Tüm alıştırma soruları
1598 soru
An enterprise security architect wants to prevent developers from creating service account keys and ensure that Compute Engine resources can only be deployed in specific approved Google Cloud regions across all projects contained within the `Production` folder. Which TWO Organization Policy constraints should be configured to satisfy these governance requirements? (Select TWO.)
Geçerli olan tümünü seçin
A security administrator needs to investigate which user modified IAM permissions and created new Compute Engine instances within a project. The administrator requires access to log entries that record administrative actions and configuration changes. Which Cloud Audit Logs category provides this record and is enabled by default across all Google Cloud projects?
A software platform team is automating the provisioning of infrastructure for a single-region transactional order processing system. The architecture requires a relational database deployed across two availability zones for high availability. Compliance guidelines mandate that storage encryption keys must be managed in Cloud KMS with custom rotation control, avoiding direct handling of raw encryption keys by the application team. Additionally, the team must protect the automated deployment pipeline state against concurrency conflicts and state file overwrites. Which combination of provisioning configurations fulfills these requirements?
A smart manufacturing company needs to migrate its regional plant monitoring infrastructure to Google Cloud within a 14-day migration window. The legacy environment consists of a archive of historical sensor logs stored on local NFS storage and a operational PostgreSQL database. The on-premises site has a single dedicated internet connection, and the database cutover requires near-zero downtime.
Which TWO architectural strategies should the team implement to meet these requirements? (Select TWO.)
Geçerli olan tümünü seçin
A security architect is establishing a new Google Cloud resource hierarchy for an enterprise workload. To ensure proper IAM role inheritance and central governance, arrange the initial administrative setup steps in the correct top-down sequence, starting from the highest scope in the resource hierarchy.
Öğeleri doğru sıraya koymak için sürükleyin
A global pharmaceutical company is building a public API service to ingest real-time webhook updates from external clinical research partners. The service workload is stateless, containerized, handles standard HTTPS POST requests, and experiences unpredictable traffic spikes interspersed with prolonged periods of complete inactivity. The enterprise architecture guidelines mandate zero server maintenance, fast automatic scaling down to zero instances during idle periods, and eliminating baseline running costs. Which compute platform should the Cloud Architect select to meet these requirements?
A cloud security architect is designing an enterprise security monitoring strategy for a multi-project Google Cloud organization. The security operations team requires real-time automated threat detection for security anomalies across all infrastructure and wants to centralize all organization-wide audit logs for export to an external Security Information and Event Management (SIEM) system. Which TWO architectural steps should the architect take to satisfy these requirements?
Geçerli olan tümünü seçin
A financial organization needs to store sensitive audit logs in Google Cloud Storage. Regulatory requirements mandate that the organization retain control of the cryptographic keys using Google Cloud Key Management Service (Cloud KMS) to support automated key rotation. They do not want the operational burden of managing and supplying raw key material for every storage request. Which encryption approach should the cloud architect recommend?
A enterprise architecture team is implementing centralized governance guardrails across their Google Cloud resource hierarchy. They must ensure that development teams cannot allocate external IP addresses to virtual machine instances within the Development folder. Additionally, they must restrict API access within the Analytics folder so that projects can only enable approved Google Cloud services (such as Cloud Storage and BigQuery). Which TWO configuration steps should the cloud architect execute using Organization Policies to achieve these requirements? (Select TWO)
Geçerli olan tümünü seçin
An enterprise organization uses a Google Cloud resource hierarchy structured with dedicated folders for Production, Staging, and Development. A central deployment pipeline requires automated authorization to provision Compute Engine instances across all projects under the Production folder. Additionally, the deployment pipeline must attach a dedicated workload service account to these newly provisioned instances. You must enforce the principle of least privilege while minimizing management complexity. Which TWO IAM configuration steps should you execute? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise organization operates a Google Cloud Shared VPC infrastructure with a Host Project for core network management and multiple Service Projects housing distinct microservice applications. The architecture team needs to enable microservices in Service Project A to privately consume an API hosted in an external software vendor's Google Cloud VPC. The solution must strictly prevent transitive network access to other Service Projects attached to the Host VPC, eliminate any risk of IP address space overlap, and avoid routing traffic across the public internet. Which network topology configuration should you implement?
A financial services organization is automating its deployment pipeline using Google Cloud Deploy to manage releases across GKE clusters in staging and production. To ensure compliance and zero downtime during application upgrades, the release process must deploy new microservice revisions to a small percentage of user traffic first, validate service metrics, and support an automated instant rollback if error thresholds are exceeded. Which deployment and automation strategy should the Cloud Architect implement?
A software development company is migrating its infrastructure management from local scripts to Terraform on Google Cloud. During continuous integration runs, multiple automated build workers occasionally attempt to apply changes to the same regional infrastructure concurrently, resulting in state file race conditions and loss of state revision history. Which remote backend strategy should the cloud architect implement to ensure safe concurrent execution and historical state recovery?
An organization is establishing baseline security logging policies across their Google Cloud projects. Which of the following statements accurately describe default behavior and capabilities of Google Cloud Audit Logs? (Select TWO)
Geçerli olan tümünü seçin
A multinational retail company structures its Google Cloud environment with dedicated folders for regional business units underneath the organization node. A third-party compliance agency requires read-only access to review IAM policies, asset metadata, and security settings across all projects in the hierarchy. However, company governance strictly prohibits the agency from viewing underlying application data stored within Cloud Storage objects or database instances. Which IAM configuration fulfills these requirements while maintaining least privilege and minimizing management overhead?
A multinational financial services enterprise manages its Google Cloud environment using a folder hierarchy divided by business units. The security compliance team requires two central guardrails across the entire `Retail-Banking` folder structure: (1) block any Compute Engine virtual machine from being provisioned with an external IP address, and (2) test a restriction against creating service account keys across the organization without breaking existing automated continuous integration pipelines. Which TWO architectural actions should the lead Cloud Architect execute using Google Cloud Organization Policies?
Geçerli olan tümünü seçin
An enterprise security team has configured Cloud Audit Logs to track all read and write operations on sensitive Cloud Storage buckets containing proprietary financial data. However, the security architect wants to ensure that authorized internal users holding valid IAM read permissions cannot copy data from these corporate buckets into external Cloud Storage buckets outside the organizational boundary. Which GCP security component must be implemented alongside IAM to prevent this unauthorized data exfiltration?
An enterprise organization requires centralized compliance logging across all existing and future Google Cloud projects. The security architecture must capture both Admin Activity and Data Access audit logs, ensure that project-level administrators cannot disable or modify log export configurations, and adhere to governance requirements by protecting the centralized storage bucket with keys managed in Cloud KMS. Which strategy should the cloud security architect implement?
An enterprise organization requires real-time security monitoring across all projects in its Google Cloud hierarchy. The security architecture team must stream both Cloud Storage Data Access audit logs and Security Command Center (SCC) Event Threat Detection findings to an on-premises Security Information and Event Management (SIEM) system. The solution must adhere to the principle of least privilege and native Google Cloud security recommendations. Which TWO actions should the security architect perform to meet these requirements?
Geçerli olan tümünü seçin
An enterprise organization is deploying a high-performance analytics platform across 15 newly created Google Cloud projects within a dedicated production folder. The deployment requires provisioning 200 N2 series Compute Engine vCPUs per project in the us-central1 region. Upon checking the newly created projects, the architect observes that the default regional quota for N2 CPUs is insufficient for the planned deployment scale. The deployment must be executed using an automated Infrastructure as Code (IaC) pipeline without causing execution failures or violating security governance principles. Which strategy should the cloud architect implement to manage this resource requirement effectively?