CompTIA Cloud+ (CV0-004) practice questions

238 free questions with answers and explanations.

Practice test
  1. 201.A cloud security engineer is tasked with securing a new Kubernetes cluster deployed in a public cloud. The cluster hosts several microservices that communicate with each other, and the engineer needs to implement granular network policies to control traffic flow between these services. Additionally, they want to enforce security policies at the application layer (Layer 7) and gain better visibility into inter-service communication. Which architectural component would best address these requirements?Security
  2. 202.A large enterprise is migrating its legacy applications to a public cloud. The security team is concerned about data exfiltration and unauthorized access to sensitive corporate data stored in various cloud services (e.g., object storage, databases, SaaS applications). They need a solution that can enforce security policies, detect anomalous behavior, and prevent data leakage across all cloud services, regardless of the user's location or device. Which security control addresses these comprehensive requirements?Security
  3. 203.A cloud security engineer is configuring an identity and access management (IAM) solution for a new cloud application. The application needs to authenticate users from multiple different organizations, each with its own existing identity provider (IdP). The goal is to allow users to use their existing corporate credentials to access the cloud application without creating new accounts in the cloud provider's IAM system. Which protocol is most commonly used to achieve this federated identity management?Security
  4. 204.A cloud security engineer needs to implement secure communication between microservices within a Kubernetes cluster. The solution must ensure that all inter-service traffic is encrypted and authenticated, providing mutual TLS (mTLS) without requiring developers to manually implement cryptographic libraries in each service. Which technology would best facilitate this?Security
  5. 205.A cloud security team is notified of an incident where an unauthorized user gained access to a critical database via a compromised web application. After containing the breach and eradicating the threat, the team needs to restore normal operations and ensure the system is secure against similar future attacks. Which phase of the incident response lifecycle directly follows eradication and focuses on returning affected systems to their original state?Security
  6. 206.A cloud security engineer needs to implement a solution to continuously monitor the security posture of multiple cloud accounts across different cloud providers. The solution must identify misconfigurations, compliance deviations, and provide recommendations for remediation. Which type of service is best suited for this purpose?Security
  7. 207.A global financial institution is expanding its cloud presence. As part of its compliance obligations, it must ensure that all data stored in the cloud is protected with encryption, both in transit and at rest. Furthermore, the cryptographic keys used for this encryption must be securely managed, rotated regularly, and have a clear audit trail of their usage. Which component of the cloud security framework is primarily responsible for generating, storing, and managing these encryption keys?Security
  8. 208.A financial institution is deploying a critical database in a public cloud. Due to stringent regulatory requirements, all network traffic to and from this database must be continuously monitored for malicious activity, and any detected threats must be automatically blocked in real-time. Which cloud security service should be implemented?Security
  9. 209.A cloud security architect is reviewing the access policies for a critical storage bucket containing customer PII. The current policy allows access from specific IP addresses. To further enhance security, the architect wants to ensure that access is ONLY granted if the request originates from a specific Virtual Private Cloud (VPC) endpoint, preventing any direct internet access to the bucket, even from allowed IPs. Which type of policy condition would achieve this?Security
  10. 210.A global e-commerce company uses a multi-cloud strategy and needs to ensure consistent security policies and configurations across all its cloud environments (AWS, Azure, GCP). The security team wants a centralized solution that can enforce security baselines, detect policy violations, and automate remediation tasks across these different platforms. Which approach would be most effective?Security
  11. 211.A company is migrating sensitive financial data to a cloud object storage service. The compliance team mandates that the integrity of the data must be verifiable at any point in time, even if the data itself is encrypted. Which cryptographic technique is primarily used to ensure data integrity?Security
  12. 212.A cloud security architect is designing a data protection strategy for sensitive customer data stored in an object storage service. The requirement is that all data uploaded to the bucket must be encrypted at rest, and the encryption keys must be managed by the cloud provider, but specific to the customer's account, not shared with other customers. Which server-side encryption method should be chosen?Security
  13. 213.A software development company is adopting a DevOps model and requires a solution to scan container images for known vulnerabilities as part of their continuous integration/continuous deployment (CI/CD) pipeline. The solution must integrate seamlessly into the pipeline and prevent deployment of images with critical vulnerabilities. Which security practice is being implemented?Security
  14. 214.A company is deploying a new web application in a public cloud. The application uses microservices architecture and needs fine-grained traffic control between individual services, as well as features like mutual TLS (mTLS) for strong authentication and encryption between service-to-service communications. A cloud security engineer recommends a solution that can manage and observe this inter-service communication. Which of the following technologies is best suited for this purpose?Security
  15. 215.A cloud security engineer is designing an access control strategy for a new critical application that will be hosted in a public cloud. The application processes highly sensitive customer data and requires strict segregation of duties. The engineer needs to ensure that users only have the minimum necessary permissions to perform their job functions and that these permissions are granted based on their organizational role rather than individual identity. Which of the following access control models best addresses these requirements?Security
  16. 216.A cloud security engineer is tasked with implementing a key management solution for an application that processes highly sensitive customer data. The solution must ensure that encryption keys are generated, stored, and used within a FIPS 140-2 Level 3 compliant hardware module, and that the cloud provider has no access to the plaintext keys. Which key management service model should the engineer recommend?Security
  17. 217.A cloud security engineer is implementing a solution to monitor and enforce security best practices across multiple cloud accounts and subscriptions within a large enterprise. The solution needs to continuously assess configurations against security benchmarks, identify misconfigurations, and provide a consolidated view of the security posture. Which type of cloud security tool is specifically designed for these capabilities?Security
  18. 218.A cloud security engineer is implementing a solution to protect against common web exploits such as SQL injection and cross-site scripting (XSS) for a public-facing web application deployed on a cloud platform. The solution needs to operate at the application layer (Layer 7 of the OSI model). Which security service should be configured?Security
  19. 219.A global enterprise is migrating its sensitive customer data to a multi-cloud environment. Due to stringent regulatory requirements in various jurisdictions, the company must ensure that encryption keys for data stored in a specific region are generated, managed, and stored exclusively within that geographic region. Which key management solution would best meet this data sovereignty and compliance requirement?Security
  20. 220.A cloud administrator is configuring a new virtual network for a highly sensitive application. The application's backend database must only be accessible from specific application servers within the same virtual network and must not be exposed to the public internet or other segments of the organization's cloud infrastructure. Which network security construct should the administrator use to enforce this strict access control at the subnet level?Security
  21. 221.A global organization is implementing a cloud-based data analytics platform that processes sensitive customer data from various regions. Due to strict regulatory requirements in Europe, all data originating from European citizens must be processed and stored exclusively within the European Union. Which compliance concept primarily addresses this requirement?Security
  22. 222.A cloud security team is performing a vulnerability assessment on a newly deployed containerized application. The assessment needs to include scanning the container images for known vulnerabilities in their operating system libraries and third-party dependencies before deployment. Which security analysis technique is most appropriate for identifying these types of vulnerabilities within the container images?Security
  23. 223.A cloud security architect is tasked with ensuring the integrity of data at rest in a cloud object storage service. The data consists of critical audit logs and financial records that must not be altered without detection. Which cryptographic technique is most suitable for verifying that the data has not been tampered with after it has been stored?Security
  24. 224.A cloud security architect is designing an authentication solution for a multi-tenant SaaS application. The application needs to integrate with various enterprise identity providers (IdPs) and support single sign-on (SSO) across different organizations, each potentially using a different IdP. Which protocol is best suited for this requirement?Security
  25. 225.A cloud security architect is reviewing the access controls for a critical storage bucket containing sensitive customer data. The current policy allows an external third-party application, identified by its AWS account ID, to write objects to the bucket. The architect wants to implement the principle of least privilege, ensuring the third-party application can only perform the specific 's3:PutObject' action and nothing else, and only when the request comes from a specific VPC endpoint. Which type of policy and specific condition key should be used to restrict access to only 's3:PutObject' via a specified VPC endpoint?Security
  26. 226.A cloud security architect is designing a data protection strategy for a highly sensitive medical imaging application. The application stores patient data in a cloud object storage service. Due to strict HIPAA compliance requirements, all data must be encrypted at rest, and the encryption keys must be managed by the cloud provider's Key Management Service (KMS) with a strong audit trail and integration with IAM for access control. Which server-side encryption method is the most appropriate choice?Security
  27. 227.A cloud security professional is reviewing the access policies for a critical serverless function that processes financial transactions. The function currently has broad permissions, including access to several object storage buckets and a database, which violates the principle of least privilege. Which IAM concept should be applied to restrict the function's permissions to only the specific resources and actions it absolutely needs?Security
  28. 228.A cloud security engineer needs to implement a solution that allows granular control over individual API calls and resource access within a cloud environment. The solution should define 'who' (identity) can perform 'what' (actions) on 'which' (resources) under 'what' (conditions). Which IAM concept best fits this requirement?Security
  29. 229.A healthcare provider is deploying a new patient records application in a public cloud. Due to stringent regulatory requirements (e.g., HIPAA), they must ensure that all access to the application and its underlying data is logged and immutable for auditing purposes. Additionally, any changes to these logs must be immediately detectable. Which cloud storage feature should be implemented for the audit logs?Security
  30. 230.A cloud administrator needs to establish a secure, private connection between a company's on-premises data center and their cloud-based virtual network. This connection must not traverse the public internet and should offer consistent network performance. Which of the following cloud networking services should the administrator implement?Security
  31. 231.A cloud security team is establishing a baseline for security configurations across their cloud environment. They need a continuous process to verify that all deployed resources (e.g., VMs, storage buckets, databases) adhere to predefined security standards and organizational policies. This process should also identify any deviations from the baseline. Which security practice is being described?Security
  32. 232.A cloud security architect is integrating a new third-party SaaS application with the company's existing identity management system. The goal is to allow users to authenticate to the SaaS application using their corporate credentials without storing those credentials in the SaaS application itself. The solution must support multiple identity sources and provide a seamless single sign-on experience. Which identity federation standard is most appropriate for this scenario?Security
  33. 233.A cloud architect is designing a highly available and secure application that relies on a managed database service. The architect needs to ensure that the database traffic remains private and does not traverse the public internet, even when accessed by other services within the same cloud provider's network. Which networking construct should the architect use to achieve this private connectivity?Security
  34. 234.A cloud security architect is designing a key management strategy for highly sensitive data that requires the highest level of security and compliance. The organization needs to maintain complete control over the cryptographic keys and wants to ensure that the cloud provider cannot access the plaintext keys. Which key management approach best meets these requirements?Security
  35. 235.A cloud security engineer is tasked with implementing a data loss prevention (DLP) solution for sensitive customer data stored in a public cloud object storage service. The solution must identify, monitor, and protect data both at rest and in transit. Which of the following best describes the primary function of a DLP solution in this scenario?Security
  36. 236.A cloud operations team discovers unusual outbound network traffic originating from several virtual machines (VMs) that are part of a production application. This traffic is destined for external IP addresses not typically associated with the application's operations. The team suspects a compromise and needs to immediately isolate the affected VMs from the rest of the network while preserving forensic evidence. Which incident response action should they prioritize?Security
  37. 237.A cloud operations team detects unusual spikes in network egress traffic from several virtual machines (VMs) that are part of a production application. Further investigation reveals that these VMs are communicating with unknown external IP addresses on non-standard ports. The team suspects a potential compromise. Which phase of the incident response lifecycle should the team prioritize next to prevent further damage?Security
  38. 238.A financial institution is migrating its core banking application to a cloud environment. The security team requires a mechanism to ensure that the integrity of data at rest is maintained and that any unauthorized modification is immediately detectable. Which of the following cryptographic techniques would best address this requirement?Security