CompTIA AutoOps + AT0-001 (V1) Exam Practice Test 5

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 25, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. A private subnet has no outbound internet access because its route table lacks a route toward a NAT gateway. To grant outbound-only internet access to resources in that subnet, the route table's default route should point to a ____.

Explanation

A NAT gateway allows resources in a private subnet to initiate outbound connections to the internet while remaining unreachable from the internet directly. Adding a default route, typically 0.0.0.0/0, that points to the NAT gateway gives the subnet outbound-only connectivity. This differs from an internet gateway, which is used by public subnets that need to be directly reachable from the internet.

Submit
Please wait...
About This Quiz
CompTIA Autoops + At0-001 (V1) Exam Practice Test 5 - Quiz

This assessment focuses on the CompTIA AutoOps + AT0-001 (V1) certification, evaluating your understanding of automation operations in IT environments. It covers essential concepts such as cloud technologies, automation tools, and operational best practices. This resource is beneficial for learners preparing for the certification, helping to reinforce knowledge and identify... see moreareas for improvement. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. Before running automation against a cloud account, an engineer wants to confirm exactly which identity their CLI session is currently authenticated as. In AWS, the command that reports this is aws sts get-caller-____.

Explanation

The aws sts get-caller-identity command returns the account, user, and role ARN currently associated with the CLI session's active credentials. Running this before executing automation confirms the session is using the intended identity and account, which helps avoid accidentally running commands against the wrong environment. Many teams add this check as a safeguard at the start of pipeline jobs.

Submit

3. A team is reviewing how their automation authenticates to a cloud provider. Which two of the following represent stronger security practices than a single shared, long-lived static credential? (Select two.)

Explanation

Assuming a scoped IAM role temporarily, and using machine identities with federated short-lived credentials, both limit the blast radius of a compromised credential because access expires quickly and is scoped narrowly to what each job needs. A shared root password or a credential committed to source control creates a single, long-lived, broadly powerful target for an attacker. Disabling IAM would remove access control entirely rather than strengthen it.

Submit

4. A team wants to reduce the overall customer impact of incidents. One proposal focuses on detecting and fixing incidents faster, and another focuses on preventing incidents from happening in the first place. Which metrics correspond to each proposal, respectively?

Explanation

Mean time to repair measures how quickly a team resolves an incident once it occurs, so improvements there directly correspond to faster fixes. Mean time between failures measures how often incidents occur in the first place, so improving it corresponds to prevention. Tracking both together gives a fuller picture of reliability than either metric alone.

Submit

5. A payment service integrates with a shipping service and a tax calculation service. Before release, the team wants to confirm that these three services correctly exchange data and produce a valid combined order total. Which QA practice targets this?

Explanation

Integration testing verifies that multiple components or services work correctly together, which is exactly the concern here: whether data flows correctly across the payment, shipping, and tax services to produce a valid total. Unit tests validate each service in isolation and would miss problems that only appear when the services interact. Load testing measures capacity rather than correctness of the interaction.

Submit

6. A team needs a delivery method that lets them test a new payment provider integration with a small, targeted slice of real production traffic before rolling it out fully, while being able to quickly reduce that slice back to zero if error rates rise. Which method best fits?

Explanation

A canary deployment is designed exactly for this: routing a small, adjustable percentage of real traffic to the new version and watching key metrics before increasing exposure. If problems appear, traffic can be shifted back to the stable version quickly, limiting the blast radius. In-place deployment offers no such gradual, reversible traffic control.

Submit

7. A pipeline stage runs three jobs at the same time so the total stage duration is close to the longest individual job rather than the sum of all three. This execution style is called ____ execution.

Explanation

Parallel execution runs multiple independent jobs at the same time rather than one after another, which shortens the overall pipeline duration when jobs do not depend on each other's output. Sequential execution, by contrast, runs jobs one at a time, which is necessary when a later job depends on an earlier one's result. Correctly identifying which jobs are truly independent is what allows a team to safely parallelize a pipeline.

Submit

8. A vault issues a database credential to a pipeline with a one-hour lease. If the pipeline job runs longer than expected and needs the credential past that hour, what typically must happen?

Explanation

Leased secrets are only valid for a defined window, and the consumer is responsible for renewing the lease if it needs the credential longer, or requesting a fresh one if renewal is not possible. This time-boxing limits how long a leaked or forgotten credential remains usable. Hardcoding a backup password would defeat the purpose of using short-lived, vault-managed credentials in the first place.

Submit

9. A repository hosted on GitHub defines its CI/CD workflow in a YAML file located at .github/workflows/deploy.yml. Which platform reads and executes this file?

Explanation

GitHub Actions specifically looks for workflow definition files under the .github/workflows/ directory in a repository. Each file defines triggers, jobs, and steps using GitHub Actions' own YAML syntax. Other CI/CD platforms look for their pipeline definitions in different, platform-specific locations.

Submit

10. A team wants routine builds triggered automatically on every push, but wants production deployments to require a person to explicitly click a button after reviewing the build. Which two trigger types support this design? (Select two.)

Explanation

Combining a push trigger for early pipeline stages with a manual trigger gating the deployment stage gives fast automatic feedback on every change while still requiring explicit human approval before production changes take effect. This is a common pattern for balancing speed with deployment safety. Removing all triggers, or relying solely on a schedule, would not give the fast feedback the team wants for routine builds.

Submit

11. A deployment pipeline monitors error rates immediately after each release and automatically reverts to the previous version if errors spike above a defined threshold within five minutes. What capability is this?

Explanation

An automated rollback uses a measurable signal, such as an error rate threshold, to detect a bad release and revert to the last known-good version without waiting for a human to notice and intervene. This significantly shortens the time a bad release affects users. Semantic versioning and branch naming are unrelated to detecting and reacting to a failing release.

Submit

12. A CI job fails to push a newly built container image with denied: requested access to the resource is denied, even though the registry URL is correct. What should the engineer check first?

Explanation

A denied access error when pushing to a registry most often points to a credentials or permissions problem: either the login token is invalid, expired, or the account lacks push rights for that specific repository. Confirming the pipeline's stored credential and its assigned permissions is the fastest way to isolate the cause. Dockerfile contents and commit messages would not produce this specific registry authorization error.

Submit

13. An architect is choosing an event-handling mechanism for different scenarios. Match each scenario to the best-fitting cloud-based event mechanism.

Explanation

Each mechanism suits a different pattern. FaaS runs event-triggered code without managing servers, notification-based events broadcast to multiple subscribers at once, and messaging queues hold work durably until a consumer is ready to process it. Choosing the wrong mechanism can lead to lost messages, unnecessary infrastructure, or unneeded complexity.

Submit

14. A deployment script must send an alert only when disk usage exceeds 90% and the environment is production, but not for any other environment or usage level. Which construct expresses this correctly in pseudocode?

Explanation

Combining both conditions with a logical AND ensures the alert fires only when both requirements are true at the same time: production environment and high disk usage. Using OR instead would also alert for any production event or any high-usage event individually, which is broader than intended. A while loop would repeatedly send alerts rather than evaluating the condition once.

Submit

15. An automation job that calls an internal API over HTTPS starts failing with a certificate verification error, though the API's certificate has not expired. What is a likely cause worth investigating?

Explanation

A certificate verification failure that is not caused by expiration often comes down to the client not trusting the certificate authority that issued the server's certificate, especially for internal or self-signed certificate chains. Adding the correct CA certificate to the job's trust store resolves this. DNS deletion or registry storage issues would produce different, unrelated errors.

Submit

16. An automation script sends a PATCH request to update a resource and receives an HTTP 404 response. Which two conclusions are reasonable? (Select two.)

Explanation

A 404 response means the server could not find the resource identified by the request's URL, regardless of which valid HTTP method was used. This points the client toward checking whether the resource ID or path in the request is correct, perhaps because the item was deleted or the ID was mistyped. PATCH is a standard, valid HTTP method, and a 404 does not indicate a server crash, which would typically appear as a 5XX response.

Submit

17. A junior engineer writes a one-off Bash script to clean up temporary files on a single server, run manually whenever disk space gets low. Which category of automation approach does this best represent?

Explanation

A simple script executed manually on a single machine, listing out the exact steps to perform, is a local, imperative approach. It has no remote execution component and does not describe a desired end state for a tool to reconcile toward. This is a reasonable quick fix, but it does not scale the way a declarative, remotely managed approach would across many servers.

Submit

18. A team's IaC pipeline runs a plan step every night and emails the team whenever the plan shows changes that were not made through the pipeline. What capability is this pipeline implementing?

Explanation

Drift detection compares the actual state of infrastructure against the declared desired state and flags any differences, often caused by manual out-of-band changes. Running this check nightly and alerting the team lets them catch and address drift before it accumulates or causes an incident. Post-deployment testing instead verifies application behavior after a release, which is a different kind of check.

Submit

19. A build fails with a message that a required library version conflicts with another dependency's requirement. What is the most direct fix?

Explanation

A version conflict means two declared dependencies require incompatible versions of the same underlying library. Resolving it requires inspecting both constraints and either widening a version range, pinning a specific compatible version, or upgrading one of the conflicting packages so their requirements overlap. Deleting the dependency file removes the information needed to resolve the conflict rather than fixing it.

Submit

20. Two developers modify the same function in different ways, and one of them also ran an auto-formatter across the whole file. When they try to merge, nearly every line shows as changed. What is the best way to prevent this in the future?

Explanation

When formatting and logic changes are mixed together, even a small logic difference can appear to touch nearly the entire file, since the formatter also rewrote unrelated lines. Enforcing one shared formatting standard, ideally applied automatically through a hook or CI check, means formatting changes stop happening as unpredictable side effects of individual edits. This keeps future diffs focused on actual logic changes, which conflict far less often.

Submit

21. A team currently patches running servers in place whenever a security update is needed, which sometimes leaves servers with inconsistent patch levels. Adopting which infrastructure as code principle would most directly address this?

Explanation

Immutable infrastructure treats running instances as disposable: instead of patching a server in place, a new image is built with the update baked in and old instances are replaced with new ones from that image. This guarantees every instance matches the same known-good state, eliminating the drift that comes from patching some servers and missing others. Idempotency and reusability address different problems, namely safe repeated execution and code duplication.

Submit

22. A library maintainer wants to publish a build for testers that is clearly newer than 2.0.0 but not yet a stable release. Which two version strings correctly express a pre-release under semantic versioning? (Select two.)

Explanation

Semantic versioning appends a hyphen and an identifier such as beta.1 or rc.1 after the core version to mark a pre-release build. Package managers recognize this suffix and, by default, do not install pre-release versions unless explicitly requested. A bare version like 2.1.0 with no suffix signals a stable, fully released version rather than a pre-release.

Submit

23. A new contributor's commits show up authored by an unrelated name because their laptop was never configured. Which command fixes this going forward?

Explanation

Git reads the author name and email from configuration values, which can be set globally for a user's machine or locally for a single repository. Running git config --global with the correct name and email ensures every future commit is attributed correctly. Amending or force-pushing would only correct already-existing commits, not prevent the same misconfiguration going forward.

Submit

24. A script defines a function check_host(hostname) that pings a host and returns True or False, and then calls it once for each of 50 hostnames stored in a list. What is the primary benefit of wrapping the ping logic in a function here?

Explanation

Defining reusable logic in a function means the same block of code does not need to be copied for every hostname, and any future change to the ping logic only needs to happen in one place. The function is still called from within a loop that iterates over the 50 hostnames. Functions by themselves do not add parallelism or logging unless that behavior is explicitly written into them.

Submit

25. An API returns {"servers":[{"name":"web01","status":"up"},{"name":"web02","status":"down"}]}. To print just the names of servers whose status is down, an engineer uses: jq '.servers[] | select(.status == "____") | .name'

Explanation

jq's select() function filters a stream of values, keeping only elements where the given condition is true. Here it keeps only server objects whose status field equals down, and the trailing .name then extracts just the name from each surviving object. This pattern of filter-then-extract is common when scripting against JSON API output.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
A private subnet has no outbound internet access because its route...
Before running automation against a cloud account, an engineer wants...
A team is reviewing how their automation authenticates to a cloud...
A team wants to reduce the overall customer impact of incidents. One...
A payment service integrates with a shipping service and a tax...
A team needs a delivery method that lets them test a new payment...
A pipeline stage runs three jobs at the same time so the total stage...
A vault issues a database credential to a pipeline with a one-hour...
A repository hosted on GitHub defines its CI/CD workflow in a YAML...
A team wants routine builds triggered automatically on every push, but...
A deployment pipeline monitors error rates immediately after each...
A CI job fails to push a newly built container image with denied:...
An architect is choosing an event-handling mechanism for different...
A deployment script must send an alert only when disk usage exceeds...
An automation job that calls an internal API over HTTPS starts failing...
An automation script sends a PATCH request to update a resource and...
A junior engineer writes a one-off Bash script to clean up temporary...
A team's IaC pipeline runs a plan step every night and emails the team...
A build fails with a message that a required library version conflicts...
Two developers modify the same function in different ways, and one of...
A team currently patches running servers in place whenever a security...
A library maintainer wants to publish a build for testers that is...
A new contributor's commits show up authored by an unrelated name...
A script defines a function check_host(hostname) that pings a host and...
An API returns...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!