Tüm alıştırma soruları
1598 soru
An enterprise infrastructure team is configuring hybrid network connectivity between an on-premises data center and Google Cloud over a Dedicated Interconnect. On-premises workloads require private access to Google APIs (such as Cloud Storage and BigQuery) through a Private Service Connect (PSC) endpoint provisioned in the hub Virtual Private Cloud (VPC) network. The PSC endpoint has been assigned an internal IP address from the VPC subnet. Which TWO actions must the network architect perform to enable on-premises workloads to successfully reach Google APIs using this Private Service Connect endpoint?
Geçerli olan tümünü seçin
A Canadian healthcare network is migrating its patient analytics platform to Google Cloud. National data sovereignty regulations mandate that all sensitive personal health information remains physically stored within Canada, data encryption keys are managed by the customer within the designated Canadian region, and any emergency administrative access by cloud service provider personnel requires explicit prior authorization and logging. Which architectural strategy fulfills all regulatory requirements while minimizing operational overhead?
A online gaming enterprise hosts two main workloads on Google Cloud: a synchronous Matchmaking Engine that pairs active players for live multiplayer games, and a Weekly Leaderboard Aggregation Pipeline that asynchronously processes player rankings once every seven days. The business requires high player retention during active gameplay sessions, while leaderboard updates can tolerate execution delays of several hours without affecting customer revenue. Which engineering strategy correctly aligns technical Service Level Objectives (SLOs) and Service Level Indicators (SLIs) with the business impact of these two services?
An online gaming enterprise runs its web frontends on Cloud Run, operates dedicated legacy backend engines on Compute Engine instances, and exports massive raw event logs to Cloud Storage. The platform maintains a predictable baseline load throughout the day, supplemented by sharp, unpredictable traffic spikes during live tournament events. The FinOps team requests an organization-wide cost optimization strategy to lower compute and storage expenses while minimizing operational complexity and maintaining low administrative overhead. Which TWO actions should the Cloud Architect recommend?
Geçerli olan tümünü seçin
A global logistics organization manages IoT fleet telemetry pipelines across multiple Google Cloud projects structured within a regional folder hierarchy. The platform engineering team is preparing to launch a fleet telemetry processing cluster in a new expansion region (europe-west9), which requires provisioning 250 Compute Engine N2 virtual machines alongside BigQuery ingestion tables via Infrastructure as Code (IaC). Default project compute quota limits in europe-west9 are insufficient for this workload. To ensure an uninterrupted automated deployment while maintaining proper governance and cost visibility, which action should the cloud architect recommend?
An online insurance platform's backend infrastructure was initially deployed on Google Cloud using ad-hoc automation and direct console actions. An architectural evaluation reveals severe technical debt: developer accounts hold project-level primitive Editor roles, and Terraform state files reside locally on developer laptops without concurrency locking or backup. As the lead cloud architect, which strategy should you recommend to mitigate this technical debt while establishing production governance?
An analytics platform operating on Google Compute Engine virtual machines in a production environment needs to dynamically retrieve database connection credentials stored in Secret Manager. The platform requires automated rotation of these credentials alongside a zero-trust credential posture that completely eliminates long-lived service account key files. Which TWO security controls should the architecture team implement to meet these requirements while following Google-recommended best practices? (Select TWO.)
Geçerli olan tümünü seçin
A semiconductor manufacturing enterprise is translating its conceptual cloud architecture for a real-time wafer defect analysis platform into logical and physical architectures on Google Cloud. The conceptual model establishes three requirements: 1) high-throughput ingestion and low-latency storage of high-frequency sensor telemetry, 2) large-scale analytical processing for yield optimization, and 3) strict data isolation controls preventing data exfiltration to external projects. Which TWO architectural decisions correctly map these conceptual requirements to physical Google Cloud components and controls? (Select TWO)
Geçerli olan tümünü seçin
An organization deploys Compute Engine instances across two regions, us-central1 and europe-west1, within a single custom-mode Virtual Private Cloud (VPC) network. A Cloud Router and Dedicated Interconnect attachment are configured in us-central1 to exchange BGP routes with an on-premises data center. Workloads in us-central1 can communicate with on-premises resources, but workloads in europe-west1 cannot reach on-premises IP ranges because dynamic routes learned by the Cloud Router are missing from the routing table in europe-west1. Which configuration change should the cloud architect implement to enable inter-region dynamic route propagation across the VPC?
A global online gaming platform is designing hybrid network connectivity between its on-premises data center and workloads deployed across multiple Google Cloud regions (`us-central1` and `europe-west1`). The hybrid connection requires a SLA of 99.99% availability and must support a baseline bandwidth of 8 Gbps with sustained peaks up to 15 Gbps. Furthermore, on-premises networks must automatically discover routes to subnets in all GCP regions without manual static route management, while avoiding un-supported transitive routing reliance on VPC Network Peering for third-party service VPCs. Which TWO architectural design choices should the lead cloud architect implement to satisfy these technical requirements? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise financial audit platform processes transaction verification requests using a GraphQL API on Google Kubernetes Engine (GKE). The Site Reliability Engineering (SRE) team needs to establish an alerting strategy to preserve the service's availability Service Level Objective (SLO) of 99.9% over a 30-day rolling window. The team wants to ensure they receive immediate notifications for rapid error budget depletion while avoiding alert fatigue from minor, transient error spikes. Which alerting configuration should the SRE team implement?
An Educational Technology (EdTech) organization hosts its online testing platform on Google Cloud. The platform features two core workloads: an interactive Student Assessment Submission API that directly impacts user grading and customer contractual SLAs, and an asynchronous Student Learning Analytics Pipeline used for internal nightly progress reporting. The organization experiences unnecessary operational friction because both workloads currently share identical availability targets and generic infrastructure alerting. You need to redesign the reliability framework to align technical Service Level Objectives (SLOs) and Service Level Indicators (SLIs) with business impact while preventing burn-out on non-critical outages. Which design strategy should you implement?
A global supply-chain enterprise processes proprietary partner trade records in Google Cloud. Raw telemetry and financial datasets reside in BigQuery and Cloud Storage within a dedicated analytical GCP project. The platform team must fulfill two security mandates: first, mitigate volumetric Layer 7 request floods and web application attacks targeting public API frontend services; second, guarantee that authorized internal data analysts operating within the GCP network cannot exfiltrate analytical datasets to unauthorized external Google Cloud Storage buckets or external GCP organizations. Which TWO architectural solutions must the cloud architect implement to meet these requirements?
Geçerli olan tümünü seçin
An enterprise online food delivery platform is optimizing its Google Cloud footprint as part of a new FinOps governance initiative. The platform operates a steady-state core order-dispatch service on Compute Engine VMs that runs continuously 24/7 with minimal traffic variance. In addition, the platform runs highly unpredictable, bursty machine learning batch jobs for real-time demand forecasting that execute intermittently for 2 to 4 hours a day. The platform engineering team needs to minimize infrastructure costs while establishing clear cost attribution per microservice team. Which cloud architecture and billing strategy should the Cloud Architect recommend?
A financial enterprise is designing a Continuous Integration and Continuous Delivery (CI/CD) pipeline on Google Cloud using Cloud Build and Terraform to manage infrastructure deployments inside a restricted security environment governed by VPC Service Controls. The architecture team requires that the pipeline prevents configuration drift, protects state files against concurrency corruption and exfiltration, and strictly enforces the principle of least privilege. Which TWO architectural controls should be implemented in this CI/CD pipeline design? (Select TWO.)
Geçerli olan tümünü seçin
A retail analytics firm provisions automated data processing jobs using temporary Compute Engine Virtual Machines across multiple sub-projects organized under a dedicated folder. The cloud operations team must ensure that no single sub-project exceeds its allocated infrastructure budget or depletes shared regional quota during peak batch processing windows. Which strategy should the Cloud Architect implement to enforce proactive resource limits and governance across these projects?
A medical SaaS provider operates a telemetry platform on Google Cloud across 40 projects under a single Cloud Billing account. The workload consists of a steady-state API tier on compute resources, predictable database usage, and highly dynamic, bursty data analysis jobs triggered during clinical trial audits. The finance team cannot map costs to specific business units or compute unit costs per active monitoring device, and overall spend is growing faster than revenue. Which combined technical and governance architecture should the Cloud Architect recommend to establish FinOps transparency and maximize cost efficiency?
A digital logistics enterprise operates an automated order-routing engine hosted on Google Cloud. Contractual agreements with major enterprise clients define a Service Level Agreement (SLA) requiring of order-routing requests to be processed in under each month, with financial penalties enforced for non-compliance. The Site Reliability Engineering (SRE) team must align technical metrics with business goals without over-engineering operational overhead. Which strategy correctly establishes the Service Level Indicator (SLI) and Service Level Objective (SLO) to protect business interests?
A multinational retail supply chain platform operates dozens of Google Cloud projects under a central Cloud Billing account. The organization is establishing a formal FinOps function to improve cost visibility, enforce governance, and reduce overall cloud expenditure without compromising workload performance. The architecture includes steady-state core databases, variable microservices, and multi-departmental development environments. Which of the following governance and cost optimization strategies should the lead Cloud Architect recommend? (Select THREE).
Geçerli olan tümünü seçin
A software engineering team is designing a CI/CD pipeline using Cloud Build to automate infrastructure updates with Terraform and deploy microservices to a private Google Kubernetes Engine (GKE) cluster. The pipeline needs to read and update Terraform state files stored in a Cloud Storage bucket, interact with the GKE control plane, and execute containerized deployments. To adhere to Google Cloud security best practices and the principle of least privilege, how should the Cloud Build pipeline permissions and network configuration be designed?