CompTIA Cloud+ (CV0-004)OperationsMedium

A cloud administrator is implementing a new security policy that mandates all virtual machines (VMs) must have a specific set of security agents installed and configured. This needs to be applied to both existing VMs and any new VMs provisioned in the future. Which lifecycle management tool or concept would best facilitate this consistent and automated deployment?

  1. AInfrastructure as Code (IaC) with configuration management
  2. BCloud provider's built-in snapshot feature
  3. CManual SSH/RDP access and installation
  4. DNetwork Security Group (NSG) rules
Show answer & explanation

Correct answer: A. Infrastructure as Code (IaC) with configuration management

Infrastructure as Code (IaC) allows defining infrastructure and its configuration in code. When combined with configuration management tools (like Ansible, Chef, Puppet), it ensures that security agents are automatically installed and configured on new VMs and can be consistently applied to existing ones, meeting the need for automation and consistency.

Why the other options are wrong

  • B. Snapshots capture the state of a VM at a point in time but don't automate the installation of agents on new VMs or manage ongoing configuration.
  • C. Manual installation is error-prone, time-consuming, and not scalable or consistent for a large or growing environment.
  • D. NSG rules manage network traffic flow but do not install or configure software agents on VMs.

Infrastructure as Code (IaC)

Managing and provisioning computer data centers through machine-readable definition files, rather than physical hardware configuration or interactive configuration tools.

  • Enables automation and repeatability.
  • Version control for infrastructure changes.
  • Reduces human error and ensures consistency.

Memory trick: IaC builds your cloud with 'Code', not 'Clicks'.

More Operations questions