Google Professional Cloud Developer Practice Test Questions and Exam Dumps Part19 Q361-380

View Full Google Professional Cloud Developer Exam Dumps and Practice Test Dumps.

 

Question 361

A developer wants external CI/CD infrastructure to authenticate to Google Cloud without storing long-lived service account keys. Which capability should be used?

  1. Workload Identity Federation
  2. Cloud Storage ACLs
  3. API keys
  4. Static service account passwords

Correct Answer: 1

Explanation

Workload Identity Federation allows external workloads to obtain short-lived Google Cloud credentials through trusted identity providers instead of storing long-lived service account keys. This is useful for external CI/CD platforms that need to deploy applications or access Google Cloud resources. The external identity is mapped to a Google Cloud service account or principal with appropriate permissions. This approach reduces the risks associated with distributing and rotating permanent credentials. Developers should configure attribute mappings and IAM permissions carefully so that only the intended external workloads can impersonate or access the required Google Cloud identities and resources.

Question 362

A Cloud Run service should be accessible only from requests originating through an internal network path or an approved external Application Load Balancer. Which ingress configuration matches this requirement?

  1. All
  2. Internal and Cloud Load Balancing
  3. Public only
  4. Disabled

Correct Answer: 2

Explanation

Cloud Run ingress controls determine which network paths can reach a service. The Internal and Cloud Load Balancing option allows traffic from internal sources while also permitting traffic delivered through an approved Google Cloud external Application Load Balancer. This configuration can help developers place controlled frontend or security layers in front of a service instead of exposing its direct endpoint broadly. Developers should combine ingress restrictions with IAM authentication when the application requires identity-based access control. Network restrictions and authorization address different security concerns, so configuring one does not automatically replace the need for the other.

Question 363

A Cloud Run service experiences slow startup because its container performs substantial initialization work. Which feature can provide additional CPU during startup?

  1. CPU quota
  2. Startup CPU boost
  3. Minimum memory
  4. Maximum concurrency

Correct Answer: 2

Explanation

Cloud Run startup CPU boost provides additional CPU resources during container startup to help reduce initialization time for workloads with substantial startup processing. This can be useful when applications load frameworks, initialize large libraries, compile resources, or perform other CPU-intensive startup operations. The feature affects startup behavior rather than permanently increasing the service’s configured CPU resources. Developers should still optimize application initialization because excessive startup work can increase deployment and scaling latency. Startup CPU boost is also distinct from minimum instances, which keeps instances warm to reduce the frequency with which new instances need to start.

Question 364

A Cloud Run service must maintain a small number of warm instances even when traffic is low to reduce request latency during sudden traffic increases. Which setting is appropriate?

  1. Maximum instances
  2. Request timeout
  3. Minimum instances
  4. Revision tag

Correct Answer: 3

Explanation

Cloud Run minimum instances allows developers to maintain a configured number of warm instances for a service even when request volume is low. Keeping instances warm can reduce startup latency when new requests arrive because some capacity is already available. This can be useful for applications with latency-sensitive requests or expensive initialization processes. Developers should consider the associated resource usage because maintaining instances can incur costs even during periods of low traffic. Minimum instances does not establish an upper scaling limit; maximum instances serves that purpose. The two settings can be configured independently according to workload requirements.

Question 365

A Cloud Run application should keep user requests associated with the same instance when possible. Which capability can support this behavior?

  1. Session affinity
  2. Artifact provenance
  3. Storage retention
  4. Build substitution

Correct Answer: 1

Explanation

Cloud Run session affinity can help route requests from the same client to the same instance when possible. This can be useful for workloads that temporarily benefit from instance-local state, such as certain session-oriented applications. However, developers should not treat session affinity as a guarantee that all requests will always reach the same instance because instances can be replaced, scaled, or become unavailable. For reliable application state, external storage should generally be used instead of depending exclusively on memory within a container. Session affinity is therefore a routing aid rather than a substitute for a durable state-management architecture.

Question 366

A Cloud Functions 2nd gen application needs several requests handled concurrently by the same function instance. Which capability is relevant?

  1. Concurrency
  2. Object versioning
  3. Topic retention
  4. BigQuery partitioning

Correct Answer: 1

Explanation

Cloud Functions 2nd gen supports configurable concurrency, allowing an instance to handle multiple requests simultaneously when the workload and runtime support that model. This can improve resource utilization for applications where requests do not require exclusive instance access. Developers should evaluate whether the application is thread-safe and whether shared in-memory state could create race conditions. Concurrency also interacts with CPU, memory, and scaling behavior. Increasing concurrency is not automatically beneficial for every workload; CPU-intensive or stateful applications may require different configurations. Proper load testing can help determine an appropriate concurrency level.

Question 367

A Cloud Functions 2nd gen function should remain available with warm instances during periods of low traffic to reduce cold-start latency. Which setting is relevant?

  1. Minimum instances
  2. Maximum payload
  3. Event filter
  4. Revision tag

Correct Answer: 1

Explanation

Cloud Functions 2nd gen supports minimum instances, which can maintain warm instances for a function even when incoming traffic is low. This can reduce cold-start latency for latency-sensitive applications because the platform can route requests to already initialized instances. Developers should balance latency requirements against resource costs because maintaining warm instances consumes resources even when traffic is limited. Minimum instances is separate from maximum instances, which limits scaling during high demand. The setting is particularly relevant for functions with expensive initialization or applications where occasional cold starts would noticeably affect user-facing response times.

Question 368

A Cloud Functions 2nd gen function is triggered by a specific event type. The developer wants to ensure unrelated events do not invoke the function. What should be configured?

  1. Event filters
  2. Memory limits only
  3. Container port
  4. Storage retention

Correct Answer: 1

Explanation

Event filters allow an event-driven function to respond only to events matching defined attributes or criteria. Narrow filtering reduces unnecessary invocations and prevents application code from receiving events it does not need to process. Developers should identify the relevant event attributes from the event source and configure filters accordingly. Filtering also helps control resource consumption because unrelated events do not trigger function executions. Developers should still implement validation inside the function when business rules require additional checks. Event filtering determines which events trigger the function; it does not replace authorization or application-level security controls.

Question 369

A developer wants to inspect whether a service is reachable from the public internet at regular intervals. Which Cloud Monitoring capability is appropriate?

  1. Uptime check
  2. Log exclusion
  3. Metric label
  4. Trace span

Correct Answer: 1

Explanation

Cloud Monitoring uptime checks periodically test whether an endpoint is reachable and responding according to configured expectations. They are useful for detecting availability problems from supported monitoring locations and can provide signals for alerting. Developers can configure checks against appropriate HTTP, HTTPS, or other supported endpoints and use the resulting monitoring data to identify service outages. Uptime checks are different from application logs because they actively test availability rather than waiting for the application to emit information. Developers should select an endpoint that accurately represents the user-facing functionality they want to monitor.

Question 370

A developer needs metrics from resources in multiple Google Cloud projects to appear in a single monitoring environment. Which Cloud Monitoring concept supports this?

  1. Metric scope
  2. Revision tag
  3. Storage class
  4. Subscription filter

Correct Answer: 1

Explanation

Cloud Monitoring metric scopes allow monitoring data from multiple Google Cloud projects to be viewed and queried within a centralized monitoring environment. This is useful for organizations where applications are distributed across several projects but operators need a unified view of metrics and dashboards. Developers and administrators can configure a scoping project and associate monitored projects according to the desired monitoring architecture. Metric scopes concern visibility and aggregation of monitoring data; they do not merge the underlying Google Cloud projects or alter resource ownership. Centralized monitoring can simplify troubleshooting for distributed applications and multi-project deployments.

Question 371

A development team wants application logs from selected projects automatically delivered to BigQuery for long-term analysis. Which Cloud Logging feature should be configured?

  1. Log sink
  2. Uptime check
  3. Revision tag
  4. Container port

Correct Answer: 1

Explanation

Cloud Logging log sinks route selected log entries to supported destinations such as BigQuery, Cloud Storage, or Pub/Sub. Developers can define filters so that only relevant application logs are exported instead of sending every available log entry. Routing logs to BigQuery is useful when teams need structured analysis, historical reporting, or custom queries over large volumes of log data. Developers should consider destination permissions, filtering requirements, and associated storage or processing costs. A log sink controls routing; it does not itself create application logs or replace Cloud Monitoring metrics and alerting.

Question 372

A Cloud Logging configuration should prevent verbose health-check messages from appearing in a production log view without deleting the underlying log entries. What feature can help?

  1. Log exclusion
  2. Cloud Run timeout
  3. Pub/Sub snapshot
  4. BigQuery clustering

Correct Answer: 1

Explanation

Cloud Logging exclusions can prevent matching log entries from being stored in a particular logging bucket according to the configured exclusion behavior. They are useful for reducing unnecessary logging volume when certain repetitive or low-value entries are not needed for retention or analysis. Developers should configure exclusions carefully because excluded logs may not be available for later investigation. Filtering can also be used when users simply want to narrow what they see without changing stored logs. Before excluding production information, developers should confirm that the excluded entries are genuinely unnecessary for troubleshooting, security monitoring, auditing, or compliance requirements.

Question 373

A developer wants to reduce the volume of distributed trace data while continuing to observe representative requests. Which concept should be configured?

  1. Trace sampling
  2. Container concurrency
  3. Storage retention
  4. Queue dispatch deadline

Correct Answer: 1

Explanation

Trace sampling controls how many requests generate distributed trace information. Sampling can reduce observability overhead and storage volume while retaining a representative view of application behavior. Developers should select sampling behavior based on traffic volume, troubleshooting requirements, and the importance of capturing particular request types. Excessive sampling can increase costs and noise, while overly aggressive reduction can make rare problems difficult to investigate. Trace sampling is separate from logging because it affects trace collection rather than ordinary application log generation. Critical applications may also use targeted observability strategies to capture important traffic more consistently.

Question 374

A Java application running on Google Cloud needs automatic collection of distributed trace information with minimal custom tracing code. Which instrumentation approach should the developer investigate?

  1. OpenTelemetry instrumentation
  2. Cloud Storage lifecycle
  3. Firestore TTL
  4. Pub/Sub retention

Correct Answer: 1

Explanation

OpenTelemetry provides standardized APIs, SDKs, and instrumentation approaches for collecting telemetry such as traces and metrics from applications. Developers can use supported instrumentation libraries to reduce the amount of custom tracing code required when integrating observability into an application. OpenTelemetry can help create consistent telemetry across services and runtimes, particularly in distributed architectures. Developers should verify compatibility between the chosen runtime, libraries, exporters, and Google Cloud observability configuration. Instrumentation should also avoid placing sensitive information into telemetry. Standardized instrumentation can make tracing easier to maintain when applications contain multiple services or programming languages.

Question 375

A developer is writing a new application in Python and wants authentication, retries, and request handling for Google Cloud services without implementing raw REST calls. What should be used?

  1. Google Cloud client libraries
  2. Cloud Storage lifecycle rules
  3. Pub/Sub snapshots
  4. BigQuery clustering only

Correct Answer: 1

Explanation

Google Cloud client libraries provide language-specific interfaces for interacting with Google Cloud services. They handle many implementation details such as authentication integration, request construction, retries, and service-specific APIs, allowing developers to focus more directly on application functionality. Client libraries are generally preferable to manually constructing every REST request when an appropriate supported library is available. Developers should still understand authentication, error handling, retry behavior, and service quotas because libraries do not remove the need for sound application design. Using official client libraries can also improve consistency and maintainability across projects using Google Cloud APIs.

Question 376

A developer runs an application locally and wants it to use the same Google Cloud authentication mechanism that production workloads can use through the environment. Which approach is appropriate?

  1. Application Default Credentials
  2. Hard-coded private keys
  3. Anonymous access
  4. Object ACLs

Correct Answer: 1

Explanation

Application Default Credentials provide a standard mechanism for Google Cloud client libraries and applications to locate credentials in supported environments. During local development, ADC can use configured developer credentials, while production environments can obtain credentials from the runtime’s associated identity when configured appropriately. This allows application code to remain largely unchanged across environments. Developers should avoid embedding service account private keys directly in source code or configuration files. ADC does not automatically grant permissions; the authenticated identity must still have the IAM roles required to access the requested Google Cloud resources.

Question 377

A developer needs a service account to access only a specific Cloud Storage bucket instead of every bucket in a project. Which IAM principle should guide the configuration?

  1. Least privilege
  2. Maximum availability
  3. Public access
  4. Anonymous authentication

Correct Answer: 1

Explanation

The principle of least privilege means granting an identity only the permissions required to perform its intended tasks. If an application needs access to one Cloud Storage bucket, developers should prefer an appropriate narrowly scoped role or resource-level permission instead of granting broad project-wide access. This reduces the potential impact if the application’s identity or credentials are misused. Developers should periodically review permissions as application requirements change. Least privilege applies across Google Cloud services and is especially important for service accounts used by automated workloads because those identities can operate without direct human interaction.

Question 378

A CI/CD provider outside Google Cloud needs temporary access to deploy a service, but the organization prohibits downloadable service account keys. Which solution fits this requirement?

  1. Workload Identity Federation
  2. Permanent JSON key
  3. Shared administrator password
  4. Public service account

Correct Answer: 1

Explanation

Workload Identity Federation enables external identities to access Google Cloud resources without requiring long-lived service account keys. An external CI/CD platform can authenticate through a supported identity provider and exchange its external identity for short-lived Google Cloud credentials. The resulting access can be restricted through IAM to the resources and operations required by the pipeline. This approach reduces the need to store private key files in third-party systems and lowers the risk associated with long-lived credentials. Developers should configure the trust relationship carefully, including identity conditions and permissions, to prevent unauthorized external workloads from gaining access.

Question 379

A developer wants Cloud KMS keys to automatically receive new cryptographic key versions on a defined schedule. Which capability addresses this requirement?

  1. Automatic key rotation
  2. Cloud Run scaling
  3. Pub/Sub filtering
  4. Firestore indexing

Correct Answer: 1

Explanation

Cloud KMS supports automatic key rotation for eligible cryptographic keys, allowing new key versions to be generated according to a configured rotation schedule. Key rotation can reduce the period during which a single key version is used and can support organizational security policies. Rotation does not automatically re-encrypt every existing piece of data; applications and services use key versions according to the relevant encryption workflow. Developers should understand how the consuming service handles key versions before configuring rotation. Key rotation is also different from deleting a key, which is a separate lifecycle and security operation with significant consequences.

Question 380

A Cloud Storage bucket contains data that must remain protected from deletion until a compliance retention period expires. Which feature should the developer configure?

  1. Object hold
  2. Cloud Run concurrency
  3. Pub/Sub ordering key
  4. BigQuery materialized view

Correct Answer: 1

Explanation

Cloud Storage object holds can temporarily prevent specific objects from being deleted or replaced while the hold remains active. This can be useful when individual objects need additional protection because of legal, compliance, or application-specific requirements. Developers should distinguish object holds from bucket-level retention policies, which establish broader minimum retention requirements. A hold applies to the protected object and must be managed appropriately when the object is eligible for normal lifecycle operations. These controls should be planned carefully because they can prevent expected cleanup operations and may affect applications that assume objects can always be deleted immediately.