Tüm alıştırma soruları
1598 soru
A global media organization recently completed a rapid cloud migration to Google Cloud, resulting in accrued technical debt across their operations. An architectural audit revealed two critical anti-patterns: infrastructure deployment engineers manage environment changes by executing automated Terraform scripts locally using unversioned state files, leading to frequent state corruption; additionally, application service accounts running stateless workloads on Compute Engine were assigned primitive Owner roles to circumvent deployment permission blockers. Which TWO mitigations should the Cloud Architect implement to resolve this technical debt while following Google Cloud recommended practices? (Select TWO answers.)
Geçerli olan tümünü seçin
A financial enterprise processes high-volume trade settlement requests using Google Cloud Pub/Sub, Dataflow, and Cloud Spanner. The business operations team determines that any settlement request taking longer than to complete creates regulatory non-compliance exposure, but the business can tolerate up to of monthly transactions exceeding this threshold before financial penalties occur. As a Cloud Architect aligning technical operations with business risk, how should you structure the service level metrics for this pipeline?
A digital entertainment platform hosts high-throughput microservices in Google Kubernetes Engine (GKE) and stores build artifacts in Artifact Registry. The security operations team requires a Google Cloud-native security architecture that automatically inspects container images for known software vulnerabilities upon repository upload, and continuously monitors runtime container behavior and cloud audit logs for compromised workloads or reverse shells without requiring third-party agent installations. Which TWO security capabilities should the cloud architect recommend? (Select TWO)
Geçerli olan tümünü seçin
A global logistics organization is migrating its core route-optimization platform from an on-premises data center to Google Cloud. The executive leadership team has mandated a strict cutover deadline, but internal operations teams are showing resistance to change due to unfamiliarity with cloud governance, Infrastructure as Code (IaC), and security frameworks. Technically, the architecture requires large-scale Compute Engine instance provisioning across two regions during peak operations and processes sensitive supply-chain data subject to strict data exfiltration prevention policies. Which TWO actions should the Lead Cloud Architect recommend to address stakeholder requirements, manage organizational change, and satisfy technical constraints? (Select TWO.)
Geçerli olan tümünü seçin
An online gaming platform headquartered in Sweden is deploying a new telemetry and payment processing pipeline on Google Cloud. To satisfy strict European regulatory compliance and data sovereignty mandates, the platform must guarantee that all data assets remain physically located within European infrastructure and that Google administrative access to underlying data is logged and requires prior time-bound authorization. Which TWO architectural controls should you implement to satisfy these requirements?
Geçerli olan tümünü seçin
A financial analytics firm structures its Google Cloud environment with a top-level folder named `FinTech-Analytics`. Within this folder, a project named `fraud-detection-prod` runs automated risk-scoring microservices on Compute Engine. The microservices run under a dedicated application service account and must read transaction audit logs stored in a Cloud Storage bucket located inside a separate project named `compliance-data-prod` under the same folder. Furthermore, the developer team requires access to deploy and manage virtual machine instances within `fraud-detection-prod`, but must not be able to modify IAM access policies across the resource hierarchy. Which two IAM configuration steps should you take to adhere to the principle of least privilege? (Select TWO)
Geçerli olan tümünü seçin
An enterprise energy management company is auditing its continuous integration and continuous delivery (CI/CD) pipelines used to deploy infrastructure and microservices on Google Cloud. The automated pipeline executes Terraform via Cloud Build. An audit reveals that the build pipeline currently stores Terraform state files locally inside the transient Cloud Build workspace container, and the Cloud Build service account is assigned the primitive Project Editor role (`roles/editor`). The architecture team must optimize the pipeline to ensure state persistence, prevent state corruption from concurrent runs, and align with least-privilege security standards. Which combination of architectural changes should the team implement?
A financial technology company stores analytical datasets containing sensitive customer transaction records in Google BigQuery. Corporate security policy mandates the use of Customer-Managed Encryption Keys (CMEK) hosted in Cloud KMS. To strictly enforce separation of duties and least privilege, security administrators must manage the key lifecycle without having permissions to query BigQuery dataset contents, while data analysts must run queries without holding permissions to manage or directly invoke Cloud KMS key operations. Furthermore, the BigQuery service must perform encryption and decryption operations automatically on behalf of the analysts. Which architecture and IAM configuration correctly meets these requirements?
A video streaming provider operates a high-throughput live event broadcasting service on Google Cloud. Executive leadership wants to ensure that technical reliability targets directly reflect subscriber retention while avoiding unnecessary operational over-engineering. The product and SRE teams are defining Service Level Indicators (SLIs), Service Level Objectives (SLOs), and error budget policies for the video chunk serving pipeline. Which TWO engineering practices effectively align technical service level metrics with business impact? (Select TWO.)
Geçerli olan tümünü seçin
A multinational logistics company runs mission-critical workloads on Google Kubernetes Engine (GKE). The security team requires a centralized container posture enforcement mechanism that automatically prevents unauthorized image deployments in GKE clusters, scans build artifacts for known vulnerabilities in Artifact Registry, and detects runtime compromise attempts such as reverse shells or cryptocurrency mining at the node and hypervisor level via Security Command Center (SCC) Premium. Which combination of Google Cloud security controls satisfies these security requirements with minimal operational overhead?
An e-commerce platform headquartered in Japan is expanding operations into South Korea. To comply with local regulatory compliance and data sovereignty laws, all customer personally identifiable information (PII) must be stored and processed strictly within South Korean territory. Additionally, cloud service provider personnel must be prevented from accessing customer data without explicit, auditable authorization. As a Cloud Architect, which solution should you implement to satisfy these compliance and governance requirements?
A global video streaming provider is designing hybrid network connectivity between its primary on-premises data center and a Google Cloud VPC hosting low-latency rendering engines. The technical specification demands a minimum throughput of 20 Gbps and a strict 99.99% availability Service Level Agreement (SLA) using direct physical infrastructure. Which TWO architecture steps must the cloud architect execute to satisfy these requirements?
Geçerli olan tümünü seçin
A financial institution is configuring its Google Cloud VPC infrastructure to provide private, secure access to a third-party SaaS provider hosted on GCP. The workload instances reside in private subnets across multiple regions within a single consumer VPC network, and on-premises operators access this VPC via a Dedicated Interconnect connection. The networking design must allow both Google Cloud Compute Engine instances and on-premises clients to access the vendor's service attachment privately without exposing traffic to the public internet or establishing direct VPC Network Peering with the vendor network. Which TWO configuration steps should the network architect implement?
Geçerli olan tümünü seçin
An enterprise freight logistics company hosts its core real-time container tracking application on Google Cloud. The primary workload operates out of `us-central1`, with a secondary disaster recovery (DR) environment prepared in `us-east4` to satisfy a recovery point objective (RPO) of near-zero and a recovery time objective (RTO) of 15 minutes. The architecture team is designing an automated validation procedure for an upcoming unannounced DR simulation drill. The objective is to validate full regional failover capabilities, end-to-end network path integrity, and database readiness while minimizing risk to live production operations. Which TWO operational procedures must be incorporated into the DR validation framework to achieve this goal? (Select TWO.)
Geçerli olan tümünü seçin
A retail enterprise manages its workloads using a Google Cloud resource hierarchy structured with an Organization node and separate parent folders named Non-Production and Production. The Non-Production folder contains multiple projects dedicated to software development and automated testing. An external CI/CD deployment pipeline requires permissions to create, modify, and delete Compute Engine virtual machine instances and attached persistent disks across all current and future projects under the Non-Production folder. The security team requires that the solution minimizes management overhead while enforcing the principle of least privilege. Which IAM role assignment strategy should a Cloud Architect recommend?
A digital banking organization operates a hybrid event-driven microservices platform across Google Kubernetes Engine (GKE) and Cloud Functions. The cloud operations team must establish an end-to-end observability and telemetry architecture to trace multi-service payment transactions in real time, aggregate critical logs, and protect against loss of high-severity application errors while managing costs. Which TWO architectural decisions should the cloud architect implement to fulfill these requirements? (Select TWO.)
Geçerli olan tümünü seçin
An automotive manufacturer is establishing a cloud architecture on Google Cloud to handle real-time telemetry and high-definition map updates for a connected fleet of autonomous vehicles. The conceptual architecture defines three logical tiers: high-throughput regional data ingestion, real-time time-series processing for operational status lookups, and long-term analytical reporting for fleet performance metrics. Which TWO physical GCP component choices correctly translate these logical requirements into Google Cloud resources while maintaining architectural efficiency? (Select TWO.)
Geçerli olan tümünü seçin
A telemetry platform company manages multiple environment folders (`Production`, `Development`) under a single Google Cloud Organization node. The security team needs to grant a deployment service account residing in a dedicated `Tools` project the exact permissions required to attach a workload-specific service account located in the `Production` project to newly created Compute Engine instances. The security team must enforce the principle of least privilege and ensure the deployment service account cannot modify IAM policies or create keys for the target service account. Which configuration should the security architect recommend?
An enterprise e-commerce platform hosts its core transaction services on Google Cloud Compute Engine instances and Cloud Run services. The cloud operations team notices escalating Google Cloud Logging ingestion costs driven by high-volume informational and debug logs. During a recent system outage, post-incident analysis revealed that critical error logs were missing because a broad exclusion filter was applied across all log entries. The lead cloud architect must reduce logging ingestion costs while ensuring that all high-severity error logs are retained in Cloud Logging for real-time operational alerting, and audit logs are archived to Cloud Storage for compliance. Which configuration strategy should the architect implement?
An enterprise operations team needs to establish a centralized observability strategy across multiple Google Cloud projects. They must securely aggregate Cloud Audit Logs into BigQuery for security analytics while ensuring key operational alerts are triggered without exposing telemetry data to exfiltration risks. Which TWO configurations should the team implement to achieve these observability requirements?
Geçerli olan tümünü seçin