Free CLOUD-DIGITAL-LEADER Exam Braindumps (page: 28)

Page 27 of 104

An organization wants to scale their existing virtual machine architecture as quickly as possible.
Why should the organization use VMware Engine?

  1. To archive virtual machine instances.
  2. To deploy custom APIs seamlessly.
  3. To migrate virtual machines to containers.
  4. To replatform virtual machines as they are.

Answer(s): D

Explanation:

VMware Engine helps migrate and run virtual machines in Google Cloud with minimal changes to the VM architecture.

https://cloud.google.com/learn/what-is-a-virtual-machine



Your Google Cloud Platform [GCP] admin has to manage a bunch of API keys for external services that are accessed by different applications, which are used by a few teams.
What is the best way to manage them?

  1. Share the information in a Github repository and grant access to the repo in IAM as required.
  2. Store the information in Secret Manager and give IAM read permissions as re-quired.
  3. Store the information in Kubernetes Secrets and only grant read permissions to users as required.
  4. Encrypt the information and store it in Cloud Storage for centralized access. Give the decrypt key only to the users who need to access it.

Answer(s): B

Explanation:

Store the information in Secret Manager is a secure and convenient storage system for API keys, passwords, certificates, and other sensitive data. Secret Manager provides a central place and single source of truth to manage access, and audit secrets across Google Cloud.
https://cloud.google.com/secret-manager



What are the key features of Google Cloud Identity.

  1. Multi-factor authentication (MFA)
  2. Single sign-on (SSO)
  3. Works with your favorite apps and Endpoint management
  4. All of the Above

Answer(s): D

Explanation:

Cloud Identity:
A unified identity, access, app, and endpoint management (IAM/EMM) platform.
- Give users easy access to apps with single sign-on.
- Multi-factor authentication protects user and company data.
- Endpoint management enforces policies for personal and corporate devices KEY FEATURES :

Modernize IT and strengthen security

Multi-factor authentication (MFA)
Help protect your user accounts and company data with a wide variety of MFA verification methods such as push notifications, Google Authenticator, phishing-resistant Titan Security Keys, and using your Android or iOS device as a security key.
Endpoint management
Improve your company's device security posture on Android, iOS, and Windows devices using a unified console. Set up devices in minutes and keep your company data more secure with endpoint management. Enforce security policies, wipe company data, deploy apps, view reports, and export details.
Single sign-on (SSO)
Enable employees to work from virtually anywhere, on any device, with single sign-on to thousands of pre-integrated apps, both in the cloud and on-premises.
Works with your favorite apps
Cloud Identity integrates with hundreds of cloud applications out of the box--and we're constantly adding more to the list so you can count on us to be your single identity platform today and in the future.



A partner of yours used to have their own private data center. Your company was already on Google Cloud and now they have also moved to Google Cloud. You are investigating whether there are ways to collaborate better or shared services.
What would be one good option to consider?

  1. Use Private Service Access within Google Cloud.
  2. Use VPC Peering to share resources privately between your two organizations.
  3. Use public IP addresses as before. It will automatically be routed internally only.
  4. Use VPC Shared Networks to share common resources.

Answer(s): B

Explanation:

VPC Network Peering allows internal IP address connectivity across two Virtual Private Cloud (VPC)

networks regardless of whether they belong to the same project or the same organization. -> Shared VPC is only within an organization - it allows an organization to connect resources from multiple projects to a common Virtual Private Cloud (VPC) network, so that they can communicate with each other securely and efficiently using internal IPs from that network. -> Private Google Access is only to access Google APIs and services


Reference:

-> https://cloud.google.com/vpc/docs/vpc-peering
-> https://cloud.google.com/vpc/docs/private-google-access -> https://cloud.google.com/vpc/docs/shared-vpc






Post your Comments and Discuss Google CLOUD-DIGITAL-LEADER exam with other Community members:

CLOUD-DIGITAL-LEADER Discussions & Posts