Free knowledge base

CompTIA Cloud+ (CV0-004) — key terms, tricks & tips

Everything from the course in one searchable place: 301 entries. Use it to review before a practice test or look up a word you forgot.

301 results · showing first 300, refine your search

Key term

Domain

A major topic category CompTIA uses to organize exam objectives and question weighting.

Getting Started: How the Exam Works

Key term

Performance-Based Question (PBQ)

A simulation-style exam item requiring you to perform a task, not just pick an answer.

Getting Started: How the Exam Works

Key term

Exam Objectives Document

CompTIA's official published list of everything the exam can test, organized by domain.

Getting Started: How the Exam Works

Key term

Scaled Score

A converted score (100-900 for CV0-004) used to report results instead of raw percent correct.

Getting Started: How the Exam Works

Key term

Domain Weight

The percentage of the exam dedicated to a given domain, indicating its relative importance.

Getting Started: How the Exam Works

Key term

High Availability

Design approach ensuring a system stays operational despite failures; part of Architecture and Design.

Getting Started: How the Exam Works

Key term

Provisioning

The process of allocating and configuring cloud resources for use; central to the Deployment domain.

Getting Started: How the Exam Works

Memory trick

CV0-004 Exam Overview and Domain Breakdown

ASDOT: Architecture, Security, Deployment, Operations, Troubleshooting — 'A Sturdy Deployment Overcomes Trouble.'

Getting Started: How the Exam Works

Exam tip

CV0-004 Exam Overview and Domain Breakdown

The exam asks scenario questions that name a task (e.g., 'configuring a backup schedule') without naming the domain — you must recognize that this is Operations and Support. Memorize the five domain names and their rough weight order (Deployment > Ops/Support ≈ Troubleshooting > Security > Architecture) so you can mentally sort any scenario into its domain.

Getting Started: How the Exam Works

Common mistake

CV0-004 Exam Overview and Domain Breakdown

Assuming Architecture and Design is the biggest domain because it's listed first — it's actually the smallest

Getting Started: How the Exam Works

Common mistake

CV0-004 Exam Overview and Domain Breakdown

Studying only multiple-choice style and ignoring hands-on practice needed for PBQs

Getting Started: How the Exam Works

Common mistake

CV0-004 Exam Overview and Domain Breakdown

Not checking the current official objectives page for the exact passing score and question count before exam day

Getting Started: How the Exam Works

Key term

Multiple-select

Question format requiring you to choose an exact number of correct answers

Getting Started: How the Exam Works

Key term

Distractor

An incorrect answer choice designed to look plausible

Getting Started: How the Exam Works

Key term

Pacing

Managing time per question so you finish the full exam

Getting Started: How the Exam Works

Key term

Spaced repetition

Study technique of reviewing material at increasing intervals to boost retention

Getting Started: How the Exam Works

Key term

Pearson VUE

Testing company that administers CompTIA exams at centers and online

Getting Started: How the Exam Works

Key term

Flag for review

Exam software feature marking a question to revisit before final submission

Getting Started: How the Exam Works

Memory trick

Study Strategy, Question Types, and Exam Day Tips

READ-FLAG-CUT-PICK-CHECK: Read twice, Flag hard ones, Cut wrong answers, Pick the best, Check flagged items before submitting.

Getting Started: How the Exam Works

Exam tip

Study Strategy, Question Types, and Exam Day Tips

The exam does not penalize guessing, so never leave a question blank; also expect PBQs to appear early and to be time-intensive, so plan to flag and return to them.

Getting Started: How the Exam Works

Common mistake

Study Strategy, Question Types, and Exam Day Tips

Spending too much time perfecting one PBQ and running out of time for easier multiple-choice questions

Getting Started: How the Exam Works

Common mistake

Study Strategy, Question Types, and Exam Day Tips

Choosing an answer that is technically correct but not the 'best practice' the question is really testing

Getting Started: How the Exam Works

Common mistake

Study Strategy, Question Types, and Exam Day Tips

Skipping a full-length timed practice exam and being caught off guard by real exam pacing

Getting Started: How the Exam Works

Key term

IaaS

Cloud model providing virtualized compute, storage, and networking infrastructure.

Cloud Architecture Foundations

Key term

PaaS

Cloud model providing a managed platform for developing and running applications.

Cloud Architecture Foundations

Key term

SaaS

Cloud model delivering a fully managed, ready-to-use software application.

Cloud Architecture Foundations

Key term

Public cloud

Multi-tenant cloud infrastructure owned and operated by a third-party provider.

Cloud Architecture Foundations

Key term

Private cloud

Cloud infrastructure dedicated to a single organization.

Cloud Architecture Foundations

Key term

Hybrid cloud

Combination of public and private clouds with workload portability between them.

Cloud Architecture Foundations

Key term

Community cloud

Cloud infrastructure shared by organizations with common requirements or goals.

Cloud Architecture Foundations

Key term

Shared responsibility model

Framework dividing security and operational duties between cloud provider and customer.

Cloud Architecture Foundations

Memory trick

Service & Deployment Models, Shared Responsibility

'I Plant Seeds' = IaaS (Infrastructure), PaaS (Platform), SaaS (Software) — control decreases, convenience increases as you go I→P→S.

Cloud Architecture Foundations

Exam tip

Service & Deployment Models, Shared Responsibility

Expect scenario questions naming a specific failure (e.g., data breach, unpatched OS, exposed bucket) and asking whether it's the provider's or customer's fault based on the service model in use; memorize that data and access control are always customer duties.

Cloud Architecture Foundations

Common mistake

Service & Deployment Models, Shared Responsibility

Assuming the cloud provider secures customer data and access in every model, even SaaS

Cloud Architecture Foundations

Common mistake

Service & Deployment Models, Shared Responsibility

Confusing PaaS with IaaS by thinking customers still manage the OS in PaaS

Cloud Architecture Foundations

Common mistake

Service & Deployment Models, Shared Responsibility

Picking public cloud for a scenario that clearly demands strict regulatory data control (should be private or hybrid)

Cloud Architecture Foundations

Key term

Block storage

Raw fixed-size storage blocks presented as a volume, low latency, used for VM disks and databases

Cloud Architecture Foundations

Key term

Object storage

Storage of data as objects with metadata in a flat namespace, accessed via API, highly scalable

Cloud Architecture Foundations

Key term

File storage

Hierarchical folder-based storage shared over network protocols like NFS or SMB

Cloud Architecture Foundations

Key term

Lifecycle policy

Automated rule that moves or deletes data between storage tiers based on age or rules

Cloud Architecture Foundations

Key term

IOPS

Input/output operations per second, a measure of storage performance and throughput

Cloud Architecture Foundations

Key term

Serverless (FaaS)

Compute model running event-triggered code without managing servers, billed per execution

Cloud Architecture Foundations

Key term

Bare metal

Dedicated physical server with no hypervisor layer, offering maximum performance and isolation

Cloud Architecture Foundations

Memory trick

Storage Tiers and Cloud Compute Options

BFO: Block=Boot/database speed, File=Folders for many, Object=Ocean of cheap scalable data.

Cloud Architecture Foundations

Exam tip

Storage Tiers and Cloud Compute Options

The exam frequently presents a scenario describing an access pattern (e.g., 'data accessed once a year for compliance') and asks you to pick the correct storage tier or type; memorize the hot/cool/archive cost-vs-retrieval-time tradeoff and the block/file/object use-case mapping.

Cloud Architecture Foundations

Common mistake

Storage Tiers and Cloud Compute Options

Choosing object storage for a database workload needing low-latency random writes, when block storage is required

Cloud Architecture Foundations

Common mistake

Storage Tiers and Cloud Compute Options

Forgetting that archive tier has retrieval delays and fees, then being surprised when 'restore now' isn't instant

Cloud Architecture Foundations

Common mistake

Storage Tiers and Cloud Compute Options

Assuming serverless is always cheapest, when steady, high-volume workloads may cost less on reserved VMs

Cloud Architecture Foundations

Key term

VPC

Virtual Private Cloud; an isolated logical network within a cloud provider's infrastructure.

Cloud Architecture Foundations

Key term

CIDR block

Notation defining an IP address range, e.g., 10.0.0.0/16.

Cloud Architecture Foundations

Key term

Subnet

A segment of a VPC's address range, usually tied to one availability zone.

Cloud Architecture Foundations

Key term

Internet Gateway

Component enabling two-way traffic between a VPC and the public internet.

Cloud Architecture Foundations

Key term

NAT Gateway

Allows private subnet resources outbound-only internet access.

Cloud Architecture Foundations

Key term

Security Group

Stateful, instance-level virtual firewall controlling allowed traffic.

Cloud Architecture Foundations

Key term

Load Balancer

Service distributing incoming traffic across multiple backend servers.

Cloud Architecture Foundations

Key term

Health Check

Automated test used by a load balancer to detect and remove failed instances.

Cloud Architecture Foundations

Memory trick

Networking Essentials: VPCs, Subnets, Load Balancing

VPC = 'Very Private Corner': your own fenced yard (VPC), with a front gate (internet gateway) for public rooms (public subnet) and a back-alley-only exit (NAT) for private rooms.

Cloud Architecture Foundations

Exam tip

Networking Essentials: VPCs, Subnets, Load Balancing

CV0-004 objectives test whether you can identify public vs private subnet by its route table (internet gateway vs NAT/no route), and whether you know load balancers operate at Layer 4 (IP/port) or Layer 7 (application/content). Memorize that NAT gateways are outbound-only and security groups are stateful.

Cloud Architecture Foundations

Common mistake

Networking Essentials: VPCs, Subnets, Load Balancing

Assuming a subnet is private just because it lacks a public IP assigned, when the real deciding factor is the route table entry for 0.0.0.0/0

Cloud Architecture Foundations

Common mistake

Networking Essentials: VPCs, Subnets, Load Balancing

Forgetting that security groups are stateful and only need inbound rules, unlike NACLs which need explicit inbound and outbound rules

Cloud Architecture Foundations

Common mistake

Networking Essentials: VPCs, Subnets, Load Balancing

Placing a database or app server directly in a public subnet, unnecessarily exposing it to internet-facing risk

Cloud Architecture Foundations

Key term

Container

Lightweight, portable unit packaging an app and dependencies, sharing the host OS kernel.

Cloud Architecture Foundations

Key term

Orchestration

Automated management of container deployment, scaling, and failure recovery (e.g., Kubernetes).

Cloud Architecture Foundations

Key term

High Availability (HA)

Design approach ensuring a system remains operational despite component failures.

Cloud Architecture Foundations

Key term

Failover

Automatic switch to a standby resource when the primary component fails.

Cloud Architecture Foundations

Key term

Fault Tolerance

Ability of a system to continue operating with little or no interruption during failure.

Cloud Architecture Foundations

Key term

Autoscaling

Automatically adjusting compute resources up or down based on demand.

Cloud Architecture Foundations

Key term

Rightsizing

Adjusting resource allocation to match actual workload usage, reducing waste.

Cloud Architecture Foundations

Key term

SLA (Service Level Agreement)

Contractual commitment defining expected uptime and remedies if unmet.

Cloud Architecture Foundations

Memory trick

Containers, High Availability, and Cost Optimization

Think 'C-H-C': Containers share the kernel, HA hides failures, Cost optimization matches spend to actual need.

Cloud Architecture Foundations

Exam tip

Containers, High Availability, and Cost Optimization

Expect scenario questions asking you to pick the best availability or cost strategy (e.g., 'workload is interruptible, minimize cost' = spot instance; 'need automatic recovery from AZ failure' = multi-AZ failover). Memorize the container vs VM distinction and know that Kubernetes is the orchestration layer, not a container runtime itself.

Cloud Architecture Foundations

Common mistake

Containers, High Availability, and Cost Optimization

Confusing containers with VMs and assuming containers include a full guest OS

Cloud Architecture Foundations

Common mistake

Containers, High Availability, and Cost Optimization

Assuming higher availability (more nines) is always worth the extra cost without checking business requirements

Cloud Architecture Foundations

Common mistake

Containers, High Availability, and Cost Optimization

Forgetting that autoscaling and reserved/spot pricing can be combined for both availability and savings

Cloud Architecture Foundations

Key term

P2V

Physical-to-Virtual migration; converting a physical server into a virtual machine.

Cloud Deployment Strategies

Key term

V2V

Virtual-to-Virtual migration; moving a VM between hypervisors or cloud platforms.

Cloud Deployment Strategies

Key term

Rehost

Lift-and-shift strategy; moving a workload with minimal or no changes.

Cloud Deployment Strategies

Key term

Refactor

Redesigning an application to be cloud-native during migration.

Cloud Deployment Strategies

Key term

Repurchase

Replacing an existing application with a new SaaS product.

Cloud Deployment Strategies

Key term

Rollback plan

A predefined procedure to revert to the original environment if migration fails.

Cloud Deployment Strategies

Key term

Pilot migration

A small-scale test migration used to validate tools and process before full rollout.

Cloud Deployment Strategies

Key term

Dependency mapping

Identifying which systems and services rely on each other before migrating.

Cloud Deployment Strategies

Memory trick

Migration Strategies and Planning

6 Rs: 'Real Restaurants Repurpose Retired Recipes Regularly' — Rehost, Replatform, Refactor, Repurchase, Retire, Retain.

Cloud Deployment Strategies

Exam tip

Migration Strategies and Planning

CV0-004 scenario questions often describe a workload and ask you to pick the correct migration type (P2V/V2V/V2P/P2P) or the correct 'R' strategy (rehost/replatform/refactor/repurchase/retire/retain). Memorize the six strategy names precisely — questions test subtle differences like replatform vs. refactor.

Cloud Deployment Strategies

Common mistake

Migration Strategies and Planning

Choosing rehost for everything just because it's fastest, ignoring long-term cost/performance benefits of replatforming or refactoring

Cloud Deployment Strategies

Common mistake

Migration Strategies and Planning

Skipping dependency mapping and migrating systems out of order, causing outages

Cloud Deployment Strategies

Common mistake

Migration Strategies and Planning

Failing to plan bandwidth/transfer time and rollback procedures before the migration window

Cloud Deployment Strategies

Key term

Infrastructure as Code (IaC)

Managing and provisioning infrastructure through machine-readable definition files instead of manual processes.

Cloud Deployment Strategies

Key term

Declarative

Code style that specifies the desired end state, letting the tool determine the steps.

Cloud Deployment Strategies

Key term

Imperative

Code style that specifies the exact sequence of steps to execute.

Cloud Deployment Strategies

Key term

Idempotency

Property where running the same code repeatedly produces the same result without duplication or error.

Cloud Deployment Strategies

Key term

Configuration drift

When a live environment's actual state no longer matches its defined IaC configuration.

Cloud Deployment Strategies

Key term

Version control

System (e.g., Git) for tracking changes to code, enabling history, review, and rollback.

Cloud Deployment Strategies

Memory trick

Provisioning and Infrastructure as Code

IaC = 'I aC(ode) it once, run it forever the same way' — write once, deploy consistently every time.

Cloud Deployment Strategies

Exam tip

Provisioning and Infrastructure as Code

The exam may present a scenario asking why infrastructure should be defined in code rather than built manually; correct answers emphasize consistency, repeatability, version control, and reduced human error. Know the term 'idempotent' and be able to recognize it as a defining property of good IaC.

Cloud Deployment Strategies

Common mistake

Provisioning and Infrastructure as Code

Treating IaC scripts like one-off manual scripts instead of storing them in version control

Cloud Deployment Strategies

Common mistake

Provisioning and Infrastructure as Code

Writing non-idempotent code that creates duplicate resources on repeated runs

Cloud Deployment Strategies

Common mistake

Provisioning and Infrastructure as Code

Allowing manual console changes that cause drift without updating the code

Cloud Deployment Strategies

Key term

Template

A pre-configured blueprint defining cloud resources and configurations.

Cloud Deployment Strategies

Key term

Automated Build

Process of provisioning infrastructure without manual intervention.

Cloud Deployment Strategies

Key term

Orchestration Tool

Software that automates the coordination of multiple tasks or services.

Cloud Deployment Strategies

Key term

CloudFormation

AWS service for defining and deploying infrastructure as code using templates.

Cloud Deployment Strategies

Key term

ARM Templates

Azure Resource Manager templates for defining and deploying Azure resources.

Cloud Deployment Strategies

Key term

Terraform

Open-source IaC tool for provisioning and managing cloud infrastructure.

Cloud Deployment Strategies

Key term

CI/CD Pipeline

Automated process for integrating and deploying code changes continuously.

Cloud Deployment Strategies

Memory trick

Templates and Automated Environment Builds

Think of a 'Cookie Cutter' for cloud. You design the perfect cookie (your environment) once, then use the cutter (template) to make identical cookies (environments) quickly and easily, every time!

Cloud Deployment Strategies

Exam tip

Templates and Automated Environment Builds

The exam often asks about the benefits of templates and automation, such as 'consistency,' 'speed,' 'reduced human error,' and 'scalability.' Be prepared to identify which tool (e.g., CloudFormation, ARM, Terraform) corresponds to which cloud provider or use case.

Cloud Deployment Strategies

Common mistake

Templates and Automated Environment Builds

Failing to version control templates, leading to inconsistencies or lost changes.

Cloud Deployment Strategies

Common mistake

Templates and Automated Environment Builds

Not testing templates thoroughly before deploying to production environments, causing unexpected issues.

Cloud Deployment Strategies

Common mistake

Templates and Automated Environment Builds

Hardcoding sensitive information directly into templates instead of using secure parameter stores.

Cloud Deployment Strategies

Key term

Virtual Private Cloud (VPC)

Logically isolated section of a cloud provider's network.

Cloud Deployment Strategies

Key term

NACL (Network ACL)

Stateless firewall controlling traffic to/from a subnet.

Cloud Deployment Strategies

Key term

Storage Tiers

Different levels of storage performance and cost based on access frequency.

Cloud Deployment Strategies

Memory trick

Deploying Cloud Storage and Network Configurations

To remember storage types: 'BOF' – Block for OS/Databases, Object for Files/Backups, File for Shared access.

Cloud Deployment Strategies

Exam tip

Deploying Cloud Storage and Network Configurations

The CompTIA Cloud+ exam often tests your understanding of when to use specific storage types (e.g., object for backups, block for databases) and the difference between stateful (Security Groups) and stateless (NACLs) firewalls. Pay attention to cost implications of different storage tiers.

Cloud Deployment Strategies

Common mistake

Deploying Cloud Storage and Network Configurations

Using expensive, high-performance storage for infrequently accessed archive data.

Cloud Deployment Strategies

Common mistake

Deploying Cloud Storage and Network Configurations

Forgetting to open necessary ports in security groups or NACLs, leading to connectivity issues.

Cloud Deployment Strategies

Common mistake

Deploying Cloud Storage and Network Configurations

Not testing network connectivity and storage access after deployment, assuming everything works.

Cloud Deployment Strategies

Common mistake

Deploying Cloud Storage and Network Configurations

Confusing the scope and behavior of Security Groups (instance-level, stateful) and NACLs (subnet-level, stateless).

Cloud Deployment Strategies

Key term

Monitoring

Collecting and analyzing quantitative data (metrics) about system performance and health.

Cloud Operations and Maintenance

Key term

Logging

Recording discrete events and messages generated by systems and applications.

Cloud Operations and Maintenance

Key term

Alerting

Proactive notification of potential issues based on predefined thresholds or patterns.

Cloud Operations and Maintenance

Key term

Metrics

Quantitative data points measured over time, such as CPU usage or network traffic.

Cloud Operations and Maintenance

Key term

Logs

Timestamped records of events, providing detailed historical context for troubleshooting.

Cloud Operations and Maintenance

Key term

Observability

The ability to understand the internal state of a system by examining its external outputs.

Cloud Operations and Maintenance

Key term

Threshold

A predefined limit that, when crossed by a metric, triggers an alert.

Cloud Operations and Maintenance

Key term

Centralized Logging

Aggregating logs from multiple sources into a single platform for analysis.

Cloud Operations and Maintenance

Memory trick

Monitoring, Logging, and Alerting Fundamentals

To remember the order: 'M.L.A.' - Monitoring, Logging, Alerting. Like a 'Master of Legal Affairs' keeps an eye on everything!

Cloud Operations and Maintenance

Exam tip

Monitoring, Logging, and Alerting Fundamentals

The CompTIA Cloud+ exam often asks about the *purpose* of each component: Monitoring for performance/health, Logging for auditing/troubleshooting, and Alerting for proactive issue notification. Know the difference between metrics (quantitative) and logs (qualitative events).

Cloud Operations and Maintenance

Common mistake

Monitoring, Logging, and Alerting Fundamentals

Ignoring log data: Relying solely on metrics often misses critical details for root cause analysis.

Cloud Operations and Maintenance

Common mistake

Monitoring, Logging, and Alerting Fundamentals

Alert fatigue: Over-alerting or setting too many low-priority alerts can desensitize teams to real issues.

Cloud Operations and Maintenance

Common mistake

Monitoring, Logging, and Alerting Fundamentals

Lack of context in alerts: Alerts that don't provide enough information (e.g., affected service, severity) lead to slower resolution.

Cloud Operations and Maintenance

Key term

Vertical Scaling

Increasing resources of a single server.

Cloud Operations and Maintenance

Key term

Horizontal Scaling

Adding more instances of a resource.

Cloud Operations and Maintenance

Key term

Caching

Storing frequently accessed data for faster retrieval.

Cloud Operations and Maintenance

Key term

CDN

Content Delivery Network; distributes content globally.

Cloud Operations and Maintenance

Key term

Throughput

Rate at which data is processed or transferred.

Cloud Operations and Maintenance

Memory trick

Scaling Strategies and Performance Optimization

Think of a 'V' for Vertical as adding 'Volume' to one machine, and 'H' for Horizontal as adding 'Hosts' (many machines).

Cloud Operations and Maintenance

Exam tip

Scaling Strategies and Performance Optimization

The CompTIA Cloud+ exam frequently tests your understanding of the differences between vertical and horizontal scaling. Memorize that 'scaling up' means vertical and 'scaling out' means horizontal, and know the primary use cases for each, especially in relation to autoscaling.

Cloud Operations and Maintenance

Common mistake

Scaling Strategies and Performance Optimization

Confusing vertical and horizontal scaling, especially on exam questions.

Cloud Operations and Maintenance

Common mistake

Scaling Strategies and Performance Optimization

Not configuring autoscaling properly, leading to either over-provisioning (wasted cost) or under-provisioning (performance issues).

Cloud Operations and Maintenance

Common mistake

Scaling Strategies and Performance Optimization

Ignoring non-scaling optimization techniques, like caching or code optimization, which can often yield better results for specific bottlenecks.

Cloud Operations and Maintenance

Key term

Backup

A copy of data or systems for recovery.

Cloud Operations and Maintenance

Key term

Restore

Process of retrieving and applying a backup.

Cloud Operations and Maintenance

Key term

Disaster Recovery Plan (DRP)

Strategy for recovering from major disruptions.

Cloud Operations and Maintenance

Key term

Recovery Time Objective (RTO)

Maximum acceptable downtime after an incident.

Cloud Operations and Maintenance

Key term

Recovery Point Objective (RPO)

Maximum acceptable data loss after an incident.

Cloud Operations and Maintenance

Key term

Full Backup

Copies all selected data.

Cloud Operations and Maintenance

Key term

Incremental Backup

Copies data changed since any last backup.

Cloud Operations and Maintenance

Key term

Differential Backup

Copies data changed since the last full backup.

Cloud Operations and Maintenance

Memory trick

Backup, Restore, and Disaster Recovery Planning

RTO is 'Recovery Time Objective' – think 'Time On' for getting back online. RPO is 'Recovery Point Objective' – think 'Point Of' last good data.

Cloud Operations and Maintenance

Exam tip

Backup, Restore, and Disaster Recovery Planning

The exam often tests your understanding of RTO and RPO, and the differences between backup types. Memorize that RTO is about time (how fast you recover) and RPO is about data (how much data you can afford to lose).

Cloud Operations and Maintenance

Common mistake

Backup, Restore, and Disaster Recovery Planning

Not regularly testing backup restoration procedures.

Cloud Operations and Maintenance

Common mistake

Backup, Restore, and Disaster Recovery Planning

Confusing RTO and RPO or not knowing their definitions.

Cloud Operations and Maintenance

Common mistake

Backup, Restore, and Disaster Recovery Planning

Assuming cloud provider redundancy is a complete DRP without additional planning.

Cloud Operations and Maintenance

Key term

Patching

Applying updates to software or systems to fix issues.

Cloud Operations and Maintenance

Key term

Zero-day vulnerability

A software flaw unknown to the vendor, exploited before a patch exists.

Cloud Operations and Maintenance

Key term

Deprovisioning

Removing or decommissioning cloud resources when no longer needed.

Cloud Operations and Maintenance

Key term

Resource Sprawl

Unmanaged growth of cloud resources, leading to waste and risk.

Cloud Operations and Maintenance

Memory trick

Patching and Lifecycle Management

Think of the 'P.O.M.D.' for the core lifecycle: Planning, Operation, Maintenance, Deprovisioning. Like a POMEgranate, it has many seeds of tasks!

Cloud Operations and Maintenance

Exam tip

Patching and Lifecycle Management

The CompTIA Cloud+ exam emphasizes the shared responsibility model. Remember that customers are always responsible for 'security in the cloud' (their data, applications, OS patching for IaaS), while providers handle 'security of the cloud' (physical security, underlying infrastructure).

Cloud Operations and Maintenance

Common mistake

Patching and Lifecycle Management

Forgetting to test patches in a non-production environment before deploying to production.

Cloud Operations and Maintenance

Common mistake

Patching and Lifecycle Management

Neglecting to deprovision unused resources, leading to unnecessary costs and security risks.

Cloud Operations and Maintenance

Common mistake

Patching and Lifecycle Management

Assuming the cloud provider handles all patching, especially for IaaS operating systems and applications.

Cloud Operations and Maintenance

Key term

Identity and Access Management (IAM)

Framework for managing digital identities and controlling resource access.

Securing the Cloud

Key term

Authentication

Process of verifying a user's identity.

Securing the Cloud

Key term

Authorization

Process of determining what an authenticated user can do.

Securing the Cloud

Key term

Multi-Factor Authentication (MFA)

Requires two or more verification factors for identity proof.

Securing the Cloud

Key term

Role-Based Access Control (RBAC)

Permissions are assigned to roles, and users to roles.

Securing the Cloud

Key term

Least Privilege

Granting only the minimum necessary permissions to perform a task.

Securing the Cloud

Key term

Single Sign-On (SSO)

One authentication session for multiple applications.

Securing the Cloud

Key term

Separation of Duties

Ensuring no single person has complete control over a critical process.

Securing the Cloud

Memory trick

Identity and Access Management (IAM) in the Cloud

To remember AAA: 'A'll 'A'ccess 'A'llowed? No, it's 'A'uthenticate, 'A'uthorize, 'A'ccount!

Securing the Cloud

Exam tip

Identity and Access Management (IAM) in the Cloud

The exam often tests the difference between authentication and authorization. Remember: Authentication is 'who you are,' Authorization is 'what you can do.' Also, be prepared to identify common IAM best practices like MFA and least privilege.

Securing the Cloud

Common mistake

Identity and Access Management (IAM) in the Cloud

Granting overly broad permissions (e.g., full admin access when only specific resource access is needed).

Securing the Cloud

Common mistake

Identity and Access Management (IAM) in the Cloud

Not enforcing Multi-Factor Authentication (MFA) for all users, especially privileged ones.

Securing the Cloud

Common mistake

Identity and Access Management (IAM) in the Cloud

Failing to regularly review and revoke outdated access permissions for users and services.

Securing the Cloud

Key term

Encryption

Transforming data into an unreadable format to protect confidentiality.

Securing the Cloud

Key term

Symmetric Encryption

Uses a single, shared secret key for both encryption and decryption.

Securing the Cloud

Key term

Asymmetric Encryption

Uses a public/private key pair; also known as public-key cryptography.

Securing the Cloud

Key term

Key Management System (KMS)

A service for generating, storing, managing, and auditing cryptographic keys.

Securing the Cloud

Key term

Hardware Security Module (HSM)

A physical computing device that safeguards and manages digital keys.

Securing the Cloud

Key term

Data at Rest

Data that is stored on storage devices, not actively moving.

Securing the Cloud

Key term

Data in Transit

Data that is actively moving over a network connection.

Securing the Cloud

Key term

Key Rotation

Periodically replacing cryptographic keys to limit exposure time.

Securing the Cloud

Memory trick

Encryption and Key Management Practices

KISS: Keep It Securely Stored. For key management, always think about where your keys are stored, how they're accessed, and how often they're changed.

Securing the Cloud

Exam tip

Encryption and Key Management Practices

The CompTIA Cloud+ exam often tests your understanding of the different states of data (at rest, in transit, in use) and which encryption methods apply. Memorize that symmetric encryption is generally faster and better for bulk data, while asymmetric is for secure key exchange and digital signatures. Also, be aware of the FIPS 140-2 standard for HSMs.

Securing the Cloud

Common mistake

Encryption and Key Management Practices

Using weak or easily guessable encryption keys.

Securing the Cloud

Common mistake

Encryption and Key Management Practices

Not rotating encryption keys regularly, increasing the risk if a key is compromised.

Securing the Cloud

Common mistake

Encryption and Key Management Practices

Hardcoding encryption keys directly into application code instead of using a KMS.

Securing the Cloud

Common mistake

Encryption and Key Management Practices

Failing to encrypt data in all states (at rest, in transit, in use).

Securing the Cloud

Key term

Network Security Group (NSG)

A virtual firewall controlling traffic to/from cloud resources.

Securing the Cloud

Key term

Network Segmentation

Dividing a network into smaller, isolated segments for security.

Securing the Cloud

Key term

PCI DSS

Payment Card Industry Data Security Standard for card data protection.

Securing the Cloud

Key term

HIPAA

Health Insurance Portability and Accountability Act for ePHI.

Securing the Cloud

Key term

Stateful Firewall

Firewall that tracks connection states, allowing return traffic automatically.

Securing the Cloud

Key term

Inbound Rule

NSG rule controlling traffic entering a resource.

Securing the Cloud

Key term

Outbound Rule

NSG rule controlling traffic leaving a resource.

Securing the Cloud

Memory trick

Network Security Groups and Compliance

NSG: 'N'o 'S'trangers 'G'etting in!

Securing the Cloud

Exam tip

Network Security Groups and Compliance

On the CompTIA Cloud+ exam, be prepared to identify how NSGs (or their cloud provider equivalents like AWS Security Groups or Google Cloud Firewall Rules) are used for network segmentation and to meet compliance requirements like PCI DSS or HIPAA. Keywords to spot include 'virtual firewall', 'traffic filtering', 'subnet isolation', and 'regulatory compliance'.

Securing the Cloud

Common mistake

Network Security Groups and Compliance

Forgetting that NSGs are stateful, meaning you don't need separate rules for return traffic once a connection is established.

Securing the Cloud

Common mistake

Network Security Groups and Compliance

Assuming that an NSG applied at the subnet level is the only one in effect; remember that NSGs can also be applied at the network interface level, and both are evaluated.

Securing the Cloud

Common mistake

Network Security Groups and Compliance

Not adhering to the principle of least privilege, creating overly permissive rules that expose resources unnecessarily.

Securing the Cloud

Key term

Vulnerability Management

Continuous process of identifying, assessing, and remediating security weaknesses.

Securing the Cloud

Key term

Vulnerability Scanner

Automated tool to identify known security weaknesses in systems.

Securing the Cloud

Key term

Penetration Testing

Simulated cyberattack to find and exploit vulnerabilities.

Securing the Cloud

Key term

CSPM

Cloud Security Posture Management; monitors cloud configurations for compliance.

Securing the Cloud

Key term

Incident Response

Organized approach to addressing and managing security breaches.

Securing the Cloud

Key term

Playbook

Step-by-step guide for responding to specific security incidents.

Securing the Cloud

Key term

Containment

Phase of IR to limit the scope and spread of an incident.

Securing the Cloud

Key term

Eradication

Phase of IR to remove the root cause of a security incident.

Securing the Cloud

Memory trick

Vulnerability Management and Incident Response

To remember the NIST IR phases, think 'P-I-C-E-R-P': Prepare, Identify, Contain, Eradicate, Recover, Post-incident. Like 'P.I.C.E.R.P. the incident before it gets worse!'

Securing the Cloud

Exam tip

Vulnerability Management and Incident Response

The CompTIA Cloud+ exam often tests your knowledge of the NIST SP 800-61 incident response lifecycle. Memorize the six phases: Preparation, Identification, Containment, Eradication, Recovery, and Post-Incident Activity. Keywords like 'lessons learned' or 'root cause analysis' point to specific phases.

Securing the Cloud

Common mistake

Vulnerability Management and Incident Response

Treating vulnerability management as a one-time scan instead of a continuous process.

Securing the Cloud

Common mistake

Vulnerability Management and Incident Response

Failing to develop and regularly test incident response playbooks, leading to chaotic responses.

Securing the Cloud

Common mistake

Vulnerability Management and Incident Response

Not performing post-incident reviews, which prevents learning from past security events.

Securing the Cloud

Key term

Version Control System (VCS)

Software that tracks changes to files over time.

DevOps Fundamentals for Cloud+

Key term

Git

A widely used distributed version control system.

DevOps Fundamentals for Cloud+

Key term

Repository

A central location where code and its history are stored.

DevOps Fundamentals for Cloud+

Key term

Continuous Integration (CI)

Developers frequently merge code, triggering automated builds and tests.

DevOps Fundamentals for Cloud+

Key term

Continuous Delivery (CD)

Software is always in a deployable state, ready for manual release.

DevOps Fundamentals for Cloud+

Key term

Continuous Deployment (CD)

Automated deployment of all changes to production after tests pass.

DevOps Fundamentals for Cloud+

Key term

Pipeline

An automated sequence of steps for building, testing, and deploying.

DevOps Fundamentals for Cloud+

Key term

Artifact

A compiled, deployable output of a build process.

DevOps Fundamentals for Cloud+

Memory trick

CI/CD Pipelines and Version Control Basics

Think of CI/CD like a 'Continuous Delivery Driver' – CI is the car being built and tested, CD (Delivery) is the car ready for you to pick up, and CD (Deployment) is the car automatically driving itself to your driveway!

DevOps Fundamentals for Cloud+

Exam tip

CI/CD Pipelines and Version Control Basics

The CompTIA Cloud+ exam expects you to distinguish clearly between Continuous Integration, Continuous Delivery, and Continuous Deployment. Pay close attention to the level of automation for the final release step.

DevOps Fundamentals for Cloud+

Common mistake

CI/CD Pipelines and Version Control Basics

Confusing Continuous Delivery with Continuous Deployment: remember, delivery means 'ready to deploy,' deployment means 'automatically deployed.'

DevOps Fundamentals for Cloud+

Common mistake

CI/CD Pipelines and Version Control Basics

Neglecting automated testing in CI/CD: without robust tests, the pipeline provides false confidence and can deploy broken code.

DevOps Fundamentals for Cloud+

Common mistake

CI/CD Pipelines and Version Control Basics

Not using branches effectively in version control: working directly on the main branch can lead to conflicts and unstable code.

DevOps Fundamentals for Cloud+

Key term

Configuration Management

Maintaining systems in a desired, consistent state using defined policies.

DevOps Fundamentals for Cloud+

Key term

Kubernetes

Open-source platform for automating deployment, scaling, and management of containers.

DevOps Fundamentals for Cloud+

Key term

Ansible

Agentless open-source automation tool for configuration management and orchestration.

DevOps Fundamentals for Cloud+

Key term

Puppet

Configuration management tool using a declarative language to manage system configurations.

DevOps Fundamentals for Cloud+

Memory trick

Orchestration and Configuration Management Tools

Orchestration is like an 'O'rchestra conductor, managing the whole show. Configuration Management 'C'onfigures individual 'C'omponents.

DevOps Fundamentals for Cloud+

Exam tip

Orchestration and Configuration Management Tools

The CompTIA Cloud+ exam often distinguishes between orchestration and configuration management. Remember that orchestration is about managing the lifecycle of an entire application or service, while configuration management is about the state of individual components within that system. Look for keywords like 'deployment of complex services' for orchestration and 'consistent server state' for configuration management.

DevOps Fundamentals for Cloud+

Common mistake

Orchestration and Configuration Management Tools

Confusing orchestration with configuration management: they are related but distinct.

DevOps Fundamentals for Cloud+

Common mistake

Orchestration and Configuration Management Tools

Believing these tools are only for large enterprises; they benefit environments of all sizes.

DevOps Fundamentals for Cloud+

Common mistake

Orchestration and Configuration Management Tools

Thinking you need to manually intervene after initial setup; the goal is full automation.

DevOps Fundamentals for Cloud+

Key term

Automation

Using technology to perform tasks with minimal human intervention.

DevOps Fundamentals for Cloud+

Key term

Scripting Language

A programming language used to automate tasks; e.g., Python, PowerShell.

DevOps Fundamentals for Cloud+

Key term

Idempotence

A script or operation that produces the same result regardless of how many times it's run.

DevOps Fundamentals for Cloud+

Key term

API (Application Programming Interface)

A set of rules allowing software components to communicate.

DevOps Fundamentals for Cloud+

Key term

Credential Management

Securely storing and retrieving sensitive authentication information.

DevOps Fundamentals for Cloud+

Key term

Error Handling

Code designed to anticipate and respond to errors during script execution.

DevOps Fundamentals for Cloud+

Memory trick

Automation Concepts and Scripting Practices

P.O.W.E.R. for scripting: Python, PowerShell, Other (Bash), Write well, Error handle, Reusable.

DevOps Fundamentals for Cloud+

Exam tip

Automation Concepts and Scripting Practices

The CompTIA Cloud+ exam expects you to understand the *benefits* of automation (efficiency, consistency, cost savings) and common *scripting languages* (Python, PowerShell, Bash) and their use cases, not necessarily to write complex scripts. Look for questions about 'reducing manual effort' or 'ensuring repeatability'.

DevOps Fundamentals for Cloud+

Common mistake

Automation Concepts and Scripting Practices

Hardcoding sensitive credentials directly into scripts, leading to security vulnerabilities.

DevOps Fundamentals for Cloud+

Common mistake

Automation Concepts and Scripting Practices

Not using version control for scripts, making collaboration difficult and changes hard to track.

DevOps Fundamentals for Cloud+

Common mistake

Automation Concepts and Scripting Practices

Neglecting error handling, causing scripts to crash unexpectedly without informative messages.

DevOps Fundamentals for Cloud+

Key term

DevOps

Practices combining Dev and Ops for faster, higher-quality software delivery.

DevOps Fundamentals for Cloud+

Key term

CALMS

Acronym for DevOps principles: Culture, Automation, Lean, Measurement, Sharing.

DevOps Fundamentals for Cloud+

Key term

DevSecOps

Integrating security practices throughout the entire DevOps pipeline.

DevOps Fundamentals for Cloud+

Key term

Cloud-Native

Applications designed to leverage cloud computing benefits, often with microservices.

DevOps Fundamentals for Cloud+

Memory trick

Integrating DevOps into Cloud Operations

To remember CALMS: 'Culture Always Leads to More Success.'

DevOps Fundamentals for Cloud+

Exam tip

Integrating DevOps into Cloud Operations

The CompTIA Cloud+ exam expects you to understand DevOps as a methodology for improving cloud service delivery, focusing on automation, collaboration, and continuous processes. Key terms like CI/CD, IaC, and the benefits of faster time-to-market are critical.

DevOps Fundamentals for Cloud+

Common mistake

Integrating DevOps into Cloud Operations

Underestimating the cultural shift required for DevOps adoption.

DevOps Fundamentals for Cloud+

Common mistake

Integrating DevOps into Cloud Operations

Focusing only on tools without addressing process changes and collaboration.

DevOps Fundamentals for Cloud+

Common mistake

Integrating DevOps into Cloud Operations

Ignoring security or compliance until late in the development cycle.

DevOps Fundamentals for Cloud+

Key term

Troubleshooting Methodology

A systematic, structured approach to diagnosing and resolving technical problems.

Cloud Troubleshooting Techniques

Key term

Root Cause Analysis

The process of identifying the fundamental reason for a problem, not just its symptoms.

Cloud Troubleshooting Techniques

Key term

Hypothesis

A proposed explanation for a phenomenon that can be tested.

Cloud Troubleshooting Techniques

Key term

Verification

Confirming that a problem has been fully resolved and no new issues exist.

Cloud Troubleshooting Techniques

Key term

Documentation

Recording problem details, actions taken, and outcomes for future reference.

Cloud Troubleshooting Techniques

Key term

Preventative Measures

Steps taken to avoid the recurrence of a problem after it has been resolved.

Cloud Troubleshooting Techniques

Key term

Symptom

An observable sign of a problem, not necessarily the underlying cause.

Cloud Troubleshooting Techniques

Memory trick

Cloud Troubleshooting Methodology

Imagine a detective: 'I Think To Plan I'll Very Diligently.' (Identify, Theory, Test, Plan, Implement, Verify, Document)

Cloud Troubleshooting Techniques

Exam tip

Cloud Troubleshooting Methodology

The CompTIA Cloud+ exam expects you to know the six-step troubleshooting methodology (Identify, Theory, Test, Plan, Implement, Verify/Document) and apply it to cloud-specific scenarios. Pay attention to the order and purpose of each step.

Cloud Troubleshooting Techniques

Common mistake

Cloud Troubleshooting Methodology

Jumping directly to a solution without fully understanding the problem or testing a theory.

Cloud Troubleshooting Techniques

Common mistake

Cloud Troubleshooting Methodology

Making multiple changes at once, making it impossible to identify which change fixed or broke something.

Cloud Troubleshooting Techniques

Common mistake

Cloud Troubleshooting Methodology

Failing to document the troubleshooting process, leading to repeated efforts for similar issues.

Cloud Troubleshooting Techniques

Key term

Service Quotas

Limits on resources or operations imposed by cloud providers.

Cloud Troubleshooting Techniques

Key term

NACL (Network Access Control List)

A stateless firewall controlling traffic at the subnet level.

Cloud Troubleshooting Techniques

Key term

VPC Routing Table

Defines rules for how network traffic is directed within a Virtual Private Cloud.

Cloud Troubleshooting Techniques

Key term

VPC Flow Logs

Records of IP traffic to and from network interfaces in a VPC.

Cloud Troubleshooting Techniques

Key term

DNS Resolution

The process of translating domain names into IP addresses.

Cloud Troubleshooting Techniques

Key term

Deployment Template

A declarative file defining cloud resources to be provisioned.

Cloud Troubleshooting Techniques

Memory trick

Diagnosing Deployment and Connectivity Issues

For network checks, remember 'DNS-F-R': DNS, Security Groups/NACLs, Firewall (implied by SG/NACLs), Routing Tables. This covers the main network components.

Cloud Troubleshooting Techniques

Exam tip

Diagnosing Deployment and Connectivity Issues

The CompTIA Cloud+ exam expects you to differentiate between infrastructure-related and application-related issues. Look for keywords like 'instance not reachable' (infrastructure) versus 'application error in logs' (application).

Cloud Troubleshooting Techniques

Common mistake

Diagnosing Deployment and Connectivity Issues

Overlooking cloud provider service quotas as a cause for deployment failures.

Cloud Troubleshooting Techniques

Common mistake

Diagnosing Deployment and Connectivity Issues

Forgetting to check both security groups and NACLs when troubleshooting network connectivity.

Cloud Troubleshooting Techniques

Common mistake

Diagnosing Deployment and Connectivity Issues

Jumping straight to application code debugging before verifying basic infrastructure reachability.

Cloud Troubleshooting Techniques

Key term

Bottleneck

A point of congestion in a system that limits overall performance.

Cloud Troubleshooting Techniques

Key term

Latency

The delay before a transfer of data begins following an instruction.

Cloud Troubleshooting Techniques

Key term

Scaling Up

Increasing the resources (CPU, RAM) of an existing instance.

Cloud Troubleshooting Techniques

Key term

Scaling Out

Adding more instances to distribute the workload.

Cloud Troubleshooting Techniques

Key term

APM

Application Performance Monitoring; tools to monitor application health.

Cloud Troubleshooting Techniques

Memory trick

Resolving Performance Bottlenecks

To remember the common bottleneck types, think 'CRuNch': CPU, RAM, Network, and Chunks (storage).

Cloud Troubleshooting Techniques

Exam tip

Resolving Performance Bottlenecks

The CompTIA Cloud+ exam expects you to differentiate between common resource bottlenecks (CPU, memory, storage, network) and understand the basic strategies for resolving each. Look for keywords like 'high utilization,' 'slow response,' 'latency,' and 'IOPS' in questions.

Cloud Troubleshooting Techniques

Common mistake

Resolving Performance Bottlenecks

Jumping to conclusions and scaling up resources without first identifying the actual bottleneck, leading to increased costs without performance improvement.

Cloud Troubleshooting Techniques

Common mistake

Resolving Performance Bottlenecks

Ignoring application-level issues and only focusing on infrastructure, missing the true root cause of performance problems.

Cloud Troubleshooting Techniques

Common mistake

Resolving Performance Bottlenecks

Failing to monitor performance after implementing a fix, which can lead to recurrence or new issues.

Cloud Troubleshooting Techniques

Key term

IAM

Identity and Access Management; manages who is authenticated and authorized to perform actions.

Cloud Troubleshooting Techniques

Key term

Policy Simulator

A tool to test the effects of IAM policies before deployment.

Cloud Troubleshooting Techniques

Key term

Audit Logs

Records of actions performed in a cloud environment, useful for troubleshooting.

Cloud Troubleshooting Techniques

Key term

Resource-Based Policy

Policy attached directly to a resource, defining who can access it.

Cloud Troubleshooting Techniques

Key term

Explicit Deny

A policy statement that specifically forbids an action, often overriding allows.

Cloud Troubleshooting Techniques

Memory trick

Fixing Security and Permission Problems

To remember the troubleshooting steps for permissions, think 'G.A.P.S. N.I.C.E.': Gather details, Audit logs, Policy simulators, Security groups, Network access, IAM policies, Confirm access, Evaluate regularly.

Cloud Troubleshooting Techniques

Exam tip

Fixing Security and Permission Problems

The exam often tests your understanding of the shared responsibility model and the principle of least privilege. Keywords to spot include 'who is responsible for...' or scenarios where a user has 'too many' or 'too few' permissions. Remember, the customer is always responsible for their data's security in the cloud.

Cloud Troubleshooting Techniques

Common mistake

Fixing Security and Permission Problems

Forgetting to check network security groups or firewalls when troubleshooting 'access denied' errors, assuming it's purely an IAM issue.

Cloud Troubleshooting Techniques

Common mistake

Fixing Security and Permission Problems

Granting overly broad permissions (e.g., `*` for actions or resources) instead of adhering to the principle of least privilege, creating security risks.

Cloud Troubleshooting Techniques