View Full Google Cloud Digital Leader Exam Dumps and Practice Test Dumps.
Question 361
Which service provides a fully managed, serverless document database built for web and mobile applications?
- Cloud SQL
- Firestore
- Cloud Spanner
- Cloud Bigtable
Correct Answer: 2
Explanation
Firestore is a flexible, scalable, fully managed NoSQL document database designed to store and sync data for serverless web and mobile applications. It organizes data in JSON-like documents grouped within collections, providing powerful querying capabilities and seamless offline synchronization for client devices. Firestore automatically scales up or down based on application demand while ensuring high availability through multi-region replication. By eliminating database server management and infrastructure provisioning tasks, it allows engineering teams to build responsive, real-time applications rapidly.
Question 362
Which fully managed data warehouse allows organizations to run ultra-fast SQL queries across petabytes of data?
- Cloud SQL
- BigQuery
- Cloud Spanner
- Cloud Bigtable
Correct Answer: 2
Explanation
BigQuery is Google Cloud’s fully managed, serverless enterprise data warehouse designed to enable lightning-fast SQL queries over massive petabyte-scale datasets. It decouples storage from compute resources, allowing organizations to scale processing power independently without managing infrastructure. BigQuery features built-in machine learning capabilities, real-time data streaming ingestion, and seamless integration with popular business intelligence reporting tools. This empowers data analysts and business leaders to uncover actionable insights instantly and make informed decisions without administrative bottlenecks.
Question 363
Which service provides secure, highly available managed Kubernetes clusters using standard APIs?
- Compute Engine
- Cloud Run
- Google Kubernetes Engine
- App Engine Standard
Correct Answer: 3
Explanation
Google Kubernetes Engine provides a managed, production-ready environment for deploying, managing, and scaling containerized applications using Kubernetes APIs. GKE automates cluster provisioning, node scaling, health monitoring, and security patching, substantially reducing operational overhead. Teams can choose between Standard mode for granular node control or Autopilot mode for a completely hands-off experience where Google manages the underlying infrastructure. GKE integrates natively with Google Cloud networking and security services, serving as a robust foundation for modern microservices architectures.
Question 364
Which interactive browser-based administrative tool provides pre-installed CLI utilities for managing Google Cloud resources?
- Cloud Shell
- Terminal Console
- Local PowerShell
- SSH Client
Correct Answer: 1
Explanation
Cloud Shell is a browser-based interactive administrative environment that gives developers and system administrators instant command-line access to Google Cloud resources from anywhere. It comes pre-installed with essential tools including the Google Cloud CLI, Terraform, and Docker, removing the need for local toolchain installations. Additionally, Cloud Shell includes five gigabytes of free, persistent home directory storage for custom scripts and configuration files. It offers a secure, convenient, and fast management interface directly inside standard web browsers.
Question 365
Which financial pricing model offers significant compute discounts in exchange for a 1- or 3-year term commitment?
- Spot VMs
- Committed Use Discounts
- Sustained Use Discounts
- Free Tier Allowances
Correct Answer: 2
Explanation
Committed Use Discounts offer substantial cost reductions on Google Cloud compute resources in exchange for a customer signing a formal one-year or three-year usage contract. This pricing structure is ideal for predictable, steady-state enterprise workloads that run consistently over extended periods. By committing to baseline resource consumption, organizations can lower their overall cloud spending considerably compared to on-demand rates. Flexible commitment options—such as resource-based or spend-based commitments—help finance teams forecast budgets accurately and optimize infrastructure expenditures.
Question 366
Which global network edge caching service delivers static and dynamic content close to users to minimize latency?
- Cloud Armor
- Cloud Router
- Cloud CDN
- Cloud NAT
Correct Answer: 3
Explanation
Cloud CDN leverages Google’s extensive global network edge points of presence to cache and serve web content close to end users worldwide. By delivering frequently accessed assets directly from nearby edge locations, Cloud CDN drastically reduces latency, accelerates page load times, and enhances user experience. Furthermore, it offloads heavy traffic demands from backend origin servers, protecting application infrastructure from sudden traffic surges. Integrated natively with Google’s external HTTP(S) load balancers, Cloud CDN ensures secure and lightning-fast content distribution for global web applications.
Question 367
Which service acts as a web application firewall to protect applications from DDoS attacks and malicious web traffic?
- Cloud NAT
- Cloud Router
- VPC Peering
- Cloud Armor
Correct Answer: 4
Explanation
Cloud Armor is a web application firewall and network security service that protects applications and load balancers from Distributed Denial of Service attacks and malicious internet traffic. Operating at Google’s global network edge, Cloud Armor intercepts and neutralizes volumetric DDoS threats, SQL injection attempts, and cross-site scripting attacks before malicious traffic reaches backend infrastructure. It provides advanced adaptive protection, custom rate-limiting rules, geo-based access controls, and pre-configured WAF filters based on OWASP Top 10 rulesets, ensuring applications remain highly available and resilient.
Question 368
Which resource hierarchy component groups related projects together to apply collective IAM policies and constraints?
- Folders
- Billing Accounts
- Resource Tags
- Zones
Correct Answer: 1
Explanation
Folders are organizational entities within the Google Cloud resource hierarchy positioned directly beneath the root Organization node and above individual projects. They allow enterprise administrators to group related projects logically by department, business unit, or environment, making it straightforward to manage access control rules and organizational policies collectively. Any IAM policy applied at the folder level inherits downward automatically to all child folders and projects contained within it, simplifying administrative governance and ensuring compliance uniformity across multi-team enterprises.
Question 369
Which self-service portal provides customers with validated third-party compliance reports and ISO audit certifications?
- Cloud Billing Statement
- Compliance Reports Manager
- Carbon Footprint
- Resource Topology
Correct Answer: 2
Explanation
Compliance Reports Manager gives Google Cloud customers instant, self-service access to crucial regulatory documentation, third-party security audit reports, ISO certifications, and framework mappings. Instead of waiting for lengthy administrative reviews, compliance teams can retrieve validated attestation documents—such as SOC reports, PCI-DSS compliance letters, and HIPAA documentation—directly through the console. This transparency accelerates internal risk assessments, simplifies regulatory auditing processes, and helps organizations demonstrate adherence to stringent industry standards when building secure workloads.
Question 370
Which service provides a fully managed relational database supporting MySQL, PostgreSQL, and SQL Server?
- Cloud Spanner
- Cloud Bigtable
- Cloud SQL
- Firestore NoSQL
Correct Answer: 3
Explanation
Cloud SQL is a fully managed relational database service that makes it easy to set up, maintain, manage, and administer MySQL, PostgreSQL, and SQL Server databases on Google Cloud. It automates database backups, replication, patch management, and capacity scaling while ensuring high availability and robust data security for standard enterprise applications. By handling routine administrative maintenance tasks automatically, Cloud SQL frees development teams to focus on writing application code rather than troubleshooting database infrastructure issues, ensuring reliable relational data management.
Question 371
Which storage service provides durable, highly scalable object storage for unstructured data assets?
- Cloud Storage
- Persistent Disk Block Storage
- Filestore File Storage
- Local SSD Storage
Correct Answer: 1
Explanation
Cloud Storage is a highly scalable, secure, and durable object storage service designed to store unstructured data such as photos, videos, backup archives, and PDF documents. It offers multiple storage classes ranging from high-performance Standard tiers to ultra-low-cost Archive tiers for long-term compliance retention. Cloud Storage ensures eleven nines of annual data durability by scattering objects across multiple geographic locations. It provides global edge access, granular security controls via IAM, and lifecycle management rules to optimize long-term storage expenditures effortlessly.
Question 372
Which GCP service manages real-time indexing, collection, and analysis of log data?
- Error Reporting Diagnostic
- Cloud Monitoring Metrics
- Cloud Logging
- Security Command Center
Correct Answer: 3
Explanation
Cloud Logging is a fully managed real-time log management service that collects, indexes, stores, and analyzes log data from Google Cloud services, virtual machines, and application code. It enables administrators to search log streams quickly, create custom metric filters, and set up real-time alerting policies based on log events. Furthermore, Cloud Logging supports exporting log entries to BigQuery or Cloud Storage for long-term auditing and forensic analysis, giving operations teams complete visibility into application behavior across distributed cloud environments.
Question 373
Which service provides fully managed Apache Spark and Hadoop clusters for big data workloads?
- Cloud Dataflow Pipeline
- Dataproc
- BigQuery Warehouse
- Cloud Pub/Sub Streaming
Correct Answer: 2
Explanation
Dataproc is a fast, easy-to-use, fully managed cloud service designed specifically for running Apache Spark and Apache Hadoop clusters efficiently. It allows data engineering teams to spin up clusters in seconds, process large datasets using familiar open-source frameworks, and scale down resources when jobs complete to save costs. Dataproc integrates tightly with Google Cloud storage and analytical ecosystems, reducing operational overhead and enabling organizations to migrate and manage big data analytics workloads without complex cluster administration.
Question 374
Which service provides comprehensive enterprise API management, security policies, and developer portals?
- Cloud DNS
- Cloud Load Balancing
- Apigee
- Cloud Armor Firewall
Correct Answer: 3
Explanation
Apigee is Google Cloud’s comprehensive API management platform designed to help organizations design, secure, publish, monitor, and scale APIs. It acts as an intelligent intermediary layer between client applications and backend services, enforcing strict security policies, managing rate limits, transforming data formats, and providing developer portals to accelerate application integration. By using Apigee, enterprise businesses can monetize digital assets, track API performance metrics, and ensure secure microservice communication across hybrid and multi-cloud architectural landscapes seamlessly.
Question 375
Which tool enables organizations to build enterprise search engines and conversational generative AI virtual agents?
- Vertex AI Search and Conversation
- Cloud Translation API
- Document AI Parser
- Cloud Vision API
Correct Answer: 1
Explanation
Vertex AI Search and Conversation enables organizations to build enterprise-grade search engines and generative AI virtual agents quickly. It connects internal documentation, product catalogs, or website content to conversational interfaces, delivering accurate answers and superior customer support experiences without requiring deep machine learning expertise. Developers can deploy voice and text-based virtual assistants across multiple digital touchpoints effortlessly, improving customer engagement while automating complex support workflows through advanced natural language understanding and generative foundation models.
Question 376
Which centralized security service continuously scans cloud resource configurations for vulnerabilities and threats?
- Cloud Audit Logs
- Security Command Center
- Compliance Reports Manager
- Organization Policy Service
Correct Answer: 2
Explanation
Security Command Center is Google Cloud’s centralized security management and risk governance platform that continuously scans your entire resource hierarchy to detect vulnerabilities, misconfigurations, and active security threats. Beyond vulnerability identification, SCC evaluates operational configurations against industry compliance frameworks like PCI-DSS, CIS benchmarks, and HIPAA standards. It acts as a centralized dashboard for security operations teams, offering immediate visibility into risk exposure along with automated remediation paths to enforce uniform security standards across cloud environments.
Question 377
Which service provides secure container image repositories with automated vulnerability scanning?
- Cloud Build Server
- Cloud Deploy Delivery
- Artifact Registry
- Cloud Source Repositories
Correct Answer: 3
Explanation
Artifact Registry is Google Cloud’s secure integrated repository service designed for storing, managing, and vulnerability-scanning container images and language software packages such as Maven or npm. It serves as the natural evolution of Container Registry, offering fine-grained access control via IAM, multi-region native replication, and automated security vulnerability scanning. Artifact Registry integrates smoothly with Cloud Build and CI/CD deployment pipelines, ensuring that development teams store and distribute production-ready software packages safely across enterprise environments.
Question 378
Which storage tier offers ultra-low-cost retention designed specifically for long-term compliance archiving?
- Archive Storage
- Coldline Storage Tier
- Nearline Storage Tier
- Standard Storage Class
Correct Answer: 1
Explanation
Archive Storage is Google Cloud’s lowest-cost, highly durable storage service designed specifically for data archiving, disaster recovery backups, and long-term regulatory compliance retention. It is optimized for data that is accessed or modified on average less than once a year. While retrieval costs are higher compared to other tiers, its ultra-low monthly storage cost makes it ideal for petabytes of archival data that organizations must keep securely for years to satisfy legal requirements.
Question 379
Which networking service enables private virtual machine instances without external IPs to access the outbound internet?
- Cloud Router
- Cloud NAT
- Cloud VPN Gateway
- VPC Peering Connection
Correct Answer: 2
Explanation
Cloud NAT allows internal virtual machine instances provisioned without public IP addresses to securely establish outbound connections to the internet. This capability allows private VMs to download operating system security patches, pull software dependencies, or query external third-party web APIs. Because Cloud NAT handles translation strictly for outbound-initiated connections, external hosts on the public internet cannot initiate inbound traffic to the private instances. This configuration maintains a strong external perimeter defense while ensuring essential maintenance workflows function smoothly.
Question 380
Which service provides secure centralized storage and management for sensitive application secrets like API keys?
- Cloud Key Management Service
- Cloud Identity and Access Management
- Secret Manager
- Security Command Center
Correct Answer: 3
Explanation
Secret Manager is a secure and centralized storage service designed to store, manage, and audit access to sensitive application secrets such as API keys, database passwords, and TLS certificates. It encrypts data at rest and in transit, allows fine-grained access control via IAM, and maintains detailed audit logs tracking every time a secret is accessed or modified. By replacing hardcoded credentials in source code with Secret Manager references, applications improve their security posture and prevent accidental credential leaks across environments.