StudyToCert

All certifications / Cloud+ / Cheat sheet

Cloud+ CV0-004 cheat sheet

Every exam tip and key term from the free Cloud+ lessons, by domain. Use your browser's Print to save it as a PDF.

Domain 1: Cloud architecture (23%)

Exam tips

Key terms

IaaS
Infrastructure as a service: the provider supplies virtual compute, storage and networking, and the customer manages the operating system and everything above it.
PaaS
Platform as a service: the provider also runs the operating system and runtime, so the customer deploys and manages only application code and data.
SaaS
Software as a service: a complete application delivered over the internet; the customer manages users, settings and data.
FaaS
Function as a service: event-driven code that runs on demand without servers for the customer to manage, billed per execution.
Shared responsibility model
The division of security and operational duties between provider and customer, which shifts with the service model.
Public cloud
Cloud infrastructure owned by a provider and shared by many tenants, consumed on demand over the internet.
Private cloud
Cloud infrastructure dedicated to one organization, on premises or hosted, that still offers self-service and elasticity.
Hybrid cloud
A combination of private or on-premises infrastructure and public cloud, connected so workloads can interoperate.
Community cloud
Cloud infrastructure shared by several organizations with common mission, security or compliance needs.
Multicloud
Using services from more than one public cloud provider.
Cloud bursting
Sending overflow demand from a private environment to a public cloud when local capacity runs out.
Region
A geographic area containing multiple isolated data center groups where a provider offers its services.
Availability zone
An isolated location within a region with independent power, cooling and networking, used to survive data center failures.
Edge location
A provider point of presence close to users, used for CDN caching, DNS and edge services rather than general compute.
Single point of failure
Any component whose failure stops the whole system.
High availability
A design that keeps a service running through component failures, usually through redundancy and automatic failover.
Type 1 hypervisor
A bare-metal hypervisor that runs directly on hardware; used by cloud providers.
Type 2 hypervisor
A hosted hypervisor that runs as an application on a general-purpose operating system.
Instance family
A group of VM sizes tuned for a workload profile, such as general purpose, compute-, memory- or storage-optimized, or GPU.
Dedicated host
A physical server reserved for one customer, giving visibility of sockets and cores for licensing and isolation.
Multitenancy
Many customers sharing the same physical infrastructure while being logically isolated from one another.
Container
A lightweight package of an application and its dependencies that shares the host operating system kernel.
Orchestration
Automated scheduling, scaling, healing and updating of containers across a cluster of hosts, for example with Kubernetes.
Pod
The smallest deployable unit in Kubernetes: one or more containers sharing network and storage.
Cold start
Extra latency when a serverless platform must create a new execution environment before running a function.
Serverless
A model where the provider runs code on demand in response to events, scaling automatically and billing per use.
Microservice
A small, independently deployable service that owns one business capability and communicates through APIs.
Message queue
A buffer that stores messages until a consumer processes them, decoupling senders from receivers.
Pub/sub
A messaging pattern where a published message is delivered to every subscriber of a topic.
Dead-letter queue
A queue that holds messages that could not be processed after a set number of attempts.
API gateway
A managed entry point that routes API requests to back-end services and handles authentication, throttling and monitoring.
Block storage
Raw volumes attached to an instance and formatted with a file system; low latency, used for boot disks and databases.
File storage
A shared, network-mounted file system (NFS or SMB) that many clients can use at once.
Object storage
Storage of objects with keys and metadata in buckets, accessed through HTTP APIs; highly durable and scalable.
IOPS
Input/output operations per second: the rate of individual read and write operations a storage device can handle.
Throughput
The amount of data transferred per second, typically measured in MB/s.
VPC / VNet
A logically isolated private network in a public cloud, defined by one or more CIDR ranges.
CIDR
Notation that writes an IP range as address/prefix length, such as 10.0.1.0/24.
Route table
A set of rules that tells traffic from a subnet which next hop to use for each destination range.
Internet gateway
A component that gives a virtual network two-way internet connectivity for resources with public IP addresses.
NAT gateway
A managed service that lets instances in private subnets start outbound internet connections while blocking unsolicited inbound ones.
Site-to-site VPN
An encrypted IPsec tunnel over the internet that connects an entire on-premises network to a cloud network.
Dedicated interconnect
A private physical link between a customer network and a cloud provider that bypasses the public internet.
VPC peering
A private connection between two virtual networks that lets them communicate with private IP addresses; typically not transitive.
Transit hub
A central router service that connects many virtual networks and on-premises links in a hub-and-spoke topology.
BGP
Border Gateway Protocol, used to exchange routes dynamically over VPN and interconnect links.
Layer 4 load balancer
A load balancer that forwards TCP or UDP connections based on addresses and ports without inspecting application data.
Layer 7 load balancer
An HTTP(S)-aware load balancer that can route by host or path, terminate TLS and use cookies.
Health check
A periodic probe used to decide whether a target should receive traffic.
TTL
Time to live: how long a DNS answer or cached object may be reused before it must be refreshed.
CDN
Content delivery network: a distributed cache at edge locations that serves content from close to the user.
RPO
Recovery point objective: the maximum acceptable data loss, expressed as time before the incident.
RTO
Recovery time objective: the maximum acceptable time to restore service after an incident.
Pilot light
A DR pattern that keeps only core components such as the database running in the recovery site, ready to be scaled up.
Warm standby
A DR pattern with a smaller, always-running copy of the full environment that is scaled up during failover.
Active-active
A multisite design in which all sites serve production traffic at the same time.
On-demand
Pay-as-you-go pricing with no commitment, charged per second or hour of use.
Reserved or committed use
A discount in exchange for committing to a level of usage for a one- or three-year term.
Spot instance
Discounted spare capacity that the provider can reclaim at short notice.
Showback
Reporting cloud costs to the teams that caused them without actually billing them.
Chargeback
Billing cloud costs back to the department or cost center that incurred them.

Domain 2: Deployment (19%)

Exam tips

Key terms

Blue-green deployment
Running two identical environments and switching traffic from the old (blue) to the new (green) all at once, with instant switch-back for rollback.
Canary release
Sending a small percentage of traffic to a new version and increasing it gradually while monitoring health.
Rolling deployment
Updating servers in batches so the service stays available throughout the release.
A/B testing
Routing user groups to different versions to compare user behavior or business metrics.
Rollback plan
Predefined triggers and steps for returning to the previous version if a release fails.
Rehost
Lift and shift: moving an application to the cloud without changing it.
Replatform
Moving with small optimizations, such as switching to a managed database, without changing the core architecture.
Refactor
Re-architecting an application to use cloud-native services and patterns.
Repurchase
Replacing an application with a different product, often SaaS.
Retire / retain
Decommissioning an application that is no longer needed, or deliberately leaving it where it is for now.
Discovery
Collecting an inventory and utilization data for the systems that may be migrated.
Dependency mapping
Identifying which systems communicate with or rely on each other so they can be migrated together.
Migration wave
A scheduled group of applications migrated together.
Pilot wave
An initial small, low-risk wave used to prove the process and tools.
Cutover
The point at which production traffic and data switch from the old environment to the new one.
Online transfer
Moving data to the cloud over a network connection such as the internet, VPN or interconnect.
Transfer appliance
A secure physical storage device shipped by the provider for bulk offline data transfer.
Change data capture
Capturing ongoing changes from a database's transaction log and replicating them to a target.
Homogeneous migration
A database migration between the same engine type.
Heterogeneous migration
A database migration between different engines, requiring schema and code conversion.
Image
A template containing an operating system and optional software, used to launch virtual machines.
Golden image
An organization-approved, patched and hardened image used as the standard starting point for new instances.
Launch template
A saved set of instance settings, including image, size, network and startup script, used for consistent launches.
User data / cloud-init
A startup script or configuration passed to an instance and run at first boot.
Burstable instance
An instance type that accrues CPU credits during idle periods and spends them to burst above its baseline.
Thick provisioning
Allocating a volume's full capacity on the underlying storage when it is created.
Thin provisioning
Allocating storage only as data is written, allowing overcommitment of capacity.
Provisioned IOPS
A volume option where you specify the performance level the volume must deliver.
Synchronous replication
Writing data to both copies before acknowledging, for zero data loss at the cost of latency.
Ephemeral storage
Temporary local storage attached to an instance that is lost when the instance stops or is terminated.
Managed database
A database service where the provider handles installation, patching, backups and failover.
Read replica
An asynchronously updated, read-only copy of a database used to scale reads.
Multi-AZ standby
A synchronously replicated database copy in another zone used for automatic failover, not for reads.
Cache-aside
A pattern where the application reads from the cache first and loads from the database on a miss.
Managed Kubernetes
A service where the provider operates the Kubernetes control plane while you manage workloads and usually the worker nodes.
Infrastructure as code
Defining and managing infrastructure through machine-readable files under version control.
Template
A file describing the resources to deploy and their configuration.
Parameter
An input value that lets one template deploy different environments or sizes.
State
The record an IaC tool keeps of the resources it manages and their real identifiers.
Drift
Differences between deployed resources and the configuration defined in code, usually from manual changes.
Immutable infrastructure
Infrastructure that is never changed after deployment; updates are made by replacing it with new instances.
Configuration drift
Gradual, undocumented differences between servers that should be identical.
Staging
A production-like environment used for final validation before release.
Environment promotion
Moving the same tested artifact from one environment to the next.
Data masking
Replacing sensitive values with realistic but fake data for use in non-production environments.
Smoke test
A quick check of critical functions right after deployment to confirm the system basically works.
Health check
A recurring probe used by load balancers or orchestrators to decide whether an instance is healthy.
Performance baseline
A recorded measure of normal performance used to detect regressions.
Readiness probe
A Kubernetes check that decides whether a pod should receive traffic.
Runbook
Documented step-by-step procedures for operating or troubleshooting a system.

Domain 3: Operations (17%)

Exam tips

Key terms

Metric
A numeric measurement recorded over time, such as CPU utilization or request latency.
Log
A timestamped record of a discrete event, often with detailed context.
Trace
A record of one request's path through multiple services, made up of timed spans.
Alert threshold
The value and duration at which a metric triggers a notification.
Alert fatigue
Desensitization caused by too many non-actionable alerts, leading to real ones being missed.
Log aggregation
Collecting logs from many sources into one central, searchable system.
Retention policy
Rules for how long each type of log or data is kept and where.
Correlation ID
A unique identifier passed along with a request so its log entries can be linked across services.
Synthetic monitoring
Scripted, scheduled tests that simulate user actions to check availability and performance.
Real user monitoring
Measuring performance and errors experienced by actual users of an application.
Vertical scaling
Increasing the resources of a single server, such as moving to a larger instance size.
Horizontal scaling
Adding or removing instances to share the workload.
Target tracking
An autoscaling policy that adjusts capacity to keep a metric near a target value.
Step scaling
An autoscaling policy that adds or removes set amounts of capacity depending on how far a metric passes a threshold.
Cooldown
A waiting period after a scaling action that prevents further actions until new capacity has taken effect.
Full backup
A complete copy of all selected data.
Incremental backup
A backup of data changed since the last backup of any type.
Differential backup
A backup of all data changed since the last full backup.
Snapshot
A point-in-time copy of a volume, VM or database, often stored incrementally at the block level.
3-2-1 rule
Keep three copies of data on two different media, with one copy offsite.
Restore test
A planned recovery from backup to confirm that data is complete and recovery meets the RTO.
Immutable backup
A backup that cannot be modified or deleted until its retention period expires.
WORM
Write once, read many: storage that allows data to be written once and prevents later changes.
Cross-account backup
A backup copy stored in a separate account with separate credentials and administrators.
Air gap
Isolation of a backup copy from networks and normal credentials so an attacker cannot reach it.
Patch baseline
The defined set of patches, by classification and severity, that instances must have installed to be compliant.
Maintenance window
A scheduled period when updates and changes may be applied with minimal impact.
Image pipeline
An automated process that builds, tests and publishes updated machine or container images.
Base image
The starting image, such as an OS or language runtime image, on which application images are built.
Emergency change
An expedited change process for urgent fixes, reviewed after implementation.
Deprecation
A provider's announcement that a feature, version or resource type will no longer be supported after a certain date.
End of support
The date after which a product no longer receives updates or security fixes.
Major version upgrade
An upgrade that can change behavior or compatibility and requires testing and planning.
Decommissioning
Retiring a resource safely, including removing its dependent resources, access and records.
CMDB
Configuration management database: an inventory of IT assets and their relationships.
Right-sizing
Adjusting resource size and type to match actual measured demand.
Capacity planning
Forecasting future resource needs from trends and business plans.
Lifecycle policy
Rules that automatically move data between storage tiers or delete it as it ages.
Minimum storage duration
A billing rule in cooler tiers that charges for a minimum period even if data is deleted sooner.
Retrieval fee
A charge for reading data from infrequent-access or archive storage tiers.
SLI
Service level indicator: a measured value of service behavior, such as success rate or latency.
SLO
Service level objective: the internal target value for an SLI over a period.
SLA
Service level agreement: a contractual commitment to a service level, usually with service credits if missed.
Error budget
The amount of unreliability an SLO allows, equal to 100 percent minus the SLO.
Service credit
A partial refund or billing credit given when a provider misses its SLA.
Scheduled start/stop
Automatically stopping resources outside working hours and starting them when needed to save cost.
Runbook
A documented procedure for a routine operation or known issue.
Runbook automation
Executing runbook steps as code, triggered manually, on a schedule or by events.
Self-healing
Automatic detection and repair of failures, such as replacing unhealthy instances.
Event-driven automation
Automation triggered by an event or alarm rather than by a schedule or a person.

Domain 4: Security (19%)

Exam tips

Key terms

IAM
Identity and access management: the service and practices that control authentication and authorization to cloud resources.
Role
A set of permissions that a user, service or application can assume, receiving temporary credentials.
Policy
A document that allows or denies specific actions on specific resources, optionally under conditions.
Least privilege
Granting only the minimum permissions required, for the minimum time.
Separation of duties
Splitting sensitive tasks among different people so no one can misuse them alone.
Identity provider (IdP)
The system that authenticates users and issues assertions or tokens that other services trust.
Federation
A trust relationship that lets users authenticated by one identity provider access other services.
SAML 2.0
An XML-based standard for exchanging signed authentication assertions, common in enterprise web SSO.
OpenID Connect
An authentication layer on OAuth 2.0 that uses JSON Web Tokens as ID tokens.
Break-glass account
A tightly controlled emergency administrator account used only when normal access fails.
Workload identity
An identity assigned to an application or resource rather than a person, used to access other services.
Instance profile / instance role
A way of attaching an IAM role to a VM so software on it receives temporary credentials.
Managed identity
An Azure identity for a resource, managed by the platform, that obtains tokens without stored secrets.
Service account
A non-human account used by applications and services, notably in Google Cloud and Kubernetes.
Instance metadata service
A local endpoint on a VM that provides configuration and temporary credentials to software running on it.
KMS
Key management service: a managed service that creates, stores and uses encryption keys under access policies.
HSM
Hardware security module: tamper-resistant hardware for generating, storing and using cryptographic keys.
Customer-managed key
A key the customer controls in KMS, including its policy, rotation and deletion.
Envelope encryption
Encrypting data with a data key and encrypting that data key with a master key.
Secrets manager
A service that stores, controls access to and rotates application secrets.
Data classification
Labeling data by sensitivity or regulatory type to decide how it must be protected.
Encryption at rest
Encrypting stored data on disks, databases, object storage and backups.
Encryption in transit
Encrypting data as it moves across networks, usually with TLS, SSH or IPsec.
Tokenization
Replacing sensitive data with a non-sensitive token, keeping the original in a secure vault.
DLP
Data loss prevention: tools that detect and stop sensitive data leaving approved locations.
Security group
A stateful virtual firewall applied to instances or interfaces.
Network ACL
A stateless, ordered allow and deny rule list applied at the subnet boundary.
Stateful filtering
Tracking connections so return traffic for an allowed connection is automatically permitted.
WAF
Web application firewall: a layer 7 filter that blocks attacks such as SQL injection and cross-site scripting.
Private endpoint
A private IP address in your virtual network that connects to a managed service without using the public internet.
Zero trust
A security model that trusts no user, device or network by default and verifies every request explicitly.
Microsegmentation
Fine-grained segmentation that controls traffic between individual workloads.
East-west traffic
Traffic between systems inside the same environment, as opposed to north-south traffic entering or leaving it.
Mutual TLS
TLS in which both client and server present certificates to authenticate each other.
ZTNA
Zero trust network access: giving users access to specific applications after identity and device checks, rather than whole-network VPN access.
CVE
Common Vulnerabilities and Exposures: a public identifier for a specific known vulnerability.
CVSS
Common Vulnerability Scoring System: a 0-10 score describing a vulnerability's severity.
Credentialed scan
A vulnerability scan that logs in to the target for a more complete view of installed software and settings.
IaC scanning
Analyzing infrastructure-as-code templates for insecure configurations before deployment.
CSPM
Cloud security posture management: continuous detection of misconfigurations and compliance gaps in cloud accounts.
Data sovereignty
The principle that data is subject to the laws of the country where it is located.
Data residency
The requirement or choice to store data in a specific geographic location.
Policy as code
Defining governance rules as machine-enforced policies that allow, deny or audit resource configurations.
Guardrail
A preventive or detective control that keeps accounts within approved configurations.
Audit log
A tamper-resistant record of actions performed in an environment, including who, what, when and where.
Hardening
Reducing attack surface by removing unnecessary components and applying secure settings.
CIS Benchmarks
Consensus-based secure configuration guides from the Center for Internet Security.
Secure baseline
An organization's approved, documented secure configuration for a type of system.
EDR
Endpoint detection and response: host agents that record activity, detect threats and support response actions.
File integrity monitoring
Detecting unauthorized changes to important system and application files.
Containment
Actions that stop an incident from spreading or causing more damage.
Isolation security group
A restrictive security group applied to a compromised instance to cut off its network access.
Chain of custody
Documentation of who collected, handled and stored evidence, and when, to preserve its integrity.
Forensic snapshot
A point-in-time copy of a compromised volume taken to preserve evidence for analysis.
Eradication
Removing the cause of an incident, such as malware, backdoors or the exploited vulnerability.

Domain 5: DevOps fundamentals (10%)

Exam tips

Key terms

Commit
A recorded snapshot of changes in Git, with an author, message and unique hash.
Branch
An independent line of development within a repository.
Pull request
A request to merge one branch into another, used for review and automated checks.
Merge conflict
A situation where two branches change the same lines and Git cannot combine them automatically.
Tag
A named pointer to a specific commit, typically used to mark a release version.
Continuous integration
Frequently merging code changes into a shared branch with automatic building and testing of each change.
Build agent / runner
The machine or container that executes pipeline jobs.
Unit test
An automated test that checks a small unit of code in isolation.
Build artifact
The versioned, deployable output of a build, such as a container image or package.
Artifact repository
A storage service for versioned build outputs, such as a package repository or container registry.
Continuous delivery
Every passing change is automatically prepared and deployed to pre-production; production release needs manual approval.
Continuous deployment
Every passing change is released to production automatically with no manual step.
Pipeline stage
A phase of a pipeline, such as build, test or deploy, that must succeed before the next begins.
Approval gate
A checkpoint that requires manual approval or automated conditions before promotion.
Feature flag
A setting that turns a feature on or off at runtime without redeploying code.
Declarative
Describing the desired end state and letting the tool determine how to reach it.
Imperative
Specifying the exact sequence of commands to execute.
Terraform
A multi-provider declarative IaC tool using HCL, providers, modules and a state file.
CloudFormation
AWS's native IaC service that deploys JSON or YAML templates as stacks.
Bicep
A domain-specific language for Azure deployments that compiles to ARM templates.
Configuration management
Automating and enforcing the software and settings inside servers.
Agentless
Managing hosts over existing protocols such as SSH or WinRM without installing software on them.
Agent-based
Managing hosts through a locally installed agent that pulls and applies configuration.
Idempotency
The property that applying an operation repeatedly gives the same result as applying it once.
Playbook
An Ansible YAML file that defines tasks to run against a group of hosts.
REST API
An HTTP-based interface where resources are addressed by URLs and manipulated with methods such as GET, POST, PUT and DELETE.
Webhook
An HTTP callback that a service sends to a registered URL when an event occurs.
JSON
A lightweight text data format of objects, arrays, strings, numbers, booleans and null.
YAML
A human-friendly data format using indentation for structure, common in configuration files.
Exponential backoff
Retrying a failed request after progressively longer waits to avoid overloading a service.
Container image
A layered, read-only package of an application and its dependencies used to run containers.
Registry
A service that stores and distributes container images.
Image tag
A human-readable label, such as a version, that points to a specific image.
Image digest
A content hash that uniquely and immutably identifies an image.
Image promotion
Deploying the same built image through successive environments without rebuilding it.
CLI
Command-line interface, such as aws, az or gcloud, for managing cloud resources from a terminal or script.
Bash
A Unix shell and scripting language used on Linux for command automation.
PowerShell
An object-based shell and scripting language whose cmdlets use Verb-Noun names.
SDK
Software development kit: a library for calling cloud APIs from a programming language such as Python.
Dry run
Running a script or command in a mode that shows what it would do without making changes.

Domain 6: Troubleshooting (12%)

Exam tips

Key terms

Scope
How widely a problem is felt: one resource, a zone, a region or all users.
Theory of probable cause
A hypothesis about what is causing the problem, to be tested.
Escalation
Passing a problem to a person or team with more authority, access or expertise, including the provider.
Change management
The process of reviewing, approving and scheduling changes to reduce risk.
Post-incident review
A blameless analysis after an incident that records the cause and improvements.
Flow logs
Records of network traffic metadata, including whether each flow was accepted or rejected.
Ephemeral ports
Temporary high-numbered ports used by clients for the return side of connections.
Resolver forwarding rule
A DNS rule that sends queries for certain domains to a specific DNS server, used in hybrid setups.
Reachability analyzer
A provider tool that analyzes configured routes and rules to explain whether a path is reachable.
Overlapping CIDR
Two networks using the same or intersecting address ranges, which prevents routing between them.
Implicit deny
The default result when no policy explicitly allows a request.
Explicit deny
A deny statement in any applicable policy, which overrides all allows.
Permission boundary
A policy that sets the maximum permissions an identity can have, regardless of what other policies allow.
Service control policy
An organization-level guardrail that limits what accounts in the organization can do.
Clock skew
A difference between a system's clock and real time that can make signed requests or tokens appear invalid.
Service quota
A limit on the number or rate of resources an account can use, often adjustable on request.
Hard limit
A service limit that cannot be increased.
Insufficient capacity
A provider-side shortage of a resource type in a location, unrelated to your quota.
Template validation
Checking IaC syntax and structure before deployment.
Image pull error
A failure to download a container image, often due to a wrong tag, missing credentials or network issues.
Bottleneck
The single component whose capacity limits the performance of the whole system.
CPU steal time
Time a virtual CPU waits because the hypervisor is serving other guests.
Throttling
Deliberate limiting of requests or throughput by a service when limits are exceeded.
Rate limit
The maximum number of API requests allowed in a period.
p95 / p99 latency
The latency below which 95 or 99 percent of requests complete, showing the experience of slower requests.
Orphaned resource
A resource left running or stored after the thing that used it is gone, still generating charges.
Data egress
Data transferred out of a provider's network or between regions, which is usually billed.
Cost anomaly detection
A service that learns normal spending patterns and alerts on unusual changes.
Budget alert
A notification when actual or forecast spend crosses a set threshold.
Runaway scaling
Uncontrolled growth in instances or invocations caused by misconfiguration, bugs or attacks.
Root cause
The underlying reason a problem occurred, which, if fixed, prevents it from recurring.
Control plane audit log
A log of management API actions, recording who changed what and when.
Provider health dashboard
A provider's view of service incidents and events affecting your resources.
Timeline
An ordered record of events and changes used to connect causes to effects during analysis.
5 whys
A root cause technique of repeatedly asking why until the underlying cause is reached.
Pipeline
An automated sequence of build, test and deployment stages.
Personal access token
A long-lived token tied to a user, often used by scripts, which can expire or leave with the user.
Workload identity federation
Exchanging an external workload's token for short-lived cloud credentials without stored secrets.
Version pinning
Specifying exact versions of dependencies and tools so builds are reproducible.
Lock file
A file recording the exact dependency versions used, so every build installs the same ones.
Study Cloud+ for free
Lessons, quizzes, exam simulations and hands-on labs.
Open the Cloud+ study plan