Which of the following statements about encryption on GCP is not true?
Answer
Google Cloud Platform encrypts customer data stored at rest by default.
Each encryption key is itself encrypted with a set of master keys.
If you want to manage your own encryption keys for data on Google Cloud Storage, the only option is Customer-Managed Encryption Keys (CMEK) using Cloud KMS.
Data in Google Cloud Platform is broken into subfile chunks for storage, and each chunk is encrypted at the storage level with an individual encryption key.
Card 202
Question
Which of these is not a principle you should apply when setting roles and permissions?
Answer
Whenever possible, assign roles to groups instead of to individuals.
Grant users the appropriate permissions to facilitate least privilege
Whenever possible, assign primitive roles rather than predefined roles.
Audit all policy changes by checking the Cloud Audit Logs.
Card 203
Question
Which of these is not a recommended method of authenticating an application with a Google Cloud service?
Answer
Use the gcloud and/or gsutil commands.
Request an OAuth2 access token and use it directly.
Embed the service account's credentials in the application's source code.
Use one of the Google Cloud Client Libraries.
Card 204
Question
What are two different features that fully isolate groups of VM instances?
Answer
Firewall rules and subnetworks
Networks and subnetworks
Projects and networks
Subnetworks and projects
Card 205
Question
Suppose you have a web server that is working properly, but you can't connect to its instance VM over SSH. Which of these troubleshooting methods can you use without disrupting production traffic? (Select 3 answers.)
Answer
Create a snapshot of the disk and use it to create a new disk; then attach the new disk to a new instance
Use netcat to try to connect to port 22
Access the serial console output
Create a startup script to collect information.
Card 206
Question
To configure Stackdriver to monitor a web server and let you know if it goes down, what steps do you need to take? (Select 2 answers.)
Answer
Install the Stackdriver Logging Agent on the web server
Create an alerting policy
Install the Stackdriver Monitoring Agent on the web server
Create an uptime check
Card 207
Question
Which of these tools can you use to copy data from AWS S3 to Cloud Storage? (Select 2 answers.)
Answer
Cloud Storage Transfer Service
Cloud Storage Console
S3 Storage Transfer Service
gsutil
Card 208
Question
Which statements about application load testing are true? (Select 2 answers.)
Answer
You should test at the maximum load that you expect to encounter.
You should test at 50% more than the maximum load that you expect to encounter.
It is not necessary to test sudden increases in traffic since GCP scales seamlessly.
Your load tests should include testing sudden increases in traffic.
Card 209
Question
Which of these statements about resilience testing are true? (Select 2 answers.)
Answer
In a resilience test, your application should keep running with little or no downtime.
To test the resilience of an autoscaling instance group, you can terminate a random instance within that group.
In order for an application to survive instance failures, it should not be stateless.
Resilience testing is the same as disaster recovery testing.
Card 210
Question
Which combination of Stackdriver services will alert you about errors generated by your applications and help you locate the root cause in the code?
Answer
Monitoring, Trace, and Debugger
Monitoring and Error Reporting
Debugger and Error Reporting
Alerts and Debugger
Card 211
Question
If you have configured Stackdriver Logging to export logs to BigQuery, but logs entries are not getting exported to BigQuery, what is the most likely cause?
Answer
The Cloud Data Transfer Service has not been enabled.
There isn't a firewall rule allowing traffic between Stackdriver and BigQuery.
The size of the Stackdriver log entries being exported exceeds the maximum capacity of the BigQuery dataset.
Stackdriver Logging does not have permission to write to the BigQuery dataset.
Card 212
Question
You can use Stackdriver to monitor virtual machines on which cloud platforms?
Answer
Google Cloud Platform, Microsoft Azure
Google Cloud Platform
Google Cloud Platform, Microsoft Azure, Amazon Web Services
Google Cloud Platform, Amazon Web Services
Card 213
Question
To minimize the risk of someone changing your log files to hide their activities, which of the following principles would help? (Select 3 answers.)
Answer
Restrict usage of the owner role for projects and log buckets.
Require two people to inspect the logs.
Implement object versioning on the log-buckets.
Encrypt the logs using Cloud KMS.
Card 214
Question
If network traffic between one Google Compute Engine instance and another instance is being dropped, what is the most likely cause?
Answer
The instances are on a network with low bandwidth.
The TCP keep-alive setting is too short.
The instances are on a default network with no additional firewall rules.
A firewall rule was deleted.
Card 215
Question
Which of the following practices can help you develop more secure software? (Select 3 answers.)
Answer
Penetration tests
Integrating static code analysis tools into your CI/CD pipeline
Encrypting your source code
Peer review of code
Card 216
Question
Which two places hold information you can use to monitor the effects of a Cloud Storage lifecycle policy on specific objects? (Select 2 answers.)
Answer
Cloud Storage Lifecycle Monitoring
Access logs
Expiration time metadata
Lifecycle config file
Card 217
Question
If you have object versioning enabled on a multi-regional bucket, what will the following lifecycle config file do?
Archive objects older than 30 days (the second rule doesn't do anything)
Delete objects older than 30 days (the second rule doesn't do anything)
Archive objects older than 30 days and move objects to Coldline Storage after 365 days
Delete objects older than 30 days and move objects to Coldline Storage after 365 days
Card 218
Question
Which of the following statements about Stackdriver Trace are true? (Select 2 answers.)
Answer
Stackdriver Trace tracks the performance of the virtual machines running the application.
Stackdriver Trace tracks the latency of incoming requests.
Applications in App Engine automatically submit traces to Stackdriver Trace. Applications outside of App Engine need to use the Trace SDK or Trace API.
To make an application work with Stackdriver Trace, you need to add instrumentation code using the Trace SDK or Trace API, even if the application is in App
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.