Cloud Solutions (402 - Cloud Solution Expert) Free Sample Questions

Create a free account to browse all 12 sample questions. The full practice test includes 150 questions. Use the simulator for timed and flashcard mode.

Try Simulator

402 Sample Questions

  1. Question 1

    Q1

    AeroLogistics is adopting a hybrid cloud model to scale their seasonal workloads. They are transitioning from owning all physical infrastructure to a model where the cloud provider manages the underlying hypervisor, storage, and networking, but AeroLogistics retains full control over the operating systems, BIG-IP Virtual Editions, and application stacks. Which cloud service model does this represent?

    Show answer & explanation

    Correct answer: B

    Infrastructure as a Service (IaaS) is a cloud computing model where the provider manages the physical infrastructure (servers, network, storage, hypervisor), while the consumer controls the operating systems, virtual appliances (like BIG-IP VE), and deployed applications. PaaS abstracts the OS layer, and SaaS abstracts everything up to the application software.

  2. Question 2

    Q2

    A security architect at FinTech Nexus is implementing cloud Identity and Access Management (IAM) for their BIG-IP administrators. They want to use Azure Active Directory (Azure AD) as the central identity provider. When an administrator attempts to log into the BIG-IP Configuration utility, they should be redirected to Azure AD for authentication, and upon success, granted role-based access on the BIG-IP. Which standard protocol should the BIG-IP APM be configured to use as a Service Provider (SP) in this scenario?

    Show answer & explanation

    Correct answer: C

    SAML 2.0 is the standard federation protocol used for web-based Single Sign-On (SSO) where the BIG-IP acts as the Service Provider (SP) and Azure AD acts as the Identity Provider (IdP). While LDAP and RADIUS can be used for authentication, they do not facilitate the standard browser-based redirection federation flow required by modern cloud IAM integrations like Azure AD SSO.

  3. Question 3

    Q3Multiple answers

    Which TWO of the following statements accurately describe the technical requirements and characteristics of application bursting in a hybrid cloud architecture? (Select TWO)

    Show answer & explanation

    Correct answers: A, D

    Application bursting fundamentally requires a mechanism to detect capacity limits in the primary data center and seamlessly steer new client requests to the secondary cloud environment. BIG-IP DNS (GSLB) achieves this using metrics like virtual server connections or available pool members.

    To be cost-effective, cloud bursting utilizes dynamic provisioning (via APIs, AWS Auto Scaling, or templates) to instantiate resources only when the burst occurs, rather than paying for idle compute continuously.

  4. Question 4

    Q4

    True or False: In a purely Software as a Service (SaaS) cloud business model, the customer is responsible for managing the operating system patching and application framework updates of the deployed solution.

    Show answer & explanation

    Correct answer: B

    False. In a SaaS model, the cloud provider manages the entire stack, including the underlying infrastructure, operating systems, application frameworks, and the application software itself. The customer is typically only responsible for user data and access management.

  5. Question 5

    Q5

    An organization is configuring BIG-IP DNS (formerly GTM) to support application bursting to AWS. Which load balancing method on the Wide IP is MOST appropriate to ensure traffic only flows to AWS when the on-premises BIG-IP LTM virtual server reaches 80% of its maximum connection capacity?

    Show answer & explanation

    Correct answer: D

    In a cloud bursting scenario, Global Availability is often used. The on-premises virtual server is prioritized as the primary pool member. By setting a hard connection limit on the LTM virtual server, BIG-IP DNS will detect when this limit is reached (or when it goes offline due to capacity) and automatically fall back to the secondary pool member (the AWS environment).

  6. Question 6

    Q6

    A cloud engineer is analyzing Identity and Access Management (IAM) flows for a multi-cloud deployment. They need to allow a custom internal application hosted in GCP to programmatically manage BIG-IP VE configurations in AWS without embedding static credentials. Which IAM mechanism is BEST suited for this machine-to-machine authentication?

    Show answer & explanation

    Correct answer: B

    The OAuth 2.0 Client Credentials grant type is specifically designed for machine-to-machine (M2M) communications where no user interaction is possible. It allows the GCP application to request a short-lived access token using its own client identity to interact securely with the BIG-IP REST API. SAML is designed for human browser-based SSO.

Register free to unlock 6 more sample questions

Create a free account to continue with the rest of the 402 sample set.

Lifetime One

Own this practice test forever.

$79.99
$75.99
one-time
  • Full access to 150 questions
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • Brainy AI Assistant
  • Lifetime updates

Two

Any 2 exams per month.

$20.00/exam
$39.99
/month
  • 2 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 1,000 Brainy AI Credits
  • Cancel anytime

Premium Twelve

Any 12 exams over 3 months.

$15.00/exam
$179.99
/3 months
  • 4 active exam slots
  • Study, Timed & Flashcard Modes
  • All past and future versions i
  • Detailed Explanations
  • Study Tracking & Past Attempts
  • 15,000 Brainy AI Credits
  • Dedicated support
  • Friend seat included — full access

Trusted by professionals at

NvidiaSupabaseGitHubOpenAITursoClerkClaude AIAmazon