
Get Google Associate-Cloud-Engineer Dumps Questions [2021] To Gain Brilliant Result
Associate-Cloud-Engineer dumps - Lead2PassExam - 100% Passing Guarantee
NEW QUESTION 83
You have sensitive data stored in three Cloud Storage buckets and have enabled data access logging. You want to verify activities for a particular user for these buckets, using the fewest possible steps. You need to verify the addition of metadata labels and which files have been viewed from those buckets. What should you do?
- A. View the bucket in the Storage section of the GCP Console.
- B. Create a trace in Stackdriver to view the information.
- C. Using the GCP Console, filter the Stackdriver log to view the information.
- D. Using the GCP Console, filter the Activity log to view the information.
Answer: D
NEW QUESTION 84
You have a Compute Engine instance hosting a production application. You want to receive an email if the instance consumes more than 90% of its CPU resources for more than 15 minutes. You want to use Google services. What should you do?
- A. 1. Create a Stackdriver Workspace, and associate your GCP project with it.
2. Write a script that monitors the CPU usage and sends it as a custom metric to Stackdriver.
3. Create an uptime check for the instance in Stackdriver. - B. 1. In Stackdriver Logging, create a logs-based metric to extract the CPU usage by using this regular expression: CPU Usage: ([0-9] {1,3})%
2. In Stackdriver Monitoring, create an Alerting Policy based on this metric.
3. Configure your email address in the notification channel. - C. 1. Create a Stackdriver Workspace, and associate your Google Cloud Platform (GCP) project with it.
2. Create an Alerting Policy in Stackdriver that uses the threshold as a trigger condition.
3. Configure your email address in the notification channel. - D. 1. Create a consumer Gmail account.
2. Write a script that monitors the CPU usage.
3. When the CPU usage exceeds the threshold, have that script send an email using the Gmail account and smtp.gmail.comon port 25 as SMTP server.
Answer: B
Explanation:
Explanation/Reference:
NEW QUESTION 85
Your organization has a dedicated person who creates and manages all service accounts for Google Cloud projects. You need to assign this person the minimum role for projects. What should you do?
- A. Add the user to roles/iam.serviceAccountAdmin role.
- B. Add the user to roles/iam.serviceAccountUser role.
- C. Add the user to roles/iam.securityAdmin role.
- D. Add the user to roles/iam.roleAdmin role.
Answer: B
Explanation:
Explanation/Reference: https://cloud.google.com/iam/docs/creating-managing-service-accounts
NEW QUESTION 86
You have an instance group that you want to load balance. You want the load balancer to terminate the client SSL session. The instance group is used to serve a public web application over HTTPS. You want to follow Google-recommended practices. What should you do?
- A. Configure an HTTP(S) load balancer.
- B. Configure an internal TCP load balancer.
- C. Configure an external TCP proxy load balancer.
- D. Configure an external SSL proxy load balancer.
Answer: A
Explanation:
For HTTP(s) Load balancer, the client SSL session terminates at the load balancer.
NEW QUESTION 87
For analysis purposes, you need to send all the logs from all of your Compute Engine instances to a BigQuery dataset called platform-logs. You have already installed the Stackdriver Logging agent on all the instances. You want to minimize cost. What should you do?
- A. 1. Give the BigQuery Data Editor role on the platform-logsdataset to the service accounts used by your instances.
2. Update your instances' metadata to add the following value: logs-destination:
bq://platform-logs. - B. 1. In Stackdriver Logging, create a filter to view only Compute Engine logs.
2. Click Create Export.
3. Choose BigQuery as Sink Service, and the platform-logsdataset as Sink Destination. - C. 1. Create a Cloud Function that has the BigQuery User role on the platform-logsdataset.
2. Configure this Cloud Function to create a BigQuery Job that executes this query:
INSERT INTO dataset.platform-logs (timestamp, log)
SELECT timestamp, log FROM compute.logs
WHERE timestamp > DATE_SUB(CURRENT_DATE(), INTERVAL 1 DAY)
3. Use Cloud Scheduler to trigger this Cloud Function once a day. - D. 1. In Stackdriver Logging, create a logs export with a Cloud Pub/Sub topic called logsas a sink.
2. Create a Cloud Function that is triggered by messages in the logstopic.
3. Configure that Cloud Function to drop logs that are not from Compute Engine and to insert Compute Engine logs in the platform-logsdataset.
Answer: B
NEW QUESTION 88
You have recently joined a startup who is migrating their infrastructure from AWS to Google Cloud. A junior was assigned the task of migrating one of their web server with Amazon Linux OS from AWS to GCP in a public subnet of custom VPC. He was able to migrate the instance successfully but is unable to get SSH access of migrated instance. What are the possible steps to look for? (Multiple Answer)
- A. Ask if he has added SSH key to the instance while launching phase.
- B. Make sure the firewall is attached to the instance with tcp port 22 open.
- C. Check if he has attached correct firewall rule with port udp:22 open to the instance.
- D. Google Cloud does not support Amazon Linux images because of market competition.
Answer: A,B
NEW QUESTION 89
You are running multiple microservices in a Kubernetes Engine cluster. One microservice is rendering images. The microservice responsible for the image rendering requires a large amount of CPU time compared to the memory it requires. The other microservices are workloads that are optimized for n1-standard machine types. You need to optimize your cluster so that all workloads are using resources as efficiently as possible.
What should you do?
- A. Create a node pool with compute-optimized machine type nodes for the image rendering microservice.
Use the node pool with general-purpose machine type nodes for the other microservices - B. Configure the required amount of CPU and memory in the resource requests specification of the image rendering microservice deployment.
Keep the resource requests for the other microservices at the default - C. Use the node pool with general-purpose machine type nodes for lite mage rendering microservice .
Create a nodepool with compute-optimized machine type nodes for the other microservices - D. Assign the pods of the image rendering microservice a higher pod priority than the older microservices
Answer: A
NEW QUESTION 90
Every employee of your company has a Google account. Your operational team needs to manage a large number of instances on Compute Engine. Each member of this team needs only administrative access to the servers. Your security team wants to ensure that the deployment of credentials is operationally efficient and must be able to determine who accessed a given instance. What should you do?
- A. Generate a new SSH key pair. Give the private key to each member of your team. Configure the public key as a project-wide public SSH key in your Cloud Platform project and allow project-wide public SSH keys on each instance.
- B. Ask each member of the team to generate a new SSH key pair and to send you their public key. Use a configuration management tool to deploy those keys on each instance.
- C. Generate a new SSH key pair. Give the private key to each member of your team. Configure the public key in the metadata of each instance.
- D. Ask each member of the team to generate a new SSH key pair and to add the public key to their Google account. Grant the "compute.osAdminLogin" role to the Google group corresponding to this team.
Answer: A
Explanation:
Explanation/Reference: https://cloud.google.com/compute/docs/instances/adding-removing-ssh-keys
NEW QUESTION 91
You want to create a new role for your colleagues that will apply to all current and future projects created in your organization. The role should have the permissions of the BigQuery Job User and Cloud Bigtable User roles. You want to follow Google's recommended practices. How should you create the new role?
- A. Use "gcloud iam combine-roles --global" to combine the 2 roles into a new custom role.
- B. For your organization, in the Google Cloud Platform Console under Roles, select both roles and combine them into a new custom role.
- C. For all projects, in the Google Cloud Platform Console under Roles, select both roles and combine them into a new custom role.
- D. For one of your projects, in the Google Cloud Platform Console under Roles, select both roles and combine them into a new custom role. Use "gcloud iam promote-role" to promote the role from a project role to an organization role.
Answer: B
Explanation:
A is not correct because this does not create a new role.
B is not correct because gcloud cannot promote a role to org level.
C is not correct because it's recommended to define the role on the organization level. Also, the role will not be applied on new projects.
D is correct because this creates a new role with the combined permissions on the organization level.
NEW QUESTION 92
Your projects incurred more costs than you expected last month. Your research reveals that a development GKE container emitted a huge number of logs, which resulted in higher costs. You want to disable the logs quickly using the minimum number of steps. What should you do?
- A. 1. Go to the Logs ingestion window in Stackdriver Logging, and disable the log source for the GKE Cluster Operations resource.
- B. 1. Go to the GKE console, and delete existing clusters.2. Recreate a new cluster.3. Clear the option to enable legacy Stackdriver Monitoring.
- C. 1. Go to the GKE console, and delete existing clusters.2. Recreate a new cluster.3. Clear the option to enable legacy Stackdriver Logging.
- D. 1. Go to the Logs ingestion window in Stackdriver Logging, and disable the log source for the GKE container resource.
Answer: D
NEW QUESTION 93
You're looking for the IP address of a specific instance that is running in your default zone. Which command and flag(s) could you use to return just the IP address?
- A. The gcloud compute instances list along with the filter and format flags.
- B. The gcloud compute list along with the filter and format flags.
- C. The gcloud compute instances list along with the o flag and jsonpath value.
- D. The gcloud compute list along with the o flag and jsonpath value.
Answer: A
NEW QUESTION 94
Your company has workloads running on Compute Engine and on-premises. The Google Cloud Virtual Private Cloud (VPC) is connected to your WAN over a Virtual Private Network (VPN). You need to deploy a new Compute Engine instance and ensure that no public Internet traffic can be routed to it. What should you do?
- A. Create a route on the VPC to route all traffic to the instance over the VPN tunnel.
Get private access to Google services, such as storage, big data, analytics, or machine learning, without having to give your service a public IP address. - B. Create the instance with Private Google Access enabled.
- C. Create the instance without a public IP address.
- D. Create a deny-all egress firewall rule on the VPC network.
Answer: B
Explanation:
Reference:
https://cloud.google.com/vpc
NEW QUESTION 95
Every employee of your company has a Google account. Your operational team needs to manage a large number of instances on Compute Engine. Each member of this team needs only administrative access to the servers. Your security team wants to ensure that the deployment of credentials is operationally efficient and must be able to determine who accessed a given instance. What should you do?
- A. Ask each member of the team to generate a new SSH key pair and to add the public key to their Google account.
Grant the "compute.osAdminLogin" role to the Google group corresponding to this team. - B. Generate a new SSH key pair. Give the private key to each member of your team.
Configure the public key as a project-wide public SSH key in your Cloud Platform project and allow project-wide public SSH keys on each instance. - C. Generate a new SSH key pair. Give the private key to each member of your team.
Configure the public key in the metadata of each instance. - D. Ask each member of the team to generate a new SSH key pair and to send you their public key.
Use a configuration management tool to deploy those keys on each instance.
Answer: B
NEW QUESTION 96
Your team has been working on building a web application. The plan is to deploy to Kubernetes. You currently have a Dockerfile that works locally. How can you get the application deployed to Kubernetes?
- A. Use docker to create a container image, save the image to Cloud Storage, deploy the uploaded image to Kubernetes with kubectl.
- B. Use docker to create a container image, push it to the Google Container Registry, deploy the uploaded image to Kubernetes with kubectl.
- C. Use kubectl to push the convert the Dockerfile into a deployment.
- D. Use kubectl apply to push the Dockerfile to Kubernetes.
Answer: B
NEW QUESTION 97
You're attempting to remove the zone property from the Compute Engine service, that was set with the incorrect value. Which command would accomplish your task?
- A. gcloud config unset compute/zone
- B. gcloud unset compute/zone
- C. gcloud config configurations unset compute/zone
- D. gcloud config unset zone
Answer: A
NEW QUESTION 98
......
Get 100% Passing Success With True Associate-Cloud-Engineer Exam: https://www.lead2passexam.com/Google/valid-Associate-Cloud-Engineer-exam-dumps.html
Premium Quality Google Associate-Cloud-Engineer Online dumps: https://drive.google.com/open?id=1sg0um2D2mKGH8Pl-FFvrtVCQ-E3QMzHK