Google Professional-Cloud-Developer Practice Exam - 265 Unique Questions [Q54-Q74]

Share

Google Professional-Cloud-Developer Practice Exam - 265 Unique Questions

Latest Questions Professional-Cloud-Developer Guide to Prepare Free Practice Tests


Google Professional-Cloud-Developer certification is a highly sought-after credential in the cloud computing industry. It demonstrates the candidate's proficiency in developing cloud-based applications on the Google Cloud Platform. Google Certified Professional - Cloud Developer certification is recognized globally and is a major asset for individuals who wish to pursue a career in cloud computing. It is an essential certification for developers who want to enhance their skills and knowledge in cloud computing.

 

NEW QUESTION # 54
You are deploying a single website on App Engine that needs to be accessible via the URL http://www.altostrat.com/. What should you do?

  • A. Verify domain ownership with Webmaster Central. Define an A record pointing to the single global App Engine IP address.
  • B. Verify domain ownership with Webmaster Central. Create a DNS CNAME record to point to the App Engine canonical name ghs.googlehosted.com.
  • C. Define a mapping in dispatch.yaml to point the domain www.altostrat.com to your App Engine service. Create a DNS CNAME record to point to the App Engine canonical name ghs.googlehosted.com.
  • D. Define a mapping in dispatch.yaml to point the domain www.altostrat.com to your App Engine service. Define an A record pointing to the single global App Engine IP address.

Answer: B


NEW QUESTION # 55
Your teammate has asked you to review the code below, which is adding a credit to an account balance in Cloud Datastore.
Which improvement should you suggest your teammate make?

  • A. Don't return the account entity from the function.
  • B. Get the entity with an ancestor query.
  • C. Get and put the entity in a transaction.
  • D. Use a strongly consistent transactional database.

Answer: B

Explanation:
Explanation/Reference:


NEW QUESTION # 56
Which service should HipLocal use to enable access to internal apps?

  • A. Cloud Identity-Aware Proxy
  • B. Virtual Private Cloud
  • C. Cloud VPN
  • D. Cloud Armor

Answer: A


NEW QUESTION # 57
You are developing an application that needs to store files belonging to users in Cloud Storage. You want each user to have their own subdirectory in Cloud Storage. When a new user is created, the corresponding empty subdirectory should also be created. What should you do?

  • A. Create an object with the name of the subdirectory that is zero bytes in length. Set the Content-Type metadata to CLOUDSTORAGE_FOLDER.
  • B. Create an object with the name of the subdirectory, and then immediately delete the object within that subdirectory.
  • C. Create an object with the name of the subdirectory ending with a trailing slash ('/') that is zero bytes in length.
  • D. Create an object with the name of the subdirectory that is zero bytes in length and has WRITER access control list permission.

Answer: C

Explanation:
Explanation
https://cloud.google.com/storage/docs/folders
If you create an empty folder using the Google Cloud console, Cloud Storage creates a zero-byte object as a placeholder. For example, if you create a folder called folder in a bucket called my-bucket, a zero- byte object called gs://my-bucket/folder/ is created. This placeholder is discoverable by other tools when listing the objects in the bucket, for example when using the gsutil ls command.


NEW QUESTION # 58
Your team is developing a new application using a PostgreSQL database and Cloud Run. You are responsible for ensuring that all traffic is kept private on Google Cloud. You want to use managed services and follow Google-recommended best practices. What should you do?

  • A. 1. Install PostgreSQL on a Compute Engine VM, and enable Cloud Run in different projects.
    2. Configure a private IP address for the VM. Enable private services access.
    3. Create a Serverless VPC Access connector.
    4. Set up a VPN connection between the two projects. Configure Cloud Run to use the connector to access the VM hosting PostgreSQL
  • B. 1. Use Cloud SQL and Cloud Run in different projects.
    2. Configure a private IP address for Cloud SQL. Enable private services access.
    3. Create a Serverless VPC Access connector.
    4. Set up a VPN connection between the two projects. Configure Cloud Run to use the connector to connect to Cloud SQL.
  • C. 1. Install PostgreSQL on a Compute Engine virtual machine (VM), and enable Cloud Run in the same project.
    2. Configure a private IP address for the VM. Enable private services access.
    3. Create a Serverless VPC Access connector.
    4. Configure Cloud Run to use the connector to connect to the VM hosting PostgreSQL.
  • D. 1. Enable Cloud SQL and Cloud Run in the same project.
    2. Configure a private IP address for Cloud SQL. Enable private services access.
    3. Create a Serverless VPC Access connector.
    4. Configure Cloud Run to use the connector to connect to Cloud SQL.

Answer: D

Explanation:
Explanation
https://cloud.google.com/sql/docs/postgres/connect-run#private-ip


NEW QUESTION # 59
You are writing a Compute Engine hosted application in project A that needs to securely authenticate to a Cloud Pub/Sub topic in project B.
What should you do?

  • A. Configure the instances with a service account owned by project B. Add the service account as a Cloud Pub/Sub publisher to project A.
  • B. Configure Application Default Credentials to use the private key of a service account owned by project A. Add the service account as a publisher on the topic
  • C. Configure Application Default Credentials to use the private key of a service account owned by project B. Add the service account as a Cloud Pub/Sub publisher to project A.
  • D. Configure the instances with a service account owned by project A. Add the service account as a publisher on the topic.

Answer: D

Explanation:
https://cloud.google.com/pubsub/docs/access-control
"For example, suppose a service account in Cloud Project A wants to publish messages to a topic in Cloud Project B. You could accomplish this by granting the service account Edit permission in Cloud Project B"


NEW QUESTION # 60
HipLocal wants to reduce the number of on-call engineers and eliminate manual scaling.
Which two services should they choose? (Choose two.)

  • A. Use Google App Engine services.
  • B. Use Knative to build and deploy serverless applications.
  • C. Use Google Kubernetes Engine for automated deployments.
  • D. Use serverless Google Cloud Functions.
  • E. Use a large Google Compute Engine cluster for deployments.

Answer: B,D


NEW QUESTION # 61
A governmental regulation was recently passed that affects your application. For compliance purposes, you are now required to send a duplicate of specific application logs from your application's project to a project that is restricted to the security team. What should you do?

  • A. Create a job that copies the togs from the _Required log bucket into the security team's log bucket in their project.
  • B. Modify the _Default tog bucket sink rules to reroute the logs into the security team's log bucket.
  • C. Create a job that copies the System Event logs from the _Required log bucket into the security team's log bucket in their project.
  • D. Create user-defined log buckets in the security team's project. Configure a Cloud Logging sink to route your application s logs to log buckets in the security team's project.

Answer: D


NEW QUESTION # 62
You are writing a Compute Engine hosted application in project A that needs to securely authenticate to a Cloud Pub/Sub topic in project B.
What should you do?

  • A. Configure the instances with a service account owned by project B. Add the service account as a Cloud Pub/Sub publisher to project A.
  • B. Configure Application Default Credentials to use the private key of a service account owned by project A. Add the service account as a publisher on the topic
  • C. Configure Application Default Credentials to use the private key of a service account owned by project B. Add the service account as a Cloud Pub/Sub publisher to project A.
  • D. Configure the instances with a service account owned by project A. Add the service account as a publisher on the topic.

Answer: D

Explanation:
https://cloud.google.com/pubsub/docs/access-control
"For example, suppose a service account in Cloud Project A wants to publish messages to a topic in Cloud Project B.
You could accomplish this by granting the service account Edit permission in Cloud Project B"


NEW QUESTION # 63
You are deploying your applications on Compute Engine. One of your Compute Engine instances failed to launch. What should you do? (Choose two.)

  • A. Troubleshoot firewall rules or routes on an instance.
  • B. Check whether your instance boot disk is completely full.
  • C. Check whether network traffic to or from your instance is being dropped.
  • D. Determine whether your file system is corrupted.
  • E. Access Compute Engine as a different SSH user.

Answer: B,D

Explanation:
https://cloud.google.com/compute/docs/troubleshooting/vm-startup


NEW QUESTION # 64
You support an application that uses the Cloud Storage API. You review the logs and discover multiple HTTP 503 Service Unavailable error responses from the API. Your application logs the error and does not take any further action. You want to implement Google-recommended retry logic to improve success rates. Which approach should you take?

  • A. Retry each failure at increasing time intervals up to a maximum number of tries.
  • B. Retry each failure at decreasing time intervals up to a maximum number of tries.
  • C. Retry each failure at a set time interval up to a maximum number of times.
  • D. Retry the failures in batch after a set number of failures is logged.

Answer: A

Explanation:
https://cloud.google.com/storage/docs/retry-strategy


NEW QUESTION # 65
You need to deploy a new European version of a website hosted on Google Kubernetes Engine. The current and new websites must be accessed via the same HTTP(S) load balancer's external IP address, but have different domain names. What should you do?

  • A. Create a new Service of type LoadBalancer specifying the existing IP address as the loadBalancerIP
  • B. Modify the existing Ingress resource with a host rule matching the new domain
  • C. Define a new Ingress resource with a host rule matching the new domain
  • D. Generate a new Ingress resource and specify the existing IP address as the kubernetes.io/ingress.global-static-ip-name annotation value

Answer: B

Explanation:
https://kubernetes.io/docs/concepts/services-networking/ingress/#name-based-virtual-hosting Name-based virtual hosts support routing HTTP traffic to multiple host names at the same IP address.


NEW QUESTION # 66
Which of the following expresses empathy rather than sympathy?

  • A. Oh, what a pity! This must make you feel disappointed.
  • B. Poor you! You must feel awful.
  • C. I feel so sorry for you. I bet you feel disappointed.
  • D. I am sorry this happened to you. I can see why you may be disappointed

Answer: D


NEW QUESTION # 67
You have written a Cloud Function that accesses other Google Cloud resources. You want to secure the environment using the principle of least privilege. What should you do?

  • A. Create a new service account that has Editor authority to access the resources. The deployer is given permission to act as the new service account.
  • B. Create a new service account that has a custom IAM role to access the resources. The deployer is given permission to act as the new service account.
  • C. Create a new service account that has Editor authority to access the resources. The deployer is given permission to get the access token.
  • D. Create a new service account that has a custom IAM role to access the resources. The deployer is given permission to get the access token.

Answer: B


NEW QUESTION # 68
You are planning to deploy hundreds of microservices in your Google Kubernetes Engine (GKE) cluster. How should you secure communication between the microservices on GKE using a managed service?

  • A. Install Anthos Service Mesh, and enable mTLS in your Service Mesh.
  • B. Install cert-manager on GKE to automatically renew the SSL certificates.
  • C. Use global HTTP(S) Load Balancing with managed SSL certificates to protect your services
  • D. Deploy open source Istio in your GKE cluster, and enable mTLS in your Service Mesh

Answer: A

Explanation:
https://cloud.google.com/service-mesh/docs/overview#security_benefits
- Ensures encryption in transit. Using mTLS for authentication also ensures that all TCP communications are encrypted in transit.


NEW QUESTION # 69
You are monitoring a web application that is written in Go and deployed in Google Kubernetes Engine. You notice an increase in CPU and memory utilization. You need to determine which source code is consuming the most CPU and memory resources. What should you do?

  • A. Import the Cloud Profiler package into your application, and initialize the Profiler agent. Review the generated flame graph in the Google Cloud console to identify time-intensive functions.
  • B. Download, install, and start the Snapshot Debugger agent in your VM. Take debug snapshots of the functions that take the longest time. Review the call stack frame, and identify the local variables at that level in the stack.
  • C. Import OpenTelemetry and Trace export packages into your application, and create the trace provider.
    Review the latency data for your application on the Trace overview page, and identify where bottlenecks are occurring.
  • D. Create a Cloud Logging query that gathers the web application's logs. Write a Python script that calculates the difference between the timestamps from the beginning and the end of the application's longest functions to identity time-intensive functions.

Answer: A


NEW QUESTION # 70
You recently joined a new team that has a Cloud Spanner database instance running in production. Your manager has asked you to optimize the Spanner instance to reduce cost while maintaining high reliability and availability of the database. What should you do?

  • A. Use Cloud Monitoring to monitor the CPU utilization, and reduce Spanner processing units by small increments until you find the minimum capacity required.
  • B. Use Cloud Trace to monitor the requests per sec of incoming requests to Spanner, and reduce Spanner processing units by small increments until you find the minimum capacity required.
  • C. Use Snapshot Debugger to check for application errors, and reduce Spanner processing units by small increments until you find the minimum capacity required.
  • D. Use Cloud Logging to check for error logs, and reduce Spanner processing units by small increments until you find the minimum capacity required.

Answer: A

Explanation:
https://cloud.google.com/spanner/docs/compute-capacity#increasing_and_decreasing_compute_capacity


NEW QUESTION # 71
Your company uses Cloud Logging to manage large volumes of log dat
a. You need to build a real-time log analysis architecture that pushes logs to a third-party application for processing. What should you do?

  • A. Create a Cloud Logging log export to BigQuery.
  • B. Create a Cloud Function to read Cloud Logging log entries and send them to the third-party application.
  • C. Create a Cloud Logging log export to Cloud Storage.
  • D. Create a Cloud Logging log export to Pub/Sub.

Answer: D


NEW QUESTION # 72
You are building an API that will be used by Android and iOS apps The API must:
* Support HTTPs
* Minimize bandwidth cost
* Integrate easily with mobile apps
Which API architecture should you use?

  • A. MQTT for APIs
  • B. gRPC-based APIs
  • C. RESTful APIs
  • D. SOAP-based APIs

Answer: C

Explanation:
Explanation
Explanation/Reference: https://www.devteam.space/blog/how-to-build-restful-api-for-your-mobile-app/


NEW QUESTION # 73
Your company has a data warehouse that keeps your application information in BigQuery. The BigQuery data warehouse keeps 2 PBs of user data. Recently, your company expanded your user base to include EU users and needs to comply with these requirements:
Your company must be able to delete all user account information upon user request.
All EU user data must be stored in a single region specifically for EU users.
Which two actions should you take? (Choose two.)

  • A. Create a dataset in the EU region that will keep information about EU users only.
  • B. Re-upload your data using to a Cloud Dataflow pipeline by filtering your user records out.
  • C. Use DML statements in BigQuery to update/delete user records based on their requests.
  • D. Use BigQuery federated queries to query data from Cloud Storage.
  • E. Create a Cloud Storage bucket in the EU region to store information for EU users only.

Answer: C,E

Explanation:
Reference: https://cloud.google.com/solutions/bigquery-data-warehouse


NEW QUESTION # 74
......

Correct and Up-to-date Google Professional-Cloud-Developer BrainDumps: https://www.briandumpsprep.com/Professional-Cloud-Developer-prep-exam-braindumps.html

Reliable Professional-Cloud-Developer Dumps Questions Available as Web-Based Practice Test Engine: https://drive.google.com/open?id=1NThlCuFdTiVckUknISjSpT5HykULAdlT