Professional Cloud DevOps Engineer
Prepare and test your skills
Prepare and test your skills
Worked example. The correct answer is already marked and every option is explained below, so there is nothing to select here. To answer questions yourself, start the free trial.
Keep the momentum going with these hand-picked practice scenarios
Want more questions like this?
Get a free certification question every week.
Last updated
An enterprise is adopting the Google Cloud Security Foundations blueprint to govern and secure its infrastructure across multiple environments. The DevOps and platform teams need to establish an automated, declarative GitOps workflow that continuously validates infrastructure definitions against compliance benchmarks, prevents configuration drift, and enforces security constraints before and during resource admission.
Which approach should the team implement to meet these governance and compliance requirements?
Grant developers individual breakglass accounts with the Organization Administrator role to manually inspect and rectify non-compliant configurations in production.
Configure automated Google SecOps SOAR playbooks with domain-wide delegation to run scheduled rollbacks for any detected resource modifications.
Implement Config Sync alongside Policy Controller with pre-built constraint templates and security bundles to continuously reconcile declarative configurations and enforce compliance policies.
Download service account JSON private keys to developer workstations and execute local verification shell scripts against the Cloud Resource Manager API prior to committing code.
Grant developers individual breakglass accounts with the Organization Administrator role to manually inspect and rectify non-compliant configurations in production.
Configure automated Google SecOps SOAR playbooks with domain-wide delegation to run scheduled rollbacks for any detected resource modifications.
Implement Config Sync alongside Policy Controller with pre-built constraint templates and security bundles to continuously reconcile declarative configurations and enforce compliance policies.
Config Sync and Policy Controller are core declarative governance tools in Google Cloud. Config Sync manages and continuously synchronizes infrastructure configurations from a centralized, version-controlled repository, while Policy Controller acts as an admission controller and compliance auditor that enforces programmable rules based on the Open Policy Agent (OPA) framework.
Combining Config Sync with Policy Controller provides shift-left policy enforcement, zero-touch production compliance, and automated remediation without introducing brittle scripts, persistent credentials, or manual review bottlenecks.
Download service account JSON private keys to developer workstations and execute local verification shell scripts against the Cloud Resource Manager API prior to committing code.