Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your enterprise enforces strict data residency requirements mandating that all compute, storage, and database resources reside exclusively within authorized European regions (europe-west1 and europe-west3) under designated folder hierarchies.
As a Cloud DevOps Engineer, you need to establish an automated governance strategy that:
Which combination of architectural controls should you implement?
Configure an Apigee API proxy with an OASValidation policy to intercept internal Google Cloud console traffic; configure Active Assist Recommender daily scans to flag misconfigured regions in the Cloud Run service list.
Embed Binary Authorization attestations on Terraform HCL code repositories in Cloud Build; configure Google Cloud Armor edge security policies across Application Load Balancers to inspect and drop infrastructure API requests originating outside European geographic regions.
Embed terraform-validator (or gcloud beta terraform vet) with a shared policy library into the Cloud Build pipeline to evaluate Terraform plans against resource location policies; configure Cloud Asset Inventory real-time feeds for resource changes subscribed to a Pub/Sub topic to trigger automated Cloud Functions for drift detection and remediation.
Run gcloud asset analyze-iam-policy during the Cloud Build build step to block non-compliant deployments; schedule nightly BigQuery export queries on Cloud Logging audit sinks to alert compliance officers of geographic drift via email.
Configure an Apigee API proxy with an OASValidation policy to intercept internal Google Cloud console traffic; configure Active Assist Recommender daily scans to flag misconfigured regions in the Cloud Run service list.
Embed Binary Authorization attestations on Terraform HCL code repositories in Cloud Build; configure Google Cloud Armor edge security policies across Application Load Balancers to inspect and drop infrastructure API requests originating outside European geographic regions.
Embed terraform-validator (or gcloud beta terraform vet) with a shared policy library into the Cloud Build pipeline to evaluate Terraform plans against resource location policies; configure Cloud Asset Inventory real-time feeds for resource changes subscribed to a Pub/Sub topic to trigger automated Cloud Functions for drift detection and remediation.
This approach combines preventative policy-as-code validation in continuous integration (shifting left) with continuous detective and reactive controls using Cloud Asset Inventory feeds and event-driven automation in Google Cloud.
terraform-validator or gcloud beta terraform vet against compiled Terraform plan files (tfplan.json) in Cloud Build, the pipeline evaluates proposed infrastructure against declarative Rego or constraint framework policies (such as constraints/gcp.resourceLocations). If a resource specifies an unauthorized region, the CI/CD job fails immediately, preventing terraform apply from executing.Run gcloud asset analyze-iam-policy during the Cloud Build build step to block non-compliant deployments; schedule nightly BigQuery export queries on Cloud Logging audit sinks to alert compliance officers of geographic drift via email.