Tüm alıştırma soruları
1598 soru
A financial enterprise is expanding its online payment fraud detection infrastructure across several regional Google Cloud projects. The team plans to deploy multiple Compute Engine N2 compute clusters in a newly added Google Cloud region (`us-east5`) next month. To ensure successful resource deployment without operational interruptions, adhere to least-privilege governance, and control unexpected cloud spend, which TWO actions should the Lead Cloud Architect implement?
Geçerli olan tümünü seçin
A global supply chain management platform runs its core transactional fulfillment service on Compute Engine Managed Instance Groups (MIGs) and Cloud SQL for PostgreSQL in us-central1 as the primary region, with a cross-region read replica in us-east4 for disaster recovery. To meet compliance standards, the organization must regularly validate its business continuity and disaster recovery (DR) procedures. The business requires a Recovery Point Objective (RPO) of under 1 minute, a Recovery Time Objective (RTO) of under 15 minutes, and zero disruption to live customer traffic during validation drills. Which validation procedure should the Cloud Architect implement?
An organization is deploying an analytics microservice in Project A on Google Cloud Compute Engine that must query sensitive BigQuery datasets located in Project B. To comply with strict internal security policies, long-lived service account key export is explicitly forbidden, and privilege escalation risks must be minimized. The microservice needs to securely call BigQuery APIs under the identity of a designated workload service account created in Project B. Which configuration strategy fulfills these operational and security requirements while adhering to the principle of least privilege?
A digital publishing platform is transitioning from a conceptual cloud design to a physical architecture on Google Cloud. The logical architecture requires an event-driven ingestion endpoint for webhooks, a fully managed stateless processing tier to sanitize and transform JSON content, a standard regional relational database for content metadata, and a perimeter security mechanism to prevent data exfiltration to unauthorized external storage. Which physical GCP architecture accurately implements these logical requirements while minimizing operational overhead and unnecessary cost?
An enterprise cloud infrastructure team is provisioning a Virtual Private Cloud (VPC) network to host internal database workloads across two regions (`us-east1` and `us-west1`). The database instances are deployed on Compute Engine virtual machines (VMs) that do not have external IP addresses assigned. The architecture requires that these private instances securely download software patches from public internet repositories and send automated backups to Google Cloud Storage endpoints, while remaining completely inaccessible to inbound traffic from the public internet. Which TWO configuration steps should the cloud architect implement to meet these requirements?
Geçerli olan tümünü seçin
A French biotechnology enterprise is migrating its genomic clinical trial pipeline to Google Cloud. To satisfy strict EU data sovereignty mandates and data governance requirements, the solution must meet three specific criteria:
1. Cryptographic keys used for data at rest must be managed within Cloud KMS hosted in a specified EU region.
2. Google Cloud personnel must obtain explicit customer authorization before accessing data during support operations.
3. Authenticated identities must be prevented from exfiltrating sensitive genomic datasets to external, unauthorized Google Cloud storage resources.
Which combination of Google Cloud security controls satisfies these compliance and governance requirements?
An enterprise microservice running on an on-premises Kubernetes cluster must programmatically access Google Cloud Storage and Cloud Spanner APIs. Enterprise compliance policies strictly prohibit downloading, exporting, or storing long-lived service account JSON key files anywhere on-premises or within deployment manifests. Furthermore, administrative scripts running in automated CI/CD pipelines via the gcloud CLI must execute operations as a targeted service account without managing key files. Which TWO implementation steps must you configure to satisfy these programmatic authentication and CLI requirements?
Geçerli olan tümünü seçin
An online gaming platform's architecture review reveals significant technical debt accumulated during rapid initial scaling on Google Cloud. The audit identifies two major operational and security risks: engineering teams maintain infrastructure using unversioned local Terraform state files stored on developer laptops, and backend service accounts have been granted the primitive Owner role across all GCP projects to simplify component interaction. Which TWO actions should you take to mitigate this technical debt and align with GCP architectural best practices?
Geçerli olan tümünü seçin
A multinational financial services enterprise hosts its core payment authorization pipeline across two Google Cloud regions (primary in us-central1, secondary in us-east4). The enterprise requires a quarterly Business Continuity and Disaster Recovery (BCP/DR) drill to validate cross-region failover efficiency under an RPO target of under 1 minute and an RTO target of under 15 minutes. As the Lead Cloud Architect, you must sequence the technical steps for executing and verifying this DR validation exercise without causing unintended data loss or unexpected service failure. Arrange the operational steps below in the correct execution sequence from first to last.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise organization is setting up a managed relational database infrastructure on Google Cloud for a regional internal application. The system requires full ACID compliance, automated backup capabilities with point-in-time recovery, and compliance with strict data governance mandates requiring customer key management control via Cloud KMS without requiring the operations team to handle raw encryption key material directly. Which database deployment and encryption configuration best fulfills these requirements while avoiding unnecessary cost and operational complexity?
An enterprise energy grid operator is designing a smart meter telemetry and analytics platform on Google Cloud. The conceptual architecture defines three main tiers: a real-time ingestion tier for 10 million smart meters, a streaming processing tier for time-series anomaly detection, and a secure storage tier for time-series analytics that prevents data exfiltration. Which TWO physical Google Cloud service and security configuration choices correctly translate these logical requirements into an optimal physical architecture? (Select TWO)
Geçerli olan tümünü seçin
A biotechnology firm migrated its genomic research data pipelines to Google Cloud by manually creating Compute Engine instances and Cloud Storage buckets via the Google Cloud Console. To accelerate initial experimentation, development teams were granted primitive Owner roles across all GCP projects. A recent technical audit revealed significant operational risk due to untracked configuration drift and excessive user permissions. Which strategy should a Cloud Architect recommend to systematically assess and mitigate this technical debt?
A South African telecommunications provider is building a data analytics platform on Google Cloud to process customer billing records and location telemetry. National regulations require that data must remain strictly within specified geographic boundaries and be protected against exfiltration, even by authenticated users with broad identity permissions. Additionally, encryption keys must be managed through Google Cloud services while respecting regional placement boundaries. Which two architectural controls should you implement to satisfy these compliance and data governance requirements? (Select TWO.)
Geçerli olan tümünü seçin
A digital banking platform on Google Cloud operates a real-time Wire Transfer API and a Monthly Account Statement Generation service. During peak trading hours, minor response delays in the Wire Transfer API lead to contractual financial penalties due to missed settlement windows, yet operations receives no proactive alerts. Meanwhile, scheduled database maintenance routinely triggers critical page alerts for the background statement generator, consuming on-call resources even though statement delivery deadlines are not at risk. Which TWO actions should the Cloud Architect take to align technical Service Level Indicators (SLIs) and Service Level Objectives (SLOs) with business impact?
Geçerli olan tümünü seçin
A fintech company operates an algorithmic trading platform on Google Cloud across multiple environments. The architecture consists of steady-state transaction microservices with predictable 24/7 resource utilization on Compute Engine, alongside analytical data pipelines in BigQuery that experience heavy, unpredictable query spikes during market opening hours. The leadership team mandates establishing a FinOps governance framework that optimizes cloud spend while maintaining performance and enabling precise cost attribution per business unit. Which strategy should the Lead Cloud Architect recommend?
An online streaming catalog platform migrated its metadata ingestion services to Google Cloud using a rapid lift-and-shift strategy. A post-migration architecture review reveals significant operational technical debt: cloud infrastructure is currently managed through unversioned local state files leading to release friction, manual Console changes have introduced configuration drift, and service accounts retain primitive Owner roles across environments. Which TWO actions should the Cloud Architect execute to mitigate this technical debt according to Google Cloud recommended practices? (Select TWO answers.)
Geçerli olan tümünü seçin
A global healthcare genomics enterprise processes petabytes of sequencing data across 45 Google Cloud projects managed under a single Cloud Billing Account. The workload profile consists of steady-state web portals running continuously, unpredictable burst compute clusters processing genomic batches, and massive archival raw sample storage. The organization wants to establish an automated FinOps cost optimization and financial governance strategy without compromising application performance or operational security. Which of the following architectural actions should the enterprise implement? (Select THREE).
Geçerli olan tümünü seçin
An enterprise security architect is designing an automated credential rotation workflow for a PostgreSQL database. The database credentials must be stored in Google Cloud Secret Manager, encrypted using a Customer-Managed Encryption Key (CMEK) stored in Cloud KMS, and automatically rotated every 30 days using a dedicated Cloud Run rotation service triggered by Pub/Sub notifications. You must establish the secure lifecycle configurations and IAM bindings following the principle of least privilege. What is the correct sequence of steps to configure this automated secret rotation workflow?
Öğeleri doğru sıraya koymak için sürükleyin
A smart utility company operates a real-time smart grid monitoring platform on Google Cloud. The architecture uses a GKE cluster and a multi-region Cloud Bigtable instance deployed across a primary region (us-east4) and a secondary DR region (us-west1) to support a strict Recovery Point Objective (RPO) of under 1 minute and a Recovery Time Objective (RTO) of under 15 minutes. The team is developing an automated Disaster Recovery (DR) validation procedure to periodically test failover capabilities without disrupting active operations. Which two procedures should the cloud architect include in the DR validation workflow? (Select TWO.)
Geçerli olan tümünü seçin
An online retail enterprise processes customer transaction data using backend microservices running on Google Cloud, storing the raw logs in BigQuery. The security team mandates two critical protections: first, authorized application service accounts must be strictly prevented from copying or exfiltrating BigQuery data to external, unauthorized Google Cloud projects; second, the public HTTPS entry point must be guarded against web application attacks, such as SQL injection, and volumetric rate abuses. Which TWO architectural controls should the Cloud Architect implement to satisfy these security requirements?
Geçerli olan tümünü seçin