CompTIA Cloud+ (CV0-004) practice questions

238 free questions with answers and explanations.

Practice test
  1. 101.A cloud engineer is designing a highly available application architecture. The application stores critical data that must be accessible even if an entire data center fails. The chosen storage solution must offer synchronous replication across multiple geographically distinct regions to ensure zero data loss (RPO = 0) and minimal downtime (RTO close to 0) during a disaster. Which storage tier characteristic is crucial for this requirement?Cloud Architecture
  2. 102.A cloud administrator is performing routine lifecycle management for virtual machines. They have identified several VMs that are no longer actively used, but still consume compute and storage resources. The administrator needs to safely reclaim these resources without impacting any dependent services. What is the most appropriate action to take?Operations
  3. 103.A cloud security specialist is hardening a serverless application that uses AWS Lambda functions and API Gateway. The team needs to ensure that Lambda functions can only be invoked by the specific API Gateway instance associated with the application, preventing unauthorized invocation from other sources or accounts. Which security measure should be implemented?Security
  4. 104.A configuration management tool allows an administrator to specify that a web server package 'must be installed and the service must be running,' without writing the individual step-by-step commands needed to achieve that outcome. Which automation approach does this represent?DevOps Fundamentals
  5. 105.A cloud architect is designing a disaster recovery (DR) strategy for a critical application that requires an Recovery Time Objective (RTO) of less than 15 minutes and a Recovery Point Objective (RPO) of less than 5 minutes. The application runs on virtual machines, utilizes a relational database, and stores user-uploaded content in object storage. Which DR strategy would best meet these stringent requirements while minimizing data loss and downtime?Operations
  6. 106.A cloud administrator is configuring a Virtual Private Cloud (VPC) and needs to define specific rules for inbound and outbound traffic at the subnet level. These rules should be stateless and apply to all instances within the subnet. Which security component should the administrator use?Cloud Architecture
  7. 107.A cloud provider is developing a new service that requires strict isolation between customer data and compute resources at a hardware level to meet stringent regulatory compliance standards. Which cloud deployment model inherently offers the highest degree of physical isolation for compute resources, making it suitable for such requirements?Security
  8. 108.A company is migrating a legacy on-premises application to a public cloud environment. The application is critical, requires minimal downtime, and has complex interdependencies with other on-premises systems that cannot be moved immediately. The migration team decides to gradually move components while maintaining connectivity between the cloud and on-premises environments. Which migration strategy is being employed?Deployment
  9. 109.A cloud administrator is investigating an issue where users are reporting slow response times and occasional timeouts when accessing a web application hosted on multiple virtual machines behind a load balancer. Monitoring shows that CPU utilization on the application VMs is consistently low (under 30%), but network I/O metrics indicate high packet retransmission rates. What is the MOST likely cause of the performance degradation?Troubleshooting
  10. 110.A global enterprise operates in multiple regulated industries, each with unique data residency and compliance requirements. They are planning to deploy a new application that will process sensitive customer data across various cloud regions. The security architect needs to implement a solution that ensures data remains within specific geopolitical boundaries and adheres to local regulations. Which architectural pattern is best suited for addressing these complex data residency and compliance needs?Security
  11. 111.A development team is frequently deploying new features to a critical production environment. To minimize risk and ensure continuous availability during deployments, they want to test new versions with a small subset of real user traffic before rolling out to everyone. Which deployment strategy should be recommended?Operations
  12. 112.A company is migrating a legacy application to the cloud. The application has specific licensing requirements that tie software licenses to physical CPU cores. To comply with these licensing terms in a cloud environment, which compute option should the company choose?Cloud Architecture
  13. 113.A cloud administrator is configuring monitoring for a critical financial application. The application processes transactions that must be completed within 500 milliseconds. If the average transaction time exceeds 400 milliseconds for more than 3 consecutive 1-minute intervals, a high-priority alert must be triggered. Which alerting configuration provides the MOST effective and timely notification for this scenario?Operations
  14. 114.A development team is deploying a new containerized application to a Kubernetes cluster. The pods are consistently failing to start and entering an `ImagePullBackOff` state. The container image exists in a private registry, and the cluster's node instances have network connectivity to the registry. Which of the following is the MOST likely cause of this issue?Troubleshooting
  15. 115.A cloud security team is establishing a baseline for security configurations across their multi-cloud environment. They need to identify deviations from established security policies, such as open storage ports, unencrypted volumes, or unpatched operating systems, to ensure continuous compliance. Which type of security audit is best suited for this ongoing, automated assessment?Security
  16. 116.A company is planning to migrate a large relational database (20TB) from an on-premises data center to a public cloud provider. The database needs to remain online during the migration with minimal performance impact on the source system. After the initial full data transfer, a continuous synchronization mechanism is required to capture ongoing changes until the cutover. Which migration strategy is most appropriate?Deployment
  17. 117.A cloud operations team is reviewing their monthly cloud bill and notices a significant increase in data transfer costs. Upon investigation, they discover that a batch processing job frequently downloads large datasets from an object storage bucket in one region, processes them on virtual machines in a different region, and then uploads the results back to the original object storage bucket. Which optimization strategy should be prioritized to reduce these data transfer costs?Operations
  18. 118.A cloud administrator has deployed a new application that uses a managed caching service (e.g., Redis, Memcached). After deployment, users report that the application frequently shows stale data, even after updates are made in the backend database. The caching service metrics show high cache hit ratios. What is the MOST likely cause of the stale data?Troubleshooting
  19. 119.An online gaming company needs to implement a highly available architecture for its game servers. The solution must ensure that if an entire data center (Availability Zone) goes offline, the game remains accessible to players with minimal disruption. The company wants to leverage multiple geographic regions to achieve this, preferring a setup where one region is fully active and serving traffic, while another region is on standby, ready to take over in case of a regional disaster. What type of disaster recovery strategy is being described?Cloud Architecture
  20. 120.A company is migrating a legacy application to the cloud. This application requires specific, certified hardware configurations and operates under a licensing model that ties software licenses to physical CPU cores. To comply with licensing agreements and ensure performance, which cloud compute model should be recommended?Cloud Architecture
  21. 121.A cloud architect is reviewing the performance of a newly deployed RESTful API service. The service is composed of several serverless functions. Users are reporting occasional slow responses, but individual function logs show fast execution times. The architect suspects that the latency is accumulating between the function calls or due to external dependencies. Which monitoring approach would be most effective in identifying the source of this cumulative latency?Operations
  22. 122.A cloud administrator is tasked with ensuring an application remains operational even if an entire cloud region experiences an outage. The Recovery Time Objective (RTO) for this application is 4 hours, and the Recovery Point Objective (RPO) is 1 hour. Which high availability strategy is most appropriate?Cloud Architecture
  23. 123.A cloud administrator needs to implement a solution that allows multiple Virtual Private Clouds (VPCs) in different regions to communicate with each other and also connect to an on-premises data center through a single, centralized gateway. This solution aims to simplify network topology and management. Which networking component should be used?Cloud Architecture
  24. 124.A global organization is implementing a new cloud-based data analytics platform. Due to strict regulatory requirements in various regions, certain sensitive datasets must be stored and processed exclusively within specific geographic boundaries. The organization also needs to ensure that data access is restricted based on the user's location. Which concept directly addresses these requirements?Security
  25. 125.A cloud architect is designing a solution for storing large volumes of unstructured data, such as images, videos, and log files. The primary requirements are extreme scalability, high durability, and cost-effectiveness for data that is accessed infrequently but needs to be retrieved instantly when requested. Which storage tier is best suited for this scenario?Cloud Architecture
  26. 126.A cloud administrator is designing a highly available architecture for a database. The requirement is to minimize data loss in the event of a regional outage. Which storage replication strategy would best meet this objective?Cloud Architecture
  27. 127.A company is migrating its on-premises applications to a public cloud provider. During the planning phase, the cloud architects identify several legacy applications that are tightly coupled and cannot be easily refactored into microservices. These applications run on specific operating system versions and require significant manual configuration. Which optimization strategy is most suitable for these particular applications in the cloud?Operations
  28. 128.A cloud architect is designing a solution for a highly sensitive application that requires all data at rest to be encrypted. The organization has a strict compliance mandate to maintain full control over the cryptographic keys. Which key management strategy BEST meets this requirement?Security
  29. 129.A cloud security engineer is tasked with securing a new Kubernetes cluster deployed in a public cloud. The requirement is to ensure that all communication between microservices within the cluster is encrypted and authenticated, and that network policies are enforced at the service level, independent of underlying network IP addresses. Which security mechanism is best suited for this purpose?Security
  30. 130.A cloud architect is designing a new application that requires high elasticity and the ability to scale compute resources rapidly up and down based on demand. The application components are stateless and can be easily replicated. Which compute model would best meet these requirements?Cloud Architecture
  31. 131.A cloud engineer is reviewing the continuous integration/continuous delivery (CI/CD) pipeline for a cloud-native application. One stage of the pipeline involves automated testing of the deployed application in a staging environment. The tests include functional validation, performance benchmarks, and security scans. Which phase of the deployment process does this stage primarily fall under?Deployment
  32. 132.A cloud engineer is configuring network connectivity for a Virtual Private Cloud (VPC) to allow resources within the VPC to securely access services on the public internet without having public IP addresses. Which component is essential for this functionality?Cloud Architecture
  33. 133.A cloud security engineer is reviewing the access policies for an AWS S3 bucket that stores highly sensitive customer data. The current policy allows public read access to all objects by default. This configuration poses a significant security risk. To remediate this, the engineer needs to ensure that access is restricted to authenticated users within the company's AWS account only, while preventing any public access. Which action should the engineer take?Security
  34. 134.A cloud security engineer needs to implement a solution that ensures all data at rest in a new object storage bucket is encrypted using keys managed exclusively by the customer, not the cloud provider. The customer requires full control over the key lifecycle, including generation, rotation, and revocation. Which encryption option should the engineer recommend?Security
  35. 135.A cloud operations team needs to automate the deployment of a complex multi-tier application. The application consists of several virtual machines, a managed database, and a load balancer, all configured with specific network settings and security rules. The team wants to ensure that the entire infrastructure stack can be provisioned consistently and repeatedly with minimal manual intervention. Which of the following tools or concepts is best suited for this task?Deployment
  36. 136.A development team reports that their new microservice deployment continuously fails to start in the Kubernetes cluster. The error logs frequently show 'CrashLoopBackOff' and 'ImagePullBackOff' messages. The image name and tag are confirmed to be correct in the deployment manifest. What is the MOST likely cause of this deployment issue?Troubleshooting
  37. 137.A cloud administrator is investigating an issue where users are reporting intermittent access to a critical web application hosted in a public cloud. The application has multiple instances behind a load balancer. Initial checks show that all instances are reporting as healthy. However, logs from the load balancer show frequent connection resets from some client IPs. What is the MOST likely cause of this issue?Troubleshooting
  38. 138.A cloud architect is designing a backup strategy for a mission-critical database that requires a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 4 hours. The database is hosted on a cloud provider's managed database service. Which backup and restore method would best meet these requirements?Operations
  39. 139.A cloud operations team manages a large fleet of virtual machines across multiple cloud providers. They need a centralized system to collect, normalize, and analyze security events and logs from all these disparate sources to detect threats and ensure compliance. Which solution should they implement?Operations
  40. 140.A cloud administrator is tasked with optimizing the storage costs for an archival database that stores historical transaction data. This data is rarely accessed after 90 days but must be retained for 7 years due to regulatory requirements. Performance for retrieval is not critical for data older than 90 days, but cost-efficiency is paramount. Which storage class optimization strategy should the administrator implement?Operations
  41. 141.A cloud security team is reviewing a recent security audit report that highlighted several misconfigured storage buckets, unencrypted databases, and overly permissive IAM roles across multiple cloud accounts. The team needs a solution that can continuously identify these types of misconfigurations and provide actionable remediation guidance. Which security tool or practice addresses this challenge most effectively?Security
  42. 142.A cloud engineer is using a template to deploy a new virtual machine. The template specifies the operating system image, instance type, and network configuration. However, the engineer needs to provide different values for the VM's name and IP address for each deployment. Which feature of templates allows the engineer to customize these values without modifying the template file itself?Deployment
  43. 143.A development team frequently deploys new versions of a web application to a cloud environment. After some deployments, users report intermittent errors and slow response times. The team wants to implement a strategy that allows them to quickly revert to a previous, stable version of the application if a new deployment introduces issues, minimizing downtime and impact. Which deployment strategy best supports this requirement?Operations
  44. 144.A cloud administrator needs to ensure that all newly provisioned virtual machines (VMs) in a specific project automatically comply with corporate security baselines, including specific operating system configurations, software installations, and agent deployments. Manual configuration is prone to errors and does not scale. Which cloud operations practice should be implemented?Operations
  45. 145.After a CI pipeline successfully compiles and tests an application, the resulting versioned binary package must be stored in a centralized, searchable location before it can be pulled for deployment to any environment. Which pipeline component is used for this purpose?DevOps Fundamentals
  46. 146.A cloud administrator is configuring a new Virtual Private Cloud (VPC) and needs to ensure that instances within a private subnet can initiate outbound connections to the internet for updates and patches, but cannot receive unsolicited inbound connections from the internet. Which of the following networking components is essential to achieve this requirement?Cloud Architecture
  47. 147.A development team is implementing a microservices architecture in the cloud. Each microservice needs to communicate with others, and the team wants to ensure that network traffic between services is secure and isolated, even within the same virtual network. Which network deployment strategy should the team implement?Deployment
  48. 148.A cloud engineer is designing a highly available and fault-tolerant architecture for a critical web application. The application needs to distribute incoming traffic across multiple instances in different geographical regions to minimize latency and ensure continuous service even if one region experiences an outage. Which of the following deployment strategies BEST addresses this requirement?Deployment
  49. 149.A financial institution is deploying a new application that requires extremely low-latency access to its database and persistent storage for transactional data. The application experiences consistent, high I/O operations throughout the day. Which storage tier is most appropriate for this requirement?Cloud Architecture
  50. 150.A DevOps engineer needs to mark a specific commit as the official v3.2.0 release so that it can be easily referenced and checked out later, without creating a new line of development. Which Git feature should be used?DevOps Fundamentals