Courseiva
← Back to CompTIA Cloud+ CV0-004 questions

Scenario-based practice

Refer to the Exhibit Practice Questions

Practise CompTIA Cloud+ CV0-004 practice questions — original exam-style scenarios covering every exam domain, with detailed explanations, wrong-answer analysis, and common exam traps.

12
scenario questions
CV0-004
exam code
CompTIA
vendor

Scenario guide

How to approach refer to the exhibit practice questions

Practise exhibit-style questions that ask you to read a topology, table, command output or diagram before choosing the best answer.

Quick answer

Exhibit-style questions test whether you can read a topology, command output, diagram or table before choosing the best answer.

How to extract the relevant detail from an exhibit.

How topology, command output or routing information affects the answer.

How to avoid answering from memory before reading the evidence.

How to map the exhibit back to the exam objective.

Related practice questions

Related CV0-004 topic practice pages

Scenario questions usually connect to one or more exam topics. Use these links to review the underlying concepts behind the scenario.

Practice set

Practice scenarios

Question 1easymultiple choice
Full question →

Refer to the exhibit. A cloud administrator runs this command on a VM. Which of the following is most likely causing the high 'wa' value?

Network Topology
procsmemoryswapio-systemcpuRefer to the exhibit.```
Question 2hardmultiple choice
Full question →

A cloud administrator is troubleshooting connectivity to a web server running on a Linux VM. The web server is configured to listen on ports 80 (HTTP) and 443 (HTTPS). The administrator runs the iptables command shown in the exhibit. Based on the output, what is the MOST likely reason that external users cannot access the web server on port 443?

Exhibit

Refer to the exhibit.

# iptables -L -n -v
Chain INPUT (policy ACCEPT 0 packets, 0 bytes)
pkts bytes target     prot opt in     out     source               destination
 100  12000 ACCEPT     all  --  *      *       0.0.0.0/0            0.0.0.0/0            state RELATED,ESTABLISHED
  50   6000 ACCEPT     tcp  --  eth0   *       0.0.0.0/0            0.0.0.0/0            tcp dpt:22
  20   2400 ACCEPT     tcp  --  eth0   *       10.0.0.0/8           0.0.0.0/0            tcp dpt:443
  10   1200 DROP       tcp  --  eth0   *       0.0.0.0/0            0.0.0.0/0            tcp dpt:80
Question 3hardmultiple choice
Full question →

A cloud administrator is troubleshooting why a newly launched VM did not complete its initialization. According to the exhibit, what is the most likely cause?

Network Topology
force-confold'option=Dpkg::Options::=force-unsafe-io'assume-yes'quiet'Refer to the exhibit.```$ cat /var/log/cloud-init-output.log...
Question 4mediummultiple choice
Full question →

A security engineer is reviewing a cloud storage bucket policy. Which of the following best describes the security issue present in the exhibit?

Exhibit

Refer to the exhibit.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Allow",
      "Principal": "*",
      "Action": "s3:GetObject",
      "Resource": "arn:aws:s3:::mycompany-data/*"
    }
  ]
}
Question 5mediummultiple choice
Full question →

Refer to the exhibit. A cloud load balancer is returning 502 Bad Gateway errors to clients. What is the most likely cause?

Exhibit

[2025-01-20 14:23:45] ERROR Backend "web-svr-01" health check failed (HTTP 502)
[2025-01-20 14:23:46] ERROR Backend "web-svr-02" health check failed (HTTP 502)
[2025-01-20 14:23:47] ERROR Backend "web-svr-03" health check failed (HTTP 502)
Question 6hardmultiple choice
Full question →

Refer to the exhibit. A cloud administrator sees this log after a nightly backup job. Which of the following is the most likely cause of the timeout?

Exhibit

Refer to the exhibit.

```
[ERROR] Backup job failed at 2024-08-21 02:00:00.
Reason: Volume snapshot creation timed out.
Volume ID: vol-0a12345
Snapshot ID: snap-0b67890
```
Question 7easymultiple choice
Full question →

A company hosts its critical applications on a cloud provider's virtual machines within a virtual private cloud. The security team receives an alert from the intrusion detection system indicating that one of the VMs is exhibiting signs of a ransomware infection. The administrator connects to the VM via a bastion host and observes that several important files have been encrypted and a ransom note has been left. The incident response plan is still being developed, but the administrator knows the immediate priority is to contain the threat and prevent it from spreading to other VMs and storage resources. The company has daily backups stored in a separate cloud storage service that is not directly accessible from the production network. Which of the following actions should the administrator take FIRST to contain the incident and minimize further damage?

Question 8mediummultiple choice
Full question →

Refer to the exhibit. The auto scaling group is fluctuating between 2 and 3 instances every few minutes. What is the most likely cause?

Exhibit

[admin@controller ~]$ cldctl log asg-web --type scaling
2025-01-20 14:20:00 INFO Scaling event: Desired capacity changed from 2 to 3
2025-01-20 14:25:00 INFO Scaling event: Desired capacity changed from 3 to 2
2025-01-20 14:40:00 INFO Scaling event: Desired capacity changed from 2 to 3
2025-01-20 14:45:00 INFO Scaling event: Desired capacity changed from 3 to 2
Question 9hardmultiple choice
Full question →

A cloud engineer runs the commands shown in the exhibit. Based on the output, which security issue is present?

Exhibit

Refer to the exhibit.

```
[user@bastion ~]$ gcloud compute instances list --format="value(name,zone,status)"
web-server-1 us-central1-a RUNNING
web-server-2 us-central1-b RUNNING
db-server us-central1-a RUNNING
[user@bastion ~]$ gcloud compute ssh web-server-1 --command="sudo systemctl status nginx"
● nginx.service - A high performance web server
   Loaded: loaded (/usr/lib/systemd/system/nginx.service; enabled; vendor preset: disabled)
   Active: active (running) since Mon 2024-03-14 10:23:45 UTC; 1h 30min ago
[user@bastion ~]$ gcloud compute firewall-rules list --filter="allowed=('tcp:22')"
NAME        NETWORK  DIRECTION  PRIORITY  ALLOW    DENY  DISABLED
allow-ssh   default  INGRESS    1000      tcp:22                False
[user@bastion ~]$ gcloud compute firewall-rules describe allow-ssh
allowed:
- IPProtocol: tcp
  ports:
  - '22'
sourceRanges:
- 0.0.0.0/0
```
Question 10easymultiple choice
Review the full subnetting walkthrough →

Refer to the exhibit. A cloud administrator runs the command to inspect an instance and notices that it is running, but the web application hosted on it is unreachable from the internet. The instance is in a public subnet with an internet gateway attached to the VPC. Which of the following is the most likely cause?

Exhibit

Refer to the exhibit.
```
$ cloud-cli compute instances describe --instance-id i-12345
{
  "instanceId": "i-12345",
  "state": "running",
  "instanceType": "t2.medium",
  "networkInterfaces": [
    {
      "ip": "10.0.1.25",
      "subnetId": "subnet-abc",
      "vpcId": "vpc-xyz",
      "securityGroups": ["sg-web"]
    }
  ],
  "blockDeviceMappings": [
    {
      "deviceName": "/dev/sda1",
      "volumeId": "vol-111",
      "status": "attached"
    }
  ]
}
```
Question 11hardmultiple choice
Full question →

A cloud administrator runs the `iostat` command on a Linux VM experiencing slow performance. Based on the exhibit, what is the most likely bottleneck?

Exhibit

Refer to the exhibit.
```
$ iostat -x 1 3
avg-cpu:  %user   %nice %system %iowait  %steal   %idle
           5.2     0.0    2.1   45.3      0.0   47.4

Device:   rrqm/s   wrqm/s   r/s   w/s   rkB/s   wkB/s avgrq-sz avgqu-sz   await r_await w_await  svctm  %util
xvda       0.00     0.00  85.0  15.0  3400.0  600.0    80.0     4.5    45.0   40.0   70.0   10.0  90.0%
```
Question 12mediummultiple choice
Full question →

A cloud engineer deploys the Kubernetes manifest shown in the exhibit. After deployment, the frontend pods are in CrashLoopBackOff state. The engineer checks the logs and finds 'OOMKilled' errors. Which of the following changes would resolve the issue?

Exhibit

Refer to the exhibit.

```yaml
# deployment.yaml
apiVersion: apps/v1
kind: Deployment
metadata:
  name: frontend
spec:
  replicas: 3
  selector:
    matchLabels:
      app: frontend
  template:
    metadata:
      labels:
        app: frontend
    spec:
      containers:
      - name: nginx
        image: nginx:1.21
        ports:
        - containerPort: 80
        resources:
          requests:
            memory: "256Mi"
            cpu: "250m"
          limits:
            memory: "512Mi"
            cpu: "500m"
---
apiVersion: v1
kind: Service
metadata:
  name: frontend-service
spec:
  type: LoadBalancer
  selector:
    app: frontend
  ports:
  - protocol: TCP
    port: 80
    targetPort: 80
```

These CV0-004 practice questions are part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style CV0-004 questions with detailed explanations, topic-based practice, mock exams, readiness tracking, and study analytics.