All Practice Exams

100+ Free IBM Cloud Professional Architect v6 Practice Questions

Pass your IBM Certified Professional Architect - Cloud v6 (C1000-172) exam on the first try — instant access, no signup required.

✓ No registration✓ No credit card✓ No hidden fees✓ Start practicing immediately
Not published Pass Rate
100+ Questions
100% Free
1 / 100
Question 1
Score: 0/0

Which IBM Cloud construct is the top-level network boundary that contains subnets, security groups, and ACLs in a region?

A
B
C
D
to track
2026 Statistics

Key Facts: IBM Cloud Professional Architect v6 Exam

64

Questions

IBM Training

60%

Passing Score

IBM Training

90 min

Exam Duration

IBM Training

$200

Exam Fee

Pearson VUE

23%

Networking

Largest domain

8 domains

Content Areas

IBM prep guide

The IBM C1000-172 exam has 64 questions in 90 minutes, requiring 60% to pass. Domains: Networking 23%, Compute 19%, Designing Cloud Solutions 16%, Storage 11%, Security 9%, Resiliency 8%, Observability 8%, Data 6%. Fee is $200 USD via Pearson VUE.

Sample IBM Cloud Professional Architect v6 Practice Questions

Try these sample questions to test your IBM Cloud Professional Architect v6 exam readiness. Each question includes a detailed explanation. Start the interactive quiz above for the full 100+ question experience with AI tutoring.

1Which IBM Cloud construct is the top-level network boundary that contains subnets, security groups, and ACLs in a region?
A.Resource group
B.Virtual Private Cloud (VPC)
C.Cloud Foundry organization
D.Account
Explanation: An IBM Cloud Virtual Private Cloud (VPC) is a logically isolated network within a region. It contains subnets (one per zone), security groups, network ACLs, public gateways, and VPN gateways, and is the top-level network construct for VPC compute resources.
2Within an IBM Cloud VPC, what is the relationship between a subnet and an availability zone?
A.A subnet spans all zones in a region for high availability
B.A subnet is bound to exactly one zone within a region
C.A subnet spans all regions globally
D.A subnet is bound to a specific account, not a zone
Explanation: In IBM Cloud VPC, every subnet is created in exactly one zone. To build a multi-zone, highly available architecture, you must create one subnet per zone and place workloads (or load-balancer pool members) in each subnet.
3Which IBM Cloud VPC firewalling option is stateful and applied at the network interface of an individual virtual server?
A.Network ACL
B.Security group
C.Public gateway
D.Floating IP
Explanation: VPC security groups are stateful firewalls attached to a virtual network interface (or load balancer/VPN). Return traffic for an allowed flow is automatically permitted, and rules support allow-only semantics tied to specific instances.
4An architect needs private, dedicated connectivity from an on-premises data center to an IBM Cloud VPC, bypassing the public internet. Which service should they use?
A.Cloud Internet Services (CIS)
B.VPC VPN gateway
C.IBM Cloud Direct Link
D.Transit Gateway
Explanation: IBM Cloud Direct Link provides a private, dedicated connection between an on-premises network and IBM Cloud, avoiding the public internet. It supports Connect, Dedicated, and Dedicated Hosting variants for different bandwidth and provider scenarios.
5Which IBM Cloud service interconnects multiple VPCs (and classic infrastructure) so they can route to each other privately?
A.Direct Link
B.Transit Gateway
C.Public gateway
D.Cloud Internet Services
Explanation: IBM Cloud Transit Gateway provides private, regional or global routing between multiple VPCs and between VPCs and classic infrastructure. It eliminates the need for full-mesh VPN tunnels between networks.
6A workload in an IBM Cloud VPC must reach the public internet to download OS patches but must not be reachable from the internet. What is the recommended configuration?
A.Attach a floating IP to each VSI
B.Attach a public gateway to the subnet, with no floating IPs on the VSIs
C.Use a VPN gateway for outbound traffic
D.Place the VSIs on a classic infrastructure VLAN
Explanation: A public gateway provides outbound-only internet connectivity for instances in a subnet via SNAT. Without floating IPs, instances are not directly reachable from the internet, satisfying patch-download needs while preventing inbound exposure.
7Which IBM Cloud edge service provides global DNS, WAF, DDoS protection, and CDN for public-facing applications?
A.Cloud Internet Services (CIS)
B.Direct Link
C.Transit Gateway
D.DNS Services (private DNS)
Explanation: Cloud Internet Services is IBM Cloud's edge offering powered by Cloudflare. It provides authoritative DNS, a Web Application Firewall, DDoS mitigation, global load balancing, and CDN for internet-facing workloads.
8Which IBM Cloud VPC load balancer type operates at OSI layers 4 and 7 with HTTP(S), HTTP/2, and host/path-based routing, and is regionally redundant by default?
A.Network Load Balancer for VPC (NLB)
B.Application Load Balancer for VPC (ALB)
C.Classic Citrix NetScaler VPX
D.Global Load Balancer in CIS
Explanation: The Application Load Balancer for VPC supports L4 and L7 with HTTPS termination, HTTP/2, and host- and path-based routing, and is deployed across the zones in the region for regional redundancy.
9An architect wants traffic between two VPCs in different regions to stay on the IBM Cloud private backbone. Which Transit Gateway configuration is required?
A.Local Transit Gateway
B.Global Transit Gateway
C.Direct Link Connect
D.Site-to-site VPN
Explanation: A Global Transit Gateway connects networks across IBM Cloud multi-zone regions over the IBM private backbone. A Local Transit Gateway only connects networks within a single region.
10Which statement correctly distinguishes a VPC security group from a network ACL in IBM Cloud VPC?
A.Security groups are stateless; network ACLs are stateful
B.Security groups are stateful and applied to NICs; network ACLs are stateless and applied to subnets
C.Both are stateful; security groups are applied to subnets, ACLs to NICs
D.Both are stateless and applied at the VPC level
Explanation: VPC security groups are stateful and attached to virtual NICs of instances, load balancers, and VPN gateways. Network ACLs are stateless and applied at the subnet level, requiring matched inbound and outbound rules.

About the IBM Cloud Professional Architect v6 Exam

IBM Certified Professional Architect - Cloud v6 validates the ability to design, plan, and architect IBM Cloud solutions. The exam covers compute options (VPC, IKS, ROKS, Code Engine), networking, storage, security, resiliency, observability, and overall solution design on IBM Cloud.

Questions

64 scored questions

Time Limit

90 minutes

Passing Score

60%

Exam Fee

$200 (IBM / Pearson VUE)

IBM Cloud Professional Architect v6 Exam Content Outline

23%

IBM Cloud Networking Options

VPCs, subnets, security groups, ACLs, public gateways, Direct Link, Transit Gateway, load balancers, CIS, and DNS Services

19%

Compute Options

VPC virtual servers, bare metal, IBM Cloud Kubernetes Service (IKS), Red Hat OpenShift on IBM Cloud (ROKS), Code Engine, and Cloud Foundry

16%

Designing Cloud Solutions

Reference architectures, well-architected framework, multi-zone regions, hybrid cloud patterns, and cost/availability trade-offs

11%

IBM Cloud Storage Options

Cloud Object Storage, Block Storage for VPC, File Storage, Backup for VPC, and storage tiering

9%

Security

IAM, access groups, Key Protect, Hyper Protect Crypto Services, Secrets Manager, App ID, Activity Tracker, and Security and Compliance Center

8%

IBM Cloud Resiliency Features

Multi-zone regions, Global Load Balancer, Cloud Internet Services, Backup for VPC, and disaster recovery patterns

8%

Observability Capabilities

IBM Cloud Monitoring (Sysdig), IBM Log Analysis (LogDNA), Activity Tracker, Flow Logs, and platform metrics

6%

Data Analytics and Data Management

Cloud Databases (Postgres, Redis, MongoDB), Cloudant, Db2 on Cloud, Watson Discovery, and analytics service selection

How to Pass the IBM Cloud Professional Architect v6 Exam

What You Need to Know

  • Passing score: 60%
  • Exam length: 64 questions
  • Time limit: 90 minutes
  • Exam fee: $200

Keys to Passing

  • Complete 500+ practice questions
  • Score 80%+ consistently before scheduling
  • Focus on highest-weighted sections
  • Use our AI tutor for tough concepts

IBM Cloud Professional Architect v6 Study Tips from Top Performers

1Focus on Networking (23%) — master VPC, ACLs, security groups, Direct Link, Transit Gateway, and CIS
2Know IBM Cloud compute trade-offs: VPC VSI vs bare metal vs IKS vs ROKS vs Code Engine vs Cloud Foundry
3Practice IAM design with access groups, service IDs, trusted profiles, and resource groups
4Understand multi-zone region patterns, Global Load Balancer, and Cloud Internet Services for resiliency
5Use the IBM Cloud Lite account to deploy a VPC, IKS cluster, and Cloud Object Storage end-to-end

Frequently Asked Questions

How many questions are on the IBM C1000-172 exam?

The exam has 64 multiple-choice questions delivered in 90 minutes. You need 60% (about 39 of 64) to pass and earn the IBM Certified Professional Architect - Cloud v6 credential.

How much does the IBM C1000-172 exam cost?

The exam fee is $200 USD when scheduled through Pearson VUE. IBM occasionally offers vouchers and discounts for Partner Plus members and via the IBM Training site.

What is the largest domain on C1000-172?

IBM Cloud Networking Options is the largest domain at 23%. Focus on VPCs, security groups, ACLs, Direct Link, Transit Gateway, public gateways, and Cloud Internet Services.

Which version replaces IBM Cloud Architect v5?

The Cloud Architect v6 (C1000-172) replaced v5 in 2024. It reflects current IBM Cloud services including VPC Gen 2, ROKS, Code Engine, Hyper Protect, and Security and Compliance Center.

Is hands-on IBM Cloud experience required?

IBM recommends 1 to 2 years of hands-on architecture experience on IBM Cloud. The free Lite account lets you practice VPC, IKS, IAM, and Cloud Object Storage without paid usage.