View Full Google Professional Cloud Developer Exam Dumps and Practice Test Dumps.
Question 81
A Cloud Run application needs to invoke a backend service privately, and the receiving service should verify the caller’s Google Cloud identity rather than relying on a shared application secret. What should the developer use?
- Anonymous access
- Cloud Storage ACLs
- Static API key
- Service account identity with authenticated requests
Correct Answer: 4
Explanation
Service-to-service authentication on Google Cloud can use service account identities so that the receiving service can verify who is making a request. For Cloud Run, an authenticated caller can obtain an identity token and present it when invoking another protected service. The receiving service validates the token and its intended audience before processing the request. Anonymous access removes identity verification, while static API keys provide a weaker shared-secret model. Cloud Storage ACLs are unrelated to service invocation. Using service account-based authentication supports identity-aware communication between application components.
Question 82
A developer wants to store configuration values such as an API endpoint and feature flag separately from application code so that the same container image can be deployed to multiple environments. What approach should be used?
- Externalized environment configuration
- Hard-coded constants
- Embedded configuration binaries
- Source-code comments
Correct Answer: 1
Explanation
Externalizing configuration allows the same application artifact to be promoted across environments while environment-specific values are supplied during deployment or execution. Cloud Run supports environment variables and other configuration mechanisms that let developers separate operational settings from application code. This approach improves portability and reduces the need to rebuild an image whenever a staging or production endpoint changes. Hard-coded constants and embedded configuration require source or artifact changes, while comments have no runtime effect. Separating configuration from code therefore supports consistent deployments and cleaner application lifecycle management.
Question 83
A Cloud Run application must handle a workload that can run for several minutes without requiring an immediate response to the original user request. Which architecture is most appropriate?
- Perform the entire task synchronously
- Increase browser timeout indefinitely
- Submit the work to an asynchronous task or event processor
- Disable request timeouts
Correct Answer: 3
Explanation
Long-running work is generally better handled asynchronously when the user does not need to wait for completion. The application can accept the request, place the work into a suitable asynchronous mechanism such as Cloud Tasks or Pub/Sub, and allow a worker service to process it independently. This avoids tying up the original request while the operation runs. Increasing browser or service timeouts does not solve the architectural problem and can create poor resource utilization. An asynchronous processing design provides better separation between request handling and lengthy background operations.
Question 84
A developer is troubleshooting why a containerized application cannot start because a required environment variable is missing. Which practice makes this type of configuration problem easier to detect before production deployment?
- Remove all environment variables
- Validate required configuration during application startup
- Ignore missing values
- Store configuration only in comments
Correct Answer: 2
Explanation
Validating required configuration during application startup allows a service to fail quickly and clearly when essential values are absent or invalid. Developers can check required environment variables, configuration formats, and other prerequisites before accepting production traffic. This is preferable to allowing the application to start and fail later during a user request, which can produce confusing runtime errors. Removing configuration or ignoring missing values does not improve reliability. Comments also cannot validate runtime configuration. Startup validation therefore provides an effective fail-fast pattern for cloud-native applications.
Question 85
A GKE application requires a Kubernetes Pod to receive a specific amount of CPU and memory for scheduling, while also preventing the container from exceeding defined resource consumption. Which configuration should be used?
- ConfigMap entries
- Ingress annotations
- Service labels
- Resource requests and limits
Correct Answer: 4
Explanation
Kubernetes resource requests specify the amount of CPU and memory a container needs for scheduling purposes, while resource limits establish maximum resource consumption. Together, they help Kubernetes place workloads appropriately and prevent individual containers from consuming unlimited resources. ConfigMaps store configuration values, Ingress annotations provide routing-related metadata, and service labels identify Kubernetes objects. Proper requests and limits are especially important for predictable workload placement and resource management in GKE. Developers should select values based on observed application behavior and expected workload requirements rather than arbitrary limits.
Question 86
A Pub/Sub subscriber may receive the same message more than once because processing succeeds but acknowledgment is delayed or lost. How should the application be designed to handle this possibility?
- Make message processing idempotent
- Assume every message is delivered once
- Delete the subscription after processing
- Disable all retries
Correct Answer: 1
Explanation
Pub/Sub applications should generally be designed to tolerate duplicate message delivery. An idempotent handler produces the same intended final result even if the same message is processed multiple times. Developers can use unique event identifiers, transactional database operations, or other deduplication techniques where appropriate. Assuming exactly-once behavior without verifying the configured delivery model can result in duplicate records or repeated side effects. Disabling retries can cause failed work to be lost. Designing consumers for idempotency therefore improves reliability when messages are redelivered.
Question 87
A Cloud Run service processes requests containing uploaded files. The application should reject files larger than an approved application-specific size before expensive processing begins. Where should this validation occur?
- After storing every file permanently
- During request handling before intensive processing
- Only during monthly monitoring
- After sending the file to unrelated services
Correct Answer: 2
Explanation
Application-specific file-size validation should occur as early as practical during request processing. Rejecting an oversized upload before expensive parsing, transformation, or downstream processing reduces unnecessary resource consumption and improves application responsiveness. The service can inspect request metadata or enforce appropriate upload constraints before performing costly operations. Waiting until after permanent storage or unrelated downstream processing wastes resources and may increase operational costs. Monthly monitoring cannot prevent an individual oversized request. Early validation is therefore a useful defensive programming practice for applications that process user-supplied files.
Question 88
A developer needs to prevent accidental exposure of database credentials stored in source code repositories. Which Google Cloud service should be used to centrally manage these credentials?
- Cloud Trace
- Secret Manager
- Cloud Profiler
- Cloud Scheduler
Correct Answer: 2
Explanation
Secret Manager is designed to securely store and manage sensitive values such as database passwords, API credentials, and tokens. Applications can access secrets at runtime using controlled identities and permissions rather than embedding credentials directly in source code or container images. This also makes credential rotation easier because the secret can be updated independently of application source code. Cloud Trace and Cloud Profiler provide observability capabilities, while Cloud Scheduler handles scheduled execution. Centralizing sensitive configuration in Secret Manager therefore reduces the risk associated with hard-coded credentials and improves operational security.
Question 89
A Cloud Build pipeline produces container images that are later deployed to production. The team wants to prevent deployment of images that contain known vulnerabilities identified by supported artifact scanning. What should be incorporated into the delivery process?
- Source-code comments
- Browser caching
- Artifact vulnerability scanning and deployment controls
- DNS forwarding
Correct Answer: 3
Explanation
Artifact vulnerability scanning can identify known security issues in container images and other supported artifacts. A delivery pipeline can use scan results as part of its release controls so that images with unacceptable findings are reviewed or blocked according to organizational policy. This creates a security checkpoint between building an artifact and deploying it. Source comments, browser caching, and DNS forwarding do not inspect container contents for known vulnerabilities. Integrating artifact scanning into the build and deployment workflow helps development teams identify security issues earlier and establish repeatable release controls.
Question 90
A Cloud Run service needs to expose a health endpoint that reports whether the application is ready to receive traffic. Which mechanism should be used to provide platform-level readiness information?
- Readiness or startup health checking
- Cloud Storage lifecycle policy
- Artifact Registry cleanup
- Pub/Sub retention policy
Correct Answer: 1
Explanation
Health checking allows the platform to determine whether an application instance has successfully initialized and is ready to handle requests. For containerized applications, developers should distinguish startup behavior from ongoing health behavior and configure suitable probes or health mechanisms supported by the deployment platform. This can prevent traffic from reaching an application before required initialization has completed. Storage lifecycle policies, Artifact Registry cleanup, and Pub/Sub retention settings address unrelated resource-management concerns. Appropriate health checks improve deployment reliability by making application readiness an explicit operational condition.
Question 91
A team wants to invoke a Cloud Run service whenever a supported Google Cloud event occurs, without building a custom polling process. Which architecture should the developer consider?
- Cloud SQL replication
- Event-driven routing with Eventarc
- Cloud Storage versioning only
- Cloud CDN invalidation
Correct Answer: 2
Explanation
Eventarc enables event-driven architectures by routing supported events from Google Cloud sources to destinations such as Cloud Run. Instead of repeatedly polling a service for changes, an application can react when an event matching a configured trigger occurs. This can reduce unnecessary requests and simplify integration between loosely coupled components. Cloud SQL replication addresses database availability and data distribution, Storage versioning preserves object versions, and CDN invalidation manages cached content. Event-driven routing with Eventarc is therefore appropriate when a Cloud Run service should respond automatically to supported cloud events.
Question 92
A developer needs a scheduled process to run every night and invoke an HTTP endpoint that starts a maintenance operation. Which Google Cloud service is designed specifically for this recurring schedule?
- Cloud Tasks
- Cloud Run Jobs
- Eventarc
- Cloud Scheduler
Correct Answer: 4
Explanation
Cloud Scheduler is designed to execute recurring jobs according to a defined schedule. It can send HTTP requests to an endpoint, making it suitable for triggering maintenance operations, periodic processing, or other scheduled application activities. Cloud Tasks is intended for asynchronous task queues rather than calendar-based recurring schedules. Eventarc responds to events, while Cloud Run Jobs execute containerized tasks but do not themselves provide the scheduling capability described. Combining Cloud Scheduler with an appropriate authenticated endpoint provides a straightforward architecture for recurring application maintenance.
Question 93
A developer wants to run a containerized batch workload that performs processing and then exits, rather than maintaining an HTTP service that continuously handles incoming requests. Which Cloud Run capability fits this workload?
- Cloud Run Jobs
- Cloud CDN
- API Gateway
- Cloud Trace
Correct Answer: 1
Explanation
Cloud Run Jobs are designed for containerized tasks that run to completion instead of continuously serving HTTP requests. They are useful for batch processing, data transformations, administrative tasks, and other workloads that can start, perform their work, and terminate. A traditional Cloud Run service is primarily intended for request-driven workloads. Cloud CDN distributes cached content, API Gateway manages API access, and Cloud Trace provides distributed tracing. For a container that should execute a batch operation and exit successfully, Cloud Run Jobs provide the appropriate execution model.
Question 94
An application uses Firestore queries that filter and sort on multiple fields. Some queries fail because the required composite indexes are missing. What should the developer do?
- Disable all indexes
- Store every document in Cloud Storage
- Create the required Firestore composite indexes
- Replace every query with a SQL query
Correct Answer: 3
Explanation
Firestore may require composite indexes for queries that combine multiple filtering, ordering, or other conditions. When a query requires an index that does not exist, the developer can create the appropriate composite index according to the query’s field requirements. Index configuration should reflect actual application access patterns because unnecessary indexes can increase storage and write costs. Disabling indexes would not solve the query requirement, while Cloud Storage is not a replacement for Firestore querying. Replacing Firestore with SQL is also unnecessary when the existing document model remains appropriate.
Question 95
A service receives an OAuth access token from a client and needs to determine whether the token is intended for the service and has not expired. Which validation should be performed?
- Check only the HTTP method
- Validate the token’s relevant claims and expiration
- Trust the token because it came from a client
- Compare the token length with previous requests
Correct Answer: 2
Explanation
Authentication tokens should be validated according to the authorization system and token type being used. Relevant checks can include signature verification where applicable, issuer, audience, expiration, and required scopes or claims. Checking only superficial request properties does not establish that the token is valid for the intended service. A client-supplied token must never be trusted simply because it was presented. Token length also provides no meaningful security validation. Proper token validation ensures that the backend accepts requests only when the credentials satisfy the application’s authentication and authorization requirements.
Question 96
A Cloud Run application has a highly variable workload and the team wants to reduce latency caused by starting new instances during sudden traffic increases. Which configuration should they investigate?
- Minimum instances
- Object versioning
- BigQuery partitioning
- DNS records
Correct Answer: 1
Explanation
Cloud Run minimum instances can keep a configured number of instances available so that the service has warm capacity when requests arrive. This can reduce cold-start-related latency for workloads where predictable responsiveness is important. The setting should be balanced against cost because maintaining instances can consume resources even when traffic is low. Object versioning affects Cloud Storage, BigQuery partitioning improves analytical query organization, and DNS records control name resolution. For an application sensitive to startup latency during periods of changing demand, minimum-instance configuration is therefore worth evaluating.
Question 97
A developer needs to deploy a new Cloud Run revision while ensuring that a controlled portion of traffic remains on the previous version until testing is complete. Which Cloud Run capability supports this requirement?
- Cloud Storage object locking
- Cloud Run traffic allocation
- Pub/Sub message retention
- Firestore collection groups
Correct Answer: 2
Explanation
Cloud Run supports traffic allocation among revisions, allowing developers to direct specified portions of incoming traffic to different deployed versions. This capability can support controlled rollouts, testing, and gradual migration between revisions. The previous revision can continue receiving traffic while the new revision is evaluated, depending on the chosen configuration. Cloud Storage object locking protects stored objects, Pub/Sub retention controls message availability, and Firestore collection groups support queries across collections. Traffic allocation is therefore the Cloud Run feature that directly addresses controlled distribution between application revisions.
Question 98
A developer wants application logs to be easier to query by fields such as user ID, operation name, and severity rather than searching unstructured text. What logging approach should be used?
- Structured logging
- Plain comments
- Binary-only logging
- Disabling log ingestion
Correct Answer: 1
Explanation
Structured logging records application events in a machine-readable format with separate fields for values such as severity, operation, request identifiers, and user-related metadata where appropriate. This makes logs easier to filter, search, aggregate, and analyze in Cloud Logging. Unstructured text can still be useful, but extracting individual fields from arbitrary messages is generally less reliable. Disabling logs removes useful operational information, while comments and binary-only output do not provide a practical searchable logging model. Structured logs therefore improve observability and make application troubleshooting more efficient.
Question 99
A Cloud Deploy pipeline should release an application to production only after a designated reviewer approves the promotion from a previous environment. Which capability should the deployment process use?
- Automatic deletion of releases
- Manual approval gate
- Anonymous deployment
- Source repository renaming
Correct Answer: 2
Explanation
A manual approval gate allows a deployment workflow to pause before a controlled promotion and require an authorized person to approve continuation. This is useful when production releases require human review after automated testing or staging validation. The approval mechanism can become part of a repeatable deployment process without requiring developers to manually execute every deployment step. Automatic deletion, anonymous deployment, and repository renaming do not provide release authorization. A manual approval gate therefore fits scenarios where production promotion must remain subject to an explicit human authorization step.
Question 100
A developer is designing a microservice that should return a response immediately while independently processing an event that may take several seconds. Which communication pattern best matches this requirement?
- Synchronous database locking
- Long-running blocking request
- Asynchronous messaging
- Repeated client polling of the same request
Correct Answer: 3
Explanation
Asynchronous messaging allows a service to accept work and communicate that work to another component without keeping the original request blocked until processing finishes. The producer can publish an event or enqueue a task, return an appropriate response, and allow a worker to process the operation independently. This pattern improves responsiveness and creates looser coupling between services. Long-running synchronous requests tie resources to the caller, while repeated polling adds unnecessary complexity. Asynchronous messaging is therefore well suited to microservices that need immediate request responses alongside independent background processing.