Google Professional Cloud DevOps Engineer 1-10

表示モード
画像位置
文字位置
理解度の自動記録
STATUS FILTER

Choose confidence levels to display

Loading...
Q1Google Professional Cloud Devops Engineer
Show answer
Correct answer: B. Manage the password in Secret Manager and mount the secret to the container as a volume.
The correct answer is B.
When you mount a secret stored in Secret Manager as a volume, Cloud Run refreshes the mounted file approximately every 30 seconds, so the application can obtain the latest password without a redeployment.The key point of this question is that the volume-mount approach reflects the latest secret with zero downtime.
The environment-variable approach (Option A) fixes the secret at startup and caches it for up to 10 minutes, making it hard to keep up with a 24-hour rotation, and it also has the drawback of exposing the value in plain text.
Options C and D embed the password at build time and therefore require a redeployment, failing to meet the zero-downtime requirement.
Configuring secrets | Cloud Run Documentation
Q2Google Professional Cloud Devops Engineer
Show answer
Correct answer: A. Enable the Personalized Service Health annotation display on the dashboard.
The correct answer is A.
Personalized Service Health is a feature that provides information about Google Cloud incidents affecting your own projects.
When you integrate it with Cloud Monitoring and enable annotations, Google Cloud outage events can be overlaid directly onto your service’s metric graphs.The basis for the correct answer is that it lets you directly distinguish your own outages from Google Cloud–side outages.
An alerting policy (B) is meant to notify you of threshold breaches and cannot isolate root cause.
Log-based metrics (C) and log widgets (D) are useful for analyzing your own logs, but they do not authoritatively indicate whether a Google Cloud–side outage is occurring.
Personalized Service Health overview | Google Cloud
Q3Google Professional Cloud Devops Engineer
Show answer
Correct answer: A. Prepare a Google service account. On a cluster with Workload Identity enabled, create a Kubernetes service account and link the two using the roles/iam.workloadIdentityUser role and the iam.gke.io/gcp-service-account annotation. Assign the created Kubernetes service account to each workload, and repeat this procedure for every workload.
The correct answer is A.
Workload Identity is Google’s recommended method for GKE workloads to securely access Google Cloud APIs with short-lived credentials, without managing service account keys.
By having the Kubernetes service account impersonate the Google service account via the roles/iam.workloadIdentityUser role and the iam.gke.io/gcp-service-account annotation, you can assign least-privilege permissions on a per-workload basis.Meeting the requirement, this approach eliminates long-lived keys while achieving both short-lived credentials and least privilege.
Option C, which uses service account keys, and Options B and D, which grant a shared identity at the node-pool level, are inappropriate because they retain long-lived keys or cannot separate permissions on a per-workload basis.
About Workload Identity | GKE Documentation
Q4Google Professional Cloud Devops Engineer
Show answer
Correct answer: B. Instrument all related applications with Stackdriver Trace (now Cloud Trace) and examine the flow of HTTP requests between services.
The correct answer is B.
Cloud Trace (formerly Stackdriver Trace) is a distributed tracing service that visualizes how requests propagate between services and where latency occurs in each segment.
By tracing HTTP requests between services, you can identify the dependent application that is the source of the delay.Distributed tracing shows the latency breakdown between services, making it ideal for identifying slow dependencies.
Profiler (A) is for analyzing code resource consumption, and Debugger (C) is for inspecting the state of running code; neither is suited to identifying dependency latency.
Logging (D) imposes a heavy implementation burden and is a roundabout approach.
Note that the Stackdriver-family services have now been renamed to Cloud Operations.
Cloud Trace overview | Google Cloud
Q5Google Professional Cloud Devops Engineer
Show answer
Correct answer: D. Configure Cloud Build to run only the tests under a specific folder, and trigger Cloud Build each time a pull request is created on GitHub.
The correct answer is D.
Because tests must run before changes are accepted (merged), triggering Cloud Build at the moment a pull request is created is the appropriate approach.
Using the Cloud Build GitHub app, you can launch a build for each pull request and run only the integration tests in a specific folder.To verify before merging, running triggers on a per-pull-request basis is essential.
Option B runs after merge, Option C asks a reviewer to run tests manually, and Option A uses periodically scheduled Jenkins; none of them satisfy the requirement of automated testing before acceptance.
Building repositories from GitHub | Cloud Build Documentation
Q6Google Professional Cloud Devops Engineer
Show answer
Correct answer: C. Enable the logging option on the existing firewall rule.
The correct answer is C.
Because a firewall rule that allows access to the API port already exists, you simply need to enable logging on that rule, achieving the goal with minimal steps.
Firewall rules logging generates a connection record for each connection and records the source and destination IP addresses.Firewall rules logging is not sampled and records every connection, so it captures each IP without omission.
VPC Flow Logs (D) sample packets, so they are inferior for the requirement of reliably recording “each IP” and also require new configuration on the subnet.
Packet Mirroring (A) and the Ops Agent (B) are excessive or inappropriate for this purpose.
Firewall rules logging | Cloud NGFW Documentation
Q7Google Professional Cloud Devops Engineer
Show answer
Correct answer: C, D
The correct answers are C and D.
To build production images only against the main branch, create a trigger whose repository event is set to “Push to a branch” and limit the target branch to main (C).
Also, to have the change management team approve every push to main, configure a branch protection rule on the main branch on the GitHub side (D).The key point is to divide responsibilities: build invocation via a Cloud Build trigger, and approval control via a GitHub branch protection rule.
The Cloud Build approval option (E) is approval for build execution, not approval for merging into a branch.
A pull-request trigger (A) and an owners filter (B) do not directly satisfy the requirements.
Building repositories from GitHub | Cloud Build Documentation
Q8Google Professional Cloud Devops Engineer
Show answer
Correct answer: A. Cloud Build and Packer
The correct answer is A.
Packer is an open-source tool that can create identical machine images for multiple platforms (Google Cloud, AWS, Azure, and so on) from a single source configuration, making it ideal for the requirement of multi-cloud custom VM images.
It can be run as a pipeline from Cloud Build.Packer, which can build multi-cloud VM images from a single configuration, is the correct answer that also adapts to future changes.
Google Cloud Deploy (B and C) automates application delivery to GKE, Cloud Run, and the like, and does not support creating VM images for other clouds.
kpt (D) is for managing Kubernetes manifests and serves a different purpose.
Building VM images with Packer | Cloud Build Documentation
Q9Google Professional Cloud Devops Engineer
Show answer
Correct answer: A. Verify the maximum size of the node pool, enable the Horizontal Pod Autoscaler, and use load testing to actually measure and validate the expected resource demand.
The correct answer is A.
Proper scaling requires a layered approach: confirming that the node pool’s maximum size can meet future demand, using the Horizontal Pod Autoscaler (HPA) to automatically increase or decrease the number of Pods based on CPU/memory consumption, and further validating the actually required resources through load testing.The key point of the correct answer is combining maximum-size verification, HPA, and load testing to substantiate real demand.
Option B, which relies solely on cluster autoscaler; Option C, which overestimates headroom; and Option D, which adds 60% capacity without basis, all lack validation or autoscaling configuration and are inappropriate in terms of cost efficiency and reliability.
Horizontal Pod Autoscaler | GKE Documentation
Q10Google Professional Cloud Devops Engineer
Show answer
Correct answer: B, E
The correct answers are B and E.
In SRE, automating repetitive work (toil) and presenting mitigation measures based on impact analysis shorten the time from detection to recovery (B).
Also, an up-to-date playbook documenting debugging and mitigation steps is essential for on-call responders to react quickly and consistently (E).Speeding up response through automation and maintaining an always-current playbook are core SRE practices.
Option A, which limits authority to the on-call team, invites bottlenecks and violates least privilege, while Option C, which allows all teams to make production changes, undermines change management.
Alerting based solely on internal behavior (D) runs counter to the principle that alerts should be based on user impact (SLOs) and creates alert fatigue.
Reliability pillar | Google Cloud Architecture Framework