CompTIA Cloud+ (CV0-004) practice questions
238 free questions with answers and explanations.
- 1.A cloud administrator is tasked with implementing a disaster recovery strategy that ensures minimal data loss for a critical financial application. The application processes transactions continuously, and any data loss could result in significant financial penalties. Which of the following backup and restore strategies would best meet this requirement?Operations
- 2.A cloud architect is designing a new application deployment that requires consistent, immutable environments across development, testing, and production. The architect wants to automate the provisioning of infrastructure resources and ensure that any changes are tracked and can be rolled back if necessary. Which of the following approaches best meets these requirements?Deployment
- 3.A cloud operations team is tasked with ensuring that all cloud resources are properly tagged for cost allocation and inventory management. They need to enforce a policy where every new virtual machine (VM) must have 'Department' and 'Project' tags, and existing untagged VMs must be identified and remediated. Which lifecycle management practice is most relevant for achieving this ongoing compliance?Operations
- 4.A cloud engineer is reviewing an alert for a critical web service that indicates 'High Error Rate (5xx)'. Further investigation shows that the error messages in the application logs are primarily 'HTTP 503 Service Unavailable'. The service runs on auto-scaling groups behind a load balancer. All instances are reporting as healthy to the load balancer, and CPU/memory utilization on the instances is normal. What is the MOST likely cause of the 503 errors?Troubleshooting
- 5.A development team is deploying a new microservices-based application using containers. They need a solution that automates the deployment, scaling, and management of these containerized applications across a cluster of virtual machines. Which cloud service model or technology is best suited for this requirement?Cloud Architecture
- 6.A cloud security engineer is conducting an audit and discovers that several critical S3 buckets (or equivalent object storage) containing sensitive logs are publicly accessible. The bucket policies explicitly deny public access, and there are no public ACLs on the buckets. What is the MOST likely reason for this public accessibility?Troubleshooting
- 7.A development team is implementing a Continuous Integration/Continuous Delivery (CI/CD) pipeline for a new microservices application. They want to ensure that every code change is automatically built, tested, and then deployed to a staging environment for further validation, without manual intervention at each step. Which of the following concepts is MOST relevant to achieving this automation?Deployment
- 8.A cloud security engineer is configuring encryption for a new object storage bucket containing highly confidential data. The organization's policy dictates that only authorized applications, and not human users, should have direct access to the encryption keys. Which IAM mechanism, when combined with encryption-at-rest provided by the cloud provider, would BEST enforce this policy?Security
- 9.A cloud architect is designing a solution for a highly sensitive application that requires the highest level of assurance for encryption key management. The organization's policy dictates that encryption keys must be generated and stored in a FIPS 140-2 Level 3 compliant hardware module, with direct control over key lifecycle operations (generation, import, deletion) and auditability. Which key management approach should the architect recommend?Security
- 10.An e-commerce company is experiencing unpredictable traffic spikes, particularly during seasonal sales events. To ensure continuous availability and optimal performance, they decide to distribute incoming web traffic across multiple identical web servers located in different availability zones. Which networking component is essential for achieving this goal?Cloud Architecture
- 11.A cloud security architect is designing the network security for a multi-tier application within a Virtual Private Cloud (VPC). The architect needs to implement stateless filtering at the subnet level to control inbound and outbound traffic, allowing or denying traffic based on IP addresses and ports, before it reaches the instances. Which security component should be configured?Cloud Architecture
- 12.A cloud operations team is deploying a critical new microservice. The deployment continuously fails with error messages indicating that the service account used by the Kubernetes pods lacks permissions to create resources in a specific cloud provider's object storage bucket. The service account has been correctly configured at the Kubernetes level. What is the MOST likely missing configuration?Troubleshooting
- 13.A pod running inside a Kubernetes cluster crashes due to an unhandled application exception. Without any administrator involvement, the cluster's control plane detects the failure and automatically starts a replacement pod to restore the desired state. Which orchestration capability does this demonstrate?DevOps Fundamentals
- 14.A cloud engineer needs to configure proactive alerting for a critical application's web server fleet. The goal is to be notified if the average CPU utilization of the fleet exceeds 80% for more than 5 consecutive minutes, to allow time to scale out before performance degrades significantly. Which alerting configuration parameter is crucial for preventing 'alert fatigue' from transient spikes while ensuring timely notification of sustained issues?Operations
- 15.A cloud architect is designing a new microservices-based application that requires stateless compute components which can scale rapidly and independently based on demand. The development team prefers to focus solely on writing code without managing servers, operating systems, or runtime environments. Which cloud service model best fits these requirements?Cloud Architecture
- 16.A cloud engineer selects a configuration management tool that connects to managed servers over SSH and pushes configuration changes without requiring any persistent software to be installed on those servers. Which type of configuration management architecture is being used?DevOps Fundamentals
- 17.A cloud architect is designing a new application deployment that requires dynamic scaling based on demand. The application's components are stateless and can be easily replicated. Which provisioning strategy would be most suitable to ensure high availability and cost-effectiveness?Deployment
- 18.A cloud administrator is implementing a new security policy that mandates all virtual machines (VMs) must have a specific set of security agents installed and configured. This needs to be applied to both existing VMs and any new VMs provisioned in the future. Which lifecycle management tool or concept would best facilitate this consistent and automated deployment?Operations
- 19.A cloud engineer is configuring monitoring for a newly deployed web application. The application consists of multiple microservices running in containers. The team needs to track HTTP request rates, error rates, and latency for each microservice, as well as overall container resource utilization (CPU, memory). Which type of monitoring is primarily being described?Operations
- 20.A systems administrator runs the same configuration management playbook against a server multiple times. Each execution produces the same end result and causes no errors or unintended changes, even if the server already matches the desired configuration. Which principle does this describe?DevOps Fundamentals
- 21.A cloud engineer is troubleshooting a multi-tier application where the web tier instances are unable to connect to the database tier instances. Both tiers are in the same Virtual Private Cloud (VPC) but in different subnets. Pinging between instances in the same subnet works, but pinging across subnets fails. Security groups are configured to allow traffic between the respective tiers. What is the MOST likely cause of this connectivity issue?Troubleshooting
- 22.A cloud operations team is investigating a severe performance degradation in a production web application. Monitoring metrics show a sudden and sustained drop in database connection pool availability, despite the database server itself showing normal CPU and memory utilization. Application logs are filled with 'connection refused' errors. Which of the following is the MOST likely cause of this issue?Operations
- 23.A company plans to migrate an existing application to the cloud. The current application is tightly coupled and runs on a single server, making it difficult to scale. The company wants to re-architect the application to use cloud-native services, such as serverless functions and managed databases, to improve scalability, resilience, and reduce operational overhead. Which migration strategy is most appropriate for this scenario?Deployment
- 24.A cloud administrator is configuring access to a highly sensitive database containing customer financial records. The database is hosted in a public cloud environment. To minimize the attack surface and ensure that only authorized services within the same virtual network can access the database, which security measure should be implemented?Security
- 25.A cloud administrator is configuring monitoring for a new batch processing application. The application processes large datasets nightly and is critical for business operations. The administrator needs to be alerted if the application fails to start or complete its processing within a predefined time window of 4 hours. Which type of alert trigger would be most suitable for this scenario?Operations
- 26.A cloud administrator needs to ensure that a critical application remains available during maintenance events or unexpected outages within a single cloud region. The application's virtual machines should automatically restart on healthy hardware if the underlying physical server fails. Which high availability strategy is being described?Cloud Architecture
- 27.A cloud architect is troubleshooting a highly available database cluster deployed across multiple availability zones. Users are reporting occasional read timeouts, especially during peak load. Monitoring shows that the primary database instance's CPU utilization is consistently high (90%+), while replica instances are underutilized. The application is configured to send all write operations to the primary and distribute read operations across replicas. What is the MOST likely performance bottleneck?Troubleshooting
- 28.A cloud engineer is troubleshooting an application that intermittently fails to connect to an external third-party API. The application is running in a private subnet and uses a NAT Gateway to access the internet. Network flow logs show successful connections to other external services, but repeated connection timeouts to this specific API endpoint. What is the MOST likely cause?Troubleshooting
- 29.A company is migrating a legacy application to the cloud. The application has strict CPU core licensing requirements that mandate a specific number of physical CPU cores per application instance. Which cloud compute model is most suitable for this scenario?Cloud Architecture
- 30.A cloud engineer is configuring a highly available and fault-tolerant architecture for a mission-critical application. The application needs to withstand the failure of an entire availability zone within a region without significant downtime. Which approach ensures that the application's compute resources are distributed and can continue operating if one availability zone becomes unavailable?Cloud Architecture
- 31.A cloud architect is designing a solution for an application that requires extremely low latency and high throughput for its database. The database is frequently accessed and critical for real-time operations. To meet these performance requirements, which storage optimization strategy should be prioritized?Operations
- 32.A cloud administrator is unable to access a newly deployed Linux virtual machine (VM) via SSH. The VM is in a private subnet, and a NAT Gateway is configured in a public subnet for outbound internet access. The security group associated with the VM allows inbound SSH (port 22) from the administrator's IP address. A bastion host is set up in the public subnet, and the administrator can successfully SSH into the bastion host. What is the MOST likely reason for the SSH failure to the private VM?Troubleshooting
- 33.A cloud engineer is trying to deploy a new virtual machine (VM) from a custom image in a specific subnet. The deployment consistently fails with an error indicating 'Insufficient IP addresses in subnet'. The subnet currently has 20 free IP addresses, and the VM requires only one. What is the MOST likely reason for this deployment failure?Troubleshooting
- 34.Two developers each modify the same lines of the same file in separate branches. When one developer attempts to merge their branch into the main branch after the other's change was already merged, Git stops and reports that it cannot automatically combine the changes. What has occurred?DevOps Fundamentals
- 35.A cloud security engineer is implementing a new customer-facing application that processes sensitive personal identifiable information (PII). The application uses a microservices architecture deployed on Kubernetes. To ensure that communication between microservices is encrypted and authenticated, and to enforce fine-grained authorization policies, which solution should the engineer implement?Security
- 36.A company is implementing a shared responsibility model for its cloud services. They are using a Platform as a Service (PaaS) offering for their application development. According to the shared responsibility model, which of the following is primarily the cloud provider's responsibility in this scenario?Cloud Architecture
- 37.A cloud administrator is configuring an auto-scaling group for a stateless web application. The application experiences predictable traffic spikes every weekday morning between 08:00 and 09:00 UTC and requires 10 instances during this period, but only 2 instances during off-peak hours. Which scaling configuration should be implemented to efficiently manage costs and performance?Operations
- 38.A company is implementing a new cloud application that requires strong authentication for privileged users. The security team wants to ensure that even if a user's password is compromised, access to critical resources remains protected. Which authentication mechanism, when combined with a strong password, provides the MOST effective additional layer of security?Security
- 39.A cloud engineer is designing a highly available architecture for a web application. The application needs to distribute incoming traffic across multiple instances in different Availability Zones within a region. Which networking component should be deployed to achieve this?Cloud Architecture
- 40.A cloud engineer is deploying a highly available application that requires its components to be distributed across multiple physical locations within a single cloud region to withstand localized failures. This ensures that if one data center goes offline, the application remains operational. Which cloud concept is being leveraged to achieve this resilience?Deployment
- 41.A cloud administrator is tasked with deploying a highly available application that spans across multiple availability zones within a region. The application's web tier consists of identical virtual machines. Which network component is responsible for distributing incoming traffic evenly across these virtual machines and automatically rerouting traffic away from unhealthy instances?Deployment
- 42.A cloud administrator is configuring an identity and access management (IAM) policy for a new cloud storage bucket. The policy must grant a specific development team read-only access to a particular folder within the bucket, while denying them any write or delete permissions. Other teams should have no access to this folder. Which IAM policy construct should the administrator use to achieve this granular control?Security
- 43.A cloud operations team is investigating performance degradation in a microservices-based application. They suspect that one of the underlying containers is consuming excessive resources but are unable to pinpoint which one using traditional host-level monitoring. Which of the following tools or techniques would be most effective for diagnosing this issue?Operations
- 44.A cloud engineer is investigating an application that allows users to upload large files to an object storage bucket. Users are reporting occasional 'Access Denied' errors during the upload process, even though the IAM policy for the application's service account explicitly grants `s3:PutObject` and `s3:GetObject` permissions to the target bucket. The bucket also has a policy that denies uploads of objects larger than 5GB. What is the MOST likely cause of the 'Access Denied' errors?Troubleshooting
- 45.A cloud administrator is designing a cost-effective storage solution for infrequently accessed log files that must be retained for compliance reasons for seven years. These logs are rarely needed after 90 days but must be retrievable within a few hours if an audit occurs. Which storage tier provides the best balance of cost and retrieval requirements?Cloud Architecture
- 46.A cloud engineer is tasked with deploying a new web application that requires high availability and scalability. The application will serve static content from a content delivery network (CDN) and dynamic content from a fleet of web servers behind a load balancer. Which type of storage should be used for the static content to ensure optimal performance and cost-effectiveness for the CDN?Deployment
- 47.A cloud engineer is deploying a new service that requires a highly available and scalable block storage solution for virtual machines. The storage needs to be directly attached to the VMs and provide low-latency access for I/O-intensive workloads. Which storage deployment option should the engineer choose?Deployment
- 48.A cloud engineer is deploying a new web application that requires high-performance, low-latency storage for its database. The database will be hosted on a virtual machine and needs to support frequent read/write operations with guaranteed IOPS. Which storage type is best suited for this requirement?Deployment
- 49.A cloud engineer needs to design a highly available architecture for a web application that experiences varying traffic loads. The solution must automatically distribute incoming requests across multiple backend servers and seamlessly handle server failures without manual intervention. Which component is essential for meeting these requirements?Cloud Architecture
- 50.A cloud architect is designing a highly available and fault-tolerant web application that needs to distribute incoming traffic across multiple instances in different availability zones. The solution must also provide SSL/TLS termination to offload encryption/decryption tasks from the web servers. Which component should the architect implement?Cloud Architecture