Tüm alıştırma soruları
1598 soru
An automotive auction platform is establishing an automated testing procedure to validate new microservices infrastructure on Google Cloud before deploying to production. The automated pipeline provisions isolated, ephemeral staging environments using Terraform, executes automated stress and load tests, and tears down resources. During automated validation runs for major releases, test pipeline executions repeatedly fail due to API quota errors when attempting to launch high-density Compute Engine instances. Additionally, security audits revealed that the CI/CD service account was granted broad administrative privileges to manage service accounts. Which solution should the cloud architect implement to ensure reliable validation procedures while adhering to Google Cloud best practices?
An enterprise e-commerce company manages dozens of Google Cloud projects across multiple product engineering teams. The infrastructure consists of steady-state backend microservices running on Compute Engine alongside highly variable, fault-tolerant batch analytical jobs and ad-hoc data exploration. The centralized FinOps team needs to establish organizational cost governance, improve spending visibility, and reduce overall infrastructure expenditure without restricting developer velocity. Which of the following actions should the Cloud Architect recommend? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise application hosted in an on-premises Kubernetes cluster needs to programmatically upload large batch analytical files to a Google Cloud Storage bucket without using static long-lived service account keys. The security team mandates that the architecture must adhere to the principle of least privilege and prevent credential exfiltration risks. Which of the following configuration steps should the team implement? (Select TWO.)
Geçerli olan tümünü seçin
A online gaming telemetry platform is establishing automated pre-deployment testing procedures on Google Cloud. The infrastructure is provisioned using Terraform and deploys containerized microservices onto private Google Kubernetes Engine (GKE) clusters. To prevent deployment failures during high-traffic game launches and enforce operational security, the cloud architecture team needs to validate solution readiness in the CI/CD pipeline prior to production release. Which TWO validation procedures should the cloud architect incorporate into the automated testing pipeline? (Select TWO.)
Geçerli olan tümünü seçin
An enterprise financial organization stores sensitive customer data in BigQuery datasets within Google Cloud. Security policies mandate that analysts working within the internal network must be able to query the data, but must be strictly prevented from copying or exporting dataset contents to external, non-company Google Cloud Storage buckets or datasets, even if the analysts possess administrative IAM permissions. Which solution should a Cloud Architect implement to meet these security requirements?
An enterprise energy utility company operates a mission-critical smart grid monitoring platform on Google Cloud. The primary infrastructure runs in europe-west3 (Frankfurt), featuring stateless microservices on a Compute Engine Managed Instance Group (MIG) and transactional telemetry data stored in Cloud SQL for PostgreSQL. The company requires a Disaster Recovery (DR) execution plan to fail over to europe-west1 (Belgium). The architecture must guarantee a Recovery Point Objective (RPO) under 1 minute and a Recovery Time Objective (RTO) under 15 minutes, while strictly minimizing ongoing secondary region infrastructure costs during normal operational state. Which disaster recovery strategy should the Cloud Architect implement?
A security team is establishing identity and access management controls for an automated workload running on Compute Engine virtual machines in a workload project `stg-workloads`. The workload requires read access to sensitive database credentials stored in Google Cloud Secret Manager in a centralized security project `sec-mgmt`. Which of the following architectural security controls should be implemented to enforce service account lifecycle security and least privilege access? (Select TWO.)
Geçerli olan tümünü seçin
A digital entertainment platform operates dozens of Google Cloud projects managed by separate game development studios. The workload architecture consists of a steady, predictable baseline of continuous backend telemetry processing, alongside unpredictable, short-lived spikes during live gaming events. The central platform team needs to implement a FinOps governance framework that enforces cost guardrails per studio while optimizing overall compute spend across all projects. Which architecture and cost management strategy should you recommend?
A digital banking SaaS platform operates a critical payment authorization API deployed on Google Kubernetes Engine (GKE). The service has an availability Service Level Objective (SLO) defined as a successful request rate measured over a rolling 30-day window. SRE engineers observed two recurring operational problems: slow, progressive budget consumption going undetected until the 30-day budget was completely exhausted, and transient 2-minute error spikes triggering high-priority pages that resolved prior to engineer intervention. The SRE team needs to establish an alerting strategy in Cloud Monitoring that reliably detects significant error budget consumption while eliminating alert fatigue from transient spikes. Which alerting implementation should the SRE team configure?
An enterprise architecture team is implementing an observability and log management design for an application running on Google Kubernetes Engine (GKE). The team wants to reduce Cloud Logging ingestion costs by preventing verbose application DEBUG logs from being ingested into the `_Default` log bucket, while ensuring that all ERROR-severity application logs and Cloud Audit Logs remain fully available for real-time alerting and compliance export. Which approach correctly achieves this observability strategy without accidentally dropping critical log entries?
A financial payment gateway company hosts its primary transaction processing system on Compute Engine Managed Instance Groups (MIGs) in `us-east1` and maintains a warm standby disaster recovery environment in `us-central1`. The infrastructure utilizes a dedicated hybrid connection to on-premises data centers and connects to central shared security services in another VPC. During a catastrophic regional facility outage in `us-east1`, the incident response team executes their Disaster Recovery (DR) runbook to restore application processing in `us-central1` within an RTO of 15 minutes. Which TWO operational steps must the cloud engineering team perform to successfully execute the DR failover? (Select TWO.)
Geçerli olan tümünü seçin
A platform engineer needs to configure a software developer's local environment to run Python scripts that programmatically manage Google Cloud Storage buckets using Google Cloud Client Libraries. Enterprise security policy strictly prohibits downloading JSON service account keys. The scripts must run using the identity and permissions of a target service account. Place the operational steps in the correct chronological sequence to establish secure programmatic access via Application Default Credentials (ADC) with service account impersonation.
Öğeleri doğru sıraya koymak için sürükleyin
An enterprise engineering team is implementing a zero-downtime Blue-Green release process on Google Cloud for a critical transactional service backed by a Cloud Spanner database. The release includes non-backward-compatible application logic and database schema changes. In which logical sequence should the team perform the deployment operations to ensure zero service disruption and safe rollback capabilities?
Öğeleri doğru sıraya koymak için sürükleyin
A financial services enterprise is establishing a release validation procedure for a mission-critical fraud detection processing system on Google Cloud. As the Principal Cloud Architect, you must sequence the testing and validation phases to ensure zero-downtime deployment, service quota adequacy, and technical solution verification prior to full customer traffic exposure. In what order should these deployment and validation steps be executed from first to last?
Öğeleri doğru sıraya koymak için sürükleyin
A multinational smart grid utility company ingests smart meter telemetry from millions of households into Google Cloud. During extreme weather events, peak message volumes rapidly surge up to six times baseline within a 15-minute window. The processing layer uses Compute Engine Managed Instance Groups (MIGs) pulling telemetry messages from Pub/Sub queues, and the workload is known to be network I/O-intensive rather than CPU-bound. You need to ensure the architecture scales dynamically and maintains operational capacity without message processing delays during sudden load spikes. Which TWO actions should you recommend?
Geçerli olan tümünü seçin
A financial payment platform processes real-time credit transactions on Google Cloud using Compute Engine Managed Instance Groups (MIGs) fronted by an External HTTP(S) Load Balancer. The engineering team is planning a zero-downtime blue-green deployment for a major application revision that includes database schema modifications on Cloud SQL for PostgreSQL. Which TWO architectural and operational steps must the team execute to achieve zero downtime and maintain immediate rollback capabilities? (Select TWO answers.)
Geçerli olan tümünü seçin
A global telematics company operates an automated fleet tracking system in Google Cloud. The primary streaming pipeline runs in `us-central1`, ingesting real-time data via Cloud Pub/Sub, processing it with Cloud Dataflow, and storing state in a regional Cloud Bigtable cluster. In the event of a catastrophic failure in `us-central1`, the operational recovery runbook requires executing a controlled regional failover to `us-east4` with zero data loss for persistent state. What is the correct sequential order of operational steps to execute this disaster recovery failover runbook?
Öğeleri doğru sıraya koymak için sürükleyin
An e-commerce company operates a critical catalog search service deployed on Google Cloud Run backed by Cloud Bigtable. The Site Reliability Engineering (SRE) team established a Service Level Objective (SLO) of 99.9% success rate over a rolling 30-day window. To balance fast detection of catastrophic failures with low false-alarm noise during minor events, which alerting policy should the team implement in Cloud Monitoring?
A global logistics provider is designing an automated testing and release validation procedure for a new real-time fleet telemetry tracking application. The infrastructure deployment uses Terraform scripts to dynamically provision Google Kubernetes Engine (GKE) clusters, Cloud SQL databases, and VPC networking in target regions for automated load testing. Past dry-run deployments failed midway due to regional API quota exhaustion and missing service account permissions, causing inconsistent test environments and corrupted state tracking. Which validation procedure should the Cloud Architect implement to prevent these deployment failures during technical testing?
A DevOps team needs to allow an application running on an external AWS EC2 instance to retrieve database credentials from GCP Secret Manager without creating or downloading service account keys. Sequence the steps required to establish Workload Identity Federation and securely access the secret following Google Cloud security best practices.
Öğeleri doğru sıraya koymak için sürükleyin