CV0-004 practice questions
CompTIA · CV0-004 · 300 questions
Validates intermediate cloud infrastructure skills across vendor-neutral multi-cloud environments, covering cloud architecture, deployment strategies, operations, security, DevOps fundamentals, and troubleshooting of deployment, network, and security issues.
This course contains the use of artificial intelligence.
About the CV0-004 exam
- Time allowed
- 1 hour 30 minutes
- Questions
- Maximum of 90
- Passing score
- 750 (scale 100-900)
- Format
- Multiple-choice and performance-based
Exam details published by the vendor, checked 28 August 2026. Vendors change fees and formats without notice — confirm on the vendor's own page before you book.
Practice Quizzes
Test your knowledge with standard 20-question practice sets.
Quiz 1
Quiz 2
Quiz 3
Quiz 4
Quiz 5
Quiz 6
Quiz 7
Quiz 8
Quiz 9
Quiz 10
Quiz 11
Quiz 12
Quiz 13
Quiz 14
Quiz 15
Browse by Domain
Study specific topics at your own pace.
Cloud Architecture · 69 questions
- A county GIS team needs virtual machines, guest OS control, and custom map engines they fully administer. Staff debate whether a turnkey SaaS mapping portal is enough. Which cloud service model fits their requirement?
- A city permitting portal team wants to deploy application code without patching servers or managing the runtime. Which cloud service model best matches that goal?
- A parks department adopts email and collaboration as a complete vendor-hosted application with no infrastructure to manage. A board member labels the purchase Infrastructure as a Service. Which service model is actually in use?
- Public works wants short event-driven jobs that resize citizen photo uploads on demand without provisioning or patching servers. Which model best fits?
- A mayor assumes that moving municipal virtual machines to the cloud means the provider now patches every guest OS and every city application. Under a typical IaaS shared-responsibility model, what remains the city's responsibility?
- A library consortium runs Platform as a Service web apps and argues that nobody on staff needs to do security work anymore. Which customer responsibilities still apply on PaaS?
- An auditor asks whether shared responsibility with a cloud provider is always a fixed 50/50 split. Which statement is accurate for CompTIA Cloud+ service models?
- A township compares renting virtual machines (IaaS), a managed application platform (PaaS), and a complete HR Software as a Service suite for the same payroll need. How should leaders choose?
- A city must keep citizen data in a named geographic area to meet residency rules and is deciding where to place primary cloud workloads. Which concept describes a geographic grouping of datacenters used for that placement?
- A 911 computer-aided dispatch redesign must remain available if a single datacenter fails inside one metro cloud region. Which construct provides that failure-domain isolation?
- Tax season spikes overwhelm on-premises capacity, and the county wants temporary overflow into the public cloud until demand drops. Which approach describes that pattern?
- Transit fare kiosks need processing close to stations for low latency rather than sending every transaction to a distant central region. Which approach best addresses that need?
- A continuity plan states municipal systems must resume within 4 hours and lose no more than 15 minutes of data. Which pair correctly maps those targets?
- Emergency management compares a fully mirrored ready site, a partially equipped site, and bare facility space for disaster recovery. Which statement correctly contrasts those site types?
- A regional consortium runs workloads across two cloud providers so a single vendor outage does not stop all citizen services. Which resilience approach does that describe?
- Remote municipal staff need encrypted access from home networks into a private cloud VPC without exposing every server to the public internet. Which connectivity approach fits?
- A court records system needs consistent high bandwidth and low jitter to the cloud rather than a best-effort internet VPN. Which connectivity option best matches that requirement?
- A citizen web portal must distribute HTTPS sessions across healthy application instances based on application content such as URL path. Which load-balancing approach is appropriate?
- A UDP-based telemetry intake must distribute flows by IP and port without inspecting HTTP paths. Which load balancer type fits?
- Static park maps and videos should cache near citizens worldwide to cut origin load and latency. Which cloud networking capability provides that?
- Two city VPCs need private routing between them without hairpinning traffic through the public internet. Which construct provides that private connectivity?
- Many spoke VPCs must interconnect through a hub rather than a full mesh of individual peerings. Which approach scales that design?
- Network teams want centralized, policy-driven virtual networking instead of configuring each device only with isolated static settings. Which concept describes that model?
- Daily active case files need low-latency access, while decade-old closed cases are rarely opened. How should storage tiers be aligned?
- A body-worn camera archive will almost never be read unless subpoenaed years later. Which storage approach best fits that access pattern?
- A municipal IT team must attach a raw boot disk to a city VM, share a hierarchical department folder for staff, and store a media lake addressed by API keys. Which storage mapping best matches these three needs?
- City database logs need sustained high IOPS with low latency, while bulk document scans can tolerate slower cheaper media. Which disk choice correctly matches both workloads?
- Finance asks why hot object storage for open-data GIS tiles costs more per GB than archive storage holding the same total size of infrequently retrieved maps. What best explains the price difference?
- A parks department app stores unstructured trail photos with metadata keys and never mounts a traditional filesystem for those images. Which storage approach best fits this design?
- A city prefers a provider-operated database service so staff stop patching database VMs themselves. Which cloud-native choice best reflects that preference?
- Permitting is split into small independently deployable services for payments, inspections, and notices instead of one monolith. What cloud-native concept does this primarily illustrate?
- If the notice service fails, city payments should keep working, so teams avoid hard synchronous coupling everywhere. Which design goal are they pursuing?
- One citizen upload event must notify virus scan, thumbnail, and archive services without the uploader calling each consumer directly. Which pattern best fits?
- Containers must find the current healthy payments endpoint without hard-coded IPs that change on every deploy. What capability should the platform provide?
- A developer runs one utility container on a laptop with no cluster scheduler for a one-off civic script. How does this differ from production orchestrated workloads?
- Production microservices for licensing need scheduling, automatic restarts, and scaling across a node pool. Which approach best meets those needs?
- A containerized permitting API listens on port 8080 inside the container but must reach citizens on 443 outside. What container networking concept solves this?
- User permit uploads must survive container restarts, while temp build cache can disappear when the container dies. Which storage distinction should the team apply?
- Teams store approved application images in a central place so deploy jobs can pull them during rollouts. What component fulfills that role?
- A stateful inspection app needs data that outlives pod rescheduling onto another node. Which storage choice best fits?
- A single hypervisor hosts a few departmental VMs with no failover cluster. Which virtualization model does this describe?
- If one virtualization host fails, city VMs should restart automatically on another host in the pool. Which capability provides that behavior?
- Before a major OS upgrade, admins want an identical copy of a tax-system VM for rollback testing. Which virtualization operation should they use?
- A licensed appliance VM must always run on a specific host that holds a hardware dongle. Which virtualization control enforces that placement?
- A forensic lab VM needs direct access to a specialty PCIe card that cannot be fully virtualized. Which technique assigns that device to the guest?
- Storage for city VMs may be local disks, shared SAN block, or NAS file shares depending on mobility needs. Which statement correctly contrasts these options?
- Compliance requires a physical server not shared with other tenants for a sensitive municipal workload. Which cloud cost or tenancy model best matches?
- A steady 24/7 records system will run unchanged for three years, and finance wants a discount for that commitment. Which pricing approach fits best?
- A weekend civic hackathon needs VMs only for two days with no long commitment. Which billing model is most appropriate?
- Batch GIS rendering can stop if capacity is reclaimed and restart later, and the city wants deep discounts for that flexibility. Which instance model fits?
- A city finance office wants every cloud resource labeled by department so monthly chargeback reports can allocate spend accurately. Which practice best enables that cost allocation?
- Monitoring shows a municipal VM averaging about 8% CPU for several months with no planned load spike. What cost action best addresses that waste?
- County payroll requires ACID transactions, normalized employee and deduction tables, and strict foreign-key relationships. Which database approach best fits?
- A citizen-feedback portal stores evolving JSON documents whose fields change as new survey types appear. Which database pattern fits better than a rigid relational schema?
- Municipal DBAs insist on installing, patching, and tuning the database engine themselves on virtual machines. Which deployment option are they choosing?
- City ops wants automated backups, patching, and high-availability features handled by the cloud vendor for a departmental database. Which option matches?
- A project team debates whether citizen records need rigid relational schemas or flexible documents, while another debate asks who patches the database engine. What distinction should the architect emphasize?
- A legacy Windows line-of-business app needs a full guest operating system and vendor-supported OS-level agents, while a new stateless REST API packages cleanly with its runtime. How should the city optimize packaging?
- A nightly municipal PDF generation job runs for a few minutes and sits idle the rest of the day. Which compute approach best avoids paying for an always-on VM?
- Dozens of city microservices need automated placement across nodes, rolling updates, and self-healing when a container dies. Which capability primarily provides that?
- A multi-step building-permit approval must move documents through scan, then human review, then citizen notify — in that order. Which optimization approach sequences those steps?
- Overseas users report that a city portal feels slow even though server CPU sits nearly idle. Distance to the hosting region is high. What is the most likely limiter?
- A municipal database volume cannot keep up with transaction writes even though the VM CPU has free headroom. What bottleneck class should the team investigate first?
- Instead of operating a message broker on city-managed VMs, the team adopts a provider-operated queue service. What optimization benefit does that primarily deliver?
- A 311 application should automatically extract text from photos of handwritten citizen complaint forms. Which evolving cloud capability best matches at Cloud+ awareness depth?
- A tourism site needs automatic translation of park descriptions into multiple languages for visiting travelers. Which cloud AI capability applies?
- Communications wants draft press releases assisted by generative models, with staff reviewing every draft before publication. What evolving cloud capability does this describe?
- Smart water meters across neighborhoods send readings through field gateways before data reaches cloud analytics. Which IoT pattern does this illustrate?
- Field devices for utility telemetry must use appropriate lightweight protocols so constrained sensors can transmit reliably to the cloud. What should the architecture emphasize?
Deployment · 57 questions
- A small town consumes email and file sync entirely from a multi-tenant provider over the internet with no city-owned compute for those services. Which deployment model is this?
- Police evidence systems must remain on city-controlled infrastructure dedicated to that agency alone. Which cloud deployment model fits?
- Computer-aided dispatch stays in the city datacenter while the public website bursts to a provider, and both environments operate together. Which model is this?
- Several counties share a purpose-built cloud for mutual-aid GIS with shared governance among those agencies. Which deployment model applies?
- A councilor calls any remote SaaS 'private cloud' because users log in with passwords. What correction should cloud staff give?
- Finance prefers CapEx ownership of gear yet still labels rented public-cloud VMs as 'private cloud' solely because a VPC isolates the network. What misconception should be corrected?
- A university research group and the city open-data office jointly fund a shared environment for civic datasets, with shared governance and a common compliance posture. Which cloud deployment model best fits this arrangement?
- After a ransomware event, the city keeps identity services on-premises but rebuilds citizen-facing apps in public cloud at the same time. Which deployment model describes this split of responsibilities?
- A new municipal portal version runs in parallel environment B while production traffic stays on environment A until cutover; rollback means flipping traffic back to A. Which deployment strategy is this?
- Only 5% of citizens should see the new UI first while metrics are watched before a wider rollout. Which deployment strategy matches this plan?
- City permit API instances are upgraded a few at a time so the service never goes fully dark. Which deployment strategy is being used?
- A tiny utility VM is upgraded on the same instance during a maintenance window with brief downtime accepted. Which deployment strategy fits this approach?
- Rollback must be near-instant after a bad release without rebuilding every server from scratch. Which strategy best supports that requirement?
- A risk-averse city council wants limited blast radius on day one of a citizen portal redesign. Which deployment strategy best minimizes initial user exposure?
- Capacity is tight and running two full production stacks for blue-green is too expensive for the parks reservation API. Which deployment approach is most appropriate?
- Health checks fail mid-rollout on the tax-payment API. What should the team do regarding the rolling wave?
- A stateful network appliance used for city VPN aggregation cannot easily run two versions side by side. Which deployment strategy is most realistic for its upgrade?
- Feature flags plus a tiny traffic slice will validate a payments change before citywide enablement. Which deployment strategy does this describe?
- After green proves healthy for the licensing portal, blue is kept briefly as instant rollback capacity and then recycled. Which practice does this describe?
- Ops confuses a canary (small user percentage) with blue-green (full parallel environment switch). What is the key distinction?
- A basement datacenter permitting app is moved into public cloud VMs with minimal redesign. Which migration direction does this represent?
- A SaaS trial ends and the city must bring data and processing back into its own datacenter. Which migration type is this?
- Workloads move from Provider A to Provider B after a municipal contract change. Which migration type is this?
- The city lifts permitting VMs to cloud IaaS with almost no code change to exit aging hardware quickly. Which migration strategy is this?
- The inspection app keeps most of its code but swaps self-managed MySQL for a provider-managed database. Which migration strategy best describes this?
- A monolith for citizen casework is redesigned into microservices and managed services to gain cloud-native scalability. Which migration strategy is this?
- A rarely used legacy license server stays on-premises for now during the cloud migration program. Which 6 R-style decision is this?
- An unused departmental Access application is shut down instead of migrated. Which migration strategy decision is this?
- Code is reworked to use cloud APIs and eventing while preserving external behavior for the grants portal. Which migration strategy is this?
- Before moving the records-management workload, teams size CPU, RAM, and disk so cloud resources match the workload profile. Which migration consideration is this?
- Large historical archives may need offline appliance shipping rather than weeks of thin WAN upload during the city's cloud migration. Which migration consideration does this highlight?
- A city's legacy permitting app still requires an OS build the target cloud marketplace images no longer offer cleanly. What migration consideration does this primarily highlight?
- A county evaluates leaving a niche PaaS that stores case files in proprietary export formats. What migration risk should planners emphasize?
- Citizen PII for a municipal benefits system must remain in-country, and several destination regions fail that rule. What migration constraint is this?
- A city plans to exit its on-premises datacenter as part of a cloud migration business case. Besides application hosting, which facilities consideration should finance include?
- Municipal cloud ops wants networks, VMs, and load balancers declared once and applied the same way every time. Which approach best meets that need?
- Ops wants OS packages, services, and config files on city VMs installed identically every time. Which practice fits best?
- A deployment script sets the cloud region from a variable and creates a NAT gateway only when a flag is true. What scripting concepts does this demonstrate?
- Cloud engineers wrap tagging standards in reusable functions so every municipal stack applies the same labels. Why does that modularity help?
- Two staging and production environments for a city portal are created from the same template and should match aside from parameters. Which IaC benefit is being pursued?
- Someone changed a security group in the cloud console for a city API. Automation must notice the live setup no longer matches the desired code. What capability is needed?
- A municipality stores infrastructure templates in Git so every change is reviewed and can be rolled back. What practice does this illustrate?
- A city pipeline validates infrastructure templates in a sandbox before any production apply. What is the primary goal?
- Runbooks explain how deployment parameters map to each municipal environment for the next on-call engineer. Why keep that documentation with the automation?
- A deployment definition for city cloud resources is stored as nested key/value text that many cloud APIs accept natively. Which common format is described?
- Ops prefers indentation-based, human-friendly templates for Kubernetes manifests and many automation tools in the city platform. Which format fits that preference?
- An engineer hotfixes a city load balancer in the console, then the next pipeline run overwrites the change. What lesson should the team reinforce?
- Police video evidence needs multi-petabyte capacity with infrequent retrieval after about 90 days. Which provisioning choice best matches those requirements?
- A municipal OLTP database requires disks with guaranteed high IOPS and low latency. What should provisioning emphasize?
- Citizen PII volumes for a benefits app must use encryption and must not be reachable over the public internet. What should provisioning enforce?
- A seasonal park reservation system must minimize idle cost between tourist peaks. Which provisioning approach best fits?
- The voting results API SLA requires survival of an availability-zone failure. How should resources be provisioned?
- A city recreation portal will process cardholder data and must land in architectures and controls suited to that obligation. What drives the provisioning choices?
- A latency-sensitive CAD integration between city design systems needs private connectivity and carefully sized bandwidth. What network provisioning focus is required?
- Batch map rendering needs many short-lived vCPUs, while an interactive GIS desktop needs fewer stronger cores or GPU-class instances. What compute provisioning principle applies?
- Architects face cheapest archive storage versus a mandate for sub-second retrieval on the same dataset. What should they do?
- A county cloud team must provision storage, compute, networking, and security controls for a new permit portal, but architects keep skipping categories until after click-ops begin. What approach best maps business requirement categories to concrete resource choices before anyone creates resources?
Operations · 51 questions
- City app servers for parking, licensing, and inspections write logs only to local disks, so ops cannot search a single incident across the fleet. What observability capability should the municipality configure first?
- Each microservice in the city’s citizen-account platform ships structured JSON logs that must be searchable in one place during outages. Which configuration best meets that need?
- Compliance requires the city to keep authentication logs for a defined period and then delete them. What should ops configure to balance that mandate with cost and privacy?
- A slow citizen checkout spans the API gateway, payments service, and notify service, and ops needs the path of one request end to end. Which observability approach should they use?
- Municipal dashboards for a tax portal should show CPU, request rate, and error rate over time—not only raw log lines. What should the operations team emphasize?
- When the city’s permit API error rate exceeds a threshold, on-call staff must be notified within minutes. What should ops configure?
- Night alerts flood the municipal on-call channel, and the team must rank which pages are urgent versus noise. What practice should they apply first?
- After triaging a water-billing outage alert, responders must mitigate the issue and keep stakeholders informed. What should guide that work?
- Without historical baselines, every CPU spike on the city’s GIS servers looks like an emergency. What should ops establish to make metrics and alerting meaningful?
- Developers want enough traces from the 311 app to debug issues without paying to store every request forever. Which design trade-off should ops apply?
- Security asks whether admin actions on the city’s cloud console are logged separately from noisy application debug spam. What should operations ensure?
- A black-box outage shows green VM metrics for the recreation portal, yet citizen journeys still fail. What observability insight should the team apply?
- Observability retention for the city’s multi-cloud estate is set to forever “just in case,” and storage cost is exploding. What should ops do?
- On-call receives an alert storm from one root failure cascading across municipal microservices. What observability practice reduces duplicate pages from that single incident?
- Peak permit season needs more capacity on identical web instances rather than enlarging a single box. Which scaling approach should the city use?
- A municipal database VM that cannot easily shard is saturating CPU and RAM. Which short-term scaling approach fits best?
- Autoscaling for the city’s library catalog API should react when average CPU trends upward over a monitoring window. What kind of scaling is that?
- The transit mobile backend should scale out when concurrent sessions or request queue depth crosses a load threshold. Which approach matches that requirement?
- A flood of IoT events from city sensors should spawn more consumer workers automatically. What scaling pattern fits?
- Every weekday at 7:00 before commute, transit apps need more capacity. Which scaling approach should ops configure?
- During a one-off election-night war room, ops needs extra capacity that automation was not designed to cover. Which scaling approach is appropriate?
- A stateful legacy permitting app cannot safely run multiple writers. Which short-term scaling choice is safest?
- When the city’s web tier scales in, active citizen sessions must not be cut mid-request. What should scale-in policies include?
- Municipal autoscaling flaps between scale-out and scale-in within minutes, thrashing instance counts. What stability control should ops add?
- A county permitting portal autoscales under load, but a runaway rule once spun up hundreds of instances overnight and exhausted the cloud budget. What scaling guardrail should operations set?
- A city recreation registration API sees heavy weekday traffic but almost none on weekends, yet the same peak capacity stays running Saturday and Sunday. What scaling approach best cuts idle cost?
- A municipal tax database team wants Sunday to capture a complete copy of the system, then weekdays to capture only what changed since the previous backup job. Which backup pattern matches that plan?
- Nightly county payroll backups must include every change since last Sunday’s full backup, not merely changes since last night’s job. Which backup type fits?
- A town hall keeps production VMs and all backup disks in the same on-premises rack. What backup placement best reduces the risk that one rack or site failure destroys production and backups together?
- Public-works cloud operators need fast restores for routine file mistakes and a separate path for regional disasters. How should they assign on-site versus geographically separate backup copies?
- A clerk of courts sets a recovery point objective of 15 minutes for the case-management database. What must backup or replication scheduling primarily satisfy?
- A city attorney places a legal hold on email related to a lawsuit, but the default backup policy purges sets after 30 days. What should operations do for the affected backups?
- A regional library consortium wants a database in another cloud region that continuously receives changes so failover is much faster than restoring from nightly backups. Which approach matches that need?
- A sheriff's office stores cloud backup images that could be stolen with the storage media. What control makes the backup data at rest unreadable to an unauthorized holder of that media?
- A county IT manager sees nightly backup jobs marked successful but worries the sets might not actually restore. What practice best proves recoverability?
- After a storage glitch, a municipal records team fears some backup objects may be silently corrupted even though catalogs still list them. What control best detects that integrity problem?
- During a planned maintenance window, utilities operators will restore a corrupted production volume by writing the backup directly onto that same volume. Which recovery approach is this?
- A city finance cloud team wants to restore a damaged ledger database, validate it thoroughly, then switch users over only after checks pass. Which recovery approach fits?
- After ransomware hits a department file share, the whole share must be recovered, while a separate ticket only needs one mailbox returned. What recovery capability distinction should the backup design support?
- A planning department asks cloud operations to keep every incremental backup forever with no purge. What should the response emphasize about retention?
- Critical CVEs are announced for guest operating systems used by a county's cloud VM images. What lifecycle action should operations take promptly?
- A municipal API platform vendor releases both a major version upgrade and a minor patch. What risk distinction should the change board expect?
- Before promoting a platform upgrade for the water-billing portal, what lifecycle step should operations complete first?
- Container workers for a parks permitting app use scratch disks that vanish when containers stop, but resident-uploaded documents must survive redeploys. How should data lifecycle be handled?
- A product used by city HR reaches vendor end-of-life and will receive no further updates. What lifecycle response is appropriate?
- A vendor ends security support for a middleware stack still running in a county integration tier. Why is continuing without a plan unacceptable?
- Decommissioning a retired municipal VM must be more than powering it off. Which checklist best reflects complete lifecycle teardown?
- New VMs for a city help-desk fleet keep launching from a six-month-old golden image that predates many critical patches. What image lifecycle practice should operations adopt?
- Temporary project sandboxes for a summer internship portal are still running months after the project ended and continue to accrue cloud charges. What lifecycle action is needed?
- A city GIS database runs on persistent block volumes attached to compute hosts that are scheduled for retirement next month. What must operations complete before those hosts are decommissioned?
- A municipal permitting portal must meet published citizen uptime SLAs while hosts need security patches. How should operations schedule the lifecycle changes?
Security · 57 questions
- A county security team is defining vulnerability scan coverage for an internet-facing tax portal and a private admin VPC. What scanning approach fits the environments?
- A weekly vulnerability scan of the city's permitting API hosts reports several outdated application libraries. Which vulnerability-management activity does that report represent?
- A metro cloud security review produces dozens of findings on citizen services. How should the team decide what to fix first?
- After prioritizing vulnerabilities on a parks recreation API, what remediation outcomes are appropriate for the operations and security teams?
- A published advisory assigns an identifier to a known flaw in the firmware version running on the city's VPN concentrators. How should the security team track that flaw?
- A rushed admin wants to push every available patch to all county cloud hosts tonight without reviewing findings. Why is that approach poor vulnerability management?
- Agent-based vulnerability scanners miss several city-issued laptops that are powered off during the scan window. What does this illustrate about scan scope?
- Engineers patched a CVE on the water-billing API hosts. What should they do to confirm remediation?
- A European sister-city partnership stores resident records that law says must remain inside that country's borders. What constraint should guide cloud region selection?
- The city moves citizen service requests into a SaaS help-desk product. Who remains accountable for how that citizen data is classified and shared?
- A public-safety analytics contract requires all related datasets to remain within a named metropolitan area. Which placement requirement is that?
- Open park event photos and sealed juvenile justice records land in the same cloud account. Why must they be handled differently?
- A lawsuit against the transit authority triggers a litigation hold on related email and ticket logs that were otherwise due for deletion. What should happen to the retention schedule?
- A managed-security vendor contract requires the city to keep related audit logs for seven years. What obligation does that create?
- State records law mandates multi-year retention for certain permitting decisions regardless of the IT team's preferred storage tier. What type of requirement is that?
- A city portal that accepts credit cards for recreation fees must protect cardholder data. Which industry standard should the design align with?
- Leadership wants an annual independent report that shows stakeholders how the city's cloud security controls are designed and operating. Which approach fits that goal?
- Infrastructure automation must create municipal cloud resources without an operator clicking the web console each time. What IAM capability enables that?
- Cloud admins want to manage the city's subscriptions from a terminal with provider command-line tools and scripts. What must IAM provide?
- Day-to-day operators use the cloud provider's browser console, while emergency break-glass accounts are reserved for outages. How should IAM treat these paths?
- Linux engineers SSH to jump targets and Windows admins use RDP for city servers. What secure access practice should apply?
- Private admin subnets hold management interfaces with no direct public IPs. How should engineers reach those hosts?
- City Active Directory users need to sign into the cloud management console without maintaining a separate password for every provider account. What IAM approach enables that?
- A city cloud console requires staff to approve a push notification or enter a one-time code after their password before opening the management portal. Which control is the municipality enforcing?
- A county mobile permitting app obtains short-lived access tokens from an identity service instead of embedding long-lived passwords in the client binary. Which authentication pattern is the team applying?
- A municipal cloud team assigns permissions by job role—billing viewer, network admin, backup operator—rather than writing unique ACL entries for every individual user. Which access model are they implementing?
- A county IT department places staff into security groups such as PublicWorks-Admins and Finance-Readers so every member inherits the same cloud permissions. Which approach scales access management for the municipality?
- A citizen services app requests limited delegated access to a user's calendar-like scheduling resource using standard authorization flows without collecting the user's cloud password. Which protocol best fits this delegated authorization scenario?
- After a questionable change in the city's cloud management account, security needs to review who performed which actions last week. Which capability should they rely on?
- A municipal architecture board decides that no network location is trusted by default and that every request to cloud resources must be verified continuously. Which security approach are they adopting?
- A city wants recognized hardening guides to baseline operating system and cloud configuration settings before production cutover. Which reference source best matches that need?
- Besides general industry guides, the parks department's PaaS database offers a vendor-published security baseline tailored to that managed service. What should the operations team do?
- Before publishing golden images for citizen-facing VMs, a city removes unnecessary services, closes unused ports, and disables default accounts. What is the primary security goal of these steps?
- TLS protects citizen browser sessions to the permitting portal, while volume encryption protects data stored on attached disks. Which statement correctly contrasts these controls?
- Developers discover API keys and database passwords checked into a municipal Git repository. What is the recommended remediation pattern for ongoing secret handling?
- A city's public APIs must validate caller tokens, throttle abusive clients, and avoid error messages that reveal internal stack traces. Which set of practices does this describe?
- A short-term contractor supporting one GIS project is granted only the permissions required for that project instead of standing admin rights 'just in case.' Which principle is the city following?
- Containerized microservices for a 311 intake API should avoid running as root and should use tight filesystem permissions inside the image. Which hardening choice aligns with that goal?
- Object buckets holding citizen PII must block public ACLs, and municipal file shares must require authenticated access only. Which storage security stance is correct?
- Managed laptops used by staff who administer cloud control planes need malware protection and full-disk encryption. Which control category addresses those device requirements?
- Outbound email and file uploads that contain Social Security numbers from municipal systems should be blocked or alerted. Which security control primarily addresses that requirement?
- Network sensors in front of cloud workloads detect exploit traffic and can block matching attack patterns. Which controls fill those detect and block roles?
- A volumetric flood saturates links toward the city's public citizen portal. Which control is best positioned to absorb that attack at provider scale?
- Cloud IAM policies for the city deny wildcard administrator actions and require MFA before privileged roles can be assumed. What do these settings exemplify?
- Subnet-level rules in a municipal VPC allow only specific ports between the web, application, and data tiers. Which control operates at that subnet scope?
- HTTPS citizen applications need filtering against common Layer 7 web exploits such as injection and abusive bots. Which control is designed for that HTTP(S) application layer?
- Instance-level allow and deny rules restrict which peers can reach a virtual machine's network interface in a city VPC. Which control matches that description?
- A municipal security design stacks a WAF, network security groups, and IAM policies rather than depending on a single control. What principle does this architecture illustrate?
- A city IT team is hardening two workloads: a public static website for park permits and a private database holding citizen payment records. Which control pairing best matches exposure and data sensitivity?
- A county cloud operations desk wants early warning when audit API calls and VPC flow patterns look abnormal across multi-cloud accounts. Which approach best supports detecting suspicious activity?
- A municipal identity console shows a surge of successful logins at 3 a.m. from a country the city has never used for remote work, far above the normal overnight baseline. What detection idea does this illustrate?
- During a weekly cloud posture scan, a city engineer finds a security group that allows SSH from 0.0.0.0/0 to a management subnet. Why is this finding important for attack monitoring?
- A utility billing API in the city’s cloud is breached after scanners find a known flaw in an outdated third-party library that patching tickets had delayed for months. Which attack path does this describe?
- City employees receive urgent email messages claiming they must ‘reset your cloud password today’ via a link that does not match the official identity portal. What type of suspicious activity is this?
- A department file share synchronized to cloud object storage suddenly contains encrypted files and a ransom note demanding payment for decryption keys. Which malware impact scenario is this?
- Finance notices a sharp rise in compute spend on idle project accounts; investigation finds abandoned instances mining cryptocurrency after a compromised API key. What cloud-typical abuse does this illustrate?
- After a web application compromise, responders see outbound requests from the app tier to the instance metadata service collecting temporary cloud credentials. Which attack path should the city treat this as?
DevOps Fundamentals · 30 questions
- A county platform team stores Terraform templates and application code and must prove who changed a production module and when. Which source-control capability primarily provides that history?
- Before a Terraform change that opens a new peering path for emergency services merges, a second city engineer must examine the diff. What source-control practice is this?
- A developer finishes a permitting-portal fix on a feature branch and wants discussion plus automated checks before the work joins main. Which collaboration mechanism fits?
- After committing locally, a city developer needs the shared team repository to receive those commits so colleagues can pull the latest work. Which source-control action accomplishes that?
- A cloud engineer finishes a local Terraform tweak for a parks subnet and wants a durable snapshot in repository history before sharing. What should they create?
- An approved feature branch for the city’s permit API has passed review; the team now needs those changes integrated into the main line. Which source-control operation does that?
- The transit authority’s cloud team insists new fare-calculator features be developed on short-lived branches instead of committing straight to production main. Why does branch management matter?
- A city release process still waits for a monthly weekend freeze, but leadership wants every commit to trigger automated build and test instead. What DevOps shift does this describe?
- Developers on the housing-vouchers service merge small changes into a shared mainline several times a day, each time running automated checks. Which CI/CD concept is this?
- Once the city’s pipeline verifies a build, the same automation releases the artifact to staging without waiting for a separate weekly install crew. Which concept does this highlight?
- In the municipal CI pipeline for a containerized licensing service, one stage compiles and packages the application before tests run. What is that stage called in CI/CD terms?
- The city’s pipeline refuses to promote a parks-map build when unit or integration tests fail. What role do those automated tests play?
- Before images from the tax-portal pipeline can deploy, the workflow runs container image scanning and secret detection. Why include those steps?
- A DevOps lead documents that every change for the court-records API must follow lint, then build, then test, then deploy with a manual approval before production. What CI/CD idea is this?
- Successful builds of the city’s microservice produce container images that later environments pull for deployment. What are those images in pipeline terms?
- Internal shared libraries for the city’s cloud apps must stay in a controlled package repository, while carefully vetted open-source dependencies may come from public registries. What distinction should the platform team enforce?
- A city permit office wants new applications to publish a message so scanners and citizen notifiers react on their own schedules without waiting on one shared call stack. Which integration approach best fits that loosely coupled design?
- County mobile inspectors need to create and read permit resources over HTTP using JSON payloads in a common modern API style. Which approach matches that requirement?
- A legacy regional planning partner still insists on XML envelope-style remote calls with a formal contract for municipal zoning exchanges. Which web service style are they most likely expecting?
- An internal city fee-calculator microservice needs another service to run a named calculation as if calling a remote procedure and return a result. Which integration pattern best describes that interaction?
- An emergency-dispatch console for the municipality needs bidirectional, low-latency updates between browsers and the cloud backend as unit statuses change. Which integration mechanism best fits?
- Civic open-data clients want to request exactly the nested fields they need from a flexible API schema instead of over-fetching fixed REST resources. Which API style addresses that need?
- A county platform team must choose between synchronous REST calls and asynchronous events for integrating a tax portal with downstream scanners. When is asynchronous event integration the better choice?
- Municipal ops wants agent-based or agentless configuration management that repeatedly enforces desired package and service state across fleets of VMs. Which tool category purpose should they prioritize?
- City developers need to package municipal apps with their dependencies into portable images that run consistently from laptop to cloud. Which tool purpose best matches that need?
- County SRE wants centralized log ingest, search, and dashboards so ops can troubleshoot multi-cloud municipal services from one place. Which stack purpose fits?
- A municipal engineering team needs distributed source history, branching, and a collaboration hub for application and infrastructure code. Which tool purpose is essential?
- Platform engineers want CI workflows defined next to municipal application code so pull requests automatically build and test. Which tool purpose fits best?
- City SRE wants time-series metrics dashboards and alert visualizations for municipal cloud workloads. Which tool purpose should they choose?
- A civic cloud team must repeatedly provision networks and instances with declarative templates, schedule containers across a cluster at scale, and run classic build jobs in a CI server. Which tool-to-job mapping is correct?
Troubleshooting · 36 questions
- After a city GIS deploy, a new application image fails on the existing host AMI because it depends on a newer library ABI the old image cannot provide. What is the most likely root cause category?
- A municipal IaC template requests more memory than the selected instance type can provide, and the stack create fails during allocation. What should ops investigate first?
- A county CI/CD pipeline identity cannot create load balancers in the target cloud account, and the deploy stops with authorization errors. What is the primary issue?
- Several municipal workloads share a constrained compute pool; performance collapses when noisy neighbors consume disproportionate capacity. Which deployment issue does this describe?
- During a city records migration, undersized disks fill mid-deploy and the job fails halfway with no free space. What is the most accurate root-cause category?
- A parks department deploy references a machine image family the provider no longer publishes, and instance create fails. What is the likely cause?
- City ops sees either an entire regional control-plane API unavailable or only one municipal microservice returning errors. Why does scoping full versus partial outage matter first?
- Automation creating hundreds of civic resources hits provider API rate limits and mass creates stall with throttling errors. What is the deployment blocker?
- New municipal stacks fail because the account’s public IP quota is exhausted even though templates and IAM look correct. What should ops address?
- A university–city AI pilot chooses a region that does not offer the required GPU SKU, so the deploy cannot place instances. What is the core issue?
- Municipal IaC apply fails because a parameter still points at a retired provider API version that the control plane no longer accepts. What is the best characterization of the failure?
- A county permit system deploy fails with both 'quota exceeded' messages and IAM permission denied errors at the same time. What should the cloud team do first to triage effectively?
- New city GIS worker instances launch successfully but never receive addresses from the cloud subnet's DHCP-equivalent address pool. What is the most likely cause to investigate?
- After a cutover, citizens cannot resolve the municipal portal hostname even though the application servers respond when reached by IP. What should the operations team investigate first?
- Municipal SSO logins start failing with token validation errors after app nodes drifted several minutes away from the identity provider's clock. What is the most appropriate fix?
- Private city subnet instances must download OS updates from the internet. An internet gateway exists in the VPC, yet private instances still cannot reach update endpoints. What is most likely missing or misconfigured?
- During a county API deploy, clients receive HTTP 502 and 503 responses while health checks flap. How should the team interpret these status codes relative to application logic bugs?
- A city department's large file transfers between regions crawl even though CPU on both ends is mostly idle. Engineers suspect path MTU problems or thin links. What troubleshooting focus best matches the symptoms?
- Citizen traffic to a municipal app drops after a new cloud security appliance is inserted in path. Packet captures show arrivals at the appliance but not egress toward the app. What is the most likely cause?
- A legacy permitting workstation cannot complete handshakes with a cloud API after the city retired an old TLS and application protocol version on the server. What is the core issue?
- A municipal autoscaling group cannot attach new NICs because the subnet reports no free addresses. What problem does this describe?
- A city peers its VPC to a partner university network, then discovers overlapping CIDR blocks and broken routes between them. What is the fundamental problem?
- Traffic from a county VPC to a remote VPC fails even though a transit gateway attachment exists. Traceroutes show packets never leave the local subnet toward the transit hop. What is most likely missing?
- A private municipal subnet's route table accidentally sends 0.0.0.0/0 to an internet gateway instead of a NAT gateway. What is the primary risk or failure mode?
- A hybrid city VM is isolated from its intended segment after a network change. The hypervisor port is set to access mode on VLAN 20 while the guest expects tagged trunk traffic for VLAN 30. What does this indicate?
- Users report that 'the cloud is down,' but the provider status page is green and traceroute from city edge routers fails before packets reach the provider's network. What should the team conclude?
- After a hardening change disables weak ciphers on a city load balancer, legacy kiosk clients fail the TLS handshake. What security troubleshooting issue does this represent?
- A help-desk role that previously could only reset passwords can suddenly delete production databases in the city's cloud account. What security issue should be investigated?
- Cloud access logs show API calls that delete security groups from an identity that should not have that permission. What is the appropriate troubleshooting focus?
- A developer pastes a municipal cloud access key into a public Git repository. What should the team treat as the primary incident?
- Login failures spike right after the city rotates MFA tokens. Some users show successful second-factor challenges; others never receive prompts. How should ops triage?
- Scanners report a critical CVE on internet-facing container images still serving the city's public portal. What is the required security operations response?
- Cluster monitoring finds an unapproved crypto-miner container running in a municipal Kubernetes namespace. What issue does this represent?
- After a municipal access key leaks, which response set best matches Cloud+ security troubleshooting depth?
- After a least-privilege IAM change, multiple city staff report access denied to the same portal. Some peers in another group still succeed. How should the team troubleshoot authorization?
- A change window disables a weak cipher on the city's API gateway and an old payment integration breaks. Leadership asks how to proceed securely. What is the best approach?
These questions are original practice material and are NOT actual exam questions or brain-dump content. All vendor marks are trademarks of their respective owners. This site is not affiliated with, endorsed by, or sponsored by the exam vendor.