CompTIA Cloud+ (CV0-004) practice questions
238 free questions with answers and explanations.
- 51.A cloud administrator deploys a new application version to a fully separate, identical production environment. After validating the new environment, traffic is switched over instantly, and if problems occur, traffic can be switched back immediately. Which deployment strategy is being used?DevOps Fundamentals
- 52.A cloud security architect is designing a new logging solution for a highly regulated environment. All logs must be immutable and tamper-proof to meet compliance requirements. Additionally, access to these logs must be restricted to specific audit teams and retained for a minimum of seven years. Which combination of cloud storage features and access controls best meets these requirements?Security
- 53.A cloud administrator is designing a highly available architecture for a stateful application that requires synchronous replication between instances to ensure zero data loss (RPO=0) in the event of an instance failure. The application is deployed within a single AWS region. Which deployment strategy should be chosen?Cloud Architecture
- 54.A cloud security engineer is conducting a security audit of an application running on a public cloud provider. During the audit, they discover that an S3 bucket containing application logs is configured with a public read/write ACL, allowing anonymous users to upload and download files. This directly violates the company's data privacy and security policies. Which compliance standard or framework is MOST directly violated by this configuration?Security
- 55.A cloud architect is designing a solution for deploying a complex, multi-tier application that consists of several virtual machines, databases, and network configurations. The architect wants to ensure that the entire infrastructure for the application can be deployed consistently and repeatedly across different environments (development, staging, production) with minimal manual intervention. Which approach is MOST suitable for achieving this goal?Deployment
- 56.A development team is implementing a Continuous Integration/Continuous Delivery (CI/CD) pipeline for a cloud-native application. They want to ensure that every code change triggers an automated process to build, test, and deploy the application to a staging environment. Which component is responsible for orchestrating these automated steps?Deployment
- 57.A development team is implementing a new microservices architecture in a public cloud. Each microservice needs to communicate with specific other microservices while restricting access from the internet and other unauthorized internal services. The team wants to define granular, stateful rules to control inbound and outbound traffic for each individual microservice instance. Which network security construct should they primarily use?Deployment
- 58.A cloud engineer is deploying a new web application using a container orchestration platform. The application consists of a front-end container, a back-end API container, and a database container. For high availability, multiple instances of each container type need to run. The engineer wants to define the deployment, scaling, and networking for all these containers in a single, declarative file. Which tool or concept is BEST suited for this?Deployment
- 59.A cloud operations team is investigating intermittent performance issues with a serverless function that processes customer orders. They suspect that the function is occasionally taking too long to execute due to external API calls. To diagnose this, they need to trace the execution path and timing of individual requests through the serverless function and any dependent services. Which logging and monitoring feature would be most beneficial for this task?Operations
- 60.A cloud administrator is investigating a sudden increase in latency and packet loss between virtual machines (VMs) located in different subnets within the same Virtual Private Cloud (VPC). Network monitoring tools show no spikes in CPU or memory utilization on the VMs themselves. What is the MOST likely cause of this issue?Troubleshooting
- 61.A cloud operations team is investigating an intermittent issue where their containerized microservices randomly experience high latency and connection timeouts, but CPU and memory metrics show normal utilization. The team suspects an issue with inter-service communication. Which monitoring tool or technique would be most effective for diagnosing this problem?Operations
- 62.A development team wants to avoid long-lived feature branches and instead have all developers commit small, frequent changes directly into the main branch, often multiple times per day, keeping any temporary branches alive for only a few hours. Which branching practice does this describe?DevOps Fundamentals
- 63.A cloud administrator is tasked with deploying a complex, multi-tier application environment that includes multiple virtual machines, databases, load balancers, and network configurations. The deployment needs to be repeatable, consistent, and version-controlled. Which approach allows defining all these resources in a declarative format that can be automatically provisioned?Deployment
- 64.A cloud administrator is investigating slow application performance during peak hours. Monitoring shows that the database server's disk I/O utilization is consistently at 100%, and the application logs frequently report 'database connection timeout' errors. The database server has sufficient CPU and memory. What is the MOST effective immediate action to mitigate this performance issue?Troubleshooting
- 65.A cloud administrator receives an alert indicating that a critical database server is running low on disk space. Upon investigation, it's discovered that detailed audit logs, which are configured to never expire, are consuming the majority of the storage. These logs are legally required to be retained for seven years but are not frequently accessed after the first 90 days. Which optimization strategy should the administrator implement to address the immediate disk space issue while meeting compliance requirements?Operations
- 66.A cloud security engineer needs to implement strict network segmentation for a highly sensitive application. The application consists of a web tier, an application tier, and a database tier, each deployed in its own subnet within a VPC. Traffic must only flow in specific directions (e.g., web to app, app to DB). Which network security construct is MOST effective for enforcing this granular, stateful traffic flow between subnets?Troubleshooting
- 67.A technician wants to define an organization's virtual machines, networks, and storage using text-based configuration files stored in version control, so that identical cloud environments can be automatically and repeatedly provisioned. Which practice is being described?DevOps Fundamentals
- 68.A cloud engineer is designing a geographically dispersed application that requires extremely low Recovery Point Objective (RPO) and Recovery Time Objective (RTO) in the event of a regional outage. Data consistency across regions is paramount. Which disaster recovery strategy would best meet these stringent requirements?Cloud Architecture
- 69.Six months after deploying infrastructure using an infrastructure-as-code tool, an administrator suspects that engineers made manual changes directly in the cloud console outside of the normal workflow. Which action should the administrator take first to identify discrepancies between the deployed resources and the code definitions?DevOps Fundamentals
- 70.A cloud security engineer is reviewing the access control policies for an object storage bucket containing sensitive customer data. The current policy grants 'Everyone' read access. The engineer needs to restrict access so that only specific authorized applications, running on designated virtual machines, can retrieve data from this bucket, while adhering to the principle of least privilege. Which access control mechanism should be implemented?Operations
- 71.A cloud operations team is reviewing their cloud expenditure and identifies that a significant portion of their compute costs comes from idle virtual machines (VMs) during off-peak hours. The applications running on these VMs can tolerate some downtime for startup. Which optimization strategy would provide the most immediate and significant cost savings?Operations
- 72.A cloud administrator is investigating why an auto-scaling group for a stateless web application is not scaling out during high CPU utilization spikes. The auto-scaling policy is configured to add an instance when average CPU utilization exceeds 70% for 5 minutes. Monitoring shows that average CPU utilization has been consistently above 85% for the past 10 minutes. The auto-scaling group's desired capacity is 2, and the maximum capacity is 5. The current number of running instances is 2. What is the MOST likely reason the auto-scaling group is not scaling out?Troubleshooting
- 73.A cloud security engineer needs to ensure that all data stored in an Amazon S3 bucket is encrypted at rest. The company's compliance policy mandates that encryption keys must be managed entirely by the cloud provider, with no customer involvement in key generation, storage, or rotation. Which S3 encryption option meets this requirement?Security
- 74.A cloud operations team is preparing to deploy a critical new application into production. Before the full production rollout, they want to perform a deployment to a small subset of real users to gather feedback and monitor for issues, while the majority of users continue to use the old version. If issues arise, they want to quickly revert to the old version without impacting the main user base. Which deployment strategy does this describe?Deployment
- 75.A cloud administrator is configuring an identity provider (IdP) for a new Software-as-a-Service (SaaS) application. The goal is to allow users to sign in once to their corporate network and then seamlessly access the SaaS application without re-entering credentials. Which protocol is MOST commonly used to achieve this single sign-on (SSO) functionality between an IdP and a service provider (SP)?Security
- 76.A cloud engineer is designing a network for a multi-tier application in a public cloud. The application requires strict isolation between the web, application, and database tiers. Each tier must reside in its own subnet, and communication between tiers must be explicitly controlled. Which network component is primarily used to achieve this logical segmentation and control traffic flow between subnets?Deployment
- 77.A financial institution is deploying a critical database in a public cloud. Due to stringent regulatory requirements (e.g., PCI DSS), all network traffic to and from this database must be inspected for malicious content and potential data exfiltration. The institution requires deep packet inspection and intrusion prevention capabilities. Which cloud networking security service is BEST suited for this purpose?Security
- 78.A cloud security architect is designing an incident response plan for a critical application hosted in a public cloud. The initial detection phase has identified a potential compromise. The next immediate step is to limit the scope of the incident and prevent further damage. Which phase of the incident response process does this describe?Security
- 79.A software development company is adopting a modern development approach where applications are packaged with all their dependencies into isolated user-space environments. This allows developers to ensure that the application runs consistently across different computing environments, from development to production. Which cloud computing concept are they implementing?Cloud Architecture
- 80.A cloud administrator is tasked with optimizing cloud costs for an application that has predictable, long-term resource requirements. The application runs continuously and its compute usage does not fluctuate significantly. Which pricing model would provide the most cost-effective solution for these compute resources?Cloud Architecture
- 81.A cloud engineer is configuring a Virtual Private Cloud (VPC) for a multi-tier application. The web servers need to be accessible from the internet, while the database servers must remain private and only accessible by the web servers. Which networking component is used to connect the public-facing subnets to the internet and allow inbound internet traffic?Cloud Architecture
- 82.A cloud architect is designing a new application that will process sensitive financial data and requires strict isolation from other tenants. The application also needs to leverage existing virtualization management tools. Which cloud deployment model best meets these requirements?Cloud Architecture
- 83.A company is planning to deploy a new application in a cloud environment. Before going live, the application needs to undergo rigorous testing to ensure it meets performance, scalability, and security requirements. The testing team wants to simulate high user load, test disaster recovery procedures, and verify compliance with security policies. Which phase of the deployment process are these activities part of?Deployment
- 84.A company wants to release a new checkout feature to only 5% of production users first, closely monitor error rates and performance, and gradually increase exposure if metrics remain healthy. Which deployment strategy best describes this approach?DevOps Fundamentals
- 85.A compliance auditor reports that a critical database containing sensitive customer data is accessible from the public internet, despite the cloud administrator having configured a security group to only allow traffic from the application's private subnet. Further investigation reveals that the database instance also has a public IP address assigned. What is the MOST likely cause of this security vulnerability?Troubleshooting
- 86.A cloud engineer is setting up a new virtual network in a public cloud. The requirement is to create a private subnet that hosts backend application servers and a public subnet for web servers. The backend servers should only be accessible from the web servers and should not have direct internet access, while the web servers need to be accessible from the internet. Which network component is essential to enable outbound internet access for resources in the private subnet without allowing inbound connections from the internet?Deployment
- 87.A cloud architect is designing a new highly available web application. During a load test, the database tier, consisting of a managed relational database service, experiences significant read replica lag and occasional primary instance connection timeouts, despite having ample CPU and memory resources. The application is write-heavy. What is the MOST effective strategy to mitigate these performance issues?Troubleshooting
- 88.A cloud administrator is setting up a new virtual network for a highly sensitive application. The requirement is to ensure that no internet traffic, neither inbound nor outbound, can ever reach the application's subnet. However, the application still needs to access some internal cloud provider services (e.g., object storage, database service) within the same region. Which of the following network configurations would BEST achieve this requirement?Troubleshooting
- 89.A cloud administrator is configuring a new Virtual Private Cloud (VPC) peering connection between two VPCs in different regions to allow direct communication between services. After establishing the peering connection, instances in VPC A can ping instances in VPC B, but instances in VPC B cannot ping instances in VPC A. Both VPCs have correctly configured route tables pointing to the peering connection for the remote CIDR blocks, and security groups allow ICMP traffic. What is the MOST likely cause of the one-way communication issue?Troubleshooting
- 90.A cloud security engineer needs to establish a secure connection from an on-premises data center to a public cloud VPC to access private resources. The connection must ensure data confidentiality and integrity during transit. Which of the following solutions is most appropriate for this requirement?Security
- 91.A cloud architect designs a server fleet so that once instances are deployed, they are never patched, reconfigured, or logged into directly. Any required update is implemented by building a new machine image with the change baked in and replacing the running instances entirely. Which principle is being applied?DevOps Fundamentals
- 92.A cloud security team is investigating a potential compromise. They discovered suspicious API calls originating from an EC2 instance that appear to be exfiltrating data to an external IP address. The instance's security group allows outbound traffic on all ports. The team needs to immediately stop the data exfiltration while preserving the instance's state for forensic analysis. Which of the following is the most appropriate action?Security
- 93.A cloud administrator is configuring a database that requires consistent, low-latency access to data with high IOPS (Input/Output Operations Per Second). The database will be actively used by a critical production application. Which storage tier is most appropriate for this workload?Cloud Architecture
- 94.A financial institution is migrating its core banking application to a cloud environment. Due to stringent regulatory requirements, the application must demonstrate data integrity and non-repudiation for all transactions. Which cryptographic mechanism, when applied to transaction logs, would best satisfy these requirements?Security
- 95.A cloud administrator is tasked with implementing a network security solution that restricts inbound and outbound traffic to specific virtual machines based on predefined rules. The solution must be highly granular and operate at the instance level within a public cloud environment. Which of the following security constructs is MOST appropriate for this requirement?Security
- 96.A cloud operations team is implementing a new monitoring solution. They want to ensure that all critical infrastructure metrics (CPU, memory, disk I/O, network traffic) are collected from all virtual machines and stored in a centralized location for analysis and alerting. Which component of a comprehensive monitoring solution is responsible for collecting this raw data from individual resources?Operations
- 97.A cloud security administrator is auditing the access logs for an object storage bucket containing sensitive customer data. They discover that a specific user account, which should only have read-only access, has successfully performed several 'DeleteObject' operations. The bucket policy explicitly denies 'DeleteObject' to this user. What is the MOST likely reason for this unauthorized action?Troubleshooting
- 98.A company is migrating its on-premises applications to a public cloud. As part of the security architecture, all network traffic between the cloud environment and the internet must be inspected for malicious activity and policy violations before reaching virtual machines. Which cloud security service should be implemented to fulfill this requirement most effectively?Security
- 99.A cloud engineer is designing an automated scaling solution for an e-commerce website that experiences predictable spikes in traffic during holiday seasons. To optimize costs and performance, the engineer wants to ensure that new instances are provisioned in anticipation of the traffic increase, rather than reacting to it. Which scaling strategy should be employed?Operations
- 100.A cloud engineer is designing a new storage solution for an application that processes large volumes of sequential data for analytics. The data needs to be highly durable and accessible, but the application does not require extremely low-latency random I/O. Cost-effectiveness for large datasets is a significant concern. Which storage type is the most appropriate choice?Deployment