Tüm alıştırma soruları
1598 soru
A global media streaming platform is migrating its on-premises infrastructure to Google Cloud. The environment includes a 1.2 PB archive of video assets on network-attached storage (NAS) and a live 4 TB PostgreSQL database supporting user metadata. The business requires zero downtime for the database cutover and minimal disruption for video asset migration. Arrange the operational steps in the correct architectural sequence to execute this data transfer and migration strategy.
Öğeleri doğru sıraya koymak için sürükleyin
An organization is preparing to deploy a large-scale batch processing workload using Compute Engine in a newly created Google Cloud project. To ensure a successful deployment following GCP resource governance and quota management best practices, which TWO actions should the Cloud Architect take? (Select TWO.)
Geçerli olan tümünü seçin
A healthcare organization is migrating its digital imaging archive and operational database from an on-premises data center to Google Cloud within a strict 14-day migration window. The data consists of of static DICOM medical imaging files and a transactional PostgreSQL database. The data center has a dedicated internet connection available for data transfer. The application requires that database downtime during the final cutover must not exceed 1 hour. Which migration strategy should you recommend?
An enterprise financial platform operates across multiple Google Cloud folders within an Organization hierarchy. The Site Reliability Engineering (SRE) team is designing a centralized operational logging architecture to route high-severity operational error logs (`severity>=ERROR`) from all current and future projects into a centralized BigQuery dataset located in a dedicated telemetry project `fin-logs-prod`. The solution must ensure that project-level administrators cannot modify or disable the log routing configuration, and the principle of least privilege must be strictly enforced for dataset access. Which TWO configuration steps should you perform to accomplish this architecture?
Geçerli olan tümünü seçin
A cloud engineer needs to provision additional Compute Engine virtual machines for an upcoming batch workload. Upon reviewing the project settings, the engineer discovers that the required core count exceeds the project's current regional CPU quota limit. Which of the following is the standard Google Cloud procedure to ensure the virtual machines can be successfully created?
An enterprise organization operates a multi-folder Google Cloud resource hierarchy. To comply with security governance, the organization must aggregate all Admin Activity and Data Access audit logs across all current and future projects in real time into an external SIEM system, while enabling centralized, agentless threat detection across all workloads. Which solution meets these requirements?
An enterprise cloud security architect needs to enforce governance guardrails across a Google Cloud organization hierarchy. The mandate requires preventing service account key generation centrally while permitting exceptions for a specific development folder. Additionally, the team must evaluate the impact of restricting external IP attachments on compute instances in production before strict enforcement. Which TWO architectural recommendations achieve these governance objectives?
Geçerli olan tümünü seçin
When designing a new cloud solution on Google Cloud, an architect documents the system across different abstraction levels. Arrange the architectural views in order from the highest level of abstraction (business-focused) to the lowest level of abstraction (concrete infrastructure implementation).
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise organization maintains a central Hub VPC network connected to an on-premises data center using Dedicated Cloud Interconnect with Cloud Router dynamic routing. The architecture team provisions two new isolated workloads in Spoke-1 VPC and Spoke-2 VPC, both of which are connected to the central Hub VPC using VPC Network Peering. The application team requires direct private connectivity between Spoke-1 VPC and Spoke-2 VPC, as well as two-way routing between both Spoke VPCs and the on-premises network. Which TWO architectural modifications must be implemented to fulfill these requirements without introducing virtual routing appliances? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise logistics organization is designing the architecture on Google Cloud for two new distinct internal applications. The first application is an event-driven stateless HTTP webhook service that receives unpredictable bursty traffic and must scale to zero instances during quiet hours to minimize idle costs. The second application is a legacy backend routing daemon that requires custom OS kernel network parameters (sysctl tuning) and raw non-HTTP TCP protocol bindings. Which TWO compute architecture options should you select to meet these technical requirements while minimizing operational overhead? (Select TWO)
Geçerli olan tümünü seçin
Your cloud architecture team needs to migrate a local Terraform state file containing critical Google Cloud infrastructure to a centralized, multi-user Google Cloud Storage (GCS) remote backend with state locking and service account impersonation. What is the correct sequence of steps to perform this state migration securely?
Öğeleri doğru sıraya koymak için sürükleyin
A cloud administrator needs to ensure that Compute Engine virtual machines created within a specific environment folder cannot be assigned public IP addresses. Which Google Cloud mechanism should be used to enforce this restriction across all projects within that folder?
An online retail platform uses Cloud Build to automate continuous deployment of microservices to Google Kubernetes Engine (GKE) clusters across staging and production environments. To maintain strict security and governance, the deployment pipeline must run with the minimum permissions required to impersonate the workload's runtime service account, while ensuring that automated Terraform infrastructure updates prevent concurrent state corruption. Which architecture strategy should the cloud team implement?
A DevOps engineer needs to configure access for a service account so that deployment pipelines can attach it to newly created Compute Engine virtual machine instances within a development project. The pipeline should not be granted administrative control over other service accounts or broad management rights over project resources. Which IAM role assignment strategy follows Google Cloud's principle of least privilege?
A cloud security architect is establishing central governance controls across an enterprise Google Cloud environment. The security policy mandates two key compliance rules for all projects residing under the 'Production' folder: first, cloud resources must only be provisioned within US regions; second, developers must be prevented from creating user-managed service account keys. Which TWO administrative actions should the architect perform to enforce these controls? (Select TWO.)
Geçerli olan tümünü seçin
A Site Reliability Engineering (SRE) team needs to set up real-time operational alerting whenever application logs contain critical error events. Sequence the correct administrative steps required to construct a metric-based alerting workflow from Cloud Logging to Cloud Monitoring.
Öğeleri doğru sıraya koymak için sürükleyin
An IoT smart city energy utility enterprise is designing its cloud solution architecture on Google Cloud to handle device management and telemetry processing. The architecture comprises two distinct workloads:
1. A stateless HTTP ingestion endpoint receiving intermittent spikes of JSON payloads from smart meters. The service must scale rapidly during peak hours, scale down to zero instances when idle to reduce costs, and require minimal infrastructure management.
2. A specialized network protocol parser running a long-lived daemon that requires custom OS kernel sysctl modifications for low-level socket buffer tuning and high-speed local NVMe scratch disk access.
Which TWO architectural choices should you select to meet these requirements with optimal operational efficiency? (Select TWO.)
Geçerli olan tümünü seçin
An organization needs to prevent authorized users from exfiltrating sensitive data stored in Cloud Storage buckets to unauthorized external locations outside the organization, even if the users possess valid IAM read permissions. Which Google Cloud security feature should be implemented to enforce this perimeter boundary?
A regional financial enterprise is building a core transaction processing system hosted entirely in a single Google Cloud region (us-east4). The workload requires full SQL compliance, complex table joins, strict ACID transactional consistency, high availability with automatic cross-zone failover, and point-in-time recovery. The enterprise security policy dictates that encryption keys must be managed centrally by the internal security team using Cloud KMS with automated key rotation. To control operational expenditure, the enterprise explicitly wants to avoid paying for globally distributed database infrastructure when regional scope is sufficient. Which storage and database architecture should you recommend to meet these requirements?
A financial enterprise is updating its cloud governance posture across its Google Cloud resource hierarchy. The lead security architect needs to enforce two enterprise-wide governance requirements across all projects under the Production folder:
1. Prevent cloud engineers from generating long-lived service account JSON keys.
2. Prevent Compute Engine virtual machines from being assigned external public IP addresses.
Which TWO Organization Policy constraints must the architect enforce at the Production folder level to satisfy these compliance requirements? (Select TWO.)
Geçerli olan tümünü seçin