Google Professional Cloud Developer Practice Test Questions and Exam Dumps Part10 Q181-200

View Full Google Professional Cloud Developer Exam Dumps and Practice Test Dumps.

 

Question 181

Which Cloud Run setting determines how long a container instance can receive CPU during request processing?

  1. Request timeout
  2. Memory limit
  3. Minimum instances
  4. Ingress setting

Correct Answer: 1

Explanation

The Cloud Run request timeout controls the maximum amount of time a request can be processed before Cloud Run terminates the request. Developers should configure the timeout according to the expected duration of application operations while avoiding unnecessarily long values. Request timeout is distinct from memory allocation, minimum instances, and ingress configuration. Long-running background work generally should not depend on an ordinary HTTP request remaining open indefinitely. Instead, developers can consider asynchronous architectures or Cloud Run Jobs when appropriate. Correct timeout configuration helps prevent legitimate operations from being terminated prematurely while maintaining predictable service behavior.

Question 182

A Cloud Run service must receive traffic only from resources inside the project or connected VPC environment. Which ingress configuration should the developer consider?

  1. All
  2. Internal
  3. Public
  4. Unauthenticated

Correct Answer: 2

Explanation

The Internal ingress setting is designed for Cloud Run services that should accept traffic from internal sources according to Google Cloud’s supported internal networking rules. This can help restrict exposure when a service is intended only for internal applications, workloads, or connected network environments. Ingress configuration controls where traffic can originate, while IAM controls whether an identified caller is authorized to invoke the service. Developers should verify the exact networking path and service dependencies before selecting the restriction. Combining ingress controls with authentication and authorization provides stronger protection for internal applications.

Question 183

A Cloud Run Job contains 100 independent tasks. The developer wants 20 tasks to run simultaneously. Which configuration should be used?

  1. Maximum instances set to 20
  2. Container concurrency set to 20
  3. Task parallelism set to 20
  4. Request timeout set to 20

Correct Answer: 3

Explanation

Cloud Run Jobs use task parallelism to specify how many tasks may run concurrently within an execution. If a job contains 100 independent tasks and parallelism is configured to 20, Cloud Run can run up to 20 tasks simultaneously, subject to available capacity and other service constraints. This differs from Cloud Run service container concurrency, which applies to request handling by service instances. Task count determines the total number of tasks, while parallelism controls concurrent task execution. Developers should select a value that balances completion time with downstream service capacity and resource consumption.

Question 184

Which Cloud Run feature can provide additional CPU during container startup to help an application initialize faster?

  1. Startup CPU boost
  2. Revision traffic splitting
  3. Request authentication
  4. Minimum request size

Correct Answer: 1

Explanation

Cloud Run startup CPU boost can provide additional CPU resources during container startup, helping applications that require significant initialization work become ready more quickly. This can be particularly useful for applications with large dependency trees, framework initialization, runtime compilation, or other CPU-intensive startup operations. Startup CPU boost affects the startup phase and should not be confused with the application’s normal runtime CPU allocation. Developers should measure startup behavior before and after enabling such features to determine whether the additional resources meaningfully improve deployment and request-start latency.

Question 185

A developer needs to mount Cloud Storage data into a Cloud Run container using a supported volume mechanism. Which resource is involved?

  1. Cloud SQL
  2. Cloud Storage bucket
  3. Pub/Sub topic
  4. BigQuery dataset

Correct Answer: 2

Explanation

Cloud Run supports certain volume configurations that allow applications to access Cloud Storage data through a mounted bucket mechanism. This can be useful when application code expects filesystem-like access rather than explicitly using Cloud Storage APIs for every operation. Developers should understand that mounted storage behavior and semantics can differ from a traditional local persistent filesystem, including performance and consistency considerations. The underlying Cloud Storage bucket must also be configured with appropriate permissions for the workload’s identity. Cloud SQL, Pub/Sub, and BigQuery are separate managed services and are not the storage resource used for this mounting pattern.

Question 186

Which Eventarc trigger type can react to specific audit log activity generated by Google Cloud services?

  1. Cloud Audit Logs event trigger
  2. Cloud CDN trigger
  3. Cloud DNS trigger
  4. Cloud Storage lifecycle trigger

Correct Answer: 1

Explanation

Eventarc can route events derived from Cloud Audit Logs to supported event destinations. This allows developers to build event-driven applications that react when specific administrative or data-access activities occur in Google Cloud services. An Eventarc trigger can use appropriate event type and filtering criteria so that only relevant audit events reach the destination. Developers should carefully define filters because broad audit-log triggers may generate more events than the application needs. This approach can connect operational or security-related cloud activity with automated processing without requiring continuous polling of audit logs.

Question 187

A Workflows execution should attempt a failed HTTP call again after a temporary service error. Which feature should be configured?

  1. Parallel steps
  2. Retry policy
  3. Environment variable
  4. Workflow label

Correct Answer: 2

Explanation

Workflows supports retry behavior for steps that may fail because of temporary conditions. A retry policy can specify how failed operations should be attempted again rather than immediately terminating the entire workflow. Developers should use retries selectively, particularly for operations that are safe to repeat or designed to be idempotent. Retry configuration can also include conditions that determine which failures are retried. This approach is useful for transient network problems, temporary service unavailability, or recoverable backend errors. Permanent failures should generally be handled through explicit error-handling logic rather than repeated indefinitely.

Question 188

A Firestore application needs to ensure users can access only documents belonging to their own user identity. Which mechanism should be used?

  1. Firestore Security Rules
  2. BigQuery clustering
  3. Cloud Run concurrency
  4. Pub/Sub retention

Correct Answer: 1

Explanation

Firestore Security Rules allow developers to define authorization conditions that determine whether clients can read or write Firestore data. A common pattern is to compare the authenticated user’s identity with fields or document paths representing ownership. This allows an application to enforce access restrictions close to the database boundary rather than relying entirely on client-side checks. Developers should design rules carefully and test them against authorized and unauthorized scenarios. Firestore Security Rules are different from IAM policies used for Google Cloud resources and are specifically important for securing client access to Firestore data.

Question 189

Which Bigtable configuration determines how long obsolete cell versions can remain before garbage collection removes them?

  1. Row key
  2. Garbage collection policy
  3. Cluster endpoint
  4. Replication route

Correct Answer: 2

Explanation

Bigtable garbage collection policies determine when older cell versions or values become eligible for removal. Developers can configure policies based on factors such as the maximum number of versions or the age of stored values. These policies help control storage growth while preserving the historical data required by the application. Garbage collection is applied according to the column family’s configured policy rather than by changing the row key. Developers should choose retention settings based on application requirements because data that becomes eligible for garbage collection may no longer be available for reads after the cleanup process completes.

Question 190

A Cloud Storage application must prevent an upload from overwriting an object that has changed since the client last observed it. What should the developer use?

  1. Object lifecycle rule
  2. Storage precondition
  3. Public access setting
  4. Bucket label

Correct Answer: 2

Explanation

Cloud Storage preconditions can help applications perform safe conditional operations on objects. A developer can use generation or metageneration conditions so an update succeeds only when the object remains in the expected state. This helps prevent race conditions in applications where multiple processes might modify the same object concurrently. Instead of blindly overwriting an object, the application can require the stored generation to match the value it previously observed. If the object changed, the conditional request fails and the application can decide how to handle the conflict. This provides useful optimistic concurrency control for object operations.

Question 191

Which IAM capability allows a developer or deployment system to act temporarily as another service account when authorized?

  1. Service account impersonation
  2. Public access
  3. Anonymous authentication
  4. Static API keys

Correct Answer: 1

Explanation

Service account impersonation allows an authorized principal to obtain short-lived credentials that act as a specified service account. This can be useful when developers need to deploy or operate resources using a service identity without distributing long-lived service account keys. The requesting principal must have the appropriate IAM permission to impersonate the target account. This model improves credential management because access can be centrally controlled and audited. Developers should grant impersonation permissions narrowly and avoid giving broad authority when a more limited service account role or workflow can satisfy the requirement.

Question 192

A GKE workload should remain available during a voluntary node disruption. Which resource can specify the minimum application availability that should be maintained?

  1. PodDisruptionBudget
  2. ConfigMap
  3. Ingress
  4. PersistentVolume

Correct Answer: 1

Explanation

A PodDisruptionBudget specifies an availability requirement for Pods during voluntary disruptions. For example, an application can define how many replicas must remain available while maintenance operations or node draining take place. This helps Kubernetes coordinate voluntary evictions without unnecessarily reducing application capacity below the specified threshold. A PodDisruptionBudget does not protect against involuntary failures such as hardware problems or sudden node loss. Developers should combine it with appropriate replica counts, health probes, and workload scheduling practices. This provides a useful control for maintaining service availability during planned infrastructure operations.

Question 193

A Cloud Build pipeline produces container images that are stored in Artifact Registry. Which practice helps ensure the same immutable image is promoted between environments?

  1. Rebuilding separately in every environment
  2. Using an image digest
  3. Changing the base image before production
  4. Retagging with random values only

Correct Answer: 2

Explanation

A container image digest identifies a specific immutable image content, making it suitable for promoting the exact artifact across development, testing, staging, and production environments. Using the digest helps prevent an environment from accidentally receiving a different image merely because a mutable tag was updated. This supports reproducible deployments and clearer release tracking. Developers can build an artifact once, validate it through the delivery pipeline, and deploy that same immutable artifact to subsequent environments. Rebuilding separately can introduce differences, while mutable tags alone do not guarantee that the referenced image content remains unchanged.

Question 194

Which Cloud Monitoring feature can evaluate application performance against a defined reliability target over time?

  1. SLO monitoring
  2. Artifact cleanup
  3. Storage versioning
  4. Pub/Sub filtering

Correct Answer: 1

Explanation

Cloud Monitoring supports service-level objective concepts that allow teams to measure service reliability against defined targets. An SLO can represent a desired level of availability, latency, or another measurable service characteristic over a specified period. Developers and operations teams can use this information to understand whether an application is meeting its reliability objectives and to identify periods of degraded performance. SLO monitoring is more specific than simply collecting raw metrics because it connects measurements to an explicit reliability target. Teams should define meaningful indicators and objectives that reflect actual user-facing service expectations.

Question 195

A developer wants to propagate distributed trace information across service-to-service HTTP calls. Which approach is appropriate?

  1. Remove request metadata
  2. Propagate trace context
  3. Disable logging
  4. Increase database storage

Correct Answer: 2

Explanation

Distributed tracing depends on propagating trace context between participating services. When one service calls another, appropriate trace-context information can be carried with the request so tracing systems can associate operations with the same distributed trace. This helps developers understand latency across service boundaries and identify where failures or delays occur. Modern instrumentation libraries and supported tracing frameworks can handle much of this propagation automatically when configured correctly. Developers should avoid accidentally dropping tracing headers at proxies or application boundaries. Trace context propagation complements application logs and metrics by providing request-flow visibility across multiple components.

Question 196

Which API Gateway feature can restrict how often clients may call an API according to configured limits?

  1. API quotas
  2. Firestore indexes
  3. Cloud Storage generations
  4. Kubernetes probes

Correct Answer: 1

Explanation

API quotas can be used to control API consumption according to configured usage limits. This helps protect backend services from excessive requests and provides predictable usage boundaries for clients. Developers should configure quotas according to the expected application workload and service capacity. Quotas are different from authentication because they regulate usage rather than establish a caller’s identity. They also differ from caching, which can reduce backend requests by serving reusable responses. Proper API quota configuration can be part of an overall API protection strategy that also includes authentication, authorization, validation, monitoring, and backend capacity planning.

Question 197

A developer wants to upload a large object to Cloud Storage while allowing the transfer to resume after an interrupted connection. Which capability should be used?

  1. Resumable upload
  2. Lifecycle deletion
  3. Object listing
  4. Bucket labeling

Correct Answer: 1

Explanation

Cloud Storage resumable uploads allow applications to upload large objects in a way that can continue from the point reached before an interruption. This is useful when network connections are unreliable or objects are too large for a simple one-shot transfer to be practical. Instead of restarting the entire upload after a failure, the client can continue the session using the resumable upload mechanism. Developers should handle upload-session state and errors appropriately. Lifecycle rules, object listing, and bucket labels provide useful management capabilities but do not provide resumable transfer behavior for interrupted uploads.

Question 198

A developer needs an application to update several Firestore documents atomically without reading their current values first. Which operation fits this requirement?

  1. Batched write
  2. Query
  3. Collection scan
  4. Single-field index

Correct Answer: 1

Explanation

A Firestore batched write is designed for atomically applying multiple write operations when the application does not need transaction-style read validation. The writes in the batch are committed together, so the operation provides an all-or-nothing result for the included writes. This makes batched writes useful for coordinated updates across multiple documents that do not depend on their current values. Firestore transactions are more appropriate when application decisions depend on reads and concurrent modifications must be detected. Developers should select the operation based on whether the workflow requires read-before-write conflict handling or simply atomic multiple-document writes.

Question 199

Which Cloud Run configuration determines whether requests can reach a service through external or internal network paths?

  1. Ingress
  2. Memory allocation
  3. Container image digest
  4. Environment variable

Correct Answer: 1

Explanation

Cloud Run ingress configuration controls the network paths through which requests can reach a service. Developers can select an ingress policy that determines whether traffic is broadly accepted or restricted to supported internal and load-balancing paths. This is a network exposure control rather than an application-level authorization mechanism. IAM can separately determine which authenticated principals are allowed to invoke the service. When designing a production application, developers should consider both the desired network exposure and caller authorization requirements. Correct ingress configuration can reduce unintended direct access while preserving the intended architecture for legitimate clients.

Question 200

A development team wants to test Firestore Security Rules locally before deploying changes. Which approach is appropriate?

  1. Firestore Emulator
  2. Cloud CDN
  3. Cloud Scheduler
  4. Artifact Registry cleanup

Correct Answer: 1

Explanation

The Firestore Emulator provides a local environment where developers can test Firestore behavior and Security Rules without relying entirely on a production database. This supports faster development and makes it easier to validate authorization scenarios, including both permitted and denied operations. Developers can create test cases that represent different authenticated users and document-access conditions before deploying rule changes. Local testing does not eliminate the need for careful production validation, but it can catch many rule and application issues earlier. Cloud CDN, Cloud Scheduler, and Artifact Registry cleanup serve unrelated infrastructure purposes.