Tüm alıştırma soruları
1598 soru
A smart grid energy company is configuring identity and access management for an IoT telemetry processing application hosted on Compute Engine instances within a dedicated project. The application must read telemetry configuration files from a Cloud Storage bucket and write metric data to Cloud Monitoring. Additionally, developer teams require permissions to deploy updated Compute Engine instances using the application's service account without acquiring administrative access to IAM policies or other resources. Which TWO architectural recommendations follow Google-recommended security best practices? (Select TWO.)
Geçerli olan tümünü seçin
An automotive manufacturer headquartered in Germany is deploying its autonomous vehicle telemetry and clinical research dataset on Google Cloud. To satisfy European Union data sovereignty regulations and internal governance policies, the cloud architecture must strictly ensure two outcomes: first, that storage and compute infrastructure cannot be provisioned outside designated European Union geographic locations; second, that Google support personnel cannot access customer data without explicit, loggable customer approval. Which TWO architectural mechanisms should the Lead Cloud Architect implement to satisfy these compliance requirements? (Select TWO.)
Geçerli olan tümünü seçin
Place the standard stages of a Google Cloud native CI/CD deployment pipeline for containerized applications in the correct sequential order, starting from the developer code commit to the final application deployment.
Öğeleri doğru sıraya koymak için sürükleyin
An educational assessment platform hosted on Google Cloud runs two primary microservices: a real-time Exam Submission API, where any request failure directly interrupts active student testing and breaches compliance rules, and an asynchronous Certificate Generation Service, which processes completion credentials within a 48-hour window. Currently, the engineering team applies a uniform 99.99% availability goal across all microservices, leading to excessive operational toil and unnecessary infrastructure cost. Which strategy should the Cloud Architect implement to properly align technical service levels with business impact?
A multinational SaaS enterprise operating across multiple GCP projects is establishing an organization-wide FinOps governance framework and cost optimization strategy. The current environment consists of steady-state backend API services processing transactional user requests, predictable daily analytical reporting workloads in BigQuery, and highly variable development and testing environments. Which of the following architectural and governance actions should the Cloud Architect recommend to optimize operational spend while enforcing budget accountability? (Select THREE.)
Geçerli olan tümünü seçin
A smart building management provider on Google Cloud experiences deployment instability and security compliance failures resulting from accrued technical debt. An architecture audit revealed two major issues: infrastructure provisioning relies on local Terraform state files saved on individual engineer workstations without concurrency locking, and application workloads run using the default Compute Engine service account bound to project-level primitive Editor roles. Which TWO architectural remediations should the cloud architect implement to mitigate this technical debt? (Select TWO.)
Geçerli olan tümünü seçin
An organization wants to establish an automated CI/CD pipeline on Google Cloud. The pipeline must trigger automatically upon code commits, build container images from source files, and store the compiled images in a secure, fully managed Google Cloud repository. Which combination of Google Cloud services best fulfills these requirements?
An enterprise analytics team is preparing to migrate an operational workload to Google Cloud during an upcoming weekend maintenance window. The target architecture requires provisioning 500 N2 vCPUs in the europe-west3 region within a single Google Cloud project. The project currently maintains standard default regional quota allocations. Which operational procedure should the Cloud Architect recommend to ensure the infrastructure deployment executes without failing due to resource ceiling restrictions?
A healthcare provider operates a telemedicine application on Google Cloud serving two distinct capabilities: a real-time emergency video triage service where disruptions create direct clinical risks and financial penalties, and an asynchronous medical record export service where generation can take up to 24 hours without violating compliance obligations. Currently, engineering applies a uniform 99.99% availability target across all infrastructure components and relies on static CPU utilization thresholds for alerting. During load surges, non-critical batch record export failures trigger high-priority paging alerts, consuming error budgets and exhausting on-call personnel. Which TWO architectural and operational adjustments should the lead cloud architect recommend to align technical service levels with business and clinical impact? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise SaaS provider is setting up hybrid connectivity between its primary on-premises management center and a Google Cloud VPC network. To meet internal reliability mandates, the connection must achieve a 99.99% availability SLA using IPsec encryption and dynamic routing. Which TWO configuration steps must be implemented on Google Cloud to fulfill these HA Cloud VPN requirements?
Geçerli olan tümünü seçin
An enterprise online gaming platform processes real-time multiplayer state and inventory data on Google Cloud, operating primarily out of us-east4 with a disaster recovery (DR) standby target in us-west1. The business mandates a Recovery Point Objective (RPO) of less than 5 seconds and a Recovery Time Objective (RTO) of less than 15 minutes. The lead cloud architect is establishing a validation procedure for bi-annual DR drills to confirm operational readiness and failover execution without disrupting live production traffic. Which of the following procedural steps must be included in the DR validation framework to satisfy these business continuity requirements? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise architecture team is configuring network connectivity between an on-premises data center, a Shared VPC host project acting as a consumer network, and an isolated producer VPC network hosting an internal microservices application. On-premises systems connected via Dedicated Interconnect and Compute Engine workloads residing in service projects attached to the Shared VPC must securely access the producer application. Transitive network routing must not be configured, and overlapping IP ranges between the producer and consumer networks must be tolerated. Which TWO configuration steps should the cloud architect implement to fulfill these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise automotive manufacturer is finalizing the cloud architecture for a global connected vehicle diagnostic platform. The conceptual architecture defines four primary logical requirements: (1) asynchronous ingestion of high-volume telemetry from millions of vehicles, (2) low-latency read/write access for time-series vehicle health metrics, (3) cost-effective long-term archival of raw diagnostic logs for safety compliance, and (4) perimeter isolation to prevent authorized users from exfiltrating data to external Google Cloud projects. Which set of Google Cloud physical services correctly implements this logical design?
A multinational financial technology enterprise headquartered in Brazil is migrating its core payment processing platform to Google Cloud. To comply with local regulatory mandates and strict data sovereignty laws, the cloud solution architecture must satisfy three mandatory requirements:
1. All Cloud Storage buckets and BigQuery datasets storing sensitive customer data must strictly be restricted to provisioning in the `southamerica-east1` (São Paulo) region.
2. All stored data must be encrypted at rest using keys where the organization maintains administrative control over key management, access policies, and rotation schedules in Cloud KMS.
3. Authorized IAM users and service accounts inside the environment must be prevented from exfiltrating data to external Google Cloud projects or non-approved resources.
Which combination of Google Cloud architectural controls satisfies all of these compliance and data sovereignty requirements?
A financial enterprise is establishing a secure CI/CD pipeline using external GitHub Actions runners to deploy infrastructure and retrieve application configuration secrets stored in Google Cloud Secret Manager. The security team mandates a zero-trust model that completely eliminates downloadable long-lived service account keys, enforces strict credential scoping to specific Git repositories, and adheres to the principle of least privilege. Which TWO actions should you incorporate into the architecture to satisfy these security requirements?
Geçerli olan tümünü seçin
Your organization is establishing a secure SDLC pipeline on Google Cloud to ensure that only verified, vulnerability-scanned container images are deployed to Google Kubernetes Engine (GKE). Place the following CI/CD pipeline stages in the correct execution sequence from initial code build to production container deployment.
Öğeleri doğru sıraya koymak için sürükleyin
An application deployed on a Compute Engine virtual machine (VM) needs to read objects from a Cloud Storage bucket programmatically using the Google Cloud SDK. Which approach is the most secure and recommended method to handle authentication for this application?
An enterprise cloud architecture team for a global satellite imagery provider is designing a new cloud solution architecture on Google Cloud to ingest, process, store, and distribute petabyte-scale earth observation data. To ensure alignment with enterprise architecture standards, the team must translate business requirements progressively through conceptual, logical, and physical architecture design phases. Arrange the architectural design activities in the correct sequential order from initial conceptual abstraction down to physical infrastructure enforcement.
Öğeleri doğru sıraya koymak için sürükleyin
A multinational organization operates a hybrid cloud network using a single Google Cloud Virtual Private Cloud (VPC) with subnets in us-central1 and europe-west1. The organization maintains a Dedicated Interconnect connection at a colocation facility in Frankfurt, which connects to a Cloud Router in europe-west1. Administrators observe that on-premises systems in Europe can successfully communicate with Compute Engine instances in europe-west1, but cannot reach instances located in us-central1. How should the Cloud Architect resolve this connectivity issue?
An international commercial airline hosts its mission-critical flight scheduling and crew dispatch platform on Google Cloud, operating primarily out of us-central1 with a secondary disaster recovery deployment in us-east4. The system is designed to meet a Recovery Point Objective (RPO) of under 5 minutes and a Recovery Time Objective (RTO) of under 30 minutes. During a scheduled disaster recovery validation drill simulating a total loss of us-central1, database failover completed within RPO target limits and Cloud DNS failover routing was initiated. However, the secondary region failed to meet the target RTO because Compute Engine instance groups in us-east4 could not scale up to handle production traffic due to unrequested regional vCPU quota limits. Which procedure should the Cloud Architect implement to ensure future disaster recovery validation drills and actual failovers successfully meet business continuity objectives?