Case Studies & Practical Application Flashcards
7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Case Studies & Practical Application flashcards as text
A startup uses a single AWS account for all environments. Security audit finds developers can access production RDS from their laptops. What is the correct architectural fix?
Answer: Separate production into its own AWS account and use AWS Organizations SCPs to restrict access
Account-level isolation using AWS Organizations and SCPs provides the strongest boundary; IAM policies within the same account can be misconfigured or overridden by admins.
A video encoding pipeline on GCP uses Cloud Run to process uploads from Cloud Storage. During peak hours, unprocessed files accumulate for 2 hours. Cloud Run scales to max instances but CPU is only 40%. What is the bottleneck?
Answer: The Cloud Storage trigger uses Pub/Sub, and the subscription's max outstanding messages limit is too low
Pub/Sub's max outstanding messages setting limits how many messages are delivered to subscribers concurrently; increasing it allows more Cloud Run instances to process files simultaneously.
An Azure-hosted app uses Managed Identity to access Key Vault. After deploying a new version of the app, it fails to read secrets with a 403 error. The Managed Identity and Key Vault access policy are unchanged. What changed?
Answer: The new deployment uses a different App Service plan that has a new Managed Identity object ID
If the new deployment created a new App Service or slot, it may have a different system-assigned Managed Identity principal ID that is not in the Key Vault access policy.
A company runs a Kafka cluster on AWS EC2. Producers experience high latency when a broker goes down. The cluster has 3 brokers with replication factor 3. What configuration change reduces leader election time?
Answer: Enable Kafka KRaft mode to remove ZooKeeper dependency
KRaft mode replaces ZooKeeper-based metadata management with a built-in Raft consensus protocol, significantly reducing controller failover and leader election time.
A microservices app on GKE uses ConfigMaps for environment-specific configuration. After a ConfigMap update, pods continue using old values. What is the cause?
Answer: Environment variables from ConfigMaps are injected at pod startup and do not update in running pods
Kubernetes injects ConfigMap values as environment variables only at pod creation; to pick up changes, pods must be restarted or the ConfigMap must be mounted as a volume (which updates dynamically).
A global company uses AWS CloudFront with an ALB origin. European users report GDPR-sensitive data appearing in US CloudFront logs. What is the correct control to restrict where logs are stored?
Answer: Configure CloudFront to deliver access logs to an S3 bucket located in an EU region and restrict replication
CloudFront access logs can be delivered to any S3 bucket you specify; choosing an EU-region bucket with no cross-region replication keeps log data within the required jurisdiction.
A team deploys a new Azure Function with a consumption plan. The function processes images from Blob Storage. Large images (>10MB) cause timeout errors despite a 5-minute function timeout setting. What is the actual constraint?
Answer: Azure Functions consumption plan has a default 230-second HTTP request timeout enforced by Azure Front Door/Load Balancer
The Azure infrastructure load balancer enforces a 230-second idle timeout for HTTP-triggered functions, which can preempt the function's own timeout setting for long-running operations.