[Q112-Q134] Excellent Associate-Cloud-Engineer PDF Dumps With 100% TestBraindump Exam Passing Guaranted [Aug-2021] | TestBraindump

[Q112-Q134] Excellent Associate-Cloud-Engineer PDF Dumps With 100% TestBraindump Exam Passing Guaranted [Aug-2021]

Share

Excellent Associate-Cloud-Engineer PDF Dumps With 100% TestBraindump Exam Passing Guaranted [Aug-2021]

100% Pass Your Associate-Cloud-Engineer Google Associate Cloud Engineer Exam at First Attempt with TestBraindump

NEW QUESTION 112
Your finance team wants to view the billing report for your projects. You want to make sure that the finance team does not get additional permissions to the project. What should you do?

  • A. Add the group for the finance team to roles/billing project/Manager role.
  • B. Add the group for the finance team to roles/billing viewer role.
  • C. Add the group for the finance team to roles/billing user role.
  • D. Add the group for the finance team to roles/billing admin role.

Answer: B

Explanation:
Billing Account Viewer access would usually be granted to finance teams, it provides access to spend information, but does not confer the right to link or unlink projects or otherwise manage the properties of the billing account.
https://cloud.google.com/billing/docs/how-to/billing-access

 

NEW QUESTION 113
You need to create a new billing account and then link it with an existing Google Cloud Platform project. What should you do?

  • A. Verify that you are Billing Administrator for the billing account. Update the existing project to link it to the existing billing account.
  • B. Verify that you are Project Billing Manager for the GCP project. Create a new billing account and link the new billing account to the existing project.
  • C. Verify that you are Billing Administrator for the billing account. Create a new project and link the new project to the existing billing account.
  • D. Verify that you are Project Billing Manager for the GCP project. Update the existing project to link it to the existing billing account.

Answer: C

Explanation:
Reference:
https://cloud.google.com/billing/docs/how-to/modify-project

 

NEW QUESTION 114
You need to grant access for three users so that they can view and edit table data on a Cloud Spanner instance. What should you do?

  • A. Run gcloud iam roles describe roles/spanner.databaseUser. Add the users to the role.
  • B. Run gcloud iam roles describe roles/spanner.databaseUser. Add the users to a new group.
    Add the group to the role.
  • C. Run gcloud iam roles describe roles/spanner.viewer - -project my-project. Add the users to a new group. Add the group to the role.
  • D. Run gcloud iam roles describe roles/spanner.viewer - -project my-project. Add the users to the role.

Answer: A

 

NEW QUESTION 115
Your projects incurred more costs than you expected last month. Your research reveals that a development GKE container emitted a huge number of logs, which resulted in higher costs. You want to disable the logs quickly using the minimum number of steps. What should you do?

  • A. 1. Go to the Logs ingestion window in Stackdriver Logging, and disable the log source for the GKE Cluster Operations resource.
  • B. 1. Go to the GKE console, and delete existing clusters.2. Recreate a new cluster.3. Clear the option to enable legacy Stackdriver Monitoring.
  • C. 1. Go to the GKE console, and delete existing clusters.2. Recreate a new cluster.3. Clear the option to enable legacy Stackdriver Logging.
  • D. 1. Go to the Logs ingestion window in Stackdriver Logging, and disable the log source for the GKE container resource.

Answer: D

 

NEW QUESTION 116
Your Dataproc cluster runs in a single Virtual Private Cloud (VPC) network in a single subnet with range 172.16.20.128/25. There are no private IP addresses available in the VPC network. You want to add new VMs to communicate with your cluster using the minimum number of steps. What should you do?

  • A. Create a new VPC network for the VMs with a subnet of 172.32.0.0/16. Enable VPC network Peering between the Dataproc VPC network and the VMs VPC network. Configure a custom Route exchange.
    A subnet has a single primary IP address range and, optionally, one or more secondary IP address ranges. For each subnet IP address range, Google Cloud creates a subnet route. When you use VPC Network Peering, Google Cloud always exchanges the subnet routes that don't use privately reused public IP addresses between the two peered networks. If firewall rules in each network permit communication, VM instances in one network can communicate with instances in the peered network.
  • B. Create a new Secondary IP Range in the VPC and configure the VMs to use that range.
  • C. Modify the existing subnet range to 172.16.20.0/24.
  • D. Create a new VPC network for the VMs. Enable VPC Peering between the VMs' VPC network and the Dataproc cluster VPC network.

Answer: B

Explanation:
Reference:
https://cloud.google.com/vpc/docs/vpc-peering

 

NEW QUESTION 117
You need to manage multiple Google Cloud Platform (GCP) projects in the fewest steps possible. You want to configure the Google Cloud SDK command line interface (CLI) so that you can easily manage multiple GCP projects. What should you?

  • A. 1. Create a configuration for each project you need to manage.
    2. Activate the appropriate configuration when you work with each of your assigned GCP projects.
  • B. 1. Use the default configuration for one project you need to manage.
    2. Use gcloud init to update the configuration values when you need to work with a non-default project.
  • C. 1. Use the default configuration for one project you need to manage.
    2. Activate the appropriate configuration when you work with each of your assigned GCP projects.
  • D. 1. Create a configuration for each project you need to manage.
    2. Use gcloud init to update the configuration values when you need to work with a non-default project

Answer: B

 

NEW QUESTION 118
You want to configure 10 Compute Engine instances for availability when maintenance occurs. Your requirements state that these instances should attempt to automatically restart if they crash. Also, the instances should be highly available including during system maintenance. What should you do?

  • A. Create an instance group for the instance. Verify that the 'Advanced creation options' setting for 'do not retry machine creation' is set to off.
  • B. Create an instance template for the instances. Set 'Automatic Restart' to off. Set 'On-host maintenance' to Terminate VM instances. Add the instance template to an instance group.
  • C. Create an instance template for the instances. Set the 'Automatic Restart' to on. Set the 'On-host maintenance' to Migrate VM instance. Add the instance template to an instance group.
  • D. Create an instance group for the instances. Set the 'Autohealing' health check to healthy (HTTP).

Answer: B

 

NEW QUESTION 119
You need to create a custom VPC with a single subnet. The subnet's range must be as large as possible. Which range should you use?

  • A. .00.0.0/0
  • B. 172.16.0.0/12
  • C. 10.0.0.0/8
  • D. 192.168.0.0/16

Answer: C

Explanation:
Explanation
https://cloud.google.com/vpc/docs/vpc#manually_created_subnet_ip_ranges

 

NEW QUESTION 120
You are building an archival solution for your data warehouse and have selected Cloud Storage to archive your dat a. Your users need to be able to access this archived data once a quarter for some regulatory requirements. You want to select a cost-efficient option. Which storage option should you use?

  • A. Cold Storage
  • B. Regional Storage
  • C. Multi-Regional Storage
  • D. Nearline Storage

Answer: A

Explanation:
Nearline, Coldline, and Archive offer ultra low-cost, highly-durable, highly available archival storage. For data accessed less than once a year, Archive is a cost-effective storage option for long-term preservation of data.
Coldline is also ideal for cold storage-data your business expects to touch less than once a quarter. For warmer storage, choose Nearline: data you expect to access less than once a month, but possibly multiple times throughout the year. All storage classes are available across all GCP regions and provide unparalleled sub-second access speeds with a consistent API.
Reference:
https://cloud.google.com/storage/archival

 

NEW QUESTION 121
You created several resources in multiple Google Cloud projects. All projects are linked to different billing accounts. To better estimate future charges, you want to have a single visual representation of all costs incurred. You want to include new cost data as soon as possible. What should you do?

  • A. Visit the Cost Table page to get a CSV export and visualize it using Data Studio.
  • B. Use the Reports view in the Cloud Billing Console to view the desired cost information.
  • C. Configure Billing Data Export to BigQuery and visualize the data in Data Studio.
  • D. Fill all resources in the Pricing Calculator to get an estimate of the monthly cost.

Answer: C

 

NEW QUESTION 122
You want to configure 10 Compute Engine instances for availability when maintenance occurs.
Your requirements state that these instances should attempt to automatically restart if they crash.
Also, the instances should be highly available including during system maintenance. What should you do?

  • A. Create an instance group for the instances.
    Set the `Autohealing' health check to healthy (HTTP).
  • B. Create an instance template for the instances.
    Set the `Automatic Restart' to on. Set the `On-host maintenance' to Migrate VM instance.
    Add the instance template to an intsance group.
  • C. Create an instance group for the instance.
    Verify that the `Advanced creation options' setting for `do not retry machine creation' is set to off.
  • D. Create an instance template for the instances.
    `Automatic Restart' to off. Set `On-host maintenance' to Terminate VM instances.
    Add the instance template to an instance group.

Answer: B

Explanation:
Configure an instance's maintenance behavior and automatic restart setting using the onHostMaintenance and automaticRestart properties. All instances are configured with default values unless you explicitly specify otherwise.
onHostMaintenance: Determines the behavior when a maintenance event occurs that might cause your instance to reboot.
[Default] migrate, which causes Compute Engine to live migrate an instance when there is a maintenance event.
terminate, which terminates an instance instead of migrating it.

 

NEW QUESTION 123
You are building an application that stores relational data from users. Users across the globe will use this application. Your CTO is concerned about the scaling requirements because the size of the user base is unknown. You need to implement a database solution that can scale with your user growth with minimum configuration changes. Which storage solution should you use?

  • A. Cloud Firestore
  • B. Cloud Datastore
  • C. Cloud SQL
  • D. Cloud Spanner

Answer: B

 

NEW QUESTION 124
You need to run an important query in BigQuery but expect it to return a lot of records. You want to find out how much it will cost to run the query. You are using on-demand pricing. What should you do?

  • A. Arrange to switch to Flat-Rate pricing for this query, then move back to on-demand.
  • B. Use the command line to run a dry run query to estimate the number of bytes returned.
    Then convert that bytes estimate to dollars using the Pricing Calculator.
  • C. Run a select count (*) to get an idea of how many records your query will look through.
    Then convert that number of rows to dollars using the Pricing Calculator.
  • D. Use the command line to run a dry run query to estimate the number of bytes read.
    Then convert that bytes estimate to dollars using the Pricing Calculator.

Answer: D

 

NEW QUESTION 125
You want to add a new auditor to a Google Cloud Platform project. The auditor should be allowed to read, but not modify, all project items.
How should you configure the auditor's permissions?

  • A. Create a custom role with view-only project permissions. Add the user's account to the custom role.
  • B. Select the built-in IAM service Viewer role. Add the user's account to this role.
  • C. Create a custom role with view-only service permissions. Add the user's account to the custom role.
  • D. Select the built-in IAM project Viewer role. Add the user's account to this role.

Answer: D

Explanation:
Reference:
https://cloud.google.com/resource-manager/docs/access-control-proj

 

NEW QUESTION 126
Your company has a 3-tier solution running on Compute Engine. The configuration of the current infrastructure is shown below.

Each tier has a service account that is associated with all instances within it. You need to enable communication on TCP port 8080 between tiers as follows:
- Instances in tier #1 must communicate with tier #2.
- Instances in tier #2 must communicate with tier #3.
What should you do?

  • A. 1. Create an ingress firewall rule with the following settings:
    Targets: all instances
    Source filter: IP ranges (with the range set to 10.0.2.0/24)
    Protocols: allow all
    2. Create an ingress firewall rule with the following settings:
    Targets: all instances
    Source filter: IP ranges (with the range set to 10.0.1.0/24)
    Protocols: allow all
  • B. 1. Create an ingress firewall rule with the following settings:
    Targets: all instances with tier #2 service account
    Source filter: all instances with tier #1 service account
    Protocols: allow all
    2. Create an ingress firewall rule with the following settings:
    Targets: all instances with tier #3 service account
    Source filter: all instances with tier #2 service account
    Protocols: allow all
  • C. 1. Create an egress firewall rule with the following settings:
    Targets: all instances
    Source filter: IP ranges (with the range set to 10.0.2.0/24)
    Protocols: allow TCP: 8080
    2. Create an egress firewall rule with the following settings:
    Targets: all instances
    Source filter: IP ranges (with the range set to 10.0.1.0/24)
    Protocols: allow TCP: 8080
  • D. 1. Create an ingress firewall rule with the following settings:
    Targets: all instances with tier #2 service account
    Source filter: all instances with tier #1 service account
    Protocols: allow TCP:8080
    2. Create an ingress firewall rule with the following settings:
    Targets: all instances with tier #3 service account
    Source filter: all instances with tier #2 service account
    Protocols: allow TCP: 8080

Answer: D

 

NEW QUESTION 127
You have a single binary application that you want to run on Google Cloud Platform. You decided to automatically scale the application based on underlying infrastructure CPU usage. Your organizational policies require you to use virtual machines directly. You need to ensure that the application scaling is operationally efficient and completed as quickly as possible. What should you do?

  • A. Create a Google Kubernetes Engine cluster, and use horizontal pod autoscaling to scale the application.
  • B. Create an instance template, and use the template in a managed instance group with autoscaling configured.
  • C. Use a set of third-party tools to build automation around scaling the application up and down, based on Stackdriver CPU usage monitoring.
  • D. Create an instance template, and use the template in a managed instance group that scales up and down based on the time of day.

Answer: A

 

NEW QUESTION 128
Your company runs its Linux workloads on Compute Engine instances. Your company will be working with a new operations partner that does not use Google Accounts. You need to grant access to the instances to your operations partner so they can maintain the installed tooling. What should you do?

  • A. Tag all the instances with the same network tag. Create a firewall rule in the VPC to grant TCP access on port 22 for traffic from the operations partner to instances with the network tag.
  • B. Enable Cloud IAP for the Compute Engine instances, and add the operations partner as a Cloud IAP Tunnel User.
  • C. Ask the operations partner to generate SSH key pairs, and add the public keys to the VM instances.
  • D. Set up Cloud VPN between your Google Cloud VPC and the internal network of the operations partner.

Answer: A

 

NEW QUESTION 129
You need to select and configure compute resources for a set of batch processing jobs. These jobs take around 2 hours to complete and are run nightly. You want to minimize service costs. What should you do?

  • A. Select Google Kubernetes Engine. Use a single-node culster with a small instance type.
  • B. Select Compute Engine. Use VM instance types that support micro bursting.
  • C. Select Google Kubernetes Engine. Use a three-node cluster with micro instance type.
  • D. Select Compute Engine. Use preemptible VM instances of the appropriate standard machine type.

Answer: D

 

NEW QUESTION 130
Your company has a single sign-on (SSO) identity provider that supports Security Assertion Markup Language (SAML) integration with service providers. Your company has users in Cloud Identity. You would like users to authenticate using your company's SSO provider. What should you do?

  • A. In Cloud Identity, set up SSO with Google as an identity provider to access custom SAML apps.
  • B. In Cloud Identity, set up SSO with a third-party identity provider with Google as a service provider.
  • C. Obtain OAuth 2.0 credentials, configure the user consent screen, and set up OAuth 2.0 for Mobile & Desktop Apps.
  • D. Obtain OAuth 2.0 credentials, configure the user consent screen, and set up OAuth 2.0 for Web Server Applications.

Answer: A

 

NEW QUESTION 131
You have a Compute Engine instance hosting a production application. You want to receive an email if the instance consumes more than 90% of its CPU resources for more than 15 minutes. You want to use Google services. What should you do?

  • A. 1. Create a Stackdriver Workspace, and associate your GCP project with it.
    2. Write a script that monitors the CPU usage and sends it as a custom metric to Stackdriver.
    3. Create an uptime check for the instance in Stackdriver.
  • B. 1. In Stackdriver Logging, create a logs-based metric to extract the CPU usage by using this regular expression: CPU Usage: ([0-9] {1,3})%
    2. In Stackdriver Monitoring, create an Alerting Policy based on this metric.
    3. Configure your email address in the notification channel.
  • C. 1. Create a Stackdriver Workspace, and associate your Google Cloud Platform (GCP) project with it.
    2. Create an Alerting Policy in Stackdriver that uses the threshold as a trigger condition.
    3. Configure your email address in the notification channel.
  • D. 1. Create a consumer Gmail account.
    2. Write a script that monitors the CPU usage.
    3. When the CPU usage exceeds the threshold, have that script send an email using the Gmail account and smtp.gmail.comon port 25 as SMTP server.

Answer: B

Explanation:
Explanation/Reference:

 

NEW QUESTION 132
An employee was terminated, but their access to Google Cloud Platform (GCP) was not removed until 2 weeks later. You need to find out this employee accessed any sensitive customer information after their termination. What should you do?

  • A. View System Event Logs in Stackdriver. Search for the user's email as the principal.
  • B. View the Admin Activity log in Stackdriver. Search for the service account associated with the user.
  • C. View System Event Logs in Stackdriver. Search for the service account associated with the user.
  • D. View Data Access audit logs in Stackdriver. Search for the user's email as the principal.

Answer: C

 

NEW QUESTION 133
You need to create a custom VPC with a single subnet. The subnet's range must be as large as possible.
Which range should you use?

  • A. 0.0.0.0/0
  • B. 172.16.0.0/12
  • C. 10.0.0.0/8
  • D. 192.168.0.0/16

Answer: C

 

NEW QUESTION 134
......

Trend for Associate-Cloud-Engineer pdf dumps before actual exam: https://www.testbraindump.com/Associate-Cloud-Engineer-exam-prep.html

Real Exam Questions & Answers - Google Associate-Cloud-Engineer Dump is Ready: https://drive.google.com/open?id=1zvxF84NnQelOc6-qymSUx4zu6qDj8P9k