Skip to content

CompTIA Cloud+ Practice Questions

Prepare for CV0-004 with more than an answer.

226 questions in the full set20 sample questionsUpdated Jan 28, 2026

Unlock the full exam and previous versions

  • v1Version 1 226 questions Current
  • CV0-002Legacy Cloud+ 228 questions Locked
Exam fee
$358 USD
Level
Professional
Valid for
3 years
Domains covered on the exam 6
  1. Cloud Architecture23%
  2. Deployment19%
  3. Operations17%
  4. Security19%
  5. DevOps Fundamentals10%
  6. Troubleshooting12%
  1. 1

    During a post-incident review of a service outage, an SRE team determined that a recent deployment introduced a critical bug. The CI/CD pipeline successfully passed all unit and integration tests, but the issue only manifested under production load. The team wants to implement a deployment strategy that would allow them to safely test new code on a small percentage of live traffic before a full rollout. Which strategy should they adopt?

    Show answer details

    Correct answer: D

    A canary deployment is specifically designed for this scenario. It involves rolling out the new version of the application to a small subset of users or servers (the 'canary'). This allows the team to monitor its performance and error rates under real production traffic. If the new version performs well, traffic is gradually shifted until all users are on the new version. If issues are detected, traffic can be quickly routed back to the stable version, minimizing the impact of the bug.

  2. 2

    A cloud architect is designing a highly available and fault-tolerant web application on AWS. The application will be deployed across multiple Availability Zones. Which of the following AWS services should be placed in front of the web server fleet to distribute incoming traffic and perform health checks?

    Show answer details

    Correct answer: D

    An Application Load Balancer (ALB) is the correct service for this purpose. It is designed to operate at the application layer (Layer 7) and can distribute HTTP/HTTPS traffic across multiple targets, such as EC2 instances, in multiple Availability Zones. Crucially, it performs health checks on the targets and automatically routes traffic only to healthy instances, which is essential for building a highly available and fault-tolerant system.

  3. 3

    True or False: In a public cloud environment, the customer is always responsible for patching the guest operating system of their IaaS virtual machines.

    Show answer details

    Correct answer: A

    This statement is true. According to the shared responsibility model for Infrastructure as a Service (IaaS), the cloud provider is responsible for the security of the cloud (i.e., the physical infrastructure, network, and hypervisor). The customer is responsible for security in the cloud, which includes securing and patching the guest operating system, managing applications, configuring firewalls, and controlling data access.

  4. 4

    A DevOps team is using an Ansible playbook to configure a fleet of web servers. The playbook needs to install Apache, ensure the service is running, and deploy a custom index.html file. The team wants to ensure the playbook can be run multiple times without causing errors or changing the system if it's already in the desired state. This quality is known as _______.

    Show answer details

    Correct answer: C

    Idempotency is a core principle of configuration management tools like Ansible. It means that applying an operation multiple times will have the same result as applying it once. An idempotent playbook checks the current state of the system before making any changes. For example, it will only install Apache if it's not already installed and will only start the service if it's not already running. This makes automation reliable and predictable.

  5. 5

    A cloud administrator is troubleshooting a network connectivity issue between two EC2 instances in the same VPC but in different subnets. Instance A (10.0.1.10) cannot ping Instance B (10.0.2.20). The security groups for both instances allow all traffic from the 10.0.0.0/16 CIDR block. What is the MOST likely cause of the issue?

    Show answer details

    Correct answer: B

    Since the security groups (which are stateful) are correctly configured to allow traffic, the next layer of network defense to check is the NACL (which is stateless). NACLs operate at the subnet level. A common issue is a default or custom NACL that does not explicitly allow ICMP (ping) traffic, or its outbound/inbound rules for the ephemeral port range are misconfigured, thus blocking the return traffic. The route tables are less likely to be the issue for intra-VPC traffic, as the local route is added by default.

  6. 6

    A company is migrating a legacy monolithic application to a microservices architecture hosted in Google Kubernetes Engine (GKE). The development team is concerned about managing the complex network communication, security, and observability between the dozens of new services. Which technology should be implemented within the GKE cluster to address these concerns centrally?

    Show answer details

    Correct answer: B

    A service mesh is an infrastructure layer that handles inter-service communication in a microservices architecture. It provides features like traffic management (e.g., routing, load balancing), security (e.g., mutual TLS encryption), and observability (e.g., distributed tracing, metrics) out-of-the-box. By deploying a service mesh like Istio, the team can manage these complex cross-cutting concerns at the platform level without embedding the logic in each individual microservice, greatly simplifying development and operations.

  7. 7

    Case Study

    Company Background:
    RetailNow is a fast-growing e-commerce company that has traditionally run its entire infrastructure on-premises. They are planning a phased migration to a multi-cloud environment, primarily using AWS for their core transactional systems and Azure for data analytics and business intelligence. Their on-premises environment consists of VMware vSphere for virtualization, NetApp storage arrays, and a mix of Windows and Linux servers. The company's peak season is from November to December, during which traffic increases by over 500%.

    Current Situation:
    The first phase of the migration involves moving the product catalog service, a three-tier web application, to AWS. The service consists of a web front-end, an application logic tier, and a PostgreSQL database. The on-premises database is 2TB in size. The team has limited cloud experience and wants to minimize the initial refactoring effort for this first migration. They are using Terraform to manage infrastructure as code.

    Requirements:

    1. The migration must be completed with minimal downtime (less than 1 hour).
    2. The AWS architecture must be highly available and automatically scale to handle peak season traffic.
    3. The database migration must ensure data consistency between the on-premises and cloud environments during the transition.
    4. The entire infrastructure stack must be defined in Terraform for reproducibility.
    5. The solution must be cost-effective during non-peak months.

    Which migration and architecture plan BEST meets all of RetailNow's requirements?

    graph TD subgraph On-Premises direction LR OnPrem_DB[(PostgreSQL)] OnPrem_App[App Tier] OnPrem_Web[Web Tier] end subgraph AWS Cloud direction LR Cloud_DB[(RDS PostgreSQL)] Cloud_App[EC2 Auto Scaling Group] Cloud_Web[EC2 Auto Scaling Group] end OnPrem_DB -- DMS Replication --> Cloud_DB User --> DNS DNS -- Cutover --> ALB ALB --> Cloud_Web --> Cloud_App --> Cloud_DB

    Show answer details

    Correct answer: C

    This plan meets all requirements. Using EC2 instances in an Auto Scaling group provides high availability and scalability for peak traffic, while also allowing for scaling down to be cost-effective. A Multi-AZ RDS instance ensures database HA. AWS DMS with ongoing replication is the ideal tool for a minimal downtime database migration, ensuring data consistency until the final cutover. Using Terraform aligns with the IaC requirement. This approach represents a 'replatform' or 'lift-and-tinker' strategy, which minimizes initial refactoring while leveraging key cloud capabilities.

  8. 8

    A software engineer needs to transfer data over the internet using programmatic access while also being able to query the data. Which of the following will best help the engineer to complete this task?

    Show answer details

    Correct answer: D

  9. 9

    Which of the following is a field of computer science that enables computers to identify and understand objects and people in images and videos?

    Show answer details

    Correct answer: D

  10. 10

    A company needs to deploy its own code directly in the cloud without provisioning additional infrastructure. Which of the following is the best cloud service model for the company to use?

    Show answer details

    Correct answer: A

Create an account to continue.