Pass Associate-Cloud-Engineer Exam in First Attempt Guaranteed 100% Cover Real Exam Questions [May-2025]
Valid Associate-Cloud-Engineer test answers & Google Associate-Cloud-Engineer exam pdf
NEW QUESTION # 74
Your company has a 3-tier solution running on Compute Engine. The configuration of the current infrastructure is shown below.
Each tier has a service account that is associated with all instances within it. You need to enable communication on TCP port 8080 between tiers as follows:
* Instances in tier #1 must communicate with tier #2.
* Instances in tier #2 must communicate with tier #3.
What should you do?
- A. 1. Create an egress firewall rule with the following settings:* Targets: all instances* Source filter: IP ranges (with the range set to 10.0.2.0/24)* Protocols: allow TCP: 80802. Create an egress firewall rule with the following settings:* Targets: all instances* Source filter: IP ranges (with the range set to
10.0.1.0/24)* Protocols: allow TCP: 8080 - B. 1. Create an ingress firewall rule with the following settings:* Targets: all instances* Source filter: IP ranges (with the range set to 10.0.2.0/24)* Protocols: allow all2. Create an ingress firewall rule with the following settings:* Targets: all instances* Source filter: IP ranges (with the range set to 10.0.1.0/24)* Protocols: allow all
- C. 1. Create an ingress firewall rule with the following settings:* Targets: all instances with tier #2 service account* Source filter: all instances with tier #1 service account* Protocols: allow TCP:80802. Create an ingress firewall rule with the following settings:* Targets: all instances with tier #3 service account* Source filter: all instances with tier #2 service account* Protocols: allow TCP: 8080
- D. 1. Create an ingress firewall rule with the following settings:* Targets: all instances with tier #2 service account* Source filter: all instances with tier #1 service account* Protocols: allow all2. Create an ingress firewall rule with the following settings:* Targets: all instances with tier #3 service account* Source filter: all instances with tier #2 service account* Protocols: allow all
Answer: C
Explanation:
1. Create an ingress firewall rule with the following settings: "¢ Targets: all instances with tier #2 service account "¢ Source filter: all instances with tier #1 service account "¢ Protocols: allow TCP:8080 2. Create an ingress firewall rule with the following settings: "¢ Targets: all instances with tier #3 service account "¢ Source filter: all instances with tier #2 service account "¢ Protocols: allow TCP: 8080
NEW QUESTION # 75
Your team has been working towards using desired state configuration for your entire infrastructure, which is why they're excited to store the Kubernetes Deployments in YAML. You created a Kubernetes Deployment with the kubectl apply command and passed on a YAML file. You need to edit the number of replicas. What steps should you take to update the Deployment?
- A. Disregard the YAML file. Use the kubectl scale command.
- B. Edit the number of replicas in the YAML file and run the kubectl set image command.
- C. Edit the number of replicas in the YAML file and rerun the kubectl apply.
- D. Edit the YAML and push it to Github so that the git triggers deploy the change.
Answer: C
NEW QUESTION # 76
You just installed the Google Cloud CLI on your new corporate laptop. You need to list the existing instances of your company on Google Cloud. What must you do before you run the gcloud compute instances list command?
Choose 2 answers
- A. Download your Cloud Identity user account key. Place the key file in a folder on your machine where gcloud CLI can find it.
- B. Run gcloud auth login, enter your login credentials in the dialog window, and paste the received login token to gcloud CLI.
- C. Run gcloud config set compute/zone $my_zone to set the default zone for gcloud CLI.
- D. Run gcloud config set project $my_project to set the default project for gcloud CLI.
- E. Create a Google Cloud service account, and download the service account key. Place the key file in a folder on your machine where gcloud CLI can find it.
Answer: B,D
Explanation:
Before you run the gcloud compute instances list command, you need to do two things: authenticate with your user account and set the default project for gcloud CLI.
To authenticate with your user account, you need to run gcloud auth login, enter your login credentials in the dialog window, and paste the received login token to gcloud CLI. This will authorize the gcloud CLI to access Google Cloud resources on your behalf1.
To set the default project for gcloud CLI, you need to run gcloud config set project $my_project, where
$my_project is the ID of the project that contains the instances you want to list. This will save you from having to specify the project flag for every gcloud command2.
Option B is not recommended, because using a service account key increases the risk of credential leakage and misuse. It is also not necessary, because you can use your user account to authenticate to the gcloud CLI3.
Option C is not correct, because there is no such thing as a Cloud Identity user account key. Cloud Identity is a service that provides identity and access management for Google Cloud users and groups4. Option D is not required, because the gcloud compute instances list command does not depend on the default zone. You can list instances from all zones or filter by a specific zone using the --filter flag.
References:
* 1: https://cloud.google.com/sdk/docs/authorizing
* 2: https://cloud.google.com/sdk/gcloud/reference/config/set
* 3: https://cloud.google.com/iam/docs/best-practices-for-managing-service-account-keys
* 4: https://cloud.google.com/identity/docs/overview
* : https://cloud.google.com/sdk/gcloud/reference/compute/instances/list
NEW QUESTION # 77
You have a virtual machine that is currently configured with 2 vCPUs and 4 GB of memory. It is running out of memory. You want to upgrade the virtual machine to have 8 GB of memory.
What should you do?
- A. Use gcloud to add metadata to the VM. Set the key to required-memory-sizeand the value to
8 GB. - B. Stop the VM, change the machine type to n1-standard-8, and start the VM.
- C. Stop the VM, increase the memory to 8 GB, and start the VM.
- D. Rely on live migration to move the workload to a machine with more memory.
Answer: C
NEW QUESTION # 78
You have been asked to set up Object Lifecycle Management for objects stored in storage buckets. The objects are written once and accessed frequently for 30 days. After 30 days, the objects are not read again unless there is a special need. The object should be kept for three years, and you need to minimize cost. What should you do?
- A. Set up a policy that uses Standard storage for 30 days and then moves to Archive storage for three years.
- B. Set up a policy that uses Nearline storage for 30 days and then moves to Archive storage for three years.
- C. Set up a policy that uses Nearline storage for 30 days, then moves the Coldline for one year, and then moves to Archive storage for two years.
- D. Set up a policy that uses Standard storage for 30 days, then moves to Coldline for one year, and then moves to Archive storage for two years.
Answer: B
Explanation:
Reference:
https://books.google.com.pk/books?id=q0nhDwAAQBAJ&pg=PA52&lpg=PA52&dq=Set+up+a
+policy+that+uses+Nearline+storage+for+30+days+and+then+moves+to+Archive+storage+for+three
+years.&source=bl&ots=kYLZN1ymA8&sig=ACfU3U2XLmzQ39cmPDwjfWxRbNtDNLc_6g&hl=en&sa=X&ved
=2ahUKEwjZmefOpr7qAhVzQkEAHTUgASYQ6AEwAHoECAoQAQ#v=onepage&q=Set%20up%20a% 20policy%20that%20uses%20Nearline%20storage%20for%2030%20days%20and%20then%20moves%20to
%20Archive%20storage%20for%20three%20years.&f=false
NEW QUESTION # 79
Your management has asked an external auditor to review all the resources in a specific project. The security team has enabled the Organization Policy called Domain Restricted Sharing on the organization node by specifying only your Cloud Identity domain. You want the auditor to only be able to view, but not modify, the resources in that project. What should you do?
- A. Create a temporary account for the auditor in Cloud Identity, and give that account the Viewer role on the project.
- B. Ask the auditor for their Google account, and give them the Viewer role on the project.
- C. Ask the auditor for their Google account, and give them the Security Reviewer role on the project.
- D. Create a temporary account for the auditor in Cloud Identity, and give that account the Security Reviewer role on the project.
Answer: A
NEW QUESTION # 80
You are building a multi-player gaming application that will store game information in a database. As the popularity of the application increases, you are concerned about delivering consistent performance. You need to ensure an optimal gaming performance for global users, without increasing the management complexity.
What should you do?
- A. Use Cloud Spanner to store user data mapped to the game statistics.
- B. Use BigQuery to store game statistics with a Redis on Memorystore instance in the front to provide global consistency.
- C. Use Cloud SQL database with cross-region replication to store game statistics in the EU, US, and APAC regions.
- D. Store game statistics in a Bigtable database partitioned by username.
Answer: A
NEW QUESTION # 81
You need to create a Compute Engine instance in a new project that doesn't exist yet. What should you do?
- A. Enable the Compute Engine API in the Cloud Console, use the Cloud SDK to create the instance, and then use the -pproject flag to specify a new project.
- B. Enable the Compute Engine API in the Cloud Console. Go to the Compute Engine section of the Console to create a new instance, and look for the Create In A New Project option in the creation form.
- C. Using the Cloud SDK, create a new project, enable the Compute Engine API in that project, and then create the instance specifying your new project.
- D. Using the Cloud SDK, create the new instance, and use the -pproject flag to specify the new project.
Answer yes when prompted by Cloud SDK to enable the Compute Engine API.
Answer: A
NEW QUESTION # 82
For analysis purposes, you need to send all the logs from all of your Compute Engine instances to a BigQuery dataset called platform-logs. You have already installed the Stackdriver Logging agent on all the instances. You want to minimize cost. What should you do?
- A. 1. In Stackdriver Logging, create a logs export with a Cloud Pub/Sub topic called logsas a sink.
2. Create a Cloud Function that is triggered by messages in the logstopic.
3. Configure that Cloud Function to drop logs that are not from Compute Engine and to insert Compute Engine logs in the platform-logsdataset. - B. 1. Give the BigQuery Data Editor role on the platform-logsdataset to the service accounts used by your instances.
2. Update your instances' metadata to add the following value: logs-destination:
bq://platform-logs. - C. 1. Create a Cloud Function that has the BigQuery User role on the platform-logsdataset.
2. Configure this Cloud Function to create a BigQuery Job that executes this query:
INSERT INTO dataset.platform-logs (timestamp, log)
SELECT timestamp, log FROM compute.logs
WHERE timestamp > DATE_SUB(CURRENT_DATE(), INTERVAL 1 DAY)
3. Use Cloud Scheduler to trigger this Cloud Function once a day. - D. 1. In Stackdriver Logging, create a filter to view only Compute Engine logs.
2. Click Create Export.
3. Choose BigQuery as Sink Service, and the platform-logsdataset as Sink Destination.
Answer: D
NEW QUESTION # 83
You've created a new "Custom Role" for a specific new job role inside your company. The role consisted of several permissions; some had a status of "Supported" others a status of "Testing." The role has been working for weeks; however, some permissions recently stopped working. What is the most likely cause for this?
- A. The custom role has reached its expiration period.
- B. One or more permissions with a status of "Testing" have changed.
- C. The latest Google applied updates reset all of the custom roles.
- D. Your account has been compromised by hackers.
Answer: B,D
NEW QUESTION # 84
Your company has workloads running on Compute Engine and on-premises. The Google Cloud Virtual Private Cloud (VPC) is connected to your WAN over a Virtual Private Network (VPN). You need to deploy a new Compute Engine instance and ensure that no public Internet traffic can be routed to it. What should you do?
- A. Create a route on the VPC to route all traffic to the instance over the VPN tunnel.
- B. Create a deny-all egress firewall rule on the VPC network.
- C. Create the instance without a public IP address.
- D. Create the instance with Private Google Access enabled.
Answer: C
Explanation:
VMs cannot communicate over the internet without a public IP address. Private Google Access permits access to Google APIs and services in Google's production infrastructure.
https://cloud.google.com/vpc/docs/private-google-access
NEW QUESTION # 85
You have a number of compute instances belonging to an unmanaged instances group. You need to SSH to one of the Compute Engine instances to run an ad hoc script. You've already authenticated gcloud, however, you don't have an SSH key deployed yet. In the fewest steps possible, what's the easiest way to SSH to the instance?
- A. Create a key with the ssh-keygen command. Upload the key to the instance. Run gcloud compute instances list to get the IP address of the instance, then use the ssh command.
- B. Run gcloud compute instances list to get the IP address of the instance, then use the ssh command.
- C. Use the gcloud compute ssh command.
- D. Create a key with the ssh-keygen command. Then use the gcloud compute ssh command.
Answer: C
Explanation:
Explanation
gcloud compute ssh ensures that the user's public SSH key is present in the project's metadata. If the user does not have a public SSH key, one is generated using ssh-keygen and added to the project's metadata. This is similar to the other option where we copy the key explicitly to the project's metadata but here it is done automatically for us. There are also security benefits with this approach. When we use gcloud compute ssh to connect to Linux instances, we are adding a layer of security by storing your host keys as guest attributes.
Storing SSH host keys as guest attributes improve the security of your connections by helping to protect against vulnerabilities such as man-in-the-middle (MITM) attacks. On the initial boot of a VM instance, if guest attributes are enabled, Compute Engine stores your generated host keys as guest attributes.
Compute Engine then uses these host keys that were stored during the initial boot to verify all subsequent connections to the VM instance.
Ref: https://cloud.google.com/compute/docs/instances/connecting-to-instanceRef: https://cloud.google.com/sdk/g
NEW QUESTION # 86
Your management has asked an external auditor to review all the resources in a specific project.
The security team has enabled the Organization Policy called Domain Restricted Sharing on the organization node by specifying only your Cloud Identity domain. You want the auditor to only be able to view, but not modify, the resources in that project. What should you do?
- A. Create a temporary account for the auditor in Cloud Identity, and give that account the Viewer role on the project.
- B. Ask the auditor for their Google account, and give them the Viewer role on the project.
- C. Ask the auditor for their Google account, and give them the Security Reviewer role on the project.
- D. Create a temporary account for the auditor in Cloud Identity, and give that account the Security Reviewer role on the project.
Answer: A
Explanation:
https://cloud.google.com/iam/docs/roles-audit-logging#scenario_external_auditors
NEW QUESTION # 87
A team of data scientists infrequently needs to use a Google Kubernetes Engine (GKE) cluster that you manage. They require GPUs for some long-running, non-restartable jobs. You want to minimize cost. What should you do?
- A. Create a node pool of instances with GPUs, and enable autoscaling on this node pool with a minimum size of 1.
- B. Create a VerticalPodAutscaler for those workloads.
- C. Create a node pool with preemptible VMs and GPUs attached to those VMs.
- D. Enable node auto-provisioning on the GKE cluster.
Answer: C
Explanation:
Reference:
https://cloud.google.com/kubernetes-engine/docs/how-to/gpus
NEW QUESTION # 88
You are hosting an application on bare-metal servers in your own data center. The application needs access to Cloud Storage. However, security policies prevent the servers hosting the application from having public IP addresses or access to the internet. You want to follow Google-recommended practices to provide the application with access to Cloud Storage. What should you do?
- A. 1. Using Cloud VPN or Interconnect, create a tunnel to a VPC in GCP.
2. Use Cloud Router to create a custom route advertisement for 199.36.153.4/30. Announce that network to your on-premises network through the VPN tunnel.
3. In your on-premises network, configure your DNS server to resolve *.googleapis.com as a CNAME to restricted.googleapis.com. - B. 1. Use Migrate for Compute Engine (formerly known as Velostrata) to migrate those servers to Compute Engine.
2. Create an internal load balancer (ILB) that uses storage.googleapis.com as backend.
3. Configure your new instances to use this ILB as proxy. - C. 1. Use nslookupto get the IP address for storage.googleapis.com.
2. Negotiate with the security team to be able to give a public IP address to the servers.
3. Only allow egress traffic from those servers to the IP addresses for storage.googleapis.com. - D. 1. Using Cloud VPN, create a VPN tunnel to a Virtual Private Cloud (VPC) in Google Cloud Platform (GCP).
2. In this VPC, create a Compute Engine instance and install the Squid proxy server on this instance.
3. Configure your servers to use that instance as a proxy to access Cloud Storage.
Answer: B
NEW QUESTION # 89
You created a Google Cloud Platform project with an App Engine application inside the project.
You initially configured the application to be served from the us-central region. Now you want the application to be served from the asia-northeast1 region. What should you do?
- A. Create a new GCP project and create an App Engine application inside this new project.
Specify asia-northeast1 as the region to serve your application. - B. Change the region property setting in the existing App Engine application from us-central to asia- northeast1.
- C. Change the default region property setting in the existing GCP project to asia-northeast1.
- D. Create a second App Engine application in the existing GCP project and specify asia-northeast1 as the region to serve your application.
Answer: A
Explanation:
https://cloud.google.com/appengine/docs/flexible/nodejs/an-overview-of-app-engine
NEW QUESTION # 90
Your organization has strict requirements to control access to Google Cloud projects. You need to enable your Site Reliability Engineers (SREs) to approve requests from the Google Cloud support team when an SRE opens a support case. You want to follow Google-recommended practices. What should you do?
- A. Add your SREs to a group and then add this group to roles/iam roleAdmin role.
- B. Add your SREs to roles/accessapproval approver role.
- C. Add your SREs to roles/iam.roleAdmin role.
- D. Add your SREs to a group and then add this group to roles/accessapproval approver role.
Answer: D
NEW QUESTION # 91
You are using Data Studio to visualize a table from your data warehouse that is built on top of BigQuery. Data is appended to the data warehouse during the day. At night, the daily summary is recalculated by overwriting the table. You just noticed that the charts in Data Studio are broken, and you want to analyze the problem. What should you do?
- A. Use the BigQuery interface to review the nightly Job and look for any errors
- B. Review the Error Reporting page in the Cloud Console to find any errors.
- C. Use the open source CLI tool. Snapshot Debugger, to find out why the data was not refreshed correctly.
- D. In Cloud Logging create a filter for your Data Studio report
Answer: C
Explanation:
Cloud Debugger helps inspect the state of an application, at any code location, without stopping or slowing down the running app // https://cloud.google.com/debugger/docs
NEW QUESTION # 92
......
Associate-Cloud-Engineer Exam Questions – Valid Associate-Cloud-Engineer Dumps Pdf: https://www.braindumpspass.com/Google/Associate-Cloud-Engineer-practice-exam-dumps.html
Verified Associate-Cloud-Engineer dumps Q&As - Pass Guarantee: https://drive.google.com/open?id=1JiaIg1ylO8VWxdW65kd5Jb2IwlFJpyM-