Cloud Engineer: Essential Google Infrastructure Flashcards
7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Engineer: Essential Google Infrastructure flashcards as text
A Cloud Engineer wants to store application configuration secrets such as database passwords securely in GCP. Which service is best suited for this?
Answer: Secret Manager
Secret Manager is GCP's dedicated service for storing, accessing, and auditing secrets like API keys and passwords with version control.
Which Cloud Storage storage class is most cost-effective for data that is accessed less than once per year, such as long-term archival backups?
Answer: Archive
Archive storage class has the lowest storage cost but highest retrieval cost, making it ideal for data accessed less than once per year.
What is the primary advantage of using a Managed Instance Group (MIG) with autoscaling in Compute Engine?
Answer: It automatically adjusts the number of VMs based on load metrics
Autoscaling MIGs automatically add or remove VM instances based on CPU utilization, load balancing capacity, or custom metrics.
In GCP's resource hierarchy, at which level do Organization Policies apply when set at the organization node?
Answer: The organization node and all descendant folders and projects
Organization Policies set at the organization node cascade down the hierarchy to all folders, projects, and resources unless overridden at lower levels.
Which GCP service enables real-time stream analytics by ingesting and processing large volumes of event data from IoT devices or application logs?
Answer: Pub/Sub
Pub/Sub is GCP's asynchronous messaging service that ingests high-throughput event streams and decouples producers from consumers.
A Cloud Engineer needs to configure DNS for a GCP application so that internal VMs resolve hostnames without exposing DNS to the public internet. Which service should they use?
Answer: Cloud DNS private zone
Cloud DNS private zones provide DNS resolution only to resources within the specified VPC networks, keeping records internal.
What is the function of a GCP Service Account when used by a Compute Engine instance?
Answer: It acts as the identity the instance uses to authenticate with GCP APIs
A service account assigned to a Compute Engine instance serves as the instance's identity, determining which GCP APIs and resources it can access.