Professional-Cloud-DevOps-Engineer Dumps 2026 New Google Professional-Cloud-DevOps-Engineer Exam Questions [Q18-Q35]

Share

Professional-Cloud-DevOps-Engineer Dumps 2026 - New Google Professional-Cloud-DevOps-Engineer Exam Questions

Free Professional-Cloud-DevOps-Engineer braindumps download (Professional-Cloud-DevOps-Engineer exam dumps Free Updated)


To become a Certified Professional Cloud DevOps Engineer, the candidate must have a deep understanding of agile and DevOps methodologies, as well as proficiency in GCP services such as Kubernetes, Google Cloud Build, Google Cloud Functions, Google Cloud Monitoring, and more. Professional-Cloud-DevOps-Engineer exam also tests the candidate's ability to design and implement continuous integration/continuous delivery (CI/CD) pipelines, automate infrastructure deployments, and monitor and optimize application performance using GCP tools.

 

NEW QUESTION # 18
Your team has an application built by using a Dockerfile. The build is executed from Cloud Build, and the resulting artifacts are stored in Artifact Registry. Your team is reporting that builds are slow. You need to increase build speed, while following Google-recommended practices. What should you do?

  • A. Use the --cache-from parameter, and point to Artifact Registry. Add the most frequently modified files to the later stages of the build process.
  • B. Use the --cache-from parameter, and point to Artifact Registry. Add the most frequently modified files to the earlier stages of the build process.
  • C. Cache the container layers of the build process to Cloud Storage. Add the most frequently modified files to the later stages of the build process.
  • D. Cache the container layers of the build process to Cloud Storage. Add the most frequently modified files to the earlier stages of the build process.

Answer: A

Explanation:
To speed up Docker builds, optimize layer caching. Google Cloud recommends using --cache-from with Artifact Registry, and placing frequently changed files late in the Dockerfile so earlier layers can be reused.
"Put instructions that are less likely to change (like installing packages) early in the Dockerfile, and more frequently changing lines (like copying app code) near the end."
- Dockerfile Best Practices
"Use the --cache-from argument to pull layers from previously built images in Artifact Registry."
- Cloud Build Docker Caching
This dramatically reduces build time by avoiding redundant rebuilds of static layers.


NEW QUESTION # 19
You support an e-commerce application that runs on a large Google Kubernetes Engine (GKE) cluster deployed on-premises and on Google Cloud Platform. The application consists of microservices that run in containers. You want to identify containers that are using the most CPU and memory. What should you do?

  • A. Use Prometheus to collect and aggregate logs per container, and then analyze the results in Grafana.
  • B. Use Stackdriver Kubernetes Engine Monitoring.
  • C. Use Stackdriver Logging to export application logs to BigOuery. aggregate logs per container, and then analyze CPU and memory consumption.
  • D. Use the Stackdriver Monitoring API to create custom metrics, and then organize your containers using groups.

Answer: B


NEW QUESTION # 20
You are performing a semiannual capacity planning exercise for your flagship service. You expect a service user growth rate of 10% month-over-month over the next six months. Your service is fully containerized and runs on Google Cloud Platform (GCP). using a Google Kubernetes Engine (GKE) Standard regional cluster on three zones with cluster autoscaler enabled. You currently consume about 30% of your total deployed CPU capacity, and you require resilience against the failure of a zone. You want to ensure that your users experience minimal negative impact as a result of this growth or as a result of zone failure, while avoiding unnecessary costs. How should you prepare to handle the predicted growth?

  • A. Proactively add 60% more node capacity to account for six months of 10% growth rate, and then perform a load test to make sure you have enough capacity.
  • B. Because you are at only 30% utilization, you have significant headroom and you won't need to add any additional capacity for this rate of growth.
  • C. Verity the maximum node pool size, enable a horizontal pod autoscaler, and then perform a load test to verity your expected resource needs.
  • D. Because you are deployed on GKE and are using a cluster autoscaler. your GKE cluster will scale automatically, regardless of growth rate.

Answer: C

Explanation:
Explanation
https://cloud.google.com/kubernetes-engine/docs/concepts/horizontalpodautoscaler The Horizontal Pod Autoscaler changes the shape of your Kubernetes workload by automatically increasing or decreasing the number of Pods in response to the workload's CPU or memory consumption


NEW QUESTION # 21
A third-party application needs to have a service account key to work properly When you try to export the key from your cloud project you receive an error "The organization policy constraint larn.disableServiceAccountKeyCreation is enforcedM You need to make the third-party application work while following Google-recommended security practices What should you do?

  • A. Enable the default service account key. and download the key
  • B. Remove the iam.disableServiceAccountKeyCreation policy at the organization level, and create a key.
  • C. Add a rule to set the iam.disableServiceAccountKeyCreation policy to off in your project and create a key.
  • D. Disable the service account key creation policy at the project's folder, and download the default key

Answer: C

Explanation:
Explanation
The best option for making the third-party application work while following Google-recommended security practices is to add a rule to set the iam.disableServiceAccountKeyCreation policy to off in your project and create a key. The iam.disableServiceAccountKeyCreation policy is an organization policy that controls whether service account keys can be created in a project or organization. By default, this policy is set to on, which means that service account keys cannot be created. However, you can override this policy at a lower level, such as a project, by adding a rule to set it to off. This way, you can create a service account key for your project without affecting other projects or organizations. You should also follow the best practices for managing service account keys, such as rotating them regularly, storing them securely, and deleting them when they are no longer needed.


NEW QUESTION # 22
You are building the Cl/CD pipeline for an application deployed to Google Kubernetes Engine (GKE) The application is deployed by using a Kubernetes Deployment, Service, and Ingress The application team asked you to deploy the application by using the blue'green deployment methodology You need to implement the rollback actions What should you do?

  • A. Delete the new container image, and delete the running Pods
  • B. Update the Kubernetes Service to point to the previous Kubernetes Deployment
  • C. Scale the new Kubernetes Deployment to zero
  • D. Run the kubectl rollout undo command

Answer: B


NEW QUESTION # 23
You support an application deployed on Compute Engine. The application connects to a Cloud SQL instance to store and retrieve dat a. After an update to the application, users report errors showing database timeout messages. The number of concurrent active users remained stable. You need to find the most probable cause of the database timeout. What should you do?

  • A. Check the serial port logs of the Compute Engine instance.
  • B. Use Stackdriver Profiler to visualize the resources utilization throughout the application.
  • C. Determine whether there is an increased number of connections to the Cloud SQL instance.
  • D. Use Cloud Security Scanner to see whether your Cloud SQL is under a Distributed Denial of Service (DDoS) attack.

Answer: A


NEW QUESTION # 24
You are monitoring a service that uses n2-standard-2 Compute Engine instances that serve large files. Users have reported that downloads are slow. Your Cloud Monitoring dashboard shows that your VMS are running at peak network throughput. You want to improve the network throughput performance. What should you do?

  • A. Deploy the Ops Agent to export additional monitoring metrics.
  • B. Add additional network interface controllers (NICs) to your VMS.
  • C. Deploy a Cloud NAT gateway and attach the gateway to the subnet of the VMS.
  • D. Change the machine type for your VMS to n2-standard-8.

Answer: D

Explanation:
Explanation
The correct answer is C. Change the machine type for your VMs to n2-standard-8.
According to the Google Cloud documentation, the network throughput performance of a Compute Engine VM depends on its machine type1. The n2-standard-2 machine type has a maximum egress bandwidth of 4 Gbps, which can be a bottleneck for serving large files. By changing the machine type to n2-standard-8, you can increase the maximum egress bandwidth to 16 Gbps, which can improve the network throughput performance and reduce the download time for users. You also need to enable per VM Tier_1 networking performance, which is a feature that allows VMs to achieve higher network performance than the default settings2.
The other options are incorrect because they do not improve the network throughput performance of your VMs. Option A is incorrect because Cloud NAT is a service that allows private IP addresses to access the internet, but it does not increase the network bandwidth or speed3. Option B is incorrect because adding additional network interfaces (NICs) or IP addresses per NIC does not increase ingress or egress bandwidth for a VM1. Option D is incorrect because deploying the Ops Agent can help you monitor and troubleshoot your VMs, but it does not affect the network throughput performance4.


NEW QUESTION # 25
You are configuring your CI/CD pipeline natively on Google Cloud. You want builds in a pre-production Google Kubernetes Engine (GKE) environment to be automatically load-tested before being promoted to the production GKE environment. You need to ensure that only builds that have passed this test are deployed to production. You want to follow Google-recommended practices. How should you configure this pipeline with Binary Authorization?

  • A. Create an attestation for the builds that pass the load test by requiring the lead quality assurance engineer to sign the attestation by using their personal private key.
  • B. Create an attestation for the builds that pass the load test by using a private key stored in Cloud Key Management Service (Cloud KMS) authenticated through Workload Identity.
  • C. Create an attestation for the builds that pass the load test by requiring the lead quality assurance engineer to sign the attestation by using a key stored in Cloud Key Management Service (Cloud KMS).
  • D. Create an attestation for the builds that pass the load test by using a private key stored in Cloud Key Management Service (Cloud KMS) with a service account JSON key stored as a Kubernetes Secret.

Answer: B

Explanation:
Explanation
The correct answer is B. Create an attestation for the builds that pass the load test by using a private key stored in Cloud Key Management Service (Cloud KMS) authenticated through Workload Identity.
According to the Google Cloud documentation, Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed on Google Kubernetes Engine (GKE) or Cloud Run1.
Binary Authorization uses attestations to certify that a specific image has completed a previous stage in the CI/CD pipeline, such as passing a load test2. Attestations are signed by private keys that are associated with attestors, which are entities that verify the attestations3. To follow Google-recommended practices, you should store your private keys in Cloud Key Management Service (Cloud KMS), which is a secure and scalable service for managing cryptographic keys4. You should also use Workload Identity, which is a feature that allows Kubernetes service accounts to act as Google service accounts, to authenticate to Cloud KMS and sign attestations without having to manage or expose service account keys5.
The other options are incorrect because they do not follow Google-recommended practices. Option A and option D require human intervention to sign the attestations, which is not scalable or automated. Option C exposes the service account JSON key as a Kubernetes Secret, which is less secure than using Workload Identity.


NEW QUESTION # 26
The new version of your containerized application has been tested and is ready to be deployed to production on Google Kubernetes Engine (GKE) You could not fully load-test the new version in your pre-production environment and you need to ensure that the application does not have performance problems after deployment Your deployment must be automated What should you do?

  • A. Deploy the application through a continuous delivery pipeline by using canary deployments Use Cloud Monitoring to look for performance issues, and ramp up traffic as supported by the metrics
  • B. Deploy the application through a continuous delivery pipeline by using blue/green deployments Migrate traffic to the new version of the application and use Cloud Monitoring to look for performance issues
  • C. Deploy the application by using kubectl and use Config Connector to slowly ramp up traffic between versions. Use Cloud Monitoring to look for performance issues
  • D. Deploy the application by using kubectl and set the spec. updatestrategy. type field to RollingUpdate Use Cloud Monitoring to look for performance issues, and run the kubectl rollback command if there are any issues.

Answer: A


NEW QUESTION # 27
You need to create a Cloud Monitoring SLO for a service that will be published soon. You want to verify that requests to the service will be addressed in fewer than 300 ms at least 90% Of the time per calendar month.
You need to identify the metric and evaluation method to use. What should you do?

  • A. Select an availability metric for a window-based method Of evaluation.
  • B. Select a latency metric for a request-based method of evaluation.
  • C. Select an availability metric for a request-based method of evaluation.
  • D. Select a latency metric for a window-based method of evaluation.

Answer: B

Explanation:
The correct answer is A. Select a latency metric for a request-based method of evaluation.
A latency metric measures how responsive your service is to users.For example, you can use thecloud.
googleapis.com/http/server/response_latenciesmetric to measure the latency of HTTP requests to your service1. A request-based method of evaluation counts the number of successful requests that meet a certain criterion, such as being below a latency threshold, and compares it to the number of all requests.For example, you can define an SLI as the ratio of requests with latency below 300 ms to all requests2. A request-based method of evaluation is suitable for measuring performance over time, such as per calendar month.You can set an SLO for the SLI to be at least 90%, which means that you expect 90% of the requests to have latency below 300 ms in a month3.
Reference:
Creating an SLO | Operations Suite | Google Cloud, Choosing a metric, Latency metric.Concepts in service monitoring | Operations Suite | Google Cloud, Service-level indicators, Request-based SLIs.Learn how to set SLOs - SRE tips | Google Cloud Blog, Setting SLOs.


NEW QUESTION # 28
You are configuring a Cl pipeline. The build step for your Cl pipeline integration testing requires access to APIs inside your private VPC network. Your security team requires that you do not expose API traffic publicly. You need to implement a solution that minimizes management overhead. What should you do?

  • A. Use Cloud Build as a pipeline runner. Configure Internal HTTP(S) Load Balancing for API access.
  • B. Use Cloud Build as a pipeline runner. Configure External HTTP(S) Load Balancing with a Google Cloud Armor policy for API access.
  • C. Use Cloud Build private pools to connect to the private VPC.
  • D. Use Spinnaker for Google Cloud to connect to the private VPC.

Answer: C


NEW QUESTION # 29
You manage several production systems that run on Compute Engine in the same Google Cloud Platform (GCP) project. Each system has its own set of dedicated Compute Engine instances. You want to know how must it costs to run each of the systems. What should you do?

  • A. Enrich all instances with metadata specific to the system they run. Configure Stackdriver Logging to export to BigQuery, and query costs based on the metadata.
  • B. Assign all instances a label specific to the system they run. Configure BigQuery billing export and query costs per label.
  • C. In the Google Cloud Platform Console, use the Cost Breakdown section to visualize the costs per system.
  • D. Name each virtual machine (VM) after the system it runs. Set up a usage report export to a Cloud Storage bucket. Configure the bucket as a source in BigQuery to query costs based on VM name.

Answer: D


NEW QUESTION # 30
You have a pool of application servers running on Compute Engine. You need to provide a secure solution that requires the least amount of configuration and allows developers to easily access application logs for troubleshooting. How would you implement the solution on GCP?

  • A. * Deploy the Stackdriver logging agent to the application servers.
    * Give the developers the IAM Logs Private Logs Viewer role to access Stackdriver and view logs.
  • B. * Install the gsutil command line tool on your application servers.
    * Write a script using gsutil to upload your application log to a Cloud Storage bucket, and then schedule it to run via cron every 5 minutes.
    * Give the developers the IAM Object Viewer access to view the logs in the specified bucket.
  • C. * Deploy the Stackdriver monitoring agent to the application servers.
    * Give the developers the IAM Monitoring Viewer role to access Stackdriver and view metrics.
  • D. * Deploy the Stackdriver logging agent to the application servers.
    * Give the developers the IAM Logs Viewer role to access Stackdriver and view logs.

Answer: A


NEW QUESTION # 31
You are troubleshooting a failed deployment in your CI/CD pipeline. The deployment logs indicate that the application container failed to start due to a missing environment variable. You need to identify the root cause and implement a solution within your CI/CD workflow to prevent this issue from recurring. What should you do?

  • A. Enable Cloud Audit Logs for the deployment.
  • B. Run integration tests in the CI pipeline.
  • C. Use a canary deployment strategy.
  • D. Implement static code analysis in the CI pipeline.

Answer: B


NEW QUESTION # 32
Your team of Infrastructure DevOps Engineers is growing, and you are starting to use Terraform to manage infrastructure. You need a way to implement code versioning and to share code with other team members.
What should you do?

  • A. Store the Terraform code in a shared Google Drive folder so it syncs automatically to every team member's computer. Organize files with a naming convention that identifies each new version.
  • B. Store the Terraform code in a version-control system. Establish procedures for pushing new versions and merging with the master.
  • C. Store the Terraform code in a Cloud Storage bucket using object versioning. Give access to the bucket to every team member so they can download the files.
  • D. Store the Terraform code in a network shared folder with child folders for each version release. Ensure that everyone works on different files.

Answer: B

Explanation:
Explanation
https://www.terraform.io/docs/cloud/guides/recommended-practices/part3.3.html


NEW QUESTION # 33
Your organization uses a change advisory board (CAB) to approve all changes to an existing service You want to revise this process to eliminate any negative impact on the software delivery performance What should you do?
Choose 2 answers

  • A. Move to a peer-review based process for individual changes that is enforced at code check-in time and supported by automated tests
  • B. Replace the CAB with a senior manager to ensure continuous oversight from development to deployment
  • C. Let developers merge their own changes but ensure that the team's deployment platform can roll back changes if any issues are discovered
  • D. Ensure that the team's development platform enables developers to get fast feedback on the impact of their changes
  • E. Batch changes into larger but less frequent software releases

Answer: A,D

Explanation:
A change advisory board (CAB) is a traditional way of approving changes to a service, but it can slow down the software delivery performance and introduce bottlenecks. A better way to improve the speed and quality of changes is to use a peer-review based process for individual changes that is enforced at code check-in time and supported by automated tests. This way, developers can get fast feedback on the impact of their changes and catch any errors or bugs before they reach production. Additionally, the team's development platform should enable developers to get fast feedback on the impact of their changes, such as using Cloud Code, Cloud Build, or Cloud Debugger.


NEW QUESTION # 34
You support a high-traffic web application and want to ensure that the home page loads in a timely manner. As a first step, you decide to implement a Service Level Indicator (SLI) to represent home page request latency with an acceptable page load time set to 100 ms. What is the Google-recommended way of calculating this SLI?

  • A. Count the number of home page requests that load in under 100 ms, and then divide by the total number of home page requests.
  • B. Count the number of home page requests that load in under 100 ms. and then divide by the total number of all web application requests.
  • C. Bucketize the request latencies into ranges, and then compute the median and 90th percentiles.
  • D. Buckelize Ihe request latencies into ranges, and then compute the percentile at 100 ms.

Answer: A


NEW QUESTION # 35
......

Verified Professional-Cloud-DevOps-Engineer dumps Q&As - Pass Guarantee Exam Dumps Test Engine: https://www.pass4surequiz.com/Professional-Cloud-DevOps-Engineer-exam-quiz.html

Professional-Cloud-DevOps-Engineer Dumps for Pass Guaranteed - Pass Professional-Cloud-DevOps-Engineer Exam: https://drive.google.com/open?id=1wfIjQ3N689bPPwD3pLStUMkuiGm8ztc-