← All Cloud Engineer Flashcard Decks

Mixed Deck — All Cloud Engineer Topics Flashcards

100 cards from real Cloud Engineer practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 20 Mixed Deck — All Cloud Engineer Topics flashcards as text
  1. A startup's MongoDB Atlas cluster on GCP starts receiving read timeouts during business hours. Atlas charts show the primary node's opcounters are normal but query executor scanned 10M documents per query. What should the engineer do?

    Answer: Identify the queries using Atlas Performance Advisor and create compound indexes on the high-cardinality filter fields

    Scanning 10M documents per query is a collection scan; the correct fix is indexing the fields used in query filters, which reduces the scanned document count from millions to the result set size.

  2. What Google Cloud tool continuously scans GCP configurations for security misconfigurations and compliance violations?

    Answer: Security Command Center

    Security Command Center (SCC) is Google Cloud's centralized security management system that detects misconfigurations, vulnerabilities, and threats across GCP resources.

  3. How should an Cloud Engineer professional approach a novel situation not covered by standard procedures?

    Answer: Apply foundational principles, assess risks, consult resources, and document the rationale for decisions

    This is fundamental to Cloud Engineer practice. Apply foundational principles, assess risks, consult resources, and document the rationale for decisions represents the professional standard for practical in the Cloud Engineer certification framework.

  4. You wish to set up a Cloud Run application that handles Cloud Pub/Sub topic message processing. You want to adhere to Google's suggestions. What ought you to do?

    Answer: 1. Deploy your application on Cloud Run on GKE with the connectivity set to Internal 2. Create a Cloud Pub/Sub subscription for that topic 3. In the same Google Kubernetes Engine cluster as your application, deploy a container that takes the messages and sends them to your application

    To process Cloud Pub/Sub messages with a Cloud Run application on GKE while adhering to internal connectivity, deploy the Cloud Run application with connectivity set to Internal. Create a standard Cloud Pub/Sub subscription for the topic. Then, within the same GKE cluster, deploy a separate container that acts as a message puller, fetching messages from the Pub/Sub subscription and forwarding them internally to your Cloud Run application. This ensures secure, private message handling within the cluster.

  5. What is the function of a GCP Service Account when used by a Compute Engine instance?

    Answer: It acts as the identity the instance uses to authenticate with GCP APIs

    A service account assigned to a Compute Engine instance serves as the instance's identity, determining which GCP APIs and resources it can access.

  6. Which practice best embodies the 'measure twice, cut once' principle in cloud infrastructure changes?

    Answer: Collecting baseline metrics before any change and defining rollback criteria, then deploying and comparing against baseline

    Establishing a pre-change baseline and clear rollback criteria creates the evidence needed to evaluate whether the change achieved its goal without harm.

  7. Your team strives to deploy your application to the GKE cluster in the desired state configuration. YAML files represent the Kubernetes deployment and service objects. The replicas parameter in app deployment.yaml specifies that your application is intended to run on two pods. The GKE load balancer is described in the app service. Your service uses YAML. You created the Kubernetes resources by running kubectl apply -f app-deployment.yaml kubectl apply -f app-service.yaml Although your deployment is now handling live traffic, it has performance problems. You would like to make five more replicas. What should you do to update the replicas in the deployed Kubernetes objects currently in use?

    Answer: Edit the number of replicas in the YAML file and rerun the kubectl apply. kubectl apply -f app-deployment.yaml

    The `kubectl apply -f` command is declarative, meaning it applies the desired state defined in the YAML file to your Kubernetes cluster. To update the number of replicas, you should modify the `replicas` parameter directly in your `app-deployment.yaml` file. Rerunning `kubectl apply -f app-deployment.yaml` will then reconcile the cluster's state with the updated YAML, ensuring your infrastructure-as-code remains the single source of truth for your deployment configuration.

  8. What does 'reproducibility' mean in the context of cloud infrastructure experiments?

    Answer: Another engineer can follow the documented methodology and obtain consistent results

    Reproducibility means the experiment is documented thoroughly enough that independent replication yields the same findings, a core scientific validity standard.

  9. A Compute Engine VM runs continuously for a full month. What automatic discount is applied without any commitment required?

    Answer: Sustained Use Discount (SUD)

    Sustained Use Discounts are automatic discounts of up to 30% applied to VMs that run for a significant portion of the billing month (no commitment required).

  10. What is the significance of a code of conduct for Cloud Engineer professionals?

    Answer: It establishes expected behaviors and ethical standards that protect the public and profession

    This is fundamental to Cloud Engineer practice. It establishes expected behaviors and ethical standards that protect the public and profession represents the professional standard for professional standards in the Cloud Engineer certification framework.

  11. Why is evidence-based practice important in Cloud Engineer?

    Answer: It integrates best available evidence with professional expertise for optimal outcomes

    This is fundamental to Cloud Engineer practice. It integrates best available evidence with professional expertise for optimal outcomes represents the professional standard for research in the Cloud Engineer certification framework.

  12. A startup uses a single AWS account for all environments. Security audit finds developers can access production RDS from their laptops. What is the correct architectural fix?

    Answer: Separate production into its own AWS account and use AWS Organizations SCPs to restrict access

    Account-level isolation using AWS Organizations and SCPs provides the strongest boundary; IAM policies within the same account can be misconfigured or overridden by admins.

  13. A cloud engineer is assessing risk for a multi-tenant Kubernetes cluster. Which threat modeling approach focuses on attacker goals rather than system assets?

    Answer: PASTA

    PASTA (Process for Attack Simulation and Threat Analysis) is attacker-centric, simulating adversary goals and correlating them with business impact.

  14. A cloud team uses a status dashboard visible to all stakeholders. This practice primarily improves which communication attribute?

    Answer: Transparency and self-service information access

    Visible dashboards reduce status-update meetings and give stakeholders real-time, self-service information.

  15. A cloud engineer discovers that a recently deployed Terraform module introduces a privilege escalation vulnerability. What is the CORRECT order of actions?

    Answer: Document, notify security, patch in a branch, test, deploy, post-mortem

    Privilege escalation vulnerabilities require security notification and tested remediation before deployment to avoid introducing new issues.

  16. What is the purpose of a Cloud Router in Google Cloud networking?

    Answer: Dynamically exchange routing information with on-premises networks via BGP

    Cloud Router uses BGP (Border Gateway Protocol) to dynamically advertise and learn routes between your VPC and on-premises networks connected via VPN or Interconnect.

  17. A company migrates on-premises VMs to Azure using Azure Migrate. Post-migration, the application team reports that internal service discovery no longer works. What is the most likely root cause?

    Answer: The migrated VMs use hardcoded IP addresses that differ in the Azure VNet

    On-premises services often use static IPs for internal communication; after migration to Azure, VMs receive new private IPs, breaking hardcoded references unless DNS or configuration is updated.

  18. What is reflective practice in Cloud Engineer professional development?

    Answer: Systematically examining experiences to gain insight and improve future practice

    This is fundamental to Cloud Engineer practice. Systematically examining experiences to gain insight and improve future practice represents the professional standard for practical in the Cloud Engineer certification framework.

  19. Which NIST Special Publication provides security controls specifically for protecting Controlled Unclassified Information (CUI) in non-federal systems?

    Answer: NIST SP 800-171

    NIST SP 800-171 defines security requirements for protecting CUI in non-federal information systems, and compliance is required for DoD contractors.

  20. What is the main advantage of using Infrastructure as Code (IaC) for research experiments in cloud environments?

    Answer: IaC enables reproducible, version-controlled environments that can be reliably replicated for consistent experiment conditions

    IaC captures environment configuration in code, ensuring each experiment iteration starts from an identical, documented baseline — a prerequisite for reproducible results.