Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise DevOps team is designing an automated workflow to ingest and process Google Cloud Recommender suggestions across multiple production projects within their GitOps CI/CD pipeline.
The governance policy defines the following criteria:
Which workflow and configuration should the team implement?
This solution establishes a secure, GitOps-aligned automation architecture that uses Google Cloud Recommender APIs to discover optimization and security insights, classifies them based on operational risk, and applies distinct remediation paths for automated enforcement versus human-in-the-loop review.
roles/recommender.viewer role allows the CI/CD worker to inspect and ingest recommendation payloads across projects without conferring broad write or administrative access.ENFORCEMENT mode ensures runtime and OS compliance configurations (such as baseline CIS benchmark settings) are automatically validated and brought into compliance across VMs without manual intervention.Directly applying high-risk IAM changes via automated scripts introduces the danger of revoking critical service agent permissions or breaking microservice mesh communication. Using read-only Recommender permissions combined with pull-request workflows for high-risk items provides safety and auditability, while OS Policy enforcement handles repetitive baseline compliance efficiently.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.