Professional Cloud Architect Free Practice Questions — Page 9
Question 83
Your company is using BigQuery as its enterprise data warehouse. Data is distributed over several Google Cloud projects. All queries on BigQuery need to be billed on a single project. You want to make sure that no query costs are incurred on the projects that contain the data. Users should be able to query the datasets, but not edit them.
How should you configure users' access roles?
A. Add all users to a group. Grant the group the role of BigQuery user on the billing project and BigQuery dataViewer on the projects that contain the data.
B. Add all users to a group. Grant the group the roles of BigQuery dataViewer on the billing project and BigQuery user on the projects that contain the data.
C. Add all users to a group. Grant the group the roles of BigQuery jobUser on the billing project and BigQuery dataViewer on the projects that contain the data.
D. Add all users to a group. Grant the group the roles of BigQuery dataViewer on the billing project and BigQuery jobUser on the projects that contain the data.
Show Answer
Correct Answer: C
Explanation: Grant BigQuery Job User on the central billing project so users can run query jobs that are billed there, and grant BigQuery Data Viewer on the data-hosting projects so they can read datasets without modifying them. Using BigQuery User on the billing project would also permit dataset creation, which exceeds the stated requirement and violates least-privilege.
Question 84
Your operations team currently stores 10 TB of data in an object storage service from a third-party provider. They want to move this data to a Cloud Storage bucket as quickly as possible, following Google-recommended practices. They want to minimize the cost of this data migration. Which approach should they use?
A. Use the gsutil mv command to move the data.
B. Use the Storage Transfer Service to move the data.
C. Download the data to a Transfer Appliance, and ship it to Google.
D. Download the data to the on-premises data center, and upload it to the Cloud Storage bucket.
Show Answer
Correct Answer: B
Explanation: Storage Transfer Service is the Google-recommended service for transferring data from third-party object storage into Cloud Storage. For an online source of only 10 TB, it is faster and more cost-effective than downloading locally or using a Transfer Appliance, and avoids routing data through an on-premises environment. The gsutil mv command is not the recommended approach for this type of cloud-to-cloud migration at this scale.
Question 85
Your company has a Google Cloud project that uses BigQuery for data warehousing. There are some tables that contain personally identifiable information (PII).
Only the compliance team may access the PII. The other information in the tables must be available to the data science team. You want to minimize cost and the time it takes to assign appropriate access to the tables. What should you do?
A. 1. From the dataset where you have the source data, create views of tables that you want to share, excluding PII. 2. Assign an appropriate project-level IAM role to the members of the data science team. 3. Assign access controls to the dataset that contains the view.
B. 1. From the dataset where you have the source data, create materialized views of tables that you want to share, excluding PII. 2. Assign an appropriate project-level IAM role to the members of the data science team. 3. Assign access controls to the dataset that contains the view.
C. 1. Create a dataset for the data science team. 2. Create views of tables that you want to share, excluding PII. 3. Assign an appropriate project-level IAM role to the members of the data science team. 4. Assign access controls to the dataset that contains the view. 5. Authorize the view to access the source dataset.
D. 1. Create a dataset for the data science team. 2. Create materialized views of tables that you want to share, excluding PII. 3. Assign an appropriate project-level IAM role to the members of the data science team. 4. Assign access controls to the dataset that contains the view. 5. Authorize the view to access the source dataset.
Show Answer
Correct Answer: C
Explanation: Use an authorized view pattern: create a separate dataset for shared views that exclude PII, grant the data science team access only to that dataset, and authorize the views to access the source dataset. This prevents direct access to the underlying tables while exposing only non-PII columns. Regular views are sufficient; materialized views add unnecessary storage and maintenance cost for this access-control use case.
Question 86
Your company has an application running on Google Cloud that is collecting data from thousands of physical devices that are globally distributed. Data is published to Pub/Sub and streamed in real time into an SSD Cloud Bigtable cluster via a Dataflow pipeline. The operations team informs you that your Cloud
Bigtable cluster has a hotspot, and queries are taking longer than expected. You need to resolve the problem and prevent it from happening in the future. What should you do?
A. Advise your clients to use HBase APIs instead of NodeJS APIs.
B. Delete records older than 30 days.
C. Review your RowKey strategy and ensure that keys are evenly spread across the alphabet.
D. Double the number of nodes you currently have.
Show Answer
Correct Answer: C
Explanation: Cloud Bigtable hotspots are most commonly caused by poor row key design that concentrates reads or writes on a small range of tablets. Reviewing and redesigning the RowKey strategy so keys are well distributed prevents hotspots and improves load balancing. Adding nodes may temporarily increase capacity but does not fix an uneven key distribution, while changing client APIs or deleting old data does not address the root cause.
Question 87
Your company has just recently activated Cloud Identity to manage users. The Google Cloud Organization has been configured as well. The security team needs to secure projects that will be part of the Organization. They want to prohibit IAM users outside the domain from gaining permissions from now on. What should they do?
A. Configure an organization policy to restrict identities by domain.
B. Configure an organization policy to block creation of service accounts.
C. Configure Cloud Scheduler to trigger a Cloud Function every hour that removes all users that don't belong to the Cloud Identity domain from all projects.
D. Create a technical user (e.g., [email protected] ), and give it the project owner role at root organization level. Write a bash script that: ג€¢ Lists all the IAM rules of all projects within the organization. ג€¢ Deletes all users that do not belong to the company domain. Create a Compute Engine instance in a project within the Organization and configure gcloud to be executed with technical user credentials. Configure a cron job that executes the bash script every hour.
Show Answer
Correct Answer: A
Explanation: Use the Organization Policy constraint to restrict IAM member identities to specific Google Workspace/Cloud Identity domains. This centrally prevents principals outside the allowed domain from being granted IAM roles across resources in the organization. The other options are either unrelated (blocking service accounts) or rely on reactive scripts instead of the built-in preventative control.
Question 89
You want to allow your operations team to store logs from all the production projects in your Organization, without including logs from other projects. All of the production projects are contained in a folder. You want to ensure that all logs for existing and new production projects are captured automatically. What should you do?
A. Create an aggregated export on the Production folder. Set the log sink to be a Cloud Storage bucket in an operations project.
B. Create an aggregated export on the Organization resource. Set the log sink to be a Cloud Storage bucket in an operations project.
C. Create log exports in the production projects. Set the log sinks to be a Cloud Storage bucket in an operations project.
D. Create log exports in the production projects. Set the log sinks to be BigQuery datasets in the production projects, and grant IAM access to the operations team to run queries on the datasets.
Show Answer
Correct Answer: A
Explanation: An aggregated log sink created at the Production folder level applies to all current and future projects within that folder, capturing only production project logs. Sending the sink to a Cloud Storage bucket in a centralized operations project satisfies the requirement for centralized storage without including non-production projects.
Question 90
You are working with a data warehousing team that performs data analysis. The team needs to process data from external partners, but the data contains personally identifiable information (PII). You need to process and store the data without storing any of the PIIE data. What should you do?
A. Create a Dataflow pipeline to retrieve the data from the external sources. As part of the pipeline, use the Cloud Data Loss Prevention (Cloud DLP) API to remove any PII data. Store the result in BigQuery.
B. Create a Dataflow pipeline to retrieve the data from the external sources. As part of the pipeline, store all non-PII data in BigQuery and store all PII data in a Cloud Storage bucket that has a retention policy set.
C. Ask the external partners to upload all data on Cloud Storage. Configure Bucket Lock for the bucket. Create a Dataflow pipeline to read the data from the bucket. As part of the pipeline, use the Cloud Data Loss Prevention (Cloud DLP) API to remove any PII data. Store the result in BigQuery.
D. Ask the external partners to import all data in your BigQuery dataset. Create a dataflow pipeline to copy the data into a new table. As part of the Dataflow bucket, skip all data in columns that have PII data
Show Answer
Correct Answer: A
Explanation: Use a Dataflow pipeline integrated with Cloud DLP to inspect and de-identify or remove PII before persisting the data. This satisfies the requirement to process external data without storing PII. The other options either retain/store PII (B, C) or rely on simply skipping known PII columns without DLP, which is less robust and may miss sensitive data (D).
Question 91
The operations team in your company wants to save Cloud VPN log events for one year. You need to configure the cloud infrastructure to save the logs. What should you do?
A. Set up a filter in Cloud Logging and a Cloud Storage bucket as an export target for the logs you want to save.
B. Enable the Compute Engine API, and then enable logging on the firewall rules that match the traffic you want to save.
C. Set up a Cloud Logging Dashboard titled Cloud VPN Logs, and then add a chart that queries for the VPN metrics over a one-year time period.
D. Set up a filter in Cloud Logging and a topic in Pub/Sub to publish the logs.
Show Answer
Correct Answer: A
Explanation: To retain Cloud VPN logs for one year, create a Cloud Logging sink with an appropriate filter and export the matching log entries to a Cloud Storage bucket configured with the desired retention/lifecycle policy. Cloud Storage is suitable for long-term log archival. Firewall logging (B) is unrelated to Cloud VPN log retention, dashboards (C) visualize data rather than archive logs, and Pub/Sub (D) is for streaming, not long-term storage.
Question 92
Your company has an application running on Compute Engine that allows users to play their favorite music. There are a fixed number of instances. Files are stored in Cloud Storage, and data is streamed directly to users. Users are reporting that they sometimes need to attempt to play popular songs multiple times before they are successful. You need to improve the performance of the application. What should you do?
A. 1. Mount the Cloud Storage bucket using gcsfuse on all backend Compute Engine instances. 2. Serve music files directly from the backend Compute Engine instance.
B. 1. Create a Cloud Filestore NFS volume and attach it to the backend Compute Engine instances. 2. Download popular songs in Cloud Filestore. 3. Serve music files directly from the backend Compute Engine instance.
C. 1. Copy popular songs into CloudSQL as a blob. 2. Update application code to retrieve data from CloudSQL when Cloud Storage is overloaded.
D. 1. Create a managed instance group with Compute Engine instances. 2. Create a global load balancer and configure it with two backends: ג—‹ Managed instance group ג—‹ Cloud Storage bucket 3. Enable Cloud CDN on the bucket backend.
Show Answer
Correct Answer: D
Explanation: The bottleneck is delivering popular static media from Cloud Storage to many users. The recommended architecture is to place Cloud Storage behind an external HTTP(S) load balancer with Cloud CDN enabled so popular objects are cached at edge locations, reducing repeated fetches and improving playback success. Using a managed instance group for the application tier also provides scalability. gcsfuse is not intended to improve serving performance, Filestore is unnecessary for objects already in Cloud Storage, and Cloud SQL is not appropriate for storing and serving large media blobs.
Question 93
Your company has a Google Workspace account and Google Cloud Organization. Some developers in the company have created Google Cloud projects outside of the Google Cloud Organization.
You want to create an Organization structure that allows developers to create projects, but prevents them from modifying production projects. You want to manage policies for all projects centrally and be able to set more restrictive policies for production projects.
You want to minimize disruption to users and developers when business needs change in the future. You want to follow Google-recommended practices. Now should you design the Organization structure?
A. 1. Create a second Google Workspace account and Organization. 2. Grant all developers the Project Creator IAM role on the new Organization. 3. Move the developer projects into the new Organization. 4. Set the policies for all projects on both Organizations. 5. Additionally, set the production policies on the original Organization.
B. 1. Create a folder under the Organization resource named ג€Production.ג€ 2. Grant all developers the Project Creator IAM role on the new Organization. 3. Move the developer projects into the new Organization. 4. Set the policies for all projects on the Organization. 5. Additionally, set the production policies on the ג€Productionג€ folder.
C. 1. Create folders under the Organization resource named ג€Developmentג€ and ג€Production.ג€ 2. Grant all developers the Project Creator IAM role on the ג€Developmentג€ folder. 3. Move the developer projects into the ג€Developmentג€ folder. 4. Set the policies for all projects on the Organization. 5. Additionally, set the production policies on the ג€Productionג€ folder.
D. 1. Designate the Organization for production projects only. 2. Ensure that developers do not have the Project Creator IAM role on the Organization. 3. Create development projects outside of the Organization using the developer Google Workspace accounts. 4. Set the policies for all projects on the Organization. 5. Additionally, set the production policies on the individual production projects.
Show Answer
Correct Answer: C
Explanation: Use a single Organization with separate Development and Production folders. Grant Project Creator on the Development folder so developers can create projects there but not in Production. Apply baseline organization policies at the Organization level and stricter policies on the Production folder. This supports centralized policy management, least privilege, and allows projects to be moved between folders with minimal disruption as business needs change.
$19
Get all 306 questions with detailed answers and explanations
Instant download HTML + PDF delivered the moment payment clears.
Secure Stripe checkout we never see or store your card details.
7-day refund if files are defective see our refund policy.