Cloud Engineer: Essential Google Infrastructure Flashcards
7 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Cloud Engineer: Essential Google Infrastructure flashcards as text
A Cloud Engineer needs to give a third-party vendor temporary access to a GCP Storage bucket without creating a GCP account for them. What is the recommended approach?
Answer: Generate a Signed URL with an expiration time
Signed URLs grant time-limited access to a specific GCS object without requiring the recipient to have a GCP account.
Which Compute Engine feature allows you to create a consistent snapshot of a persistent disk even while the disk is in use?
Answer: Persistent Disk Snapshot
Persistent Disk Snapshots in GCP are application-consistent, incremental backups that can be taken while the disk is attached and in use.
What is the role of Workload Identity Federation in GCP?
Answer: It maps Kubernetes service accounts to GCP service accounts without key files
Workload Identity Federation (for GKE specifically Workload Identity) lets Kubernetes workloads authenticate to GCP APIs as a service account without needing exported key files.
A Cloud Engineer configures a Cloud Armor security policy on an HTTP(S) Load Balancer. What can Cloud Armor protect against?
Answer: DDoS attacks and OWASP Top 10 web application threats
Cloud Armor provides DDoS protection and WAF capabilities with pre-configured rules for OWASP Top 10 threats at the load balancer edge.
In BigQuery, what is a partitioned table and what is its primary benefit?
Answer: A table divided into segments based on a column value to reduce query cost and improve performance
Partitioned tables divide data by a column (e.g., date) so queries that filter on that column scan only relevant partitions, reducing cost and latency.
Which GCP tool enables infrastructure provisioning using declarative configuration files, supporting version control and repeatable deployments?
Answer: Cloud Deployment Manager
Cloud Deployment Manager allows you to define GCP infrastructure in YAML or Python templates and manages the lifecycle of those resources declaratively.
What is the purpose of a VPC Service Control perimeter in Google Cloud?
Answer: To define a security boundary around GCP services that prevents data exfiltration
VPC Service Controls create a security perimeter around GCP API services to mitigate data exfiltration risks, even if IAM is misconfigured.