Courseiva

CV0-004 · domain

scenario questions

Practise CompTIA Cloud+ CV0-004 scenario questions practice questions — original exam-style scenarios with answer choices, explanations, and analysis of common mistakes.

834 questions219 easy375 medium240 hard

Focused practice

Practice scenario questions questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about scenario questions

scenario questions questions test whether you can apply the concept in context, not just recognise a definition.

How the topic appears in realistic exam-style scenarios.

Which detail in the question changes the correct answer.

How to eliminate plausible but wrong options.

How to connect the question back to the wider exam objective.

Watch out for

Common scenario questions exam traps

  • ▸Answering from memory before reading the full scenario.
  • ▸Missing a constraint such as cost, availability, security, scope or command context.
  • ▸Choosing a broad answer when the question asks for the most specific fix.
  • ▸Ignoring why the wrong options are tempting.

Question index

All scenario questions questions (834)

Click any question to see the full explanation, or start a practice session above.

1

A company uses a cloud-based load balancer to distribute traffic to web servers. Recently, a new security policy was applied that restricts traffic to certain geographic regions. Users from an allowed region report they cannot access the website. The load balancer status shows health checks are passing. What should the administrator check?

Medium
2

A cloud administrator is configuring a web application hosted on a public cloud VM. The application must be accessible over HTTPS, and the administrator needs to ensure that all traffic between the client and the server is encrypted. The cloud provider offers a managed certificate service. Which of the following is the BEST practice for securing the application?

Medium
3

A company is migrating its on-premises database to a cloud-managed database service. The database contains sensitive financial data. Which of the following is the MOST important security configuration to implement after migration?

Easy
4

A company is migrating a legacy application to the cloud. The application uses a relational database and requires strong consistency and ACID transactions. Which cloud service model is most appropriate?

Easy
5

A cloud architect is designing a solution that requires a shared, POSIX-compliant file system that can be mounted concurrently by hundreds of Linux EC2 instances across multiple Availability Zones in the same AWS Region. The workload is read-heavy, and the file system must scale storage capacity automatically as data grows. Which AWS service should the architect choose?

Medium
6

Which THREE are common reasons why a cloud database instance may become unreachable?

Hard
7

A cloud administrator is configuring cost management for a multi-account cloud environment. The company wants to allocate costs by department and project. Which TWO steps should the administrator take to achieve this? (Choose two.)

Medium
8

A cloud engineer is troubleshooting a connectivity issue between two virtual networks in different regions. The engineer has verified that the virtual networks are peered and the routing tables are correct. Which of the following is the MOST likely cause of the issue?

Medium
9

Which of the following is a stateless network access control that requires explicit allow rules for both inbound and outbound traffic?

Easy
10

A cloud operations team is investigating suspicious activity in a production subscription. Logs show that a service principal authenticated successfully from an unexpected country and then enumerated storage accounts. The team needs to shorten the window in which a stolen credential remains usable and receive an alert when anomalous sign-ins occur. Which combination of controls should the team prioritize?

Hard
11

A cloud administrator needs to audit all API calls made in a GCP project for compliance purposes. Which service should be enabled to log these actions?

Medium
12

A cloud engineer is implementing a tagging strategy for cost allocation. Which tags should be applied to resources to track costs by business unit and environment?

Easy
13

A cloud architect is designing a stateless containerized workload that must remain available even if an entire data center fails. The workload has no persistent local state and must be able to scale horizontally across regions. Which design decision BEST meets these requirements?

Medium
14

Arrange the steps to implement a cloud security group that allows only specific IPs to access an application.

Medium
15

An organization uses AWS CloudFormation to deploy resources across multiple AWS accounts. They need to manage a common set of resources in several accounts from a single template. Which CloudFormation feature should they use?

Medium
16

A company is deploying a new application on AWS and needs to ensure that the infrastructure is defined as code. The team wants to use AWS CloudFormation to provision resources. They require that the template can be reused across multiple environments (dev, test, prod) with different configurations, such as instance types and subnet IDs. The team also needs to ensure that changes to the infrastructure are applied in a controlled manner. Which two features should the team use to meet these requirements? (Choose two.)

Hard
17

A company runs a stateless web application on auto-scaling EC2 instances behind an Application Load Balancer. The application experiences sudden traffic spikes. Which scaling approach will handle the spikes most efficiently while minimizing cost?

Hard
18

Which TWO of the following are best practices for securing access to a cloud management console?

Easy
19

An organization is subject to PCI DSS compliance and must demonstrate that it is meeting security requirements. Which cloud service can aggregate compliance findings and provide a dashboard?

Medium
20

A cloud engineer needs to store database backups that must be retained for seven years. The backups are rarely accessed. Which storage type is most cost-effective for this use case?

Medium
21

A cloud operations team manages a containerized microservices application running on an Amazon EKS cluster. During peak hours, the team observes that pods are frequently being terminated and restarted, and node CPU utilization is consistently above 90 percent. The team wants to automatically scale the number of pods based on CPU utilization while ensuring the cluster has enough nodes to schedule the pods. Which combination of actions should the team take to meet these requirements?

Medium
22

Sequence the steps to set up a cloud storage bucket with versioning and lifecycle policies.

Medium
23

A healthcare company runs a patient portal on virtual machines in a single on-premises datacenter. Regulatory requirements mandate that data must remain on-premises, but the company wants to burst to a public cloud during seasonal peaks and maintain a consistent operational model. The architect must design a hybrid solution that supports workload portability and centralized identity. Which approach BEST meets these requirements?

Hard
24

A cloud operations team is responsible for a multi-tier application on AWS. They need to improve observability by correlating metrics, logs, and traces to diagnose performance issues across services. The team wants to use AWS services that natively support this correlation. Which TWO actions should the team take? (Choose two.)

Hard
25

A company uses Google Cloud Platform and wants to enforce that all Compute Engine instances use a specific Customer-Managed Encryption Key (CMEK) for disk encryption. Which GCP service should be used to enforce this policy?

Hard
26

Refer to the exhibit. A cloud administrator runs the command to inspect an instance and notices that it is running, but the web application hosted on it is unreachable from the internet. The instance is in a public subnet with an internet gateway attached to the VPC. Which of the following is the most likely cause?

Easy
27

A cloud engineer is troubleshooting a performance issue in a microservices application. Which THREE tools can help with distributed tracing and latency diagnosis?

Hard
28

A cloud administrator needs to monitor CPU utilization for a fleet of EC2 instances and receive notifications when utilization exceeds 80%. Which AWS service should be used to create a metric alarm that triggers an SNS notification?

Easy
29

Match each storage type to its characteristic.

Medium
30

A cloud administrator is troubleshooting an issue where a user in the finance department cannot access a critical application hosted on a private cloud. The user can access other applications in the same subnet. The security team recently implemented a new network security policy. Which of the following is MOST likely causing the issue?

Medium
31

A cloud engineer receives an alert that the root filesystem (/) is at 93% usage. The /data volume has plenty of free space. The application stores logs in /var/log/app/ on the root filesystem. Which of the following is the BEST long-term solution?

Medium
32

A cloud administrator needs to automate the process of patching multiple virtual machines in a private cloud. Which of the following is the best tool for this purpose?

Easy
33

A company is deploying a web application on AWS using an Application Load Balancer (ALB) and an Auto Scaling group. The application must handle sudden traffic spikes without manual intervention. The engineer needs to configure the Auto Scaling group to scale based on the number of requests per target. Which CloudWatch metric should be used as the basis for the scaling policy?

Medium
34

A financial services firm runs a latency-sensitive trading application in a public cloud. The security team requires that traffic between the application tier and the database tier never traverse the public internet, that both tiers reside in the same virtual network, and that access to the database be restricted to specific application subnet addresses. Which combination of cloud networking controls should the architect implement?

Hard
35

Which cloud characteristic allows a user to provision additional resources automatically without requiring human intervention?

Easy
36

A company runs a stateless web application on virtual machines. To handle increased traffic, they add more virtual machines and distribute incoming requests among them. What is this scaling method called?

Medium
37

A cloud architect is designing a disaster recovery plan. The application requires a Recovery Time Objective (RTO) of 15 minutes and a Recovery Point Objective (RPO) of 1 hour. Which strategy best meets these requirements?

Medium
38

A cloud engineer is designing a disaster recovery plan with an RTO of 2 hours and RPO of 15 minutes. Which strategy best meets these requirements?

Medium
39

A cloud database cluster is experiencing replication lag. The primary node shows high write activity, and the replicas are on different availability zones. Which of the following is the most likely cause?

Hard
40

A hybrid cloud deployment connects an on-premises data center to a public cloud. Which TWO components are typically required to establish this connectivity? (Select TWO.)

Easy
41

A cloud architect is designing a multi-tier application on a public cloud. To minimize costs while maintaining performance for variable workloads, the architect decides to use a mix of reserved and spot instances. Which design principle is being applied?

Medium
42

A company is considering using a public cloud provider. Which TWO characteristics are typical of a public cloud deployment? (Select TWO.)

Easy
43

A cloud architect is designing a disaster recovery plan for a critical application. Which TWO metrics should be defined to establish recovery objectives?

Medium
44

Sequence the steps to configure a cloud monitoring alert for high memory usage on a virtual machine.

Medium
45

Which TWO steps should be performed to ensure that a new cloud user has only the minimum required permissions to perform their job? (Choose two.)

Easy
46

A cloud administrator is troubleshooting why a newly launched VM did not complete its initialization. According to the exhibit, what is the most likely cause?

Hard
47

A web application is deployed across multiple availability zones behind a load balancer. The administrator notices that all traffic is being routed to instances in only one availability zone, causing performance issues. The load balancer is configured to distribute traffic across all zones evenly. What is the most likely cause?

Hard
48

A cloud administrator is troubleshooting a failed deployment of a new application version using a continuous integration/continuous deployment (CI/CD) pipeline. The pipeline fails at the 'test' stage. What is the first step the administrator should take?

Easy
49

A company uses AWS CloudFormation to manage infrastructure. The operations team needs to be alerted when a stack update fails. Which TWO methods can be used to send notifications? (Choose two.)

Easy
50

A cloud administrator notices that a virtual machine in a public cloud is running slower than expected. The VM is part of a production web application. The administrator has verified that the VM's CPU and memory utilization are below 50%. What should the administrator check next?

Easy
51

A DevOps team is implementing a CI/CD pipeline using Jenkins. They want to ensure that code is automatically built, tested, and deployed to a staging environment before manual approval for production. Which stage should include the deployment to staging?

Medium
52

Which THREE design principles are fundamental to building a highly available cloud architecture?

Medium
53

A cloud architect is designing a microservices-based application that requires inter-service communication. The services must be loosely coupled, and the architecture must handle service failures gracefully. Which communication pattern is most appropriate?

Hard
54

A cloud engineer is configuring a web application that must comply with PCI DSS. The application runs on virtual machines in a public cloud. Which of the following security responsibilities falls under the customer's scope according to the shared responsibility model?

Medium
55

A cloud security team is implementing a zero-trust security model for a microservices application deployed on Azure Kubernetes Service (AKS). The team needs to ensure that all service-to-service communication is authenticated and encrypted, and that access policies are enforced based on service identity rather than network location. Which TWO components should the team implement to achieve these goals? (Choose two.)

Hard
56

A cloud administrator is setting up monitoring for a web application. The application must be highly available across multiple availability zones. Which of the following metrics should be monitored to ensure that the application meets its service level agreement (SLA) for uptime?

Easy
57

A company is migrating on-premises workloads to a public cloud. The disaster recovery plan requires an RTO of 15 minutes and an RPO of 5 minutes. Which replication strategy should be used for a critical database?

Hard
58

A multinational company uses Google Cloud and needs to ensure that its data cannot be exfiltrated to unauthorized networks even if an attacker obtains valid IAM credentials. The security team wants to define a boundary around specific projects and restrict access to only approved VPC networks and services. Which GCP feature should they implement?

Hard
59

Which of the following is a best practice for managing secrets in cloud applications?

Easy
60

A cloud administrator needs to monitor CPU utilization of a group of virtual machines and automatically add more instances when utilization exceeds 80% for 5 minutes. Which cloud service should the administrator use to define this scaling policy?

Easy
61

An organization uses AWS and wants to control inbound traffic to its EC2 instances. They need a solution that automatically allows response traffic for any permitted inbound request. Which of the following should they use?

Hard
62

A cloud administrator is deploying a containerized workload to Google Kubernetes Engine. The workload must automatically scale based on the number of incoming HTTP requests per second rather than CPU utilization. Which GKE feature should the administrator configure to meet this requirement?

Medium
63

A financial services company is subject to strict compliance requirements. They need to ensure that all cloud storage objects are written to a write-once-read-many (WORM) state for a defined retention period. Which feature should be enabled?

Hard
64

A cloud operations team is reviewing the shared responsibility model for a SaaS customer relationship management application. The team wants to document which security tasks remain the customer's responsibility. Which task is the customer responsible for under the shared responsibility model?

Easy
65

A cloud engineer is troubleshooting a containerized application deployed on a managed Kubernetes service. Pods are repeatedly failing to start with the status 'CrashLoopBackOff'. The engineer has confirmed that the container image exists and the pod specification is valid. Which command should the engineer use to view the most recent logs from the previous instance of the crashing container?

Hard
66

A company needs to deploy a web application quickly and reliably. Which approach is best?

Easy
67

A financial services firm stores regulated customer records in an Amazon S3 bucket. Auditors require that every object be encrypted at rest with a customer-managed key, that key usage be logged, and that the firm be able to revoke access to the data by disabling the key. Which configuration meets these requirements?

Hard
68

A company is migrating a legacy application to the cloud. The application uses a fixed IP address that is hard-coded in several clients. The company needs to ensure the IP address remains the same even if the underlying virtual machine is replaced. Which cloud networking feature should be used?

Easy
69

An organization is designing a disaster recovery plan with a Recovery Time Objective (RTO) of 4 hours and a Recovery Point Objective (RPO) of 1 hour. Which disaster recovery strategy best meets these requirements while minimizing cost?

Medium
70

A company wants to reduce costs by identifying underutilized EC2 instances and receiving recommendations to downsize them. Which AWS service provides rightsizing recommendations based on historical utilization metrics?

Medium
71

A multinational enterprise uses Amazon Route 53 for public DNS. A recent incident showed that an attacker changed a registrar's nameserver delegation and redirected traffic to a malicious site. The security team wants to detect unauthorized changes to DNS records and receive alerts when records are modified outside the change-management process. Which combination should the team implement?

Hard
72

A company is deploying a web application on GCP and needs to protect against OWASP Top 10 threats and DDoS attacks. Which THREE services should be combined to provide comprehensive protection?

Hard
73

An administrator is configuring a backup policy for a critical application database. The policy must allow point-in-time recovery up to the last 5 minutes. The database is updated continuously throughout the day. Which of the following backup strategies BEST meets the requirement?

Easy
74

A cloud engineer is deploying a web application that requires SSL termination and content-based routing. Which type of load balancer should be used?

Medium
75

An organization requires that all cloud resources be tagged with the cost center and environment (e.g., production, development). A compliance checker runs weekly to report untagged resources. The cloud administrator notices that newly created resources are often missing tags. What is the most effective long-term solution?

Easy
76

A cloud engineer is designing a microservices architecture on AWS. The services must communicate asynchronously and decouple producers from consumers. The engineer needs a fully managed message queuing service that supports dead-letter queues and message retention up to 14 days. Which AWS service should be used?

Medium
77

A cloud administrator manages a fleet of Amazon EC2 instances hosting a stateless web tier. The security team requires that any administrative SSH access is logged to a tamper-evident, centralized location, and that the private keys never leave a hardware device. Which approach should the administrator implement?

Medium
78

A cloud administrator is troubleshooting a database performance issue in a cloud environment. The database is hosted on a virtual machine with a high-performance SSD. Users report slow query responses. Monitoring shows high disk I/O wait and low CPU utilization. Which action should the administrator take to improve performance?

Hard
79

A cloud architect is designing a web application that must remain available during a full region outage. They plan to deploy identical resources in two separate geographical regions. Which high availability architecture is described?

Medium
80

A cloud administrator is deploying a new application to a Kubernetes cluster using a Deployment manifest. The application requires persistent storage that must survive pod restarts and be accessible by a single pod at a time. Which Kubernetes resource should be used to define the storage?

Easy
81

A cloud operations team runs a three-tier application on Google Cloud and wants to reduce the mean time to recovery for incidents. They want automated actions to run when a Cloud Monitoring alert fires, and they want to capture the exact configuration state at the moment of the incident for later analysis. Which TWO approaches should the team implement? (Choose two.)

Medium
82

Which THREE of the following are best practices for deploying applications in a cloud environment? (Choose three.)

Medium
83

A company's cloud environment uses a shared responsibility model. The security team notices that a data breach occurred due to misconfigured storage buckets in the public cloud. Which party is primarily responsible for this misconfiguration according to the shared responsibility model?

Medium
84

A cloud administrator is responsible for a production account and needs to ensure that an Amazon S3 bucket containing sensitive data cannot be made public, even by an administrator. The administrator wants a preventive control that blocks public access at the bucket and account level. Which action should the administrator take?

Medium
85

A cloud application is experiencing intermittent high latency. The operations team has enabled distributed tracing using AWS X-Ray but is unable to pinpoint the source. Which additional step should the team take to identify the root cause of the latency?

Medium
86

A cloud administrator manages a hybrid cloud environment where on-premises servers connect to a VPC in AWS via a VPN connection. The on-premises network uses IP range 10.0.0.0/16. The VPC uses 172.16.0.0/16. The VPN is established and the tunnel status is UP. However, on-premises hosts cannot ping EC2 instances in the VPC. The administrator logs into an EC2 instance and can ping the on-premises VPN gateway IP. The security groups and network ACLs are configured to allow all traffic. The route tables in the VPC have a route to the on-premises network via the virtual private gateway. The on-premises firewall logs show that packets from the VPC are being dropped. What is the most likely cause?

Medium
87

A company uses a cloud storage service with versioning enabled. An employee accidentally deleted a critical file. The administrator attempts to restore the file from the version history, but the file does not appear in the list of versions. What is the most likely reason?

Hard
88

A cloud engineer is responsible for a Kubernetes cluster on AWS EKS. The cluster runs a stateful application that requires persistent storage. The engineer must ensure that storage volumes are automatically provisioned when persistent volume claims are created, and that the storage remains available if the pod is rescheduled to a different node. Which solution should the engineer implement?

Hard
89

Which of the following is a key benefit of using object storage like Amazon S3 over block storage?

Easy
90

A cloud engineer needs to ensure that an auto-scaling group does not launch new instances immediately after a scale-in event to allow metrics to stabilize. Which feature should they configure?

Hard
91

A cloud administrator receives an alert that a virtual machine (VM) is unresponsive. The VM is hosted on a hypervisor that shows high CPU ready time. Which of the following is the most likely cause?

Medium
92

A cloud administrator is configuring auto-scaling for a batch processing application that uses an SQS queue. The number of jobs varies unpredictably. Which metric is most appropriate for scaling the worker instances?

Hard
93

A cloud administrator is responsible for ensuring the availability of a critical application that runs on a virtual machine. The administrator needs to implement a solution that can automatically restart the virtual machine if it becomes unresponsive due to an operating system crash. Which of the following should the administrator configure?

Hard
94

A cloud engineer is writing a Terraform configuration to provision an AWS EC2 instance. They need to pass the AMI ID as a variable to make the configuration reusable. Which Terraform block should be used to define the variable?

Easy
95

A healthcare company must ensure that patient records stored in a public cloud are encrypted at rest and that the company alone controls the keys used for encryption, including the ability to revoke access immediately if an employee leaves. Which key management approach BEST satisfies these requirements?

Medium
96

A cloud team is planning a disaster recovery drill for their application running in a public cloud. They want to validate that the recovery process meets the defined RTO and RPO. Which THREE activities should be included in the DR drill? (Select THREE.)

Hard
97

A cloud engineer is deploying a containerized application using Kubernetes. The application consists of a frontend, a backend API, and a database. The engineer needs to ensure that the backend API can be reached by the frontend but not from outside the cluster. Which Kubernetes resource should the engineer use to expose the backend API?

Medium
98

A developer wants to deploy an application using Azure Bicep. What is a key benefit of using Bicep over ARM templates?

Easy
99

A cloud operations team runs a containerized payroll application on Amazon EKS. Compliance requires that the application pod retrieve database credentials at runtime without embedding them in the container image, and that the credentials be rotated automatically every 30 days. Which approach BEST meets these requirements?

Medium
100

A company is migrating a legacy application to Google Cloud. The application requires a relational database with automatic failover and replication across multiple zones within a region. Which Google Cloud service should the company use?

Easy
101

A cloud architect is designing a VPC for a three-tier web application. The web servers must be accessible from the internet, the application servers should only be reachable from the web tier, and the database servers should not have any public IP addresses and should be isolated. Which subnet design meets these requirements?

Hard
102

Which THREE of the following are common causes of cloud resource provisioning failures?

Medium
103

A DevOps team is deploying containerized applications on Kubernetes. They want to ensure containers do not run with root privileges and that host filesystem access is restricted. Which Kubernetes feature should they use?

Medium
104

A cloud engineer is deploying a containerized workload to a Kubernetes cluster running in a public cloud. The security team requires that the application pods never use long-lived static credentials to access the cloud provider's object storage service. The cluster already runs an OpenID Connect (OIDC) identity provider that the cloud provider trusts. Which approach should the engineer implement to meet this requirement?

Medium
105

A company uses Azure AD for identity federation with an on-premises Active Directory. They want to enable single sign-on (SSO) for cloud applications using an open standard. Which protocol should they use?

Hard
106

A financial services company runs a containerized payment application on Google Kubernetes Engine (GKE). A compliance auditor requires that all container images deployed to the cluster be cryptographically verified for integrity and provenance before admission. The security team wants to enforce this at the cluster level without modifying each application's deployment pipeline. Which GKE feature should they implement?

Medium
107

Which TWO characteristics are essential for a cloud service to be considered as a true Infrastructure as a Service (IaaS) offering?

Easy
108

A cloud administrator is configuring a new virtual private cloud (VPC) and needs to ensure that traffic between web servers and database servers is restricted to only the necessary ports. Which security approach should the administrator implement?

Medium
109

A company deploys a stateless web application across two AWS Availability Zones behind a load balancer. This design primarily improves which characteristic?

Medium
110

A cloud engineer is configuring object storage for a media company that stores video archives accessed a few times per year but must retain them for seven years for compliance. Retrieval latency of several hours is acceptable, and cost must be minimized. Which storage tier characteristic should the engineer select?

Easy
111

A cloud operations team is implementing a tagging strategy for cost attribution. They need to track costs by environment (dev, test, prod), project, and team. Which approach should they use?

Medium
112

A cloud architect is designing a DDoS protection strategy for a web application hosted on AWS. The application uses an Application Load Balancer (ALB). Which service provides automatic, always-on DDoS protection at no additional cost?

Hard
113

A company wants to migrate its on-premises workloads to the cloud but must keep sensitive customer data on-premises due to regulatory compliance. Which cloud deployment model should they use?

Easy
114

A cloud administrator needs to transfer 50 TB of data from an on-premises NAS to Amazon S3. The office has limited bandwidth (50 Mbps). Which service is most suitable for this offline transfer?

Easy
115

Which TWO metrics should be monitored to determine if a cloud database is experiencing a memory bottleneck?

Medium
116

A company uses AWS and wants to implement structured logging for their applications to improve queryability. Which THREE practices should they follow? (Select THREE.)

Hard
117

A company uses GitLab CI for its CI/CD pipeline. The pipeline includes a 'deploy' job that runs only when a tag is pushed. Which GitLab CI keyword should be used to control job execution based on tags?

Medium
118

A company is designing a disaster recovery plan for a critical database that requires a recovery point objective (RPO) of 1 minute and a recovery time objective (RTO) of 15 minutes. The database runs on a cloud virtual machine. Which backup strategy should the administrator implement to meet these requirements?

Easy
119

A user reports that they cannot connect to a RDS database instance from their application. The security group for the RDS instance allows inbound traffic on port 3306 from the application server's security group. What should the administrator check NEXT?

Easy
120

A company wants to migrate its on-premises virtualized workloads to the cloud while maintaining control over the operating system and middleware. Which cloud service model should they choose?

Easy
121

A cloud administrator is troubleshooting a network connectivity issue between two VPCs connected via a VPC peering connection. The administrator has verified that the route tables are correct and that the security groups allow traffic. However, instances in VPC A cannot ping instances in VPC B. Which TWO of the following could be causing the issue? (Choose TWO.)

Hard
122

A cloud architect is designing a multi-tier web application that must handle sudden traffic spikes. The application layer is stateless, and the database layer is read-heavy with occasional writes. Which design best meets the requirement for elasticity and cost efficiency?

Medium
123

A cloud engineer is deploying a containerized application on Amazon ECS using the Fargate launch type. The application requires persistent storage for a database container. The engineer needs to ensure that the data persists even if the task is stopped and restarted. Which storage option should the engineer use?

Medium
124

A cloud operations team deploys a containerized workload to a Kubernetes cluster managed by Amazon EKS. The application pods intermittently fail during peak traffic hours, and the team suspects that the pods are being terminated because they exceed their configured resource limits. Which action should the team take FIRST to confirm this suspicion?

Medium
125

A cloud administrator is deploying a new Amazon EC2 instance that must run a custom application. The application requires a specific IAM role to access an S3 bucket. The administrator wants to avoid embedding AWS credentials in the instance. What should the administrator do?

Medium
126

A company is designing a hybrid cloud architecture connecting their on-premises data center to AWS. Which TWO options provide dedicated, private network connectivity? (Select TWO.)

Medium
127

A security engineer is reviewing IAM policies and notices a policy that allows all actions on all resources for a user. Which principle of security is being violated?

Medium
128

A cloud architect is designing identity and access management (IAM) for a multi-cloud environment. The architect wants to enforce least privilege and support federation with an on-premises Active Directory. Which TWO of the following should be implemented? (Select TWO).

Easy
129

A healthcare company runs a web application on Google Cloud. A security analyst notices that attackers are submitting crafted SQL statements through the application's search form and reading data from the backend database. The company wants to block these requests before they reach the application servers while keeping false positives low for legitimate search traffic. Which service should be implemented?

Easy
130

Which TWO of the following are characteristics of a hybrid cloud deployment? (Select exactly two.)

Easy
131

A cloud administrator is troubleshooting a performance issue in a virtualized environment. Which TWO metrics should the administrator monitor to identify CPU contention? (Choose two.)

Medium
132

A company wants to deploy a Kubernetes application across multiple AWS accounts using a single set of manifests. The team needs to manage the deployment centrally while allowing each account to have its own configuration values (e.g., environment-specific variables). Which approach should the team use?

Medium
133

A company runs a critical e-commerce application on a cloud platform. The architecture includes a load balancer in front of an auto scaling group of compute instances across two availability zones. The instances are in a private subnet and use a NAT gateway for outbound internet access. The application stores session data in a managed Redis cache cluster. During a flash sale, users report that the site is extremely slow and some requests time out. Monitoring shows the load balancer's latency metric is high, and the number of healthy hosts fluctuates. The CPU utilization on the compute instances averages 60% and memory averages 70%. The Redis cluster's CPU utilization is 90%, and its memory usage is 95%. The NAT gateway's metrics show high BytesOutToSource but no errors. Which of the following is the most likely cause of the performance issue?

Hard
134

A cloud architect is designing a disaster recovery plan for a critical application with an RTO of 15 minutes and an RPO of 1 minute. The application runs on AWS EC2 instances with data stored on EBS volumes. Which replication strategy best meets these requirements?

Hard
135

A cloud security team is reviewing audit logs and notices that a service account has been used to launch several high-risk API calls that are not part of its normal behavior. Which security control should be implemented to detect such anomalies in real time?

Hard
136

An organization uses CloudFormation to manage infrastructure across multiple AWS accounts. The team wants to deploy a common set of resources, such as VPCs and security groups, to all accounts in a consistent manner. Which CloudFormation feature should they use?

Medium
137

A cloud engineer is deploying a three-tier web application using AWS CloudFormation. The application requires a relational database that must be encrypted at rest and support automated backups. The engineer wants to minimize management overhead. Which AWS CloudFormation resource should be used for the database tier?

Medium
138

A DevOps team is deploying a new version of a microservice to a Kubernetes cluster on AWS. They want to minimize the risk of introducing errors by gradually shifting traffic to the new version while monitoring key metrics. They also need the ability to automatically roll back if the new version does not perform well. Which deployment strategy should they use?

Hard
139

A cloud engineer is designing a storage solution for a high-performance database that requires consistent low-latency access to block-level storage. The database runs on a single virtual machine and must support frequent random read/write operations. Which storage type should the engineer choose?

Hard
140

During a security audit, a cloud engineer discovers that a container image used in production has a known critical vulnerability in a base layer. Which practice should be implemented to prevent this in the future?

Hard
141

A company is migrating its on-premises applications to a public cloud. The security team wants to ensure that the cloud provider is responsible for physical security of data centers, while the company remains responsible for securing guest operating systems. Which concept does this describe?

Medium
142

An e-commerce application experiences variable traffic with sudden spikes during flash sales. The application is designed to be stateless. Which scaling approach should the cloud architect implement to handle these spikes efficiently?

Medium
143

Which cloud service model provides the customer with the most control over the operating system and applications?

Easy
144

A cloud administrator is standardizing infrastructure provisioning across teams and wants to enforce that all deployed resources carry a mandatory cost-center tag. The administrator needs non-compliant deployments to be rejected automatically across multiple accounts in an AWS Organization. Which control should be implemented?

Hard
145

A cloud engineer needs to apply security patches to a group of Linux VMs running in Azure. The engineer wants to automate the patching process and ensure that patches are applied during a predefined maintenance window. Which Azure service should be used?

Easy
146

An organization is migrating a legacy application to the cloud. The application writes logs to a local file system. The cloud architect recommends using a centralized logging service. Which of the following BEST explains why this change is important?

Hard
147

Which THREE of the following are key considerations when designing a cloud-native application for high availability? (Select exactly three.)

Hard
148

A cloud engineer is designing a solution for a financial application that requires strict data residency in a specific country. The application must also be highly available across multiple data centers within that country. Which design consideration is most critical?

Hard
149

Which cloud service model provides the customer with the ability to deploy and manage custom applications without managing the underlying operating system or runtime environment?

Easy
150

A developer is deploying a serverless application using AWS Lambda. They want to reuse common code (e.g., database connection logic) across multiple functions without duplicating it. Which Lambda feature should they use?

Medium
151

A cloud engineer needs to deploy a containerized application on Amazon EKS. The application requires a persistent storage volume that can be dynamically provisioned. Which Kubernetes resource should be used to request storage?

Medium
152

Which cloud service model provides the customer with the highest level of control over the operating system and middleware?

Easy
153

A developer deployed a new version of a cloud function, but the function is returning 500 errors. The previous version worked fine. What is the most likely cause?

Medium
154

A company has a cloud-based application that uses a relational database. The database team performs daily backups to an on-premises storage system using a VPN connection. Recently, backups have been failing with timeout errors. The network team confirms the VPN is up and stable. Which of the following is the MOST likely cause?

Easy
155

Refer to the exhibit. The auto scaling group is fluctuating between 2 and 3 instances every few minutes. What is the most likely cause?

Medium
156

A healthcare organization uses a cloud-based virtual private cloud (VPC) to host a web application that processes protected health information (PHI). The application consists of a public-facing load balancer, a web server tier in a public subnet, and a database tier in a private subnet. The database runs on a managed relational database service with encryption at rest enabled using a cloud provider-managed key. The security auditor requires that the database encryption key must be controlled by the organization and rotated every 90 days. Additionally, the database must only be accessible from the web server tier. The database is currently accessible from the entire VPC CIDR block. What should the cloud administrator do to meet these requirements?

Medium
157

A healthcare organization must protect electronic protected health information stored in a public cloud object storage bucket. Compliance requires encryption at rest with customer-controlled keys and verifiable evidence that data has not been altered. Which TWO controls should be implemented to meet these requirements? (Choose two.)

Medium
158

A cloud administrator is troubleshooting a performance degradation issue on a database server hosted in a public cloud. The server is experiencing high disk I/O wait times. The administrator suspects that the storage volume type is not optimized for the workload. Which two actions should the administrator take to address the issue? (Choose two.)

Medium
159

A company recently migrated its database to a cloud-managed database service. After the migration, the application team reports that some queries are returning stale data. The database is configured with read replicas. What is the most likely reason for the stale data?

Hard
160

A company has deployed a containerized application on a Kubernetes cluster. The security team wants to ensure that containers cannot run as the root user and that the container's root filesystem is read-only. Which Kubernetes security mechanism should be used?

Hard
161

A cloud administrator notices that a virtual machine (VM) is running slowly. The hypervisor shows high CPU ready time for that VM. Which of the following is the most likely cause?

Easy
162

An architect is designing a cloud application that must handle unpredictable spikes in traffic. The application should automatically add resources during peak demand and remove them when demand decreases to minimize costs. Which scaling strategy should be used?

Easy
163

A cloud administrator notices that an IAM role in a public cloud environment has permissions to perform all actions on all resources. The principle of least privilege should be applied. What is the best first step to reduce the security risk?

Medium
164

A cloud administrator needs to set up a centralized logging solution to collect logs from multiple projects. Which cloud service should be used?

Easy
165

A cloud administrator is designing an auto-scaling policy for a web application that experiences predictable traffic spikes during business hours. The administrator wants to ensure that the application scales out before the start of business hours to avoid performance degradation. Which scaling policy type should be used?

Hard
166

A security team runs workloads in Microsoft Azure and must ensure that all data stored in Azure SQL Database and Azure Storage accounts is encrypted with customer-managed keys (CMK) rather than platform-managed keys. The compliance officer requires that the organization be able to revoke access to the data by disabling the key, and that key rotation be controlled internally. Which Azure service should the team configure to meet these requirements?

Hard
167

During a cloud migration, a database server is moved from on-premises to a cloud-managed database service. After migration, the application team reports that some queries are running slower than before. The database CPU utilization is low. What is the most likely cause?

Medium
168

A cloud architect is designing a system that requires a durable, highly available object storage solution for storing backups and media files. The data must be accessible from anywhere via HTTP/HTTPS. Which AWS service should be used?

Easy
169

A security administrator is deploying a web application firewall (WAF) to protect a public-facing web application. The application experiences a high volume of traffic from a specific geographic region that is not part of the target customer base. Which WAF feature would best reduce the attack surface without impacting legitimate users?

Hard
170

A company has a three-tier application in a cloud VPC: web servers in a public subnet, application servers in a private subnet, and database servers in a private subnet. The web servers can connect to the application servers, but the application servers cannot connect to the database servers. The security groups are configured as follows: - Web SG: inbound HTTP from 0.0.0.0/0, outbound all - App SG: inbound HTTP from Web SG, outbound all - DB SG: inbound MySQL from App SG, outbound all What is the most likely cause of the connectivity issue?

Medium
171

An Azure administrator needs to deploy a cloud-native application using Azure DevOps. The team wants to define the entire Azure infrastructure as code using a declarative language that is concise and integrated with Azure. Which tool should the administrator use?

Medium
172

A company is considering a multi-cloud deployment to avoid vendor lock-in. Which TWO factors should they consider? (Select TWO.)

Medium
173

A cloud operations team is preparing for a disaster recovery drill for a multi-tier application. Which TWO activities are essential for verifying the effectiveness of the DR plan? (Select TWO.)

Medium
174

A company is deploying a microservices architecture that must scale dynamically based on traffic. Which technology should be used?

Hard
175

During a CI/CD pipeline for a web application, the team wants to reduce risk by deploying a new version to a small percentage of users initially, monitoring for errors, and automatically rolling back if issues are detected. Which deployment strategy should they implement?

Medium
176

A cloud administrator receives an alert that a virtual machine's disk usage is at 95%. The VM hosts a database. Which of the following troubleshooting steps should the administrator take FIRST?

Medium
177

An organization is migrating a MySQL database to Amazon Aurora with minimal downtime. The migration must capture ongoing changes from the source database and apply them to the target during the cutover. Which AWS Database Migration Service (DMS) feature should be used?

Hard
178

A cloud engineer is deploying a containerized application to a Kubernetes cluster. The application requires a configuration file that contains database credentials and API keys. The engineer wants to avoid hardcoding sensitive information in the container image or in the deployment manifest. Which Kubernetes resource should be used to store and manage this sensitive data securely?

Medium
179

An organization is using CloudFormation to manage AWS infrastructure. They need to detect if any manual changes have been made to resources outside of CloudFormation. Which CloudFormation feature should they use?

Medium
180

A cloud administrator receives an alert that a virtual machine has unexpectedly shut down. The administrator checks the hypervisor logs and finds an entry "Out of memory: killed process" in the VM's OS logs. Which of the following is the most likely cause?

Hard
181

A cloud engineer runs the commands shown in the exhibit. Based on the output, which security issue is present?

Hard
182

A cloud architect is designing a highly available two-tier web application. The database tier must remain available if a single Availability Zone fails. Which TWO design decisions should the architect make? (Choose two.)

Medium
183

A cloud architect is designing a deployment pipeline using GitHub Actions. They want to automatically run tests on every push to the main branch. Which GitHub Actions component defines the automation workflow?

Easy
184

A cloud administrator manages a three-tier application in a public cloud. After a change window, users can reach the web front end, but every request to the API tier returns HTTP 504 Gateway Timeout. The web tier and API tier are in different subnets, and the API instances report healthy in the load balancer target group. Which action should the administrator take FIRST to isolate the fault?

Medium
185

A DevOps engineer is configuring a Kubernetes deployment for a microservices application. The application requires that new pods receive traffic only after a health check endpoint returns HTTP 200. Which Kubernetes feature should be configured on the pods?

Hard
186

A company is deploying a web application on AWS using an Auto Scaling group of Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores user session data locally on each instance. During a scaling event, users are being logged out because their sessions are not available on new instances. The company wants to implement a solution that allows sessions to persist across all instances without modifying the application code. Which approach should be used?

Medium
187

A cloud administrator is troubleshooting a database failover issue. The database is a managed service with a primary and standby replica in different availability zones. The application uses a read-write endpoint. During a recent maintenance event, the primary database failed over automatically, but the application experienced a 10-minute outage. The administrator checks the failover logs and sees that it completed within 2 minutes. What is the most likely cause of the extended outage?

Hard
188

A cloud administrator needs to grant a third-party auditing firm read-only access to compliance reports in an Amazon S3 bucket for a limited period. The firm's identity provider supports SAML 2.0. Which approach best meets the requirement with least administrative overhead?

Easy
189

A cloud architect needs to choose a compute service for a batch processing job that runs once a day and takes about 30 minutes. The job is CPU-intensive and can tolerate interruptions. Which compute option is the most cost-effective?

Easy
190

A company's compliance team must provide evidence that their cloud environment meets PCI DSS requirements. Which AWS service can aggregate security findings and automate compliance checks?

Medium
191

A company migrated to a hybrid cloud and users report slow access to files stored in the cloud. The on-premises network is 100 Mbps. What troubleshooting step should be taken?

Medium
192

A cloud architect is designing a multi-tier application that must be resilient to the failure of a single availability zone. The application consists of a web tier, an application tier, and a database tier. Which TWO design decisions will help achieve this resilience? (Choose two.)

Medium
193

An organization needs to recover its critical database within 15 minutes and lose at most 1 minute of data. Which configuration meets these requirements?

Hard
194

A cloud engineer is troubleshooting a performance issue in a virtualized environment. A critical application is running slowly, and the engineer suspects resource contention. The host server has 32 vCPUs and 256 GB of RAM, running four VMs. Which tool should the engineer use to determine if CPU ready time is causing the performance degradation?

Easy
195

An organization is subject to PCI DSS compliance and must ensure that all data transmitted between its cloud application and users is encrypted. Which encryption method should be enforced?

Medium
196

A company wants to ensure fault tolerance for a critical application by deploying across multiple availability zones. Which THREE design decisions contribute to fault tolerance? (Select THREE.)

Hard
197

A cloud administrator manages a SaaS-based CRM application integrated with an on-premises Active Directory via SAML 2.0. Users report intermittent authentication failures during peak hours (09:00-11:00), with error messages indicating 'SAML assertion validation failed'. The IdP logs show successful authentications, but the SP logs show signature validation errors. The IdP's signing certificate was rotated 30 days ago, and the SP metadata was updated 45 days ago. Which of the following is the MOST likely cause?

Medium
198

A cloud administrator is troubleshooting a VM whose performance metrics show high 'CPU ready' (or 'CPU steal') time, even though the VM's own CPU utilization is only 20%. The VM runs a latency-sensitive database and is hosted on a shared hypervisor. Which action is the MOST appropriate first step to resolve the performance issue?

Hard
199

A company hosts a web application on AWS and wants to improve latency for global users. Which service should they use to cache static content at edge locations?

Hard
200

A cloud engineer is deploying a multi-tier web application on AWS. The web tier must be able to scale out during traffic spikes, but the database tier should remain on a fixed set of instances. The engineer wants to define the infrastructure as code using AWS CloudFormation. Which CloudFormation feature should be used to automatically adjust the number of web tier instances based on CPU utilization?

Medium
201

A cloud engineer is deploying a multi-tier web application on AWS using AWS Elastic Beanstalk. The application requires a relational database and must be able to scale automatically based on demand. The engineer wants to minimize management overhead. Which deployment approach should the engineer use?

Medium
202

A cloud architect is designing a solution that must automatically provision and configure compute, storage, and networking resources in a repeatable manner across multiple cloud providers. The solution must minimize manual intervention and ensure consistent configurations. Which approach best meets these requirements?

Medium
203

A cloud engineer is troubleshooting performance issues in a virtualized environment. Which of the following tools would BEST help identify CPU contention on a hypervisor?

Easy
204

Match each networking concept to its definition.

Medium
205

An organization needs to store database credentials and API keys securely in the cloud, with automatic rotation every 90 days. Which service should be used?

Medium
206

A cloud administrator is responsible for a set of Linux virtual machines in AWS. The administrator needs to run a script on all of the instances at a scheduled time each night to rotate application logs. The script must run without the administrator logging in to each instance, and the administrator wants to avoid managing SSH keys for this task. Which AWS service should the administrator use?

Easy
207

A cloud engineer needs to deploy a stateless application across multiple availability zones. The application must scale horizontally based on CPU utilization. Which of the following is the BEST configuration?

Easy
208

A company is deploying a stateful application on AWS that requires a shared, POSIX-compliant file system that can be mounted on multiple Amazon EC2 instances simultaneously. The application also needs to support high throughput and must be durable across multiple Availability Zones. Which AWS storage service should the company use?

Hard
209

A security analyst is investigating a potential data exfiltration from a cloud environment. The analyst finds that an instance IAM role was assumed by a compromised user, and the role has permissions to read from a sensitive database. What is the BEST way to prevent this type of attack in the future?

Hard
210

A cloud administrator needs to ensure that an Amazon S3 bucket containing regulated data logs every object-level access attempt, including reads and writes, for audit purposes. Which action should the administrator take?

Easy
211

A company is using a PaaS offering to host a web application. Which THREE management responsibilities are retained by the customer? (Select THREE.)

Medium
212

A cloud administrator notices that an AWS IAM user has more permissions than necessary. Which principle should be applied to correct this?

Medium
213

A cloud architect is evaluating a multi-cloud strategy to improve resilience. Which THREE factors should be considered when designing multi-cloud architecture? (Select THREE.)

Hard
214

Which TWO of the following are best practices for securing an API gateway in a cloud environment?

Medium
215

A cloud engineer is deploying a containerized microservices application on Google Kubernetes Engine. The team wants each pod to authenticate to Google Cloud APIs without embedding long-lived service account keys, and they want per-workload identity that can be granted least-privilege IAM roles. Which approach should the engineer implement?

Hard
216

A company is implementing a cloud governance strategy. They need to ensure that all resources are tagged with cost center and environment, and any untagged resources are automatically remediated. Which of the following best practices should be applied?

Hard
217

A cloud operations team manages a multi-account AWS environment with AWS Organizations. They need a centralized, near-real-time view of security findings across all accounts and want the ability to automatically suppress findings that match approved exceptions. Which service should they use to aggregate and manage these findings?

Hard
218

A cloud engineer wants to be notified when the average CPU utilization of an auto-scaling group exceeds 80% for 5 minutes. Which alerting mechanism should be used?

Medium
219

After reviewing the Terraform plan, a cloud administrator notices that the instance will be created with a public IP address. However, the company policy requires that all instances in this subnet remain private. What should the administrator do to meet the policy before applying the plan?

Hard
220

A company is deploying a new version of a microservice on Amazon EKS. The deployment must ensure that new pods are created and become healthy before old pods are terminated. The current deployment uses a ReplicaSet. Which Kubernetes resource and strategy should be used?

Medium
221

A cloud administrator is deploying a new containerized workload on Google Kubernetes Engine in Google Cloud. The security team requires that the containers run with a non-root user, have a read-only root filesystem where possible, and are prevented from gaining additional Linux capabilities. Which GKE feature should the administrator enable to enforce these restrictions at the pod level?

Easy
222

A company wants to implement a disaster recovery strategy with an RTO of 15 minutes and an RPO of 1 hour for a critical application running on AWS. Which approach would best meet these requirements?

Medium
223

A cloud engineer needs to deploy a serverless function that runs when a new object is uploaded to an S3 bucket. Which AWS service event trigger should be configured?

Easy
224

A cloud administrator is troubleshooting connectivity to a web server running on a Linux VM. The web server is configured to listen on ports 80 (HTTP) and 443 (HTTPS). The administrator runs the iptables command shown in the exhibit. Based on the output, what is the MOST likely reason that external users cannot access the web server on port 443?

Hard
225

A cloud administrator notices that a load balancer is marking all instances as unhealthy. The health check is configured to check a specific URL path. Which of the following is the MOST likely cause?

Easy
226

An organization wants to automate patching of their EC2 instances running Windows Server. They need to schedule patching during a maintenance window and ensure minimal downtime. Which AWS service should they use?

Medium
227

During a scheduled DR drill, the cloud team fails over a critical application to the secondary region. After the drill, the application is failed back. The application's RTO was 2 hours, but the actual failover took 2.5 hours. Which action should be taken to improve future failover times?

Hard
228

A company wants to migrate its on-premises workload to the cloud and needs to maintain full control over the operating system, middleware, and applications. Which cloud service model should the company choose?

Easy
229

A company deploys a multi-tier application in a public cloud. The web tier uses an auto scaling group across multiple availability zones. The database tier runs on a single large VM. The application experiences intermittent slowdowns during peak load. Which of the following is the BEST long-term solution?

Hard
230

A cloud administrator is configuring network ACLs (NACLs) for a VPC subnet. The subnet hosts a web server that must accept HTTP (port 80) and HTTPS (port 443) from the internet, and the server needs to respond to clients. Which TWO rules are required?

Medium
231

A company uses GCP and wants to implement alerting based on anomaly detection for their Compute Engine instances. Which GCP service should they use?

Medium
232

A cloud engineer is deploying a new web application on Google Cloud. The application must be reachable from the internet on HTTP and HTTPS, and the engineer wants Google's global edge network to terminate TLS and route users to the closest healthy backend. The backend instances should not be directly exposed to the internet. Which Google Cloud service should the engineer use?

Easy
233

A company wants to ensure that logs from their application are easily searchable and structured for analysis. Which logging format should be recommended?

Medium
234

A company is migrating a legacy monolithic application to the cloud. The application currently runs on a single server with 16 vCPUs and 64 GB RAM. The cloud architect recommends redesigning the application to be stateless and horizontally scalable. What is the primary benefit of this approach?

Medium
235

A cloud engineer is deploying a containerized application on Kubernetes. The security team requires that containers run with reduced privileges and that certain capabilities are dropped. Which Kubernetes feature should be used to enforce these requirements?

Medium
236

A cloud administrator needs to centralize logs from multiple cloud provider accounts and on-premises servers for security analysis. Which approach should be used?

Medium
237

A company uses a cloud-based load balancer to distribute traffic to a fleet of web servers. Users report intermittent timeouts. The administrator reviews the load balancer logs and notices that one backend server has a significantly higher error rate than the others. Which of the following is the BEST course of action?

Hard
238

A cloud administrator is reviewing the security posture of a cloud deployment. The company has a policy of least privilege and must ensure that only authorized services can access storage buckets. Which THREE mechanisms should the administrator configure to enforce this policy? (Choose three.)

Hard
239

A DevOps team is setting up a CI/CD pipeline using GitHub Actions. They want the pipeline to automatically deploy a containerized application to a Kubernetes cluster only when changes are pushed to the main branch. Which GitHub Actions component should they use to trigger the deployment?

Medium
240

A company is experiencing increased traffic to its web application. They want to handle the load by adding more web server instances behind a load balancer. This approach is known as:

Medium
241

A security team needs to enforce multi-factor authentication (MFA) for all users accessing the cloud management console. Which IAM feature should be configured?

Medium
242

A company's cloud environment uses Azure Active Directory for identity management. They want to allow employees to sign in using their existing on-premises Active Directory credentials without synchronizing passwords to the cloud. Which federation protocol should they use?

Hard
243

A cloud administrator needs to ensure that a set of AWS EC2 instances can only be accessed via SSH from the corporate office IP range 203.0.113.0/24. Which configuration should the administrator implement?

Medium
244

A cloud administrator needs to deploy a web application in a public cloud. The application must automatically scale out based on CPU utilization and scale in during low demand. Which of the following is the BEST approach?

Medium
245

Which TWO of the following are common causes of performance degradation in a cloud-based application?

Medium
246

A cloud engineer is investigating why an application hosted on Amazon EC2 cannot connect to an Amazon RDS for MySQL database in the same VPC. The database security group allows traffic on port 3306 from the application's security group. The engineer confirms the application is using the correct endpoint and credentials. Which action should the engineer take NEXT to identify the cause?

Hard
247

A company uses Azure DevOps to deploy a critical application. They need to implement a deployment strategy that ensures zero downtime by directing all traffic to the new environment after validation, while keeping the old environment as a fallback. Which deployment strategy should be configured in the Azure Pipelines release pipeline?

Hard
248

A cloud team uses Azure Bicep for deploying resources. They need to create a modular deployment that includes a virtual network and a subnet. Which THREE best practices should they follow when authoring Bicep files? (Choose three.)

Hard
249

A cloud application returns HTTP 503 errors during high traffic. The application runs on VMs behind a load balancer. Which action is most likely to resolve the issue?

Easy
250

Which TWO of the following are best practices when configuring a cloud-based virtual private cloud (VPC) for a multi-tier application?

Easy
251

A financial services company runs a multi-tenant SaaS application on AWS. Each tenant has dedicated Amazon RDS for MySQL databases. The security team must ensure that data at rest is encrypted with keys that are unique per tenant and that the company can independently audit key usage. Which approach should be used?

Hard
252

An automated snapshot of a cloud VM is failing with the error 'Quota exceeded for resource snapshots'. What is the most likely cause?

Medium
253

A cloud engineer is deploying a new application on AWS and needs to ensure that the deployment is highly available and can withstand the failure of a single Availability Zone. The application uses an Application Load Balancer (ALB) and an Auto Scaling group. Which two configurations should the engineer implement to meet these requirements? (Choose two.)

Medium
254

A cloud engineer needs to implement a solution to automatically scale an application based on the number of messages in an SQS queue. The goal is to keep the queue length short. Which Auto Scaling policy type should the engineer use?

Medium
255

A cloud engineer is investigating why a nightly batch job on Amazon EC2 takes far longer than expected. CloudWatch shows the instance's CPU and memory usage are low throughout the run, but the job performs many small reads against an Amazon EBS gp3 volume. The engineer wants to reduce the time the job spends waiting on storage. Which action should the engineer take?

Hard
256

A company hosts its critical applications on a cloud provider's virtual machines within a virtual private cloud. The security team receives an alert from the intrusion detection system indicating that one of the VMs is exhibiting signs of a ransomware infection. The administrator connects to the VM via a bastion host and observes that several important files have been encrypted and a ransom note has been left. The incident response plan is still being developed, but the administrator knows the immediate priority is to contain the threat and prevent it from spreading to other VMs and storage resources. The company has daily backups stored in a separate cloud storage service that is not directly accessible from the production network. Which of the following actions should the administrator take FIRST to contain the incident and minimize further damage?

Easy
257

A cloud architect is designing a highly available web application. The application must remain available even if an entire AWS Availability Zone fails. The architect decides to deploy identical application instances in two separate Availability Zones and distribute traffic equally. Which architecture is being implemented?

Medium
258

A company uses AWS and wants to analyze cost trends and identify the top services contributing to monthly spending. Which AWS tool provides a pre-built dashboard for this purpose?

Hard
259

A cloud operations team manages a multi-account AWS environment. Auditors require that every API call made in all accounts be logged to a central location, that logs be immutable for 90 days, and that the logs capture the identity of the caller, the source IP, and the request time. The team wants minimal custom development. Which combination should the team implement?

Medium
260

A cloud administrator is troubleshooting an application that fails to connect to a database. The application and database are in the same VPC. Which THREE steps should the administrator take to diagnose the issue?

Hard
261

An organization is using Azure and wants to implement a patch management strategy with minimal disruption. Which TWO actions should they take? (Select TWO.)

Medium
262

A cloud administrator manages a Microsoft Azure subscription. The security team requires that all virtual machines in a resource group be protected by a host-based firewall that filters traffic by port and protocol, independent of any network security group rules. The administrator needs a solution that can be applied directly to the operating system of each VM. Which solution should the administrator implement?

Medium
263

A DevOps team uses Ansible to automate cloud resource provisioning. Which of the following best describes Ansible's architecture?

Medium
264

A deployment fails with a message about missing dependencies. What should the administrator check first?

Medium
265

A company wants to protect data in transit between its on-premises data center and a public cloud environment. Which technology should be used to create a secure encrypted tunnel over the internet?

Easy
266

A cloud architect is selecting a deployment model for a workload that has strict data sovereignty requirements; data must remain within the company's on-premises data center. Which cloud deployment model should be chosen?

Easy
267

A cloud administrator receives an alert that a virtual machine is unresponsive. The hypervisor shows the VM status as 'running'. Which of the following should the administrator check FIRST to diagnose the issue?

Medium
268

A cloud administrator manages an AWS environment where developers require temporary, least-privilege access to specific S3 buckets. The administrator wants to avoid creating long-term IAM user credentials and needs the ability to audit who assumed which role and when. Which AWS service should be used to issue short-lived credentials for these developers?

Medium
269

A cloud administrator is troubleshooting a web application that uses a cloud load balancer. Users report intermittent 502 Bad Gateway errors. The administrator checks the load balancer's target group and sees that some targets are marked as unhealthy. The application runs on virtual machines behind the load balancer. Which action should the administrator take to resolve the issue?

Medium
270

An organization is implementing a CI/CD pipeline for a critical application. The team wants to deploy a new version to a small subset of users initially to validate performance and functionality before rolling out to the entire user base. Which deployment strategy best fits this requirement?

Medium
271

A company is designing a VPC in AWS. They need to host a web application with a public-facing load balancer, web servers in private subnets, and a database in a separate private subnet. Which network architecture is most secure and aligns with best practices?

Hard
272

A company is deploying a containerized application using Kubernetes on a public cloud. The development team has created a Docker image and pushed it to a private container registry. The deployment YAML points to the registry. However, when the deployment is applied, the pods fail to start with an 'ImagePullBackOff' error. The cloud administrator verifies that the registry is reachable from the cluster nodes and that the image exists. What is the most likely reason for the failure?

Medium
273

A company wants to ensure high availability for a stateless web application. Which architecture should be recommended?

Easy
274

A company has a requirement to enforce least privilege for its cloud resources. The cloud engineer is configuring IAM policies. Which of the following best describes least privilege?

Medium
275

A global company runs a SaaS application in multiple cloud regions. They use DNS-based global load balancing to route users to the nearest region. Recently, users in Asia are experiencing high latency and timeouts. The administrator checks the health of the Asian region's resources and finds everything operational. Latency measurements from a monitoring tool show that traffic from Asian users is being routed to the European region. What should the administrator investigate first?

Hard
276

A company is deploying a new web application in a hybrid cloud environment. The application must be able to scale out automatically during peak usage and scale in during low usage. The deployment must also ensure that the application remains available if a single Availability Zone fails. Which deployment strategy should the architect recommend?

Medium
277

A cloud administrator is troubleshooting a web application hosted on a cloud VM that is experiencing intermittent high latency. The administrator reviews the cloud provider's monitoring metrics and sees that the VM's CPU utilization is consistently around 30%, memory usage is 40%, and network throughput is well below the instance's limit. Which factor is the most likely cause of the latency?

Medium
278

A cloud administrator is configuring a Linux virtual machine in Google Cloud. The security policy requires that all administrative access to the VM use short-lived SSH certificates issued by an internal certificate authority, rather than static SSH keys. Which GCP feature should be used to meet this requirement?

Medium
279

A company wants to migrate a stateful application to the cloud but needs to ensure it can scale horizontally. What architectural change is required?

Hard
280

A cloud operations engineer is responsible for a fleet of Amazon EC2 instances that run a stateless web application behind an Application Load Balancer. The engineer needs to perform a rolling replacement of the instances with a new AMI while ensuring that the application remains available and that the deployment automatically rolls back if a specified Amazon CloudWatch alarm enters the ALARM state. Which AWS deployment service should the engineer use?

Medium
281

A company is adopting a shared responsibility model for a PaaS cloud deployment. Which THREE responsibilities belong to the customer?

Easy
282

Which GCP service provides centralized log management and analysis with the ability to create log-based metrics and alerts?

Easy
283

A cloud administrator wants to analyze network traffic to troubleshoot connectivity issues between VMs. Which feature should be enabled?

Medium
284

A cloud engineer must ensure that a critical Azure virtual machine automatically restarts if the guest operating system becomes unresponsive, even when the Azure host is healthy. Which Azure feature should be configured?

Hard
285

A cloud operations team is configuring cost anomaly detection for a multi-account AWS organization. They want to be notified proactively when spending deviates from expected patterns and to attribute the deviation to the right team. Which TWO actions should they take? (Choose two.)

Medium
286

A DevOps team uses Terraform to manage cloud infrastructure. They want to store the state file in a remote backend to enable team collaboration. Which backend configuration stores Terraform state in an S3 bucket?

Easy
287

A company uses a cloud object storage service to store backup data. The cloud provider charges for storage and retrieval. The operations team wants to minimize costs while ensuring data is available within 24 hours of a restore request. Which storage tier should they use?

Medium
288

A cloud architect is designing a VPC with multiple tiers. The web servers must be accessible from the internet, but the database servers must not be directly accessible. Which subnet design should the architect implement?

Medium
289

A company is migrating a legacy application to the cloud using a replatforming strategy. The application uses a proprietary logging framework that writes logs to local disk. The cloud architecture uses ephemeral storage for the application servers. The operations team notices that logs are lost when servers are replaced during auto-scaling events. What is the best solution to ensure logs are preserved?

Medium
290

A company is moving a 10 TB SQL Server database to Azure SQL Database. They need to migrate with minimal downtime while keeping the source database operational. Which service should they use?

Medium
291

A company is migrating a 50 TB on-premises SQL Server database to Amazon RDS for MySQL with minimal downtime. The schema must be converted from SQL Server to MySQL. Which combination of AWS services should the cloud architect use?

Hard
292

A cloud administrator is configuring an alert for an Azure virtual machine. The alert should trigger when the average CPU percentage exceeds 90% for more than 10 minutes. Which Azure service should be used to create this metric alert?

Medium
293

A cloud team is implementing a CI/CD pipeline for a containerized application. They want to automatically build a Docker image, push it to a registry, and deploy it to a Kubernetes cluster. Which TWO tools from the options below are commonly used as part of this pipeline? (Select 2)

Medium
294

A small business hosts a web application on a single cloud server. The server has 2 vCPUs and 4 GB RAM. Recently, the application crashes when the number of concurrent users exceeds 50. The administrator checks the system logs and finds out-of-memory (OOM) errors. What is the best course of action to resolve this issue without redesigning the application?

Easy
295

A cloud administrator manages an Amazon EC2 Auto Scaling group behind an Application Load Balancer. Users report intermittent 502 errors during scale-in events. Logs show that instances are terminated while still serving in-flight requests. Which configuration change should the administrator make to resolve this?

Hard
296

A company plans to use a public cloud to host a static website with minimal configuration. The website content is stored in an object storage bucket. Users access the site via a custom domain name. Which cloud service should the company use to serve the content with low latency globally?

Easy
297

A cloud engineer is deploying a containerized workload to Google Kubernetes Engine. The security team requires that the container run as a non-root user, that the root filesystem be mounted read-only, and that privilege escalation be disallowed. The engineer wants to enforce these controls at the pod level so that any violating pod is rejected during admission. Which action should the engineer take?

Hard
298

A company is deploying a containerized application on Amazon ECS using the Fargate launch type. The application must be highly available and able to handle sudden increases in traffic. The operations team wants to ensure that the service automatically adjusts the number of running tasks based on CPU utilization. Which ECS service configuration should the team implement?

Medium
299

An organization uses GCP and wants to implement a tagging strategy to track costs by project and environment. Which GCP feature should be used to assign metadata to resources for cost attribution?

Medium
300

An organization wants to minimize costs for a batch processing workload that runs nightly for 2 hours and can tolerate interruptions. Which pricing model is most cost-effective?

Hard
301

A cloud engineer is troubleshooting a performance issue in a Microsoft Azure environment. The application runs on an Azure Virtual Machine Scale Set (VMSS) behind an Azure Load Balancer. Users report intermittent slow response times. The engineer suspects that the VMSS instances are experiencing high CPU utilization due to uneven traffic distribution. The engineer needs to collect and analyze performance data to identify the root cause. Which Azure feature should the engineer use to gain deep visibility into the performance of the VMSS instances and the load balancer?

Hard
302

Which TWO of the following are best practices for managing cloud costs? (Select TWO.)

Medium
303

Which TWO of the following are advantages of using a configuration management tool (e.g., Ansible, Chef, Puppet) in cloud deployments? (Choose two.)

Medium
304

A company has a hybrid cloud environment where on-premises servers communicate with cloud resources via a VPN connection. The network team notices intermittent connectivity issues and packet loss. The VPN tunnel is established, but performance is degraded. Which step should the team take first to diagnose the issue?

Hard
305

A cloud administrator is troubleshooting a network connectivity issue between two subnets. They suspect a security group or NACL is blocking traffic. Which tool should they use to analyze the traffic flow?

Hard
306

A cloud architect is designing a container security strategy. Which TWO of the following should be implemented to secure containers? (Choose two.)

Medium
307

A cloud administrator is planning a migration of on-premises workloads to the cloud. Which TWO factors should be considered when selecting the appropriate cloud service model (IaaS, PaaS, SaaS)?

Easy
308

A cloud administrator is configuring an auto-scaling group for a web application. The application experiences predictable traffic spikes every weekday at 9 AM. Which scaling policy is most appropriate?

Medium
309

A cloud operations team runs a fleet of Amazon EC2 instances behind an Application Load Balancer. During a recent incident, the team discovered that a single unhealthy instance continued to receive traffic for several minutes before being removed. The team wants to reduce the time it takes for the load balancer to detect and stop routing traffic to unhealthy targets. Which action should the administrator take to meet this requirement?

Medium
310

A developer is deploying a serverless function that processes images uploaded to an S3 bucket. The function should be triggered automatically whenever a new object is created in the bucket. Which event source should be configured to invoke the Lambda function?

Easy
311

A company needs to migrate 50 TB of data from an on-premises file server to a cloud storage service. The network bandwidth is limited and the migration must be completed within one week. Which cloud service is specifically designed for offline data transfer of large datasets?

Easy
312

A company stores sensitive customer data in an S3 bucket and must encrypt the data at rest using a key managed by the company (not AWS). Which encryption option should the company use?

Medium
313

A company wants to reduce cloud costs for a stateless batch processing workload that runs nightly for about 3 hours. The workload can tolerate interruptions. Which pricing model is most cost-effective?

Medium
314

A cloud administrator wants to ensure that patches are applied to cloud workloads with minimal risk. Which TWO practices should the administrator follow? (Choose two.)

Easy
315

An organization runs a batch processing job that runs for 2 hours every night. The job can tolerate interruptions and can resume from the last checkpoint. Which cloud purchasing option minimizes cost?

Hard
316

A cloud engineer is writing a Terraform configuration to deploy an AWS EC2 instance. The engineer wants to pass the AMI ID and instance type into the configuration at runtime without hardcoding them. Which Terraform feature should be used?

Medium
317

A cloud administrator is troubleshooting a virtual machine (VM) in a public cloud that has become unresponsive. The administrator cannot SSH into the VM, and the cloud provider's console shows the VM is running. The administrator suspects the VM's OS has hung. Which action should the administrator take to regain access to the VM with minimal data loss?

Easy
318

A cloud administrator is troubleshooting a performance issue in a virtualized environment. Which THREE of the following metrics should the administrator analyze to identify potential resource contention? (Select THREE.)

Hard
319

A developer wants to deploy a containerized application on a Kubernetes cluster using a package manager that simplifies deployment and management. Which tool should be used?

Easy
320

A cloud architect is designing a disaster recovery strategy for a critical application with a Recovery Time Objective of 15 minutes and a Recovery Point Objective of 5 minutes. The secondary Region must be able to take over with minimal manual effort. Which strategy should the architect implement?

Hard
321

A cloud operations team runs a containerized workload on Amazon ECS with tasks spread across an Auto Scaling group of EC2 instances. During a peak-traffic event, the team observes that a single task repeatedly restarts with an out-of-memory error while the host instance still shows 40% free memory. The team wants the scheduler to stop placing new tasks on that host when its committed memory is exhausted. Which action should the team take?

Medium
322

A company uses a multi-cloud strategy with workloads in AWS and Azure. The cloud team wants a centralized log management solution to correlate security events across both platforms. Which approach is most suitable?

Medium
323

A cloud operations team wants to analyze application performance and identify slow database queries. They need a distributed tracing solution. Which service should they use?

Medium
324

A company is migrating a legacy monolithic application to AWS. The application requires a relational database and must support read-heavy workloads with minimal latency for users across North America and Europe. The database must be highly available and provide automatic failover. Which AWS database solution should the architect recommend?

Hard
325

An organization wants to migrate its on-premises virtual machines to the cloud with minimal changes. Which deployment model is most appropriate?

Easy
326

A team is using Kubernetes for container orchestration. They want to ensure that a new deployment does not cause downtime by gradually updating pods with a rolling update strategy. Which parameter in a Deployment manifest controls the number of pods that can be unavailable during the update?

Hard
327

A cloud administrator is designing a backup strategy for a virtual machine running a critical application. The application stores data on a separate data disk. Which TWO of the following practices should the administrator include to ensure a reliable backup?

Easy
328

A company stores sensitive data in a cloud object storage. They want to ensure that data is automatically deleted after a retention period of 7 years to comply with legal requirements. Which feature should be used?

Easy
329

A company is implementing a secrets management solution. The security team wants to ensure that secrets are protected and rotated regularly. Which THREE of the following are best practices for secrets management?

Hard
330

Refer to the exhibit. What is the effect of this bucket policy?

Medium
331

A cloud engineer is deploying a new application that requires high availability. The solution must include automated failover and load balancing. Which TWO of the following should the engineer implement?

Easy
332

A company uses AWS and needs to enforce that all S3 buckets are encrypted at rest with customer-managed keys stored in AWS KMS. Which IAM policy condition would ensure this?

Hard
333

A cloud architect is designing a containerized microservices application that must handle unpredictable traffic spikes and scale rapidly. The architect wants to minimize operational overhead while ensuring high availability across multiple Availability Zones. Which solution best meets these requirements?

Medium
334

A company is deploying a multi-tier application on AWS using AWS CloudFormation. The application consists of an Auto Scaling group, an RDS instance, and an Application Load Balancer. The team needs to ensure that the RDS instance is created before the Auto Scaling group and that the Auto Scaling group is updated only after the load balancer is ready. Which CloudFormation feature should be used to define these dependencies?

Hard
335

A cloud administrator is reviewing cost reports and notices that a development environment is incurring high costs due to idle compute resources. The environment is used only during business hours on weekdays. Which of the following actions would MOST effectively reduce costs?

Medium
336

A company uses AWS and wants to receive alerts when CPU utilization of an EC2 instance exceeds 90% for 10 minutes. Which AWS service should be used to create this alarm?

Easy
337

A cloud engineer needs to ensure that a web application can scale out automatically during traffic spikes. Which design best practice should be implemented?

Easy
338

A cloud administrator is deploying a web application on Azure. The application requires a shared, highly available file storage that can be mounted simultaneously by multiple virtual machines across different availability zones. Which Azure storage solution should the administrator choose?

Medium
339

An administrator is configuring access to a cloud management console for a large team. The organization wants to require a second authentication factor for all users and centralize the identity source so that disabling an account in the corporate directory immediately removes cloud access. Which approach should the administrator implement?

Easy
340

A financial services firm is moving a regulated trading application to a public cloud. The security team must prove that data is encrypted in transit between the application tier and the database tier, and that only the application tier can reach the database port. Which two controls should the cloud architect implement? (Choose two.)

Medium
341

A cloud administrator sees the output above when troubleshooting a virtual machine that is unresponsive. The VM is critical and must be restored quickly. What should the administrator do first?

Hard
342

A company is planning to migrate to AWS and wants to achieve the lowest possible compute costs for a steady-state workload that will run 24/7. Which purchasing option should be recommended?

Medium
343

During a disaster recovery test, a cloud administrator finds that the replicated VMs in the secondary site fail to start because they are assigned to a resource pool that does not exist in the secondary site. Which of the following should the administrator have done to prevent this issue?

Hard
344

A startup wants to run code in response to events without provisioning or managing servers. Which cloud service model should they use?

Easy
345

A cloud team wants to automatically scale an application based on the number of pending messages in a message queue. Which scaling policy type should be used?

Medium
346

A cloud engineer notices that a virtual machine (VM) in a public cloud environment is consistently running at 90% CPU during business hours. The VM hosts a customer-facing web application. Which of the following is the BEST initial troubleshooting step?

Easy
347

A security engineer is reviewing a cloud storage bucket policy. Which of the following best describes the security issue present in the exhibit?

Medium
348

A cloud operations team is designing a backup strategy for a set of Amazon RDS for MySQL databases that support a production application. The team needs to be able to restore the database to any point in time within the last 35 days and must also retain a copy of the database for seven years for regulatory compliance. The team wants to minimize operational overhead. Which TWO actions should the team take? (Choose two.)

Hard
349

A company uses a hybrid cloud environment with workloads in AWS and on-premises. They want to use a single monitoring dashboard to view metrics from both environments. Which solution should they implement?

Hard
350

A cloud architect is designing a deployment pipeline for a multi-tier application. The team wants to automate testing and deployment while ensuring that only healthy code reaches production. Which TWO practices should they implement?

Medium
351

A cloud administrator notices that a virtual machine is consuming excessive CPU resources with no apparent workload. Which of the following should the administrator investigate FIRST to determine the cause?

Hard
352

A company uses a hybrid cloud model with an on-premises data center and a public cloud. The network team reports that traffic between the cloud and on-premises is experiencing high latency and packet loss. The cloud administrator verifies that the VPN connection is up. What is the most likely cause?

Hard
353

A cloud administrator is tasked with ensuring that only encrypted connections are used to transfer files to a cloud storage bucket. Which of the following should the administrator enforce?

Easy
354

A company wants to migrate its on-premises workloads to the cloud and requires full control over the operating system, installed software, and security configurations. Which cloud service model should they choose?

Easy
355

A company wants to migrate its on-premises workloads to the cloud but must keep sensitive data on-premises due to regulatory requirements. Which cloud deployment model should the company use?

Easy
356

A DevOps engineer is deploying an application on Kubernetes. The exhibit shows the status of pods and a describe output. The frontend pod is stuck in Pending state. Which action should the engineer take to resolve the issue?

Hard
357

A cloud engineer needs to collect and query log data from multiple cloud services in a centralized location. Which cloud service should be used for centralized log management?

Easy
358

A cloud engineer is planning a disaster recovery drill for a critical application that spans multiple availability zones. The drill must validate RTO and RPO without affecting production. Which THREE actions should the engineer include? (Choose three.)

Hard
359

A financial services firm stores regulated customer records in an object storage bucket in a public cloud. A compliance auditor requires that every object be encrypted with a customer-managed key so the firm can revoke access instantly and prove key custody, while still allowing the provider to perform envelope encryption for performance. Which configuration meets these requirements?

Hard
360

A cloud administrator notices that an IAM user has permissions that are not explicitly assigned. The administrator suspects that the user is inheriting permissions through group membership or role assignment. Which TWO methods can the administrator use to identify all effective permissions for this user? (Choose TWO.)

Medium
361

An organization is moving sensitive data to the cloud and must ensure it is encrypted while stored on disk. Which type of encryption should be implemented?

Easy
362

A cloud administrator needs to deploy a new version of an application to a Kubernetes cluster. The administrator wants to update the application without downtime and ensure that if the new version fails, the deployment automatically rolls back to the previous version. Which Kubernetes resource should the administrator use?

Easy
363

An organization is using Azure DevOps to implement a CI/CD pipeline. In which stage of the pipeline would automated unit tests typically be executed?

Easy
364

Refer to the exhibit. A cloud administrator runs this command on a VM. Which of the following is most likely causing the high 'wa' value?

Easy
365

A company wants to deploy a Lambda function that processes objects uploaded to an S3 bucket. Which event trigger should be configured on the Lambda function?

Easy
366

A company is migrating to a public cloud and wants to understand security responsibilities. According to the shared responsibility model, which of the following is the customer responsible for in an IaaS deployment?

Medium
367

A cloud administrator needs to receive real-time notifications when CPU utilization exceeds 90% on a production server. Which AWS service should be used to trigger an alert based on a metric threshold?

Easy
368

During a deployment using a script, an administrator receives a 'Permission Denied' error. What is the most likely cause?

Medium
369

A cloud operations team needs to reduce the mean time to recovery for a microservices application running on Amazon EKS. They want to detect service degradation earlier and automatically replace unhealthy pods without manual intervention. Which TWO actions should the team take? (Choose two.)

Medium
370

A company uses a cloud load balancer to distribute traffic to web servers. The load balancer health checks are failing for all instances. The instances are running and can be accessed directly via their private IPs from within the VPC. What is the most likely cause?

Easy
371

A company running a critical web application wants to protect against SQL injection and cross-site scripting attacks. The application is behind a load balancer. Which type of service should be deployed to provide this protection?

Hard
372

A cloud operations team is implementing structured logging for better querying. They have decided to use JSON format. What is a key benefit of structured logging over unstructured logging?

Hard
373

A company is designing a cloud network architecture for a three-tier application. The web tier must be accessible from the internet, the application tier should only be accessible from the web tier, and the database tier should only be accessible from the application tier. The company uses a single VPC with multiple subnets. The security team requires that all traffic between tiers be encrypted in transit. The architect proposes using security groups and network ACLs. Which combination of security group rules meets these requirements while following the principle of least privilege?

Hard
374

A cloud engineer is troubleshooting an issue where an application running in a container on a Kubernetes cluster is unable to resolve DNS names. The cluster uses CoreDNS. The engineer checks the CoreDNS pod logs and sees no errors. Which of the following should the engineer check next?

Hard
375

A cloud architect is designing a highly available application on AWS. The application must be fault-tolerant and able to withstand the failure of an entire Availability Zone. Which TWO actions should the architect take? (Select TWO.)

Medium
376

A cloud engineer is troubleshooting a performance issue where a web server cluster experiences high latency during peak hours. The cluster uses an auto-scaling group behind a load balancer. Which THREE steps should the engineer take to identify the root cause?

Hard
377

A company uses a SaaS application for customer relationship management (CRM). The security team wants to monitor user activities and enforce data loss prevention (DLP) policies. Which type of security tool should be deployed?

Medium
378

What is the primary benefit of using Infrastructure as Code (IaC)?

Easy
379

Which of the following is the best practice for securely storing secrets such as database passwords in a cloud environment?

Easy
380

Which TWO of the following are common security concerns specific to a public cloud infrastructure?

Easy
381

A cloud architect is designing a VPC with three tiers: web, application, and database. Which subnet design provides the best security posture?

Hard
382

Which storage type is most suitable for hosting a shared file system accessible by multiple virtual machines in a cloud environment?

Easy
383

A cloud administrator is asked to give the security team read-only visibility into all objects stored in an Amazon S3 bucket used for application logs, without granting the ability to delete or overwrite any object. The security team authenticates as an IAM role. Which action should the administrator take?

Easy
384

A company recently migrated its on-premises backup server to a cloud virtual machine running Windows Server with a dedicated data disk for backups. The backup software is configured to write to a folder on the data disk. After two weeks, the backup jobs start failing with 'disk full' errors. The cloud engineer logs into the VM and verifies that the data disk has 500 GB of total space and the backup folder shows only 300 GB used. However, the operating system reports the disk as 100% full. The engineer also notices that the recycle bin on the data disk appears to be empty. Which of the following is the MOST likely cause of the discrepancy?

Easy
385

Arrange the steps to configure auto-scaling for a group of virtual machines based on CPU utilization.

Medium
386

Which THREE of the following are common causes of application performance degradation in a cloud environment? (Choose three.)

Medium
387

An organization is deploying a multi-tier application in the cloud. The web tier uses auto scaling, and the database tier uses a managed database service. During a load test, the web tier scales up correctly, but the database performance degrades significantly, causing timeout errors. The administrator reviews the database metrics and finds that CPU and memory are normal, but the number of connections is high. Which of the following is the BEST action to resolve the issue?

Hard
388

A cloud administrator is configuring a Linux VM as a router. The iptables rules are shown. The administrator can SSH into the VM from the network but cannot forward traffic between interfaces. What is the most likely cause?

Easy
389

An organization is migrating its on-premises virtualization environment to a public cloud. The current environment uses VMware vSphere with VM templates. The cloud provider supports importing VMs in OVF format. Which step should the cloud administrator take to prepare the VMs for migration?

Easy
390

A cloud operations team is hardening a Microsoft Azure subscription that hosts production virtual machines. The security lead wants to ensure that only approved operating system images can be deployed and that any drift from the baseline configuration is automatically detected. Which TWO Azure services should be implemented to meet these goals? (Choose two.)

Medium
391

Which deployment strategy minimizes risk by gradually shifting a small percentage of traffic to a new version before full rollout?

Hard
392

A cloud administrator receives reports that a newly deployed application stack fails health checks and is repeatedly replaced by the orchestrator. Logs show the container starts, then exits after a few seconds with no error. The container image runs a process that daemonizes and returns control to the shell. Which of the following is the MOST likely cause?

Easy
393

A cloud operations team is troubleshooting a performance issue with a database that is running on a virtual machine. The database is experiencing high latency during peak hours. Metrics show that CPU and memory usage are below 50%, but disk I/O latency spikes. The database is hosted on a cloud provider's virtual machine with premium SSDs. Which of the following is the MOST likely cause of the disk I/O latency?

Hard
394

A company is migrating to AWS and needs to meet PCI DSS compliance. Which THREE of the following should be implemented? (Choose three.)

Hard
395

Which TWO of the following are benefits of using a content delivery network (CDN) with cloud-hosted applications? (Choose two.)

Easy
396

A cloud administrator is troubleshooting network connectivity issues between two VPCs in AWS. The administrator wants to examine traffic flow logs to identify dropped packets. Which AWS feature provides detailed network traffic logs for VPCs?

Medium
397

A cloud architect is designing a new application that must be highly available across multiple geographic regions. The application uses a relational database that must be writable in the primary region and readable in a secondary region with minimal replication lag. Which AWS database feature should the architect implement to meet these requirements?

Medium
398

A security analyst is reviewing logs and finds that an unauthorized user accessed a storage blob in a cloud environment. The analyst needs to determine which permissions allowed the access. Which cloud feature provides a detailed view of effective permissions for a user?

Medium
399

During a security audit, it is discovered that a cloud application can be accessed using a shared service account that has elevated privileges. The audit recommends implementing a just-in-time (JIT) access model. What is the primary benefit of JIT access in this scenario?

Hard
400

A cloud security team is implementing a secrets management solution for applications running on AWS. They need to automatically rotate database credentials every 30 days and avoid hardcoding secrets. Which service should they use?

Hard
401

A large enterprise is migrating multiple applications to the cloud. They need to ensure compliance with industry regulations and maintain security during the transition. Which THREE best practices should they follow?

Hard
402

An organization uses multiple SaaS applications and wants to enforce data loss prevention policies and gain visibility into user activity. Which technology should they implement?

Medium
403

A cloud administrator is deploying a new virtual machine in a public cloud. The administrator needs to ensure that the VM can be accessed remotely for management purposes. The security group associated with the VM currently allows only outbound traffic. Which inbound rule should be added to allow SSH access from the administrator's corporate network?

Easy
404

A cloud architect is designing a multi-tier application that must be resilient to the failure of an entire availability zone. Which of the following strategies BEST meets this requirement?

Medium
405

A cloud security team is hardening a Microsoft Azure subscription that hosts production virtual machines. The team must ensure that administrative access to the VMs requires multi-factor authentication and that privileged role assignments are reviewed on a recurring basis. (Choose two.)

Medium
406

A company has a cloud-based application that uses an auto-scaling group across multiple Availability Zones (AZs). The application experiences periodic spikes in traffic. The auto-scaling policy uses a step scaling policy based on CPU utilization. The operations team notices that during a traffic spike, new instances are launched but take over five minutes to become healthy and begin serving traffic. During this time, existing instances are overloaded and some requests fail. The team wants to reduce the time it takes for new instances to handle traffic. Which action would be most effective?

Medium
407

A cloud administrator runs the command shown in the exhibit on a storage node in a hyper-converged cluster. The node is experiencing intermittent I/O errors and degraded performance. Based on the SMART data, what is the most likely cause of the issue?

Medium
408

An organization has a hybrid cloud environment with resources in both a private cloud and a public cloud. The operations team reports that the cloud management platform cannot collect monitoring data from the public cloud instances. The security team recently updated firewall rules. Which of the following is the MOST likely cause?

Hard
409

A cloud administrator is troubleshooting a containerized application deployed on a managed Kubernetes cluster. Pods are failing to start, and the events show 'FailedMount' errors for a persistent volume claim (PVC). The PVC is bound to a persistent volume (PV) that uses a storage class with a reclaim policy of Delete. Which two actions should the administrator take to resolve the issue? (Choose two.)

Hard
410

A cloud administrator is designing a multi-tier application. The database tier must not be directly accessible from the internet, but the web tier must be able to connect to it. Which of the following should the administrator implement?

Easy
411

A cloud operations team must ensure that a critical workload continues to run even if an entire AWS Region becomes unavailable. The workload's data is stored in Amazon S3, and the team wants the data available in a second Region with minimal operational effort and automatic replication. Which action should the team take?

Hard
412

A company is migrating on-premises workloads to the cloud. They need to ensure high availability for a stateless web application across two availability zones. Which THREE components should be configured to meet this requirement?

Hard
413

A cloud engineer is tasked with deploying a containerized application on Kubernetes. The application must handle varying loads, and the deployment should automatically replace failed containers. Which Kubernetes object should the engineer use to achieve self-healing and scalability?

Medium
414

An organization's cloud environment has a policy that all administrative access must be logged and recorded. Which of the following is the best method to enforce this policy?

Medium
415

A cloud engineer deployed the infrastructure shown. The load balancer's health checks are failing for the EC2 instance. Which of the following is the MOST likely cause?

Medium
416

An organization is migrating a MySQL database to Amazon RDS using AWS DMS. They want to minimize downtime by using ongoing replication from the source. Which DMS feature should they enable to capture changes as they occur on the source database?

Medium
417

A cloud engineer is deploying a containerized application on Amazon ECS using the Fargate launch type. The application requires persistent storage for a shared cache that must be accessible by multiple tasks across different Availability Zones. The cache data must survive task restarts. Which storage solution should the engineer use?

Hard
418

A company is using a SaaS application and wants to gain visibility into user activity and enforce data loss prevention policies. Which technology should be deployed?

Medium
419

A company is migrating a legacy application that requires static public IP addresses for licensing. The cloud provider assigns public IPs dynamically by default. Which solution should the administrator recommend while minimizing cost?

Hard
420

A company is deploying a containerized microservices architecture on Azure Kubernetes Service (AKS). The security team requires that all container images are scanned for vulnerabilities before deployment. Which deployment approach should the DevOps team implement to ensure only approved images are used?

Hard
421

A cloud security engineer is hardening a Kubernetes cluster. Which TWO measures should be implemented to improve container security? (Choose two.)

Medium
422

A company is deploying a global web application that serves static content (images, CSS, JavaScript) to users worldwide. They want to reduce latency and offload traffic from the origin servers. Which service should they implement?

Medium
423

A security team discovers that a container image used in production contains a known vulnerability in one of its base image layers. Which action should be taken to remediate this issue?

Medium
424

A cloud security team is implementing a key management strategy for workloads spread across AWS and Azure. The team wants a single system of record for cryptographic keys, with the ability to import existing keys from on-premises HSMs, enforce automatic annual rotation, and produce immutable audit logs of every key use. Which approach best satisfies these requirements?

Medium
425

A cloud architect is designing a multi-tier application on a public cloud. The application must be highly available and fault-tolerant within a single region. Which three items should be included in the architecture? (Select THREE.)

Hard
426

A company is running a stateless web application on a public cloud. They expect traffic to spike during certain hours. Which scaling strategy would be most cost-effective and efficient?

Medium
427

Which of the following storage types is most suitable for hosting a shared file system that multiple virtual machines need to access concurrently using NFS?

Easy
428

A mid-sized company is migrating its on-premises applications to a public cloud. The security team has implemented a cloud access security broker (CASB) to monitor and enforce policies for sensitive data. The company uses a multi-cloud environment with both AWS and Azure. After deployment, the security team receives alerts that a developer accidentally exposed a set of credentials in a public GitHub repository. The credentials were associated with a service account that has read-write access to an AWS S3 bucket containing customer PII (personally identifiable information). The team immediately revokes the credentials and rotates the access keys. The security team wants to prevent such incidents in the future and ensure that any exposed credentials are promptly detected without relying solely on manual GitHub scans. The company also wants to maintain a least-privilege model for all cloud resources. Given this scenario, which of the following actions should the security team take FIRST to reduce the risk of credential exposure and improve detection?

Medium
429

A financial services company stores regulated data in Amazon S3 buckets. A security architect must ensure that objects are encrypted at rest using keys that the company controls, can be rotated on a schedule, and can be audited independently of AWS-managed keys. The keys must not leave AWS hardware security modules in plaintext. Which encryption option should the architect choose?

Hard
430

A cloud architect is designing a system that must durably store an unlimited amount of unstructured data, such as images and videos, with 99.999999999% (11 nines) durability. The data will be accessed infrequently, but when accessed, it must be available within milliseconds. The architect wants the most cost-effective storage class for this access pattern. Which Amazon S3 storage class should the architect choose?

Medium
431

Which TWO of the following are effective methods to protect data in transit within a cloud environment? Select two.

Easy
432

A company runs a stateless web application on AWS EC2 instances behind an Application Load Balancer. To reduce costs, they want to use the most cost-effective compute option that can handle variable traffic and be interrupted. Which pricing model should they use for the EC2 instances?

Hard
433

A security team wants to implement host-based intrusion detection on their virtual machines in a public cloud. Which approach provides the most effective detection while minimizing performance impact?

Medium
434

A company uses GitHub Actions to build and deploy a microservices application. They want to automate the deployment to a Kubernetes cluster only when changes are pushed to the main branch. Which GitHub Actions event trigger should be used in the workflow?

Hard
435

A company wants to connect its on-premises data center to a public cloud provider with a dedicated, high-bandwidth, low-latency connection. The connection must be private and not traverse the internet. Which connectivity option should be used?

Medium
436

A cloud administrator is troubleshooting a connectivity issue between two VPCs in the same region. Which TWO actions should the administrator verify? (Choose two.)

Medium
437

A company is migrating a legacy monolithic application to a microservices architecture on the cloud. The application has tight coupling and shared database schemas. Which migration strategy should the company adopt to reduce risk and enable iterative migration?

Hard
438

A cloud security engineer is implementing a data loss prevention (DLP) strategy for sensitive data stored in Amazon S3. The company must detect and prevent accidental exposure of personally identifiable information (PII) in objects uploaded by users. The engineer needs a solution that automatically scans new objects, identifies PII, and can trigger alerts or block access. Which AWS service should the engineer use?

Hard
439

A cloud engineer wants to receive real-time notifications when a CloudWatch Alarm enters the ALARM state. Which notification channel can be configured directly within the CloudWatch Alarm action?

Easy
440

Which cloud service model provides the customer with the most control over the operating system and software stack?

Easy
441

A cloud architect is designing a shared file system for a machine learning cluster where multiple Linux virtual machines must read and write the same training data concurrently with POSIX semantics. The workload runs for several weeks and needs high aggregate throughput. Which storage solution should the architect select?

Hard
442

A cloud administrator needs to design a storage solution that provides block-level access for a database server and must be highly durable. Which storage type should be used?

Easy
443

A company is migrating its on-premises application to a public cloud. The application requires low-latency access to a legacy database that cannot be moved to the cloud. The cloud deployment must use a hybrid architecture. Which network connectivity solution should the cloud architect recommend to minimize latency and provide secure, reliable communication?

Hard
444

A company is designing a disaster recovery (DR) plan for a critical application hosted in a public cloud. The application requires a recovery time objective (RTO) of 1 hour and a recovery point objective (RPO) of 15 minutes. Which of the following DR strategies BEST meets these requirements?

Medium
445

Arrange the steps to configure a VPN connection between an on-premises network and a cloud VPC.

Medium
446

A cloud administrator needs to give the security team read-only visibility into all API activity across an AWS account, including who made each call, when, and from which IP address. The records must be retained for 365 days for compliance. Which service should the administrator use?

Easy
447

A cloud user is unable to connect to a web server VM from the internet after a security group rule was modified. The VM is running and can be pinged from other VMs in the same subnet. What is the most likely cause?

Easy
448

A company wants to centralize logs from multiple AWS services and analyze them using SQL-like queries. Which service should they use?

Easy
449

A cloud engineer manages a Kubernetes cluster on Google Kubernetes Engine (GKE). An application team reports that a compromised container in the 'payments' namespace attempted to read secrets belonging to the 'analytics' namespace, but the request was denied. The engineer wants to enforce a policy that restricts pod-to-pod traffic so that only pods labeled 'app=frontend' can reach pods labeled 'app=api' on TCP port 8080, while denying all other ingress to the api pods. Which mechanism should the engineer implement?

Medium
450

A cloud administrator is designing network security for a three-tier application. The web tier must be accessible from the internet, but the application and database tiers should only be reachable from the web tier. Which security group configuration should be used?

Medium
451

A cloud administrator needs to ensure that log data is retained for one year to meet compliance requirements. Which action should be taken for the log group in CloudWatch Logs?

Easy
452

A cloud administrator manages workloads in Microsoft Azure. The security team requires that all virtual machines apply operating system updates automatically during a defined window without the administrator logging in to each machine. Which Azure feature should the administrator use to meet this requirement?

Easy
453

A company is deploying a containerized application on AWS Fargate. The application requires a persistent, shared storage volume that can be accessed by multiple tasks simultaneously and must survive task restarts. The storage must be highly available and scalable. Which storage solution should the company use?

Hard
454

A company is experiencing intermittent connectivity issues between its on-premises data center and a public cloud environment over a VPN connection. Which TWO of the following should the administrator check to troubleshoot the problem?

Medium
455

Which of the following is a characteristic of serverless computing (FaaS)?

Easy
456

A company is migrating to the cloud and needs to transfer 200 TB of data from an on-premises data center to GCP. The network bandwidth is limited, so they want to use a physical appliance for offline transfer. Which GCP service should they use?

Easy
457

A cloud administrator notices that a virtual machine is unresponsive. The VM is running on a hypervisor host that shows high CPU utilization. What should the administrator do first?

Easy
458

A cloud administrator is tasked with reducing costs for a development environment that runs 24/7. The environment consists of several virtual machines and a load balancer. Which action would most effectively reduce costs without affecting developer access during business hours?

Easy
459

A company runs a containerized application on a Kubernetes cluster. The application logs indicate occasional 'CrashLoopBackOff' errors. The developer says the application works fine locally. What is the most likely cause in the cloud environment?

Hard
460

A cloud administrator receives an alert that the CPU utilization on a production web server has exceeded 90% for the past hour. The administrator checks the metrics and sees that the request rate has increased. Which of the following is the MOST appropriate action to resolve the issue in the short term?

Medium
461

A cloud operations team manages a fleet of Amazon EC2 instances behind an Application Load Balancer. During a recent incident, several instances stopped passing their ELB health checks but the Auto Scaling group did not replace them. The team wants the Auto Scaling group to automatically terminate and replace instances that fail ELB health checks, not just EC2 status checks. Which action should the team take?

Medium
462

A cloud architect is designing a highly available three-tier application on AWS. The web tier must survive the loss of a single Availability Zone, and the database tier must support automatic failover with minimal administrative intervention. Which TWO design decisions should the architect implement? (Choose two.)

Medium
463

Refer to the exhibit. A cloud load balancer is returning 502 Bad Gateway errors to clients. What is the most likely cause?

Medium
464

A cloud administrator is investigating a sudden increase in cost for a production environment. The administrator wants to identify the sources of the cost increase and implement a tagging strategy for cost allocation. Which TWO actions should the administrator take? (Choose two.)

Medium
465

A cloud engineer is tasked with setting up a disaster recovery (DR) plan for a critical application that runs on virtual machines in a private cloud. The DR site is a public cloud. The application requires low recovery time objective (RTO) of less than 15 minutes and recovery point objective (RPO) of less than 5 minutes. Which of the following replication strategies BEST meets these requirements?

Medium
466

A company uses AWS and Azure for redundancy. They deploy the same application on both clouds to avoid vendor lock-in and improve disaster recovery. Which cloud deployment model is this?

Medium
467

A company wants to be notified when their monthly AWS spending exceeds $10,000. Which AWS service should they use to set up this alert?

Easy
468

A cloud engineer is deploying a containerized application on Amazon ECS using the Fargate launch type. The application requires a persistent shared storage volume that can be accessed by multiple tasks simultaneously. The engineer needs to ensure that the storage is highly available and can be mounted to multiple ECS tasks across different Availability Zones. Which storage solution should the engineer use?

Hard
469

A cloud security team needs to ensure that all API calls made to the cloud provider are logged and monitored for suspicious activity. Which service should be enabled?

Easy
470

A company uses a cloud-based logging service to aggregate logs from multiple servers. Suddenly, the logging service stops receiving logs from several servers. The administrator checks the logging agent status on those servers and finds that the agents are running but not sending data. The network connectivity between the servers and the logging service is verified as working. Which of the following is the MOST likely cause?

Medium
471

A DevOps team wants to deploy a Kubernetes application using a package manager that simplifies the deployment process by bundling all Kubernetes resources into a single package. Which tool should the team use?

Easy
472

Which storage type is most appropriate for a shared file system that multiple virtual machines need to mount simultaneously with read/write access?

Easy
473

Which THREE of the following are best practices when deploying a cloud application using Infrastructure as Code (IaC)? (Choose three.)

Hard
474

A cloud engineer deploys the Kubernetes manifest shown in the exhibit. After deployment, the frontend pods are in CrashLoopBackOff state. The engineer checks the logs and finds 'OOMKilled' errors. Which of the following changes would resolve the issue?

Medium
475

A cloud engineer is using Ansible to automate the configuration of cloud resources. The engineer needs to ensure that the automation does not require any agent software to be installed on the target nodes. Which characteristic of Ansible makes this possible?

Medium
476

During a disaster recovery test, a cloud administrator discovers that the standby database in a different region is not synchronized with the primary. The primary database uses asynchronous replication. What is the MOST likely reason for the sync failure?

Medium
477

An administrator is writing an Ansible playbook to provision cloud resources across multiple cloud providers. The playbook must manage instances in AWS, Azure, and GCP. Which Ansible concept should the administrator use to interact with each cloud provider's API?

Medium
478

A company operates a multi-tier web application on AWS. The web tier runs on EC2 instances behind an Application Load Balancer. The application tier runs on EC2 instances that connect to an RDS MySQL database. Recently, users have reported slow page load times. The cloud administrator investigates and finds the following: CPU utilization on web and app tier instances is below 50%, memory usage is normal, but the RDS instance's CPU utilization is consistently above 80% and the number of database connections is at the maximum. The administrator also notices that the application code opens a new database connection for each HTTP request and does not close them properly. Which action should the administrator take to resolve the performance issue?

Hard
479

A cloud administrator is deploying a microservices application on Kubernetes in a public cloud. The services must be able to discover each other dynamically and route traffic without hardcoded IP addresses. Which Kubernetes resource should the administrator use to provide a stable network endpoint for a set of pods?

Easy
480

A cloud administrator needs to ensure that application logs are retained for three years to comply with regulatory requirements. Which of the following is the MOST cost-effective solution?

Easy
481

A cloud administrator is investigating why a virtual machine is running slowly. The administrator checks the hypervisor performance metrics. Which TWO of the following metrics indicate CPU contention? (Choose TWO.)

Easy
482

A company is designing a highly available architecture for a critical application. The solution must tolerate the failure of an entire availability zone. Which TWO design principles should be implemented? (Choose two.)

Hard
483

Match each cloud deployment model to its description.

Medium
484

A cloud administrator notices that an auto-scaling group is frequently adding and removing instances due to brief spikes in CPU usage. What should be adjusted to stabilize the scaling activity?

Hard
485

A company uses a cloud load balancer to distribute traffic to a group of web servers. After a recent update, some users report being redirected to a maintenance page when the application is actually available. What is the most likely cause?

Medium
486

A cloud engineer is setting up automated patching for Linux instances in AWS. They need to define a maintenance window during which patches are applied. Which service should they use?

Medium
487

A media company stores finished video masters in Amazon S3. Regulators require that each master be retained unaltered for exactly seven years, and that no user, including the root account, be able to delete or overwrite it during that period. Which S3 capability should the administrator implement?

Easy
488

A cloud engineer is troubleshooting a Microsoft Azure virtual machine that becomes unresponsive under sustained load. The engineer suspects a storage performance bottleneck but needs to confirm whether the issue is IOPS throttling or throughput throttling on the managed disk. Which Azure Monitor metrics should the engineer examine to distinguish between these two causes?

Hard
489

A cloud administrator is planning a migration of on-premises workloads to a public cloud. Which THREE factors should the administrator consider to ensure minimal downtime? (Choose three.)

Medium
490

A cloud architect is designing a multi-tier application. The application tier needs to access a database, but the database should not be reachable from the internet. Which network security control should be used?

Medium
491

A company is adopting Infrastructure as Code (IaC) to manage its cloud resources. Which THREE statements are true about IaC? (Select THREE.)

Easy
492

During a security audit, an organization discovers their cloud-based database is accessible from any public IP address due to a firewall rule allowing 0.0.0.0/0 on port 3306 (MySQL). The database must remain accessible to remote developers working from home. What is the most effective remediation?

Hard
493

An organization wants to deploy a new microservice to a Kubernetes cluster with zero downtime. The deployment should update pods gradually by replacing old pods with new ones, and if the new pods fail health checks, the rollout should stop. Which Kubernetes deployment strategy meets these requirements?

Medium
494

Which cloud service model gives the customer the most control over the operating system and applications, while the provider manages the physical hardware, network, and storage?

Easy
495

A company decides to use AWS for compute and Azure for storage to leverage best-of-breed services. This is an example of which cloud deployment model?

Easy
496

A cloud engineer needs to deploy a Lambda function that processes objects uploaded to an S3 bucket. The function code is stored in a .zip file. Which event trigger should the engineer configure to invoke the function automatically?

Easy
497

A company is experiencing latency issues when accessing a cloud-based application. The cloud administrator runs a traceroute and notices high latency at the ISP's edge router. Which of the following is the MOST likely cause?

Easy
498

A cloud administrator notices that an Auto Scaling group is launching and terminating instances too frequently, causing instability. What should the administrator adjust to reduce this flapping behavior?

Medium
499

A cloud engineer is deploying a new version of a web application to a Kubernetes cluster. The application must remain available during the update, and the team wants to minimize the risk of exposing users to a faulty version. They decide to use a deployment strategy that gradually shifts traffic to the new version while monitoring for errors. Which Kubernetes resource should they configure to achieve this?

Medium
500

Which THREE of the following are valid methods to manage identity and access in a multi-cloud environment?

Hard
501

Which THREE of the following are valid considerations when selecting a cloud deployment model (public, private, hybrid)? (Choose three.)

Hard
502

A cloud administrator is troubleshooting a web application that is hosted on a VM in a public cloud. Users report that the application is intermittently unavailable. The administrator checks the cloud provider's status page and sees no ongoing incidents. Which two actions should the administrator take to diagnose the issue? (Choose two.)

Medium
503

A company uses GCP and wants to ensure that log entries from Compute Engine instances are automatically exported to BigQuery for analysis. The logs must include structured JSON data. Which GCP service should be configured to route logs?

Hard
504

A cloud administrator needs to apply a critical security patch to a virtual machine that is part of a production application. The application must remain available during patching. Which of the following is the BEST approach?

Easy
505

A cloud engineer is writing a Bicep file to deploy Azure resources. Bicep is a domain-specific language (DSL) that transpiles to ARM templates. Which of the following is a benefit of using Bicep over ARM JSON templates?

Medium
506

A cloud operations team runs a Kubernetes cluster on Google Kubernetes Engine (GKE). They need to ensure that a critical payment microservice is automatically restarted if its container process fails, and that a new Pod is created if the node hosting it becomes unhealthy. Which Kubernetes object should they configure to meet these requirements?

Medium
507

A company is deploying a containerized application on Amazon ECS. The operations team needs to ensure that the application can scale automatically based on CPU utilization and that the underlying container instances are managed without manual intervention. They also want to minimize the operational overhead of managing the container host infrastructure. Which ECS launch type should they use?

Medium
508

A cloud architect is reviewing costs for a production environment. The environment uses a mix of EC2 instances and RDS databases. Which THREE of the following are effective cost optimization strategies?

Medium
509

A cloud engineer is troubleshooting a performance issue in a multi-tier application on AWS. The web tier shows high latency, but the application logs indicate no errors. The engineer wants to trace a request end-to-end across services. Which AWS service should be used?

Hard
510

A virtual machine in a cloud environment is experiencing high disk I/O latency. The administrator checks the performance metrics and sees that the disk queue length is consistently above 100. What is the best immediate action?

Easy
511

A cloud administrator notices that an application's latency has increased. The application is distributed across multiple microservices. Which tool can help trace requests across services to identify the bottleneck?

Medium
512

A cloud engineer is troubleshooting an issue where a virtual machine (VM) in a VPC cannot communicate with an on-premises database server through a site-to-site VPN. The VPN tunnel status shows 'UP' and the on-premises firewall logs show packets from the VM's public IP (but the VM is in a private subnet with no public IP). What is the MOST likely cause?

Hard
513

A cloud architect is designing a multi-tier application that must remain available during a single Availability Zone failure. Which TWO design principles should the architect apply?

Easy
514

A company uses Azure and wants to set up an alert that triggers when the average CPU of a virtual machine exceeds 90% for the past 15 minutes. The alert should send an email to the operations team. Which Azure resources are needed?

Medium
515

A company wants to reduce costs by identifying underutilized EC2 instances. Which tool should they use to get rightsizing recommendations?

Medium
516

A company is deploying a new application on AWS and wants to automate the creation of infrastructure using infrastructure as code. The team needs to define resources such as Amazon VPC, subnets, and security groups in a template that can be version-controlled and reused across multiple environments. Which AWS service should they use?

Easy
517

A company is migrating a 50 TB on-premises database to AWS RDS MySQL. The migration must have minimal downtime and support ongoing replication during the cutover. The database schema is standard MySQL. Which combination of services should the company use?

Hard
518

A cloud administrator needs to apply security patches to a group of Windows servers during a maintenance window to minimize disruption. Which type of service should be used?

Medium
519

A containerized application deployment fails with an 'ImagePullBackOff' error. What should the administrator verify?

Medium
520

A cloud administrator is troubleshooting a web application that is hosted on multiple virtual machines behind a load balancer. Users report that the application is occasionally slow, but the load balancer health checks show all instances as healthy. The administrator suspects that one of the virtual machines is performing poorly. Which of the following should the administrator do to confirm this suspicion?

Easy
521

A cloud administrator is investigating a performance issue with a cloud-based application. The application's response time has increased significantly. Monitoring shows low CPU and memory, but high network latency. Which two actions should the administrator take? (Choose two.)

Hard
522

An organization wants to ensure that only authenticated users from their corporate Active Directory can access cloud resources. Which federation protocol is most commonly used for this purpose?

Medium
523

A company is planning to migrate a 200 TB on-premises file server to AWS S3. The network link is 1 Gbps and cannot be saturated due to other traffic. The migration must be completed within two weeks. Which TWO services or features should the cloud engineer consider to accelerate the transfer? (Choose two.)

Medium
524

A cloud architect is choosing a compute pricing model for a batch processing job that runs for 2 hours every night. The job can be interrupted. Which option is most cost-effective?

Medium
525

A cloud administrator is managing a hybrid cloud environment where on-premises servers connect to a public cloud VPC via a site-to-site VPN. Users report intermittent connectivity issues to cloud resources. The administrator examines the VPN tunnel logs and sees 'Phase 2 negotiation failed' errors. Which of the following is the MOST likely cause?

Hard
526

A cloud administrator is troubleshooting a web application hosted on a cloud virtual machine (VM) that is experiencing intermittent high latency during peak traffic hours. The application is deployed on a single VM instance with 4 vCPUs and 8 GB RAM, running a Linux OS. The VM is connected to a virtual network with a public IP. The administrator has verified that the application code is optimized and there are no memory leaks. CPU utilization remains below 50% during peaks, but network outbound traffic shows periodic spikes up to 500 Mbps. The VM's network interface is configured with a 1 Gbps bandwidth cap. The administrator suspects that the issue is related to network throttling or packet loss. Which of the following actions should the administrator take to resolve the issue?

Hard
527

In the shared responsibility model, which of the following is the cloud customer responsible for?

Easy
528

A cloud architect is designing a highly available web application on AWS. The application must continue serving traffic even if an entire AWS Availability Zone fails. Which architecture should the architect implement?

Medium
529

A cloud operations team is using AWS and needs to monitor the CPU utilization of a fleet of Amazon EC2 instances. The team wants to receive an alert when the average CPU utilization exceeds 80% for 5 consecutive minutes. Which AWS service should they use to create the alarm?

Easy
530

A company wants to implement a disaster recovery strategy with an RTO of 15 minutes and an RPO of 1 minute for a critical database. Which approach should be used?

Hard
531

A cloud administrator is troubleshooting connectivity issues between two virtual networks in a public cloud. The networks are in the same region but different VPCs. Both VPCs have route tables and security groups configured. Instances in VPC A cannot ping instances in VPC B. Which of the following is the most likely cause?

Hard
532

A company uses Azure and wants to connect its on-premises data center to Azure with a dedicated, private, and high-bandwidth connection. Which service should the company use?

Medium
533

A cloud administrator is responsible for a Microsoft Azure environment. The administrator needs to ensure that virtual machine (VM) disks are backed up daily and that backups are retained for 30 days. The administrator also needs to be able to restore individual files from the backups. Which TWO actions should the administrator take to meet these requirements? (Choose two.)

Medium
534

A cloud operations team uses a configuration management tool to apply patches to hundreds of Linux servers. Recently, the automation script that applies security patches has been failing with an error: 'Package not found.' The administrator verifies that the patch repository URL is correct and that the servers have internet access. The script runs every Sunday at 2:00 AM and the failures started two weeks ago. The failed patches are all for the latest kernel update. What should the administrator check FIRST?

Easy
535

A cloud engineer is deploying a web application on AWS and needs to ensure that the application is fault-tolerant across multiple Availability Zones. The engineer plans to use an Auto Scaling group with a launch template. What should the engineer configure to ensure that instances are launched in multiple Availability Zones?

Medium
536

An organization uses CloudFormation to manage resources across multiple AWS accounts. They need to deploy a common set of resources (e.g., logging configuration) to all accounts in an AWS Organization. Which CloudFormation feature should they use?

Hard
537

A cloud administrator is configuring a notification channel for critical alerts. Which TWO of the following are commonly used notification channels in cloud monitoring systems? (Select TWO.)

Medium
538

An organization needs to connect its on-premises data center to a public cloud with a dedicated, low-latency, and consistent network connection. Which connectivity option should they use?

Medium
539

A company is deploying a cloud-native application that uses containers orchestrated by Kubernetes. The security team wants to enforce the principle of least privilege at the Kubernetes level. Which THREE measures should be implemented? (Choose three.)

Hard
540

A company is performing a disaster recovery test for a critical application. The test reveals that the application's RTO of 1 hour is not being met due to slow database restoration. Which THREE actions could help improve the restoration time? (Select THREE.)

Hard
541

A company is designing stateless application tiers to support horizontal scaling. Which TWO design principles support statelessness? (Select TWO.)

Medium
542

A cloud engineer is migrating a legacy application to AWS. The application requires minimal downtime during the database migration from SQL Server to Aurora MySQL. Which TWO AWS services should the engineer use to achieve this?

Medium
543

A company wants to implement automated patching for their Windows and Linux servers in AWS. They need to schedule patching during a maintenance window and have a rollback plan. Which service should they use?

Hard
544

A cloud engineer is responsible for a fleet of Amazon EC2 instances running a stateless web application. The engineer needs to ensure that if an instance fails a status check, it is automatically replaced without manual intervention. Which AWS feature should be used to meet this requirement?

Hard
545

Which cloud deployment model connects an on-premises data center to a public cloud using VPN or dedicated connections like AWS Direct Connect?

Easy
546

Match each disaster recovery term to its definition.

Medium
547

A company is deploying a web application on Google Cloud that requires low-latency access to static content (images, CSS) for global users. The application also needs to handle SSL termination to reduce load on backend instances. Which TWO services should the architect use? (Select TWO.)

Hard
548

A cloud architect is selecting a storage solution for a database that requires low-latency reads and writes. The database will run on a single VM and must support consistent performance. Which storage type is most appropriate?

Medium
549

A cloud operations team runs a fleet of Amazon EC2 instances behind an Application Load Balancer. During a load test, the team notices that healthy targets are being marked unhealthy and removed from rotation whenever a deployment briefly pushes CPU utilization above 90 percent. The team wants the load balancer to remove an instance only when the application stops responding to HTTP requests, not when it is merely busy. Which action should the team take?

Medium
550

A DevOps engineer is designing a CI/CD pipeline for a microservices application. The team wants to isolate each build job to avoid interference. Which cloud concept should be utilized?

Hard
551

Which THREE of the following are common causes of VM migration failures in a cloud environment? (Choose three.)

Hard
552

A security administrator needs to store database credentials and API keys securely in AWS. The credentials must be automatically rotated every 90 days. Which service should the administrator use?

Easy
553

A cloud security team is reviewing a Google Cloud environment. They need to ensure that data stored in Cloud Storage buckets is protected with customer-managed encryption keys and that access to those keys is tightly controlled. Which TWO actions should the team take? (Choose two.)

Hard
554

Which TWO design patterns can help a cloud architect achieve a Recovery Time Objective (RTO) of less than 5 minutes for a critical application?

Hard
555

A cloud engineer notices that an auto-scaling group is adding and removing instances too frequently, causing instability. Which configuration parameter should be adjusted to reduce this behavior?

Medium
556

A security administrator is configuring a Web Application Firewall (WAF) to protect a public-facing web application. The application experiences a high volume of traffic from certain geographic regions that are not serving customers. Which WAF feature should be used to block this traffic?

Hard
557

A cloud engineer is troubleshooting a VM that is experiencing high latency. The VM is hosted on a hypervisor with other VMs. Which TWO metrics should the engineer review to identify if resource contention is occurring?

Medium
558

A company wants to implement a tagging strategy for their cloud resources to track costs by department and project. Tags must be applied to resources such as virtual machines and storage buckets. Which of the following is a best practice for cost attribution using tags?

Medium
559

A company is migrating a large Oracle database (2 TB) from on-premises to AWS RDS for Oracle. They require minimal downtime and need to keep the source database running during migration. Which AWS service should they use to achieve continuous replication?

Medium
560

An organization uses a cloud-based infrastructure with multiple VPCs peered together. The security team notices that traffic between VPCs is not being inspected by the central firewall. What design change should be implemented to ensure all inter-VPC traffic passes through a centralized firewall?

Hard
561

A company uses Azure RBAC to manage access to resources. A user is assigned a Contributor role at the subscription scope. Which of the following is true regarding the scope of this role?

Hard
562

A cloud engineer is troubleshooting a serverless function that is intermittently failing with timeout errors. The function is triggered by an HTTP API and processes data from an external database. The function's timeout is set to 30 seconds. Which of the following is the MOST likely cause of the timeouts?

Easy
563

A financial services company is deploying a critical application on AWS. The security team requires that all data stored in Amazon S3 be encrypted at rest using keys managed by the company, with the ability to audit key usage and rotate keys annually. The company also wants to minimize operational overhead. Which S3 encryption option should the cloud engineer implement?

Hard
564

A cloud administrator needs to grant a developer read-only access to a specific storage bucket in AWS. Which IAM component should the administrator modify?

Easy
565

A financial services firm runs containerized workloads on a managed Kubernetes service. Auditors require that no container can run as root, that privilege escalation is blocked, and that the policy is enforced at admission time without modifying existing deployment manifests. Which control best meets these requirements?

Hard
566

A cloud engineer is responsible for securing a multi-tier application deployed on IaaS. The application consists of web servers, application servers, and database servers. The engineer needs to implement network segmentation to minimize the attack surface. Which of the following is the BEST approach?

Easy
567

A cloud architect is designing a solution to store and retrieve large volumes of unstructured data for a media company. The data must be highly durable, available, and accessible from multiple AWS Regions with low latency. The company also wants to minimize costs for data that is infrequently accessed but must be retained for years. Which AWS service and feature combination should the architect use?

Hard
568

A company uses Azure and wants to enforce multi-factor authentication (MFA) for all administrative users. The solution must be centrally managed and apply to all Azure subscriptions. Which approach should be used?

Hard
569

A cloud architect is designing a deployment strategy for a web application that must handle unpredictable traffic spikes. The application runs in containers on a Kubernetes cluster. The architect wants to minimize costs while ensuring that the cluster can scale out rapidly during spikes. Which deployment strategy best meets these requirements?

Medium
570

A DevOps team wants to deploy a containerized application to a Kubernetes cluster with zero downtime. The team needs to gradually shift traffic from the old version to the new version, monitoring error rates and automatically rolling back if errors exceed a threshold. Which deployment strategy should the team implement?

Medium
571

A company uses Google Cloud Platform (GCP) and wants to enforce that all service accounts used by applications have only the permissions necessary to perform their tasks. Which IAM concept should the administrator apply?

Hard
572

A cloud engineer is configuring a web application on AWS and needs to ensure that only HTTP and HTTPS traffic from the internet is allowed to reach the EC2 instances. Which AWS service should be used to control inbound traffic at the instance level?

Easy
573

A cloud architect is designing an auto-scaling policy for a web application. The application's traffic spikes predictably every weekday at 9 AM and decreases after 5 PM. Which scaling policy is most cost-effective?

Medium
574

A company uses a public cloud PaaS service to run a custom application. They need to ensure the application can handle increased load without downtime. Which action should they take?

Medium
575

Which TWO of the following are benefits of a multi-cloud strategy? (Select exactly two.)

Medium
576

A cloud engineer is responsible for a set of Amazon EC2 instances that run a stateless web application. The engineer must ensure that the application can automatically recover from instance-level failures and that new instances are launched in multiple Availability Zones to maintain high availability. Which combination of AWS services should the engineer use?

Hard
577

A security administrator is configuring a web application firewall (WAF) to protect against SQL injection attacks. Which WAF feature should be enabled?

Medium
578

A company is migrating a legacy stateful application to the cloud. The application currently runs on a single server and stores session data locally. To enable horizontal scaling, which two design changes should the architect recommend? (Select TWO.)

Medium
579

An organization uses multiple cloud providers and wants to centralize secrets management. Which solution would best meet this requirement?

Medium
580

A cloud architect is designing a serverless application on AWS Lambda. The function needs to process messages from an SQS queue. Which event trigger should be configured for the Lambda function?

Easy
581

An organization uses a cloud-based monitoring service to track CPU utilization across a fleet of virtual machines. The administrator notices that one VM consistently shows 100% CPU utilization at the same time each day. Which of the following should the administrator do NEXT?

Medium
582

A cloud operations team runs a three-tier application on Amazon EC2 instances behind an Application Load Balancer. During a peak-traffic event, users report intermittent 503 errors, and the operations team wants to automatically add capacity when the average CPU utilization of the Auto Scaling group exceeds 70 percent for five consecutive minutes, then remove capacity when it drops below 30 percent. Which TWO configuration elements must the team define to accomplish this? (Choose two.)

Medium
583

A cloud architect is designing a containerized microservices platform for a retail company. The company requires that individual services scale independently, that failed containers be replaced automatically without manual intervention, and that the platform abstract away the underlying compute hosts. The operations team has limited experience with cluster management. Which cloud-native orchestration approach BEST meets these requirements?

Medium
584

A cloud administrator is responsible for a Microsoft Azure environment with a hub-and-spoke network topology. The administrator needs to ensure that all traffic from the spoke virtual networks to the internet is routed through a network virtual appliance (NVA) in the hub virtual network for inspection. Which Azure feature should the administrator configure?

Medium
585

A cloud administrator needs to centrally collect, search, and retain application and system logs from hundreds of Amazon EC2 instances and AWS services for troubleshooting and compliance. The administrator wants a managed service that stores logs in durable storage and allows ad hoc queries using a query language. Which AWS service should the administrator use?

Easy
586

A cloud operations team is setting up log-based alerting for security events. They want to use structured logging to facilitate querying. Which TWO practices support effective log-based alerting? (Choose TWO.)

Medium
587

A cloud load balancer is not distributing traffic evenly to backend servers. All servers pass health checks. Which of the following is the most likely cause?

Medium
588

A cloud administrator notices that a storage bucket in a cloud object storage service is publicly accessible. The bucket contains sensitive customer data. What is the most likely cause of this issue?

Easy
589

A cloud administrator runs the `iostat` command on a Linux VM experiencing slow performance. Based on the exhibit, what is the most likely bottleneck?

Hard
590

A cloud engineer is sizing a relational database for an application with unpredictable read volume that spikes sharply during business hours. The database must scale read capacity without downtime and without changing the application's connection string. Which approach should the engineer use?

Medium
591

A cloud engineer is planning a database migration from an on-premises Oracle database to Amazon RDS for PostgreSQL. The migration must minimize downtime and preserve ongoing changes. Which TWO services should the engineer consider using together? (Choose two.)

Medium
592

A cloud administrator wants to troubleshoot network connectivity issues between two VPCs. Which AWS feature provides detailed logs of IP traffic for analysis?

Easy
593

A company wants to optimize cloud costs by identifying underutilized EC2 instances. Which AWS service provides rightsizing recommendations?

Medium
594

Which TWO factors should be considered when choosing a cloud deployment model (public, private, hybrid)? (Select TWO.)

Medium
595

Match each high-availability concept to its description.

Medium
596

A cloud administrator needs to apply security patches to a fleet of 50 Linux servers running on AWS without interrupting business hours. Which approach should the administrator use to schedule patching during a maintenance window?

Medium
597

An organization wants to audit all API calls made in their AWS account. Which AWS service should be enabled to capture these logs?

Easy
598

A cloud architect is designing a landing zone in AWS Organizations. The security team mandates that all member accounts must centrally log API activity and that individual account administrators must not be able to disable or alter the log destination. The architect needs to enforce this across every current and future account with minimal operational overhead. Which combination of actions should the architect take?

Medium
599

A DevOps team sets up a CI/CD pipeline for a containerized application on Kubernetes. They want to test a new version with a small subset of users before full rollout. Which deployment method should they use?

Medium
600

A cloud operations team runs a three-tier web application on AWS. During a recent incident, the on-call engineer received hundreds of Amazon CloudWatch alarms within minutes and could not identify the root cause. The team wants to reduce alarm fatigue while still capturing meaningful signals. Which action should the team take FIRST?

Medium
601

A company is deploying a containerized microservices application on a cloud platform. The operations team needs to manage secrets, such as database credentials and API keys, securely without embedding them in container images. Which solution should they use?

Medium
602

A company uses AWS and wants to optimize costs by receiving recommendations to downsize over-provisioned EC2 instances. Which tool provides rightsizing recommendations?

Medium
603

Match each acronym to its definition.

Medium
604

A company has a policy that all cloud resources must be tagged with 'CostCenter' and 'Project' tags. The cloud operations team uses a monitoring tool to alert when untagged resources are created. The team receives an alert for a new EC2 instance that lacks the required tags. The instance was launched two hours ago by a DevOps engineer who is on leave. The instance is critical for production. What should the administrator do to resolve the compliance violation?

Easy
605

An organization uses Azure and wants to ensure that only authenticated users from its on-premises Active Directory can access cloud resources. The company has Azure AD Connect set up and wants to enable single sign-on (SSO) for cloud applications. Which federation standard should be used?

Medium
606

Which TWO are advantages of using containers over virtual machines? (Select TWO.)

Easy
607

A cloud engineer needs to troubleshoot network connectivity issues between two subnets. Which feature can help capture and analyze network traffic metadata?

Easy
608

A cloud operations team runs a containerized API on Amazon ECS with the Fargate launch type. During peak hours, CPU utilization on the tasks regularly reaches 95 percent and response latency doubles. The team wants the service to add tasks automatically before users notice degradation, and to remove them when demand drops. Which action should the team take?

Medium
609

A development team uses AWS CodePipeline to deploy a web application. They need to insert a manual approval step so that a release manager can review the build before it is deployed to production. Which action should the team take?

Easy
610

Match each troubleshooting command to its function.

Medium
611

A cloud administrator manages a fleet of Linux virtual machines on Google Cloud. A compliance rule requires that an interactive SSH session to any of these instances be brokered through an identity-aware proxy so that sessions are authenticated and auditable, and that no external IP addresses be assigned to the instances. Which solution should the administrator implement?

Medium
612

An organization is designing a VPC with public and private subnets. The web servers must be accessible from the internet, but database servers must not. The architecture also requires high availability across two Availability Zones. What is the minimum number of public subnets and private subnets needed?

Hard
613

A company is designing a disaster recovery plan for its cloud infrastructure. The primary site is in US-East, and the DR site is in US-West. The RPO is 15 minutes, and the RTO is 2 hours. Which replication strategy best meets these requirements at the lowest cost?

Medium
614

A cloud administrator is troubleshooting slow performance on a managed relational database. Read queries against a read replica are fast, but write operations on the primary node take far longer than during testing. Monitoring shows the primary's CPU is moderate, disk queue depth is high, and provisioned IOPS are consistently saturated. Which action should the administrator take to resolve the bottleneck?

Medium
615

A company is deploying a stateful application that requires persistent storage. They are using Kubernetes. Which resource should they create to ensure data persists across pod restarts?

Medium
616

Which cloud deployment model involves using services from multiple public cloud providers to avoid vendor lock-in and leverage best-of-breed solutions?

Easy
617

A company wants to minimize cloud costs for a batch processing job that runs for a few hours each night and can be interrupted. Which pricing model is most appropriate?

Medium
618

Which TWO of the following are valid considerations when deploying a virtual machine in a cloud environment? (Choose two.)

Medium
619

A company is adopting a CI/CD pipeline using Jenkins to deploy a web application. The pipeline must include steps to compile code, run unit tests, package the application, deploy to a test environment, and then deploy to production. Which pipeline stage should be configured immediately after the build stage?

Medium
620

A company's cloud environment has experienced a sudden spike in network traffic, causing a critical application to become unresponsive. Which of the following is the FIRST step the cloud administrator should take to address this issue?

Easy
621

A cloud engineer is investigating a sudden increase in egress charges. The engineer suspects that a misconfigured Amazon S3 bucket is being read frequently from the internet. Which tool should the engineer use to identify the source IP addresses and request patterns for that bucket?

Medium
622

A cloud security team is investigating a potential data breach. Which THREE actions should be taken immediately?

Hard
623

A load balancer log entry shows the above for a request. What is the MOST likely cause of the 504 error?

Medium
624

A cloud administrator runs a deployment script that creates multiple resources using Infrastructure as Code (IaC). The script fails with a "400 Bad Request" error when attempting to create a storage account. Which troubleshooting step should the administrator take first?

Easy
625

A cloud engineer is configuring an auto-scaling group with a lifecycle hook to run a custom script when instances are launched. The script installs software and registers the instance with a load balancer. The engineer wants to ensure the instance does not receive traffic until the script completes successfully. What should the engineer do?

Hard
626

A cloud engineer is deploying a stateful application on Amazon EC2 that requires a persistent block storage volume with the highest possible IOPS and lowest latency for a database. The database will run on a single instance in one Availability Zone, and the engineer needs to choose the appropriate Amazon EBS volume type. Which volume type should the engineer select?

Hard
627

A company is deploying a global web application and wants to reduce latency for users around the world. The application serves static content (images, CSS) and dynamic API responses. Which combination of services should the architect use?

Medium
628

A cloud architect is designing a globally distributed application on Google Cloud. The application must serve users from the closest possible point of presence with minimal latency while using a single anycast IP address. Which load balancing solution should the architect choose?

Medium
629

Which of the following is the cloud provider's responsibility under the shared responsibility model?

Easy
630

A startup is deploying a web application on a public cloud and expects variable traffic throughout the day. The team wants to minimize costs while ensuring that the application can handle sudden spikes in demand. Which scaling strategy best meets these requirements?

Easy
631

A cloud engineer is using Terraform to manage infrastructure. They need to store the state file remotely for team collaboration and to enable state locking. Which THREE of the following backends support state locking? (Select THREE.)

Easy
632

Refer to the exhibit. A cloud administrator sees this log after a nightly backup job. Which of the following is the most likely cause of the timeout?

Hard
633

A company is migrating a legacy application to AWS. The application requires a shared file system that can be mounted on multiple Linux-based EC2 instances simultaneously. The file system must be highly available and scalable, and it must support POSIX permissions. Which AWS service should be used?

Medium
634

A company uses a multi-cloud environment with AWS and Azure. They want to centralize log collection and enable advanced querying for troubleshooting. Which combination of services should they use?

Medium
635

A cloud engineer is troubleshooting an issue where users cannot connect to a web application hosted on a cloud VM. The VM's security group allows HTTP (port 80) from 0.0.0.0/0, and the VM's OS firewall is disabled. The engineer can ping the VM's public IP from the internet. What is the most likely cause of the issue?

Medium
636

A cloud engineer is deploying a web application to a Kubernetes cluster. The application requires zero downtime during updates, and the team wants to test new versions with a small percentage of users before full rollout. Which deployment strategy should the engineer use?

Medium
637

A cloud engineer is deploying a serverless application that processes images uploaded to an object storage bucket. The application must automatically resize each image and store the resized version in a second bucket. The engineer wants to minimize operational overhead and ensure the processing runs only when new images are added. Which AWS service should the engineer use to trigger the processing?

Medium
638

A cloud operations team manages a fleet of Amazon EC2 instances running a stateless web tier behind an Application Load Balancer. The team wants to replace instances automatically when an instance fails an Elastic Load Balancing health check, without manual intervention, while keeping the desired capacity constant. Which AWS feature should the team configure to meet this requirement?

Medium
639

A cloud administrator is deploying a critical application that requires the lowest possible latency between compute instances. The instances will be running in a private subnet and must communicate with each other using their private IP addresses. Which of the following deployment configurations would best meet these requirements?

Hard
640

A security administrator needs to enforce least privilege for a Kubernetes cluster in a cloud environment. Which approach should be used to restrict permissions for pods that need to access the cloud provider's API?

Hard
641

A company uses AWS and wants to centralize security monitoring across multiple accounts. Which service should they use to aggregate security findings and check compliance against standards like CIS AWS Foundations?

Medium
642

A cloud administrator notices that a cloud-based application is running slowly. The administrator checks the cloud monitoring dashboard and sees that CPU utilization is at 95% for the application server. Which of the following should the administrator do first?

Easy
643

A cloud engineer is deploying a serverless function using AWS Lambda. The function needs to process messages from an SQS queue. Which event source should be configured to trigger the Lambda function?

Medium
644

A cloud administrator needs to automate the patching of operating systems on a fleet of EC2 instances. Which AWS service should be used?

Easy
645

A cloud engineer manages a Kubernetes cluster on Google Kubernetes Engine. A production Deployment repeatedly enters CrashLoopBackOff after a configuration change, and the engineer needs to inspect why the container is terminating without modifying the running workload. Which action should the engineer take?

Hard
646

A company uses Azure and needs shared file storage accessible from multiple Linux VMs using standard file sharing protocols. Which storage type should they choose?

Medium
647

A cloud engineer notices that an application is running slower than expected. Monitoring shows that the CPU utilization is consistently below 30%, but memory usage is at 95%. Which of the following is the most likely cause of the performance issue?

Easy
648

A cloud administrator is reviewing a security audit report that shows an instance has been sending outbound traffic to a known malicious IP address. The instance hosts a production application. Which action should the administrator take first?

Medium
649

During a security assessment, a cloud auditor discovers that a virtual machine has a publicly accessible SSH port (22) open to the entire internet (0.0.0.0/0). The VM is a bastion host intended for administration. What should be done to reduce risk?

Medium
650

A company has a hybrid cloud environment with an on-premises data center and Microsoft Azure. The on-premises infrastructure includes a VPN gateway connected to an Azure virtual network via site-to-site VPN. The network team reports that traffic from on-premises to Azure is experiencing high latency and packet loss. The VPN tunnel status shows as connected. The team has verified that the on-premises firewall is not dropping packets. The Azure administrator checks the virtual network gateway metrics and sees high inbound packet drops and a high number of VPN tunnel rekeys. What is the MOST likely cause of the issue?

Medium
651

A company is using Azure VMs and wants to centralize logs from multiple applications for security analysis. The logs must be retained for 2 years. Which Azure service should they use?

Medium
652

A cloud administrator is troubleshooting a performance issue in a virtualized environment. Which TWO metrics should be monitored to identify CPU contention on the hypervisor?

Hard
653

A cloud security engineer is responsible for an AWS environment that stores regulated data in Amazon S3 buckets. An audit finding states that data at rest in S3 is not encrypted with a customer-managed key, and the organization must retain control over key rotation and access policies. The engineer must implement encryption that satisfies the audit while minimizing changes to existing applications. Which approach should the engineer take?

Hard
654

An organization needs to store archival data for 7 years to meet compliance requirements. The data is rarely accessed, and retrieval time is not critical. Which cloud storage type is most cost-effective?

Easy
655

A team is developing a serverless application on AWS Lambda. The application uses several third-party libraries that are large in size. To reduce deployment package size and enable reuse across functions, the team wants to include these libraries as a separate layer. However, the total unzipped size of all layers exceeds the Lambda limits. What should the team do to resolve this?

Hard
656

A cloud engineer manages an application running on Amazon ECS with the Fargate launch type. The application occasionally experiences task failures during deployment. The engineer wants to inspect the container's standard output and standard error to determine why a task stopped, without modifying the application to write to a file. Which action should the engineer take?

Hard
657

A company is migrating an on-premises Oracle database to Amazon RDS for MySQL. The migration must have minimal downtime and must handle ongoing changes during migration. The schema needs to be converted to MySQL-compatible format. Which combination of AWS services should the team use?

Hard
658

A financial services company runs a critical application on Google Cloud. The security team requires that all data at rest in Cloud Storage buckets be encrypted with customer-managed encryption keys (CMEK) that are rotated every 90 days. The company also needs to maintain full control over key lifecycle and revoke access immediately if a key is compromised. Which GCP service should be used to manage these keys?

Medium
659

A DevOps team uses infrastructure as code to deploy cloud resources. Security policy requires that all storage buckets have versioning enabled and are not publicly accessible. How can these requirements be enforced automatically?

Hard
660

A cloud administrator is responsible for an application hosted on Amazon EC2 that stores session data in memory. The business requires that, in the event of an instance failure, a replacement instance can resume serving users with the existing session data intact and with minimal interruption. Which action should the administrator take to meet this requirement?

Medium
661

A cloud administrator wants to choose an auto-scaling policy that can respond to changing demand patterns. Which TWO policy types support dynamic adjustments based on real-time metrics? (Choose TWO)

Medium
662

A cloud administrator is managing a multi-tier application in a public cloud. The database tier is hosted on a VM with a persistent disk. Users report that the application is slow, and the administrator notices that disk I/O latency is high. The VM's disk is a standard network-attached storage volume. Which action should the administrator take to improve disk performance?

Medium
663

Which of the following compliance frameworks is specifically designed for handling healthcare information in the United States?

Easy
664

A cloud administrator is deploying a virtual machine (VM) in a public cloud and must ensure that the VM can be recovered quickly in case of failure. The administrator configures the VM to use a managed disk. What additional deployment step should be taken to meet the recovery objective with minimal cost?

Medium
665

A company wants to deploy a containerized application to a Kubernetes cluster using a rolling update strategy. They have defined a Kubernetes Deployment manifest. Which field controls the number of pods that can be unavailable during the update?

Medium
666

A cloud security team is implementing encryption for data at rest using customer-managed keys in a cloud KMS. Which THREE practices should be followed?

Hard
667

A company uses CloudFormation to manage infrastructure across multiple AWS accounts. They want to deploy a common set of resources (e.g., VPC, IAM roles) to all accounts in their organization. Which CloudFormation feature should they use?

Medium
668

A cloud architect is designing a multi-tenant SaaS application on AWS. Which of the following security responsibilities is the CUSTOMER responsible for under the shared responsibility model?

Easy
669

A cloud administrator is investigating a sudden increase in latency for a microservices application. Distributed traces show that a single downstream service's response time grew from 20 ms to 2 seconds, and its CPU utilization remains low at 15 percent. The service makes calls to an external third-party API. Which of the following is the MOST likely cause?

Hard
670

A cloud administrator needs to centralize logs from multiple AWS services, including VPC flow logs and application logs, to enable searching and querying. Which solution should be used?

Medium
671

A cloud operations team manages a three-tier application on Google Cloud. After a deployment, users report intermittent 503 errors from the HTTP(S) load balancer, and backend health checks are flapping between healthy and unhealthy. The team suspects the backend instances are being overwhelmed during health check bursts. Which TWO actions should the team take to stabilize the health checks and reduce false failures? (Choose two.)

Hard
672

A cloud architect is designing a multi-account AWS environment and wants to deploy CloudFormation stacks consistently across many accounts. The architect needs a solution that can manage stack instances across multiple accounts and Regions from a single administrator account. Which AWS feature should be used?

Hard
673

A company is designing a hybrid cloud storage solution. Which TWO storage services are suitable for a shared file system accessible from both on-premises and cloud VMs? (Select TWO.)

Medium
674

A DevOps team deploys a containerized application on Amazon EKS. The security team wants to ensure that containers do not run as root and that read-only root filesystems are enforced. Which Kubernetes mechanism should be used?

Hard
675

During a penetration test, a cloud security engineer discovers that a storage bucket is publicly accessible because of a misconfigured block public access setting. The bucket contains encrypted data. Which of the following is the primary risk?

Hard
676

An organization is designing a cloud architecture that must be fault-tolerant within a single region. The architect decides to deploy application instances in multiple Availability Zones (AZs). Which cloud characteristic is being leveraged?

Medium
677

A cloud administrator needs to provide external partners with access to a cloud application using their existing corporate credentials. Which federation protocol should be used?

Medium
678

A cloud engineer is deploying a new version of an application to an Amazon ECS cluster using the rolling update deployment type. The engineer wants to ensure that the new version is deployed without downtime and that the old tasks are terminated only after the new tasks are healthy. Which parameter should the engineer configure?

Medium
679

A cloud engineer is designing a CI/CD pipeline using Azure DevOps. They need to ensure that code changes are automatically built, tested, and deployed to a staging environment, and then after manual approval, deployed to production. Which pipeline configuration should they use?

Hard
680

A cloud engineer is troubleshooting a network connectivity issue between two VPCs in AWS. To analyze traffic patterns and identify dropped packets, which feature should be enabled?

Medium
681

A cloud engineer is deploying a containerized application on Amazon EKS. The application pods need to access an Amazon RDS database. The security team wants to avoid storing database credentials in the container image or environment variables and prefers short-lived credentials. Which mechanism should be used?

Hard
682

After deploying a new cloud application, users report that they cannot connect to the application. The cloud administrator checks the security group rules and finds that the inbound rule for HTTP traffic is missing. What is the best practice to prevent this issue in future deployments?

Easy
683

A cloud administrator is designing a backup strategy for a critical database. The recovery point objective (RPO) is 15 minutes, and the recovery time objective (RTO) is 1 hour. Which backup approach BEST meets these objectives?

Medium
684

A company runs a web application on three virtual machines behind a load balancer. During a traffic spike, one VM becomes unresponsive. The load balancer continues sending traffic to it, causing errors. Which configuration change would prevent this issue in the future?

Medium
685

A company is designing a disaster recovery plan for its critical application. The application must be recovered within 4 hours (RTO) and can tolerate up to 1 hour of data loss (RPO). Which replication strategy is most cost-effective?

Medium
686

A cloud engineer is deploying a stateful application on Amazon EKS. The application requires persistent storage that must be highly available and automatically replicated across multiple Availability Zones. The engineer needs to define the storage class in Kubernetes. Which storage class provisioner should be used?

Hard
687

A company is designing an auto-scaling solution for a stateless application. Which TWO features are essential for the application to scale horizontally without issues? (Select TWO.)

Medium
688

A company is migrating an on-premises MySQL database to Azure SQL Database using Azure Database Migration Service. They want minimal downtime. Which migration mode should they choose?

Medium
689

An organization wants to deploy a new application with zero downtime by switching traffic between two identical production environments. Which deployment strategy should be used?

Easy
690

A cloud administrator needs to provide a shared file system that can be accessed by multiple Linux-based virtual machines in the same VPC. Which storage type should be used?

Easy
691

Which TWO factors should be considered when selecting a cloud region for deploying a globally distributed application to minimize latency?

Medium
692

An organization must comply with a regulation requiring that all data stored in the cloud be encrypted at rest using a cloud provider's native encryption service. The company also needs to maintain control over the encryption keys. Which solution should the architect recommend?

Hard
693

A cloud administrator is tasked with monitoring CPU utilization across a fleet of virtual machines. Which cloud service should be used to collect and visualize this metric?

Easy
694

A company wants to move its on-premises web application to the cloud with minimal code changes to reduce risk. Which deployment strategy is most appropriate?

Easy
695

After deploying a new application version, users get 503 errors. The application runs on Kubernetes in a private cloud. What is the most likely cause?

Hard
696

A company wants to migrate its existing on-premises web application to the cloud to reduce operational overhead. The application runs on a custom Linux distribution with specific kernel modules. Which cloud deployment model would best minimize the need to refactor the application while still reducing maintenance of the underlying infrastructure?

Medium
697

A company wants to track cloud spending by department and project. Which strategy should be implemented to enable cost attribution?

Easy
698

A cloud engineer is troubleshooting a containerized application deployed on a managed Kubernetes cluster. The application pods are repeatedly restarting with 'OOMKilled' status. The engineer reviews the pod specification and sees that the memory request is 512Mi and the memory limit is 1Gi. The application is a Java-based service with a heap size set to 768Mi. Node metrics show that nodes have 8Gi of memory with 2Gi available. Which of the following is the MOST likely cause of the OOMKilled events?

Hard
699

A cloud administrator is managing a Microsoft Azure environment. The administrator needs to enforce a policy that prevents the creation of any Azure Storage account without HTTPS-only traffic enabled and without a minimum TLS version of 1.2. The policy must apply to all current and future subscriptions in the tenant and must be evaluated when resources are created or updated. Which Azure feature should the administrator use?

Hard
700

A cloud administrator is setting up auto-scaling for a web application that uses an SQS queue for incoming requests. The administrator wants to scale the number of EC2 instances based on the queue depth. Which two metrics are appropriate for this auto-scaling policy? (Choose TWO.)

Medium
701

A cloud administrator is tasked with ensuring that all API requests to the cloud management plane are encrypted. Which protocol should be enforced to meet this requirement?

Easy
702

Which encryption standard is most commonly used for data at rest in cloud storage services?

Easy
703

A cloud engineer is deploying a new application on AWS and needs to ensure that the application's environment variables are securely stored and not exposed in the source code or CloudFormation templates. Which AWS service should be used to store and retrieve these secrets?

Easy
704

A cloud engineer is configuring an Azure Storage account that holds regulated customer data. The compliance team requires that data is encrypted at rest with customer-managed keys stored in Azure Key Vault, and that key usage is auditable. Which configuration should the engineer apply?

Easy
705

A company is experiencing intermittent performance issues in a microservices application. Which TWO tools can help diagnose latency problems through distributed tracing? (Choose TWO)

Hard
706

A cloud administrator is optimizing costs for a batch processing workload that runs nightly for 2 hours. The workload can tolerate interruptions. Which THREE purchasing options should the administrator consider? (Choose three.)

Medium
707

A company is deploying a containerized application on Amazon EKS. The security team requires that the application pods use an IAM role to access AWS services without storing credentials in the container images or environment variables. Which approach should the team use?

Hard
708

A financial services firm requires a cloud deployment that keeps sensitive customer data on-premises while bursting compute-intensive risk analysis workloads to a public cloud during peak times. Which deployment model best meets this requirement?

Medium
709

A cloud engineer is investigating intermittent latency in a three-tier application hosted in Google Cloud. The engineer suspects that a specific Compute Engine instance is experiencing packet loss to its database backend. The engineer needs to capture and analyze the traffic at the packet level on the instance without installing third-party agents on the instance and without disrupting production traffic. Which Google Cloud feature should the engineer use?

Medium
710

Which THREE of the following are essential components of a cloud incident response plan? Select three.

Hard
711

A cloud engineer is designing a VPC for a web application that requires a public subnet for a load balancer and a private subnet for application servers. The application servers must access the internet for software updates without being directly accessible from the internet. Which configuration should the engineer implement?

Medium
712

A systems administrator needs to apply a critical security patch to a set of application servers running in a cloud environment. The administrator wants to minimize downtime and ensure that if the patch causes issues, the servers can be rolled back quickly. Which of the following is the BEST approach?

Easy
713

A company uses AWS CloudFormation to manage its infrastructure. After updating a stack, a developer notices that the actual infrastructure differs from the expected template. Which CloudFormation feature should be used to identify these differences?

Easy
714

A cloud administrator is deploying a new application in a cloud environment. The application requires high availability and fault tolerance. Which two design principles should the administrator implement? (Select TWO).

Easy
715

A cloud administrator needs to detect unusual spikes in CPU usage across a fleet of EC2 instances. Which AWS service should be used to create an alarm that triggers when CPU utilization exceeds an expected baseline?

Medium
716

A cloud architect is deploying a web application across multiple availability zones within a single region to achieve high availability. The application requires that if one availability zone fails, traffic should automatically be rerouted to the remaining zones without manual intervention. Which configuration is required?

Medium
717

Which TWO of the following are common vulnerabilities in cloud environments that can lead to unauthorized access? Select two.

Medium
718

A company is migrating a legacy on-premises application to a public cloud. The application currently uses a single monolithic architecture and relies on a local file system for storage. The cloud architect needs to redesign the application to take advantage of cloud-native features. Which design principle should the architect prioritize to ensure scalability and resilience?

Easy
719

A company manages a multi-account AWS environment and wants to deploy consistent infrastructure across several accounts using CloudFormation. The solution must support updates to the infrastructure and detect configuration drift. Which TWO CloudFormation features should be used?

Hard
720

A company stores sensitive customer data in an Amazon S3 bucket. A security audit reveals that the data is encrypted at rest using SSE-S3. The company now requires that they manage and control the encryption keys themselves, including the ability to rotate and revoke them. Which S3 encryption option should be used?

Easy
721

A cloud customer is deploying a virtual machine (VM) in a public IaaS environment. According to the shared responsibility model, which of the following security tasks is the customer responsible for?

Easy
722

A company uses a cloud provider's key management service to encrypt data at rest. The security team wants to ensure that encryption keys are automatically rotated every 90 days to meet compliance requirements. Which feature should be enabled?

Easy
723

A cloud administrator is responsible for a Microsoft Azure environment where several production virtual machines must be backed up nightly. The recovery requirements state that backups must be retained for 90 days, that individual files must be restorable without recovering the entire VM, and that the backup data must be encrypted at rest. Which Azure Backup configuration should the administrator implement?

Medium
724

Arrange the steps to deploy a new virtual machine in a public cloud environment (e.g., AWS, Azure, GCP) in the correct order.

Medium
725

An engineer is deploying a Kubernetes application on EKS and needs to ensure that pods are only considered healthy after a startup delay, and that traffic stops to unhealthy pods. Which two probe types should be configured in the deployment manifest?

Hard
726

A security engineer is designing a data classification policy for a cloud environment. The policy must identify sensitive data, apply appropriate controls, and monitor access. Which THREE of the following should be included in the policy? (Select THREE.)

Hard
727

A cloud engineer is designing a disaster recovery strategy for a critical application hosted on Azure. The application uses a SQL Database and must be able to fail over to a secondary region with minimal data loss. The Recovery Point Objective (RPO) is 5 minutes and the Recovery Time Objective (RTO) is 15 minutes. The engineer needs a solution that automatically replicates data and provides a connection endpoint that remains constant during failover. Which Azure feature should be implemented?

Hard
728

Which of the following is a benefit of using a Cloud Access Security Broker (CASB) for SaaS applications?

Easy
729

A cloud engineer wants to view a dashboard showing cost breakdown by department. Which tool provides pre-built billing dashboards?

Easy
730

A company is selecting a cloud deployment model. They require the ability to keep sensitive data on-premises due to regulatory compliance, but want to leverage cloud resources for burst computing capacity. Which THREE characteristics describe this model?

Medium
731

A company uses AWS and wants to implement a structured logging format to simplify querying and analysis of application logs. Which three best practices should be followed when implementing structured logging? (Choose THREE.)

Hard
732

A company wants to reduce cloud costs by identifying underutilized EC2 instances. Which AWS service provides rightsizing recommendations?

Easy
733

A company runs a stateful application that maintains session data in memory on the server. The application experiences performance issues during traffic spikes. Which design change would best improve scalability?

Medium
734

A cloud security architect is designing a data protection strategy for a multi-tenant SaaS application hosted in a public cloud. The application stores tenant data in object storage and a managed relational database. Regulators require that each tenant's data be cryptographically isolated so that a key compromise for one tenant cannot expose another tenant's data, and that the organization be able to prove key usage is auditable. Which TWO measures should the architect implement? (Choose two.)

Hard
735

A cloud engineer is writing a Terraform configuration to deploy an AWS EC2 instance. Which file extension is typically used for Terraform configuration files written in HCL?

Easy
736

A cloud administrator is investigating a sudden increase in egress charges for an application running on multiple Linux VMs in a public cloud. The application makes frequent calls to a third-party REST API over the public internet. Which action should the administrator take FIRST to identify the source of the unexpected egress traffic?

Medium
737

A DevOps engineer is deploying a containerized application to Amazon ECS using the Fargate launch type. The application must be highly available across multiple Availability Zones and automatically scale based on CPU utilization. The engineer has already created a task definition and an Application Load Balancer. Which additional configuration is required to meet these requirements?

Hard
738

A company is deploying a multi-tier application in a cloud environment. The application must comply with PCI DSS, which requires encryption of data at rest and in transit. The database tier must be isolated from direct internet access, while the web tier must be accessible from the internet. Which of the following deployment architectures best meets these requirements?

Hard
739

A company uses a hybrid cloud model with an on-premises data center connected to a public cloud via a VPN. Users report intermittent connectivity issues to cloud applications. Which THREE components should the administrator check to isolate the problem? (Choose three.)

Hard
740

A cloud operations team is deploying a three-tier application across multiple availability zones. To meet a strict recovery time objective, they want the application to keep serving traffic if an entire availability zone becomes unavailable. Which TWO design actions should the team take? (Choose two.)

Hard
741

A cloud architect is designing a deployment for a multi-tier application on AWS. The application consists of a web tier, an application tier, and a database tier. The architect needs to ensure that the deployment is highly available and can survive an Availability Zone failure. Which two configurations should be included in the design? (Choose two.)

Medium
742

Which TWO of the following are key components of a disaster recovery plan in the cloud? (Select TWO.)

Medium
743

A cloud operations team supports a latency-sensitive application running on Amazon EC2 instances. Users in a remote region report that responses are slow even though the application's own metrics show normal processing times. The team wants to continuously measure the network path between the users' region and the application endpoint, capturing round-trip latency and packet loss without modifying the application. Which AWS service should they use?

Medium
744

A cloud engineer is designing a VPC in AWS for a three-tier web application. The web servers must be accessible from the internet, the application servers should only be accessible from the web servers, and the database servers should only be accessible from the application servers. What is the most secure VPC design?

Hard
745

A cloud architect is designing a deployment for a multi-tier application that must meet compliance requirements for data residency. The application consists of a web tier, application tier, and database tier. Which TWO deployment strategies should the architect consider to ensure data remains in a specific geographic region while maintaining high availability?

Hard
746

A cloud engineer is designing a serverless application that processes messages from an Amazon SQS queue. The application must scale automatically based on the number of messages in the queue and must handle failures gracefully by retrying failed messages. Which AWS service should the engineer use to run the application code?

Hard
747

A cloud engineer is troubleshooting a storage performance issue. The storage is backed by a SAN with a mix of SSD and HDD drives. Which of the following metrics would BEST indicate that the storage subsystem is the bottleneck?

Hard
748

A cloud architect is designing a highly available architecture on AWS for a web application that must survive the failure of an entire Availability Zone. The application uses an Application Load Balancer, web servers, and an Amazon RDS database. Which TWO design actions should the architect take? (Choose two.)

Medium
749

A cloud orchestration template fails to deploy resources with the error 'Resource limit exceeded'. The administrator has enough quota for all services. What is the most likely cause?

Hard
750

A cloud administrator manages a three-tier application in a public cloud. Users report that API calls from the web tier to the database tier fail with connection timeouts, but the database tier responds normally when queried from a bastion host on the same subnet. The web tier instances reside in a different subnet. Which of the following is the MOST likely cause?

Medium
751

A DevOps team deploys a containerized application to a Kubernetes cluster. They need to ensure that containers cannot run with privileged access. Which Kubernetes security mechanism should be applied?

Hard
752

Which TWO of the following are best practices for managing cloud storage in a multi-account environment? (Choose two.)

Easy
753

A cloud engineer is optimizing costs for a data analytics workload that runs periodically. The workload processes large datasets stored in Amazon S3 and runs on EC2 instances. Which THREE strategies should the engineer consider to reduce costs? (Select THREE.)

Hard
754

A company is migrating 100 TB of data from an on-premises NAS to Amazon S3. The network bandwidth is limited to 100 Mbps, and the transfer must complete within 30 days. Which service should the company use to meet the deadline?

Medium
755

A company is migrating its on-premises e-commerce application to a public cloud. The application consists of a stateless web tier, a stateful application tier that stores session data in memory, and a relational database. The migration must ensure high availability, scalability, and minimal downtime during cutover. The cloud provider offers load balancers, auto-scaling groups, managed database services, and caching services. The current on-premises architecture uses a single web server, a single application server, and a single database server. The application tier stores session data in local memory, which is lost if the server fails. The team needs to redesign the architecture to be cloud-native. Which of the following is the BEST course of action?

Hard
756

A cloud engineer is deploying a serverless application using AWS Lambda. The application processes files uploaded to an S3 bucket. To minimize cold start latency, which deployment configuration should the engineer use?

Medium
757

An organization wants to reduce cloud costs by identifying underutilized EC2 instances. Which AWS service provides rightsizing recommendations?

Easy
758

A cloud architect is designing a multi-tier application in a public cloud that must comply with PCI DSS. The web tier must be accessible from the internet, but the application tier should not have any public IP addresses. Which architecture meets these requirements?

Hard
759

A company uses a hybrid cloud model and experiences intermittent connectivity issues between the on-premises network and the public cloud VPC. The administrator has verified that the VPN connection is established. Which of the following should the administrator check next?

Medium
760

A company is deploying a critical financial application on a private cloud. The compliance team requires that all data at rest be encrypted with a key managed by the company's hardware security module (HSM). The cloud architect must select a storage solution that supports customer-managed keys and integrates with the existing HSM. Which storage option should the architect choose?

Hard
761

A startup is deploying a web application on AWS and wants to protect it from common Layer 7 attacks such as SQL injection and cross-site scripting. The application runs behind an Application Load Balancer, and the team wants a managed service that can be deployed quickly with minimal configuration. Which AWS service should they use?

Easy
762

A cloud administrator is tasked with ensuring that a cloud database is backed up daily. The backup must be stored off-site for disaster recovery. Which of the following is the most cost-effective solution?

Easy
763

A company is designing a hybrid cloud architecture. They need to ensure high availability for a critical application. Which TWO of the following are best practices for achieving high availability in a hybrid cloud environment?

Medium
764

A company uses AWS and Azure to run identical workloads for redundancy. They want to simplify management by using a single set of tools across both clouds. Which architectural approach should they consider?

Hard
765

A cloud operations team manages a multi-tier web application on Google Cloud. The application logs are being written to Cloud Logging, and the team needs to be alerted whenever the number of HTTP 500 errors exceeds 50 in a 5-minute window. Which action should the team take to meet this requirement?

Medium
766

A cloud engineer is using Ansible to automate cloud resource provisioning. Which statement about Ansible is true?

Easy
767

A cloud administrator is writing an Ansible playbook to provision cloud resources. The administrator wants to ensure that the playbook can run without requiring any agent software on the target machines. Which Ansible feature enables this agentless operation?

Medium
768

A DevOps team uses Jenkins for CI/CD. They want to automatically deploy containerized applications to a Kubernetes cluster. Which Jenkins feature or plugin can integrate with Kubernetes to manage deployments?

Medium
769

A company is migrating its on-premises application to the cloud and needs to ensure high availability. The application requires a stateless web tier and a stateful database tier. Which design approach BEST meets these requirements?

Easy
770

Which cloud deployment model involves connecting an on-premises data center to a public cloud provider using a VPN or dedicated connection?

Easy
771

A cloud operations team needs to ensure that all Amazon S3 buckets in their AWS account have server access logging enabled. They want to automatically detect and remediate any bucket that does not have logging enabled. Which combination of AWS services should they use?

Medium
772

A cloud engineer is designing a deployment strategy for a web application that requires zero downtime. The engineer has set up two identical production environments, one active and one idle. After deploying the new version to the idle environment, the engineer switches the DNS record to point to the idle environment. This deployment method is known as:

Easy
773

A company runs a customer-facing web application on Azure virtual machines. During a regional outage, the operations team needs to bring up the same environment in a secondary Azure region. The team wants an automated, repeatable deployment that includes virtual networks, load balancers, and VM configurations. Which Azure capability should the team use to meet this goal?

Easy
774

A cloud architect is designing a Kubernetes deployment for a stateless web application. The application must be highly available and automatically recover from failures. Which THREE components are required to achieve this? (Select 3)

Medium
775

Which of the following is a benefit of using a Web Application Firewall (WAF)?

Easy
776

A DevOps team is implementing a canary deployment for a microservice running on Amazon ECS. They want to gradually shift 10% of traffic to the new version and automatically roll back if error rates exceed 1% in 5 minutes. Which combination of services should they use?

Hard
777

A cloud administrator is troubleshooting a Linux virtual machine (VM) in a public cloud that is experiencing packet loss when communicating with another VM in the same subnet. The administrator runs 'ip -s link show eth0' and observes a high number of dropped packets on the receive side. The VM's CPU utilization is low, and the network interface is a paravirtualized driver (virtio). Which of the following is the MOST likely cause of the dropped packets?

Medium
778

A cloud engineer is managing infrastructure as code using Terraform. Which command should be run to preview changes before applying them to the cloud environment?

Easy
779

A cloud operations team runs a three-tier web application on Amazon EC2 instances behind an Application Load Balancer. Users report intermittent 502 errors, and the operations team wants to identify whether the issue originates from unhealthy targets before the load balancer removes them. Which AWS feature should the team enable to actively probe target health at a configurable interval?

Medium
780

A DevOps team is deploying a containerized application to Google Kubernetes Engine (GKE). The team wants to automate the deployment of the application along with its dependencies, such as ConfigMaps and Services, using a single package. Which tool should the team use?

Medium
781

Which THREE are common tasks in a CI/CD pipeline? (Select THREE.)

Hard
782

A company's application is unable to connect to a managed cloud database. The database is deployed in a VPC with public accessibility disabled. The application runs on an EC2 instance in the same VPC. Which three troubleshooting steps should the administrator take? (Choose three.)

Medium
783

A cloud administrator needs to apply security patches to a fleet of EC2 instances running Windows Server. The patches must be applied during a maintenance window to minimize downtime. Which AWS service can automate patching?

Medium
784

A cloud administrator is troubleshooting a performance issue where a web application is responding slowly. The application runs on virtual machines in a private cloud. The administrator has verified that CPU and memory utilization are within normal limits. Which TWO additional metrics should the administrator check to diagnose the issue?

Hard
785

A cloud architect is designing a disaster recovery strategy for a mission-critical application hosted in a single cloud region. The business requires that the application survive the loss of an entire region and that failover be largely automated with minimal data loss. The budget permits a warm standby environment. Which TWO design elements should the architect include to meet these requirements? (Choose two.)

Hard
786

A company uses a hybrid cloud model with an AWS Direct Connect connection to its on-premises network. Users report intermittent connectivity to cloud resources. A network engineer finds packet loss on the Direct Connect virtual interface. Which of the following should be checked FIRST to resolve the issue?

Hard
787

A cloud architect is designing a network to protect a web application from common attacks such as SQL injection and cross-site scripting. Which cloud service should be used?

Easy
788

A cloud administrator receives an alert that the CPU usage on a virtual machine has spiked to 100% for 10 minutes. The VM hosts a critical application. What is the best first step?

Medium
789

A cloud administrator needs to perform a disaster recovery test for a critical application running in a different AWS region. The RTO is 1 hour, and the RPO is 15 minutes. Which replication strategy should be used to meet the RPO?

Medium
790

A security engineer is configuring a network security group (NSG) in Azure to allow inbound HTTPS traffic to a web server. The engineer creates an inbound rule allowing TCP port 443 from the Internet. What must be done to ensure the web server can respond to clients?

Medium
791

A cloud administrator needs to deploy a new application that requires a static IP address. The administrator is using a cloud provider that allows the reservation of elastic IP addresses. Which deployment step should be taken to ensure the IP address is not lost when the resource is stopped?

Easy
792

A cloud administrator manages a fleet of Amazon EC2 instances that must receive operating system patches on a defined schedule. The administrator wants to automate patching, control the maintenance window, and receive compliance reports showing which instances are missing patches. Which AWS service should the administrator use?

Easy
793

A security engineer is configuring an AWS IAM policy for a new application. The policy must allow the application to read objects from a specific S3 bucket. Which IAM policy element determines whether the action is allowed or denied?

Medium
794

A cloud engineer is writing Terraform code to provision AWS resources. They need to define the cloud provider and authentication details. Which block should they use in their HCL configuration?

Easy
795

A cloud administrator notices that a cloud-based web application is experiencing intermittent latency during peak hours. The application runs on an auto-scaling group of virtual machines behind a load balancer. Which of the following should the administrator investigate FIRST to resolve the issue?

Medium
796

According to the shared responsibility model, which of the following is the cloud provider responsible for?

Easy
797

A cloud administrator is troubleshooting a performance issue where an application occasionally experiences high latency. The application runs on AWS and uses EC2, ELB, and RDS. Which combination of tools would best help trace the request flow and identify the bottleneck?

Hard
798

A cloud security team is implementing the principle of least privilege for IAM roles. Which TWO actions are consistent with this principle?

Medium
799

A cloud architect is designing a serverless application using Azure Functions. The function must process messages from an Azure Storage Queue. How should the architect configure the trigger?

Easy
800

A company is moving a legacy monolithic application to the cloud. The application has interdependencies that make it difficult to refactor. The architect needs to minimize changes while gaining cloud benefits like elasticity and pay-as-you-go. Which migration strategy is BEST?

Hard
801

A security auditor is reviewing the IAM configuration for a cloud account. The auditor finds that a user has permissions to create and delete resources in all services. Which principle of security is being violated?

Medium
802

A cloud operations team is designing a disaster recovery plan that includes regular testing. Which TWO activities should be part of the DR testing process? (Select TWO.)

Medium
803

A cloud architect needs to monitor CPU utilization across a fleet of EC2 instances and receive an alert when the average CPU exceeds 80% for 10 minutes. Which AWS service should be used to collect the metric and trigger the alert?

Easy
804

A company runs a critical application on a cloud VM that must achieve a 99.99% monthly uptime SLA. The VM is deployed in a single availability zone. The current architecture has no redundancy. What is the most effective design change to meet the SLA requirement?

Hard
805

A company runs a production application on multiple cloud regions for high availability. They want to minimize latency for global users. Which DNS routing policy should they use?

Medium
806

An organization wants to ensure that only authorized personnel can access the cloud management console. Which of the following is the BEST method to achieve this?

Easy
807

A cloud architect is deploying a serverless application using AWS Lambda. The application must process messages from an Amazon SQS queue. The messages are expected to be processed in order, and the application must handle failures without losing messages. Which configuration should be used?

Medium
808

A cloud administrator notices that a virtual machine running a critical application is using 95% CPU consistently. The application is single-threaded and performance is degraded. Which action should the administrator take to resolve the issue?

Medium
809

A company wants to migrate its on-premises workloads to the cloud while maintaining the ability to run some sensitive applications on-premises. Which cloud deployment model best meets this requirement?

Easy
810

An organization uses Azure DevOps for CI/CD. They want to implement a deployment strategy where a new version of an application is deployed to a small subset of users (e.g., 5%) and if no errors are detected, the percentage is gradually increased to 100%. Which deployment strategy should they use?

Hard
811

A cloud operations team needs to implement a monitoring solution for a microservices architecture. The solution must provide centralized logging, metrics, and alerting, and must be able to correlate data from multiple services. Which THREE of the following components should the team include?

Hard
812

Which of the following is a key benefit of using a Cloud Access Security Broker (CASB)?

Easy
813

An organization uses a cloud-based load balancer to distribute traffic to a web application across multiple availability zones. Users report that the application is intermittently unavailable. The cloud administrator finds that the load balancer health checks are failing on instances in one availability zone. What is the most likely cause?

Medium
814

Which THREE of the following are recommended practices for securing cloud API access? (Choose three.)

Medium
815

A cloud architect is designing an auto-scaling policy for a web application that experiences predictable traffic spikes every weekday morning from 8 to 10 AM. The application runs on a group of virtual machines behind a load balancer. Which scaling approach is MOST cost-effective while ensuring performance during the spike?

Medium
816

A cloud administrator is deploying a new three-tier application on Google Cloud. The web tier must be accessible from the internet, the application tier must only accept traffic from the web tier, and the database tier must only accept traffic from the application tier. The administrator needs to implement network security controls to enforce these requirements. Which two Google Cloud features should be used? (Choose two.)

Medium
817

A DevOps team uses CloudFormation to manage multi-account infrastructure. They need to deploy a common set of resources across multiple AWS accounts in an organization. Which CloudFormation feature should they use?

Medium
818

A cloud administrator is configuring a CASB (Cloud Access Security Broker) for SaaS applications. Which TWO capabilities should the administrator expect from the CASB? (Choose two.)

Medium
819

A cloud security team is hardening a Linux virtual machine that hosts a public-facing API in a public cloud. The team wants to reduce the attack surface at the operating system layer and detect unauthorized file changes. Which TWO measures should the team implement? (Choose two.)

Medium
820

During a cloud deployment, a virtual machine is created from a custom image. After boot, the VM is not accessible via SSH. Which of the following should the administrator check FIRST?

Easy
821

A cloud administrator is troubleshooting a performance issue where an application running on a VM in a private cloud is experiencing high latency. The VM is connected to a virtual switch that uses SR-IOV. The administrator suspects network bottlenecks. Which of the following is the MOST likely cause of the latency?

Hard
822

A company uses a multi-cloud strategy with both AWS and Azure. The cloud operations team needs to centrally monitor all cloud resources and receive alerts when resource usage exceeds predefined thresholds. Which of the following solutions should the team implement?

Hard
823

A cloud operations team supports a microservices application running on Amazon ECS with AWS Fargate tasks. Users report that some requests fail intermittently, and the team suspects that containers are being terminated because they exceed resource limits or fail health checks. The team wants to collect the relevant diagnostic data to confirm the cause. (Choose two.)

Hard
824

A company is implementing a cloud-based SIEM solution. Which TWO of the following are essential data sources that should be integrated to ensure comprehensive security monitoring?

Medium
825

A cloud administrator is troubleshooting a newly deployed web application on a cloud VM. Users cannot access the application via its public IP address, but the administrator can SSH into the VM and access the application locally using curl http://localhost:8080. The VM's security group allows inbound traffic on port 22 and port 80. The application is listening on port 8080. Which of the following is the MOST likely cause of the issue?

Easy
826

A cloud administrator cannot deploy a new VM from a custom image. The deployment fails with an error stating 'Incompatible hypervisor version'. What is the most likely cause?

Easy
827

A company needs to connect its on-premises data center to a public cloud provider with a dedicated, consistent network connection that bypasses the internet. Which connectivity method should be used?

Hard
828

A cloud administrator needs to protect a web application from common attacks such as SQL injection and cross-site scripting (XSS). Which cloud service should be implemented?

Easy
829

A cloud engineer is tasked with automating the deployment of a new web application. Which of the following tools is BEST suited for managing infrastructure as code in a hybrid cloud environment?

Easy
830

A cloud administrator is responsible for a set of Amazon EC2 instances that must be patched on a recurring schedule. The administrator wants to define a maintenance window, register the target instances, and have the system apply operating system patches automatically with a defined baseline. Which AWS service should the administrator use to accomplish this with the least operational overhead?

Medium
831

A cloud architect is designing a disaster recovery plan that includes testing. Which TWO activities are commonly performed as part of DR testing?

Medium
832

A cloud administrator is configuring a new virtual private cloud (VPC) for a three-tier application. The web tier must be accessible from the internet, the application tier should only be accessible from the web tier, and the database tier should only be accessible from the application tier. Which network architecture should be used?

Medium
833

A cloud administrator is configuring an Azure environment for a healthcare application that must comply with HIPAA. Which TWO configurations are required to meet HIPAA security and privacy rules? (Choose two.)

Medium
834

A company wants to automate the deployment of cloud resources using code. Which tool is BEST suited for this purpose?

Easy

Frequently asked questions

What does the scenario questions domain cover on the CV0-004 exam?
scenario questions questions test whether you can apply the concept in context, not just recognise a definition.
How many questions are in this domain?
This page lists all 834 scenario questions questions in the CV0-004 question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only scenario questions questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.