CompTIA CloudNetX Practice Test 1

CompTIA CloudNetX Practice Exam

1 / 90

Which approach provides the fastest recovery time objective (RTO) for a mission-critical cloud application?

2 / 90

An organization is transitioning to a Zero Trust security model in its cloud infrastructure. What is the most critical component?

3 / 90

Which strategy is most effective for optimizing cloud networking costs without sacrificing performance?

4 / 90

An enterprise is using cloud-based object storage for critical backups. What method ensures the integrity of stored data?

5 / 90

A cloud provider wants to optimize data traffic flow between different availability zones while minimizing latency. What is the best strategy?

6 / 90

What is a key advantage of employing behavior-based threat detection systems in a cloud environment?

7 / 90

Which security measure is considered a cloud-native control?

8 / 90

Which approach best ensures both scalability and redundancy in a cloud network design?

9 / 90

What is the primary benefit of implementing network segmentation within a cloud environment?

10 / 90

An organization is designing a hybrid cloud network to ensure high availability and fault tolerance. Which strategy best achieves this goal?

11 / 90

A development team wants to test an entirely new environment configuration alongside the existing production environment without interfering with it. What environment strategy should they use?

12 / 90

A cloud operations team needs real-time visibility into resource metrics, such as CPU saturation and disk IO, across thousands of nodes. What should they use?

13 / 90

A data processing pipeline must guarantee that once a job begins, it cannot be run again concurrently. What mechanism supports this?

14 / 90

A microservices workload experiences high latency due to services repeatedly fetching the same reference data. What is the best optimization?

15 / 90

A global e-commerce platform needs to ensure that authentication requests go to the closest available region for lowest latency. What solution provides this?

16 / 90

A compliance officer requires proof that certain cloud data has not been modified for ten years. What technology ensures immutability?

17 / 90

A company wants to allow external partners to publish messages into its event stream without granting internal permissions. What should be implemented?

18 / 90

An application performs heavy CPU-bound calculations and requires long-running tasks without interruption. Which compute option is ideal?

19 / 90

A financial auditing service must verify all configuration changes across the environment. What solution best satisfies this?

20 / 90

A developer needs to ensure that a serverless function triggers only when a set of required events completes, not on each individual event. What cloud pattern supports this?

21 / 90

A workload generates 10 TB/day of logs. Costs are increasing due to retained logs in hot storage, but the logs must be searchable for 90 days. What solution is most cost-efficient?

22 / 90

An organization wants to prevent overprivileged accounts and enforce least privilege automatically. Which approach accomplishes this?

23 / 90

A multi-cloud architecture needs unified access control, so administrators can manage permissions across all cloud providers in one place. What solution should be used?

24 / 90

A business requires automatic detection of unusual data flows, such as sudden spikes to unknown IP ranges. What technology supports this requirement?

25 / 90

A distributed application must ensure that writes made to one node are propagated to all other nodes with minimal delay but does NOT require strict locking. Which consistency model is best?

26 / 90

A security team requires that VM images undergo malware scanning before being allowed into the production environment. What should they implement?

27 / 90

An application relies on a high-throughput stream ingestion service. The engineer wants to ensure that consumer processes can pick up exactly where they left off after restarts. What feature ensures this?

28 / 90

A company wants to ensure that infrastructure changes are always tracked and reversible. What should they implement?

29 / 90

A machine learning pipeline requires fast retrieval of training data stored in structured format with SQL-like querying capabilities. Which storage architecture is most appropriate?

30 / 90

A cloud architect needs to ensure that a newly deployed cluster of microservices can automatically discover each other without hardcoding IP addresses. Which technology should be implemented?

31 / 90

You must ensure every deployed container image can be traced back to the exact source commit and build input. What should the pipeline produce?

32 / 90

A cluster needs patching with zero downtime. Which approach fits?

33 / 90

A large CI/CD pipeline requires that container images are reproducible and traceable to each build and code commit. What practice ensures this?

34 / 90

Your organization wants to detect zero-day attacks and unusual behaviors across cloud infrastructure using adaptive models rather than static rules. Which capability should you add?

35 / 90

A Kubernetes environment requires policies that ensure containers do not run as root and must use read-only filesystem mounts where applicable. Where should these controls be enforced centrally?

36 / 90

A security control requires that even if a cloud provider is compromised, tenant data keys must remain secret to the tenant. Which key-management model enforces this strongest separation?

37 / 90

A streaming analytics pipeline needs to handle backpressure when downstream consumers lag while preventing unbounded memory growth on producers. Which mechanism is appropriate?

38 / 90

A DevOps team must ensure every infrastructure change is reviewed before applying to production. What pipeline feature enforces that policy automatically?

39 / 90

A cloud architect wants to minimize inter-region read latency for global users while ensuring each region’s dataset can be updated independently for local compliance. Which pattern balances latency and regional control?

40 / 90

An application must allow users to upload large media files directly to cloud object storage from clients without exposing storage credentials. What pattern secures this flow?

41 / 90

An enterprise architect is designing a multi-cloud strategy and wants to avoid being locked into any single provider's proprietary services. Which design approach best supports this goal?

42 / 90

An organization needs private, low-latency, high-bandwidth connectivity between its on-premises data center and a public cloud provider, avoiding the public internet entirely. Which connectivity option best meets this requirement?

43 / 90

Which architecture pattern allows independent, loosely coupled services to communicate over well-defined APIs, enabling teams to develop, deploy, and scale each service independently?

44 / 90

Which network design pattern uses a central hub network connected to multiple isolated spoke networks, commonly used to centralize shared services like a firewall or VPN gateway in a multi-VPC or multi-VNet environment?

45 / 90

Which subnetting notation would represent a network that has been divided to support exactly 510 usable host addresses per subnet?

46 / 90

Which architecture design consideration ensures that a critical service can continue operating, potentially with reduced functionality, even if a dependent component fails?

47 / 90

Which content delivery approach caches content at geographically distributed edge locations closer to end users, reducing latency for accessing frequently requested static content?

48 / 90

Which wireless technology is best suited for short-range, low-power proximity-based services, such as indoor location tracking and asset tracking beacons?

49 / 90

Which serverless computing model allows code to execute in response to specific events, such as an HTTP request or a file upload, without the customer provisioning or managing any underlying servers?

50 / 90

Which architecture design goal is achieved by deploying identical application instances across multiple independent data centers or cloud regions, so a regional outage does not take down the entire service?

51 / 90

An architect designing inter-cloud connectivity for a multi-cloud environment needs workloads in AWS to securely communicate with workloads in Azure without traversing the public internet. Which general approach addresses this need?

52 / 90

Which data synchronization approach for a multi-cloud database deployment allows writes to occur in multiple regions or clouds simultaneously, with conflict resolution logic handling any simultaneous updates to the same record?

53 / 90

Which governance approach ensures that consistent security and compliance policies are automatically enforced across resources deployed in multiple different cloud providers within a multi-cloud environment?

54 / 90

Which architecture consideration determines how a design accounts for handling significantly increased load in the future without requiring a complete redesign?

55 / 90

Which network architecture pattern eliminates a traditional hardware-based network core in favor of software-defined, centrally controlled forwarding logic across the underlying physical fabric?

56 / 90

Which authentication protocol, commonly paired with 802.1X, sends authentication requests to a centralized server and is widely used for network access control at the switch port or wireless access point level?

57 / 90

Which authentication protocol is specifically designed for authenticating administrators for device management (such as CLI access to a router), offering granular command-level authorization not found in RADIUS?

58 / 90

Which Zero Trust architecture principle requires that every access request be authenticated and authorized based on all available context, such as user identity, device health, and location, regardless of whether the request originates from inside or outside the traditional network perimeter?

59 / 90

Which network segmentation approach divides a network into small, tightly controlled zones at the workload level, limiting lateral movement even if an attacker compromises one specific workload?

60 / 90

Which secure DNS protocol encrypts DNS queries using TLS, encapsulated within the standard DNS transport, to prevent eavesdropping on DNS lookups?

61 / 90

Which DNS security extension provides cryptographic signatures for DNS records, allowing a resolver to verify that a DNS response has not been tampered with and genuinely originated from the authoritative source?

62 / 90

Which cloud identity and access management practice grants users only the specific permissions required for their role, following the principle of least privilege in a multi-cloud environment?

63 / 90

Which secure access model replaces traditional perimeter-based VPN access with identity-aware, application-specific access, granting users connectivity only to the specific applications they are authorized for, rather than the entire network?

64 / 90

Which cloud-delivered security architecture converges SD-WAN networking with cloud-based security functions, such as secure web gateway and ZTNA, into a single, unified service delivered from the cloud?

65 / 90

Which cloud security tool continuously scans multi-cloud resource configurations against security benchmarks, automatically flagging misconfigurations such as an overly permissive storage bucket policy?

66 / 90

Which encryption key management approach allows an organization to generate and control their own encryption keys, storing them independently of the cloud provider, while the provider still performs the actual encryption operations?

67 / 90

Which network security control inspects encrypted traffic by decrypting, inspecting, and re-encrypting it at a security gateway, allowing deep packet inspection of otherwise opaque TLS traffic?

68 / 90

Which security concept for a hybrid or multi-cloud identity architecture allows a user authenticated in one identity domain, such as on-premises Active Directory, to seamlessly access resources in a separate cloud identity domain without a separate login?

69 / 90

Which type of network security device inspects traffic at multiple layers, incorporating capabilities such as application awareness, intrusion prevention, and TLS inspection into a single unified platform, beyond traditional stateful packet filtering?

70 / 90

Which automation practice defines network device configurations in machine-readable files, enabling consistent, version-controlled, and repeatable provisioning across an enterprise network?

71 / 90

Which network monitoring technology allows an administrator to collect and analyze summarized traffic flow data, such as source/destination pairs and byte counts, across a large enterprise network without capturing full packet payloads?

72 / 90

Which scripting-driven network automation practice uses tools like Python with libraries such as Netmiko or NAPALM to programmatically configure and retrieve information from multi-vendor network devices?

73 / 90

Which performance monitoring metric measures the round-trip time it takes for a packet to travel from a source to a destination and back, directly impacting the perceived responsiveness of real-time applications?

74 / 90

Which performance monitoring metric measures the variation in latency between consecutive packets, which can significantly degrade the quality of real-time voice or video applications if too high?

75 / 90

Which centralized logging protocol allows network and cloud infrastructure devices to send event and diagnostic messages to a remote server for aggregation and long-term retention?

76 / 90

Which capacity planning practice reviews current utilization trends against historical data to proactively forecast when additional network bandwidth or compute resources will be needed?

77 / 90

Which network management protocol allows a centralized system to query devices for status information and also receive unsolicited alerts, called traps, when a significant event occurs, such as an interface going down?

78 / 90

Users in one region report they cannot reach an application hosted in a different cloud region, while users in that same remote region have no issues. Which troubleshooting step would most directly help isolate whether the issue is regional network path related?

79 / 90

A hybrid cloud connection over a dedicated direct connection service is experiencing intermittent packet loss. Which troubleshooting step would help determine whether the issue lies within the customer's on-premises network versus the provider's connectivity service?

80 / 90

A network engineer suspects a routing loop is occurring between two routers running a distance-vector protocol after a recent link failure. Which loop-prevention mechanism, if not properly functioning, is most likely to explain this specific symptom?

81 / 90

An application intermittently fails to resolve an internal, private DNS name that is hosted in a hybrid environment split between on-premises and cloud DNS servers. Which troubleshooting step would most directly help isolate the cause?

82 / 90

A microsegmented environment is blocking legitimate traffic between two workloads that were recently migrated to a new subnet. Which troubleshooting step is most directly appropriate?

83 / 90

A load balancer is intermittently marking healthy backend instances as unhealthy and removing them from rotation. Which troubleshooting step would most directly help diagnose this specific issue?

84 / 90

A site-to-site VPN tunnel between an on-premises data center and a cloud VPC repeatedly drops and re-establishes. Which troubleshooting area should be investigated first?

85 / 90

An organization's DNSSEC-signed zone suddenly starts failing validation for external resolvers, causing widespread resolution failures for that domain. Which cause is most likely?

86 / 90

A network engineer is troubleshooting asymmetric routing, where outbound traffic takes a different path than the corresponding return traffic, causing a stateful firewall to drop the return packets. Which general remediation approach addresses this issue?

87 / 90

A newly deployed cloud workload cannot reach the internet despite having a public IP address assigned. Which component is most likely missing or misconfigured?

88 / 90

A newly provisioned virtual machine cannot obtain an IP address via DHCP in a segmented cloud network. Which configuration is most likely preventing this?

89 / 90

A hybrid cloud environment experiences degraded application performance specifically during business hours, correlating with increased WAN utilization. Which remediation approach most directly addresses this specific pattern?

90 / 90

A network administrator notices that traffic between two specific microservices in a Kubernetes cluster is being unexpectedly blocked after a recent policy update. Which Kubernetes-native construct is most likely responsible and should be reviewed first?

Your score is

The average score is 75%

0%