All practice questions
174 questions
An enterprise architecture team is designing an automated progressive delivery release pipeline using Google Cloud Deploy for a microservice deployed on Google Kubernetes Engine (GKE). The pipeline must enforce container image provenance via Binary Authorization and perform automated canary metric verification prior to full traffic shifting.
Arrange the following pipeline execution steps in the correct chronological order from source build to final production rollout.
Drag items to arrange them in the correct order
An enterprise organization is establishing a secure continuous integration and continuous delivery (CI/CD) pipeline on Google Cloud to deploy containerized applications to Google Kubernetes Engine (GKE) under strict Binary Authorization compliance policies. Arrange the operational pipeline stages in the correct chronological order from the initial developer code check-in to successful pod scheduling in the cluster.
Drag items to arrange them in the correct order
A multinational financial services enterprise hosts its core payment authorization pipeline across two Google Cloud regions (primary in us-central1, secondary in us-east4). The enterprise requires a quarterly Business Continuity and Disaster Recovery (BCP/DR) drill to validate cross-region failover efficiency under an RPO target of under 1 minute and an RTO target of under 15 minutes. As the Lead Cloud Architect, you must sequence the technical steps for executing and verifying this DR validation exercise without causing unintended data loss or unexpected service failure. Arrange the operational steps below in the correct execution sequence from first to last.
Drag items to arrange them in the correct order
An enterprise security architect is designing an automated credential rotation workflow for a PostgreSQL database. The database credentials must be stored in Google Cloud Secret Manager, encrypted using a Customer-Managed Encryption Key (CMEK) stored in Cloud KMS, and automatically rotated every 30 days using a dedicated Cloud Run rotation service triggered by Pub/Sub notifications. You must establish the secure lifecycle configurations and IAM bindings following the principle of least privilege. What is the correct sequence of steps to configure this automated secret rotation workflow?
Drag items to arrange them in the correct order
An enterprise intermodal freight operator is designing a modernized fleet telemetry system on Google Cloud. As the Principal Cloud Architect, you must translate high-level business requirements into a production-ready solution following Google Cloud architecture framework best practices. Place the architectural design phases in the correct sequential order, starting from initial business abstraction down to physical infrastructure deployment.
Drag items to arrange them in the correct order
An enterprise organization is restructuring its software delivery lifecycle to establish an end-to-end secure, automated CI/CD pipeline for deploying a critical microservice to Google Kubernetes Engine (GKE). The security policy mandates least-privilege access, container vulnerability scanning, cryptographic image attestation using Binary Authorization, Terraform state validation, and controlled canary traffic routing. Place the operational stages of this deployment pipeline in the correct chronological order from initial source submission to full production release.
Drag items to arrange them in the correct order
An enterprise Site Reliability Engineering (SRE) team is implementing an automated incident response and notification suppression pipeline on Google Cloud for a mission-critical financial settlement service. The pipeline must detect SLO degradation, prevent alert storms during active outages, execute automated self-healing without relying on long-lived service account keys or primitive IAM roles, and archive operational telemetry for post-mortems. In what chronological sequence should the SRE team structure the operational steps for this automated incident lifecycle?
Drag items to arrange them in the correct order
An enterprise web application deployed across primary region `us-central1` and secondary recovery region `us-east4` experiences a total regional failure in `us-central1`. The application uses a Pilot Light DR pattern comprising a Cloud SQL PostgreSQL cross-region read replica and a minimal regional Managed Instance Group (MIG) in `us-east4`. To achieve recovery without split-brain data corruption or premature exposure of unvalidated endpoints, in what exact sequence should the SRE team execute the disaster recovery failover runbook tasks?
Drag items to arrange them in the correct order
A global supply chain enterprise operates a critical order management platform with a warm standby disaster recovery topology across Google Cloud regions `us-central1` (primary) and `europe-west3` (secondary). The application relies on Cloud SQL for PostgreSQL with asynchronous cross-region read replication. Following an unrecoverable regional disaster in `us-central1`, the operational engineering team must execute the disaster recovery runbook to restore service while ensuring data consistency and preventing split-brain states. In what sequential order should the operational team execute the disaster recovery failover tasks?
Drag items to arrange them in the correct order
An enterprise operating a multi-folder Google Cloud resource hierarchy needs to stream all Data Access audit logs and Security Command Center (SCC) Premium findings to a third-party SIEM hosted on Google Kubernetes Engine (GKE). The security architecture must adhere to the principle of least privilege and ensure zero log loss. What is the correct sequence of steps to implement this centralized logging and threat export pipeline?
Drag items to arrange them in the correct order
A regulatory compliance audit requires a healthcare organization to capture all Google Cloud Data Access audit logs across all projects and securely retain them for seven years. The solution must ensure that log data is encrypted using customer-managed encryption keys (CMEK) and protected against premature deletion or tampering by any privileged user, including organization admins. In which chronological order should a Cloud Security Architect perform the required implementation steps?
Drag items to arrange them in the correct order
An enterprise organization is establishing an automated, highly reliable Infrastructure as Code (IaC) continuous integration and deployment pipeline using Cloud Build and Terraform to provision multi-region production environments on Google Cloud. The architecture must guarantee state safety, strictly enforce security guardrails before resource creation, and prevent deployment rollouts if operational verification fails. In what sequential order should the pipeline execute these environment provisioning steps?
Drag items to arrange them in the correct order
An operations engineer needs to set up automated alerts whenever specific application error log entries occur in Google Cloud. Order the steps required to configure an operational alert using a custom log-based metric and Cloud Monitoring.
Drag items to arrange them in the correct order
An enterprise needs to perform an offline bulk migration of 200 TB of archive data from an on-premises data center to Google Cloud Storage using a Transfer Appliance. In what chronological sequence should the cloud architect perform the key steps of this transfer strategy?
Drag items to arrange them in the correct order
An operations team needs to set up automated alerting for specific application error logs occurring in a Compute Engine environment. Order the configuration steps from first to last to establish a complete log-based alerting workflow.
Drag items to arrange them in the correct order
A cloud engineering team needs to safely migrate an existing local Terraform state file to a secure Google Cloud Storage (GCS) remote backend with state locking enabled. Arrange the operational steps in the correct sequence to complete this migration.
Drag items to arrange them in the correct order
A DevOps engineer needs to migrate an existing local Terraform state file to a Google Cloud Storage (GCS) remote backend for shared team access. What is the correct sequence of steps to migrate the local Terraform state to the GCS remote backend?
Drag items to arrange them in the correct order
An enterprise is planning a near-zero downtime database migration from an on-premises PostgreSQL database to Google Cloud SQL for PostgreSQL using Database Migration Service (DMS). Place the following migration steps in the correct chronological execution order from initial preparation to final cutover.
Drag items to arrange them in the correct order
A multinational retail enterprise is planning to migrate its core e-commerce database (a 40 TB PostgreSQL instance) and associated 300 TB object store from an on-premises data center to Google Cloud (Cloud SQL for PostgreSQL and Cloud Storage). The enterprise mandates continuous data synchronization prior to cutover to comply with a strict maximum allowed maintenance window of 30 minutes. What is the correct sequence of steps to plan and execute this zero-data-loss migration strategy?
Drag items to arrange them in the correct order
A Cloud Architect needs to migrate an existing local Terraform state file containing critical production Google Cloud resources to a secure Google Cloud Storage (GCS) remote backend with state locking and CMEK encryption. Arrange the operational steps in the correct chronological order to safely complete this backend migration while maintaining resource integrity.
Drag items to arrange them in the correct order