CompTIA Cloud+ (CV0-004) practice questions
238 free questions with answers and explanations.
- 151.A software team commits code to a shared repository multiple times per day. Each commit automatically triggers a build and a suite of automated tests to catch integration errors as early as possible. Which practice does this describe?DevOps Fundamentals
- 152.A cloud architect is designing a solution for storing infrequently accessed archive data that needs to be retained for several years due to regulatory compliance. Retrieval times can be several hours, but cost optimization is a primary concern. Which storage tier is most appropriate?Cloud Architecture
- 153.A cloud engineer is deploying a stateless web application that needs to scale quickly and efficiently based on demand. The application code is packaged with all its dependencies into a lightweight, portable unit. Which compute technology is most suitable for this deployment?Cloud Architecture
- 154.A cloud administrator is tasked with deploying a new web application that requires a database. The application's backend code is written in Python, and it needs to connect to a PostgreSQL database. The administrator wants to use a service that handles all the underlying infrastructure management for both the application runtime and the database, allowing the development team to focus solely on their code. Which cloud service model BEST fits this requirement?Deployment
- 155.A cloud architect is designing a disaster recovery strategy for a critical application that must have near-zero RTO (Recovery Time Objective) and RPO (Recovery Point Objective). The application runs across multiple regions, and data must be continuously synchronized across these regions. Which network deployment strategy is crucial for enabling this level of cross-region data synchronization and application availability?Deployment
- 156.A global enterprise uses a multi-cloud strategy and needs to enforce a consistent security posture across all its cloud environments (AWS, Azure, GCP). The security team requires continuous monitoring for misconfigurations, compliance violations, and security risks, along with automated remediation where possible. Which type of cloud security solution should they implement?Security
- 157.A cloud engineer is designing a new storage solution for an application that processes large volumes of data. The data is initially accessed frequently for a few days, then less frequently for several weeks, and finally rarely, but must be retained for compliance for five years. The engineer wants to optimize costs by automatically moving data between different storage classes based on access patterns. Which storage strategy should be implemented?Deployment
- 158.During a security incident, a cloud forensics team discovers that an attacker gained unauthorized access to a virtual machine by exploiting a vulnerability in a web application. The attacker then created new IAM users and roles to escalate privileges and access sensitive data in a storage bucket. Which of the following incident response steps should be prioritized immediately after containment to prevent further damage and remove the attacker's presence?Security
- 159.A cloud engineer is designing a new cloud environment for a financial institution. Due to stringent regulatory compliance requirements (e.g., PCI DSS, HIPAA), all network traffic, including internal communication between virtual machines, must be inspected and logged. Additionally, the institution requires the ability to enforce granular, layer 7 security policies for web applications. Which network security component is best suited for both deep packet inspection and application-level filtering?Deployment
- 160.A company is migrating a legacy application to the cloud. The application is tightly coupled to the underlying operating system and has specific licensing requirements that mandate dedicated physical hardware. Which compute model would satisfy these constraints while still leveraging cloud infrastructure?Cloud Architecture
- 161.A cloud security engineer is tasked with ensuring that all cloud resources are running the latest security patches. The organization uses a hybrid cloud environment with a mix of Linux and Windows virtual machines, containers, and serverless functions. What is the MOST efficient lifecycle management approach for consistently applying security patches across this diverse environment?Operations
- 162.A cloud engineer is setting up a new Virtual Private Cloud (VPC) for an application that needs to securely connect to an external on-premises data center. This connection requires a dedicated, private network link to ensure consistent network performance and enhanced security, bypassing the public internet. Which VPC connectivity option should be chosen?Cloud Architecture
- 163.A large enterprise is adopting a multi-cloud strategy and needs a centralized vulnerability management solution that can scan and report on vulnerabilities across different cloud providers' environments (e.g., AWS, Azure, GCP). The solution must also integrate with existing ticketing systems for remediation tracking. Which characteristic is MOST important for such a solution?Security
- 164.A company is migrating a critical legacy application to the cloud. The application has a large, monolithic architecture and cannot be easily broken down into smaller services. Downtime must be minimized, and the application's functionality must remain identical post-migration. Which migration strategy is most appropriate for this scenario?Deployment
- 165.A cloud engineer is reviewing an alert for a critical web service that indicates 'High Error Rate (HTTP 5xx)'. Further investigation reveals that the 503 Service Unavailable errors are occurring intermittently, often following periods of high traffic. The application is deployed behind a load balancer and uses an auto-scaling group. What is the MOST likely root cause?Troubleshooting
- 166.An organization's configuration management server initiates SSH connections to managed nodes and immediately pushes new configuration changes out to them whenever an administrator triggers a run, rather than waiting for the nodes to check in on their own schedule. Which configuration management model is being used?DevOps Fundamentals
- 167.A cloud security administrator needs to ensure that all virtual machines (VMs) deployed in their environment automatically receive the latest security patches within a defined maintenance window. The current process involves manual updates, which is time-consuming and error-prone. Which cloud operations practice should the administrator implement to address this requirement?Operations
- 168.A cloud security engineer needs to implement a solution that continuously monitors the cloud environment for misconfigurations, vulnerabilities, and compliance violations against predefined baselines. The solution should also provide automated remediation capabilities where possible. Which type of cloud security tool is BEST suited for this task?Security
- 169.A cloud administrator observes consistently high CPU utilization (90%+) on several virtual machines (VMs) during peak business hours. These VMs host a critical e-commerce application that experiences slow response times during these periods. The administrator needs to implement a solution that automatically adjusts resources to meet demand and prevent performance degradation without manual intervention. Which of the following scaling strategies should the administrator implement?Operations
- 170.A company is migrating its on-premises applications to a public cloud environment. The security team is concerned about ensuring that identity and access management (IAM) policies are consistently applied across both environments and that user provisioning/deprovisioning is automated. Which IAM solution would BEST address these concerns?Security
- 171.A cloud operations team is preparing to deploy a new version of their core application. To minimize risk, they want to gradually roll out the new version to a small subset of users, observe its performance, and then progressively expand the rollout to the entire user base. If any issues arise, they need the ability to quickly revert to the previous stable version. Which deployment strategy best fits these requirements?Deployment
- 172.A cloud security architect is tasked with ensuring that all sensitive data stored in a multi-region object storage solution remains accessible only from specific IP ranges belonging to the company's corporate network, regardless of the region. This must be enforced at the network perimeter before data access attempts reach the storage service itself. Which security control is most effective for this requirement?Security
- 173.A cloud administrator is tasked with deploying a new application that requires a database. The administrator needs to select a provisioning method that allows for rapid deployment, scaling, and automated patching, without requiring direct access to the underlying operating system of the database server. Which provisioning method should be chosen?Deployment
- 174.A cloud security architect is designing a key management strategy for a multi-tenant SaaS application that stores data for various customers. Each customer's data must be encrypted using a unique key, and the application needs to perform cryptographic operations without direct access to the master keys. Which key management service feature would best meet these requirements?Security
- 175.A financial institution is migrating its on-premises data center to a public cloud. Due to stringent regulatory compliance requirements, the institution must maintain strict control over its data and infrastructure, and cannot tolerate data residing in a shared multi-tenant environment. What cloud deployment model would best suit their needs?Operations
- 176.A cloud security architect is integrating a third-party SaaS application with the company's internal identity provider (IdP). The goal is to allow users to log in to the SaaS application using their existing corporate credentials without creating new accounts, while also enabling centralized access management and de-provisioning. Which protocol is most commonly used to achieve this single sign-on (SSO) and identity federation securely?Security
- 177.A cloud engineer is deploying a new web application and needs to ensure that the application's resources (compute, storage, network) are provisioned in a way that allows for easy rollback to a previous known good state if a deployment fails. The current deployment model involves creating new resources for each version. Which provisioning concept is crucial for achieving this rollback capability efficiently?Deployment
- 178.A cloud administrator needs to implement a solution that allows multiple Virtual Private Clouds (VPCs) to communicate with each other and with on-premises networks through a central hub. This design should simplify network management and scale efficiently. Which networking component is best suited for this requirement?Cloud Architecture
- 179.A development team wants the ability to instantly disable a newly released feature for all users if problems occur, without redeploying code or performing a full application rollback. Which technique should be implemented in the CI/CD pipeline?DevOps Fundamentals
- 180.A Kubernetes Horizontal Pod Autoscaler (HPA) is configured with a target CPU utilization of 50%. There are currently 4 replicas running, and the HPA measures the average CPU utilization across those pods at 80%. Using the formula desiredReplicas = ceil(currentReplicas × (currentMetricValue ÷ desiredMetricValue)), how many replicas will the HPA scale the deployment to?DevOps Fundamentals
- 181.A company is migrating its on-premises database to a cloud environment. The database contains highly sensitive customer financial data that must comply with strict regulatory requirements regarding data residency and data isolation. Which cloud deployment model would be most appropriate to meet these specific compliance and isolation needs?Cloud Architecture
- 182.A cloud engineer is provisioning a new compute instance for a highly sensitive application that processes personally identifiable information (PII). The company policy dictates that the underlying physical server for this instance must be isolated from any other customer's workloads to prevent co-mingling of data and enhance security. Which compute option ensures this level of physical isolation?Cloud Architecture
- 183.A cloud administrator needs to update a fleet of 20 web servers behind a load balancer to a new application version without taking the service fully offline. The plan is to update a small batch of servers at a time, verify health, then move to the next batch until all servers run the new version. Which deployment strategy is being used?DevOps Fundamentals
- 184.A cloud engineer is designing a highly available application that needs to distribute incoming user requests across multiple backend servers to ensure no single server becomes a bottleneck. The solution must also automatically detect unhealthy servers and redirect traffic away from them. Which network component is essential for this functionality?Deployment
- 185.A cloud administrator is configuring an auto-scaling group for a web application. The application experiences predictable spikes in traffic during business hours and sudden, unpredictable surges during marketing campaigns. To optimize costs and performance, the administrator needs to define rules that automatically adjust the number of instances based on CPU utilization and also pre-scale the environment during known peak times. Which two types of scaling policies should be implemented?Deployment
- 186.In a Kubernetes cluster, an administrator edits a deployment manifest to scale replicas from 3 to 5. Without further manual intervention, the control plane automatically creates two additional pods until the running state matches the manifest. Which orchestration concept does this illustrate?DevOps Fundamentals
- 187.A cloud architect is designing a new application that will process sensitive customer data. The application requires dedicated compute resources to meet strict compliance regulations and performance isolation requirements. Which compute model should the architect recommend?Cloud Architecture
- 188.A cloud engineer is tasked with deploying a new virtual machine using a pre-defined template. The template specifies the operating system, instance type, and network configuration. However, the engineer needs to provide a unique hostname, IP address, and an SSH key for the specific deployment. Where should these unique values be specified when using the template?Deployment
- 189.A cloud engineer is analyzing logs from a distributed application to troubleshoot an issue that occurs only during specific hours of the day. The logs are generated by various microservices and stored in a centralized logging solution. To efficiently find relevant events, the engineer needs to filter logs based on specific time ranges, log levels (e.g., ERROR, WARNING), and message content. Which logging capability is being utilized?Operations
- 190.A cloud provider offers a service where customers can deploy their applications without managing the underlying servers, operating systems, or even the runtime environment. They only pay for the actual compute time consumed by their code. Which cloud service model does this represent?Cloud Architecture
- 191.A cloud architect is planning the migration of a large, monolithic on-premises application to a public cloud environment. The application has tightly coupled components and a shared database. The architect wants to minimize changes to the existing code and infrastructure during the migration to reduce risk and effort, but also aims to benefit from cloud scalability. Which migration strategy is most appropriate for this initial phase?Deployment
- 192.A cloud administrator is configuring a Virtual Private Cloud (VPC) and needs to ensure that instances in a private subnet can initiate outbound connections to the internet for updates, but prevent unsolicited inbound connections from the internet. Which AWS networking component should be deployed in the public subnet to facilitate this communication pattern?Cloud Architecture
- 193.A cloud administrator is configuring a new storage service for sensitive log data. The company's compliance policy requires that this data be immutable and protected from accidental deletion or modification for a period of seven years. Which feature of cloud object storage should the administrator enable to meet this requirement?Security
- 194.A financial institution is building a new application that processes real-time stock market data. This application requires extremely low-latency access to frequently updated data and high I/O operations per second (IOPS). The data does not need to persist beyond the lifespan of the processing instance. Which storage tier is most suitable for this use case?Cloud Architecture
- 195.A cloud administrator is tasked with implementing a cost-effective storage solution for infrequently accessed log files that must be retained for compliance purposes for seven years. Retrieval times can be several hours, and data access patterns are unpredictable. Which storage tier is most appropriate for this use case?Cloud Architecture
- 196.A security incident response team is investigating a potential data breach within a cloud environment. The team needs to quickly isolate the compromised virtual machines (VMs) to prevent further lateral movement and data exfiltration, while preserving their state for forensic analysis. Which of the following actions should the team prioritize?Security
- 197.A compliance officer is reviewing the data residency requirements for a new cloud-based application. The application will process sensitive customer data, and regulations dictate that this data MUST remain within specific geographic boundaries. Which aspect of cloud infrastructure is MOST critical to ensure compliance?Security
- 198.A cloud architect is designing a multi-tier application within a Virtual Private Cloud (VPC). The application consists of a web tier, an application tier, and a database tier. The database tier must be completely isolated from direct internet access, while the web tier needs to be publicly accessible. How should the subnets be configured to meet these requirements?Cloud Architecture
- 199.A cloud customer is using a public cloud provider and wants to ensure that they are only responsible for securing their applications, data, and operating system configurations, while the cloud provider handles the underlying infrastructure, network controls, and physical security. Which cloud service model aligns with this shared responsibility breakdown?Cloud Architecture
- 200.A DevOps engineer wants the definition of the CI/CD pipeline itself (build stages, test steps, deployment triggers) to be stored and versioned in the same repository as the application source code, so pipeline changes go through the same code review and history tracking as application changes. Which practice enables this?DevOps Fundamentals