All practice questions
1598 questions
An enterprise DevOps team is setting up an automated CI/CD pipeline on a self-hosted runner outside of Google Cloud. The deployment script needs to programmatically execute gcloud CLI commands and custom Python client library scripts to manage infrastructure across multiple target Google Cloud projects. Enterprise security policy strictly prohibits creating, downloading, or storing long-lived service account JSON keys. Which approach should the Cloud Architect recommend to enable secure, programmatic authentication for the pipeline?
An enterprise organization operates hybrid workloads across Compute Engine virtual machines and Google Kubernetes Engine (GKE) clusters. The operations team requires a centralized observability architecture that retains application and system logs for seven years to meet regulatory compliance while enabling real-time alerting for operational anomalies. The architecture must ensure that high-severity logs and security audit trails are guaranteed to be ingested without loss. Which TWO architectural actions should the team implement to fulfill these requirements?
Select all that apply
Match each Google Cloud security product or feature to its corresponding container vulnerability management or threat detection role within an enterprise architecture.
Click a left item, then click its matching right item
Items
Matches
A logistics software platform runs containerized microservices on Google Kubernetes Engine (GKE). The security architect must ensure that container images in Artifact Registry are continuously monitored for newly discovered vulnerabilities, only verified CI/CD container images can be deployed to production GKE clusters, and runtime container threats are detected without installing third-party agent sidecars on the worker nodes. Which combination of Google Cloud services and configurations meets these requirements?
An online retail enterprise requires an external auditing system to read data from BigQuery datasets residing inside multiple Google Cloud projects under a dedicated 'Analytics-Prod' folder. Additionally, the external system must be able to generate short-lived credentials by impersonating a specific managed service account without using static service account keys. Which two administrative actions should you take to fulfill these security requirements while strictly adhering to the principle of least privilege?
Select all that apply
A central security auditing application hosted on a Compute Engine instance needs to programmatically scan metadata and security postures across multiple Google Cloud projects in an organization using the official Cloud Client Libraries. Security governance policies strictly prohibit the creation of exportable, long-lived service account key files and mandate minimal role privilege grants across all target projects. Which TWO configuration choices should you implement to establish secure programmatic authentication for the audit application?
Select all that apply
A cloud architect needs to consolidate all Administrative Activity audit logs from all projects within a Google Cloud organization into a centralized BigQuery dataset for compliance auditing. Which approach represents the recommended Google Cloud observability integration pattern while following security best practices?
An enterprise organization is migrating sensitive customer identity verification files to Cloud Storage. Compliance policy dictates that the key encryption keys (KEKs) must physically reside within the organization's existing on-premises Hardware Security Module (HSM) and that Google Cloud must never store the root key material. Additionally, application developers must not handle raw key material directly in application code or send key bytes within individual HTTP request headers. Which encryption strategy should you recommend?
A global retail company is designing an automated validation procedure for a new microservices-based inventory management platform on Google Cloud. The deployment process must validate infrastructure availability, security compliance, and system performance before pushing releases to production. The environment relies on private Google Kubernetes Engine (GKE) clusters, Terraform for Infrastructure as Code (IaC), and strict VPC Service Controls. Which testing procedure best aligns with Google Cloud recommended best practices for validating this technical solution?
An enterprise financial organization is establishing an automated testing and validation procedure for a high-throughput transaction microservice on Google Kubernetes Engine (GKE). The Cloud Architect must define a sequential validation procedure that ensures static configuration integrity, resource quota readiness, synthetic performance compliance, and production canary safety. In what chronological sequence should the cloud team execute these validation steps?
Drag items to arrange them in the correct order
Your organization is executing a major application update for a mission-critical microservice running on Google Kubernetes Engine (GKE). The release requires a non-backward-compatible database schema change. To meet business requirements of zero downtime and zero data loss, your architecture team chose an Expand-Contract deployment pattern combined with a Blue-Green release traffic shift via GKE Gateway API HTTPRoute resources. Arrange the operational steps below in the correct logical execution sequence from start to finish.
Drag items to arrange them in the correct order
Match each Google Cloud data encryption and key management mechanism to its defining operational control and key lifecycle characteristic.
Click a left item, then click its matching right item
Items
Matches
An enterprise organization is deploying application workloads on Compute Engine virtual machines in Google Cloud. The operations team needs to collect basic system metrics, custom application telemetry, and ensure high-priority error log entries are retained while managing overall logging ingestion volume. Which TWO implementation steps should the Cloud Architect recommend? (Select TWO)
Select all that apply
A digital agriculture enterprise operates a Google Cloud environment to ingest daily IoT sensor data and run seasonal machine learning (ML) crop yield models. The environment features a predictable, 24/7 baseline web and API service alongside bursty, highly variable ML batch processing workloads. Currently, all resources are billed at standard on-demand rates, resulting in high monthly spend. The executive team has mandated a FinOps governance strategy to optimize costs without risking budget lock-in for unpredictable workloads. Which architecture and purchasing strategy should the Cloud Architect recommend?
A logistics company is establishing deployment standards for a new application team that will manage automated GCP infrastructure releases using Cloud Build pipelines. During initial testing, the team encountered failure errors due to insufficient regional VM quotas when deploying large Compute Engine instance groups, and they are unsure of the minimal IAM permissions needed for the build pipeline service account to attach runtime identities to created resources. As a Cloud Architect advising this team, which TWO recommendations should you offer to satisfy operational reliability and least privilege principles?
Select all that apply
An organization is migrating a legacy monolithic web application to Google Cloud. To manage technical debt effectively without delaying the initial cloud adoption schedule, the enterprise wants to reduce operational overhead for database maintenance while avoiding unnecessary application rewrites during the first phase. Which TWO cloud migration strategies should the team adopt? (Select TWO.)
Select all that apply
An enterprise organization is restructuring its Google Cloud resource hierarchy to support autonomous engineering teams across multiple regional projects. The Cloud Architecture team needs to implement centralized cost tracking and prevent service disruptions caused by regional Compute Engine quota limits. Which TWO solutions should the Cloud Architect implement to satisfy these administrative and governance requirements? (Select TWO answers.)
Select all that apply
Your organization is implementing an automated canary release strategy using Google Cloud Deploy and GKE Gateway API for a mission-critical transaction microservice connected to a Cloud SQL relational database. The deployment pipeline must shift traffic incrementally from the active revision to the canary revision while continuously evaluating Cloud Monitoring metrics against a target Service Level Indicator (SLI). The upcoming software release includes a relational database schema update that adds a mandatory field required by the new software version. Which release management approach ensures continuous service availability and automated rollback capabilities during this rollout?
A global EdTech enterprise operates a digital learning platform on Google Cloud across multiple projects under a single organization. Their environment experiences predictable baseline compute usage alongside sharp, seasonal traffic spikes during worldwide examination periods. The analytics pipeline processes multi-terabyte analytical queries in BigQuery with fluctuating on-demand query costs. Additionally, petabytes of historical student assignment media remain stored in Cloud Storage Standard storage classes long after courses complete. The executive team has mandated a comprehensive FinOps initiative to reduce cloud spending and improve cost predictability without impacting platform performance or increasing operational overhead. Which THREE cost-optimization and governance strategies should the Cloud Architect recommend?
Select all that apply
A smart grid energy utility completed a rapid migration of its customer metering infrastructure to Google Cloud. A post-migration technical debt assessment identified two key architecture issues: simple stateless HTTP ingestion microservices are currently running on self-managed Compute Engine virtual machines requiring manual OS patching and fixed compute costs, and sensitive meter telemetry stored in Cloud Storage buckets remains vulnerable to data exfiltration by authorized identity credentials operating outside the enterprise network perimeter. Which TWO architectural mitigations should the Cloud Architect recommend to resolve this technical debt?
Select all that apply