Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your enterprise uses automated CI/CD pipelines to dynamically provision ephemeral test environments for pull requests. Multiple engineering teams deploy dozens of short-lived Google Cloud projects daily. You must implement a governance, lifecycle, and cost control strategy that satisfies the following requirements:
What should you do?
Grant the CI/CD service account the Billing Account Administrator role (roles/billing.admin) to set programmatic project budgets, export billing data to CSV files in Cloud Storage, and deploy Cloud Monitoring uptime checks that terminate projects upon failed HTTP pings.
Grant the CI/CD service account the Billing Account User role (roles/billing.user) at the organization level, apply metadata labels such as environment, team, and ttl to each provisioned project, configure Cloud Billing export to BigQuery, and schedule a Cloud Run function to scan project labels and delete expired projects.
Assign separate Cloud Billing accounts for each engineering team, grant developers the Billing Account Viewer role (roles/billing.viewer) at the organization level, and enforce Compute Engine OS Policies inside VMs to delete projects during idle periods.
Grant developers the Organization Administrator role (roles/resourcemanager.organizationAdmin) to manage project lifecycles directly, rely on default unlabelled Cloud Monitoring dashboards, and configure hard-stop Cloud Billing budgets to disable billing when limits are exceeded.
Grant the CI/CD service account the Billing Account Administrator role (roles/billing.admin) to set programmatic project budgets, export billing data to CSV files in Cloud Storage, and deploy Cloud Monitoring uptime checks that terminate projects upon failed HTTP pings.
Grant the CI/CD service account the Billing Account User role (roles/billing.user) at the organization level, apply metadata labels such as environment, team, and ttl to each provisioned project, configure Cloud Billing export to BigQuery, and schedule a Cloud Run function to scan project labels and delete expired projects.
This solution implements a complete automated lifecycle and governance framework for dynamic, short-lived environments. It combines principle-of-least-privilege Identity and Access Management (IAM), structured resource tagging, granular analytical billing exports, and serverless automation to manage ephemeral infrastructure safely at scale.
roles/billing.user) at the organization or billing account level allows the automation service account to attach the billing account to newly created projects without granting permissions to view invoices, modify billing admins, or adjust payment profiles.environment: ephemeral, team: core-platform, and ttl: 24h) ensures every dollar spent is tracked. Exporting billing data directly into BigQuery provides a robust, real-time analytics warehouse to slice and dice costs across teams, environments, and specific pipeline runs.This architecture establishes a secure, hands-off operational model. It avoids administrative bottlenecks and enforces resource disposal at the project root level, guaranteeing that all child cloud resources (disks, IPs, services) are destroyed together.
Assign separate Cloud Billing accounts for each engineering team, grant developers the Billing Account Viewer role (roles/billing.viewer) at the organization level, and enforce Compute Engine OS Policies inside VMs to delete projects during idle periods.
Grant developers the Organization Administrator role (roles/resourcemanager.organizationAdmin) to manage project lifecycles directly, rely on default unlabelled Cloud Monitoring dashboards, and configure hard-stop Cloud Billing budgets to disable billing when limits are exceeded.