Question 1:


A company has decided to scale its e-commerce application from its corporate datacenter to a commercial cloud provider to meet an anticipated increase in demand during an upcoming holiday.

The majority of the application load takes place on the application server under normal conditions. For this reason, the company decides to deploy additional application servers into a commercial cloud provider using the on-premises

orchestration engine that installs and configures common software and network configurations.

The remote computing environment is connected to the on-premises datacenter via a site-to-site IPSec tunnel. The external DNS provider has been configured to use weighted round-robin routing to load balance connections from the Internet.

During testing, the company discovers that only 20% of connections completed successfully.


Review the network architecture and supporting documents and fulfill these requirements:

Part 1:


Analyze the configuration of the following components: DNS, Firewall 1, Firewall 2, Router 1, Router 2, VPN and Orchestrator Server.


Identify the problematic device(s).

Part 2:


Identify the correct options to provide adequate configuration for hybrid cloud architecture.


If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

Part 1:

Cloud Hybrid Network Diagram

Part 2:

Only select a maximum of TWO options from the multiple choice question

A. Check the answer in explanation.

Correct Answer: A

Change the Address Space on Router2 Update the PSK (Pre-shared key in Router2)

Question 2:


The QA team is testing a newly implemented clinical trial management (CTM) SaaS application that uses a business intelligence application for reporting. The UAT users were instructed to use HTTP and HTTPS.

Refer to the application dataflow:

1A -The end user accesses the application through a web browser to enter and view clinical data.

2A -The CTM application server reads/writes data to/from the database server.

1B -The end user accesses the application through a web browser to run reports on clinical data.

2B -The CTM application server makes a SOAP call on a non-privileged port to the BI application server.

3B -The BI application server gets the data from the database server and presents it to the CTM application server.

When UAT users try to access the application using or, they get a message stating: “Browser cannot display the webpage.” The QA team has raised a ticket to troubleshoot the issue.


You are a cloud engineer who is tasked with reviewing the firewall rules as well as virtual network settings.

You should ensure the firewall rules are allowing only the traffic based on the dataflow.

You have already verified the external DNS resolution and NAT are working.

Verify and appropriately configure the VLAN assignments and ACLs. Drag and drop the appropriate VLANs to each tier from the VLAN Tags table. Click on each Firewall to change ACLs as needed.

If at any time you would like to bring back the initial state of the simulation, please click the Reset All button.

A. Check the answer in explanation.

Correct Answer: A

On firewall 3, change the DENY entry to rule 3 not rule 1.

Question 3:

To save on licensing costs, the on-premises, IaaS-hosted databases need to be migrated to a public DBaaS solution. Which of the following would be the BEST technique?

A. Live migration

B. Physical-to-virtual

C. Storage-level mirroring

D. Database replication

Correct Answer: B

Question 4:

An SQL injection vulnerability was reported on a web application, and the cloud platform team needs to mitigate the vulnerability while it is corrected by the development team. Which of the following controls will BEST mitigate the risk of exploitation?





Correct Answer: B


Question 5:

A systems administrator is troubleshooting performance issues with a Windows VDI environment. Users have reported that VDI performance has been slow since the images were upgraded from Windows 7 to Windows 10. This VDI environment is used to run simple tasks, such as Microsoft Office. The administrator investigates the virtual machines and finds the following settings:


4 vCPU




10Gb networking


256MB frame buffer

Which of the following MOST likely needs to be upgraded?





Correct Answer: D

Question 6:

A systems administrator recently upgraded the processors in a web application host. Upon the next login, the administrator sees a new alert regarding the license being out of compliance. Which of the following licensing models is the application MOST likely using?

A. Per device

B. Per user

C. Core-based

D. Volume-based

Correct Answer: C

Reference: percorelicensing_definitions_vlbrief.pdf

Question 7:

An organization has two businesses that are developing different software products. They are using a single cloud provider with multiple IaaS instances. The organization identifies that the tracking of costs for each business are inaccurate. Which of the following is the BEST method for resolving this issue?

A. Perform segregation of the VLAN and capture egress and ingress values of each network interface

B. Tag each server with a dedicated cost and sum them based on the businesses

C. Split the total monthly invoice equally between the businesses

D. Create a dedicated subscription for the businesses to manage the costs

Correct Answer: B

Question 8:

A systems administrator needs to configure SSO authentication in a hybrid cloud environment. Which of the following is the BEST technique to use?

A. Access controls

B. Federation

C. Multifactor authentication

D. Certificate authentication

Correct Answer: C

Explanation: Section: (none)


Question 9:

A systems administrator recently deployed a VDI solution in a cloud environment; however, users are now experiencing poor rendering performance when trying to display 3-D content on their virtual desktops, especially at peak times. Which of the following actions will MOST likely solve this issue?

A. Update the quest graphics drivers from the official repository

B. Add more vGPU licenses to the host

C. Instruct users to access virtual workstations only on the VLAN

D. Select vGPU profiles with higher video RAM

Correct Answer: D


Question 10:

A systems administrator has migrated an internal application to a public cloud. The new web server is running under a TLS connection and has the same TLS certificate as the internal application that is deployed. However, the IT department reports that only internal users who are using new versions of the OSs are able to load the application home page.

Which of the following is the MOST likely cause of the issue?

A. The local firewall from older OSs is not allowing outbound connections

B. The local firewall from older OSs is not allowing inbound connections

C. The cloud web server is using a self-signed certificate that is not supported by older browsers

D. The cloud web server is using strong ciphers that are not supported by older browsers

Correct Answer: C

Question 11:

Lateral-moving malware has infected the server infrastructure. Which of the following network changes would MOST effectively prevent lateral movement in the future?

A. Implement DNSSEC in all DNS servers

B. Segment the physical network using a VLAN

C. Implement microsegmentation on the network

D. Implement 802.1X in the network infrastructure

Correct Answer: B

Question 12:

A company is switching from one cloud provider to another and needs to complete the migration as quickly as possible.

Which of the following is the MOST important consideration to ensure a seamless migration?

A. The cost of the environment

B. The I/O of the storage

C. Feature compatibility

D. Network utilization

Correct Answer: D

Question 13:

A cloud architect is designing the VPCs for a new hybrid cloud deployment. The business requires the following:


High availability


Horizontal auto-scaling


60 nodes peak capacity per region


Five reserved network IP addresses per subnet


/24 range

Which of the following would BEST meet the above requirements?

A. Create two /25 subnets in different regions

B. Create three /25 subnets in different regions

C. Create two /26 subnets in different regions

D. Create three /26 subnets in different regions

E. Create two /27 subnets in different regions

F. Create three /27 subnets in different regions

Correct Answer: B

Question 14:

A systems administrator would like to reduce the network delay between two servers.

Which of the following will reduce the network delay without taxing other system resources?

A. Decrease the MTU size on both servers

B. Adjust the CPU resources on both servers

C. Enable compression between the servers

D. Configure a VPN tunnel between the servers

Correct Answer: A


Question 15:

A company is planning to migrate applications to a public cloud, and the Chief Information Officer (CIO) would like to know the cost per business unit for the applications in the cloud. Before the migration, which of the following should the administrator implement FIRST to assist with reporting the cost for each business unit?

A. An SLA report

B. Tagging

C. Quotas

D. Showback

Correct Answer: D


