Guaranteed High Marks with Updated & Real Professional-Cloud-Architect Dumps pdf Free Updates
PASS RATE Google Cloud Certified Professional-Cloud-Architect Certified Exam DUMP
NEW QUESTION # 15
For this question, refer to the Dress4Win case study. You are responsible for the security of data stored in Cloud Storage for your company, Dress4Win. You have already created a set of Google Groups and assigned the appropriate users to those groups. You should use Google best practices and implement the simplest design to meet the requirements.
Considering Dress4Win's business and technical requirements, what should you do?
- A. Assign predefined IAM roles to the Google Groups you created in order to enforce security requirements. Utilize Google's default encryption at rest when storing files in Cloud Storage.
- B. Assign predefined IAM roles to the Google Groups you created in order to enforce security requirements. Ensure that the default Cloud KMS key is set before storing files in Cloud Storage.
- C. Assign custom IAM roles to the Google Groups you created in order to enforce security requirements.
Encrypt data with a customer-supplied encryption key when storing files in Cloud Storage. - D. Assign custom IAM roles to the Google Groups you created in order to enforce security requirements.
Enable default storage encryption before storing files in Cloud Storage.
Answer: A
Explanation:
Explanation/Reference:
Mix Questions
Question Set 1
NEW QUESTION # 16
You are monitoring Google Kubernetes Engine (GKE) clusters in a Cloud Monitoring workspace. As a Site Reliability Engineer (SRE), you need to triage incidents quickly. What should you do?
- A. Navigate the predefined dashboards in the Cloud Monitoring workspace, and then add metrics and create alert policies.
- B. Write a shell script that gathers metrics from GKE nodes, publish these metrics to a Pub/Sub topic, export the data to BigQuery, and make a Data Studio dashboard.
- C. Navigate the predefined dashboards in the Cloud Monitoring workspace, create custom metrics, and install alerting software on a Compute Engine instance.
- D. Create a custom dashboard in the Cloud Monitoring workspace for each incident, and then add metrics and create alert policies.
Answer: D
Explanation:
Reference: https://cloud.google.com/monitoring/charts/dashboards
NEW QUESTION # 17
The current Dress4win system architecture has high latency to some customers because it is located in one data center.
As of a future evaluation and optimizing for performance in the cloud, Dresss4win wants to distribute it's system architecture to multiple locations when Google cloud platform.
Which approach should they use?
- A. Use regional managed instance groups and a global load balancer to increase performance because the regional managed instance group can grow instances in each region separately based on traffic.
- B. Use regional managed instance groups and a global load balancer to increase reliability by providing automatic failover between zones in different regions.
- C. Use a global load balancer with a set of virtual machines that forward the requests to a closer group of virtual machines managed by your operations team.
- D. Use a global load balancer with a set of virtual machines that forward the requests to a closer group of virtual machines as part of a separate managed instance groups.
Answer: A
Explanation:
Reference:
NEW QUESTION # 18
Your company and one of its partners each nave a Google Cloud protect in separate organizations. Your company s protect (prj-a) runs in Virtual Private Cloud (vpc-a). The partner's project (prj-b) runs in vpc-b. There are two instances running on vpc-a and one instance running on vpc-b Subnets denned in both VPCs are not overlapping. You need to ensure that all instances communicate with each other via internal IPs minimizing latency and maximizing throughput. What should you do?
- A. Set up a VPN between vpc-a and vpc-b using Cloud VPN
- B. Configure IAP TCP forwarding on the instance in vpc b and then launch the following gcloud command from one of the instance in vpc-gcloud
- C. Set up a network peering between vpc-a and vpc-b
Answer: B
Explanation:
1. Create an additional instance in vpc-a
2. Create an additional instance n vpc-b
3. Instal OpenVPN in newly created instances
4. Configure a VPN tunnel between vpc-a and vpc-b with the help of OpenVPN
NEW QUESTION # 19
Your company has announced that they will be outsourcing operations functions. You want to allow developers to easily stage new versions of a cloud-based application in the production environment and allow the outsourced operations team to autonomously promote staged versions to production. You want to minimize the operational overhead of the solution. Which Google Cloud product should you migrate to?
- A. Google Kubernetes Engine
- B. GKE On-Prem
- C. App Engine
- D. Compute Engine
Answer: A
NEW QUESTION # 20
For this question, refer to the JencoMart case study.
The migration of JencoMart's application to Google Cloud Platform (GCP) is progressing too slowly. The infrastructure is shown in the diagram. You want to maximize throughput. What are three potential bottlenecks? (Choose 3 answers.)
- A. A separate storage layer outside the VMs, which is not suited for this task
- B. A copy command that is not suited to operate over long distances
- C. Fewer virtual machines (VMs) in GCP than on-premises machines
- D. Complicated internet connectivity between the on-premises infrastructure and GCP
- E. A single VPN tunnel, which limits throughput
- F. A tier of Google Cloud Storage that is not suited for this task
Answer: A,D,E
NEW QUESTION # 21
The operations manager asks you for a list of recommended practices that she should consider when migrating a J2EE application to the cloud. Which three practices should you recommend? Choose 3 answers
- A. Port the application code to run on Google App Engine.
- B. Migrate from MySQL to a managed NoSQL database like Google Cloud Datastore or Bigtable.
- C. Deploy a continuous integration tool with automated testing in a staging environment.
- D. Integrate Cloud Dataflow into the application to capture real-time metrics.
- E. Select an automation framework to reliably provision the cloud infrastructure.
- F. Instrument the application with a monitoring tool like Stackdriver Debugger.
Answer: A,B,C
Explanation:
References: https://cloud.google.com/appengine/docs/standard/java/tools/uploadinganapp
https://cloud.google.com/appengine/docs/standard/java/building-app/cloud-sql
NEW QUESTION # 22
For this question, refer to the TerramEarth case study.
TerramEarth's 20 million vehicles are scattered around the world. Based on the vehicle's location its telemetry data is stored in a Google Cloud Storage (GCS) regional bucket (US. Europe, or Asia). The CTO has asked you to run a report on the raw telemetry data to determine why vehicles are breaking down after 100 K miles.
You want to run this job on all the data. What is the most cost-effective way to run this job?
- A. Launch a cluster in each region to preprocess and compress the raw data, then move the data into a multi region bucket and use a Dataproc cluster to finish the job.
- B. Launch a cluster in each region to preprocess and compress the raw data, then move the data into a region bucket and use a Cloud Dataproc cluster to finish the jo
- C. Move all the data into 1 region, then launch a Google Cloud Dataproc cluster to run the job.
- D. Move all the data into 1 zone, then launch a Cloud Dataproc cluster to run the job.
Answer: B
Explanation:
Explanation
Storageguarantees 2 replicates which are geo diverse (100 miles apart) which can get better remote latency and availability.
More importantly, is that multiregional heavily leverages Edge caching and CDNs to provide the content to the end users.
All this redundancy and caching means that Multiregional comes with overhead to sync and ensure consistency between geo-diverse areas. As such, it's much better for write-once-read-many scenarios. This means frequently accessed (e.g. "hot" objects) around the world, such as website content, streaming videos, gaming or mobile applications.
References:
https://medium.com/google-cloud/google-cloud-storage-what-bucket-class-for-the-best-performance-5c847ac8f9
NEW QUESTION # 23
You have a Python web application with many dependencies that requires 0.1 CPU cores and 128 MB of memory to operate in production. You want to monitor and maximize machine utilization. You also want to reliably deploy new versions of the application. Which set of steps should you take?
- A. Perform the following:
1. Create a managed instance group with n1-standard-1 type machines.
2. Build a Compute Engine image from the production branch that contains all of the dependencies and automatically starts the Python app.
3. Rebuild the Compute Engine image, and update the instance template to deploy new production releases. - B. Perform the following:
1. Create a GKE cluster with n1-standard-4 type machines.
2. Build a Docker image from the master branch with all of the dependencies, and tag it with 'latest'.
3. Create a Kubernetes Deployment in the default namespace with the imagePullPolicy set to 'Always'.
Restart the pods to automatically deploy new production releases. - C. Perform the following:
1. Create a managed instance group with f1-micro type machines.
2. Use a startup script to clone the repository, check out the production branch, install the dependencies, and start the Python app.
3. Restart the instances to automatically deploy new production releases. - D. Perform the following:
1. Create a Google Kubernetes Engine (GKE) cluster with n1-standard-1 type machines.
2. Build a Docker image from the production branch with all of the dependencies, and tag it with the version number.
3. Create a Kubernetes Deployment with the imagePullPolicy set to 'IfNotPresent' in the staging namespace, and then promote it to the production namespace after testing.
Answer: A
NEW QUESTION # 24
Your web application uses Google Kubernetes Engine to manage several workloads. One workload requires a consistent set of hostnames even after pod scaling and relaunches.
Which feature of Kubernetes should you use to accomplish this?
- A. StatefulSets
- B. Container environment variables
- C. Role-based access control
- D. Persistent Volumes
Answer: A
Explanation:
Explanation
https://kubernetes.io/docs/tutorials/stateful-application/basic-stateful-set/
NEW QUESTION # 25
You write a Python script to connect to Google BigQuery from a Google Compute Engine virtual machine.
The script is printing errors that it cannot connect to BigQuery. What should you do to fix the script?
- A. Install the latest BigQuery API client library for Python
- B. Run your script on a new virtual machine with the BigQuery access scope enabled
- C. Install the bq component for gccloud with the command gcloud components install bq.
- D. Create a new service account with BigQuery access and execute your script with that user
Answer: B
Explanation:
Explanation
https://cloud.google.com/compute/docs/access/service-accounts
NEW QUESTION # 26
One of the developers on your team deployed their application in Google Container Engine with the Dockerfile below. They report that their application deployments are taking too long.
You want to optimize this Dockerfile for faster deployment times without adversely affecting the app's functionality.
Which two actions should you take? Choose 2 answers.
- A. Copy the source after the package dependencies (Python and pip) are installed.
- B. Use a slimmed-down base image like Alpine linux.
- C. Remove dependencies from requirements.txt.
- D. Remove Python after running pip.
- E. Use larger machine types for your Google Container Engine node pools.
Answer: A,B
Explanation:
The speed of deployment can be changed by limiting the size of the uploaded app, limiting the complexity of the build necessary in the Dockerfile, if present, and by ensuring a fast and reliable internet connection.
Note: Alpine Linux is built around musl libc and busybox. This makes it smaller and more resource efficient than traditional GNU/Linux distributions. A container requires no more than 8 MB and a minimal installation to disk requires around 130 MB of storage. Not only do you get a fully-fledged Linux environment but a large selection of packages from the repository.
References:
https://groups.google.com/forum/#!topic/google-appengine/hZMEkmmObDU
https://www.alpinelinux.org/about/
NEW QUESTION # 27
Your customer is moving an existing corporate application to Google Cloud Platform from an on-premises data center. The business owners require minimal user disruption. There are strict security team requirements for storing passwords. What authentication strategy should they use?
- A. Use G Suite Password Sync to replicate passwords into Google.
- B. Ask users to set their Google password to match their corporate password.
- C. Federate authentication via SAML 2.0 to the existing Identity Provider.
- D. Provision users in Google using the Google Cloud Directory Sync tool.
Answer: D
Explanation:
Explanation
https://support.google.com/a/answer/2611859?hl=en
Provision users to Google's directory
The global Directory is available to both Cloud Platform and G Suite resources and can be provisioned by a number of means. Provisioned users can take advantage of rich authentication features including single sign-on (SSO), OAuth, and two-factor verification.
You can provision users automatically using one of the following tools and services:
Google Cloud Directory Sync (GCDS)
Google Admin SDK
A third-party connector
GCDS is a connector that can provision users and groups on your behalf for both Cloud Platform and G Suite.
Using GCDS, you can automate the addition, modification, and deletion of users, groups, and non-employee contacts. You can synchronize the data from your LDAP directory server to your Cloud Platform domain by using LDAP queries. This synchronization is one-way: the data in your LDAP directory server is never modified.
References:
https://cloud.google.com/docs/enterprise/best-practices-for-enterprise-organizations#authentication-and-identity
NEW QUESTION # 28
You are designing a mobile chat application. You want to ensure people cannot spoof chat messages, by providing a message were sent by a specific user.
What should you do
- A. Encrypt the message client side using block-based encryption with a shared key.
- B. Use a trusted certificate authority to enable SSL connectivity between the client application and the server.
- C. Use public key infrastructure (PKI) to encrypt the message client side using the originating user's private key.
- D. Tag messages client side with the originating user identifier and the destination user.
Answer: B
Explanation:
Explanation
Encrypting each block and tagging each message at the client side is an overhead on the application. Best method which has been adopted since years is contacting the SSL provider and use the public certificate to encrypt the traffic between client and the server.
NEW QUESTION # 29
You need to develop procedures to verify resilience of disaster recovery for remote recovery using GCP. Your production environment is hosted on-premises. You need to establish a secure, redundant connection between your on premises network and the GCP network.
What should you do?
- A. Verify that Dedicated Interconnect can replicate files to GCP. Verify that direct peering can establish a secure connection between your networks if Dedicated Interconnect fails.
- B. Verify that the Transfer Appliance can replicate files to GCP. Verify that Cloud VPN can establish a secure connection between your networks if the Transfer Appliance fails.
- C. Verify that Dedicated Interconnect can replicate files to GCP. Verify that Cloud VPN can establish a secure connection between your networks if Dedicated Interconnect fails.
- D. Verify that the Transfer Appliance can replicate files to GCP. Verify that direct peering can establish a secure connection between your networks if the Transfer Appliance fails.
Answer: A
NEW QUESTION # 30
Your company just finished a rapid lift and shift to Google Compute Engine for your compute needs. You have another 9 months to design and deploy a more cloud-native solution. Specifically, you want a system that is no-ops and auto-scaling. Which two compute products should you choose? Choose 2 answers
- A. Google App Engine Standard Environment
- B. Compute Engine with custom instance types
- C. Google Container Engine with containers
- D. Compute Engine with containers
- E. Compute Engine with managed instance groups
Answer: B,D
NEW QUESTION # 31
Your company wants to track whether someone is present in a meeting room reserved for a scheduled meeting. There are 1000 meeting rooms across 5 offices on 3 continents. Each room is equipped with a motion sensor that reports its status every second. The data from the motion detector includes only a sensor ID and several different discrete items of information. Analysts will use this data, together with information about account owners and office locations. Which database type should you use?
- A. NoSQL
- B. Relational
- C. Flat file
- D. Blobstore
Answer: A
NEW QUESTION # 32
......
Best Professional-Cloud-Architect Exam Preparation Material with New Dumps Questions: https://examtorrent.testkingpdf.com/Professional-Cloud-Architect-testking-pdf-torrent.html

