Tested Material Used To Professional-Cloud-Architect Test Engine Exam Questions in here [Dec-2021]
Penetration testers simulate Professional-Cloud-Architect exam PDF
NEW QUESTION 15
Your development team has created a mobile game app. You want to test the new mobile app on Android and iOS devices with a variety of configurations. You need to ensure that testing is efficient and cost-effective.
What
should you do?
- A. Upload your mobile app to the Firebase Test Lab, and test the mobile app on Android and iOS devices.
- B. Upload your mobile app with different configurations to Firebase Hosting and test each configuration.
- C. Create Android and iOS VMs on Google Cloud, install the mobile app on the VMs, and test the mobile app.
- D. Create Android and iOS containers on Google Kubernetes Engine (GKE), install the mobile app on the containers, and test the mobile app.
Answer: D
NEW QUESTION 16
Your company has decided to build a backup replica of their on-premises user authentication PostgreSQL database on Google Cloud Platform. The database is 4 TB, and large updates are frequent. Replication requires private address space communication. Which networking approach should you use?
- A. Google Cloud VPN connected to the data center network
- B. Google Cloud Dedicated Interconnect
- C. A Google Compute Engine instance with a VPN server installed connected to the data center network
- D. A NAT and TLS translation gateway installed on-premises
Answer: B
Explanation:
https://cloud.google.com/docs/enterprise/best-practices-for-enterprise-organizations Google Cloud Dedicated Interconnect provides direct physical connections and RFC 1918 communication between your on-premises network and Google's network. Dedicated Interconnect enables you to transfer large amounts of data between networks, which can be more cost effective than purchasing additional bandwidth over the public Internet or using VPN tunnels.
Benefits:
* Traffic between your on-premises network and your VPC network doesn't traverse the public Internet. Traffic traverses a dedicated connection with fewer hops, meaning there are less points of failure where traffic might get dropped or disrupted.
* Your VPC network's internal (RFC 1918) IP addresses are directly accessible from your on-premises network. You don't need to use a NAT device or VPN tunnel to reach internal IP addresses. Currently, you can only reach internal IP addresses over a dedicated connection. To reach Google external IP addresses, you must use a separate connection.
* You can scale your connection to Google based on your needs. Connection capacity is delivered over one or more 10 Gbps Ethernet connections, with a maximum of eight connections (80 Gbps total per interconnect).
* The cost of egress traffic from your VPC network to your on-premises network is reduced. A dedicated connection is generally the least expensive method if you have a high-volume of traffic to and from Google's network.
References:
https://cloud.google.com/interconnect/docs/details/dedicated
NEW QUESTION 17
For this question, refer to the Dress4Win case study.
Dress4Win has end-to-end tests covering 100% of their endpoints. They want to ensure that the move to the cloud does not introduce any new bugs. Which additional testing methods should the developers employ to prevent an outage?
- A. They should run the end-to-end tests in the cloud staging environment to determine if the code is working as intended.
- B. They should add additional unit tests and production scale load tests on their cloud staging environment.
- C. They should add canary tests so developers can measure how much of an impact the new release causes to latency.
- D. They should enable Google Stackdriver Debugger on the application code to show errors in the code.
Answer: C
NEW QUESTION 18
For this question, refer to the Mountkirk Games case study. Mountkirk Games wants to migrate from their current analytics and statistics reporting model to one that meets their technical requirements on Google Cloud Platform.
Which two steps should be part of their migration plan? (Choose two.)
- A. Load 10 TB of analytics data from a previous game into a Cloud SQL instance, and run test queries against the full dataset to confirm that they complete successfully.
- B. Write a schema migration plan to denormalize data for better performance in BigQuery.
- C. Evaluate the impact of migrating their current batch ETL code to Cloud Dataflow.
- D. Integrate Cloud Armor to defend against possible SQL injection attacks in analytics files uploaded to Cloud Storage.
- E. Draw an architecture diagram that shows how to move from a single MySQL database to a MySQL cluster.
Answer: B,C
NEW QUESTION 19
For this question, refer to the TerramEarth case study. A new architecture that writes all incoming data to BigQuery has been introduced. You notice that the data is dirty, and want to ensure data quality on an automated daily basis while managing cost.
What should you do?
- A. Use Cloud Dataprep and configure the BigQuery tables as the source. Schedule a daily job to clean the data.
- B. Create a Cloud Function that reads data from BigQuery and cleans it. Trigger it. Trigger the Cloud Function from a Compute Engine instance.
- C. Set up a streaming Cloud Dataflow job, receiving data by the ingestion process. Clean the data in a Cloud Dataflow pipeline.
- D. Create a SQL statement on the data in BigQuery, and save it as a view. Run the view daily, and save the result to a new table.
Answer: C
NEW QUESTION 20
Your architecture calls for the centralized collection of all admin activity and VM system logs within your project.
How should you collect these logs from both VMs and services?
- A. Install the Stackdriver Logging agent on a single compute instance and let it collect all audit and access logs for your environment.
- B. All admin and VM system logs are automatically collected by Stackdriver.
- C. Stackdriver automatically collects admin activity logs for most services. The Stackdriver Logging agent must be installed on each instance to collect system logs.
- D. Launch a custom syslogd compute instance and configure your GCP project and VMs to forward all logs to it.
Answer: C
Explanation:
Reference:
https://cloud.google.com/logging/docs/agent/default-logs
NEW QUESTION 21
You are analyzing and defining business processes to support your startup's trial usage of GCP, and you don't yet know what consumer demand for your product will be. Your manager requires you to minimize GCP service costs and adhere to Google best practices. What should you do?
- A. Utilize free tier and committed use discounts. Provide training to the team about service cost management.
- B. Utilize free tier and committed use discounts. Provision a staff position for service cost management.
- C. Utilize free tier and sustained use discounts. Provision a staff position for service cost management.
- D. Utilize free tier and sustained use discounts. Provide training to the team about service cost management.
Answer: D
NEW QUESTION 22
You have developed an application using Cloud ML Engine that recognizes famous paintings from uploaded images. You want to test the application and allow specific people to upload images for the next 24 hours. Not all users have a Google Account. How should you have users upload images?
- A. Have users upload the images to Cloud Storage. Protect the bucket with a password that expires after 24 hours.
- B. Create an App Engine web application where users can upload images. Configure App Engine to disable the application after 24 hours. Authenticate users via Cloud Identity.
- C. Have users upload the images to Cloud Storage using a signed URL that expires after 24 hours.
- D. Create an App Engine web application where users can upload images for the next 24 hours. Authenticate users via Cloud Identity.
Answer: A
NEW QUESTION 23
You have been asked to select the storage system for the click-data of your company's large portfolio of websites. This data is streamed in from a custom website analytics package at a typical rate of 6,000 clicks per minute, with bursts of up to 8,500 clicks per second. It must been stored for future analysis by your data science and user experience teams. Which storage infrastructure should you choose?
- A. Google Cloud SQL
- B. Google cloud Datastore
- C. Google Cloud Storage
- D. Google Cloud Bigtable
Answer: C
Explanation:
Reference:
https://cloud.google.com/bigquery/docs/loading-data-cloud-storage
NEW QUESTION 24
Case Study: 4 - Dress4Win case study
Company Overview
Dress4win is a web-based company that helps their users organize and manage their personal wardrobe using a website and mobile application. The company also cultivates an active social network that connects their users with designers and retailers. They monetize their services through advertising, e-commerce, referrals, and a freemium app model.
Company Background
Dress4win's application has grown from a few servers in the founder's garage to several hundred servers and appliances in a colocated data center. However, the capacity of their infrastructure is now insufficient for the application's rapid growth. Because of this growth and the company's desire to innovate faster, Dress4win is committing to a full migration to a public cloud.
Solution Concept
For the first phase of their migration to the cloud, Dress4win is considering moving their development and test environments. They are also considering building a disaster recovery site, because their current infrastructure is at a single location. They are not sure which components of their architecture they can migrate as is and which components they need to change before migrating them.
Existing Technical Environment
The Dress4win application is served out of a single data center location.
Databases:
MySQL - user data, inventory, static data
* Redis - metadata, social graph, caching
* Application servers:
Tomcat - Java micro-services
* Nginx - static content
* Apache Beam - Batch processing
* Storage appliances:
iSCSI for VM hosts
* Fiber channel SAN - MySQL databases
* NAS - image storage, logs, backups
* Apache Hadoop/Spark servers:
Data analysis
* Real-time trending calculations
* MQ servers:
Messaging
* Social notifications
* Events
* Miscellaneous servers:
Jenkins, monitoring, bastion hosts, security scanners
* Business Requirements
* Build a reliable and reproducible environment with scaled parity of production. Improve security by defining and adhering to a set of security and Identity and Access Management (IAM) best practices for cloud.
Improve business agility and speed of innovation through rapid provisioning of new resources.
Analyze and optimize architecture for performance in the cloud. Migrate fully to the cloud if all other requirements are met.
Technical Requirements
Evaluate and choose an automation framework for provisioning resources in cloud. Support failover of the production environment to cloud during an emergency. Identify production services that can migrate to cloud to save capacity.
Use managed services whenever possible.
Encrypt data on the wire and at rest.
Support multiple VPN connections between the production data center and cloud environment.
CEO Statement
Our investors are concerned about our ability to scale and contain costs with our current infrastructure. They are also concerned that a new competitor could use a public cloud platform to offset their up-front investment and freeing them to focus on developing better features.
CTO Statement
We have invested heavily in the current infrastructure, but much of the equipment is approaching the end of its useful life. We are consistently waiting weeks for new gear to be racked before we can start new projects. Our traffic patterns are highest in the mornings and weekend evenings; during other times, 80% of our capacity is sitting idle.
CFO Statement
Our capital expenditure is now exceeding our quarterly projections. Migrating to the cloud will likely cause an initial increase in spending, but we expect to fully transition before our next hardware refresh cycle. Our total cost of ownership (TCO) analysis over the next 5 years puts a cloud strategy between 30 to 50% lower than our current model.
For this question, refer to the Dress4Win case study.
The Dress4Win security team has disabled external SSH access into production virtual machines (VMs) on Google Cloud Platform (GCP). The operations team needs to remotely manage the VMs, build and push Docker containers, and manage Google Cloud Storage objects. What can they do?
- A. Develop a new access request process that grants temporary SSH access to cloud VMs when an operations engineer needs to perform a task.
- B. Configure a VPN connection to GCP to allow SSH access to the cloud VMs.
- C. Have the development team build an API service that allows the operations team to execute specific remote procedure calls to accomplish their tasks.
- D. Grant the operations engineers access to use Google Cloud Shell.
Answer: B
NEW QUESTION 25
You want to automate the creation of a managed instance group. The VMs have many OS package dependencies. You want to minimize the startup time for new VMs in the instance group.
What should you do?
- A. Use Deployment Manager to create the managed instance group and Ansible to install the OS package dependencies.
- B. Create a custom VM image with all OS package dependencies. Use Deployment Manager to create the managed instance group with the VM image.
- C. Use Terraform to create the managed instance group and a startup script to install the OS package dependencies.
- D. Use Puppet to create the managed instance group and install the OS package dependencies.
Answer: B
NEW QUESTION 26
Your organization requires that metrics from all applications be retained for 5 years for future analysis in possible legal proceedings. Which approach should you use?
- A. Configure Stackdriver Monitoring for all Projects, and export to BigQuery.
- B. Configure Stackdriver Monitoring for all Projects, and export to Google Cloud Storage.
- C. Grant the security team access to the logs in each Project.
- D. Configure Stackdriver Monitoring for all Projects with the default retention policies.
Answer: B
Explanation:
D - Cloud Storage 3 yrs estimated at 3k per 3 years
References:
https://cloud.google.com/monitoring/api/v3/metrics
https://cloud.google.com/stackdriver/
NEW QUESTION 27
TerramEarth's 20 million vehicles are scattered around the world. Based on the vehicle's location, its telemetry data is stored in a Google Cloud Storage (GCS) regional bucket (US, Europe, or Asia). The CTO has asked you to run a report on the raw telemetry data to determine why vehicles are breaking down after 100 K miles.
You want to run this job on all the data.
What is the most cost-effective way to run this job?
- A. Move all the data into 1 zone, then launch a Cloud Dataproc cluster to run the job
- B. Launch a cluster in each region to preprocess and compress the raw data, then move the data into a multi- region bucket and use a Dataproc cluster to finish the job
- C. Launch a cluster in each region to preprocess and compress the raw data, then move the data into a region bucket and use a Cloud Dataproc cluster to finish the job
- D. Move all the data into 1 region, then launch a Google Cloud Dataproc cluster to run the job
Answer: C
NEW QUESTION 28
A development team at your company has created a dockerized HTTPS web application. You need to deploy the application on Google Kubernetes Engine (GKE) and make sure that the application scales automatically.
How should you deploy to GKE?
- A. Enable autoscaling on the Compute Engine instance group. Use an Ingress resource to load balance the HTTPS traffic.
- B. Enable autoscaling on the Compute Engine instance group. Use a Service resource of type LoadBalancer to load-balance the HTTPS traffic.
- C. Use the Horizontal Pod Autoscaler and enable cluster autoscaling on the Kubernetes cluster. Use a Service resource of type LoadBalancer to load-balance the HTTPS traffic.
- D. Use the Horizontal Pod Autoscaler and enable cluster autoscaling. Use an Ingress resource to loadbalance the HTTPS traffic.
Answer: C
Explanation:
Reference:
https://cloud.google.com/kubernetes-engine/docs/tutorials/http-balancer
https://cloud.google.com/kubernetes-engine/docs/concepts/network-overview#ext-lb
NEW QUESTION 29
As part of Dress4Win's plans to migrate to the cloud, they want to be able to set up a managed logging
and monitoring system so they can handle spikes in their traffic load.
They want to ensure that:
* The infrastructure can be notified when it needs to scale up and down to handle the ebb and flow of
usage throughout the day
* Their administrators are notified automatically when their application reports errors.
* They can filter their aggregated logs down in order to debug one piece of the application across many
hosts
Which Google StackDriver features should they use?
- A. Monitoring, Logging, Debug, Error Report
- B. Logging, Alerts, Insights, Debug
- C. Monitoring, Trace, Debug, Logging
- D. Monitoring, Logging, Alerts, Error Reporting
Answer: C
NEW QUESTION 30
A recent audit revealed that a new network was created in your GCP project. In this network, a GCE instance has an SSH port open to the world. You want to discover this network's origin.
What should you do?
- A. Search for Create VM entry in the Stackdriver alerting console
- B. Connect to the GCE instance using project SSH keys. Identify previous logins in system logs, and match these with the project owners list
- C. Navigate to the Activity page in the Home section. Set category to Data Access and search for Create VM entry
- D. In the Logging section of the console, specify GCE Network as the logging section. Search for the Create Insert entry
Answer: D
Explanation:
Incorrect Answers:
A: To use the Stackdriver alerting console we must first set up alerting policies.
B: Data access logs only contain read-only operations.
Audit logs help you determine who did what, where, and when.
Cloud Audit Logging returns two types of logs:
Admin activity logs
Data access logs: Contains log entries for operations that perform read-only operations do not modify any data, such as get, list, and aggregated list methods.
NEW QUESTION 31
You are designing a large distributed application with 30 microservices. Each of your distributed microservices needs to connect to a database back-end. You want to store the credentials securely.
Where should you store the credentials?
- A. In a secret management system
- B. In the source code
- C. In a config file that has restricted access through ACLs
- D. In an environment variable
Answer: A
Explanation:
https://cloud.google.com/docs/authentication/production#providing_credentials_to_your_application
NEW QUESTION 32
Case Study: 4 - Dress4Win case study
Company Overview
Dress4win is a web-based company that helps their users organize and manage their personal wardrobe using a website and mobile application. The company also cultivates an active social network that connects their users with designers and retailers. They monetize their services through advertising, e-commerce, referrals, and a freemium app model.
Company Background
Dress4win's application has grown from a few servers in the founder's garage to several hundred servers and appliances in a colocated data center. However, the capacity of their infrastructure is now insufficient for the application's rapid growth. Because of this growth and the company's desire to innovate faster, Dress4win is committing to a full migration to a public cloud.
Solution Concept
For the first phase of their migration to the cloud, Dress4win is considering moving their development and test environments. They are also considering building a disaster recovery site, because their current infrastructure is at a single location. They are not sure which components of their architecture they can migrate as is and which components they need to change before migrating them.
Existing Technical Environment
The Dress4win application is served out of a single data center location.
Databases:
MySQL - user data, inventory, static data
Redis - metadata, social graph, caching
Application servers:
Tomcat - Java micro-services
Nginx - static content
Apache Beam - Batch processing
Storage appliances:
iSCSI for VM hosts
Fiber channel SAN - MySQL databases
NAS - image storage, logs, backups
Apache Hadoop/Spark servers:
Data analysis
Real-time trending calculations
MQ servers:
Messaging
Social notifications
Events
Miscellaneous servers:
Jenkins, monitoring, bastion hosts, security scanners
Business Requirements
Build a reliable and reproducible environment with scaled parity of production. Improve security by defining and adhering to a set of security and Identity and Access Management (IAM) best practices for cloud.
Improve business agility and speed of innovation through rapid provisioning of new resources.
Analyze and optimize architecture for performance in the cloud. Migrate fully to the cloud if all other requirements are met.
Technical Requirements
Evaluate and choose an automation framework for provisioning resources in cloud. Support failover of the production environment to cloud during an emergency. Identify production services that can migrate to cloud to save capacity.
Use managed services whenever possible.
Encrypt data on the wire and at rest.
Support multiple VPN connections between the production data center and cloud environment.
CEO Statement
Our investors are concerned about our ability to scale and contain costs with our current infrastructure. They are also concerned that a new competitor could use a public cloud platform to offset their up-front investment and freeing them to focus on developing better features.
CTO Statement
We have invested heavily in the current infrastructure, but much of the equipment is approaching the end of its useful life. We are consistently waiting weeks for new gear to be racked before we can start new projects. Our traffic patterns are highest in the mornings and weekend evenings; during other times, 80% of our capacity is sitting idle.
CFO Statement
Our capital expenditure is now exceeding our quarterly projections. Migrating to the cloud will likely cause an initial increase in spending, but we expect to fully transition before our next hardware refresh cycle. Our total cost of ownership (TCO) analysis over the next 5 years puts a cloud strategy between 30 to 50% lower than our current model.
For this question, refer to the Dress4Win case study.
Dress4Win has asked you for advice on how to migrate their on-premises MySQL deployment to the cloud. They want to minimize downtime and performance impact to their on-premises solution during the migration. Which approach should you recommend?
- A. Create a dump of the MySQL replica server into the cloud environment, load it into: Google Cloud Datastore, and configure applications to read/write to Cloud Datastore at cutover.
- B. Create a new MySQL cluster in the cloud, configure applications to begin writing to both on- premises and cloud MySQL masters, and destroy the original cluster at cutover.
- C. Setup a MySQL replica server/slave in the cloud environment, and configure it for asynchronous replication from the MySQL master server on-premises until cutover.
- D. Create a dump of the on-premises MySQL master server, and then shut it down, upload it to the cloud environment, and load into a new MySQL cluster.
Answer: C
NEW QUESTION 33
......
Introduction to Google Professional Cloud Architect Exam
Google Professional Cloud Architect Exam is a certification exam that is conducted by Google to validates candidate knowledge and skills of working as a Professional Cloud Architect in the IT industry.
After passing this exam, candidates get a certificate from Google that helps them to demonstrate their proficiency in Google Professional Cloud Architect to their clients and employers.
Authentic Best resources for Professional-Cloud-Architect Online Practice Exam: https://www.practicedump.com/Professional-Cloud-Architect_actualtests.html
Get the superior quality Professional-Cloud-Architect Dumps with explanations waiting just for you, get it now: https://drive.google.com/open?id=1VB7clOzHR13VL0DqmGBXpm1e9mOak8bP