{"id":13002,"date":"2026-09-16T05:48:59","date_gmt":"2026-09-16T05:48:59","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=13002"},"modified":"2026-09-16T05:48:59","modified_gmt":"2026-09-16T05:48:59","slug":"google-associate-cloud-engineer-practice-test-questions-and-exam-dumps-part-20-q381-400","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/google-associate-cloud-engineer-practice-test-questions-and-exam-dumps-part-20-q381-400\/","title":{"rendered":"Google Associate Cloud Engineer Practice Test Questions and Exam Dumps Part 20 Q381-400"},"content":{"rendered":"<p><b>View Full <a href=\"https:\/\/www.examlabs.com\/associate-cloud-engineer-exam-dumps\">Google Associate Cloud Engineer Exam Dumps<\/a> and Practice Test Dumps<\/b><\/p>\n<p>&nbsp;<\/p>\n<h3><b>Q381. Which Google Cloud service is designed to execute code in response to events without requiring management of servers?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Cloud Functions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Compute Engine<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud Storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud DNS<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Functions is a serverless compute service designed to execute code in response to events. Developers can create functions that respond to events from supported Google Cloud services, HTTP requests, or other event sources without managing underlying servers. This makes Cloud Functions useful for lightweight event-driven processing, automation, and application integrations. Compute Engine requires virtual machine management, Cloud Storage provides object storage, and Cloud DNS manages DNS records. Therefore, Cloud Functions is the appropriate service when an application needs to execute code automatically in response to events while minimizing infrastructure management responsibilities.<\/span><\/p>\n<h3><b>Q382. A company wants to trigger processing automatically whenever a new object is uploaded to a Cloud Storage bucket. Which architecture is appropriate?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Cloud Functions triggered by a storage event<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud DNS with a private zone<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud NAT with a static IP<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud Storage lifecycle rules only<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Functions can be configured to respond to events associated with Cloud Storage objects. When a new object is created, an event can trigger a function that performs processing such as validation, metadata extraction, transformation, or notification. This event-driven architecture avoids the need for a continuously running server that repeatedly checks the bucket for changes. Cloud DNS handles name resolution, Cloud NAT provides outbound connectivity, and lifecycle rules automate object management rather than executing arbitrary application code. Therefore, using a Cloud Function triggered by a Cloud Storage event is an appropriate design for automatic object processing.<\/span><\/p>\n<h3><b>Q383. Which Google Cloud service provides asynchronous messaging between independent application components?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Cloud Pub\/Sub<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud DNS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud KMS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud Monitoring<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Pub\/Sub is a managed messaging service designed to enable asynchronous communication between independent application components. Publishers send messages to topics, and subscribers receive those messages according to their subscription configuration. This architecture helps decouple applications because the publisher does not need to communicate directly with a specific consumer at the time the message is created. Cloud DNS manages DNS, Cloud KMS manages cryptographic keys, and Cloud Monitoring provides observability and metrics. Therefore, Cloud Pub\/Sub is the appropriate service when applications need reliable asynchronous messaging and loose coupling between producers and consumers.<\/span><\/p>\n<h3><b>Q384. A subscriber successfully processes a Pub\/Sub message and wants Pub\/Sub to consider that message completed. What should the subscriber do?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Acknowledge the message<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Delete the topic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Disable the API<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Create a new project<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Pub\/Sub subscriber should acknowledge a message after successfully processing it. The acknowledgment tells Pub\/Sub that the subscriber has successfully handled the message and that it does not need to be redelivered under normal acknowledgment processing. If a message is not acknowledged within the relevant delivery period, Pub\/Sub may deliver it again. This behavior helps support reliable message processing. Deleting the topic, disabling the API, or creating another project does not indicate successful processing. Therefore, acknowledging the message is the correct action after the subscriber successfully completes its processing.<\/span><\/p>\n<h3><b>Q385. A company wants Pub\/Sub messages that repeatedly fail processing to be redirected for separate investigation. Which feature should be configured?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Dead-letter topic<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud CDN<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud NAT<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> BigQuery clustering<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Pub\/Sub dead-letter topic can be configured to handle messages that cannot be successfully processed after repeated delivery attempts. Instead of allowing problematic messages to continue interfering with normal processing, they can be redirected to a separate topic for later investigation or remediation. This can help application teams identify malformed messages, processing failures, or other recurring problems. Cloud CDN is used for content caching, Cloud NAT provides outbound connectivity, and BigQuery clustering organizes analytical data. Therefore, a dead-letter topic is the appropriate Pub\/Sub feature for isolating messages that repeatedly fail processing.<\/span><\/p>\n<h3><b>Q386. An application requires that related Pub\/Sub messages be delivered to subscribers in the order they were published. Which feature should be configured?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Message ordering<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud Storage Versioning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud NAT<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud Scheduler<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pub\/Sub message ordering can be enabled when an application requires related messages to be delivered in publishing order. Ordering is configured around ordering keys, allowing messages with the same ordering key to maintain their relative order for supported subscription processing. This is useful for workflows where the sequence of events matters, such as processing updates for the same entity. Cloud Storage Versioning preserves previous object versions, Cloud NAT provides outbound network translation, and Cloud Scheduler manages recurring jobs. Therefore, Pub\/Sub message ordering is the correct feature when applications depend on a defined sequence of related messages.<\/span><\/p>\n<h3><b>Q387. A company wants to run a containerized HTTP application without managing the underlying servers or Kubernetes cluster. Which service should it use?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Cloud Run<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Compute Engine<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> GKE Standard<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud Storage<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Run is a managed serverless platform designed to run containerized applications without requiring users to manage servers or a Kubernetes cluster. It automatically manages infrastructure and can scale application instances based on incoming requests and configured settings. This makes Cloud Run particularly suitable for stateless HTTP applications packaged as containers. Compute Engine requires VM management, GKE provides Kubernetes environments, and Cloud Storage is an object storage service. Therefore, Cloud Run is the best choice when an organization wants to deploy a containerized HTTP application while minimizing infrastructure and cluster administration.<\/span><\/p>\n<h3><b>Q388. A Cloud Run service has a new version that must receive only a small percentage of production traffic for testing. Which feature should be used?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Traffic splitting between revisions<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud Storage lifecycle management<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud DNS forwarding<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud NAT<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Run supports traffic splitting between service revisions, allowing different percentages of incoming requests to be directed to different deployed versions. This can be useful for gradual rollouts, canary testing, and validating a new revision before directing all production traffic to it. For example, a team can route a small percentage of traffic to a new revision while keeping most traffic on the established version. Cloud Storage lifecycle management automates object actions, Cloud DNS manages name resolution, and Cloud NAT provides outbound connectivity. Therefore, traffic splitting between Cloud Run revisions is the appropriate feature for controlled production testing.<\/span><\/p>\n<h3><b>Q389. A Cloud Run application needs a password stored securely rather than embedded directly in the container image. Which service should be used?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Secret Manager<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud CDN<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud Scheduler<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud DNS<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Secret Manager provides a centralized and secure way to store sensitive information such as passwords, API keys, tokens, and other application secrets. A Cloud Run service can be configured to access required secrets at runtime instead of embedding sensitive values directly into source code or container images. This reduces the risk of accidentally exposing credentials through source repositories, container layers, or configuration files. Cloud CDN handles content caching, Cloud Scheduler manages recurring tasks, and Cloud DNS manages domain name resolution. Therefore, Secret Manager is the appropriate service for securely storing a password required by a Cloud Run application.<\/span><\/p>\n<h3><b>Q390. A company wants to automatically scale a GKE workload based on CPU utilization. Which Kubernetes feature should be considered?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Horizontal Pod Autoscaler<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud Storage Versioning<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud NAT<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud DNS<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Kubernetes Horizontal Pod Autoscaler, or HPA, automatically adjusts the number of pod replicas based on observed resource utilization or other supported metrics. For example, an application can be configured to increase its number of pods when CPU utilization rises above a defined target and reduce replicas when demand decreases. This helps applications respond to changing workloads without requiring administrators to manually change replica counts. Cloud Storage Versioning, Cloud NAT, and Cloud DNS provide unrelated storage and networking capabilities. Therefore, Horizontal Pod Autoscaler is the appropriate Kubernetes feature for automatically scaling pods based on CPU utilization.<\/span><\/p>\n<h3><b>Q391. A GKE cluster needs to automatically add or remove worker nodes as the workload&#8217;s scheduling requirements change. Which feature should be used?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Cluster Autoscaler<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud CDN<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud KMS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud Scheduler<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">GKE Cluster Autoscaler adjusts the number of nodes in a node pool based on the scheduling requirements of workloads. If pods cannot be scheduled because additional capacity is needed, the cluster can add nodes according to configured limits. When nodes are no longer required, the autoscaler can reduce capacity while considering workload scheduling and availability. This differs from Horizontal Pod Autoscaler, which adjusts the number of pods rather than the underlying nodes. Cloud CDN, Cloud KMS, and Cloud Scheduler provide different functions. Therefore, Cluster Autoscaler is the appropriate feature for automatically adjusting GKE node capacity.<\/span><\/p>\n<h3><b>Q392. A company wants a GKE cluster whose control plane is not directly exposed through a public endpoint. Which configuration should be considered?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Private cluster<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Public Cloud Storage bucket<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud CDN<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> External HTTP load balancer<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A GKE private cluster is designed to reduce direct public exposure of cluster infrastructure. In a private cluster configuration, nodes use internal IP addresses, and the cluster can be configured with private connectivity for control-plane communication. This can improve the network security posture of workloads by limiting direct exposure to the public internet. Additional access mechanisms may be required for administrators or external systems depending on the architecture. A public Cloud Storage bucket, Cloud CDN, and external load balancer serve different purposes. Therefore, a private GKE cluster is the appropriate configuration when minimizing public exposure of cluster infrastructure is required.<\/span><\/p>\n<h3><b>Q393. A GKE application must authenticate to Google Cloud APIs without storing service account keys inside Kubernetes pods. Which approach is recommended?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Workload Identity Federation for GKE<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Store a JSON key in every pod<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Use a public Cloud Storage bucket<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Assign Owner permissions to every pod<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Workload Identity Federation for GKE allows Kubernetes workloads to access Google Cloud resources using federated identities instead of distributing long-lived service account keys to pods. This provides a more secure authentication model because credentials do not need to be manually stored inside containers. Administrators can associate Kubernetes workloads with appropriate Google Cloud identities and grant only the permissions required by the application. Storing JSON keys in pods introduces credential-management risks, while public buckets and broad Owner permissions are inappropriate security practices. Therefore, Workload Identity Federation for GKE is the recommended approach for secure workload authentication.<\/span><\/p>\n<h3><b>Q394. A company needs to store Docker container images and manage them as versioned artifacts in Google Cloud. Which service should be used?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Artifact Registry<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud Logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud DNS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud Scheduler<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Artifact Registry is a managed service for storing, managing, and securing software artifacts, including container images and supported language packages. Development teams can push container images to repositories, assign versions or tags, and allow deployment platforms such as Cloud Run or GKE to retrieve the required images. This provides centralized artifact management and supports integration with build and deployment pipelines. Cloud Logging stores and analyzes logs, Cloud DNS manages DNS records, and Cloud Scheduler runs recurring jobs. Therefore, Artifact Registry is the appropriate service for storing and managing Docker container images in Google Cloud.<\/span><\/p>\n<h3><b>Q395. A development team wants a build to start automatically whenever new code is pushed to a source repository. Which Google Cloud feature should be configured?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Cloud Build trigger<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud NAT<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud DNS private zone<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Persistent Disk snapshot<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Build triggers can automatically start build processes when specified events occur in a connected source repository. A trigger can be configured to respond to events such as commits or changes to selected branches, allowing the development team to automate the build portion of a CI\/CD pipeline. This reduces the need for developers to manually start builds after every code change. Cloud NAT provides outbound connectivity, Cloud DNS manages name resolution, and Persistent Disk snapshots protect VM disk data. Therefore, a Cloud Build trigger is the correct feature for automatically starting builds when new code is pushed.<\/span><\/p>\n<h3><b>Q396. A company wants to monitor VM CPU utilization and receive a notification when utilization remains above a defined threshold. Which Google Cloud service should be used?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Cloud Monitoring<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud Storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud DNS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud Build<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Monitoring collects metrics from Google Cloud resources and supports dashboards, alerting policies, and notifications. An administrator can create an alerting policy that evaluates VM CPU utilization and sends a notification when the metric meets a defined threshold or condition. This helps operations teams identify resource pressure and respond before application performance is significantly affected. Cloud Storage is used for object storage, Cloud DNS manages DNS resolution, and Cloud Build automates software builds. Therefore, Cloud Monitoring is the appropriate service for tracking VM CPU utilization and generating threshold-based alerts.<\/span><\/p>\n<h3><b>Q397. A team needs centralized storage and search capabilities for application and infrastructure logs across multiple Google Cloud resources. Which service should be used?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Cloud Logging<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud NAT<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud Scheduler<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud Run<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Logging provides centralized collection, storage, searching, and analysis capabilities for logs generated by Google Cloud resources and applications. Administrators can use Logs Explorer and other logging features to investigate errors, troubleshoot services, and analyze operational activity. Log sinks can also route selected logs to supported destinations for long-term retention or further analysis. Cloud NAT provides network address translation, Cloud Scheduler executes recurring tasks, and Cloud Run runs containers. Therefore, Cloud Logging is the appropriate service when an organization needs centralized log management and search across its Google Cloud environment.<\/span><\/p>\n<h3><b>Q398. An administrator wants to identify which user changed a Google Cloud resource and determine when the change occurred. Which capability should be examined?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Cloud Audit Logs<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud CDN<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud NAT<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> BigQuery clustering<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Audit Logs provide records of activities performed against Google Cloud resources. They can help administrators determine which identity performed an action, what operation occurred, and when the activity took place, depending on the applicable audit log type and service. These records are valuable for security investigations, troubleshooting, compliance, and accountability. Cloud CDN manages content caching, Cloud NAT provides outbound network translation, and BigQuery clustering organizes analytical data. Therefore, Cloud Audit Logs should be examined when an administrator needs to investigate who changed a resource and when the change occurred.<\/span><\/p>\n<h3><b>Q399. A company wants to prevent users from accidentally assigning external IP addresses to Compute Engine resources across multiple projects. Which control should be considered?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Organization Policy Service<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud Scheduler<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud CDN<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> Cloud Storage Versioning<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Organization Policy Service can enforce constraints across organizations, folders, and projects to prevent configurations that violate organizational requirements. An organization can use an appropriate policy constraint to restrict external IP address usage where supported, helping prevent users from accidentally exposing resources to the public internet. Applying the policy at a higher level can provide consistent governance across multiple projects through policy inheritance. Cloud Scheduler manages recurring tasks, Cloud CDN caches content, and Cloud Storage Versioning preserves previous object versions. Therefore, Organization Policy Service is the appropriate centralized governance mechanism for restricting unwanted external IP configurations.<\/span><\/p>\n<h3><b>Q400. A system administrator needs to run a command against a Compute Engine VM directly from the command line without opening the Google Cloud console. Which tool is most appropriate?<\/b><\/h3>\n<p><b>1)<\/b><span style=\"font-weight: 400;\"> Google Cloud CLI<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>2)<\/b><span style=\"font-weight: 400;\"> Cloud Storage<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>3)<\/b><span style=\"font-weight: 400;\"> Cloud DNS<\/span><span style=\"font-weight: 400;\"><br \/>\n<\/span><b>4)<\/b><span style=\"font-weight: 400;\"> BigQuery<\/span><\/p>\n<p><b>Correct Answer: 1)<\/b><\/p>\n<p><b>Explanation:<\/b><\/p>\n<p><span style=\"font-weight: 400;\">The Google Cloud CLI provides command-line tools for managing and interacting with Google Cloud resources. Administrators can use commands such as <\/span><span style=\"font-weight: 400;\">gcloud compute ssh<\/span><span style=\"font-weight: 400;\"> to connect to Compute Engine instances and execute commands without relying on the graphical Google Cloud console. The CLI is also useful for automation, scripting, deployment workflows, and routine administration. Cloud Storage provides object storage, Cloud DNS manages DNS services, and BigQuery supports analytics. Therefore, the Google Cloud CLI is the appropriate tool when an administrator needs command-line access to manage or connect to a Compute Engine VM.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Google Associate Cloud Engineer Exam Dumps and Practice Test Dumps &nbsp; Q381. Which Google Cloud service is designed to execute code in response to events without requiring management of servers? 1) Cloud Functions 2) Compute Engine 3) Cloud Storage 4) Cloud DNS Correct Answer: 1) Explanation: Cloud Functions is a serverless compute service [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13002"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=13002"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13002\/revisions"}],"predecessor-version":[{"id":13009,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/13002\/revisions\/13009"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=13002"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=13002"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=13002"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}