Courseiva

CCNA Clp Deployment Questions

75 of 116 questions · Page 1/2 · Clp Deployment topic · Answers revealed

1
MCQmedium

An organization uses AWS CloudFormation to deploy resources across multiple AWS accounts. They need to manage a common set of resources in several accounts from a single template. Which CloudFormation feature should they use?

A.Change sets
B.Nested stacks
C.Drift Detection
D.StackSets
AnswerD

StackSets deploy a single CloudFormation template across multiple AWS accounts and regions from one administration account, satisfying the requirement to manage common resources in several accounts centrally. Stack policies, change sets, and nested stacks operate within one account, so they cannot span accounts.

Why this answer

StackSets allow deploying stacks across multiple accounts and regions. Change sets show changes before execution; Drift Detection detects configuration drift; Nested stacks are for reusability within a single account.

2
Multi-Selecthard

A company is deploying a new application on AWS and needs to ensure that the infrastructure is defined as code. The team wants to use AWS CloudFormation to provision resources. They require that the template can be reused across multiple environments (dev, test, prod) with different configurations, such as instance types and subnet IDs. The team also needs to ensure that changes to the infrastructure are applied in a controlled manner. Which two features should the team use to meet these requirements? (Choose two.)

Select 2 answers
A.Use CloudFormation drift detection to identify resources that have been modified outside of CloudFormation.
B.Use CloudFormation parameters to pass environment-specific values into the template.
C.Use CloudFormation stack policies to prevent updates to specific resources.
D.Use CloudFormation change sets to preview how proposed changes will impact running resources before executing them.
E.Use CloudFormation nested stacks to modularize the template into smaller, reusable components.
AnswersB, D

CloudFormation parameters allow you to input custom values when creating or updating a stack, such as instance types, key pairs, and subnet IDs. This enables template reuse across environments without modifying the template itself. Parameters can have default values, allowed values, and descriptions, making them ideal for environment-specific configurations. This directly addresses the requirement for different configurations per environment.

Why this answer

Parameters enable the same CloudFormation template to be used across multiple environments by supplying different values at stack creation or update time. Change sets allow you to preview the effects of updates before applying them, ensuring controlled changes. Together, they satisfy the need for reusable templates with environment-specific configurations and safe, controlled updates.

The other features address different concerns such as modularity, resource protection, and drift detection.

Exam trap

The trap here is confusing features that improve template organization or safety with those that directly enable environment-specific customization and controlled change preview.

3
MCQmedium

A company is deploying a web application on AWS using an Application Load Balancer (ALB) and an Auto Scaling group. The application must handle sudden traffic spikes without manual intervention. The engineer needs to configure the Auto Scaling group to scale based on the number of requests per target. Which CloudWatch metric should be used as the basis for the scaling policy?

A.ALB ActiveConnectionCount
B.Auto Scaling Group DesiredCapacity
C.ALB RequestCountPerTarget
D.EC2 CPUUtilization
AnswerC

RequestCountPerTarget is a metric emitted by the Application Load Balancer that measures the average number of requests received per target (e.g., EC2 instance) over a specified period. Scaling based on this metric directly ties capacity to actual demand, allowing the Auto Scaling group to add instances when request load increases, ensuring responsive scaling during traffic spikes.

Why this answer

The ALB RequestCountPerTarget metric directly measures the average request load per instance, making it the most appropriate for scaling based on request volume. It allows the Auto Scaling group to add or remove instances proportionally to traffic, ensuring the application can handle spikes. Other metrics like CPU or connections may not accurately reflect request rate.

Exam trap

The trap here is assuming that CPU utilization is always the best scaling metric, when in fact request-based metrics can be more directly tied to demand for web applications.

4
MCQmedium

A DevOps team is implementing a CI/CD pipeline using Jenkins. They want to ensure that code is automatically built, tested, and deployed to a staging environment before manual approval for production. Which stage should include the deployment to staging?

A.Build
B.Deploy
C.Source
D.Verify
AnswerB

The Deploy stage performs the actual release of built artefacts to the staging environment, so it is where staging deployment belongs. Build compiles, test validates, and manual approval gates production, matching the pipeline's required sequence.

Why this answer

In a Jenkins CI/CD pipeline, the Deploy stage is responsible for taking the built and verified artifact and releasing it to an environment — in this case, the staging environment. The pipeline flow is typically Source → Build → Test/Verify → Deploy (staging) → Manual Approval → Deploy (production). Placing staging deployment in the Deploy stage correctly separates it from build and test activities.

Exam trap

CV0-004 often tests whether candidates conflate 'Verify' (testing) with 'Deploy' (releasing to an environment), causing them to place staging deployment in the Verify stage because staging is used for verification.

How to eliminate wrong answers

Option A is wrong because the Build stage compiles code and produces artifacts; it does not deploy to any environment. Option C is wrong because the Source stage is where Jenkins checks out code from the SCM (Git, SVN) — it is the entry point, not a deployment stage. Option D is wrong because the Verify stage runs tests (unit, integration, static analysis) against the built artifact; it validates quality but does not push code to staging.

Deployment to any environment, including staging, belongs in the Deploy stage.

5
MCQeasy

A cloud administrator is deploying a new application to a Kubernetes cluster using a Deployment manifest. The application requires persistent storage that must survive pod restarts and be accessible by a single pod at a time. Which Kubernetes resource should be used to define the storage?

A.ConfigMap mounted as a volume
B.emptyDir volume mounted in the pod spec
C.hostPath volume pointing to a directory on the node
D.PersistentVolumeClaim with accessMode ReadWriteOnce
AnswerD

A PersistentVolumeClaim (PVC) with ReadWriteOnce allows a single node to mount the volume for read-write access, which is suitable for a single pod. It provides persistent storage that survives pod restarts. This is the standard way to request durable storage in Kubernetes and meets the requirement.

Why this answer

A PersistentVolumeClaim with ReadWriteOnce provides durable storage accessible by a single node, which is appropriate for a single pod. It decouples storage from the pod lifecycle, ensuring data persists across restarts. The other options are either ephemeral, node-specific, or meant for configuration, not persistent storage.

Exam trap

The trap here is confusing configuration or ephemeral volumes with persistent storage, especially when the application needs data to survive pod restarts.

6
MCQeasy

A cloud engineer is writing a Terraform configuration to provision an AWS EC2 instance. They need to pass the AMI ID as a variable to make the configuration reusable. Which Terraform block should be used to define the variable?

A.output
B.provider
C.variable
D.resource
AnswerC

The variable block declares an input variable, letting the AMI ID be supplied at plan or apply time rather than hard-coded, which makes the configuration reusable across environments. Output exposes values, locals compute intermediates, and provider configures the AWS plugin.

Why this answer

Variables are defined using the 'variable' block. 'resource' declares resources; 'provider' configures providers; 'output' defines outputs.

7
MCQeasy

A developer wants to deploy an application using Azure Bicep. What is a key benefit of using Bicep over ARM templates?

A.Bicep has simpler, more readable syntax than ARM JSON
B.Bicep can be used to manage any cloud provider
C.Bicep eliminates the need for resource providers
D.Bicep supports imperative scripting
AnswerA

Bicep's declarative DSL compiles directly to ARM JSON, so it provides identical resource coverage while replacing verbose JSON brackets, quotes and nested expressions with concise, readable syntax. This directly satisfies the stem's requirement for a key benefit over ARM templates: reduced authoring complexity without losing any deployment capability.

Why this answer

Bicep is a domain-specific language that provides a cleaner, more readable, and more concise syntax than ARM JSON templates. It abstracts away much of the JSON boilerplate, such as parameters, variables, and resource declarations, while still compiling to ARM JSON for deployment. This makes authoring and maintaining infrastructure-as-code easier.

Exam trap

CV0-004 often tests the misconception that Bicep is multi-cloud or imperative; it is Azure-specific and declarative, compiling to ARM JSON.

How to eliminate wrong answers

Option B is wrong because Bicep is specific to Azure; it cannot manage other cloud providers like AWS or GCP. Option C is wrong because Bicep still relies on Azure resource providers to deploy resources; it does not eliminate them. Option D is wrong because Bicep is declarative, not imperative; it describes the desired end state, and Azure Resource Manager handles the deployment orchestration.

8
MCQeasy

A cloud administrator needs to transfer 50 TB of data from an on-premises NAS to Amazon S3. The office has limited bandwidth (50 Mbps). Which service is most suitable for this offline transfer?

A.AWS VPN
B.AWS DataSync
C.AWS Snowball
D.S3 Transfer Acceleration
AnswerC

AWS Snowball provides a physical appliance for offline bulk data transfer, bypassing the 50 Mbps bandwidth constraint that would make 50 TB take months to upload. Data is shipped to AWS and imported into S3.

Why this answer

AWS Snowball is a physical petabyte-scale data transport device designed for offline data migration when network bandwidth is insufficient. With 50 TB of data and only 50 Mbps bandwidth, transferring over the network would take months (roughly 100+ days), making Snowball the appropriate choice for offline transfer to S3.

Exam trap

CV0-004 often tests whether candidates pick online transfer services (DataSync, Transfer Acceleration) for scenarios where bandwidth makes network transfer impractical, missing the cue that 'offline' and 'limited bandwidth' point to Snowball.

How to eliminate wrong answers

Option A is wrong because AWS VPN establishes an encrypted network tunnel over the internet — it does not solve the bandwidth limitation and would still require transferring 50 TB over a 50 Mbps link. Option B is wrong because AWS DataSync is an online data transfer service that moves data over the network (or via Direct Connect); it is not an offline solution and would be bottlenecked by the 50 Mbps link. Option D is wrong because S3 Transfer Acceleration uses AWS edge locations to speed up uploads over the internet — it improves throughput but cannot overcome a 50 Mbps origin uplink for 50 TB of data.

9
MCQmedium

A company uses GitLab CI for its CI/CD pipeline. The pipeline includes a 'deploy' job that runs only when a tag is pushed. Which GitLab CI keyword should be used to control job execution based on tags?

A.stage
B.except
C.only
D.needs
AnswerC

The only keyword restricts a job to specified conditions, such as only: tags, so the deploy job runs solely when a tag is pushed. This satisfies the stem's requirement to control execution based on tags rather than branches or merge requests.

Why this answer

The 'only' keyword in GitLab CI controls when a job runs based on conditions such as tags, branches, or changes. Using 'only: tags' ensures the deploy job executes only when a tag is pushed, which matches the requirement.

Exam trap

CV0-004 often tests the distinction between 'only' and 'except' (inverse conditions) and between 'only' and 'rules' (legacy vs modern syntax) — candidates who pick 'except' or 'needs' misunderstand the direction of the condition.

How to eliminate wrong answers

Option A is wrong because 'stage' defines the pipeline stage a job belongs to (e.g., build, test, deploy) and does not control execution based on tags. Option B is wrong because 'except' is the inverse of 'only' — it excludes jobs from running under specified conditions, which is the opposite of what is needed. Option D is wrong because 'needs' defines job dependencies for out-of-order execution (DAG), not tag-based execution conditions.

10
MCQmedium

A cloud engineer is deploying a containerized application on Amazon ECS using the Fargate launch type. The application requires persistent storage for a database container. The engineer needs to ensure that the data persists even if the task is stopped and restarted. Which storage option should the engineer use?

A.Amazon S3 bucket mounted as a file system using s3fs
B.Docker volume on the host instance
C.Amazon EBS volume attached to the Fargate task
D.Amazon EFS file system mounted as a volume in the task definition
AnswerD

Amazon EFS provides a shared, elastic file system that can be mounted by multiple Fargate tasks simultaneously. It supports persistent storage that survives task restarts and can be used for database containers that require a file system. EFS is the recommended solution for persistent storage with Fargate because it integrates natively and supports the required durability and scalability.

Why this answer

Amazon EFS is the only storage option that provides persistent, shared file storage that can be mounted by Fargate tasks. It survives task restarts and can be used for database containers that require a file system. EBS volumes cannot be attached to Fargate tasks, Docker volumes on the host are not accessible, and S3 is not suitable for database storage due to performance and consistency limitations.

Exam trap

The trap here is assuming that any AWS storage service can be used with Fargate, when in fact Fargate has specific supported storage integrations, and EFS is the primary persistent file storage option.

11
MCQmedium

A cloud administrator is deploying a new Amazon EC2 instance that must run a custom application. The application requires a specific IAM role to access an S3 bucket. The administrator wants to avoid embedding AWS credentials in the instance. What should the administrator do?

A.Configure the application to use the AWS SDK's default credential provider chain with environment variables set on the instance.
B.Generate an access key and secret key for an IAM user, then store them in a configuration file on the instance.
C.Use AWS Systems Manager Parameter Store to store the credentials and retrieve them at runtime.
D.Create an IAM role with the necessary S3 permissions and attach it to the EC2 instance using an instance profile.
AnswerD

AWS recommends using IAM roles for EC2 instances to grant permissions without embedding long-term credentials. An instance profile is a container for an IAM role that can be attached to an EC2 instance at launch or later. The instance then retrieves temporary credentials from the instance metadata service, which are automatically rotated. This method is secure and aligns with best practices.

Why this answer

The most secure and recommended way to grant an EC2 instance access to AWS services like S3 is to create an IAM role with the required permissions and attach it to the instance via an instance profile. The instance can then obtain temporary credentials from the instance metadata service, eliminating the need for hardcoded credentials and enabling automatic rotation.

Exam trap

The trap here is believing that storing credentials in Parameter Store or environment variables is equally secure, when they still require an IAM role or introduce static credentials.

12
MCQmedium

A company wants to deploy a Kubernetes application across multiple AWS accounts using a single set of manifests. The team needs to manage the deployment centrally while allowing each account to have its own configuration values (e.g., environment-specific variables). Which approach should the team use?

A.Use Terraform workspaces with Kubernetes provider
B.Use Helm charts with per-environment values files
C.Use CloudFormation StackSets with Kubernetes resources
D.Create separate manifests for each account
AnswerB

Helm charts separate templated manifests from environment-specific values, so one chart deploys across accounts while each account supplies its own values file. This satisfies the requirement for a single set of manifests with per-account configuration, since overrides are injected at render time rather than duplicated per account.

Why this answer

Helm charts with per-environment values files allow a single set of Kubernetes manifests (templated) to be deployed across multiple AWS accounts, with each account providing its own configuration values (e.g., environment-specific variables) via separate values files. This enables centralized management of the deployment logic while allowing per-account customization.

Exam trap

CV0-004 often tests the difference between infrastructure-as-code tools; candidates may choose Terraform workspaces because they think it can template Kubernetes manifests, but Helm is specifically designed for parameterized Kubernetes deployments.

How to eliminate wrong answers

Option A is wrong because Terraform workspaces are used to manage multiple instances of the same configuration with different state files, but they are not designed for templating Kubernetes manifests; the Kubernetes provider in Terraform is for managing Kubernetes resources, not for packaging and parameterizing manifests. Option C is wrong because CloudFormation StackSets are for deploying AWS resources across accounts, but they do not natively manage Kubernetes resources; you would need custom resources or nested stacks, which is not the intended use. Option D is wrong because creating separate manifests for each account leads to duplication and drift, defeating the goal of a single set of manifests.

13
MCQmedium

An organization uses CloudFormation to manage infrastructure across multiple AWS accounts. The team wants to deploy a common set of resources, such as VPCs and security groups, to all accounts in a consistent manner. Which CloudFormation feature should they use?

A.Change sets
B.Drift detection
C.StackSets
D.Nested stacks
AnswerC

StackSets extend a single CloudFormation template across multiple AWS accounts and regions from one administrator account, provisioning identical VPCs and security groups consistently. This directly meets the stem's requirement to deploy a common resource set to all accounts without duplicating stacks manually.

Why this answer

StackSets allow deploying stacks across multiple accounts and regions. Change sets preview changes, drift detection checks for manual changes, and nested stacks organize templates within a single account.

14
MCQmedium

A cloud engineer is deploying a three-tier web application using AWS CloudFormation. The application requires a relational database that must be encrypted at rest and support automated backups. The engineer wants to minimize management overhead. Which AWS CloudFormation resource should be used for the database tier?

A.AWS::RDS::DBInstance with the Engine property set to mysql and StorageEncrypted set to true
B.AWS::ElastiCache::CacheCluster with the Engine property set to redis and automatic backups enabled
C.AWS::EC2::Instance with a MySQL AMI and an EBS volume encrypted using AWS::EC2::Volume
D.AWS::DynamoDB::Table with the SSESpecification property and point-in-time recovery enabled
AnswerA

AWS::RDS::DBInstance is the correct resource for deploying a managed relational database. Setting StorageEncrypted to true ensures encryption at rest, and RDS automatically handles backups and patching, minimizing management overhead. This matches the requirements exactly and is the standard way to provision RDS via CloudFormation.

Why this answer

The AWS::RDS::DBInstance resource is designed for managed relational databases, offering encryption at rest via StorageEncrypted and automated backups. It reduces operational burden by handling patching, backups, and replication. The other options either require manual management, use a non-relational engine, or provide caching rather than a primary database.

Exam trap

The trap here is assuming that any encrypted storage or backup-capable service can serve as the database tier, overlooking the need for a managed relational database.

15
MCQhard

A DevOps team is deploying a new version of a microservice to a Kubernetes cluster on AWS. They want to minimize the risk of introducing errors by gradually shifting traffic to the new version while monitoring key metrics. They also need the ability to automatically roll back if the new version does not perform well. Which deployment strategy should they use?

A.Canary deployment
B.Recreate deployment
C.Rolling update
D.Blue/green deployment
AnswerA

Canary deployment involves releasing the new version to a small subset of users or traffic, then gradually increasing the traffic while monitoring metrics. If issues are detected, the deployment can be automatically rolled back. This strategy minimizes risk by limiting exposure and allows for data-driven decisions based on real-time performance. It aligns perfectly with the requirements for gradual traffic shifting and automated rollback.

Why this answer

Canary deployment is designed to reduce risk by gradually shifting a small percentage of traffic to the new version, monitoring its performance, and then progressively increasing traffic if metrics are satisfactory. It supports automated rollback if anomalies are detected. Recreate causes downtime, rolling update lacks fine-grained traffic control and automated rollback based on metrics, and blue/green switches all traffic at once, which is riskier.

Exam trap

The trap here is confusing rolling updates with canary deployments, as both are gradual, but only canary provides controlled traffic shifting and automated rollback based on custom metrics.

16
MCQmedium

A developer is deploying a serverless application using AWS Lambda. They want to reuse common code (e.g., database connection logic) across multiple functions without duplicating it. Which Lambda feature should they use?

A.Lambda versions
B.Lambda aliases
C.Lambda layers
D.Lambda environment variables
AnswerC

Lambda layers package shared libraries and dependencies separately from function code, so database connection logic is referenced by multiple functions rather than duplicated in each deployment package. This directly satisfies the requirement to reuse common code across functions while keeping individual deployment artefacts small.

Why this answer

Lambda Layers allow you to package and share code across multiple functions, enabling code reuse and reducing deployment package size.

17
MCQmedium

A cloud engineer needs to deploy a containerized application on Amazon EKS. The application requires a persistent storage volume that can be dynamically provisioned. Which Kubernetes resource should be used to request storage?

A.PersistentVolume
B.PersistentVolumeClaim
C.StorageClass
D.ConfigMap
AnswerB

A PersistentVolumeClaim requests storage from a StorageClass, which triggers dynamic provisioning of a PersistentVolume. This satisfies the stem's requirement for dynamically provisioned persistent storage on Amazon EKS, unlike a PersistentVolume, which represents already-provisioned capacity, or a StorageClass, which only defines the provisioning template.

Why this answer

A PersistentVolumeClaim (PVC) is the correct Kubernetes resource to request storage because it acts as a request for storage by a pod, specifying size, access modes, and optionally a StorageClass. In Amazon EKS, a PVC can trigger dynamic provisioning of an EBS or EFS volume via a StorageClass, decoupling the storage request from the underlying PersistentVolume. This allows the cloud engineer to deploy the containerized application without manually pre-provisioning storage.

Exam trap

The exam often tests the distinction between a PersistentVolume (the actual storage resource) and a PersistentVolumeClaim (the request for storage), leading candidates to mistakenly select PV when the question asks for the resource that 'requests' storage.

How to eliminate wrong answers

Option A is wrong because a PersistentVolume (PV) is a cluster resource representing pre-provisioned storage, not a request for storage; it is the backend volume that a PVC binds to. Option C is wrong because a StorageClass defines the storage type and provisioner (e.g., 'ebs.csi.aws.com') but does not itself request storage; it is referenced by a PVC to enable dynamic provisioning. Option D is wrong because a ConfigMap is used to inject configuration data (key-value pairs) into pods, not for persistent storage requests.

18
MCQmedium

An Azure administrator needs to deploy a cloud-native application using Azure DevOps. The team wants to define the entire Azure infrastructure as code using a declarative language that is concise and integrated with Azure. Which tool should the administrator use?

A.Terraform
B.Bicep
C.Ansible
D.ARM templates (JSON)
AnswerB

Bicep is a declarative domain-specific language that compiles to Azure Resource Manager templates, offering concise syntax with native Azure integration. It satisfies the stem's requirement for infrastructure as code in a declarative, concise form, unlike imperative scripting or JSON-based ARM templates.

Why this answer

Bicep is a domain-specific language for deploying Azure resources that provides a simpler syntax than ARM templates while being fully integrated with Azure.

19
MCQmedium

During a CI/CD pipeline for a web application, the team wants to reduce risk by deploying a new version to a small percentage of users initially, monitoring for errors, and automatically rolling back if issues are detected. Which deployment strategy should they implement?

A.Blue/green deployment
B.Rolling deployment
C.In-place deployment
D.Canary deployment
AnswerD

Canary deployment routes a small percentage of traffic to the new version while the majority still hits the stable release, enabling error monitoring and automatic rollback. This directly satisfies the requirement to limit initial user exposure and revert on detected issues.

Why this answer

Canary deployment routes a small percentage of production traffic to the new version while the majority continues to hit the stable version, allowing the team to monitor error rates and latency in real time. If metrics degrade, traffic can be shifted back automatically, limiting blast radius. This matches the requirement of exposing only a small subset of users, monitoring, and auto-rolling back.

Exam trap

CV0-004 often tests the distinction between canary and blue/green — candidates pick blue/green because both reduce risk, but only canary exposes a small percentage of users with gradual traffic shifting.

How to eliminate wrong answers

Option A is wrong because blue/green deployment shifts 100% of traffic from the old environment to the new one after validation, so all users are exposed simultaneously rather than a small percentage. Option B is wrong because rolling deployment replaces instances in batches across the entire fleet, gradually increasing exposure to all users rather than isolating a small canary cohort. Option C is wrong because in-place deployment updates the existing instances directly, causing downtime or full-fleet exposure with no traffic-splitting mechanism for gradual risk reduction.

20
MCQhard

An organization is migrating a MySQL database to Amazon Aurora with minimal downtime. The migration must capture ongoing changes from the source database and apply them to the target during the cutover. Which AWS Database Migration Service (DMS) feature should be used?

A.Validation
B.Change data capture (CDC)
C.Full load only
D.Schema conversion
AnswerB

Change data capture reads ongoing inserts, updates and deletes from the source's transaction log and applies them to Aurora, keeping the target synchronised until cutover. This satisfies the minimal-downtime constraint by replicating changes continuously rather than requiring a stop-and-copy migration.

Why this answer

Change data capture (CDC) in AWS DMS continuously reads the source database's transaction log (binary log for MySQL) and applies ongoing changes to the target, enabling near-zero-downtime cutover. It is the specific DMS feature designed to replicate changes that occur after the initial full load.

Exam trap

CV0-004 often tests the misconception that 'full load' or 'validation' handles ongoing changes, when only CDC (also called 'replication' or 'ongoing replication') captures and applies changes made after the initial load.

How to eliminate wrong answers

Option A is wrong because Validation compares source and target data to confirm consistency — it does not capture or apply ongoing changes. Option C is wrong because Full load only performs a one-time bulk copy of existing data and does not replicate subsequent changes, which would cause data loss during cutover. Option D is wrong because Schema conversion is an AWS SCT (Schema Conversion Tool) function that translates DDL between engines; it does not handle ongoing data replication.

21
MCQmedium

A cloud engineer is deploying a containerized application to a Kubernetes cluster. The application requires a configuration file that contains database credentials and API keys. The engineer wants to avoid hardcoding sensitive information in the container image or in the deployment manifest. Which Kubernetes resource should be used to store and manage this sensitive data securely?

A.Secret
B.ConfigMap
C.PersistentVolumeClaim
D.ServiceAccount
AnswerA

Kubernetes Secrets are designed to hold sensitive information such as passwords, tokens, and keys. They are stored in etcd and can be encrypted at rest if configured. Secrets can be mounted as files or exposed as environment variables, and they are only distributed to nodes running pods that require them. Using a Secret avoids hardcoding credentials in the image or manifest and follows security best practices.

Why this answer

Kubernetes Secrets are the appropriate resource for storing sensitive configuration data such as database credentials and API keys. They keep secrets separate from the container image and deployment manifest, and they can be encrypted at rest. Secrets can be consumed as environment variables or mounted as files, providing flexibility while maintaining security.

This approach aligns with the principle of least privilege and avoids exposing sensitive data in source control.

Exam trap

The trap here is assuming ConfigMaps are sufficient for secrets because they are easy to use, but they lack the security controls of Secrets.

22
MCQmedium

An organization is using CloudFormation to manage AWS infrastructure. They need to detect if any manual changes have been made to resources outside of CloudFormation. Which CloudFormation feature should they use?

A.Change sets
B.Drift detection
C.Stack sets
D.Resource signals
AnswerB

Drift detection compares each stack resource's actual configuration against its expected template-defined state, reporting any divergence. This directly satisfies the requirement to identify manual changes made outside CloudFormation, since it flags resources whose live properties no longer match the stack's declared configuration.

Why this answer

CloudFormation drift detection compares the current state of resources with the expected state defined in the stack template. It identifies resources that have been modified manually, known as drift.

23
MCQeasy

A cloud architect is designing a deployment pipeline using GitHub Actions. They want to automatically run tests on every push to the main branch. Which GitHub Actions component defines the automation workflow?

A.Job
B.Step
C.Action
D.Workflow
AnswerD

A workflow is the YAML-defined automation unit in GitHub Actions, containing the triggers and jobs that run. Defining it with an on: push trigger scoped to the main branch executes the test jobs automatically on every push, meeting the stated requirement.

Why this answer

A GitHub Actions workflow is the top-level YAML file (in .github/workflows) that defines when automation runs and what jobs it contains. It is the component that binds triggers (like push to main) to jobs and steps, so it is the correct answer for 'defines the automation workflow.'

Exam trap

CV0-004 often tests the confusion between the workflow (top-level YAML) and its sub-components (job, step, action); candidates must identify the workflow as the automation definition.

How to eliminate wrong answers

Option A is wrong because a job is a set of steps that runs on a runner within a workflow; it is a sub-component, not the top-level definition. Option B is wrong because a step is a single task within a job (a shell command or an action), the smallest unit. Option C is wrong because an action is a reusable unit of code invoked by a step, not the workflow definition itself.

24
MCQhard

A DevOps engineer is configuring a Kubernetes deployment for a microservices application. The application requires that new pods receive traffic only after a health check endpoint returns HTTP 200. Which Kubernetes feature should be configured on the pods?

A.Startup probe
B.Liveness probe
C.Resource limits
D.Readiness probe
AnswerD

A readiness probe checks the health endpoint and only adds the pod to the Service endpoints once it returns HTTP 200. This directly satisfies the requirement that new pods receive traffic only after the health check passes, unlike a liveness probe, which restarts containers.

Why this answer

A readiness probe determines whether a pod is ready to receive traffic. If the readiness probe fails, the pod is removed from the endpoints of the service, preventing traffic from being sent to it until it passes. This matches the requirement that new pods receive traffic only after a health check endpoint returns HTTP 200.

Exam trap

The trap is confusing readiness probes with liveness probes; candidates must remember that readiness controls traffic, while liveness controls restarts.

How to eliminate wrong answers

Option A is wrong because a startup probe is used to determine when a container has started, and it disables other probes until it succeeds; it does not control traffic routing. Option B is wrong because a liveness probe checks if the container is still running and restarts it if not, but it does not affect traffic routing. Option C is wrong because resource limits control CPU and memory allocation, not traffic routing based on health checks.

25
MCQmedium

A company is deploying a web application on AWS using an Auto Scaling group of Amazon EC2 instances behind an Application Load Balancer (ALB). The application stores user session data locally on each instance. During a scaling event, users are being logged out because their sessions are not available on new instances. The company wants to implement a solution that allows sessions to persist across all instances without modifying the application code. Which approach should be used?

A.Enable sticky sessions (session affinity) on the ALB.
B.Store session data in an Amazon ElastiCache for Redis cluster.
C.Configure the Auto Scaling group to use a launch template with a pre-baked AMI that includes session data.
D.Use an Amazon RDS database to store session data.
AnswerB

Amazon ElastiCache for Redis provides a centralized, in-memory data store that can be used to store session data. By configuring the application to use Redis as the session store, sessions become available to all instances in the Auto Scaling group. This requires no application code changes if the application already supports external session stores, or minimal configuration changes. It ensures sessions persist even if instances are added or removed.

Why this answer

Amazon ElastiCache for Redis is a fully managed in-memory data store that is ideal for session management. It provides sub-millisecond latency and can scale to handle high request rates. By externalizing session state to Redis, all instances in the Auto Scaling group can access the same session data, so users remain logged in even when instances are added or removed.

This is a common pattern for stateless web applications.

Exam trap

The trap here is assuming that sticky sessions on the load balancer are sufficient for session persistence during scaling events, when in fact they only tie a user to a single instance and do not share session data across instances.

26
MCQmedium

A cloud engineer is deploying a multi-tier web application on AWS. The web tier must be able to scale out during traffic spikes, but the database tier should remain on a fixed set of instances. The engineer wants to define the infrastructure as code using AWS CloudFormation. Which CloudFormation feature should be used to automatically adjust the number of web tier instances based on CPU utilization?

A.Use a CloudFormation stack policy to allow scaling actions.
B.Use a CloudFormation change set to modify the desired capacity.
C.Use an Auto Scaling group with a scaling policy based on the CPUUtilization metric.
D.Use a CloudFormation update policy with AutoScalingRollingUpdate.
AnswerC

An Auto Scaling group with a scaling policy that references the Amazon CloudWatch CPUUtilization metric automatically adjusts the desired capacity of the web tier instances when average CPU crosses defined thresholds. This is the standard, declarative way to implement dynamic scaling in CloudFormation, ensuring the application can handle traffic spikes without manual intervention.

Why this answer

The correct approach is to define an Auto Scaling group with a scaling policy that uses the CPUUtilization metric. This allows CloudFormation to manage the group and its scaling behavior declaratively, automatically increasing or decreasing instances as needed. Other options either handle updates, protect resources, or preview changes, but none provide dynamic scaling based on metrics.

Exam trap

The trap here is confusing update policies or change sets with actual scaling mechanisms; only a scaling policy tied to a metric enables dynamic capacity adjustments.

27
MCQmedium

A cloud engineer is deploying a multi-tier web application on AWS using AWS Elastic Beanstalk. The application requires a relational database and must be able to scale automatically based on demand. The engineer wants to minimize management overhead. Which deployment approach should the engineer use?

A.Deploy the application as a container on Amazon ECS with an Amazon RDS database, and configure Application Auto Scaling.
B.Create a new Elastic Beanstalk environment with a web server tier and configure an Amazon RDS database instance using the Elastic Beanstalk console.
C.Use AWS CloudFormation to create an EC2 instance with a user data script that installs the application and a MySQL database.
D.Launch an Amazon EC2 instance, install the application and database software, and configure an Auto Scaling group manually.
AnswerB

Elastic Beanstalk supports integrating an RDS database directly through the console, which automates the creation of the database and configures the necessary security groups and environment properties. This minimizes management overhead because Beanstalk handles provisioning, scaling, and monitoring of both the application and the database lifecycle. The web server tier handles HTTP requests and can scale automatically based on load.

Why this answer

Elastic Beanstalk is designed to simplify deployment by handling capacity provisioning, load balancing, scaling, and application health monitoring. Integrating an RDS database through the Elastic Beanstalk console automates database setup and lifecycle management, reducing administrative tasks. The other options require manual configuration of scaling or database management, which increases overhead and does not leverage Beanstalk's integrated features.

Exam trap

The trap here is assuming that any automated deployment service reduces management overhead equally, when Elastic Beanstalk specifically provides integrated database provisioning and automatic scaling with minimal configuration.

28
MCQhard

A company is deploying a stateful application on AWS that requires a shared, POSIX-compliant file system that can be mounted on multiple Amazon EC2 instances simultaneously. The application also needs to support high throughput and must be durable across multiple Availability Zones. Which AWS storage service should the company use?

A.Amazon FSx for Windows File Server
B.Amazon EFS
C.Amazon EBS with Multi-Attach
D.Amazon S3
AnswerB

Amazon EFS is a fully managed, POSIX-compliant file system that can be mounted on multiple EC2 instances simultaneously. It is durable across multiple Availability Zones and supports high throughput with Bursting or Provisioned Throughput modes. EFS is designed for shared access and automatically scales. This matches the requirements for a shared file system with multi-AZ durability and high throughput.

Why this answer

Amazon EFS is the correct choice because it provides a POSIX-compliant, shared file system that can be mounted on multiple EC2 instances across multiple Availability Zones. It offers high throughput and durability, making it ideal for stateful applications requiring shared storage. Other options either do not support POSIX semantics or do not span multiple AZs.

Exam trap

The trap here is assuming that EBS Multi-Attach provides a shared file system, but it is block storage limited to a single AZ and requires a cluster file system.

29
MCQmedium

A company is deploying a new version of a microservice on Amazon EKS. The deployment must ensure that new pods are created and become healthy before old pods are terminated. The current deployment uses a ReplicaSet. Which Kubernetes resource and strategy should be used?

A.ReplicaSet with RollingUpdate strategy
B.DaemonSet with RollingUpdate
C.Deployment with RollingUpdate strategy
D.StatefulSet with OnDelete strategy
AnswerC

RollingUpdate replaces pods incrementally, honouring maxSurge and maxUnavailable so new pods reach readiness before old ones terminate. A bare ReplicaSet cannot orchestrate this ordering during updates, so the Deployment controller is required to satisfy the zero-downtime constraint.

Why this answer

A Deployment manages ReplicaSets and supports a RollingUpdate strategy that creates new pods and waits for them to become ready before terminating old ones.

30
MCQeasy

A cloud engineer needs to deploy a serverless function that runs when a new object is uploaded to an S3 bucket. Which AWS service event trigger should be configured?

A.API Gateway
B.EventBridge
C.S3
D.SQS
AnswerC

S3 emits event notifications when objects are created, so configuring an S3 event trigger invokes the serverless function on upload. This directly satisfies the requirement that the function runs when a new object lands in the bucket, without polling.

Why this answer

Amazon S3 can directly invoke AWS Lambda when a new object is uploaded by configuring an S3 event notification on the bucket. This native integration allows the S3 service to trigger the function without any intermediary service, making option C the correct choice for a serverless function triggered by an S3 upload event.

Exam trap

Candidates often confuse direct service integrations (S3 → Lambda) with event bus patterns (EventBridge), where they may overcomplicate by choosing EventBridge when the native S3 trigger is simpler and sufficient.

How to eliminate wrong answers

Option A is wrong because API Gateway is a service for creating RESTful or WebSocket APIs to front-end applications or services, not for directly triggering functions from S3 events; it would require an additional integration layer. Option B is wrong because EventBridge is a serverless event bus for routing events between AWS services and custom applications, but S3 can send events directly to Lambda without needing EventBridge as an intermediary. Option D is wrong because SQS is a message queue service that decouples components, not a direct trigger for Lambda from S3; while S3 can send events to SQS, the queue would then need to be polled by a consumer, adding latency and complexity.

31
MCQmedium

A DevOps team is setting up a CI/CD pipeline using GitHub Actions. They want the pipeline to automatically deploy a containerized application to a Kubernetes cluster only when changes are pushed to the main branch. Which GitHub Actions component should they use to trigger the deployment?

A.A cron job that checks the repository every hour
B.A GitHub webhook configured in the repository settings
C.A pull request review requirement
D.A workflow with an on.push trigger for the main branch
AnswerD

The on.push trigger with a main branch filter causes the workflow to run only when commits are pushed to main, satisfying the conditional deployment requirement. This event-driven trigger is the GitHub Actions component that initiates the pipeline at the correct moment.

Why this answer

GitHub Actions workflows are defined in YAML and can include an 'on' trigger specifying events such as push to a branch. This allows automation of the deployment when code is pushed to main.

32
MCQhard

A company uses Azure DevOps to deploy a critical application. They need to implement a deployment strategy that ensures zero downtime by directing all traffic to the new environment after validation, while keeping the old environment as a fallback. Which deployment strategy should be configured in the Azure Pipelines release pipeline?

A.Canary deployment
B.In-place deployment
C.Blue/green deployment
D.Rolling deployment
AnswerC

Blue/green deployment keeps the existing environment live while the new one is validated, then switches all traffic at once. The old environment remains available for rollback, delivering the zero-downtime cutover with fallback that the release pipeline requires.

Why this answer

Blue/green deployment is the correct strategy because it maintains two identical environments (blue and green) and switches the router or load balancer to direct all traffic to the new (green) environment only after validation is complete. The old (blue) environment remains untouched and can serve as an immediate fallback if issues arise, ensuring zero downtime during the cutover.

Exam trap

CompTIA often tests the distinction between canary and blue/green by emphasizing 'gradual traffic shift' versus 'instant full cutover with fallback,' leading candidates to confuse canary's incremental rollout with the zero-downtime fallback requirement.

How to eliminate wrong answers

Option A is wrong because canary deployment gradually shifts a small percentage of traffic to the new version before full rollout, which does not guarantee zero downtime for all users during the initial validation phase and does not keep the old environment as a full fallback. Option B is wrong because in-place deployment updates the existing environment directly, causing downtime during the update process and no fallback environment is preserved. Option D is wrong because rolling deployment replaces instances incrementally, which can cause temporary capacity reduction or version mismatch during the update, and it does not maintain a complete fallback environment.

33
Multi-Selecthard

A cloud team uses Azure Bicep for deploying resources. They need to create a modular deployment that includes a virtual network and a subnet. Which THREE best practices should they follow when authoring Bicep files? (Choose three.)

Select 3 answers
A.Use hard-coded resource names to ensure consistency.
B.Use modules to encapsulate and reuse resource definitions.
C.Use symbolic names for resources to reference them elsewhere in the file.
D.Use parameters for configurable values like address prefixes.
E.Define all resources in a single file for simplicity.
AnswersB, C, D

Modules let the virtual network and subnet definitions be encapsulated into reusable files, so the parent deployment references them rather than duplicating code. This directly satisfies the modular deployment requirement, keeping each resource definition scoped and independently maintainable.

Why this answer

Using parameters for configurable values, using modules for reuse, and using symbolic names for resource references are best practices.

34
Multi-Selectmedium

A cloud engineer is deploying a new application on AWS and needs to ensure that the deployment is highly available and can withstand the failure of a single Availability Zone. The application uses an Application Load Balancer (ALB) and an Auto Scaling group. Which two configurations should the engineer implement to meet these requirements? (Choose two.)

Select 2 answers
A.Attach an Elastic IP address to each instance in the Auto Scaling group.
B.Enable cross-zone load balancing on the ALB.
C.Configure the Auto Scaling group to span at least two Availability Zones.
D.Set the Auto Scaling group to use a single instance type.
E.Configure the ALB to use a single Availability Zone for simplicity.
AnswersB, C

Cross-zone load balancing allows the ALB to distribute traffic evenly across all registered targets in all enabled Availability Zones. Without it, traffic is distributed only to targets in the same AZ as the load balancer node, which can lead to uneven load and reduced fault tolerance. Enabling cross-zone load balancing ensures that if one AZ fails, the remaining AZs handle the full load.

Why this answer

To achieve high availability and withstand an AZ failure, the Auto Scaling group must span multiple Availability Zones, and the ALB should have cross-zone load balancing enabled. These two configurations ensure that if one AZ becomes unavailable, the remaining AZs continue to serve traffic and the load balancer distributes requests evenly across all healthy targets.

Exam trap

The trap here is thinking that assigning Elastic IPs or using a single instance type improves availability, when the real requirements are multi-AZ distribution and cross-zone load balancing.

35
MCQmedium

A DevOps team uses Ansible to automate cloud resource provisioning. Which of the following best describes Ansible's architecture?

A.It uses a declarative language similar to Terraform.
B.It uses a master-server architecture with a central controller.
C.It requires an agent installed on each managed node.
D.It is agentless and uses SSH or WinRM to execute tasks.
AnswerD

Ansible pushes modules over SSH on Linux and WinRM on Windows, so managed hosts need no installed agent or persistent daemon. This agentless push model is the architectural axis distinguishing it from agent-based configuration tools such as Puppet or Chef.

Why this answer

Ansible is agentless and uses SSH (for Linux/Unix) or WinRM (for Windows) to execute tasks on managed nodes. The control node pushes modules to target hosts over these standard protocols, executes them, and removes them — no persistent agent or daemon is required on managed nodes.

Exam trap

CV0-004 often tests the distinction between agentless tools (Ansible) and agent-based tools (Puppet, Chef, SaltStack) — candidates confuse Ansible's YAML declarative syntax with Terraform's declarative IaC model.

How to eliminate wrong answers

Option A is wrong because while Ansible playbooks are declarative in style, Ansible is fundamentally a procedural/imperative automation tool using YAML playbooks, and it is not 'similar to Terraform' — Terraform is a declarative infrastructure-as-code tool with state files, whereas Ansible is configuration management/orchestration. Option B is wrong because Ansible uses an agentless push architecture from a control node; it does not have a master-server model with agents like Puppet or Chef. Option C is wrong because requiring an agent on each node describes Puppet, Chef, or SaltStack in agent mode — Ansible explicitly does not require agents.

36
MCQmedium

An organization is implementing a CI/CD pipeline for a critical application. The team wants to deploy a new version to a small subset of users initially to validate performance and functionality before rolling out to the entire user base. Which deployment strategy best fits this requirement?

A.Rolling deployment
B.Blue/green deployment
C.Immutable deployment
D.Canary deployment
AnswerD

Canary deployment routes a small percentage of live traffic to the new version while the majority continues using the stable release, directly satisfying the requirement to validate performance and functionality with a subset of users before full rollout. Unlike blue-green, which switches all traffic at once, canary limits blast radius incrementally.

Why this answer

Canary deployment releases the new version to a small percentage of users, monitors its performance, and gradually increases traffic if successful.

37
MCQeasy

A DevOps team uses Terraform to manage cloud infrastructure. They want to store the state file in a remote backend to enable team collaboration. Which backend configuration stores Terraform state in an S3 bucket?

A.backend 'consul'
B.backend 'azurerm'
C.backend 's3'
D.backend 'gcs'
AnswerC

Configuring `backend "s3"` writes the Terraform state file directly to an Amazon S3 bucket, satisfying the remote-backend requirement for shared team access. Terraform's S3 backend also supports state locking via DynamoDB, preventing concurrent runs from corrupting state. Other backend types target different storage services, so they cannot store state in S3.

Why this answer

Terraform's 's3' backend is specifically designed to store state files in an AWS S3 bucket, enabling team collaboration through remote state locking and versioning. This backend uses the AWS SDK to interact with S3, supporting features like DynamoDB-based state locking and encryption with KMS.

Exam trap

The CompTIA Cloud+ exam often tests the specific backend names mapped to cloud providers, and the trap here is that candidates may confuse 's3' with a generic storage term or assume 'azurerm' or 'gcs' are interchangeable, when each is tied to a distinct cloud platform.

How to eliminate wrong answers

Option A is wrong because the 'consul' backend stores state in HashiCorp Consul, a service mesh and key-value store, not in an S3 bucket. Option B is wrong because the 'azurerm' backend stores state in Azure Blob Storage, not in AWS S3. Option D is wrong because the 'gcs' backend stores state in Google Cloud Storage, not in AWS S3.

38
MCQmedium

A company is moving a 10 TB SQL Server database to Azure SQL Database. They need to migrate with minimal downtime while keeping the source database operational. Which service should they use?

A.Azure Database Migration Service (DMS)
B.Azure Data Sync
C.Azure Import/Export Service
D.Azure Data Box
AnswerA

Azure Database Migration Service performs online migrations, continuously replicating ongoing transactions from the source SQL Server to Azure SQL Database until cutover. This satisfies the minimal-downtime constraint, since the source stays operational and readable throughout. Offline approaches such as backup-and-restore or BACPAC export would require pausing writes for the full 10 TB transfer.

Why this answer

Azure Database Migration Service supports online migrations with minimal downtime using continuous sync (CDC) from SQL Server to Azure SQL Database.

39
MCQhard

A company is migrating a 50 TB on-premises SQL Server database to Amazon RDS for MySQL with minimal downtime. The schema must be converted from SQL Server to MySQL. Which combination of AWS services should the cloud architect use?

A.AWS DMS and AWS Schema Conversion Tool (SCT)
B.AWS Database Migration Service (DMS) only
C.AWS Snowball and AWS DMS
D.AWS DataSync and AWS Schema Conversion Tool (SCT)
AnswerA

AWS Schema Conversion Tool converts the SQL Server schema and objects to MySQL-compatible definitions, while AWS DMS performs the ongoing data replication. Together they satisfy the heterogeneous engine migration with minimal downtime that the scenario demands.

Why this answer

AWS DMS can migrate data with minimal downtime using CDC. Schema Conversion Tool (SCT) converts the schema from SQL Server to MySQL. DMS then performs the ongoing replication.

40
Multi-Selectmedium

A cloud team is implementing a CI/CD pipeline for a containerized application. They want to automatically build a Docker image, push it to a registry, and deploy it to a Kubernetes cluster. Which TWO tools from the options below are commonly used as part of this pipeline? (Select 2)

Select 2 answers
A.Jenkins
B.CloudFormation
C.GitLab CI
D.Terraform
E.Docker Compose
AnswersA, C

Jenkins orchestrates the pipeline stages: it triggers builds, runs Docker commands to build and push images to a registry, then applies Kubernetes manifests to deploy. Its extensive plugin ecosystem integrates each of these steps, satisfying the stem's requirement for automated build, push and deployment tooling.

Why this answer

Jenkins and GitLab CI are both CI/CD tools that can build Docker images, push to registries, and deploy to Kubernetes. Terraform and CloudFormation are IaC tools, not CI/CD. Docker Compose is for local development.

41
MCQmedium

A company is deploying a containerized application on Amazon ECS using the Fargate launch type. The application must be highly available and able to handle sudden increases in traffic. The operations team wants to ensure that the service automatically adjusts the number of running tasks based on CPU utilization. Which ECS service configuration should the team implement?

A.Set up a CloudWatch alarm that triggers an AWS Lambda function to call the UpdateService API to change the desired count.
B.Enable ECS cluster auto scaling by associating the cluster with a capacity provider that manages EC2 Auto Scaling groups.
C.Configure an Application Auto Scaling target tracking scaling policy for the ECS service using the ECSServiceAverageCPUUtilization metric.
D.Use the ECS deployment circuit breaker to automatically roll back and scale the service when CPU utilization exceeds a threshold.
AnswerC

Application Auto Scaling for ECS supports target tracking scaling policies that can automatically adjust the desired count of tasks based on a specified metric. The ECSServiceAverageCPUUtilization metric is a predefined metric that represents the average CPU utilization across all tasks in the service. This directly meets the requirement to scale based on CPU utilization.

Why this answer

Application Auto Scaling with a target tracking policy using the ECSServiceAverageCPUUtilization metric is the native AWS solution for automatically scaling ECS services based on CPU usage. It dynamically adjusts the desired task count to maintain the target utilization, ensuring high availability and responsiveness to traffic changes without manual intervention or custom code.

Exam trap

The trap here is assuming that cluster auto scaling or custom Lambda solutions are needed for Fargate task scaling, when Application Auto Scaling directly supports it.

42
MCQeasy

A developer is deploying a serverless function that processes images uploaded to an S3 bucket. The function should be triggered automatically whenever a new object is created in the bucket. Which event source should be configured to invoke the Lambda function?

A.Amazon SQS
B.Amazon EventBridge
C.Amazon S3
D.API Gateway
AnswerC

Amazon S3 event notifications invoke Lambda directly when objects are created, satisfying the automatic trigger requirement. Configuring the bucket's `s3:ObjectCreated:*` event type with the function as destination removes polling entirely. This is the native push integration for object-creation events, unlike pull-based sources such as Kinesis or DynamoDB Streams.

Why this answer

Amazon S3 is the correct event source because it natively supports event notifications that can directly invoke AWS Lambda functions when objects are created, deleted, or modified in a bucket. This integration is built into the S3 service and requires no additional services or polling. The developer simply configures an S3 bucket notification to trigger the Lambda function on 's3:ObjectCreated:*' events, which is the standard serverless pattern for processing uploaded files.

Exam trap

CV0-004 often tests the misconception that any AWS service that can invoke Lambda is a valid event source for S3 events, but the key is that S3 itself must be configured as the event source for direct, automatic triggering.

How to eliminate wrong answers

Option A is wrong because Amazon SQS is a message queue service, not an event source for S3 object creation; while SQS can be used as a Lambda event source, it would require an intermediary process to poll S3 and enqueue messages, adding unnecessary complexity. Option B is wrong because Amazon EventBridge can receive S3 events, but it is not the direct event source for S3 object creation; using EventBridge would involve configuring S3 to send events to EventBridge and then routing them to Lambda, which is an indirect and more complex approach than native S3 triggers. Option D is wrong because API Gateway is used for synchronous HTTP requests, not for reacting to S3 object creation events; it would require an external system to call the API upon upload, which is not automatic.

43
MCQeasy

A company needs to migrate 50 TB of data from an on-premises file server to a cloud storage service. The network bandwidth is limited and the migration must be completed within one week. Which cloud service is specifically designed for offline data transfer of large datasets?

A.Online data transfer service
B.Offline data transfer via physical device
C.Batch processing service
D.Data transfer acceleration
AnswerB

Offline data transfer via a physical device ships data on encrypted disks to the cloud provider, bypassing limited network bandwidth. This satisfies the 50 TB volume and one-week deadline that online upload over the constrained link cannot meet.

Why this answer

Offline data transfer via physical device is specifically designed for offline data transfer of large datasets, such as 50 TB, when network bandwidth is limited. It provides physical storage devices that are shipped to the customer, loaded with data, and returned to the cloud provider for ingestion into the cloud storage service, bypassing network constraints entirely. This makes it the ideal choice for completing a 50 TB migration within one week over a limited bandwidth connection.

Exam trap

The trap here is that candidates often confuse online data transfer services with offline transfer solutions, overlooking that the physical device service is the only option designed for moving large data when bandwidth is insufficient.

How to eliminate wrong answers

Option A is wrong because AWS DataSync is an online data transfer service that requires network connectivity and is not designed for offline transfer; it would be impractical for 50 TB over limited bandwidth within one week. Option C is wrong because Amazon S3 Batch Operations is used for managing bulk actions on existing S3 objects (e.g., copying, tagging) and does not handle initial data ingestion from on-premises sources. Option D is wrong because S3 Transfer Acceleration is a network optimization feature that speeds up uploads over the internet but still relies on available bandwidth and cannot overcome severe bandwidth limitations for large datasets.

44
MCQmedium

A cloud engineer is writing a Terraform configuration to deploy an AWS EC2 instance. The engineer wants to pass the AMI ID and instance type into the configuration at runtime without hardcoding them. Which Terraform feature should be used?

A.Locals
B.Outputs
C.Variables
D.Data sources
AnswerC

Input variables let the configuration accept the AMI ID and instance type at runtime via CLI flags, variable files, or environment variables, rather than hardcoding values. This satisfies the requirement to pass values in without editing the configuration.

Why this answer

Variables in Terraform allow you to define parameters that can be supplied at runtime, making configurations reusable and flexible.

45
MCQeasy

A developer wants to deploy a containerized application on a Kubernetes cluster using a package manager that simplifies deployment and management. Which tool should be used?

A.Docker Compose
B.Helm
C.Terraform
D.Ansible
AnswerB

Helm is the Kubernetes package manager, bundling manifests into charts with templating, versioning and release tracking. It simplifies deploying and managing the containerised application across cluster environments, which is precisely the package-manager capability the developer requires.

Why this answer

Helm is the package manager for Kubernetes. It uses charts to define, install, and upgrade complex Kubernetes applications.

46
MCQhard

A team is using Kubernetes for container orchestration. They want to ensure that a new deployment does not cause downtime by gradually updating pods with a rolling update strategy. Which parameter in a Deployment manifest controls the number of pods that can be unavailable during the update?

A.spec.minReadySeconds
B.spec.replicas
C.spec.strategy.rollingUpdate.maxSurge
D.spec.strategy.rollingUpdate.maxUnavailable
AnswerD

maxUnavailable caps how many pods may be taken offline simultaneously during a rolling update, directly satisfying the no-downtime constraint. Setting it to 0 with maxSurge above 0 keeps full capacity while new pods start, so the deployment never drops below the desired replica count.

Why this answer

The `spec.strategy.rollingUpdate.maxUnavailable` parameter in a Kubernetes Deployment manifest specifies the maximum number of pods that can be unavailable during a rolling update. This ensures that a controlled number of pods are taken down at a time, preventing downtime by maintaining a minimum number of available pods throughout the update process.

Exam trap

The trap here is that candidates often confuse `maxSurge` (which controls extra pods created above the desired count) with `maxUnavailable` (which controls pods that can be taken down), leading them to select option C instead of D.

How to eliminate wrong answers

Option A is wrong because `spec.minReadySeconds` controls how long a newly created pod must be ready before it is considered available, not the number of pods that can be unavailable during an update. Option B is wrong because `spec.replicas` defines the desired number of pod replicas, not the availability constraints during a rolling update. Option C is wrong because `spec.strategy.rollingUpdate.maxSurge` controls the maximum number of pods that can be created above the desired replica count during an update, not the number that can be unavailable.

47
MCQhard

A company is deploying a multi-tier application on AWS using AWS CloudFormation. The application consists of an Auto Scaling group, an RDS instance, and an Application Load Balancer. The team needs to ensure that the RDS instance is created before the Auto Scaling group and that the Auto Scaling group is updated only after the load balancer is ready. Which CloudFormation feature should be used to define these dependencies?

A.Metadata section
B.DependsOn attribute
C.UpdatePolicy attribute
D.CreationPolicy attribute
AnswerB

The DependsOn attribute in CloudFormation explicitly defines that a resource creation or update depends on another resource. By specifying DependsOn, you can ensure that the RDS instance is created before the Auto Scaling group, and the Auto Scaling group waits for the load balancer. This controls the order of resource provisioning and updates, meeting the requirement.

Why this answer

The DependsOn attribute explicitly defines dependencies between CloudFormation resources, ensuring that the RDS instance is created before the Auto Scaling group and that the Auto Scaling group waits for the load balancer. CreationPolicy and UpdatePolicy control signaling and update behavior, not creation order, and Metadata is for informational purposes only.

Exam trap

The trap here is confusing CreationPolicy with dependency management; CreationPolicy waits for signals but does not enforce that one resource is created before another.

48
MCQeasy

A cloud administrator needs to deploy a new version of an application to a Kubernetes cluster. The administrator wants to update the application without downtime and ensure that if the new version fails, the deployment automatically rolls back to the previous version. Which Kubernetes resource should the administrator use?

A.Deployment
B.StatefulSet
C.DaemonSet
D.Job
AnswerA

A Kubernetes Deployment manages the rollout of new versions by creating a ReplicaSet and gradually replacing pods. It supports rolling updates and automatic rollback if the new version fails health checks, ensuring zero downtime and safe deployment, which matches the administrator's requirements.

Why this answer

A Kubernetes Deployment is the correct resource because it provides declarative updates for pods and ReplicaSets, enabling rolling updates and automatic rollbacks. It ensures that the application remains available during updates and reverts to the previous version if the new version fails. Other resources are designed for different use cases and do not offer these capabilities.

Exam trap

The trap here is assuming that any workload controller can handle rolling updates and rollbacks, but only Deployments are specifically designed for stateless application version management with automatic rollback.

49
MCQeasy

An organization is using Azure DevOps to implement a CI/CD pipeline. In which stage of the pipeline would automated unit tests typically be executed?

A.Deploy
B.Build
C.Verify
D.Source
AnswerB

Automated unit tests run during the Build stage, immediately after compilation and before artefacts are published. Executing them here fails fast on broken code, satisfying the stem's CI/CD requirement by gating later Release and Deploy stages on passing tests.

Why this answer

In a typical CI/CD pipeline, automated unit tests are executed during the Build stage, immediately after code compilation, to validate that individual components function correctly before any deployment. This early feedback loop catches defects quickly and prevents broken code from progressing to later stages. The Build stage is where code is compiled, packaged, and unit-tested.

Exam trap

CV0-004 often tests the confusion between Build and Verify/Test stages, causing candidates to place unit tests in a later stage when they should be executed during the Build stage for early feedback.

How to eliminate wrong answers

Option A is wrong because the Deploy stage is where the built and tested artifacts are released to an environment; unit tests are not typically run there. Option C is wrong because the Verify stage (or Test stage) usually runs integration, system, or acceptance tests, not unit tests; unit tests belong earlier in the pipeline. Option D is wrong because the Source stage is where code is checked out or triggered, not where tests are executed.

50
MCQeasy

A company wants to deploy a Lambda function that processes objects uploaded to an S3 bucket. Which event trigger should be configured on the Lambda function?

A.API Gateway
B.CloudWatch Events
C.S3 bucket event notification
D.SQS
AnswerC

S3 bucket event notifications push records directly to Lambda when objects are created, satisfying the stem's requirement to process uploads automatically. This native integration invokes the function per object without polling, unlike scheduled or manual triggers. Configuring the notification on the bucket, filtered by event type, delivers the object metadata Lambda needs.

Why this answer

S3 bucket event notifications can be configured to directly invoke a Lambda function when objects are uploaded. This is the native, serverless integration where S3 publishes an event (e.g., s3:ObjectCreated:Put) to Lambda, triggering the function automatically without any intermediary service.

Exam trap

CompTIA Cloud+ often tests the misconception that SQS or CloudWatch Events are required to bridge S3 and Lambda, when in fact S3 can invoke Lambda directly via its event notification feature.

How to eliminate wrong answers

Option A is wrong because API Gateway is used to create RESTful or WebSocket APIs that trigger Lambda functions via HTTP requests, not for S3 object upload events. Option B is wrong because CloudWatch Events (now Amazon EventBridge) is used for scheduling or responding to AWS service events, but it is not the direct trigger for S3 object uploads; S3 can send events directly to Lambda without CloudWatch. Option D is wrong because SQS is a message queue service; while Lambda can poll SQS, S3 can send events directly to Lambda without needing an SQS queue as an intermediary.

51
MCQeasy

A cloud administrator is deploying a new virtual machine in a public cloud. The administrator needs to ensure that the VM can be accessed remotely for management purposes. The security group associated with the VM currently allows only outbound traffic. Which inbound rule should be added to allow SSH access from the administrator's corporate network?

A.Allow inbound TCP port 443 from the corporate network's CIDR block.
B.Allow inbound UDP port 22 from the corporate network's CIDR block.
C.Allow inbound TCP port 3389 from the corporate network's CIDR block.
D.Allow inbound TCP port 22 from the corporate network's CIDR block.
AnswerD

SSH uses TCP port 22 by default. To allow remote management, an inbound rule permitting TCP port 22 from the specific corporate network CIDR is necessary. This restricts access to known IP addresses, enhancing security. Without this rule, the VM would be unreachable via SSH, preventing management. This is a fundamental step in securing remote access to cloud instances.

Why this answer

SSH access requires an inbound rule allowing TCP port 22 from the administrator's network. This ensures that only trusted sources can connect, reducing the attack surface. Port 3389 is for RDP, UDP 22 is not used by SSH, and port 443 is for HTTPS.

Therefore, the rule allowing TCP 22 from the corporate CIDR is the correct choice for secure remote management.

Exam trap

The trap here is confusing SSH with RDP or using the wrong protocol; SSH is TCP port 22, not 3389 or UDP.

52
MCQmedium

A cloud engineer is tasked with deploying a containerized application on Kubernetes. The application must handle varying loads, and the deployment should automatically replace failed containers. Which Kubernetes object should the engineer use to achieve self-healing and scalability?

A.ConfigMap
B.Service
C.Deployment
D.Pod
AnswerC

A Deployment manages ReplicaSets, which maintain the desired pod count and automatically replace failed containers, satisfying the self-healing requirement. Its Horizontal Pod Autoscaler integration adjusts replica counts as load varies, delivering the scalability the stem demands. Bare pods or DaemonSets cannot reschedule failed replicas or scale dynamically in this manner.

Why this answer

A Deployment is the correct Kubernetes object because it manages ReplicaSets to provide declarative updates, self-healing (automatic replacement of failed pods), and scalability (adjusting replica counts). Unlike a standalone Pod, a Deployment ensures the desired state is maintained, automatically rescheduling containers if they fail.

Exam trap

CompTIA Cloud+ often tests the misconception that a Pod alone provides self-healing, but in Kubernetes, a Pod is a non-self-healing atomic unit; only controllers like Deployment (or StatefulSet/DaemonSet) provide automatic replacement and scaling.

How to eliminate wrong answers

Option A (ConfigMap) is wrong because it is used to inject configuration data (e.g., environment variables, files) into pods, not to manage pod lifecycle, self-healing, or scaling. Option B (Service) is wrong because it provides a stable network endpoint and load balancing for a set of pods, but does not handle pod replacement or scaling of replicas. Option D (Pod) is wrong because a single Pod lacks self-healing capabilities; if the Pod fails, it is not automatically replaced unless managed by a higher-level controller like a Deployment.

53
MCQmedium

An organization is migrating a MySQL database to Amazon RDS using AWS DMS. They want to minimize downtime by using ongoing replication from the source. Which DMS feature should they enable to capture changes as they occur on the source database?

A.Data validation
B.Change Data Capture (CDC)
C.Full load
D.Schema conversion
AnswerB

Change Data Capture reads the source's transaction logs and streams ongoing inserts, updates and deletes to the target, so RDS stays synchronised after the initial full load. This satisfies the requirement to minimise downtime during cutover.

Why this answer

Change Data Capture (CDC) in AWS DMS captures ongoing changes from the source database by reading the transaction logs (e.g., binary log for MySQL) and applying them to the target. This enables near-zero downtime migration because after the initial full load, CDC continuously replicates inserts, updates, and deletes.

Exam trap

CV0-004 often tests the difference between full load and CDC; the trap is choosing Full load when the requirement is to capture ongoing changes to minimize downtime.

How to eliminate wrong answers

Option A is wrong because Data validation compares source and target data to ensure consistency; it does not capture changes. Option C is wrong because Full load only performs the initial bulk copy of existing data, not ongoing changes. Option D is wrong because Schema conversion is a feature of AWS SCT (Schema Conversion Tool) that converts schemas between different database engines; it does not capture ongoing changes.

54
MCQhard

A cloud engineer is deploying a containerized application on Amazon ECS using the Fargate launch type. The application requires persistent storage for a shared cache that must be accessible by multiple tasks across different Availability Zones. The cache data must survive task restarts. Which storage solution should the engineer use?

A.Amazon FSx for Windows File Server
B.Amazon S3 bucket mounted as a file system using s3fs
C.Amazon EBS volume attached to each task
D.Amazon EFS file system mounted to each task
AnswerD

Amazon EFS is a shared, elastic file system that can be mounted by multiple ECS tasks across different Availability Zones. It provides persistent storage that survives task restarts. Fargate tasks support EFS mounts, making it suitable for a shared cache that requires concurrent access and durability.

Why this answer

Amazon EFS provides a shared, durable, and scalable file system that can be mounted by multiple ECS tasks across Availability Zones. It supports the POSIX interface, making it ideal for shared cache storage that requires concurrent access and persistence. Fargate tasks can mount EFS file systems, ensuring the cache data remains available even if tasks are restarted or replaced.

Exam trap

The trap here is assuming that Amazon EBS can be shared across multiple tasks or that S3 can serve as a low-latency file system for a shared cache.

55
MCQhard

A company uses GitHub Actions to build and deploy a microservices application. They want to automate the deployment to a Kubernetes cluster only when changes are pushed to the main branch. Which GitHub Actions event trigger should be used in the workflow?

A.on: workflow_dispatch:
B.on: push: branches: [ main ]
C.on: schedule: - cron: '0 0 * * *'
D.on: pull_request: branches: [ main ]
AnswerB

The push event with a branches filter limited to main triggers the workflow only when commits land on that branch, ignoring pushes to feature branches. This precisely matches the requirement to deploy solely on main-branch changes.

Why this answer

The 'push' event with branch filters triggers on pushes to main. 'pull_request' triggers on PR events; 'schedule' triggers on a cron; 'workflow_dispatch' triggers manually.

56
MCQhard

A company is deploying a containerized application on AWS Fargate. The application requires a persistent, shared storage volume that can be accessed by multiple tasks simultaneously and must survive task restarts. The storage must be highly available and scalable. Which storage solution should the company use?

A.Amazon Elastic File System (EFS)
B.Amazon Elastic Block Store (EBS) volumes
C.Amazon S3 bucket mounted as a file system
D.AWS Fargate ephemeral storage
AnswerA

Amazon EFS is a fully managed, scalable, elastic file system that can be mounted by multiple EC2 instances and Fargate tasks simultaneously. It provides shared storage that persists independently of task lifecycle, meeting the requirements for high availability and scalability in a multi-task Fargate deployment.

Why this answer

Amazon EFS is designed for shared, elastic file storage that can be mounted by multiple Fargate tasks concurrently. It provides the persistent, highly available, and scalable storage needed for the application, unlike EBS volumes which are not shared, ephemeral storage which is temporary, or S3 which is not a file system.

Exam trap

The trap here is assuming that EBS volumes can be shared across multiple Fargate tasks, but EBS is block storage that supports only single-attach for Fargate, and multi-attach is limited to specific EC2 instances.

57
MCQeasy

A company is migrating to the cloud and needs to transfer 200 TB of data from an on-premises data center to GCP. The network bandwidth is limited, so they want to use a physical appliance for offline transfer. Which GCP service should they use?

A.Azure Data Box
B.Transfer Appliance
C.AWS DataSync
D.Storage Transfer Service
AnswerB

Transfer Appliance is Google's physical, rackable device shipped to the customer, loaded with data, then returned for ingestion into GCP. It bypasses the limited-bandwidth constraint by moving 200 TB offline rather than over the network.

Why this answer

Storage Transfer Service is for online transfers; Transfer Appliance is Google's offline physical device; DataSync is AWS; Azure Data Box is Microsoft's offline device.

58
MCQhard

A cloud engineer is deploying a containerized application on Amazon ECS using the Fargate launch type. The application requires a persistent shared storage volume that can be accessed by multiple tasks simultaneously. The engineer needs to ensure that the storage is highly available and can be mounted to multiple ECS tasks across different Availability Zones. Which storage solution should the engineer use?

A.Amazon S3 bucket
B.Amazon EFS file system
C.Amazon FSx for Windows File Server
D.Amazon EBS volume
AnswerB

Amazon EFS is a fully managed, highly available, and scalable file storage service that can be mounted to multiple ECS tasks across different Availability Zones simultaneously. It supports the Network File System (NFS) protocol and is designed for shared access, making it ideal for this requirement.

Why this answer

Amazon EFS is the correct choice because it provides shared, highly available file storage that can be mounted to multiple ECS tasks across Availability Zones. It uses NFS and is designed for concurrent access. EBS is single-attach, S3 is object storage, and FSx for Windows is for Windows workloads, so they do not meet the requirements.

Exam trap

The trap here is assuming that Amazon EBS can be shared across multiple tasks like a network file system; EBS is block storage with single-attach limitations.

59
MCQeasy

A DevOps team wants to deploy a Kubernetes application using a package manager that simplifies the deployment process by bundling all Kubernetes resources into a single package. Which tool should the team use?

A.Kustomize
B.Helm
C.Ansible
D.Terraform
AnswerB

Helm packages Kubernetes manifests into versioned charts, letting the team install, upgrade and roll back the whole application as one unit. It bundles Deployments, Services and ConfigMaps into a single release, satisfying the requirement for a package manager.

Why this answer

Helm is the package manager for Kubernetes that uses charts to define, install, and upgrade even the most complex Kubernetes applications.

60
MCQmedium

A cloud engineer is using Ansible to automate the configuration of cloud resources. The engineer needs to ensure that the automation does not require any agent software to be installed on the target nodes. Which characteristic of Ansible makes this possible?

A.It uses PowerShell Desired State Configuration
B.It uses a master-agent architecture
C.It is agentless
D.It requires a pull-based model
AnswerC

Ansible connects to target nodes over standard SSH or WinRM, pushing modules at runtime rather than relying on a persistent agent. This agentless architecture satisfies the constraint that no software be pre-installed on managed hosts.

Why this answer

Ansible is agentless because it communicates with managed nodes over standard SSH (Linux/Unix) or WinRM (Windows) rather than requiring a persistent agent daemon to be installed and maintained on each target. The control node pushes Python-based modules to the target at runtime, executes them, and removes them afterward. This is why option C directly answers the requirement that no agent software be installed on target nodes.

Exam trap

The trap here is confusing 'agentless' with 'no dependencies' — candidates may pick the pull-based option assuming Ansible works like Puppet, but Ansible is push-based by default and its agentless nature comes from SSH/WinRM, not from a pull model.

How to eliminate wrong answers

Option A is wrong because PowerShell Desired State Configuration is a Microsoft push/pull configuration platform used by tools like Ansible's win_dsc module, not the mechanism that makes Ansible agentless. Option B is wrong because a master-agent architecture is the opposite of agentless — it describes tools like Puppet, Chef, or Salt in agent mode, which require a persistent agent on each managed node. Option D is wrong because Ansible's default mode is push-based (the control node initiates SSH connections), not pull-based; pull mode (ansible-pull) is an optional pattern and does not explain agentless operation.

61
MCQmedium

An administrator is writing an Ansible playbook to provision cloud resources across multiple cloud providers. The playbook must manage instances in AWS, Azure, and GCP. Which Ansible concept should the administrator use to interact with each cloud provider's API?

A.Modules
B.Roles
C.Inventories
D.Playbooks
AnswerA

Ansible modules are provider-specific plugins that translate playbook tasks into each cloud API's native calls, so AWS, Azure and GCP each expose dedicated modules covering compute, networking and storage. This satisfies the stem's multi-cloud requirement, since a single playbook can invoke the appropriate module per provider without custom API scripting.

Why this answer

Ansible modules are the units of code that perform specific tasks, such as interacting with cloud provider APIs. For multi-cloud provisioning, the administrator would use modules like `amazon.aws.ec2_instance`, `azure.azcollection.azure_rm_virtualmachine`, and `google.cloud.gcp_compute_instance` to manage resources in AWS, Azure, and GCP respectively. Modules abstract the underlying API calls, allowing the playbook to execute tasks across providers.

Exam trap

CV0-004 often tests the confusion between Ansible roles and modules, where candidates might think roles handle API interactions, but roles are just a structural organization method.

How to eliminate wrong answers

Option B is wrong because roles are a way to organize playbooks and tasks into reusable components, not to interact with APIs directly. Option C is wrong because inventories define the hosts or nodes that playbooks target, not the API interactions. Option D is wrong because playbooks are the orchestration files that call modules; they do not themselves interact with cloud APIs.

62
Multi-Selecteasy

A company is adopting Infrastructure as Code (IaC) to manage its cloud resources. Which THREE statements are true about IaC? (Select THREE.)

Select 3 answers
A.IaC allows for automated provisioning of infrastructure
B.IaC eliminates the need for manual configuration changes
C.IaC is only applicable for immutable infrastructure
D.IaC configurations are typically stored in version control
E.IaC ensures that deployments are repeatable and consistent
AnswersA, D, E

IaC codifies infrastructure definitions, so provisioning happens through automated pipelines rather than manual console work. This directly satisfies the scenario's adoption goal: repeatable, version-controlled deployment of cloud resources. Templates or configuration files drive the automation, removing human error and enabling consistent environments across deployments.

Why this answer

Option A is correct because IaC tools such as Terraform, AWS CloudFormation, and Ansible automate the provisioning of infrastructure by declaring resources in code and applying them through APIs, removing manual click-through provisioning. Option D is correct because IaC configuration files (e.g., .tf, YAML templates, playbooks) are text-based and are normally committed to a version control system like Git, enabling change tracking, peer review, and rollback. Option E is correct because the same declarative or idempotent IaC code produces the same resulting infrastructure state on every run, giving repeatable and consistent deployments across environments.

Option B is not marked correct because IaC does not eliminate manual configuration changes entirely; out-of-band or drift changes can still occur and must be detected and reconciled. Option C is not marked correct because IaC supports both mutable and immutable infrastructure models, so it is not limited to immutable infrastructure.

Exam trap

CV0-004 often tests the misconception that IaC eliminates all manual changes or is only for immutable infrastructure — candidates may overstate its scope and pick incorrect statements.

63
MCQmedium

An organization wants to deploy a new microservice to a Kubernetes cluster with zero downtime. The deployment should update pods gradually by replacing old pods with new ones, and if the new pods fail health checks, the rollout should stop. Which Kubernetes deployment strategy meets these requirements?

A.Canary
B.Recreate
C.Rolling update
D.Blue/green
AnswerC

A rolling update replaces pods incrementally, keeping the service available throughout. Its maxUnavailable and maxSurge settings control the gradual replacement, and the rollout halts automatically when new pods fail readiness probes, satisfying the zero-downtime and health-check constraints.

Why this answer

A rolling update strategy in Kubernetes replaces pods incrementally and can be configured to pause on failed health checks.

64
MCQeasy

A cloud engineer needs to deploy a Lambda function that processes objects uploaded to an S3 bucket. The function code is stored in a .zip file. Which event trigger should the engineer configure to invoke the function automatically?

A.S3 event notification
B.API Gateway
C.SQS
D.EventBridge
AnswerA

S3 event notifications publish ObjectCreated events to Lambda, invoking the function whenever an object lands in the bucket. This satisfies the automatic invocation requirement for uploaded objects, avoiding polling and needing no manual trigger configuration.

Why this answer

S3 event notifications can be configured on a bucket to invoke a Lambda function when objects are created (e.g., s3:ObjectCreated:*), which directly satisfies the requirement to process uploaded objects automatically. This is the native, serverless integration between S3 and Lambda. API Gateway, SQS, and EventBridge are not triggered by S3 PUT events without additional configuration.

Exam trap

The trap is overcomplicating the trigger — candidates pick EventBridge or SQS thinking they are more 'event-driven,' but the simplest native S3-to-Lambda trigger is an S3 event notification.

How to eliminate wrong answers

Option B is wrong because API Gateway invokes Lambda in response to HTTP/REST requests, not S3 object uploads — it would require the uploader to call an API instead of using S3 directly. Option C is wrong because SQS is a queue that Lambda polls; S3 does not natively enqueue messages to SQS without an event notification or Lambda in between, so it does not directly trigger on upload. Option D is wrong because EventBridge can receive S3 events, but that requires S3 event notifications to be enabled first and an EventBridge rule to route them — it is an indirect path, not the direct trigger the question asks for.

65
MCQmedium

A cloud engineer is deploying a new version of a web application to a Kubernetes cluster. The application must remain available during the update, and the team wants to minimize the risk of exposing users to a faulty version. They decide to use a deployment strategy that gradually shifts traffic to the new version while monitoring for errors. Which Kubernetes resource should they configure to achieve this?

A.A Deployment with a RollingUpdate strategy and maxSurge/maxUnavailable parameters.
B.A StatefulSet with ordered pod management.
C.A Service of type LoadBalancer with session affinity enabled.
D.A DaemonSet that runs a pod on every node.
AnswerA

A Deployment with RollingUpdate strategy gradually replaces old pods with new ones while maintaining availability. By setting maxSurge and maxUnavailable, the engineer controls the pace of the rollout. This allows monitoring and, if needed, pausing or rolling back the deployment. It is the standard way to achieve zero-downtime updates in Kubernetes without additional tools.

Why this answer

A Deployment with a RollingUpdate strategy is the native Kubernetes mechanism for gradually updating application instances while preserving availability. By configuring maxSurge and maxUnavailable, the engineer can control how many extra pods are created and how many old pods are taken down at once. This enables monitoring and, if necessary, pausing or rolling back the update to avoid exposing users to a faulty version.

Exam trap

The trap here is confusing a Service's traffic distribution with a Deployment's rollout control; a Service balances traffic but does not manage version updates.

66
MCQmedium

A cloud engineer is writing a Bicep file to deploy Azure resources. Bicep is a domain-specific language (DSL) that transpiles to ARM templates. Which of the following is a benefit of using Bicep over ARM JSON templates?

A.Bicep automatically manages state
B.Bicep reduces code verbosity and supports modules
C.Bicep is natively executed by Azure Resource Manager
D.Bicep supports imperative scripting
AnswerB

Bicep's declarative syntax removes much of ARM JSON's boilerplate, such as repeated parameters and nested resource declarations, and supports modules for reusable, composable deployments. This directly satisfies the stem's requirement for a benefit over ARM JSON templates.

Why this answer

Bicep provides a simpler syntax with less boilerplate, modularity, and reusable modules. It reduces complexity compared to raw ARM JSON.

67
MCQmedium

A company is deploying a containerized application on Amazon ECS. The operations team needs to ensure that the application can scale automatically based on CPU utilization and that the underlying container instances are managed without manual intervention. They also want to minimize the operational overhead of managing the container host infrastructure. Which ECS launch type should they use?

A.EKS launch type
B.AWS Batch launch type
C.Fargate launch type
D.EC2 launch type
AnswerC

AWS Fargate is a serverless compute engine for containers that eliminates the need to manage EC2 instances. It automatically scales based on CPU utilization when used with ECS service auto scaling. The team only defines task definitions and services, and Fargate handles the infrastructure. This directly reduces operational overhead and meets the requirement for automatic scaling without manual host management.

Why this answer

The Fargate launch type for Amazon ECS removes the need to manage EC2 instances, allowing the team to focus on the application. It supports service auto scaling based on CPU utilization and other metrics. By using Fargate, the operations team minimizes infrastructure management and achieves automatic scaling, which aligns with the stated requirements for reduced operational overhead.

Exam trap

The trap here is confusing ECS launch types with other AWS container services like EKS or Batch, which serve different purposes.

68
MCQeasy

A company is deploying a new application on AWS and wants to automate the creation of infrastructure using infrastructure as code. The team needs to define resources such as Amazon VPC, subnets, and security groups in a template that can be version-controlled and reused across multiple environments. Which AWS service should they use?

A.AWS CodeDeploy
B.AWS CloudFormation
C.AWS OpsWorks
D.AWS Elastic Beanstalk
AnswerB

AWS CloudFormation allows you to define infrastructure as code using JSON or YAML templates. It supports version control, parameterization, and reuse across environments. It can create and manage a wide range of AWS resources, including VPCs, subnets, and security groups, making it ideal for this scenario.

Why this answer

AWS CloudFormation is the correct choice because it enables infrastructure as code, allowing the team to define and version AWS resources such as VPCs, subnets, and security groups in templates. It supports reuse across environments through parameters and mappings. Elastic Beanstalk, OpsWorks, and CodeDeploy serve different purposes and do not provide the same level of infrastructure definition and version control.

Exam trap

The trap here is confusing infrastructure as code with application deployment services; Elastic Beanstalk and CodeDeploy automate deployments but do not define infrastructure resources like VPCs and subnets.

69
MCQhard

A company is migrating a 50 TB on-premises database to AWS RDS MySQL. The migration must have minimal downtime and support ongoing replication during the cutover. The database schema is standard MySQL. Which combination of services should the company use?

A.AWS DMS with schema conversion tool to convert to MySQL
B.AWS Database Migration Service (DMS) with Change Data Capture (CDC) replication
C.AWS Snowball Edge to transfer database dump, then import to RDS
D.AWS DataSync to transfer database files to S3, then restore to RDS
AnswerB

DMS performs the initial full load while Change Data Capture continuously replicates ongoing inserts, updates and deletes from the source MySQL binlog, keeping the target in sync until cutover. This satisfies the minimal-downtime and ongoing-replication constraints for the 50 TB migration.

Why this answer

AWS DMS with Change Data Capture (CDC) performs the initial full load and then continuously replicates ongoing changes from the source MySQL to RDS MySQL, enabling minimal-downtime cutover. Because the schema is standard MySQL, no schema conversion is needed, and CDC keeps the target in sync until the application is switched over.

Exam trap

CV0-004 often tests the distinction between schema conversion (SCT, needed only for heterogeneous migrations) and data replication (DMS/CDC) — candidates pick SCT even when the schema is already the target engine.

How to eliminate wrong answers

Option A is wrong because the AWS Schema Conversion Tool (SCT) is used when converting from a different database engine (e.g., Oracle to MySQL); since the schema is already standard MySQL, SCT is unnecessary and adds complexity. Option C is wrong because Snowball Edge is an offline bulk-transfer appliance — it cannot support ongoing replication or minimal downtime during cutover. Option D is wrong because DataSync transfers files to S3, not database-native replication to RDS; restoring database files from S3 to RDS MySQL is not a supported or practical migration path for a live 50 TB database.

70
Multi-Selectmedium

A company is planning to migrate a 200 TB on-premises file server to AWS S3. The network link is 1 Gbps and cannot be saturated due to other traffic. The migration must be completed within two weeks. Which TWO services or features should the cloud engineer consider to accelerate the transfer? (Choose two.)

Select 2 answers
A.AWS Direct Connect
B.AWS DMS
C.AWS DataSync
D.AWS Snowball
E.AWS Storage Gateway
AnswersC, D

DataSync can accelerate transfers over the network and is designed for large datasets.

Why this answer

AWS DataSync is correct because it is designed to efficiently migrate large datasets to AWS by using parallel multi-threaded transfers and incremental syncs, which can optimize the use of the available 1 Gbps link without saturating it. It can handle the 200 TB file server migration by automating the transfer and reducing the time required compared to manual copying, though the 1 Gbps link alone may still be insufficient for the two-week window, making it a partial solution.

Exam trap

The trap here is that candidates often assume AWS DataSync alone can handle any large transfer over a network link, but they overlook the bandwidth calculation—200 TB at 1 Gbps takes over 18 days, so a physical transport like Snowball is necessary to meet the two-week deadline.

71
MCQmedium

A cloud engineer is deploying a web application on AWS and needs to ensure that the application is fault-tolerant across multiple Availability Zones. The engineer plans to use an Auto Scaling group with a launch template. What should the engineer configure to ensure that instances are launched in multiple Availability Zones?

A.Specify multiple subnets, each in a different Availability Zone, in the Auto Scaling group configuration.
B.Create multiple Auto Scaling groups, each with a single subnet in a different Availability Zone.
C.Use a single subnet and enable cross-zone load balancing on the load balancer.
D.Configure the launch template to specify multiple Availability Zones.
AnswerA

An Auto Scaling group can be configured with multiple subnets across different Availability Zones. When the group scales, it launches instances evenly across the specified subnets, providing fault tolerance. This directly meets the requirement for multi-AZ deployment without additional complexity.

Why this answer

Configuring the Auto Scaling group with multiple subnets in different Availability Zones ensures that instances are launched across those AZs, providing fault tolerance. This is the standard and simplest method to achieve multi-AZ deployment for an Auto Scaling group, unlike using a single subnet or multiple groups.

Exam trap

The trap here is thinking that the launch template defines Availability Zones, but actually the subnets specified in the Auto Scaling group determine the AZ placement of instances.

72
MCQhard

An organization uses CloudFormation to manage resources across multiple AWS accounts. They need to deploy a common set of resources (e.g., logging configuration) to all accounts in an AWS Organization. Which CloudFormation feature should they use?

A.Change sets
B.StackSets
C.Drift detection
D.Nested stacks
AnswerB

StackSets deploy a single CloudFormation template across multiple accounts and Regions from one administration account, satisfying the requirement to roll out shared logging configuration organisation-wide. Unlike ordinary stacks, which are scoped to one account and Region, StackSets use service-managed or self-managed permissions to target every account in the AWS Organization automatically.

Why this answer

CloudFormation StackSets allow you to deploy stacks across multiple accounts and regions in a single operation, ideal for multi-account governance.

73
Multi-Selectmedium

A cloud engineer is migrating a legacy application to AWS. The application requires minimal downtime during the database migration from SQL Server to Aurora MySQL. Which TWO AWS services should the engineer use to achieve this?

Select 2 answers
A.AWS Snowball
B.AWS Schema Conversion Tool (SCT)
C.AWS Direct Connect
D.AWS DataSync
E.AWS Database Migration Service (DMS)
AnswersB, E

SCT converts the SQL Server schema and stored procedures into Aurora MySQL-compatible DDL, which is essential because the two engines use different syntax. Without this conversion the migrated schema would fail on Aurora, so it satisfies the heterogeneous-engine requirement underpinning the minimal-downtime cutover.

Why this answer

The AWS Schema Conversion Tool (SCT) is used to convert the source SQL Server database schema and code to be compatible with Aurora MySQL, handling differences in data types, stored procedures, and other database objects. The AWS Database Migration Service (DMS) then performs the actual data migration with minimal downtime by continuously replicating changes from the source to the target database until a cutover is performed. Together, SCT and DMS enable a heterogeneous migration with near-zero downtime.

Exam trap

CompTIA often tests the distinction between data migration services (DMS) and data transfer services (DataSync, Snowball), where candidates mistakenly choose DataSync for database migrations because it sounds similar to 'data synchronization' but it lacks schema conversion and live database replication capabilities.

74
MCQmedium

A company is migrating a large Oracle database (2 TB) from on-premises to AWS RDS for Oracle. They require minimal downtime and need to keep the source database running during migration. Which AWS service should they use to achieve continuous replication?

A.AWS DataSync
B.AWS DMS with CDC
C.AWS S3 Transfer Acceleration
D.AWS Snowball Edge
AnswerB

AWS DMS with change data capture continuously replicates ongoing changes from the live Oracle source to RDS, so the source stays running and cutover downtime is limited to final catch-up. Native tools like Data Pump require quiescing the database, which the minimal-downtime constraint rules out.

Why this answer

AWS DMS with Change Data Capture (CDC) is the correct choice because it enables continuous replication of ongoing changes from the source Oracle database to the target RDS for Oracle instance, allowing the source to remain fully operational during migration. CDC captures incremental changes (inserts, updates, deletes) from the source's redo logs, minimizing downtime to a brief cutover window. This meets the requirement of a 2 TB database with minimal downtime while keeping the source running.

Exam trap

The trap here is that candidates confuse AWS DataSync or S3 Transfer Acceleration as suitable for database replication, but they lack CDC capabilities and are designed for file or object transfers, not transactional database synchronization.

How to eliminate wrong answers

Option A is wrong because AWS DataSync is designed for one-time bulk data transfers between on-premises storage and AWS, not for continuous database replication or CDC. Option C is wrong because AWS S3 Transfer Acceleration speeds up uploads to S3 buckets over the internet but does not support database replication or CDC for Oracle to RDS. Option D is wrong because AWS Snowball Edge is a physical device for offline bulk data transfer, which cannot provide continuous replication and would require taking the source database offline to transfer data.

75
MCQhard

A financial services company is deploying a critical application on AWS. The security team requires that all data stored in Amazon S3 be encrypted at rest using keys managed by the company, with the ability to audit key usage and rotate keys annually. The company also wants to minimize operational overhead. Which S3 encryption option should the cloud engineer implement?

A.SSE-S3 with AWS managed keys
B.SSE-KMS with AWS managed keys
C.SSE-KMS with customer managed keys
D.SSE-C with customer-provided keys
AnswerC

SSE-KMS with customer managed keys allows the company to create and manage their own KMS keys, control key policies, enable automatic key rotation, and audit key usage via AWS CloudTrail. This meets all requirements: customer-managed keys, auditing, rotation, and minimal operational overhead since KMS handles the encryption/decryption.

Why this answer

SSE-KMS with customer managed keys provides the necessary control and auditing. The company can create KMS keys, set key policies, enable rotation, and track key usage through CloudTrail. This option balances security requirements with operational efficiency, as AWS manages the encryption and decryption process, but the customer retains control over the keys.

Exam trap

The trap here is confusing SSE-KMS with AWS managed keys and customer managed keys, or assuming SSE-C provides auditing when it does not.

Page 1 of 2 · 116 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Clp Deployment questions.