4.5/5 - (2 votes)

CompTIA CV0-003 Cert Guide PDF 100% Cover Real Exam Questions

Pass CV0-003 Exam – Real Questions and Answers

CompTIA CV0-003 Exam Syllabus Topics:

Topic Details

Cloud Architecture and Design – 13%

Compare and contrast the different types of cloud models. – Deployment models

  • Public
  • Private
  • Hybrid
  • Community
  • Cloud within a cloud
  • Multicloud
  • Multitenancy

– Service models

  • Infrastructure as a Service (IaaS)
  • Platform as a Service (PaaS)
  • Software as a Service (SaaS)

– Advanced cloud services

  • Internet of Things (IoT)
  • Serverless
  • Machine learning/Artificial intelligence (AI)

– Shared responsibility model

Explain the factors that contribute to capacity planning. – Requirements

  • Hardware
  • Software
  • Budgetary
  • Business need analysis

– Standard templates

  • Per-user
  • Socket-based
  • Volume-based
  • Core-based
  • Subscription

– Licensing
– User density
– System load
– Trend analysis

  • Baselines
  • Patterns
  • Anomalies

– Performance capacity planning

Explain the importance of high availability and scaling in cloud environments. – Hypervisors

  • Affinity
  • Anti-affinity

– Oversubscription

  • Compute
  • Network
  • Storage

– Regions and zones
– Applications
– Containers
– Clusters
– High availability of network functions

  • Switches
  • Routers
  • Load balancers
  • Firewalls

– Avoid single points of failure
– Scalability

  • Auto-scaling
  • Horizontal scaling
  • Vertical scaling
  • Cloud bursting
Given a scenario, analyze the solution design in support of the business requirements. – Requirement analysis

  • Software
  • Hardware
  • Integration
  • Budgetary
  • Compliance
  • Service-level agreement (SLA)
  • User and business needs
  • Security
  • Network requirements
    1. Sizing
    2. Subnetting
    3. Routing

– Environments

  • Development
  • Quality assurance (QA)
  • Staging
  • Blue-green
  • Production
  • Disaster recovery (DR)

– Testing techniques

  • Vulnerability testing
  • Penetration testing
  • Performance testing
  • Regression testing
  • Functional testing
  • Usability testing

Security – 20%

Given a scenario, configure identity and access management. – Identification and authorization

  • Privileged access management
  • Logical access management
  • Account life-cycle management
    1. Provision and deprovision accounts
  • Access controls
    1. Role-based
    2. Discretionary
    3. Non-discretionary
    4. Mandatory

– Directory services

  • Lightweight directory access protocol (LDAP)

– Federation
– Certificate management
– Multifactor authentication (MFA)
– Single sign-on (SSO)

  • Security assertion markup language (SAML)

– Public key infrastructure (PKI)
– Secret management
– Key management

Given a scenario, secure a network in a cloud environment. – Network segmentation

  • Virtual LAN (VLAN)/Virtual extensible LAN (VXLAN)/Generic network virtualization encapsulation (GENEVE)
  • Micro-segmentation
  • Tiering

– Protocols

  • Domain name service (DNS)
    1. DNS over HTTPS (DoH)/DNS over TLS (DoT)
    2. DNS security (DNSSEC)
  • Network time protocol (NTP)
    1. Network time security (NTS)
  • Encryption
    1. IPSec
    2. Transport layer security (TLS)
    3. Hypertext transfer protocol secure (HTTPS)
  • Tunneling
    1. Secure Shell (SSH)
    2. Layer 2 tunneling protocol (L2TP)/Point-to-point tunneling protocol (PPTP)
    3. Generic routing encapsulation (GRE)

– Network services

  • Firewalls
    1. Stateful
    2. Stateless
  • Web application firewall (WAF)
  • Application delivery controller (ADC)
  • Intrusion protection system (IPS)/Intrusion detection system (IDS)
  • Data loss prevention (DLP)
  • Network access control (NAC)
  • Packet brokers

– Log and event monitoring
– Network flows
– Hardening and configuration changes

  • Disabling unnecessary ports and services
  • Disabling weak protocols and ciphers
  • Firmware upgrades
  • Control ingress and egress traffic
    1. Allow list (previously known as whitelisting) or blocklist (previously known as blacklisting)
    2. Proxy servers
  • Distributed denial of service (DDoS) protection
Given a scenario, apply the appropriate OS and application security controls. – Policies

  • Password complexity
  • Account lockout
  • Application approved list (previously known as whitelisting)
  • Software feature
  • User/group

– User permissions
– Antivirus/anti-malware/endpoint detection and response (EDR)
– Host-based IDS (HIDS)/Host-based IPS (HIPS)
– Hardened baselines

  • Single function

– File integrity
– Log and event monitoring
– Configuration management
– Builds

  • Stable
  • Long-term support (LTS)
  • Beta
  • Canary

– Operating system (OS) upgrades
– Encryption

  • Application programming interface (API) endpoint
  • Application
  • OS
  • Storage
  • Filesystem

– Mandatory access control
– Software firewall

Given a scenario, apply data security and compliance controls in cloud environments. – Encryption
– Integrity

  • Hashing algorithms
  • Digital signatures
  • File integrity monitoring (FIM)

– Classification
– Segmentation
– Access control
– Impact of laws and regulations

  • Legal hold

– Records management

  • Versioning
  • Retention
  • Destruction
  • Write once read many

– Data loss prevention (DLP)
– Cloud access security broker (CASB)

Given a scenario, implement measures to meet security requirements. – Tools

  • Vulnerability scanners
  • Port scanners

– Vulnerability assessment

  • Default and common credential scans
  • Credentialed scans
  • Network-based scans
  • Agent-based scans
  • Service availabilities

– Security patches

  • Hot fixes
  • Scheduled updates
  • Virtual patches
  • Signature updates
  • Rollups

– Risk register
– Prioritization of patch application
– Deactivate default accounts
– Impacts of security tools on systems and services
– Effects of cloud service models on security implementation

Explain the importance of incident response procedures. – Preparation

  • Documentation
  • Call trees
  • Training
  • Tabletops
  • Documented incident types/categories
  • Roles and responsibilities

– Incident response procedures

  • Identification
    1. Scope
  • Investigation
  • Containment, eradication, and recovery
    1. Isolation
    2. Evidence acquisition
    3. Chain of custody
    4. Root cause analysis
  • Post-incident and lessons learned

Deployment – 23%

Given a scenario, integrate components into a cloud solution. – Subscription services

  • File subscriptions
  • Communications
    1. Email
    2. Voice over IP (VoIP)
    3. Messaging
  • Collaboration
  • Virtual desktop infrastructure (VDI)
  • Directory and identity services
  • Cloud resources
    1. IaaS
    2. PaaS
    3. SaaS

– Provisioning resources

  • Compute
  • Storage
  • Network

– Application

  • Serverless

– Deploying virtual machines (VMs) and custom images
– Templates

  • OS templates
  • Solution templates

– Identity management
– Containers

  • Configure variables
  • Configure secrets
  • Persistent storage

– Auto-scaling
– Post-deployment validation

Given a scenario, provision storage in cloud environments. – Types

  • Block
    1. Storage area network (SAN)
    – Zoning
  • File
    1. Network attached storage (NAS)
  • Object
    1. Tenants
    2. Buckets

– Tiers

  • Flash
  • Hybrid
  • Spinning disks
  • Long-term

– Input/output operations per second (IOPS) and read/write
– Protocols

  • Network file system (NFS)
  • Common Internet file system (CIFS)
  • Internet small computer system interface (iSCSI)
  • Fibre Channel (FC)
  • Non-volatile memory express over fabrics (NVMe-oF)

– Redundant array of inexpensive disks (RAID)

  • 0
  • 1
  • 5
  • 6
  • 10

– Storage system features

  • Compression
  • Deduplication
  • Thin provisioning
  • Thick provisioning
  • Replication

– User quotas
– Hyperconverged
– Software-defined storage (SDS)

Given a scenario, deploy cloud networking solutions. – Services

  • Dynamic host configuration protocol (DHCP)
  • NTP
  • DNS
  • Content delivery network (CDN)
  • IP address management (IPAM)

– Virtual private networks (VPNs)

  • Site-to-site
  • Point-to-point
  • Point-to-site
  • IPSec
  • Multiprotocol label switching (MPLS)

– Virtual routing

  • Dynamic and static routing
  • Virtual network interface controller (vNIC)
  • Subnetting

– Network appliances

  • Load balancers
  • Firewalls

– Virtual private cloud (VPC)

  • Hub and spoke
  • Peering

– VLAN/VXLAN/GENEVE
– Single root input/output virtualization (SR-IOV)
– Software-defined network (SDN)

 

NEW QUESTION 74
Users are experiencing slow response times from an intranet website that is hosted on a cloud platform. There is a site-to-site VPN connection to the cloud provider over a link of 100Mbps.
Which of the following solutions will resolve the issue the FASTEST?

 
 
 
 

NEW QUESTION 75
A cloud architect wants to minimize the risk of having systems administrators in an IaaS compute instance perform application code changes. The development group should be the only group allowed to modify files in the directory.
Which of the following will accomplish the desired objective?

 
 
 
 

NEW QUESTION 76
To save on licensing costs, the on-premises, IaaS-hosted databases need to be migrated to a public DBaaS solution. Which of the following would be the BEST technique?

 
 
 
 

NEW QUESTION 77
A cloud provider wants to make sure consumers are utilizing its IaaS platform but prevent them from installing a hypervisor on the server. Which of the following will help the cloud provider secure the environment and limit consumers’ activity?

 
 
 
 

NEW QUESTION 78
A systems administrator swapped a failed hard drive on a server with a RAID 5 array. During the RAID resynchronization, a second hard drive failed.
Which of the following actions will make the server fully operational?

 
 
 
 

NEW QUESTION 79
A systems administrator is using VMs to deploy a new solution that contains a number of application VMs.
Which of the following would provide high availability to the application environment in case of hypervisor failure?

 
 
 
 

NEW QUESTION 80
A marketing team is using a SaaS-based service to send emails to large groups of potential customers. The internally managed CRM system is configured to generate a list of target customers automatically on a weekly basis, and then use that list to send emails to each customer as part of a marketing campaign. Last week, the first email campaign sent emails successfully to 3,000 potential customers. This week, the email campaign attempted to send out 50,000 emails, but only 10,000 were sent.
Which of the following is the MOST likely reason for not sending all the emails?

 
 
 
 

NEW QUESTION 81
Which of the following is relevant to capacity planning in a SaaS environment?

 
 
 
 

NEW QUESTION 82
A systems administrator needs to configure an email client to ensure data integrity of the email messages.
Which of the following provides the BEST mechanism to achieve this goal?

 
 
 
 

NEW QUESTION 83
After analyzing a web server’s logs, a systems administrator sees that users are connecting to the company’s application through HTTP instead of HTTPS. The administrator then configures a redirect from HTTP to HTTPS on the web server, and the application responds with a connection time-out message.
Which of the following should the administrator verify NEXT?

 
 
 
 

NEW QUESTION 84
A systems administrator is deploying a GPU-accelerated VDI solution. Upon requests from several users, the administrator installs an older version of the OS on their virtual workstations. The majority of the VMs run the latest LTS version of the OS.
Which of the following types of drivers will MOST likely ensure compatibility will all virtual workstations?

 
 
 
 

NEW QUESTION 85
A systems administrator would like to reduce the network delay between two servers.
Which of the following will reduce the network delay without taxing other system resources?

 
 
 
 

NEW QUESTION 86
A systems administrator notices that a piece of networking equipment is about to reach its end of support.
Which of the following actions should the administrator recommend?

 
 
 
 

NEW QUESTION 87
A company is switching from one cloud provider to another and needs to complete the migration as quickly as possible.
Which of the following is the MOST important consideration to ensure a seamless migration?

 
 
 
 

NEW QUESTION 88
A DevOps administrator is automating an existing software development workflow. The administrator wants to ensure that prior to any new code going into production, tests confirm the new code does not negatively impact existing automation activities.
Which of the following testing techniques would be BEST to use?

 
 
 
 

100% Free CV0-003 Daily Practice Exam With 145 Questions: https://www.actualcollection.com/CV0-003-exam-questions.html

Related Links: www.stes.tyc.edu.tw myportal.utt.edu.tt www.stes.tyc.edu.tw myportal.utt.edu.tt myportal.utt.edu.tt www.stes.tyc.edu.tw