Download Free Google Associate-Cloud-Engineer Real Exam Questions Download [Q119-Q135]

Share

Download Free Google Associate-Cloud-Engineer Real Exam Questions Download

Latest Google Associate-Cloud-Engineer Real Exam Dumps PDF


Configuring Security & Access

  • View audit logs or managed services and projects.
  • Manage Service Account: the candidates should know how to manage service accounts with restricted privileges; grant access to service accounts within another project; assign service accounts to virtual machine instances;
  • Manage IAM: this domain involves your ability to view IAM role allocations; assign IAM roles to Google Groups or accounts; define custom IAM duties;

Below are the Problems in taking the Associate Cloud Engineer Exam

Google Certified Specialist is the most powerful certification that candidates can have on their resume. But for this, they will have to pass Associate Cloud Engineer questions. Associate Cloud Engineer is a challenging exam to pass this exam Candidates will have to work hard with the help of the right focus and preparation material passing this exam is an achievable goal. ExamTorrent help candidates by providing the most relevant and updated Associate Cloud Engineer dumps. Furthermore, We also provide the Associate Cloud Engineer practice test that will be much beneficial in the preparation. ExamTorrent aims to provide the best Associate Cloud Engineer dumps that are verified by the Google experts. If Candidates feel any doubt in the Associate Cloud Engineer practice test then our team is always there to help them. Associate Cloud Engineer dumps are the perfect way to prepare the Associate Cloud Engineer exam with good grades in the just first attempt. So, Candidates want instant success in the Associate Cloud Engineer exam with quality Associate Cloud Engineer training material then ExamTorrent is the best option for them because our management is well trained in it and we update each question of all exams on regular basis after consulting recent updates with our Google certified professionals.

 

NEW QUESTION 119
The core business of your company is to rent out construction equipment at a large scale. All the equipment that is being rented out has been equipped with multiple sensors that send event information every few seconds. These signals can vary from engine status, distance traveled, fuel level, and more. Customers are billed based on the consumption monitored by these sensors.
You expect high throughput ?up to thousands of events per hour per device ?and need to retrieve consistent data based on the time of the event. Storing and retrieving individual signals should be atomic. What should you do?

  • A. Ingest the data into Cloud Bigtable. Create a row key based on the event timestamp.
  • B. Create a file in Cloud Filestore per device and append new data to that file.
  • C. Create a file in Cloud Storage per device and append new data to that file.
  • D. Ingest the data into Datastore. Store data in an entity group based on the device.

Answer: D

 

NEW QUESTION 120
You want to find out who in your organization has Owner access to a project called "my- project".What should you do?

  • A. Use "gcloud iam list-grantable-role --project my-project" from your Terminal.
  • B. Use "gcloud iam list-grantable-role" from Cloud Shell on the project page.
  • C. In the Google Cloud Platform Console, go to the IAM page for your organization and apply the filter "Role:Owner".
  • D. In the Google Cloud Platform Console, go to the IAM page for your project and apply the filter
    "Role:Owner".

Answer: D

Explanation:
A is not correct because it will give the org-wide owners, but you are interested in the project owners, which could be different.
B is correct because this shows you the Owners of the project.
C is not correct because this command is to list grantable roles for a resource, but does not return who has a specific role.
D is not correct because this command is to list grantable roles for a resource, but does not return who has a specific role.

 

NEW QUESTION 121
You are configuring service accounts for an application that spans multiple projects. Virtual machines (VMs) running in the web-applications project need access to BigQuery datasets in crm-databases-proj. You want to follow Google-recommended practices to give access to the service account in the web- applications project. What should you do?

  • A. Give bigquery.dataViewer role to crm-databases-proj and appropriate roles to web-applications.
  • B. Give "project owner" role to crm-databases-proj and the web-applications project.
  • C. Give "project owner" role to crm-databases-proj and bigquery.dataViewer role to web- applications.
  • D. Give "project owner" for web-applications appropriate roles to crm-databases- proj

Answer: A

Explanation:
You just need read access for DB at the project.

 

NEW QUESTION 122
You have 32 GB of data in a single file that you need to upload to a Nearline Storage bucket. The WAN connection you are using is rated at 1 Gbps, and you are the only one on the connection.
You want to use as much of the rated 1 Gbps as possible to transfer the file rapidly. How should you upload the file?

  • A. Use the GCP Console to transfer the file instead of gsutil.
  • B. Decrease the TCP window size on the machine initiating the transfer.
  • C. Change the storage class of the bucket from Nearline to Multi-Regional.
  • D. Enable parallel composite uploads using gsutil on the file transfer.

Answer: D

Explanation:
https://cloud.google.com/storage/docs/gsutil/commands/cp#parallel-composite-uploads_1 Warning: Parallel composite uploads should not be used with NEARLINE, COLDLINE, or ARCHIVE storage class buckets, because doing so incurs an early deletion charge for each component object.
Warning: Parallel composite uploads should not be used in buckets that have a retention policy, because the component pieces cannot be deleted until each has met the bucket's minimum retention period.

 

NEW QUESTION 123
You are operating a Google Kubernetes Engine (GKE) cluster for your company where different teams can run non-production workloads. Your Machine Learning (ML) team needs access to Nvidia Tesla P100 GPUs to train their models. You want to minimize effort and cost. What should you do?

  • A. Ask your ML team to add the "accelerator: gpu" annotation to their pod specification.
  • B. Add a new, GPU-enabled, node pool to the GKE cluster. Ask your ML team to add the cloud.google.com/gke -accelerator: nvidia-tesla-p100 nodeSelectorto their pod specification.
  • C. Create your own Kubernetes cluster on top of Compute Engine with nodes that have GPUs.
    Dedicate this cluster to your ML team.
  • D. Recreate all the nodes of the GKE cluster to enable GPUs on all of them.

Answer: B

Explanation:
https://cloud.google.com/kubernetes-engine/docs/how-to/gpus

 

NEW QUESTION 124
You are planning to build a micro-service application with docker containers and want to host them on Google Cloud as stateless and serverless. Which service will help you serve the need?

  • A. CloudRun
  • B. Cloud Function
  • C. App Engine Standard
  • D. App Engine Flexible

Answer: A

 

NEW QUESTION 125
You're deploying an application to a Compute Engine instance, and it's going to need to make calls to read from Cloud Storage and Bigtable. You want to make sure you're following the principle of least privilege. What's the easiest way to ensure the code can authenticate to the required Google Cloud APIs?

  • A. Create a new user account with the required roles. Store the credentials in Cloud Key Management Service and download them to the instance in code.
  • B. Create a new service account and key with the required limited permissions. Set the instance to use the new service account. Edit the code to use the service account key.
  • C. Use the default Compute Engine service account and set its scopes. Let the code find the default service account using "Application Default Credentials".
  • D. Register the application with the Binary Registration Service and apply the required roles.

Answer: C

 

NEW QUESTION 126
Your organization needs to grant users access to query datasets in BigQuery but prevent them from accidentally deleting the datasets. You want a solution that follows Google-recommended practices. What should you do?

  • A. Add users to roles/bigquery dataEditor role only, instead of roles/bigquery dataOwner.
  • B. Create a custom role by removing delete permissions, and add users to that role only.
  • C. Add users to roles/bigquery user role only, instead of roles/bigquery dataOwner.
  • D. Create a custom role by removing delete permissions. Add users to the group, and then add the group to the custom role.

Answer: A

 

NEW QUESTION 127
You want to configure autohealing for network load balancing for a group of Compute Engine instances that run in multiple zones, using the fewest possible steps. You need to configure re-creation of VMs if they are unresponsive after 3 attempts of 10 seconds each. What should you do?

  • A. Create an HTTP load balancer with a backend configuration that references an existing instance group. Define a balancing mode and set the maximum RPS to 10.
  • B. Create a managed instance group. Verify that the autoscaling setting is on.
  • C. Create an HTTP load balancer with a backend configuration that references an existing instance group. Set the health check to healthy (HTTP)
  • D. Create a managed instance group. Set the Autohealing health check to healthy (HTTP)

Answer: B

 

NEW QUESTION 128
You are using Container Registry to centrally store your company's container images in a separate project. In another project, you want to create a Google Kubernetes Engine (GKE) cluster. You want to ensure that Kubernetes can download images from Container Registry. What should you do?

  • A. In the project where the images are stored, grant the Storage Object Viewer IAM role to the service account used by the Kubernetes nodes.
  • B. Configure the ACLs on each image in Cloud Storage to give read-only access to the default Compute Engine service account.
  • C. Create a service account, and give it access to Cloud Storage. Create a P12 key for this service account and use it as an imagePullSecrets in Kubernetes.
  • D. When you create the GKE cluster, choose the Allow full access to all Cloud APIs option under 'Access scopes'.

Answer: D

 

NEW QUESTION 129
You've deployed a microservice called myapp1 to a Google Kubernetes Engine cluster using the YAML file specified below:

You need to refactor this configuration so that the database password is not stored in plain text.
You want to follow Google-recommended practices. What should you do?

  • A. Store the database password inside a Secret object.
    Modify the YAML file to populate the DB_PASSWORD environment variable from the Secret.
  • B. Store the database password inside the Docker image of the container, not in the YAML file.
  • C. Store the database password inside a ConfigMap object.
    Modify the YAML file to populate the DB_PASSWORD environment variable from the ConfigMap.
  • D. Store the database password in a file inside a Kubernetes persistent volume, and use a persistent volume claim to mount the volume to the container.

Answer: C

 

NEW QUESTION 130
You are assigned to maintain a Google Kubernetes Engine (GKE) cluster named dev that was deployed on Google Cloud. You want to manage the GKE configuration using the command line interface (CLI). You have just downloaded and installed the Cloud SDK. You want to ensure that future CLI commands by default address this specific cluster. What should you do?

  • A. Use the command gcloud container clusters update dev
  • B. Use the command gcloud config sot container/cluster dev
  • C. Create a file called gke. default in the -/ .gcloud folder that contains the cluster name
  • D. Create a file called defaults. j son in the -/.gcioud folder that contains the cluster name

Answer: A

 

NEW QUESTION 131
Your company's infrastructure is on-premises, but all machines are running at maximum capacity.
You want to burst to Google Cloud. The workloads on Google Cloud must be able to directly communicate to the workloads on-premises using a private IP range. What should you do?

  • A. Create bastion hosts both in your on-premises environment and on Google Cloud. Configure both as proxy servers using their public IP addresses.
  • B. In Google Cloud, configure the VPC for VPC Network Peering.
  • C. Set up Cloud VPN between the infrastructure on-premises and Google Cloud.
  • D. In Google Cloud, configure the VPC as a host for Shared VPC.

Answer: C

Explanation:
vpc network peering does not connect to on-prem. Cloud VPN is the correct solution.
https://cloud.google.com/vpn/docs/concepts/overview

 

NEW QUESTION 132
You need to create a copy of a custom Compute Engine virtual machine (VM) to facilitate an expected increase in application traffic due to a business acquisition. What should you do?

  • A. Create a custom Compute Engine image from a snapshot. Create your images from that image.
  • B. Create a Compute Engine snapshot of your base VM. Create your images from that snapshot.
  • C. Create a custom Compute Engine image from a snapshot. Create your instances from that image.
    :
    A custom image belongs only to your project. To create an instance with a custom image, you must first have a custom image.
  • D. Create a Compute Engine snapshot of your base VM. Create your instances from that snapshot.

Answer: C

Explanation:
Reference:
https://cloud.google.com/compute/docs/instances/create-start-instance

 

NEW QUESTION 133
Your application has a large international audience and runs stateless virtual machines within a managed instance group across multiple locations. One feature of the application lets users upload files and share them with other users. Files must be available for 30 days; after that, they are removed from the system entirely. Which storage solution should you choose?

  • A. Persistent SSD on virtual machine instances.
  • B. A Cloud Datastore database.
  • C. A multi-regional Cloud Storage bucket.
  • D. A managed instance group of Filestore servers.

Answer: C

Explanation:
A is not correct because a Datastore database is not designed for file storage.
B is correct because buckets can be multi-regional and have lifecycle management.
C is not correct because disks are generally ephemeral for virtual machines in managed instance groups.
D is not correct because content would be restricted to a single region for all international users.

 

NEW QUESTION 134
You significantly changed a complex Deployment Manager template and want to confirm that the dependencies of all defined resources are properly met before committing it to the project. You want the most rapid feedback on your changes. What should you do?

  • A. Monitor activity of the Deployment Manager execution on the Stackdriver Logging page of the GCP Console.
  • B. Use granular logging statements within a Deployment Manager template authored in Python.
  • C. Execute the Deployment Manager template using the --preview option in the same project, and observe the state of interdependent resources.
  • D. Execute the Deployment Manager template against a separate project with the same configuration, and monitor for failures.

Answer: C

Explanation:
Reference:
https://cloud.google.com/deployment-manager/docs/deployments/updating-deployments

 

NEW QUESTION 135
......

PDF (New 2021) Actual Google Associate-Cloud-Engineer Exam Questions: https://www.examtorrent.com/Associate-Cloud-Engineer-valid-vce-dumps.html

Associate-Cloud-Engineer Exam Dumps, Associate-Cloud-Engineer Practice Test Questions: https://drive.google.com/open?id=19lspXdsgIkrqZSqPLHp7G7G7ozCJPu7g