Summer Certification Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: force70

Pass the Google Google Cloud Certified Associate-Cloud-Engineer Questions and answers with CertsForce

Viewing page 5 out of 11 pages
Viewing questions 41-50 out of questions
Questions # 41:

Your company has multiple projects linked to a single billing account in Google Cloud. You need to visualize the costs with specific metrics that should be dynamically calculated based on company-specific criteria. You want to automate the process. What should you do?

Options:

A.

In the Google Cloud console, visualize the costs related to the projects in the Reports section.


B.

In the Google Cloud console, visualize the costs related to the projects in the Cost breakdown section.


C.

In the Google Cloud console, use the export functionality of the Cost table. Create a Looker Studiodashboard on top of the CSV export.


D.

Configure Cloud Billing data export to BigOuery for the billing account. Create a Looker Studio dashboard on top of the BigQuery export.


Expert Solution
Questions # 42:

You have a Linux VM that must connect to Cloud SQL. You created a service account with the appropriate access rights. You want to make sure that the VM uses this service account instead of the default Compute Engine service account. What should you do?

Options:

A.

When creating the VM via the web console, specify the service account under the ‘Identity and API Access’ section.


B.

Download a JSON Private Key for the service account. On the Project Metadata, add that JSON as the value for the key compute-engine-service-account.


C.

Download a JSON Private Key for the service account. On the Custom Metadata of the VM, add that JSON as the value for the key compute-engine-service-account.


D.

Download a JSON Private Key for the service account. After creating the VM, ssh into the VM and save the JSON under ~/.gcloud/compute-engine-service-account.json.


Expert Solution
Questions # 43:

You are a Google Cloud organization policy administrator for your company that operates in a regulated industry. You need to enforce a policy that restricts all new location-based Google Cloud resources to the australia-southeast1 and australia-southeast2 regions only. You want to ensure that this policy requires minimal configuration. What should you do?

Options:

A.

Create a custom organization policy that uses the resource.location == ' australia-southeast1 ' || resource.location == ' australia-southeast2 ' Common Expression Language (CEL) condition.


B.

Modify the gcp.resourceLocations list constraint by adding in:australia-locations to the allowed_values list.


C.

Modify the gcp.resourceLocations list constraint by adding in:australia-locations to the denied_values list.


D.

Create a custom organization policy that uses the resource.location.startsWith( ' australia ' ) Common Expression Language (CEL) condition.


Expert Solution
Questions # 44:

You have a batch workload that runs every night and uses a large number of virtual machines (VMs). It is fault- tolerant and can tolerate some of the VMs being terminated. The current cost of VMs is too high. What should you do?

Options:

A.

Run a test using simulated maintenance events. If the test is successful, use preemptible N1 Standard VMs when running future jobs.


B.

Run a test using simulated maintenance events. If the test is successful, use N1 Standard VMs when running future jobs.


C.

Run a test using a managed instance group. If the test is successful, use N1 Standard VMs in the managed instance group when running future jobs.


D.

Run a test using N1 standard VMs instead of N2. If the test is successful, use N1 Standard VMs when running future jobs.


Expert Solution
Questions # 45:

You installed the Google Cloud CLI on your workstation and set the proxy configuration. However, you are worried that your proxy credentials will be recorded in the gcloud CLI logs. You want to prevent your proxy credentials from being logged What should you do?

Options:

A.

Configure username and password by using gcloud configure set proxy/username and gcloud configure set proxy/ proxy/password commands.


B.

Encode username and password in sha256 encoding, and save it to a text file. Use filename as a value in the gcloud configure set core/custom_ca_certs_file command.


C.

Provide values for CLOUDSDK_USERNAME and CLOUDSDK_PASSWORD in the gcloud CLI tool configure file.


D.

Set the CLOUDSDK_PROXY_USERNAME and CLOUDSDK_PROXY PASSWORD properties by using environment variables in your command line tool.


Expert Solution
Questions # 46:

(You have an application running inside a Compute Engine instance. You want to provide the application with secure access to a BigQuery dataset. You must ensure that credentials are only valid for a short period of time, and your application will only have access to the intended BigQuery dataset. You want to follow Google-recommended practices and minimize your operational costs. What should you do?)

Options:

A.

Attach a custom service account to the instance, and grant the service account the BigQuery Data Viewer IAM role on the project.


B.

Attach a new service account to the instance every hour, and grant the service account the BigQuery Data Viewer IAM role on the dataset.


C.

Attach a custom service account to the instance, and grant the service account the BigQuery Data Viewer IAM role on the dataset.


D.

Attach a new service account to the instance every hour, and grant the service account the BigQuery Data Viewer IAM role on the project.


Expert Solution
Questions # 47:

(You are managing the security configuration of your company ' s Google Cloud organization. The Operations team needs specific permissions on both a Google Kubernetes Engine (GKE) cluster and a Cloud SQL instance. Two predefined Identity and Access Management (IAM) roles exist that contain a subset of the permissions needed by the team. You need to configure the necessary IAM permissions for this team while following Google-recommended practices. What should you do?)

Options:

A.

Grant the team the two predefined IAM roles.


B.

Create a custom IAM role that combines the permissions from the two relevant predefined roles.


C.

Create a custom IAM role that includes only the required permissions from the predefined roles.


D.

Grant the team the IAM roles of Kubernetes Engine Admin and Cloud SQL Admin.


Expert Solution
Questions # 48:

You need to grant access for three users so that they can view and edit table data on a Cloud Spanner instance. What should you do?

Options:

A.

Run gcloud iam roles describe roles/spanner.databaseUser. Add the users to the role.


B.

Run gcloud iam roles describe roles/spanner.databaseUser. Add the users to a new group. Add the group to the role.


C.

Run gcloud iam roles describe roles/spanner.viewer --project my-project. Add the users to the role.


D.

Run gcloud iam roles describe roles/spanner.viewer --project my-project. Add the users to a new group. Add the group to the role.


Expert Solution
Questions # 49:

You are using Data Studio to visualize a table from your data warehouse that is built on top of BigQuery. Data is appended to the data warehouse during the day. At night, the daily summary is recalculated by overwriting the table. You just noticed that the charts in Data Studio are broken, and you want to analyze the problem. What should you do?

Options:

A.

Use the BigQuery interface to review the nightly Job and look for any errors


B.

Review the Error Reporting page in the Cloud Console to find any errors.


C.

In Cloud Logging create a filter for your Data Studio report


D.

Use the open source CLI tool. Snapshot Debugger, to find out why the data was not refreshed correctly.


Expert Solution
Questions # 50:

You are performing a monthly security check of your Google Cloud environment and want to know who has access to view data stored in your Google Cloud

Project. What should you do?

Options:

A.

Enable Audit Logs for all APIs that are related to data storage.


B.

Review the IAM permissions for any role that allows for data access.


C.

Review the Identity-Aware Proxy settings for each resource.


D.

Create a Data Loss Prevention job.


Expert Solution
Viewing page 5 out of 11 pages
Viewing questions 41-50 out of questions