Free Google Cloud Architect Professional Exam Braindumps (page: 32)

Page 31 of 68

Your customer is moving their corporate applications to Google Cloud Platform. The security team wants detailed visibility of all projects in the organization. You provision the Google Cloud Resource Manager and set up yourself as the org admin.
What Google Cloud Identity and Access Management (Cloud IAM) roles should you give to the security team'?

  1. Org viewer, project owner
  2. Org viewer, project viewer
  3. Org admin, project browser
  4. Project owner, network admin

Answer(s): B

Explanation:

https://cloud.google.com/iam/docs/using-iam-securely



Your company places a high value on being responsive and meeting customer needs quickly. Their primary business objectives are release speed and agility. You want to reduce the chance of security errors being accidentally introduced.
Which two actions can you take? Choose 2 answers

  1. Ensure every code check-in is peer reviewed by a security SME.
  2. Use source code security analyzers as part of the CI/CD pipeline.
  3. Ensure you have stubs to unit test all interfaces between components.
  4. Enable code signing and a trusted binary repository integrated with your CI/CD pipeline.
  5. Run a vulnerability security scanner as part of your continuous-integration /continuous-delivery (CI/CD) pipeline.

Answer(s): B,E

Explanation:

https://docs.microsoft.com/en-us/vsts/articles/security-validation-cicd-pipeline?view=vsts



You are helping the QA team to roll out a new load-testing tool to test the scalability of your primary cloud services that run on Google Compute Engine with Cloud Bigtable.
Which three requirements should they include? Choose 3 answers

  1. Ensure that the load tests validate the performance of Cloud Bigtable.
  2. Create a separate Google Cloud project to use for the load-testing environment.
  3. Schedule the load-testing tool to regularly run against the production environment.
  4. Ensure all third-party systems your services use are capable of handling high load.
  5. Instrument the production services to record every transaction for replay by the load-testing tool.
  6. Instrument the load-testing tool and the target services with detailed logging and metrics collection.

Answer(s): A,B,F



You want to make a copy of a production Linux virtual machine in the US-Central region. You want to manage and replace the copy easily if there are changes on the production virtual machine. You will deploy the copy as a new instances in a different project in the US-East region.
What steps must you take?

  1. Use the Linux dd and netcat command to copy and stream the root disk contents to a new virtual machine instance in the US-East region.
  2. Create a snapshot of the root disk and select the snapshot as the root disk when you create a new virtual machine instance in the US-East region.
  3. Create an image file from the root disk with Linux dd command, create a new disk from the image file, and use it to create a new virtual machine instance in the US-East region
  4. Create a snapshot of the root disk, create an image file in Google Cloud Storage from the snapshot, and create a new virtual machine instance in the US-East region using the image file for the root disk.

Answer(s): D

Explanation:

https://stackoverflow.com/questions/36441423/migrate-google-compute-engine-instance-to-a- different-region






Post your Comments and Discuss Google Google Cloud Architect Professional exam with other Community members:

Google Cloud Architect Professional Discussions & Posts