CompTIA Network+ N10-009 Cloud Concepts And Connectivity Practice Test
Objective 1.3 • 20 original questions
This CompTIA Network+ N10-009 practice test focuses on cloud concepts and connectivity. All questions are original ExamSnap scenarios aligned to the current N10-009 blueprint; they are not copied from CompTIA exam content. Use the complete N10-009 collection for broader practice across all five domains. For broader exam preparation, review the CompTIA Network+ N10-009 Exam Dumps page.
Instructions: Select the best answer for each question. Review the explanation after answering; each distractor includes a reason it is not the best choice for that scenario.
At Litware Manufacturing, a systems administrator is reviewing a network change. The requirement is to deploy network functions as software instances instead of purpose-built hardware. Which option is the best fit? The decision applies to a branch-office rollout.
Correct answer: D
Why: Implements network functions such as routing or firewalls as software rather than dedicated appliances. This directly satisfies the requirement: deploy network functions as software instances instead of purpose-built hardware.
Option review:
A: Consumes compute, storage, and networking while the customer manages OS and applications. However, it does not most directly satisfy the requirement in this scenario: deploy network functions as software instances instead of purpose-built hardware.
B: Lets private cloud workloads initiate outbound internet access without accepting unsolicited inbound sessions. However, it does not most directly satisfy the requirement in this scenario: deploy network functions as software instances instead of purpose-built hardware.
C: Applies subnet-level packet-filtering rules in cloud environments that support security lists. However, it does not most directly satisfy the requirement in this scenario: deploy network functions as software instances instead of purpose-built hardware.
D: Implements network functions such as routing or firewalls as software rather than dedicated appliances. This directly satisfies the requirement: deploy network functions as software instances instead of purpose-built hardware.
E: Uses a private provider connection such as Direct Connect/ExpressRoute rather than the public internet. However, it does not most directly satisfy the requirement in this scenario: deploy network functions as software instances instead of purpose-built hardware.
Learning point: Use Network functions virtualization (NFV) when the key requirement is to deploy network functions as software instances instead of purpose-built hardware.
A ticket at Woodgrove Bank says the team must create an isolated cloud network with subnets, routing, and security controls. Which technology or concept most directly addresses this requirement? The decision applies to a campus refresh.
Correct answer: C
Why: Provides a logically isolated virtual network inside a public cloud provider. This directly satisfies the requirement: create an isolated cloud network with subnets, routing, and security controls.
Option review:
A: Provides a path between a cloud VPC/VNet and the public internet for appropriately routed resources. However, it does not most directly satisfy the requirement in this scenario: create an isolated cloud network with subnets, routing, and security controls.
B: Consumes an application platform/runtime while the provider manages lower infrastructure layers. However, it does not most directly satisfy the requirement in this scenario: create an isolated cloud network with subnets, routing, and security controls.
C: Provides a logically isolated virtual network inside a public cloud provider. This directly satisfies the requirement: create an isolated cloud network with subnets, routing, and security controls.
D: Automatically expands or contracts resources in response to changing demand. However, it does not most directly satisfy the requirement in this scenario: create an isolated cloud network with subnets, routing, and security controls.
E: Consumes compute, storage, and networking while the customer manages OS and applications. However, it does not most directly satisfy the requirement in this scenario: create an isolated cloud network with subnets, routing, and security controls.
Learning point: Use Virtual private cloud (VPC) when the key requirement is to create an isolated cloud network with subnets, routing, and security controls.
During a design meeting at Blue Yonder Airlines, the junior network administrator needs to control permitted traffic to or from individual cloud workloads or interfaces. What should be selected? The decision applies to a data-center segment.
Correct answer: C
Why: Applies instance or interface-level filtering rules to cloud workloads, depending on platform. This directly satisfies the requirement: control permitted traffic to or from individual cloud workloads or interfaces.
Option review:
A: Lets private cloud workloads initiate outbound internet access without accepting unsolicited inbound sessions. However, it does not most directly satisfy the requirement in this scenario: control permitted traffic to or from individual cloud workloads or interfaces.
B: Automatically expands or contracts resources in response to changing demand. However, it does not most directly satisfy the requirement in this scenario: control permitted traffic to or from individual cloud workloads or interfaces.
C: Applies instance or interface-level filtering rules to cloud workloads, depending on platform. This directly satisfies the requirement: control permitted traffic to or from individual cloud workloads or interfaces.
D: Uses encrypted tunnels over the internet to connect an on-premises network to a cloud network. However, it does not most directly satisfy the requirement in this scenario: control permitted traffic to or from individual cloud workloads or interfaces.
E: Supports increasing workload capacity by adding or enlarging resources. However, it does not most directly satisfy the requirement in this scenario: control permitted traffic to or from individual cloud workloads or interfaces.
Learning point: Use Network security group when the key requirement is to control permitted traffic to or from individual cloud workloads or interfaces.
Contoso Health is updating its network standard. Which option best meets the need to enforce subnet-oriented cloud filtering rules? The decision applies to a remote-site migration.
Correct answer: A
Why: Applies subnet-level packet-filtering rules in cloud environments that support security lists. This directly satisfies the requirement: enforce subnet-oriented cloud filtering rules.
Option review:
A: Applies subnet-level packet-filtering rules in cloud environments that support security lists. This directly satisfies the requirement: enforce subnet-oriented cloud filtering rules.
B: Supports increasing workload capacity by adding or enlarging resources. However, it does not most directly satisfy the requirement in this scenario: enforce subnet-oriented cloud filtering rules.
C: Cloud infrastructure is operated by a provider and shared across customers with logical isolation. However, it does not most directly satisfy the requirement in this scenario: enforce subnet-oriented cloud filtering rules.
D: Consumes a complete provider-hosted application while the provider manages the underlying platform. However, it does not most directly satisfy the requirement in this scenario: enforce subnet-oriented cloud filtering rules.
E: Uses encrypted tunnels over the internet to connect an on-premises network to a cloud network. However, it does not most directly satisfy the requirement in this scenario: enforce subnet-oriented cloud filtering rules.
Learning point: Use Network security list when the key requirement is to enforce subnet-oriented cloud filtering rules.
A field technician at Litware Manufacturing is validating a proposed solution. The design must give internet-routable cloud resources a gateway path to the public internet. Which answer is most appropriate? The decision applies to a operations lab.
Correct answer: B
Why: Provides a path between a cloud VPC/VNet and the public internet for appropriately routed resources. This directly satisfies the requirement: give internet-routable cloud resources a gateway path to the public internet.
Option review:
A: Automatically expands or contracts resources in response to changing demand. However, it does not most directly satisfy the requirement in this scenario: give internet-routable cloud resources a gateway path to the public internet.
B: Provides a path between a cloud VPC/VNet and the public internet for appropriately routed resources. This directly satisfies the requirement: give internet-routable cloud resources a gateway path to the public internet.
C: Provides a logically isolated virtual network inside a public cloud provider. However, it does not most directly satisfy the requirement in this scenario: give internet-routable cloud resources a gateway path to the public internet.
D: Consumes a complete provider-hosted application while the provider manages the underlying platform. However, it does not most directly satisfy the requirement in this scenario: give internet-routable cloud resources a gateway path to the public internet.
E: Implements network functions such as routing or firewalls as software rather than dedicated appliances. However, it does not most directly satisfy the requirement in this scenario: give internet-routable cloud resources a gateway path to the public internet.
Learning point: Use Internet gateway when the key requirement is to give internet-routable cloud resources a gateway path to the public internet.
For a new deployment at Woodgrove Bank, the networking team wants to allow private cloud instances outbound internet access while keeping them non-public. Which choice most directly satisfies the goal? The decision applies to a production maintenance window.
Correct answer: C
Why: Lets private cloud workloads initiate outbound internet access without accepting unsolicited inbound sessions. This directly satisfies the requirement: allow private cloud instances outbound internet access while keeping them non-public.
Option review:
A: Automatically expands or contracts resources in response to changing demand. However, it does not most directly satisfy the requirement in this scenario: allow private cloud instances outbound internet access while keeping them non-public.
B: Cloud infrastructure is operated by a provider and shared across customers with logical isolation. However, it does not most directly satisfy the requirement in this scenario: allow private cloud instances outbound internet access while keeping them non-public.
C: Lets private cloud workloads initiate outbound internet access without accepting unsolicited inbound sessions. This directly satisfies the requirement: allow private cloud instances outbound internet access while keeping them non-public.
D: Provides a path between a cloud VPC/VNet and the public internet for appropriately routed resources. However, it does not most directly satisfy the requirement in this scenario: allow private cloud instances outbound internet access while keeping them non-public.
E: Applies subnet-level packet-filtering rules in cloud environments that support security lists. However, it does not most directly satisfy the requirement in this scenario: allow private cloud instances outbound internet access while keeping them non-public.
Learning point: Use NAT gateway when the key requirement is to allow private cloud instances outbound internet access while keeping them non-public.
At Blue Yonder Airlines, a systems administrator is reviewing a network change. The requirement is to connect on-premises and cloud networks securely without a private carrier circuit. Which option is the best fit? The decision applies to a new floor deployment.
Correct answer: C
Why: Uses encrypted tunnels over the internet to connect an on-premises network to a cloud network. This directly satisfies the requirement: connect on-premises and cloud networks securely without a private carrier circuit.
Option review:
A: Applies subnet-level packet-filtering rules in cloud environments that support security lists. However, it does not most directly satisfy the requirement in this scenario: connect on-premises and cloud networks securely without a private carrier circuit.
B: Uses a private provider connection such as Direct Connect/ExpressRoute rather than the public internet. However, it does not most directly satisfy the requirement in this scenario: connect on-premises and cloud networks securely without a private carrier circuit.
C: Uses encrypted tunnels over the internet to connect an on-premises network to a cloud network. This directly satisfies the requirement: connect on-premises and cloud networks securely without a private carrier circuit.
D: Allows multiple customers to share provider infrastructure with logical isolation. However, it does not most directly satisfy the requirement in this scenario: connect on-premises and cloud networks securely without a private carrier circuit.
E: Implements network functions such as routing or firewalls as software rather than dedicated appliances. However, it does not most directly satisfy the requirement in this scenario: connect on-premises and cloud networks securely without a private carrier circuit.
Learning point: Use Site-to-site cloud VPN when the key requirement is to connect on-premises and cloud networks securely without a private carrier circuit.
A ticket at Contoso Health says the team must obtain predictable private connectivity from a data center to a cloud provider. Which technology or concept most directly addresses this requirement? The decision applies to a service-recovery review.
Correct answer: C
Why: Uses a private provider connection such as Direct Connect/ExpressRoute rather than the public internet. This directly satisfies the requirement: obtain predictable private connectivity from a data center to a cloud provider.
Option review:
A: Allows multiple customers to share provider infrastructure with logical isolation. However, it does not most directly satisfy the requirement in this scenario: obtain predictable private connectivity from a data center to a cloud provider.
B: Consumes an application platform/runtime while the provider manages lower infrastructure layers. However, it does not most directly satisfy the requirement in this scenario: obtain predictable private connectivity from a data center to a cloud provider.
C: Uses a private provider connection such as Direct Connect/ExpressRoute rather than the public internet. This directly satisfies the requirement: obtain predictable private connectivity from a data center to a cloud provider.
D: Consumes a complete provider-hosted application while the provider manages the underlying platform. However, it does not most directly satisfy the requirement in this scenario: obtain predictable private connectivity from a data center to a cloud provider.
E: Provides a path between a cloud VPC/VNet and the public internet for appropriately routed resources. However, it does not most directly satisfy the requirement in this scenario: obtain predictable private connectivity from a data center to a cloud provider.
Learning point: Use Dedicated cloud connection when the key requirement is to obtain predictable private connectivity from a data center to a cloud provider.
During a design meeting at Litware Manufacturing, the junior network administrator needs to consume provider-operated infrastructure without owning the underlying data center. What should be selected? The decision applies to a branch-office rollout.
Correct answer: E
Why: Cloud infrastructure is operated by a provider and shared across customers with logical isolation. This directly satisfies the requirement: consume provider-operated infrastructure without owning the underlying data center.
Option review:
A: Consumes a complete provider-hosted application while the provider manages the underlying platform. However, it does not most directly satisfy the requirement in this scenario: consume provider-operated infrastructure without owning the underlying data center.
B: Provides a path between a cloud VPC/VNet and the public internet for appropriately routed resources. However, it does not most directly satisfy the requirement in this scenario: consume provider-operated infrastructure without owning the underlying data center.
C: Applies subnet-level packet-filtering rules in cloud environments that support security lists. However, it does not most directly satisfy the requirement in this scenario: consume provider-operated infrastructure without owning the underlying data center.
D: Cloud-style infrastructure is dedicated to one organization. However, it does not most directly satisfy the requirement in this scenario: consume provider-operated infrastructure without owning the underlying data center.
E: Cloud infrastructure is operated by a provider and shared across customers with logical isolation. This directly satisfies the requirement: consume provider-operated infrastructure without owning the underlying data center.
Learning point: Use Public cloud when the key requirement is to consume provider-operated infrastructure without owning the underlying data center.
Woodgrove Bank is updating its network standard. Which option best meets the need to retain dedicated organizational control while using cloud operating models? The decision applies to a campus refresh.
Correct answer: E
Why: Cloud-style infrastructure is dedicated to one organization. This directly satisfies the requirement: retain dedicated organizational control while using cloud operating models.
Option review:
A: Applies subnet-level packet-filtering rules in cloud environments that support security lists. However, it does not most directly satisfy the requirement in this scenario: retain dedicated organizational control while using cloud operating models.
B: Consumes a complete provider-hosted application while the provider manages the underlying platform. However, it does not most directly satisfy the requirement in this scenario: retain dedicated organizational control while using cloud operating models.
C: Allows multiple customers to share provider infrastructure with logical isolation. However, it does not most directly satisfy the requirement in this scenario: retain dedicated organizational control while using cloud operating models.
D: Consumes compute, storage, and networking while the customer manages OS and applications. However, it does not most directly satisfy the requirement in this scenario: retain dedicated organizational control while using cloud operating models.
E: Cloud-style infrastructure is dedicated to one organization. This directly satisfies the requirement: retain dedicated organizational control while using cloud operating models.
Learning point: Use Private cloud when the key requirement is to retain dedicated organizational control while using cloud operating models.
A field technician at Blue Yonder Airlines is validating a proposed solution. The design must integrate on-premises or private resources with public cloud services. Which answer is most appropriate? The decision applies to a data-center segment.
Correct answer: A
Why: Combines private/on-premises resources with public cloud services. This directly satisfies the requirement: integrate on-premises or private resources with public cloud services.
Option review:
A: Combines private/on-premises resources with public cloud services. This directly satisfies the requirement: integrate on-premises or private resources with public cloud services.
B: Automatically expands or contracts resources in response to changing demand. However, it does not most directly satisfy the requirement in this scenario: integrate on-premises or private resources with public cloud services.
C: Consumes a complete provider-hosted application while the provider manages the underlying platform. However, it does not most directly satisfy the requirement in this scenario: integrate on-premises or private resources with public cloud services.
D: Supports increasing workload capacity by adding or enlarging resources. However, it does not most directly satisfy the requirement in this scenario: integrate on-premises or private resources with public cloud services.
E: Consumes compute, storage, and networking while the customer manages OS and applications. However, it does not most directly satisfy the requirement in this scenario: integrate on-premises or private resources with public cloud services.
Learning point: Use Hybrid cloud when the key requirement is to integrate on-premises or private resources with public cloud services.
For a new deployment at Contoso Health, the networking team wants to use a finished application without managing operating systems or runtime infrastructure. Which choice most directly satisfies the goal? The decision applies to a remote-site migration.
Correct answer: D
Why: Consumes a complete provider-hosted application while the provider manages the underlying platform. This directly satisfies the requirement: use a finished application without managing operating systems or runtime infrastructure.
Option review:
A: Provides a path between a cloud VPC/VNet and the public internet for appropriately routed resources. However, it does not most directly satisfy the requirement in this scenario: use a finished application without managing operating systems or runtime infrastructure.
B: Lets private cloud workloads initiate outbound internet access without accepting unsolicited inbound sessions. However, it does not most directly satisfy the requirement in this scenario: use a finished application without managing operating systems or runtime infrastructure.
C: Allows multiple customers to share provider infrastructure with logical isolation. However, it does not most directly satisfy the requirement in this scenario: use a finished application without managing operating systems or runtime infrastructure.
D: Consumes a complete provider-hosted application while the provider manages the underlying platform. This directly satisfies the requirement: use a finished application without managing operating systems or runtime infrastructure.
E: Uses encrypted tunnels over the internet to connect an on-premises network to a cloud network. However, it does not most directly satisfy the requirement in this scenario: use a finished application without managing operating systems or runtime infrastructure.
Learning point: Use SaaS when the key requirement is to use a finished application without managing operating systems or runtime infrastructure.
At Litware Manufacturing, a systems administrator is reviewing a network change. The requirement is to provision virtual machines and networks while retaining OS administration. Which option is the best fit? The decision applies to a operations lab.
Correct answer: E
Why: Consumes compute, storage, and networking while the customer manages OS and applications. This directly satisfies the requirement: provision virtual machines and networks while retaining OS administration.
Option review:
A: Applies subnet-level packet-filtering rules in cloud environments that support security lists. However, it does not most directly satisfy the requirement in this scenario: provision virtual machines and networks while retaining OS administration.
B: Lets private cloud workloads initiate outbound internet access without accepting unsolicited inbound sessions. However, it does not most directly satisfy the requirement in this scenario: provision virtual machines and networks while retaining OS administration.
C: Allows multiple customers to share provider infrastructure with logical isolation. However, it does not most directly satisfy the requirement in this scenario: provision virtual machines and networks while retaining OS administration.
D: Consumes an application platform/runtime while the provider manages lower infrastructure layers. However, it does not most directly satisfy the requirement in this scenario: provision virtual machines and networks while retaining OS administration.
E: Consumes compute, storage, and networking while the customer manages OS and applications. This directly satisfies the requirement: provision virtual machines and networks while retaining OS administration.
Learning point: Use IaaS when the key requirement is to provision virtual machines and networks while retaining OS administration.
A ticket at Woodgrove Bank says the team must deploy application code without managing the guest operating system. Which technology or concept most directly addresses this requirement? The decision applies to a production maintenance window.
Correct answer: D
Why: Consumes an application platform/runtime while the provider manages lower infrastructure layers. This directly satisfies the requirement: deploy application code without managing the guest operating system.
Option review:
A: Lets private cloud workloads initiate outbound internet access without accepting unsolicited inbound sessions. However, it does not most directly satisfy the requirement in this scenario: deploy application code without managing the guest operating system.
B: Applies instance or interface-level filtering rules to cloud workloads, depending on platform. However, it does not most directly satisfy the requirement in this scenario: deploy application code without managing the guest operating system.
C: Implements network functions such as routing or firewalls as software rather than dedicated appliances. However, it does not most directly satisfy the requirement in this scenario: deploy application code without managing the guest operating system.
D: Consumes an application platform/runtime while the provider manages lower infrastructure layers. This directly satisfies the requirement: deploy application code without managing the guest operating system.
E: Cloud-style infrastructure is dedicated to one organization. However, it does not most directly satisfy the requirement in this scenario: deploy application code without managing the guest operating system.
Learning point: Use PaaS when the key requirement is to deploy application code without managing the guest operating system.
During a design meeting at Blue Yonder Airlines, the junior network administrator needs to add and remove capacity dynamically as workload demand changes. What should be selected? The decision applies to a new floor deployment.
Correct answer: E
Why: Automatically expands or contracts resources in response to changing demand. This directly satisfies the requirement: add and remove capacity dynamically as workload demand changes.
Option review:
A: Cloud infrastructure is operated by a provider and shared across customers with logical isolation. However, it does not most directly satisfy the requirement in this scenario: add and remove capacity dynamically as workload demand changes.
B: Applies subnet-level packet-filtering rules in cloud environments that support security lists. However, it does not most directly satisfy the requirement in this scenario: add and remove capacity dynamically as workload demand changes.
C: Uses encrypted tunnels over the internet to connect an on-premises network to a cloud network. However, it does not most directly satisfy the requirement in this scenario: add and remove capacity dynamically as workload demand changes.
D: Consumes an application platform/runtime while the provider manages lower infrastructure layers. However, it does not most directly satisfy the requirement in this scenario: add and remove capacity dynamically as workload demand changes.
E: Automatically expands or contracts resources in response to changing demand. This directly satisfies the requirement: add and remove capacity dynamically as workload demand changes.
Learning point: Use Elasticity when the key requirement is to add and remove capacity dynamically as workload demand changes.
Contoso Health is updating its network standard. Which option best meets the need to design a service so capacity can grow as demand increases? The decision applies to a service-recovery review.
Correct answer: E
Why: Supports increasing workload capacity by adding or enlarging resources. This directly satisfies the requirement: design a service so capacity can grow as demand increases.
Option review:
A: Implements network functions such as routing or firewalls as software rather than dedicated appliances. However, it does not most directly satisfy the requirement in this scenario: design a service so capacity can grow as demand increases.
B: Consumes an application platform/runtime while the provider manages lower infrastructure layers. However, it does not most directly satisfy the requirement in this scenario: design a service so capacity can grow as demand increases.
C: Provides a logically isolated virtual network inside a public cloud provider. However, it does not most directly satisfy the requirement in this scenario: design a service so capacity can grow as demand increases.
D: Applies subnet-level packet-filtering rules in cloud environments that support security lists. However, it does not most directly satisfy the requirement in this scenario: design a service so capacity can grow as demand increases.
E: Supports increasing workload capacity by adding or enlarging resources. This directly satisfies the requirement: design a service so capacity can grow as demand increases.
Learning point: Use Scalability when the key requirement is to design a service so capacity can grow as demand increases.
A field technician at Litware Manufacturing is validating a proposed solution. The design must serve multiple customer tenants on shared cloud infrastructure while maintaining separation. Which answer is most appropriate? The decision applies to a branch-office rollout.
Correct answer: D
Why: Allows multiple customers to share provider infrastructure with logical isolation. This directly satisfies the requirement: serve multiple customer tenants on shared cloud infrastructure while maintaining separation.
Option review:
A: Supports increasing workload capacity by adding or enlarging resources. However, it does not most directly satisfy the requirement in this scenario: serve multiple customer tenants on shared cloud infrastructure while maintaining separation.
B: Cloud-style infrastructure is dedicated to one organization. However, it does not most directly satisfy the requirement in this scenario: serve multiple customer tenants on shared cloud infrastructure while maintaining separation.
C: Combines private/on-premises resources with public cloud services. However, it does not most directly satisfy the requirement in this scenario: serve multiple customer tenants on shared cloud infrastructure while maintaining separation.
D: Allows multiple customers to share provider infrastructure with logical isolation. This directly satisfies the requirement: serve multiple customer tenants on shared cloud infrastructure while maintaining separation.
E: Provides a logically isolated virtual network inside a public cloud provider. However, it does not most directly satisfy the requirement in this scenario: serve multiple customer tenants on shared cloud infrastructure while maintaining separation.
Learning point: Use Multitenancy when the key requirement is to serve multiple customer tenants on shared cloud infrastructure while maintaining separation.
During a operations lab, Woodgrove Bank is comparing several networking concepts. Which option is accurately characterized by this statement: Implements network functions such as routing or firewalls as software rather than dedicated appliances.
Correct answer: D
Why: Implements network functions such as routing or firewalls as software rather than dedicated appliances. This directly satisfies the requirement: Implements network functions such as routing or firewalls as software rather than dedicated appliances..
Option review:
A: Applies instance or interface-level filtering rules to cloud workloads, depending on platform. However, it does not most directly satisfy the requirement in this scenario: Implements network functions such as routing or firewalls as software rather than dedicated appliances..
B: Uses a private provider connection such as Direct Connect/ExpressRoute rather than the public internet. However, it does not most directly satisfy the requirement in this scenario: Implements network functions such as routing or firewalls as software rather than dedicated appliances..
C: Uses encrypted tunnels over the internet to connect an on-premises network to a cloud network. However, it does not most directly satisfy the requirement in this scenario: Implements network functions such as routing or firewalls as software rather than dedicated appliances..
D: Implements network functions such as routing or firewalls as software rather than dedicated appliances. This directly satisfies the requirement: Implements network functions such as routing or firewalls as software rather than dedicated appliances..
E: Applies subnet-level packet-filtering rules in cloud environments that support security lists. However, it does not most directly satisfy the requirement in this scenario: Implements network functions such as routing or firewalls as software rather than dedicated appliances..
Learning point: Use Network functions virtualization (NFV) when the key requirement is to deploy network functions as software instances instead of purpose-built hardware.
During a production maintenance window, Blue Yonder Airlines is comparing several networking concepts. Which option is accurately characterized by this statement: Provides a logically isolated virtual network inside a public cloud provider.
Correct answer: B
Why: Provides a logically isolated virtual network inside a public cloud provider. This directly satisfies the requirement: Provides a logically isolated virtual network inside a public cloud provider..
Option review:
A: Applies instance or interface-level filtering rules to cloud workloads, depending on platform. However, it does not most directly satisfy the requirement in this scenario: Provides a logically isolated virtual network inside a public cloud provider..
B: Provides a logically isolated virtual network inside a public cloud provider. This directly satisfies the requirement: Provides a logically isolated virtual network inside a public cloud provider..
C: Uses a private provider connection such as Direct Connect/ExpressRoute rather than the public internet. However, it does not most directly satisfy the requirement in this scenario: Provides a logically isolated virtual network inside a public cloud provider..
D: Cloud infrastructure is operated by a provider and shared across customers with logical isolation. However, it does not most directly satisfy the requirement in this scenario: Provides a logically isolated virtual network inside a public cloud provider..
E: Applies subnet-level packet-filtering rules in cloud environments that support security lists. However, it does not most directly satisfy the requirement in this scenario: Provides a logically isolated virtual network inside a public cloud provider..
Learning point: Use Virtual private cloud (VPC) when the key requirement is to create an isolated cloud network with subnets, routing, and security controls.
During a new floor deployment, Contoso Health is comparing several networking concepts. Which option is accurately characterized by this statement: Applies instance or interface-level filtering rules to cloud workloads, depending on platform.
Correct answer: A
Why: Applies instance or interface-level filtering rules to cloud workloads, depending on platform. This directly satisfies the requirement: Applies instance or interface-level filtering rules to cloud workloads, depending on platform..
Option review:
A: Applies instance or interface-level filtering rules to cloud workloads, depending on platform. This directly satisfies the requirement: Applies instance or interface-level filtering rules to cloud workloads, depending on platform..
B: Automatically expands or contracts resources in response to changing demand. However, it does not most directly satisfy the requirement in this scenario: Applies instance or interface-level filtering rules to cloud workloads, depending on platform..
C: Provides a logically isolated virtual network inside a public cloud provider. However, it does not most directly satisfy the requirement in this scenario: Applies instance or interface-level filtering rules to cloud workloads, depending on platform..
D: Uses encrypted tunnels over the internet to connect an on-premises network to a cloud network. However, it does not most directly satisfy the requirement in this scenario: Applies instance or interface-level filtering rules to cloud workloads, depending on platform..
E: Cloud infrastructure is operated by a provider and shared across customers with logical isolation. However, it does not most directly satisfy the requirement in this scenario: Applies instance or interface-level filtering rules to cloud workloads, depending on platform..
Learning point: Use Network security group when the key requirement is to control permitted traffic to or from individual cloud workloads or interfaces.
Popular posts
Recent Posts
