Tüm alıştırma soruları
1591 soru
An enterprise is designing a multi-region Google Cloud network topology for two workloads: a public-facing static web portal and a private internal microservices application using gRPC over HTTP/2. The network design must satisfy the following architectural constraints:
1. The public static web portal requires global SSL termination, edge content caching, and web application firewall protection.
2. The internal gRPC microservices must be accessible exclusively from on-premises systems over Dedicated Interconnect and from authorized internal VPC subnets, requiring layer 7 content-based routing and internal load balancing across multiple regions.
Which TWO network architectural components should be included in the design to meet these requirements?
Geçerli olan tümünü seçin
An organization needs to expand an existing subnet within a custom-mode Virtual Private Cloud (VPC) network in Google Cloud to accommodate new virtual machines. The target subnet currently uses the primary IP CIDR block . The VPC network is connected via VPC Network Peering to a partner network using the CIDR block ( to ). Which extended CIDR range can be configured to expand the existing subnet without causing an IP address collision or violating GCP subnet expansion rules?
An enterprise security engineer must configure conditional IAM access for a cloud operational team at the project level. The access must grant the Cloud Functions Developer predefined role (`roles/cloudfunctions.developer`) only for resources whose names start with `prod-`. What is the correct sequential order of steps to programmatically apply and verify this conditional IAM policy update using the `gcloud` CLI?
Öğeleri doğru sıraya koymak için sürükleyin
A DevOps engineer needs to request a regional Compute Engine GPU quota increase for a production project using the Google Cloud Console. What is the correct sequence of steps to perform this request?
Öğeleri doğru sıraya koymak için sürükleyin
A DevOps team needs to optimize storage costs for an application logs bucket named `app-logs-prod` by automatically transitioning objects older than 30 days to Nearline Storage and deleting objects older than 365 days. The configuration must be applied using Google Cloud's current recommended CLI tooling. Which command should the team run to apply the local lifecycle configuration file named `lifecycle.json` to the bucket?
A lead researcher at a university data lab creates a new Google Cloud project to analyze genomic datasets. The researcher has already been granted the Project Owner role (roles/owner) on the new project. However, when attempting to link the project to the university's centralized Cloud Billing Account, the researcher receives a permission error. Following Google Cloud least-privilege best practices, which IAM role must the central billing administrator grant to the researcher on the Billing Account?
An infrastructure team is preparing to deploy a specialized network monitoring workload to Google Kubernetes Engine (GKE). The workload container requires running in privileged mode (`securityContext.privileged: true`) and modifying node-level kernel `sysctl` settings. Which GKE cluster operational mode should the team select to accommodate this requirement?
An operations team is establishing deployment workflows and node architecture for a new fault-tolerant, stateless batch-processing workload on Google Kubernetes Engine (GKE). Engineers need to manage cluster resources from local administrative workstations while minimizing compute infrastructure costs. Which TWO actions should the team implement to fulfill these requirements?
Geçerli olan tümünü seçin
A cloud operations team needs to enforce automated governance by deploying a serverless remediation pipeline that triggers whenever a GCP billing account exceeds defined financial thresholds. In what order should the engineer execute the configuration steps to establish this automated budget notification and remediation workflow?
Öğeleri doğru sıraya koymak için sürükleyin
An Associate Cloud Engineer is tasked with setting up a new isolated environment for a financial analytics team under an existing Google Cloud Organization. The team requires a dedicated workspace where organization policies are pre-enforced before any project is provisioned, and team leads are granted permissions to create projects only within their assigned scope. Place the following administrative steps in the correct sequence to establish this resource hierarchy according to Google Cloud best practices.
Öğeleri doğru sıraya koymak için sürükleyin
An organization operates a custom-mode Virtual Private Cloud (VPC) network connected to an on-premises data center. A critical application deployed in the `us-east4` region resides within a primary subnet using the IP range . Due to an influx of new microservice instances, the cloud engineering team needs to double the IP capacity of this primary subnet without recreating the subnet, causing service downtime, or altering the IP addresses of running Virtual Machines (VMs). Which primary subnet expansion configuration meets these requirements?
An organization wants to delegate resource quota management responsibilities for a production Google Cloud project to a junior operations analyst. The analyst must be able to view current resource quotas and submit formal quota increase requests, but must not be granted permissions to create, modify, or delete infrastructure resources within the project. Which IAM role should be assigned to the analyst to adhere to the principle of least privilege?
A financial technology enterprise generates daily transaction report files. These files are queried continuously by automated analytics pipelines during the first 30 days after creation. Between day 31 and day 90, the files are accessed infrequently for monthly audit checks. After 90 days, the files are rarely accessed but must be retained for 5 years to meet regulatory compliance requirements. Which TWO configuration steps should a Cloud Engineer implement to minimize total storage and data retrieval costs? (Select TWO.)
Geçerli olan tümünü seçin
An organization is deploying a global gaming application on Google Cloud that uses a custom binary non-HTTP protocol over TCP. Clients worldwide must connect to the service with encrypted TLS sessions. To minimize latency, the solution must terminate TLS at Google's global edge network using Google-managed SSL certificates and distribute the decrypted raw TCP traffic to backend Compute Engine instance groups located in multiple regions. Which load balancing architecture should you recommend to meet these requirements?
Place the following steps in the correct chronological sequence to deploy and verify a Compute Engine virtual machine configured with an automated web server startup script.
Öğeleri doğru sıraya koymak için sürükleyin
A cloud engineer is tasked with estimating monthly infrastructure costs using the Google Cloud Pricing Calculator for a mission-critical, high-availability PostgreSQL database running on Compute Engine instances. The workload requires persistent data storage with daily automated backups that will be accessed regularly by automated audit scripts. Which approach in the Pricing Calculator correctly applies GCP billing mechanics and pricing options for this workload?
A digital publishing firm is designing a new containerized document transformation pipeline on Google Cloud. The workload consists of stateless microservices that process uploaded files. The engineering team wants to minimize operational overhead by eliminating the need to manage, size, or patch underlying cluster nodes and node pools. The application does not require custom Linux kernel parameters or privileged container access. Which Google Kubernetes Engine (GKE) cluster architecture should the cloud engineer select to satisfy these requirements?
A cloud engineer needs to deploy a containerized application to a newly provisioned Google Kubernetes Engine (GKE) cluster from a local workstation. What is the correct sequence of steps to configure cluster access, deploy the workload, and verify pod execution?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise platform team is provisioning Google Kubernetes Engine (GKE) infrastructure for two application components. Component 1 is a daemon daemonset that requires privileged kernel capabilities (`CAP_SYS_ADMIN`) and custom hostPath volume mounts to load proprietary kernel modules on the underlying node. Component 2 is a stateless, fault-tolerant data ingestion pipeline designed to handle sudden instance terminations gracefully. Which cluster architecture and node pool strategy correctly supports both components while optimizing cost and operational overhead?
A Cloud Engineer needs to deploy a Cloud SQL for PostgreSQL instance that connects exclusively via private IP to a Virtual Private Cloud (VPC) network and supports regional High Availability (HA). Which TWO configuration actions must be performed to meet these requirements?
Geçerli olan tümünü seçin