View Full Google Professional Cloud Developer Exam Dumps and Practice Test Dumps.
Question 41
A developer is designing a microservices application in which services need to discover and communicate with one another inside a Google Kubernetes Engine cluster. Which Kubernetes capability provides stable service endpoints?
- ConfigMaps
- PersistentVolumes
- Kubernetes Services
- Container images
Correct Answer: 3
Explanation
Kubernetes Services provide stable network endpoints for accessing groups of pods, even when individual pods are replaced or their IP addresses change. In a microservices architecture, each service can communicate with another through its Kubernetes Service name and configured port, rather than depending on individual pod addresses. This simplifies service discovery and supports application scaling and rolling updates. ConfigMaps store non-sensitive configuration, PersistentVolumes provide storage, and container images package application software. Kubernetes Services are therefore suitable for enabling reliable internal communication between microservices running in a GKE cluster.
Question 42
A developer wants to deploy a containerized application to Cloud Run from source code without manually building and managing a container image. Which command-line tool can support this workflow?
- gcloud run deploy with source
- gsutil rsync
- kubectl get pods
- bq query
Correct Answer: 1
Explanation
The Google Cloud CLI supports deploying applications to Cloud Run from source using the gcloud run deploy command with the appropriate source deployment option. This workflow can invoke a build process, produce a container image, and deploy the resulting application to Cloud Run. It reduces the need for developers to manually construct each stage of the container build and deployment process. The deployment still requires suitable permissions, configuration, and a supported application source structure. gsutil rsync transfers storage objects, kubectl get pods inspects Kubernetes workloads, and bq query runs BigQuery queries.
Question 43
A team needs to ensure that a Cloud Run service can access a private Cloud SQL instance securely. Which networking approach should be considered?
- Expose the database publicly without restrictions
- Configure supported private connectivity between Cloud Run and Cloud SQL
- Embed database credentials in the container image
- Disable database authentication
Correct Answer: 2
Explanation
Cloud Run can connect to Cloud SQL using supported connection and networking configurations. For a private Cloud SQL instance, developers should configure an appropriate private connectivity path, such as Direct VPC egress or a Serverless VPC Access connector where applicable, and ensure that the service has the necessary database permissions and credentials. This allows the application to communicate with the database without exposing it publicly. Embedding credentials in an image or disabling authentication introduces security risks. The selected networking design should also account for region compatibility, connection limits, and operational monitoring.
Question 44
A developer needs to prevent a Kubernetes application from receiving traffic until it has completed initialization and is ready to serve requests. Which probe should be configured?
- Liveness probe
- Startup script only
- Readiness probe
- Resource quota
Correct Answer: 3
Explanation
A readiness probe determines whether a container is ready to accept traffic. Kubernetes uses the probe result to decide whether the pod should be included among the endpoints receiving traffic through its Service. This is particularly useful during startup, initialization, temporary dependency failures, or application warm-up. A liveness probe determines whether a container should be restarted, while a startup probe can protect slow-starting applications from premature liveness failures. Resource quotas limit resource consumption. A readiness probe is therefore the appropriate mechanism for controlling when an application instance begins receiving requests.
Question 45
A developer is configuring a GKE application that takes a long time to initialize. Which probe helps prevent Kubernetes from restarting it prematurely while it starts?
- Startup probe
- Readiness probe only
- Network policy
- Horizontal Pod Autoscaler
Correct Answer: 1
Explanation
A startup probe is designed for containers that require significant time to initialize. It allows Kubernetes to defer liveness and readiness probe evaluation until the startup condition succeeds, preventing slow-starting applications from being restarted prematurely because they have not yet become responsive. Developers can configure suitable probe intervals, thresholds, and timeouts based on the application’s expected initialization behavior. A readiness probe controls traffic eligibility, a network policy governs pod communication, and a Horizontal Pod Autoscaler adjusts replica counts. A startup probe is therefore appropriate when an application needs additional time to initialize safely.
Question 46
An application running on GKE experiences increased request volume, and the developer wants Kubernetes to adjust its pod replica count based on observed CPU utilization. Which resource should be configured?
- ConfigMap
- Horizontal Pod Autoscaler
- PersistentVolumeClaim
- Ingress
Correct Answer: 2
Explanation
The Horizontal Pod Autoscaler (HPA) adjusts the number of pod replicas according to observed metrics and configured scaling targets. For example, it can increase or decrease a Deployment’s replica count based on CPU utilization when the required metrics infrastructure and resource requests are configured. This helps applications respond to changing workloads while avoiding a permanently fixed replica count. Developers should define sensible minimum and maximum replicas and verify that the application can handle scaling events. ConfigMaps store configuration, PersistentVolumeClaims request storage, and Ingress defines HTTP routing. HPA is therefore appropriate for metric-based pod scaling.
Question 47
A developer wants to restrict communication between selected Kubernetes workloads so that only approved pods can connect to a sensitive backend. Which feature should be configured?
- Cloud Scheduler
- Container registry
- Kubernetes NetworkPolicy
- Cloud Build trigger
Correct Answer: 3
Explanation
Kubernetes NetworkPolicy controls network traffic to and from selected pods, subject to support from the cluster’s networking implementation. Developers can define rules that allow communication only from approved workloads or on specified ports, helping reduce unnecessary network access between application components. This is useful for isolating sensitive backends and implementing a more restrictive network design. Policies should be tested carefully because overly restrictive rules can interrupt legitimate application communication. Cloud Scheduler manages scheduled jobs, a container registry stores images, and Cloud Build triggers initiate build workflows. NetworkPolicy is therefore appropriate for controlling pod-to-pod network access.
Question 48
A developer wants to avoid hard-coding a database connection string in a GKE application’s container image. Which Kubernetes object can provide non-sensitive configuration to the container?
- ConfigMap
- Ingress
- Deployment strategy
- Horizontal Pod Autoscaler
Correct Answer: 1
Explanation
A Kubernetes ConfigMap stores non-sensitive configuration values separately from application code and container images. It can supply configuration through environment variables or mounted files, allowing the same image to be used across multiple environments with different settings. Connection strings that contain passwords or other secrets should not be stored as ordinary ConfigMap values; sensitive information should be handled through Kubernetes Secrets or an appropriate managed secret service. Ingress handles HTTP routing, deployment strategies control updates, and HPA adjusts replica counts. ConfigMap is appropriate for separating non-sensitive application configuration from the container image.
Question 49
A developer wants to store database passwords securely and make them available to an application running on Google Cloud. Which service should be used?
- Cloud CDN
- Secret Manager
- Cloud DNS
- Cloud Scheduler
Correct Answer: 2
Explanation
Secret Manager provides centralized storage and controlled access to sensitive information such as database passwords, API keys, and certificates. Applications can retrieve secrets using authorized identities, while administrators manage access through IAM and monitor usage through audit capabilities. Secret versions also support controlled updates and rotation workflows. Developers should avoid embedding credentials in source code, container images, or ordinary configuration files. Cloud CDN accelerates content delivery, Cloud DNS manages domain resolution, and Cloud Scheduler initiates scheduled tasks. Secret Manager is therefore suitable for securely managing application credentials across Google Cloud environments.
Question 50
A developer wants a GKE application to automatically retrieve a secret from Secret Manager without placing a long-lived service account key inside the container. Which identity approach is suitable?
- Public bucket access
- Shared administrator credentials
- Workload Identity Federation for GKE
- Anonymous authentication
Correct Answer: 3
Explanation
Workload Identity Federation for GKE allows Kubernetes workloads to obtain federated identities for accessing Google Cloud resources, including Secret Manager, when the required IAM configuration is in place. The application can use its workload identity to request access without storing a long-lived service account key in the container. Administrators should grant only the permissions needed to access the relevant secret and verify the Kubernetes service account mapping and workload configuration. Public access, shared administrator credentials, and anonymous authentication do not provide appropriate protection for sensitive secrets. This identity approach supports safer workload authentication and credential management.
Question 51
A developer needs to inspect the configuration and status of a deployed Kubernetes workload from a command-line environment. Which tool is designed for interacting with Kubernetes clusters?
- kubectl
- gsutil
- bq
- gcloud storage
Correct Answer: 1
Explanation
kubectl is the Kubernetes command-line tool used to inspect and manage resources in a Kubernetes cluster. Developers can use it to retrieve workload status, examine pod details, view events, apply configuration manifests, and perform other administrative or troubleshooting operations. When working with GKE, the tool must be configured with appropriate cluster credentials and context. gsutil is associated with Cloud Storage operations, bq is used for BigQuery, and gcloud storage provides Cloud Storage commands through the Google Cloud CLI. kubectl is therefore the appropriate tool for interacting with Kubernetes resources.
Question 52
A developer wants to inspect application output from a running GKE container to investigate an unexpected error. Which command is commonly used to retrieve container logs?
- kubectl logs
- kubectl scale
- kubectl expose
- kubectl label
Correct Answer: 1
Explanation
The kubectl logs command retrieves logs emitted by containers in Kubernetes pods. Developers can use it to investigate application errors, startup problems, unexpected behavior, and other issues reported through standard output or standard error. For pods with multiple containers, the appropriate container may need to be specified. Logs from terminated containers can sometimes be retrieved using the previous-container option, subject to availability. kubectl scale changes replica counts, kubectl expose creates a Service, and kubectl label manages resource labels. kubectl logs is therefore the appropriate command for examining container output during troubleshooting.
Question 53
A developer needs to expose a GKE application externally using an HTTP load balancer and route traffic to the appropriate Kubernetes Service. Which resource can define the routing rules?
- PersistentVolume
- Ingress
- ConfigMap
- Secret
Correct Answer: 2
Explanation
An Ingress resource defines HTTP or HTTPS routing rules for directing external requests to Kubernetes Services. Depending on the GKE configuration and selected controller, creating an Ingress can provision or configure a Google Cloud load-balancing resource. Developers can define host-based and path-based routing and configure TLS where supported. The backend Services must be configured correctly, and health checks and firewall requirements should be considered during deployment. PersistentVolumes provide storage, ConfigMaps store non-sensitive configuration, and Secrets manage sensitive values. Ingress is therefore appropriate for defining external web traffic routing to GKE application services.
Question 54
A developer wants to create a managed relational database that supports automated backups and high availability for a production application. Which Cloud SQL configuration should be considered?
- A single local database file
- High availability configuration
- An unauthenticated public database
- A container image containing database files
Correct Answer: 2
Explanation
Cloud SQL offers high availability configurations designed to improve database resilience by maintaining a standby instance and supporting failover when certain failures occur. For production workloads, developers should also configure automated backups, suitable maintenance settings, access controls, and monitoring. High availability can reduce downtime from some infrastructure failures, but it does not replace a comprehensive backup, recovery, and disaster-recovery strategy. A local database file or database files packaged inside an application container are not substitutes for managed production database resilience. A properly configured Cloud SQL high availability setup is therefore appropriate for applications with stronger availability requirements.
Question 55
A developer is building a Cloud Run application that must handle requests from a Pub/Sub subscription. Which integration pattern can deliver messages to the service through HTTP requests?
- Pub/Sub push subscription
- Cloud DNS zone transfer
- Cloud Storage lifecycle rule
- Kubernetes PersistentVolume
Correct Answer: 1
Explanation
A Pub/Sub push subscription delivers messages to a configured HTTPS endpoint by sending HTTP requests. A Cloud Run service can act as that endpoint, allowing the application to process incoming messages without continuously polling Pub/Sub. The service must be configured to authenticate and authorize the requests appropriately, and its response behavior should follow Pub/Sub acknowledgment expectations. Developers should also design message processing to handle retries and possible duplicate deliveries safely. DNS zone transfers, storage lifecycle rules, and Kubernetes PersistentVolumes address unrelated infrastructure concerns. A push subscription is therefore a suitable integration pattern for HTTP-based message delivery to Cloud Run.
Question 56
A developer needs to ensure that a message-processing application does not lose work when a consumer temporarily fails. Which Pub/Sub design consideration is important?
- Disable acknowledgments
- Acknowledge messages only after successful processing
- Delete the subscription after every message
- Publish all messages to an unrelated topic
Correct Answer: 2
Explanation
A Pub/Sub subscriber should acknowledge a message after its processing has completed successfully. If the consumer fails before acknowledgment, Pub/Sub can redeliver the message according to the subscription’s delivery behavior. This supports reliable processing, but developers must design consumers to tolerate duplicate deliveries because a message may be processed more than once. Idempotent operations, appropriate retry handling, and dead-letter topic configurations can help manage failure scenarios. Disabling acknowledgments or deleting subscriptions undermines reliable processing. Acknowledging only after successful processing is therefore a key design consideration for resilient message-driven applications.
Question 57
A developer wants to reduce cold-start latency for a Cloud Run service that receives occasional traffic but must respond quickly when requests arrive. Which configuration can help keep instances available?
- Minimum instances
- Disable authentication
- Remove health monitoring
- Increase log retention only
Correct Answer: 1
Explanation
Cloud Run supports minimum instance settings that can keep a specified number of instances available, helping reduce cold-start latency for workloads with intermittent traffic. This can improve responsiveness when requests arrive after periods of inactivity, although it may introduce additional cost because instances are kept available. Developers should evaluate the application’s latency requirements, traffic pattern, resource allocation, and billing implications before enabling the setting. Disabling authentication or removing monitoring does not address instance startup latency, and log retention affects diagnostic data storage. Minimum instances are therefore a relevant configuration for latency-sensitive Cloud Run services.
Question 58
A developer needs to ensure that a Cloud Run service uses a specific container image version rather than an image tag that may change over time. Which reference is most suitable for deployment reproducibility?
- A mutable tag such as latest
- An image digest
- An untracked local directory
- A public webpage URL
Correct Answer: 2
Explanation
A container image digest uniquely identifies the content of a specific image artifact. Referencing an image by digest helps make deployments reproducible because the deployed workload uses the exact image content associated with that digest, rather than relying on a mutable tag that may later point to a different image. This is particularly useful for controlled releases, auditing, and rollback procedures. Mutable tags can be convenient during development but may introduce uncertainty if they are overwritten. A local directory or webpage URL is not an appropriate immutable container artifact reference. An image digest is therefore suitable for precise deployment identification.
Question 59
A developer wants to identify which revision of a Cloud Run service generated a particular request during troubleshooting. Which information should be included in application logs?
- Revision and request context
- Only the developer’s password
- Unrelated billing details
- A static message with no identifiers
Correct Answer: 1
Explanation
Including revision identifiers and useful request context in structured application logs helps developers associate errors or performance issues with a specific Cloud Run revision. Contextual fields such as request identifiers, operation names, severity, and relevant non-sensitive metadata can make log searches more effective. Developers should avoid recording passwords, access tokens, or unnecessary personal data. Revision-aware logging is especially valuable during gradual rollouts, when multiple versions may receive traffic concurrently. A static message without identifiers can make diagnosis difficult, while unrelated billing details do not establish which revision handled a request. Revision and request context improve troubleshooting clarity.
Question 60
A developer is preparing a production release and wants to verify that the application works correctly before promoting it to the next environment. Which practice supports a controlled release process?
- Skip testing and deploy immediately
- Test the release in a staging environment
- Disable monitoring during deployment
- Replace production configuration with development credentials
Correct Answer: 2
Explanation
Testing a release in a staging environment helps developers validate application behavior under conditions that resemble production before promoting the release. Staging tests can cover functionality, integrations, configuration, permissions, performance, and deployment procedures. The environment should use appropriate test data and carefully managed credentials, while avoiding unintended access to production resources. Monitoring and release checks should remain available to help detect problems. Skipping tests or replacing production configuration with development credentials can introduce avoidable operational and security risks. Staging validation is therefore an important step in a controlled application release process.