Free 2025 Associate-Cloud-Engineer Dumps 100 Pass Guarantee With Latest Demo [Q64-Q80]

Share

Free 2025 Associate-Cloud-Engineer Dumps 100 Pass Guarantee With Latest Demo

Prepare Associate-Cloud-Engineer Question Answers Free Update With 100% Exam Passing Guarantee [2025]

NEW QUESTION # 64
You need to create a custom VPC with a single subnet. The subnet's range must be as large as possible. Which range should you use?

  • A. 0.0.0.0/0
  • B. 192.168.0.0/16
  • C. 10.0.0.0/8
  • D. 172.16.0.0/12

Answer: C


NEW QUESTION # 65
Your security team has been reluctant to move to the cloud because they don't have the level of network visibility they're used to. Which feature might help them to gain insights into your Google Cloud network?

  • A. Subnets
  • B. Firewall rules
  • C. Routes
  • D. Flow logs

Answer: D


NEW QUESTION # 66
You have a web application deployed as a managed instance group. You have a new version of the application to gradually deploy. Your web application is currently receiving live web traffic. You want to ensure that the available capacity does not decrease during the deployment. What should you do?

  • A. Create a new instance template with the new application version. Update the existing managed instance group with the new instance template. Delete the instances in the managed instance group to allow the managed instance group to recreate the instance using the new instance template.
  • B. Create a new managed instance group with an updated instance template. Add the group to the backend service for the load balancer. When all instances in the new managed instance group are healthy, delete the old managed instance group.
  • C. Perform a rolling-action start-update with maxSurge set to 0 and maxUnavailable set to 1.
  • D. Perform a rolling-action start-update with maxSurge set to 1 and maxUnavailable set to 0.

Answer: D

Explanation:
Explanation
https://cloud.google.com/compute/docs/instance-groups/rolling-out-updates-to-managed-instance-groups#max_u


NEW QUESTION # 67
You are migrating a production-critical on-premises application that requires 96 vCPUs to perform its task.
You want to make sure the application runs in a similar environment on GCP. What should you do?

  • A. Create the VM using Compute Engine default settings. Use gcloud to modify the running instance to have 96 vCPUs.
  • B. Start the VM using Compute Engine default settings, and adjust as you go based on Rightsizing Recommendations.
  • C. When creating the VM, use Intel Skylake as the CPU platform.
  • D. When creating the VM, use machine type n1-standard-96.

Answer: D

Explanation:
Ref: https://cloud.google.com/compute/docs/machine-types#n1_machine_type


NEW QUESTION # 68
You need to manage a third-party application that will run on a Compute Engine instance. Other Compute Engine instances are already running with default configuration. Application installation files are hosted on Cloud Storage. You need to access these files from the new instance without allowing other virtual machines (VMs) to access these files. What should you do?

  • A. Create the instance with the default Compute Engine service account Grant the service account permissions on Cloud Storage.
  • B. Create a new service account and assign this service account to the new instance Add metadata to the objects on Cloud Storage that matches the metadata on the new instance.
  • C. Create a new service account and assign this service account to the new instance Grant the service account permissions on Cloud Storage.
  • D. Create the instance with the default Compute Engine service account Add metadata to the objects on Cloud Storage that matches the metadata on the new instance.

Answer: D

Explanation:
https://cloud.google.com/iam/docs/best-practices-for-using-and-managing-service-accounts If an application uses third-party or custom identities and needs to access a resource, such as a BigQuery dataset or a Cloud Storage bucket, it must perform a transition between principals. Because Google Cloud APIs don't recognize third-party or custom identities, the application can't propagate the end-user's identity to BigQuery or Cloud Storage. Instead, the application has to perform the access by using a different Google identity.


NEW QUESTION # 69
You have been asked to set up Object Lifecycle Management for objects stored in storage buckets. The objects are written once and accessed frequently for 30 days. After 30 days, the objects are not read again unless there is a special need. The object should be kept for three years, and you need to minimize cost. What should you do?

  • A. Set up a policy that uses Standard storage for 30 days, then moves to Coldline for one year, and then moves to Archive storage for two years.
  • B. Set up a policy that uses Standard storage for 30 days and then moves to Archive storage for three years.
  • C. Set up a policy that uses Nearline storage for 30 days and then moves to Archive storage for three years.
  • D. Set up a policy that uses Nearline storage for 30 days, then moves the Coldline for one year, and then moves to Archive storage for two years.

Answer: C


NEW QUESTION # 70
You just installed the Google Cloud CLI on your new corporate laptop. You need to list the existing instances of your company on Google Cloud. What must you do before you run the gcloud compute instances list command?
Choose 2 answers

  • A. Run gcloud config set project $my_project to set the default project for gcloud CLI.
  • B. Download your Cloud Identity user account key. Place the key file in a folder on your machine where gcloud CLI can find it.
  • C. Run gcloud config set compute/zone $my_zone to set the default zone for gcloud CLI.
  • D. Create a Google Cloud service account, and download the service account key. Place the key file in a folder on your machine where gcloud CLI can find it.
  • E. Run gcloud auth login, enter your login credentials in the dialog window, and paste the received login token to gcloud CLI.

Answer: A,E

Explanation:
Before you run the gcloud compute instances list command, you need to do two things: authenticate with your user account and set the default project for gcloud CLI.
To authenticate with your user account, you need to run gcloud auth login, enter your login credentials in the dialog window, and paste the received login token to gcloud CLI. This will authorize the gcloud CLI to access Google Cloud resources on your behalf1.
To set the default project for gcloud CLI, you need to run gcloud config set project $my_project, where
$my_project is the ID of the project that contains the instances you want to list. This will save you from having to specify the project flag for every gcloud command2.
Option B is not recommended, because using a service account key increases the risk of credential leakage and misuse. It is also not necessary, because you can use your user account to authenticate to the gcloud CLI3.
Option C is not correct, because there is no such thing as a Cloud Identity user account key. Cloud Identity is a service that provides identity and access management for Google Cloud users and groups4. Option D is not required, because the gcloud compute instances list command does not depend on the default zone. You can list instances from all zones or filter by a specific zone using the --filter flag.


NEW QUESTION # 71
Your organization has user identities in Active Directory. Your organization wants to use Active Directory as their source of truth for identities. Your organization wants to have full control over the Google accounts used by employees for all Google services, including your Google Cloud Platform (GCP) organization. What should you do?

  • A. Ask each employee to create a Google account using self signup. Require that each employee use their company email address and password.
  • B. Use Google Cloud Directory Sync (GCDS) to synchronize users into Cloud Identity.
  • C. Use the cloud Identity APIs and write a script to synchronize users to Cloud Identity.
  • D. Export users from Active Directory as a CSV and import them to Cloud Identity via the Admin Console.

Answer: B


NEW QUESTION # 72
You need to host an application on a Compute Engine instance in a project shared with other teams. You want to prevent the other teams from accidentally causing downtime on that application. Which feature should you use?

  • A. Use a Preemptible VM.
  • B. Use a Shielded VM.
  • C. Enable deletion protection on the instance.
  • D. Use a sole-tenant node.

Answer: C

Explanation:
As part of your workload, there might be certain VM instances that are critical to running your application or services, such as an instance running a SQL server, a server used as a license manager, and so on. These VM instances might need to stay running indefinitely so you need a way to protect these VMs from being deleted. By setting the deletionProtection flag, a VM instance can be protected from accidental deletion. If a user attempts to delete a VM instance for which you have set the deletionProtection flag, the request fails. Only a user that has been granted a role with compute.instances.create permission can reset the flag to allow the resource to be deleted.
Ref: https://cloud.google.com/compute/docs/instances/preventing-accidental-vm-deletion


NEW QUESTION # 73
Your team has developed a stateless application which requires it to be run directly on virtual machines. The application is expected to receive a fluctuating amount of traffic and needs to scale automatically. You need to deploy the application. What should you do?

  • A. Deploy the application on a managed instance group and configure autoscaling.
  • B. Deploy the application on a Kubernetes Engine cluster and configure node pool autoscaling.
  • C. Deploy the application on Cloud Functions and configure the maximum number instances.
  • D. Deploy the application on Cloud Run and configure autoscaling.

Answer: A

Explanation:
A managed instance group (MIG) is a group of identical virtual machines (VMs) that you can manage as a single entity. You can use a MIG to deploy and maintain a stateless application that runs directly on VMs. A MIG can automatically scale the number of VMsbased on the load or a schedule. A MIG can also automatically heal the VMs if they become unhealthy or unavailable. A MIG is suitable for applications that need to run on VMs rather than containers or serverless platforms.
B is incorrect because Kubernetes Engine is a managed service for running containerized applications on a cluster of nodes. It is not necessary to use Kubernetes Engine if the application does not use containers and can run directly on VMs.
C is incorrect because Cloud Functions is a serverless platform for running event-driven code in response to triggers. It is not suitable for applications that need to run continuously and handle HTTP requests.
D is incorrect because Cloud Run is a serverless platform for running stateless containerized applications. It is not suitable for applications that do not use containers and can run directly on VMs.
References:
* Managed instance groups documentation
* Choosing a compute option for Google Cloud


NEW QUESTION # 74
Your company has a single sign-on (SSO) identity provider that supports Security Assertion Markup Language (SAML) integration with service providers. Your company has users in Cloud Identity. You would like users to authenticate using your company's SSO provider. What should you do?

  • A. Obtain OAuth 2.0 credentials, configure the user consent screen, and set up OAuth 2.0 for Mobile & Desktop Apps.
  • B. In Cloud Identity, set up SSO with Google as an identity provider to access custom SAML apps.
  • C. Obtain OAuth 2.0 credentials, configure the user consent screen, and set up OAuth 2.0 for Web Server Applications.
  • D. In Cloud Identity, set up SSO with a third-party identity provider with Google as a service provider.

Answer: D

Explanation:
Explanation
https://support.google.com/cloudidentity/answer/6262987?hl=en&ref_topic=7558767


NEW QUESTION # 75
You are building an application that will run in your data center. The application will use Google Cloud Platform (GCP) services like AutoML. You created a service account that has appropriate access to AutoML.
You need to enable authentication to the APIs from your on-premises environment. What should you do?

  • A. Use service account credentials in your on-premises application.
  • B. Set up direct interconnect between your data center and Google Cloud Platform to enable authentication for your on-premises applications.
  • C. Go to the IAM & admin console, grant a user account permissions similar to the service account permissions, and use this user account for authentication from your data center.
  • D. Use gcloud to create a key file for the service account that has appropriate permissions.

Answer: D


NEW QUESTION # 76
You want to send and consume Cloud Pub/Sub messages from your App Engine application. The Cloud Pub/Sub API is currently disabled. You will use a service account to authenticate your application to the API.
You want to make sure your application can use Cloud Pub/Sub. What should you do?

  • A. Enable the Cloud Pub/Sub API in the API Library on the GCP Console.
  • B. Grant the App Engine Default service account the role of Cloud Pub/Sub Admin. Have your application enable the API on the first connection to Cloud Pub/Sub.
  • C. Use Deployment Manager to deploy your application. Rely on the automatic enablement of all APIs used by the application being deployed.
  • D. Rely on the automatic enablement of the Cloud Pub/Sub API when the Service Account accesses it.

Answer: A

Explanation:
Explanation
Quickstart: using the Google Cloud Console
This page shows you how to perform basic tasks in Pub/Sub using the Google Cloud Console.
Note: If you are new to Pub/Sub, we recommend that you start with the interactive tutorial.
Before you begin
Set up a Cloud Console project.
Set up a project
Click to:
Create or select a project.
Enable the Pub/Sub API for that project.
You can view and manage these resources at any time in the Cloud Console.
Install and initialize the Cloud SDK.
Note: You can run the gcloud tool in the Cloud Console without installing the Cloud SDK. To run the gcloud tool in the Cloud Console, use Cloud Shell .
https://cloud.google.com/pubsub/docs/quickstart-console


NEW QUESTION # 77
You are building an application that will run in your data center. The application will use Google Cloud Platform (GCP) services like AutoML. You created a service account that has appropriate access to AutoML. You need to enable authentication to the APIs from your on-premises environment. What should you do?

  • A. Use service account credentials in your on-premises application.
  • B. Set up direct interconnect between your data center and Google Cloud Platform to enable authentication for your on-premises applications.
  • C. Go to the IAM & admin console, grant a user account permissions similar to the service account permissions, and use this user account for authentication from your data center.
  • D. Use gcloud to create a key file for the service account that has appropriate permissions.

Answer: D

Explanation:
https://cloud.google.com/vision/automl/docs/before-you-begin


NEW QUESTION # 78
You have a website hosted on App Engine standard environment. You want 1% of your users to see a new test version of the website. You want to minimize complexity. What should you do?

  • A. Create a new App Engine application in the same project. Deploy the new version in that application. Configure your network load balancer to send 1% of the traffic to that new application.
  • B. Create a new App Engine application in the same project. Deploy the new version in that application. Use the App Engine library to proxy 1% of the requests to the new version.
  • C. Deploy the new version in the same application and use the --splits option to give a weight of 99 to the current version and a weight of 1 to the new version.
  • D. Deploy the new version in the same application and use the --migrate option.

Answer: C

Explanation:
https://cloud.google.com/appengine/docs/standard/python/splitting-traffic#gcloud


NEW QUESTION # 79
You have an application that looks for its licensing server on the IP 10.0.3.21. You need to deploy the licensing server on Compute Engine. You do not want to change the configuration of the application and want the application to be able to reach the licensing server. What should you do?

  • A. Reserve the IP 10.0.3.21 as a static public IP address using gcloud and assign it to the licensing server.
  • B. Reserve the IP 10.0.3.21 as a static internal IP address using gcloud and assign it to the licensing server.
  • C. Start the licensing server with an automatic ephemeral IP address, and then promote it to a static internal IP address.
  • D. Use the IP 10.0.3.21 as a custom ephemeral IP address and assign it to the licensing server.

Answer: B

Explanation:
Explanation
IP 10.0.3.21 is internal by default, and to ensure that it will be static non-changing it should be selected as static internal ip address.


NEW QUESTION # 80
......

Dumps Real Google Associate-Cloud-Engineer Exam Questions [Updated 2025]: https://www.actualtests4sure.com/Associate-Cloud-Engineer-test-questions.html

Free Associate-Cloud-Engineer Exam Dumps to Pass Exam Easily: https://drive.google.com/open?id=1F20HVagF73wUCL4ObHFk41Bn_hmTJ8mH