表示モード
画像位置
文字位置
理解度の自動記録
Q1Google Professional Cloud Devops Engineer
Q1. You have a service running on Cloud Run that requires a database password at startup.
Company policy mandates that all passwords be rotated every 24 hours, and the service must always be able to reference the latest password.
In addition, you do not want to incur any downtime each time the password is updated.
How should you address this?
Show answer
Correct answer: B. Manage the password in Secret Manager and mount the secret to the container as a volume.
The correct answer is B.When you mount a secret stored in Secret Manager as a volume, Cloud Run refreshes the mounted file approximately every 30 seconds, so the application can obtain the latest password without a redeployment.The key point of this question is that the volume-mount approach reflects the latest secret with zero downtime.
The environment-variable approach (Option A) fixes the secret at startup and caches it for up to 10 minutes, making it hard to keep up with a 24-hour rotation, and it also has the drawback of exposing the value in plain text.
Options C and D embed the password at build time and therefore require a redeployment, failing to meet the zero-downtime requirement.
Configuring secrets | Cloud Run Documentation
Q2Google Professional Cloud Devops Engineer
Q2. A mission-critical internal service has recently experienced a string of consecutive incidents.
To make root-cause investigation more efficient, you want to build a Cloud Monitoring dashboard that lets you tell at a glance whether an outage originates from your own application or from the Google Cloud platform you use.
How do you achieve this?
Show answer
Correct answer: A. Enable the Personalized Service Health annotation display on the dashboard.
The correct answer is A.Personalized Service Health is a feature that provides information about Google Cloud incidents affecting your own projects.
When you integrate it with Cloud Monitoring and enable annotations, Google Cloud outage events can be overlaid directly onto your service’s metric graphs.The basis for the correct answer is that it lets you directly distinguish your own outages from Google Cloud–side outages.
An alerting policy (B) is meant to notify you of threshold breaches and cannot isolate root cause.
Log-based metrics (C) and log widgets (D) are useful for analyzing your own logs, but they do not authoritatively indicate whether a Google Cloud–side outage is occurring.
Personalized Service Health overview | Google Cloud
Q3Google Professional Cloud Devops Engineer
Q3. You are designing a new multi-tenant Google Kubernetes Engine (GKE) cluster for a business partner.
The partner is concerned about the risk of using long-lived credentials and requires that, in accordance with the principle of least privilege (PoLP), each GKE workload be granted only the minimum necessary Identity and Access Management (IAM) permissions.
You must design an IAM impersonation approach in line with Google’s recommended best practices.
How do you configure this?
Show answer
Correct answer: A. Prepare a Google service account. On a cluster with Workload Identity enabled, create a Kubernetes service account and link the two using the roles/iam.workloadIdentityUser role and the iam.gke.io/gcp-service-account annotation. Assign the created Kubernetes service account to each workload, and repeat this procedure for every workload.
The correct answer is A.Workload Identity is Google’s recommended method for GKE workloads to securely access Google Cloud APIs with short-lived credentials, without managing service account keys.
By having the Kubernetes service account impersonate the Google service account via the roles/iam.workloadIdentityUser role and the iam.gke.io/gcp-service-account annotation, you can assign least-privilege permissions on a per-workload basis.Meeting the requirement, this approach eliminates long-lived keys while achieving both short-lived credentials and least privilege.
Option C, which uses service account keys, and Options B and D, which grant a shared identity at the node-pool level, are inappropriate because they retain long-lived keys or cannot separate permissions on a per-workload basis.
About Workload Identity | GKE Documentation
Q4Google Professional Cloud Devops Engineer
Q4. You are responsible for operating a Node.js application running on production Google Kubernetes Engine (GKE).
This application is configured to send HTTP requests to multiple dependent applications.
You want to know in advance which dependency could become a cause of performance degradation in the future.
How do you address this?
Show answer
Correct answer: B. Instrument all related applications with Stackdriver Trace (now Cloud Trace) and examine the flow of HTTP requests between services.
The correct answer is B.Cloud Trace (formerly Stackdriver Trace) is a distributed tracing service that visualizes how requests propagate between services and where latency occurs in each segment.
By tracing HTTP requests between services, you can identify the dependent application that is the source of the delay.Distributed tracing shows the latency breakdown between services, making it ideal for identifying slow dependencies.
Profiler (A) is for analyzing code resource consumption, and Debugger (C) is for inspecting the state of running code; neither is suited to identifying dependency latency.
Logging (D) imposes a heavy implementation burden and is a roundabout approach.
Note that the Stackdriver-family services have now been renamed to Cloud Operations.
Cloud Trace overview | Google Cloud
Q5Google Professional Cloud Devops Engineer
Q5. You are developing a set of reusable Infrastructure as Code (IaC) modules.
Each module includes an integration test that actually launches the module on a test project.
You use GitHub for source control, and you want to continuously test feature branches to guarantee that all code is tested before it is merged.
You need to implement a mechanism that automates these integration tests.
How do you achieve this?
Show answer
Correct answer: D. Configure Cloud Build to run only the tests under a specific folder, and trigger Cloud Build each time a pull request is created on GitHub.
The correct answer is D.Because tests must run before changes are accepted (merged), triggering Cloud Build at the moment a pull request is created is the appropriate approach.
Using the Cloud Build GitHub app, you can launch a build for each pull request and run only the integration tests in a specific folder.To verify before merging, running triggers on a per-pull-request basis is essential.
Option B runs after merge, Option C asks a reviewer to run tests manually, and Option A uses periodically scheduled Jenkins; none of them satisfy the requirement of automated testing before acceptance.
Building repositories from GitHub | Cloud Build Documentation
Q6Google Professional Cloud Devops Engineer
Q6. You operate an internal application that runs on Compute Engine.
This application exposes an API through its own HTTP server and is accessed by other applications through an internal TCP/UDP load balancer.
Currently, the firewall rules still allow access to the API port from 0.0.0.0/0.
With as little effort as possible, you want to record in Cloud Logging each IP address that accesses the API.
What should you do?
Show answer
Correct answer: C. Enable the logging option on the existing firewall rule.
The correct answer is C.Because a firewall rule that allows access to the API port already exists, you simply need to enable logging on that rule, achieving the goal with minimal steps.
Firewall rules logging generates a connection record for each connection and records the source and destination IP addresses.Firewall rules logging is not sampled and records every connection, so it captures each IP without omission.
VPC Flow Logs (D) sample packets, so they are inferior for the requirement of reliably recording “each IP” and also require new configuration on the subnet.
Packet Mirroring (A) and the Ops Agent (B) are excessive or inappropriate for this purpose.
Firewall rules logging | Cloud NGFW Documentation
Q7Google Professional Cloud Devops Engineer
Q7. You have built a CI/CD pipeline with Cloud Build to build your application’s container image.
The application source code is managed on GitHub.
Company rules stipulate that production image builds be performed only against the main branch, and that every push to the main branch go through approval from the change management team.
You want to automate image builds as much as possible.
What should you do? (Choose two.)
Show answer
Correct answer: C, D
The correct answers are C and D.To build production images only against the main branch, create a trigger whose repository event is set to “Push to a branch” and limit the target branch to main (C).
Also, to have the change management team approve every push to main, configure a branch protection rule on the main branch on the GitHub side (D).The key point is to divide responsibilities: build invocation via a Cloud Build trigger, and approval control via a GitHub branch protection rule.
The Cloud Build approval option (E) is approval for build execution, not approval for merging into a branch.
A pull-request trigger (A) and an owners filter (B) do not directly satisfy the requirements.
Building repositories from GitHub | Cloud Build Documentation
Q8Google Professional Cloud Devops Engineer
Q8. You are building a CI/CD pipeline for an application in your multi-cloud environment.
This application is deployed using a custom Compute Engine image and an equivalent image on another cloud provider.
You need a mechanism that can build and deploy images for the current environment while also flexibly accommodating future changes.
Which solution stack should you choose?
Show answer
Correct answer: A. Cloud Build and Packer
The correct answer is A.Packer is an open-source tool that can create identical machine images for multiple platforms (Google Cloud, AWS, Azure, and so on) from a single source configuration, making it ideal for the requirement of multi-cloud custom VM images.
It can be run as a pipeline from Cloud Build.Packer, which can build multi-cloud VM images from a single configuration, is the correct answer that also adapts to future changes.
Google Cloud Deploy (B and C) automates application delivery to GKE, Cloud Run, and the like, and does not support creating VM images for other clouds.
kpt (D) is for managing Kubernetes manifests and serves a different purpose.
Building VM images with Packer | Cloud Build Documentation
Q9Google Professional Cloud Devops Engineer
Q9. You perform capacity planning for your core service every six months.
Over the next six months, the number of users is forecast to grow by 10% each month.
This service is fully containerized and runs on Google Cloud Platform (GCP) on a three-zone Google Kubernetes Engine (GKE) Standard regional cluster with cluster autoscaler enabled.
You currently use about 30% of the deployed CPU capacity, and you must also ensure tolerance for a single-zone failure.
You want to minimize the impact on users even if this growth in usage or a zone failure occurs, while avoiding wasted cost.
How should you prepare for the anticipated growth?
Show answer
Correct answer: A. Verify the maximum size of the node pool, enable the Horizontal Pod Autoscaler, and use load testing to actually measure and validate the expected resource demand.
The correct answer is A.Proper scaling requires a layered approach: confirming that the node pool’s maximum size can meet future demand, using the Horizontal Pod Autoscaler (HPA) to automatically increase or decrease the number of Pods based on CPU/memory consumption, and further validating the actually required resources through load testing.The key point of the correct answer is combining maximum-size verification, HPA, and load testing to substantiate real demand.
Option B, which relies solely on cluster autoscaler; Option C, which overestimates headroom; and Option D, which adds 60% capacity without basis, all lack validation or autoscaling configuration and are inappropriate in terms of cost efficiency and reliability.
Horizontal Pod Autoscaler | GKE Documentation
Q10Google Professional Cloud Devops Engineer
Q10. You are in the middle of migrating your production systems to Google Cloud.
To minimize the impact of potential future incidents on customers, you need to adopt Site Reliability Engineering (SRE) practices in parallel with the migration work.
Which two SRE practices should you introduce? (Choose two.)
Show answer
Correct answer: B, E
The correct answers are B and E.In SRE, automating repetitive work (toil) and presenting mitigation measures based on impact analysis shorten the time from detection to recovery (B).
Also, an up-to-date playbook documenting debugging and mitigation steps is essential for on-call responders to react quickly and consistently (E).Speeding up response through automation and maintaining an always-current playbook are core SRE practices.
Option A, which limits authority to the on-call team, invites bottlenecks and violates least privilege, while Option C, which allows all teams to make production changes, undermines change management.
Alerting based solely on internal behavior (D) runs counter to the principle that alerts should be based on user impact (SLOs) and creates alert fatigue.
Reliability pillar | Google Cloud Architecture Framework
