Pay attention to our Valid and Useful Exam Reviews and take our Exam Torrent as your Study Material. With little time and energy investment, you have a High Efficiency Study experience. Pass your Actual Test with the help of our Actual Reviews.

Pass Your Professional-Cloud-DevOps-Engineer Dumps as PDF Updated on 2024 With 166 Questions [Q64-Q79]

Share

Pass Your Professional-Cloud-DevOps-Engineer Dumps as PDF Updated on 2024 With 166 Questions

Google Professional-Cloud-DevOps-Engineer Real Exam Questions and Answers FREE


Google Professional-Cloud-DevOps-Engineer exam is a comprehensive assessment that tests the candidate's knowledge and skills in various areas of cloud-based DevOps engineering. Professional-Cloud-DevOps-Engineer exam consists of multiple-choice questions and requires the candidate to demonstrate a deep understanding of the subject matter. Professional-Cloud-DevOps-Engineer exam is designed to evaluate the candidate's ability to apply their knowledge and skills to real-world scenarios.

 

NEW QUESTION # 64
You support an application deployed on Compute Engine. The application connects to a Cloud SQL instance to store and retrieve data. After an update to the application, users report errors showing database timeout messages. The number of concurrent active users remained stable. You need to find the most probable cause of the database timeout. What should you do?

  • A. Check the serial port logs of the Compute Engine instance.
  • B. Determine whether there is an increased number of connections to the Cloud SQL instance.
  • C. Use Cloud Security Scanner to see whether your Cloud SQL is under a Distributed Denial of Service (DDoS) attack.
  • D. Use Stackdriver Profiler to visualize the resources utilization throughout the application.

Answer: B

Explanation:
Explanation
The most probable cause of the database timeout is an increased number of connections to the Cloud SQL instance. This could happen if the application does not close connections properly or if it creates too many connections at once. You can check the number of connections to the Cloud SQL instance using Cloud Monitoring or Cloud SQL Admin API .


NEW QUESTION # 65
Your company is developing applications that are deployed on Google Kubernetes Engine (GKE). Each team manages a different application. You need to create the development and production environments for each team, while minimizing costs. Different teams should not be able to access other teams' environments. What should you do?

  • A. Create a Development and a Production GKE cluster in separate projects. In each cluster, create a Kubernetes namespace per team, and then configure Kubernetes Role-based access control (RBAC) so that each team can only access its own namespace.
  • B. Create a Development and a Production GKE cluster in separate projects. In each cluster, create a Kubernetes namespace per team, and then configure Identity Aware Proxy so that each team can only access its own namespace.
  • C. Create one GCP Project per team. In each project, create a cluster with a Kubernetes namespace for Development and one for Production. Grant the teams IAM access to their respective clusters.
  • D. Create one GCP Project per team. In each project, create a cluster for Development and one for Production. Grant the teams IAM access to their respective clusters.

Answer: A


NEW QUESTION # 66
You are developing a strategy for monitoring your Google Cloud Platform (GCP) projects in production using Stackdriver Workspaces. One of the requirements is to be able to quickly identify and react to production environment issues without false alerts from development and staging projects. You want to ensure that you adhere to the principle of least privilege when providing relevant team members with access to Stackdriver Workspaces. What should you do?

  • A. Choose an existing GCP production project to host the monitoring workspace. Attach the production projects to this workspace. Grant relevant team members read access to the Stackdriver Workspace.
  • B. Create a new GCP monitoring project, and create a Stackdriver Workspace inside it. Attach the production projects to this workspace. Grant relevant team members read access to the Stackdriver Workspace.
  • C. Grant relevant team members the Project Viewer IAM role on all GCP production projects. Create Slackdriver workspaces inside each project.
  • D. Grant relevant team members read access to all GCP production projects. Create Stackdriver workspaces inside each project.

Answer: A


NEW QUESTION # 67
You need to build a CI/CD pipeline for a containerized application in Google Cloud Your development team uses a central Git repository for trunk-based development You want to run all your tests in the pipeline for any new versions of the application to improve the quality What should you do?

  • A. 1. Trigger Cloud Build to build the application container and run unit tests with the container
    2. If unit tests are successful, deploy the application container to a testing environment, and run integration tests
    3. If the integration tests are successful the pipeline deploys the application container to the production environment After that, run acceptance tests
  • B. 1. Install a Git hook to require developers to run unit tests before pushing the code to a central repository If all tests are successful build a container
    2. Trigger Cloud Build to deploy the application container to a testing environment, and run integration tests and acceptance tests
    3. If all tests are successful tag the code as production ready Trigger Cloud Build to build and deploy the application container to the production environment
  • C. 1. Trigger Cloud Build to run unit tests when the code is pushed If all unit tests are successful, build and push the application container to a central registry.
    2. Trigger Cloud Build to deploy the container to a testing environment, and run integration tests and acceptance tests
    3. If all tests are successful the pipeline deploys the application to the production environment and runs smoke tests
  • D. 1. Install a Git hook to require developers to run unit tests before pushing the code to a central repository
    2. Trigger Cloud Build to build the application container Deploy the application container to a testing environment, and run integration tests
    3. If the integration tests are successful deploy the application container to your production environment. and run acceptance tests

Answer: C

Explanation:
The best option for building a CI/CD pipeline for a containerized application in Google Cloud is to trigger Cloud Build to run unit tests when the code is pushed, if all unit tests are successful, build and push the application container to a central registry, trigger Cloud Build to deploy the container to a testing environment, and run integration tests and acceptance tests, and if all tests are successful, the pipeline deploys the application to the production environment and runs smoke tests. This option follows the best practices for CI/CD pipelines, such as running tests at different stages of the pipeline, using a central registry for storing and managing containers, deploying to different environments, and using Cloud Build as a unified tool for building, testing, and deploying.


NEW QUESTION # 68
You have an application running in Google Kubernetes Engine. The application invokes multiple services per request but responds too slowly. You need to identify which downstream service or services are causing the delay. What should you do?

  • A. Create a Dataflow pipeline to analyze service metrics in real time.
  • B. Investigate the Liveness and Readiness probes for each service.
  • C. Analyze VPC flow logs along the path of the request.
  • D. Use a distributed tracing framework such as OpenTelemetry or Stackdriver Trace.

Answer: A


NEW QUESTION # 69
Your company runs applications in Google Kubernetes Engine (GKE) that are deployed following a GitOps methodology.
Application developers frequently create cloud resources to support their applications. You want to give developers the ability to manage infrastructure as code, while ensuring that you follow Google-recommended practices. You need to ensure that infrastructure as code reconciles periodically to avoid configuration drift. What should you do?

  • A. Create a Pod resource with a Terraform docker image to execute terraform plan and terraform apply commands.
  • B. Configure Cloud Build with a Terraform builder to execute plan and apply commands.
  • C. Install and configure Config Connector in Google Kubernetes Engine (GKE).
  • D. Create a Job resource with a Terraform docker image to execute terraforrm plan and terraform apply commands.

Answer: C

Explanation:
The best option to give developers the ability to manage infrastructure as code, while ensuring that you follow Google-recommended practices, is to install and configure Config Connector in Google Kubernetes Engine (GKE).
Config Connector is a Kubernetes add-on that allows you to manage Google Cloud resources through Kubernetes. You can use Config Connector to create, update, and delete Google Cloud resources using Kubernetes manifests. Config Connector also reconciles the state of the Google Cloud resources with the desired state defined in the manifests, ensuring that there is no configuration drift1.
Config Connector follows the GitOps methodology, as it allows you to store your infrastructure configuration in a Git repository, and use tools such as Anthos Config Management or Cloud Source Repositories to sync the configuration to your GKE cluster. This way, you can use Git as the source of truth for your infrastructure, and enable reviewable and version-controlled workflows2.
Config Connector can be installed and configured in GKE using either the Google Cloud Console or the gcloud command-line tool. You need to enable the Config Connector add-on for your GKE cluster, and create a Google Cloud service account with the necessary permissions to manage the Google Cloud resources. You also need to create a Kubernetes namespace for each Google Cloud project that you want to manage with Config Connector3.
By using Config Connector in GKE, you can give developers the ability to manage infrastructure as code, while ensuring that you follow Google-recommended practices. You can also benefit from the features and advantages of Kubernetes, such as declarative configuration, observability, and portability4.
Reference:
1: Overview | Artifact Registry Documentation | Google Cloud
2: Deploy Anthos on GKE with Terraform part 1: GitOps with Config Sync | Google Cloud Blog
3: Installing Config Connector | Config Connector Documentation | Google Cloud
4: Why use Config Connector? | Config Connector Documentation | Google Cloud


NEW QUESTION # 70
You have a CI/CD pipeline that uses Cloud Build to build new Docker images and push them to Docker Hub. You use Git for code versioning. After making a change in the Cloud Build YAML configuration, you notice that no new artifacts are being built by the pipeline. You need to resolve the issue following Site Reliability Engineering practices. What should you do?

  • A. Upload the configuration YAML file to Cloud Storage and use Error Reporting to identify and fix the issue.
  • B. Change the CI pipeline to push the artifacts to Container Registry instead of Docker Hub.
  • C. Disable the CI pipeline and revert to manually building and pushing the artifacts.
  • D. Run a Git compare between the previous and current Cloud Build Configuration files to find and fix the bug.

Answer: B


NEW QUESTION # 71
Your company runs services by using Google Kubernetes Engine (GKE). The GKE clusters in the development environment run applications with verbose logging enabled. Developers view logs by using the kubect1 logs command and do not use Cloud Logging. Applications do not have a uniform logging structure defined. You need to minimize the costs associated with application logging while still collecting GKE operational logs.
What should you do?

  • A. Run the gcloud container clusters update logging=WORKLOAD command for the development cluster.
  • B. Run the gcloud container clusters update --logging-SYSTEM command for the development cluster.
  • C. Run the gcloud logging sinks update _Defau1t --disabled command in the project associated with the development environment.
  • D. Add the severity >= DEBUG resource. type "k83 container" exclusion filter to the Default logging sink in the project associated with the development environment.

Answer: B


NEW QUESTION # 72
Your organization recently adopted a container-based workflow for application development. Your team develops numerous applications that are deployed continuously through an automated build pipeline to the production environment. A recent security audit alerted your team that the code pushed to production could contain vulnerabilities and that the existing tooling around virtual machine (VM) vulnerabilities no longer applies to the containerized environment. You need to ensure the security and patch level of all code running through the pipeline. What should you do?

  • A. Implement static code analysis tooling against the Docker files used to create the containers.
  • B. Set up Container Analysis to scan and report Common Vulnerabilities and Exposures.
  • C. Reconfigure the existing operating system vulnerability software to exist inside the container.
  • D. Configure the containers in the build pipeline to always update themselves before release.

Answer: A

Explanation:
Explanation
https://cloud.google.com/binary-authorization
Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed on Google Kubernetes Engine (GKE) or Cloud Run. With Binary Authorization, you can require images to be signed by trusted authorities during the development process and then enforce signature validation when deploying. By enforcing validation, you can gain tighter control over your container environment by ensuring only verified images are integrated into the build-and-release process.


NEW QUESTION # 73
Your company follows Site Reliability Engineering principles. You are writing a postmortem for an incident, triggered by a software change, that severely affected users. You want to prevent severe incidents from happening in the future. What should you do?

  • A. Design a policy that will require on-call teams to immediately call engineers and management to discuss a plan of action if an incident occurs.
  • B. Follow up with the employees who reviewed the changes and prescribe practices they should follow in the future.
  • C. Ensure that test cases that catch errors of this type are run successfully before new software releases.
  • D. Identify engineers responsible for the incident and escalate to their senior management.

Answer: B


NEW QUESTION # 74
You are the on-call Site Reliability Engineer for a microservice that is deployed to a Google Kubernetes Engine (GKE) Autopilot cluster. Your company runs an online store that publishes order messages to Pub/Sub and a microservice receives these messages and updates stock information in the warehousing system. A sales event caused an increase in orders, and the stock information is not being updated quickly enough. This is causing a large number of orders to be accepted for products that are out of stock You check the metrics for the microservice and compare them to typical levels.

You need to ensure that the warehouse system accurately reflects product inventory at the time orders are placed and minimize the impact on customers What should you do?

  • A. Increase the number of Pod replicas
  • B. Increase the Pod CPU and memory limits
  • C. Add a virtual queue to the online store that allows typical traffic levels
  • D. Decrease the acknowledgment deadline on the subscription

Answer: A

Explanation:
Explanation
The best option for ensuring that the warehouse system accurately reflects product inventory at the time orders are placed and minimizing the impact on customers is to increase the number of Pod replicas. Increasing the number of Pod replicas will increase the scalability and availability of your microservice, which will allow it to handle more Pub/Sub messages and update stock information faster. This way, you can reduce the backlog of undelivered messages and oldest unacknowledged message age, which are causing delays in updating product inventory. You can use Horizontal Pod Autoscaler or Cloud Monitoring metrics-based autoscaling to automatically adjust the number of Pod replicas based on load or custom metrics.


NEW QUESTION # 75
You are writing a postmortem for an incident that severely affected users. You want to prevent similar incidents in the future. Which two of the following sections should you include in the postmortem? (Choose two.)

  • A. A list of employees responsible for causing the incident
  • B. Your opinion of the incident's severity compared to past incidents
  • C. An explanation of the root cause of the incident
  • D. A list of action items to prevent a recurrence of the incident
  • E. Copies of the design documents for all the services impacted by the incident

Answer: A,C


NEW QUESTION # 76
You work for a global organization and run a service with an availability target of 99% with limited engineering resources. For the current calendar month you noticed that the service has 99 5% availability. You must ensure that your service meets the defined availability goals and can react to business changes including the upcoming launch of new features You also need to reduce technical debt while minimizing operational costs You want to follow Google-recommended practices What should you do?

  • A. Define an error budget for your service level availability and minimize the remaining error budget
  • B. Identify, measure and eliminate toil by automating repetitive tasks
  • C. Allocate available engineers to the feature backlog while you ensure that the sen/ice remains within the availability target
  • D. Add N+1 redundancy to your service by adding additional compute resources to the service

Answer: A


NEW QUESTION # 77
You are responsible for creating and modifying the Terraform templates that define your Infrastructure.
Because two new engineers will also be working on the same code, you need to define a process and adopt a tool that will prevent you from overwriting each other's code. You also want to ensure that you capture all updates in the latest version. What should you do?

  • A. * Store your code as text files in Google Drive in a defined folder structure that organizes the files.
    * At the end of each day, confirm that all changes have been captured in the files within the folder structure and create a new .zip archive with a predefined naming convention.
    * Upload the .zip archive to a versioned Cloud Storage bucket and accept it as the latest version.
  • B. * Store your code as text files in Google Drive in a defined folder structure that organizes the files.
    * At the end of each day. confirm that all changes have been captured in the files within the folder structure.
    * Rename the folder structure with a predefined naming convention that increments the version.
  • C. * Store your code in a Git-based version control system.
    * Establish a process that includes code reviews by peers and unit testing to ensure integrity and functionality before integration of code.
    * Establish a process where the fully integrated code in the repository becomes the latest master version.
  • D. * Store your code in a Git-based version control system.
    * Establish a process that allows developers to merge their own changes at the end of each day.
    * Package and upload code lo a versioned Cloud Storage bucket as the latest master version.

Answer: C


NEW QUESTION # 78
You are using Stackdriver to monitor applications hosted on Google Cloud Platform (GCP). You recently deployed a new application, but its logs are not appearing on the Stackdriver dashboard.
You need to troubleshoot the issue. What should you do?

  • A. Confirm that port 25 has been opened in the firewall to allow messages through to Stackdriver.
  • B. Confirm that the application is using the required client library and the service account key has proper permissions.
  • C. Confirm that the Stackdriver agent has been installed in the hosting virtual machine.
  • D. Confirm that your account has the proper permissions to use the Stackdriver dashboard.

Answer: D


NEW QUESTION # 79
......

Pass Google Professional-Cloud-DevOps-Engineer Exam Info and Free Practice Test: https://www.examsreviews.com/Professional-Cloud-DevOps-Engineer-pass4sure-exam-review.html

New 2024 Latest Questions Professional-Cloud-DevOps-Engineer Dumps - Use Updated Google Exam: https://drive.google.com/open?id=1g85AkxtUZ5I7sdR5RBPdse-ZLll-SG9T