โ† All CompTIA Cloud+ Flashcard Decks

Cloud Environment Troubleshooting Flashcards

6 cards from real CompTIA Cloud+ practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 6 Cloud Environment Troubleshooting flashcards as text
  1. A cloud engineer is troubleshooting a connectivity issue where an application on a virtual machine (VM) in a private subnet cannot access a public API on the internet. A NAT gateway exists in a public subnet, and the security group for the VM allows all outbound traffic. What is the MOST likely misconfiguration causing this issue?

    Answer: The route table for the private subnet does not have a route pointing to the NAT gateway.

    For a resource in a private subnet to access the internet, its subnet's route table must have a default route (0.0.0.0/0) that directs traffic to a NAT gateway. The NAT gateway, located in a public subnet, then forwards the traffic to the Internet Gateway. A missing or incorrect route in the private subnet's route table is the most common cause of this specific problem.

  2. An e-commerce application is experiencing slow performance. Monitoring dashboards show that the database instances have CPU utilization consistently above 90% but normal memory and I/O metrics. The database is primarily handling a large volume of read requests. Which of the following is the MOST effective solution to resolve this performance bottleneck?

    Answer: Implement a read replica and direct read queries to it.

    The high CPU utilization indicates the database server is overwhelmed with processing queries. Since the workload is read-heavy, introducing a read replica allows the application to offload the read queries from the primary database instance. This distributes the load and reduces the CPU pressure on the primary, resolving the bottleneck.

  3. A deployment of a new application version using an Infrastructure as Code (IaC) script fails with an error message: "The requested resource is not available in the specified availability zone." The script attempts to create a virtual machine using a specific instance type. Which of the following is the MOST likely cause of this error?

    Answer: The specified instance type is not offered in the selected availability zone.

    Cloud providers do not always offer every instance type in every availability zone within a region. This error indicates that the specific combination of instance type and availability zone chosen in the IaC script is invalid. The troubleshooting step is to check the cloud provider's documentation for available instance types in that zone and update the script.

  4. A cloud administrator receives an alert that a storage bucket containing sensitive data is publicly accessible, which violates company policy. Which of the following tools should the administrator use to proactively and continuously scan the cloud environment for such misconfigurations and policy violations?

    Answer: A Cloud Security Posture Management (CSPM) tool

    A Cloud Security Posture Management (CSPM) tool is designed to automate the detection of security risks related to misconfigurations in cloud environments. It continuously monitors for policy violations, such as publicly exposed storage buckets or overly permissive IAM roles, and provides remediation guidance.

  5. An application hosted in the cloud has stopped responding. A cloud engineer discovers that a critical service on the virtual machine has crashed. The engineer restarts the service, and the application recovers. To prevent manual intervention for this issue in the future, which of the following should be implemented?

    Answer: Create an automated health check that restarts the service upon failure.

    The most effective solution is to automate the remediation process. By configuring a health check, the system can automatically detect when the critical service is unresponsive and execute a pre-defined action, such as restarting the service. This improves reliability and reduces Mean Time to Recovery (MTTR).

  6. A user reports being unable to access a newly deployed web application via its domain name. An engineer confirms the application is running correctly on its virtual machine and that security groups allow inbound traffic. Pinging the server's public IP address is successful, but attempting to resolve the domain name fails. Which of the following is the MOST likely service to investigate to resolve this issue?

    Answer: Domain Name System (DNS)

    The problem description states that the domain name fails to resolve, while the server is reachable via its IP address. This is a classic symptom of an issue with the Domain Name System (DNS). The engineer should check the DNS records (e.g., the 'A' record) to ensure the domain name correctly points to the server's public IP address.