Mixed Deck — All CompTIA Cloud+ Topics Flashcards
99 cards from real CompTIA Cloud+ practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 20 Mixed Deck — All CompTIA Cloud+ Topics flashcards as text
What is the likely cause if a cloud-based database stops responding during a query?
Answer: Lock contention or deadlock in the database
Deadlocks can occur when two or more processes compete for the same resources, causing the database to hang.
A security team wants to automate the detection of misconfigurations and compliance violations across their entire multi-cloud IaaS environment. Their goal is to continuously scan for issues like publicly accessible storage buckets, overly permissive IAM policies, and unused security groups. Which type of tool is specifically designed for this purpose?
Answer: Cloud Security Posture Management (CSPM)
Cloud Security Posture Management (CSPM) tools are designed to identify and remediate misconfiguration risks and compliance violations in cloud environments. They work by continuously monitoring the configuration of cloud infrastructure services against a set of security best practices and compliance standards, which is exactly what the security team requires.
What is the CIDR notation for a subnet that provides exactly 254 usable host addresses?
Answer: /24
A /24 subnet provides 256 total addresses (2^8), with 254 usable host addresses after reserving the network address and broadcast address.
A DevOps engineer is troubleshooting a multi-tier application where a user request flows through a web server, an application server, and a database. To trace the entire lifecycle of a single user request across all these services, which of the following is MOST essential to have implemented?
Answer: Centralized logging with correlation IDs
A correlation ID is a unique identifier attached to a request at the beginning and passed along through each service it touches. When logs from all services are aggregated into a centralized system, an engineer can filter by this correlation ID to see all log entries related to that single transaction. This makes it possible to trace a request's entire journey across a distributed system, which is essential for effective troubleshooting.
An organization wants to centralize the collection and analysis of log data from various cloud resources, including virtual machines, databases, and network components. The goal is to enable real-time threat detection, security incident investigation, and compliance reporting. Which of the following security controls should be implemented?
Answer: Security Information and Event Management (SIEM)
A Security Information and Event Management (SIEM) system is the most appropriate solution. SIEMs specialize in aggregating, correlating, and analyzing log and event data from a wide variety of sources across an IT environment. This centralized analysis allows security teams to detect potential threats, investigate incidents, and generate reports for compliance purposes.
A cloud engineer wants to proactively monitor the user experience of a global e-commerce application by simulating common user journeys, such as logging in, adding an item to the cart, and checking out. This monitoring should be performed from various geographic locations even when there is no real user traffic. What type of monitoring is this?
Answer: Synthetic monitoring
Synthetic monitoring involves using scripts or bots to simulate user paths and transactions against an application. This allows for proactive, 24/7 monitoring of availability and performance from different locations, independent of actual user traffic. Real User Monitoring (RUM), in contrast, collects performance data from the browsers of actual users as they interact with the site.
Which routing protocol is standard for exchanging routes between autonomous systems in hybrid cloud and internet environments?
Answer: BGP
Border Gateway Protocol (BGP) is the standard inter-AS routing protocol used on the internet and in hybrid cloud connections such as Direct Connect and ExpressRoute.
The finance department has notified the cloud operations team of a sudden and significant increase in the monthly cloud bill, specifically related to data egress charges. Which of the following actions should the team take FIRST to investigate the root cause?
Answer: Analyze detailed billing and usage reports, filtering by data transfer out of the cloud region.
Before taking any corrective action, the first step is to diagnose the problem. Data egress fees are charges for moving data out of a cloud provider's network. Analyzing detailed billing and cost management reports will provide data on which service, resource, or region is responsible for the high volume of data transfer, allowing the team to pinpoint the cause. The other options are potential solutions, not investigative steps.
A company experiences intermittent connectivity between their on-premises network and a cloud VPC. The VPN tunnel status shows as active. What should the engineer check NEXT?
Answer: Verify BGP routing tables and route propagation settings on both ends
An active tunnel status confirms the VPN is up, but intermittent connectivity often indicates routing issues — verifying BGP tables and route propagation is the correct next diagnostic step.
What is a common method for securing data in transit?
Answer: Transport Layer Security (TLS) encryption
Transport Layer Security (TLS) encryption is a common and highly effective method for securing data in transit across networks, including the internet. TLS establishes an encrypted connection between a client and a server, ensuring the confidentiality and integrity of the data exchanged. This protocol protects information from eavesdropping, tampering, and message forgery, making it crucial for secure communication.
Which of the following best describes data encryption?
Answer: The practice of converting data into an unreadable format to prevent unauthorized access
Data encryption is the practice of converting data into an unreadable format, known as ciphertext, using an algorithm and an encryption key. This process prevents unauthorized access by rendering the data unintelligible to anyone without the correct decryption key. It is a fundamental security measure for protecting sensitive information both at rest and in transit.
A large enterprise wants to allow its employees to use their corporate Active Directory credentials to access several third-party SaaS applications. The goal is to provide a seamless single sign-on (SSO) experience and centralize identity management. Which cloud architecture concept would enable this functionality?
Answer: Federated Identity Management (FIM)
Federated Identity Management (FIM) is a system that allows users from different security domains to access resources across those domains using a single set of credentials. It establishes a trust relationship between the enterprise's identity provider (Active Directory) and the service providers (SaaS applications), enabling SSO.
A company is developing a cloud-native application using containers and serverless functions. They need a security solution that focuses specifically on protecting these ephemeral workloads during runtime. The solution should provide vulnerability scanning, malware detection, and integrity monitoring for the workloads themselves. Which of the following is the BEST choice?
Answer: Cloud Workload Protection Platform (CWPP)
A Cloud Workload Protection Platform (CWPP) is designed to secure cloud workloads, such as virtual machines, containers, and serverless functions, throughout their lifecycle. It provides runtime protection, including threat detection, vulnerability management, and integrity monitoring, specifically for the applications and services running in the cloud, which is distinct from securing the cloud infrastructure itself (the focus of CSPM).
According to the shared responsibility model for a Platform-as-a-Service (PaaS) offering, which of the following is typically the CUSTOMER'S responsibility to secure?
Answer: The applications and data deployed on the platform
In the PaaS model, the cloud provider is responsible for securing the underlying infrastructure, including the physical data center, network, servers, operating systems, and the platform runtime. The customer is responsible for securing the applications they deploy on the platform, the data those applications process, and managing user access.
A company has determined that for a specific application, the maximum tolerable data loss is 15 minutes and the maximum tolerable downtime is 4 hours. Which disaster recovery solution BEST aligns with these RPO and RTO requirements in a cost-effective manner?
Answer: Asynchronous replication to a warm standby site
An RPO of 15 minutes and an RTO of 4 hours can be met effectively by a warm standby site. Asynchronous replication, where data is copied periodically, can easily meet a 15-minute RPO. [21] A warm standby site, which has a scaled-down but functional environment always running, can be scaled up to handle the production load within the 4-hour RTO. [22, 24] Daily backups (24-hour RPO) and synchronous replication (near-zero RPO/RTO but very expensive) do not fit the requirements as cost-effectively.
A user reports being unable to access a newly deployed web application via its domain name. An engineer confirms the application is running correctly on its virtual machine and that security groups allow inbound traffic. Pinging the server's public IP address is successful, but attempting to resolve the domain name fails. Which of the following is the MOST likely service to investigate to resolve this issue?
Answer: Domain Name System (DNS)
The problem description states that the domain name fails to resolve, while the server is reachable via its IP address. This is a classic symptom of an issue with the Domain Name System (DNS). The engineer should check the DNS records (e.g., the 'A' record) to ensure the domain name correctly points to the server's public IP address.
When designing a cloud solution, an architect chooses to use different cloud service providers for different services to avoid dependency on a single vendor and to leverage the best-of-breed services from each. For example, they use one provider for IaaS, another for database services, and a third for machine learning capabilities. What is this architectural strategy called?
Answer: Multi-cloud
A multi-cloud strategy involves using multiple cloud computing services from more than one cloud provider in a single heterogeneous architecture. This approach allows organizations to prevent vendor lock-in and select the best services from each provider to fit specific needs, as described in the scenario.
A cloud monitoring system triggers a critical alert indicating a potential DDoS attack against a company's public-facing web application. According to a typical incident response lifecycle, which phase involves actions taken to limit the impact of the attack?
Answer: Containment
The standard incident response lifecycle includes phases like Preparation, Identification/Detection, Containment, Eradication, Recovery, and Post-Incident Activity/Lessons Learned. The Containment phase specifically focuses on actions to isolate the affected systems and limit the scope and magnitude of the incident to prevent further damage.
A financial services company is designing a cloud architecture for a critical trading application. The primary business requirement is that the application must continue to operate without any user-discernible interruption, even if an underlying component fails. Which of the following design principles is MOST critical to meet this requirement?
Answer: Fault tolerance
Fault tolerance is the ability of a system to continue operating without interruption when one or more of its components fail. This is distinct from high availability, which focuses on minimizing downtime but may involve a brief recovery period. For a critical trading application where no interruption is acceptable, fault tolerance is the most crucial design principle.
What is the purpose of cloud monitoring tools?
Answer: To track and report the performance and availability of cloud resources
The purpose of cloud monitoring tools is to continuously track and report the performance, availability, and health of cloud resources, applications, and services. These tools collect metrics, logs, and traces to provide real-time insights into resource utilization, network traffic, and error rates. This enables administrators to proactively identify issues, optimize performance, and ensure the reliability of their cloud environment.