CompTIA Cloud Essentials+ (CLO-002) practice questions
202 free questions with answers and explanations.
- 1.A retail chain migrated its inventory system to a cloud provider that uses heavily customized, proprietary APIs and a unique data format not supported by any other vendor. Two years later, the company finds it cannot feasibly switch providers without a costly rebuild. To prevent this in future projects, the IT director mandates that all new cloud deployments use containerized applications built on open-source orchestration platforms. What risk is this policy primarily intended to mitigate?Governance, Risk, Compliance and Security
- 2.A financial services company is planning a cloud migration for its highly regulated customer data. They currently have robust on-premises security controls and compliance frameworks. The company wants to extend its existing security policies and governance across its cloud resources while maintaining direct control over the underlying infrastructure for specific sensitive applications. Which cloud deployment model would best align with these requirements?Business Principles of Cloud Environments
- 3.A financial services company implements a policy requiring every dataset stored in its cloud environment to be labeled as Public, Internal, Confidential, or Restricted, with each label carrying specific handling and encryption requirements. A dataset containing customer Social Security numbers and account balances would most appropriately be labeled as which classification?Governance, Risk, Compliance and Security
- 4.A development team is implementing a Continuous Integration/Continuous Delivery (CI/CD) pipeline for a new cloud-native application. They want to ensure that every code change triggers an automated process that builds, tests, and deploys the application to a staging environment. Which component is primarily responsible for initiating these automated workflows upon code commits?Management and Technical Operations
- 5.A financial services company is evaluating cloud providers for a new application that will process sensitive customer transactions. Due to regulatory compliance requirements (e.g., GDPR, PCI DSS), they must maintain strict control over data residency and encryption keys, and ensure that their data never leaves a specific geographical region. Which cloud deployment model would give them the MOST control over these aspects?Management and Technical Operations
- 6.A company's HR system automatically notifies the IT department whenever an employee's status changes to 'terminated.' Upon receiving this notification, the cloud IAM administrator immediately disables the employee's cloud accounts and revokes all access tokens. Which stage of the identity lifecycle does this action represent?Governance, Risk, Compliance and Security
- 7.A cloud administrator is reviewing resource utilization metrics and notices that several virtual machines (VMs) are consistently operating at less than 20% CPU and memory utilization, even during peak hours. The goal is to reduce cloud spending without impacting application performance. Which cost optimization technique should be applied?Management and Technical Operations
- 8.A US-based cloud provider will host personal data for a company operating in the European Union, and no EU adequacy decision covers the United States. Which mechanism should the parties include in their contract to legally justify this cross-border transfer of personal data under GDPR?Governance, Risk, Compliance and Security
- 9.A cloud administrator is configuring a new cloud environment and needs to ensure that all virtual machines (VMs) deployed are automatically assigned appropriate cost center tags and security group rules based on their purpose (e.g., 'development', 'production', 'testing'). Which cloud management practice should be implemented to achieve this?Management and Technical Operations
- 10.A global manufacturing company with operations in multiple countries is evaluating a cloud provider for its new enterprise resource planning (ERP) system. The company requires consistent application performance and data residency compliance across its global offices. The cloud provider offers 'Regions' and 'Availability Zones'. To meet the global performance and compliance requirements, which strategy should the company prioritize when deploying its ERP system?Business Principles of Cloud Environments
- 11.A company has signed a Service Level Agreement (SLA) with its cloud provider for a critical database service. The SLA specifies a 99.95% uptime guarantee and a maximum response time of 100ms for read operations. During a recent incident, the database experienced 20 minutes of downtime in a 30-day month, and the average read response time increased to 150ms for a continuous period of 4 hours. Which of the following statements is true regarding the SLA violation?Business Principles of Cloud Environments
- 12.A cloud architect is designing a new application that needs to handle sudden, unpredictable spikes in user traffic without manual intervention. The application must automatically provision and de-provision resources based on demand. Which cloud characteristic is most relevant to this requirement?Cloud Concepts
- 13.A small startup is rapidly developing a new mobile application. They need an environment that provides pre-configured operating systems, databases, and development tools, allowing their developers to focus solely on writing code without managing the underlying infrastructure. Which cloud service model best fits their requirements?Cloud Concepts
- 14.A company is designing its cloud data backup strategy. They have critical application data that requires a Recovery Point Objective (RPO) of 1 hour and a Recovery Time Objective (RTO) of 4 hours. Which backup and recovery approach is most appropriate to meet these requirements?Management and Technical Operations
- 15.A retail company was previously locked into a single cloud provider due to heavy use of proprietary services, causing costly delays when it later needed to migrate. To avoid repeating this problem with a new deployment, the company designs its new application using containerized microservices, open APIs, and infrastructure-as-code templates that can run on multiple cloud platforms. Which strategy is the company pursuing?Governance, Risk, Compliance and Security
- 16.A cloud administrator is configuring a new cloud environment and needs to ensure that all virtual machines and storage buckets are consistently categorized for cost allocation and access control purposes. Which cloud management tool or practice should the administrator implement to meet this requirement most effectively?Management and Technical Operations
- 17.A cloud operations team is tasked with ensuring high availability for an application that processes real-time financial transactions. The application is deployed across multiple virtual machines in a single cloud region. To mitigate the risk of a single data center outage, they need to distribute these VMs across physically isolated locations within that region. Which concept describes these isolated locations?Management and Technical Operations
- 18.A cloud architect is designing a new cloud environment for a financial institution that will process highly sensitive customer data. The institution is subject to stringent regulatory requirements regarding data integrity and non-alteration. Which security principle should be a primary consideration to ensure that data, once recorded, cannot be changed or deleted without detection?Governance, Risk, Compliance and Security
- 19.A cloud security engineer is designing a new cloud environment and needs to implement a policy that automatically enforces specific security configurations across all newly provisioned virtual machines (VMs). This policy must ensure that certain ports are closed by default and a specific antivirus agent is installed. Which of the following approaches BEST meets this requirement?Management and Technical Operations
- 20.A cloud architect is designing a new application that will process sensitive customer data. The application requires highly available and scalable storage that can be accessed by multiple compute instances simultaneously. Data encryption at rest and in transit is a strict requirement. Which storage type is BEST suited for this scenario?Management and Technical Operations
- 21.A company is migrating its existing relational database to a cloud environment. The database requires low-latency access, consistent performance, and the ability to attach directly to virtual machines. Which cloud storage type is BEST suited for this requirement?Cloud Concepts
- 22.A company operating in a highly regulated industry stores sensitive customer data in the cloud. They need to understand who is primarily responsible for patching the guest operating system of their virtual machines and encrypting the data at rest within their application. According to the shared responsibility model, who is responsible for these tasks in an IaaS environment?Cloud Concepts
- 23.A cloud engineer needs to track the operational status, performance metrics, and resource utilization of several new virtual machines deployed in a public cloud. The engineer also wants to receive alerts when CPU utilization exceeds 80% for more than 5 minutes. Which cloud management function is primarily responsible for fulfilling these requirements?Management and Technical Operations
- 24.A cloud administrator is tasked with optimizing costs for a development environment that is only active during business hours (9 AM to 5 PM, Monday to Friday). The current setup involves always-on virtual machines (VMs). Which cost optimization strategy would provide the most immediate and significant savings for this specific scenario?Management and Technical Operations
- 25.A company subscribes to a SaaS-based customer relationship management (CRM) platform. Under the shared responsibility model, which of the following remains the customer's responsibility rather than the SaaS provider's?Governance, Risk, Compliance and Security
- 26.A multi-national corporation is planning to migrate its enterprise resource planning (ERP) system to a cloud environment. Due to strict data sovereignty laws and internal security policies, certain highly sensitive modules of the ERP must remain within the company's own data centers, while less sensitive modules can leverage public cloud resources. Which cloud deployment model best supports this requirement?Cloud Concepts
- 27.A small startup is evaluating different cloud service providers for its new application. They have a limited budget and want to avoid large upfront capital expenditures. Which of the following financial models is MOST aligned with their goal?Business Principles of Cloud Environments
- 28.A large enterprise is evaluating cloud migration and needs a comprehensive understanding of all direct and indirect costs associated with both their current on-premises infrastructure and potential cloud solutions over a multi-year period. Which financial analysis tool would provide the MOST complete picture for this comparison?Business Principles of Cloud Environments
- 29.A cloud customer is experiencing intermittent network performance issues when accessing their cloud-hosted applications. They suspect the problem lies with the path their traffic takes over the public internet, rather than within the cloud provider's internal network. Which networking solution would provide a dedicated, private connection to bypass the public internet and potentially resolve these issues?Cloud Concepts
- 30.A financial services firm's risk team estimates that a specific type of cloud service outage would cause $50,000 in losses each time it occurs, and historical data suggests this outage happens 3 times per year. What is the annualized loss expectancy (ALE) for this risk?Governance, Risk, Compliance and Security
- 31.A cloud administrator is configuring network access for a new application deployed in a Virtual Private Cloud (VPC). The application needs to communicate with an external third-party API over the public internet, but all outbound traffic from the application's subnet must first pass through a specific security appliance for inspection. Which VPC networking component should the administrator implement to enforce this traffic flow?Cloud Concepts
- 32.A financial institution is migrating its legacy applications to a cloud environment. During the initial assessment phase, they identify that some critical applications are highly dependent on specific hardware and operating system versions that are not supported by the target cloud provider. This situation primarily highlights a challenge in which aspect of cloud feasibility?Business Principles of Cloud Environments
- 33.A company is evaluating moving its critical enterprise resource planning (ERP) system to a public cloud. The ERP system has numerous custom integrations with other on-premises applications and requires significant modifications to function optimally in a cloud-native environment. Which migration approach would involve substantial re-architecture and code changes to leverage cloud services fully?Business Principles of Cloud Environments
- 34.A cloud customer is migrating a legacy monolithic application to the cloud. The application's database requires extremely high input/output operations per second (IOPS) and very low latency, as it processes millions of transactions per second. Which cloud storage type is BEST suited for this specific database requirement?Cloud Concepts
- 35.A company posts a visible notice at every cloud application login screen stating that all user activity is logged, monitored, and subject to disciplinary or legal action if misused. The primary purpose of this notice is to discourage employees from attempting unauthorized actions. Which type of security control does this notice represent?Governance, Risk, Compliance and Security
- 36.A cloud architect is designing a solution for a client's highly sensitive financial data application. The client requires complete isolation of their network traffic from all other tenants and demands direct, private connectivity from their on-premises data center to the cloud environment. Which cloud networking component should the architect implement?Business Principles of Cloud Environments
- 37.A global media company uses cloud services to host its video streaming platform. They experience unpredictable surges in viewer traffic during major live events. The cloud solution must automatically adjust computing resources up or down to handle these fluctuations without manual intervention. Which cloud characteristic is most critical for this requirement?Cloud Concepts
- 38.A cloud architect is designing a solution for an application that requires dedicated hardware isolation, complete control over the underlying infrastructure, and strict compliance with internal security policies. The application cannot be hosted on multi-tenant environments. Which cloud deployment model should the architect recommend?Cloud Concepts
- 39.A global conglomerate is migrating its enterprise resource planning (ERP) system to a multi-region public cloud deployment. The company operates in several countries, each with unique data residency and privacy laws. To ensure compliance while maintaining operational efficiency, the cloud architecture team must implement a solution that dynamically routes user requests to the nearest compliant data center based on the user's geographical location and the data's regulatory requirements. Which architectural component is crucial for achieving this goal?Governance, Risk, Compliance and Security
- 40.A cloud service provider's data center requires all visitors to pass through a mantrap, present government-issued ID, and be escorted by an authorized employee before reaching the server floor. Which category of security control does this represent?Governance, Risk, Compliance and Security
- 41.A retail company's PCI DSS assessment reveals that a legacy point-of-sale server cannot be patched to the latest firmware without breaking compatibility with critical hardware, and the vendor no longer supports updates. To remain compliant, the security team instead isolates the server on a dedicated segmented VLAN, restricts access to two authorized administrators, and enables enhanced logging and alerting on all traffic to and from it. Which type of security control is being implemented?Governance, Risk, Compliance and Security
- 42.A cloud security engineer is tasked with implementing a policy that restricts network access between different development environments (Dev, Test, Prod) within the same Virtual Private Cloud (VPC). Specifically, resources in the Dev environment should not be able to initiate connections to resources in the Production environment, but Test can connect to Dev. Which networking construct is most suitable for enforcing such granular network segmentation within a VPC?Management and Technical Operations
- 43.A global software company is expanding its operations and needs to deploy its applications in new geographic regions to reduce latency for local users and comply with regional data sovereignty laws. They are looking for a cloud provider that offers a wide distribution of data centers and services across the globe. Which characteristic of a cloud provider is most relevant to this requirement?Business Principles of Cloud Environments
- 44.A company's cloud-hosted web application transmits customer form submissions over the public internet to a backend database. To ensure this data cannot be intercepted and read by an attacker performing a man-in-the-middle attack during transmission, which encryption approach must be implemented?Governance, Risk, Compliance and Security
- 45.A financial services company is planning to migrate its highly regulated customer data platform to the cloud. Due to stringent compliance requirements and the need for maximum control over data sovereignty, the company decides to build and manage its own cloud infrastructure within its private data center. Which cloud deployment model is being adopted?Business Principles of Cloud Environments
- 46.A company is migrating a legacy application to the cloud. The application uses a monolithic architecture and requires a specific operating system and custom runtime libraries that are not readily available as managed services. The development team wants to retain full control over the operating system and application stack. Which cloud service model would be most appropriate for this migration?Management and Technical Operations
- 47.A company is considering migrating its entire IT infrastructure to a cloud provider. Before making a decision, they need to thoroughly understand the current state of their on-premises environment, identify potential challenges, and determine the readiness for cloud adoption. Which assessment process would be crucial at this initial stage?Business Principles of Cloud Environments
- 48.A cloud security team enforces a policy requiring that all encryption keys protecting sensitive customer data be automatically replaced with new keys every 90 days, with old keys securely retired after a defined grace period. What is the primary security benefit of this practice?Governance, Risk, Compliance and Security
- 49.A company is planning to migrate its legacy on-premises application to a public cloud. The application has complex dependencies and a highly customized architecture. The primary goal is to minimize code changes and leverage existing licenses where possible, while still benefiting from cloud scalability. Which migration approach is most suitable for this scenario?Business Principles of Cloud Environments
- 50.A large enterprise is evaluating the long-term financial implications of moving its data center operations to a public cloud. They want to account for not only direct costs like cloud subscriptions but also indirect costs such as migration efforts, training for staff, changes in governance, and potential downtime during transition. Which financial analysis metric is designed to capture this comprehensive view of all costs?Business Principles of Cloud Environments