View Full Google Professional Cloud Developer Exam Dumps and Practice Test Dumps.
Question 221
Which Google Cloud service is designed to coordinate multiple API calls and application steps as a managed workflow?
- Cloud Storage
- Workflows
- Bigtable
- Artifact Registry
Correct Answer: 2
Explanation
Workflows is a managed orchestration service that allows developers to define and execute sequences of steps involving Google Cloud services, HTTP endpoints, and other supported operations. It is useful when an application needs explicit coordination between multiple actions rather than embedding all orchestration logic inside one application process. Workflows can also provide error handling, retries, conditional logic, and parallel execution. Developers should keep individual workflow steps focused and use appropriate retry behavior for transient failures. This approach can reduce custom orchestration code and provide a clearer representation of complex application processes.
Question 222
A developer wants an HTTP application to remain accessible only through an external Application Load Balancer while blocking direct public access to the Cloud Run service URL. Which configuration is relevant?
- Internal
- All
- Internal and Cloud Load Balancing
- Unauthenticated invocation
Correct Answer: 3
Explanation
The Internal and Cloud Load Balancing ingress configuration is designed for architectures where Cloud Run traffic should arrive through supported load-balancing infrastructure while direct external access to the service is restricted. This can provide a controlled entry point for an application while allowing the load balancer to handle external client traffic. Ingress controls network reachability, whereas IAM determines whether an authenticated identity is permitted to invoke the service. Developers should configure both according to the intended architecture. Choosing All would permit broader network access and therefore would not provide the same ingress restriction.
Question 223
A Cloud Run Job must process 1,000 independent files, with each task responsible for one file. Which configuration determines the total number of tasks created for the execution?
- Task count
- Container concurrency
- Request timeout
- Minimum instances
Correct Answer: 1
Explanation
Cloud Run Jobs use task count to determine how many task instances participate in a job execution. When a workload contains independent items, developers can divide the work among multiple tasks, with each task responsible for a portion of the overall processing. Task parallelism separately determines how many tasks can run concurrently. This distinction allows developers to control both total workload division and execution concurrency. For large batch workloads, the application should also determine which item each task processes and handle retries safely so that a failed task does not corrupt or duplicate the overall result.
Question 224
A developer wants an application to respond when a specific Google Cloud administrative operation is recorded in Cloud Audit Logs. Which service can route that event to a destination?
- Cloud CDN
- Eventarc
- Cloud Profiler
- Cloud Storage
Correct Answer: 2
Explanation
Eventarc can route supported events from Google Cloud services, including events derived from Cloud Audit Logs, to configured destinations. This enables event-driven applications to react to administrative activity without continuously polling logs. Developers can define event filters so that the trigger responds only to relevant operations. For example, an application could initiate an automated process when a particular resource-management event occurs. Careful filtering is important because broad audit-log events can generate unnecessary invocations. Eventarc therefore provides a useful bridge between cloud operational events and automated application processing.
Question 225
Which Cloud Tasks property can help ensure that a logical operation is not queued repeatedly under the same deterministic task identifier?
- Queue location
- Task name
- Retry delay
- Dispatch deadline
Correct Answer: 2
Explanation
Cloud Tasks supports task naming, which can provide deduplication behavior when an application uses deterministic task names. If the same task name is submitted again while it is subject to the service’s naming constraints, the duplicate creation can be rejected. This can be useful when an application receives repeated requests to schedule the same logical operation. Developers should design task names carefully so that they uniquely represent the intended operation. Task naming should not replace idempotent processing because a task can still be executed more than once under certain failure and retry conditions.
Question 226
A Pub/Sub subscription should receive only messages whose environment attribute equals production. Which feature should be configured?
- Subscription filter
- Message retention
- Topic replication
- Publisher batching
Correct Answer: 1
Explanation
A Pub/Sub subscription filter allows a subscriber to receive only messages whose attributes satisfy a specified expression. In this scenario, messages can carry an environment attribute, and the subscription can filter for the production value. This prevents the consumer from unnecessarily processing messages intended for other environments. Filtering is configured on the subscription, allowing different subscriptions on the same topic to select different event subsets. Developers should ensure publishers consistently populate the attributes used by filters. Filtering can reduce downstream processing while preserving a shared event-publishing model for multiple consumers.
Question 227
A Pub/Sub consumer needs to reprocess messages that were available before a known application defect was corrected. What should the developer consider?
- Subscription seek or snapshot
- Cloud Storage lifecycle management
- Cloud Run startup CPU boost
- Artifact Registry cleanup
Correct Answer: 1
Explanation
Pub/Sub provides mechanisms such as subscription seek and snapshots that can support message replay when an application needs to process earlier messages again. This can be useful after fixing a consumer defect, recovering from an operational problem, or validating new processing logic against previously published events. Developers must consider message-retention limits and the subscription’s state before attempting replay. Reprocessing also requires application logic that can safely tolerate repeated events, particularly when processing changes external state. Replay mechanisms should therefore be combined with appropriate idempotency and data consistency strategies.
Question 228
Which Firestore feature is specifically intended to authorize client operations based on the authenticated user’s identity and requested data?
- Firestore Security Rules
- BigQuery SQL
- Cloud Run ingress
- Cloud Build substitutions
Correct Answer: 1
Explanation
Firestore Security Rules provide authorization logic for client access to Firestore data. Rules can evaluate information about the authenticated user and the requested document or operation, allowing developers to permit or reject reads and writes according to application requirements. This is especially important for applications where clients interact directly with Firestore. Developers should avoid relying solely on client-side checks because clients can be modified or bypassed. Security Rules should be tested carefully with both authorized and unauthorized scenarios. IAM remains relevant for Google Cloud resource access but serves a different authorization layer.
Question 229
A BigQuery table is partitioned by event date. A query filters for only one day’s events. What benefit can partition pruning provide?
- More application instances
- Less irrelevant data scanned
- Automatic schema deletion
- Increased Pub/Sub throughput
Correct Answer: 2
Explanation
Partition pruning allows BigQuery to avoid scanning partitions that do not satisfy the query’s relevant partition conditions. When a large event table is partitioned by date and a query requests only one day, BigQuery can potentially process only the relevant partition rather than scanning the entire table. This can improve query efficiency and reduce the amount of data processed. Developers should write queries that use the partitioning field appropriately to benefit from pruning. Partitioning does not automatically optimize every query, so table design should reflect the application’s common analytical access patterns.
Question 230
A developer wants to organize data inside BigQuery partitions based on a frequently filtered customer identifier. Which feature should be considered?
- Clustering
- Cloud Tasks
- Firestore transactions
- Cloud Run ingress
Correct Answer: 1
Explanation
BigQuery clustering organizes table data according to selected clustering columns, which can improve query efficiency when workloads frequently filter or aggregate on those columns. If a table is partitioned by date and queries also commonly filter by customer identifier, customer ID can be considered as a clustering column. This allows partitioning and clustering to address different levels of data organization. Developers should choose clustering columns based on actual query patterns rather than adding many columns without a clear purpose. Properly designed clustering can improve performance for large analytical datasets with recurring filtering patterns.
Question 231
Which Cloud SQL feature can provide a managed connection path from an application while avoiding direct exposure of database credentials in application code?
- Cloud SQL connector
- BigQuery partition
- Pub/Sub snapshot
- Cloud CDN
Correct Answer: 1
Explanation
Cloud SQL connectors provide an application-oriented connection mechanism that can simplify secure connectivity to Cloud SQL instances. They can help establish authenticated and encrypted connections while integrating with Google Cloud identity and connection controls. Developers can use supported language-specific connectors or libraries instead of manually implementing all connection security details. The application should still manage database credentials and authorization according to the selected authentication model. Cloud SQL connectors do not replace database-level permissions or application security. Their purpose is to simplify and secure the network and authentication aspects of connecting applications to Cloud SQL.
Question 232
A GKE deployment must maintain a minimum number of available Pods during voluntary maintenance disruptions. Which resource should be configured?
- PodDisruptionBudget
- PersistentVolumeClaim
- ConfigMap
- NetworkPolicy
Correct Answer: 1
Explanation
A PodDisruptionBudget defines availability requirements for Pods during voluntary disruptions. This helps Kubernetes avoid evicting too many replicas of a workload at once during activities such as node maintenance or draining. The resource can express requirements such as a minimum number or percentage of Pods that should remain available. Developers should deploy enough replicas for the availability requirement to be meaningful. A PodDisruptionBudget does not protect against involuntary failures such as unexpected node crashes. It works as one component of a broader resilience strategy alongside health checks, replication, scheduling, and capacity planning.
Question 233
Which Kubernetes probe should be used to determine whether a running container is unhealthy enough to require a restart?
- Readiness probe
- Liveness probe
- Startup probe
- Resource limit
Correct Answer: 2
Explanation
A Kubernetes liveness probe determines whether a running container is functioning sufficiently to continue operating. When a container repeatedly fails its configured liveness check, Kubernetes can restart it. This differs from readiness probes, which control whether a Pod is considered ready to receive traffic, and startup probes, which are useful for applications that need significant initialization time. Developers should avoid overly aggressive liveness checks because transient problems could cause unnecessary restarts. A good liveness probe should test a meaningful indication that the application process is unhealthy rather than merely checking whether a process exists.
Question 234
A developer wants to keep a previous Secret Manager credential available while deploying a new credential version. What should be created?
- New secret version
- New project
- New Pub/Sub topic
- New Cloud Run revision only
Correct Answer: 1
Explanation
Secret Manager supports multiple versions of a secret, making it possible to introduce a new credential while retaining the previous version according to the secret’s lifecycle and access configuration. This is useful for credential rotation because applications can transition between versions without requiring a completely new secret resource. Developers can control which version is accessed and can disable or destroy obsolete versions when they are no longer needed. Access to the secret should remain restricted through IAM. Versioning provides a structured way to manage changing sensitive values while reducing disruption during credential updates.
Question 235
Which IAM feature is useful when a deployment pipeline needs to obtain temporary credentials as a deployment service account?
- Service account impersonation
- Public IAM binding
- Anonymous access
- Password authentication
Correct Answer: 1
Explanation
Service account impersonation allows an authorized identity to act as another service account using temporary credentials. This is useful for CI/CD systems because the pipeline can deploy resources using a dedicated service identity without storing a long-lived private key. The identity initiating impersonation must have the appropriate IAM permission on the target service account. Developers should keep impersonation permissions narrowly scoped and audit their use. This model supports stronger credential hygiene than distributing service account keys across build systems. The deployment account should still follow least-privilege principles and receive only the permissions needed for its tasks.
Question 236
A Cloud Run application performs CPU-intensive initialization before serving requests. Which feature may reduce the time required for startup?
- Startup CPU boost
- Pub/Sub filtering
- Firestore indexing
- Storage lifecycle rules
Correct Answer: 1
Explanation
Cloud Run startup CPU boost can provide additional CPU capacity during container startup, which may help applications complete CPU-intensive initialization more quickly. This can be useful for workloads that load large frameworks, compile components, initialize substantial libraries, or perform other computationally expensive startup operations. Developers should evaluate actual startup behavior because the benefit depends on the application’s initialization workload. Startup CPU boost is specifically associated with the startup phase and is distinct from normal runtime CPU allocation. Other options, such as Pub/Sub filtering and Firestore indexing, address data or messaging behavior rather than container initialization speed.
Question 237
A developer needs to store a custom application role containing only a carefully selected set of IAM permissions. Which IAM capability supports this design?
- Custom role
- Storage bucket
- Pub/Sub subscription
- Cloud Run revision
Correct Answer: 1
Explanation
IAM custom roles allow administrators to define a role containing a selected collection of supported permissions. This can be useful when predefined roles are either too broad or do not align precisely with an application’s required access. Developers and administrators should first determine whether an existing predefined role already satisfies the requirement before creating a custom role. When custom roles are used, permissions should be reviewed periodically as application needs change. This supports least-privilege access by avoiding unnecessary permissions while providing the workload or team with the capabilities it actually requires.
Question 238
A Cloud Build pipeline needs to pass a release version into several build steps without duplicating the value in the configuration. Which feature should be used?
- Build substitutions
- Cloud Trace
- Firestore Security Rules
- Bigtable garbage collection
Correct Answer: 1
Explanation
Cloud Build substitutions provide parameterized values that can be referenced throughout a build configuration. A release version can therefore be supplied once and reused in commands that build an image, assign an artifact tag, or perform deployment-related operations. This helps keep build definitions reusable and reduces the chance of inconsistent hard-coded values across multiple steps. Developers should validate substitution values and define them consistently for manual and automated builds. Substitutions are intended for build-time parameterization and should not be used as a secure storage mechanism for passwords, tokens, or other sensitive credentials.
Question 239
Which Cloud Storage capability can automatically delete temporary objects after they reach a specified age?
- Lifecycle management
- Object metadata
- Bucket location
- Storage class selection
Correct Answer: 1
Explanation
Cloud Storage lifecycle management allows developers to define automatic actions based on object conditions such as age. A lifecycle rule can delete temporary objects after they have existed for a specified period, reducing the need for application code to perform routine cleanup. This is particularly useful for generated files, temporary exports, processing artifacts, and other data with a predictable retention period. Developers should verify that lifecycle conditions will not remove data needed for business operations, recovery, or compliance. Lifecycle management can therefore provide consistent automated storage hygiene while reducing manual maintenance work.
Question 240
A development team wants to validate Firestore authorization rules locally before releasing them to production. Which tool is most appropriate?
- Firestore Emulator
- Cloud Load Balancing
- Cloud Scheduler
- Artifact Registry
Correct Answer: 1
Explanation
The Firestore Emulator provides a local testing environment for Firestore applications and Security Rules. Developers can use it to simulate database operations and test whether different users or application scenarios should be allowed or denied. This can make rule development faster and reduce the need to repeatedly test experimental changes against production data. Automated tests can also be built around expected authorization behavior. Although emulator testing is valuable, developers should still validate production configuration and deployment procedures carefully. Cloud Load Balancing, Cloud Scheduler, and Artifact Registry do not provide a local Firestore authorization testing environment.