Question 41

You are disabling DNSSEC for one of your Cloud DNS-managed zones. You removed the DS records from your zone file, waited for them to expire from the cache, and disabled DNSSEC for the zone. You receive reports that DNSSEC validating resolves are unable to resolve names in your zone.
What should you do?
  • Question 42

    Your company has just launched a new critical revenue-generating web application. You deployed the application for scalability using managed instance groups, autoscaling, and a network load balancer as frontend. One day, you notice severe bursty traffic that the caused autoscaling to reach the maximum number of instances, and users of your application cannot complete transactions. After an investigation, you think it as a DDOS attack. You want to quickly restore user access to your application and allow successful transactions while minimizing cost.
    Which two steps should you take? (Choose two.)
  • Question 43

    Your on-premises data center has 2 routers connected to your Google Cloud environment through a VPN on each router. All applications are working correctly; however, all of the traffic is passing across a single VPN instead of being load-balanced across the 2 connections as desired.
    During troubleshooting you find:
    * Each on-premises router is configured with a unique ASN.
    * Each on-premises router is configured with the same routes and priorities.
    * Both on-premises routers are configured with a VPN connected to a single Cloud Router.
    * BGP sessions are established between both on-premises routers and the Cloud Router.
    * Only 1 of the on-premises router's routes are being added to the routing table.
    What is the most likely cause of this problem?
  • Question 44

    You are trying to update firewall rules in a shared VPC for which you have been assigned only Network Admin permissions. You cannot modify the firewall rules. Your organization requires using the least privilege necessary.
    Which level of permissions should you request?
  • Question 45

    You want to apply a new Cloud Armor policy to an application that is deployed in Google Kubernetes Engine (GKE). You want to find out which target to use for your Cloud Armor policy.
    Which GKE resource should you use?