Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
A DevOps team manages container images in Google Cloud Artifact Registry for microservices deployed across multiple Google Kubernetes Engine (GKE) clusters in us-central1 and us-east4. Frequent CI/CD pipeline builds have caused storage costs to escalate significantly.
The team must implement an automated repository configuration that satisfies the following requirements:
release- at all times, regardless of age.stable indefinitely.Which configuration should the DevOps team implement?
Create two separate regional repositories in 'us-central1' and 'us-east4' and synchronize them using Cloud Storage Transfer Service. Apply Cloud Storage object lifecycle rules directly on the underlying storage buckets with a 14-day deletion condition.
Create a regional repository in 'us-central1' with an Artifact Registry remote repository configured in 'us-east4'. Deploy a Cloud Function triggered by Cloud Pub/Sub on an hourly schedule to query tags, count versions, and invoke the deletion API.
Create the repository in the 'us' multi-region location. Configure a single DELETE rule targeting untagged artifacts older than 14 days, and apply Cloud IAM read-only locks to all packages with 'release-' and 'stable' tags.
Create the repository in the 'us' multi-region location. Define Artifact Registry cleanup policies containing a KEEP rule with 'mostRecentVersions.keepCount' set to 5 and 'tagPrefixes' set to ['release-'], a KEEP rule matching tagPrefixes ['stable'], and a DELETE rule matching tagState 'UNTAGGED' with 'olderThan' set to '14d'.
Create two separate regional repositories in 'us-central1' and 'us-east4' and synchronize them using Cloud Storage Transfer Service. Apply Cloud Storage object lifecycle rules directly on the underlying storage buckets with a 14-day deletion condition.
Create a regional repository in 'us-central1' with an Artifact Registry remote repository configured in 'us-east4'. Deploy a Cloud Function triggered by Cloud Pub/Sub on an hourly schedule to query tags, count versions, and invoke the deletion API.
Create the repository in the 'us' multi-region location. Configure a single DELETE rule targeting untagged artifacts older than 14 days, and apply Cloud IAM read-only locks to all packages with 'release-' and 'stable' tags.
Create the repository in the 'us' multi-region location. Define Artifact Registry cleanup policies containing a KEEP rule with 'mostRecentVersions.keepCount' set to 5 and 'tagPrefixes' set to ['release-'], a KEEP rule matching tagPrefixes ['stable'], and a DELETE rule matching tagState 'UNTAGGED' with 'olderThan' set to '14d'.
Artifact Registry is Google Cloud's fully managed universal package manager and container registry. It allows repositories to be created in single regions (such as us-central1) or multi-regions (such as us, europe, or asia). Artifact Registry includes native Cleanup Policies (lifecycle rules) that evaluate container image tags, version counts, and artifact ages without requiring custom scripts or external schedulers.
us multi-region automatically stores and replicates artifacts across multiple data centers in the United States, providing low-latency pulls to GKE clusters in us-central1 and us-east4 without needing custom replication syncs.mostRecentVersions with keepCount: 5 and tagPrefixes: ["release-"] guarantees that the 5 latest versions matching that tag prefix are preserved even if they would otherwise match deletion criteria.tagPrefixes: ["stable"] ensures that any version bearing the stable tag is never removed, as KEEP rules always take precedence over DELETE rules in Artifact Registry policy evaluation.tagState: "UNTAGGED" with olderThan: "14d" automatically cleans up intermediate and dangling layers after two weeks.gcloud, Terraform, or the Cloud Console using JSON/YAML policy definitions.This solution relies entirely on native, declarative Google Cloud Artifact Registry features, eliminating custom script maintenance while ensuring strict governance over image lifecycle costs and multi-region availability.