D-CIS-FN-01 Cloud Infrastructure and Services Foundations Practice Questions
Prepare for D-CIS-FN-01 with more than an answer.
- Time limit
- 90 minutes
- Questions on the exam
- ~60
- Passing score
- 60% (scale 0-100%)
- Level
- Foundations
- Valid for
- Does not expire
Domains covered on the exam 4
- Digital Transformation, Cloud Computing Reference Architecture, and Introduction to Cloud Computing16%
- Application, Cloud Services, Orchestration, and Modern Infrastructure28%
- Cloud Security and Business Continuity42%
- Cloud Service Management and IT Transformation14%
- 1
A security architect is designing a defense-in-depth strategy for a new public-facing web application hosted in the cloud. The goal is to protect against common web vulnerabilities and ensure secure user access. Which security control mechanisms should be implemented as part of this strategy? (Select THREE)
Show answer details
Correct answer: A, B, D
A WAF is essential for protecting against web-based attacks like SQL injection and cross-site scripting (XSS).
MFA is critical for securing user accounts and preventing unauthorized access, even if passwords are compromised.
An IAM system is fundamental for managing user identities and enforcing the principle of least privilege, ensuring users only have access to the resources they need.
- 2
Which of the following is a key characteristic of a microservices architecture that distinguishes it from a traditional monolithic application?
Show answer details
Correct answer: B
In a microservices architecture, an application is built as a collection of small, independent services. Each service is self-contained, runs in its own process, and communicates with other services through well-defined APIs. This loose coupling allows individual services to be developed, deployed, and scaled independently, which is a major advantage over monolithic designs where the entire application must be redeployed for any change.
- 3
An enterprise is using a private cloud for sensitive data processing and a public cloud for its customer-facing web applications. They have implemented technology that allows workloads and data to be moved between these two environments seamlessly. What is the correct term for this cloud deployment model?
Show answer details
Correct answer: C
A hybrid cloud is a composition of a public cloud and a private environment, such as a private cloud or on-premises data center, with orchestration and connectivity between the two. The key characteristic described is the integration and workload portability between the private and public cloud environments, which defines a hybrid cloud model.
- 4
A hospital's patient record system requires a disaster recovery solution between two data centers located 500 km apart. The system must have a Recovery Point Objective (RPO) of zero to prevent any loss of critical patient data. However, application performance must not be significantly impacted by the replication process. Which data replication method presents the greatest challenge in meeting all these requirements simultaneously?
Show answer details
Correct answer: C
Synchronous replication is the only method that can achieve a zero RPO, as it requires write acknowledgment from both the primary and secondary sites before confirming the write to the application. However, the speed of light introduces latency over long distances (500 km). This latency directly impacts application performance, as the application must wait for the round trip acknowledgment. Therefore, meeting the zero RPO requirement with synchronous replication over a long distance while also avoiding performance impact is a significant challenge.
- 5
An operations manager is reviewing the monthly cloud spending report for their organization. The goal is to identify the largest area of expenditure to target for cost optimization efforts. The following chart shows the cost distribution.
Based on this data, which area should be the primary focus for optimization?
pie title Monthly Cloud Service Costs "Compute Instances" : 55 "Object Storage" : 15 "Managed Databases" : 20 "Network Egress" : 5 "Other" : 5Show answer details
Correct answer: D
According to the pie chart, Compute Instances account for 55% of the total monthly cloud costs, which is more than all other categories combined. To make the most significant impact on cost reduction, the operations manager should prioritize optimizing compute resources. This could involve right-sizing instances, using reserved instances, or implementing auto-scaling.
- 6
A cloud engineering team needs to provision infrastructure on multiple cloud platforms using a single, declarative configuration language. The team wants to define the desired state of their infrastructure in code, preview changes before applying them, and have a consistent workflow for provisioning resources regardless of the target cloud provider. Which type of tool is best suited for this task?
Show answer details
Correct answer: B
Infrastructure as Code (IaC) tools like Terraform are specifically designed for provisioning and managing infrastructure using a declarative approach. Terraform uses a consistent workflow (init, plan, apply) and supports multiple cloud providers, which directly matches the team's requirements. While configuration management tools like Ansible can provision infrastructure, they are primarily focused on configuring existing systems (procedural), whereas Terraform excels at provisioning the systems themselves (declarative).
- 7
Before an organization can develop an effective business continuity plan, it must first understand which business functions are most critical and the potential impact a disruption to those functions would have. What is the name of the formal process used to identify and evaluate the potential effects of an interruption to critical business operations?
Show answer details
Correct answer: C
A Business Impact Analysis (BIA) is the foundational process in business continuity planning. Its purpose is to identify critical business functions and determine the quantitative (financial) and qualitative (reputational) impacts that a disruption might have on them. The output of the BIA, including Recovery Time Objectives (RTO) and Recovery Point Objectives (RPO), directly informs the strategy for the Business Continuity Plan (BCP) and Disaster Recovery Plan (DRP).
- 8
A financial services firm is migrating its on-premises data warehouse to a hybrid cloud model. To comply with industry regulations, the firm must ensure that data encryption keys are never accessible to the cloud provider. The security team has mandated a solution where key generation, storage, and management remain entirely within the firm's on-premises hardware security module (HSM). Which security control mechanism meets this stringent requirement?
Show answer details
Correct answer: C
Hold Your Own Key (HYOK) is the correct model for this scenario. It allows an organization to use its on-premises key management infrastructure, such as an HSM, to generate and manage encryption keys. The cloud service uses these keys to encrypt and decrypt data but never has access to the keys themselves, fulfilling the strict compliance requirement. Cloud provider-managed keys and keys in a cloud vault both involve the provider having some level of access or control, which is forbidden by the requirements. Encryption in use protects data during processing, which is different from key management.
- 9
An organization is implementing the 3-2-1 backup rule for its critical data. The primary data resides on a Dell EMC VxRail cluster. Which actions align with the principles of this rule? (Select THREE)
Show answer details
Correct answer: B, C, D
The 3-2-1 rule dictates maintaining at least three copies of your data (the primary data plus two backups).
The rule specifies using two different storage media types (e.g., disk and cloud storage, or disk and tape) to protect against media-specific failures.
The rule requires keeping one copy off-site to protect against local disasters like fire or flood.
- 10
A retail company runs a monolithic e-commerce application on-premises. The application is difficult to scale during peak shopping seasons, and deploying new features takes months. The company wants to improve agility and scalability. The application's core business logic is sound, but its components are tightly coupled. They want to move to the cloud without a complete rewrite, while enabling individual services (like payment processing and inventory) to be scaled and updated independently. Which application modernization approach is most suitable?
Show answer details
Correct answer: C
Refactoring is the most appropriate approach. It involves restructuring and re-architecting parts of the application to take advantage of cloud-native features, such as breaking down the monolith into microservices. This directly addresses the need to scale and update components independently without a complete rewrite. Rehosting would not solve the underlying architectural problems. Replatforming would make only minor changes. Rebuilding implies a complete rewrite, which the company wants to avoid.
