All practice questions
174 questions
In what sequence should a Cloud Security Architect configure an organization-level aggregated log sink to stream Data Access audit logs from all child projects into a centralized BigQuery dataset within a dedicated logging project?
Drag items to arrange them in the correct order
A enterprise security architect is auditing access control evaluation for a Google Cloud environment structured with an Organization node, nested Department and Environment Folders, Workload Projects, and Cloud Storage resources. A user requests `storage.objects.get` on a specific bucket. To verify permission resolution and troubleshoot unexpected access results, the architect must trace the exact sequence of Google Cloud Identity and Access Management (IAM) policy evaluation logic.
In what exact sequence does Google Cloud IAM process policy rules and resource hierarchy grants to determine if the user is authorized to perform the action?
Drag items to arrange them in the correct order
An enterprise platform engineering team is setting up an automated Terraform provisioning pipeline for a production Cloud SQL for PostgreSQL database. Security and networking policies require that the database must utilize Customer-Managed Encryption Keys (CMEK), be accessible strictly via private IP over Private Services Access, and enforce IAM database authentication. To ensure an automated execution without resource dependency deadlocks or authorization failures, in what chronological order must these deployment steps be executed?
Drag items to arrange them in the correct order
An enterprise pharmaceutical firm is migrating an on-premises Oracle relational database and historical clinical trial data archives to Google Cloud. The target architecture uses Cloud SQL for PostgreSQL for operational data and Cloud Storage for unstructured archives. To ensure minimal downtime and data integrity during cutover, place the migration workflow steps in the correct chronological order from first to last.
Drag items to arrange them in the correct order
An enterprise cloud architecture team at a global pharmaceutical corporation is establishing a design framework for a new GCP-based clinical trial telemetry platform. The framework requires systematic translation of business goals into provisioned infrastructure. In which sequential order should the cloud architect arrange the architectural design phases, starting from initial business requirements through to final GCP infrastructure deployment?
Drag items to arrange them in the correct order
An enterprise cloud security architect is documenting the evaluation order for Google Cloud Identity and Access Management (IAM) permissions. When a principal requests access to a Google Cloud resource, IAM evaluates policies hierarchically. Place the following evaluation steps in the correct order, starting from the initial policy evaluation check to the final access decision.
Drag items to arrange them in the correct order
An organization requires all Data Access audit logs across all projects in their Google Cloud organization to be centralized into a BigQuery dataset housed within a dedicated security governance project for compliance analytics. In what sequential order should a Cloud Security Architect execute these implementation steps to establish this aggregated log export?
Drag items to arrange them in the correct order
A cloud architect is establishing a secure provisioning workflow to deploy a multi-cluster Cloud Bigtable database for processing real-time trade data. The database must use Customer-Managed Encryption Keys (CMEK) and be accessible only via private network endpoints. In what order should the architect execute these steps to ensure all security and resource dependencies are satisfied?
Drag items to arrange them in the correct order
You need to configure secure, keyless authentication for an external GitHub Actions CI/CD pipeline accessing Google Cloud resources using Workload Identity Federation. What is the correct sequence of steps to establish this setup?
Drag items to arrange them in the correct order
A cloud architect is establishing an automated deployment sequence to provision a high-availability Cloud SQL PostgreSQL database instance using Customer-Managed Encryption Keys (CMEK) and Private Services Access (PSA) within a dedicated VPC. To ensure all infrastructure dependencies and security access controls are satisfied before instance initialization, in what correct sequential order should these provisioning steps be executed?
Drag items to arrange them in the correct order
An enterprise organization is establishing a standardized disaster recovery (DR) validation procedure for a critical multi-region application on Google Cloud. The architecture uses Cloud SQL cross-region read replicas and Compute Engine managed instance groups (MIGs). In what operational sequence should a cloud architect execute the disaster recovery failover drill from start to finish?
Drag items to arrange them in the correct order
An architecture team is establishing an automated progressive release pipeline for a mission-critical microservice deployed on Google Kubernetes Engine (GKE). The deployment process must strictly enforce container security attestations, progressive traffic shifting, and continuous automated health monitoring before achieving full production rollout. Place the operational stages of this release strategy in the correct chronological order from first to last.
Drag items to arrange them in the correct order
An organization is implementing a zero-trust credential architecture to allow workloads running on an external on-premises Kubernetes cluster to retrieve sensitive credentials stored in Google Cloud Secret Manager. To comply with strict security standards, you must eliminate all static, long-lived service account keys and enforce least privilege. Arrange the operational and architectural steps in the correct chronological order required to establish Workload Identity Federation and securely retrieve the secret payload.
Drag items to arrange them in the correct order
An organization is executing a planned disaster recovery (DR) simulation for a critical web application hosted on Google Cloud. Arrange the standard operational steps in the correct chronological sequence to perform the failover and validation procedure.
Drag items to arrange them in the correct order
A principal attempts to execute an API call on a Compute Engine instance residing in a project nested within a folder hierarchy under an Organization node. IAM Deny policies and IAM Allow policies are configured across multiple levels of the resource hierarchy. In what correct chronological order does Google Cloud IAM evaluate these policies to determine whether to authorize or reject the request?
Drag items to arrange them in the correct order
An enterprise security architect needs to configure an organization-wide aggregated Cloud Audit Log pipeline to stream Data Access audit logs from all current and future child projects into a centralized BigQuery dataset in a security management project. Arrange the deployment steps in the correct chronological order required to successfully establish this aggregated sink with least privilege access.
Drag items to arrange them in the correct order
An enterprise architecture team is designing an automated, secure CI/CD pipeline for a microservices application targeted for Cloud Run. To satisfy security and operational requirements, the pipeline must incorporate automated unit testing, container registry storage, security vulnerability scanning, policy validation, and progressive deployment. What is the correct chronological sequence of pipeline steps from initial source code commit to final production release?
Drag items to arrange them in the correct order
An enterprise cloud security architect is auditing how access rights are evaluated across a Google Cloud environment. When a principal attempts an action on a specific resource, IAM permissions are evaluated along the resource hierarchy. Arrange the following evaluation steps in the correct order, starting from the highest ancestor node in the hierarchy down to the specific target resource.
Drag items to arrange them in the correct order
An organization is executing a planned disaster recovery (DR) validation drill for a mission-critical web application on Google Cloud. Arrange the following steps into the correct sequence from first to last to ensure a successful failover test.
Drag items to arrange them in the correct order
A national smart power grid operator ingests real-time telemetry from millions of edge meters into Google Cloud across a primary region (us-central1) and a secondary disaster recovery region (us-east4). The organization must execute a scheduled business continuity validation drill to prove recovery capability without corrupting live state or exceeding target Recovery Point Objective (RPO) and Recovery Time Objective (RTO) limits. In what sequential order should the cloud architecture team execute the following procedure steps to validate regional disaster recovery failover?
Drag items to arrange them in the correct order