CompTIA Cloud+ (CV0-004) flashcards
172 free flashcards. Tap a card to flip it.
Scheduled Job Completion Alert
Flip cardAn alert triggered when a scheduled or batch process fails to start, complete, or send a success signal within a specified timeframe.
- Often uses a 'heartbeat' mechanism or 'dead man's switch'.
- Ensures critical batch processes are running and completing as expected.
- Proactively detects hung or failed jobs that might not generate traditional errors.
Memory trick: For batch jobs, check the clock, or get a shock!
High-Performance Block Storage
Flip cardA type of storage that provides raw, unformatted blocks of data to a server, optimized for low latency and high throughput, often using Solid State Drives (SSDs).
- Ideal for databases, transactional workloads, and high-performance computing.
- Offers high IOPS (Input/Output Operations Per Second).
- Directly attached to compute instances for optimal performance.
Memory trick: For speed, block storage is the best deed.
Object Storage Bucket Policy Conditions
Flip cardConditional statements within an object storage bucket policy that allow or deny actions based on specific criteria, such as object size, content type, or encryption status.
- Provides fine-grained control over actions on objects.
- Conditions can override general IAM permissions if met.
- Often used for security (e.g., encryption enforcement) or operational limits (e.g., max object size).
Memory trick: Your ID says you can enter, but the size limit sign says 'No big packages!'
Cold Object Storage (Archive)
Flip cardCold Object Storage, often referred to as Archive Storage, is a cloud storage tier optimized for extremely infrequent access and long-term data retention. It offers the lowest storage costs but typically has higher retrieval latency (minutes to hours) and potentially retrieval costs.
- Lowest storage costs per GB
- Designed for long-term archival and compliance
- Infrequent access patterns
- Retrieval times range from minutes to hours
Memory trick: Cold Archive is like putting your data in a deep freeze – cheap to store, but takes time to thaw out.
Object Storage
Flip cardA data storage architecture that manages data as objects, distinct from other data types like files or blocks. Objects typically include the data itself, metadata, and a globally unique identifier.
- Highly scalable and durable.
- Ideal for unstructured data, backups, and static content.
- Accessed via APIs (e.g., HTTP/S).
Memory trick: Objects Block Files from Ephemeral Loss.
Block Storage
Flip cardA storage architecture that treats data as blocks, each with a unique address, allowing them to be stored independently and attached directly to compute instances.
- Provides raw storage volumes, like a virtual hard drive.
- Offers low-latency access, suitable for databases and OS volumes.
- Can be provisioned as Elastic Block Storage (EBS) or similar services.
Memory trick: Blocks for VMs, Files for Shares, Objects for Apps, Archive for Deep Freeze.
Load Balancer
Flip cardA device or service that distributes network traffic efficiently across multiple servers to ensure high availability and responsiveness.
- Improves application scalability and reliability.
- Performs health checks on backend servers.
- Can be hardware or software-based.
Memory trick: A Load Balancer is like a traffic cop for your servers, always pointing cars to the open lanes.
Bastion Host
Flip cardA special purpose server in a public subnet that acts as a secure jump server to access instances located in private subnets.
- Provides a single, hardened entry point.
- Requires inbound SSH/RDP rules from trusted IPs only.
- Used to manage instances in private subnets without public IPs.
Memory trick: Bastion's Door is Open, But Subnet's Gate May Be Shut.
Function as a Service (FaaS)
Flip cardFunction as a Service (FaaS) is a serverless computing model where developers write and deploy small, single-purpose functions that are executed in response to events. The cloud provider fully manages all the underlying infrastructure, server provisioning, and scaling.
- Serverless compute model
- Event-driven execution
- Automatic scaling (scales to zero)
- No server management for developers
Memory trick: FaaS is the ultimate 'hands-off' model – just give it your function, and the cloud handles the rest.
Reserved IP Addresses (Subnet)
Flip cardSpecific IP addresses within a subnet's CIDR range that are reserved by the cloud provider for internal network services and cannot be assigned to customer resources.
- Typically includes network address, broadcast address, and gateway.
- Often includes addresses for DNS or other service endpoints.
- Reduces the number of usable IP addresses for VMs/containers.
Memory trick: Reserved IPs Reduce Available Spots.
Merge Conflict
Flip cardA situation where version control software cannot automatically reconcile changes made to the same part of a file in two different branches, requiring manual intervention.
- Occurs during merge or rebase operations
- Developer must manually edit conflict markers
- Common with overlapping edits to shared files
Memory trick: Two cooks editing the same recipe line clash - merge conflict!
Agentless Configuration Management
Flip cardAn architecture where a control node pushes configuration changes to managed nodes using existing protocols (e.g., SSH, WinRM) without installing persistent agent software.
- Ansible is a common example of agentless tooling
- Reduces overhead of managing agent software
- Relies on existing remote access protocols
Memory trick: Agentless is a courier who delivers the package and leaves — no one stays behind at your house.
Automated Provisioning
Flip cardThe process of automatically setting up and configuring IT infrastructure and application resources without manual intervention, often as part of a CI/CD pipeline.
- Reduces human error and increases deployment speed.
- Ensures consistency across environments.
- Key component of CI/CD and DevOps practices.
Memory trick: Continuous Innovation Drives Fast Release.
Shared Responsibility Model (PaaS)
Flip cardA framework outlining the security responsibilities between a cloud provider and its customer. In PaaS, the provider manages the underlying infrastructure and platform, while the customer is responsible for applications, data, and access controls.
- Provider: physical security, infrastructure, OS, network controls
- Customer: application, data, identity & access management, network configuration within app
- Context-dependent on service model (IaaS, PaaS, SaaS)
Memory trick: PaaS: provider's platform, your apps.
Service Mesh
Flip cardA dedicated infrastructure layer for handling service-to-service communication in microservices architectures, enabling secure and observable interactions.
- Provides mTLS for encryption/authentication.
- Enforces fine-grained authorization policies.
- Abstracts networking concerns from application code.
Memory trick: Service mesh makes microservices talk securely.
Scheduled Scaling
Flip cardAn auto-scaling policy that adjusts the number of instances based on a predefined schedule, ideal for predictable traffic patterns.
- Proactive scaling based on time.
- Ensures resources are available before peak load.
- Cost-effective by scaling down during off-peak times.
Memory trick: Schedule for Predictable Peaks, Save Cents on Off-Peaks.
Multi-Factor Authentication (MFA)
Flip cardAn authentication method that requires a user to provide two or more verification factors to gain access to a resource.
- Combines factors from different categories: knowledge, possession, inherence.
- Significantly reduces the risk of credential compromise.
- Common forms include passwords, tokens, biometrics.
Memory trick: KISS: Knowledge, Inherence, Something you have.
Infrastructure as Code (IaC)
Flip cardManaging and provisioning computer data centers through machine-readable definition files, rather than physical hardware configuration or interactive configuration tools.
- Enables automation and repeatability.
- Version control for infrastructure changes.
- Reduces human error and ensures consistency.
Memory trick: IaC builds your cloud with 'Code', not 'Clicks'.
IAM Roles for Applications
Flip cardA cloud identity and access management feature that allows applications or services to assume specific roles with defined permissions, enabling secure access to other cloud resources without embedding credentials.
- Provides temporary credentials for applications.
- Enforces the principle of least privilege for programmatic access.
- Key for securing communication between cloud services.
Memory trick: Roles for bots, not humans, to touch the key.
Availability Zones (AZs)
Flip cardLogically and physically separate data centers within a single cloud region, designed to be isolated from failures in other AZs.
- Provides high availability and fault tolerance.
- Connected by low-latency links.
- Allows distributing application components for resilience.
Memory trick: Regions hold Zones, Zones hold resources.
Role-Based Access Control (RBAC)
Flip cardA method of access control where permissions are associated with roles, and users are assigned to roles, simplifying the management of complex access rights.
- Permissions assigned to roles
- Users assigned to roles
- Simplifies access management
Memory trick: Roles are like job titles, giving specific access to specific folders.
Application Performance Monitoring (APM)
Flip cardTools and processes used to monitor and manage the performance and availability of software applications.
- Focuses on application-level metrics (e.g., response time, error rate).
- Helps identify bottlenecks within the application code or services.
- Often includes distributed tracing for microservices.
Memory trick: APM watches the 'App', Infra watches the 'Ground'.
Container Monitoring
Flip cardThe process of collecting and analyzing metrics, logs, and events from individual containers to ensure their health, performance, and resource utilization.
- Provides granular visibility into container-level resource consumption.
- Includes metrics like CPU, memory, network I/O, and disk I/O per container.
- Essential for microservices architectures and container orchestration platforms.
Memory trick: Microservices need Micro-Monitoring.
Ephemeral Port Exhaustion
Flip cardOccurs when a client (e.g., an application server) attempts to open too many outbound connections in a short period, running out of available ephemeral (short-lived) port numbers.
- Prevents new outbound connections.
- Manifests as 'connection refused' or 'address already in use' errors.
- Can be mitigated by increasing port range, connection pooling, or scaling out clients.
Memory trick: Ephemeral ports are like phone lines: run out, no new calls.
VPC Routing Tables
Flip cardRules that determine where network traffic from a subnet or gateway is directed, specifying targets for various IP address ranges.
- Each subnet must be associated with a route table.
- Contains local routes for intra-VPC communication.
- Can include routes to Internet Gateways, VPNs, or peering connections.
Memory trick: Routes are Roads for Subnet Neighbors.
Idempotency
Flip cardA property where applying the same operation multiple times produces the same result as applying it once, without unintended side effects.
- Core principle of configuration management tools
- Prevents configuration drift from repeated runs
- Enables safe re-execution of automation scripts
Memory trick: Press the elevator button as many times as you want — it still just goes to the same floor once.
Private/Service Endpoints
Flip cardNetwork interfaces that connect cloud services privately to a virtual network, preventing traffic from traversing the public internet.
- Enhances security by isolating traffic.
- Reduces attack surface for cloud services.
- Requires services to be within the same virtual network.
Memory trick: Private roads for private data, no public highways.
Refactor (Rearchitect)
Flip cardA cloud migration strategy that involves fundamentally re-architecting an application to take full advantage of cloud-native features and services.
- Significant code changes and architectural redesign.
- Aims for improved scalability, resilience, and cost optimization.
- Leverages services like serverless, containers, managed databases.
Memory trick: Remembering Cloud's 6 R's for Right Migration.
Automatic Failover
Flip cardA high availability mechanism where a system automatically detects the failure of a primary component (e.g., server, database, VM) and switches operations to a redundant or standby component without manual intervention, minimizing downtime.
- Automated detection and switchover
- Minimizes human error and RTO
- Commonly used for VMs, databases, and network devices
- Requires redundant components and health checks
Memory trick: Failover's quick, disaster's deep, fault tolerance won't sleep.
Kubernetes Node IAM Role
Flip cardThe Identity and Access Management (IAM) role assigned to the underlying virtual machines that host Kubernetes nodes, which grants permissions for pods running on those nodes to interact with cloud provider services.
- Pods inherit permissions from the node's IAM role for cloud service access.
- Crucial for granting access to cloud resources like S3, databases, message queues.
- Misconfiguration leads to 'access denied' errors when pods try to use cloud APIs.
Memory trick: Node's IAM role is the passport for pods to leave Kubernetes and talk to the cloud.
Network Access Control List (NACL)
Flip cardA Network Access Control List (NACL) is an optional layer of security for your VPC that acts as a stateless firewall for controlling traffic in and out of one or more subnets. Rules are processed in order, and it applies to all instances within the associated subnets.
- Operates at the subnet level
- Stateless filtering (inbound and outbound rules are separate)
- Rules are processed in order (lowest rule number evaluated first)
- Default NACLs allow all inbound/outbound traffic
Memory trick: NACL is the 'bouncer' at the subnet entrance, checking everyone, both ways, against a strict rule list.
Database Read/Write Splitting
Flip cardA common database scaling strategy where write operations are directed to a primary instance, and read operations are distributed among one or more replica instances.
- Improves read scalability and performance.
- Reduces load on the primary database.
- Requires careful application configuration to route queries correctly.
Memory trick: Distribute Reads, Don't Let One Database Do Everything.
Third-Party API IP Whitelisting
Flip cardA security measure where an external API restricts access to a predefined list of trusted source IP addresses, often requiring cloud NAT Gateway or egress IP addresses to be explicitly added.
- Restricts API access to specific IP ranges.
- Commonly causes 'connection refused' or 'timeout' errors if not whitelisted.
- Cloud applications using NAT Gateways need their public IP(s) whitelisted.
Memory trick: The API gatekeeper only knows friendly faces (IPs).
Self-Healing (Orchestration)
Flip cardThe capability of an orchestrator like Kubernetes to automatically detect and replace failed containers or nodes to maintain the desired application state.
- Driven by continuous reconciliation between desired and actual state
- Requires no manual admin intervention
- Works alongside health checks (liveness/readiness probes)
Memory trick: Self-healing: the cluster is its own doctor, replacing sick pods instantly.
Dedicated Hosts for Licensing
Flip cardUsing Dedicated Hosts in the cloud to meet software licensing requirements that are tied to physical CPU cores, sockets, or specific hardware.
- Ensures compliance for 'per-core' or 'per-socket' licenses.
- Provides full visibility and control over underlying hardware.
- Avoids complex licensing issues in shared/virtualized environments.
Memory trick: For 'strict' 'CPU core' licensing, a 'Dedicated Host' is your only 'solution'.
Multi-Availability Zone Deployment
Flip cardA high availability strategy that involves deploying application components (e.g., compute instances, databases) across two or more geographically distinct availability zones within the same cloud region. This protects against the failure of a single availability zone.
- Protects against AZ-level failures
- Requires a regional load balancer for traffic distribution
- Increases availability and fault tolerance within a region
- Typically involves synchronous data replication between AZs
Memory trick: Multi-AZ, Load Balancer, always on the go.
Alerting Thresholds
Flip cardConfigurable values that define when a monitored metric's state is considered abnormal and should trigger an alert.
- Includes a metric, operator, value, and evaluation period.
- Proper configuration prevents alert fatigue.
- Should be set to be actionable and indicative of real issues.
Memory trick: An alert is triggered by a 'Metric' that 'Exceeds' a 'Value' for a 'Duration'.
Object Storage ACLs
Flip cardAccess Control Lists (ACLs) applied at the individual object level within object storage services, granting specific permissions to users or groups.
- Can grant public read/write access to individual objects.
- Can potentially override bucket policies for specific objects.
- Often a source of unintended public data exposure if not managed carefully.
Memory trick: Object ACLs Can Open Private Buckets.
Platform as a Service (PaaS)
Flip cardA cloud service model that provides a complete development and deployment environment in the cloud, with resources that enable organizations to build, run, and manage applications without the complexity of building and maintaining the infrastructure typically associated with developing and launching an app.
- Abstracts underlying infrastructure (OS, servers)
- Provides tools for development, deployment, and management
- Common for web applications and microservices
- Examples: Google App Engine, AWS Elastic Beanstalk, Azure App Service
Memory trick: IaaS is raw, PaaS is flow, SaaS is go.
Cloud Governance
Flip cardThe set of rules, policies, and processes that guide the use of cloud computing resources to ensure compliance, security, and cost-effectiveness.
- Includes identity, security, cost, and resource management.
- Often implemented using cloud provider's policy services.
- Ensures alignment with organizational standards and regulations.
Memory trick: Governance is the 'Guardrail' for your cloud resources.
Hardware Security Module (HSM) as a Service
Flip cardA cloud service offering dedicated, FIPS-compliant hardware for cryptographic key generation, storage, and management, providing high assurance.
- Provides highest level of key security.
- Meets strict compliance standards (e.g., FIPS 140-2 Level 3).
- Customer retains direct control over keys.
Memory trick: FIPS Level 3 needs a dedicated HSM fortress.
HTTP 5xx Errors
Flip cardServer error status codes indicating that the server failed to fulfill an apparently valid request.
- 500 Internal Server Error: General error.
- 502 Bad Gateway: Server received invalid response from upstream.
- 503 Service Unavailable: Server is temporarily unable to handle the request.
- 504 Gateway Timeout: Server didn't receive a timely response from upstream.
Memory trick: Server Errors Signal Serious Situations.
Continuous Data Protection (CDP)
Flip cardA backup and recovery strategy that continuously captures or tracks data changes, allowing recovery to any previous point in time with minimal data loss.
- Offers near-zero Recovery Point Objective (RPO).
- Captures changes as they occur, not just at scheduled intervals.
- Ideal for mission-critical applications where data loss is unacceptable.
Memory trick: CDP: Continuous Data Protection, Continuously Does Protection.
Monitoring Agent
Flip cardA software component installed on a monitored resource (e.g., VM, server) that collects metrics, logs, and other data for a centralized monitoring system.
- Gathers raw performance data (CPU, memory, network, disk).
- Pushes or pulls data to a central monitoring backend.
- Essential for granular visibility into individual resource health.
Memory trick: The Agent is the eye, collecting data from high to low.
Digital Signature
Flip cardA cryptographic mechanism that uses asymmetric cryptography to verify the authenticity and integrity of a digital message or document, providing non-repudiation.
- Uses asymmetric cryptography (public/private key pair)
- Ensures data integrity
- Provides non-repudiation (proof of origin)
Memory trick: Digital Signatures: the unbreakable promise for data integrity and non-repudiation.
Immutable Infrastructure
Flip cardAn infrastructure management approach where deployed servers/instances are never modified after creation; updates are made by deploying new images and replacing old instances.
- Eliminates configuration drift by design
- Relies on automated image building pipelines
- Often paired with blue-green or rolling deployment for cutover
Memory trick: Immutable = frozen statue; you don't repaint it, you cast a whole new one.
Virtual Private Network (VPN)
Flip cardA VPN establishes a secure, encrypted connection over a less secure network, like the internet, to provide data confidentiality and integrity.
- Creates an encrypted tunnel
- Ensures data confidentiality and integrity
- Connects private networks over public infrastructure
Memory trick: Connect on-prem to cloud securely, like a secret tunnel.
Cloud Storage Tiering
Flip cardThe practice of moving data between different storage classes (tiers) based on access frequency, performance needs, and cost considerations.
- Optimizes storage costs.
- Balances performance and cost.
- Commonly used with object storage (e.g., standard, infrequent access, archive).
Memory trick: Optimize Storage Costs with Tiered Objects.
Multi-Region Active/Active DR
Flip cardA disaster recovery strategy where full application stacks are deployed and actively serving traffic in multiple geographic regions simultaneously.
- Offers near-zero RPO and RTO.
- Requires advanced data synchronization mechanisms.
- Highest cost among DR strategies.
Memory trick: Active/Active is like having two fully staffed, identical stores open at the same time in different cities.
Private Cloud
Flip cardA cloud deployment model where the cloud infrastructure is provisioned for exclusive use by a single organization.
- Offers highest level of control and security.
- Can be managed internally or by a third party.
- Often used for sensitive data and regulatory compliance.
Memory trick: Private clouds are like your own secure, isolated office building.
Internet Gateway (IGW)
Flip cardA VPC component that allows communication between instances in your Virtual Private Cloud (VPC) and the internet. It enables instances to send and receive traffic from the internet.
- Enables internet connectivity for VPC instances
- Attached to the VPC, not a specific subnet
- Required for public subnets to communicate with the internet
- Acts as a target in public subnet route tables
Memory trick: Internet Gateway for public, NAT Gateway for private's out.
Cloud IAM Policy Evaluation Order
Flip cardThe hierarchical process by which cloud providers determine effective permissions, often involving evaluating explicit denies, explicit allows from various policy types (identity-based, resource-based), and implicit denies.
- Explicit 'Deny' generally takes precedence over 'Allow'.
- An 'Explicit Allow' in an identity policy can sometimes override a 'Deny' in a resource policy, depending on the exact cloud provider's evaluation logic.
- Understanding the full set of policies (user, group, role, resource) is crucial for effective permissions management.
Memory trick: The user's personal badge (IAM policy) might be stronger than the building's rules (bucket policy).
Intrusion Detection/Prevention System (IDS/IPS)
Flip cardA security system that monitors network traffic for suspicious activity and can either alert on (IDS) or actively block (IPS) threats based on predefined rules or anomaly detection.
- Performs deep packet inspection.
- Can operate in detection (IDS) or prevention (IPS) modes.
- Critical for protecting sensitive networks from known and unknown threats.
Memory trick: IDS/IPS: The vigilant guard that looks inside the packages.
Security Group
Flip cardA virtual firewall that controls inbound and outbound traffic for one or more compute instances (e.g., EC2 instances, containers).
- Operates at the instance level.
- Is stateful, automatically allowing return traffic.
- Allows granular control over specific ports and protocols.
Memory trick: VPC for Isolation, NACL for Subnets, SG for Instances, IG for Internet.
Blue-Green Deployment
Flip cardA deployment strategy using two identical environments (blue and green) where traffic is switched entirely from one to the other, enabling instant rollback.
- Requires double the infrastructure temporarily
- Provides near-zero downtime cutover
- Rollback is as simple as switching traffic back
Memory trick: Blue-green: flip the traffic light switch instantly between two full copies.
WORM Storage for Logs
Flip cardCloud object storage configured with Write Once Read Many (WORM) or Object Lock to ensure data immutability for compliance.
- Prevents alteration or deletion for a set period.
- Crucial for regulatory compliance (e.g., financial, healthcare).
- Often combined with IAM for granular access control.
Memory trick: WORM locks logs, IAM lets auditors look.
Continuous Integration (CI) Server
Flip cardAn automation server that orchestrates the build, test, and integration of code changes into a shared repository.
- Monitors VCS for changes.
- Triggers automated builds and tests.
- Provides immediate feedback on code quality.
Memory trick: CI Server is the conductor of the pipeline orchestra.
GDPR Data Protection Principles
Flip cardA set of principles under GDPR that govern the processing of personal data, emphasizing data protection by design and default.
- Lawfulness, fairness, and transparency.
- Purpose limitation, data minimization.
- Accuracy, storage limitation, integrity, and confidentiality.
Memory trick: Public PII means GDPR is very mad.
Cloud Security Groups
Flip cardA virtual firewall that controls inbound and outbound traffic for one or more virtual instances, operating at the instance level and maintaining connection state.
- Stateful: automatically allows return traffic for established connections.
- Instance-level control: rules apply to instances, not subnets.
- Granular: allows specific port, protocol, and source/destination IP rules.
Memory trick: Security groups are like bodyguards for each server, watching who comes and goes.
Virtual Network Gateway Congestion
Flip cardA bottleneck at the central routing component within a cloud VPC that can lead to increased latency and packet loss for traffic between different subnets or to external networks.
- Handles routing for inter-subnet and external VPC traffic.
- Can become a bottleneck under heavy network load.
- Symptoms include increased latency and packet loss across the network.
Memory trick: VPC Gate is a Traffic Cop; if it's jammed, everyone's slow.