View Full Google Professional Cloud Developer Exam Dumps and Practice Test Dumps.
Question 381
A GKE application needs to maintain stable network identities and persistent storage for each replica. Which Kubernetes workload resource is designed for this requirement?
- Deployment
- StatefulSet
- DaemonSet
- ConfigMap
Correct Answer: 2
Explanation
A Kubernetes StatefulSet is designed for workloads that require stable identities, predictable Pod naming, and persistent storage associations. This makes it suitable for stateful applications such as databases and distributed systems where individual replicas may need to retain identity across restarts or rescheduling. A Deployment is generally intended for stateless workloads, while a DaemonSet places Pods on selected nodes rather than managing a set of uniquely identified replicas. Developers should also consider storage classes, persistent volumes, and application-specific clustering requirements when deploying stateful workloads on GKE.
Question 382
A GKE cluster requires a monitoring agent to run on every eligible node. Which Kubernetes resource is appropriate?
- Job
- StatefulSet
- DaemonSet
- CronJob
Correct Answer: 3
Explanation
A Kubernetes DaemonSet ensures that a Pod runs on each node that matches its scheduling requirements. This makes it appropriate for node-level agents such as monitoring, logging, security, or storage-related components. When a new eligible node joins the cluster, the DaemonSet controller can create the corresponding Pod there as well. Developers should use node selectors, tolerations, and resource requirements when the agent should run only on particular nodes. A DaemonSet differs from a Deployment because the goal is node coverage rather than maintaining an arbitrary number of interchangeable application replicas.
Question 383
A batch process must run automatically every hour on GKE. Which Kubernetes resource should create the required batch execution on a schedule?
- Service
- CronJob
- ConfigMap
- PersistentVolume
Correct Answer: 2
Explanation
A Kubernetes CronJob creates Jobs according to a defined schedule. It is appropriate for recurring batch workloads such as periodic reports, cleanup operations, synchronization tasks, and scheduled data processing. Each scheduled execution can create a Job that runs the finite workload and eventually completes. Developers should configure concurrency behavior, failure handling, and history limits according to the application’s requirements. A CronJob differs from a Job because a Job performs a finite execution, while a CronJob controls repeated creation of Jobs. Scheduling should also account for workloads that may overlap when an earlier execution takes longer than expected.
Question 384
A GKE application has several replicas and should spread them across failure domains to reduce the chance of losing all replicas together. Which Kubernetes scheduling capability can express this preference?
- Pod topology spread constraints
- ConfigMap
- Service account
- Container command
Correct Answer: 1
Explanation
Pod topology spread constraints allow Kubernetes workloads to express how Pods should be distributed across topology domains such as zones or nodes. Developers can use these constraints to encourage or require balanced placement of replicas, improving resilience when infrastructure failures affect a particular domain. The configuration can specify topology keys, matching labels, and permitted skew. Developers should distinguish required constraints from preferred behavior because strict placement rules can prevent scheduling when the cluster lacks suitable capacity. Topology spread constraints provide more explicit distribution control than simply relying on the scheduler’s default placement decisions.
Question 385
An API Gateway deployment should expose a REST API according to a defined OpenAPI specification. Which configuration is central to defining the API interface?
- OpenAPI document
- Storage lifecycle rule
- Pub/Sub snapshot
- Firestore TTL policy
Correct Answer: 1
Explanation
API Gateway can use an OpenAPI specification to define an API’s paths, operations, parameters, responses, and related configuration. The specification provides a structured description of the API contract and can also contain gateway-specific configuration needed to connect requests with backend services. Developers should maintain the OpenAPI definition alongside application source and deployment configuration so that changes to the API contract can be reviewed and versioned. The gateway configuration should also address authentication, quotas, and backend behavior where applicable. A well-defined API specification helps keep the exposed interface consistent with the intended application design.
Question 386
An API Gateway API needs browser-based clients hosted on a different origin to call its endpoints. Which HTTP mechanism must be configured correctly?
- CORS
- Pub/Sub ordering
- Cloud Storage retention
- Firestore indexing
Correct Answer: 1
Explanation
Cross-Origin Resource Sharing, or CORS, controls whether browsers permit web applications from one origin to make requests to resources hosted on another origin. For an API consumed by browser-based clients from a different domain, the API and backend must provide appropriate CORS behavior, including the necessary response headers and handling of preflight requests when required. Developers should restrict allowed origins and methods according to the application’s actual requirements rather than permitting every origin unnecessarily. CORS is a browser security mechanism and should not be confused with API authentication or authorization, which provide separate security controls.
Question 387
A Cloud Deploy rollout fails verification after deployment, and the release should return to the previously working version. Which deployment capability is relevant?
- Rollback
- Log exclusion
- Topic retention
- Object versioning
Correct Answer: 1
Explanation
Cloud Deploy supports rollback workflows that can return a target to an earlier successful deployment when a newer rollout does not meet requirements. Rollback is useful when deployment verification identifies application failures, configuration problems, or unexpected runtime behavior after release. Developers should establish clear verification criteria and retain suitable release history so that an appropriate previous version can be identified. Rollback should be treated as a controlled deployment operation rather than an emergency substitute for testing. Automated verification, monitoring, and staged deployment practices can help detect issues before a release reaches a broad production audience.
Question 388
A Cloud Deploy pipeline should run automated checks against a newly deployed application before considering the rollout successful. Which capability supports this requirement?
- Deployment verification
- Storage lifecycle
- Firestore TTL
- Pub/Sub filtering
Correct Answer: 1
Explanation
Cloud Deploy deployment verification allows automated verification processes to evaluate an application after deployment. Verification can check whether the newly deployed version behaves according to predefined expectations before the rollout proceeds or is considered successful. This provides an additional quality gate beyond simply completing the deployment operation. Developers can use application health signals, tests, or other verification mechanisms appropriate to the workload. Verification should be designed to detect meaningful failures rather than merely confirming that a deployment command completed. Combining verification with staged delivery can reduce the risk of promoting defective application versions broadly.
Question 389
An organization wants to cache packages from an external public repository inside Artifact Registry while controlling how dependencies are retrieved. Which repository type is relevant?
- Remote repository
- Standard repository only
- Cloud Storage bucket
- Pub/Sub subscription
Correct Answer: 1
Explanation
Artifact Registry remote repositories can act as a caching proxy for supported external package sources. When an application requests a package, the repository can retrieve and cache the package according to its configuration, reducing repeated direct access to the upstream repository. This can improve dependency availability and provide organizations with greater control over package retrieval. Developers should still establish dependency-management and security policies, including reviewing package provenance and versions. Remote repositories differ from standard repositories, which are primarily used to store artifacts directly managed by the organization, and virtual repositories, which can provide a unified access layer across repositories.
Question 390
A development team wants one Artifact Registry endpoint to provide access to packages from multiple configured repositories. Which repository capability supports this?
- Virtual repository
- Cloud Run Job
- Storage lifecycle rule
- BigQuery view
Correct Answer: 1
Explanation
Artifact Registry virtual repositories provide a unified access point over multiple upstream repositories. This can simplify dependency configuration because developers can use a single repository endpoint while the virtual repository determines where matching packages are obtained according to its configured priorities and sources. This approach can combine organization-managed repositories with other configured package sources. Developers should define repository priorities and access permissions carefully to ensure expected packages are selected. Virtual repositories differ from remote repositories, which focus on caching from an upstream source, and standard repositories, which directly store artifacts managed by the organization.
Question 391
A Cloud Storage bucket contains sensitive data and must use a customer-managed encryption key rather than Google-managed encryption alone. Which capability should be configured?
- Customer-managed encryption key
- Public object ACL
- Storage class
- Lifecycle condition
Correct Answer: 1
Explanation
Customer-managed encryption keys, commonly implemented through Cloud KMS, allow organizations to control the cryptographic key used to protect supported Google Cloud resources. For Cloud Storage, developers can configure a customer-managed key when the application’s security or compliance requirements call for additional control over encryption key management. The identity accessing the resource must have the necessary permissions to use the key. Developers should also understand key lifecycle operations because disabling or destroying a key can affect access to encrypted data. Customer-managed encryption is separate from storage class and lifecycle configuration, which address storage behavior rather than encryption-key control.
Question 392
A security team wants an IAM permission to apply only when a request satisfies a defined resource or request attribute condition. Which IAM capability should be used?
- IAM Conditions
- Service labels
- Storage classes
- Pub/Sub ordering keys
Correct Answer: 1
Explanation
IAM Conditions allow access bindings to include logical conditions that determine when granted permissions apply. Developers can use conditions to restrict access based on supported attributes such as resource characteristics or request context. This provides more precise authorization than granting a role unconditionally across every applicable resource. Conditions should be designed carefully because an incorrect expression can unintentionally deny legitimate access or create broader access than intended. Developers should test conditional bindings with representative identities and resources. IAM Conditions complement least-privilege design by allowing permissions to be constrained to specific circumstances rather than simply assigning broad unconditional roles.
Question 393
A Secret Manager secret should receive new versions automatically according to a defined rotation process. Which capability can coordinate this requirement?
- Secret rotation
- Cloud Run concurrency
- BigQuery clustering
- Pub/Sub snapshot
Correct Answer: 1
Explanation
Secret Manager supports secret rotation workflows that can help organizations replace sensitive values periodically. Rotation generally involves generating or obtaining a new secret value and creating a new secret version through an appropriate automated process. Applications should retrieve the current usable version according to their configuration and be designed to handle changes without unnecessary downtime. Developers should also ensure that old versions are managed appropriately and that rotation identities have only the permissions required to perform the operation. Secret rotation reduces reliance on manually changing credentials and can support security policies requiring periodic replacement of sensitive values.
Question 394
A Secret Manager consumer should always retrieve the current enabled version of a secret without hard-coding a numeric version. Which version reference is suitable?
- latest
- v0
- current-static
- primary
Correct Answer: 1
Explanation
The latest version alias in Secret Manager can refer to the most recently created secret version, subject to the service’s version and state semantics. Using a version alias can reduce the need to update application configuration every time a new secret version is created. Developers should understand the implications of automatically consuming newly created versions, particularly during credential rotation. Applications with strict rollout requirements may instead intentionally reference a specific version. Secret versions can also be disabled or destroyed according to lifecycle policies. Developers should choose the reference strategy based on whether automatic adoption or controlled promotion is required.
Question 395
A Cloud Run service must use a different configuration value in staging and production while deploying the same container image. Which approach is appropriate?
- Environment-specific runtime configuration
- Rebuilding the image for every environment
- Embedding passwords in source code
- Creating separate application logic branches
Correct Answer: 1
Explanation
Separating runtime configuration from the container image allows the same immutable artifact to be deployed across staging and production while environment-specific values are supplied at deployment or runtime. This approach improves consistency because application code does not need to change simply because an environment has different endpoints, feature settings, or resource identifiers. Sensitive values should be supplied through appropriate secret-management mechanisms rather than ordinary configuration when confidentiality is required. Developers should avoid creating environment-specific image variants unless there is a genuine application requirement. Keeping configuration separate supports repeatable deployments and reduces differences between environments.
Question 396
A developer needs to identify the Google Cloud resource that a log entry belongs to when troubleshooting an application. Which information is especially useful in structured Cloud Logging data?
- Resource metadata
- Container image color
- Storage class
- DNS label length
Correct Answer: 1
Explanation
Cloud Logging entries contain structured information describing the monitored resource associated with the log entry. Resource metadata can identify the service, instance, container, or other relevant resource producing the log. This information helps developers filter logs and distinguish activity from different components in a distributed application. Structured logging can provide additional fields such as severity, timestamps, trace identifiers, and application-specific context. Developers should design log output so important troubleshooting information is available without exposing secrets or sensitive data. Correct resource identification is especially valuable when many services share a centralized logging environment.
Question 397
A developer wants an automated build to be reproducible even when a container tag is later moved to another image. Which reference should the deployment pipeline prefer?
- Image digest
- Mutable tag only
- Service display name
- Repository description
Correct Answer: 1
Explanation
A container image digest identifies a specific immutable image content, whereas a mutable tag can potentially point to a different image later. Using a digest in deployment workflows helps ensure that the exact artifact tested during a build is the artifact deployed to subsequent environments. This supports reproducibility and reduces ambiguity in release pipelines. Developers can still use human-readable tags for organization and release naming, but production promotion should rely on immutable artifact identity when consistent deployments are required. Combining digests with build provenance and deployment verification provides stronger traceability across the software delivery lifecycle.
Question 398
A Cloud Run service needs to connect to a private backend without routing traffic through the public internet. Which connectivity approach can provide controlled VPC access?
- Direct VPC egress
- Public DNS only
- Revision tags
- Cloud Storage lifecycle
Correct Answer: 1
Explanation
Cloud Run Direct VPC egress allows service traffic to reach resources in a VPC network without requiring a separate connector resource in the traditional architecture. Developers can use this capability when a Cloud Run application needs access to private resources such as internal services or databases. Network routing, firewall rules, DNS, and IAM must still be configured appropriately for the target resource. VPC connectivity does not automatically grant permission to the backend. Developers should also consider which traffic should use the VPC path and configure egress behavior according to the application’s network requirements.
Question 399
A developer wants a Cloud Run service to reject requests that exceed the application’s maximum processing duration. Which setting should be configured?
- Request timeout
- Minimum instances
- Revision tag
- Maximum image size
Correct Answer: 1
Explanation
Cloud Run request timeout determines how long a request can be processed before the platform terminates the request according to its timeout behavior. Developers should choose a value that accommodates legitimate application processing while preventing requests from remaining active indefinitely. The appropriate setting depends on the application’s workload, downstream dependencies, and user experience requirements. Long-running background work may be better suited to asynchronous architectures or Cloud Run Jobs rather than increasing request timeouts indefinitely. Developers should also ensure that application code handles interrupted requests safely and avoids leaving inconsistent state when a request exceeds its permitted duration.
Question 400
A developer is designing a service that should expose only the permissions necessary for its runtime identity to access Google Cloud resources. Which IAM practice should be followed?
- Grant project-wide Owner access
- Use least-privilege permissions
- Make the service account public
- Disable authorization
Correct Answer: 2
Explanation
Least-privilege access means granting a workload identity only the permissions required to perform its intended operations. For a Cloud Run or other managed application, developers should identify the specific Google Cloud resources and actions needed and assign the narrowest suitable IAM roles. Avoiding broad roles reduces the potential impact of application vulnerabilities, configuration errors, or compromised credentials. Service accounts should not be made publicly accessible simply to simplify integration. Developers should periodically review permissions because application requirements can change over time. Least privilege is a foundational IAM practice for reducing unnecessary access across cloud applications.