Tüm alıştırma soruları
1598 soru
An automotive technology company is setting up Google Cloud compute infrastructure to process real-time telemetry streams from connected vehicles. The architecture requires provisioning a Google Kubernetes Engine (GKE) cluster to run containerized microservices that write processed metrics to BigQuery and Cloud Storage. Corporate security policies require that the cluster control plane is secured against unrestricted public internet access while allowing management access from designated corporate CIDR blocks, and that container pods authenticate to Google Cloud APIs using fine-grained, least-privilege IAM roles without relying on exported long-lived service account keys. Which deployment approach meets these requirements?
A cloud architect is establishing a secure provisioning workflow to deploy a multi-cluster Cloud Bigtable database for processing real-time trade data. The database must use Customer-Managed Encryption Keys (CMEK) and be accessible only via private network endpoints. In what order should the architect execute these steps to ensure all security and resource dependencies are satisfied?
Öğeleri doğru sıraya koymak için sürükleyin
A biomedical research enterprise needs to execute high-throughput genomic processing jobs on Google Cloud. The workload consists of non-HTTP containerized batch tasks that run between 15 and 45 minutes per execution, require GPU acceleration for parallel processing, and run unpredictably based on daily research submissions. The architecture team must select compute platforms that minimize operational management overhead while ensuring zero cost incurred when no jobs are executing. Which TWO compute architecture deployment strategies fulfill these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise financial institution is designing a zero-trust container pipeline and runtime protection architecture on Google Cloud for their mission-critical Google Kubernetes Engine (GKE) clusters. The security policy mandates three operational requirements:
1. Container images stored in Artifact Registry must be automatically analyzed for software vulnerabilities.
2. Only container images verified with cryptographic attestations created during the CI/CD pipeline can be deployed to GKE clusters.
3. Runtime security monitoring must analyze GKE node telemetry and audit streams to detect suspicious container executions, shell spawns, and anomaly events without requiring third-party agent deployments inside individual pods.
Which TWO architectural components must the Cloud Architect integrate to fulfill these security requirements? (Select TWO options.)
Geçerli olan tümünü seçin
A cloud security architect needs to implement continuous container image security for an enterprise application. The requirement is to automatically inspect container images for known software vulnerabilities immediately after they are pushed to Google Artifact Registry. Which Google Cloud solution fulfills this requirement with minimal operational overhead?
An enterprise security team must ensure that authorized users inside an organization cannot exfiltrate sensitive data from Google Cloud Storage buckets into external, unauthorized projects. Which Google Cloud feature should the architecture team implement to establish a security perimeter around these managed service resources?
A media streaming company structures its Google Cloud resource hierarchy into an Organization node with environment folders, including a dedicated Production-Workloads folder and a separate Tools-and-CI project. An automated CI/CD pipeline running on a Compute Engine instance in the Tools-and-CI project uses a dedicated deployment Service Account to manage application compute instances inside projects under the Production-Workloads folder. Developers need to trigger builds that execute deployment tasks through this pipeline, but security governance requires enforcing least privilege while preventing developers from altering the deployment Service Account policy or accessing production instances directly. How should IAM roles and resource hierarchy bindings be configured to meet these requirements?
An enterprise organization is deploying a centralized Shared VPC topology in Google Cloud to connect multiple application service projects with an on-premises environment via Dedicated Interconnect. The architecture must enable a third-party partner organization to securely consume an internal microservice hosted in one of the service projects, while strictly preventing the partner from accessing the on-premises network over the hybrid connection. Additionally, on-premises systems require reliable access to subnets in the service projects. Which TWO network topology configurations should the Cloud Architect implement? (Select TWO.)
Geçerli olan tümünü seçin
A financial enterprise processes sensitive analytical records in BigQuery and archives raw log files in Cloud Storage. Enterprise compliance guidelines specify three mandatory controls:
1. Key Management: Data at rest must be encrypted using Customer-Managed Encryption Keys (CMEK) managed via Cloud KMS to support automated key rotation.
2. Access Governance: Key access must follow the principle of least privilege using predefined IAM roles assigned to dedicated service agents without granting administrative privileges.
3. Perimeter Protection: Data exfiltration must be strictly prevented so that authorized identity credentials cannot copy data to external Cloud Storage buckets outside the organizational boundary.
Which TWO configurations must the security architect implement to fulfill these compliance requirements?
Geçerli olan tümünü seçin
An organization is deploying an internal analytics service in a Producer VPC behind an Internal HTTP(S) Load Balancer. Multiple independent consumer projects with overlapping IP address spaces require secure, private access to this analytics API without enabling full IP routing or VPC Network Peering between the consumer VPCs. Which TWO network topology configurations must you implement to establish this connectivity?
Geçerli olan tümünü seçin
A multinational financial services enterprise operating in South America must host its payment processing workloads and financial transaction archives on Google Cloud while complying with strict central bank data sovereignty mandates and regulatory audit requirements. The compliance framework dictates that all data and primary infrastructure must remain geographically restricted to the São Paulo region, and any emergency administrative access by cloud provider support personnel must require explicit, real-time approval and auditing from the enterprise security team. Which TWO architectural controls should the lead cloud architect implement to meet these requirements?
Geçerli olan tümünü seçin
An international maritime shipping logistics enterprise is designing a modern vessel telemetry and port operations platform on Google Cloud. The architecture team needs to map high-level business goals into conceptual, logical, and physical tiers. The system must ingest high-velocity IoT position and engine diagnostic telemetry from thousands of vessels globally, process stateless tracking pings with minimal infrastructure management overhead, and enforce strict data exfiltration defenses around sensitive manifest records stored in managed storage. Which TWO architectural decisions correctly map these requirements across logical and physical layers? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise organization is automating its continuous deployment pipeline using Google Cloud Deploy to roll out application releases across multiple GKE environments. The architecture team needs to ensure that the infrastructure state files managed by Terraform during pipeline execution are safe from concurrent modification and state corruption, while ensuring the execution service account adheres to the principle of least privilege. Which deployment pipeline configuration should the team implement?
An organization needs to ensure that authorized users cannot copy sensitive data stored in Cloud Storage to external, unauthorized Google Cloud projects. Which Google Cloud security feature should be configured to establish this security boundary?
A security architect is configuring perimeter controls for an enterprise application on Google Cloud. The application backend stores sensitive analytical data that must be guarded against unauthorized data exfiltration, while the public endpoint requires protection against Layer 7 distributed denial-of-service (DDoS) attacks. Which TWO security controls should you implement to satisfy these requirements?
Geçerli olan tümünü seçin
An enterprise team wants to secure their container pipeline on Google Cloud. They need to automatically detect software vulnerabilities in container images stored in Artifact Registry and ensure that only cryptographically signed images can be deployed to Google Kubernetes Engine (GKE). Which TWO security solutions should the cloud architect implement?
Geçerli olan tümünü seçin
An enterprise organization is setting up a hybrid connectivity architecture between an on-premises data center and Google Cloud using Dedicated Interconnect. The architecture uses a single custom-mode VPC network with application subnets deployed in both the us-central1 and europe-west1 regions. Cloud Routers are deployed in both regions to establish BGP sessions with on-premises routers. The lead network architect requires workloads in all GCP regions to dynamically send and receive traffic to and from on-premises through the Interconnect attachments in any region. Which VPC network configuration must be applied to satisfy this requirement?
An organization is deploying application container images to Google Kubernetes Engine (GKE). To prevent unauthorized or untested code from running in production, the cloud security team requires that only container images digitally signed by an approved CI/CD attestation authority can be deployed to the cluster. Which Google Cloud service should the cloud architect configure to enforce this requirement?
An organization is analyzing its automated continuous deployment pipeline, which uses Cloud Build to deploy microservice updates to a Google Kubernetes Engine (GKE) cluster and store images in Artifact Registry. An architecture review reveals that the pipeline currently uses the default Cloud Build service account with broad broad-spectrum project access, violating security compliance guidelines. Which IAM configuration strategy should the cloud architect recommend to secure the CI/CD pipeline while adhering to the principle of least privilege?
An enterprise organization is preparing to migrate its core application workloads to Google Cloud ahead of a major product launch. During pilot testing, automated deployment pipelines failed because the target region exceeded default Compute Engine vCPU limits. Which operational change management practice should the Cloud Architect implement to prevent this deployment disruption?