All practice questions
1598 questions
An enterprise supply chain platform processes high-throughput freight tracking telemetry using a microservices application deployed on Google Kubernetes Engine (GKE), backed by Cloud SQL for PostgreSQL. The development team is preparing to release a major version update that includes non-backward-compatible database schema changes. The business requires zero downtime during release and immediate rollback capabilities if application errors increase. Which TWO implementation steps must the cloud architect mandate to safely execute this release?
Select all that apply
A digital publishing organization is preparing to deploy a serverless document indexing architecture on Google Cloud using Cloud Functions, Eventarc, and Firestore. The lead architect must establish a pre-flight testing and validation procedure to ensure automated infrastructure deployment, quota readiness, and operational stability before releasing to production. Which validation procedure represents Google Cloud best practices for testing technical solutions?
A healthcare company hosts microservices across multiple Google Cloud projects under an organization resource. The operations team requires a centralized observability solution that achieves two main goals:
1. Operational metrics from all workload projects must be visible in a single dashboard without granting engineers administrative or broad resource access to workload projects.
2. Audit logs and critical error logs across all projects must be forwarded automatically to a central security project in real time for ingestion, while keeping lower-severity debug logs localized to their source project.
Which TWO architectural steps should you take to satisfy these requirements according to Google Cloud best practices?
Select all that apply
A healthcare provider is deploying a microservice on Google Kubernetes Engine (GKE) in Google Cloud project `prod-apps`. The microservice requires read-only access to a database password stored securely in GCP Secret Manager located in a separate project, `prod-secrets`. Security governance policy strictly mandates eliminating long-lived service account JSON keys, enforcing least-privilege IAM permissions, and avoiding manual credential management inside pod environments. Which architectural approach satisfies these security and operational requirements?
An enterprise security team needs to establish automated secret rotation for database credentials stored in GCP Secret Manager according to Google Cloud recommended security practices. What is the correct sequence of steps to configure this automated rotation workflow?
Drag items to arrange them in the correct order
A software development team is building an automated CI/CD pipeline task in Cloud Build using the Python Google API Client Library to configure Cloud Logging export sinks across multiple Google Cloud projects. Security policy strictly prohibits storing long-lived service account private keys in source code or storage buckets. To comply with security policies while ensuring seamless API access, how should the team configure authentication for the Python script?
A global media streaming platform hosts its microservices on Google Kubernetes Engine (GKE). The platform team is designing a progressive delivery strategy using Google Cloud Deploy to automate release rollouts across production clusters. The operational objective requires deploying new service revisions using a canary release pattern, gradually advancing traffic from 10% to 100%, while continuously validating application metrics against Cloud Monitoring. If the canary revision's HTTP 5xx error rate exceeds 1% during any evaluation phase, the deployment pipeline must automatically halt progress and roll back traffic to the previous stable release without manual intervention. Which architecture and release configuration best fulfills these requirements?
An online retail platform processes customer orders in the primary region `europe-west1` and maintains a warm standby disaster recovery setup in `europe-west4`. The architecture uses Cloud SQL for PostgreSQL with cross-region asynchronous read replicas and Compute Engine Managed Instance Groups (MIGs) fronted by Cloud Load Balancing and Cloud DNS. Business operational requirements specify a Recovery Point Objective (RPO) of under 1 minute and a Recovery Time Objective (RTO) of under 15 minutes. During a total regional failure of `europe-west1`, which TWO actions must be executed as part of the regional disaster recovery failover runbook? Select 2 response options.
Select all that apply
A software enterprise is designing a comprehensive perimeter defense architecture on Google Cloud. Match each enterprise network security requirement with the most appropriate Google Cloud perimeter security mechanism.
Click a left item, then click its matching right item
Items
Matches
An enterprise organization operates multiple Google Cloud projects under a single Organization resource. The operations and security teams require a centralized logging and observability solution. They need to aggregate high-severity application errors and security audit logs into a central location for long-term compliance analysis, while simultaneously reducing log ingestion costs by filtering out non-critical debug telemetry from individual projects. Which TWO configuration steps should the Cloud Architect recommend to fulfill these requirements? (Select TWO)
Select all that apply
A enterprise SaaS payroll platform runs its primary application tier on Compute Engine Managed Instance Groups (MIGs) and its transactional database on Cloud SQL for PostgreSQL in the primary region `us-east1`. The business continuity requirement specifies a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 2 hours, with strict budget limits preventing a full multi-region active-active deployment. During a scheduled disaster recovery failover exercise to the secondary region `us-central1`, the database read replica was successfully promoted, but compute instance creation in `us-central1` failed due to insufficient regional vCPU quota limits. Which architectural solution should the cloud architect implement to guarantee successful disaster recovery execution while adhering to the RPO, RTO, and cost constraints?
A connected vehicle technology provider operates an API service on Google Cloud Run backed by Cloud SQL for PostgreSQL. The engineering team needs to release a new version of the microservice that introduces a schema modification adding a new column required by the application. The release must guarantee zero downtime and allow seamless immediate rollback to the previous Cloud Run revision if anomalies occur during deployment. Which deployment and database migration strategy should the Cloud Architect recommend?
An automotive telemetry company ingests real-time vehicle diagnostics through an application running on Google Cloud and stores aggregated analytics inside BigQuery. The architecture team must enforce strict perimeter security to satisfy two mandatory requirements:
1. Incoming HTTP(S) traffic from public vehicles must be inspected and filtered at the network edge against Layer 7 web application attacks and SQL injection attempts.
2. Internal service accounts and authorized developers must be restricted from copying or exfiltrating sensitive BigQuery datasets to unauthorized external Cloud Storage buckets, even if they hold valid IAM read permissions.
Which TWO security controls should you implement to meet these requirements?
Select all that apply
A healthcare enterprise is establishing a pre-flight deployment validation procedure on Google Cloud for a patient telemetry microservices application running on private Google Kubernetes Engine (GKE) clusters with sensitive datasets protected by VPC Service Controls. The validation procedure must ensure infrastructure readiness, pipeline safety, and service quality prior to directing live production traffic to new software releases. Which TWO validation practices should be included in the automated pre-deployment testing procedure? (Select TWO.)
Select all that apply
An organization runs an automated Python script on a third-party continuous integration (CI) platform outside Google Cloud. The script programmatically uploads build artifacts to Cloud Storage and writes log entries to Cloud Logging. To adhere to Google Cloud security and operational best practices for programmatic interactions from external environments, which TWO actions should the engineering team perform?
Select all that apply
An enterprise IoT platform ingests telemetry from connected vehicles and serves real-time data to fleet analytics dashboards via a Cloud Load Balancer and backend service. The Site Reliability Engineering (SRE) team defines a Service Level Objective (SLO) requiring 99.9% successful HTTP responses over a rolling 30-day window. The SRE team needs an operational alerting mechanism that detects active, severe budget consumption promptly while eliminating alert fatigue from brief transient errors or slow, non-critical budget consumption. Which alerting strategy should the Cloud Architect recommend?
An enterprise SaaS platform hosts an AI-powered data processing service on Google Kubernetes Engine (GKE) backed by Cloud SQL for PostgreSQL. The team needs to execute a zero-downtime release that includes both a non-breaking database schema modification and a new application version deployment using a canary release strategy. What is the correct sequence of operational steps to perform this release safely?
Drag items to arrange them in the correct order
An enterprise organization operates a web microservice on a Compute Engine Managed Instance Group (MIG) placed behind an External Application Load Balancer. The site reliability engineering team needs to implement a release management policy that supports automated progressive rollout based on real-time HTTP 5xx telemetry, allowing automatic rollback if health thresholds are breached. Furthermore, the accompanying CI/CD automation pipeline must maintain Infrastructure as Code (IaC) state securely without risk of state corruption, while observing strict least-privilege identity controls. Which deployment strategy and configuration should the cloud architect recommend?
A renewable energy utility enterprise is building a smart-grid telemetry platform on Google Cloud. The infrastructure requires a multi-layered perimeter security model to meet strict compliance guidelines. Match each perimeter security requirement on the left with the corresponding Google Cloud security control mechanism on the right that fulfills it.
Click a left item, then click its matching right item
Items
Matches
An enterprise financial institution operates a critical transaction ledger service on Compute Engine Managed Instance Groups (MIGs). The application is heavily network I/O-bound and database connection-bound during peak trading hours. During recent market volatility, transaction latency spiked significantly because the MIG autoscaler failed to add instances, even though overall CPU utilization remained low at approximately . When the operations team attempted an emergency manual scale-out to absorb the load, instance creation failed due to exceeding the regional compute API resource limits. Which combined auto-scaling configuration and capacity planning strategy should a Cloud Architect implement to ensure system reliability during sudden market volatility events?