CompTIA Cloud + CV0-004 (V4) Exam Practice Test 3

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. An application's scaling policy is configured to add capacity every weekday at 8 AM in anticipation of the regular morning traffic surge, and remove that capacity every evening at 8 PM, regardless of actual real-time demand. Which scaling approach is this?

Explanation

Scaling based on a predefined time, regardless of real-time demand, is scheduled scaling. Triggered scaling based on load or trending reacts to actual real-time metrics rather than a fixed clock time, manual scaling requires human initiation, and vertical scaling specifically concerns resizing existing resources rather than the scheduling mechanism itself.

Submit
Please wait...
About This Quiz
CompTIA Cloud + Cv0-004 (V4) Exam Practice Test 3 - Quiz

This practice assessment focuses on the CompTIA Cloud + CV0-004 (V4) certification, evaluating your understanding of cloud architecture, deployment, and security. It is designed for individuals preparing for the certification exam, providing relevant scenarios and concepts to enhance your cloud knowledge. Engaging with this assessment can help solidify your skills... see moreand boost your confidence for the certification process. see less

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A security audit finds that several cloud instances are still configured to accept connections using an outdated, deprecated cipher suite that no longer provides adequate protection against modern cryptographic attacks. Which security troubleshooting category is this?

Explanation

Instances still accepting an outdated, deprecated cipher suite is specifically a cipher suite deprecation issue. Authorization issues concern permission-related problems like privilege escalation, authentication issues concern credential-related problems, unauthorized software concerns unapproved applications, and software vulnerability issues generically concern exploitable code flaws rather than an outdated cryptographic algorithm configuration.

Submit

3. A network administrator troubleshooting connectivity discovers that two separate cloud VPCs were both configured with the same private IP address range, causing routing conflicts when the two networks are peered together. Which issue is this?

Explanation

Two networks configured with the same address range, causing conflicts when connected, is network overlap. Scope exhaustion concerns a DHCP pool running out of addresses, missing routes concerns absent routing table entries, misconfigured tags concerns VLAN tagging errors, and access versus trunk ports concerns switch port configuration rather than overlapping address ranges between two VPCs.

Submit

4. A cloud administrator finds that a newly deployed application fails to start because the container image references a base image version that was removed from the registry months ago and is no longer available. Which deployment issue is this?

Explanation

A deployment referencing a component version that no longer exists in the registry is specifically an outdated component definition issue. Incompatibility concerns components that exist but don't work together correctly, sizing issues concern inappropriately sized resources, permission issues concern access rights, and regional service availability concerns whether a service exists in a given region rather than a stale version reference.

Submit

5. A team integrating two internal systems wants one system to expose data through a lightweight, resource-oriented API using standard HTTP methods like GET and POST, favoring simplicity over the more rigid, XML-based messaging structure of an older protocol. Which web service style are they choosing?

Explanation

REST uses a lightweight, resource-oriented approach with standard HTTP methods, favoring simplicity over more rigid alternatives. SOAP relies on a more rigid, XML-based messaging structure, RPC invokes remote procedures directly rather than emphasizing resource orientation, web sockets provide persistent bidirectional connections, and GraphQL exclusively offers a flexible query language approach rather than this simpler HTTP-method-based style.

Submit

6. A developer wants a version control record showing the specific line-by-line changes introduced by a particular set of commits, before deciding whether to approve merging a pull request. Which source control concept enables reviewing these specific changes?

Explanation

Code review is the process of examining specific line-by-line changes before approving a merge, exactly matching this pull request evaluation step. Code push uploads commits to a remote repository, branch management alone organizes separate lines of development, version management alone tracks change history broadly, and a code commit alone records a snapshot locally rather than describing the act of reviewing changes.

Submit

7. A cloud security team discovers a running instance that was provisioned months ago for a since-completed project, was never properly decommissioned, and continues consuming resources and potentially exposing an attack surface without anyone actively monitoring it. Complete the sentence: this abandoned but still-running resource is called a ______.

Explanation

A zombie instance is a forgotten, still-running resource that was never properly decommissioned, continuing to consume resources and potentially expand attack surface unmonitored.

Submit

8. A company deploys a control specifically designed to detect and block a volumetric flood of traffic aimed at overwhelming a public-facing application's availability, distinct from a control that filters application-layer content like SQL injection attempts. Which control is this?

Explanation

DDoS protection specifically detects and mitigates volumetric floods aimed at overwhelming availability. A WAF filters application-layer content like SQL injection, a network ACL filters traffic at the subnet level, IAM policies govern identity permissions, and a network security group filters traffic at the instance level rather than specifically defending against volumetric availability floods.

Submit

9. A company wants users authenticating to its cloud application to be automatically granted permissions based on their assigned job function, such as 'analyst' or 'administrator,' rather than having permissions individually assigned to each user one at a time. Which authorization model is this?

Explanation

Role-based access control assigns permissions based on a defined role or job function, such as analyst or administrator, rather than individually per user. OAuth 2.0 is an authorization delegation framework, discretionary access control lets resource owners assign permissions directly, group-based access control assigns permissions by group membership rather than role definition specifically, and token-based describes an authentication model rather than a role-driven authorization model.

Submit

10. A company's legal team places a hold on deleting certain email records because those records may become relevant evidence in ongoing litigation, overriding the normal data retention schedule. Which compliance concept is this?

Explanation

A litigation hold suspends normal data destruction schedules for records that may become relevant evidence in legal proceedings. Data sovereignty concerns geographic data residency requirements, data classification categorizes data by sensitivity, data locality concerns where data physically resides, and data ownership concerns who holds rights to data rather than this litigation-driven retention override.

Submit

11. A security team defines the specific systems, applications, and network ranges that will be included in an upcoming vulnerability assessment, explicitly excluding a legacy system scheduled for retirement next month. Which vulnerability management step does this represent?

Explanation

Defining which systems, applications, and ranges will be included or excluded from an assessment is establishing the scanning scope. Identification discovers vulnerabilities within that defined scope, assessment evaluates findings, remediation applies fixes, and CVE cataloging references the standardized vulnerability database rather than defining what will be scanned.

Submit

12. A cloud resource reaches the point where the vendor no longer provides any technical support or troubleshooting assistance for it, even though the vendor may still occasionally release critical security patches for a limited additional period. Which lifecycle concept is this?

Explanation

End of support marks the point where vendor technical assistance stops, which can occur separately from and sometimes before complete end of life when all patches stop entirely. Major and minor updates describe version change types, and decommissioning generically describes the broader retirement process rather than this specific support-cutoff milestone.

Submit

13. A company's backup policy requires that in addition to on-site backups for fast recovery, a copy of critical data also be stored at a geographically separate location to protect against a site-wide disaster. Complete the sentence: this second copy's storage location is described as ______.

Explanation

Off-site backup storage keeps a copy at a geographically separate location, protecting against a disaster affecting the primary site entirely, unlike on-site backups stored at the same location as the primary data.

Submit

14. A company operating a global application wants to ensure that if one entire cloud region becomes unavailable due to a natural disaster, a completely separate region can take over serving traffic. Which resource availability concept specifically describes the isolated fault domain within a single region that this is more granular than?

Explanation

An availability zone is an isolated fault domain within a single region, more granular than the region-level failover described in the question. Cloud bursting overflows to additional capacity during demand spikes, edge computing brings processing closer to end users, multicloud tenancy describes using multiple providers, and availability monitoring tracks uptime rather than describing this specific intra-region isolation unit.

Submit

15. A company's log management strategy defines how long different categories of logs must be kept before being automatically deleted, balancing compliance needs against storage costs. Which logging concept is this?

Explanation

Retention defines how long logs are kept before deletion, balancing compliance requirements against storage costs. Collection concerns gathering logs from sources, aggregation concerns combining logs into a centralized location, tracing follows individual requests across services, and alerting notifies based on log-derived conditions rather than defining storage duration.

Submit

16. A company provisioning cloud resources for a new e-commerce platform must ensure the infrastructure can handle Black Friday-level traffic spikes without service degradation, while keeping normal-day costs reasonable. Which provisioning requirement category primarily drives this consideration?

Explanation

Ensuring infrastructure can handle traffic spikes without degradation while balancing cost is primarily an availability requirement, often addressed through elastic scaling. Cost requirements alone would focus purely on budget without the traffic-handling angle, compliance requirements concern regulatory constraints, storage requirements alone concern data storage needs, and security requirements concern protection controls rather than handling traffic spikes specifically.

Submit

17. A DevOps engineer chooses to write infrastructure-as-code templates in a human-readable format that uses indentation to define structure, commonly used for configuration files and widely favored for its readability over more verbose alternatives. Which format is this?

Explanation

YAML uses indentation to define structure and is widely favored for its human readability in configuration files. JSON uses brackets and braces rather than indentation for structure, XML uses verbose tag-based markup, CSV is a flat tabular format unsuited to nested configuration, and binary formats are not human-readable at all.

Submit

18. A company migrating an application decides to make minor code adjustments to take advantage of cloud-native features like managed load balancing, without fully redesigning the application's core architecture. Which application migration strategy is this?

Explanation

Replatforming makes minor adjustments to leverage cloud-native features without a full architectural redesign. Rehosting moves the application with no changes at all, re-architecting substantially redesigns the application, retaining keeps the application where it is, and retiring shuts the application down entirely rather than migrating it with minor adjustments.

Submit

19. A team deploys a new application version by maintaining two complete, separate production environments, then instantly switching all live traffic from the old environment to the fully tested new one, keeping the old environment available briefly in case a rollback is needed. Separately, a different team updates production instances one at a time, removing each from the load balancer, updating it, and returning it to service before moving to the next. Which two deployment strategies are described, respectively?

Explanation

Maintaining two complete environments and switching all traffic at once is blue-green deployment, while incrementally updating instances one at a time while keeping some capacity available is rolling deployment. Canary releases to a small percentage of traffic first, in-place deployment updates every instance simultaneously with no gradual replacement, and parallel recovery is a disaster recovery concept rather than either of these two deployment strategies.

Submit

20. A hospital system and a private cloud provider jointly agree to combine the hospital's own on-premises private cloud with the provider's public cloud, allowing the hospital to burst overflow workloads to the public cloud during peak demand while keeping sensitive data on-premises. Which cloud deployment model is this?

Explanation

A hybrid cloud combines private and public cloud environments, allowing workloads to move between them, exactly matching this on-premises-plus-public-cloud-bursting scenario. Public cloud alone is third-party-operated for general use, private cloud alone serves a single organization exclusively, community cloud is shared among multiple organizations with common needs, and on-premises alone describes hosting location rather than this specific combination of two deployment models.

Submit

21. A virtualization team configures a VM's network so that multiple physical hosts appear to share a single flat virtual network regardless of their underlying physical network topology, encapsulating traffic to achieve this abstraction. Separately, the team configures a distinct virtual network specifically dedicated to traffic between VMs on the same host. Which two virtualization network types are described, respectively?

Explanation

A virtual network that abstracts multiple physical hosts into a single flat network through encapsulation is an overlay network, while a virtual network dedicated to VM-to-VM traffic on the same host is a VM network. SAN and NAS are storage technologies rather than networking concepts, and local storage refers to storage attached directly to a single host rather than either of these networking abstractions.

Submit

22. A containerized application exposes an internal port 8080 to the outside world on the host's port 80, so external traffic on the standard web port reaches the correct internal application port. Which containerization concept is this?

Explanation

Port mapping connects a host port to a container's internal port, exactly matching external port 80 traffic being routed to internal port 8080. Persistent volumes and ephemeral storage concern data durability, image registries store container images, and workload orchestration manages container scheduling and deployment rather than network port translation.

Submit

23. A cloud-native application relies entirely on managed services provided by the cloud vendor, such as managed databases and managed message queues, rather than operating and patching that underlying software itself. Which cloud-native design concept is this?

Explanation

Relying on vendor-operated components like managed databases and queues, rather than operating that software directly, is cloud-provided managed services. Microservices alone describes the architectural style, service discovery describes how services locate each other, fan-out describes distributing one event to many consumers, and loosely coupled architecture alone describes independence between components rather than describing reliance on vendor-managed infrastructure.

Submit

24. Match each storage tier to its best-fit description.

Explanation

Hot tier suits frequent access at higher cost, warm tier balances moderate access and cost, cold tier further prioritizes cost over speed, and archive tier is the lowest-cost, slowest-retrieval option for rarely accessed long-term data, together forming a cost-versus-access-speed spectrum.

Submit

25. A network engineer configures a protocol that dynamically exchanges routing information between a company's on-premises network and its cloud provider's network, allowing routes to adjust automatically if a path becomes unavailable. Which protocol is this?

Explanation

BGP dynamically exchanges routing information between networks, allowing routes to adapt automatically to path changes. VLAN segments a local network at layer 2, SDN generically describes software-controlled networking broadly, static routes are manually defined and don't adjust automatically, and route tables alone store routing entries without providing the dynamic exchange protocol itself.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
An application's scaling policy is configured to add capacity every...
A security audit finds that several cloud instances are still...
A network administrator troubleshooting connectivity discovers that...
A cloud administrator finds that a newly deployed application fails to...
A team integrating two internal systems wants one system to expose...
A developer wants a version control record showing the specific...
A cloud security team discovers a running instance that was...
A company deploys a control specifically designed to detect and block...
A company wants users authenticating to its cloud application to be...
A company's legal team places a hold on deleting certain email records...
A security team defines the specific systems, applications, and...
A cloud resource reaches the point where the vendor no longer provides...
A company's backup policy requires that in addition to on-site backups...
A company operating a global application wants to ensure that if one...
A company's log management strategy defines how long different...
A company provisioning cloud resources for a new e-commerce platform...
A DevOps engineer chooses to write infrastructure-as-code templates in...
A company migrating an application decides to make minor code...
A team deploys a new application version by maintaining two complete,...
A hospital system and a private cloud provider jointly agree to...
A virtualization team configures a VM's network so that multiple...
A containerized application exposes an internal port 8080 to the...
A cloud-native application relies entirely on managed services...
Match each storage tier to its best-fit description.
A network engineer configures a protocol that dynamically exchanges...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!