Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
Your enterprise manages multiple Google Kubernetes Engine (GKE) clusters grouped into staging and production fleets. Your platform engineering team needs to implement a fleet-wide GitOps architecture using Config Sync and Policy Controller that satisfies the following requirements:
Which configuration architecture should you implement?
Configure a single hierarchical Git repository containing abstract namespaces and CRDs in the cluster/ directory, manage both application and security configs within the same repository using long-lived Git branches (staging and prod), and authenticate the ConfigManagement Operator using Compute Engine default service accounts.
Configure a central Git repository containing application source code and deployment manifests together, define all namespace configurations using cluster-scoped RootSync objects directly, and use the client.lifecycle.config.k8s.io/mutation: ignore annotation on all Policy Controller constraints so application teams can override them locally.
Configure cluster-scoped RootSync objects to deploy Kubernetes Job resources that execute kubectl apply commands for Policy Controller constraints, use dynamic ClusterSelectors with DRY template rendering in a single monorepo for all environments, and store access tokens in cluster secrets.
Configure a central unstructured Git repository managed by the platform team that deploys cluster-scoped RootSync objects for Policy Controller constraints, alongside namespace-scoped RepoSync objects pointing to dedicated application configuration repositories in WET folder structures; authenticate reconcilers using Workload Identity Federation for GKE.
Configure a single hierarchical Git repository containing abstract namespaces and CRDs in the cluster/ directory, manage both application and security configs within the same repository using long-lived Git branches (staging and prod), and authenticate the ConfigManagement Operator using Compute Engine default service accounts.
Configure a central Git repository containing application source code and deployment manifests together, define all namespace configurations using cluster-scoped RootSync objects directly, and use the client.lifecycle.config.k8s.io/mutation: ignore annotation on all Policy Controller constraints so application teams can override them locally.
Configure cluster-scoped RootSync objects to deploy Kubernetes Job resources that execute kubectl apply commands for Policy Controller constraints, use dynamic ClusterSelectors with DRY template rendering in a single monorepo for all environments, and store access tokens in cluster secrets.
Configure a central unstructured Git repository managed by the platform team that deploys cluster-scoped RootSync objects for Policy Controller constraints, alongside namespace-scoped RepoSync objects pointing to dedicated application configuration repositories in WET folder structures; authenticate reconcilers using Workload Identity Federation for GKE.
This architecture uses Config Sync with a multi-repository model that separates root platform configurations from delegated namespace configurations, managed through declarative Kubernetes Custom Resources (RootSync and RepoSync) across GKE Enterprise fleets.
RootSync managed by the platform team deploys cluster-wide RBAC and declarative Policy Controller constraints across all fleet clusters.RepoSync objects instantiate dedicated namespace reconcilers with limited permissions (RoleBinding scoped to the target namespace), allowing app teams to deploy resources without granting cluster-admin access.This approach aligns with Google Cloud recommended enterprise patterns by combining the delegated authority of multi-repo Config Sync, the declarative enforcement of Policy Controller, and IAM-based Workload Identity Federation.