Step2Study
IT & TechnologyCV0-004100% Free

CompTIA Cloud+ (CV0-004)

Practice bank
238 Qs
Real exam
90 Qs
Time limit
90 min
Passing
750 on a 100–900 scale

Exam blueprint

Cloud Architecture
23%
Deployment
19%
Operations
17%
Security
19%
DevOps Fundamentals
10%
Troubleshooting
12%

Practice

Untimed · instant feedback · 4 practice tests of 90 questions

Questions per test

Custom practice

Flashcard on every question Mental map when you miss

Exam simulation

4 timed tests · 90 questions each · 90 min · pass 83% · 238 questions in the bank

+50 XP per test · +100 XP for a pass

Random simulation (weighted by domain)

Everything is open to everyone. Create a free account to save scores, XP, badges and get progress emails.

Free study resources

All resources →

Part of a learning path

Study with friends

Challenge a friend to beat your score.

CompTIA Cloud+ (CV0-004) practice test questions

Sample questions from the 238-question bank, with answers and explanations.

All questions
  1. 1. A cloud engineer is investigating an application that allows users to upload large files to an object storage bucket. Users are reporting occasional 'Access Denied' errors during the upload process, even though the IAM policy for the application's service account explicitly grants `s3:PutObject` and `s3:GetObject` permissions to the target bucket. The bucket also has a policy that denies uploads of objects larger than 5GB. What is the MOST likely cause of the 'Access Denied' errors?

    Troubleshooting

    • A. The object storage bucket has versioning enabled, conflicting with upload permissions.
    • B. The application's service account is missing `s3:PutObjectAcl` permission.
    • C. The bucket policy's size restriction is being enforced, leading to an 'Access Denied' error.
    • D. The user's network connection is unstable, causing intermittent upload failures.
    Show answer

    C. The bucket policy's size restriction is being enforced, leading to an 'Access Denied' error.

    Cloud object storage services often enforce bucket policies with conditions, such as object size limits. When an upload exceeds such a limit, the service will deny the request. Even though the IAM policy grants `PutObject`, the bucket policy's explicit deny (or condition-based deny) for oversized objects takes precedence, resulting in an 'Access Denied' error.

  2. 2. A cloud administrator is designing a cost-effective storage solution for infrequently accessed log files that must be retained for compliance reasons for seven years. These logs are rarely needed after 90 days but must be retrievable within a few hours if an audit occurs. Which storage tier provides the best balance of cost and retrieval requirements?

    Cloud Architecture

    • A. Nearline Archive Storage
    • B. Standard Object Storage
    • C. Block Storage
    • D. Cold Object Storage (Archive)
    Show answer

    D. Cold Object Storage (Archive)

    Cold Object Storage (Archive) is designed for long-term retention of infrequently accessed data, offering the lowest storage costs with retrieval times ranging from minutes to hours, which aligns with the compliance and retrieval requirements.

  3. 3. A cloud engineer is tasked with deploying a new web application that requires high availability and scalability. The application will serve static content from a content delivery network (CDN) and dynamic content from a fleet of web servers behind a load balancer. Which type of storage should be used for the static content to ensure optimal performance and cost-effectiveness for the CDN?

    Deployment

    • A. File storage shared across all web servers.
    • B. Block storage attached to individual web servers.
    • C. Object storage for static assets.
    • D. Ephemeral storage on the web servers.
    Show answer

    C. Object storage for static assets.

    Object storage is highly scalable, cost-effective, and ideal for storing static content like images, videos, and documents. It integrates seamlessly with CDNs, allowing content to be cached at edge locations for optimal performance and global accessibility.

  4. 4. A cloud engineer is deploying a new service that requires a highly available and scalable block storage solution for virtual machines. The storage needs to be directly attached to the VMs and provide low-latency access for I/O-intensive workloads. Which storage deployment option should the engineer choose?

    Deployment

    • A. Archive Storage
    • B. Block Storage
    • C. Object Storage
    • D. File Storage
    Show answer

    B. Block Storage

    Block storage provides raw storage volumes that can be attached to virtual machines, similar to a physical hard drive. It offers low-latency access and is suitable for I/O-intensive workloads, making it ideal for databases and operating system volumes where high performance and direct attachment are critical.

  5. 5. A cloud engineer is deploying a new web application that requires high-performance, low-latency storage for its database. The database will be hosted on a virtual machine and needs to support frequent read/write operations with guaranteed IOPS. Which storage type is best suited for this requirement?

    Deployment

    • A. Object Storage
    • B. Archive Storage
    • C. Block Storage
    • D. File Storage
    Show answer

    C. Block Storage

    Block storage provides raw, unformatted storage volumes that can be attached to virtual machines. It offers high performance, low latency, and guaranteed IOPS, making it ideal for databases and other applications requiring direct, fast access to data.

  6. 6. A cloud engineer needs to design a highly available architecture for a web application that experiences varying traffic loads. The solution must automatically distribute incoming requests across multiple backend servers and seamlessly handle server failures without manual intervention. Which component is essential for meeting these requirements?

    Cloud Architecture

    • A. Distributed Cache
    • B. Load Balancer
    • C. Message Queue
    • D. Content Delivery Network (CDN)
    Show answer

    B. Load Balancer

    A load balancer distributes incoming application traffic across multiple targets, such as EC2 instances, in multiple Availability Zones. It also monitors the health of its registered targets and routes traffic only to healthy targets, automatically handling server failures.

  7. 7. A cloud administrator is unable to access a newly deployed Linux virtual machine (VM) via SSH. The VM is in a private subnet, and a NAT Gateway is configured in a public subnet for outbound internet access. The security group associated with the VM allows inbound SSH (port 22) from the administrator's IP address. A bastion host is set up in the public subnet, and the administrator can successfully SSH into the bastion host. What is the MOST likely reason for the SSH failure to the private VM?

    Troubleshooting

    • A. The NAT Gateway is misconfigured, preventing inbound SSH traffic.
    • B. The Network Access Control List (NACL) for the private subnet is blocking inbound SSH.
    • C. The security group on the bastion host is blocking outbound SSH to the private VM.
    • D. The routing table for the public subnet is not configured to send traffic to the private subnet.
    Show answer

    B. The Network Access Control List (NACL) for the private subnet is blocking inbound SSH.

    Since the administrator can SSH into the bastion, and the VM's security group allows SSH, the issue is likely at the subnet level. NAT Gateways are for outbound traffic, not inbound. NACLs are stateless and apply to subnets, so an incorrectly configured NACL on the private subnet could be blocking the inbound SSH traffic from the bastion host.

  8. 8. A cloud architect is designing a new microservices-based application that requires stateless compute components which can scale rapidly and independently based on demand. The development team prefers to focus solely on writing code without managing servers, operating systems, or runtime environments. Which cloud service model best fits these requirements?

    Cloud Architecture

    • A. Platform as a Service (PaaS)
    • B. Infrastructure as a Service (IaaS)
    • C. Software as a Service (SaaS)
    • D. Function as a Service (FaaS)
    Show answer

    D. Function as a Service (FaaS)

    Function as a Service (FaaS), a subset of Serverless computing, allows developers to deploy stateless code that scales automatically and independently, entirely abstracting away server management and runtime environments, aligning perfectly with the requirements.

  9. 9. A cloud engineer is trying to deploy a new virtual machine (VM) from a custom image in a specific subnet. The deployment consistently fails with an error indicating 'Insufficient IP addresses in subnet'. The subnet currently has 20 free IP addresses, and the VM requires only one. What is the MOST likely reason for this deployment failure?

    Troubleshooting

    • A. The subnet's CIDR block is too small to accommodate any new VM deployments.
    • B. The VM's network interface is configured to request multiple IP addresses.
    • C. The custom image is too large, exceeding the maximum size allowed for the subnet.
    • D. The cloud provider reserves a certain number of IP addresses in each subnet for internal use.
    Show answer

    D. The cloud provider reserves a certain number of IP addresses in each subnet for internal use.

    Cloud providers typically reserve a few IP addresses in each subnet for internal network infrastructure (e.g., network gateway, DNS, broadcast), even if the reported 'free' count doesn't explicitly subtract them. This can lead to 'insufficient IP' errors when the actual usable IPs are fewer than expected.

  10. 10. Two developers each modify the same lines of the same file in separate branches. When one developer attempts to merge their branch into the main branch after the other's change was already merged, Git stops and reports that it cannot automatically combine the changes. What has occurred?

    DevOps Fundamentals

    • A. Git rebase
    • B. Merge conflict
    • C. Fast-forward merge
    • D. Repository fork
    Show answer

    B. Merge conflict

    A merge conflict happens when Git cannot automatically reconcile differing changes to the same lines of a file from two branches, requiring manual resolution. Fast-forward merge applies when no conflicting history exists, a fork is a separate copy of a repository, and rebase is a way to reapply commits rather than a conflict condition.

  11. 11. A development team is implementing a Continuous Integration/Continuous Delivery (CI/CD) pipeline for a new microservices application. They want to ensure that every code change is automatically built, tested, and then deployed to a staging environment for further validation, without manual intervention at each step. Which of the following concepts is MOST relevant to achieving this automation?

    Deployment

    • A. Canary Deployment
    • B. Automated Provisioning
    • C. Infrastructure as Code (IaC)
    • D. Immutable Infrastructure
    Show answer

    B. Automated Provisioning

    Automated provisioning directly addresses the need to automatically build, test, and deploy resources and applications without manual intervention, which is central to a CI/CD pipeline.

  12. 12. A company is implementing a shared responsibility model for its cloud services. They are using a Platform as a Service (PaaS) offering for their application development. According to the shared responsibility model, which of the following is primarily the cloud provider's responsibility in this scenario?

    Cloud Architecture

    • A. Data encryption at rest for application data
    • B. Application code development and deployment
    • C. Operating system patching and management
    • D. Network configuration within the application
    Show answer

    C. Operating system patching and management

    In a PaaS model, the cloud provider is responsible for managing the underlying infrastructure, including the operating system, its patching, and the runtime environment. The customer focuses on their application code and data.

  13. 13. A cloud security engineer is implementing a new customer-facing application that processes sensitive personal identifiable information (PII). The application uses a microservices architecture deployed on Kubernetes. To ensure that communication between microservices is encrypted and authenticated, and to enforce fine-grained authorization policies, which solution should the engineer implement?

    Security

    • A. Configure Network Access Control Lists (NACLs) for each microservice pod.
    • B. Deploy a service mesh to manage inter-service communication.
    • C. Implement a VPN connection between each microservice.
    • D. Utilize a Web Application Firewall (WAF) at the ingress controller.
    Show answer

    B. Deploy a service mesh to manage inter-service communication.

    A service mesh (e.g., Istio, Linkerd) is specifically designed for microservices architectures to handle inter-service communication. It provides features like automatic mTLS (encryption and authentication), traffic management, and policy enforcement (fine-grained authorization) without requiring changes to application code.

  14. 14. A cloud administrator is configuring an auto-scaling group for a stateless web application. The application experiences predictable traffic spikes every weekday morning between 08:00 and 09:00 UTC and requires 10 instances during this period, but only 2 instances during off-peak hours. Which scaling configuration should be implemented to efficiently manage costs and performance?

    Operations

    • A. Step scaling policy based on network ingress.
    • B. Predictive scaling policy integrated with machine learning.
    • C. Scheduled scaling policy with minimum and desired capacities.
    • D. Target tracking scaling policy based on CPU utilization.
    Show answer

    C. Scheduled scaling policy with minimum and desired capacities.

    For predictable traffic spikes at specific times, a scheduled scaling policy is the most efficient. It allows the administrator to define exact scaling actions (e.g., increase to 10 instances at 07:55 UTC and decrease to 2 instances at 09:05 UTC) without relying on real-time metrics, thus preventing delays in scaling up and ensuring cost savings during off-peak hours.

  15. 15. A company is implementing a new cloud application that requires strong authentication for privileged users. The security team wants to ensure that even if a user's password is compromised, access to critical resources remains protected. Which authentication mechanism, when combined with a strong password, provides the MOST effective additional layer of security?

    Security

    • A. Security questions
    • B. Single Sign-On (SSO)
    • C. Knowledge-based authentication (KBA)
    • D. Biometric authentication
    Show answer

    D. Biometric authentication

    Biometric authentication, as a form of multi-factor authentication, provides a strong additional layer of security beyond a password, as it relies on something the user 'is' rather than something they 'know' or 'have'.

  16. 16. A cloud administrator is implementing a new security policy that mandates all virtual machines (VMs) must have a specific set of security agents installed and configured. This needs to be applied to both existing VMs and any new VMs provisioned in the future. Which lifecycle management tool or concept would best facilitate this consistent and automated deployment?

    Operations

    • A. Infrastructure as Code (IaC) with configuration management
    • B. Cloud provider's built-in snapshot feature
    • C. Manual SSH/RDP access and installation
    • D. Network Security Group (NSG) rules
    Show answer

    A. Infrastructure as Code (IaC) with configuration management

    Infrastructure as Code (IaC) allows defining infrastructure and its configuration in code. When combined with configuration management tools (like Ansible, Chef, Puppet), it ensures that security agents are automatically installed and configured on new VMs and can be consistently applied to existing ones, meeting the need for automation and consistency.

  17. 17. A cloud architect is designing a new application deployment that requires dynamic scaling based on demand. The application's components are stateless and can be easily replicated. Which provisioning strategy would be most suitable to ensure high availability and cost-effectiveness?

    Deployment

    • A. Just-in-Time Provisioning
    • B. Automated Provisioning
    • C. Static Provisioning
    • D. Manual Provisioning
    Show answer

    B. Automated Provisioning

    Automated provisioning allows for dynamic scaling and rapid deployment of resources based on predefined rules or real-time demand, which is crucial for stateless applications requiring high availability and cost-effectiveness. It eliminates manual intervention, reducing errors and speeding up resource allocation.

  18. 18. A cloud security engineer is configuring encryption for a new object storage bucket containing highly confidential data. The organization's policy dictates that only authorized applications, and not human users, should have direct access to the encryption keys. Which IAM mechanism, when combined with encryption-at-rest provided by the cloud provider, would BEST enforce this policy?

    Security

    • A. Granting IAM roles directly to the applications with specific key usage permissions.
    • B. Utilizing a Cloud Access Security Broker (CASB) to filter key access requests.
    • C. Implementing a strong password policy for all human users.
    • D. Storing encryption keys in a customer-managed Hardware Security Module (HSM).
    Show answer

    A. Granting IAM roles directly to the applications with specific key usage permissions.

    Granting IAM roles directly to applications with specific key usage permissions ensures that only the applications, authenticated via their assigned roles, can access the encryption keys, thereby preventing human users from direct access, as per the policy.

  19. 19. A cloud engineer is deploying a highly available application that requires its components to be distributed across multiple physical locations within a single cloud region to withstand localized failures. This ensures that if one data center goes offline, the application remains operational. Which cloud concept is being leveraged to achieve this resilience?

    Deployment

    • A. Content Delivery Network (CDN)
    • B. Regions
    • C. Edge Locations
    • D. Availability Zones
    Show answer

    D. Availability Zones

    Availability Zones (AZs) are distinct physical locations within a cloud region, each with independent power, cooling, and networking, designed to be isolated from failures in other AZs. Deploying across multiple AZs within a region ensures high availability against localized data center outages.

  20. 20. A cloud engineer is designing a highly available architecture for a web application. The application needs to distribute incoming traffic across multiple instances in different Availability Zones within a region. Which networking component should be deployed to achieve this?

    Cloud Architecture

    • A. Load Balancer
    • B. Network Access Control List (NACL)
    • C. VPC Endpoint
    • D. Internet Gateway
    Show answer

    A. Load Balancer

    A Load Balancer is specifically designed to distribute incoming application traffic across multiple targets, such as EC2 instances, in multiple Availability Zones, enhancing both performance and high availability.

  21. 21. A cloud administrator is tasked with deploying a highly available application that spans across multiple availability zones within a region. The application's web tier consists of identical virtual machines. Which network component is responsible for distributing incoming traffic evenly across these virtual machines and automatically rerouting traffic away from unhealthy instances?

    Deployment

    • A. Load Balancer
    • B. Network Security Group (NSG)
    • C. Router
    • D. Virtual Private Cloud (VPC)
    Show answer

    A. Load Balancer

    A Load Balancer distributes incoming network traffic across multiple servers (like virtual machines) to ensure high availability and scalability. It also performs health checks and automatically reroutes traffic away from unhealthy instances, ensuring continuous service.

  22. 22. A cloud administrator is configuring an identity and access management (IAM) policy for a new cloud storage bucket. The policy must grant a specific development team read-only access to a particular folder within the bucket, while denying them any write or delete permissions. Other teams should have no access to this folder. Which IAM policy construct should the administrator use to achieve this granular control?

    Security

    • A. Resource-based policy with 'Allow' on specific actions and 'Deny' on others.
    • B. Identity-based policy with 'Allow' on the bucket and 'Deny' on the folder.
    • C. Role-based access control (RBAC) with a custom role for read-only access to the folder.
    • D. Attribute-based access control (ABAC) using tags for the folder and team.
    Show answer

    C. Role-based access control (RBAC) with a custom role for read-only access to the folder.

    Role-based access control (RBAC) allows the creation of a custom role that explicitly defines read-only permissions for the specific folder. This role can then be assigned to the development team, ensuring they only have the required access and no others, while other teams are not assigned this role, thus having no access.

  23. 23. A cloud engineer is configuring monitoring for a newly deployed web application. The application consists of multiple microservices running in containers. The team needs to track HTTP request rates, error rates, and latency for each microservice, as well as overall container resource utilization (CPU, memory). Which type of monitoring is primarily being described?

    Operations

    • A. Synthetic monitoring
    • B. Infrastructure monitoring
    • C. Application performance monitoring (APM)
    • D. Log monitoring
    Show answer

    C. Application performance monitoring (APM)

    Application Performance Monitoring (APM) focuses on the performance and availability of software applications, including metrics like request rates, error rates, latency, and resource usage at the application or microservice level. While infrastructure monitoring captures container resource utilization, the specific focus on application-level metrics points to APM.

  24. 24. A cloud operations team is investigating performance degradation in a microservices-based application. They suspect that one of the underlying containers is consuming excessive resources but are unable to pinpoint which one using traditional host-level monitoring. Which of the following tools or techniques would be most effective for diagnosing this issue?

    Operations

    • A. Reviewing application logs for error messages.
    • B. Utilizing container-specific monitoring tools.
    • C. Network packet sniffing on the host machine.
    • D. Implementing a distributed tracing solution.
    Show answer

    B. Utilizing container-specific monitoring tools.

    Container-specific monitoring tools provide granular visibility into individual container resource consumption (CPU, memory, disk I/O, network) and performance metrics, which is crucial for identifying resource-intensive containers in a microservices environment.

  25. 25. A cloud operations team is investigating a severe performance degradation in a production web application. Monitoring metrics show a sudden and sustained drop in database connection pool availability, despite the database server itself showing normal CPU and memory utilization. Application logs are filled with 'connection refused' errors. Which of the following is the MOST likely cause of this issue?

    Operations

    • A. The application's auto-scaling group is failing to scale up.
    • B. The database server's network interface card (NIC) is failing.
    • C. The database server is experiencing high I/O wait times.
    • D. The application servers are exhausting their ephemeral port range.
    Show answer

    D. The application servers are exhausting their ephemeral port range.

    A sudden and sustained drop in database connection pool availability, with 'connection refused' errors, while the database server itself is healthy, strongly suggests that the *client* (application server) cannot establish new connections. Exhaustion of the ephemeral port range on the application servers prevents them from opening new outbound connections, leading to connection refused errors, even if the database is ready to accept them.

CompTIA Cloud+ (CV0-004) flashcards

Tap a card to flip it. 172 flashcards in the full deck.

  • Object Storage Bucket Policy Conditions

    Flip card

    Conditional statements within an object storage bucket policy that allow or deny actions based on specific criteria, such as object size, content type, or encryption status.

    • Provides fine-grained control over actions on objects.
    • Conditions can override general IAM permissions if met.
    • Often used for security (e.g., encryption enforcement) or operational limits (e.g., max object size).
    Study this card →
  • Cold Object Storage (Archive)

    Flip card

    Cold Object Storage, often referred to as Archive Storage, is a cloud storage tier optimized for extremely infrequent access and long-term data retention. It offers the lowest storage costs but typically has higher retrieval latency (minutes to hours) and potentially retrieval costs.

    • Lowest storage costs per GB
    • Designed for long-term archival and compliance
    • Infrequent access patterns
    Study this card →
  • Object Storage

    Flip card

    A data storage architecture that manages data as objects, distinct from other data types like files or blocks. Objects typically include the data itself, metadata, and a globally unique identifier.

    • Highly scalable and durable.
    • Ideal for unstructured data, backups, and static content.
    • Accessed via APIs (e.g., HTTP/S).
    Study this card →
  • Block Storage

    Flip card

    A storage architecture that treats data as blocks, each with a unique address, allowing them to be stored independently and attached directly to compute instances.

    • Provides raw storage volumes, like a virtual hard drive.
    • Offers low-latency access, suitable for databases and OS volumes.
    • Can be provisioned as Elastic Block Storage (EBS) or similar services.
    Study this card →
  • Load Balancer

    Flip card

    A device or service that distributes network traffic efficiently across multiple servers to ensure high availability and responsiveness.

    • Improves application scalability and reliability.
    • Performs health checks on backend servers.
    • Can be hardware or software-based.
    Study this card →
  • Bastion Host

    Flip card

    A special purpose server in a public subnet that acts as a secure jump server to access instances located in private subnets.

    • Provides a single, hardened entry point.
    • Requires inbound SSH/RDP rules from trusted IPs only.
    • Used to manage instances in private subnets without public IPs.
    Study this card →
  • Function as a Service (FaaS)

    Flip card

    Function as a Service (FaaS) is a serverless computing model where developers write and deploy small, single-purpose functions that are executed in response to events. The cloud provider fully manages all the underlying infrastructure, server provisioning, and scaling.

    • Serverless compute model
    • Event-driven execution
    • Automatic scaling (scales to zero)
    Study this card →
  • Reserved IP Addresses (Subnet)

    Flip card

    Specific IP addresses within a subnet's CIDR range that are reserved by the cloud provider for internal network services and cannot be assigned to customer resources.

    • Typically includes network address, broadcast address, and gateway.
    • Often includes addresses for DNS or other service endpoints.
    • Reduces the number of usable IP addresses for VMs/containers.
    Study this card →
  • Merge Conflict

    Flip card

    A situation where version control software cannot automatically reconcile changes made to the same part of a file in two different branches, requiring manual intervention.

    • Occurs during merge or rebase operations
    • Developer must manually edit conflict markers
    • Common with overlapping edits to shared files
    Study this card →
  • Automated Provisioning

    Flip card

    The process of automatically setting up and configuring IT infrastructure and application resources without manual intervention, often as part of a CI/CD pipeline.

    • Reduces human error and increases deployment speed.
    • Ensures consistency across environments.
    • Key component of CI/CD and DevOps practices.
    Study this card →
  • Shared Responsibility Model (PaaS)

    Flip card

    A framework outlining the security responsibilities between a cloud provider and its customer. In PaaS, the provider manages the underlying infrastructure and platform, while the customer is responsible for applications, data, and access controls.

    • Provider: physical security, infrastructure, OS, network controls
    • Customer: application, data, identity & access management, network configuration within app
    • Context-dependent on service model (IaaS, PaaS, SaaS)
    Study this card →
  • Service Mesh

    Flip card

    A dedicated infrastructure layer for handling service-to-service communication in microservices architectures, enabling secure and observable interactions.

    • Provides mTLS for encryption/authentication.
    • Enforces fine-grained authorization policies.
    • Abstracts networking concerns from application code.
    Study this card →
  • Scheduled Scaling

    Flip card

    An auto-scaling policy that adjusts the number of instances based on a predefined schedule, ideal for predictable traffic patterns.

    • Proactive scaling based on time.
    • Ensures resources are available before peak load.
    • Cost-effective by scaling down during off-peak times.
    Study this card →
  • Multi-Factor Authentication (MFA)

    Flip card

    An authentication method that requires a user to provide two or more verification factors to gain access to a resource.

    • Combines factors from different categories: knowledge, possession, inherence.
    • Significantly reduces the risk of credential compromise.
    • Common forms include passwords, tokens, biometrics.
    Study this card →
  • Infrastructure as Code (IaC)

    Flip card

    Managing and provisioning computer data centers through machine-readable definition files, rather than physical hardware configuration or interactive configuration tools.

    • Enables automation and repeatability.
    • Version control for infrastructure changes.
    • Reduces human error and ensures consistency.
    Study this card →
  • IAM Roles for Applications

    Flip card

    A cloud identity and access management feature that allows applications or services to assume specific roles with defined permissions, enabling secure access to other cloud resources without embedding credentials.

    • Provides temporary credentials for applications.
    • Enforces the principle of least privilege for programmatic access.
    • Key for securing communication between cloud services.
    Study this card →
  • Availability Zones (AZs)

    Flip card

    Logically and physically separate data centers within a single cloud region, designed to be isolated from failures in other AZs.

    • Provides high availability and fault tolerance.
    • Connected by low-latency links.
    • Allows distributing application components for resilience.
    Study this card →
  • Role-Based Access Control (RBAC)

    Flip card

    A method of access control where permissions are associated with roles, and users are assigned to roles, simplifying the management of complex access rights.

    • Permissions assigned to roles
    • Users assigned to roles
    • Simplifies access management
    Study this card →
  • Application Performance Monitoring (APM)

    Flip card

    Tools and processes used to monitor and manage the performance and availability of software applications.

    • Focuses on application-level metrics (e.g., response time, error rate).
    • Helps identify bottlenecks within the application code or services.
    • Often includes distributed tracing for microservices.
    Study this card →
  • Container Monitoring

    Flip card

    The process of collecting and analyzing metrics, logs, and events from individual containers to ensure their health, performance, and resource utilization.

    • Provides granular visibility into container-level resource consumption.
    • Includes metrics like CPU, memory, network I/O, and disk I/O per container.
    • Essential for microservices architectures and container orchestration platforms.
    Study this card →
  • Ephemeral Port Exhaustion

    Flip card

    Occurs when a client (e.g., an application server) attempts to open too many outbound connections in a short period, running out of available ephemeral (short-lived) port numbers.

    • Prevents new outbound connections.
    • Manifests as 'connection refused' or 'address already in use' errors.
    • Can be mitigated by increasing port range, connection pooling, or scaling out clients.
    Study this card →
  • VPC Routing Tables

    Flip card

    Rules that determine where network traffic from a subnet or gateway is directed, specifying targets for various IP address ranges.

    • Each subnet must be associated with a route table.
    • Contains local routes for intra-VPC communication.
    • Can include routes to Internet Gateways, VPNs, or peering connections.
    Study this card →
  • Idempotency

    Flip card

    A property where applying the same operation multiple times produces the same result as applying it once, without unintended side effects.

    • Core principle of configuration management tools
    • Prevents configuration drift from repeated runs
    • Enables safe re-execution of automation scripts
    Study this card →
  • Private/Service Endpoints

    Flip card

    Network interfaces that connect cloud services privately to a virtual network, preventing traffic from traversing the public internet.

    • Enhances security by isolating traffic.
    • Reduces attack surface for cloud services.
    • Requires services to be within the same virtual network.
    Study this card →

Questions are original practice items written to match the published exam objectives. Step2Study is not affiliated with or endorsed by any certification body.