Courseiva

CCNA Clp Deployment Questions

41 of 116 questions · Page 2/2 · Clp Deployment topic · Answers revealed

76
MCQmedium

A DevOps team wants to deploy a containerized application to a Kubernetes cluster with zero downtime. The team needs to gradually shift traffic from the old version to the new version, monitoring error rates and automatically rolling back if errors exceed a threshold. Which deployment strategy should the team implement?

A.Blue/green deployment
B.Rolling deployment
C.Recreate deployment
D.Canary deployment
AnswerD

Canary deployment routes a small percentage of traffic to the new version first, then gradually shifts the remainder while monitoring error rates. If errors exceed the threshold, traffic reverts to the old version, delivering the gradual shift, monitoring and automatic rollback the team requires.

Why this answer

Canary deployment is correct because it introduces the new version to a small subset of users/traffic first, allowing the team to monitor error rates and metrics in production before progressively shifting more traffic. If error thresholds are breached, traffic can be instantly routed back to the stable version, achieving zero-downtime with automated rollback. This matches the requirement for gradual traffic shifting with monitoring and automatic rollback.

Exam trap

The trap here is confusing rolling deployment with canary deployment — both are gradual, but only canary provides percentage-based traffic control with automated metric-driven rollback, which is what the question explicitly requires.

How to eliminate wrong answers

Option A is wrong because blue/green deployment switches all traffic at once between two identical environments, which does not provide gradual traffic shifting or fine-grained monitoring of a small user subset before full cutover. Option B is wrong because rolling deployment replaces pods incrementally but does not offer precise traffic-percentage control or the ability to route a defined slice of users to the new version for canary-style metric comparison. Option C is wrong because recreate deployment tears down the old version before starting the new one, causing downtime and offering no rollback automation.

77
MCQeasy

A cloud architect is designing a serverless application on AWS Lambda. The function needs to process messages from an SQS queue. Which event trigger should be configured for the Lambda function?

A.API Gateway
B.SQS trigger
C.S3 bucket event
D.EventBridge rule
AnswerB

An SQS trigger uses event source mapping, letting Lambda poll the queue and invoke the function with batched messages. This pull-based integration handles scaling and failed-message handling natively, matching the requirement to process queue messages.

Why this answer

AWS Lambda can be triggered by SQS messages. By configuring an SQS trigger, Lambda automatically polls the queue and invokes the function with each message.

78
Multi-Selectmedium

A cloud engineer is planning a database migration from an on-premises Oracle database to Amazon RDS for PostgreSQL. The migration must minimize downtime and preserve ongoing changes. Which TWO services should the engineer consider using together? (Choose two.)

Select 2 answers
A.AWS DataSync
B.AWS Snowball
C.AWS Database Migration Service (DMS)
D.Amazon S3 Transfer Acceleration
E.AWS Schema Conversion Tool (SCT)
AnswersC, E

AWS DMS performs the actual data migration and continuous replication, capturing ongoing changes from the source Oracle database so the target stays synchronised. This change data capture capability minimises downtime during cutover to Amazon RDS for PostgreSQL.

Why this answer

Option C, AWS Database Migration Service (DMS), is correct because DMS is purpose-built for migrating databases to AWS with minimal downtime, supporting ongoing replication (change data capture) from the source Oracle database to the target RDS for PostgreSQL so that changes made during the migration are continuously applied. Option E, AWS Schema Conversion Tool (SCT), is correct because migrating from Oracle to PostgreSQL involves heterogeneous engine conversion, and SCT automatically converts the source schema, stored procedures, and other database objects into a PostgreSQL-compatible format that DMS can then use for the data migration. The unmarked options do not belong: AWS DataSync (A) is for transferring file and object data, not for database replication; AWS Snowball (B) is a physical device for bulk offline data transfer; and Amazon S3 Transfer Acceleration (D) only speeds up uploads to S3 and has no role in database migration or schema conversion.

79
MCQeasy

A development team uses AWS CodePipeline to deploy a web application. They need to insert a manual approval step so that a release manager can review the build before it is deployed to production. Which action should the team take?

A.Use AWS CodeDeploy to create a deployment group that requires manual approval.
B.Add an approval action in the pipeline between the build and deploy stages.
C.Configure an AWS Lambda function to send an email and wait for a response before continuing.
D.Enable AWS CloudTrail logging on the pipeline and review logs before each deployment.
AnswerB

AWS CodePipeline supports manual approval actions that pause the pipeline until an authorized user approves or rejects. Placing the approval action after the build stage and before the deploy stage ensures that a release manager can review the build artifacts before they reach production. This directly satisfies the requirement without custom scripting.

Why this answer

AWS CodePipeline includes a built-in manual approval action that halts the pipeline until a designated approver responds. By inserting this action between the build and deploy stages, the team ensures that a release manager can inspect the build artifacts and approve or reject the release. This is the standard, least-effort method to implement a human gate without custom code.

Exam trap

The trap here is assuming that CodeDeploy or CloudTrail can provide manual approval, when only CodePipeline has a native approval action.

80
MCQmedium

A company is adopting a CI/CD pipeline using Jenkins to deploy a web application. The pipeline must include steps to compile code, run unit tests, package the application, deploy to a test environment, and then deploy to production. Which pipeline stage should be configured immediately after the build stage?

A.Verify
B.Test
C.Deploy to production
D.Source
AnswerB

Unit tests validate the compiled artefact before it is packaged or promoted, so the test stage must follow build. Running tests immediately after compilation catches defects earliest, satisfying the pipeline's requirement to verify code before deploying to the test environment.

Why this answer

In a typical CI/CD pipeline, after build (compile) comes test (e.g., unit tests) to validate the code before proceeding to deploy.

81
Multi-Selecteasy

A cloud engineer is using Terraform to manage infrastructure. They need to store the state file remotely for team collaboration and to enable state locking. Which THREE of the following backends support state locking? (Select THREE.)

Select 3 answers
A.Consul backend
B.Local file system
C.HTTP backend
D.Azure Blob Storage with blob lease
E.Amazon S3 with DynamoDB for locking
AnswersA, D, E

The Consul backend stores state in Consul's key-value store and uses Consul's session mechanism to acquire a lock, preventing concurrent Terraform runs from corrupting state. This satisfies the stem's state-locking requirement alongside remote storage for team collaboration.

Why this answer

The Consul backend (A) supports state locking natively through Consul's session and key-value store mechanisms, so Terraform can acquire a lock before modifying state. Azure Blob Storage with blob lease (D) supports locking because Terraform uses Azure's blob lease feature to prevent concurrent state writes. Amazon S3 with DynamoDB for locking (E) supports locking by using a DynamoDB table to coordinate and hold the lock while state is stored in S3.

The local file system (B) does not provide remote locking suitable for team collaboration, and the HTTP backend (C) does not support state locking, so neither belongs among the correct answers.

Exam trap

CV0-004 often tests the misconception that any remote backend supports locking — candidates pick HTTP or local because they 'store state remotely' and forget that locking requires a backend with a locking API.

82
MCQmedium

A cloud engineer is deploying a web application to a Kubernetes cluster. The application requires zero downtime during updates, and the team wants to test new versions with a small percentage of users before full rollout. Which deployment strategy should the engineer use?

A.Rolling deployment
B.Blue/green deployment
C.Canary deployment
D.Immutable deployment
AnswerC

Canary deployment routes a small percentage of live traffic to the new version while the remainder continues to the stable release, then gradually shifts traffic. This satisfies both constraints: zero downtime during updates and validating new versions with a limited user subset before full rollout.

Why this answer

A canary deployment routes a small percentage of traffic to the new version, allowing monitoring and automatic rollback if issues arise, meeting the requirements.

83
MCQmedium

A cloud engineer is deploying a serverless application that processes images uploaded to an object storage bucket. The application must automatically resize each image and store the resized version in a second bucket. The engineer wants to minimize operational overhead and ensure the processing runs only when new images are added. Which AWS service should the engineer use to trigger the processing?

A.Amazon EC2 Auto Scaling group with a custom application
B.AWS Batch with a job queue
C.AWS Lambda with an S3 event trigger
D.AWS Step Functions with a polling loop
AnswerC

AWS Lambda natively integrates with Amazon S3 events, allowing the function to execute automatically when an object is created. This serverless approach eliminates server management and scales with the number of uploads, matching the requirement for minimal operational overhead and event-driven processing.

Why this answer

AWS Lambda with an S3 event trigger is the correct choice because it directly responds to object creation events in Amazon S3 without requiring any server management. The integration is native, so the function runs only when new images are uploaded, aligning with the need for minimal operational overhead and automatic processing. Other options involve more management or are not event-driven.

Exam trap

The trap here is assuming that any compute service can be triggered by S3 events, when actually only AWS Lambda provides native, direct event integration with S3 without additional infrastructure.

84
MCQmedium

A cloud engineer is deploying a serverless function using AWS Lambda. The function needs to process messages from an SQS queue. Which event source should be configured to trigger the Lambda function?

A.Amazon S3
B.Amazon SQS
C.Amazon API Gateway
D.Amazon EventBridge
AnswerB

Amazon SQS is a supported Lambda event source; configuring it lets Lambda poll the queue and invoke the function with batched messages. This matches the requirement to process queue messages, unlike push-based sources such as API Gateway or S3.

Why this answer

Lambda can be triggered by SQS, S3, API Gateway, etc. For SQS, the trigger is SQS. S3 triggers on object events; API Gateway for HTTP; EventBridge for events.

85
MCQhard

A team is developing a serverless application on AWS Lambda. The application uses several third-party libraries that are large in size. To reduce deployment package size and enable reuse across functions, the team wants to include these libraries as a separate layer. However, the total unzipped size of all layers exceeds the Lambda limits. What should the team do to resolve this?

A.Increase the Lambda function's reserved concurrency
B.Use a container image for the Lambda function instead of layers
C.Reduce the number of layers by combining libraries into fewer custom layers
D.Request a service limit increase from AWS for layer size
AnswerB

Container images bypass the layer unzipped-size ceiling entirely, since Lambda permits images up to 10 GB. Packaging the large third-party libraries into the image satisfies the stem's constraint that combined layer size exceeds the limit, while still allowing reuse across functions via a shared image base.

Why this answer

AWS Lambda has a hard limit of 250 MB unzipped for the combined deployment package and all layers. When layers exceed this, packaging the function as a container image (up to 10 GB) is the supported workaround. Container images can include large third-party libraries directly in the image, bypassing the layer size limit while still allowing reuse via shared base images.

Exam trap

CV0-004 often tests the misconception that layer size limits can be raised via support tickets or that consolidating layers reduces total size — candidates must recognize the 250 MB unzipped hard limit and the container image escape hatch.

How to eliminate wrong answers

Option A is wrong because reserved concurrency controls how many concurrent invocations a function can handle; it has no effect on deployment package or layer size limits. Option C is wrong because combining libraries into fewer layers does not reduce the total unzipped size — the 250 MB limit applies to the sum of all layers plus the function package, so consolidation does not help. Option D is wrong because AWS does not offer a service limit increase for Lambda layer size; the 250 MB unzipped limit is a hard quota.

86
MCQhard

A company is migrating an on-premises Oracle database to Amazon RDS for MySQL. The migration must have minimal downtime and must handle ongoing changes during migration. The schema needs to be converted to MySQL-compatible format. Which combination of AWS services should the team use?

A.AWS SCT alone
B.AWS DMS with AWS Schema Conversion Tool (SCT)
C.AWS DataSync
D.AWS DMS alone
AnswerB

AWS DMS performs continuous replication using change data capture (CDC) from the Oracle redo logs, satisfying the minimal-downtime and ongoing-changes constraints. AWS SCT converts the Oracle schema to MySQL-compatible DDL, addressing the schema conversion requirement. Together they cover both migration phases without extended outage.

Why this answer

AWS DMS can perform ongoing replication using CDC, and SCT converts schemas between different database engines.

87
MCQmedium

A company wants to deploy a containerized application to a Kubernetes cluster using a rolling update strategy. They have defined a Kubernetes Deployment manifest. Which field controls the number of pods that can be unavailable during the update?

A.spec.strategy.rollingUpdate.maxSurge
B.spec.template.spec.containers[].readinessProbe
C.spec.strategy.rollingUpdate.maxUnavailable
D.spec.replicas
AnswerC

The `maxUnavailable` field, nested under `spec.strategy.rollingUpdate`, directly caps how many pods may be simultaneously unavailable while a rolling update proceeds. This satisfies the stem's requirement to control unavailability during the rollout, whereas `maxSurge` governs extra pods created above the desired replica count instead.

Why this answer

The `spec.strategy.rollingUpdate.maxUnavailable` field in a Kubernetes Deployment manifest explicitly controls the maximum number of Pods that can be unavailable during a rolling update. This field can be set as an absolute number or a percentage of the desired Pod count, ensuring that the update proceeds without dropping below a specified availability threshold.

Exam trap

In CompTIA Cloud+ exams, candidates often confuse `maxSurge` and `maxUnavailable`. While `maxSurge` controls the number of extra Pods created above the target, `maxUnavailable` specifically governs how many Pods can be taken down during a rolling update.

How to eliminate wrong answers

Option A is wrong because `spec.strategy.rollingUpdate.maxSurge` controls the maximum number of Pods that can be created above the desired replica count during an update, not the number of unavailable Pods. Option B is wrong because `spec.template.spec.containers[].readinessProbe` defines a health check that determines when a container is ready to serve traffic, but it does not control the number of Pods that can be unavailable during a rolling update. Option D is wrong because `spec.replicas` sets the desired number of Pod replicas for the Deployment, but it has no direct role in managing the availability constraints during a rolling update.

88
MCQmedium

A company uses CloudFormation to manage infrastructure across multiple AWS accounts. They want to deploy a common set of resources (e.g., VPC, IAM roles) to all accounts in their organization. Which CloudFormation feature should they use?

A.Change sets
B.Nested stacks
C.Stack sets
D.Drift detection
AnswerC

Stack sets extend a single CloudFormation template across multiple accounts and regions from one operation, using organisational or administrator accounts as targets. This directly satisfies the requirement to deploy common VPC and IAM resources to every account in the organisation.

Why this answer

CloudFormation StackSets allow you to deploy a single template across multiple AWS accounts and regions in one operation, using either self-managed permissions or AWS Organizations integration. This is the designed feature for organization-wide resource deployment like VPCs and IAM roles. StackSets handle the orchestration, rollback, and drift detection across all target accounts.

Exam trap

CV0-004 often tests the confusion between nested stacks (modularization within one account) and StackSets (multi-account/multi-region deployment), so candidates who see 'common set of resources' and pick nested stacks miss the multi-account requirement.

How to eliminate wrong answers

Option A is wrong because change sets only preview how a stack update will affect a single existing stack; they do not deploy across accounts. Option B is wrong because nested stacks are used to modularize a single stack into reusable child stacks within one account, not to deploy across multiple accounts. Option D is wrong because drift detection identifies configuration differences between the template and actual resources; it does not deploy resources.

89
MCQhard

A cloud architect is designing a multi-account AWS environment and wants to deploy CloudFormation stacks consistently across many accounts. The architect needs a solution that can manage stack instances across multiple accounts and Regions from a single administrator account. Which AWS feature should be used?

A.Stack sets
B.Drift detection
C.Nested stacks
D.Change sets
AnswerA

Stack sets allow a single administrator account to deploy and manage CloudFormation stacks across multiple target accounts and Regions, satisfying the requirement for centralised, consistent multi-account deployment. The specific mechanism is the stack set’s ability to define a template and parameters once, then automatically create and update stack instances in specified accounts and Regions, handling permissions via service-linked roles.

Why this answer

AWS CloudFormation StackSets allow you to deploy stacks across multiple accounts and Regions from a single administrator account. They are designed for consistent, scalable deployments, enabling you to create, update, or delete stacks in many accounts simultaneously using a single CloudFormation template and set of parameters.

Exam trap

CV0-004 often tests the confusion between StackSets and nested stacks; candidates might think nested stacks can span accounts, but they are limited to a single account and Region.

How to eliminate wrong answers

Option B is wrong because drift detection only identifies differences between the actual stack resources and the expected template, it does not deploy stacks. Option C is wrong because nested stacks are used to modularize a single stack by referencing other stacks as resources, but they do not span multiple accounts or Regions. Option D is wrong because change sets preview how changes will affect running resources, but they do not facilitate multi-account deployment.

90
MCQmedium

A cloud engineer is deploying a new version of an application to an Amazon ECS cluster using the rolling update deployment type. The engineer wants to ensure that the new version is deployed without downtime and that the old tasks are terminated only after the new tasks are healthy. Which parameter should the engineer configure?

A.Set the task placement strategy to spread across Availability Zones.
B.Set the minimum healthy percent to 100 and the maximum percent to 200.
C.Set the deployment circuit breaker to enabled with rollback.
D.Set the minimum healthy percent to 50 and the maximum percent to 100.
AnswerB

With a minimum healthy percent of 100, ECS ensures that the number of running tasks never drops below the desired count during deployment. The maximum percent of 200 allows ECS to launch additional tasks beyond the desired count, enabling new tasks to start and become healthy before old ones are stopped. This achieves zero-downtime deployment.

Why this answer

For a rolling update on Amazon ECS, the deployment configuration's minimum healthy percent and maximum percent control how many tasks must remain running and how many extra tasks can be launched. Setting minimum healthy percent to 100 and maximum percent to 200 ensures that the desired number of tasks is always running while allowing new tasks to start and become healthy before old tasks are terminated, thus achieving zero downtime.

Exam trap

The trap here is confusing the deployment circuit breaker with the parameters that control the rolling update strategy; the circuit breaker only handles rollbacks on failure.

91
MCQhard

A cloud engineer is designing a CI/CD pipeline using Azure DevOps. They need to ensure that code changes are automatically built, tested, and deployed to a staging environment, and then after manual approval, deployed to production. Which pipeline configuration should they use?

A.Multi-stage pipeline with environment approvals on the production stage
B.Single stage pipeline with conditional deployment
C.Release pipeline with continuous deployment trigger
D.Build pipeline only
AnswerA

A multi-stage pipeline separates build, test, staging and production into discrete stages, and environment approvals gate the production stage so deployment waits for manual sign-off. This satisfies both the automated staging deployment and the approval-before-production constraint.

Why this answer

Azure DevOps multi-stage pipelines allow defining stages such as build, test, and deploy, with gates and approvals. An approval gate on the production stage ensures manual review before deployment.

92
MCQhard

A cloud engineer is deploying a stateful application on Amazon EKS. The application requires persistent storage that must be highly available and automatically replicated across multiple Availability Zones. The engineer needs to define the storage class in Kubernetes. Which storage class provisioner should be used?

A.fsx.csi.aws.com with Lustre
B.efs.csi.aws.com
C.ebs.csi.aws.com with volume type io1
D.local.csi.aws.com
AnswerB

Amazon EFS is a managed file system that provides shared, elastic storage across multiple Availability Zones. The EFS CSI driver allows Kubernetes to dynamically provision persistent volumes backed by EFS, which is automatically replicated across AZs within a region. This makes it ideal for stateful applications requiring high availability and multi-AZ resilience.

Why this answer

Amazon EFS, accessed via the EFS CSI driver, is the correct choice for persistent storage that is automatically replicated across multiple Availability Zones. It provides a shared file system that can be mounted by multiple pods across AZs, ensuring high availability. Other options either are single-AZ, not replicated, or ephemeral.

Exam trap

The trap here is assuming that high-performance block storage like EBS or FSx automatically provides multi-AZ replication, when in fact they are typically tied to a single AZ unless configured otherwise.

93
MCQmedium

A company is migrating an on-premises MySQL database to Azure SQL Database using Azure Database Migration Service. They want minimal downtime. Which migration mode should they choose?

A.Bulk copy
B.Offline migration
C.Online migration with continuous sync
D.Schema conversion only
AnswerC

Online migration with continuous sync keeps the source MySQL database available whilst replicating ongoing changes to Azure SQL Database, then performs a brief cutover. This directly satisfies the minimal-downtime constraint, unlike offline migration, which requires the source to be taken offline for the entire data copy.

Why this answer

Azure DMS offers online migration mode that uses CDC to replicate ongoing changes, allowing near-zero downtime. Offline mode requires stopping writes during migration.

94
MCQeasy

An organization wants to deploy a new application with zero downtime by switching traffic between two identical production environments. Which deployment strategy should be used?

A.Rolling deployment
B.Canary deployment
C.In-place deployment
D.Blue/green deployment
AnswerD

Blue/green deployment maintains two identical production environments and switches traffic at the load balancer or DNS layer once the new version is verified. Because cutover is atomic and rollback is immediate, users experience no downtime during release.

Why this answer

Blue/green deployment maintains two identical production environments (blue and green) and switches traffic from one to the other, typically via a load balancer or DNS cutover. This provides near-zero downtime and instant rollback by simply redirecting traffic back to the previous environment if issues arise.

Exam trap

CV0-004 often tests the confusion between blue/green and canary — candidates pick canary because both reduce risk, but only blue/green provides an instant full cutover and rollback via environment switching.

How to eliminate wrong answers

Option A is wrong because rolling deployment replaces instances incrementally within the same environment, which can cause version skew and does not provide an instant rollback path. Option B is wrong because canary deployment routes a small percentage of traffic to the new version for validation, which is gradual rather than a full cutover and does not guarantee zero downtime during the ramp. Option C is wrong because in-place deployment updates the existing environment directly, causing downtime and offering no easy rollback.

95
MCQeasy

A cloud engineer is deploying a new application on AWS and needs to ensure that the application's environment variables are securely stored and not exposed in the source code or CloudFormation templates. Which AWS service should be used to store and retrieve these secrets?

A.AWS Systems Manager Parameter Store (String type)
B.AWS Secrets Manager
C.AWS CloudFormation parameters with the NoEcho attribute
D.Amazon S3 bucket with default encryption
AnswerB

AWS Secrets Manager is designed to securely store and manage secrets such as database credentials, API keys, and environment variables. It provides encryption at rest using KMS, automatic rotation, and fine-grained access control via IAM. Applications can retrieve secrets at runtime using the AWS SDK, keeping them out of source code and templates, which meets the requirement.

Why this answer

AWS Secrets Manager is the appropriate service for securely storing and retrieving secrets like environment variables. It encrypts secrets at rest, supports automatic rotation, and integrates with IAM for access control. Other options either store plaintext, only mask values, or lack secret management features, making them unsuitable for secure secret storage.

Exam trap

The trap here is thinking that CloudFormation NoEcho or Parameter Store String type provides secure secret storage, when they either only hide values or store them unencrypted.

96
MCQhard

A company is deploying a containerized application on Amazon EKS. The security team requires that the application pods use an IAM role to access AWS services without storing credentials in the container images or environment variables. Which approach should the team use?

A.Use the AWS SDK for Java with a custom credential provider that reads from the pod's environment variables.
B.Attach an IAM role to the EC2 worker nodes and rely on the instance metadata service for pod credentials.
C.Create a Kubernetes service account and associate it with an IAM role using IAM Roles for Service Accounts (IRSA).
D.Store AWS credentials in a Kubernetes secret and mount it as a volume in the pod.
AnswerC

IAM Roles for Service Accounts (IRSA) allows Kubernetes pods to assume an IAM role via a service account. The EKS cluster's OIDC provider is used to federate the service account to IAM, and the pod receives temporary credentials through a projected service account token. This eliminates the need to store credentials in images or environment variables, meeting the security requirement.

Why this answer

IAM Roles for Service Accounts (IRSA) is the AWS-recommended method to grant AWS permissions to individual pods in an EKS cluster. By associating a Kubernetes service account with an IAM role, the pod can obtain temporary credentials via the cluster's OIDC provider. This approach adheres to least privilege and eliminates the need to store or manage long-term credentials in images or environment variables.

Exam trap

The trap here is assuming that node-level IAM roles or Kubernetes secrets are sufficient, but they either grant excessive permissions or still involve stored credentials.

97
MCQeasy

A company uses AWS CloudFormation to manage its infrastructure. After updating a stack, a developer notices that the actual infrastructure differs from the expected template. Which CloudFormation feature should be used to identify these differences?

A.Drift detection
B.Stack sets
C.Change sets
D.Rollback triggers
AnswerA

Drift detection compares the actual deployed resource configuration against the expected stack template and reports any divergence. It directly identifies where live infrastructure no longer matches the template, satisfying the developer's need to locate differences after the update.

Why this answer

Drift detection allows you to detect whether a stack's actual configuration differs from its expected template configuration.

98
Multi-Selecthard

A company manages a multi-account AWS environment and wants to deploy consistent infrastructure across several accounts using CloudFormation. The solution must support updates to the infrastructure and detect configuration drift. Which TWO CloudFormation features should be used?

Select 2 answers
A.Change sets
B.StackSets
C.Outputs
D.Nested stacks
E.Drift detection
AnswersB, E

StackSets deploy a single CloudFormation template across multiple AWS accounts and Regions from one administrator account, satisfying the multi-account consistency requirement. They also support update operations and drift detection on each stack instance, so infrastructure changes propagate and configuration drift is identified per account.

Why this answer

StackSets (B) is correct because it is the CloudFormation feature designed to deploy and update the same template across multiple AWS accounts and Regions from a single administrator account, which directly satisfies the requirement for consistent infrastructure across several accounts. Drift detection (E) is correct because it lets CloudFormation compare a stack's actual resource configuration against its expected template configuration and report resources that have been modified outside CloudFormation, satisfying the drift-detection requirement. Change sets (A) only preview how proposed changes would affect a single stack before execution, so they do not provide multi-account deployment or drift detection.

Outputs (C) merely export values from a stack for cross-stack references and do not deploy or monitor infrastructure. Nested stacks (D) help organize reusable templates within a single account/stack hierarchy but do not natively roll out stacks across multiple accounts or detect drift.

99
MCQhard

An engineer is deploying a Kubernetes application on EKS and needs to ensure that pods are only considered healthy after a startup delay, and that traffic stops to unhealthy pods. Which two probe types should be configured in the deployment manifest?

A.Startup probe and readiness probe
B.Liveness probe and startup probe
C.Only readiness probe
D.Readiness probe and liveness probe
AnswerA

A startup probe suppresses liveness and readiness checks until the container initialises, preventing premature restarts, while the readiness probe removes the pod from Service endpoints when unhealthy. Together they satisfy both the startup-delay and traffic-stopping requirements.

Why this answer

Startup probes delay health checks until the pod has had time to initialize, which satisfies the startup delay requirement. Readiness probes control when the pod receives traffic, stopping traffic to unhealthy pods. Together, they meet both needs.

Liveness probes restart unhealthy pods but do not handle startup delay or traffic routing.

Exam trap

Candidates often confuse startup probes with liveness probes. Startup probes defer other probes until initialization completes, while liveness probes restart pods that become unresponsive after startup.

100
MCQeasy

A cloud engineer is writing a Terraform configuration to deploy an AWS EC2 instance. Which file extension is typically used for Terraform configuration files written in HCL?

A..yaml
B..tf
C..json
D..hcl
AnswerB

HCL configuration files that Terraform loads from a working directory use the .tf extension, holding resource, variable and provider blocks. Terraform also reads .tf.json for JSON syntax and .tfvars for variable values, but .tf is the standard for HCL-authored configuration, satisfying the scenario's requirement.

Why this answer

Terraform configuration files written in HCL (HashiCorp Configuration Language) typically use the .tf file extension. This is the standard convention for Terraform modules and configurations, and Terraform automatically loads files with this extension. Other extensions like .tf.json are used for JSON-based configurations, but .tf is the primary one for HCL.

Exam trap

CV0-004 often tests the distinction between .tf and .hcl; candidates may think .hcl is the Terraform extension, but Terraform uses .tf for HCL configurations.

How to eliminate wrong answers

Option A is wrong because .yaml is used for YAML configuration files, not for Terraform HCL; Terraform does not natively parse YAML for configuration. Option C is wrong because .json is used for JSON-based Terraform configurations (with .tf.json extension), but the question specifies HCL, which uses .tf. Option D is wrong because .hcl is a generic extension for HCL files, but Terraform specifically uses .tf for its configuration files; .hcl is not the typical extension for Terraform.

101
MCQhard

A DevOps engineer is deploying a containerized application to Amazon ECS using the Fargate launch type. The application must be highly available across multiple Availability Zones and automatically scale based on CPU utilization. The engineer has already created a task definition and an Application Load Balancer. Which additional configuration is required to meet these requirements?

A.Create an ECS service with a desired count of at least two, spread across multiple subnets in different Availability Zones, and configure a target tracking scaling policy.
B.Create an ECS service with a placement constraint to spread tasks evenly across instances and enable service auto scaling based on memory.
C.Configure the task definition to use the EC2 launch type and place instances in an Auto Scaling group across multiple AZs.
D.Deploy the tasks as a standalone task using the RunTask API and enable CloudWatch alarms to trigger Lambda functions for scaling.
AnswerA

An ECS service with a desired count of two or more and tasks spread across multiple subnets in different AZs ensures high availability. A target tracking scaling policy based on CPU utilization automatically adjusts the number of tasks. This combination meets both the high availability and auto-scaling requirements.

Why this answer

To achieve high availability and auto-scaling with Fargate, you need an ECS service that runs multiple tasks across AZs and a target tracking scaling policy. The service ensures tasks are rescheduled if they fail, and the scaling policy adjusts capacity based on CPU. The other options either use the wrong launch type or lack native service management.

Exam trap

The trap here is assuming that Fargate tasks can be spread using placement constraints or that standalone tasks can auto-scale without a service.

102
Multi-Selectmedium

A cloud architect is designing a deployment for a multi-tier application on AWS. The application consists of a web tier, an application tier, and a database tier. The architect needs to ensure that the deployment is highly available and can survive an Availability Zone failure. Which two configurations should be included in the design? (Choose two.)

Select 2 answers
A.Configure the database tier with a Multi-AZ deployment using Amazon RDS.
B.Deploy the web and application tiers across multiple Availability Zones using an Auto Scaling group.
C.Place all tiers in a single Availability Zone to minimize latency.
D.Use a single NAT gateway for all private subnets to reduce cost.
E.Use an Application Load Balancer to distribute traffic only within a single Availability Zone.
AnswersA, B

Amazon RDS Multi-AZ deployments create a standby replica in a different Availability Zone and automatically fail over to it in case of an AZ failure. This ensures database availability and durability. It is a key component for a highly available multi-tier application, as it eliminates the database as a single point of failure.

Why this answer

To achieve high availability and survive an Availability Zone failure, the web and application tiers should be deployed across multiple AZs using an Auto Scaling group, and the database tier should use a Multi-AZ deployment such as Amazon RDS Multi-AZ. These two configurations ensure that no single AZ failure takes down the entire application. The Auto Scaling group maintains capacity, and the Multi-AZ database provides automatic failover.

Exam trap

The trap here is assuming that a single NAT gateway or a single Availability Zone deployment is sufficient for high availability, when in fact they introduce single points of failure.

103
MCQmedium

A company is migrating 100 TB of data from an on-premises NAS to Amazon S3. The network bandwidth is limited to 100 Mbps, and the transfer must complete within 30 days. Which service should the company use to meet the deadline?

A.AWS DataSync
B.Amazon S3 Transfer Acceleration
C.AWS Snowball
D.AWS Direct Connect
AnswerC

At 100 Mbps, transferring 100 TB would take roughly 100 days, far exceeding the 30-day deadline. AWS Snowball ships data physically on a rugged appliance, bypassing the bandwidth constraint entirely, so the migration completes within the required window.

Why this answer

AWS Snowball is the correct choice because transferring 100 TB over a 100 Mbps link would take far longer than 30 days. At 100 Mbps, the theoretical maximum is about 12.5 MB/s, which over 30 days yields roughly 32 TB, well short of 100 TB. Snowball uses physical devices to ship data, bypassing network bandwidth limitations and meeting the deadline.

Exam trap

CV0-004 often tests the calculation of transfer time versus bandwidth, so candidates who pick DataSync or Direct Connect overlook that the 100 Mbps limit makes network transfer infeasible within the deadline.

How to eliminate wrong answers

Option A is wrong because AWS DataSync transfers data over the network and is subject to the same 100 Mbps bandwidth constraint, making it unable to complete 100 TB in 30 days. Option B is wrong because S3 Transfer Acceleration speeds up transfers over the internet using edge locations, but it cannot overcome a 100 Mbps origin uplink limitation. Option D is wrong because AWS Direct Connect provides a dedicated network connection but still requires sufficient bandwidth; a 100 Mbps Direct Connect link would have the same throughput limitation and would take too long to provision for a 30-day deadline.

104
MCQeasy

A cloud engineer is using Ansible to automate cloud resource provisioning. Which statement about Ansible is true?

A.Ansible uses JSON for configuration management.
B.Ansible requires an agent to be installed on each managed node.
C.Ansible uses YAML for playbook definitions.
D.Ansible is a cloud-only tool that cannot manage on-premises servers.
AnswerC

Ansible playbooks are written in YAML, a human-readable data serialisation format, and executed over SSH without agents on managed nodes. This is the factual property distinguishing Ansible from agent-based configuration tools that use other definition languages.

Why this answer

Ansible playbooks are written in YAML, a human-readable data serialization format that defines plays, tasks, modules, and variables. This YAML-based syntax is a defining characteristic of Ansible and is why it is popular for configuration management and orchestration.

Exam trap

CV0-004 often tests the misconception that Ansible requires agents or uses JSON, when in fact it is agentless and YAML-based — a common point of confusion with other configuration management tools.

How to eliminate wrong answers

Option A is wrong because Ansible uses YAML, not JSON, for playbook and configuration definitions (though JSON can be used for some data structures, it is not the primary format). Option B is wrong because Ansible is agentless; it connects to managed nodes over SSH (Linux) or WinRM (Windows) without requiring an agent installation. Option D is wrong because Ansible is not cloud-only; it can manage on-premises servers, network devices, and hybrid environments equally well.

105
MCQmedium

A cloud administrator is writing an Ansible playbook to provision cloud resources. The administrator wants to ensure that the playbook can run without requiring any agent software on the target machines. Which Ansible feature enables this agentless operation?

A.Ansible inventory files that list hosts
B.Ansible modules that run on the control node
C.SSH-based connection to managed nodes
D.Pull mode from a central repository
AnswerC

Ansible connects over SSH and pushes Python modules to managed nodes, executing them remotely without installing a persistent agent. This satisfies the agentless requirement, unlike pull-based configuration tools that mandate agent software on every target machine.

Why this answer

Ansible is agentless by design and connects to managed nodes over standard SSH (or WinRM for Windows). This means no Ansible agent or daemon needs to be installed on target machines — the control node pushes modules over SSH, executes them, and removes them. SSH-based connection is the foundational mechanism that enables this agentless architecture.

Exam trap

CV0-004 often tests the misconception that Ansible requires an agent or that modules run on the control node — candidates must remember that Ansible pushes modules over SSH and executes them on the managed node.

How to eliminate wrong answers

Option A is wrong because inventory files simply list and group managed hosts — they define targets but do not enable agentless operation. Option B is wrong because Ansible modules are pushed to and executed on the managed node (not the control node); stating they run on the control node misrepresents how Ansible works. Option D is wrong because pull mode (ansible-pull) is a less common alternative where nodes pull playbooks from a repository, but it still relies on SSH or local execution and is not the feature that enables agentless operation.

106
MCQmedium

A DevOps team uses Jenkins for CI/CD. They want to automatically deploy containerized applications to a Kubernetes cluster. Which Jenkins feature or plugin can integrate with Kubernetes to manage deployments?

A.Jenkins Declarative Pipeline
B.Jenkins Blue Ocean
C.Jenkins Multibranch Pipeline
D.Kubernetes plugin
AnswerD

The Kubernetes plugin provisions dynamic Jenkins agents as pods in the cluster and executes build steps within them, enabling containerised deployments to be orchestrated directly against Kubernetes. It satisfies the requirement to integrate Jenkins pipelines with cluster-managed deployment workloads.

Why this answer

The Kubernetes plugin for Jenkins allows Jenkins agents to be dynamically provisioned as pods within a Kubernetes cluster, enabling automated deployment of containerized applications. It integrates directly with the Kubernetes API to manage deployments, services, and other resources, making it the correct choice for this scenario.

Exam trap

The CompTIA Cloud+ exam often tests the distinction between Jenkins features that define pipeline logic (like Declarative Pipeline) and plugins that provide external integrations (like the Kubernetes plugin), leading candidates to confuse syntax with integration capabilities.

How to eliminate wrong answers

Option A is wrong because Jenkins Declarative Pipeline is a syntax for defining CI/CD pipelines, not a plugin that integrates with Kubernetes for deployment management. Option B is wrong because Jenkins Blue Ocean is a user interface redesign for Jenkins, providing a modern UI but no native Kubernetes integration or deployment capabilities. Option C is wrong because Jenkins Multibranch Pipeline is a feature that automatically creates pipelines for multiple branches in a repository, but it does not provide Kubernetes-specific deployment integration.

107
MCQeasy

A cloud engineer is designing a deployment strategy for a web application that requires zero downtime. The engineer has set up two identical production environments, one active and one idle. After deploying the new version to the idle environment, the engineer switches the DNS record to point to the idle environment. This deployment method is known as:

A.Blue/green deployment
B.Rolling deployment
C.A/B testing deployment
D.Canary deployment
AnswerA

Blue/green deployment maintains two identical environments, routing traffic via DNS cutover from the active (blue) to the idle (green) once the new version is verified. This satisfies the zero-downtime constraint, since the switch is near-instantaneous and rollback simply reverts DNS to the original environment.

Why this answer

Blue/green deployment maintains two identical environments: one live (blue) and one idle (green). After deploying the new version to the idle environment and testing it, traffic is switched from the active to the idle environment, typically via DNS or a load balancer. This provides zero downtime and instant rollback because the previous environment remains intact until the switch is validated.

Exam trap

CV0-004 often tests the distinction between deployment strategies that provide zero downtime versus those that reduce risk; candidates confuse blue/green with canary or rolling because all aim to minimize downtime, but only blue/green uses two identical environments with an atomic traffic switch.

How to eliminate wrong answers

Option B is wrong because rolling deployment updates instances in batches within the same environment, so both old and new versions run simultaneously during the rollout, which can cause compatibility issues and does not provide an instant, atomic cutover. Option C is wrong because A/B testing deployment routes a subset of users to a different version to compare behavior or metrics, not to achieve zero-downtime release of a single new version. Option D is wrong because canary deployment gradually shifts a small percentage of traffic to the new version while the majority still uses the old version, requiring monitoring and progressive rollout rather than an immediate full switch.

108
Multi-Selectmedium

A cloud architect is designing a Kubernetes deployment for a stateless web application. The application must be highly available and automatically recover from failures. Which THREE components are required to achieve this? (Select 3)

Select 3 answers
A.ConfigMap
B.Deployment resource
C.Service resource
D.StatefulSet
E.Readiness probe
AnswersB, C, E

A Deployment manages a ReplicaSet, maintaining the desired pod count and recreating failed pods automatically. This reconciliation loop delivers the self-healing, highly available behaviour the stem demands for the stateless web application across node or pod failures.

Why this answer

A Deployment manages replicas and supports rolling updates. A Service provides stable networking to the pods. Readiness probes ensure only healthy pods receive traffic.

ConfigMaps and StatefulSets are not required for stateless HA.

109
MCQhard

A DevOps team is implementing a canary deployment for a microservice running on Amazon ECS. They want to gradually shift 10% of traffic to the new version and automatically roll back if error rates exceed 1% in 5 minutes. Which combination of services should they use?

A.AWS CloudFormation and SSM
B.AWS Lambda and Step Functions
C.AWS CodeDeploy with CloudWatch alarms
D.AWS Elastic Beanstalk and Route 53
AnswerC

CodeDeploy natively supports ECS canary and linear traffic shifting, and its deployment configuration can reference CloudWatch alarms to trigger automatic rollback. This directly satisfies the 10% gradual shift and the 1%-error-rate/5-minute rollback constraint without custom scripting.

Why this answer

AWS CodeDeploy natively supports canary deployments for Amazon ECS, allowing you to specify a traffic shift percentage (e.g., 10%) and integrate with CloudWatch alarms to automatically trigger a rollback when error rates exceed a defined threshold (e.g., 1% over 5 minutes). This combination directly fulfills the gradual traffic shifting and automated rollback requirements without custom scripting.

Exam trap

A common mistake is assuming that any orchestration service (like Step Functions) is equivalent to a native deployment service, but the key is that CodeDeploy provides built-in traffic shifting and alarm-based rollback without custom code, which is exactly the requirement in the question.

How to eliminate wrong answers

Option A is wrong because AWS CloudFormation and SSM are infrastructure provisioning and management tools; they do not provide built-in traffic shifting or automated rollback based on error rate thresholds for ECS deployments. Option B is wrong because AWS Lambda and Step Functions can orchestrate custom deployment logic but require significant custom code to implement traffic shifting and alarm-based rollback, whereas CodeDeploy offers this natively. Option D is wrong because AWS Elastic Beanstalk is a PaaS service that does not support canary deployments for ECS microservices, and Route 53 is a DNS service that cannot shift traffic at the application load balancer level for ECS tasks.

110
MCQeasy

A cloud engineer is managing infrastructure as code using Terraform. Which command should be run to preview changes before applying them to the cloud environment?

A.terraform apply
B.terraform destroy
C.terraform plan
D.terraform init
AnswerC

`terraform plan` performs a dry run that refreshes state and computes the execution plan, showing exactly which resources will be created, modified or destroyed without touching the cloud environment. This satisfies the stem's requirement to preview changes before applying them, unlike `terraform apply`, which executes them.

Why this answer

The terraform plan command creates an execution plan, showing what actions Terraform will take to change the infrastructure. It is used as a dry run before applying changes.

111
MCQmedium

A DevOps team is deploying a containerized application to Google Kubernetes Engine (GKE). The team wants to automate the deployment of the application along with its dependencies, such as ConfigMaps and Services, using a single package. Which tool should the team use?

A.Helm charts
B.kubectl apply with multiple manifest files
C.Kustomize overlays
D.Docker Compose
AnswerA

Helm charts package Kubernetes manifests into one versioned, parameterised release, bundling Deployments with ConfigMaps and Services so a single `helm install` deploys the application and its dependencies together. This directly satisfies the stem's requirement for one package automating GKE deployment of the app plus its dependencies.

Why this answer

Helm is the de facto package manager for Kubernetes and bundles all related manifests — Deployments, Services, ConfigMaps, Secrets, Ingress — into a single versioned chart that can be installed, upgraded, and rolled back with one command. This directly matches the requirement to deploy an application and its dependencies as a single package. Helm also supports templating and values files for environment-specific configuration.

Exam trap

CV0-004 often tests the distinction between packaging/lifecycle tools (Helm) and customization tools (Kustomize) or raw kubectl, so candidates who pick Kustomize miss that it does not provide single-package install with versioned releases.

How to eliminate wrong answers

Option B is wrong because kubectl apply with multiple manifests is imperative, has no packaging, versioning, or rollback semantics, and requires manually tracking which files belong together. Option C is wrong because Kustomize overlays customize existing manifests for different environments but do not package an application with dependencies into a single installable unit with lifecycle management. Option D is wrong because Docker Compose is a local development tool for Docker, not a GKE/Kubernetes packaging mechanism, and does not deploy native Kubernetes resources.

112
MCQeasy

A cloud engineer is writing Terraform code to provision AWS resources. They need to define the cloud provider and authentication details. Which block should they use in their HCL configuration?

A.resource block
B.provider block
C.variable block
D.module block
AnswerB

The provider block declares the cloud platform, such as AWS, and supplies authentication details like access keys or region, so Terraform knows which API to call and how to authenticate. Resource blocks then reference that configured provider when provisioning.

Why this answer

In HashiCorp Configuration Language (HCL), the provider block declares which cloud provider Terraform should use (e.g., aws, azure, google) and supplies the configuration needed to authenticate and target the correct region or account. For AWS, this includes region, access keys, or references to credential profiles/roles. Without a provider block, Terraform cannot know which API to call or how to authenticate.

Exam trap

The trap is conflating the block that defines infrastructure (resource) with the block that defines how Terraform authenticates and connects (provider); candidates who focus on 'provisioning AWS resources' may wrongly select the resource block.

How to eliminate wrong answers

Option A is wrong because a resource block defines a specific infrastructure object to create or manage (e.g., aws_instance, aws_s3_bucket); it consumes the provider configuration but does not define it. Option C is wrong because a variable block declares input parameters that make configurations reusable and parameterized — it does not configure provider authentication. Option D is wrong because a module block calls a reusable collection of Terraform configurations; it packages resources but does not itself define provider credentials or endpoints.

113
MCQeasy

A cloud architect is designing a serverless application using Azure Functions. The function must process messages from an Azure Storage Queue. How should the architect configure the trigger?

A.Blob trigger
B.Event Grid trigger
C.Queue trigger
D.HTTP trigger with queue polling
AnswerC

A queue trigger binds the function to an Azure Storage Queue, so the Functions runtime polls the queue and invokes the function whenever a message arrives. This is the native mechanism for queue-driven, serverless message processing without manual polling code.

Why this answer

Azure Functions natively supports a Queue trigger that automatically polls an Azure Storage Queue for new messages and executes the function code when a message is detected. This is the simplest and most efficient way to process messages from a Storage Queue without custom polling logic.

Exam trap

CompTIA Cloud+ candidates often mistakenly choose Event Grid because it is event-driven, but it does not directly integrate with Storage Queues without custom event subscriptions.

How to eliminate wrong answers

Option A is wrong because a Blob trigger is designed to respond to blob storage events (e.g., new or updated blobs), not queue messages. Option B is wrong because an Event Grid trigger handles events from Azure Event Grid, which is a separate event routing service, not a direct queue message source. Option D is wrong because an HTTP trigger with queue polling would require custom code to poll the queue, which defeats the purpose of using a built-in trigger and adds unnecessary complexity.

114
MCQmedium

A cloud architect is deploying a serverless application using AWS Lambda. The application must process messages from an Amazon SQS queue. The messages are expected to be processed in order, and the application must handle failures without losing messages. Which configuration should be used?

A.Use Amazon Kinesis Data Streams as the event source and configure the Lambda function to process records in batches.
B.Configure the Lambda function with an SQS trigger and set the batch size to 10, and enable a dead-letter queue for the source queue.
C.Create an SNS topic and subscribe the Lambda function to it, then publish messages to the topic.
D.Use an SQS FIFO queue as the event source for the Lambda function and configure a dead-letter queue for the source queue.
AnswerD

SQS FIFO queues provide strict message ordering and exactly-once processing. Configuring a dead-letter queue for the source queue ensures that messages that fail processing are moved to a DLQ after a specified number of attempts, preventing message loss. This meets both the ordering and failure handling requirements.

Why this answer

SQS FIFO queues guarantee message order and support dead-letter queues for failed messages. Using a FIFO queue as the Lambda event source ensures ordered processing, and the DLQ captures messages that cannot be processed, preventing loss. The other options either lack ordering guarantees or use the wrong service.

Exam trap

The trap here is assuming that standard SQS queues preserve order or that SNS can provide durable, ordered delivery.

115
MCQhard

An organization uses Azure DevOps for CI/CD. They want to implement a deployment strategy where a new version of an application is deployed to a small subset of users (e.g., 5%) and if no errors are detected, the percentage is gradually increased to 100%. Which deployment strategy should they use?

A.Rolling
B.Recreate
C.Canary
D.Blue/green
AnswerC

Canary releases route a small percentage of live traffic to the new version, then incrementally shift the remainder once health checks pass. This satisfies the gradual 5%-to-100% rollout with error detection that Azure DevOps pipelines can automate.

Why this answer

Canary deployment routes a small percentage of live traffic (e.g., 5%) to the new version while the majority still hits the stable version, then gradually shifts traffic as health metrics remain clean. Azure DevOps supports this natively via deployment rings, traffic-splitting in App Service/Container Apps, or feature flags. The gradual, metric-gated traffic shift is the defining characteristic of canary.

Exam trap

CV0-004 often tests the confusion between canary (percentage-based gradual traffic shift to a subset of users) and blue/green (two full environments with an all-at-once cutover) — candidates pick blue/green because both involve two versions running simultaneously.

How to eliminate wrong answers

Option A is wrong because rolling deployment replaces instances in batches across the entire fleet with no traffic-percentage control or user subsetting — all users eventually hit the new version as instances cycle. Option B is wrong because recreate tears down the old version entirely before bringing up the new one, causing downtime and offering no gradual exposure. Option D is wrong because blue/green runs two full parallel environments and flips 100% of traffic at once (or via a single cutover), not a gradual percentage ramp.

116
MCQmedium

A DevOps team uses CloudFormation to manage multi-account infrastructure. They need to deploy a common set of resources across multiple AWS accounts in an organization. Which CloudFormation feature should they use?

A.Nested stacks
B.Drift detection
C.Stack sets
D.Change sets
AnswerC

Stack sets let a single CloudFormation template deploy identical resources across many AWS accounts and regions from one administrator account. This satisfies the stem's requirement for consistent multi-account deployment, unlike ordinary stacks, which are scoped to a single account.

Why this answer

CloudFormation StackSets allow a single template to be deployed across multiple AWS accounts and regions from a central administrator account, which is exactly what the DevOps team needs for multi-account infrastructure. StackSets support automatic deployment to new accounts as they join the organization and can use service-managed permissions for Organizations integration. This makes it the correct feature for cross-account, multi-region rollouts.

Exam trap

The trap is confusing nested stacks (intra-account template composition) with StackSets (cross-account/cross-region deployment) — both involve 'stacks' but solve entirely different problems.

How to eliminate wrong answers

Option A is wrong because nested stacks are used to decompose a large template into reusable child stacks within a single account and region — they do not span accounts. Option B is wrong because drift detection identifies when actual resource configuration differs from the template, which is a monitoring capability, not a deployment mechanism. Option D is wrong because change sets preview how proposed template changes will affect existing resources before execution, but they operate within a single stack and do not deploy across accounts.

← PreviousPage 2 of 2 · 116 questions total

Ready to test yourself?

Try a timed practice session using only Clp Deployment questions.