Your company captures all web traffic data in Google Analytics 360 and stores it in BigQuery. Each country has its own dataset. Each dataset has multiple tables.
You want analysts from each country
to be able to see and query only the data for their respective countries.
How should you configure the access rights?
Answer
Create a group per country. Add analysts to their respective country-groups. Create a single group "˜all_analysts', and add all country-groups as members. Grant the "˜all-analysts' group the IAM role of BigQuery jobUser. Share the appropriate dataset with view access with each respective analyst country-group.
Create a group per country. Add analysts to their respective country-groups. Create a single group "˜all_analysts', and add all country-groups as members. Grant the "˜all-analysts' group the IAM role of BigQuery jobUser. Share the appropriate tables with view access with each respective analyst country-group.
Create a group per country. Add analysts to their respective country-groups. Create a single group "˜all_analysts', and add all country-groups as members. Grant the "˜all-analysts' group the IAM role of BigQuery dataViewer. Share the appropriate dataset with view access with each respective analyst country-group.
Create a group per country. Add analysts to their respective country-groups. Create a single group "˜all_analysts', and add all country-groups as members. Grant the "˜all-analysts' group the IAM role of BigQuery dataViewer. Share the appropriate table with view access with each respective analyst country-group.
Card 122
Question
You have been engaged by your client to lead the migration of their application infrastructure to GCP. One of their current problems is that the on-premises high performance SAN is requiring frequent and expensive upgrades to keep up with the variety of workloads that are identified as follows: 20TB of log archives retained for legal reasons; 500 GB of VM boot/data volumes and templates; 500 GB of image thumbnails; 200 GB of customer session state data that allows customers to restart sessions even if off-line for several days.
Which of the following best reflects your recommendations for a cost-effective storage allocation?
Answer
Local SSD for customer session state data. Lifecycle-managed Cloud Storage for log archives, thumbnails, and VM boot/data volumes.
Memcache backed by Cloud SQL for customer session state data. Assorted local SSD-backed instances for VM boot/data volumes. Cloud Storage for log archives and thumbnails.
Memcache backed by Cloud Datastore for the customer session state data. Lifecycle- managed Cloud Storage for log archives, thumbnails, and VM boot/data volumes.
Memcache backed by Persistent Disk SSD storage for customer session state data. Assorted local SSD-backed instances for VM boot/data volumes. Cloud Storage for log archives and thumbnails.
Card 123
Question
Your web application uses Google Kubernetes Engine to manage several workloads. One workload requires a consistent set of hostnames even after pod scaling and relaunches.
Which feature of Kubernetes should you use to accomplish this?
Answer
StatefulSets
Role-based access control
Container environment variables
Persistent Volumes
Card 124
Question
You are using Cloud CDN to deliver static HTTP(S) website content hosted on a Compute Engine instance group. You want to improve the cache hit ratio.
What should you do?
Answer
Customize the cache keys to omit the protocol from the key.
Shorten the expiration time of the cached objects.
Make sure the HTTP(S) header "Cache-Region" points to the closest region of your users.
Replicate the static content in a Cloud Storage bucket. Point CloudCDN toward a load balancer on that bucket.
Card 125
Question
Your architecture calls for the centralized collection of all admin activity and VM system logs within your project.
How should you collect these logs from both VMs and services?
Answer
All admin and VM system logs are automatically collected by Stackdriver.
Stackdriver automatically collects admin activity logs for most services. The Stackdriver Logging agent must be installed on each instance to collect system logs.
Launch a custom syslogd compute instance and configure your GCP project and VMs to forward all logs to it.
Install the Stackdriver Logging agent on a single compute instance and let it collect all audit and access logs for your environment.
Card 126
Question
You have an App Engine application that needs to be updated. You want to test the update with production traffic before replacing the current application version.
What should you do?
Answer
Deploy the update using the Instance Group Updater to create a partial rollout, which allows for canary testing.
Deploy the update as a new version in the App Engine application, and split traffic between the new and current versions.
Deploy the update in a new VPC, and use Google's global HTTP load balancing to split traffic between the update and current applications.
Deploy the update as a new App Engine application, and use Google's global HTTP load balancing to split traffic between the new and current applications.
Card 127
Question
All compute Engine instances in your VPC should be able to connect to an Active Directory server on specific ports. Any other traffic emerging from your instances is not allowed. You want to enforce this using VPC firewall rules.
How should you configure the firewall rules?
Answer
Create an egress rule with priority 1000 to deny all traffic for all instances. Create another egress rule with priority 100 to allow the Active Directory traffic for all instances.
Create an egress rule with priority 100 to deny all traffic for all instances. Create another egress rule with priority 1000 to allow the Active Directory traffic for all instances.
Create an egress rule with priority 1000 to allow the Active Directory traffic. Rely on the implied deny egress rule with priority 100 to block all traffic for all instances.
Create an egress rule with priority 100 to allow the Active Directory traffic. Rely on the implied deny egress rule with priority 1000 to block all traffic for all instances.
Card 128
Question
Your customer runs a web service used by e-commerce sites to offer product recommendations to users. The company has begun experimenting with a machine learning model on Google Cloud Platform to improve the quality of results.
What should the customer do to improve their model's results over time?
Answer
Export Cloud Machine Learning Engine performance metrics from Stackdriver to BigQuery, to be used to analyze the efficiency of the model.
Build a roadmap to move the machine learning model training from Cloud GPUs to Cloud TPUs, which offer better results.
Monitor Compute Engine announcements for availability of newer CPU architectures, and deploy the model to them as soon as they are available for additional performance.
Save a history of recommendations and results of the recommendations in BigQuery, to be used as training data.
Card 129
Question
A development team at your company has created a dockerized HTTPS web application. You need to deploy the application on Google Kubernetes Engine (GKE) and make sure that the application scales automatically.
How should you deploy to GKE?
Answer
Use the Horizontal Pod Autoscaler and enable cluster autoscaling. Use an Ingress resource to load-balance the HTTPS traffic.
Use the Horizontal Pod Autoscaler and enable cluster autoscaling on the Kubernetes cluster. Use a Service resource of type LoadBalancer to load-balance the HTTPS traffic.
Enable autoscaling on the Compute Engine instance group. Use a Service resource of type LoadBalancer to load-balance the HTTPS traffic.
Enable autoscaling on the Compute Engine instance group. Use an Ingress resource to load balance the HTTPS traffic.
Card 130
Question
You need to design a solution for global load balancing based on the URL path being requested. You need to ensure operations reliability and end-to-end in- transit encryption based on Google best practices.
What should you do?
Answer
Create a cross-region load balancer with URL Maps.
Create an HTTPS load balancer with URL maps.
Create appropriate instance groups and instances. Configure SSL proxy load balancing.
Create a global forwarding rule. Configure SSL proxy balancing.
Card 131
Question
You have an application that makes HTTP requests to Cloud Storage. Occasionally the requests fail with HTTP status codes of 5xx and 429.
How should you handle these types of errors?
Answer
Use gRPC instead of HTTP for better performance.
Make sure the Cloud Storage bucket is multi-regional for geo-redundancy.
Implement retry logic using a truncated exponential backoff strategy.
Monitor https://status.cloud.google.com/feed.atom and only make requests if Cloud Storage is not reporting an incident.
Card 132
Question
You need to develop procedures to test a disaster plan for a mission-critical application. You want to use Google-recommended practices and native capabilities within GCP.
What should you do?
Answer
Use Deployment Manager to automate service provisioning. Use Activity Logs to monitor and debug your tests.
Use gcloud scripts to automate service provisioning. Use Activity Logs monitor and debug your tests.
Use Deployment Manager to automate service provisioning. Use Stackdriver to monitor and debug your tests.
Use gcloud scripts to automate service provisioning. Use Activity Logs monitor and debug your tests.
Card 133
Question
Your company creates rendering software which users can download from the company website. Your company has customers all over the world. You want to minimize latency for all your customers. You want to follow Google-recommended practices.
How should you store the files?
Answer
Save the files in a Multi-Regional Cloud Storage bucket.
Save the files in a Regional Cloud Storage bucket, one bucket per zone of the region.
Save the files in multiple Regional Cloud Storage buckets, one bucket per zone per region.
Save the files in multiple Multi-Regional Cloud Storage buckets, one bucket per multi-region.
Card 134
Question
Your company acquired a healthcare startup and must retain its customers' medical information for up to 4 more years, depending on when it was created. Your corporate policy is to securely retain this data, and then delete it as soon as regulations allow.
Which approach should you take?
Answer
Store the data in Google Drive and manually delete records as they expire.
Anonymize the data using the Cloud Data Loss Prevention API and store it indefinitely.
Store the data in Cloud Storage and use lifecycle management to delete files when they expire.
Store the data in Cloud Storage and run a nightly batch script that deletes all expired data.
Card 135
Question
You are deploying a PHP App Engine Standard service with SQL as the backend. You want to minimize the number of queries to the database.
What should you do?
Answer
Set the memcache service level to dedicated. Create a key from the hash of the query, and return database values from memcache before issuing a query to Cloud SQL.
Set the memcache service level to dedicated. Create a cron task that runs every minute to populate the cache with keys containing query results.
Set the memcache service level to shared. Create a key called "cached-queries", and return database values from the key before using a query to Cloud SQL.
Set the memcache service level to shared. Create a cron task that runs every minute to save all expected queries to a key called "cached-queries".
Card 136
Question
You need to ensure reliability for your application and operations by supporting reliable task a scheduling for compute on GCP. Leveraging Google best practices, what should you do?
Answer
Using the Cron service provided by App Engine, publishing messages directly to a message-processing utility service running on Compute Engine instances.
Using the Cron service provided by App Engine, publish messages to a Cloud Pub/Sub topic. Subscribe to that topic using a message-processing utility service running on Compute Engine instances.
Using the Cron service provided by Google Kubernetes Engine (GKE), publish messages directly to a message-processing utility service running on Compute Engine instances.
Using the Cron service provided by GKE, publish messages to a Cloud Pub/Sub topic. Subscribe to that topic using a message-processing utility service running on Compute Engine instances.
Card 137
Question
Your company is building a new architecture to support its data-centric business focus. You are responsible for setting up the network. Your company's mobile and web-facing applications will be deployed on-premises, and all data analysis will be conducted in GCP. The plan is to process and load 7 years of archived .csv files totaling 900 TB of data and then continue loading 10 TB of data daily. You currently have an existing 100-MB internet connection.
What actions will meet your company's needs?
Answer
Compress and upload both archived files and files uploaded daily using the gsutil -m option.
Lease a Transfer Appliance, upload archived files to it, and send it, and send it to Google to transfer archived data to Cloud Storage. Establish a connection with Google using a Dedicated Interconnect or Direct Peering connection and use it to upload files daily.
Lease a Transfer Appliance, upload archived files to it, and send it, and send it to Google to transfer archived data to Cloud Storage. Establish one Cloud VPN Tunnel to VPC networks over the public internet, and compares and upload files daily using the gsutil ""m option.
Lease a Transfer Appliance, upload archived files to it, and send it to Google to transfer archived data to Cloud Storage. Establish a Cloud VPN Tunnel to VPC networks over the public internet, and compress and upload files daily.
Card 138
Question
You are developing a globally scaled frontend for a legacy streaming backend data API. This API expects events in strict chronological order with no repeat data for proper processing.
Which products should you deploy to ensure guaranteed-once FIFO (first-in, first-out) delivery of data?
Answer
Cloud Pub/Sub alone
Cloud Pub/Sub to Cloud DataFlow
Cloud Pub/Sub to Stackdriver
Cloud Pub/Sub to Cloud SQL
Card 139
Question
Mountkirk Games wants to set up a real-time analytics platform for their new game. The new platform must meet their technical requirements.
Which combination of Google technologies will meet all of their requirements?
Answer
Kubernetes Engine, Cloud Pub/Sub, and Cloud SQL
Cloud Dataflow, Cloud Storage, Cloud Pub/Sub, and BigQuery
Cloud Pub/Sub, Compute Engine, Cloud Storage, and Cloud Dataproc
Cloud Dataproc, Cloud Pub/Sub, Cloud SQL, and Cloud Dataflow
Cloud SQL, Cloud Storage, Cloud Pub/Sub, and Cloud Dataflow
Card 140
Question
For this question, refer to the Mountkirk Games case study. Mountkirk Games wants to migrate from their current analytics and statistics reporting model to one that meets their technical requirements on Google Cloud Platform.
Which two steps should be part of their migration plan? (Choose two.)
Answer
valuate the impact of migrating their current batch ETL code to Cloud Dataflow.
Write a schema migration plan to denormalize data for better performance in BigQuery.
Draw an architecture diagram that shows how to move from a single MySQL database to a MySQL cluster.
Integrate Cloud Armor to defend against possible SQL injection attacks in analytics files uploaded to Cloud Storage.
Load 10 TB of analytics data from a previous game into a Cloud SQL instance, and run test queries against the full dataset to confirm that they complete successfully.
How to use this set
Read the preview and check whether the content and answers suit your learning goal. You can add the public set to your sets to study it. Your account shows the available actions.