Spring Sale Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: simple70

Pass the Google Google Cloud Certified Professional-Cloud-Architect Questions and answers with CertsForce

Viewing page 4 out of 7 pages
Viewing questions 31-40 out of questions
Questions # 31:

For this question, refer to the JencoMart case study.

The JencoMart security team requires that all Google Cloud Platform infrastructure is deployed using a least privilege model with separation of duties for administration between production and development resources. What Google domain and project structure should you recommend?

Options:

A.

Create two G Suite accounts to manage users: one for development/test/staging and one for production. Each account should contain one project for every application.


B.

Create two G Suite accounts to manage users: one with a single project for all development applications and one with a single project for all production applications.


C.

Create a single G Suite account to manage users with each stage of each application in its own project.


D.

Create a single G Suite account to manage users with one project for the development/test/staging environment and one project for the production environment.


Expert Solution
Questions # 32:

For this question, refer to the JencoMart case study.

JencoMart has decided to migrate user profile storage to Google Cloud Datastore and the application servers to Google Compute Engine (GCE). During the migration, the existing infrastructure will need access to Datastore to upload the data. What service account key-management strategy should you recommend?

Options:

A.

Provision service account keys for the on-premises infrastructure and for the GCE virtual machines (VMs).


B.

Authenticate the on-premises infrastructure with a user account and provision service account keys for the VMs.


C.

Provision service account keys for the on-premises infrastructure and use Google Cloud Platform (GCP) managed keys for the VMs


D.

Deploy a custom authentication service on GCE/Google Container Engine (GKE) for the on-premises infrastructure and use GCP managed keys for the VMs.


Expert Solution
Questions # 33:

For this question, refer to the JencoMart case study.

JencoMart has built a version of their application on Google Cloud Platform that serves traffic to Asia. You want to measure success against their business and technical goals. Which metrics should you track?

Options:

A.

Error rates for requests from Asia


B.

Latency difference between US and Asia


C.

Total visits, error rates, and latency from Asia


D.

Total visits and average latency for users in Asia


E.

The number of character sets present in the database


Expert Solution
Questions # 34:

For this question, refer to the JencoMart case study.

The migration of JencoMart’s application to Google Cloud Platform (GCP) is progressing too slowly. The infrastructure is shown in the diagram. You want to maximize throughput. What are three potential bottlenecks? (Choose 3 answers.)

Options:

A.

A single VPN tunnel, which limits throughput


B.

A tier of Google Cloud Storage that is not suited for this task


C.

A copy command that is not suited to operate over long distances


D.

Fewer virtual machines (VMs) in GCP than on-premises machines


E.

A separate storage layer outside the VMs, which is not suited for this task


F.

Complicated internet connectivity between the on-premises infrastructure and GCP


Expert Solution
Questions # 35:

For this question, refer to the Helicopter Racing League (HRL) case study. HRL wants better prediction

accuracy from their ML prediction models. They want you to use Google’s AI Platform so HRL can understand

and interpret the predictions. What should you do?

Options:

A.

Use Explainable AI.


B.

Use Vision AI.


C.

Use Google Cloud’s operations suite.


D.

Use Jupyter Notebooks.


Expert Solution
Questions # 36:

For this question, refer to the JencoMart case study.

JencoMart wants to move their User Profiles database to Google Cloud Platform. Which Google Database should they use?

Options:

A.

Cloud Spanner


B.

Google BigQuery


C.

Google Cloud SQL


D.

Google Cloud Datastore


Expert Solution
Questions # 37:

For this question, refer to the Helicopter Racing League (HRL) case study. A recent finance audit of cloud

infrastructure noted an exceptionally high number of Compute Engine instances are allocated to do video

encoding and transcoding. You suspect that these Virtual Machines are zombie machines that were not deleted

after their workloads completed. You need to quickly get a list of which VM instances are idle. What should you

do?

Options:

A.

Log into each Compute Engine instance and collect disk, CPU, memory, and network usage statistics for

analysis.


B.

Use the gcloud compute instances list to list the virtual machine instances that have the idle: true label set.


C.

Use the gcloud recommender command to list the idle virtual machine instances.


D.

From the Google Console, identify which Compute Engine instances in the managed instance groups are

no longer responding to health check probes.


Expert Solution
Questions # 38:

Altostrat stores a large library of media content, including sensitive interviews and documentaries, in Cloud Storage. They are concerned about the confidentiality of this content and want to protect it from unauthorized access. You need to implement a Google-recommended solution that is easy to integrate and provides Altostrat with control and auditability of the encryption keys. What should you do?

Options:

A.

Configure Cloud Storage to use server-side encryption with Google-managed encryption keys. Create a bucket policy to restrict access to only authorized Google groups and required service accounts.


B.

Use Cloud Storage default encryption at rest. Implement fine-grained access control using IAM roles and groups to restrict access to sensitive buckets.


C.

Implement client-side encryption before uploading it to Cloud Storage. Store the encryption keys in a HashiCorp Vault instance deployed on Google Kubernetes Engine (GKE). Implement fine-grained access control to sensitive Cloud Storage buckets using IAM roles.


D.

Use customer-managed encryption keys (CMEK) for all Cloud Storage buckets storing sensitive media content. Implement fine-grained access control using IAM roles and groups to restrict access to sensitive buckets.


Expert Solution
Questions # 39:

Refer to the Altostrat Media case study for the following solution regarding API management and cost control.

Altostrat is using Apigee for API management and wants to ensure their APIs are protected from overuse and abuse. You need to implement an Apigee feature to control the total number of API calls for cost management. What should you do?

Options:

A.

Set up API key validation.


B.

Integrate OAuth 2.0 authorization.


C.

Configure Quota policies.


D.

Activate XML threat protection.


Expert Solution
Questions # 40:

Refer to the Altostrat Media case study for the following solution.

Altostrat is concerned about sophisticated, multi-vector Distributed Denial of Service (DDoS) attacks targeting various layers of their infrastructure. DDoS attacks could potentially disrupt video streaming and cause financial losses. You need to mitigate this risk. What should you do?

Options:

A.

Set up VPC Service Controls to restrict access to sensitive resources and prevent data exfiltration.


B.

Configure Cloud Next Generation Firewall (NGFW) with custom rules to filter malicious traffic at the network level.


C.

Deploy Google Cloud Armor with pre-configured and custom rules for L3/L4 and L7 protection.


D.

Activate Security Command Center to monitor security posture and detect potential threats.


Expert Solution
Viewing page 4 out of 7 pages
Viewing questions 31-40 out of questions