Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your organization operates multiple Google Kubernetes Engine (GKE) clusters across staging and production environments. All production clusters are enrolled in the Regular release channel to ensure baseline operational stability. Due to strict corporate security policies, your team must ensure that newly published security patches are automatically applied to the control plane and nodes as quickly as possible without waiting for GKE's multi-week qualification period, while still strictly honoring configured maintenance windows and exclusions.
Which configuration should you apply to meet these requirements?
Remove the clusters from release channels and use Cloud Build to manually trigger node pool upgrades whenever new patch versions appear.
Configure a recurring maintenance exclusion of type no_upgrades during business hours and execute manual surge upgrades overnight.
Switch the production clusters from the Regular release channel to the Rapid release channel.
Enable accelerated patch auto-upgrades on the production clusters enrolled in the Regular release channel.
Remove the clusters from release channels and use Cloud Build to manually trigger node pool upgrades whenever new patch versions appear.
Configure a recurring maintenance exclusion of type no_upgrades during business hours and execute manual surge upgrades overnight.
Switch the production clusters from the Regular release channel to the Rapid release channel.
Enable accelerated patch auto-upgrades on the production clusters enrolled in the Regular release channel.
Accelerated patch auto-upgrades is a GKE feature designed for clusters enrolled in a release channel (such as Rapid, Regular, or Stable). When a new patch release is introduced to a release channel, GKE initially makes it available for new cluster creation and manual upgrades before qualifying it over a multi-day or multi-week window to become an automatic upgrade target.
This approach provides an automated, policy-compliant pipeline for rapid vulnerability remediation without requiring manual CLI interventions or moving production clusters to the higher-churn Rapid channel.