Tüm alıştırma soruları
1591 soru
An organization is setting up detailed cost analytics and needs to export daily Cloud Billing data to a BigQuery dataset located in a central management project. A cloud engineer has already been granted the BigQuery Data Editor role on the destination project and dataset, but receives a permission denied error when attempting to configure the BigQuery export sink in the Google Cloud Console. Which Identity and Access Management (IAM) role must be assigned to the engineer on the Cloud Billing account to successfully complete this export setup?
A centralized accounting department manages a primary Google Cloud Billing Account for your company. To support decentralized resource deployment, project managers require the ability to associate their newly created Google Cloud projects with this central billing account. However, organizational security policies mandate that project managers must not be allowed to view invoice payment histories, change billing account settings, or manage billing permissions. Which IAM role should be assigned to the project managers on the billing account to satisfy these requirements while adhering to the principle of least privilege?
A cloud engineer is configuring command-line administration and compute resources for a stateless, fault-tolerant batch data processing pipeline on Google Kubernetes Engine (GKE). The target cluster `analytics-batch-cluster` is deployed in region `us-central1`. Which TWO configuration steps must the engineer perform?
Geçerli olan tümünü seçin
A cloud engineer manages a stateless application deployed as a Kubernetes Deployment on a Google Kubernetes Engine (GKE) cluster. During peak business hours, CPU usage increases significantly. The engineer needs to automatically scale the number of running application Pods up or down based on CPU utilization metrics. Which Kubernetes resource should the engineer configure?
A logistics enterprise is designing a Google Kubernetes Engine (GKE) cluster architecture to host a real-time tracking system containing two workloads:
1. A stateless API service that ingests location updates continuously.
2. A batch analytics engine that processes bulk telemetry data, can easily recover from unexpected instance terminations, and requires specialized Linux kernel parameters (`sysctl` network tuning) configured at the node OS level.
Which cluster configuration strategy satisfies all technical and operational requirements while optimizing node management and compute costs?
An enterprise is planning a high-availability multi-region network architecture on Google Cloud. The workload requirements specify:
1. Global HTTPS web traffic must support edge caching for static assets and path-based routing to Compute Engine managed instance groups deployed in both `us-central1` and `europe-west3`.
2. Internal microservice RPC traffic running a non-HTTP raw TCP protocol on port 8443 within `us-central1` must be load-balanced with minimal latency across private Compute Engine instances without exposing public IP addresses.
Which TWO load balancing and network service configurations should you select to fulfill these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A network engineering lead at a financial institution is designing a multi-tier enterprise architecture in Google Cloud. The infrastructure requires dedicated Virtual Private Cloud (VPC) subnets across multiple regions for database clusters, web microservices, and internal administrative services. To enforce strict administrative segregation and prevent cross-team network provisioning errors, the security governance team dictates that IP address allocations must be explicitly controlled per subnet without automatic default subnet creation across all GCP regions. Furthermore, the architecture must support future IP space expansion without downtime, while maintaining isolation from legacy on-premises RFC 1918 addresses. Which VPC network design approach best satisfies these requirements?
A cloud engineer needs to apply an automated lifecycle configuration policy file named `lifecycle.json` to an existing Google Cloud Storage bucket named `analytics-raw-data-prod`. According to Google Cloud CLI standards, which command should be executed to apply this lifecycle policy to the bucket?
An online gaming company is planning a Google Kubernetes Engine (GKE) cluster architecture to host two distinct workloads:
1. A stateless, fault-tolerant match history analytics engine that processes asynchronous batch jobs with high sensitivity to compute costs.
2. A specialized security monitoring agent deployed as a DaemonSet that requires low-level custom Linux kernel sysctl parameter modifications on host nodes.
The cloud team wants to minimize cluster management overhead as much as possible while satisfying all technical requirements. Which TWO architectural decisions should the team implement? (Select 2 choices.)
Geçerli olan tümünü seçin
A security auditing team requires access to run SQL queries and analyze table data within a specific BigQuery dataset in the project `finance-analytics-prod`. The team must be able to execute jobs in the project, but company security policy mandates strict adherence to the principle of least privilege, prohibiting the use of primitive roles or broad administrative privileges. Which TWO actions should you perform to grant the minimum required access? (Select TWO.)
Geçerli olan tümünü seçin
A lead cloud engineer at a renewable energy analytics firm needs to authorize a junior site reliability engineer (SRE) to link a newly created project, grid-telemetry-prod, to the company's central Cloud Billing account. Following the Google Cloud principle of least privilege, which combination of IAM roles must be granted to the SRE?
A satellite remote-sensing analytics organization ingests radar dataset files into a Google Cloud Storage bucket. The operations team outlines the following access pattern and compliance lifecycle for the data:
• For the first days after ingestion, dataset files undergo intense processing and are accessed multiple times per day by automated analytical workloads.
• Between day and day , dataset files are queried sporadically (approximately once every days) for custom customer reporting.
• After days, the datasets are accessed less than once per year but must be retained for years to meet regulatory compliance requirements.
Which Cloud Storage bucket lifecycle strategy minimizes the total cost of ownership (TCO) while adhering to storage class minimum duration rules and retrieval cost considerations?
An enterprise application team is preparing to deploy a fault-tolerant, stateless data processing microservice to an existing Google Kubernetes Engine (GKE) Standard cluster. To optimize compute expenses, the cluster administrator has provisioned a secondary node pool using Spot VMs. Which configuration must be included in the application's Deployment manifest to ensure its pods are scheduled only on the Spot VM node pool?
A cloud network architect is planning a Virtual Private Cloud (VPC) network in Google Cloud to support a hybrid enterprise environment connected to an on-premises data center via Cloud VPN. The on-premises network uses the CIDR range for internal services. The planned GCP footprint requires a primary subnet in region `us-central1` starting at and another primary subnet in region `us-east1` allocated at .
Which TWO subnet planning and design requirements must be applied to ensure seamless hybrid connectivity and prevent IP address collisions? (Select TWO.)
Geçerli olan tümünü seçin
A cloud engineering team is expanding a compute-intensive microservices application in project `ecommerce-inventory-prod`. During rollout, the team discovers that deploying additional virtual machine instances in the `us-central1` region will exceed the project's regional Compute Engine `CPUS` resource quota. Which TWO valid strategies can the team use to resolve this regional quota constraint? (Select TWO.)
Geçerli olan tümünü seçin
A solutions architect is planning a multi-region network layout for an enterprise application across two custom-mode Virtual Private Cloud (VPC) networks named `vpc-analytics` and `vpc-services`. The organization plans to establish VPC Network Peering between `vpc-analytics` and `vpc-services` so instances in both networks can communicate using internal IP addresses. Which network planning requirement must be met before creating the VPC Network Peering connection?
A Lead Systems Engineer is configuring a new administrative workstation to manage deployments on an existing Google Kubernetes Engine (GKE) Standard cluster named `analytics-prod-cluster` in region `us-central1`. The engineer has completed authentication via `gcloud auth login` and installed `kubectl`. However, executing `kubectl get pods` results in an error indicating connection attempts to `localhost:8080`. Simultaneously, the team needs to create a new node pool dedicated to processing fault-tolerant, asynchronous batch calculations while keeping compute costs to a minimum. Which pair of actions correctly resolves the command-line authentication issue and fulfills the workload requirement?
A cloud administrator needs to establish command-line management from a local workstation to a newly created Google Kubernetes Engine (GKE) cluster and deploy an application. Which two actions must the administrator perform to authenticate kubectl and deploy the Kubernetes workload? (Select TWO.)
Geçerli olan tümünü seçin
A cloud engineer needs to set up a new Google Cloud Storage bucket for an analytics project, grant read permissions to a designated service account, and upload an initial data file. In what sequence should the engineer execute these operational steps?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise cloud engineer is tasked with configuring financial management controls for a Google Cloud organization. The requirements specify that historical cost metrics must be saved daily to BigQuery for SQL-based cost analysis, and an event-driven mechanism must be established to broadcast real-time messages when monthly project expenditure hits 80% of a defined financial limit. Which TWO configuration steps are required to fulfill these requirements?
Geçerli olan tümünü seçin