You are developing a microservice-based application that will run on Google Kubernetes Engine (GKE). Some of the services need to access different Google Cloud APIs. How should you set up authentication of these services in the cluster following Google-recommended best practices?
(Choose two.)
A. Use gcloud to bind the Kubernetes service account and the Google service account using roles/iam.workloadIdentity.
B. Use the service account attached to the GKE node.
C. Enable Workload Identity in the cluster via the gcloud command-line tool.
D. Store the Google service account keys in a central secret management service.
E. Access the Google service account keys from a secret management service.
正解:A,C
解説: (Pass4Test メンバーにのみ表示されます)
質問 2:
Case Study 1 - HipLocal
Company Overview
HipLocal is a community application designed to facilitate communication between people in close proximity. It is used for event planning and organizing sporting events, and for businesses to connect with their local communities. HipLocal launched recently in a few neighborhoods in Dallas and is rapidly growing into a global phenomenon. Its unique style of hyper-local community communication and business outreach is in demand around the world.
Executive Statement
We are the number one local community app; it's time to take our local community services global. Our venture capital investors want to see rapid growth and the same great experience for new local and virtual communities that come online, whether their members are 10 or 10000 miles away from each other.
Solution Concept
HipLocal wants to expand their existing service, with updated functionality, in new regions to better serve their global customers. They want to hire and train a new team to support these regions in their time zones. They will need to ensure that the application scales smoothly and provides clear uptime data.
Existing Technical Environment
HipLocal's environment is a mix of on-premises hardware and infrastructure running in Google Cloud Platform. The HipLocal team understands their application well, but has limited experience in global scale applications. Their existing technical environment is as follows:
* Existing APIs run on Compute Engine virtual machine instances hosted in GCP.
* State is stored in a single instance MySQL database in GCP.
* Data is exported to an on-premises Teradata/Vertica data warehouse.
* Data analytics is performed in an on-premises Hadoop environment.
* The application has no logging.
* There are basic indicators of uptime; alerts are frequently fired when the APIs are unresponsive.
Business Requirements
HipLocal's investors want to expand their footprint and support the increase in demand they are seeing. Their requirements are:
* Expand availability of the application to new regions.
* Increase the number of concurrent users that can be supported.
* Ensure a consistent experience for users when they travel to different regions.
* Obtain user activity metrics to better understand how to monetize their product.
* Ensure compliance with regulations in the new regions (for example, GDPR).
* Reduce infrastructure management time and cost.
* Adopt the Google-recommended practices for cloud computing.
Technical Requirements
* The application and backend must provide usage metrics and monitoring.
* APIs require strong authentication and authorization.
* Logging must be increased, and data should be stored in a cloud analytics platform.
* Move to serverless architecture to facilitate elastic scaling.
* Provide authorized access to internal apps in a secure manner.
In order to meet their business requirements, how should HipLocal store their application state?
A. Replace the MySQL instance with Cloud SQL.
B. Put a memcache layer in front of MySQL.
C. Use local SSDs to store state.
D. Move the state storage to Cloud Spanner.
正解:A
質問 3:
Your analytics system executes queries against a BigQuery dataset. The SQL query is executed in batch and passes the contents of a SQL file to the BigQuery CLI. Then it redirects the BigQuery CLI output to another process. However, you are getting a permission error from the BigQuery CLI when the queries are executed.
You want to resolve the issue. What should you do?
A. Grant the service account BigQuery Data Editor and BigQuery Data Viewer roles.
B. Create a view in BigQuery from the SQL query and SELECT* from the view in the CLI.
C. Grant the service account BigQuery Data Viewer and BigQuery Job User roles.
D. Create a new dataset in BigQuery, and copy the source table to the new dataset Query the new dataset and table from the CLI.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 4:
Your infrastructure team is responsible for creating and managing Compute Engine VMs. Your team uses the Google Cloud console and gcloud CLI to provision resources for the development environment. You need to ensure that all Compute Engine VMs are labeled correctly for compliance reasons. In case of missing labels, you need to implement corrective actions so the labels are configured accordingly without changing the current deployment process. You want to use the most scalable approach. What should you do?
A. Use a Cloud Audit Logs trigger to invoke a Cloud Run function when a Compute Engine VM is created. Check for missing labels and assign them if necessary.
B. Write a script to check all Compute Engine VMs for missing labels regularly by using Cloud Scheduler. Use the script to assign the labels.
C. Deploy resources with Terraform. Use the gcloud terraform vet command with a policy to ensure that every Compute Engine VM that is provisioned by Terraform has labels set.
D. Check all Compute Engine VMs for missing labels regularly. Use the console to assign the labels.
正解:A
解説: (Pass4Test メンバーにのみ表示されます)
質問 5:
You are developing a JPEG image-resizing API hosted on Google Kubernetes Engine (GKE).
Callers of the service will exist within the same GKE cluster. You want clients to be able to get the IP address of the service.
What should you do?
A. Define a GKE Endpoint. Clients should get the endpoint name from the appropriate environment variable in the client container.
B. Define a GKE Service. Clients should use the name of the A record in Cloud DNS to find the service's cluster IP address.
C. Define a GKE Endpoint. Clients should get the endpoint name from Cloud DNS.
D. Define a GKE Service. Clients should use the service name in the URL to connect to the service.
正解:D
解説: (Pass4Test メンバーにのみ表示されます)
質問 6:
You recently developed an application. You need to call the Cloud Storage API from a Compute Engine instance that doesn't have a public IP address. What should you do?
A. Use Carrier Peering
B. Use Private Google Access
C. Use VPC Network Peering
D. Use Shared VPC networks
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
質問 7:
You have an application running in Cloud Run that validates bucket names based on your organization's compliance rule. You want the Cloud Run application to receive a notification as quickly as possible each time a new Cloud Storage bucket is created, and send an alert to the project owner if the bucket name is not in compliance. You need to configure the notification while following Google-recommended practices. What should you do?
A. Configure a log-based alerting policy using the storage.buckets.create filter in the audit logs that sends a notification to a Pub/Sub topic that is pushed to the Cloud Run service.
B. Configure a log-based alerting policy using the storage.buckets.create filter in the audit logs that sends a notification to the Cloud Run webhook.
C. Configure an Eventarc trigger using the storage.buckets.create filter that sends a notification to the Cloud Run endpoint.
D. Create a log-based metric with an alerting policy that sends a notification using the webhook to the Cloud Run endpoint.
正解:C
解説: (Pass4Test メンバーにのみ表示されます)
質問 8:
You are developing a new public-facing application that needs to retrieve specific properties in the metadata of users' objects in their respective Cloud Storage buckets. Due to privacy and data residency requirements, you must retrieve only the metadata and not the object data. You want to maximize the performance of the retrieval process. How should you retrieve the metadata?
A. Use the patch method.
B. Use the fields request parameter.
C. Use the copy method.
D. Use the compose method.
正解:B
解説: (Pass4Test メンバーにのみ表示されます)
988 お客様のコメント





Koyanagi -
勉強はちょっと大変だと思います。
でも最後まで頑張りました。合格できるのは何よりです。