Google Professional Cloud DevOps Engineer exam dumps

Google Professional Cloud DevOps Engineer practice question 39 of 268

Professional Cloud DevOps Engineer. Associate level, Google Cloud. Free question with the correct answer and a full explanation.

Google Professional Cloud DevOps Engineer Question 39

Select 2Google Cloud Platform

Your team is using Google Cloud and wants to implement consistent configuration and policy management across multiple environments (e.g., development, staging, production). The team needs to ensure that configurations are validated before deployment and policies are enforced to meet compliance standards. Which combination of tools should you use to achieve this?

  1. A

    Terraform to define infrastructure as code and Google Cloud Policy Analyzer to validate policies

  2. B

    Google Cloud Config Connector to manage Google Cloud resources using Kubernetes and Config Validator to enforce policy compliance

  3. C

    Terraform with Sentinel to define infrastructure as code and enforce policy compliance during deployment

  4. D

    Google Cloud Deployment Manager to define configurations and Binary Authorization to validate infrastructure before deployment

  5. E

    Kubernetes ConfigMaps to define configuration and Google Cloud IAM to enforce policies

Show answer and explanation

Correct answers: B, C

Explanation

To ensure consistent configuration and policy management across environments, Google Cloud Config Connector and Config Validator can be used for declarative resource management and compliance validation, respectively. Alternatively, Terraform with Sentinel provides infrastructure as code capabilities along with policy enforcement during the deployment process. These combinations address the requirements for configuration validation and compliance enforcement effectively.

  • A. Incorrect.

    Terraform can define infrastructure as code, but Google Cloud Policy Analyzer is used mainly for analyzing existing policies, not for validating configurations before deployment or enforcing compliance.

  • B. Correct.

    Google Cloud Config Connector integrates well with Kubernetes for managing Google Cloud resources declaratively, and Config Validator is a tool specifically designed to enforce compliance with organization policies.

  • C. Correct.

    Terraform provides infrastructure as code capabilities, and Sentinel can be used to enforce policy compliance during deployment processes, ensuring validation and adherence to compliance requirements.

  • D. Incorrect.

    Google Cloud Deployment Manager can define configurations, but Binary Authorization is primarily used for verifying container images, not infrastructure configurations or policies.

  • E. Incorrect.

    Kubernetes ConfigMaps are used to manage application configuration data, but they are not a tool for enforcing compliance policies. Similarly, Google Cloud IAM manages permissions but is not used for validating configurations.

Timed practice exam

Take a Google Professional Cloud DevOps Engineer practice test under exam conditions

60 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam