
[UPDATED 2023] Read Associate-Cloud-Engineer Study Guide Cover to Cover as Literally
100% Real & Accurate Associate-Cloud-Engineer Questions and Answers with Free and Fast Updates
Google Associate Cloud Engineer Exam is a certification that validates the skills of an individual to work effectively as a cloud engineer on the Google Cloud Platform. Associate-Cloud-Engineer exam is intended for individuals who have a good understanding of cloud computing concepts and are familiar with the tools and services offered by the Google Cloud Platform. Google Associate Cloud Engineer Exam certification exam evaluates the candidate's knowledge on various topics such as computing, networking, storage, security, and deployment.
NEW QUESTION # 47
You are working with a Cloud SQL MySQL database at your company. You need to retain a month-end copy of the database for three years for audit purposes. What should you do?
- A. Set up an export job for the first of the month.
Write the export file to an Archive class Cloud Storage bucket. - B. Save the automatic first-of-the-month backup for three years.
Store the backup file in an Archive class Cloud Storage bucket. - C. Convert the automatic first-of-the-month backup to an export file.
Write the export file to a Coldline class Cloud Storage bucket. - D. Set up an on-demand backup for the first of the month.
Write the backup to an Archive class Cloud Storage bucket.
Answer: B
NEW QUESTION # 48
You need to create an autoscaling managed instance group for an HTTPS web application. You want to make sure that unhealthy VMs are recreated. What should you do?
- A. In the Instance Template, add the label `health-check'.
- B. In the Instance Template, add a startup script that sends a heartbeat to the metadata server.
- C. Select Multi-Zone instead of Single-Zone when creating the Managed Instance Group.
- D. Create a health check on port 443 and use that when creating the Managed Instance Group.
Answer: D
Explanation:
MIGs support autohealing, load balancing, autoscaling, and auto-updating. no the Images templates, this is set up in the MIG.
NEW QUESTION # 49
You're attempting to set up a File based Billing Export. Which of the following components are required?
- A. A Cloud Storage bucket.
- B. A Budget and at least one alert.
- C. A BigQuery dataset.
- D. A report prefix.
Answer: D
NEW QUESTION # 50
Your company runs one batch process in an on-premises server that takes around 30 hours to complete. The task runs monthly, can be performed offline, and must be restarted if interrupted. You want to migrate this workload to the cloud while minimizing cost. What should you do?
- A. Migrate the workload to a Google Kubernetes Engine cluster with Preemptible nodes.
- B. Migrate the workload to a Compute Engine Preemptible VM.
- C. Create an Instance Template with Preemptible VMs On. Create a Managed Instance Group from the template and adjust Target CPU Utilization. Migrate the workload.
- D. Migrate the workload to a Compute Engine VM. Start and stop the instance as needed.
Answer: C
Explanation:
Install the workload in a compute engine VM, start and stop the instance as needed, because as per the question the VM runs for 30 hours, process can be performed offline and should not be interrupted, if interrupted we need to restart the batch process again. Preemptible VMs are cheaper, but they will not be available beyond 24hrs, and if the process gets interrupted the preemptible VM will restart.
NEW QUESTION # 51
You have one GCP account running in your default region and zone and another account running in a non-default region and zone. You want to start a new Compute Engine instance in these two Google Cloud Platform accounts using the command line interface. What should you do?
- A. Create two configurations using gcloud config configurations create [NAME]. Run gcloud config configurations activate [NAME] to switch between accounts when running the commands to start the Compute Engine instances.
- B. Activate two configurations using gcloud configurations activate [NAME]. Run gcloud config list to start the Compute Engine instances.
- C. Create two configurations using gcloud config configurations create [NAME]. Run gcloud configurations list to start the Compute Engine instances.
- D. Activate two configurations using gcloud configurations activate [NAME]. Run gcloud configurations list to start the Compute Engine instances.
Answer: A
Explanation:
Explanation
"Run gcloud configurations list to start the Compute Engine instances". How the heck are you expecting to
"start" GCE instances doing "configuration list".
Each gcloud configuration has a 1 to 1 relationship with the region (if a region is defined). Since we have two different regions, we would need to create two separate configurations using gcloud config configurations createRef: https://cloud.google.com/sdk/gcloud/reference/config/configurations/create Secondly, you can activate each configuration independently by running gcloud config configurations activate
[NAME]Ref: https://cloud.google.com/sdk/gcloud/reference/config/configurations/activate Finally, while each configuration is active, you can run the gcloud compute instances start [NAME] command to start the instance in the configurations region.https://cloud.google.com/sdk/gcloud/reference/compute/instances/start
NEW QUESTION # 52
Your company has embraced a hybrid cloud strategy where some of the applications are deployed on Google Cloud. A Virtual Private Network (VPN) tunnel connects your Virtual Private Cloud (VPC) in Google Cloud with your company's on-premises network. Multiple applications in Google Cloud need to connect to an on- premises database server, and you want to avoid having to change the IP configuration in all of your applications when the IP of the database changes. What should you do?
- A. Create a private zone on Cloud DNS, and configure the applications with the DNS name.
- B. Configure Cloud NAT for all subnets of your VPC to be used when egressing from the VM instances.
- C. Query the Compute Engine internal DNS from the applications to retrieve the IP of the database.
- D. Configure the IP of the database as custom metadata for each instance, and query the metadata server.
Answer: B
NEW QUESTION # 53
Your company is moving its entire workload to Compute Engine. Some servers should be accessible through the Internet, and other servers should only be accessible over the internal network. All servers need to be able to talk to each other over specific ports and protocols. The current on-premises network relies on a demilitarized zone (DMZ) for the public servers and a Local Area Network (LAN) for the private servers. You need to design the networking infrastructure on Google Cloud to match these requirements. What should you do?
- A. 1. Create a VPC with a subnet for the DMZ and another VPC with a subnet for the LAN. 2. Set up firewall rules to open up relevant traffic between the DMZ and the LAN subnets, and another firewall rule to allow public egress traffic for the DMZ.
- B. 1. Create a single VPC with a subnet for the DMZ and a subnet for the LAN. 2. Set up firewall rules to open up relevant traffic between the DMZ and the LAN subnets, and another firewall rule to allow public egress traffic for the DMZ.
- C. 1. Create a single VPC with a subnet for the DMZ and a subnet for the LAN. 2. Set up firewall rules to open up relevant traffic between the DMZ and the LAN subnets, and another firewall rule to allow public ingress traffic for the DMZ.
- D. 1. Create a VPC with a subnet for the DMZ and another VPC with a subnet for the LAN. 2. Set up firewall rules to open up relevant traffic between the DMZ and the LAN subnets, and another firewall rule to allow public ingress traffic for the DMZ.
Answer: D
Explanation:
https://cloud.google.com/vpc/docs/vpc-peering
NEW QUESTION # 54
You deployed an LDAP server on Compute Engine that is reachable via TLS through port 636 using UDP.
You want to make sure it is reachable by clients over that port. What should you do?
- A. Create a route called allow-udp-636 and set the next hop to be the VM instance running the LDAP server.
- B. Add a network tag of your choice to the instance. Create a firewall rule to allow ingress on UDP port
636 for that network tag. - C. Add a network tag of your choice to the instance running the LDAP server. Create a firewall rule to allow egress on UDP port 636 for that network tag.
- D. Add the network tag allow-udp-636 to the VM instance running the LDAP server.
Answer: B
NEW QUESTION # 55
You have a Dockerfile that you need to deploy on Kubernetes Engine. What should you do?
- A. Use gcloud app deploy <dockerfilename>.
- B. Create a docker image from the Dockerfile and upload it to Cloud Storage.
Create a Deployment YAML file to point to that image.
Use kubectl to create the deployment with that file. - C. Use kubectl app deploy <dockerfilename>.
- D. Create a docker image from the Dockerfile and upload it to Container Registry.
Create a Deployment YAML file to point to that image.
Use kubectl to create the deployment with that file.
Answer: D
Explanation:
https://cloud.google.com/kubernetes-engine/docs/tutorials/hello-app
NEW QUESTION # 56
Your company has a single sign-on (SSO) identity provider that supports Security Assertion Markup Language (SAML) integration with service providers. Your company has users in Cloud Identity. You would like users to authenticate using your company's SSO provider. What should you do?
- A. Obtain OAuth 2.0 credentials, configure the user consent screen, and set up OAuth 2.0 for Web Server Applications.
- B. In Cloud Identity, set up SSO with Google as an identity provider to access custom SAML apps.
- C. Obtain OAuth 2.0 credentials, configure the user consent screen, and set up OAuth 2.0 for Mobile & Desktop Apps.
- D. In Cloud Identity, set up SSO with a third-party identity provider with Google as a service provider.
Answer: D
Explanation:
https://support.google.com/cloudidentity/answer/6262987?hl=en&ref_topic=7558767
NEW QUESTION # 57
You built an application on Google Cloud Platform that uses Cloud Spanner. Your support team needs to monitor the environment but should not have access to table data. You need a streamlined solution to grant the correct permissions to your support team, and you want to follow Google-recommended practices. What should you do?
- A. Add the support team group to the roles/spanner.databaseReader role.
- B. Add the support team group to the roles/monitoring.viewer role
- C. Add the support team group to the roles/stackdriver.accounts.viewer role.
- D. Add the support team group to the roles/spanner.databaseUser role.
Answer: B
Explanation:
Explanation
roles/monitoring.viewer provides read-only access to get and list information about all monitoring data and configurations. This role provides monitoring access and fits our requirements.
roles/monitoring.viewer. is the right answer.
Ref: https://cloud.google.com/iam/docs/understanding-roles#cloud-spanner-roles
NEW QUESTION # 58
You are building an archival solution for your data warehouse and have selected Cloud Storage to archive your data. Your users need to be able to access this archived data once a quarter for some regulatory requirements.
You want to select a cost-efficient option. Which storage option should you use?
- A. Multi-Regional Storage
- B. Nearline Storage
- C. Cold Storage
- D. Regional Storage
Answer: C
Explanation:
Nearline, Coldline, and Archive offer ultra low-cost, highly-durable, highly available archival storage. For data accessed less than once a year, Archive is a cost-effective storage option for long-term preservation of data.
Coldline is also ideal for cold storage-data your business expects to touch less than once a quarter. For warmer storage, choose Nearline: data you expect to access less than once a month, but possibly multiple times throughout the year. All storage classes are available across all GCP regions and provide unparalleled sub-second access speeds with a consistent API.
Reference: https://cloud.google.com/storage/archival
NEW QUESTION # 59
A colleague handed over a Google Cloud Platform project for you to maintain. As part of a security checkup, you want to review who has been granted the Project Owner role. What should you do?
- A. In the console, validate which SSH keys have been stored as project-wide keys.
- B. Use the command gcloud projects get-iam-policy to view the current role assignments.
- C. Enable Audit Logs on the IAM & admin page for all resources, and validate the results.
- D. Navigate to Identity-Aware Proxy and check the permissions for these resources.
Answer: A
NEW QUESTION # 60
You are developing a financial trading application that will be used globally. Data is stored and queried using a relational structure, and clients from all over the world should get the exact identical state of the data. The application will be deployed in multiple regions to provide the lowest latency to end users. You need to select a storage option for the application data while minimizing latency. What should you do?
- A. Use Cloud Spanner for data storage.
- B. Use Firestore for data storage.
- C. Use Cloud Bigtable for data storage.
- D. Use Cloud SQL for data storage.
Answer: A
Explanation:
Cloud Spanner, keywords are globally, relational structure and lastly "clients from all over the world should get the exact identical state of the data" which implies strong consistency is needed.
NEW QUESTION # 61
A colleague handed over a Google Cloud Platform project for you to maintain. As part of a security checkup, you want to review who has been granted the Project Owner role. What should you do?
- A. In the console, validate which SSH keys have been stored as project-wide keys.
- B. Navigate to Identity-Aware Proxy and check the permissions for these resources.
- C. Use the command gcloud projects get-iam-policy to view the current role assignments.
- D. Enable Audit Logs on the IAM & admin page for all resources, and validate the results.
Answer: B
NEW QUESTION # 62
You need to create a copy of a custom Compute Engine virtual machine (VM) to facilitate an expected increase in application traffic due to a business acquisition. What should you do?
- A. Create a Compute Engine snapshot of your base VM. Create your images from that snapshot.
- B. Create a custom Compute Engine image from a snapshot. Create your instances from that image.
- C. Create a custom Compute Engine image from a snapshot. Create your images from that image.
- D. Create a Compute Engine snapshot of your base VM. Create your instances from that snapshot.
Answer: B
Explanation:
A custom image belongs only to your project. To create an instance with a custom image, you must first have a custom image.
Reference:
Preparing your instance for an image
You can create an image from a disk even while it is attached to a running VM instance. However, your image will be more reliable if you put the instance in a state that is easier for the image to capture. Use one of the following processes to prepare your boot disk for the image:
Stop the instance so that it can shut down and stop writing any data to the persistent disk.
If you can't stop your instance before you create the image, minimize the amount of writes to the disk and sync your file system.
Pause apps or operating system processes that write data to that persistent disk.
Run an app flush to disk if necessary. For example, MySQL has a FLUSH statement. Other apps might have similar processes.
Stop your apps from writing to your persistent disk.
Run sudo sync.
After you prepare the instance, create the image.
https://cloud.google.com/compute/docs/images/create-delete-deprecate-private-images#prepare_instance_for_image
NEW QUESTION # 63
You want to deploy an application on Cloud Run that processes messages from a Cloud Pub/Sub topic. You want to follow Google-recommended practices. What should you do?
- A. 1. Create a Cloud Function that uses a Cloud Pub/Sub trigger on that topic.2. Call your application on Cloud Run from the Cloud Function for every message.
- B. 1. Create a service account.2. Give the Cloud Run Invoker role to that service account for your Cloud Run application.3. Create a Cloud Pub/Sub subscription that uses that service account and uses your Cloud Run application as the push endpoint.
- C. 1. Deploy your application on Cloud Run on GKE with the connectivity set to Internal.2. Create a Cloud Pub/Sub subscription for that topic.3. In the same Google Kubernetes Engine cluster as your application, deploy a container that takes the messages and sends them to your application.
- D. 1. Grant the Pub/Sub Subscriber role to the service account used by Cloud Run.2. Create a Cloud Pub/Sub subscription for that topic.3. Make your application pull messages from that subscription.
Answer: B
Explanation:
Explanation
https://cloud.google.com/run/docs/tutorials/pubsub#integrating-pubsub
1. Create a service account. 2. Give the Cloud Run Invoker role to that service account for your Cloud Run application. 3. Create a Cloud Pub/Sub subscription that uses that service account and uses your Cloud Run application as the push endpoint.
NEW QUESTION # 64
You need to create a new billing account and then link it with an existing Google Cloud Platform project.
What should you do?
- A. Verify that you are Project Billing Manager for the GCP project. Create a new billing account and link the new billing account to the existing project.
- B. Verify that you are Billing Administrator for the billing account. Create a new project and link the new project to the existing billing account.
- C. Verify that you are Billing Administrator for the billing account. Update the existing project to link it to the existing billing account.
- D. Verify that you are Project Billing Manager for the GCP project. Update the existing project to link it to the existing billing account.
Answer: B
NEW QUESTION # 65
Your company set up a complex organizational structure on Google Could Platform. The structure includes hundreds of folders and projects. Only a few team members should be able to view the hierarchical structure. You need to assign minimum permissions to these team members and you want to follow Google-recommended practices. What should you do?
- A. Add the users to roles/iam.roleViewer role.
- B. Add the users to a group, and add this group to roles/browser role.
- C. Add the users to a group, and add this group to roles/iam.roleViewer role.
- D. Add the users to roles/browser role.
Answer: B
Explanation:
We need to apply the GCP Best practices. roles/browser Browser Read access to browse the hierarchy for a project, including the folder, organization, and IAM policy. This role doesn't include permission to view resources in the project. https://cloud.google.com/iam/docs/understanding-roles
NEW QUESTION # 66
You are developing a new web application that will be deployed on Google Cloud Platform. As part of your release cycle, you want to test updates to your application on a small portion of real user traffic. The majority of the users should still be directed towards a stable version of your application. What should you do?
- A. Deploy the application on Kubernetes Engine For a now release, create a new deployment for the new version Update the service e to use the now deployment.
- B. Deploy me application on App Engine For each update, create a new version of the same service Configure traffic splitting to send a small percentage of traffic to the new version
- C. Deploy the application on Kubernetes Engine For a new release, update the deployment to use the new version
- D. Deploy the application on App Engine For each update, create a new service Configure traffic splitting to send a small percentage of traffic to the new service.
Answer: B
Explanation:
Explanation
Keyword, Version, traffic splitting, App Engine supports traffic splitting for versions before releasing.
NEW QUESTION # 67
A company has a website running on Amazon EC2. The application DNS name points to an Elastic IP address associated with the EC2 instance. In the event of an attack on the website coming from a specific IP address, the company wants a way to block the offending IP address.
Which tool or service should a Solutions Architect recommend to block the IP address?
- A. Security groups
- B. Network ACL
- C. AWS Shield
- D. AWS WAF
Answer: D
NEW QUESTION # 68
You are storing sensitive information in a Cloud Storage bucket. For legal reasons, you need to be able to record all requests that read any of the stored data. You want to make sure you comply with these requirements. What should you do?
- A. Scan the bucket using the Data Loss Prevention API.
- B. Enable the Identity Aware Proxy API on the project.
- C. Allow only a single Service Account access to read the data.
- D. Enable Data Access audit logs for the Cloud Storage API.
Answer: D
Explanation:
Explanation/Reference: https://cloud.google.com/storage/docs/audit-logs
NEW QUESTION # 69
You have a web application deployed as a managed instance group. You have a new version of the application to gradually deploy. Your web application is currently receiving live web traffic.
You want to ensure that the available capacity does not decrease during the deployment. What should you do?
- A. Create a new instance template with the new application version.
Update the existing managed instance group with the new instance template.
Delete the instances in the managed instance group to allow the managed instance group to recreate the instance using the new instance template. - B. Perform a rolling-action start-update with maxSurge set to 0 and maxUnavailable set to 1.
- C. Create a new managed instance group with an updated instance template.
Add the group to the backend service for the load balancer.
When all instances in the new managed instance group are healthy, delete the old managed instance group. - D. Perform a rolling-action start-update with maxSurge set to 1 and maxUnavailable set to 0.
Answer: D
Explanation:
We need to ensure the global capacity remains intact, for that reason we need to establish maxUnavailable to 0. On the other hand, we need to ensure new instances can be created. We do that by establishing the maxSurge to 1.
Option C is more expensive and more difficult to set up and option D won't meet requirements since it won't keep global capacity intact.
https://cloud.google.com/compute/docs/instance-groups/rolling-out-updates-to-managed- instance-groups#options
NEW QUESTION # 70
You need to create a custom IAM role for use with a GCP service. All permissions in the role must be suitable for production use. You also want to clearly share with your organization the status of the custom role. This will be the first version of the custom role. What should you do?
- A. Use permissions in your role that use the 'supported' support level for role permissions. Set the role stage to BETA while testing the role permissions.
- B. Use permissions in your role that use the 'testing' support level for role permissions. Set the role stage to BETA while testing the role permissions.
- C. Use permissions in your role that use the 'testing' support level for role permissions. Set the role stage to ALPHA while testing the role permissions.
- D. Use permissions in your role that use the 'supported' support level for role permissions. Set the role stage to ALPHA while testing the role permissions.
Answer: D
Explanation:
Explanation
When setting support levels for permissions in custom roles, you can set to one of SUPPORTED, TESTING or NOT_SUPPORTED.
Ref: https://cloud.google.com/iam/docs/custom-roles-permissions-support
NEW QUESTION # 71
......
Reliable Study Materials for Associate-Cloud-Engineer Exam Success For Sure: https://www.vceengine.com/Associate-Cloud-Engineer-vce-test-engine.html
Get Unlimited Access to Associate-Cloud-Engineer Certification Exam Cert Guide: https://drive.google.com/open?id=1VarVX1ywXRtqahK0oXfsLpnufNPXrTWu
