Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
An enterprise organization operates multiple Google Kubernetes Engine (GKE) clusters across separate Google Cloud projects for production and staging environments. A DevOps engineer is tasked with registering these heterogeneous clusters into a centralized fleet host project to establish unified Fleet Workload Identity for seamless, cross-cluster credential exchange and service authentication.
Which configuration requirement and architectural constraint must the engineer apply when implementing this fleet architecture?
GKE Fleet Management provides a centralized control plane to group, manage, and govern multiple Kubernetes clusters across different Google Cloud projects, on-premises environments, and third-party clouds. Fleet Workload Identity Federation extends Google Cloud Workload Identity across all member clusters in the fleet, establishing a common identity pool (FLEET_PROJECT_ID.svc.id.goog) that allows workloads to securely authenticate against Google Cloud APIs and exchange credentials across clusters without static service account keys.
production, staging) can be explicitly registered to a centralized fleet host project using appropriate cross-project IAM permissions.Registering clusters to a central fleet host project with standard memberships is the only method that establishes unified Fleet Workload Identity Federation across project boundaries. It ensures full access to fleet-wide enterprise capabilities while avoiding the architectural limitations imposed by lightweight memberships.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.