All certifications / Cloud+ / Lessons
Cloud+ CV0-004 lessons
Study Cloud+ for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the Cloud+ study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Cloud architecture
- Cloud service models (IaaS, PaaS, SaaS, FaaS) and the shared responsibility model
- Deployment models: public, private, hybrid, community and multicloud
- Regions, availability zones, edge locations and designing for high availability
- Virtualization and compute: hypervisors, instance families, dedicated hosts and multitenancy
- Containers, orchestration and serverless compared with virtual machines
- Microservices, event-driven architecture, message queues and API gateways
- Cloud storage types: block, file and object; storage tiers and performance (IOPS, throughput)
- Virtual networks: VPC/VNet design, CIDR planning, subnets, route tables, NAT and internet gateways
- Hybrid connectivity: site-to-site VPN, dedicated interconnects, peering and transit hubs
- Load balancing, DNS routing and content delivery networks
- Disaster recovery architectures: backup and restore, pilot light, warm standby, multisite active-active; RPO and RTO
- Cloud cost models: on-demand, reserved and committed use, spot, tagging for showback and chargeback
Domain 2: Deployment
- Deployment strategies: blue-green, canary, rolling, in-place and A/B releases, with rollback plans
- Migration strategies: rehost, replatform, refactor, repurchase, retire and retain
- Migration planning: discovery, dependency mapping, pilot waves, cutover and validation
- Online vs offline data transfer, transfer appliances and database migration with minimal downtime
- Provisioning compute: choosing instance size and type, images and templates, golden images
- Provisioning storage: volume types, thin vs thick provisioning, replication and encryption settings
- Deploying managed services: managed databases, read replicas, caches and managed Kubernetes
- Infrastructure as code for deployment: templates, parameters, state and repeatable environments
- Immutable infrastructure and environment separation: development, test, staging and production
- Post-deployment validation: smoke tests, health checks, performance baselines and documentation
Domain 3: Operations
- Observability: metrics, logs and traces; dashboards, baselines and alert thresholds
- Log aggregation, retention and synthetic monitoring for user-facing services
- Scaling: horizontal vs vertical, autoscaling policies (target tracking, scheduled, step) and cooldowns
- Backup types (full, incremental, differential, snapshots), retention and the 3-2-1 rule
- Restore testing, immutable and cross-account backups, and protecting backups from ransomware
- Patch and update management for VMs, images, containers and managed services
- Resource lifecycle: provider deprecations, version upgrades, end of support and decommissioning
- Right-sizing, capacity planning and storage lifecycle policies to control cost
- Service level agreements, SLOs and availability math (99.9% vs 99.99%)
- Operational automation: scheduled start and stop, runbooks and self-healing
Domain 4: Security
- Identity and access management: users, groups, roles, policies and least privilege
- Federation and single sign-on (SAML, OpenID Connect), MFA and protecting the root or global admin account
- Workload identities: instance roles, managed identities and service accounts instead of stored keys
- Secrets and key management: KMS, HSMs, customer-managed keys, rotation and secrets managers
- Data protection: encryption at rest and in transit, tokenization, data classification and DLP
- Network security controls: security groups vs network ACLs, WAF, DDoS protection and private endpoints
- Zero trust and segmentation for cloud workloads
- Vulnerability management: scanning hosts, container images and IaC; CSPM for misconfigurations
- Compliance and governance: data sovereignty, regulatory frameworks, policy enforcement and audit logs
- Hardening: CIS benchmarks, secure baselines, disabling unused services and endpoint protection
- Cloud incident response: containment, evidence preservation with snapshots and logs, and recovery
Domain 5: DevOps fundamentals
- Source control with Git: branches, pull requests, merges and tagging releases
- Continuous integration: automated builds, unit tests and artifact creation
- Continuous delivery vs continuous deployment, approval gates and pipeline stages
- Infrastructure as code tools: declarative vs imperative, Terraform, CloudFormation, ARM/Bicep
- Configuration management: Ansible, Puppet and Chef; agent vs agentless; idempotency
- APIs, webhooks and data formats (JSON, YAML) for cloud automation
- Container images, registries, tagging and promoting one build through environments
- Scripting for cloud administration: CLI tools, Bash, PowerShell and Python
Domain 6: Troubleshooting
- The troubleshooting methodology applied to cloud incidents
- Network troubleshooting: routes, security groups, NACLs, DNS, NAT and peering problems
- Access and permission failures: policy evaluation, explicit deny, expired credentials and certificates
- Deployment failures: quotas and service limits, template errors, capacity and image problems
- Performance problems: resource contention, throttling and API rate limits, latency and bottlenecks
- Cost and billing anomalies: orphaned resources, data egress charges and runaway autoscaling
- Using logs, metrics, traces and provider health dashboards to find root cause
- Automation and integration failures: broken pipelines, expired tokens, version and dependency mismatches