Summer Special Flat 65% Limited Time Discount offer - Ends in 0d 00h 00m 00s - Coupon code: netdisc

Google Cloud-Digital-Leader Google Cloud Digital Leader exam Exam Practice Test

Google Cloud Digital Leader exam Questions and Answers

Testing Engine

  • Product Type: Testing Engine
$43.75  $124.99

PDF Study Guide

  • Product Type: PDF Study Guide
$38.5  $109.99
Question 1

What is the Site Reliability Engineering (SRE) term for an organizations desired level of reliability and performance?

Options:

A.

Enhanced support

B.

Scalable infrastructure

C.

Service-level indicator

D.

Service-level objective

Question 2

Which policy helps Google Cloud keep customer data private?

Options:

A.

Google tests the service availability of customer applications.

B.

Google does not use customer data for advertising purposes.

C.

Google migrates customer data to an offline server when a threat is detected.

D.

Google does not allow customers to change encryption keys.

Question 3

Which technology allows organizations to run multiple computer operating systems on a single piece of physical hardware?

Options:

A.

Hypervisor

B.

Containers

C.

Serverless computing

D.

Open source

Question 4

An organization wants to use an open source library with a flexible ecosystem of tools to create and train its own machine learning models Which product or solution should the organization use1?

Options:

A.

Cloud Functions

B.

TensorFlow

C.

Apache Beam

D.

Dataflow

Question 5

An organization recently launched a virtual customer support agent, generating vast amounts of text and speech data.

Why should they use a cloud data warehouse to interpret this data?

Options:

A.

To natively visualize both types of data using a dashboard in real time

B.

To ingest and analyze structured and unstructured data at scale, in real time

C.

To secure data transmission between cloud and on-premises environments

D.

To transform data from structured to unstructured

Question 6

An organization needs to increase the speed at which they can train machine learning models Which domain-specific hardware is designed for this task?

Options:

A.

Preemptible or Spot VMs

B.

Containers

C.

Bare Metal Solution

D.

Cloud TPUs

Question 7

An organization is running Kubernetes applications across multiple cloud environments They want a consistent and centralized management platform Which service should they choose?

Options:

A.

Cloud Run

B.

Compute Engine

C.

GKE Enterprise

D.

Cloud Functions

Question 8

An organization is training a machine learning model to make predictions.

What could improve the prediction accuracy of their model?

Options:

A.

An increase in storage capacity

B.

Higher network bandwidth

C.

An increase in training data

D.

Faster CPU processors

Question 9

An organization has a large dataset that contains text transcripts of conversations between their customers and service representatives. They want an automated solution to identify the topics their customers care most about. Which service should the organization use?

Options:

A.

Cloud Translation API

B.

Speech-to-Text API

C.

Vision API

D.

Natural Language API

Question 10

An organization stores backup files in Cloud Storage The files will be accessed annually to test the disaster recovery plan s. Which storage class is the most cost-effective?

Options:

A.

Nearline class

B.

Standard class

C.

Coldline class

D.

Archive class

Question 11

How is privacy defined in the context of cloud technology?

Options:

A.

Restrictions on data access and sharing

B.

Procedures to authenticate user identity

C.

Susceptibility to data breaches and cyber attacks

D.

Compliance with regulatory standards

Question 12

An organization is deciding on the layout of their resource hierarchy in Google Cloud. They have several projects within a folder. What will happen when user access policies are applied to the folder?

Options:

A.

The policy applies to the folder only, and will not be inherited by any projects.

B.

The policy will be inherited by the projects and their resources within the folder.

C.

The policy will be applied to all folders within the organization.

D.

The policy will be inherited by the projects in the folder but will not affect their resources.

Question 13

What does Cloud Debugger help an organization do?

Options:

A.

Implement code updates in real time without affecting the service level objective (SLO).

B.

Inspect source code in real time without affecting user downtime.

C.

Manage code and accelerate application development.

D.

Analyze live source code during user downtime.

Question 14

What does the shift toward cloud computing represent for an organization's transformation?

Options:

A.

An opportunity that is only relevant to the IT department

B.

An opportunity to continue business as usual with new cost savings

C.

An opportunity to redefine existing business processes and services

D.

An opportunity that is limited to large enterprises

Question 15

An organization is transforming their raw data into a format that can be used to derive business insights Which step of the data value chain does this action represent?

Options:

A.

Data collection

B.

Data analysis

C.

Data processing

D.

Data storage

Question 16

An organization operates their entire IT infrastructure from Google Cloud.

What should they do to prepare for data breaches?

Options:

A.

Reduce reliance on multi-factor authentication

B.

Data security is Google's responsibility, so preparation is minimal

C.

Create an incident plan to mitigate impacts

D.

Strengthen their data center perimeter security

Question 17

After rolling out a new update, an organization found a minor bug in its online video game.

How should the organization approach this bug while following SRE principles?

Options:

A.

Accept and learn from the bug because failure is normal

B.

Accept and ignore the bug because it is only minor

C.

Hold a postmortem to reprimand the employee responsible for the bug

D.

Document bug correction to eliminate all future bugs

Question 18

An organization is running critical workloads in production and requires a Google Cloud support service with fast response times and a dedicated Technical Account Manager. Which customer care service level should the organization choose?

Options:

A.

Premium

B.

Standard

C.

Enhanced

D.

Basic

Question 19

An organization wants to collect metrics and metadata from their cloud applications and put them into dashboards.

Which Google Cloud tool should they use?

Options:

A.

Cloud Monitoring

B.

Cloud Trace

C.

Cloud Logging

D.

Cloud Debugger

Question 20

An organization needs a flexible and scalable NoSQL database with strong web and mobile application support. Which Google Cloud product or service should the organization use?

Options:

A.

Cloud Spanner

B.

BigQuery

C.

Cloud Storage

D.

restore

Question 21

What is the purpose of an application programming interface (API)?

Options:

A.

To provide cloud plugins for integrated development environments

B.

To manage multiple containerized workloads

C.

To connect networks from different cloud providers

D.

To provide a set of instructions that allow computer programs to communicate with each other

Question 22

An organization has a large archive of unstructured data, including video and audio files. Which storage solution should the organization use?

Options:

A.

Cloud SQL

B.

Cloud Spanner

C.

Cloud Bigtable

D.

Cloud Storage

Question 23

An organization is struggling to keep up with the growth of their application which is running on legacy infrastructure.

What might be holding them back?

Options:

A.

The inaccessibility of their data due to perimeter security

B.

The overreliance on platform as a service

C.

The time it takes their serverless compute function to scale

D.

The cost of provisioning hardware for peak usage

Question 24

An organization is looking for a storage solution that will help them serve content to users worldwide. They need a solution that offers a high level of availability

What feature of Cloud Storage would they benefit from?

Options:

A.

Global metadata

B.

Object versioning

C.

Data encryption

D.

Multi-regional storage

Question 25

Several departments in an organization are working together on a project. The organization wants to customize access to resources for each department.

What is the quickest and most efficient way to achieve this?

Options:

A.

By mapping IAM roles to job functions for each department

B.

By assigning IAM primitive roles to each employee

C.

By applying least-privilege to roles for each employee

D.

By creating a single shared service account for all departments

Question 26

An organization wants to run their custom application in the cloud in a flexible and scalable way without managing any infrastructure.

Which service model should they use?

Options:

A.

Infrastructure as a service

B.

Platform as a service

C.

Network as a service

D.

Software as a service

Question 27

An organization wants to refactor their application by using a microservices architecture when migrating to the cloud. Which benefit would this action provide?

Options:

A.

The refactored application is more efficient and scalable.

B.

No code changes will be required.

C.

This migration pattern provides the fastest path to the cloud.

D.

The application will become PCI-DSS compliant by default.

Question 28

When an organization adopts cloud technology, how does their total cost of ownership (TCO) shift?

Options:

A.

Away from cost management toward capital expenditure

B.

Away from operational expenditure toward cost management

C.

Away from capital expenditure toward operational expenditure

D.

Away from operational expenditure toward capital expenditure

Question 29

An organization is moving away from an on-premises infrastructure. Instead, they want to create, access, and share information virtually in the cloud.

What should the organization consider?

Options:

A.

Built-in security when moving their data to the cloud

B.

Replacing their perimeter security with data encryption keys

C.

Optimizing cost-management with a capital expenditure model

D.

Increased hardware capacity when moving their data to the cloud

Question 30

An organization wants to use Apigee to manage all their application programming interfaces (APIs).

What will Apigee enable the organization to do?

Options:

A.

Increase application privacy

B.

Measure and track API performance Most Voted

C.

Analyze application development speed

D.

Market and sell APIs

Question 31

An organization has migrated several large databases to the cloud. It wants to increase the value of its data, improve cost controls and strengthen regulatory compliance. What should the organization do?

Options:

A.

Delete data stored for over a year.

B.

Establish an effective data governance program.

C.

Export relational data to modern NoSQL databases.

D.

Create monthly reports on data access and uses.

Question 32

An organization decides to migrate their on-prenwses environment to the cloud They need to determine which resource components still need to be assigned ownership

Which two functions does a public cloud provider own? (Choose 2)

Choose 2 answers

Options:

A.

Fixing application security issues

B.

Infrastructure architecture

C.

Hardware capacity management

D.

Hardware maintenance

E.

Infrastructure deployment automation

Question 33

An organization is planning to deploy a new workload to Google Cloud. They need an accurate estimate of the likely costs of running the workload. How should the organization create this estimate?

Options:

A.

Use the Google Cloud Pricing Calculator.

B.

Deploy workload to test environment to observe costs.

C.

Use historic costs of an existing similar workload.

D.

Refer to pricing information and manually calculate an estimate.

Question 34

Customers are reporting very high latencies when accessing an application from the United States. The application is currently running in a single region in Europe.

What should the organization do?

Options:

A.

Set up a new billing account in the United States.

B.

Run the application in additional regions in Europe.

C.

Run the application in additional zones in the European region.

D.

Run a replica of the application in a region in the United States.

Question 35

An organization wants to lease the resources they need for their customized servers from a cloud provider on a pay-as-you-go basis, instead of paying one time for hardware. Which service model should they use?

Options:

A.

Hybrid cloud

B.

infrastructure as a service

C.

Platform as a service

D.

Software as a service

Question 36

How does the legal concept of data sovereignty affect data*?

Options:

A.

An individual has the right to control their personal data

B.

Data must always be encrypted in transit and at rest.

C.

Data is subject to the laws and regulations of the country where it resides.

D.

A country has the right to access the data generated within its borders

Question 37

An organization has a large VMWare environment that they want to migrate to the cloud. They want to retain existing operational processes and tools. Which Google Cloud service should the organization use?

Options:

A.

Google Cloud VMware Engine

B.

Bare Metal Solution

C.

VMWare vSphere

D.

Compute Engine

Question 38

An organization wants to introduce a new image recognition login system

What should the organization do to follow SRE principles?

Options:

A.

Roll out the new system to a subset of employees to test it out

B.

Roll out the new system to all employees to collect as much data as possible

C.

Avoid rolling out the new system because it may have security flaws

D.

Avoid rolling out the new system because it may violate privacy policy

Question 39

An organization has servers running mission-critical workloads on-premises around the world. They want to modernize their infrastructure with a multi-cloud architecture.

What benefit could the organization experience?

Options:

A.

Ability to disable regional network connectivity during cyber attacks

B.

Ability to keep backups of their data on-premises in case of failure

C.

Full management access to their regional infrastructure

D.

Reduced likelihood of system failure during high demand events

Question 40

A large retail organization uses traditional technology for their ecommerce website During peaks m traffic resources are often underutilized or overprovisioned They have decided to migrate to cloud technology

What aspect of cloud technology will benefit their ecommerce business?

Options:

A.

Agile infrastructure means that they only pay tor what they need, when they need it

B.

Shared responsibility means that the cloud provider brings increased visibility during peaks in traffic

C.

Operational expenditure means that their total cost of ownership is more predictable

D.

Unlimited storage means that their website will never experience downtime

Question 41

What is the typical cloud spending behavior of most organizations?

Options:

A.

Decentralized and variable

B.

Centralized and variable

C.

Decentralized and fixed

D.

Centralized and fixed

Question 42

An organization is concerned about the risk of data loss that may occur due to hardware failures or cyber attacks. They want to restore their systems to a previous state if such an event occurs. What should the organization do?

Options:

A.

Use Cloud Monitoring.

B.

Back up data regularly.

C.

Set service level objectives (SLOs).

D.

Enable autoscaling.

Question 43

A customer has a tens of applications that are dependent on Oracle databases in their on-premise data centers. The customer wants to migrate to Google Cloud. Their long term goal is to move to other cloud native database technologies. What options do they have to initially move their data?

Options:

A.

Migrate to a Bare Metal server.

B.

Migrate to Cloud SQL.

C.

Since there is no hosted Oracle solution, leave the Oracle data on-premise while doing analytics on Google Cloud.

D.

Containerize Oracle and run it using Cloud Run.

Question 44

Your client is building a custom machine learning pipeline to identify lesions in the lungs based on x-rays. Different teams of data scientists are sharing common source data and building many ver-sions of ML models. Which of these Cloud Storage options would be best for them?

Options:

A.

Retain the data in use in a single region bucket with nearline storage. Retain the data in use in a dual-region bucket.

B.

Retain the data in use in a single region bucket with standard storage.

C.

Retain the data in use in a multi-region bucket.

D.

Retain the data in use in a dual-region bucket.

Question 45

You are consulting for a client who is migrating to Google Cloud. They presently have a matrix or-ganization. Their IT environments were managed around projects. Each team had multiple projects. All the projects had a flat structure under the company. What would you advise them when plan-ning for the move?

Options:

A.

On Google Cloud, create a folder corresponding to each team. Under that, there could be projects or further sub folders as the team decides.

B.

In terms of not disturbing the project developers and testers, advise them that the strategic decision is to retain the structure on Google Cloud also.

C.

Since a Project could spawn other sub-Projects, on Google Cloud it is better to as-sign a folder for each Project.

D.

The flat structure is what is currently used in IT organizations, and this can be used as-is which will provide the best results.

Question 46

You are a cloud architect in a software solution provider company, one of the client that is a Na-tional Bank who wants to build an application that deals with transactions processing, and it needs a relational database with petabyte of scale data. Which of the following Google Cloud Services will you use?

Options:

A.

Cloud SQL

B.

Cloud Bigtable

C.

Cloud Spanner

D.

Google Cloud BigQuery

Question 47

The customer has applications that do data processing on-premise. They have been built using Ha-doop and Spark. What product should I use on Google Cloud?

Options:

A.

Dataproc

B.

Dataflow

C.

Dataprep

D.

Dataplex

Question 48

Customer Managed Encryption Keys (CMEK) can be used for encrypting data inside Cloud BigTable, which of the following statements is/are correct. (Select two answer)

Options:

A.

Administrators can not rotate

B.

Not supported for instances that have clustered in more than one region.

C.

CMEK can only be configured at the cluster level.

D.

You can not use the same CMEK key in multiple projects

Question 49

You are storing sensitive information in a Cloud Storage bucket. For legal reasons, you need to be able to record all requests that read any of the stored data. You want to make sure you comply with these requirements. What should you do?

Options:

A.

Scan the bucket using the Data Loss Prevention API.

B.

Enable Data Access audit logs for the Cloud Storage API.

C.

Enable the Identity Aware Proxy API on the project.

D.

Allow only a single Service Account access to read the data.

Question 50

You have experimented with Google Cloud using your own credit card and expensed the costs to your company. Your company wants to streamline the billing process and charge the costs of your projects to their monthly invoice. What should you do?

Options:

A.

Grant the financial team the IAM role of ג€Billing Account Userג€ on the billing ac-count linked to your credit card.

B.

Change the billing account of your projects to the billing account of your company.

C.

Create a ticket with Google Billing Support to ask them to send the invoice to your company.

D.

Set up BigQuery billing export and grant your financial department IAM access to query the data.

Question 51

Google offers Firebase, In terms of Firebase Console, any particular message that has to be deliv-ered to a customer at a certain degree of change in behavior can be managed through _________________.

Options:

A.

A/B testing

B.

Notification Composer

C.

Firebase Remote config.

D.

None of the above

Question 52

Which of these are defined by the following statement: a contract you have with your end custom-ers, which, if you don't meet, you might even have to pay fines?

Options:

A.

SLA - Service Level Agreement

B.

SLC - Service Level Contract

C.

SLO - Service Level Objective

D.

SLI - Service Level Indicator

Question 53

In Google Cloud IAM: if a policy applied at the project level gives you Owner permissions, your access to an individual resource in that project might be restricted to View permission if someone applies a more restrictive policy directly to that resource. What is correct below the options

Options:

A.

False

B.

None of the above.

C.

True

D.

Not defined by GCP.

Question 54

A customer has contacted you about migrating to Google Cloud. The customer would like to mi-grate their data from on premises as soon as possible. They don’t have the budget to rewrite code, and they want the most direct route. What migration option should suggest to the customer?

Options:

A.

None, since the customer is not cloud native ready.

B.

Rip and Replace

C.

Lift and Shift

D.

Improve and Move

Question 55

DriveSuper Inc. teaches its clients to drive cars and bikes and helps them get their license. They are planning to build a mobile application where users can sign up, plan their schedules, and take stock of progress. They want the onboarding process to be smooth and frictionless, giving users a great experience from the get-go. They want this done as quickly as possible and not be expensive. What is their best option on Google Cloud?

Options:

A.

Build the mobile app with Cloud SQL as the backend

B.

Build the mobile app with Cloud Storage as the backend

C.

Build the mobile application with Firebase as the backend

D.

Build the mobile app with Cloud Spanner as the backend

Question 56

Cloud Data Loss Prevention (DLP) is a fully managed service designed to help discover, classify, and protect the most sensitive data. DLP provides three key features (Select Three Answers)

Options:

A.

Classification

B.

De-identification

C.

De-classification

D.

Inspection

E.

Reinspection

Question 57

Your company has a requirement to run manual tests on their web products for UX research before it is released to end customers. The people who will do the tests are external to the company. They will either use their own Gmail id or be given temporary email ids using the applications and record-ing their inputs in another app. The UX testing is done in the last week of the month. Each month the UX testers could be different. How should the IT team manage the users?

Options:

A.

Since the app is anyways going to be public, create permanent credentials for the UX testers that they can conveniently use each time.

B.

It would be a security issue to have users come and go. Recommend that the test-ers be permanently hired to plug the vulnerability issue.

C.

It would be a security issue to have users come and go. Recommend that the test-ers be permanently hired to plug the vulnerability issue.

D.

Create a Group with the permissions required to do the test and record their in-puts. When users arrive each week, add them to the group and after the testing period, remove them from the group.

Question 58

Which of the following is / are true for Preemptible Instances.

Options:

A.

Preemptible Instances have no Service Level Agreement (Compute Engine SLA).

B.

Google Cloud Free Tier credits for compute engine do not apply to preemptible in-stances.

C.

Preemptible instances can't live migrate to a regular VM instance, or be set to au-tomatically restart when there is a maintenance event.

D.

All of the above.

Question 59

You are a program manager in a company and handling a project and you need to create a virtual machine on google cloud console that will be very simple to set up, by flipping a bit via command, API, or with developer console that gives you 30 seconds to shut down when you’re preempted, allow you to save your work that also helps in the company budget upto 70-80% of less charges than the regular VMs.

Options:

A.

Bare Metal Solutions

B.

Preemptible Virtual Machines.

C.

Google Cloud VM Instances

D.

None of the above.

Question 60

A customer in the European Union region is very clear that their data should not go outside the Eu-ropean Union. Their end users are spread all over the European U. They have to choose a storage option that serves all the users within Asia via web browsers as quickly as possible. Which storage option will work for them?

Options:

A.

Cloud Storage with a single region that is known to be within the European U

B.

Cloud Filestore is connected to virtual machines which are guaranteed to be within the European U

C.

Cloud Storage with the multi-region option of European U

D.

Cloud Storage with the dual-region option of European U

Question 61

What characteristics should an organization adopt to be a DevOps organization?

Options:

A.

Teamwork over individual work

B.

Obsession with Automation over preoccupation with manual work

C.

Product based teams over component teams.

D.

All of the Above

Question 62

You are a database manager working for a new product that will need millions of reading and writ-ing from the database, with zero downtime, key-value i.e. NoSQL features, no manual steps should be required to ensure consistency, repair data, synchronize writes and deletes, Which of the follow-ing database you choose?

Options:

A.

Cloud SQL

B.

Cloud BigTable

C.

Cloud Spanner

D.

Cloud Firestore

Question 63

You have contracted a partner to conduct some medical trials. This is a limited, 2-month contract. At the end of each day, you are expecting about 10 Gbs of data. The data is highly sensitive. What networking option would you employ?

Options:

A.

As the name indicates, set up Partner Interconnect with your partner company.

B.

Setup Dedicated Interconnect with your partner.

C.

Setup Cloud VPN and create an IPsec VPN tunnel with your partner.

D.

Create a public IP for a VM and share that with your partners so that they can access it over the internet and share the data.

Question 64

If you increase the size of a subnet in a custom VPC network, the IP addresses of virtual machines already on that subnet might be affected. Which options are Correct.

Options:

A.

False

B.

None of the above

C.

True

D.

Not Defined by Google Cloud Platform

Question 65

When creating machine learning models, a key initial step is to identify the type of model required. One of these is the classification model. Which of these statements define a classification model?

Options:

A.

A type of machine learning model for distinguishing among two or more discrete values. E.g. "book", "car".

B.

A type of machine learning model is a meta-model maker, which classifies algo-rithms based on the quality of their output.

C.

A type of machine learning model that outputs continuous (typically, floating-point) values. E.g. the predicted price of the house is $120,000.

D.

A type of classic model approach that is less used today and which has been re-placed by the regression model.

Question 66

You are working with a government agency. A web application serves users of the country. It al-lows citizens to receive certain services in providing their national identity. Citizens have com-plained that they are seeing delays in web page loading compared to before. On investigating, they are seeing a lot of spurious traffic coming in from a few IPs which they have identified as for-eign. What should they do?

Options:

A.

Setup Firewall rules to deny access to the malicious IPs.

B.

Setup Cloud Armor and add the malicious IPs to the deny list.

C.

Setup Firewall rules to allow access only to the IPs from within the country.

D.

Setup Cloud NAT and remove all the internal IPs and replace it with a single public IP.

Question 67

A customer is migrating there on-promises data analytics solution to Google Cloud. The current solution has a lot of data being read form and written to disk. The performance of this approach has occasionally been a bottleneck for a scale of operations that your cus-tomer has. The application is fault tolerant and can with stand machine going down fre-quently. In moving to Google Cloud they are asking your advice on any way to improve performance?

Options:

A.

Use Big Query Which has very fast data access and analysis

B.

Use Cloud Storage which can be central, scalable storage

C.

Use local SSDs with the VMs

D.

Use Persistent Disk with the VMs

Question 68

A customer has an application running in virtual machines. They are migrating this application to Google Cloud. They have previously had scaling issues when on-premises as VMs had to be pre-allocated. Capacity planning was repeatedly off mark - it's either too many VMs or too less. They want to match the capacity to demand while keeping the application running always. They don't have the time or budget to re-architect the systems using containers and Kubernetes at the mo-ment. What would be your recommendation?

Options:

A.

Run a load test on Compute Engine VMs. Get an estimate of usage. Then plan for a VM capacity of 25% above the load test value.

B.

Use the Managed Instance Group with Compute Engine

C.

Inform them that new-age companies are using microservices, containers, and Kubernetes for this and they can plan to rewrite the app quickly.

D.

Inform them that using a serverless option will take care of the scaling and they can move to Cloud Run or App Engine.

Question 69

You have deployed a new public web application that allows users to register and login with email ids, phone numbers, or user ids. You are seeing some unusual activity with user registrations and logins from a few IPs. A large number of accounts were created very quickly. Logins are also hap-pening quickly thereafter from these new accounts. Different parts of the application are being ex-plored, all of which are putting a heavy load on the application. What could be a problem and how can you solve it?

Options:

A.

A hacker group has hired a bunch of people to create accounts and manually use the system. Use Cloud Asset Inventory to see if there have been changes in the inventory.

B.

Bots are creating accounts and then using them. Use Google Cloud's Web App and API Protection (WAAP).

C.

Bots are creating accounts and then using them. Use Identity-Aware Proxy to re-strict the users to known users.

D.

Automated testing tools might still be running and creating accounts. Use Identity-Aware Proxy to restrict the users to known users.

Question 70

Google Cloud Platform (GCP) provides three main compliance resource webpages. What are they? (Select Three Answer)

Options:

A.

Compliance Reports Manager

B.

Support Hub

C.

Compliance Offerings

D.

GDPR Home Page

E.

TechCentral

Question 71

Which of the following is/are core storage options available on the Google Cloud Platform?

Options:

A.

Cloud Storage and Cloud Data Store

B.

Cloud Spanner

C.

Cloud SQL and Google Big Table

D.

All of the above

Question 72

You're negotiating SLAs with a customer. You have communicated that there will be a 99.99% (four 9s) availability for the service you are providing. Every aspect of the service is under your con-trol. They want to modify the reliability to 99.999% (five 9s). What do you tell them? (Choose two answer)

Options:

A.

Yes, that could be possible. If yes, there will be a significantly higher charge be-cause the effort is significantly higher too.

B.

Yes, that is possible, but there will be an additional charge of 9% for the service because that is the additional effort required.

C.

Yes, that is possible. There is hardly any difference to provide another 0.009% availability.

D.

Ask them for the reasonable downtime they are willing to absorb. If it is more than 60 minutes in an entire year, explain how the current SLA meets that requirement.

Question 73

Which of the following statements is/are true about Google Cloud BigTable?

Options:

A.

It is not compatible with Hadoop.

B.

It Scales from Giga Byte to Peta Byte with No Downtime.

C.

It can not be used in Real-time Ad analytics and tracking thousands of IoT Devices Data.

D.

It is an enterprise-level Database that offers relational and non-relational features

Question 74

Your company has signed up with a cloud provider and you will be using storage and vir-tual machines with the provider. The provider has provided your organization some expec-tations for what the service should perform at. What type of agreement provides a guar-antee of a certain level of service such as “Uptime”?

Options:

A.

Performance Agreement

B.

Interconnection Agreement

C.

Warranty

D.

Service Level Agreement

Question 75

A customer deploys an application to App Engine and needs to check for Open Web Appli-cation Security Project (OWASP) vulnerabilities. Which service should be used to accom-plish this?

Options:

A.

Cloud Armor

B.

Cloud Security Scanner

C.

Binary Authorization

D.

Forseti Security

Question 76

In terms of Cloud SQL for MySQL Features offered by Google Cloud Platform which of the statements is/are correct?

Options:

A.

Do not support Private IP (private service access).

B.

Customer data is encrypted on Google's internal networks and in database tables, temporary files, and backups.

C.

Do not Provide automated and on-demand backups and point-in-time recovery.

D.

None of the above

Question 77

Keeping Flavours of Apigee in mind, which of the following statements is/are correct?

Options:

A.

A hybrid version consisting of a runtime plane installed on-premises or in a cloud provider of your choice, and a management plane running in Apigee's cloud. In this model, API traffic and data are confined within your own enterprise-approved boundaries.

B.

A hosted SaaS version in which Apigee maintains the environment, allowing you to concentrate on building your services and defining the APIs to those services.

C.

There are two types of Flavours in Apigee i.e. Apigee & Apigee Hybrid.

D.

All of the above are correct.

Question 78

How does a least privilege resource access model contribute to cloud security?

Options:

A.

Google is responsible for determining access to cloud resources.

B.

Employees may only access on-premises software with special permission.

C.

Only managers and other senior employees have cloud resource access.

D.

Employees only have access to the cloud resources necessary for their job.

Question 79

Which of the following statements describe the features of a preemptible VM in-stance? (Select Three Answer)

Options:

A.

Instance is alive for no more than 12 hours

B.

Can be pre-empted with a 30 minute notice

C.

Can be pre-empted with a 30 second notice

D.

Discounted Significantly

E.

Instance is alive for no more than 24 hours

F.

Can use free tier credits

Question 80

An e-commerce company's business has been booming. To keep up with the growth the IT team also grew. Many new people are being added and new resources are being set up. The CIO is in conver-sation with you over coffee one day and expresses her growing concern that they might be moving too fast. Their security checks and policies have not kept pace. She worries that somebody would make a misconfiguration or compliance violation thus exposing the company to data and privacy loss. What can you advise her?

Options:

A.

Use Cloud Identity-Aware Proxy to allow only specific users to access the data.

B.

Use Security Command Center to have a centralized view of assets and get noti-fied on misconfigurations and vulnerabilities.

C.

Use Cloud Data Loss Prevention to prevent the loss of any data.

D.

Use Cloud Armor to block any DDoS attacks that could be a threat.

Question 81

Your client's IT environment has so far been on-premises. They run a mix of applications and data-bases on Linux and Windows. They want to move to Google Cloud in the easiest manner possi-ble. What are their best options?

Options:

A.

Compute Engine with VMs with either Linux or Windows OS.

B.

App Engine Standard

C.

Cloud Functions

D.

Cloud Run

Question 82

You are looking for a one stop reference page for GCP support. What Page would you se-lect?

Options:

A.

Compliance Hub

B.

Google Cloud Platform Status

C.

Support Hub

D.

Pricing Page

Question 83

In discussions with a prospective customer who wants to move to Google Cloud to make use of the latest, scalable technologies available therein, you learn that there are very strict regulations concern-ing the storage of data. They only have the approval to store it in their current private data cen-ter. What would you advise them?

Options:

A.

Retain on-premise itself those portions of data and compute which are under regulation. Take advantage of all the other cloud capabilities for remaining work-loads.

B.

It is too risky to touch anything in such a scenario. It is best to remain entirely on-premise.

C.

Regulations are guidelines. As long as the data remains encrypted, you can move it anywhere.

D.

Petition the government for changes to such regulations as all industries are mov-ing to the public cloud. Then, when the regulations are eased, move to Google Cloud.

Question 84

You are running a data warehouse on BigQuery. A partner company is offering a recommendation engine based on the data in your data warehouse. The partner company is also running their applica-tion on Google Cloud. They manage the resources in their own project, but they need access to the BigQuery dataset in your project. You want to provide the partner company with access to the da-taset. What should you do?

Options:

A.

Ask the partner to create a Service Account in their project, and have them give the Service Account access to BigQuery in their project.

B.

Create a Service Account in your own project, and grant this Service Account ac-cess to BigQuery in your project.

C.

Create a Service Account in your own project, and ask the partner to grant this Service Account access to BigQuery in their project.

D.

Ask the partner to create a Service Account in their project, and grant their Service Account access to the BigQuery dataset in your project.

Question 85

You decide to migrate your on-premises environment to the cloud. You need to determine which resource components still need to be assigned ownership.

Which two functions are owned by a public cloud provider? (Choose two.)

Options:

A.

Hardware maintenance

B.

Infrastructure architecture

C.

Infrastructure deployment automation

D.

Hardware capacity management

E.

Fixing application security issues

Question 86

Which Google Cloud product gives you a consistent platform for multi-cloud application deployments and extends other Google Cloud services to your environment?

Options:

A.

Google Kubernetes Engine

B.

Virtual Public Cloud

C.

Compute Engine

D.

Anthos

Question 87

Your organization wants to migrate your on-premises environment to Google Cloud. The on-premises environment consists of containers and virtual machine instances. Which Google Cloud products can help to migrate the container images and the virtual machine disks?

Options:

A.

Compute Engine and Filestore

B.

Artifact Registry and Cloud Storage

C.

Dataflow and BigQuery

D.

Pub/Sub and Cloud Storage

Question 88

Which of the following is/are true about Anthos?

Options:

A.

Enterprise-grade container orchestration and management service.

B.

Modernizing your security for hybrid and multi-cloud deployments

C.

Fully managed service mesh with built-in visibility

D.

All of the Above

Question 89

Your organization needs to ensure that the Google Cloud resources of each of your departments are segregated from one another. Each department has several environments of its own: development, testing, and production. Which strategy should your organization choose?

Options:

A.

Create a project per department, and create a folder per environment in each project.

B.

Create a folder per department, and create a project per environment in each folder.

C.

Create a Cloud Identity domain per department, and create a project per environment in each domain.

D.

Create a Cloud Identity domain per environment, and create a project per department in each domain.

Question 90

Which Google Cloud product is designed to reduce the risks of handling personally identifiable information (PII)?

Options:

A.

Cloud Storage

B.

Google Cloud Armor

C.

Cloud Data Loss Prevention

D.

Secret Manager

Question 91

The operating systems of some of your organization’s virtual machines may have a security vulnerability.

How can your organization most effectively identify all virtual machines that do not have the latest security update?

Options:

A.

View the Security Command Center to identify virtual machines running vulnerable disk images

B.

View the Compliance Reports Manager to identify and download a recent PCI audit

C.

View the Security Command Center to identify virtual machines started more than 2 weeks ago

D.

View the Compliance Reports Manager to identify and download a recent SOC 1 audit

Question 92

Your organization is developing a mobile app and wants to select a fully featured cloud-based compute platform for it.

Which Google Cloud product or feature should your organization use?

Options:

A.

Google Kubernetes Engine

B.

Firebase

C.

Cloud Functions

D.

App Engine

Question 93

Your organization runs many workloads in different Google Cloud projects, each linked to the same billing account. Each project's workload costs can vary from month to month, but the overall combined cost of all projects is relatively stable. Your organization needs to optimize its cost.

What should your organization do?

Options:

A.

Purchase a commitment per project for each project’s usual minimum

B.

Create a billing account per project, and link each project to a different billing account

C.

Turn on committed use discount sharing, and create a commitment for the combined usage

D.

Move all workloads from all different projects into one single consolidated project

Question 94

An organization wants to dynamically adjust its application to serve different user needs. What are the benefits of storing their data in the cloud for this use case?

Options:

A.

Data can be stored in archive for long term access

B.

Automatic data cleaning and validation

C.

Real-time data ingestion and analysis

D.

No data access management required

Question 95

Your organization needs to minimize how much it pays for data traffic from the Google network to the internet. What should your organization do?

Options:

A.

Choose the Standard network service tier.

B.

Choose the Premium network service tier.

C.

Deploy Cloud VPN.

D.

Deploy Cloud NAT.

Question 96

Your organization needs to restrict access to a Cloud Storage bucket. Only employees who are based in Canada should be allowed to view the contents.

What is the most effective and efficient way to satisfy this requirement?

Options:

A.

Deploy the Cloud Storage bucket to a Google Cloud region in Canada

B.

Configure Google Cloud Armor to allow access to the bucket only from IP addresses based in Canada

C.

Give each employee who is based in Canada access to the bucket

D.

Create a group consisting of all Canada-based employees, and give the group access to the bucket

Question 97

There are internal compliance requirements that demand that we do not use any APIs or services that are not backed by SLAs. Which of these are acceptable for us? (Choose two answer)

Options:

A.

Alpha, Beta

B.

Early Access, Preview

C.

General Availability

D.

Deprecated, but ensure that the SLA support period is still valid.

Question 98

Your organization wants to optimize its use of Google Cloud’s discounts on virtual machine-based workloads. You plan to use 200 CPUs constantly for the next 3 years, and you forecast that spikes of up to 300 CPUs will occur approximately 30% of the time. What should you choose?

Options:

A.

1-year committed use discount for 200 CPUs

B.

3-year committed use discount for 300 CPUs

C.

3-year committed use discount for 200 CPUs

D.

Regular pay-as-you-go pricing

Question 99

An organization has completely migrated all their infrastructure to the cloud to benefit from its agility. Now they want to innovate faster and achieve a higher return on investment. What should the organization do?

Options:

A.

Manually provision all cloud infrastructure for increased control.

B.

Modernize their applications.

C.

Lower their service level objective (SLO).

D.

Move to a hybrid architecture with some of their infrastructure on-premises.

Question 100

A video game organization has invested in cloud technology to generate insights from user behaviors. They want to ensure recommendations of games are aligned to players' interests. What may have prompted this business decision?

Options:

A.

Customers expect faster time to market for games.

B.

Employees expect source code changes to be deployed faster.

C.

Customers expect a personalized experience.

D.

Employees expect more predictable data management spending.

Question 101

Your company needs to segment Google Cloud resources used by each team from the others. The teams’ efforts are changing frequently, and you need to reduce operational risk and maintain cost visibility. Which approach does Google recommend?

Options:

A.

One project per team.

B.

One organization per team.

C.

One project that contains all of each team's resources.

D.

One top-level folder per team.

Question 102

A multinational retail company has approached you to help design its systems. They have millions of transactions at their point of sale systems across the world that need to be captured, stored, and analyzed. They are seeing more growth and expect to expand into even more geographies. Which database would be appropriate for them?

Options:

A.

Cloud Datastore

B.

Cloud Storage

C.

Cloud Spanner

D.

Cloud SQL

Question 103

Your manager wants to restrict communication of all virtual machines with internet access; with resources in another network; or with a resource outside Compute Engine. It is expected that different teams will create new folders and projects in the near future.

How would you restrict all virtual machines from having an external IP address?

Options:

A.

Define an organization policy at the root organization node to restrict virtual machine instances from having an external IP address

B.

Define an organization policy on all existing folders to define a constraint to restrict virtual machine instances from having an external IP address

C.

Define an organization policy on all existing projects to restrict virtual machine instances from having an external IP address

D.

Communicate with the different teams and agree that each time a virtual machine is created, it must be configured without an external IP address

Question 104

Your Google Cloud Platform [GCP] admin has to manage a bunch of API keys for external services that are accessed by different applications, which are used by a few teams. What is the best way to manage them?

Options:

A.

Share the information in a Github repository and grant access to the repo in IAM as required.

B.

Store the information in Secret Manager and give IAM read permissions as re-quired.

C.

Store the information in Kubernetes Secrets and only grant read permissions to users as required.

D.

Encrypt the information and store it in Cloud Storage for centralized access. Give the decrypt key only to the users who need to access it.

Question 105

An organization has had a data leak scare because one employee made a sensitive Cloud Storage bucket available to the public. Given the nature of the company's business, it is understood that there is never any reason to give the public direct access to any file. The security head wants to ensure that such an event never occurs again. How can you ensure this?

Options:

A.

Remove Edit access rights of all Cloud Storage buckets so that no user can make any edits.

B.

Set an organizational policy constraint to restrict bucket access set to the public.

C.

Use Cloud Scheduler to run a job at a specified interval to scan buckets. Any public permissions can be programmatically changed.

D.

Write Cloud Functions code connected to Cloud Storage. Any changes will be notified to the function which can be used to reset the public access.

Question 106

What are the key features of Google Cloud Identity.

Options:

A.

Multi-factor authentication (MFA)

B.

Single sign-on (SSO)

C.

Works with your favorite apps and Endpoint management

D.

All of the Above

Question 107

You are currently managing workloads running on Windows Server for which your company owns the licenses. Your workloads are only needed during working hours, which allows you to shut down the instances during the weekend. Your Windows Server licenses are up for renewal in a month, and you want to optimize your license cost.

What should you do?

Options:

A.

Renew your licenses for an additional period of 3 years. Renew your licenses for an additional period of 3 years. Negotiate a cost reduction with your current hosting provider wherein infrastructure cost is reduced when workloads are not in use

B.

Renew your licenses for an additional period of 2 years. Negotiate a cost reduction by committing to an automatic renewal of the licenses at the end of the 2 year period

C.

Migrate the workloads to Compute Engine with a bring-your-own-license (BYOL) model

D.

Migrate the workloads to Compute Engine with a pay-as-you-go (PAYG) model

Question 108

Which of the following NIST Cloud characteristics uses the business model of shared re-sources in a cloud environment?

Options:

A.

Elasticity

B.

Availability

C.

Broad Network Access

D.

Multi-Tenancy

Question 109

Your organization runs a distributed application in the Compute Engine virtual machines. Your organization needs redundancy, but it also needs extremely fast communication (less than 10 milliseconds) between the parts of the application in different virtual machines.

Where should your organization locate this virtual machines?

Options:

A.

In a single zone within a single region

B.

In different zones within a single region

C.

In multiple regions, using one zone per region

D.

In multiple regions, using multiple zones per region

Question 110

Your company has multiple internal applications used by your employees. You also have to give access to certain vendors and contractors. What is a good option for you to adopt?

Options:

A.

Keep the credentials separate for each application to reduce the blast radius in case of any issues.

B.

Use an external identity provider that is famous and popular like Facebook or Twitter; that way, even your vendors and contractors will have an account there.

C.

Allow all users, especially contractors and vendors, to bring their own identities, like those at gmail.com.

D.

Use an IDaaS (Identity as a Service) product that can centrally manage authenti-cation and authorization for the applications.

Question 111

Your company’s development team is building an application that will be deployed on Cloud Run. You are designing a CI/CD pipeline so that any new version of the application can be deployed in the fewest number of steps possible using the CI/CD pipeline you are designing. You need to select a storage location for the images of the application after the CI part of your pipeline has built them.

What should you do?

Options:

A.

Create a Compute Engine image containing the application

B.

Store the images in Container Registry

C.

Store the images in Cloud Storage

D.

Create a Compute Engine disk containing the application

Question 112

Your organization is moving an application to Google Cloud. As part of that effort, it needs to migrate the application’s working database from another cloud provider to Cloud SQL. The database runs on the MySQL engine. The migration must cause minimal disruption to users. Data must be secured while in transit.

Which should your organization use?

Options:

A.

BigQuery Data Transfer Service

B.

MySQL batch insert

C.

Database Migration Service

D.

Cloud Composer

Question 113

Your organization is running all its workloads in a private cloud on top of a hypervisor. Your organization has decided it wants to move to Google Cloud as quickly as possible. Your organization wants minimal changes to the current environment, while using the maximim amount of managed services Google offers.

What should your organization do?

Options:

A.

Migrate the workloads to Google Cloud VMware Engine

B.

Migrate the workloads to Compute Engine

C.

Migrate the workloads to Bare Metal Solution

D.

Migrate the workloads to Google Kubernetes Engine

Question 114

What is the difference between Standard and Coldline storage?

Options:

A.

Coldline storage is for data for which a slow transfer rate is acceptable.

B.

Standard and Coldline storage have different durability guarantees.

C.

Standard and Coldline storage use different APIs.

D.

Coldline storage is for infrequently accessed data.

Question 115

Your organization needs to allow a production job to have access to a BigQuery dataset. The production job is running on a Compute Engine instance that is part of an instance group.

What should be included in the IAM Policy on the BigQuery dataset?

Options:

A.

The Compute Engine instance group

B.

The project that owns the Compute Engine instance

C.

The Compute Engine service account

D.

The Compute Engine instance

Question 116

As your organization increases its release velocity, the VM-based application upgrades take a long time to perform rolling updates due to OS boot times. You need to make the application deployments faster.

What should your organization do?

Options:

A.

Migrate your VMs to the cloud, and add more resources to them

B.

Convert your applications into containers

C.

Increase the resources of your VMs

D.

Automate your upgrade rollouts

Question 117

Your organization is building an application running in Google Cloud. Currently, software builds, tests, and regular deployments are done manually, but you want to reduce work for the team. Your organization wants to use Google Cloud managed solutions to automate your build, testing, and deployment process.

Which Google Cloud product or feature should your organization use?

Options:

A.

Cloud Scheduler

B.

Cloud Code

C.

Cloud Build

D.

Cloud Deployment Manager

Question 118

Which of the following statements is/are correct about Bare Metal Solutions?

Options:

A.

The network, which Google Cloud manages includes a low-latency Cloud Inter-connect connection into the customer Bare Metal Solution environment.

B.

Bare Metal Solution also includes the provisioning and maintenance of the cus-tom, sole-tenancy hardware with local SAN, and smart hands support.

C.

Bare Metal Solution uses a bring-your-own-license (BYOL) model.

D.

All of the Above.

Question 119

Your organization consists of many teams. Each team has many Google Cloud projects. Your organization wants to simplify the management of identity and access policies for these projects.

How can you group these projects to meet this goal?

Options:

A.

Group each team’s projects into a separate domain

B.

Assign labels based on the virtual machines that are part of each team’s projects

C.

Use folders to group each team’s projects

D.

Group each team’s projects into a separate organization node

Question 120

Your organization stores highly sensitive data on-premises that cannot be sent over the public internet. The data must be processed both on-premises and in the cloud.

What should your organization do?

Options:

A.

Configure Identity-Aware Proxy (IAP) in your Google Cloud VPC network

B.

Create a Cloud VPN tunnel between Google Cloud and your data center

C.

Order a Partner Interconnect connection with your network provider

D.

Enable Private Google Access in your Google Cloud VPC network

Question 121

Your organization wants to migrate its data management solutions to Google Cloud because it needs to dynamically scale up or down and to run transactional SQL queries against historical data at scale. Which Google Cloud product or service should your organization use?

Options:

A.

BigQuery

B.

Cloud Bigtable

C.

Pub/Sub

D.

Cloud Spanner

Question 122

What would provide near-unlimited availability of computing resources without requiring your organization to procure and provision new equipment?

Options:

A.

Public cloud

B.

Containers

C.

Private cloud

D.

Microservices

Question 123

Your organization is developing and deploying an application on Google Cloud. Tracking your Google Cloud spending needs to stay as simple as possible.

What should you do to ensure that workloads in the development environment are fully isolated from production workloads?

Options:

A.

Apply a unique tag to development resources

B.

Associate the development resources with their own network

C.

Associate the development resources with their own billing account

D.

Put the development resources in their own project

Question 124

Which Google Cloud product can report on and maintain compliance on your entire Google Cloud organization to cover multiple projects?

Options:

A.

Cloud Logging

B.

Identity and Access Management

C.

Google Cloud Armor

D.

Security Command Center