Step2Study
IT & TechnologyCLO-002100% Free

CompTIA Cloud Essentials+ (CLO-002)

Practice bank
202 Qs
Real exam
75 Qs
Time limit
60 min
Passing
720 on a 100–900 scale

Exam blueprint

Cloud Concepts
24%
Business Principles of Cloud Environments
28%
Management and Technical Operations
26%
Governance, Risk, Compliance and Security
22%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 72 min · pass 80% · 202 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Part of a learning path

Study with friends

Challenge a friend to beat your score.

CompTIA Cloud Essentials+ (CLO-002) practice test questions

Sample questions from the 202-question bank, with answers and explanations.

All questions
  1. 1. A company has signed a Service Level Agreement (SLA) with its cloud provider for a critical database service. The SLA specifies a 99.95% uptime guarantee and a maximum response time of 100ms for read operations. During a recent incident, the database experienced 20 minutes of downtime in a 30-day month, and the average read response time increased to 150ms for a continuous period of 4 hours. Which of the following statements is true regarding the SLA violation?

    Business Principles of Cloud Environments

    • A. Only the response time guarantee was violated.
    • B. Neither guarantee was violated, as the downtime was within acceptable limits.
    • C. Both the uptime and response time guarantees were violated.
    • D. Only the uptime guarantee was violated.
    Show answer

    C. Both the uptime and response time guarantees were violated.

    First, calculate the uptime: 30 days * 24 hours/day * 60 minutes/hour = 43,200 total minutes. Downtime = 20 minutes. Uptime = 43,200 - 20 = 43,180 minutes. Uptime % = (43,180 / 43,200) * 100 = 99.9536%. Since 99.9536% is greater than or equal to 99.95%, the uptime guarantee was NOT violated. Second, the response time increased to 150ms, which is above the 100ms maximum, meaning the response time guarantee WAS violated. Therefore, only the response time guarantee was violated.

  2. 2. A cloud architect is designing a new application that needs to handle sudden, unpredictable spikes in user traffic without manual intervention. The application must automatically provision and de-provision resources based on demand. Which cloud characteristic is most relevant to this requirement?

    Cloud Concepts

    • A. Rapid Elasticity
    • B. Resource Pooling
    • C. Broad Network Access
    • D. Measured Service
    Show answer

    A. Rapid Elasticity

    Rapid elasticity is the ability of a cloud system to quickly scale resources up or down in response to changing demand, often automatically. This perfectly matches the requirement for handling sudden, unpredictable traffic spikes without manual intervention.

  3. 3. A small startup is rapidly developing a new mobile application. They need an environment that provides pre-configured operating systems, databases, and development tools, allowing their developers to focus solely on writing code without managing the underlying infrastructure. Which cloud service model best fits their requirements?

    Cloud Concepts

    • A. Function as a Service (FaaS)
    • B. Platform as a Service (PaaS)
    • C. Software as a Service (SaaS)
    • D. Infrastructure as a Service (IaaS)
    Show answer

    B. Platform as a Service (PaaS)

    PaaS provides a complete development and deployment environment in the cloud, abstracting away the underlying infrastructure management. This allows developers to focus on application code, which directly aligns with the startup's need.

  4. 4. A company is designing its cloud data backup strategy. They have critical application data that requires a Recovery Point Objective (RPO) of 1 hour and a Recovery Time Objective (RTO) of 4 hours. Which backup and recovery approach is most appropriate to meet these requirements?

    Management and Technical Operations

    • A. Daily full backups stored off-site with weekly restoration drills.
    • B. Weekly incremental backups with manual restoration procedures.
    • C. Snapshots taken every hour, replicated to a secondary region, with automated recovery scripts.
    • D. Database dumps performed every 24 hours to object storage.
    Show answer

    C. Snapshots taken every hour, replicated to a secondary region, with automated recovery scripts.

    An RPO of 1 hour means data loss must be limited to the last hour, which hourly snapshots satisfy. An RTO of 4 hours requires a fast recovery mechanism, which automated recovery scripts leveraging replicated snapshots to a secondary region can provide, significantly faster than manual or full backup restorations.

  5. 5. A retail company was previously locked into a single cloud provider due to heavy use of proprietary services, causing costly delays when it later needed to migrate. To avoid repeating this problem with a new deployment, the company designs its new application using containerized microservices, open APIs, and infrastructure-as-code templates that can run on multiple cloud platforms. Which strategy is the company pursuing?

    Governance, Risk, Compliance and Security

    • A. Business associate agreement
    • B. Data residency compliance
    • C. Multi-cloud portability strategy
    • D. Risk transfer through insurance
    Show answer

    C. Multi-cloud portability strategy

    A multi-cloud portability strategy uses open standards, containers, and platform-agnostic tooling to design applications that can be deployed or migrated across multiple cloud providers, reducing dependency on any single vendor's proprietary technologies and mitigating vendor lock-in risk.

  6. 6. A cloud administrator is configuring a new cloud environment and needs to ensure that all virtual machines and storage buckets are consistently categorized for cost allocation and access control purposes. Which cloud management tool or practice should the administrator implement to meet this requirement most effectively?

    Management and Technical Operations

    • A. Identity and Access Management (IAM) roles
    • B. Automated scaling groups
    • C. Resource tagging
    • D. Cloud auditing services
    Show answer

    C. Resource tagging

    Resource tagging allows administrators to assign custom metadata (key-value pairs) to cloud resources. This metadata can then be used for organizing, tracking, cost allocation, and applying policies for access control across different resources consistently.

  7. 7. A cloud operations team is tasked with ensuring high availability for an application that processes real-time financial transactions. The application is deployed across multiple virtual machines in a single cloud region. To mitigate the risk of a single data center outage, they need to distribute these VMs across physically isolated locations within that region. Which concept describes these isolated locations?

    Management and Technical Operations

    • A. Edge Locations
    • B. Virtual Private Clouds (VPCs)
    • C. Availability Zones (AZs)
    • D. Cloud Regions
    Show answer

    C. Availability Zones (AZs)

    Availability Zones (AZs) are distinct, isolated locations within a single cloud region. They are designed to be independent of each other, providing fault isolation for power, cooling, and networking, thus mitigating the impact of a single data center failure.

  8. 8. A cloud architect is designing a new cloud environment for a financial institution that will process highly sensitive customer data. The institution is subject to stringent regulatory requirements regarding data integrity and non-alteration. Which security principle should be a primary consideration to ensure that data, once recorded, cannot be changed or deleted without detection?

    Governance, Risk, Compliance and Security

    • A. Confidentiality
    • B. Non-repudiation
    • C. Integrity
    • D. Availability
    Show answer

    C. Integrity

    Data integrity ensures that data remains accurate, consistent, and unaltered over its entire lifecycle. For sensitive financial data subject to regulatory scrutiny, ensuring that data cannot be changed or deleted without detection is paramount to maintaining its trustworthiness and compliance.

  9. 9. A cloud security engineer is designing a new cloud environment and needs to implement a policy that automatically enforces specific security configurations across all newly provisioned virtual machines (VMs). This policy must ensure that certain ports are closed by default and a specific antivirus agent is installed. Which of the following approaches BEST meets this requirement?

    Management and Technical Operations

    • A. Manual VM configuration after provisioning
    • B. Using a Golden Image (AMI/VM Image)
    • C. Implementing a Security Information and Event Management (SIEM) system
    • D. Relying on network firewalls for port closure
    Show answer

    B. Using a Golden Image (AMI/VM Image)

    A Golden Image, also known as an AMI (Amazon Machine Image) or VM Image, is a pre-configured template that includes the operating system, applications, and desired security configurations (like closed ports and installed agents). Using it ensures consistency and automation for newly provisioned VMs.

  10. 10. A cloud architect is designing a new application that will process sensitive customer data. The application requires highly available and scalable storage that can be accessed by multiple compute instances simultaneously. Data encryption at rest and in transit is a strict requirement. Which storage type is BEST suited for this scenario?

    Management and Technical Operations

    • A. Block Storage
    • B. Ephemeral Storage
    • C. Object Storage
    • D. Archive Storage
    Show answer

    C. Object Storage

    Object storage is highly scalable, highly available by design, inherently supports encryption at rest and in transit, and can be accessed concurrently by multiple compute instances via APIs, making it ideal for sensitive, shared, and scalable data processing.

  11. 11. A global software company is expanding its operations and needs to deploy its applications in new geographic regions to reduce latency for local users and comply with regional data sovereignty laws. They are looking for a cloud provider that offers a wide distribution of data centers and services across the globe. Which characteristic of a cloud provider is most relevant to this requirement?

    Business Principles of Cloud Environments

    • A. Vendor Lock-in Avoidance
    • B. Global Reach and Availability Zones
    • C. Elasticity and Scalability
    • D. Managed Services Portfolio
    Show answer

    B. Global Reach and Availability Zones

    Global Reach and Availability Zones refer to a cloud provider's widespread network of data centers and isolated locations within those regions. This characteristic directly addresses the need to deploy applications in new geographic regions to reduce latency and comply with data sovereignty laws by placing data and services closer to users and within specific jurisdictional boundaries.

  12. 12. A company operating in a highly regulated industry stores sensitive customer data in the cloud. They need to understand who is primarily responsible for patching the guest operating system of their virtual machines and encrypting the data at rest within their application. According to the shared responsibility model, who is responsible for these tasks in an IaaS environment?

    Cloud Concepts

    • A. The customer is responsible for both patching the OS and data encryption.
    • B. The cloud provider is responsible for patching the OS, and the customer is responsible for data encryption.
    • C. The cloud provider is responsible for both patching the OS and data encryption.
    • D. The customer is responsible for patching the OS, and the cloud provider is responsible for data encryption.
    Show answer

    A. The customer is responsible for both patching the OS and data encryption.

    In an IaaS model, the customer is responsible for the operating system (including patching) and everything above it, including application data and its encryption. The cloud provider is responsible for the underlying physical infrastructure and its security.

  13. 13. A cloud engineer needs to track the operational status, performance metrics, and resource utilization of several new virtual machines deployed in a public cloud. The engineer also wants to receive alerts when CPU utilization exceeds 80% for more than 5 minutes. Which cloud management function is primarily responsible for fulfilling these requirements?

    Management and Technical Operations

    • A. Provisioning
    • B. Automation
    • C. Monitoring
    • D. Tagging
    Show answer

    C. Monitoring

    Monitoring tools collect data on resource performance and health, providing visibility into operational status and utilization. They also allow setting up alerts based on predefined thresholds, directly addressing the engineer's requirements.

  14. 14. A cloud administrator is tasked with optimizing costs for a development environment that is only active during business hours (9 AM to 5 PM, Monday to Friday). The current setup involves always-on virtual machines (VMs). Which cost optimization strategy would provide the most immediate and significant savings for this specific scenario?

    Management and Technical Operations

    • A. Implementing automated scheduled start/stop of VMs
    • B. Reserving instances for 1-year terms
    • C. Switching to serverless functions for all applications
    • D. Migrating to a different cloud provider with lower hourly rates
    Show answer

    A. Implementing automated scheduled start/stop of VMs

    Automated scheduled start/stop of VMs directly addresses the problem of idle resources. By stopping VMs outside of business hours, the administrator eliminates compute costs for the majority of the week, leading to significant and immediate savings.

  15. 15. A company subscribes to a SaaS-based customer relationship management (CRM) platform. Under the shared responsibility model, which of the following remains the customer's responsibility rather than the SaaS provider's?

    Governance, Risk, Compliance and Security

    • A. Managing which employees have access to customer records
    • B. Maintaining the physical data center hardware
    • C. Securing the hypervisor that runs virtual machines
    • D. Patching the underlying operating system
    Show answer

    A. Managing which employees have access to customer records

    In a SaaS model, the provider manages nearly the entire stack, including infrastructure, OS, and application code, but the customer always retains responsibility for their own data and identity and access management, such as controlling which employees can view records.

  16. 16. A multi-national corporation is planning to migrate its enterprise resource planning (ERP) system to a cloud environment. Due to strict data sovereignty laws and internal security policies, certain highly sensitive modules of the ERP must remain within the company's own data centers, while less sensitive modules can leverage public cloud resources. Which cloud deployment model best supports this requirement?

    Cloud Concepts

    • A. Hybrid Cloud
    • B. Public Cloud
    • C. Community Cloud
    • D. Private Cloud
    Show answer

    A. Hybrid Cloud

    Hybrid cloud combines private infrastructure (for sensitive data) with public cloud resources (for less sensitive modules), allowing organizations to meet specific regulatory and security requirements while still benefiting from cloud scalability.

  17. 17. A small startup is evaluating different cloud service providers for its new application. They have a limited budget and want to avoid large upfront capital expenditures. Which of the following financial models is MOST aligned with their goal?

    Business Principles of Cloud Environments

    • A. Capital Expenditure (CapEx)
    • B. Fixed Asset Expenditure (FAE)
    • C. Operational Expenditure (OpEx)
    • D. Return on Investment (ROI)
    Show answer

    C. Operational Expenditure (OpEx)

    Operational Expenditure (OpEx) involves paying for services or products as they are consumed, typically on a recurring basis. This model avoids large upfront costs, making it ideal for startups with limited capital.

  18. 18. A large enterprise is evaluating cloud migration and needs a comprehensive understanding of all direct and indirect costs associated with both their current on-premises infrastructure and potential cloud solutions over a multi-year period. Which financial analysis tool would provide the MOST complete picture for this comparison?

    Business Principles of Cloud Environments

    • A. Total Cost of Ownership (TCO)
    • B. Return on Investment (ROI)
    • C. Net Present Value (NPV)
    • D. Payback Period
    Show answer

    A. Total Cost of Ownership (TCO)

    Total Cost of Ownership (TCO) provides a holistic view of all costs, both direct (hardware, software, cloud subscriptions) and indirect (maintenance, administration, downtime, training, energy, opportunity costs), over the entire lifecycle of an asset or solution. This makes it ideal for comparing on-premises vs. cloud over multiple years.

  19. 19. A cloud customer is experiencing intermittent network performance issues when accessing their cloud-hosted applications. They suspect the problem lies with the path their traffic takes over the public internet, rather than within the cloud provider's internal network. Which networking solution would provide a dedicated, private connection to bypass the public internet and potentially resolve these issues?

    Cloud Concepts

    • A. Direct Connect / ExpressRoute
    • B. Cloud Load Balancer
    • C. Content Delivery Network (CDN)
    • D. Virtual Private Network (VPN)
    Show answer

    A. Direct Connect / ExpressRoute

    Direct Connect (AWS) or ExpressRoute (Azure) are dedicated, private network connections from an on-premises data center to a public cloud provider. They bypass the public internet, offering consistent, high-bandwidth, and low-latency connectivity, which can resolve intermittent performance issues caused by public internet routing.

  20. 20. A financial services firm's risk team estimates that a specific type of cloud service outage would cause $50,000 in losses each time it occurs, and historical data suggests this outage happens 3 times per year. What is the annualized loss expectancy (ALE) for this risk?

    Governance, Risk, Compliance and Security

    • A. $50,000
    • B. $150,000
    • C. $16,667
    • D. $200,000
    Show answer

    B. $150,000

    ALE = Single Loss Expectancy (SLE) × Annualized Rate of Occurrence (ARO) = $50,000 × 3 = $150,000. This quantitative measure helps prioritize risk treatment decisions and justify security spending.

  21. 21. A cloud administrator is configuring network access for a new application deployed in a Virtual Private Cloud (VPC). The application needs to communicate with an external third-party API over the public internet, but all outbound traffic from the application's subnet must first pass through a specific security appliance for inspection. Which VPC networking component should the administrator implement to enforce this traffic flow?

    Cloud Concepts

    • A. VPC Endpoint
    • B. Direct Connect
    • C. NAT Gateway
    • D. Internet Gateway
    Show answer

    C. NAT Gateway

    A NAT Gateway allows instances in a private subnet to connect to services outside the VPC (like the public internet) while preventing external services from initiating connections to those instances. By routing outbound traffic through a NAT Gateway, which can then be configured to send traffic via a security appliance, the administrator can enforce inspection for all outbound public internet traffic.

  22. 22. A financial institution is migrating its legacy applications to a cloud environment. During the initial assessment phase, they identify that some critical applications are highly dependent on specific hardware and operating system versions that are not supported by the target cloud provider. This situation primarily highlights a challenge in which aspect of cloud feasibility?

    Business Principles of Cloud Environments

    • A. Schedule Feasibility
    • B. Operational Feasibility
    • C. Technical Feasibility
    • D. Economic Feasibility
    Show answer

    C. Technical Feasibility

    Technical feasibility evaluates whether the proposed cloud solution can be implemented with existing technology, resources, and capabilities. Incompatibility with specific hardware and OS versions directly relates to the technical ability to migrate and run applications in the cloud.

  23. 23. A company is evaluating moving its critical enterprise resource planning (ERP) system to a public cloud. The ERP system has numerous custom integrations with other on-premises applications and requires significant modifications to function optimally in a cloud-native environment. Which migration approach would involve substantial re-architecture and code changes to leverage cloud services fully?

    Business Principles of Cloud Environments

    • A. Refactoring
    • B. Rehosting
    • C. Repurchasing
    • D. Retiring
    Show answer

    A. Refactoring

    Refactoring, also known as re-architecting, involves significant modifications to an application's code and architecture to take full advantage of cloud-native features and services. This approach is chosen when an application requires substantial changes to optimize its performance, scalability, and cost-efficiency in the cloud.

  24. 24. A cloud customer is migrating a legacy monolithic application to the cloud. The application's database requires extremely high input/output operations per second (IOPS) and very low latency, as it processes millions of transactions per second. Which cloud storage type is BEST suited for this specific database requirement?

    Cloud Concepts

    • A. Cold Archive Storage
    • B. General Purpose SSD Block Storage
    • C. High Performance IOPS SSD Block Storage
    • D. Standard Object Storage
    Show answer

    C. High Performance IOPS SSD Block Storage

    For 'extremely high IOPS' and 'very low latency' for a transactional database processing millions of transactions, a specialized 'High Performance IOPS SSD Block Storage' is the most appropriate. General Purpose SSD Block Storage offers good performance but not the 'extremely high' levels needed, and object/archive storage are unsuitable for databases with these performance demands.

  25. 25. A company posts a visible notice at every cloud application login screen stating that all user activity is logged, monitored, and subject to disciplinary or legal action if misused. The primary purpose of this notice is to discourage employees from attempting unauthorized actions. Which type of security control does this notice represent?

    Governance, Risk, Compliance and Security

    • A. Corrective control
    • B. Deterrent control
    • C. Preventive control
    • D. Detective control
    Show answer

    B. Deterrent control

    A deterrent control discourages undesirable behavior by warning of consequences, such as a monitoring notice, without technically blocking or detecting the action itself. It differs from preventive controls that block actions and detective controls that identify them after they occur.

CompTIA Cloud Essentials+ (CLO-002) flashcards

Tap a card to flip it. 134 flashcards in the full deck.

  • SLA Compliance Assessment

    Flip card

    The process of verifying if a cloud provider has met the terms and conditions outlined in a Service Level Agreement (SLA), typically involving uptime and performance metrics.

    • Requires calculation of actual metrics
    • Compares actuals against agreed-upon thresholds
    • Multiple metrics can be part of one SLA
    Study this card →
  • Rapid Elasticity

    Flip card

    The ability of cloud resources to be quickly and elastically provisioned or released to scale rapidly outward and inward commensurate with demand.

    • Automatic scaling of resources.
    • Handles unpredictable demand spikes.
    • Minimizes over-provisioning and under-provisioning.
    Study this card →
  • Platform as a Service (PaaS)

    Flip card

    A cloud computing service model that provides a platform allowing customers to develop, run, and manage applications without the complexity of building and maintaining the infrastructure typically associated with developing and launching an app.

    • Cloud provider manages infrastructure, OS, middleware, and runtime.
    • User manages applications and data.
    • Ideal for developers who want to focus on coding.
    Study this card →
  • RPO and RTO

    Flip card

    Recovery Point Objective (RPO) defines the maximum acceptable amount of data loss. Recovery Time Objective (RTO) defines the maximum acceptable downtime after a disaster.

    • RPO is measured in time (e.g., 1 hour of data loss).
    • RTO is measured in time (e.g., 4 hours to recover).
    • Lower RPO/RTO typically means higher cost and complexity.
    Study this card →
  • Multi-cloud / Portability Strategy

    Flip card

    An architectural approach using open standards, containers, and platform-agnostic tools to design applications that can run across multiple cloud providers, reducing vendor lock-in risk.

    • Uses containers, open APIs, and infrastructure-as-code
    • Avoids proprietary provider-specific services where possible
    • Directly mitigates vendor lock-in risk
    Study this card →
  • Resource Tagging

    Flip card

    Applying metadata (key-value pairs) to cloud resources for identification, organization, and management purposes.

    • Used for cost allocation, automation, and access control.
    • Enables consistent management across diverse resources.
    • Tags can be used in policies, reports, and searches.
    Study this card →
  • Availability Zone (AZ)

    Flip card

    A physically distinct, isolated location within a cloud region, designed to be independent of other AZs in terms of power, cooling, and networking, for high availability.

    • Provides fault isolation within a region.
    • Connected by low-latency links.
    • Deploying across multiple AZs enhances application availability.
    Study this card →
  • Data Integrity

    Flip card

    The assurance that data is accurate, consistent, and complete throughout its entire lifecycle and has not been altered or destroyed in an unauthorized manner.

    • Protects against unauthorized modification or deletion.
    • Essential for trust, compliance, and accuracy.
    • Often implemented through hashing, digital signatures, and access controls.
    Study this card →
  • Golden Image

    Flip card

    A pre-configured, hardened virtual machine image (template) that includes the operating system, required applications, and security configurations, used to provision new instances consistently.

    • Ensures consistency and compliance for new deployments.
    • Reduces manual configuration and potential for human error.
    • Often includes security baselines, agents, and closed ports.
    Study this card →
  • Object Storage

    Flip card

    A cloud storage architecture that manages data as objects, offering high scalability, availability, durability, and features like metadata tagging and encryption, accessible via APIs.

    • Highly scalable (virtually unlimited).
    • High availability and durability.
    • Supports encryption at rest and in transit.
    Study this card →
  • Global Reach and Availability Zones

    Flip card

    A cloud provider's characteristic referring to its extensive network of data centers distributed across various geographic regions, often subdivided into isolated Availability Zones for high availability and disaster recovery.

    • Reduces latency for global users
    • Enables compliance with data residency laws
    • Provides enhanced resilience and fault tolerance
    Study this card →
  • Shared Responsibility Model (IaaS)

    Flip card

    A framework outlining the security and compliance responsibilities of both the cloud provider and the customer in a cloud computing environment. In IaaS, the customer has significant responsibility for the operating system and above.

    • Provider: 'Security *of* the Cloud' (physical infrastructure, virtualization).
    • Customer: 'Security *in* the Cloud' (OS, applications, data, network configuration).
    • Responsibility shifts based on service model (IaaS, PaaS, SaaS).
    Study this card →
  • Cloud Monitoring

    Flip card

    The process of collecting and analyzing data on the performance, health, and utilization of cloud resources and applications.

    • Provides visibility into cloud infrastructure and application behavior.
    • Enables proactive identification and resolution of issues.
    • Includes metrics, logs, traces, and alerting capabilities.
    Study this card →
  • Cloud Cost Optimization

    Flip card

    The process of managing and reducing cloud spending by optimizing resource usage, selecting appropriate pricing models, and eliminating waste.

    • Focuses on aligning costs with business value.
    • Strategies include rightsizing, automation, and leveraging discounts.
    • Continuous process that requires monitoring and analysis.
    Study this card →
  • Shared Responsibility Model

    Flip card

    A framework defining which security and operational tasks are handled by the cloud provider versus the customer, varying by service model (IaaS, PaaS, SaaS).

    • Provider responsibility increases from IaaS to SaaS
    • Customer always retains responsibility for data and access management
    • Understanding the split prevents security gaps from assumed coverage
    Study this card →
  • Hybrid Cloud

    Flip card

    A cloud computing environment that combines a private cloud with one or more public cloud services, with proprietary software enabling communication between the two distinct environments.

    • Combines public and private cloud.
    • Allows data and applications to move between environments.
    • Ideal for regulatory compliance and workload flexibility.
    Study this card →
  • Operational Expenditure (OpEx)

    Flip card

    Funds used to run day-to-day business operations, typically expensed in the period in which they are incurred.

    • Paid as a recurring cost (e.g., monthly, annually).
    • No large upfront investment.
    • Common in cloud computing for services like SaaS, IaaS, PaaS.
    Study this card →
  • Total Cost of Ownership (TCO)

    Flip card

    A comprehensive financial estimate that includes all direct and indirect costs associated with an asset or system over its entire lifecycle.

    • Includes hardware, software, services, maintenance, administration, training, energy, downtime.
    • Used for comparing different IT solutions (e.g., on-premises vs. cloud).
    • Provides a long-term financial perspective.
    Study this card →
  • Dedicated Cloud Connectivity

    Flip card

    Services like AWS Direct Connect or Azure ExpressRoute provide a dedicated, private network connection from an on-premises data center to a cloud provider, bypassing the public internet.

    • Bypasses the public internet, improving security and performance.
    • Offers consistent bandwidth and lower latency.
    • Ideal for hybrid cloud environments and large data transfers.
    Study this card →
  • Annualized Loss Expectancy (ALE)

    Flip card

    A quantitative risk metric calculated as SLE multiplied by ARO, representing the expected yearly financial loss from a given risk.

    • SLE = single loss expectancy per incident
    • ARO = annualized rate of occurrence (frequency per year)
    • ALE = SLE × ARO
    Study this card →
  • NAT Gateway

    Flip card

    A Network Address Translation service that allows instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating connections to those instances.

    • Enables outbound internet connectivity for private subnets.
    • Provides a single public IP address for multiple private instances.
    • Crucial for security and controlled internet access.
    Study this card →
  • Technical Feasibility

    Flip card

    An assessment of the practical and technical resources required to implement a proposed project or solution, determining if the technology exists and can be integrated.

    • Evaluates compatibility with existing systems and infrastructure.
    • Assesses availability of required hardware, software, and skills.
    • Determines if the project is technically achievable.
    Study this card →
  • Refactoring (Re-architecting)

    Flip card

    A cloud migration strategy that involves making significant modifications to an application's code and architecture to optimize it for cloud-native features and services, improving scalability, performance, and cost-efficiency.

    • Involves substantial code changes
    • Aims to leverage cloud-native services
    • Higher initial effort, but better long-term benefits
    Study this card →
  • High Performance IOPS SSD Block Storage

    Flip card

    A cloud storage type optimized for applications requiring the highest levels of IOPS and lowest latency, often provisioned with dedicated performance characteristics.

    • Designed for critical, I/O-intensive databases.
    • Guaranteed IOPS and throughput.
    • More expensive than other block storage options.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.