Tüm alıştırma soruları
1591 soru
An engineering team runs an automated batch processing pipeline on a Compute Engine virtual machine residing in `project-analytics`. The script needs to read raw log files stored in a Cloud Storage bucket inside `project-data`. Following Google Cloud security best practices for least privilege and identity management, which approach should be taken to grant the VM access to the storage bucket?
An infrastructure team hosts a critical enterprise order processing application on a fleet of Compute Engine Linux virtual machines. The team needs to collect both guest operating system memory utilization metrics and application logs from a custom log file path at `/var/log/orders/process.log`, forwarding all telemetry to Cloud Logging and Cloud Monitoring using Google's current recommended practices. Which two actions should the team perform to fulfill this requirement? (Select TWO.)
Geçerli olan tümünü seçin
A lead infrastructure engineer is setting up audit log access for a developer team working within a Google Cloud project. The developers currently possess permissions to view standard Admin Activity audit logs, but they are unable to view Data Access audit logs required for troubleshooting data interactions. Following Google Cloud security best practices and the principle of least privilege, which IAM role should be assigned to the developers?
A cloud operations team recently deployed a set of database virtual machines on Compute Engine. While reviewing the Cloud Monitoring dashboard, they observe that hypervisor-level metrics like CPU utilization and network traffic are visible, but guest OS memory utilization and disk space usage metrics are unavailable. Which action should the team take to collect these missing metrics in accordance with Google-recommended practices?
A cloud engineer needs to set up secure, keyless authentication for an external CI/CD pipeline to deploy containerized microservices to Google Cloud Run using Workload Identity Federation. In what order should the engineer perform the following steps to configure the service account identity and authorization according to GCP security best practices?
Öğeleri doğru sıraya koymak için sürükleyin
An organization requires all Cloud Audit Logs from a production project to be exported to a central BigQuery dataset in a dedicated security project for long-term retention and analysis. Which TWO of the following configurations are required to complete this log routing setup successfully? Select two.
Geçerli olan tümünü seçin
A security audit workload needs to periodically list and view all user-managed service accounts and their associated keys within a Google Cloud project named `corp-analytics-prod`. The workload must be granted only the minimum necessary permissions to view service account configurations without the ability to create, delete, modify, or impersonate any service account. Following Google Cloud security best practices and the principle of least privilege, which action should you take?
A security compliance team needs to provide access for an external vulnerability scanner running in an on-premises data center. The scanner must read compute instance details within the project `sec-ops-prod`. Which strategy should the team implement to adhere to Google Cloud security best practices?
A compliance auditor needs to inspect all Cloud Audit Logs for a target Google Cloud project, including sensitive Data Access logs containing personally identifiable information (PII). Following the principle of least privilege, the auditor must be granted read access to these logs without being given access to inspect resource data or perform administrative changes. Which IAM role should be assigned to the auditor?
An operations team has created a log-based metric in Google Cloud Logging to measure HTTP 5xx response counts for an application deployed on Cloud Run. The team needs to ensure on-call engineers receive immediate automated alerts via a webhook when the rate of 5xx errors breaches a specific operational threshold. Which action should the cloud engineer take to complete this configuration?
A cloud engineering team is deploying an automated data ingestion workload on Compute Engine virtual machine instances in a staging project. The workload must read source files from Google Cloud Storage buckets located in a separate production analytics project. Following Google Cloud security best practices for managing service accounts and IAM access, which two configuration steps should the team perform? (Select TWO.)
Geçerli olan tümünü seçin
A security analyst must investigate object access patterns on a sensitive Google Cloud Storage bucket. Place the steps required to grant necessary access, configure audit logging, generate test events, and analyze the resulting logs in the correct sequential order.
Öğeleri doğru sıraya koymak için sürükleyin
An organization manages a fleet of Linux Compute Engine instances hosting an internal application. The operations team needs to collect both system memory utilization metrics and custom log files from these instances. Additionally, they must forward high-severity application error logs to a Pub/Sub topic located in a centralized auditing project. Which TWO actions should the cloud engineer take to implement this solution? (Select TWO)
Geçerli olan tümünü seçin
A company hosts an e-commerce platform across a fleet of Linux Compute Engine virtual machines. The operations team needs to set up an alert whenever system memory utilization exceeds 80%. When configuring a Cloud Monitoring alerting policy, they observe that memory metrics are missing from the available resource metrics list. Which action should you take to make system memory metrics available in Cloud Monitoring?
A team of external compliance reviewers needs permission to inspect Admin Activity audit logs for a target Google Cloud project to verify infrastructure modification events. The reviewers must not be able to view sensitive Data Access audit logs containing user payloads, nor should they receive read or write permissions for project compute and storage resources. Following Google Cloud security best practices and the principle of least privilege, which IAM role configuration should be implemented?
A security analyst needs to review Cloud Audit Logs for a Google Cloud project to investigate access to sensitive data stored in Cloud Storage. The analyst must be able to view both standard logs and Data Access audit logs containing private log entries in the Logs Explorer, while adhering strictly to the principle of least privilege without granting access to project resources or administrative configurations. Which TWO IAM roles should be granted to the security analyst?
Geçerli olan tümünü seçin
A cloud engineering team needs to capture memory utilization metrics and custom file logs from a fleet of Compute Engine virtual machines, sending the logs to a central security project. Which TWO actions should the team perform to meet these requirements using Google Cloud best practices? (Select TWO)
Geçerli olan tümünü seçin
A cloud engineer needs to configure a Compute Engine virtual machine to securely export application logs to Cloud Logging using a dedicated service account and least privilege access. What is the correct sequence of steps to establish this service account authentication flow?
Öğeleri doğru sıraya koymak için sürükleyin
A cloud engineer is configuring identity management for a new background processing workload in Google Cloud. The engineer needs to create a new user-managed service account named `data-processor` within the project `analytics-prod` using the Google Cloud CLI (`gcloud`). Which command should the engineer execute to correctly create this service account?
An operations team needs to track the frequency of specific application error messages captured in Google Cloud Logging from Compute Engine instances and receive email notifications whenever the error rate exceeds a defined threshold. Which TWO actions must be performed to fulfill these requirements?
Geçerli olan tümünü seçin