dc dotCreds
CompTIA Cloud+ Practice Test

CompTIA Cloud+ Practice Test

Start today’s free 10-question CompTIA Cloud+ set with source-backed explanations, local progress, and a fresh rotation every morning.

10 Free Daily Questions Source-backed Explanations 200 Verified Questions

Questions updated at Aug 17, 2026, 11:07 AM CDT

Go Pro - One Time Unlock

Unlock the full CV0-004 bank

200 verified questions Exam Mode Practice Mode Detailed explanations Weak-area review No subscription - one-time unlock

Get the complete source-backed bank with Interview Questions, the full Study Guide, full Course Notes, detailed explanations, weak-area review, and exam-style practice.

Interview Questions Full Study Guide Full Course Notes Exam Mode Practice Mode Guided Course Detailed explanations Weak-area review No subscription
$4.99 One-time payment
See bundle and PDF options

We will confirm your site email in one quick checkout step.

Why DotCreds?

Practice with explanations that teach.

Source links for every answer Every wrong answer explained Guided Course included Practice and Exam Mode Weak-area tracking Same verified bank across web practice

What you get with free practice

10 Free Questions Daily Fresh set every day from the live bank
Detailed Explanations Learn with clear source-backed answers
Track Your Progress Daily history and performance insights
Upgrade Anytime Unlock the full bank when you are ready
Today's 10 CompTIA Cloud+ questions

Use this CompTIA Cloud+ practice test to review CompTIA Cloud+. Questions rotate daily and each answer links back to the source used to write it.

Today’s Set
10 questions
Rotates at 10:00 AM local time
Progress
0/10
Answered on this page
Accuracy
0%
Loading countdown…

200 verified questions are in the live bank. Free daily questions are selected from a rotating sample set. Unlock Pro to access the full question bank.

Preparing today’s free questions... Ordering the final locked-bank set before showing the practice cards.
Question 1 of 10
Objective 4.6 Given a scenario, monitor suspicious activities to identify common attacks. 4. Security (19%)

A compromised web application attempts repeated requests to the cloud instance metadata endpoint to retrieve temporary role credentials. Which cloud-specific attack path is MOST directly indicated?

Concept tested:
Question 2 of 10
Objective 3.4 Given a scenario, manage the life cycle of cloud resources. 3. Operations (17%)

A database engine is moving from version 12 to version 13 and the vendor documents breaking changes that require application testing. Which lifecycle category BEST describes the change?

Concept tested:
Question 3 of 10
Objective 3.2 Given a scenario, configure appropriate scaling approaches. 3. Operations (17%)

An online retailer has a predictable traffic surge every Friday from 6 p.m. to 9 p.m. and wants capacity added before the surge starts. Which approach is BEST?

Concept tested:
Question 4 of 10
Objective 5.1 Explain source control concepts. 5. DevOps Fundamentals (10%)

Two approved feature branches now need to be combined into the release branch. Which source-control operation is required?

Concept tested:
Question 5 of 10
Objective 6.1 Given a scenario, troubleshoot deployment issues. 6. Troubleshooting (12%)

A deployment requests 250 instances, but the account is allowed only 200 in that region. Which issue must be addressed?

Concept tested:
Question 6 of 10
Objective 1.6 Compare and contrast containerization concepts. 1. Cloud Architecture (23%)

A company is moving from a few manually launched containers to hundreds of replicas that need automated placement, scaling, and recovery. Which capability is MOST appropriate?

Concept tested:
Question 7 of 10
Objective 2.1 Compare and contrast cloud deployment models. 2. Deployment (19%)

A startup wants elastic infrastructure from a provider's shared platform and has no requirement for exclusive infrastructure ownership. Which deployment model BEST fits?

Concept tested:
Question 8 of 10
Objective 5.2 Explain concepts related to continuous integration/continuous deployment (CI/CD) pipelines. 5. DevOps Fundamentals (10%)

A container image with a critical vulnerability must never be promoted to production. Which pipeline control BEST enforces the requirement?

Concept tested:
Question 9 of 10
Objective 4.4 Given a scenario, apply security best practices. 4. Security (19%)

An application sends credentials from a client to an API across an untrusted network. Which control MOST directly protects the data on the wire?

Concept tested:
Question 10 of 10
Objective 6.2 Given a scenario, troubleshoot network issues. 6. Troubleshooting (12%)

Users can reach a web server by IP address but not by its hostname. Which service should be investigated FIRST?

Concept tested:
Locked preview

You are viewing today’s free 10. Unlock 190 more questions.

Unlock full bank
Daily sample Rotating practice Free daily questions are selected from a rotating sample set.
Pro bank Full access Unlock Pro to access the full question bank, Exam Mode, Practice Mode, and random tests.
CV0-004 Pro $4.99 one-time

Unlock all 200 CompTIA Cloud+ questions, explanations, review tools, and exam-style practice.

50 Exam Practice Test $1.99 one-time

A 50-question CV0-004 PDF for short review sessions. Questions come first, then the answer review and explanations later in the file.

Linux / DevOps Access Bundle $6.99/month

Linux systems, Kubernetes, Terraform, data platform, and TensorFlow practice in one monthly unlock.

What’s includedCompTIA Linux+, CompTIA Cloud+, LFCS, CKA, Terraform Associate, Databricks ML Associate, TensorFlow Developer

Choose an unlock option to continue. We will confirm your site email in one quick checkout step.

Secure checkout powered by Stripe. Source-backed questions. Not brain dumps. Checkout stays on this page and unlocks the same Pro builder on this practice page.

Purchase options

Unlock the full CV0-004 bank.

Get the full bank, Exam Mode, Practice Mode, question sets, random tests, readiness tracking, saved box scores, and review tools for this exam.

The PDF versions keep questions first and move the answer review, explanations, and distractor notes to the back of the file.

200 verified exam-style questions Every choice explained Exam Mode and Practice Mode Question sets and random tests Readiness score and trends Previous test box scores

You've answered 0/10 questions in today's set.

Locked: 190 more questions in the full bank.

Locked: exam simulation mode, practice mode, readiness tracking, and saved review history.

Checkout stays on this page, so you can keep practicing, unlock the full bank, and start Exam Mode or Practice Mode when you are ready.

Cheat Sheets

7-day score keeper

Answer questions today and this will become a rolling 7-day scorecard.

Local history
Optional progress sync

Keep today’s practice moving

Guest progress saves automatically on this device. Add an email later when you want a magic link that keeps your daily CV0-004 practice in sync across browsers.

Guest progress saves on this device automatically

Guest progress is available without an account.

Source-backed answer review

The free daily CompTIA Cloud+ set includes crawlable question text, answer choices, correct answer labels, objective mapping, and source links. Only the first SEO card includes answer explanations and any extra learning features. Pro-only bank questions stay locked; this section mirrors only the 10 free daily questions already shown on this page.

Question 1 A compromised web application attempts repeated requests to the cloud instance metadata endpoint to retrieve temporary role credentials. Which cloud-specific attack path is MOST directly indicated?

Answer choices

  1. A. Ransomware
  2. B. Baseline deviation
  3. C. Phishing
  4. D. Metadata abuse

Correct answer

Metadata abuse

Metadata abuse is correct. Cloud instance metadata services can expose temporary credentials to the instance; restricting and hardening metadata access reduces abuse from compromised workloads. Metadata abuse targets cloud instance metadata services to obtain credentials or configuration information.

Wrong-answer review

  • A. Ransomware: Ransomware encrypts or otherwise denies access to data or systems to extort payment. It is a plausible concept from the objective, but it does not satisfy the scenario's decisive requirement; Metadata abuse does.
  • B. Baseline deviation: A baseline deviation is behavior that differs materially from established normal activity and may warrant investigation. It is a plausible concept from the objective, but it does not satisfy the scenario's decisive requirement; Metadata abuse does.
  • C. Phishing: Phishing uses deceptive messages or sites to induce users to reveal information or execute malicious actions. It is a plausible concept from the objective, but it does not satisfy the scenario's decisive requirement; Metadata abuse does.

Extra learning features

Why candidates miss this

The temptation to select 'Ransomware' stems from the scenario's description of malicious activity. However, ransomware's core function is extortion, not the specific mechanism of metadata abuse. The decisive clue is the explicit mention of metadata services, highlighting the vulnerability exploited. Likely wrong answer: Ransomware Review focus: Amazon EC2 Instance Metadata Service

Objective/domain: 4. Security (19%)

Source: Amazon EC2 Instance Metadata Service

Question 2 A database engine is moving from version 12 to version 13 and the vendor documents breaking changes that require application testing. Which lifecycle category BEST describes the change?

Answer choices

  1. A. End of support
  2. B. Patching
  3. C. Major update
  4. D. Minor update

Correct answer

Major update

Objective/domain: 3. Operations (17%)

Source: NIST SP 800-40 Rev. 4: Enterprise Patch Management Planning

Question 3 An online retailer has a predictable traffic surge every Friday from 6 p.m. to 9 p.m. and wants capacity added before the surge starts. Which approach is BEST?

Answer choices

  1. A. Manual scaling
  2. B. Vertical scaling
  3. C. Scheduled scaling
  4. D. Load-triggered scaling

Correct answer

Scheduled scaling

Objective/domain: 3. Operations (17%)

Source: Microsoft Azure Well-Architected Framework: Reliable scaling strategy

Question 4 Two approved feature branches now need to be combined into the release branch. Which source-control operation is required?

Answer choices

  1. A. Push
  2. B. Merge
  3. C. Commit
  4. D. Branch

Correct answer

Merge

Objective/domain: 5. DevOps Fundamentals (10%)

Source: Git Documentation

Question 5 A deployment requests 250 instances, but the account is allowed only 200 in that region. Which issue must be addressed?

Answer choices

  1. A. Permission issue
  2. B. Service quota
  3. C. Partial outage
  4. D. API throttling

Correct answer

Service quota

Objective/domain: 6. Troubleshooting (12%)

Source: AWS Service Quotas User Guide

Question 6 A company is moving from a few manually launched containers to hundreds of replicas that need automated placement, scaling, and recovery. Which capability is MOST appropriate?

Answer choices

  1. A. Workload orchestration
  2. B. Port mapping
  3. C. Stand-alone container
  4. D. Image registry

Correct answer

Workload orchestration

Objective/domain: 1. Cloud Architecture (23%)

Source: Kubernetes Documentation: Workloads

Question 7 A startup wants elastic infrastructure from a provider's shared platform and has no requirement for exclusive infrastructure ownership. Which deployment model BEST fits?

Answer choices

  1. A. Public cloud
  2. B. Hybrid cloud
  3. C. Private cloud
  4. D. Community cloud

Correct answer

Public cloud

Objective/domain: 2. Deployment (19%)

Source: NIST SP 800-145: The NIST Definition of Cloud Computing

Question 8 A container image with a critical vulnerability must never be promoted to production. Which pipeline control BEST enforces the requirement?

Answer choices

  1. A. Workflow
  2. B. Security gate
  3. C. Artifact
  4. D. Automated build

Correct answer

Security gate

Objective/domain: 5. DevOps Fundamentals (10%)

Source: GitHub Docs: Understanding GitHub Actions

Question 9 An application sends credentials from a client to an API across an untrusted network. Which control MOST directly protects the data on the wire?

Answer choices

  1. A. CIS benchmark
  2. B. Encryption in transit
  3. C. Unprivileged container
  4. D. Encryption at rest

Correct answer

Encryption in transit

Objective/domain: 4. Security (19%)

Source: NIST SP 800-53 Rev. 5: Security and Privacy Controls

Question 10 Users can reach a web server by IP address but not by its hostname. Which service should be investigated FIRST?

Answer choices

  1. A. NAT
  2. B. DNS
  3. C. NTP
  4. D. DHCP

Correct answer

DNS

Objective/domain: 6. Troubleshooting (12%)

Source: RFC 1034: Domain Names - Concepts and Facilities

Where to go after the daily web set

How are CompTIA Cloud+ questions generated?

dotCreds builds CompTIA Cloud+ practice questions from public exam objectives and CompTIA exam objectives and source-backed references. The questions are written for realistic study practice, not copied from exam dumps.

How are explanations sourced?

Each question includes an explanation and, when available, a source link back to the provider documentation or reference used to validate the answer. That keeps the practice tied to study material you can actually review.

What score do I get?

The page tracks today's answered count and accuracy for the 10-question daily set, then saves a 7-day score history on this device so you can see your recent practice trend.

Why use this site?

The site is the fastest way to start CompTIA Cloud+ practice without installing anything. It is built for daily recall, quick weak-topic discovery, and source-backed explanations you can review immediately.