Tüm alıştırma soruları
1591 soru
A DevOps team is configuring an automated deployment runner in project `proj-ci-runner` that needs to deploy compute resources into target project `proj-prod-app`. Following Google Cloud security best practices, the team wants to avoid long-lived credentials while enforcing the principle of least privilege. Which two actions should the team perform to configure service account access correctly?
Geçerli olan tümünü seçin
A cloud operations engineer creates a custom Log Router sink in Cloud Logging to export critical application logs from a production project to a Pub/Sub topic in a centralized security project. After creating the sink, the engineer observes that log entries are not arriving in the destination topic. Which action must the engineer perform to resolve this issue?
An organization requires that sensitive financial audit logs stored in a Cloud Storage bucket in the europe-west1 region be encrypted using Customer-Managed Encryption Keys (CMEK) managed via Cloud KMS. A cloud engineer creates a Cloud KMS Key Ring named audit-keyring in the us-central1 region and a CryptoKey named audit-key inside it. When attempting to set audit-key as the default encryption key for the europe-west1 Cloud Storage bucket, the command fails. How should the engineer resolve this issue?
A cloud administrator needs to track specific HTTP 500 error patterns contained within application log entries and receive automated notifications whenever the error frequency exceeds a set threshold within a 5-minute window. Which TWO actions should the administrator perform in Google Cloud Observability to meet these requirements?
Geçerli olan tümünü seçin
A security operations team is configuring Cloud KMS key management policies for encryption keys protecting Pub/Sub topics. According to corporate compliance rules, the cryptographic keys must automatically rotate every 90 days. Additionally, if an individual key version is suspected of being compromised, security administrators must immediately render that specific version unusable for encryption and decryption operations while preserving the historical KeyRing structure. Which TWO configurations or management actions should the security administrator execute? (Select TWO)
Geçerli olan tümünü seçin
An organization processes financial batch jobs using a Compute Engine Managed Instance Group (MIG) equipped with an autoscaler. During sudden traffic drops, the autoscaler immediately terminates instances, causing several active, long-running batch jobs to fail prematurely. The cloud engineering team must ensure active jobs complete safely while still allowing the MIG to scale down gracefully when load decreases. Which TWO actions should the team implement to meet these requirements?
Geçerli olan tümünü seçin
A cloud administrator is setting up centralized compliance controls for a data analytics department organized inside a Google Cloud folder named 'Analytics'. The administrator needs to prevent Cloud Storage buckets within any projects under this folder from being publicly accessible, and also ensure that new projects under this folder do not automatically create a default VPC network. Which TWO of the following configurations correctly achieve these objectives using Organization Policies?
Geçerli olan tümünü seçin
An engineer needs to configure a custom service account for an application running on a Google Compute Engine VM instance in project `prod-data-pipeline`. The application requires permission to write objects to Cloud Storage buckets within the project. What is the correct sequence of steps to configure least-privilege access and attach the service account to the VM instance?
Öğeleri doğru sıraya koymak için sürükleyin
A company is setting up Customer-Managed Encryption Keys (CMEK) in Google Cloud KMS to protect sensitive data stored in a BigQuery dataset located in the us-central1 region. Following the principle of least privilege and separation of duties, the infrastructure team needs to allow BigQuery to automatically encrypt and decrypt data using the KMS key, while preventing the BigQuery service account from performing administrative operations on the key. Which configuration correctly satisfies these security requirements?
A DevOps team manages a web microservice behind an External HTTP(S) Load Balancer in Google Cloud. To maintain strict service level objectives, they need to establish an automated alerting system that notifies the Site Reliability Engineering (SRE) team via PagerDuty whenever the HTTP 5xx error rate from the load balancer exceeds 2% of total requests over a 5-minute rolling window. Which configuration sequence in Google Cloud Observability should the team perform to meet this operational goal?
An Associate Cloud Engineer is managing a specialized analytics application deployed on a Compute Engine virtual machine in the us-central1-a zone. To process a new data pipeline, the engineer updates the VM configuration to attach an NVIDIA GPU. When attempting to start the VM, the operation fails with a QUOTA_EXCEEDED error for GPU resources in that zone. The application must remain in us-central1-a due to strict low-latency requirements with adjacent infrastructure. Which action should the engineer take to resolve this issue following Google-recommended practices?
An enterprise organization requires that all Compute Engine virtual machine instances residing within a folder named 'Production' mandate OS Login for user authentication to disable instance-level SSH keys. Which approach correctly enforces this constraint across the resource hierarchy?
A security team alerts a cloud administrator that a specific version of a Cloud KMS CryptoKey used for encrypting database backups may have been exposed. The administrator must quickly stop any new data from being encrypted with the compromised key version while retaining the ability to decrypt existing backups. Additionally, the organization wants to comply with Cloud KMS resource lifecycle constraints. Which two actions should the administrator take to resolve this security incident? (Select TWO)
Geçerli olan tümünü seçin
A cloud administrator needs to grant an external automated system temporary access to collect metrics from Compute Engine instances within a Google Cloud project. To adhere to Google Cloud security standards, the administrator must avoid generating and downloading long-lived service account JSON keys. Which implementation strategy should the administrator select?
An IT operations team needs to set up observability for a fleet of Compute Engine virtual machines. They require collecting detailed system memory and disk utilization metrics, as well as automatically exporting all ERROR and CRITICAL level application logs to a centralized BigQuery dataset located in a separate security administration project. Which TWO actions should the team take to meet these requirements following Google Cloud recommended practices?
Geçerli olan tümünü seçin
A cloud security engineer is tasked with establishing service account governance and credential security standards across several Google Cloud projects. Which of the following administrative actions and security practices align with Google Cloud recommendations for managing service accounts? (Select TWO.)
Geçerli olan tümünü seçin
A DevOps engineer is configuring telemetry collection for a batch processing workload running on Linux Compute Engine virtual machines. Upon opening the Google Cloud Monitoring console, the engineer notices that basic hypervisor metrics such as CPU utilization and disk I/O are visible, but guest OS memory utilization and internal system logs are missing. Which action should the engineer take to collect these missing metrics and logs?
A cloud security administrator needs to prevent Compute Engine VM instances from being assigned external IP addresses across all projects contained within the 'Engineering' folder. Additionally, one specific testing project inside that folder requires external IPs for synthetic user testing. Which two steps must the administrator take to configure this resource hierarchy constraint correctly?
Geçerli olan tümünü seçin
A cloud administration team needs to ensure that IAM roles within a specific organizational Folder can only be granted to user accounts belonging to their verified corporate Google Workspace domain. They want to prevent project owners within that Folder from adding external Gmail or third-party accounts to IAM policies. Which administrative action correctly enforces this restriction across all current and future projects inside the Folder?
An operations team is auditing security compliance for a project in Google Cloud. During the audit, they discover that a developer generated a user-managed JSON service account key for local testing, which violates the organization's credential management policy. The team needs to immediately neutralize this specific compromised credential file without disabling the service account itself, as other production workloads rely on the service account. Which action should the operations team take?