Tüm alıştırma soruları
1598 soru
Your engineering team is executing a blue-green deployment strategy for a stateless microservice on Google Kubernetes Engine (GKE) that relies on a Cloud SQL database. In what sequence should you execute these deployment steps to achieve a zero-downtime release?
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise is designing a multi-project CI/CD pipeline on Google Cloud to deploy containerized microservices across staging and production environments. The security team mandates that container images built by Cloud Build in a shared build project must be verified for compliance using Binary Authorization attestations before release. Additionally, deployments to target Google Kubernetes Engine (GKE) clusters must support automated progressive delivery pipelines with mandatory manual approval gates for production targets, while strictly avoiding granting broad administrative permissions to build execution accounts. Which architectural solution satisfies these security and deployment requirements?
A multinational financial enterprise is modernizing its legacy payment-processing system by migrating to Google Cloud. During executive alignment sessions, business stakeholders express deep concerns that rapid architectural changes will disrupt critical quarterly financial reporting and exceed the operational capabilities of existing support teams. As the Lead Lead Cloud Architect, which strategy best aligns Google Cloud technical modernization with business stakeholder change management best practices?
A media enterprise organizes its Google Cloud environment into a parent folder named 'Video-Streaming', which contains sub-folders for 'Transcoding' and 'Distribution'. An automated deployment pipeline using a dedicated service account needs to create and delete Compute Engine VM instances across all projects under both sub-folders. The pipeline must not be granted permissions to modify IAM security policies, manage service accounts, or alter VPC firewall rules. Which IAM role configuration meets these requirements while adhering to the principle of least privilege and minimizing maintenance overhead?
A healthcare organization processes Electronic Health Records (EHR) stored in BigQuery and Cloud Storage inside a dedicated Google Cloud project named Project-Analytics. Authorized analysts access these services from an on-premises datacenter via a Dedicated Interconnect connection. To satisfy regulatory mandates, the security team must enforce two controls: 1) Authorized internal users with valid IAM permissions must be strictly prevented from copying datasets to unauthorized external Google Cloud storage locations or external projects. 2) An analytics service running in a separate VPC inside Project-App must securely query BigQuery in Project-Analytics using internal IP routing, without granting Project-App network visibility to all other resources in Project-Analytics. Which architectural design should you recommend?
An international freight logistics enterprise operates its core container dispatch platform on Google Cloud using `europe-west1` as its primary region and `europe-west4` as a secondary disaster recovery (DR) region. Business operations mandate a Recovery Time Objective (RTO) of 30 minutes and a Recovery Point Objective (RPO) of under 5 minutes. During a scheduled DR validation drill, traffic was switched to `europe-west4`, but compute instance creation failed because the target project lacked sufficient N2 CPU regional quotas in `europe-west4`, breaching the RTO. Which procedure should the cloud architect incorporate into the business continuity and DR validation framework to prevent this failure in future drills?
A cloud engineering team is adopting Terraform to manage infrastructure deployments on Google Cloud. Multiple team members will be executing Terraform configurations simultaneously. Which deployment pattern is the Google Cloud recommended best practice for storing and managing the Terraform state file safely?
An enterprise organization is establishing a centralized governance and resource management framework across its Google Cloud folder hierarchy. The cloud architecture team must implement real-time cost visibility and ensure that large scheduled batch processing jobs run smoothly without hitting infrastructure limits. Which TWO actions should the team implement to satisfy these operational and billing requirements?
Geçerli olan tümünü seçin
A cloud security architect is defining data protection standards across several enterprise applications migrating to Google Cloud. Match each business or regulatory requirement to the appropriate Google Cloud key management or encryption model.
Soldaki öğeye tıklayın, sonra eşleşen sağdaki öğeye tıklayın
Öğeler
Eşleşmeler
An organization is architecting a multi-tenant microservices platform hosted on Google Kubernetes Engine (GKE). Each microservice requires access to third-party API credentials stored in Secret Manager. To satisfy strict enterprise governance standards, all secret versions stored in Secret Manager must be encrypted using Customer-Managed Encryption Keys (CMEK) managed in a dedicated central KMS project, and pods must authenticate without using long-lived downloadable service account JSON keys. Which implementation design best meets these security requirements while enforcing least privilege?
A platform engineering team is establishing automated infrastructure provisioning routines for a regional order processing service on Google Cloud. The architecture requires a managed relational database instance and an object storage bucket for audit logs. Corporate security policies demand that all storage encryption keys remain under central organization management in Cloud KMS without developers handling raw key material, and infrastructure automation must prevent concurrent state modification and accidental state file corruption. Which TWO provisioning configurations should the engineering team implement? (Select TWO.)
Geçerli olan tümünü seçin
A principal cloud architect is tasked with bringing an unmanaged, production Google Cloud environment containing critical Compute Engine and VPC resources under Terraform management. The solution must enforce remote state locking, prevent resource destruction, ensure zero downtime, and align with Google Cloud security best practices. What is the correct sequence of operational steps to safely import the infrastructure and establish managed IaC execution?
Öğeleri doğru sıraya koymak için sürükleyin
A healthcare enterprise is preparing to deploy a clinical data platform across multiple Google Cloud projects organized under a dedicated folder hierarchy. During pre-deployment load testing, the automation scripts failed because default project quota limits for regional Pub/Sub throughput and BigQuery streaming inserts were exceeded. The platform requires high availability and predictable scaling across two target regions. Which operational governance strategy should the Cloud Architect implement to prevent deployment failures while maintaining resource oversight?
An enterprise organization is designing a secure CI/CD pipeline on Google Cloud to deploy microservices to Google Kubernetes Engine (GKE). The pipeline architecture must enforce automated container vulnerability scanning, software supply chain security using Binary Authorization attestations, and progressive delivery governance across staging and production environments. Sequence the steps required to execute a secure deployment from initial source code commit to final production rollout in the correct chronological order.
Öğeleri doğru sıraya koymak için sürükleyin
An engineering team needs to migrate their local Terraform state file to a centralized Google Cloud Storage (GCS) bucket for collaborative management. Arrange the operational steps in the correct sequential order to complete this state migration.
Öğeleri doğru sıraya koymak için sürükleyin
Your organization is planning a blue-green deployment strategy for a critical application hosted on Google Cloud. You must ensure zero downtime during traffic cutover and preserve the ability to execute an instant rollback if issues arise. Which TWO architectural practices are required to safely support this deployment strategy? (Select TWO answers.)
Geçerli olan tümünü seçin
An enterprise operations team is preparing to launch a multi-region application using Compute Engine managed instance groups across three Google Cloud regions via an automated Infrastructure as Code (IaC) CI/CD pipeline. During staging validation for a new target region, the pipeline failed mid-execution because the project reached its default regional compute instance quota. The team needs an operational strategy to prevent automated pipeline failures during future regional expansions while maintaining deployment reliability and security best practices. Which recommendation should you provide to the development and operations teams?
A financial technology enterprise structures its Google Cloud resource hierarchy using dedicated environment folders, including a parent folder named 'Payments-Prod'. The security auditing team requires read-only access to examine Cloud Logging log entries across all current and future projects located beneath the 'Payments-Prod' folder tree. Which IAM configuration adheres to Google Cloud recommended best practices for enforcing least privilege while minimizing administrative overhead?
An online media streaming enterprise hosts two key workloads on Google Cloud: a real-time Live Video Playback API supporting live high-profile sports broadcasts, and an asynchronous Recommendation Generation Pipeline that processes user viewing history overnight to update playlist recommendations. The Site Reliability Engineering (SRE) team needs to define service indicators and objectives that reflect business priorities without creating unnecessary operational overhead. Which TWO strategies should the team implement to align technical SLOs and error budgets with business impact? (Select TWO.)
Geçerli olan tümünü seçin
A biotechnology firm is setting up a secure, isolated environment for a genomic data analytics pipeline in Google Cloud. The lead cloud security architect must establish a resource hierarchy and grant access using custom IAM roles while maintaining minimal operational overhead and strict least-privilege access controls. Arrange the implementation steps in the correct chronological sequence from first to last to establish the resource hierarchy and role inheritance correctly.
Öğeleri doğru sıraya koymak için sürükleyin