All practice questions
1598 questions
An enterprise operating a multi-folder Google Cloud organization must centralize security operations and satisfy regulatory audit requirements across all current and future projects. The security team requires real-time detection of high-risk threat activity, such as compromised credentials or anomalous data access. Additionally, Data Access audit logs must be preserved for five years in an immutable state, while preventing project-level administrators from modifying retention policies or disabling audit log collection. Which architectural solution fulfills these compliance and security requirements?
A global retail firm is migrating its legacy inventory management system to Google Cloud. The environment consists of a archive of unstructured product catalog images and a operational PostgreSQL database. The on-premises facility has a shared internet uplink that must remain available for active business operations. The migration must complete within a target window of 14 days with minimal database downtime during cutover. Which migration strategy should the Cloud Architect recommend?
An enterprise architecture team needs to prevent developers across all Google Cloud projects from granting IAM permissions to external Google accounts outside the corporate Cloud Identity directory. This governance control must apply automatically across all existing and newly created folders and projects within the organization. Which architectural approach should the team implement to meet this requirement?
A multinational financial services company operating on Google Cloud needs to implement automated threat detection and immediate remediation for misconfigured resources (such as publicly exposed storage buckets or anomalous service account key creation) across hundreds of projects. Additionally, compliance requirements mandate that all Admin Activity and Data Access audit logs must be immutable and centralized in a manner that prevents project-level resource administrators from modifying or deleting their own project audit records. Which architecture strategy best satisfies these operational and security compliance requirements?
Your enterprise cloud architecture team is establishing an automated, secure progressive delivery pipeline using Cloud Build, Artifact Registry, Binary Authorization, and Google Cloud Deploy. In what chronological sequence should the pipeline execution steps occur to safely roll out a new microservice release from code build to full production traffic?
Drag items to arrange them in the correct order
A security administration team needs to grant a group of compliance auditors read-only access to inspect resource configurations and review IAM policies across all projects grouped under a specific department folder in Google Cloud. Which TWO role assignments at the folder level satisfy these requirements while adhering to the principle of least privilege?
Select all that apply
A retail enterprise is configuring a Cloud Logging sink to route operational logs from multiple Compute Engine projects into a centralized Cloud Storage bucket located in a dedicated security project. The log sink is configured using a sink-specific writer identity service account. According to Google Cloud security best practices and the principle of least privilege, which IAM role assignment should be applied to the destination bucket?
A high-throughput logistics firm uses Google Cloud Deploy to automate release pipelines for a mission-critical fleet management service running on Google Kubernetes Engine (GKE). The team is configuring a progressive release strategy that deploys candidate releases through a canary phase followed by automated rollout to production GKE targets upon successful validation. The release management team needs to ensure the execution service account used by Cloud Deploy has minimal required permissions to perform render and deploy operations on the GKE targets, while preventing infrastructure state corruption during automated Infrastructure as Code (IaC) pipeline runs. Which combination of IAM roles and pipeline state management configurations should be implemented to satisfy these operational and security requirements?
A biotechnology enterprise manages its Google Cloud infrastructure using a resource hierarchy where all production applications reside inside a folder named 'Production-Workloads'. The security governance board mandates that service account key creation must be blocked across all projects within this folder to reduce exposure to credential leaks. However, a legacy data ingestion project inside 'Production-Workloads' relies on service account keys and cannot be immediately refactored until a Workload Identity Federation migration completes. Which approach should the cloud architect implement to enforce this governance requirement with minimal operational complexity?
A security architect is configuring an enterprise-wide audit logging solution in Google Cloud Platform to stream Cloud Audit Logs from an entire organization to an external SIEM system via Pub/Sub. In what sequence should these steps be executed to establish the log export pipeline successfully?
Drag items to arrange them in the correct order
A gaming company is deploying a fleet of GPU-accelerated Compute Engine virtual machines in the us-central1 region using Terraform to host an upcoming real-time gaming event. Pre-deployment testing in a low-scale development environment completed successfully. However, when the automated CI/CD deployment pipeline executes the production Terraform apply job to provision 150 NVIDIA T4 GPUs, the deployment fails instantly before any virtual machines are instantiated. Which action should the Cloud Architect take to resolve this issue?
A global media streaming platform is designing the architecture for a new stateless image processing service on Google Cloud. The service processes incoming HTTP requests containing user uploaded images, converts them into multiple web formats, and returns the result. The workload experiences unpredictable traffic spikes ranging from thousands of requests per second during major events to long periods of complete inactivity overnight. To align with FinOps goals and minimize engineering maintenance, the platform team requires a serverless compute model that automatically scales down to zero instances when idle, charges only during request execution, and requires zero cluster administration or node maintenance. Which compute platform should you recommend?
An enterprise cloud governance architect must enforce baseline security constraints on a newly acquired subsidiary's folder structure within Google Cloud. The governance mandate requires restricting resource deployment exclusively to specified European regions and preventing default service accounts from automatically receiving the Editor primitive role upon API enablement. These policies must apply to all current and future projects under the subsidiary folder without affecting legacy projects outside this folder hierarchy. Which TWO Organization Policy constraints should the architect enforce at the subsidiary folder level to achieve these requirements? (Select TWO)
Select all that apply
An enterprise Cloud Architecture team is establishing an automated progressive release pipeline for a mission-critical microservice deployed to Google Kubernetes Engine (GKE). The release process must integrate Cloud Build, Artifact Registry, Cloud KMS, Binary Authorization, Google Cloud Deploy, and Cloud Monitoring to enforce zero-trust artifact security and automated metric-driven canary verification. Arrange the continuous deployment operational steps in the correct chronological execution sequence from artifact compilation to 100% production traffic cutover.
Drag items to arrange them in the correct order
An energy utility corporation is setting up a secure telemetry processing platform on Google Cloud. The architecture requires a private Google Kubernetes Engine (GKE) cluster for microservices and a Managed Instance Group (MIG) of Compute Engine VMs for legacy batch processing. The operations team will administer the private GKE cluster control plane remotely from an on-premises administrative subnet () over Cloud Interconnect. Automated deployment pipelines using a dedicated service account will provision both the compute infrastructure and workloads. Which TWO configuration steps are required to ensure secure provisioning and access according to Google recommended practices?
Select all that apply
An enterprise security architect must establish organization-wide Data Access audit logging for sensitive Cloud Storage resources, store the logs in an immutable archive encrypted with customer-managed keys, and enable Security Command Center (SCC) detection for storage bucket misconfigurations. Arrange the configuration steps in the correct chronological sequence to implement this operational pipeline.
Drag items to arrange them in the correct order
An organization needs to configure real-time exporting of Google Cloud Security Command Center (SCC) Premium threat findings to an external SIEM solution operating on-premises. Arrange the steps in the correct operational sequence to implement this security log export architecture.
Drag items to arrange them in the correct order
An organization wants to grant a central network administration team permissions to create and manage Virtual Private Cloud (VPC) networks across all Google Cloud projects within a specific department folder. Which IAM role assignment strategy follows Google Cloud best practices for resource hierarchy and least privilege?
An enterprise digital publishing company is modernizing its legacy content delivery architecture on Google Cloud. The solution requires hosting two distinct workloads:
1. A stateless REST API microservice that receives variable public HTTP traffic and must scale to zero during off-peak hours while minimizing operational infrastructure management.
2. A batch processing engine for raw media encoding that requires low-level Linux kernel sysctl parameters and custom OS kernel modules.
Which TWO compute platform choices should the Cloud Architect recommend to fulfill these requirements while optimizing operational efficiency and adherence to Google Cloud best practices? (Select TWO.)
Select all that apply
A financial enterprise is expanding its cloud presence by establishing private, low-latency network connectivity between its on-premises data center and resources deployed across two Google Cloud regions (`us-east4` and `europe-west3`) within a single Custom Mode Virtual Private Cloud (VPC) network. The on-premises connection requires a guaranteed bandwidth of 10 Gbps, and resources in both regions must dynamically exchange routes with on-premises routers without creating separate regional peering loops. Which TWO architectural actions should be implemented to fulfill these requirements?
Select all that apply