Which of the following container commands implements network port mapping?
A. $docker run –it myimage –e /bin/port 8080
B. $docker run myimage:port
C. $docker run –it –p 1-65535 myimage –e netstat 8080
D. $docker run –it –p 80:8080 myimage
Show Answer
Correct Answer: D
Explanation: Docker uses the -p (or --publish) flag to map a host port to a container port in the form hostPort:containerPort. The command '-p 80:8080' maps host port 80 to port 8080 inside the container. The other options use invalid Docker syntax or misuse unrelated flags such as -e.
Question 90
Which of the following facilitates the continuous deployment of cloud applications without performing a clean install on each iteration?
A. Debian package
B. Version management
C. Container image
D. Bare-metal server
Show Answer
Correct Answer: C
Explanation: Container images package an application together with its runtime and dependencies into an immutable artifact. Continuous deployment pipelines can build and distribute updated images without performing a traditional clean install on each iteration, enabling consistent, repeatable deployments. Debian packages install software onto the host, version management tracks code or dependency versions rather than deployment artifacts, and bare-metal servers are infrastructure rather than a deployment mechanism.
Question 91
A cloud developer resigned from an organization and gave a two-week notice. Within the first week since the developer resigned, a security analyst identifies large volumes of file downloads to the developer’s laptop from the source code repository. Which of the following security controls would be the best way to mitigate the organization’s risk of data loss?
A. Implementing a policy to stop cloud developers from sharing passwords
B. Preventing cloud developers from accessing the source code repository
C. Updating outbound firewall rules to block the cloud developer’s IP address
D. Blocking internet access for employees that resign from the organization
E. Prohibiting files on the local drive from being transferred to USB drives
Show Answer
Correct Answer: B
Explanation: The highest-risk asset is the source code repository. Once suspicious bulk downloads are detected during an employee's notice period, the most effective mitigation is to revoke or prevent that individual's access to the repository, following least-privilege and offboarding practices. Blocking an IP address or internet access is less reliable and may be bypassed or disrupt unrelated activity, while the other options do not address the observed exfiltration risk.
Sources:
https://www.marks4sure.com/cv0-004-comptia-cloudp-questions.html
Question 92
A cloud solutions architect wants to deploy a three-tier web application that requires the minimum amount of operational overhead. Which of the following is the best template given these requirements?
A.
B.
C.
D.
Show Answer
Correct Answer: B
Explanation: For a three-tier web application with the minimum operational overhead, the best architecture is one that uses fully managed services: static object storage for the presentation tier, serverless functions for the application tier, and a managed relational database for the data tier. This minimizes server administration, patching, scaling, and infrastructure management.
Question 93
Which of the following protocols is often used in IoT to reduce the amount of data exchanged?
A. MQTT
B. SMB
C. NFS
D. HTTPS
Show Answer
Correct Answer: A
Explanation: MQTT is a lightweight publish/subscribe messaging protocol designed for constrained devices and low-bandwidth, high-latency, or unreliable networks. Its compact protocol overhead helps reduce the amount of data exchanged in IoT. SMB and NFS are file-sharing protocols, and HTTPS has higher overhead than MQTT for typical IoT messaging.
Question 94
A healthcare provider contacts a MSP about moving an on-premises infrastructure to the cloud. Which of the following requirements are most important for the MSP to consider when migrating this customer? (Choose two.)
A. Security
B. Cost
C. Availability
D. Storage
E. Compliance
F. Compute
Show Answer
Correct Answer: A, E
Explanation: For a healthcare provider, protecting sensitive patient information and meeting healthcare regulations are the highest-priority considerations during cloud migration. Security is essential for safeguarding data through controls such as encryption and access management, while compliance is critical to satisfy regulatory requirements (such as HIPAA or similar healthcare regulations). Cost, storage, compute, and availability are important design considerations but are not as uniquely critical as security and compliance in this scenario.
Question 95
A cloud administrator recently created three servers in the cloud. The goal was to create ACLs so the servers could not communicate with each other. The servers were configured with the following IP addresses:
After implementing the ACLs, the administrator confirmed that some servers are still able to reach the other servers. Which of the following should the administrator change to prevent the servers from being on the same network?
A. The IP address of Server 1 to 172.16.12.36
B. The IP address of Server 1 to 172.16.12.2
C. The IP address of Server 2 to 172.16.12.18
D. The IP address of Server 2 to 172.16.14.14
Show Answer
Correct Answer: C
Explanation: With a /28 subnet, each subnet spans 16 addresses. Changing Server 2 from an address that overlaps another server's subnet to 172.16.12.18 moves it into the 172.16.12.16/28 subnet, separating it from the conflicting network while staying within the same overall addressing scheme. The other options either remain in the same subnet or introduce a different network without sufficient context.
Question 96
A bank was recently hacked. The bank reviews the logs to see how the attack occurred. The security administrator suspects the logs were manipulated because no traces of the attack can be found in them. Which of the following should have been enabled before the attack occurred?
A. Metric and alerts
B. Tracing and aggregation
C. Dashboard and reporting
D. Versioning and immutability
Show Answer
Correct Answer: D
Explanation: If logs may have been manipulated, the missing control is immutable, versioned log storage. Immutability prevents alteration or deletion of log records, and versioning preserves prior states, making forensic evidence reliable even after an attacker gains access. Metrics, tracing, dashboards, and reporting improve visibility but do not protect log integrity.
Question 97
A customer is migrating applications to the cloud and wants to grant authorization using the classification levels of each system. Which of the following should the customer implement to ensure authorization to systems is granted when the user and system classification properties match? (Choose two.)
A. Resource tagging
B. Single sign-on
C. Multifactor authentication
D. Attribute-based access control
E. Token-based authentication
F. Bastion host
Show Answer
Correct Answer: A, D
Explanation: Attribute-based access control (ABAC) authorizes access based on attributes of the user and resource, such as matching classification levels. Resource tagging provides the resource attributes (for example, classification labels) that ABAC policies evaluate. Single sign-on, multifactor authentication, token-based authentication, and bastion hosts address authentication or access pathways rather than authorization based on matching classification attributes.
Question 98
A developer is building a tool on the cloud that needs to allow other developers to programmatically read and write to the web application resources. Which of the following should the developer do to meet these requirements with the least complexity?
A. Build a REST API endpoint.
B. Allow access via the cloud portal.
C. Provision cloud-based SQL access.
D. Implement RPC on the web application.
Show Answer
Correct Answer: A
Explanation: A REST API endpoint is the standard, low-complexity way to expose web application resources for programmatic read/write access over HTTP. It is language-agnostic, widely supported, and designed for external developer integration. A cloud portal is intended for human interaction, SQL access exposes the database rather than application resources, and RPC is generally more tightly coupled and less interoperable than REST for this use case.
$19
Get all 182 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.