Click Study Flashcards above to open the flashcard hub — hundreds of Cloud+ cards you can flip, match, type, or quiz yourself on. Every card is drawn from the six official CV0-004 domains, so you study exactly what the exam tests.[1] Pair them with our free practice test and study guide.
CompTIA Cloud+ is one of the 14 CompTIA certifications — explore our CompTIA flashcards to compare and prep across the whole family.
Cloud+ Flashcard Study Modes
Flip mode lets you turn cards one at a time and rate what stuck. Type mode shows the definition and asks you to spell the term back, so a front like Replatform has to come from memory. Match pairs terms against definitions under a clock, and Quiz builds multiple choice questions from the same 290 cards for exam-style recall.

Why Flashcards Work for the Cloud+
Cloud Architecture is the largest group at 79 cards and carries 23% of the exam, so it sets the vocabulary everything else leans on. The cards drill storage and network building blocks such as SAN, NAS and VPC, delivery and edge terms like CDN, and the service model trio of IaaS, PaaS and SaaS that shows up in scenario wording all through the test.
Deployment holds 41 cards against a 19% weight and covers how workloads get defined and placed. You get configuration and template formats including JSON and YAML, migration decisions such as Retire, Retain and Replatform, and placement models like On-premises, Public cloud and Hybrid cloud that questions often compare side by side.
Security also sits at 19% and is the second-biggest set with 58 cards. Expect identity and access terms such as IAM, MFA and RBAC, protective controls including DLP and WAF, federation with SAML, and reporting and vulnerability references like SOC 2 and CVE that you need to recognize instantly rather than reason out.
Operations brings 40 cards for 17% and focuses on keeping a running environment healthy. The observability cards cover Logging, Metrics and Tracing, with Alerting and Monitoring close behind, while maintenance and resilience appear through Patching, Full backup and Replication.
Troubleshooting is 34 cards at 12% and reads like a fault catalog: DNS failure, DHCP failure and NTP issue for name and time problems, plus Missing route, Sizing issue and Service quota for capacity and path faults. DevOps Fundamentals closes with 38 cards for 10%, drilling tooling and interface terms such as Git, Docker, Ansible, REST and GraphQL.
The Cloud+ is dense with vocabulary you simply have to know cold — the four service models, object vs block vs file storage, the 6 R’s of migration, backup types, IAM terms, and the DevOps toolchain.[1] Spaced flashcards are the most efficient way to keep it all fresh. Used alongside our practice test and study guide, they turn review time into measurable progress.
Cloud+ Flashcards by Domain
The cards are organized by the six official CV0-004 domains. Drill the highest-weighted ones first — Cloud Architecture, Security, and Deployment make up more than 60% of the exam:[1]
| Domain | Exam weight |
|---|---|
| Cloud Architecture | 23% |
| Deployment | 19% |
| Security | 19% |
| Operations | 17% |
| Troubleshooting | 12% |
| DevOps Fundamentals | 10% |
How to Get the Most Out of These Flashcards
- Start with architecture. Cloud Architecture is both the heaviest domain at 23% and the largest set at 79 cards, and terms like VPC and SaaS reappear inside security and deployment questions.
- Type the confusable pairs. Definitions for SAN and NAS, or IaaS against PaaS, blur together in Flip mode, so typing the term forces you to commit to one answer.
- Match the acronyms. Security is full of short forms such as IAM, MFA and SAML, and the timed pairing game is the fastest way to make those decode without hesitation.
- Move to the practice test early. Once Cloud Architecture and Security recall feels automatic, work practice questions so scenario wording, not bare terms, drives your review of the remaining cards.
- Cycle in small blocks. With 290 cards, run one domain per session, quiz the domain you finished last time, and use the study guide for any front you keep missing.
Cloud+ Flashcards FAQ
Hundreds of free Cloud+ flashcards, organized across all six CV0-004 domains — Cloud Architecture, Deployment, Operations, Security, DevOps Fundamentals, and Troubleshooting. They're free with no account required.
Yes. Flashcards use active recall — retrieving an answer from memory — which research shows is one of the most effective study methods, especially in short, spaced sessions. They're ideal for the Cloud+'s heavy vocabulary: service models, storage types, deployment strategies, and DevOps tools.
All six CV0-004 domains: Cloud Architecture (service models, storage, containers), Deployment (strategies, migration, IaC), Operations (observability, scaling, backup), Security (IAM, encryption, controls), DevOps Fundamentals (source control, CI/CD), and Troubleshooting.
Lead with the heaviest domains — Cloud Architecture (23%), then Security and Deployment (19% each). Drill service models, storage types, and the 6 R's of migration with Type and Quiz modes until automatic, then mix in DevOps tools and troubleshooting. Pair the cards with our full practice test before exam day.
Yes — 100% free, all four study modes, no paywall.
Yes. The cards are organized to the current CompTIA Cloud+ CV0-004 exam objectives — the version that replaced CV0-003 in 2024 and added the DevOps Fundamentals domain — covering all six scored domains in their official proportions.
Cloud+ flashcard bank
All 290 cards, by topic
A reference copy of every card in this deck. Each answer stays hidden until you choose to show it. To study with Flip, Match, Type and Quiz modes and track what you have mastered, use Study Flashcards at the top of the page.
Cloud Architecture (79)
- IaaS
Show answerHide answer
Infrastructure as a Service: the provider supplies compute, storage, and networking; you manage the OS, runtime, and apps. Example: virtual machines.
- PaaS
Show answerHide answer
Platform as a Service: the provider manages the OS and runtime; you deploy and manage only your application and data.
- SaaS
Show answerHide answer
Software as a Service: the provider manages everything; you just use the application over the internet. Example: webmail, CRM.
- FaaS
Show answerHide answer
Function as a Service: run individual functions on demand without managing servers (serverless); you are billed per invocation/execution.
- Shared responsibility model
Show answerHide answer
A split of security duties: the cloud provider secures the cloud (hardware, host, network); the customer secures what is in the cloud (data, config, access).
- Region
Show answerHide answer
A separate geographic area of a cloud provider's infrastructure, made up of multiple availability zones.
- Availability zone (AZ)
Show answerHide answer
One or more isolated data centers within a region, with independent power and networking, used to build high availability.
- Cloud bursting
Show answerHide answer
A hybrid pattern where a private cloud overflows extra workload into a public cloud during demand spikes.
- Edge computing
Show answerHide answer
Processing data near where it is generated (the network edge) to reduce latency and bandwidth use.
- Multicloud
Show answerHide answer
Using services from two or more cloud providers, often to avoid vendor lock-in and improve resilience.
- RTO (Recovery Time Objective)
Show answerHide answer
The maximum acceptable time to restore a service after an outage.
- RPO (Recovery Point Objective)
Show answerHide answer
The maximum acceptable amount of data loss, measured as time since the last good backup.
- Hot site
Show answerHide answer
A fully equipped, always-running standby site that can take over almost immediately; the most expensive DR option.
- Warm site
Show answerHide answer
A partially configured standby site with some equipment ready; faster than cold, cheaper than hot.
- Cold site
Show answerHide answer
A basic facility (space, power) with no running systems; the cheapest, slowest DR option.
- Object storage
Show answerHide answer
Stores data as objects with metadata in a flat namespace; ideal for unstructured data and massive scale (e.g., S3-style).
- Block storage
Show answerHide answer
Storage presented as raw volumes (blocks) attached to a VM, like a virtual disk; low latency for databases.
- File storage
Show answerHide answer
Storage presented as a shared file system (NFS/SMB) accessible by multiple clients.
- Hot storage tier
Show answerHide answer
Frequently accessed data on fast, higher-cost storage.
- Cold storage tier
Show answerHide answer
Infrequently accessed data on cheaper, slower storage.
- Archive storage tier
Show answerHide answer
Rarely accessed, long-retention data at the lowest cost with the slowest retrieval.
- SSD vs HDD
Show answerHide answer
SSD (solid-state) is faster with no moving parts and higher cost; HDD (hard disk) is slower and cheaper per GB.
- Managed service
Show answerHide answer
A cloud-provided service (e.g., managed database) where the provider handles patching, scaling, and availability for you.
- Microservices
Show answerHide answer
An architecture that breaks an application into small, independently deployable services that communicate over APIs.
- Loosely coupled architecture
Show answerHide answer
A design where components depend minimally on each other, so one can change or fail without breaking the others.
- Fan-out
Show answerHide answer
A messaging pattern where one message is delivered to many subscribers/consumers in parallel.
- Service discovery
Show answerHide answer
A mechanism that lets services automatically find and connect to each other (e.g., via a registry or DNS).
- Container
Show answerHide answer
A lightweight, portable unit that packages an app with its dependencies, sharing the host OS kernel; faster and smaller than a VM.
- Workload orchestration
Show answerHide answer
Automating the deployment, scaling, networking, and lifecycle of containers (e.g., Kubernetes).
- Image registry
Show answerHide answer
A repository that stores and distributes container images (public or private).
- Persistent volume
Show answerHide answer
Container storage that survives the container's lifecycle, keeping data after the container stops.
- Ephemeral storage
Show answerHide answer
Temporary container storage that is deleted when the container stops.
- Virtualization
Show answerHide answer
Running multiple virtual machines on one physical host via a hypervisor, each with its own guest OS.
- Hypervisor
Show answerHide answer
Software that creates and runs virtual machines by abstracting and sharing physical hardware.
- Clustering
Show answerHide answer
Grouping multiple hosts/nodes so they act as one system for high availability and load distribution.
- Host affinity
Show answerHide answer
A rule that controls which physical host a VM runs on (affinity keeps VMs together; anti-affinity keeps them apart).
- Hardware pass-through
Show answerHide answer
Giving a VM direct access to a physical device (e.g., GPU) for better performance.
- Overlay network
Show answerHide answer
A virtual network built on top of a physical network (e.g., VXLAN) to connect VMs/containers across hosts.
- SAN
Show answerHide answer
Storage Area Network: high-speed block storage shared over a dedicated network.
- NAS
Show answerHide answer
Network-Attached Storage: file-level storage shared over a standard network.
- Pay-as-you-go
Show answerHide answer
A billing model charging only for the resources you actually consume.
- Reserved instances
Show answerHide answer
Discounted capacity committed for a fixed term (e.g., 1-3 years) in exchange for lower rates.
- Spot instance
Show answerHide answer
Spare cloud capacity offered at a steep discount that the provider can reclaim with little notice.
- Dedicated host
Show answerHide answer
A physical server reserved for a single customer's use, often for licensing or compliance.
- Tagging
Show answerHide answer
Labeling cloud resources with key-value metadata for cost allocation, automation, and organization.
- Rightsizing
Show answerHide answer
Matching resource size/type to actual workload demand to cut waste and cost.
- Resource metering
Show answerHide answer
Measuring resource usage so it can be billed, monitored, or charged back.
- Relational database
Show answerHide answer
A database that stores data in tables with defined schemas and relationships, queried with SQL.
- Non-relational (NoSQL) database
Show answerHide answer
A database for flexible/unstructured data (key-value, document, column, graph) that scales horizontally.
- Serverless
Show answerHide answer
A compute model where the provider runs your code on demand and handles all server management; you pay per execution.
- IOPS
Show answerHide answer
Input/Output Operations Per Second: a measure of storage performance (how many reads/writes per second).
- VPC
Show answerHide answer
Virtual Private Cloud: an isolated, logically private section of a public cloud where you launch resources.
- VPC peering
Show answerHide answer
A direct, private connection between two VPCs so they can route traffic to each other.
- Transit gateway
Show answerHide answer
A hub that connects many VPCs and on-premises networks through a single gateway.
- CDN
Show answerHide answer
Content Delivery Network: distributed edge servers that cache content close to users to cut latency.
- Application load balancer (ALB)
Show answerHide answer
A Layer 7 load balancer that routes HTTP/HTTPS traffic based on content (URL, headers).
- Network load balancer (NLB)
Show answerHide answer
A Layer 4 load balancer that distributes TCP/UDP traffic at high performance and low latency.
- IoT
Show answerHide answer
Internet of Things: networks of sensors and devices that collect and transmit data, often via gateways, to the cloud.
- Generative AI
Show answerHide answer
AI that creates new content (text, images, code) from learned patterns; an evolving cloud-delivered capability.
- Cloud computing
Show answerHide answer
On-demand delivery of compute, storage, and services over the internet with pay-per-use pricing and elasticity.
- Elasticity
Show answerHide answer
The ability to automatically grow and shrink resources to match demand.
- On-demand self-service
Show answerHide answer
A user can provision resources automatically without human interaction from the provider.
- Resource pooling
Show answerHide answer
Provider resources are shared among multiple tenants and dynamically assigned (multitenancy).
- Measured service
Show answerHide answer
Usage is metered and reported transparently so customers pay for what they use.
- Multitenancy
Show answerHide answer
A single instance of software/hardware serves multiple isolated customers (tenants).
- Orchestration
Show answerHide answer
Automating the arrangement, coordination, and management of complex systems and services.
- Cloud-native
Show answerHide answer
Applications designed specifically for the cloud: containerized, microservices-based, and dynamically managed.
- Tiered storage
Show answerHide answer
Placing data on hot, warm, cold, or archive tiers based on access frequency and cost.
- Application gateway
Show answerHide answer
A managed entry point that routes and secures application traffic, often with Layer 7 features.
- Firewall (cloud)
Show answerHide answer
A virtual control that permits or blocks network traffic by rules to protect cloud resources.
- Route table
Show answerHide answer
A set of rules that determines where network traffic in a VPC/subnet is directed.
- Subnet
Show answerHide answer
A logical subdivision of a network/VPC, typically public (internet-facing) or private.
- Dedicated connection
Show answerHide answer
A private, high-bandwidth link from on-premises to a cloud provider (e.g., Direct Connect).
- Availability monitoring
Show answerHide answer
Continuously checking that services/resources are reachable and healthy.
- Cost implications (storage)
Show answerHide answer
Faster tiers (SSD, hot) cost more; slower tiers (HDD, archive) cost less per GB.
- Provider-managed database
Show answerHide answer
A database where the cloud provider handles patching, backups, and scaling (DBaaS).
- Self-managed database
Show answerHide answer
A database the customer installs and operates on cloud compute, retaining full control.
- Port mapping
Show answerHide answer
Exposing a container's internal port on the host so external traffic can reach it.
- Machine learning service
Show answerHide answer
A cloud-delivered capability for text/visual recognition, sentiment, and voice tasks.
Deployment (41)
- Public cloud
Show answerHide answer
Cloud infrastructure owned by a provider and shared by many tenants over the internet.
- Private cloud
Show answerHide answer
Cloud infrastructure dedicated to a single organization, on-premises or hosted.
- Hybrid cloud
Show answerHide answer
A mix of public and private cloud (and/or on-prem) connected so workloads and data can move between them.
- Community cloud
Show answerHide answer
Cloud infrastructure shared by several organizations with common requirements (e.g., compliance).
- Blue-green deployment
Show answerHide answer
Run two identical environments (blue=current, green=new); switch all traffic to green at once, with instant rollback to blue.
- Canary deployment
Show answerHide answer
Release a new version to a small subset of users first; expand gradually if it is healthy.
- Rolling deployment
Show answerHide answer
Update instances in batches so the service stays available throughout the rollout.
- In-place deployment
Show answerHide answer
Update the existing servers directly rather than spinning up new ones; simpler but riskier.
- Rehost (lift and shift)
Show answerHide answer
Migrate an application to the cloud with little or no change.
- Replatform
Show answerHide answer
Migrate with minor optimizations (e.g., move to a managed database) without changing the core architecture.
- Refactor / re-architect
Show answerHide answer
Significantly redesign an application to be cloud-native (e.g., microservices, serverless).
- Retire
Show answerHide answer
Decommission an application that is no longer needed during a migration.
- Retain
Show answerHide answer
Keep an application where it is (on-prem) rather than migrating it.
- Vendor lock-in
Show answerHide answer
Dependence on one provider's proprietary services that makes switching costly or difficult.
- Infrastructure as Code (IaC)
Show answerHide answer
Defining and provisioning infrastructure through machine-readable files instead of manual setup; repeatable and version-controlled.
- Configuration as Code (CaC)
Show answerHide answer
Managing system/app configuration in version-controlled code so environments are consistent and repeatable.
- Drift detection
Show answerHide answer
Identifying when running infrastructure no longer matches its declared (code) state.
- Idempotency / repeatability
Show answerHide answer
Applying the same IaC repeatedly yields the same result, with no unintended changes.
- JSON
Show answerHide answer
JavaScript Object Notation: a lightweight, human-readable data format used for config and APIs.
- YAML
Show answerHide answer
YAML Ain't Markup Language: a human-readable, indentation-based data format common in IaC and CI/CD.
- Cloud-to-cloud migration
Show answerHide answer
Moving workloads from one cloud provider to another.
- Versioning (IaC)
Show answerHide answer
Tracking changes to infrastructure code over time so you can review, roll back, and audit.
- Provisioning to requirements
Show answerHide answer
Selecting resource size and type based on storage, performance, security, cost, availability, and compliance needs.
- On-premises
Show answerHide answer
Computing resources hosted in an organization's own data center rather than in the cloud.
- Scripting variable
Show answerHide answer
A named placeholder that stores a value reused throughout deployment code.
- Conditional logic
Show answerHide answer
Code that runs different actions based on whether a condition is true (if/else) during provisioning.
- Migration (on-prem to cloud)
Show answerHide answer
Moving workloads from a local data center into the cloud.
- Resource allocation (migration)
Show answerHide answer
Assigning the right compute, storage, and network capacity to migrated workloads.
- Platform compatibility
Show answerHide answer
Ensuring the target cloud supports the OS, software, and dependencies being migrated.
- Management overhead
Show answerHide answer
The ongoing effort to operate a workload; a key migration trade-off.
- Regulatory/compliance (migration)
Show answerHide answer
Legal and standards requirements that constrain where and how workloads can move.
- Environmental considerations
Show answerHide answer
Factors like power and cooling that affect migration and placement decisions.
- Scripting operators
Show answerHide answer
Symbols (e.g., +, ==, &&) used to compute and compare values in deployment code.
- Data types (scripting)
Show answerHide answer
Categories of values (string, integer, boolean, list) used in scripts.
- Functions (scripting)
Show answerHide answer
Reusable named blocks of code that perform a task, reducing duplication.
- Testing (IaC)
Show answerHide answer
Validating infrastructure code before applying it to catch errors and drift.
- Documentation (IaC)
Show answerHide answer
Recording infrastructure design and code so it is maintainable and auditable.
- Public deployment model
Show answerHide answer
Resources hosted by a provider and shared across many organizations.
- Cloud-to-on-prem migration
Show answerHide answer
Repatriating workloads from the cloud back to a local data center.
- Security requirements (provisioning)
Show answerHide answer
Provisioning resources to meet required encryption, access, and isolation controls.
- Compliance requirements (provisioning)
Show answerHide answer
Sizing/placing resources to satisfy regulatory and contractual obligations.
Operations (40)
- Observability
Show answerHide answer
The ability to understand a system's internal state from its outputs: logs, metrics, and traces.
- Logging
Show answerHide answer
Recording discrete events from systems and applications, then collecting, aggregating, and retaining them.
- Metrics
Show answerHide answer
Numeric measurements over time (CPU, latency, request rate) used for monitoring and alerting.
- Tracing
Show answerHide answer
Following a single request as it moves across services to find bottlenecks and failures.
- Monitoring
Show answerHide answer
Continuously observing metrics and health to detect problems and verify performance.
- Alerting
Show answerHide answer
Notifying responders when a metric crosses a threshold, including triage and response.
- Log aggregation
Show answerHide answer
Centralizing logs from many sources into one searchable system.
- Log retention
Show answerHide answer
The policy for how long logs are kept before deletion, balancing cost and compliance.
- Horizontal scaling
Show answerHide answer
Adding or removing instances (scaling out/in) to handle load; the cloud-preferred approach.
- Vertical scaling
Show answerHide answer
Increasing or decreasing the size of an instance (scaling up/down), e.g., more CPU/RAM.
- Auto-scaling
Show answerHide answer
Automatically adjusting capacity based on triggers like load, schedule, or events.
- Triggered scaling
Show answerHide answer
Scaling driven by a condition such as trending demand, current load, or a specific event.
- Scheduled scaling
Show answerHide answer
Scaling capacity ahead of known time-based demand (e.g., business hours).
- Full backup
Show answerHide answer
A complete copy of all selected data; largest and slowest to create, fastest to restore.
- Incremental backup
Show answerHide answer
Backs up only data changed since the last backup of any type; small and fast, slower restore.
- Differential backup
Show answerHide answer
Backs up all data changed since the last full backup; bigger than incremental, simpler restore.
- Replication
Show answerHide answer
Continuously copying data to another location for availability and disaster recovery.
- Backup testing
Show answerHide answer
Verifying backups by checking recoverability and integrity, not just that they ran.
- In-place recovery
Show answerHide answer
Restoring data over the original/existing system.
- Parallel recovery
Show answerHide answer
Restoring to a separate system running alongside the original.
- Patching
Show answerHide answer
Applying vendor fixes to software/systems to resolve bugs and security flaws.
- Major vs minor update
Show answerHide answer
Major updates add significant features/changes; minor updates are small fixes or improvements.
- Decommissioning
Show answerHide answer
Retiring a resource at end of life or end of support, including data handling and cleanup.
- Ephemeral data
Show answerHide answer
Temporary data that does not need to survive a resource's lifecycle.
- Persistent data
Show answerHide answer
Data that must be retained beyond a resource's lifecycle and is stored durably.
- Backup schedule
Show answerHide answer
How often backups run (e.g., hourly, daily), balancing protection and cost.
- Backup retention
Show answerHide answer
How long backups are kept before being deleted, often set by policy/compliance.
- Backup encryption
Show answerHide answer
Encrypting backup data so it is protected at rest and in transit.
- On-site vs off-site backup
Show answerHide answer
On-site backups restore fast; off-site backups protect against site-wide disasters.
- Bulk vs granular recovery
Show answerHide answer
Bulk recovery restores everything at once; granular recovery restores specific items.
- Recoverability testing
Show answerHide answer
Confirming a backup can actually be restored to a working state.
- Integrity testing
Show answerHide answer
Verifying backup data is not corrupted.
- Manual scaling
Show answerHide answer
An operator changes capacity by hand rather than automatically.
- Trending trigger
Show answerHide answer
Scaling based on a sustained upward/downward usage trend.
- Load trigger
Show answerHide answer
Scaling when a metric (CPU, requests) crosses a threshold.
- Event trigger
Show answerHide answer
Scaling in response to a discrete event (e.g., a queue depth spike).
- Lifecycle management
Show answerHide answer
Managing resources from provisioning through patching, updates, and decommissioning.
- End of life vs end of support
Show answerHide answer
End of life: product retired; end of support: no more patches/help, raising risk.
- Log collection
Show answerHide answer
Gathering log data from sources before aggregation and analysis.
- Response (alerting)
Show answerHide answer
The action taken after triage to resolve or mitigate an alert.
Security (58)
- Zero Trust
Show answerHide answer
A security model that trusts no user or device by default and verifies every request (identity, posture, least privilege).
- Least privilege
Show answerHide answer
Granting users and services only the minimum access needed to do their job.
- Vulnerability management
Show answerHide answer
The cycle of defining scanning scope, identifying, assessing, and remediating weaknesses.
- CVE
Show answerHide answer
Common Vulnerabilities and Exposures: a public catalog of known security flaws, each with a unique ID.
- IAM
Show answerHide answer
Identity and Access Management: controlling who (or what) can access which cloud resources and actions.
- RBAC
Show answerHide answer
Role-Based Access Control: permissions assigned to roles, and roles assigned to users.
- MFA
Show answerHide answer
Multifactor Authentication: requiring two or more factors (something you know/have/are) to sign in.
- Federation
Show answerHide answer
Letting users authenticate with one trusted identity provider to access multiple systems (e.g., via SAML).
- SAML
Show answerHide answer
Security Assertion Markup Language: an XML standard for exchanging authentication/authorization between identity and service providers.
- OAuth 2.0
Show answerHide answer
An authorization framework that lets an app access resources on a user's behalf without sharing their password.
- OpenID Connect
Show answerHide answer
An identity layer built on OAuth 2.0 that adds authentication (verifying who the user is).
- Encryption in transit
Show answerHide answer
Protecting data as it moves across networks, typically with TLS.
- Encryption at rest
Show answerHide answer
Protecting stored data by encrypting it on disk so it is unreadable if stolen.
- Secrets management
Show answerHide answer
Securely storing and controlling access to credentials, keys, and tokens (e.g., a vault).
- API security
Show answerHide answer
Protecting APIs with authentication, authorization, rate limiting, and input validation.
- Data sovereignty
Show answerHide answer
The principle that data is subject to the laws of the country where it is stored.
- Data classification
Show answerHide answer
Labeling data by sensitivity (e.g., public, confidential) to apply the right controls.
- SOC 2
Show answerHide answer
An audit framework reporting on a service organization's security, availability, and confidentiality controls.
- PCI DSS
Show answerHide answer
Payment Card Industry Data Security Standard: rules for protecting cardholder data.
- ISO 27001
Show answerHide answer
An international standard for an information security management system (ISMS).
- DLP
Show answerHide answer
Data Loss Prevention: tools that detect and block sensitive data from leaving the organization.
- IDS / IPS
Show answerHide answer
Intrusion Detection System (alerts) and Intrusion Prevention System (alerts and blocks) for malicious traffic.
- WAF
Show answerHide answer
Web Application Firewall: filters HTTP traffic to block web attacks like SQL injection and XSS.
- Network security group
Show answerHide answer
A virtual firewall of allow/deny rules controlling traffic to cloud resources.
- DDoS protection
Show answerHide answer
Defenses that absorb or filter distributed denial-of-service floods to keep services available.
- Endpoint protection
Show answerHide answer
Security software on hosts/VMs/devices to detect and stop malware and intrusions.
- Hardening
Show answerHide answer
Reducing attack surface by removing unneeded services, closing ports, and applying secure configs.
- CIS Benchmark
Show answerHide answer
Center for Internet Security configuration guidelines for securely hardening systems.
- Bastion host
Show answerHide answer
A hardened, monitored jump server that provides controlled access into a private network.
- Phishing
Show answerHide answer
A social-engineering attack that tricks users into revealing credentials or running malware.
- Ransomware
Show answerHide answer
Malware that encrypts data and demands payment for the decryption key.
- Cryptojacking
Show answerHide answer
Unauthorized use of cloud resources to mine cryptocurrency.
- Zombie instance
Show answerHide answer
A running cloud resource that is unused, unmonitored, or compromised, wasting cost and adding risk.
- Privilege escalation
Show answerHide answer
An attacker gaining higher permissions than they were granted.
- Audit trail
Show answerHide answer
An immutable record of who did what and when, supporting accountability and investigations.
- Container security
Show answerHide answer
Securing images and runtime: prefer unprivileged containers, scan images, and limit file permissions.
- CIA triad
Show answerHide answer
Confidentiality, Integrity, and Availability: the three core goals of information security.
- Confidentiality
Show answerHide answer
Ensuring data is accessible only to authorized parties.
- Integrity
Show answerHide answer
Ensuring data is accurate and unaltered by unauthorized changes.
- Availability
Show answerHide answer
Ensuring systems and data are accessible when needed.
- Authentication vs authorization
Show answerHide answer
Authentication verifies who you are; authorization determines what you may access.
- Token-based authentication
Show answerHide answer
Issuing a signed token after login so the user need not resend credentials each request.
- Directory-based authentication
Show answerHide answer
Verifying identities against a central directory (e.g., LDAP/Active Directory).
- Discretionary access control
Show answerHide answer
The resource owner decides who gets access.
- Group-based access control
Show answerHide answer
Granting permissions to groups, then placing users in groups.
- Data ownership
Show answerHide answer
Defining who is accountable for specific data and its protection.
- Data locality
Show answerHide answer
Where data physically resides, which affects performance and legal jurisdiction.
- Data retention (legal)
Show answerHide answer
Keeping data for required periods, including litigation hold, contractual, and regulatory drivers.
- Cloud Security Alliance
Show answerHide answer
An organization that publishes cloud security best practices and frameworks.
- Scanning scope
Show answerHide answer
Defining which assets and systems a vulnerability scan will assess.
- Remediation
Show answerHide answer
Fixing identified vulnerabilities by patching, reconfiguring, or mitigating.
- Privileged container
Show answerHide answer
A container with elevated host access; risky and discouraged in favor of unprivileged ones.
- Object/file storage security
Show answerHide answer
Protecting stored data with access policies, encryption, and least-privilege permissions.
- Event monitoring
Show answerHide answer
Watching security-relevant events to detect suspicious activity.
- Deviation from baseline
Show answerHide answer
Activity that differs from normal patterns, signaling a possible attack.
- Unnecessary open ports
Show answerHide answer
Exposed ports that widen the attack surface and should be closed.
- Social engineering
Show answerHide answer
Manipulating people into revealing information or granting access.
- Vulnerability exploitation
Show answerHide answer
Attacking a known weakness, often from human error or outdated software.
DevOps Fundamentals (38)
- DevOps
Show answerHide answer
A culture and practice that unites development and operations to deliver software faster and more reliably through automation.
- Version control
Show answerHide answer
Tracking and managing changes to source code over time (e.g., with Git).
- Git
Show answerHide answer
A distributed version-control system that tracks code changes and supports branching and merging.
- Pull request
Show answerHide answer
A proposal to merge code changes, enabling review and discussion before integration.
- Code review
Show answerHide answer
Peers examining proposed changes for quality, security, and correctness before merge.
- Branch management
Show answerHide answer
Organizing parallel lines of development (branches) and merging them back safely.
- CI (Continuous Integration)
Show answerHide answer
Frequently merging code and automatically building and testing it to catch issues early.
- CD (Continuous Delivery/Deployment)
Show answerHide answer
Automatically delivering tested code to staging (delivery) or production (deployment).
- CI/CD pipeline
Show answerHide answer
An automated workflow that builds, tests, and deploys code through defined stages.
- Build artifact
Show answerHide answer
The packaged output of a build (e.g., a container image or zip) that gets deployed.
- Container image
Show answerHide answer
A read-only template containing an app and its dependencies, used to run containers.
- Artifact repository
Show answerHide answer
A store for build artifacts and packages (public or private).
- REST
Show answerHide answer
Representational State Transfer: a stateless web-service style using HTTP verbs and resources.
- SOAP
Show answerHide answer
Simple Object Access Protocol: a strict, XML-based web-service protocol.
- RPC
Show answerHide answer
Remote Procedure Call: invoking a function on a remote system as if it were local.
- GraphQL
Show answerHide answer
A query language for APIs that lets clients request exactly the data they need in one call.
- Event-driven architecture
Show answerHide answer
A design where services react to events/messages asynchronously, enabling loose coupling.
- WebSocket
Show answerHide answer
A protocol providing a persistent, two-way connection between client and server.
- Docker
Show answerHide answer
A platform for building, shipping, and running applications in containers.
- Kubernetes
Show answerHide answer
An open-source platform that automates deploying, scaling, and managing containers.
- Terraform
Show answerHide answer
An IaC tool that provisions infrastructure across providers using declarative config.
- Ansible
Show answerHide answer
An agentless automation tool for configuration management and app deployment.
- Jenkins
Show answerHide answer
An automation server widely used to build CI/CD pipelines.
- GitHub Actions
Show answerHide answer
A CI/CD platform built into GitHub that automates workflows on repository events.
- ELK stack
Show answerHide answer
Elasticsearch, Logstash, and Kibana: a toolset for collecting, storing, and visualizing logs.
- Grafana
Show answerHide answer
An open-source tool for visualizing metrics and building monitoring dashboards.
- Source control concepts
Show answerHide answer
Managing code changes: commit, push, merge, pull request, review, and branching.
- Code commit
Show answerHide answer
Saving a set of changes to the version-control repository with a message.
- Code merge
Show answerHide answer
Combining changes from one branch into another.
- Automation (CI/CD)
Show answerHide answer
Using tooling to run builds, tests, and deployments without manual steps.
- Code integration
Show answerHide answer
Combining developers' code frequently and verifying it builds and passes tests.
- Build stage
Show answerHide answer
The pipeline step that compiles/packages code into a deployable artifact.
- Pipeline security
Show answerHide answer
Scanning code and dependencies for vulnerabilities within the CI/CD workflow.
- Public vs private repository
Show answerHide answer
Public repos are open to all; private repos restrict access to authorized users.
- VM image vs container image
Show answerHide answer
A VM image includes a full OS; a container image shares the host kernel and is smaller.
- Web service
Show answerHide answer
An application component exposed over a network via standard protocols (REST, SOAP, RPC).
- Flat file
Show answerHide answer
A simple file (e.g., CSV) with no structured relationships, sometimes used as an artifact/data.
- RPM / Debian packages
Show answerHide answer
Linux software package formats (RPM for Red Hat, .deb for Debian/Ubuntu).
Troubleshooting (34)
- API throttling
Show answerHide answer
A provider limiting the rate of API calls; exceeding it causes errors until requests slow down.
- Service quota
Show answerHide answer
A provider-imposed limit on resources (e.g., max instances) that can block new deployments when hit.
- Oversubscription
Show answerHide answer
Allocating more virtual resources than the physical hardware can provide, causing contention.
- Resource misconfiguration
Show answerHide answer
Incorrect settings (allocation, permissions, sizing) that cause a deployment to fail or underperform.
- Deprecation
Show answerHide answer
Removal or end-of-support of a feature/version that breaks dependent deployments.
- Regional service availability
Show answerHide answer
A service or feature not being offered in a particular region, breaking a deployment there.
- DHCP failure
Show answerHide answer
Clients cannot obtain IP settings, often shown by scope exhaustion or no address; breaks connectivity.
- DNS failure
Show answerHide answer
Name resolution fails, so hosts can reach IPs but not names; a classic 'site is down' cause.
- NTP issue
Show answerHide answer
Clock drift from a failed time service can break authentication, certificates, and logging.
- Scope exhaustion
Show answerHide answer
A DHCP pool runs out of addresses, so new clients cannot get an IP.
- Network overlap
Show answerHide answer
Two networks using the same IP range, causing routing conflicts after a migration or peering.
- Missing route
Show answerHide answer
A routing table lacks a path to a destination, so traffic is dropped.
- Misconfigured route
Show answerHide answer
A routing entry sends traffic the wrong way, causing unreachable resources or loops.
- VLAN tag misconfiguration
Show answerHide answer
Wrong 802.1Q tags or access-vs-trunk port settings break Layer 2 segmentation and connectivity.
- Latency issue
Show answerHide answer
High delay between request and response, often from distance, congestion, or under-provisioning.
- Bandwidth/throughput issue
Show answerHide answer
Insufficient capacity for the traffic volume, causing slowness or drops.
- HTTP 4xx vs 5xx
Show answerHide answer
4xx errors indicate a client problem (e.g., 403 forbidden, 404 not found); 5xx indicate a server-side error.
- Cipher suite deprecation
Show answerHide answer
Old encryption algorithms being disabled, breaking TLS connections that still rely on them.
- Leaked credentials
Show answerHide answer
Exposed keys/passwords that enable unauthorized access until rotated/revoked.
- Unauthorized access
Show answerHide answer
Access by an entity without proper permission, often from misconfigured authorization.
- Software vulnerability
Show answerHide answer
A flaw in software that attackers can exploit; remediated by patching or updating.
- Unauthorized software
Show answerHide answer
Unapproved applications running in the environment, creating risk and policy violations.
- Protocol incompatibility
Show answerHide answer
Two systems unable to communicate because they use incompatible protocols/versions.
- Outage (full vs partial)
Show answerHide answer
A complete service failure (full) versus degraded or partial loss of functionality.
- Incompatibility (deployment)
Show answerHide answer
A component that does not work with others, causing a failed deployment.
- Outdated component definition
Show answerHide answer
An old template/definition causing a deployment to use deprecated or wrong resources.
- Permission misconfiguration
Show answerHide answer
Wrong access settings that block or over-expose a deployed resource.
- Sizing issue
Show answerHide answer
Under- or over-provisioning resources, causing failure or wasted cost.
- NAT issue
Show answerHide answer
Failed address translation breaking outbound/inbound connectivity for private hosts.
- Network device misconfiguration
Show answerHide answer
Incorrect settings on a router/switch/firewall that disrupt traffic.
- Protocol deprecation
Show answerHide answer
An older protocol/version being disabled, breaking systems that still use it.
- Access vs trunk port
Show answerHide answer
Access ports carry one VLAN; trunk ports carry multiple tagged VLANs; mixing them breaks connectivity.
- Authorization issue
Show answerHide answer
A failure or misconfiguration in what an authenticated entity is allowed to do.
- Authentication issue
Show answerHide answer
A failure to verify identity, sometimes caused by leaked or expired credentials.
References
- 1.CompTIA. “Cloud+ (CV0-004) Certification Exam Objectives.” comptia.org. ↑
- 2.National Institute of Standards and Technology. “SP 800-145 — The NIST Definition of Cloud Computing.” csrc.nist.gov. ↑
- 3.National Institute of Standards and Technology. “SP 800-207 — Zero Trust Architecture.” csrc.nist.gov. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
