CompTIA Cloud + CV0-004 (V4) Exam Practice Test 1

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. An application experiencing increased load is scaled by adding more server instances behind a load balancer, rather than increasing the CPU and memory of existing instances. Complete the sentence: this scaling type is called ______ scaling.

Explanation

Horizontal scaling adds more instances to handle increased load. Vertical scaling instead increases the resources of existing instances rather than adding more of them.

Submit
Please wait...
About This Quiz
CompTIA Cloud + Cv0-004 (V4) Exam Practice Test 1 - Quiz

This practice test focuses on the CompTIA Cloud + CV0-004 (V4) Exam, assessing your knowledge in cloud technologies, deployment models, and security. It's designed to help you prepare effectively for the certification, ensuring you understand essential concepts and skills required in the cloud computing domain.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. An attacker who gained low-level access to a cloud instance exploits a misconfigured IAM policy to grant themselves administrative permissions across the entire cloud account. Which security troubleshooting category is this?

Explanation

An attacker exploiting a misconfiguration to grant themselves higher permissions than originally held is privilege escalation. Unauthorized access generically describes gaining access without permission at all rather than elevating existing access, leaked credentials concerns exposed authentication secrets, software vulnerability issue generically concerns exploitable code flaws, and cipher suite deprecation concerns outdated encryption algorithms rather than an IAM permission escalation.

Submit

3. New devices joining a network segment fail to receive an IP address at all, and an administrator discovers the DHCP server's configured address pool for that segment has no addresses left to assign. Complete the sentence: this issue is called ______.

Explanation

Scope exhaustion occurs when a DHCP server's configured address pool runs out of available addresses to assign to new clients, exactly matching this symptom of new devices failing to receive an address at all.

Submit

4. A cloud host allows more virtual CPUs to be allocated to VMs than physical CPU cores actually exist, betting that not all VMs will demand full CPU simultaneously, but performance degrades when several VMs spike CPU usage at once. Which deployment issue does this represent?

Explanation

Oversubscription allocates more virtual resources than physical capacity actually supports, betting on statistical demand patterns, and causes degradation when that assumption fails under simultaneous load. Sizing issues concern choosing an inappropriately sized resource for a workload, permission issues concern access rights, resource allocation misconfiguration generically is broader, and API throttling concerns rate-limited API calls rather than this specific CPU overcommitment pattern.

Submit

5. A CI/CD pipeline produces a versioned container image as the final output of its build stage, ready to be deployed to any environment. Which CI/CD concept does this container image represent?

Explanation

An artifact is the packaged output of a build stage, such as a versioned container image or package, ready for deployment. Workflow describes the overall sequence of pipeline stages, testing validates the build before release, code integration merges changes from multiple contributors, and automation generically describes the broader hands-off execution of pipeline steps rather than the specific packaged build output.

Submit

6. A developer finishes work on a feature branch and submits it for team review and discussion before it can be merged into the main branch, rather than merging directly without any review step. Which source control concept is this?

Explanation

A pull request submits proposed changes for review and discussion before merging, exactly matching this team review step. A code commit records a snapshot of changes locally, a code push uploads local commits to a remote repository, branch management alone describes organizing separate lines of development, and version management alone describes tracking change history rather than this specific review-and-approval workflow step.

Submit

7. A company wants a control specifically positioned to inspect and filter HTTP/HTTPS traffic to a web application, blocking attacks like SQL injection and cross-site scripting before they reach the application. Which control is this?

Explanation

A WAF specifically inspects and filters application-layer HTTP/HTTPS traffic for attacks like SQL injection and XSS. A network ACL filters traffic at the subnet level based on IP and port, a network security group filters traffic at the instance level, IPS/IDS generically covers broader intrusion detection and prevention, and DDoS protection specifically addresses volumetric availability attacks rather than application-layer attack filtering.

Submit

8. A development team removes hardcoded database passwords from their application code and instead retrieves them at runtime from a centralized, access-controlled vault service. Which security best practice does this represent?

Explanation

Secrets management centralizes storage and controlled retrieval of sensitive credentials like passwords, avoiding hardcoding them into application code. Zero Trust is a broader security philosophy of continuous verification, hardening reduces a system's attack surface generally, least privilege alone limits granted permissions, and benchmark compliance checks configuration against published standards rather than describing centralized credential storage specifically.

Submit

9. An administrator needs to SSH into private cloud instances that have no direct public IP address, by first connecting to a single hardened, publicly accessible instance that then forwards the connection inward. Which concept is this hardened intermediary instance?

Explanation

A bastion host is a hardened, publicly accessible instance used as a secure intermediary to reach private instances that have no direct public exposure. An API gateway manages API traffic, federation extends identity trust across organizations, directory-based authentication centralizes identity in a directory service, and OAuth 2.0 is an authorization framework rather than describing this specific network access intermediary.

Submit

10. A company operating in the European Union must ensure that customer data collected from EU residents remains stored and processed within EU borders, per local legal requirements. Which compliance concept does this requirement represent?

Explanation

Data sovereignty concerns legal requirements that data be stored and processed within specific geographic or jurisdictional boundaries. Data classification categorizes data by sensitivity, data retention concerns how long data is kept, data ownership concerns who holds rights to the data, and litigation hold suspends deletion schedules for anticipated legal proceedings rather than governing geographic data location.

Submit

11. A security team runs a scan across cloud resources, confirms which findings represent genuine exploitable weaknesses rather than false positives, and then applies patches to address the confirmed issues. Which vulnerability management step does confirming genuine exploitable weaknesses represent?

Explanation

Assessment evaluates identified findings to confirm which represent genuine, exploitable weaknesses rather than false positives, informing prioritization before action is taken. Scanning scope defines what will be scanned, identification discovers potential vulnerabilities in the first place, remediation applies the actual fix, and CVE cataloging references the standardized vulnerability database rather than describing this confirmation step.

Submit

12. A cloud resource's operating system version has reached the point where the vendor will no longer release any security patches or updates for it at all, even though the vendor briefly continued limited technical support after that cutoff. Which lifecycle concept does the complete stop of patches represent?

Explanation

End of life marks the point where a vendor stops all patches and updates entirely. End of support is typically a separate, sometimes earlier or later, milestone marking the end of vendor technical assistance, major and minor updates describe types of version changes rather than lifecycle endpoints, and decommissioning generically describes the broader retirement process rather than this specific patch-cutoff milestone.

Submit

13. A backup strategy performs a complete copy of all data every Sunday, and on the other six days of the week only backs up data that has changed since the most recent backup of any type, minimizing daily backup time and storage. Which backup type describes the daily backups?

Explanation

Incremental backups capture only data changed since the most recent backup of any type, whether full or incremental, minimizing daily backup size and time. A full backup captures everything regardless of prior backups, a differential backup captures all changes since the last full backup specifically, growing larger each day, and replication continuously copies data to another location rather than describing a scheduled backup type.

Submit

14. A company deploys a PaaS-based application platform and understands that while the cloud provider manages the underlying infrastructure and runtime environment, the company itself remains responsible for securing the application code and data it deploys onto that platform. Which concept describes this division of responsibility?

Explanation

The shared responsibility model defines which security and management responsibilities belong to the cloud provider versus the customer, varying by service model. Multicloud tenancy concerns using multiple providers simultaneously, cloud bursting concerns overflow capacity, availability monitoring tracks uptime, and resource metering tracks consumption for billing rather than describing this responsibility division.

Submit

15. A team troubleshooting a slow microservices-based application wants to follow a single user request as it travels through multiple services, measuring how long each service takes to process its portion of the request. Which observability concept is this?

Explanation

Tracing follows a single request's path across multiple services, measuring the time spent in each, exactly matching this cross-service request-tracking need. Logging records discrete events, alerting notifies when a condition is met, metrics measure quantitative system behavior generally, and triage is the process of prioritizing alerts once they occur rather than following an individual request's path.

Submit

16. Match each provisioning requirement category to an example consideration within it.

Explanation

Each provisioning requirement category drives specific technical decisions: storage requirements determine storage type selection, performance requirements drive sizing and IOPS decisions, compliance requirements constrain where resources can be deployed, and network requirements define connectivity and bandwidth needs.

Submit

17. An operations team notices that a cloud resource's actual configuration no longer matches what is defined in their infrastructure-as-code templates, because someone made a manual change directly through the console. Which IaC concept identifies this kind of discrepancy?

Explanation

Drift detection identifies when a resource's actual live configuration has diverged from what is defined in code, exactly matching an undocumented manual console change. Repeatability describes IaC's ability to consistently reproduce the same environment, versioning tracks changes to the code itself over time, testing validates the code before applying it, and documentation records how the code works rather than detecting a live configuration mismatch.

Submit

18. A company moves an application to the cloud by simply copying its virtual machines as-is onto cloud infrastructure, making no changes to the application's architecture or code. Which application migration strategy is this?

Explanation

Rehosting, often called lift-and-shift, moves an application to the cloud with no changes to its architecture or code. Refactoring modifies code to better leverage cloud-native features, re-architecting substantially redesigns the application, replatforming makes minor adjustments without a full redesign, and retaining means keeping the application where it currently is rather than migrating it.

Submit

19. A team releases a new application version to only 5% of production traffic first, closely monitoring for errors before gradually increasing that percentage, rather than switching all traffic at once. Which deployment strategy is this?

Explanation

A canary deployment releases a new version to a small subset of traffic first, monitoring closely before gradually increasing exposure. Blue-green maintains two complete parallel environments and switches all traffic at once, rolling deployment incrementally replaces instances across the fleet, in-place deployment updates instances directly, and a rollback reverts to a previous version rather than describing this gradual traffic-shifting release approach.

Submit

20. Several universities in a research consortium jointly fund and share a cloud environment specifically built to support their shared research computing needs, with access restricted to consortium members only. Which cloud deployment model is this?

Explanation

A community cloud is shared by several organizations with common interests or requirements, exactly matching this consortium-shared research environment restricted to members. Public cloud is available to the general public, private cloud serves a single organization, hybrid combines multiple deployment models, and on-premises alone describes a private cloud hosted within an organization's own facilities.

Submit

21. A containerized database needs its data to survive even if the container itself is deleted and recreated, while a separate stateless web-serving container only needs temporary scratch space that can be discarded when the container stops. Which two container storage concepts are described, respectively?

Explanation

Data that must survive container deletion and recreation requires persistent volumes, while temporary scratch space that can be discarded is ephemeral storage. Port mapping connects container network ports to the host, image registries store container images, and workload orchestration manages container deployment and scheduling rather than describing these two storage durability concepts.

Submit

22. A development team designs an application so that its individual services communicate through well-defined APIs and can be updated, scaled, or replaced independently without requiring changes to other services. Which cloud-native design concept does this represent?

Explanation

Loosely coupled architecture specifically describes services that interact through well-defined interfaces and can be changed independently without cascading impact on others. Fan-out describes distributing a single event to multiple consumers, service discovery describes how services locate each other dynamically, microservices alone describes the architectural style without necessarily emphasizing the loose-coupling property itself, and cloud-provided managed services describes provider-operated components rather than this independence characteristic.

Submit

23. Match each storage type to its best-fit use case description.

Explanation

Object storage suits large volumes of unstructured data accessed via API, block storage provides raw low-latency volumes for OS or database use, and file storage provides a shared hierarchical directory structure for simultaneous multi-client access, each fitting different workload patterns.

Submit

24. A company wants to connect two separate virtual private clouds directly so resources in each can communicate using private IP addresses, without routing traffic over the public internet, for exactly this one pair of VPCs. Which concept fits this specific point-to-point connection?

Explanation

VPC peering creates a direct, private network connection between exactly two VPCs, allowing private IP communication without traversing the public internet. A transit gateway instead serves as a central hub connecting many VPCs and on-premises networks simultaneously, BGP is a routing protocol, static routes are manually defined paths, and SDN is a broader software-defined networking approach rather than this specific point-to-point peering connection.

Submit

25. A disaster recovery plan specifies that after a major outage, the business can tolerate at most 4 hours of downtime before operations must be restored, and separately can tolerate losing at most 15 minutes of transaction data since the last backup. Which two DR concepts are described, respectively?

Explanation

The maximum tolerable downtime before operations are restored is the recovery time objective, while the maximum tolerable data loss measured in time since the last backup is the recovery point objective. A hot, warm, or cold site describes the readiness level of a standby recovery facility rather than these two specific time-based metrics.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
An application experiencing increased load is scaled by adding more...
An attacker who gained low-level access to a cloud instance exploits a...
New devices joining a network segment fail to receive an IP address at...
A cloud host allows more virtual CPUs to be allocated to VMs than...
A CI/CD pipeline produces a versioned container image as the final...
A developer finishes work on a feature branch and submits it for team...
A company wants a control specifically positioned to inspect and...
A development team removes hardcoded database passwords from their...
An administrator needs to SSH into private cloud instances that have...
A company operating in the European Union must ensure that customer...
A security team runs a scan across cloud resources, confirms which...
A cloud resource's operating system version has reached the point...
A backup strategy performs a complete copy of all data every Sunday,...
A company deploys a PaaS-based application platform and understands...
A team troubleshooting a slow microservices-based application wants to...
Match each provisioning requirement category to an example...
An operations team notices that a cloud resource's actual...
A company moves an application to the cloud by simply copying its...
A team releases a new application version to only 5% of production...
Several universities in a research consortium jointly fund and share a...
A containerized database needs its data to survive even if the...
A development team designs an application so that its individual...
Match each storage type to its best-fit use case description.
A company wants to connect two separate virtual private clouds...
A disaster recovery plan specifies that after a major outage, the...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!