Google Professional Cloud Developer Practice Test Questions and Exam Dumps Part9 Q161-180

View Full Google Professional Cloud Developer Exam Dumps and Practice Test Dumps.

 

Question 161

Which Cloud Run Jobs setting controls how many tasks can run concurrently during an execution?

  1. Task timeout
  2. Task parallelism
  3. Container concurrency
  4. Maximum instances

Correct Answer: 2

Explanation

Cloud Run Jobs use task parallelism to control how many tasks can execute simultaneously within a job execution. Increasing parallelism can reduce the overall completion time when tasks are independent and sufficient resources are available. This setting is different from Cloud Run service container concurrency, which controls how many requests a service container instance handles concurrently. Task count determines how many tasks the job contains, while parallelism determines how many of those tasks may run at the same time. Developers should select parallelism based on workload characteristics, downstream capacity, and resource constraints.

Question 162

A Cloud Run application needs access to private resources in a VPC. Which configuration should the developer consider?

  1. Public ingress
  2. Cloud CDN
  3. VPC connectivity
  4. Artifact Registry

Correct Answer: 3

Explanation

When a Cloud Run application needs to communicate with resources reachable through a Virtual Private Cloud, the developer must configure appropriate VPC connectivity. This allows the serverless workload to reach private services such as internal databases, private APIs, or other VPC resources. Depending on the architecture and supported configuration, Cloud Run can use Direct VPC egress or a Serverless VPC Access connector. Public ingress and Artifact Registry do not provide private network connectivity. The exact configuration should account for routing, firewall rules, DNS, and the destination’s network accessibility requirements.

Question 163

A developer wants Cloud Run to accept requests only from internal sources and the associated Cloud Load Balancing infrastructure. Which ingress option is appropriate?

  1. Internal and Cloud Load Balancing
  2. All
  3. Internal
  4. Unauthenticated

Correct Answer: 1

Explanation

The Internal and Cloud Load Balancing ingress configuration allows a Cloud Run service to receive traffic from internal sources while also permitting requests delivered through supported Cloud Load Balancing infrastructure. This can be useful when an organization wants to expose an application through a controlled load-balancing layer while preventing direct public access to the service endpoint. The All option permits broader ingress, whereas authentication controls who can invoke a service rather than determining network ingress paths. Developers should combine ingress restrictions with appropriate IAM and load-balancing controls for defense in depth.

Question 164

Which Cloud Tasks feature prevents two tasks with the same task name from being created simultaneously?

  1. Queue routing
  2. Retry configuration
  3. Task deduplication
  4. Dispatch rate

Correct Answer: 3

Explanation

Cloud Tasks can use task naming to provide deduplication behavior. When a task is created with a name that already exists or has recently existed according to the service’s naming and retention behavior, another task with that same name can be rejected. This is useful when an application may submit the same logical operation multiple times and wants to avoid duplicate queued tasks. Developers should choose deterministic task names carefully when deduplication is required. Dispatch rate and retry settings control execution behavior, not whether duplicate task names are accepted.

Question 165

A developer needs Cloud Tasks to call a private HTTP endpoint and authenticate using a service account. What should be configured?

  1. OIDC authentication
  2. Cloud CDN
  3. API Gateway caching
  4. Pub/Sub ordering

Correct Answer: 1

Explanation

Cloud Tasks supports OIDC authentication for HTTP targets, allowing a task request to include an identity token generated using a specified service account. The receiving service can then authenticate the request based on that identity. This approach is useful for protected HTTP endpoints where developers want queued work to execute without embedding static credentials in application code. The service account must have the necessary permissions, and the target should validate the token appropriately. Cloud CDN, API caching, and Pub/Sub ordering are unrelated to authenticating Cloud Tasks HTTP requests.

Question 166

Which Pub/Sub feature allows a subscription to receive only messages matching specified attributes?

  1. Snapshots
  2. Subscription filters
  3. Dead-letter topics
  4. Message retention

Correct Answer: 2

Explanation

Pub/Sub subscription filters allow subscribers to receive only messages whose attributes satisfy a specified filter expression. This can reduce unnecessary processing when multiple consumers share a topic but each application needs a particular subset of events. For example, messages can include attributes identifying an environment, event type, or application component, allowing a subscription to select relevant messages. Filtering is configured at the subscription level, so different subscriptions can consume different subsets of messages from the same topic. This approach can simplify event-driven architectures while reducing downstream processing work.

Question 167

A developer wants to replay previously published Pub/Sub messages for a subscription after an application bug is fixed. Which capability can help?

  1. Cloud Scheduler
  2. Subscription snapshot and seek
  3. Cloud Trace
  4. Cloud Profiler

Correct Answer: 2

Explanation

Pub/Sub snapshots and seek capabilities can help developers replay messages for a subscription when previously delivered messages need to be processed again. A snapshot represents the acknowledgment state of a subscription at a particular point, and seeking can move the subscription’s acknowledgment position so eligible messages can be delivered again. This can be valuable after fixing application logic, recovering from processing problems, or testing consumers against earlier events. Developers should understand retention constraints and the specific subscription state before using replay mechanisms in production.

Question 168

Which Firestore operation should a developer use when multiple document writes must succeed together but no read-dependent conflict detection is required?

  1. Batched write
  2. Transaction
  3. Single-document update
  4. Query

Correct Answer: 1

Explanation

A Firestore batched write is appropriate when several document writes should be committed atomically without requiring the operation to read documents and make decisions based on their current values. All writes in the batch succeed together or the batch fails as a whole. Transactions are designed for situations where reads influence subsequent writes and concurrent changes must be detected and handled. Choosing a batched write for independent atomic updates can simplify application logic and avoid unnecessary transaction retries. Developers should still keep batches within Firestore’s supported operation limits.

Question 169

An application stores analytical events in BigQuery. The table contains billions of rows, and queries usually filter by event date. Which design can reduce the amount of data scanned?

  1. Increasing API quotas
  2. Table partitioning
  3. Disabling clustering
  4. Increasing query timeout

Correct Answer: 2

Explanation

BigQuery table partitioning can reduce the amount of data scanned when queries filter on the partitioning column. For event-oriented workloads, partitioning a table by date or timestamp can allow BigQuery to eliminate partitions that are outside the requested time range. This can improve query efficiency and potentially reduce query processing costs. Developers should design partitioning around common access patterns rather than arbitrarily choosing a column. Query predicates must reference the partitioning field appropriately for effective partition pruning. API quotas and query timeouts do not reduce the underlying amount of data scanned.

Question 170

Which BigQuery technique can organize data within partitions to improve queries that frequently filter on specific columns?

  1. Replication
  2. Sharding
  3. Clustering
  4. Compression only

Correct Answer: 3

Explanation

BigQuery clustering organizes table data based on selected clustering columns. When queries frequently filter or aggregate using those columns, clustering can help BigQuery process relevant data more efficiently within the applicable partitions. Partitioning and clustering can also be combined: partitioning separates data into larger partitions, while clustering organizes data within those partitions. Developers should choose clustering columns based on recurring query patterns and avoid selecting columns without a meaningful workload benefit. Clustering does not replace partitioning in every scenario, but it can complement partitioning for large analytical datasets.

Question 171

A developer wants to estimate BigQuery query processing without actually executing the query. Which approach is appropriate?

  1. Run a dry run
  2. Create a Pub/Sub snapshot
  3. Start a Cloud Run Job
  4. Enable Cloud Trace

Correct Answer: 1

Explanation

A BigQuery dry run allows developers to validate a query and obtain information about the amount of data that would be processed without actually running the query to completion. This is useful during development and automation when teams want to estimate query processing before submitting an expensive operation. Developers can use dry runs to catch certain query issues and evaluate expected processing volume. A dry run does not produce the query’s normal result set because the query is not executed as a completed analytical operation. Pub/Sub snapshots and Cloud Trace address unrelated concerns.

Question 172

Which GKE mechanism can help prevent too many application Pods from being voluntarily disrupted at the same time?

  1. Horizontal Pod Autoscaler
  2. PodDisruptionBudget
  3. ConfigMap
  4. Service

Correct Answer: 2

Explanation

A Kubernetes PodDisruptionBudget can limit the number of Pods from a workload that may be voluntarily disrupted at one time. This is particularly useful during planned maintenance, node draining, or other administrative activities where Kubernetes attempts to evict Pods. By specifying an availability requirement, developers can help maintain sufficient application capacity while disruptions occur. A PodDisruptionBudget does not prevent all possible failures, such as hardware crashes, because it primarily addresses voluntary disruptions. It should be configured alongside appropriate replica counts and application health checks to support resilient workloads.

Question 173

Which Kubernetes probe is primarily intended to determine whether a container should be restarted?

  1. Readiness probe
  2. Startup probe
  3. Liveness probe
  4. Resource request

Correct Answer: 3

Explanation

A Kubernetes liveness probe determines whether a container is still functioning correctly enough to continue running. If the configured liveness check repeatedly fails according to the probe settings, Kubernetes can restart the affected container. This differs from a readiness probe, which determines whether a Pod should receive traffic, and a startup probe, which gives slow-starting applications time to initialize before other probes become active. Developers should design liveness checks carefully so temporary downstream failures do not unnecessarily restart healthy application processes.

Question 174

A developer wants a Secret Manager secret to use a new credential while retaining the previous credential for rollback. What should the application use?

  1. A new secret version
  2. A new project
  3. A new Cloud Run region
  4. A new IAM organization

Correct Answer: 1

Explanation

Secret Manager supports multiple versions of a secret, allowing applications and administrators to manage credential changes without immediately deleting the previous value. Creating a new secret version can provide a controlled transition to a new credential while the previous version remains available according to the secret’s configuration and lifecycle. Applications can reference an appropriate version or use the latest version when that behavior is intended. This versioning model is useful for credential rotation and rollback scenarios. Developers should still manage access permissions carefully and remove obsolete credentials when they are no longer required.

Question 175

A developer is building a local application that uses Google Cloud client libraries. Which mechanism commonly supplies credentials automatically in supported environments?

  1. Application Default Credentials
  2. Kubernetes Service
  3. Cloud CDN
  4. Bigtable replication

Correct Answer: 1

Explanation

Application Default Credentials, or ADC, provide a standard way for Google Cloud client libraries to discover credentials without requiring application code to manually implement authentication. During local development, ADC can commonly use credentials configured through supported developer authentication mechanisms. In managed Google Cloud environments, ADC can use the workload’s attached service identity when supported. This allows the same client-library authentication pattern to work across development and deployed environments while reducing credential-handling code. Developers should avoid embedding long-lived service account keys directly into application source code.

Question 176

Which Artifact Registry capability can automatically remove older artifacts according to configured retention rules?

  1. Cleanup policies
  2. VPC firewall rules
  3. Cloud Scheduler jobs
  4. Pub/Sub filters

Correct Answer: 1

Explanation

Artifact Registry cleanup policies allow organizations to define rules for automatically deleting artifacts that meet specified conditions. Developers can use these policies to manage repositories that accumulate large numbers of outdated container images or packages. Cleanup rules can help control storage growth while retaining artifacts that are still needed for releases or operational workflows. The policy should be designed carefully so important production versions are not removed prematurely. Cleanup policies operate within Artifact Registry and are separate from network controls, scheduled task execution, and Pub/Sub message filtering.

Question 177

A Cloud Build pipeline needs to reuse values such as an environment name across multiple builds without hard-coding them in the build steps. What feature is designed for this purpose?

  1. Cloud Trace
  2. Build substitutions
  3. Firestore transactions
  4. Cloud Armor rules

Correct Answer: 2

Explanation

Cloud Build substitutions allow build configurations to use parameterized values instead of hard-coding environment-specific or build-specific information into individual steps. This can make a CI/CD configuration more reusable across environments and invocation contexts. Substitution variables can represent values such as deployment targets, image tags, or other parameters supported by the build configuration. Developers should define and reference substitutions consistently and validate values supplied by automated triggers. This approach helps separate reusable build logic from changing deployment parameters without requiring separate copies of the entire build configuration.

Question 178

A developer wants to encrypt application data with a customer-controlled encryption key managed in Cloud KMS. Which concept addresses this requirement?

  1. Public DNS
  2. Customer-managed encryption keys
  3. Anonymous access
  4. Load balancing

Correct Answer: 2

Explanation

Customer-managed encryption keys, commonly referred to as CMEK, allow organizations to use encryption keys that they manage through Cloud KMS for supported Google Cloud services. This can provide greater control over key lifecycle, permissions, rotation, and auditing than relying solely on provider-managed encryption keys. Whether CMEK is available depends on the specific Google Cloud service and resource being configured. Developers should consider key access permissions and operational responsibilities before adopting CMEK. Public DNS, anonymous access, and load balancing do not provide application data encryption through customer-controlled Cloud KMS keys.

Question 179

Which Google Cloud capability can turn matching Cloud Logging entries into metrics that can be monitored?

  1. Log-based metrics
  2. Artifact cleanup policies
  3. Cloud Storage lifecycle rules
  4. Firestore indexes

Correct Answer: 1

Explanation

Log-based metrics derive metric data from matching entries in Cloud Logging. Developers can use them to count or measure events represented in application logs, such as specific error conditions, security events, or operational states. These metrics can then be used with Cloud Monitoring for dashboards and alerting. Log-based metrics are especially useful when an application emits meaningful structured or identifiable log entries but does not directly publish a corresponding custom metric. Developers should design log fields and filtering expressions carefully so the resulting metric accurately represents the operational condition being monitored.

Question 180

A Cloud Run service receives requests from an external load balancer, but developers want to prevent users from bypassing the load balancer by calling the service’s direct public endpoint. Which configuration is most relevant?

  1. Increasing container concurrency
  2. Setting appropriate ingress restrictions
  3. Increasing request timeout
  4. Adding more revisions

Correct Answer: 2

Explanation

Cloud Run ingress controls determine which network paths are permitted to reach a service. When an application should be accessed through an external load balancer rather than directly through its Cloud Run endpoint, developers can configure an appropriate ingress restriction that supports the load-balancing architecture while limiting unwanted direct access. This network-level control is distinct from IAM authentication, which governs who can invoke the service. Container concurrency, request timeout, and revision count affect runtime behavior or deployment management but do not prevent users from reaching an otherwise exposed endpoint.