{"id":23472,"date":"2026-09-28T07:02:33","date_gmt":"2026-09-28T07:02:33","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=23472"},"modified":"2026-09-28T07:02:33","modified_gmt":"2026-09-28T07:02:33","slug":"google-professional-cloud-developer-practice-test-questions-and-exam-dumps-part15-q281-300","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/google-professional-cloud-developer-practice-test-questions-and-exam-dumps-part15-q281-300\/","title":{"rendered":"Google Professional Cloud Developer Practice Test Questions and Exam Dumps Part15 Q281-300"},"content":{"rendered":"<h2><b>View Full <\/b><a href=\"https:\/\/www.examlabs.com\/professional-cloud-developer-exam-dumps\"><b>Google Professional Cloud Developer Exam Dumps<\/b><\/a><b> and Practice Test Dumps.<\/b><\/h2>\n<p>&nbsp;<\/p>\n<h3><b>Question 281<\/b><\/h3>\n<p><b>Which Google Cloud service is designed to provide a managed environment for deploying containerized web applications and APIs?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Run<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BigQuery<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud KMS<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Run provides a managed platform for deploying and operating containerized applications without requiring developers to manage servers or Kubernetes clusters directly. It is well suited to HTTP services, APIs, and other request-driven workloads packaged as containers. Cloud Run can automatically scale instances according to incoming demand and supports configuration for resources, authentication, networking, revisions, and traffic. Developers remain responsible for the application and container image while Google Cloud manages the underlying infrastructure. This serverless model can simplify deployment and operational management for applications that do not require direct control of the underlying compute infrastructure.<\/span><\/p>\n<h3><b>Question 282<\/b><\/h3>\n<p><b>A developer needs to protect a Cloud Run service from receiving more concurrent traffic than its backend database can handle. Which setting can help?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Maximum instances<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Minimum instances<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Startup CPU boost<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Revision name<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Run maximum instances can limit how many container instances are created for a service. This can help control the amount of concurrent workload reaching a constrained backend such as a database or external API. Without an appropriate limit, Cloud Run may scale out rapidly during traffic increases, potentially creating more backend connections or requests than the dependency can support. Developers should determine the limit from measured capacity rather than selecting an arbitrary value. The setting should be considered alongside connection pooling, request concurrency, backend limits, and expected traffic patterns.<\/span><\/p>\n<h3><b>Question 283<\/b><\/h3>\n<p><b>A Cloud Run application needs to access a private service in a VPC. Which configuration is relevant?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public DNS only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">VPC egress configuration<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Artifact Registry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Run applications that need to reach private resources in a VPC require appropriate outbound VPC connectivity. Developers can configure supported VPC egress options so requests from the Cloud Run service can reach private IP addresses and other resources available through the selected network path. Network routes, firewall rules, and destination permissions must also permit the traffic. This configuration is separate from ingress, which controls how traffic reaches the Cloud Run service. Artifact Registry stores software artifacts, while Cloud CDN and public DNS address content delivery and name-resolution requirements rather than private VPC connectivity.<\/span><\/p>\n<h3><b>Question 284<\/b><\/h3>\n<p><b>Which Cloud Run feature allows a new application version to exist as a separate deployable version?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Revision<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bucket<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Subscription<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Dataset<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Cloud Run revision represents a specific deployed version of a service configuration and container image. Each time a new version is deployed with relevant changes, Cloud Run can create a new revision. Revisions make it possible to test versions independently and control traffic allocation between them. They also provide a useful rollback mechanism because an earlier revision can remain available when the deployment strategy requires it. Developers should treat revisions as immutable deployment versions and use traffic management to control which revision receives production requests. This supports controlled application release processes.<\/span><\/p>\n<h3><b>Question 285<\/b><\/h3>\n<p><b>A developer needs a service to execute a finite batch operation and then stop. Which Cloud Run option matches this workload?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Run service<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Run Job<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud CDN<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">API Gateway<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Run Jobs are designed for containerized workloads that perform tasks and terminate after the work is completed. They are suitable for batch processing, migrations, scheduled calculations, data exports, and similar finite operations. Unlike a continuously available Cloud Run service, a job does not need to remain ready to handle incoming HTTP requests. Developers can configure task count and parallelism to divide and control the workload. Jobs can also be initiated by automation when required. Applications running as jobs should handle retries safely because individual tasks may be retried after failures.<\/span><\/p>\n<h3><b>Question 286<\/b><\/h3>\n<p><b>A Pub\/Sub subscription should receive only events where the <\/b><b>type<\/b><b> message attribute is <\/b><b>invoice.created<\/b><b>. Which feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Subscription filter<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message retention<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Topic label<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Snapshot schedule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pub\/Sub subscription filters allow subscribers to receive messages whose attributes match a defined filtering expression. In this scenario, publishers can attach a type attribute to each message, and the subscription can select only messages representing invoice creation events. This allows different consumers to use the same topic while processing different event categories. Filtering is configured at the subscription rather than publisher level, so publishers can continue publishing a broader stream of events. Developers should ensure that the required attributes are consistently populated and that consumer logic correctly handles the selected event types.<\/span><\/p>\n<h3><b>Question 287<\/b><\/h3>\n<p><b>Which Pub\/Sub capability can help a developer replay messages from an earlier subscription state after correcting consumer code?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Publisher batching<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Subscription seek<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Topic naming<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Message ordering<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Pub\/Sub seek allows a subscription to move its acknowledgment position so that eligible messages from an earlier point can become available for delivery again. This is useful when a consumer has processed messages incorrectly and the developer needs to replay them after fixing the application. Snapshots can also preserve a subscription state that can later be used in replay workflows. Developers must consider message retention because messages are replayable only while they remain available. Replay should also be combined with safe consumer design because previously processed messages may be delivered again and could otherwise produce duplicate side effects.<\/span><\/p>\n<h3><b>Question 288<\/b><\/h3>\n<p><b>A Firestore application must authorize users according to their authenticated identity. Which feature should enforce these client-side access rules?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Scheduler<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firestore Security Rules<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Artifact Registry<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Firestore Security Rules provide authorization controls for client access to Firestore data. Rules can evaluate the authenticated user&#8217;s identity and the requested document or operation before allowing or denying access. Developers can use these rules to enforce requirements such as allowing users to read only their own documents or permitting writes only when specific conditions are satisfied. Security Rules should be tested carefully with both authorized and unauthorized scenarios. Client-side checks alone are insufficient because clients cannot be treated as trusted enforcement points. IAM serves a different purpose for Google Cloud resource-level access.<\/span><\/p>\n<h3><b>Question 289<\/b><\/h3>\n<p><b>A BigQuery table contains years of event data, but most queries retrieve only recent dates. Which design can reduce unnecessary scanning?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Date partitioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Removing all indexes<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Increasing request timeout<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Adding more application servers<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Date partitioning can divide a large BigQuery table into logical partitions based on a date or timestamp field. Queries that restrict the partitioning field to a specific range can potentially scan only the relevant partitions instead of processing the entire table. This is especially useful for application event data, logs, and transactions where time-based queries are common. Developers should select partitioning columns based on actual access patterns and write queries that allow partition pruning. Partitioning does not automatically improve every query, but it can substantially reduce unnecessary processing for suitable time-filtered workloads.<\/span><\/p>\n<h3><b>Question 290<\/b><\/h3>\n<p><b>Which BigQuery feature can organize data within partitions according to frequently filtered columns?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">API quotas<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Clustering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Tasks<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Secret Manager<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">BigQuery clustering organizes table data based on selected columns and can improve processing efficiency for queries that frequently filter or aggregate using those columns. Clustering can be combined with partitioning, allowing partitioning to organize data by a broad dimension such as date while clustering organizes data within partitions according to additional query patterns. Developers should select clustering columns based on common workloads rather than choosing fields arbitrarily. Clustering does not replace appropriate schema design or query optimization, but it can provide additional efficiency for large analytical tables when the selected columns match recurring access patterns.<\/span><\/p>\n<h3><b>Question 291<\/b><\/h3>\n<p><b>A Cloud SQL application needs to avoid opening a new database connection for every incoming request. What should the developer implement?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Connection pooling<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Object versioning<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pub\/Sub filtering<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Trace sampling<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Connection pooling allows an application to reuse a controlled collection of database connections rather than creating a new connection for every request. This can reduce connection establishment overhead and help prevent a Cloud SQL instance from reaching its connection limit. The pool size should be selected according to database capacity, application concurrency, and workload characteristics. Developers should also configure appropriate connection timeouts and handling for stale connections. In serverless environments, multiple application instances may each maintain their own pool, so the total possible number of connections must be considered when configuring Cloud Run scaling and database capacity.<\/span><\/p>\n<h3><b>Question 292<\/b><\/h3>\n<p><b>A GKE application must limit communication between Pods so only explicitly permitted traffic is allowed. Which resource provides this control?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">PersistentVolumeClaim<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NetworkPolicy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">ConfigMap<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Kubernetes NetworkPolicy provides rules that control network traffic involving selected Pods. Developers can use policies to restrict ingress, egress, or both based on supported selectors, namespaces, ports, and other criteria. This helps establish network segmentation within a GKE cluster and reduces unnecessary communication paths between workloads. NetworkPolicy enforcement depends on the cluster&#8217;s networking implementation supporting the feature. Developers should combine network restrictions with application-level authentication and authorization rather than treating network policy as the only security mechanism. ConfigMaps, Services, and PersistentVolumeClaims address configuration, networking endpoints, and storage rather than traffic authorization.<\/span><\/p>\n<h3><b>Question 293<\/b><\/h3>\n<p><b>Which Kubernetes probe should prevent a healthy but temporarily unready Pod from receiving application traffic?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Startup probe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Liveness probe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Readiness probe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Resource limit<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A readiness probe determines whether a Pod is currently prepared to receive traffic. If the readiness check fails, Kubernetes can remove the Pod from the relevant Service endpoints while leaving the container running. This is useful when an application temporarily cannot serve requests because it is initializing, overloaded, or waiting for an essential dependency. A liveness probe has a different purpose: detecting a container that should be restarted. Developers should design readiness checks around actual serving capability rather than simply checking whether the process is running. Proper readiness configuration can reduce failed requests during temporary application conditions.<\/span><\/p>\n<h3><b>Question 294<\/b><\/h3>\n<p><b>A Kubernetes application takes several minutes to initialize. Which probe helps prevent Kubernetes from restarting it before startup completes?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">NetworkPolicy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Readiness probe only<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Startup probe<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A startup probe is intended for applications that require significant time to initialize. Kubernetes can use the startup probe to determine when the application has successfully started before applying normal liveness and readiness checking behavior. This prevents a slow-starting application from being incorrectly treated as failed simply because it has not yet completed initialization. Developers should configure the probe&#8217;s timing and failure thresholds according to measured startup behavior. Once the startup probe succeeds, the regular health probes can provide ongoing monitoring. This is particularly useful for applications with expensive framework or dependency initialization.<\/span><\/p>\n<h3><b>Question 295<\/b><\/h3>\n<p><b>Which Google Cloud capability allows a developer to create a custom IAM role containing selected supported permissions?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Custom roles<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage lifecycle<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pub\/Sub snapshot<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">BigQuery partition<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">IAM custom roles allow organizations to define role permissions specifically for an application&#8217;s or team&#8217;s requirements. This can support least-privilege access when predefined roles contain more permissions than necessary. Developers should first determine whether an existing predefined role already provides the required access because custom roles introduce additional management responsibilities. When creating a custom role, only supported permissions should be included, and the role should be reviewed as application requirements change. Custom roles are especially useful when security requirements demand more precise permission boundaries than broad predefined roles can provide.<\/span><\/p>\n<h3><b>Question 296<\/b><\/h3>\n<p><b>A CI\/CD pipeline needs to pass different deployment project IDs without creating separate Cloud Build configuration files. Which feature supports this?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Build substitutions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Trace<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firestore transactions<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bigtable garbage collection<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Build substitutions allow build configurations to use parameterized values that can change between build executions. A deployment project ID, environment name, image reference, or similar value can be supplied through supported substitution mechanisms rather than hard-coded into multiple copies of the build configuration. This makes CI\/CD definitions more reusable and easier to maintain. Developers should validate supplied values and ensure deployment identities have appropriate permissions for each target project. Substitutions are intended for build-time parameterization and should not be treated as secure storage for passwords, private keys, or other sensitive credentials.<\/span><\/p>\n<h3><b>Question 297<\/b><\/h3>\n<p><b>A Cloud Storage application must automatically remove temporary objects after seven days. Which feature should be configured?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage class<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Lifecycle rule<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Bucket location<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Object metadata only<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 2<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Storage lifecycle rules allow developers to automatically perform actions on objects when specified conditions are met. For temporary files, a rule can delete objects after they reach a defined age, such as seven days. This reduces the need for application code to perform routine cleanup and helps control storage growth. Developers should verify that the retention period is appropriate before enabling automatic deletion because lifecycle actions can remove data that an application still needs. Lifecycle management can be combined with object versioning and other storage controls to establish a broader data-retention strategy.<\/span><\/p>\n<h3><b>Question 298<\/b><\/h3>\n<p><b>A Cloud Run service must call a protected backend without storing a long-lived password in its container. Which identity mechanism should be used?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Service account identity<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Public anonymous access<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Static API key in source code<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Database password in an image<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">A Cloud Run service can use its assigned service account identity when calling another protected Google Cloud service. The calling workload can obtain appropriate short-lived credentials through supported Google Cloud authentication mechanisms, while the receiving service can authorize the identity using IAM or another supported authorization layer. This avoids embedding long-lived passwords or private keys in the container image. Developers should grant the service account only the permissions required for the intended backend operations. This identity-based model also makes credential management and auditing more centralized than manually distributing static secrets among application containers.<\/span><\/p>\n<h3><b>Question 299<\/b><\/h3>\n<p><b>Which Cloud Monitoring feature can notify operators when a monitored metric meets a configured condition?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Alerting policy<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Artifact Registry repository<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Firestore index<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Storage lifecycle rule<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 1<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Monitoring alerting policies define conditions that can trigger notifications when monitored metrics or other supported signals meet specified criteria. Developers can use alerting policies for conditions such as elevated error rates, excessive latency, resource saturation, or availability problems. A well-designed alert should represent a condition that requires investigation or action rather than every minor fluctuation. Notification channels can deliver alerts to configured destinations. Developers should also tune thresholds and evaluation periods to reduce false alarms. Alerting policies complement dashboards and logs by actively notifying teams when important operational conditions occur.<\/span><\/p>\n<h3><b>Question 300<\/b><\/h3>\n<p><b>A developer wants to inspect which application functions consume significant CPU resources in production. Which service is designed for this analysis?<\/b><\/p>\n<ol>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Scheduler<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Storage<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Cloud Profiler<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Pub\/Sub<\/span><\/li>\n<\/ol>\n<p><b>Correct Answer: 3<\/b><\/p>\n<p><b>Explanation<\/b><\/p>\n<p><span style=\"font-weight: 400;\">Cloud Profiler provides runtime profiling information that can help developers understand how an application consumes resources such as CPU. Profiling can reveal code paths or functions that account for significant resource usage and can therefore help identify optimization opportunities. It complements other observability tools because logs show events, metrics show measurements, and traces show request paths, while profiling provides deeper insight into runtime execution. Developers should evaluate profiling data under representative workloads because performance characteristics can vary with traffic and application behavior. The resulting information can guide targeted optimization rather than relying solely on assumptions about bottlenecks.<\/span><\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>View Full Google Professional Cloud Developer Exam Dumps and Practice Test Dumps. &nbsp; Question 281 Which Google Cloud service is designed to provide a managed environment for deploying containerized web applications and APIs? Cloud Storage Cloud Run BigQuery Cloud KMS Correct Answer: 2 Explanation Cloud Run provides a managed platform for deploying and operating containerized [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23472"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=23472"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23472\/revisions"}],"predecessor-version":[{"id":23473,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/23472\/revisions\/23473"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=23472"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=23472"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=23472"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}