compute Optimizer is the service specifically designed to analyze resource utilization metrics (such as CPU, memory, network, and disk) and generate rightsizing recommendations for EC2 instances, Auto Scaling groups, EBS volumes, and Lambda functions. It uses machine learning to identify over-provisioned or under-provisioned resources and provides actionable recommendations to downsize or upsize, directly addressing the goal of cost optimization. Unlike other tools that focus on billing or budgets, Compute Optimizer delivers instance-type-level guidance based on actual usage patterns.

Exam trap

CV0-004 often tests the distinction between cost visibility tools (Cost Explorer, Budgets) and cost optimization recommendation engines (Compute Optimizer, Trusted Advisor), so candidates must remember that only Compute Optimizer provides detailed EC2 rightsizing recommendations based on utilization metrics.

How to eliminate wrong answers

Option A is wrong because AWS Budgets is used to set custom spending limits and receive alerts when costs or usage exceed thresholds, but it does not analyze resource utilization or provide instance rightsizing recommendations. Option B is wrong because AWS Trusted Advisor offers best-practice checks across cost optimization, security, fault tolerance, and performance, but its cost optimization checks are high-level (e.g., idle load balancers, unassociated Elastic IPs) and do not generate detailed EC2 rightsizing recommendations based on utilization metrics. Option C is wrong because AWS Cost Explorer visualizes and analyzes historical cost and usage data, allowing you to see spending trends and forecast costs, but it does not provide specific rightsizing recommendations for EC2 instances.

115
MCQeasy

A cloud engineer needs to troubleshoot network connectivity issues between two subnets. Which feature can help capture and analyze network traffic metadata?

A.Amazon Inspector
B.AWS Config
C.VPC Flow Logs
D.AWS CloudTrail
AnswerC

VPC Flow Logs capture IP traffic metadata at the network interface level, recording source/destination IPs, ports, protocols, and packet accept/reject decisions without inspecting packet payloads. This satisfies the stem’s requirement to *analyse traffic metadata* between subnets, as the logs are published to Amazon CloudWatch Logs or S3 for querying with tools like Athena, enabling identification of blocked flows or asymmetric routing.

Why this answer

VPC Flow Logs capture IP traffic metadata (source/destination IP, ports, protocol, bytes, packets, action) for traffic flowing through ENIs, subnets, or VPCs. This metadata is exactly what's needed to diagnose connectivity issues between subnets, since it shows whether traffic is being accepted or rejected by security groups and NACLs. It can be published to CloudWatch Logs or S3 for analysis.

Exam trap

The trap here is confusing observability services — candidates often pick CloudTrail because it sounds like it 'logs everything,' but CloudTrail logs API calls, not network flows.

How to eliminate wrong answers

Option A is wrong because Amazon Inspector is a vulnerability management service that scans EC2 instances, container images, and Lambda functions for software vulnerabilities and unintended network exposure — it does not capture traffic metadata. Option B is wrong because AWS Config records resource configuration changes and evaluates them against compliance rules; it has no packet or flow-level visibility. Option D is wrong because AWS CloudTrail records API activity and management events (who did what, when, from where), not network traffic between subnets.

116
MCQmedium

A cloud operations team runs a containerized API on Amazon ECS with the Fargate launch type. During peak hours, CPU utilization on the tasks regularly reaches 95 percent and response latency doubles. The team wants the service to add tasks automatically before users notice degradation, and to remove them when demand drops. Which action should the team take?

A.Increase the task definition CPU reservation from 1024 to 4096 CPU units and redeploy the service so each task can process more requests.
B.Create an EC2 Auto Scaling group with a launch configuration that runs the container image, and attach the group to the ECS cluster as a capacity provider.
C.Configure an Application Auto Scaling target tracking scaling policy on the ECS service using the ECSServiceAverageCPUUtilization metric with a target value and a scale-out cooldown.
D.Enable burstable performance mode on the ECS cluster so tasks can consume additional CPU credits during peak hours.
AnswerC

Application Auto Scaling for ECS services supports target tracking policies that watch the ECSServiceAverageCPUUtilization metric and adjust the desired task count to hold utilization near the target. Because the metric reflects the whole service, Fargate tasks scale out before saturation and scale in when load falls, which directly addresses the latency spike.

Why this answer

Target tracking scaling on the ECS service is the native mechanism for elastic task capacity. It monitors the service-level average CPU metric and adjusts the desired count toward the configured target, scaling out ahead of user-visible degradation and scaling in afterward. Adjusting task size, cluster-level settings, or EC2 capacity providers does not change the number of running Fargate tasks in response to demand.

Exam trap

The trap here is assuming that giving each task more CPU, or enabling a cluster-wide performance setting, will scale capacity, when only a service scaling policy changes the number of running tasks.

117
MCQmedium

A cloud administrator manages a fleet of Linux virtual machines on Google Cloud. A compliance rule requires that an interactive SSH session to any of these instances be brokered through an identity-aware proxy so that sessions are authenticated and auditable, and that no external IP addresses be assigned to the instances. Which solution should the administrator implement?

A.Configure a Cloud VPN tunnel from the corporate network and allow SSH from the corporate address range only.
B.Assign external IP addresses to each instance and restrict ingress to the administrator's source IP range with firewall rules.
C.Deploy a bastion host with an external IP and have administrators SSH to the bastion before connecting to each instance.
D.Use Identity-Aware Proxy TCP forwarding to reach each instance over its internal IP, with firewall rules allowing the IAP range.
AnswerD

IAP TCP forwarding tunnels SSH over the internal IP through Google's infrastructure, authenticating the user's identity and IAM role before the connection is allowed. Because the instance needs no external address and the firewall permits only the IAP source range, the compliance rule is satisfied. Access is also logged per session, giving the auditability the rule demands.

Why this answer

The rule has two parts: identity-aware brokering of interactive sessions and no external addresses on the instances. Identity-Aware Proxy TCP forwarding satisfies both because it authenticates the user's identity and IAM permissions before tunneling SSH over the internal address, and the firewall only needs to allow the IAP source range. External IPs, bastion hosts, and VPN-only access all authenticate network location rather than user identity.

Exam trap

The trap here is treating a network-location control such as a VPN or firewall range as equivalent to identity-aware session brokering.

118
MCQmedium

A cloud engineer is investigating a sudden increase in egress charges. The engineer suspects that a misconfigured Amazon S3 bucket is being read frequently from the internet. Which tool should the engineer use to identify the source IP addresses and request patterns for that bucket?

A.AWS Budgets
B.S3 server access logging
C.AWS Cost Explorer
D.Amazon S3 Storage Lens
AnswerB

S3 server access logs capture detailed records for every request made to a bucket, including the requester's IP address, the operation, and the response code. Analyzing these logs lets the engineer identify which sources are generating the traffic that drives the egress charges.

Why this answer

S3 server access logging records each request to a bucket with fields including the requester's IP address, the operation performed, and the response. That request-level detail is what allows the engineer to trace the egress charges back to specific clients and patterns, which the aggregated cost and metrics tools cannot provide.

Exam trap

The trap here is relying on cost or usage dashboards that aggregate data when the scenario needs per-request attribution.

119
MCQhard

A cloud engineer is configuring an auto-scaling group with a lifecycle hook to run a custom script when instances are launched. The script installs software and registers the instance with a load balancer. The engineer wants to ensure the instance does not receive traffic until the script completes successfully. What should the engineer do?

A.Set the lifecycle hook to 'terminating:wait' to delay termination.
B.Use a lifecycle hook with a 'pending:wait' state and then send a 'complete-lifecycle-action' signal after the script succeeds.
C.Configure the load balancer health check to fail until the script runs.
D.Configure the launch configuration with a user-data script that runs after the instance is in service.
AnswerB

The pending:wait lifecycle state holds the instance in service-pending until the script signals complete-lifecycle-action, so the load balancer never routes traffic to an unconfigured instance. This satisfies the constraint that traffic must wait for successful script completion.

Why this answer

Option B is correct because using a lifecycle hook with a 'pending:wait' state allows you to pause the instance launch process until the custom script completes. After the script succeeds, you send a 'complete-lifecycle-action' signal to the auto-scaling group, which then proceeds to put the instance into service. This ensures the instance does not receive traffic until the script is done.

Exam trap

CV0-004 often tests the misconception that user data or health checks can delay traffic until a script completes; candidates must remember that lifecycle hooks with 'pending:wait' and explicit 'complete-lifecycle-action' signals are required to pause the instance launch process.

How to eliminate wrong answers

Option A is wrong because a 'terminating:wait' lifecycle hook is used during instance termination, not launch; it would not prevent traffic during launch. Option C is wrong because configuring the load balancer health check to fail until the script runs would cause the instance to be marked unhealthy and potentially terminated, and it does not guarantee the script completes before traffic is routed; it's a reactive approach. Option D is wrong because user-data scripts run during launch but do not inherently delay the instance from being put into service; the instance could receive traffic before the script finishes.

120
MCQmedium

A company uses a multi-cloud environment with AWS and Azure. They want to centralize log collection and enable advanced querying for troubleshooting. Which combination of services should they use?

A.AWS CloudTrail and Azure Monitor
B.AWS CloudWatch Logs and Azure Log Analytics
C.AWS S3 and Azure Blob Storage
D.AWS CloudWatch and Azure Application Insights
AnswerB

AWS CloudWatch Logs ingests and stores logs from AWS workloads, while Azure Log Analytics provides the centralised workspace and Kusto queries for advanced troubleshooting. Together they satisfy the multi-cloud constraint by covering both providers and enabling cross-environment querying.

Why this answer

AWS CloudWatch Logs and Azure Log Analytics are the native log aggregation and querying services in their respective clouds. CloudWatch Logs centralizes logs from AWS resources and supports Logs Insights for querying, while Azure Log Analytics provides a powerful KQL-based query engine over data collected in a Log Analytics workspace. Using both together gives centralized collection and advanced querying across the multi-cloud environment.

Exam trap

CV0-004 often tests whether candidates confuse monitoring/APM tools (Azure Monitor, Application Insights) with the actual log storage and query engine (Log Analytics), leading them to pick a service that cannot perform advanced log querying.

How to eliminate wrong answers

Option A is wrong because CloudTrail records API activity (audit trail) rather than application or system logs, and Azure Monitor is an umbrella monitoring platform, not a log query engine — the querying component is Log Analytics. Option C is wrong because S3 and Blob Storage are object storage services for retention, not log collection or querying platforms. Option D is wrong because CloudWatch (without specifying Logs) is a broader monitoring service and Application Insights is an APM tool focused on application performance telemetry, not centralized log querying across infrastructure.

121
MCQmedium

A cloud operations team manages a fleet of Amazon EC2 instances running a stateless web tier behind an Application Load Balancer. The team wants to replace instances automatically when an instance fails an Elastic Load Balancing health check, without manual intervention, while keeping the desired capacity constant. Which AWS feature should the team configure to meet this requirement?

A.EC2 Auto Scaling group with health check type set to ELB
B.EC2 Auto Scaling group with health check type set to EC2
C.AWS Lambda function triggered by Amazon CloudWatch alarms on CPU utilization
D.AWS Elastic Beanstalk environment with rolling updates
AnswerA

An Auto Scaling group configured with the ELB health check type uses the load balancer's health status to determine instance health. When an instance fails the ELB health check, Auto Scaling terminates it and launches a replacement to maintain the desired capacity, providing the automatic recovery the team needs without manual intervention.

Why this answer

Automatic replacement of instances that fail load balancer health checks requires an Auto Scaling group whose health check type is set to ELB. In that mode, the group treats an instance as unhealthy when the load balancer reports it as unhealthy, terminates it, and launches a replacement to preserve desired capacity. Other options either react to metrics rather than health checks or only evaluate EC2-level status.

Exam trap

The trap here is assuming that EC2 status checks and ELB health checks are equivalent, when an instance can pass EC2 checks yet still be removed from load balancer rotation.

122
MCQhard

A cloud engineer manages a Kubernetes cluster on Google Kubernetes Engine. A production Deployment repeatedly enters CrashLoopBackOff after a configuration change, and the engineer needs to inspect why the container is terminating without modifying the running workload. Which action should the engineer take?

A.Enable GKE node auto-repair to replace the node hosting the failing pod
B.Run kubectl logs on the failing pod with the --previous flag to retrieve logs from the prior container instance
C.Delete the Deployment and recreate it with a higher restart backoff limit
D.Scale the Deployment to zero replicas and then back to the original count
AnswerB

When a container crashes and restarts, the current container may not yet have produced logs. The --previous flag retrieves logs from the terminated instance, which is exactly where the crash reason appears. This is a non-disruptive read-only action that satisfies the requirement to inspect without modifying the running workload, making it the correct diagnostic step.

Why this answer

Retrieving logs from the previous container instance surfaces the actual termination error without altering the Deployment or node configuration. Because CrashLoopBackOff restarts containers, the current instance may not have logged anything yet, so the --previous flag is essential. Disruptive actions like deleting, scaling, or replacing nodes neither reveal the cause nor respect the constraint of not modifying the running workload.

Exam trap

The trap here is assuming the current container's logs will show the crash, when a restarted container often has no output yet and the prior instance's logs are required.

123
MCQmedium

A company is using Azure VMs and wants to centralize logs from multiple applications for security analysis. The logs must be retained for 2 years. Which Azure service should they use?

A.Azure Activity Log
B.Azure Application Insights
C.Azure Log Analytics
D.Azure Storage Analytics
AnswerC

Azure Log Analytics ingests application logs from multiple sources into a single workspace, then supports KQL queries for security analysis and configurable retention extending to two years. This directly meets the centralisation and long-retention constraints in the stem.

Why this answer

Azure Log Analytics is the service designed to collect, store, and query log data from multiple sources, including applications, VMs, and Azure resources. It supports configurable retention (including long-term retention beyond the default 30 days) and provides KQL-based querying for security analysis. This makes it the correct choice for centralizing logs with a 2-year retention requirement.

Exam trap

CV0-004 often tests the confusion between Application Insights (APM telemetry) and Log Analytics (centralized log store), tricking candidates into choosing Application Insights when the requirement is broad log centralization and retention.

How to eliminate wrong answers

Option A is wrong because Azure Activity Log records subscription-level control plane operations (who created/deleted resources) and is not a general-purpose application log store. Option B is wrong because Application Insights is an APM service for application performance telemetry (requests, dependencies, exceptions) and is not intended as a centralized multi-application log repository. Option D is wrong because Azure Storage Analytics provides metrics and logs specifically for Azure Storage accounts, not for application logs across VMs and services.

124
MCQhard

A cloud engineer manages an application running on Amazon ECS with the Fargate launch type. The application occasionally experiences task failures during deployment. The engineer wants to inspect the container's standard output and standard error to determine why a task stopped, without modifying the application to write to a file. Which action should the engineer take?

A.Connect to the Fargate task using SSH to read the container's console output
B.Retrieve the task's output from the Amazon ECR repository where the image is stored
C.Configure the task definition to use the awslogs log driver and view the logs in CloudWatch Logs
D.Enable ECS Exec on the service and run docker logs inside the container to retrieve output
AnswerC

Configuring the task definition's container to use the awslogs log driver sends the container's stdout and stderr streams to a specified CloudWatch Logs log group and stream. This captures the output the engineer needs to diagnose why a task stopped, and it requires no application changes because Docker's logging mechanism handles the capture.

Why this answer

For ECS tasks on Fargate, container stdout and stderr must be directed to a logging destination through a log driver in the task definition. The awslogs driver forwards those streams to CloudWatch Logs, where the engineer can review output from both running and stopped tasks. SSH is unavailable, ECS Exec only works on running tasks, and ECR stores images rather than runtime logs.

Exam trap

The trap here is assuming that a stopped Fargate task can be inspected interactively, when Fargate provides no host access and stopped tasks cannot be entered.

125
MCQmedium

A cloud administrator is responsible for an application hosted on Amazon EC2 that stores session data in memory. The business requires that, in the event of an instance failure, a replacement instance can resume serving users with the existing session data intact and with minimal interruption. Which action should the administrator take to meet this requirement?

A.Create an Amazon Machine Image of the instance after each user session is established.
B.Move session state to an external store such as Amazon ElastiCache for Redis and configure the application to use it.
C.Enable detailed monitoring on the EC2 instances to capture session data in Amazon CloudWatch.
D.Configure an Auto Scaling group with a minimum and maximum size of one to replace failed instances automatically.
AnswerB

Externalizing session state to ElastiCache for Redis decouples the session data from any single instance. If an instance fails, a replacement instance can read the same session data from the shared store, allowing users to continue without losing their sessions. This directly satisfies the requirement for session continuity with minimal interruption.

Why this answer

Session data held only in instance memory is lost when that instance fails. Storing sessions in a shared external service such as Amazon ElastiCache for Redis lets any replacement instance retrieve the same session data. This decouples session state from compute, so failover restores both capacity and user continuity with minimal disruption.

Exam trap

The trap here is assuming that Auto Scaling or monitoring restores application session data, when those features only restore or observe compute capacity.

126
Multi-Selectmedium

A cloud administrator wants to choose an auto-scaling policy that can respond to changing demand patterns. Which TWO policy types support dynamic adjustments based on real-time metrics? (Choose TWO)

Select 2 answers
A.Predictive scaling
B.Target tracking scaling
C.Step scaling
D.Scheduled scaling
E.Simple scaling
AnswersB, C

Target tracking scaling continuously adjusts capacity to hold a chosen metric, such as average CPU utilisation, at a target value. It reacts to real-time metric changes automatically, satisfying the requirement for dynamic adjustment without manually defined thresholds.

Why this answer

Target tracking scaling (B) is correct because it continuously adjusts capacity to keep a chosen metric (such as average CPU utilization or ALB request count per target) at a specified target value, reacting dynamically to real-time metric fluctuations. Step scaling (C) is also correct because it adds or removes capacity in defined step adjustments when a CloudWatch alarm breaches a threshold, allowing graduated responses to real-time metric changes. Predictive scaling (A) is not correct here because it forecasts future demand from historical patterns and provisions capacity ahead of time rather than reacting to real-time metrics.

Scheduled scaling (D) is not correct because it scales based on a defined date/time schedule, not on live metrics. Simple scaling (E) is not correct because it performs a single fixed adjustment when an alarm triggers and then enforces a cooldown, so it does not provide the dynamic, metric-driven responsiveness described.

Exam trap

CV0-004 often tests the distinction between reactive policies (target tracking, step scaling) and proactive policies (predictive, scheduled), tricking candidates into selecting predictive scaling when the question emphasizes real-time metric response.

127
MCQmedium

A cloud administrator needs to centralize logs from multiple AWS services, including VPC flow logs and application logs, to enable searching and querying. Which solution should be used?

A.AWS CloudTrail
B.Amazon S3 with Athena
C.AWS Config
D.Amazon CloudWatch Logs
AnswerD

Amazon CloudWatch Logs ingests VPC flow logs and application logs into log groups, then supports CloudWatch Logs Insights for searching and querying across them. This satisfies the centralisation requirement directly, since both log types converge in one service without additional infrastructure, unlike S3-based aggregation that lacks native querying.

Why this answer

Amazon CloudWatch Logs is the native centralized log management service that ingests logs from EC2, Lambda, VPC Flow Logs, CloudTrail, and application sources, and provides Logs Insights for searching and querying. It supports metric filters, alarms, and subscription filters for downstream processing, making it the correct choice for centralized search and query across multiple AWS services.

Exam trap

CV0-004 often tests the confusion between CloudTrail (API audit), AWS Config (configuration compliance), and CloudWatch Logs (operational log aggregation and search), tempting candidates to pick CloudTrail for log centralization.

How to eliminate wrong answers

Option A is wrong because AWS CloudTrail records API activity and management events for auditing, not application or VPC flow log content, and it is not a search/query engine for arbitrary logs. Option B is wrong because Amazon S3 with Athena can query logs stored in S3, but it requires you to first deliver logs to S3 and does not provide the centralized ingestion, real-time search, or native integration that CloudWatch Logs offers. Option C is wrong because AWS Config evaluates resource configuration compliance and does not centralize or search application or flow logs.

128
Multi-Selecthard

A cloud operations team manages a three-tier application on Google Cloud. After a deployment, users report intermittent 503 errors from the HTTP(S) load balancer, and backend health checks are flapping between healthy and unhealthy. The team suspects the backend instances are being overwhelmed during health check bursts. Which TWO actions should the team take to stabilize the health checks and reduce false failures? (Choose two.)

Select 2 answers
A.Increase the health check's check interval and timeout settings so probes are less frequent and tolerate brief slowdowns.
B.Reduce the number of backend instances in the instance group so each instance receives fewer health check probes.
C.Enable Cloud CDN on the backend service so cached responses absorb the health check traffic.
D.Switch the backend service to use a network load balancer instead of the HTTP(S) load balancer.
E.Configure a longer healthy threshold and unhealthy threshold on the health check to require more consecutive successes and failures.
AnswersA, E

Lengthening the interval and timeout gives backends more time to respond and reduces the probe rate that may be contributing to the flapping. It does not mask a truly failed instance, because consecutive failures are still required, but it prevents transient latency spikes from marking healthy instances as unhealthy during bursts.

Why this answer

Health check flapping during bursts is addressed by tuning the probe itself: a longer interval and timeout reduce probe intensity and tolerate brief slowdowns, while higher healthy and unhealthy thresholds require more consistent evidence before an instance's state changes. Together these settings distinguish transient latency from genuine failure. Caching, changing load balancer type, or removing instances do not reduce false health check failures.

Exam trap

The trap here is treating health check flapping as a capacity or caching problem, when the direct fix is adjusting probe interval, timeout, and consecutive-result thresholds.

129
MCQmedium

A cloud engineer is troubleshooting a network connectivity issue between two VPCs in AWS. To analyze traffic patterns and identify dropped packets, which feature should be enabled?

A.VPC Flow Logs
B.AWS CloudTrail
C.Amazon Inspector
D.AWS X-Ray
AnswerA

VPC Flow Logs capture IP traffic metadata for network interfaces, subnets or VPCs, recording accepted and rejected packets. Enabling them on the affected interfaces lets the engineer analyse traffic patterns and pinpoint where packets are dropped between the two VPCs.

Why this answer

VPC Flow Logs capture information about IP traffic going to and from network interfaces in a VPC, useful for troubleshooting connectivity and security issues.

130
MCQeasy

A cloud administrator is tasked with monitoring CPU utilization across a fleet of virtual machines. Which cloud service should be used to collect and visualize this metric?

A.Cloud monitoring service
B.Audit logging service
C.Configuration management service
D.Advisor or optimization service
AnswerA

A cloud monitoring service ingests metrics such as CPU utilisation from VM agents and hypervisor APIs, then stores and visualises them in dashboards. It satisfies the requirement to collect and visualise CPU metrics across the fleet, unlike compute or storage services that do not provide metric aggregation.

Why this answer

A cloud monitoring service is specifically designed to collect, aggregate, and visualize performance metrics like CPU utilization from virtual machines and other resources. It provides time-series data storage, dashboards, and alerting capabilities, making it the correct tool for this task. Other services focus on different operational aspects such as logging, configuration, or recommendations, not real-time metric collection and visualization.

Exam trap

CV0-004 often tests the distinction between monitoring (metrics) and logging (events), so candidates may confuse audit logging with performance monitoring, especially when both are used for operational visibility.

How to eliminate wrong answers

Option B is wrong because an audit logging service records API activity and user actions for compliance and security analysis, not performance metrics like CPU utilization. Option C is wrong because a configuration management service automates the deployment and management of resource configurations, but does not collect or visualize runtime performance data. Option D is wrong because an advisor or optimization service analyzes resource usage to provide recommendations, but it does not directly collect or visualize raw metrics; it relies on monitoring data.

131
MCQeasy

A company wants to track cloud spending by department and project. Which strategy should be implemented to enable cost attribution?

A.Use a single account for all workloads
B.Enable detailed billing reports
C.Implement a resource tagging strategy
D.Use AWS Organizations only
AnswerC

Tagging resources with department and project keys lets cost management tools group and filter spend along those dimensions. This enables accurate cost attribution, which untagged resources cannot support because billing data lacks the metadata needed to map charges to owners.

Why this answer

Resource tagging is the foundational mechanism for cost attribution in cloud environments. By applying consistent key-value tags (e.g., Department=Finance, Project=Alpha) to every resource, billing systems can group and filter costs along those dimensions. AWS Cost Explorer, Azure Cost Management, and GCP Billing all support grouping by tag, which directly answers the requirement to track spending by department and project.

Exam trap

CV0-004 often tests the misconception that enabling billing reports or Organizations alone provides cost attribution, when in reality tags are the prerequisite for any meaningful cost grouping.

How to eliminate wrong answers

Option A is wrong because a single account collapses all workloads into one billing boundary, making per-department or per-project attribution impossible without tags anyway. Option B is wrong because detailed billing reports only provide granular line-item data — they do not by themselves create the logical grouping needed for attribution. Option D is wrong because AWS Organizations provides account-level consolidated billing and governance, but without tags on resources, costs still cannot be split by department or project within an account.

132
MCQhard

A cloud administrator is managing a Microsoft Azure environment. The administrator needs to enforce a policy that prevents the creation of any Azure Storage account without HTTPS-only traffic enabled and without a minimum TLS version of 1.2. The policy must apply to all current and future subscriptions in the tenant and must be evaluated when resources are created or updated. Which Azure feature should the administrator use?

A.Azure Role-Based Access Control (RBAC)
B.Azure Blueprints
C.Azure Policy
D.Microsoft Defender for Cloud
AnswerC

Azure Policy is the governance service that evaluates resources against business rules and can deny noncompliant resource creation or updates. By assigning a built-in or custom policy definition that requires HTTPS-only traffic and a minimum TLS version, the administrator can enforce the requirement across all subscriptions in the tenant, including future ones, at deployment time.

Why this answer

Azure Policy is the correct choice because it evaluates resource properties during create and update operations and can deny noncompliant resources. Assigning a policy that requires HTTPS-only traffic and TLS 1.2 at a management group scope ensures the rule applies to all current and future subscriptions in the tenant, satisfying both the enforcement and scope requirements.

Exam trap

The trap here is confusing a security posture or reporting service, such as Microsoft Defender for Cloud, with an enforcement mechanism that can block noncompliant resource creation.

133
Multi-Selectmedium

A cloud administrator is setting up auto-scaling for a web application that uses an SQS queue for incoming requests. The administrator wants to scale the number of EC2 instances based on the queue depth. Which two metrics are appropriate for this auto-scaling policy? (Choose TWO.)

Select 2 answers
A.CPU utilization of instances
B.ApproximateNumberOfMessagesVisible (queue depth)
C.Memory utilization of instances
D.Network throughput
E.BacklogPerInstance (queue depth per instance)
AnswersB, E

ApproximateNumberOfMessagesVisible reports the count of messages awaiting retrieval, directly reflecting backlog depth. Scaling on this metric adds EC2 capacity precisely when consumer throughput lags behind incoming demand, satisfying the requirement to scale on queue depth rather than CPU or network statistics.

Why this answer

Option B, ApproximateNumberOfMessagesVisible (queue depth), is correct because it is the native CloudWatch metric that reports how many messages are available in the SQS queue, directly reflecting the incoming workload that the EC2 fleet must process. Option E, BacklogPerInstance (queue depth per instance), is correct because it is a custom metric that divides the queue backlog by the number of running instances, giving a per-instance workload signal that is ideal for target-tracking scaling policies on an SQS-backed web tier. Options A (CPU utilization) and C (memory utilization) are not appropriate here because the workload is driven by queue depth rather than instance-level compute or memory pressure, and memory utilization is not even a default CloudWatch EC2 metric.

Option D (network throughput) is also unsuitable because it measures data transfer volume, not the amount of pending work in the queue, so it would not reliably track the backlog the application must drain.

Exam trap

CV0-004 often tests the temptation to scale on CPU or memory for queue-based workloads, when the correct signal is queue depth or backlog per instance.

134
Multi-Selecthard

A company is experiencing intermittent performance issues in a microservices application. Which TWO tools can help diagnose latency problems through distributed tracing? (Choose TWO)

Select 2 answers
A.AWS CloudWatch Logs
B.Azure Monitor
C.Azure Application Insights
D.AWS CloudTrail
E.AWS X-Ray
AnswersC, E

Azure Application Insights satisfies the distributed tracing requirement by correlating requests across microservices through its telemetry model, using operation IDs to stitch spans into an end-to-end transaction view. This exposes per-hop latency, letting you pinpoint which service introduces delay during intermittent performance issues.

Why this answer

Azure Application Insights (C) is correct because it provides distributed tracing across microservices, correlating requests with dependency calls and showing end-to-end latency breakdowns via the Application Map and transaction diagnostics. AWS X-Ray (E) is correct because it natively performs distributed tracing for microservices, using trace IDs and segments/subsegments to visualize latency bottlenecks across services, including integrations with Lambda, API Gateway, and ECS. AWS CloudWatch Logs (A) only aggregates log data and does not by itself provide distributed trace correlation across services.

Azure Monitor (B) is a broader monitoring platform whose distributed tracing capability comes specifically through Application Insights, so it is not the precise tracing tool here. AWS CloudTrail (D) records API activity for auditing and governance, not request-level latency tracing.

Exam trap

CV0-004 often tests the distinction between monitoring/logging tools and true distributed tracing tools; candidates may incorrectly select CloudWatch Logs or Azure Monitor because they are familiar monitoring services.

135
MCQmedium

A cloud engineer is investigating intermittent latency in a three-tier application hosted in Google Cloud. The engineer suspects that a specific Compute Engine instance is experiencing packet loss to its database backend. The engineer needs to capture and analyze the traffic at the packet level on the instance without installing third-party agents on the instance and without disrupting production traffic. Which Google Cloud feature should the engineer use?

A.Cloud NAT logging
B.Firewall Rules Logging
C.Packet Mirroring
D.VPC Flow Logs
AnswerC

Packet Mirroring clones traffic from a specified instance or subnet and sends it to a collector instance for analysis. It operates at the VPC level, requires no agent on the monitored instance, and does not disrupt production traffic. This allows the engineer to capture and analyze packet-level details to diagnose the suspected packet loss.

Why this answer

Packet Mirroring is the correct choice because it clones traffic at the VPC level and forwards it to a collector without requiring an agent on the source instance and without affecting production traffic. This gives the engineer full packet-level visibility to analyze retransmissions, dropped packets, and TCP behavior between the instance and the database.

Exam trap

The trap here is assuming that VPC Flow Logs, which capture flow metadata, provide the same packet-level detail as an actual packet capture mechanism.

136
MCQmedium

A cloud administrator needs to detect unusual spikes in CPU usage across a fleet of EC2 instances. Which AWS service should be used to create an alarm that triggers when CPU utilization exceeds an expected baseline?

A.AWS Config
B.AWS CloudTrail
C.AWS CloudWatch Alarms with anomaly detection
D.AWS Systems Manager
AnswerC

CloudWatch anomaly detection builds a learned baseline from historical CPU patterns and alarms on deviations, catching unusual spikes rather than fixed thresholds. Static thresholds would either miss subtle spikes or fire constantly on normal variation.

Why this answer

Amazon CloudWatch Alarms supports anomaly detection bands, which use machine learning to establish a normal baseline for a metric such as CPUUtilization and then alarm when the metric falls outside the expected band. This is the correct service for detecting unusual spikes relative to a learned baseline across a fleet of EC2 instances.

Exam trap

CV0-004 often tests whether candidates pick a monitoring-adjacent service like CloudTrail or Config for metric-based alerting, confusing activity logging with performance monitoring.

How to eliminate wrong answers

Option A is wrong because AWS Config is a configuration compliance and recording service — it tracks resource configuration changes, not performance metrics like CPU utilization. Option B is wrong because AWS CloudTrail records API activity and management events, not runtime performance metrics. Option D is wrong because AWS Systems Manager is used for operational tasks such as patching, inventory, and run commands, not for creating metric-based alarms.

137
MCQmedium

A cloud administrator is responsible for a Microsoft Azure environment where several production virtual machines must be backed up nightly. The recovery requirements state that backups must be retained for 90 days, that individual files must be restorable without recovering the entire VM, and that the backup data must be encrypted at rest. Which Azure Backup configuration should the administrator implement?

A.Create a Recovery Services vault, enable Azure Backup for the VMs, and set a daily backup policy with 90-day retention.
B.Configure Azure Site Recovery replication with a 90-day retention policy.
C.Configure Azure Files share snapshots with a 90-day retention policy for the VM data.
D.Enable Azure Disk Encryption on each VM and schedule snapshots with a 90-day retention rule.
AnswerA

Azure Backup stores VM backups in a Recovery Services vault, which encrypts data at rest by default. The policy controls the backup schedule and retention, and file-level recovery is supported directly from the recovery point. This combination satisfies the nightly schedule, 90-day retention, file restore, and encryption requirements.

Why this answer

Azure Backup with a Recovery Services vault is the native solution for VM backup in Azure. The vault encrypts backup data at rest, the backup policy defines the nightly schedule and 90-day retention, and file-level recovery lets administrators restore individual files from a recovery point without recovering the entire VM, matching all three requirements in the scenario.

Exam trap

The trap here is confusing replication for disaster recovery, such as Azure Site Recovery, with point-in-time backup that supports file-level restore and long-term retention.

138
MCQeasy

A cloud engineer wants to view a dashboard showing cost breakdown by department. Which tool provides pre-built billing dashboards?

A.AWS CloudWatch
B.AWS Cost Explorer
C.AWS Trusted Advisor
D.AWS Config
AnswerB

AWS Cost Explorer provides pre-built dashboards that visualise cost and usage data, including breakdowns by dimension such as department when costs are tagged accordingly. This directly satisfies the requirement for an existing billing dashboard, unlike raw billing reports or custom-built tooling that would need manual configuration.

Why this answer

AWS Cost Explorer includes pre-built reports and dashboards that break down costs by dimensions such as service, linked account, and tag, which can represent departments. It is the native AWS tool for visualizing and analyzing billing data, including cost by department when tags are used.

Exam trap

CV0-004 often tests whether candidates confuse monitoring tools like CloudWatch with billing tools, or pick Trusted Advisor because it sounds like it would surface cost insights.

How to eliminate wrong answers

Option A is wrong because AWS CloudWatch is a monitoring service for metrics, logs, and alarms — it does not provide billing dashboards or cost breakdowns. Option C is wrong because AWS Trusted Advisor provides best-practice checks and recommendations, not cost breakdown dashboards by department. Option D is wrong because AWS Config records and evaluates resource configurations for compliance, not billing or cost data.

139
Multi-Selecthard

A company uses AWS and wants to implement a structured logging format to simplify querying and analysis of application logs. Which three best practices should be followed when implementing structured logging? (Choose THREE.)

Select 3 answers
A.Write logs in plain text to reduce storage costs
B.Include a unique request ID for each transaction
C.Use consistent key names across all services
D.Use JSON format for log entries
E.Embed binary data in log messages for performance
AnswersB, C, D

A unique request ID per transaction lets you correlate every log line belonging to one request across services, which is essential for tracing distributed calls. Without it, entries from concurrent requests interleave and become impossible to reconstruct during analysis.

Why this answer

Option B is correct because including a unique request ID for each transaction enables correlation of log entries across distributed services, making it possible to trace a single request through multiple components during querying and analysis. Option C is correct because using consistent key names across all services ensures that queries and dashboards work uniformly, avoiding the need to map different field names for the same data in tools like CloudWatch Logs Insights or Athena. Option D is correct because JSON is a structured, machine-readable format that supports native parsing and filtering of fields, which directly simplifies querying and analysis compared to unstructured text.

Option A is not appropriate because plain text logs are unstructured, defeating the purpose of structured logging and making querying harder, even if storage costs are lower. Option E is not appropriate because embedding binary data in log messages bloats log size, harms readability, and is not queryable, so it does not support structured logging best practices.

Exam trap

CV0-004 often tests whether candidates pick cost-saving or performance-sounding options like plain text or binary embedding, which contradict the goals of structured logging.

140
MCQeasy

A company wants to reduce cloud costs by identifying underutilized EC2 instances. Which AWS service provides rightsizing recommendations?

A.AWS Budgets
B.AWS Trusted Advisor
C.AWS Cost Explorer
D.AWS Compute Optimizer
AnswerD

AWS Compute Optimizer analyses CloudWatch metrics for EC2 instances and delivers rightsizing recommendations, directly satisfying the requirement to identify underutilised instances and cut cloud spend. It evaluates CPU, memory and network utilisation over time, unlike billing tools that only report cost.

Why this answer

AWS Compute Optimizer analyzes historical utilization metrics of EC2 instances and provides rightsizing recommendations to identify underutilized or overprovisioned instances. It uses machine learning to recommend optimal instance types based on CPU, memory, network, and disk usage, directly addressing the goal of reducing costs by identifying underutilized instances.

Exam trap

CV0-004 often tests the confusion between cost visualization tools (Cost Explorer, Budgets) and cost optimization tools (Compute Optimizer, Trusted Advisor), tricking candidates into choosing a tool that only reports costs rather than recommends rightsizing.

How to eliminate wrong answers

Option A is wrong because AWS Budgets is used to set custom cost and usage budgets and receive alerts when thresholds are exceeded; it does not provide rightsizing recommendations. Option B is wrong because AWS Trusted Advisor offers best-practice checks, including some cost optimization checks (e.g., low utilization EC2 instances), but it does not provide detailed rightsizing recommendations with specific instance type suggestions. Option C is wrong because AWS Cost Explorer visualizes and analyzes cost and usage data, but it does not generate rightsizing recommendations; it helps you understand spending patterns, not optimize instance types.

141
Multi-Selecthard

A cloud operations team is deploying a three-tier application across multiple availability zones. To meet a strict recovery time objective, they want the application to keep serving traffic if an entire availability zone becomes unavailable. Which TWO design actions should the team take? (Choose two.)

Select 2 answers
A.Increase the instance size to handle the full production load on a single instance.
B.Configure the database with a multi-AZ standby that can be promoted automatically.
C.Distribute application instances across at least two availability zones behind a load balancer.
D.Take nightly snapshots of the database volumes and store them in a separate region.
E.Enable termination protection on all production instances.
AnswersB, C

A multi-AZ database keeps a synchronized standby in a separate zone and promotes it automatically during a zone failure. This removes the need to restore from backup, keeping database downtime within the recovery time objective and allowing the application tier to reconnect with minimal delay.

Why this answer

High availability across zones requires both a resilient application tier and a resilient data tier. Running instances in multiple zones behind a load balancer keeps the application serving traffic, while a multi-AZ database with automatic failover keeps data available without a lengthy restore, together meeting the aggressive recovery time objective.

Exam trap

The trap here is treating backup and protection features, such as snapshots or termination protection, as substitutes for high availability.

142
MCQmedium

A cloud operations team supports a latency-sensitive application running on Amazon EC2 instances. Users in a remote region report that responses are slow even though the application's own metrics show normal processing times. The team wants to continuously measure the network path between the users' region and the application endpoint, capturing round-trip latency and packet loss without modifying the application. Which AWS service should they use?

A.Amazon CloudWatch Network Monitor.
B.AWS Network Manager with a global network configured.
C.VPC Flow Logs with a custom metric filter.
D.AWS CloudTrail with data events enabled on the load balancer.
AnswerA

CloudWatch Network Monitor continuously probes network paths between source and destination resources in different regions and reports round-trip latency and packet loss. It works without application changes, which fits the requirement to measure the user-to-endpoint path while leaving the workload untouched, making it the correct monitoring service here.

Why this answer

CloudWatch Network Monitor is purpose-built to probe paths between AWS and external or cross-region endpoints, reporting latency and packet loss continuously. Because it operates at the network layer and requires no agent or code change, it fits the scenario where application metrics look healthy but the user-perceived path is slow, allowing the team to correlate network degradation with the reported slowness.

Exam trap

The trap here is choosing VPC Flow Logs because they sound like network monitoring, when they actually record connection metadata rather than latency or loss measurements.

143
MCQeasy

An organization wants to reduce cloud costs by identifying underutilized EC2 instances. Which AWS service provides rightsizing recommendations?

A.AWS Budgets
B.AWS Compute Optimizer
C.AWS Trusted Advisor
D.AWS Cost Explorer
AnswerB

AWS Compute Optimizer analyses CloudWatch metrics and resource configuration to generate rightsizing recommendations for EC2 instances, identifying over-provisioned capacity. This directly satisfies the requirement to reduce costs by flagging underutilised instances, unlike billing or cost-explorer tools that report spend without recommending instance-size changes.

Why this answer

AWS Compute Optimizer analyzes CloudWatch metrics and resource configurations to generate rightsizing recommendations for EC2 instances, including whether instances are over-provisioned. It uses machine learning to compare your workload against historical patterns and provides specific instance type recommendations, directly addressing the goal of identifying underutilized EC2 instances.

Exam trap

CV0-004 often tests the confusion between cost visibility tools (Budgets, Cost Explorer) and cost optimization tools (Compute Optimizer, Trusted Advisor), so candidates must distinguish monitoring from rightsizing.

How to eliminate wrong answers

Option A is wrong because AWS Budgets only tracks spending against thresholds and sends alerts — it does not analyze instance utilization or recommend instance sizes. Option C is wrong because AWS Trusted Advisor offers a limited set of cost optimization checks (e.g., idle load balancers, low-utilization EC2) but does not provide detailed rightsizing recommendations with specific instance type alternatives. Option D is wrong because Cost Explorer visualizes and forecasts costs but does not analyze CPU, memory, or network utilization to recommend rightsizing.

144
MCQmedium

A cloud operations team manages a multi-tier web application on Google Cloud. The application logs are being written to Cloud Logging, and the team needs to be alerted whenever the number of HTTP 500 errors exceeds 50 in a 5-minute window. Which action should the team take to meet this requirement?

A.Enable Cloud Trace on the application and create an alerting policy that triggers when the error rate exceeds 50 per 5 minutes.
B.Create a log-based metric in Cloud Logging that counts HTTP 500 entries, then create a Cloud Monitoring alerting policy based on that metric with a threshold of 50 over 5 minutes.
C.Use Cloud Monitoring uptime checks to monitor the application endpoint and alert when the failure count exceeds 50 in 5 minutes.
D.Configure a Cloud Logging sink to Pub/Sub and create a Cloud Function that counts errors and sends an email when the count exceeds 50.
AnswerB

Log-based metrics in Cloud Logging convert log entries matching a filter into a numeric time series. Creating a metric that counts HTTP 500 entries, then attaching a Cloud Monitoring alerting policy with the specified threshold and window, directly satisfies the requirement. This is the standard Google Cloud pattern for alerting on log content.

Why this answer

The correct approach is to derive a metric from the logs using a log-based metric in Cloud Logging, then use Cloud Monitoring to alert on that metric. This natively supports counting specific log entries and applying a threshold over a time window, which matches the requirement exactly without custom code.

Exam trap

The trap here is assuming that Cloud Trace or uptime checks can alert on application error counts, when they actually measure latency or availability rather than log-derived error volume.

145
MCQmedium

A cloud operations team needs to ensure that all Amazon S3 buckets in their AWS account have server access logging enabled. They want to automatically detect and remediate any bucket that does not have logging enabled. Which combination of AWS services should they use?

A.Amazon GuardDuty with S3 protection and AWS Lambda remediation
B.Amazon Inspector with S3 assessment and AWS Systems Manager Automation
C.AWS CloudTrail with Amazon EventBridge and AWS Lambda to enable logging
D.AWS Config rule with automatic remediation using AWS Systems Manager Automation
AnswerD

AWS Config can evaluate S3 bucket configurations against a rule that checks if server access logging is enabled. When a bucket is non-compliant, Config can trigger automatic remediation using an SSM Automation document that enables logging. This provides continuous compliance and automatic correction, meeting the requirement.

Why this answer

The need is to detect and remediate S3 buckets without server access logging. AWS Config provides managed rules that can check for this configuration. When a bucket is non-compliant, Config can automatically run an SSM Automation document to enable logging.

This creates a continuous compliance loop with automatic remediation, which is the most direct and native solution.

Exam trap

The trap here is assuming that security services like GuardDuty or Inspector can enforce configuration compliance, when AWS Config is the service designed for configuration evaluation and remediation.

146
MCQmedium

A cloud operations team runs a three-tier web application on Amazon EC2 instances behind an Application Load Balancer. Users report intermittent 502 errors, and the operations team wants to identify whether the issue originates from unhealthy targets before the load balancer removes them. Which AWS feature should the team enable to actively probe target health at a configurable interval?

A.AWS CloudTrail data events on the target instances
B.VPC Flow Logs on the subnet hosting the targets
C.Application Load Balancer health checks with a shortened healthy and unhealthy threshold
D.Amazon Route 53 latency-based routing with failover records
AnswerC

ALB health checks periodically probe each registered target on a configured protocol, port, and path. Reducing healthy and unhealthy thresholds makes the load balancer react faster to failing targets, which directly addresses identifying unhealthy targets before they serve traffic. This is the native mechanism for detecting target health in an ALB and is the correct operational control in this scenario.

Why this answer

Application Load Balancer health checks are the built-in mechanism that actively probes each registered target and removes unhealthy ones from rotation. Tuning the healthy and unhealthy thresholds lets the team detect failing targets faster and correlate the 502 errors with backend health. Logging and DNS-based services operate at different layers and cannot actively determine target health behind an ALB.

Exam trap

The trap here is assuming that logging services like CloudTrail or Flow Logs perform active health probes, when only the load balancer's own health check mechanism evaluates target health.

147
MCQmedium

A cloud administrator needs to apply security patches to a fleet of EC2 instances running Windows Server. The patches must be applied during a maintenance window to minimize downtime. Which AWS service can automate patching?

A.AWS CloudFormation
B.AWS Systems Manager Patch Manager
C.AWS Config
D.Amazon Inspector
AnswerB

Patch Manager, part of AWS Systems Manager, applies OS and security patches to managed EC2 instances on a schedule you define. Configuring a maintenance window satisfies the low-downtime constraint, since patching runs automatically during the specified period rather than requiring manual intervention on each instance.

Why this answer

AWS Systems Manager Patch Manager automates the process of patching EC2 instances, including Windows Server, and supports maintenance windows to control when patches are applied. It can scan for missing patches and install them on a schedule, minimizing downtime.

Exam trap

CV0-004 often tests whether candidates confuse vulnerability assessment tools like Inspector with remediation tools like Patch Manager, or pick CloudFormation because it sounds like automation.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation is an infrastructure-as-code service for provisioning resources, not for applying OS patches. Option C is wrong because AWS Config evaluates resource compliance and configuration changes, but it does not install patches. Option D is wrong because Amazon Inspector assesses vulnerabilities and can identify missing patches, but it does not apply them.

148
MCQmedium

A cloud administrator needs to perform a disaster recovery test for a critical application running in a different AWS region. The RTO is 1 hour, and the RPO is 15 minutes. Which replication strategy should be used to meet the RPO?

A.Hourly snapshot-based replication
B.Daily snapshot-based replication
C.Cross-region replication with eventual consistency
D.Continuous replication
AnswerD

Continuous replication copies every write to the DR region, giving an RPO measured in seconds or minutes, comfortably inside the 15-minute target. Snapshot or batch approaches would leave larger gaps between recovery points, breaching the stated RPO.

Why this answer

Continuous replication replicates data continuously, so the recovery point objective (RPO) — the maximum acceptable data loss — can be as low as seconds or minutes, meeting the 15-minute requirement. Snapshot-based approaches at hourly or daily intervals cannot meet a 15-minute RPO.

Exam trap

CV0-004 often tests whether candidates match snapshot frequency to RPO incorrectly, or pick 'eventual consistency' as a replication strategy when the question demands a specific RPO guarantee.

How to eliminate wrong answers

Option A is wrong because hourly snapshots mean up to 60 minutes of data loss, which exceeds the 15-minute RPO. Option B is wrong because daily snapshots mean up to 24 hours of data loss, far exceeding the RPO. Option C is wrong because cross-region replication with eventual consistency does not guarantee a specific RPO and is not a defined replication strategy for meeting a 15-minute RPO in this context.

149
MCQeasy

A cloud administrator manages a fleet of Amazon EC2 instances that must receive operating system patches on a defined schedule. The administrator wants to automate patching, control the maintenance window, and receive compliance reports showing which instances are missing patches. Which AWS service should the administrator use?

A.AWS Config with managed rules for patch compliance
B.Amazon Inspector with automated assessment schedules
C.AWS Trusted Advisor with security category checks
D.AWS Systems Manager Patch Manager
AnswerD

Patch Manager, part of AWS Systems Manager, automates patching of EC2 instances and on-premises managed nodes using patch baselines, maintenance windows, and compliance reporting. It supports scheduled scans and installs, and its compliance dashboard shows which nodes are missing patches. This directly satisfies the requirement for automated, scheduled patching with compliance visibility across the fleet.

Why this answer

AWS Systems Manager Patch Manager is built to automate operating system patching across EC2 and hybrid nodes. It combines patch baselines, maintenance windows, and compliance reporting so the administrator can schedule installs and prove which instances are compliant. Other services either assess configuration or detect vulnerabilities but do not install patches or provide the required scheduling and compliance workflow.

Exam trap

The trap here is confusing vulnerability assessment or configuration tracking services with the service that actually installs operating system patches on a schedule.

150
MCQhard

A cloud administrator is troubleshooting a performance issue where an application occasionally experiences high latency. The application runs on AWS and uses EC2, ELB, and RDS. Which combination of tools would best help trace the request flow and identify the bottleneck?

A.AWS X-Ray and VPC Flow Logs
B.AWS Trusted Advisor and AWS Personal Health Dashboard
C.Amazon CloudWatch Logs and AWS Shield
D.AWS CloudTrail and AWS Config
AnswerA

X-Ray traces requests across EC2, ELB and RDS, exposing per-segment latency so the bottleneck service is identified. VPC Flow Logs complement this by revealing network-level drops or rejects along the path that tracing alone may not show.

Why this answer

AWS X-Ray traces requests through the application, including calls to downstream services like RDS, and VPC Flow Logs capture IP traffic to and from network interfaces, helping identify network-level bottlenecks. Together, they provide end-to-end visibility from the request entry point to the database and network layer. This combination is best for tracing request flow and pinpointing latency issues.

Exam trap

CV0-004 often tests the confusion between auditing tools (CloudTrail, Config) and performance tracing tools (X-Ray, Flow Logs), leading candidates to choose options that provide compliance or configuration data instead of latency insights.

How to eliminate wrong answers

Option B is wrong because Trusted Advisor provides best practice checks and Personal Health Dashboard shows AWS service health, neither of which trace request flow or identify application bottlenecks. Option C is wrong because CloudWatch Logs can capture application logs but does not trace requests across services, and AWS Shield is for DDoS protection, not performance troubleshooting. Option D is wrong because CloudTrail records API activity for auditing, and AWS Config tracks resource configurations, neither of which helps trace request flow or latency.

← PreviousPage 2 of 3 · 155 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Operations and Support questions.