exam questions

Exam Professional Cloud Developer All Questions

View all questions & answers for the Professional Cloud Developer exam

Exam Professional Cloud Developer topic 1 question 169 discussion

Actual exam question from Google's Professional Cloud Developer
Question #: 169
Topic #: 1
[All Professional Cloud Developer Questions]

Case study -

This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided.

To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study.

At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section.


To start the case study -
To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question.


Company Overview -
HipLocal is a community application designed to facilitate communication between people in close proximity. It is used for event planning and organizing sporting events, and for businesses to connect with their local communities. HipLocal launched recently in a few neighborhoods in Dallas and is rapidly growing into a global phenomenon. Its unique style of hyper-local community communication and business outreach is in demand around the world.


Executive Statement -
We are the number one local community app; it's time to take our local community services global. Our venture capital investors want to see rapid growth and the same great experience for new local and virtual communities that come online, whether their members are 10 or 10000 miles away from each other.


Solution Concept -
HipLocal wants to expand their existing service, with updated functionality, in new regions to better serve their global customers. They want to hire and train a new team to support these regions in their time zones. They will need to ensure that the application scales smoothly and provides clear uptime data, and that they analyze and respond to any issues that occur.


Existing Technical Environment -
HipLocal's environment is a mix of on-premises hardware and infrastructure running in Google Cloud Platform. The HipLocal team understands their application well, but has limited experience in global scale applications. Their existing technical environment is as follows:
• Existing APIs run on Compute Engine virtual machine instances hosted in GCP.
• State is stored in a single instance MySQL database in GCP.
• Release cycles include development freezes to allow for QA testing.
• The application has no logging.
• Applications are manually deployed by infrastructure engineers during periods of slow traffic on weekday evenings.
• There are basic indicators of uptime; alerts are frequently fired when the APIs are unresponsive.


Business Requirements -
HipLocal's investors want to expand their footprint and support the increase in demand they are seeing. Their requirements are:
• Expand availability of the application to new regions.
• Support 10x as many concurrent users.
• Ensure a consistent experience for users when they travel to different regions.
• Obtain user activity metrics to better understand how to monetize their product.
• Ensure compliance with regulations in the new regions (for example, GDPR).
• Reduce infrastructure management time and cost.
• Adopt the Google-recommended practices for cloud computing.
○ Develop standardized workflows and processes around application lifecycle management.
○ Define service level indicators (SLIs) and service level objectives (SLOs).


Technical Requirements -
• Provide secure communications between the on-premises data center and cloud-hosted applications and infrastructure.
• The application must provide usage metrics and monitoring.
• APIs require authentication and authorization.
• Implement faster and more accurate validation of new features.
• Logging and performance metrics must provide actionable information to be able to provide debugging information and alerts.
• Must scale to meet user demand.


For this question, refer to the HipLocal case study.

HipLocal's application uses Cloud Client Libraries to interact with Google Cloud. HipLocal needs to configure authentication and authorization in the Cloud Client Libraries to implement least privileged access for the application. What should they do?

  • A. Create an API key. Use the API key to interact with Google Cloud.
  • B. Use the default compute service account to interact with Google Cloud.
  • C. Create a service account for the application. Export and deploy the private key for the application. Use the service account to interact with Google Cloud.
  • D. Create a service account for the application and for each Google Cloud API used by the application. Export and deploy the private keys used by the application. Use the service account with one Google Cloud API to interact with Google Cloud.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
JonathanSJ
9 months ago
Selected Answer: C
C is correct.
upvoted 1 times
...
__rajan__
1 year, 1 month ago
Selected Answer: C
C is correct.
upvoted 1 times
...
purushi
1 year, 2 months ago
Selected Answer: C
B is easily eliminated. A is not that much secure. Provides only authorization and not authentication. There is no IAM here. D is more complex and not necessary to create service account for every API within the application.
upvoted 1 times
...
omermahgoub
1 year, 9 months ago
C. Create a service account for the application. Export and deploy the private key for the application. Use the service account to interact with Google Cloud. This approach allows for least privileged access, as the service account will only have the necessary permissions to access the specific Google Cloud resources that the application needs. Option A, using an API key, would not provide the same level of granularity in terms of access permissions. Option B, using the default compute service account, would not provide the ability to restrict access to specific resources. Option D, creating a service account for each API, would be overly complex and may not be necessary if the permissions can be granted on a more general level.
upvoted 1 times
...
telp
1 year, 9 months ago
Selected Answer: C
Answer C
upvoted 1 times
...
TNT87
1 year, 10 months ago
Answer C
upvoted 1 times
...
zellck
1 year, 10 months ago
Selected Answer: C
C is the answer.
upvoted 1 times
...
micoams
1 year, 10 months ago
Selected Answer: C
A,B,D can be eliminated: A. Cloud Client Libraries do not use API Keys to authenticate B. Compute engine default service account has too many privileges D. It does not make sense to create an SA for every API being access. The SA represents the Application itself, not the API So that leaves C as the only valid option. Still, ideally you should not copy SA keys around. Most of the time, GCP gives you a way to associate a service account with a workload.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago