Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your enterprise operates a hybrid and multi-cloud infrastructure consisting of multiple Google Kubernetes Engine (GKE) clusters managed under a centralized fleet. You are implementing a GitOps continuous delivery workflow using Config Sync and Kustomize to continuously enforce declarative cluster configurations, network policies, and security baselines across all environments.
Your security team has established the following operational requirements:
Which configuration strategy should you implement?
Configure Config Sync with Kustomize overlays targeting Standard GKE clusters with Dataplane V2 inter-node transparent encryption enabled, ensure total fleet nodes remain under 500, avoid FQDN network policies, and declaratively maintain cross-subnet firewall rules.
Configure Eventarc triggers to monitor Pub/Sub topics and execute gcloud container clusters update commands to apply runtime encryption whenever configuration drift is detected.
Deploy GKE Autopilot clusters across all environments, configure Config Sync to sync an unstructured repository, and enable FQDN network policies alongside inter-node transparent encryption.
Grant the Kubernetes Engine Default Node Service Agent the securitycentermanagement.admin role, and deploy Config Sync to push Packet Mirroring and Pod CIDR-based VPC firewall policies to all clusters.
Configure Config Sync with Kustomize overlays targeting Standard GKE clusters with Dataplane V2 inter-node transparent encryption enabled, ensure total fleet nodes remain under 500, avoid FQDN network policies, and declaratively maintain cross-subnet firewall rules.
This solution pairs Config Sync and Kustomize with GKE Dataplane V2 inter-node transparent encryption across Standard GKE clusters, applying declarative GitOps principles while adhering to the technical and architectural constraints of multi-cluster encryption.
kubectl operations with an automated reconciliation loop managed by Config Sync.This approach respects all documented platform boundaries for GKE multi-cluster networking and Dataplane V2 while leveraging native Google Cloud declarative GitOps tooling.
Configure Eventarc triggers to monitor Pub/Sub topics and execute gcloud container clusters update commands to apply runtime encryption whenever configuration drift is detected.
Deploy GKE Autopilot clusters across all environments, configure Config Sync to sync an unstructured repository, and enable FQDN network policies alongside inter-node transparent encryption.
Grant the Kubernetes Engine Default Node Service Agent the securitycentermanagement.admin role, and deploy Config Sync to push Packet Mirroring and Pod CIDR-based VPC firewall policies to all clusters.