โ† All Cloud Engineer Flashcard Decks

Case Studies & Practical Application Flashcards

7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Case Studies & Practical Application flashcards as text
  1. A startup uses a single AWS account for all environments. Security audit finds developers can access production RDS from their laptops. What is the correct architectural fix?

    Answer: Separate production into its own AWS account and use AWS Organizations SCPs to restrict access

    Account-level isolation using AWS Organizations and SCPs provides the strongest boundary; IAM policies within the same account can be misconfigured or overridden by admins.

  2. A video encoding pipeline on GCP uses Cloud Run to process uploads from Cloud Storage. During peak hours, unprocessed files accumulate for 2 hours. Cloud Run scales to max instances but CPU is only 40%. What is the bottleneck?

    Answer: The Cloud Storage trigger uses Pub/Sub, and the subscription's max outstanding messages limit is too low

    Pub/Sub's max outstanding messages setting limits how many messages are delivered to subscribers concurrently; increasing it allows more Cloud Run instances to process files simultaneously.

  3. An Azure-hosted app uses Managed Identity to access Key Vault. After deploying a new version of the app, it fails to read secrets with a 403 error. The Managed Identity and Key Vault access policy are unchanged. What changed?

    Answer: The new deployment uses a different App Service plan that has a new Managed Identity object ID

    If the new deployment created a new App Service or slot, it may have a different system-assigned Managed Identity principal ID that is not in the Key Vault access policy.

  4. A company runs a Kafka cluster on AWS EC2. Producers experience high latency when a broker goes down. The cluster has 3 brokers with replication factor 3. What configuration change reduces leader election time?

    Answer: Enable Kafka KRaft mode to remove ZooKeeper dependency

    KRaft mode replaces ZooKeeper-based metadata management with a built-in Raft consensus protocol, significantly reducing controller failover and leader election time.

  5. A microservices app on GKE uses ConfigMaps for environment-specific configuration. After a ConfigMap update, pods continue using old values. What is the cause?

    Answer: Environment variables from ConfigMaps are injected at pod startup and do not update in running pods

    Kubernetes injects ConfigMap values as environment variables only at pod creation; to pick up changes, pods must be restarted or the ConfigMap must be mounted as a volume (which updates dynamically).

  6. A global company uses AWS CloudFront with an ALB origin. European users report GDPR-sensitive data appearing in US CloudFront logs. What is the correct control to restrict where logs are stored?

    Answer: Configure CloudFront to deliver access logs to an S3 bucket located in an EU region and restrict replication

    CloudFront access logs can be delivered to any S3 bucket you specify; choosing an EU-region bucket with no cross-region replication keeps log data within the required jurisdiction.

  7. A team deploys a new Azure Function with a consumption plan. The function processes images from Blob Storage. Large images (>10MB) cause timeout errors despite a 5-minute function timeout setting. What is the actual constraint?

    Answer: Azure Functions consumption plan has a default 230-second HTTP request timeout enforced by Azure Front Door/Load Balancer

    The Azure infrastructure load balancer enforces a 230-second idle timeout for HTTP-triggered functions, which can preempt the function's own timeout setting for long-running operations.