πŸ”

PCA β€” questions

Page 7 of 17 Β· 337 total questions.

Topic 1 Β· Question 121

You need to deploy an application on Google Cloud that must run on a Debian Linux environment. The application requires extensive configuration in order to operate correctly. You want to ensure that you can install Debian distribution updates with minimal manual intervention whenever they become available. What should you do?

  • ACreate a Compute Engine instance template using the most recent Debian image. Create an instance from this template, and install and configure the application as part of the startup script. Repeat this process whenever a new Google-managed Debian image becomes available.
  • BCreate a Debian-based Compute Engine instance, install and configure the application, and use OS patch management to install available updates. (correct answer)
  • CCreate an instance with the latest available Debian image. Connect to the instance via SSH, and install and configure the application on the instance. Repeat this process whenever a new Google-managed Debian image becomes available.
  • DCreate a Docker container with Debian as the base image. Install and configure the application as part of the Docker image creation process. Host the container on Google Kubernetes Engine and restart the container whenever a new update is available.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Create a Debian-based Compute Engine instance, install and configure the application, and use OS patch management to install available updates.

Explanation

Compute Engine provides configurable virtual machines when you need full control of the OS.

Topic 1 Β· Question 122

You have an application that runs in Google Kubernetes Engine (GKE). Over the last 2 weeks, customers have reported that a specific part of the application returns errors very frequently. You currently have no logging or monitoring solution enabled on your GKE cluster. You want to diagnose the problem, but you have not been able to replicate the issue. You want to cause minimal disruption to the application. What should you do?

  • A1. Update your GKE cluster to use Cloud Operations for GKE. 2. Use the GKE Monitoring dashboard to investigate logs from affected Pods. (correct answer)
  • B1. Create a new GKE cluster with Cloud Operations for GKE enabled. 2. Migrate the affected Pods to the new cluster, and redirect traffic for those Pods to the new cluster. 3. Use the GKE Monitoring dashboard to investigate logs from affected Pods.
  • C1. Update your GKE cluster to use Cloud Operations for GKE, and deploy Prometheus. 2. Set an alert to trigger whenever the application returns an error.
  • D1. Create a new GKE cluster with Cloud Operations for GKE enabled, and deploy Prometheus. 2. Migrate the affected Pods to the new cluster, and redirect traffic for those Pods to the new cluster. 3. Set an alert to trigger whenever the application returns an error.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: 1. Update your GKE cluster to use Cloud Operations for GKE. 2. Use the GKE Monitoring dashboard to investigate logs from affected Pods.

Explanation

Google Kubernetes Engine runs managed Kubernetes for containerized, portable workloads.

Topic 1 Β· Question 123

You need to deploy a stateful workload on Google Cloud. The workload can scale horizontally, but each instance needs to read and write to the same POSIX filesystem. At high load, the stateful workload needs to support up to 100 MB/s of writes. What should you do?

  • AUse a persistent disk for each instance.
  • BUse a regional persistent disk for each instance.
  • CCreate a Cloud Filestore instance and mount it in each instance. (correct answer)
  • DCreate a Cloud Storage bucket and mount it in each instance using gcsfuse.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Create a Cloud Filestore instance and mount it in each instance.

Explanation

Filestore provides fully managed NFS file storage that multiple VMs can mount concurrently.

Topic 1 Β· Question 124

Your company has an application deployed on Anthos clusters (formerly Anthos GKE) that is running multiple microservices. The cluster has both Anthos Service Mesh and Anthos Config Management configured. End users inform you that the application is responding very slowly. You want to identify the microservice that is causing the delay. What should you do?

  • AUse the Service Mesh visualization in the Cloud Console to inspect the telemetry between the microservices. (correct answer)
  • BUse Anthos Config Management to create a ClusterSelector selecting the relevant cluster. On the Google Cloud Console page for Google Kubernetes Engine, view the Workloads and filter on the cluster. Inspect the configurations of the filtered workloads.
  • CUse Anthos Config Management to create a namespaceSelector selecting the relevant cluster namespace. On the Google Cloud Console page for Google Kubernetes Engine, visit the workloads and filter on the namespace. Inspect the configurations of the filtered workloads.
  • DReinstall istio using the default istio profile in order to collect request latency. Evaluate the telemetry between the microservices in the Cloud Console.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Use the Service Mesh visualization in the Cloud Console to inspect the telemetry between the microservices.

Topic 1 Β· Question 125

You are working at a financial institution that stores mortgage loan approval documents on Cloud Storage. Any change to these approval documents must be uploaded as a separate approval file, so you want to ensure that these documents cannot be deleted or overwritten for the next 5 years. What should you do?

  • ACreate a retention policy on the bucket for the duration of 5 years. Create a lock on the retention policy. (correct answer)
  • BCreate the bucket with uniform bucket-level access, and grant a service account the role of Object Writer. Use the service account to upload new files.
  • CUse a customer-managed key for the encryption of the bucket. Rotate the key after 5 years.
  • DCreate the bucket with fine-grained access control, and grant a service account the role of Object Writer. Use the service account to upload new files.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Create a retention policy on the bucket for the duration of 5 years. Create a lock on the retention policy.

Topic 1 Β· Question 126

Your team will start developing a new application using microservices architecture on Kubernetes Engine. As part of the development lifecycle, any code change that has been pushed to the remote develop branch on your GitHub repository should be built and tested automatically. When the build and test are successful, the relevant microservice will be deployed automatically in the development environment. You want to ensure that all code deployed in the development environment follows this process. What should you do?

  • AHave each developer install a pre-commit hook on their workstation that tests the code and builds the container when committing on the development branch. After a successful commit, have the developer deploy the newly built container image on the development cluster.
  • BInstall a post-commit hook on the remote git repository that tests the code and builds the container when code is pushed to the development branch. After a successful commit, have the developer deploy the newly built container image on the development cluster.
  • CCreate a Cloud Build trigger based on the development branch that tests the code, builds the container, and stores it in Container Registry. Create a deployment pipeline that watches for new images and deploys the new image on the development cluster. Ensure only the deployment tool has access to deploy new versions. (correct answer)
  • DCreate a Cloud Build trigger based on the development branch to build a new container image and store it in Container Registry. Rely on Vulnerability Scanning to ensure the code tests succeed. As the final step of the Cloud Build process, deploy the new container image on the development cluster. Ensure only Cloud Build has access to deploy new versions.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Create a Cloud Build trigger based on the development branch that tests the code, builds the container, and stores it in Container Registry. Create a deployment pipeline that watches for new images and deploys the new...

Explanation

Cloud Build runs managed CI pipelines to build, test, and package code.

Topic 1 Β· Question 127

Your operations team has asked you to help diagnose a performance issue in a production application that runs on Compute Engine. The application is dropping requests that reach it when under heavy load. The process list for affected instances shows a single application process that is consuming all available CPU, and autoscaling has reached the upper limit of instances. There is no abnormal load on any other related systems, including the database. You want to allow production traffic to be served again as quickly as possible. Which action should you recommend?

  • AChange the autoscaling metric to agent.googleapis.com/memory/percent_used.
  • BRestart the affected instances on a staggered schedule.
  • CSSH to each instance and restart the application process.
  • DIncrease the maximum number of instances in the autoscaling group. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Increase the maximum number of instances in the autoscaling group.

Topic 1 Β· Question 128

You are implementing the infrastructure for a web service on Google Cloud. The web service needs to receive and store the data from 500,000 requests per second. The data will be queried later in real time, based on exact matches of a known set of attributes. There will be periods where the web service will not receive any requests. The business wants to keep costs low. Which web service platform and database should you use for the application?

  • ACloud Run and BigQuery
  • BCloud Run and Cloud Bigtable (correct answer)
  • CA Compute Engine autoscaling managed instance group and BigQuery
  • DA Compute Engine autoscaling managed instance group and Cloud Bigtable
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Cloud Run and Cloud Bigtable

Explanation

Cloud Run runs stateless containers serverlessly and scales to zero, minimizing operational overhead. Cloud Bigtable is a managed, low-latency NoSQL wide-column store for very high-throughput workloads. This option meets the real-time / low-latency performance requirement.

Topic 1 Β· Question 129

You are developing an application using different microservices that should remain internal to the cluster. You want to be able to configure each microservice with a specific number of replicas. You also want to be able to address a specific microservice from any other microservice in a uniform way, regardless of the number of replicas the microservice scales to. You need to implement this solution on Google Kubernetes Engine. What should you do?

  • ADeploy each microservice as a Deployment. Expose the Deployment in the cluster using a Service, and use the Service DNS name to address it from other microservices within the cluster. (correct answer)
  • BDeploy each microservice as a Deployment. Expose the Deployment in the cluster using an Ingress, and use the Ingress IP address to address the Deployment from other microservices within the cluster.
  • CDeploy each microservice as a Pod. Expose the Pod in the cluster using a Service, and use the Service DNS name to address the microservice from other microservices within the cluster.
  • DDeploy each microservice as a Pod. Expose the Pod in the cluster using an Ingress, and use the Ingress IP address name to address the Pod from other microservices within the cluster.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Deploy each microservice as a Deployment. Expose the Deployment in the cluster using a Service, and use the Service DNS name to address it from other microservices within the cluster.

Topic 1 Β· Question 130

Your company has a networking team and a development team. The development team runs applications on Compute Engine instances that contain sensitive data. The development team requires administrative permissions for Compute Engine. Your company requires all network resources to be managed by the networking team. The development team does not want the networking team to have access to the sensitive data on the instances. What should you do?

  • A1. Create a project with a standalone VPC and assign the Network Admin role to the networking team. 2. Create a second project with a standalone VPC and assign the Compute Admin role to the development team. 3. Use Cloud VPN to join the two VPCs.
  • B1. Create a project with a standalone Virtual Private Cloud (VPC), assign the Network Admin role to the networking team, and assign the Compute Admin role to the development team. (correct answer)
  • C1. Create a project with a Shared VPC and assign the Network Admin role to the networking team. 2. Create a second project without a VPC, configure it as a Shared VPC service project, and assign the Compute Admin role to the development team.
  • D1. Create a project with a standalone VPC and assign the Network Admin role to the networking team. 2. Create a second project with a standalone VPC and assign the Compute Admin role to the development team. 3. Use VPC Peering to join the two VPCs.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: 1. Create a project with a standalone Virtual Private Cloud (VPC), assign the Network Admin role to the networking team, and assign the Compute Admin role to the development team.

Explanation

A VPC provides a global, software-defined private network for your Google Cloud resources.

Topic 1 Β· Question 131

Your company wants you to build a highly reliable web application with a few public APIs as the backend. You don't expect a lot of user traffic, but traffic could spike occasionally. You want to leverage Cloud Load Balancing, and the solution must be cost-effective for users. What should you do?

  • AStore static content such as HTML and images in Cloud CDN. Host the APIs on App Engine and store the user data in Cloud SQL.
  • BStore static content such as HTML and images in a Cloud Storage bucket. Host the APIs on a zonal Google Kubernetes Engine cluster with worker nodes in multiple zones, and save the user data in Cloud Spanner.
  • CStore static content such as HTML and images in Cloud CDN. Use Cloud Run to host the APIs and save the user data in Cloud SQL.
  • DStore static content such as HTML and images in a Cloud Storage bucket. Use Cloud Functions to host the APIs and save the user data in Firestore. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Store static content such as HTML and images in a Cloud Storage bucket. Use Cloud Functions to host the APIs and save the user data in Firestore.

Explanation

Cloud Functions runs event-driven code without managing servers and scales automatically. Cloud Storage provides durable, scalable object storage that is fully managed. Firestore is a serverless, autoscaling NoSQL document database ideal for app and user data. This option delivers the requirement at the lowest cost.

Topic 1 Β· Question 132

Your company sends all Google Cloud logs to Cloud Logging. Your security team wants to monitor the logs. You want to ensure that the security team can react quickly if an anomaly such as an unwanted firewall change or server breach is detected. You want to follow Google-recommended practices. What should you do?

  • ASchedule a cron job with Cloud Scheduler. The scheduled job queries the logs every minute for the relevant events.
  • BExport logs to BigQuery, and trigger a query in BigQuery to process the log data for the relevant events.
  • CExport logs to a Pub/Sub topic, and trigger Cloud Function with the relevant log events. (correct answer)
  • DExport logs to a Cloud Storage bucket, and trigger Cloud Run with the relevant log events.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Export logs to a Pub/Sub topic, and trigger Cloud Function with the relevant log events.

Explanation

Pub/Sub is a serverless, global messaging service that decouples services and ingests high-volume event streams.

Topic 1 Β· Question 133

You have deployed several instances on Compute Engine. As a security requirement, instances cannot have a public IP address. There is no VPN connection between Google Cloud and your office, and you need to connect via SSH into a specific machine without violating the security requirements. What should you do?

  • AConfigure Cloud NAT on the subnet where the instance is hosted. Create an SSH connection to the Cloud NAT IP address to reach the instance.
  • BAdd all instances to an unmanaged instance group. Configure TCP Proxy Load Balancing with the instance group as a backend. Connect to the instance using the TCP Proxy IP.
  • CConfigure Identity-Aware Proxy (IAP) for the instance and ensure that you have the role of IAP-secured Tunnel User. Use the gcloud command line tool to ssh into the instance. (correct answer)
  • DCreate a bastion host in the network to SSH into the bastion host from your office location. From the bastion host, SSH into the desired instance.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Configure Identity-Aware Proxy (IAP) for the instance and ensure that you have the role of IAP-secured Tunnel User. Use the gcloud command line tool to ssh into the instance.

Explanation

Identity-Aware Proxy enforces per-request access control to apps without a VPN.

Topic 1 Β· Question 134

Your company is using Google Cloud. You have two folders under the Organization: Finance and Shopping. The members of the development team are in a Google Group. The development team group has been assigned the Project Owner role on the Organization. You want to prevent the development team from creating resources in projects in the Finance folder. What should you do?

  • AAssign the development team group the Project Viewer role on the Finance folder, and assign the development team group the Project Owner role on the Shopping folder.
  • BAssign the development team group only the Project Viewer role on the Finance folder.
  • CAssign the development team group the Project Owner role on the Shopping folder, and remove the development team group Project Owner role from the Organization. (correct answer)
  • DAssign the development team group only the Project Owner role on the Shopping folder.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Assign the development team group the Project Owner role on the Shopping folder, and remove the development team group Project Owner role from the Organization.

Topic 1 Β· Question 135

You are developing your microservices application on Google Kubernetes Engine. During testing, you want to validate the behavior of your application in case a specific microservice should suddenly crash. What should you do?

  • AAdd a taint to one of the nodes of the Kubernetes cluster. For the specific microservice, configure a pod anti-affinity label that has the name of the tainted node as a value.
  • BUse Istio's fault injection on the particular microservice whose faulty behavior you want to simulate. (correct answer)
  • CDestroy one of the nodes of the Kubernetes cluster to observe the behavior.
  • DConfigure Istio's traffic management features to steer the traffic away from a crashing microservice.
Reveal answer & explanation
Correct answer: B

The correct answer is B. Option B: Use Istio's fault injection on the particular microservice whose faulty behavior you want to simulate.

Topic 1 Β· Question 136

Your company is developing a new application that will allow globally distributed users to upload pictures and share them with other selected users. The application will support millions of concurrent users. You want to allow developers to focus on just building code without having to create and maintain the underlying infrastructure. Which service should you use to deploy the application?

  • AApp Engine (correct answer)
  • BCloud Endpoints
  • CCompute Engine
  • DGoogle Kubernetes Engine
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: App Engine

Explanation

App Engine is a fully managed platform that runs and autoscales web apps with little operational effort.

Topic 1 Β· Question 137

Your company provides a recommendation engine for retail customers. You are providing retail customers with an API where they can submit a user ID and the API returns a list of recommendations for that user. You are responsible for the API lifecycle and want to ensure stability for your customers in case the API makes backward-incompatible changes. You want to follow Google-recommended practices. What should you do?

  • ACreate a distribution list of all customers to inform them of an upcoming backward-incompatible change at least one month before replacing the old API with the new API.
  • BCreate an automated process to generate API documentation, and update the public API documentation as part of the CI/CD process when deploying an update to the API.
  • CUse a versioning strategy for the APIs that increases the version number on every backward-incompatible change. (correct answer)
  • DUse a versioning strategy for the APIs that adds the suffix "DEPRECATED" to the current API version number on every backward-incompatible change. Use the current version number for the new API.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: Use a versioning strategy for the APIs that increases the version number on every backward-incompatible change.

Topic 1 Β· Question 138

Your company has developed a monolithic, 3-tier application to allow external users to upload and share files. The solution cannot be easily enhanced and lacks reliability. The development team would like to re-architect the application to adopt microservices and a fully managed service approach, but they need to convince their leadership that the effort is worthwhile. Which advantage(s) should they highlight to leadership?

  • AThe new approach will be significantly less costly, make it easier to manage the underlying infrastructure, and automatically manage the CI/CD pipelines.
  • BThe monolithic solution can be converted to a container with Docker. The generated container can then be deployed into a Kubernetes cluster.
  • CThe new approach will make it easier to decouple infrastructure from application, develop and release new features, manage the underlying infrastructure, manage CI/CD pipelines and perform A/B testing, and scale the solution if necessary. (correct answer)
  • DThe process can be automated with Migrate for Compute Engine.
Reveal answer & explanation
Correct answer: C

The correct answer is C. Option C: The new approach will make it easier to decouple infrastructure from application, develop and release new features, manage the underlying infrastructure, manage CI/CD pipelines and perform A/B testing, and scale the s...

Topic 1 Β· Question 139

Your team is developing a web application that will be deployed on Google Kubernetes Engine (GKE). Your CTO expects a successful launch and you need to ensure your application can handle the expected load of tens of thousands of users. You want to test the current deployment to ensure the latency of your application stays below a certain threshold. What should you do?

  • AUse a load testing tool to simulate the expected number of concurrent users and total requests to your application, and inspect the results. (correct answer)
  • BEnable autoscaling on the GKE cluster and enable horizontal pod autoscaling on your application deployments. Send curl requests to your application, and validate if the auto scaling works.
  • CReplicate the application over multiple GKE clusters in every Google Cloud region. Configure a global HTTP(S) load balancer to expose the different clusters over a single global IP address.
  • DUse Cloud Debugger in the development environment to understand the latency between the different microservices.
Reveal answer & explanation
Correct answer: A

The correct answer is A. Option A: Use a load testing tool to simulate the expected number of concurrent users and total requests to your application, and inspect the results.

Topic 1 Β· Question 140

Your company has a Kubernetes application that pulls messages from Pub/Sub and stores them in Filestore. Because the application is simple, it was deployed as a single pod. The infrastructure team has analyzed Pub/Sub metrics and discovered that the application cannot process the messages in real time. Most of them wait for minutes before being processed. You need to scale the elaboration process that is I/O-intensive. What should you do?

  • AUse kubectl autoscale deployment APP_NAME --max 6 --min 2 --cpu-percent 50 to configure Kubernetes autoscaling deployment.
  • BConfigure a Kubernetes autoscaling deployment based on the subscription/push_request_latencies metric.
  • CUse the --enable-autoscaling flag when you create the Kubernetes cluster.
  • DConfigure a Kubernetes autoscaling deployment based on the subscription/num_undelivered_messages metric. (correct answer)
Reveal answer & explanation
Correct answer: D

The correct answer is D. Option D: Configure a Kubernetes autoscaling deployment based on the subscription/num_undelivered_messages metric. This option meets the real-time / low-latency performance requirement.

Showing questions 121–140 of 337 Β· Page 7 of 17