CompTIA Cloud + CV0-004 (V4) Exam Practice Test 4

Reviewed by Editorial Team
The ProProfs editorial team is comprised of experienced subject matter experts. They've collectively created over 10,000 quizzes and lessons, serving over 100 million users. Our team includes in-house content moderators and subject matter experts, as well as a global network of rigorously trained contributors. All adhere to our comprehensive editorial guidelines, ensuring the delivery of high-quality content.
Learn about Our Editorial Process
| By Thames
T
Thames
Community Contributor
Quizzes Created: 11201 | Total Attempts: 9,875,275
| Questions: 25 | Updated: Sep 30, 2026
Please wait...
Question 1 / 26
🏆 Rank #-- ▾
0 %
0/100
Score 0/100

1. Match each deployment strategy to its description.

Explanation

Blue-green switches all traffic between two parallel environments at once, canary gradually increases exposure starting from a small percentage, rolling incrementally replaces instances while maintaining availability, and in-place updates every instance simultaneously, typically with some downtime.

Submit
Please wait...
About This Quiz
CompTIA Cloud + Cv0-004 (V4) Exam Practice Test 4 - Quiz

This practice assessment focuses on the CompTIA Cloud + CV0-004 (V4) certification, evaluating your understanding of cloud technologies, deployment models, and security. It is designed to enhance your knowledge and prepare you for real-world scenarios in cloud environments, making it an essential resource for aspiring cloud professionals.

2.

What first name or nickname would you like us to use?

You may optionally provide this to label your report, leaderboard, or certificate.

2. A security review finds that an employee installed an unapproved remote access tool on a cloud instance to bypass the organization's standard access controls, creating an unmonitored entry point into the environment. Which security troubleshooting category is this?

Explanation

An unapproved tool installed to bypass standard access controls is specifically unauthorized software. Authentication issues concern credential-related problems like leaked credentials, cipher suite deprecations concern outdated encryption algorithms, software vulnerability issues generically concern exploitable code flaws in otherwise approved software, and authorization issues concern permission-related problems like privilege escalation rather than an unapproved tool being installed.

Submit

3. A network administrator troubleshooting connectivity finds that a switch port connected to a server is configured to carry traffic for only one VLAN, but the server actually needs to send and receive tagged traffic for multiple VLANs simultaneously. Which issue is this?

Explanation

A port configured for a single untagged VLAN when the server needs multi-VLAN tagged traffic is an access-versus-trunk-port misconfiguration; the port needs to be a trunk port rather than an access port. Scope exhaustion concerns a DHCP pool running out of addresses, network overlap concerns duplicate address ranges, missing routes concerns absent routing entries, and MTU mismatch concerns packet size handling rather than VLAN tagging capability.

Submit

4. A cloud deployment fails because a newly provisioned resource requires a specific permission that the deploying service account was never granted, causing the automation pipeline to halt with an access-denied error. Which deployment issue is this?

Explanation

A deployment halting because the service account lacks a required permission is specifically a permission issue. Incompatibility concerns components that don't work together correctly, sizing issues concern inappropriately sized resources, outdated component definitions concerns stale version references, and deprecation of functionality concerns a feature being phased out entirely rather than a missing access grant.

Submit

5. A company must classify its data into categories such as public, internal, confidential, and restricted, so that appropriate handling and protection controls can be applied based on sensitivity. Separately, the company must ensure that data collected from customers in a specific country remains stored and processed only within that country's borders, per local legal requirements. Which two compliance concepts are described, respectively?

Explanation

Categorizing data by sensitivity level is data classification, while requiring data to remain within a specific country's borders per legal requirement is data sovereignty. Data ownership concerns who holds rights to the data, litigation hold suspends deletion for legal proceedings, and data locality alone is a related but narrower physical-location concept rather than the broader legal residency requirement described here.

Submit

6. A company's cloud security team catalogs every publicly known vulnerability affecting the software components in their environment using a standardized identifier system, to track and reference specific issues consistently across tools and reports. Which system provides these standardized identifiers?

Explanation

CVE provides standardized identifiers for publicly known vulnerabilities, enabling consistent tracking and reference across tools and reports. CVSS scores the severity of a given vulnerability rather than identifying it, and SOC2, PCI DSS, and ISO 27001 are compliance and industry standards rather than a vulnerability identifier system.

Submit

7. A vendor releases a new version of a cloud service that adds significant new capabilities and may include breaking changes requiring customers to update their integration code. Complete the sentence: this type of release is called a ______ update.

Explanation

A major update typically introduces significant new capabilities and may include breaking changes requiring integration updates, unlike a minor update which typically adds smaller, backward-compatible improvements.

Submit

8. A recovery test verifies not only that a backup can be restored, but that the restored data is complete and uncorrupted by comparing checksums against the original. Which testing concept does this checksum comparison represent?

Explanation

Integrity testing confirms restored data is complete and uncorrupted, such as through checksum comparison against the original. Recoverability testing confirms that a restore can actually be performed successfully at all, while bulk recovery, granular recovery, and in-place recovery describe recovery scope and method rather than data correctness verification.

Submit

9. An application's scaling policy requires an administrator to explicitly click a button to add or remove capacity, with no automatic trigger based on load, schedule, or trend at all. Which scaling approach is this?

Explanation

Manual scaling requires explicit human action to add or remove capacity, with no automatic trigger of any kind. Triggered scaling based on load or trending reacts automatically to metrics, scheduled scaling activates at predefined times, and horizontal scaling specifically concerns adding instances rather than describing the human-initiated activation mechanism itself.

Submit

10. A company's log management strategy defines how long different categories of logs must be kept before being automatically deleted, balancing compliance needs against storage costs. Complete the sentence: this logging concept is called ______.

Explanation

Retention defines how long logs are kept before deletion, balancing compliance requirements against storage costs.

Submit

11. A company provisioning cloud resources for a healthcare application must ensure patient data is only stored and processed in regions meeting specific regulatory data residency requirements. Which provisioning requirement category primarily drives this?

Explanation

Ensuring data is stored and processed only in regions meeting regulatory residency requirements is a compliance requirement. Performance requirements concern speed and responsiveness, cost requirements concern budget, network requirements concern connectivity and bandwidth, and compute requirements concern processing capacity rather than regulatory geographic constraints.

Submit

12. An infrastructure-as-code script needs to execute a specific block of logic only if a resource does not already exist, avoiding an error from trying to create a duplicate. Which scripting logic concept enables this decision?

Explanation

A conditional executes a block of logic only if a specified condition, such as a resource not already existing, evaluates as true. Variables store reusable values, data types generically describe the kind of value stored, functions encapsulate reusable logic blocks, and operators alone perform comparisons or calculations rather than making the branching decision itself.

Submit

13. A company migrating a monolithic application decides to substantially redesign it into a microservices architecture specifically to take full advantage of cloud-native scalability, rather than making only minor adjustments. Which application migration strategy is this?

Explanation

Re-architecting substantially redesigns an application, such as converting a monolith to microservices, to fully leverage cloud-native capabilities. Rehosting moves the application with no changes, replatforming makes only minor adjustments, retaining keeps the application where it is, and retiring shuts the application down entirely rather than redesigning it.

Submit

14. A finance team reviewing the monthly cloud bill wants to attribute costs to specific departments and projects by applying key-value labels to every resource at creation time. Which cost consideration concept is this?

Explanation

Tagging applies key-value labels to resources, enabling cost attribution to specific departments or projects. Rightsizing adjusts resource sizing to match actual usage, resource metering tracks consumption for billing broadly, and reserved resources and spot instances are billing models rather than the labeling mechanism itself.

Submit

15. A company decides to run its own private cloud entirely within its own data center, giving it full control over hardware while adopting cloud-like self-service provisioning internally, without any public cloud component at all. Which specific deployment sub-model is this?

Explanation

An on-premises deployment runs a private cloud within the organization's own data center, giving full hardware control while adopting cloud-like self-service capabilities. Public cloud is operated by a third-party provider for general use, hybrid combines multiple deployment models, community cloud is shared among multiple organizations, and multicloud describes using multiple different cloud providers rather than describing where a single private cloud is physically hosted.

Submit

16. A DevOps team wants a specific tool to automate configuration management across a fleet of servers, using simple, human-readable playbooks and requiring no agent software installed on the managed servers themselves. Which tool fits this description?

Explanation

Ansible automates configuration management using human-readable playbooks and is agentless, requiring no software installed on managed servers. Terraform focuses on infrastructure provisioning rather than configuration management specifically, Jenkins automates CI/CD pipeline execution, Grafana visualizes metrics and dashboards, and Kubernetes orchestrates containerized workloads rather than providing agentless configuration management.

Submit

17. A developer wants to permanently record a snapshot of their staged code changes into the local repository's history, with a descriptive message explaining what changed, before later sharing those changes with the team. Which source control concept is this?

Explanation

A code commit records a snapshot of staged changes into the local repository history with a descriptive message. Code push uploads those local commits to a remote repository, a pull request submits changes for team review before merging, code review examines the changes themselves, and branch management alone organizes separate lines of development rather than recording a snapshot of changes.

Submit

18. A security team investigating suspicious activity finds that an attacker gained access to a container and is now using its compute resources to mine cryptocurrency without authorization, silently running in the background. Which attack type is this?

Explanation

Cryptojacking is the unauthorized use of compute resources to mine cryptocurrency, typically running silently in the background. Ransomware encrypts data for extortion, DDoS floods a target with traffic to disrupt availability, a zombie instance generically describes an abandoned but legitimate resource rather than active unauthorized mining, and social engineering manipulates people rather than describing this resource-hijacking attack.

Submit

19. A company wants to reference a widely recognized set of configuration hardening recommendations for its cloud instances, developed through industry consensus and applicable across multiple cloud providers, distinct from recommendations published by any single vendor. Which benchmark source is this?

Explanation

CIS benchmarks are widely recognized, industry-consensus configuration hardening recommendations applicable across multiple providers. Vendor-specific benchmarks are published by a single cloud provider for their own platform, PCI DSS addresses payment card data protection specifically, SOC2 addresses broader trust service criteria, and GDPR governs personal data protection rather than providing general configuration hardening guidance.

Submit

20. A network architect configures a device to inspect and control traffic entering or leaving an entire virtual network subnet based on IP address and port rules, evaluating traffic statelessly rule by rule. Separately, the architect configures a different control that filters traffic at the individual instance level, tracking connection state to allow return traffic automatically. Which two network security components are described, respectively?

Explanation

A subnet-level control evaluating traffic statelessly by IP and port is a network ACL, while an instance-level, stateful control that tracks connections is a network security group. A WAF filters application-layer web traffic specifically, IPS/IDS provides broader intrusion detection and prevention, and VPC peering connects two virtual networks rather than filtering traffic at either the subnet or instance level.

Submit

21. A company maintains a fully staffed, continuously running standby data center with real-time data replication, ready to take over operations within minutes of a primary site failure, at significant ongoing cost. Which disaster recovery site type is this?

Explanation

A hot site is a fully staffed, continuously running standby facility with real-time replication, ready for near-immediate failover at significant cost. A cold site provides only basic infrastructure requiring substantial setup time, a warm site is partially configured with a moderate activation time, and an availability zone or region alone describe cloud infrastructure geography rather than a dedicated standby disaster recovery facility.

Submit

22. A startup wants to purchase a complete, ready-to-use email marketing application over the internet, accessed through a web browser, without installing, managing, or maintaining any of the underlying software or infrastructure themselves. Which cloud service model is this?

Explanation

SaaS delivers a complete, ready-to-use application accessed over the internet, with the provider handling all underlying software and infrastructure. IaaS provides virtualized infrastructure the customer still manages, PaaS provides a platform for deploying custom applications, FaaS runs individual triggered functions, and the shared responsibility model describes the division of security duties rather than being a service model itself.

Submit

23. A logistics company deploys thousands of low-power sensors on shipping containers that periodically transmit location and temperature data to a centralized cloud platform for fleet monitoring. Which evolving technology category do these devices belong to?

Explanation

Low-power sensors transmitting data to a centralized platform for monitoring is a core IoT use case. Machine learning and AI describes a different category of evolving technology focused on data analysis and pattern recognition, and generative AI, visual recognition, and text-to-voice are all specific AI capabilities rather than the sensor-and-connectivity category these devices belong to.

Submit

24. A team optimizing storage-heavy workloads focuses specifically on the number of read and write operations a storage volume can handle per second, which directly impacts database and transactional application performance. Which storage optimization metric is this?

Explanation

IOPS measures the number of read and write operations a storage volume can handle per second, directly impacting database and transactional performance. Throughput alone measures data volume transferred over time rather than operation count, latency measures delay per operation, CPU utilization measures compute usage, and network bandwidth measures network capacity rather than storage operation rate.

Submit

25. A company wants a fully managed database service where the cloud provider handles patching, backups, and infrastructure maintenance, allowing the internal team to focus purely on schema design and queries. Which database deployment option is this?

Explanation

Provider-managed database deployment has the cloud vendor handle patching, backups, and infrastructure maintenance, letting the team focus on schema and queries. Self-managed deployment requires the customer to handle that maintenance directly, relational and non-relational describe database data models rather than management responsibility, and on-premises hosted describes physical location rather than who manages the database.

Submit
×
Saved
Thank you for your feedback!
View My Results
Cancel
  • All
    All (25)
  • Unanswered
    Unanswered ()
  • Answered
    Answered ()
Match each deployment strategy to its description.
A security review finds that an employee installed an unapproved...
A network administrator troubleshooting connectivity finds that a...
A cloud deployment fails because a newly provisioned resource requires...
A company must classify its data into categories such as public,...
A company's cloud security team catalogs every publicly known...
A vendor releases a new version of a cloud service that adds...
A recovery test verifies not only that a backup can be restored, but...
An application's scaling policy requires an administrator to...
A company's log management strategy defines how long different...
A company provisioning cloud resources for a healthcare application...
An infrastructure-as-code script needs to execute a specific block of...
A company migrating a monolithic application decides to substantially...
A finance team reviewing the monthly cloud bill wants to attribute...
A company decides to run its own private cloud entirely within its own...
A DevOps team wants a specific tool to automate configuration...
A developer wants to permanently record a snapshot of their staged...
A security team investigating suspicious activity finds that an...
A company wants to reference a widely recognized set of configuration...
A network architect configures a device to inspect and control traffic...
A company maintains a fully staffed, continuously running standby data...
A startup wants to purchase a complete, ready-to-use email marketing...
A logistics company deploys thousands of low-power sensors on shipping...
A team optimizing storage-heavy workloads focuses specifically on the...
A company wants a fully managed database service where the cloud...
play-Mute sad happy unanswered_answer up-hover down-hover success oval cancel Check box square blue
Alert!