Networking and Connectivity Flashcards
7 cards from real CompTIA Cloud+ practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Networking and Connectivity flashcards as text
A cloud administrator notices high latency for users accessing an application from a specific geographic region. What is the FIRST step to diagnose this issue?
Answer: Use network monitoring and tracing tools to identify where in the path the bottleneck occurs
The first step in troubleshooting latency is to use monitoring and path-tracing tools to pinpoint the location of the bottleneck before taking any remediation action.
Which cloud networking component evaluates rules in ascending numerical order to control traffic at the subnet boundary?
Answer: Network ACL
Network ACLs (NACLs) evaluate rules in ascending numerical order and apply the first matching rule, operating as a stateless firewall at the subnet level.
What information is contained in a cloud VPC route table entry?
Answer: Destination CIDR blocks and their corresponding next-hop targets
Route table entries consist of a destination CIDR block and a target (such as an internet gateway, NAT gateway, or peering connection) that specifies where matching traffic should be sent.
A company experiences intermittent connectivity between their on-premises network and a cloud VPC. The VPN tunnel status shows as active. What should the engineer check NEXT?
Answer: Verify BGP routing tables and route propagation settings on both ends
An active tunnel status confirms the VPN is up, but intermittent connectivity often indicates routing issues — verifying BGP tables and route propagation is the correct next diagnostic step.
Which metric is MOST important to monitor for evaluating the health and performance of a cloud load balancer?
Answer: Target response time and request error rate
Target response time and request error rate directly reflect whether the load balancer is distributing traffic effectively and whether backend targets are responding correctly to users.
A cloud security team needs to capture all network traffic metadata flowing through a VPC for compliance auditing WITHOUT impacting production performance. Which solution is BEST?
Answer: Enable VPC Flow Logs to capture IP traffic metadata
VPC Flow Logs capture metadata (source/destination IPs, ports, protocol, allow/deny action) without adding latency or impacting throughput, satisfying compliance traffic-monitoring requirements.
A cloud engineer is troubleshooting why instances in a private subnet cannot reach the internet even though a NAT Gateway exists in the public subnet. What is the MOST likely cause?
Answer: The private subnet route table lacks a route pointing 0.0.0.0/0 to the NAT Gateway
Even with a NAT Gateway deployed, private subnet instances cannot reach the internet unless the private subnet's route table has a 0.0.0.0/0 route pointing to the NAT Gateway.