All certifications / Cloud+ / Cheat sheet
Cloud+ CV0-004 cheat sheet
Domain 1: Cloud architecture (23%)
Exam tips
- When a question asks who is responsible for something, first identify the service model. Data, identities, access policies and configuration always stay with the customer; physical security and the hypervisor always stay with the provider.
- Do not confuse hybrid with multicloud. Hybrid means private plus public; multicloud means two or more public providers. A design can be both at the same time.
- Multi-AZ protects against a data center failure within a region; multi-region protects against a regional outage or disaster. If a question mentions a whole region being unavailable, multi-AZ alone is not the answer.
- Licensing tied to physical sockets or cores, or a requirement for physical isolation, points to dedicated hosts. A memory-hungry cache points to a memory-optimized family, not simply a bigger general-purpose VM.
- Containers share the host kernel; VMs each have their own OS. If a question stresses fast startup, portability and density, think containers; if it stresses event-driven, pay-per-use and no server management, think serverless.
- Queue means one consumer per message and buffering; pub/sub means fan-out to many subscribers. An API gateway is the answer when a question mentions a single entry point, rate limiting or authentication in front of many APIs.
- Databases and boot disks point to block storage; a share mounted by many servers points to file storage; backups, logs and static content at scale point to object storage. Many small random operations mean IOPS; large sequential transfers mean throughput.
- What makes a subnet public is a route to an internet gateway. If private instances cannot download patches, check for a NAT gateway and a 0.0.0.0/0 route to it. Overlapping CIDR ranges block peering and VPN routing.
- Need it today and cheaply: site-to-site VPN. Need consistent latency and high bandwidth that avoids the internet: dedicated interconnect. Many VPCs needing to talk to each other: a transit hub, because peering is not transitive.
- Routing by URL path or host header needs a layer 7 load balancer. Sending users to the nearest region is a DNS latency policy or a global load balancer. A failover that seems slow is often DNS caching because of a long TTL.
- RPO is about data (how far back), RTO is about time (how long down). Order the patterns by cost and speed: backup and restore, pilot light, warm standby, active-active. Choose the cheapest one that still meets both targets.
- Steady, predictable, long-running: reserved or committed. Interruptible and fault-tolerant: spot. Short-term or unpredictable: on-demand. Showback only reports costs; chargeback actually bills them.
Key terms
- IaaS
- Infrastructure as a service: the provider supplies virtual compute, storage and networking, and the customer manages the operating system and everything above it.
- PaaS
- Platform as a service: the provider also runs the operating system and runtime, so the customer deploys and manages only application code and data.
- SaaS
- Software as a service: a complete application delivered over the internet; the customer manages users, settings and data.
- FaaS
- Function as a service: event-driven code that runs on demand without servers for the customer to manage, billed per execution.
- Shared responsibility model
- The division of security and operational duties between provider and customer, which shifts with the service model.
- Public cloud
- Cloud infrastructure owned by a provider and shared by many tenants, consumed on demand over the internet.
- Private cloud
- Cloud infrastructure dedicated to one organization, on premises or hosted, that still offers self-service and elasticity.
- Hybrid cloud
- A combination of private or on-premises infrastructure and public cloud, connected so workloads can interoperate.
- Community cloud
- Cloud infrastructure shared by several organizations with common mission, security or compliance needs.
- Multicloud
- Using services from more than one public cloud provider.
- Cloud bursting
- Sending overflow demand from a private environment to a public cloud when local capacity runs out.
- Region
- A geographic area containing multiple isolated data center groups where a provider offers its services.
- Availability zone
- An isolated location within a region with independent power, cooling and networking, used to survive data center failures.
- Edge location
- A provider point of presence close to users, used for CDN caching, DNS and edge services rather than general compute.
- Single point of failure
- Any component whose failure stops the whole system.
- High availability
- A design that keeps a service running through component failures, usually through redundancy and automatic failover.
- Type 1 hypervisor
- A bare-metal hypervisor that runs directly on hardware; used by cloud providers.
- Type 2 hypervisor
- A hosted hypervisor that runs as an application on a general-purpose operating system.
- Instance family
- A group of VM sizes tuned for a workload profile, such as general purpose, compute-, memory- or storage-optimized, or GPU.
- Dedicated host
- A physical server reserved for one customer, giving visibility of sockets and cores for licensing and isolation.
- Multitenancy
- Many customers sharing the same physical infrastructure while being logically isolated from one another.
- Container
- A lightweight package of an application and its dependencies that shares the host operating system kernel.
- Orchestration
- Automated scheduling, scaling, healing and updating of containers across a cluster of hosts, for example with Kubernetes.
- Pod
- The smallest deployable unit in Kubernetes: one or more containers sharing network and storage.
- Cold start
- Extra latency when a serverless platform must create a new execution environment before running a function.
- Serverless
- A model where the provider runs code on demand in response to events, scaling automatically and billing per use.
- Microservice
- A small, independently deployable service that owns one business capability and communicates through APIs.
- Message queue
- A buffer that stores messages until a consumer processes them, decoupling senders from receivers.
- Pub/sub
- A messaging pattern where a published message is delivered to every subscriber of a topic.
- Dead-letter queue
- A queue that holds messages that could not be processed after a set number of attempts.
- API gateway
- A managed entry point that routes API requests to back-end services and handles authentication, throttling and monitoring.
- Block storage
- Raw volumes attached to an instance and formatted with a file system; low latency, used for boot disks and databases.
- File storage
- A shared, network-mounted file system (NFS or SMB) that many clients can use at once.
- Object storage
- Storage of objects with keys and metadata in buckets, accessed through HTTP APIs; highly durable and scalable.
- IOPS
- Input/output operations per second: the rate of individual read and write operations a storage device can handle.
- Throughput
- The amount of data transferred per second, typically measured in MB/s.
- VPC / VNet
- A logically isolated private network in a public cloud, defined by one or more CIDR ranges.
- CIDR
- Notation that writes an IP range as address/prefix length, such as 10.0.1.0/24.
- Route table
- A set of rules that tells traffic from a subnet which next hop to use for each destination range.
- Internet gateway
- A component that gives a virtual network two-way internet connectivity for resources with public IP addresses.
- NAT gateway
- A managed service that lets instances in private subnets start outbound internet connections while blocking unsolicited inbound ones.
- Site-to-site VPN
- An encrypted IPsec tunnel over the internet that connects an entire on-premises network to a cloud network.
- Dedicated interconnect
- A private physical link between a customer network and a cloud provider that bypasses the public internet.
- VPC peering
- A private connection between two virtual networks that lets them communicate with private IP addresses; typically not transitive.
- Transit hub
- A central router service that connects many virtual networks and on-premises links in a hub-and-spoke topology.
- BGP
- Border Gateway Protocol, used to exchange routes dynamically over VPN and interconnect links.
- Layer 4 load balancer
- A load balancer that forwards TCP or UDP connections based on addresses and ports without inspecting application data.
- Layer 7 load balancer
- An HTTP(S)-aware load balancer that can route by host or path, terminate TLS and use cookies.
- Health check
- A periodic probe used to decide whether a target should receive traffic.
- TTL
- Time to live: how long a DNS answer or cached object may be reused before it must be refreshed.
- CDN
- Content delivery network: a distributed cache at edge locations that serves content from close to the user.
- RPO
- Recovery point objective: the maximum acceptable data loss, expressed as time before the incident.
- RTO
- Recovery time objective: the maximum acceptable time to restore service after an incident.
- Pilot light
- A DR pattern that keeps only core components such as the database running in the recovery site, ready to be scaled up.
- Warm standby
- A DR pattern with a smaller, always-running copy of the full environment that is scaled up during failover.
- Active-active
- A multisite design in which all sites serve production traffic at the same time.
- On-demand
- Pay-as-you-go pricing with no commitment, charged per second or hour of use.
- Reserved or committed use
- A discount in exchange for committing to a level of usage for a one- or three-year term.
- Spot instance
- Discounted spare capacity that the provider can reclaim at short notice.
- Showback
- Reporting cloud costs to the teams that caused them without actually billing them.
- Chargeback
- Billing cloud costs back to the department or cost center that incurred them.
Domain 2: Deployment (19%)
Exam tips
- Fastest rollback: blue-green. Test with a small share of real users first: canary. Limited spare capacity with no full outage: rolling. Comparing features or business outcomes, not reducing risk: A/B testing.
- Look for the clue words: no code changes and fastest means rehost; a managed service with minimal changes means replatform; rewrite for cloud-native or microservices means refactor; switch to SaaS means repurchase.
- The order is discovery, dependency mapping, wave planning with a pilot, cutover, then validation. If a migrated app is suddenly slow and its database stayed on premises, the missing step was dependency mapping.
- Calculate transfer time (data in bits divided by usable bandwidth). When it runs to weeks or months, the answer is an offline appliance. For databases with minimal downtime, the answer is initial load plus continuous replication or CDC, then a short cutover.
- If new instances drift in configuration or launch unpatched, the fix is a golden image kept current by an automated build, used through launch templates. Remember that golden images age: they must be rebuilt, not just created once.
- Thin provisioning saves space but risks the pool running out; thick gives predictable capacity. Synchronous replication means zero data loss over short distances; asynchronous allows long distances with some data loss.
- Read scaling points to read replicas or a cache; automatic failover within a region points to a multi-AZ deployment. With managed services the provider patches the engine, but you still own users, data, network access and backups settings.
- If environments differ unexpectedly or a manual change keeps disappearing, think drift and IaC. Parameters make one template reusable; state lets the tool know what already exists. Never hard-code secrets in templates.
- If a question describes servers that differ because of manual changes, the cure is immutable infrastructure built from images and IaC. Staging should mirror production; development and test can be smaller. Keep production in its own account or subscription.
- Smoke tests are fast checks of critical paths right after deployment; baselines tell you whether performance changed. You cannot say something is slower without a baseline to compare against.
Key terms
- Blue-green deployment
- Running two identical environments and switching traffic from the old (blue) to the new (green) all at once, with instant switch-back for rollback.
- Canary release
- Sending a small percentage of traffic to a new version and increasing it gradually while monitoring health.
- Rolling deployment
- Updating servers in batches so the service stays available throughout the release.
- A/B testing
- Routing user groups to different versions to compare user behavior or business metrics.
- Rollback plan
- Predefined triggers and steps for returning to the previous version if a release fails.
- Rehost
- Lift and shift: moving an application to the cloud without changing it.
- Replatform
- Moving with small optimizations, such as switching to a managed database, without changing the core architecture.
- Refactor
- Re-architecting an application to use cloud-native services and patterns.
- Repurchase
- Replacing an application with a different product, often SaaS.
- Retire / retain
- Decommissioning an application that is no longer needed, or deliberately leaving it where it is for now.
- Discovery
- Collecting an inventory and utilization data for the systems that may be migrated.
- Dependency mapping
- Identifying which systems communicate with or rely on each other so they can be migrated together.
- Migration wave
- A scheduled group of applications migrated together.
- Pilot wave
- An initial small, low-risk wave used to prove the process and tools.
- Cutover
- The point at which production traffic and data switch from the old environment to the new one.
- Online transfer
- Moving data to the cloud over a network connection such as the internet, VPN or interconnect.
- Transfer appliance
- A secure physical storage device shipped by the provider for bulk offline data transfer.
- Change data capture
- Capturing ongoing changes from a database's transaction log and replicating them to a target.
- Homogeneous migration
- A database migration between the same engine type.
- Heterogeneous migration
- A database migration between different engines, requiring schema and code conversion.
- Image
- A template containing an operating system and optional software, used to launch virtual machines.
- Golden image
- An organization-approved, patched and hardened image used as the standard starting point for new instances.
- Launch template
- A saved set of instance settings, including image, size, network and startup script, used for consistent launches.
- User data / cloud-init
- A startup script or configuration passed to an instance and run at first boot.
- Burstable instance
- An instance type that accrues CPU credits during idle periods and spends them to burst above its baseline.
- Thick provisioning
- Allocating a volume's full capacity on the underlying storage when it is created.
- Thin provisioning
- Allocating storage only as data is written, allowing overcommitment of capacity.
- Provisioned IOPS
- A volume option where you specify the performance level the volume must deliver.
- Synchronous replication
- Writing data to both copies before acknowledging, for zero data loss at the cost of latency.
- Ephemeral storage
- Temporary local storage attached to an instance that is lost when the instance stops or is terminated.
- Managed database
- A database service where the provider handles installation, patching, backups and failover.
- Read replica
- An asynchronously updated, read-only copy of a database used to scale reads.
- Multi-AZ standby
- A synchronously replicated database copy in another zone used for automatic failover, not for reads.
- Cache-aside
- A pattern where the application reads from the cache first and loads from the database on a miss.
- Managed Kubernetes
- A service where the provider operates the Kubernetes control plane while you manage workloads and usually the worker nodes.
- Infrastructure as code
- Defining and managing infrastructure through machine-readable files under version control.
- Template
- A file describing the resources to deploy and their configuration.
- Parameter
- An input value that lets one template deploy different environments or sizes.
- State
- The record an IaC tool keeps of the resources it manages and their real identifiers.
- Drift
- Differences between deployed resources and the configuration defined in code, usually from manual changes.
- Immutable infrastructure
- Infrastructure that is never changed after deployment; updates are made by replacing it with new instances.
- Configuration drift
- Gradual, undocumented differences between servers that should be identical.
- Staging
- A production-like environment used for final validation before release.
- Environment promotion
- Moving the same tested artifact from one environment to the next.
- Data masking
- Replacing sensitive values with realistic but fake data for use in non-production environments.
- Smoke test
- A quick check of critical functions right after deployment to confirm the system basically works.
- Health check
- A recurring probe used by load balancers or orchestrators to decide whether an instance is healthy.
- Performance baseline
- A recorded measure of normal performance used to detect regressions.
- Readiness probe
- A Kubernetes check that decides whether a pod should receive traffic.
- Runbook
- Documented step-by-step procedures for operating or troubleshooting a system.
Domain 3: Operations (17%)
Exam tips
- Metrics tell you something changed, logs tell you what happened, traces tell you where in a multi-service request the time went. Alert on sustained conditions and user-facing symptoms to avoid alert fatigue.
- Logs on ephemeral instances vanish when those instances are terminated, so centralize them. Synthetic monitoring finds problems even with no real traffic; RUM shows what real users experience. Retention requirements for audit logs usually come from compliance, not convenience.
- Predictable load changes at known times mean scheduled scaling; keeping a metric at a value means target tracking; different adjustments for different breach sizes means step scaling. If a group keeps adding and removing instances rapidly, check the cooldown.
- Incremental: fastest backup, slowest restore (full plus every incremental). Differential: slower backups as the week goes on, faster restore (full plus last differential). Replication and snapshots in the same account are not a complete backup strategy.
- Ransomware scenarios point to immutable (WORM or locked) backups, stored in a separate account with separate credentials, plus MFA on deletion. If a question asks how to prove backups work, the answer is regular restore testing, not checking job success messages.
- Containers and immutable instances are patched by rebuilding and redeploying, never by patching in place. For managed services, the provider patches the platform, but you pick the maintenance window and plan major version upgrades.
- Watch provider notifications and keep an inventory so deprecations never surprise you. When decommissioning, remember the attached resources: volumes, snapshots, IP addresses, DNS records and credentials.
- Right-sizing uses measured utilization over time, including peaks. Lifecycle policies save money only if data is rarely read after the transition; frequent reads from a cold tier cost more because of retrieval fees.
- Memorize the approximate numbers: 99.9 percent is about 8.76 hours per year (about 43 minutes per month); 99.99 percent is about 52.6 minutes per year (about 4.3 minutes per month). Serial dependencies multiply and lower availability; redundancy raises it.
- Idle non-production environments outside business hours point to scheduled stop and start, selected by tags. Self-healing should notify and log, not hide problems; recurring automated fixes signal a root cause to address.
Key terms
- Metric
- A numeric measurement recorded over time, such as CPU utilization or request latency.
- Log
- A timestamped record of a discrete event, often with detailed context.
- Trace
- A record of one request's path through multiple services, made up of timed spans.
- Alert threshold
- The value and duration at which a metric triggers a notification.
- Alert fatigue
- Desensitization caused by too many non-actionable alerts, leading to real ones being missed.
- Log aggregation
- Collecting logs from many sources into one central, searchable system.
- Retention policy
- Rules for how long each type of log or data is kept and where.
- Correlation ID
- A unique identifier passed along with a request so its log entries can be linked across services.
- Synthetic monitoring
- Scripted, scheduled tests that simulate user actions to check availability and performance.
- Real user monitoring
- Measuring performance and errors experienced by actual users of an application.
- Vertical scaling
- Increasing the resources of a single server, such as moving to a larger instance size.
- Horizontal scaling
- Adding or removing instances to share the workload.
- Target tracking
- An autoscaling policy that adjusts capacity to keep a metric near a target value.
- Step scaling
- An autoscaling policy that adds or removes set amounts of capacity depending on how far a metric passes a threshold.
- Cooldown
- A waiting period after a scaling action that prevents further actions until new capacity has taken effect.
- Full backup
- A complete copy of all selected data.
- Incremental backup
- A backup of data changed since the last backup of any type.
- Differential backup
- A backup of all data changed since the last full backup.
- Snapshot
- A point-in-time copy of a volume, VM or database, often stored incrementally at the block level.
- 3-2-1 rule
- Keep three copies of data on two different media, with one copy offsite.
- Restore test
- A planned recovery from backup to confirm that data is complete and recovery meets the RTO.
- Immutable backup
- A backup that cannot be modified or deleted until its retention period expires.
- WORM
- Write once, read many: storage that allows data to be written once and prevents later changes.
- Cross-account backup
- A backup copy stored in a separate account with separate credentials and administrators.
- Air gap
- Isolation of a backup copy from networks and normal credentials so an attacker cannot reach it.
- Patch baseline
- The defined set of patches, by classification and severity, that instances must have installed to be compliant.
- Maintenance window
- A scheduled period when updates and changes may be applied with minimal impact.
- Image pipeline
- An automated process that builds, tests and publishes updated machine or container images.
- Base image
- The starting image, such as an OS or language runtime image, on which application images are built.
- Emergency change
- An expedited change process for urgent fixes, reviewed after implementation.
- Deprecation
- A provider's announcement that a feature, version or resource type will no longer be supported after a certain date.
- End of support
- The date after which a product no longer receives updates or security fixes.
- Major version upgrade
- An upgrade that can change behavior or compatibility and requires testing and planning.
- Decommissioning
- Retiring a resource safely, including removing its dependent resources, access and records.
- CMDB
- Configuration management database: an inventory of IT assets and their relationships.
- Right-sizing
- Adjusting resource size and type to match actual measured demand.
- Capacity planning
- Forecasting future resource needs from trends and business plans.
- Lifecycle policy
- Rules that automatically move data between storage tiers or delete it as it ages.
- Minimum storage duration
- A billing rule in cooler tiers that charges for a minimum period even if data is deleted sooner.
- Retrieval fee
- A charge for reading data from infrequent-access or archive storage tiers.
- SLI
- Service level indicator: a measured value of service behavior, such as success rate or latency.
- SLO
- Service level objective: the internal target value for an SLI over a period.
- SLA
- Service level agreement: a contractual commitment to a service level, usually with service credits if missed.
- Error budget
- The amount of unreliability an SLO allows, equal to 100 percent minus the SLO.
- Service credit
- A partial refund or billing credit given when a provider misses its SLA.
- Scheduled start/stop
- Automatically stopping resources outside working hours and starting them when needed to save cost.
- Runbook
- A documented procedure for a routine operation or known issue.
- Runbook automation
- Executing runbook steps as code, triggered manually, on a schedule or by events.
- Self-healing
- Automatic detection and repair of failures, such as replacing unhealthy instances.
- Event-driven automation
- Automation triggered by an event or alarm rather than by a schedule or a person.
Domain 4: Security (19%)
Exam tips
- Assign permissions to groups or roles, not directly to individual users. Least privilege means specific actions on specific resources; any answer that grants full administrator access or wildcards to solve a narrow need is usually wrong.
- SAML means XML assertions and enterprise web SSO; OIDC means JSON tokens, modern apps and APIs; OAuth alone is authorization, not authentication. Root or global admin protection always includes MFA, no routine use and no access keys.
- Whenever a question describes access keys stored in code, config files or environment variables for an app running in the cloud, the answer is an instance role, managed identity or service account with least privilege.
- Control over rotation, key policy and revocation means customer-managed keys; a single-tenant, compliance-driven requirement for dedicated hardware means a cloud HSM. Passwords and tokens belong in a secrets manager, not in code or environment files.
- Tokenization is not encryption: a token cannot be mathematically reversed, and it reduces compliance scope. Encryption at rest does not protect against someone with valid access reading data through the application; that needs access control and monitoring.
- Stateful and per-instance: security group. Stateless, ordered, per-subnet and able to deny: NACL. SQL injection or cross-site scripting: WAF, not a network firewall. Keep traffic to a managed service off the internet: private endpoint.
- Zero trust keywords are never trust, always verify; verify explicitly; least privilege; assume breach. If a question describes lateral movement in a flat network, the answer involves segmentation or microsegmentation.
- Misconfigurations in live cloud accounts, such as public buckets or disabled logging, point to CSPM. Catching insecure templates before deployment points to IaC scanning. Vulnerable packages in images point to registry or pipeline image scanning.
- Keeping data in a country is data residency or sovereignty; enforce it with region restriction policies. Using a certified provider does not make your workload compliant, because of shared responsibility. Audit logs belong in a separate, protected account.
- Hardening questions usually want the option that removes or disables something unnecessary, or applies a recognized benchmark. Build baselines into images and IaC, then scan for drift.
- Isolate, don't terminate: terminating a compromised instance destroys evidence. Preserve with snapshots and logs copied to a separate account and document chain of custody. Recover from known-good images and backups, not by cleaning the compromised host.
Key terms
- IAM
- Identity and access management: the service and practices that control authentication and authorization to cloud resources.
- Role
- A set of permissions that a user, service or application can assume, receiving temporary credentials.
- Policy
- A document that allows or denies specific actions on specific resources, optionally under conditions.
- Least privilege
- Granting only the minimum permissions required, for the minimum time.
- Separation of duties
- Splitting sensitive tasks among different people so no one can misuse them alone.
- Identity provider (IdP)
- The system that authenticates users and issues assertions or tokens that other services trust.
- Federation
- A trust relationship that lets users authenticated by one identity provider access other services.
- SAML 2.0
- An XML-based standard for exchanging signed authentication assertions, common in enterprise web SSO.
- OpenID Connect
- An authentication layer on OAuth 2.0 that uses JSON Web Tokens as ID tokens.
- Break-glass account
- A tightly controlled emergency administrator account used only when normal access fails.
- Workload identity
- An identity assigned to an application or resource rather than a person, used to access other services.
- Instance profile / instance role
- A way of attaching an IAM role to a VM so software on it receives temporary credentials.
- Managed identity
- An Azure identity for a resource, managed by the platform, that obtains tokens without stored secrets.
- Service account
- A non-human account used by applications and services, notably in Google Cloud and Kubernetes.
- Instance metadata service
- A local endpoint on a VM that provides configuration and temporary credentials to software running on it.
- KMS
- Key management service: a managed service that creates, stores and uses encryption keys under access policies.
- HSM
- Hardware security module: tamper-resistant hardware for generating, storing and using cryptographic keys.
- Customer-managed key
- A key the customer controls in KMS, including its policy, rotation and deletion.
- Envelope encryption
- Encrypting data with a data key and encrypting that data key with a master key.
- Secrets manager
- A service that stores, controls access to and rotates application secrets.
- Data classification
- Labeling data by sensitivity or regulatory type to decide how it must be protected.
- Encryption at rest
- Encrypting stored data on disks, databases, object storage and backups.
- Encryption in transit
- Encrypting data as it moves across networks, usually with TLS, SSH or IPsec.
- Tokenization
- Replacing sensitive data with a non-sensitive token, keeping the original in a secure vault.
- DLP
- Data loss prevention: tools that detect and stop sensitive data leaving approved locations.
- Security group
- A stateful virtual firewall applied to instances or interfaces.
- Network ACL
- A stateless, ordered allow and deny rule list applied at the subnet boundary.
- Stateful filtering
- Tracking connections so return traffic for an allowed connection is automatically permitted.
- WAF
- Web application firewall: a layer 7 filter that blocks attacks such as SQL injection and cross-site scripting.
- Private endpoint
- A private IP address in your virtual network that connects to a managed service without using the public internet.
- Zero trust
- A security model that trusts no user, device or network by default and verifies every request explicitly.
- Microsegmentation
- Fine-grained segmentation that controls traffic between individual workloads.
- East-west traffic
- Traffic between systems inside the same environment, as opposed to north-south traffic entering or leaving it.
- Mutual TLS
- TLS in which both client and server present certificates to authenticate each other.
- ZTNA
- Zero trust network access: giving users access to specific applications after identity and device checks, rather than whole-network VPN access.
- CVE
- Common Vulnerabilities and Exposures: a public identifier for a specific known vulnerability.
- CVSS
- Common Vulnerability Scoring System: a 0-10 score describing a vulnerability's severity.
- Credentialed scan
- A vulnerability scan that logs in to the target for a more complete view of installed software and settings.
- IaC scanning
- Analyzing infrastructure-as-code templates for insecure configurations before deployment.
- CSPM
- Cloud security posture management: continuous detection of misconfigurations and compliance gaps in cloud accounts.
- Data sovereignty
- The principle that data is subject to the laws of the country where it is located.
- Data residency
- The requirement or choice to store data in a specific geographic location.
- Policy as code
- Defining governance rules as machine-enforced policies that allow, deny or audit resource configurations.
- Guardrail
- A preventive or detective control that keeps accounts within approved configurations.
- Audit log
- A tamper-resistant record of actions performed in an environment, including who, what, when and where.
- Hardening
- Reducing attack surface by removing unnecessary components and applying secure settings.
- CIS Benchmarks
- Consensus-based secure configuration guides from the Center for Internet Security.
- Secure baseline
- An organization's approved, documented secure configuration for a type of system.
- EDR
- Endpoint detection and response: host agents that record activity, detect threats and support response actions.
- File integrity monitoring
- Detecting unauthorized changes to important system and application files.
- Containment
- Actions that stop an incident from spreading or causing more damage.
- Isolation security group
- A restrictive security group applied to a compromised instance to cut off its network access.
- Chain of custody
- Documentation of who collected, handled and stored evidence, and when, to preserve its integrity.
- Forensic snapshot
- A point-in-time copy of a compromised volume taken to preserve evidence for analysis.
- Eradication
- Removing the cause of an incident, such as malware, backdoors or the exploited vulnerability.
Domain 5: DevOps fundamentals (10%)
Exam tips
- Pull requests with branch protection provide review, automated checks and an audit trail. Tags identify releases. If a secret is committed, removing it in a new commit is not enough; rotate the secret, because it remains in history.
- CI is about building and testing every change automatically and producing a versioned artifact. Build once and promote the same artifact; do not rebuild for each environment.
- The only difference between continuous delivery and continuous deployment is the manual approval before production. If a human approves production releases, it is continuous delivery.
- Terraform is multi-provider and uses a state file; CloudFormation is AWS-only; ARM and Bicep are Azure-only. Declarative describes what; imperative describes how. Multicloud IaC in one tool points to Terraform.
- Ansible: agentless, push, YAML playbooks over SSH. Puppet and Chef: agent-based, pull from a central server. Idempotent means safe to run repeatedly with the same result.
- 401 means authentication failed (who are you?); 403 means authenticated but not allowed; 429 means rate limited, so back off and retry. Webhooks push events to you; polling asks repeatedly. YAML uses spaces for indentation, never tabs.
- Avoid latest in production; use immutable version tags or digests. Build once and promote the same image; rebuilding per environment breaks the guarantee that what you tested is what you run.
- Bash passes text; PowerShell passes objects; Python suits complex logic and SDK work. Any script answer that hard-codes access keys is wrong; use profiles, SSO or workload identities.
Key terms
- Commit
- A recorded snapshot of changes in Git, with an author, message and unique hash.
- Branch
- An independent line of development within a repository.
- Pull request
- A request to merge one branch into another, used for review and automated checks.
- Merge conflict
- A situation where two branches change the same lines and Git cannot combine them automatically.
- Tag
- A named pointer to a specific commit, typically used to mark a release version.
- Continuous integration
- Frequently merging code changes into a shared branch with automatic building and testing of each change.
- Build agent / runner
- The machine or container that executes pipeline jobs.
- Unit test
- An automated test that checks a small unit of code in isolation.
- Build artifact
- The versioned, deployable output of a build, such as a container image or package.
- Artifact repository
- A storage service for versioned build outputs, such as a package repository or container registry.
- Continuous delivery
- Every passing change is automatically prepared and deployed to pre-production; production release needs manual approval.
- Continuous deployment
- Every passing change is released to production automatically with no manual step.
- Pipeline stage
- A phase of a pipeline, such as build, test or deploy, that must succeed before the next begins.
- Approval gate
- A checkpoint that requires manual approval or automated conditions before promotion.
- Feature flag
- A setting that turns a feature on or off at runtime without redeploying code.
- Declarative
- Describing the desired end state and letting the tool determine how to reach it.
- Imperative
- Specifying the exact sequence of commands to execute.
- Terraform
- A multi-provider declarative IaC tool using HCL, providers, modules and a state file.
- CloudFormation
- AWS's native IaC service that deploys JSON or YAML templates as stacks.
- Bicep
- A domain-specific language for Azure deployments that compiles to ARM templates.
- Configuration management
- Automating and enforcing the software and settings inside servers.
- Agentless
- Managing hosts over existing protocols such as SSH or WinRM without installing software on them.
- Agent-based
- Managing hosts through a locally installed agent that pulls and applies configuration.
- Idempotency
- The property that applying an operation repeatedly gives the same result as applying it once.
- Playbook
- An Ansible YAML file that defines tasks to run against a group of hosts.
- REST API
- An HTTP-based interface where resources are addressed by URLs and manipulated with methods such as GET, POST, PUT and DELETE.
- Webhook
- An HTTP callback that a service sends to a registered URL when an event occurs.
- JSON
- A lightweight text data format of objects, arrays, strings, numbers, booleans and null.
- YAML
- A human-friendly data format using indentation for structure, common in configuration files.
- Exponential backoff
- Retrying a failed request after progressively longer waits to avoid overloading a service.
- Container image
- A layered, read-only package of an application and its dependencies used to run containers.
- Registry
- A service that stores and distributes container images.
- Image tag
- A human-readable label, such as a version, that points to a specific image.
- Image digest
- A content hash that uniquely and immutably identifies an image.
- Image promotion
- Deploying the same built image through successive environments without rebuilding it.
- CLI
- Command-line interface, such as aws, az or gcloud, for managing cloud resources from a terminal or script.
- Bash
- A Unix shell and scripting language used on Linux for command automation.
- PowerShell
- An object-based shell and scripting language whose cmdlets use Verb-Noun names.
- SDK
- Software development kit: a library for calling cloud APIs from a programming language such as Python.
- Dry run
- Running a script or command in a mode that shows what it would do without making changes.
Domain 6: Troubleshooting (12%)
Exam tips
- Know the order: identify, theory, test, plan, implement or escalate, verify and prevent, document. Questioning users and asking what changed belong to identifying the problem, which comes before forming a theory.
- Work the path in order: DNS, routes, NACLs, security groups, host firewall, application. Flow logs with REJECT entries point to a security group or NACL; no traffic at all usually points to routing or DNS.
- Explicit deny always wins, and it can come from an organization policy, a resource policy or a boundary, not just the user's own policy. Token expired or signature errors point to credentials, certificates or clock skew, not to missing permissions.
- Limit or quota exceeded: request an increase or clean up. Insufficient capacity: change zone or instance type. Image not found in a new region: copy the image, because image IDs are usually regional.
- A metric flat-lining at an exact value, such as IOPS at the provisioned number, is a sign of throttling at a limit. HTTP 429 means rate limited: back off and retry. Burstable instances that slow down after a busy period have likely exhausted CPU credits.
- Cost questions usually point to one of three causes: orphaned resources (unattached volumes, idle IPs, old snapshots), egress (data leaving the cloud or crossing regions) or runaway scaling (no sensible maximum). Budgets and anomaly detection catch them early.
- Metrics show when and where, logs show what, traces show where in the request chain, audit logs show what changed, and health dashboards show whether it is the provider. Always ask what changed just before the problem began.
- Worked yesterday, fails today with no code change: think expired token or certificate, or an unpinned dependency or tool that updated. 401 errors point to credentials; unexpected behavior after an update points to version mismatch.
Key terms
- Scope
- How widely a problem is felt: one resource, a zone, a region or all users.
- Theory of probable cause
- A hypothesis about what is causing the problem, to be tested.
- Escalation
- Passing a problem to a person or team with more authority, access or expertise, including the provider.
- Change management
- The process of reviewing, approving and scheduling changes to reduce risk.
- Post-incident review
- A blameless analysis after an incident that records the cause and improvements.
- Flow logs
- Records of network traffic metadata, including whether each flow was accepted or rejected.
- Ephemeral ports
- Temporary high-numbered ports used by clients for the return side of connections.
- Resolver forwarding rule
- A DNS rule that sends queries for certain domains to a specific DNS server, used in hybrid setups.
- Reachability analyzer
- A provider tool that analyzes configured routes and rules to explain whether a path is reachable.
- Overlapping CIDR
- Two networks using the same or intersecting address ranges, which prevents routing between them.
- Implicit deny
- The default result when no policy explicitly allows a request.
- Explicit deny
- A deny statement in any applicable policy, which overrides all allows.
- Permission boundary
- A policy that sets the maximum permissions an identity can have, regardless of what other policies allow.
- Service control policy
- An organization-level guardrail that limits what accounts in the organization can do.
- Clock skew
- A difference between a system's clock and real time that can make signed requests or tokens appear invalid.
- Service quota
- A limit on the number or rate of resources an account can use, often adjustable on request.
- Hard limit
- A service limit that cannot be increased.
- Insufficient capacity
- A provider-side shortage of a resource type in a location, unrelated to your quota.
- Template validation
- Checking IaC syntax and structure before deployment.
- Image pull error
- A failure to download a container image, often due to a wrong tag, missing credentials or network issues.
- Bottleneck
- The single component whose capacity limits the performance of the whole system.
- CPU steal time
- Time a virtual CPU waits because the hypervisor is serving other guests.
- Throttling
- Deliberate limiting of requests or throughput by a service when limits are exceeded.
- Rate limit
- The maximum number of API requests allowed in a period.
- p95 / p99 latency
- The latency below which 95 or 99 percent of requests complete, showing the experience of slower requests.
- Orphaned resource
- A resource left running or stored after the thing that used it is gone, still generating charges.
- Data egress
- Data transferred out of a provider's network or between regions, which is usually billed.
- Cost anomaly detection
- A service that learns normal spending patterns and alerts on unusual changes.
- Budget alert
- A notification when actual or forecast spend crosses a set threshold.
- Runaway scaling
- Uncontrolled growth in instances or invocations caused by misconfiguration, bugs or attacks.
- Root cause
- The underlying reason a problem occurred, which, if fixed, prevents it from recurring.
- Control plane audit log
- A log of management API actions, recording who changed what and when.
- Provider health dashboard
- A provider's view of service incidents and events affecting your resources.
- Timeline
- An ordered record of events and changes used to connect causes to effects during analysis.
- 5 whys
- A root cause technique of repeatedly asking why until the underlying cause is reached.
- Pipeline
- An automated sequence of build, test and deployment stages.
- Personal access token
- A long-lived token tied to a user, often used by scripts, which can expire or leave with the user.
- Workload identity federation
- Exchanging an external workload's token for short-lived cloud credentials without stored secrets.
- Version pinning
- Specifying exact versions of dependencies and tools so builds are reproducible.
- Lock file
- A file recording the exact dependency versions used, so every build installs the same ones.
Study Cloud+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Cloud+ study planLessons, quizzes, exam simulations and hands-on labs.