表示モード
画像位置
文字位置
理解度の自動記録
Q1Google Professional Cloud Developer
Q1. Last week you released to production an API that accepts hotel room reservations.
For each customer, you want to enforce a quota that limits the number of API search requests they can make to a maximum of 1,000 for every reservation that is completed.
The quota should reset every 24 hours.
Rather than guaranteeing exactly 1,000 searches per reservation, you want to prioritize the API’s response speed.
How should you configure this?
Show answer
Correct answer: A. Configure an Apigee Quota policy and set the Synchronous attribute to false.
Reset the quota when a reservation is completed or when 24 hours have elapsed.
In an Apigee Quota policy, setting the Synchronous attribute to false processes the count update asynchronously, so each request can return a response without waiting for the counter update to complete.Reset the quota when a reservation is completed or when 24 hours have elapsed.
The question prioritizes API response speed over guaranteeing “exactly 1,000 times,” and asynchronous counting delivers high performance while tolerating a small margin of error.
Resetting the quota when a reservation is completed or after 24 hours can also be configured within the policy.
Approaches that use BigQuery or Firestore offer high counting accuracy but incur a read/write on every request, which is a disadvantage for speed.
The in-memory approach cannot share the counter across multiple instances and lacks reliability.
Apigee Quota policy (official documentation)
Q2Google Professional Cloud Developer
Q2. You are developing the backend for a single-player mobile game that users play at any time of day, making traffic patterns hard to predict.
You want to optimize costs by securing enough resources to handle requests while avoiding over-provisioning.
You also want a mechanism that can efficiently handle sudden traffic spikes.
Which compute platform should you choose?
Show answer
Correct answer: A. Cloud Run
Cloud Run is a fully managed serverless platform that automatically scales with request volume and can scale in to zero while there is no traffic.It flexibly handles unpredictable traffic and sudden spikes while charging only for what you use, so it avoids over-provisioning and best fits the cost-optimization requirement.
Compute Engine (both managed and unmanaged) scales at the VM level, cannot shrink to zero, and takes time to start up, making it unsuitable.
GKE cluster autoscaling takes time to add nodes and is prone to over-provisioning, so it is inferior for this requirement.
What is Cloud Run (official documentation)
Q3Google Professional Cloud Developer
Q3. You are a developer working with a CI/CD team, and you are responsible for troubleshooting a feature the team has newly introduced.
The CI/CD team used HashiCorp Packer to build a new Compute Engine image from your development branch.
The image build itself succeeded, but instances launched from that image do not start up.
You need to work with the CI/CD team to investigate this problem.
What should you do?
Show answer
Correct answer: D. Use the serial port to inspect the Compute Engine OS logs, and also inspect the Cloud Logging logs to verify serial port access.
When investigating a VM that fails to start, Google’s recommended approach is to inspect the serial console (serial port output).Even when startup fails, the serial port output records messages from the boot process, so you can directly identify the cause of the startup failure.
Serial port output can also be forwarded to Cloud Logging to be stored and reviewed.
Mounting the disk locally (A) involves considerable effort and may make it hard to obtain boot-stage logs.
Rebuilding locally (B) or re-requesting a build (C) does not lead to investigating the cause itself.
Troubleshooting using the serial console (official documentation)
Q4Google Professional Cloud Developer
Q4. You are building a highly available, globally accessible application that delivers static content to users.
You need to configure the storage and delivery components.
You want to maximize reliability for users while minimizing management overhead and latency.
How should you configure this?
Show answer
Correct answer: D. 1. Create a multi-region Cloud Storage bucket with the Standard storage class and store the static content.
2. Reserve an external IP address and create an external HTTP(S) load balancer.
3. Enable Cloud CDN and route traffic to the backend bucket.
For delivering static content, using a Cloud Storage bucket as the backend significantly reduces management overhead compared with operating VMs.2. Reserve an external IP address and create an external HTTP(S) load balancer.
3. Enable Cloud CDN and route traffic to the backend bucket.
The optimal combination is a multi-region Cloud Storage bucket for high availability, an external HTTP(S) load balancer for global access, and Cloud CDN for low-latency delivery.
A regional bucket (C) is limited to a single region and is inferior in terms of availability.
The instance group approaches (A and B) require replicating and managing VMs, which conflicts with the requirement to minimize management overhead.
Setting up Cloud CDN with a Cloud Storage bucket (official documentation)
Q5Google Professional Cloud Developer
Q5. Your team is developing a Cloud Function that is triggered by Cloud Storage events.
Following Google’s recommended best practices, you want to speed up the Cloud Function’s testing and development cycle.
What should you do?
Show answer
Correct answer: C. Install the Functions Framework library and configure the Cloud Function on localhost.
Create a copy of the function and make changes to the new version.
Use curl to test the new version.
The Functions Framework is an official library provided by Google for running and testing Cloud Function code in a local environment.Create a copy of the function and make changes to the new version.
Use curl to test the new version.
Because you can invoke the function locally using tools such as curl to validate it, you can greatly speed up the development cycle without waiting for a deployment, and this is Google’s recommended best practice.
Testing in production (D) is high risk and not recommended.
Rewriting to an HTTP trigger (B) or integrating with audit logs (A) cannot reproduce the original trigger condition and adds unnecessary complexity.
Functions Framework (official documentation)
Q6Google Professional Cloud Developer
Q6. You are developing a new application that must meet the following design requirements.
– The creation and modification of the application infrastructure must be version-controlled and auditable.
– The application and its deployment infrastructure should use Google-managed services as much as possible.
– The application must run on a serverless compute platform.
How should you design the application’s architecture?
Show answer
Correct answer: A. 1. Store the application and infrastructure source code in a Git repository.
2. Use Cloud Build to deploy the application infrastructure with Terraform.
3. Deploy the application to a Cloud Function as one step of the pipeline.
To make infrastructure creation and modification version-controlled and auditable, you need a configuration that manages Infrastructure as Code (IaC) with Git.2. Use Cloud Build to deploy the application infrastructure with Terraform.
3. Deploy the application to a Cloud Function as one step of the pipeline.
The configuration that stores source code and infrastructure definitions in Git, deploys with Cloud Build and Terraform, and deploys to the serverless Cloud Function (A) satisfies all requirements.
gcloud commands (D) cannot provide declarative version control and violate the auditability requirement.
Jenkins (B) is not Google-managed and requires self-management.
Deploying to Compute Engine (C) does not satisfy the serverless requirement.
Best practices for Terraform (official documentation)
Q7Google Professional Cloud Developer
Q7. Your company has introduced a new security policy that requires all data stored in Google Cloud to be encrypted with customer-managed encryption keys (CMEK).
You plan to configure access to the keys using Cloud Key Management Service (KMS).
You must follow both the principle of separation of duties and Google’s recommended best practices.
What should you do? (Choose two.)
Show answer
Correct answer: A, B
To achieve separation of duties, it is important to divide key management and key usage into separate permissions and separate projects.Placing Cloud KMS in a dedicated project (A) and not assigning an owner to that project (B) is Google’s recommended configuration, as it eliminates the existence of a privileged user who could manage and use the keys single-handedly.
Having an organization-level administrator control only the IAM policy preserves the separation.
Co-locating with the key-using project (C) or granting the KMS admin role to the using-side owner (D) violates the separation principle.
Cloud KMS separation of duties (official documentation)
Q8Google Professional Cloud Developer
Q8. Your security team is auditing all deployed applications running on Google Kubernetes Engine.
The audit revealed that some applications are sending in-cluster traffic in plaintext (cleartext).
You need to encrypt all application traffic as quickly as possible while keeping changes to the applications minimal and maintaining Google support.
What should you do?
Show answer
Correct answer: B. Install Istio, enable sidecar proxy injection in the target applications’ namespaces, and enable mTLS.
A service mesh (Istio / now the Google-managed Cloud Service Mesh) injects sidecar proxies to achieve automatic encryption via mutual TLS (mTLS) without changing application code.Simply enabling proxy injection and mTLS encrypts all in-cluster traffic with minimal changes and maintains Google support.
Network Policies (A) control traffic but do not encrypt it.
Defining a trusted range within the app (C) or manually embedding Let’s Encrypt certificates (D) involves large changes to the application and conflicts with the requirement.
Cloud Service Mesh mTLS (official documentation)
Q9Google Professional Cloud Developer
Q9. As part of a data migration, you want to upload files located on an on-premises virtual machine to Google Cloud Storage.
These files will be used by a Cloud Dataproc Hadoop cluster in your Google Cloud environment.
Which command should you use?
Show answer
Correct answer: A. gsutil cp [LOCAL_OBJECT] gs://[DESTINATION_BUCKET_NAME]/
The standard command to copy local files to Cloud Storage is gsutil cp.The syntax gsutil cp [LOCAL_OBJECT] gs://[BUCKET_NAME]/ uploads directly from on-premises to Cloud Storage, and this is the correct command.
gcloud cp and gcloud dataproc cp do not exist as object-copy commands.
hadoop fs cp is intended for operations within HDFS and is not suitable for an initial upload from local.
Note that the newer gcloud storage cp is now also available, but among these options gsutil cp is the correct answer.
gsutil cp command (official documentation)
Q10Google Professional Cloud Developer
Q10. You are a cluster administrator for Google Kubernetes Engine (GKE).
Your organization’s clusters are enrolled in a release channel.
You want to receive notifications about relevant events affecting your GKE clusters, such as available upgrades and security bulletins.
What should you do?
Show answer
Correct answer: A. Configure cluster notifications to be sent to a Pub/Sub topic.
GKE has a “cluster notifications” feature that delivers events such as upgrade information and security bulletins affecting a specific cluster to a Pub/Sub topic.Configuring cluster notifications to be sent to a Pub/Sub topic lets you receive events relevant to the target cluster in real time and automatically.
BigQuery scheduled queries (B) and querying the GKE API (C) require active polling.
An RSS subscription (D) covers release notes for all of GKE and is not suitable for event notifications specific to your own cluster.
Cluster notifications (official documentation)
