CV0-004 Sample Questions & Answers
Virtualization, containerization and the underlying cloud service and deployment models carry the heaviest weight, alongside identity and data security, scaling and observability, infrastructure-as-code migration, and CI/CD practices.
Launch the full CV0-004 simulator →Showing 10 of 20 free samples.
- Question 1Intermediate
Which of the following is a difference between a SAN and a NAS?
Show answer & explanation
Correct answer: D
- Question 2Intermediate
A cloud engineer is troubleshooting an application that consumes multiple third-party REST APIs. The application is randomly experiencing high latency. Which of the following would best help determine the source of the latency?
Show answer & explanation
Correct answer: D
- Question 3Intermediate
A cloud engineer is reviewing the following Dockerfile to deploy a Python web application:Which of the following changes should the engineer make to the file to improve container security? A.Add the instruction USER nonroot.B.Change the version from latest to 3.11.C.Remove the ENTRYPOINT instruction.D.Ensure myapp/main/py is owned by root.

Show answer & explanation
Correct answer: A
- Question 4Advanced
DevOps Fundamentals · Implement CI/CD
A financial services company is deploying a new containerized application to an Amazon EKS cluster. A recent security audit mandates that all container images must be scanned for vulnerabilities before being admitted to the cluster, and deployments with 'CRITICAL' severity vulnerabilities must be blocked. Which combination of tools and configurations BEST enforces this policy in an automated fashion?
Show answer & explanation
Correct answer: B
This is the most comprehensive and automated solution. The CI/CD pipeline integration with Trivy provides 'shift-left' security by catching vulnerabilities early. The validating admission webhook with OPA acts as a final gatekeeper, enforcing the policy at the cluster level before any pod is created. This combination ensures that no container with critical vulnerabilities can run, regardless of how it was deployed, providing a robust defense-in-depth security posture.
- Question 5Intermediate
Operations · Configure observability
A lead SRE is designing a monitoring strategy for a distributed application that spans multiple geographic regions and cloud providers. The primary goal is to gain deep insights into request flows and pinpoint performance bottlenecks across service boundaries. Which observability practice is MOST critical to achieving this goal?
Show answer & explanation
Correct answer: C
Distributed tracing is specifically designed to track the entire lifecycle of a request as it travels through a distributed system. By instrumenting applications with a framework like OpenTelemetry, each request is assigned a unique trace ID, and each service call generates a span. This allows SREs to visualize the full request path, identify which service calls are contributing the most latency, and diagnose errors that occur deep within the call stack. While logging and metrics are crucial parts of observability, only distributed tracing provides the end-to-end visibility needed to effectively troubleshoot performance in a complex, multi-service environment.
- Question 6Intermediate
Operations · Manage backups and recovery
A cloud administrator is tasked with implementing a cost-effective backup solution for a 10TB file server hosted on an EC2 instance. The recovery time objective (RTO) is 8 hours, and the recovery point objective (RPO) is 24 hours. Data must be retained for 7 years for compliance. Which AWS service combination meets these requirements MOST efficiently?
Show answer & explanation
Correct answer: A
This solution is the most cost-effective and operationally efficient. AWS Backup provides a centralized, automated way to manage backups across AWS services, meeting the 24-hour RPO with daily snapshots. EBS Snapshots allow for recovery within the 8-hour RTO. Transitioning the snapshots to S3 Glacier Deep Archive, the lowest-cost storage class, after a short period satisfies the 7-year retention requirement in the most economical way.
- Question 7AdvancedSelect 2
Security · Implement IAM
A security architect is designing an authentication and authorization system for a multi-cloud environment consisting of AWS and Azure. The requirements are to use the company's on-premises Active Directory as the single source of truth for user identities and to enforce role-based access control (RBAC) consistently across both cloud platforms. Which TWO of the following should be implemented? (Select TWO)
Show answer & explanation
Correct answers: B, C
SAML 2.0 federation is the standard protocol for enabling single sign-on (SSO) and passing authentication information from a central identity provider (like AD FS) to service providers (like AWS and Azure). This allows users to authenticate once against their on-premises Active Directory and gain access to resources in both clouds without separate credentials.
After establishing federation, the next step is to implement RBAC. This is done by creating roles in each cloud provider that define specific permissions. These roles are then mapped to security groups in the on-premises Active Directory. When a user authenticates, their group memberships are passed in the SAML assertion, allowing them to assume the corresponding role and its permissions in AWS or Azure.
- Question 8Advanced
Deployment · Implement Infrastructure as Code
A developer is writing a Terraform configuration to provision an S3 bucket for storing sensitive logs. The company policy requires that all data written to the bucket must be encrypted. The developer has included a server-side encryption configuration block. However, they need to ensure that any
PutObjectrequests without encryption headers are explicitly denied. Which addition to the S3 bucket policy is required?Show answer & explanation
Correct answer: B
The most secure way to enforce encryption on upload is to explicitly deny any
s3:PutObjectaction if the encryption header is missing. A bucket policy with"Effect": "Deny"and a condition checking if"Null": {"s3:x-amz-server-side-encryption": "true"}will reject any upload attempt that does not specify server-side encryption. This ensures that unencrypted objects can never be written to the bucket, providing a stronger guarantee than just setting a default encryption configuration. - Question 9Intermediate
Deployment · Deployment Automation
During a post-incident review of a service outage, an SRE team determined that a recent deployment introduced a critical bug. The CI/CD pipeline successfully passed all unit and integration tests, but the issue only manifested under production load. The team wants to implement a deployment strategy that would allow them to safely test new code on a small percentage of live traffic before a full rollout. Which strategy should they adopt?
Show answer & explanation
Correct answer: D
A canary deployment is specifically designed for this scenario. It involves rolling out the new version of the application to a small subset of users or servers (the 'canary'). This allows the team to monitor its performance and error rates under real production traffic. If the new version performs well, traffic is gradually shifted until all users are on the new version. If issues are detected, traffic can be quickly routed back to the stable version, minimizing the impact of the bug.
- Question 10Beginner
Cloud Architecture · Design for service availability
A cloud architect is designing a highly available and fault-tolerant web application on AWS. The application will be deployed across multiple Availability Zones. Which of the following AWS services should be placed in front of the web server fleet to distribute incoming traffic and perform health checks?
Show answer & explanation
Correct answer: D
An Application Load Balancer (ALB) is the correct service for this purpose. It is designed to operate at the application layer (Layer 7) and can distribute HTTP/HTTPS traffic across multiple targets, such as EC2 instances, in multiple Availability Zones. Crucially, it performs health checks on the targets and automatically routes traffic only to healthy instances, which is essential for building a highly available and fault-tolerant system.
Ready for the real thing?
The full CV0-004 simulator has every exam-style question, timed mode, and instant scoring.