Pre-Winter Sale Special - Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: sntaclus

For this question, refer to the EHR Healthcare case study. In the past, configuration errors put public IP addresses on backend servers that should not have been accessible from the Internet. You need to ensure that no one can put external IP addresses on backend Compute Engine instances and that external IP addresses can only be configured on frontend Compute Engine instances. What should you do?

A.

Create an Organizational Policy with a constraint to allow external IP addresses only on the frontend Compute Engine instances.

B.

Revoke the compute.networkAdmin role from all users in the project with front end instances.

C.

Create an Identity and Access Management (IAM) policy that maps the IT staff to the compute.networkAdmin role for the organization.

D.

Create a custom Identity and Access Management (IAM) role named GCE_FRONTEND with the compute.addresses.create permission.

Your company sends all Google Cloud logs to Cloud Logging. Your security team wants to monitor the logs. You want to ensure that the security team can react quickly if an anomaly such as an unwanted firewall change or server breach is detected. You want to follow Google-recommended practices. What should you do?

A.

Schedule a cron job with Cloud Scheduler. The scheduled job queries the logs every minute for the relevant events.

B.

Export logs to BigQuery, and trigger a query in BigQuery to process the log data for the relevant events.

C.

Export logs to a Pub/Sub topic, and trigger Cloud Function with the relevant log events.

D.

Export logs to a Cloud Storage bucket, and trigger Cloud Run with the relevant log events.

You need to reduce the number of unplanned rollbacks of erroneous production deployments in your company ' s web hosting platform. Improvement to the QA/Test processes accomplished an 80% reduction. Which additional two approaches can you take to further reduce the rollbacks? Choose 2 answers

A.

Introduce a green-blue deployment model.

B.

Replace the QA environment with canary releases.

C.

Fragment the monolithic platform into microservices.

D.

Reduce the platform ' s dependency on relational database systems.

E.

Replace the platform ' s relational database systems with a NoSQL database.

Your company has successfully migrated to the cloud and wants to analyze their data stream to optimize operations. They do not have any existing code for this analysis, so they are exploring all their options. These options include a mix of batch and stream processing, as they are running some hourly jobs and live-processing some data as it comes in. Which technology should they use for this?

A.

Google Cloud Dataproc

B.

Google Cloud Dataflow

C.

Google Container Engine with Bigtable

D.

Google Compute Engine with Google BigQuery

Your application needs to process credit card transactions. You want the smallest scope of Payment Card Industry (PCI) compliance without compromising the ability to analyze transactional data and trends relating to which payment methods are used. How should you design your architecture?

A.

Create a tokenizer service and store only tokenized data.

B.

Create separate projects that only process credit card data.

C.

Create separate subnetworks and isolate the components that process credit card data.

D.

Streamline the audit discovery phase by labeling all of the virtual machines (VMs) that process PCI data.

E.

Enable Logging export to Google BigQuery and use ACLs and views to scope the data shared with the auditor.

Your organization has a significant amount of log data stored in Cloud Logging. The data engineering team is accustomed to using SQL for analysis and wants the ability to create insightful dashboards for visualizing log trends and patterns. You want to follow the recommendations of the Google Cloud Well-Architected Framework to provide a solution for the data engineering team What should you do?

A.

Enable log analytics and run queries in the linked log dataset in BigQuery. Visualize the data with Looker Studio dashboards.

B.

Create a log sink, and export the data to a storage bucket. Create an external table in BigQuery for the data in the bucket Run queries and visualize the data with

Cloud Monitoring dashboards

C.

Enable log analytics and run queries in Cloud Monitoring Visualize the data using Vertex Al workbench.

D.

Create a log sink, and export the data to BigQuery using Pub/Sub. Run queries and visualize the data with Cloud Monitoring dashboards.

Your company has a Google Cloud project that uses BlgQuery for data warehousing There are some tables that contain personally identifiable information (PI!) Only the compliance team may access the PH. The other information in the tables must be available to the data science team. You want to minimize cost and the time it takes to assign appropriate access to the tables What should you do?

A.

1 From the dataset where you have the source data, create views of tables that you want to share, excluding Pll

2 Assign an appropriate project-level IAM role to the members of the data science team

3 Assign access controls to the dataset that contains the view

B.

1 From the dataset where you have the source data, create materialized views of tables that you want to share excluding Pll

2 Assign an appropriate project-level IAM role to the members of the data science team 3. Assign access controls to the dataset that contains the view.

C.

1 Create a dataset for the data science team

2 Create views of tables that you want to share excluding Pll

3 Assign an appropriate project-level IAM role to the members of the data science team

4 Assign access controls to the dataset that contains the view

5 Authorize the view to access the source dataset

D.

1. Create a dataset for the data science team.

2. Create materialized views of tables that you want to share, excluding Pll

3. Assign an appropriate project-level IAM role to the members of the data science team

4 Assign access controls to the dataset that contains the view

5 Authorize the view to access the source dataset

For this question, refer to the TerramEarth case study. A new architecture that writes all incoming data to

BigQuery has been introduced. You notice that the data is dirty, and want to ensure data quality on an

automated daily basis while managing cost.

What should you do?

A.

Set up a streaming Cloud Dataflow job, receiving data by the ingestion process. Clean the data in a Cloud Dataflow pipeline.

B.

Create a Cloud Function that reads data from BigQuery and cleans it. Trigger it. Trigger the Cloud Function from a Compute Engine instance.

C.

Create a SQL statement on the data in BigQuery, and save it as a view. Run the view daily, and save the result to a new table.

D.

Use Cloud Dataprep and configure the BigQuery tables as the source. Schedule a daily job to clean the data.

Your company runs a critical, revenue-generating ecommerce application that is served by a regional managed instance group (MIG) behind an external HTTP(S) Load Balancer. The operations team is currently overwhelmed with low-priority notifications. Your team ' s service level objective (SLO) is to maintain 99.9% availability. You want to minimize noise from non-critical events and ensure that the team is only notified of issues that are actionable and threaten the SLO. What should you do?

A.

Focus on cause-based alerts, creating alerting policies with thresholds for the Compute Engine instances, including CPU utilization, memory usage, disk I/O, and network traffic.

B.

Configure alerts based on predictive metrics. Use the instance count of the MIG as the primary metric to trigger an alert.

C.

Implement an error budget policy based on the availability of the SLO. Create a " page " alert that triggers only when the rate of burn of the error budget predicts a full exhaustion within the next 24 hours.

D.

Create log-based alerts for only the WARN and ERROR log entries generated by the application to ensure that no potential issue is missed.

You have broken down a legacy monolithic application into a few containerized RESTful microservices. You want to run those microservices on Cloud Run. You also want to make sure the services are highly available with low latency to your customers. What should you do?

A.

Deploy Cloud Run services to multiple availability zones. Create Cloud Endpoints that point to the services. Create a global HTIP(S) Load Balancing instance and attach the Cloud Endpoints to its backend.

B.

Deploy Cloud Run services to multiple regions Create serverless network endpoint groups pointing to the services. Add the serverless NE Gs to a backend service that is used by a global HTIP(S) Load Balancing instance.

C.

Cloud Run services to multiple regions. In Cloud DNS, create a latency-based DNS name that points to the services.

D.

Deploy Cloud Run services to multiple availability zones. Create a TCP/IP global load balancer. Add the Cloud Run Endpoints to its backend service.