
Real Professional-Cloud-DevOps-Engineer are Uploaded by Prep4away provide 2021 Latest Professional-Cloud-DevOps-Engineer Practice Tests Dumps.
All Professional-Cloud-DevOps-Engineer Dumps and Google Cloud Certified - Professional Cloud DevOps Engineer Exam Training Courses Help candidates to study and pass the Google Cloud Certified - Professional Cloud DevOps Engineer Exam Exams hassle-free!
NEW QUESTION 10
You deploy a new release of an internal application during a weekend maintenance window when there is minimal user tragic. After the window ends, you learn that one of the new features isn't working as expected in the production environment. After an extended outage, you roll back the new release and deploy a fix. You want to modify your release process to reduce the mean time to recovery so you can avoid extended outages in the future. What should you do? (Choose two.)
- A. Before merging new code, require 2 different peers to review the code changes.
- B. Configure a CI server. Add a suite of unit tests to your code and have your CI server run them on commit and verify any changes.
- C. Adopt the blue/green deployment strategy when releasing new code via a CD server.
- D. Require developers to run automated integration tests on their local development environments before release.
- E. Integrate a code linting tool to validate coding standards before any code is accepted into the repository.
Answer: A,E
NEW QUESTION 11
Your company follows Site Reliability Engineering practices. You are the person in charge of Communications for a large, ongoing incident affecting your customer-facing applications. There is still no estimated time for a resolution of the outage. You are receiving emails from internal stakeholders who want updates on the outage, as well as emails from customers who want to know what is happening. You want to efficiently provide updates to everyone affected by the outage. What should you do?
- A. Provide all internal stakeholder emails to the Incident Commander, and allow them to manage internal communications. Focus on providing responses directly to customers.
- B. Provide periodic updates to all stakeholders in a timely manner. Commit to a "next update" time in all communications.
- C. Delegate the responding to internal stakeholder emails to another member of the Incident Response Team. Focus on providing responses directly to customers.
- D. Focus on responding to internal stakeholders at least every 30 minutes. Commit to "next update" times.
Answer: C
NEW QUESTION 12
Your application services run in Google Kubernetes Engine (GKE). You want to make sure that only images from your centrally-managed Google Container Registry (GCR) image registry in the altostrat-images project can be deployed to the cluster while minimizing development time. What should you do?
- A. Use a Binary Authorization policy that includes the whitelist name pattern gcr.io/altostrat-images/.
- B. Add logic to the deployment pipeline to check that all manifests contain only images from gcr.io/altostrat- images.
- C. Add a tag to each image in gcr.io/altostrat-images and check that this tag is present when the image is deployed.
- D. Create a custom builder for Cloud Build that will only push images to gcr.io/altostrat-images.
Answer: C
NEW QUESTION 13
You support an application deployed on Compute Engine. The application connects to a Cloud SQL instance to store and retrieve dat a. After an update to the application, users report errors showing database timeout messages. The number of concurrent active users remained stable. You need to find the most probable cause of the database timeout. What should you do?
- A. Check the serial port logs of the Compute Engine instance.
- B. Use Stackdriver Profiler to visualize the resources utilization throughout the application.
- C. Use Cloud Security Scanner to see whether your Cloud SQL is under a Distributed Denial of Service (DDoS) attack.
- D. Determine whether there is an increased number of connections to the Cloud SQL instance.
Answer: A
NEW QUESTION 14
Your company experiences bugs, outages, and slowness in its production systems. Developers use the production environment for new feature development and bug fixes. Configuration and experiments are done in the production environment, causing outages for users. Testers use the production environment for load testing, which often slows the production systems. You need to redesign the environment to reduce the number of bugs and outages in production and to enable testers to toad test new features. What should you do?
- A. Secure the production environment to ensure that developers can't change it and set up one controlled update per year.
- B. Create a development environment with smaller server capacity and give access only to developers and testers.
- C. Create an automated testing script in production to detect failures as soon as they occur.
- D. Create a development environment for writing code and a test environment for configurations, experiments, and load testing.
Answer: C
NEW QUESTION 15
Your team is designing a new application for deployment into Google Kubernetes Engine (GKE). You need to set up monitoring to collect and aggregate various application-level metrics in a centralized location. You want to use Google Cloud Platform services while minimizing the amount of work required to set up monitoring. What should you do?
- A. Install the Cloud Pub/Sub client libraries, push various metrics from the application to various topics, and then observe the aggregated metrics in Stackdriver.
- B. Install the OpenTelemetry client libraries in the application, configure Stackdriver as the export destination for the metrics, and then observe the application's metrics in Stackdriver.
- C. Publish various metrics from the application directly to the Slackdriver Monitoring API, and then observe these custom metrics in Stackdriver.
- D. Emit all metrics in the form of application-specific log messages, pass these messages from the containers to the Stackdriver logging collector, and then observe metrics in Stackdriver.
Answer: B
NEW QUESTION 16
You need to deploy a new service to production. The service needs to automatically scale using a Managed Instance Group (MIG) and should be deployed over multiple regions. The service needs a large number of resources for each instance and you need to plan for capacity. What should you do?
- A. Validate that the resource requirements are within the available quota limits of each region.
- B. Monitor results of Stackdriver Trace to determine the required amount of resources.
- C. Deploy the service in one region and use a global load balancer to route traffic to this region.
- D. Use the n1-highcpu-96 machine type in the configuration of the MIG.
Answer: C
NEW QUESTION 17
You created a Stackdriver chart for CPU utilization in a dashboard within your workspace project. You want to share the chart with your Site Reliability Engineering (SRE) team only. You want to ensure you follow the principle of least privilege. What should you do?
- A. Click "Share chart by URL" and provide the URL to the SRE team. Assign the SRE team the Dashboard Viewer IAM role in the workspace project.
- B. Share the workspace Project ID with the SRE team. Assign the SRE team the Monitoring Viewer IAM role in the workspace project.
- C. Click "Share chart by URL" and provide the URL to the SRE team. Assign the SRE team the Monitoring Viewer IAM role in the workspace project.
- D. Share the workspace Project ID with the SRE team. Assign the SRE team the Dashboard Viewer IAM role in the workspace project.
Answer: D
NEW QUESTION 18
You need to run a business-critical workload on a fixed set of Compute Engine instances for several months. The workload is stable with the exact amount of resources allocated to it. You want to lower the costs for this workload without any performance implications. What should you do?
- A. Purchase Committed Use Discounts.
- B. Create an Unmanaged Instance Group for the instances used to run the workload.
- C. Migrate the instances to a Managed Instance Group.
- D. Convert the instances to preemptible virtual machines.
Answer: D
NEW QUESTION 19
Your application artifacts are being built and deployed via a CI/CD pipeline. You want the CI/CD pipeline to securely access application secrets. You also want to more easily rotate secrets in case of a security breach. What should you do?
- A. Store secrets in a separate configuration file on Git. Provide select developers with access to the configuration file.
- B. Encrypt the secrets and store them in the source code repository. Store a decryption key in a separate repository and grant your pipeline access to it
- C. Store secrets in Cloud Storage encrypted with a key from Cloud KMS. Provide the CI/CD pipeline with access to Cloud KMS via IAM.
- D. Prompt developers for secrets at build time. Instruct developers to not store secrets at rest.
Answer: A
NEW QUESTION 20
You manage an application that is writing logs to Stackdriver Logging. You need to give some team members the ability to export logs. What should you do?
- A. Create and grant a custom IAM role with the permissions logging.sinks.list and logging.sink.get.
- B. Grant the team members the IAM role of logging.configWriter on Cloud IAM.
- C. Create an Organizational Policy in Cloud IAM to allow only these members to create log exports.
- D. Configure Access Context Manager to allow only these members to export logs.
Answer: B
Explanation:
Explanation/Reference: https://cloud.google.com/logging/docs/access-control
NEW QUESTION 21
You have a CI/CD pipeline that uses Cloud Build to build new Docker images and push them to Docker Hub.
You use Git for code versioning. After making a change in the Cloud Build YAML configuration, you notice that no new artifacts are being built by the pipeline. You need to resolve the issue following Site Reliability Engineering practices. What should you do?
- A. Disable the CI pipeline and revert to manually building and pushing the artifacts.
- B. Run a Git compare between the previous and current Cloud Build Configuration files to find and fix the bug.
- C. Change the CI pipeline to push the artifacts is Container Registry instead of Docker Hub.
- D. Upload the configuration YAML file to Cloud Storage and use Error Reporting to identify and fix the issue.
Answer: C
NEW QUESTION 22
You support an application that stores product information in cached memory. For every cache miss, an entry is logged in Stackdriver Logging. You want to visualize how often a cache miss happens over time. What should you do?
- A. Configure BigOuery as a sink for Stackdriver Logging. Create a scheduled query to filter the cache miss logs and write them to a separate table
- B. Link Stackdriver Logging as a source in Google Data Studio. Filler (he logs on the cache misses.
- C. Configure Stackdriver Profiler to identify and visualize when the cache misses occur based on the logs.
- D. Create a logs-based metric in Stackdriver Logging and a dashboard for that metric in Stackdriver Monitoring.
Answer: D
NEW QUESTION 23
You are part of an organization that follows SRE practices and principles. You are taking over the management of a new service from the Development Team, and you conduct a Production Readiness Review (PRR). After the PRR analysis phase, you determine that the service cannot currently meet its Service Level Objectives (SLOs). You want to ensure that the service can meet its SLOs in production. What should you do next?
- A. djust the SLO targets to be achievable by the service so you can bring it into production.
- B. Notify the development team that they will have to provide production support for the service.
- C. Identify recommended reliability improvements to the service to be completed before handover.
- D. Bring the service into production with no SLOs and build them when you have collected operational data.
Answer: C
NEW QUESTION 24
Your team is designing a new application for deployment into Google Kubernetes Engine (GKE). You need to set up monitoring to collect and aggregate various application-level metrics in a centralized location. You want to use Google Cloud Platform services while minimizing the amount of work required to set up monitoring.
What should you do?
- A. Install the Cloud Pub/Sub client libraries, push various metrics from the application to various topics, and then observe the aggregated metrics in Stackdriver.
- B. Publish various metrics from the application directly to the Stackdriver Monitoring API, and then observe these custom metrics in Stackdriver.
- C. Install the OpenTelemetry client libraries in the application, configure Stackdriver as the export destination for the metrics, and then observe the application's metrics in Stackdriver.
- D. Emit all metrics in the form of application-specific log messages, pass these messages from the containers to the Stackdriver logging collector, and then observe metrics in Stackdriver.
Answer: C
NEW QUESTION 25
Your product is currently deployed in three Google Cloud Platform (GCP) zones with your users divided between the zones. You can fail over from one zone to another, but it causes a 10-minute service disruption for the affected users. You typically experience a database failure once per quarter and can detect it within five minutes. You are cataloging the reliability risks of a new real-time chat feature for your product. You catalog the following information for each risk:
* Mean Time to Detect (MUD} in minutes
* Mean Time to Repair (MTTR) in minutes
* Mean Time Between Failure (MTBF) in days
* User Impact Percentage
The chat feature requires a new database system that takes twice as long to successfully fail over between zones. You want to account for the risk of the new database failing in one zone. What would be the values for the risk of database failover with the new system?
- A. MTTD: 5
MTTR: 10
MTBF: 90
Impact: 33% - B. MTTD:5
MTTR: 20
MTBF: 90
Impact: 33% - C. MTTD:5
MTTR: 20
MTBF: 90
Impact: 50% - D. MTTD:5
MTTR: 10
MTBF: 90
Impact 50%
Answer: A
NEW QUESTION 26
Your application artifacts are being built and deployed via a CI/CD pipeline. You want the CI/CD pipeline to securely access application secrets. You also want to more easily rotate secrets in case of a security breach.
What should you do?
- A. Store secrets in Cloud Storage encrypted with a key from Cloud KMS. Provide the CI/CD pipeline with access to Cloud KMS via IAM.
- B. Encrypt the secrets and store them in the source code repository. Store a decryption key in a separate repository and grant your pipeline access to it.
- C. Store secrets in a separate configuration file on Git. Provide select developers with access to the configuration file.
- D. Prompt developers for secrets at build time. Instruct developers to not store secrets at rest.
Answer: A
NEW QUESTION 27
Your team uses Cloud Build for all CI/CO pipelines. You want to use the kubectl builder for Cloud Build to deploy new images to Google Kubernetes Engine (GKE). You need to authenticate to GKE while minimizing development effort. What should you do?
- A. Create a new service account with the Container Developer role and use it to run Cloud Build.
- B. Create a separate step in Cloud Build to retrieve service account credentials and pass these to kubectl.
- C. Assign the Container Developer role to the Cloud Build service account.
- D. Specify the Container Developer role for Cloud Build in the cloudbuild.yaml file.
Answer: C
NEW QUESTION 28
You are running a real-time gaming application on Compute Engine that has a production and testing environment. Each environment has their own Virtual Private Cloud (VPC) network. The application frontend and backend servers are located on different subnets in the environment's VPC. You suspect there is a malicious process communicating intermittently in your production frontend servers. You want to ensure that network traffic is captured for analysis. What should you do?
- A. Enable VPC Flow Logs on the testing and production VPC network frontend and backend subnets with a volume scale of 0.5. Apply changes in testing before production.
- B. Enable VPC Flow Logs on the production VPC network frontend and backend subnets only with a sample volume scale of 0.5.
- C. Enable VPC Flow Logs on the production VPC network frontend and backend subnets only with a sample volume scale of 1.0.
- D. Enable VPC Flow Logs on the testing and production VPC network frontend and backend subnets with a volume scale of 1.0. Apply changes in testing before production.
Answer: C
NEW QUESTION 29
You need to deploy a new service to production. The service needs to automatically scale using a Managed Instance Group (MIG) and should be deployed over multiple regions. The service needs a large number of resources for each instance and you need to plan for capacity. What should you do?
- A. Validate that the resource requirements are within the available quota limits of each region.
- B. Monitor results of Stackdriver Trace to determine the required amount of resources.
- C. Use the n1-highcpu-96 machine type in the configuration of the MIG.
- D. Deploy the service in one region and use a global load balancer to route traffic to this region.
Answer: C
NEW QUESTION 30
......
Valid Way To Pass Google's Professional-Cloud-DevOps-Engineer Exam with : https://www.prep4away.com/Google-certification/braindumps.Professional-Cloud-DevOps-Engineer.ete.file.html
Free Test Engine For Google Cloud Certified - Professional Cloud DevOps Engineer Exam Certification Exams: https://drive.google.com/open?id=1xnv6xWZuXUOFtORRUV8ly3KX37dMI9-A