CompTIA Cloud+ sample questions with answers
10 free CompTIA Cloud+ sample questions across the exam's domains, each with its answer and an explanation. No account needed.
CompTIA Cloud+ sample questions
CompTIA Cloud+ (V4), CompTIA.
Question 1
Domain: Cloud Architecture
A Go service's image is 900 MB because the Dockerfile installs the full compiler toolchain and then builds the binary in the same image.
Which Dockerfile technique most directly produces a small runtime image?
- A multi-stage build that copies only the compiled binary into a minimal final stage
- Combining every RUN instruction into a single line so that the image contains fewer layers overall
- Adding a .dockerignore file so the build context is smaller
- Using the experimental --squash build option so that all the toolchain layers are merged into one
Show the answer
Answer: A. A multi-stage build that copies only the compiled binary into a minimal final stage
Multi-stage builds let you use a heavy builder image and then COPY --from that stage only the artefacts you need into a small base image, leaving the toolchain behind. A .dockerignore file only shrinks the build context sent to the builder; the compiler installed by RUN would still be in the final image.
Checked against: https://docs.docker.com/build/building/multi-stage/
Question 2
Domain: Cloud Architecture
A team runs a PostgreSQL container with docker run and stores data in the container's default file system. After the container is removed and recreated from the same image, all the data is gone.
How should they persist the database files?
- Commit the running container to a new image after each change
- Add a COPY instruction for the data directory to the Dockerfile
- Mount a Docker volume at the database's data directory
- Increase the size of the container's writable layer
Show the answer
Answer: C. Mount a Docker volume at the database's data directory
Data written to a container's writable layer is removed with the container, whereas a named volume is managed by Docker and persists independently of any container's lifecycle. Committing the container to an image is a tempting workaround, but images are meant to be immutable build artefacts and this approach is not a reliable way to store database state.
Checked against: https://docs.docker.com/engine/storage/volumes/
Question 3
Domain: Deployment
A 2 TB production database must be migrated to a managed cloud database with only a few minutes of downtime at cutover.
Which approach best meets the requirement?
- Take an offline backup, copy it to the cloud and restore it there during a planned weekend outage
- Perform a full load, then replicate ongoing changes with change data capture until cutover
- Export every table to CSV files and then import them in parallel during the final cutover window
- Stop writes for the duration of a single full copy and then switch over
Show the answer
Answer: B. Perform a full load, then replicate ongoing changes with change data capture until cutover
A full load followed by change data capture keeps the target synchronised with the source while the application keeps running, so the final cutover only needs to wait for replication to catch up. An offline backup-and-restore requires downtime for the whole copy of 2 TB, which does not meet a minutes-long window.
Checked against: https://docs.aws.amazon.com/dms/latest/userguide/CHAP_Task.CDC.html
Question 4
Domain: Deployment
A monolithic order system cannot scale individual features and suffers long release cycles. The business agrees to redesign it as event-driven microservices on managed cloud services.
Which migration strategy is this?
- Replatform
- Rehost
- Relocate
- Refactor
Show the answer
Answer: D. Refactor
Refactoring changes the application's architecture to take full advantage of cloud-native features, which matches redesigning a monolith into microservices. Replatforming is tempting but only makes limited optimisations without changing the core architecture.
Checked against: https://docs.aws.amazon.com/prescriptive-guidance/latest/large-migration-guide/migration-strategies.html
Question 5
Domain: Operations
Several production Lambda functions use a language runtime that the provider has announced will reach deprecation next quarter.
What is the main operational risk if the team takes no action?
- The functions are automatically rewritten to target the newest runtime version and may break
- Patching of the runtime may stop, and later functions using it can't be created or updated
- The functions are deleted on the deprecation date along with their logs
- The functions are automatically moved to a more expensive pricing tier until they are upgraded
Show the answer
Answer: B. Patching of the runtime may stop, and later functions using it can't be created or updated
After deprecation AWS may no longer apply security patches or updates to the runtime and functions lose technical support; later, Lambda blocks creating and then updating functions that use it, so teams should migrate to a supported runtime first. The provider does not silently rewrite code to a new runtime; upgrading is the customer's responsibility.
Checked against: https://docs.aws.amazon.com/lambda/latest/dg/lambda-runtimes.html
Question 6
Domain: Operations
Web servers in an Auto Scaling group write logs to local disk. When instances are terminated during scale-in, their logs are lost before anyone can investigate errors.
What should be implemented?
- Increase the size of each instance's root volume
- Disable scale-in so instances are never terminated
- Ship logs continuously to a centralised log service with a defined retention period
- Take a snapshot of each instance's disk every 24 hours
Show the answer
Answer: C. Ship logs continuously to a centralised log service with a defined retention period
Centralised logging streams logs off the instances as they are written, so they survive instance termination and can be searched and retained. Disabling scale-in keeps the logs but sacrifices elasticity and cost efficiency, and still leaves logs scattered across hosts.
Checked against: https://docs.aws.amazon.com/AmazonCloudWatch/latest/logs/WhatIsCloudWatchLogs.html
Question 7
Domain: Security
An auditor asks a company to show PCI DSS compliance for an application hosted on AWS. The company downloads AWS's PCI DSS attestation of compliance from AWS Artifact.
Why is this alone insufficient?
- AWS Artifact reports are marketing documents that auditors are not allowed to review
- PCI DSS does not apply to any workload hosted in a public cloud, so no evidence is required at all
- The attestation automatically expires as soon as it is downloaded
- It covers AWS's side of the shared responsibility model, not the customer's own controls
Show the answer
Answer: D. It covers AWS's side of the shared responsibility model, not the customer's own controls
Provider compliance reports show that the cloud infrastructure meets the standard, but the customer is still responsible for its own controls, such as access management, encryption and network configuration in its environment. PCI DSS does apply to cloud-hosted cardholder data, so the claim that it does not is wrong.
Checked against: https://aws.amazon.com/artifact/
Question 8
Domain: Security
A customer asks its SaaS vendor for evidence that the vendor's security controls operated effectively over the last twelve months, not just that they were designed correctly at one moment.
Which report should the vendor provide?
- A SOC 2 Type 2 report
- A SOC 2 Type 1 report
- A PCI DSS self-assessment questionnaire
- A penetration test summary from last week
Show the answer
Answer: A. A SOC 2 Type 2 report
A SOC 2 Type 2 report covers the design and operating effectiveness of controls over a period of time, which is what the customer wants. A Type 1 report is the tempting option, but it only addresses the design of controls at a specific point in time.
Checked against: https://www.aicpa-cima.com/resources/landing/system-and-organization-controls-soc-suite-of-services
Question 9
Domain: DevOps Fundamentals
A Terraform repository keeps showing local .terraform directories and *.tfstate files as untracked changes, and a developer nearly committed a state file containing secrets.
What is the correct way to stop Git from picking up these files?
- Mark the files as read-only on each developer's workstation
- Add patterns for them to the repository's .gitignore file
- Run git add for the files and then delete them from disk
- Create a separate branch that holds only the state files
Show the answer
Answer: B. Add patterns for them to the repository's .gitignore file
A .gitignore file lists intentionally untracked files that Git should ignore, so they no longer show up or get staged by accident. Adding them with git add does the opposite and would commit them into history, where secrets are hard to remove.
Checked against: https://git-scm.com/docs/gitignore
Question 10
Domain: Troubleshooting
An IaC pipeline fails when launching 40 new instances with an error saying the request exceeds the account's vCPU limit for that instance family in the region.
What is the correct resolution?
- Request a service quota increase for that instance family and region, or use fewer vCPUs
- Retry the pipeline repeatedly, with backoff, until more capacity becomes available in the region
- Switch the launch to a different Availability Zone in the same region, where more capacity is free
- Add more IAM permissions to the pipeline's role
Show the answer
Answer: A. Request a service quota increase for that instance family and region, or use fewer vCPUs
Service quotas are account-level limits per region, and exceeding them requires a quota increase request or a smaller deployment. Changing AZ is tempting but the vCPU quota applies to the whole region, so the request would still fail.
Checked against: https://docs.aws.amazon.com/general/latest/gr/aws_service_limits.html
More practice
A 20-question practice sampler is free with an account; Pro adds the full question bank and timed mock exams.
CompTIA Cloud+ course and practice exam: CV0-004: the exam guide, with the format, cost, pass mark and domains from the vendor.