Tüm alıştırma soruları
1598 soru
A enterprise compliance team needs to restrict virtual machines from being assigned public IP addresses across a development folder while testing policy impact before enforcing strict blocking. Which TWO actions should a Cloud Architect perform using Google Cloud Organization Policies? (Select TWO)
Geçerli olan tümünü seçin
A cloud architect is configuring network connectivity across three independent Google Cloud Virtual Private Cloud (VPC) networks: VPC-1, VPC-2, and VPC-3. Active VPC Network Peering connections exist between VPC-1 and VPC-2, as well as between VPC-2 and VPC-3. Compute instances in VPC-1 are unable to reach instances in VPC-3 using internal IP addresses. Which network topology configuration is required to allow direct private communication between VPC-1 and VPC-3?
A company organizes its Google Cloud resources into dedicated folders per department. The security team needs to grant a developer group read-only access to object content in all Cloud Storage buckets across all projects contained within the 'Data Analytics' folder. The solution must follow Google recommended best practices for least privilege and operational simplicity. Which IAM role assignment strategy should be implemented?
An enterprise security administrator needs to ensure that virtual machines created inside a specific environment folder cannot be configured with public IP addresses. Which GCP mechanism should be configured at the folder level to enforce this restriction?
An infrastructure engineer needs to provision a managed relational database on Google Cloud for a standard regional web application that requires ACID compliance and automatic high-availability failover. The application does not require global multi-region scaling. Which Google Cloud database service should be provisioned?
A financial data organization is modernizing an API endpoint that receives lightweight HTTP validation requests for market transactions. The workload is entirely stateless, experiences severe traffic fluctuations ranging from zero requests at night to thousands of requests per second during market open, and requires automatic scaling to zero. The lead architect wants to minimize operational overhead by eliminating server management while keeping costs strictly proportional to actual execution time. Which compute platform on Google Cloud best fulfills these requirements?
Arrange the levels of the Google Cloud resource hierarchy in sequence from the highest level (broadest IAM policy inheritance scope) to the lowest level (most specific resource scope).
Öğeleri doğru sıraya koymak için sürükleyin
An network administrator is setting up a hub-and-spoke VPC architecture in Google Cloud. The environment consists of three custom mode VPC networks: `vpc-hub`, `vpc-spoke-1`, and `vpc-spoke-2`. Peering is configured between `vpc-hub` and `vpc-spoke-1`, and between `vpc-hub` and `vpc-spoke-2`. No direct peering exists between `vpc-spoke-1` and `vpc-spoke-2`. Which two statements regarding communication and configuration in this VPC network topology are correct? (Select TWO.)
Geçerli olan tümünü seçin
A global healthcare technology company is deploying a HIPAA-compliant patient monitoring platform on Google Cloud. As the principal cloud architect, you must provision private Google Kubernetes Engine (GKE) clusters using Terraform in a shared Virtual Private Cloud (VPC) environment, ensuring strict control plane isolation, least-privilege automation, and reliable IaC state management. Which THREE architectural configurations and deployment practices should you implement to satisfy these security and operational requirements?
Geçerli olan tümünü seçin
A global supply chain organization is architecting a new containerized route-optimization service on Google Cloud. The service receives stateless HTTP requests from mobile dispatch devices, executes short-lived algorithms requiring less than 15 seconds per request, experiences dramatic traffic fluctuations ranging from 0 to over 50,000 requests per minute during peak operational hours, and must scale down to zero during inactive periods to minimize costs. The organization enforces strict security policies prohibiting unmanaged server infrastructure, and the devops team aims to eliminate Kubernetes control plane management overhead while ensuring minimal cost for idle resources. Which compute platform design should you recommend?
An enterprise cloud engineering team is establishing design documentation standards for new Google Cloud solutions. The lead architect requires team members to clearly differentiate between conceptual, logical, and physical architectural representations during the design phase. Which of the following best describes the core responsibility of a logical architecture in this framework?
A cloud architect needs to provision a new relational database using Cloud SQL with Customer-Managed Encryption Keys (CMEK) enabled. What is the correct chronological sequence of steps required to successfully provision this encrypted database infrastructure?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise e-commerce platform is refactoring its data storage architecture on Google Cloud to support a global expansion across North America and Europe. The new architecture must satisfy two distinct workload requirements:
1. A core transactional order-processing database requiring relational schema support, multi-region active-active write capabilities across continents, sub-10 millisecond latencies, and strict global ACID compliance.
2. A centralized audit logging repository requiring tamper-proof, immutable WORM (write once, read many) storage to satisfy strict regulatory compliance rules for 7 years.
Which TWO architecture decisions should you include in your storage and database design to satisfy these requirements? (Select TWO answers.)
Geçerli olan tümünü seçin
A enterprise security team is implementing governance guardrails across a multitenant Google Cloud environment. They plan to restrict the activation of unauthorized service APIs using the `constraints/gcp.restrictServiceUsage` Organization Policy. However, to avoid disrupting existing workloads currently undergoing active development, the team wants to monitor potential violations in real time and evaluate the impact of the policy without blocking resource creation. Which configuration approach meets these requirements?
A financial services organization is establishing an automated deployment framework using Terraform to manage core Google Cloud infrastructure across multiple enterprise projects. To ensure environment stability, state integrity, and adherence to security best practices, the security team requires that the pipeline prevents concurrent modifications, maintains state history, and operates under least privilege. Which combination of actions should the architecture team implement?
A financial data organization is setting up an automated pipeline to provision a cluster of custom Compute Engine virtual machines in the us-east4 region for nightly risk calculation workloads. During the initial deployment execution, the orchestration system fails immediately with a quota constraint error regarding N2_CPUS before any instances can be created. Which action should the Cloud Architect take to resolve this provisioning failure?
An enterprise cloud architecture team is implementing governance controls for a newly acquired business unit organized under a dedicated Google Cloud folder. The compliance mandate requires that all resource creation be strictly limited to specified approved regions (`us-central1` and `us-east4`). To prevent operational disruptions to ongoing automated deployments, the security team needs to evaluate existing infrastructure and incoming requests for non-compliance without actively blocking deployments during the initial phase. Which TWO actions should the cloud architect take to satisfy these requirements?
Geçerli olan tümünü seçin
A multinational enterprise manages a multi-tier Google Cloud resource hierarchy containing active production workloads across several folders. To comply with new data sovereignty regulations, the security team must restrict all future resource deployments to specified US regions (`in:us-locations`). They need to identify existing non-compliant resources across all projects without disrupting running workloads or blocking active CI/CD deployments during a 30-day evaluation period. Furthermore, once evaluation completes, the restriction must be globally enforced across the entire organization hierarchy while preventing project owners from overriding the constraint. Which Google Cloud strategy achieves these governance objectives?
An enterprise SaaS platform is provisioning a private Google Kubernetes Engine (GKE) cluster to execute secure background analytics workloads. Organization security policy mandates that worker nodes must not be assigned public IP addresses and that management access to the GKE control plane must be strictly restricted to an internal management subnet (10.200.0.0/24). During automated deployment, node provisioning completes successfully, but administrators report that kubectl commands issued from bastion hosts within 10.200.0.0/24 are blocked when reaching the control plane. Additionally, the CI/CD pipeline service account used for deployment has been granted roles/iam.serviceAccountAdmin to allow compute instances to attach to custom service accounts. Which combination of architectural modifications should you recommend to resolve the control plane connectivity failure while enforcing least privilege IAM access?
An enterprise platform engineering team is establishing an automated pipeline to deploy a private Google Kubernetes Engine (GKE) cluster and a fleet of Compute Engine virtual machines in a designated Virtual Private Cloud (VPC). The security compliance policy dictates two requirements: administrative traffic to the GKE control plane must be restricted strictly to specified internal subnet IP ranges, and the CI/CD pipeline's service account must be allowed to configure compute resources to run under dedicated workload service accounts without granting administrative control over those service accounts. Which two configuration actions should you implement to meet these requirements? (Select TWO)
Geçerli olan tümünü seçin