Be able to map requirements to concrete GCP services and configurations, justifying cost, availability, and security choices. The single most important thing: match the workload's tolerance for interruption and its availability target to the right compute, storage, and security building blocks.
Start practicing
Design and plan a cloud solution architecture — choose a session length
Free · No account required
Domain overview
This domain covers translating business and technical requirements into GCP designs: choosing compute, storage, networking, and security services, and defining reliability, scalability, and cost tradeoffs. Questions present scenarios (batch jobs, GKE microservices, credential handling) and ask you to select or sequence the most appropriate Google Cloud architecture.
Exam objectives
Selecting Compute Engine preemptible/Spot VMs for interruptible batch workloads to cut cost.
Designing regional GKE clusters with multi-zone node pools, autoscaling, and rolling updates.
Mapping Cloud IAM, Cloud KMS, Secret Manager, and VPC Service Controls to security needs.
Choosing managed services like Cloud SQL, Pub/Sub, and Cloud Storage for durability and scale.
Picking always-on standard VMs for fault-tolerant batch jobs instead of Spot/preemptible instances, ignoring the stated cost goal.
Confusing zonal and regional GKE cluster availability, or forgetting node pool autoscaling and surge upgrade settings.
Leaving credentials in plaintext or instance metadata instead of using Secret Manager with least-privilege IAM.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company is migrating on-premises workloads to Google Cloud. They have a critical application that requires consistent low-latency access to a database, with read replicas in multiple regions for disaster recovery. The application is expected to grow by 10x over the next year. Which database service and configuration should the architect choose to meet these requirements?
2A company is migrating a legacy monolithic application to Google Cloud. The application currently runs on a single on-premises server and uses a local MySQL database. The company wants to minimize changes to the application code while improving scalability and reliability. Which migration strategy should the architect recommend?
3A global e-commerce platform is experiencing intermittent latency spikes during flash sales. The application is deployed on Google Kubernetes Engine (GKE) with a regional cluster. The architecture includes a frontend service, a product catalog service using Cloud Spanner, and an order processing service using Cloud Pub/Sub. During high load, the catalog service shows increased query latency, and some requests time out. What should the architect prioritize to address the issue?
4A startup is developing a real-time analytics dashboard that ingests data from IoT devices. The data volume is unpredictable but can spike to millions of events per second. The dashboard must display near real-time aggregations with sub-second latency. Which Google Cloud architecture should the architect recommend?
5A company wants to restrict access to a Cloud Storage bucket so that only a specific service account can read objects. The bucket contains sensitive data. Which identity and access management (IAM) approach should the architect use?
6Drag and drop the steps to set up a VPC network peering between two projects in Google Cloud into the correct order.
7Drag and drop the steps to recover a Cloud SQL instance from a backup into the correct order.
8Match each GCP security service to its function.
9A multinational e-commerce company needs a globally distributed database that provides strong consistency and transactional support for order processing. Which Google Cloud database service should they use?
10A data analytics company runs nightly batch jobs using Compute Engine instances. The jobs can tolerate interruptions, and the company wants to minimize costs. What should they do?
11A financial services company is designing a multi-region application on Google Kubernetes Engine (GKE) for high availability. They need to serve user requests from the closest region and automatically failover if a region becomes unavailable. Which architecture should they use?
12A media company wants to serve publicly available images and videos to a global audience with low latency. Which Google Cloud service should they primarily use?
13A company is migrating an on-premises PostgreSQL database to Cloud SQL with minimal downtime. The database is 1 TB and the network link has 500 Mbps bandwidth. Which migration approach is most appropriate?
14A small startup wants to deploy a containerized web application that scales automatically and only charges for resources used. They have limited operational experience. Which compute solution should they choose?
15A company has set up an external HTTP(S) load balancer with a backend service pointing to a managed instance group. Some instances are failing health checks. Which TWO actions should the company take to troubleshoot the issue?
16Which THREE practices are recommended for organizing projects in a Google Cloud organization?
17Refer to the exhibit. What is the primary benefit of the `--preemptible` flag in this command?
18Refer to the exhibit. A Cloud Storage bucket has this IAM policy. What security recommendation should be made?
19Refer to the exhibit. A subnet was created with the `--enable-private-ip-google-access` flag. What does this flag enable for instances in this subnet?
20A company is migrating to Google Cloud and needs to connect their on-premises network to a VPC. They require high bandwidth and a reliable connection with a Service Level Agreement (SLA). Which solution should they choose?
21A company hosts a web application on Compute Engine behind a global HTTP(S) load balancer. They notice that some users experience high latency from certain regions. They want to improve performance without adding complexity. What should they do?
22A company is migrating a monolithic application to Google Cloud. The application consists of a stateful service that writes to local disk and a stateless web server. They want to minimize changes to the code. Which architecture should they use?
23A company is designing a VPC architecture for a multi-tenant SaaS platform. Each tenant has isolated workloads that must not communicate with each other. They also need centralized network security and logging. Which VPC design meets these requirements?
24The exhibit shows a command to create a Compute Engine instance. The instance is intended to run a web server that needs to access Cloud Storage buckets using its service account. However, the web server fails to read from a storage bucket. What is the most likely cause?
25The exhibit shows a Cloud Storage bucket IAM policy. A developer (admin@example.com) wants to upload a file to the bucket but gets a permission denied error. What is the most likely reason?
26A company is designing a microservices architecture on Google Kubernetes Engine (GKE) for a global user base. They require high availability across multiple zones, automatic scaling, and rolling updates without downtime. Which Kubernetes workload resource should they use for each service?
27A company is planning a hybrid cloud architecture using Anthos to manage workloads across on-premises data centers and Google Cloud. They need to select two key components that enable consistent configuration, policy, and security across environments. Which two should they choose?
28Your company has migrated its legacy web application from a single Compute Engine instance to a managed instance group (MIG) behind an HTTP(S) load balancer. The application was updated to a new version as part of the migration. After the migration, users report intermittent 502 Bad Gateway errors. The application logs show no errors, and the load balancer backend health checks are reported as healthy. On investigation, the developers discover that the new version requires a specific environment variable for authentication to a downstream service. This variable was set manually on the original instance but is missing from the MIG's instance template. The health check endpoint does not depend on this variable and always returns a 200 status even when the variable is absent. As a result, instances created from the template are considered healthy by the load balancer, but when they receive requests that require authentication, they fail and return a 502 error to the client. What is the most likely cause of the 502 errors?
29A company runs a multi-tier web application on Google Kubernetes Engine (GKE) with a frontend service, a backend service, and a Cloud SQL for PostgreSQL database. During peak hours, the frontend pod CPU usage is high (consistently above 80%), while the backend service shows moderate CPU usage (around 50%). Response times for user requests increase significantly, often exceeding the 200ms p99 latency target. Cloud SQL metrics show low query latency and no contention. The team wants to improve performance in a cost-effective manner. Which initial step should they take?
30A company is migrating a legacy on-premises application to Google Cloud. The application has strict low-latency requirements between its components and requires stateful TCP sessions. Which TWO design decisions should the architect recommend?
31A company runs a web application on Compute Engine instances behind a global HTTP(S) Load Balancer. The application uses Cloud SQL for MySQL for user data. Users report that during peak hours, the page load times increase significantly. The development team notices that the number of database connections exceeds the maximum allowed, causing some requests to fail. The application is designed to use connection pooling with a maximum pool size of 100 connections per instance. There are currently 10 instances. The Cloud SQL instance is configured with 4 vCPUs and 15 GB memory, and the maximum connections is set to 400. The application team wants to minimize cost while resolving the issue. What should the architect recommend?
32Refer to the exhibit. An engineer deploys this Terraform configuration. After deployment, they can SSH into the VM using its public IP. However, they want to restrict SSH access to only a specific IP range (203.0.113.0/24). What change is required?
33Refer to the exhibit. All five nginx pods are scheduled on the same node (default-pool-1). What is the most likely reason?
34Refer to the exhibit. An engineer deployed this Terraform configuration and can SSH to the instance using the external IP. However, they notice that the instance has a public IP address even though they intended to have no public IP. What change should be made to the configuration to ensure the instance does not get a public IP?
35Refer to the exhibit. A developer is trying to connect to the Kubernetes API server from their workstation using the master IP (34.67.89.12) but receives a timeout. The developer can reach other external IPs. What is the most likely reason for the timeout?
36A retail company is planning to migrate its on-premises data warehouse to Google Cloud. They want a fully managed, petabyte-scale, and highly scalable analytics data warehouse that supports ANSI SQL and integrates with their existing BI tools. Which Google Cloud service should they choose?
37A financial services firm is designing a new application on Google Cloud. The application must store sensitive customer data and comply with regulations that require encryption at rest with keys managed by the company. The company also needs to control key rotation and revocation. Which Google Cloud service should the solutions architect use to meet these requirements?
38A healthcare company is designing a system to process sensitive patient records on Google Cloud. They need to ensure that data is encrypted at rest with keys they control and can rotate on demand. They also require that the encryption keys are stored in a hardware security module (HSM) that is FIPS 140-2 Level 3 validated. Which Google Cloud service should they use?
39A healthcare company is designing a solution to ingest and process millions of patient records daily. The data must be stored in a way that supports SQL queries and also allows for real-time analytics. The company wants to minimize operational overhead and needs a fully managed, petabyte-scale data warehouse. Which Google Cloud service should the solutions architect recommend?
40A global e-commerce company is designing a multi-region architecture on Google Cloud to ensure high availability and low latency for users worldwide. They want to use a global load balancer that can route traffic to the closest healthy backend and support HTTP(S) and TCP traffic. Which Google Cloud load balancing option should they use?
41A company is designing a hybrid cloud architecture where on-premises applications need to access data stored in a Cloud Storage bucket. The company requires that traffic between on-premises and Google Cloud does not traverse the public internet and must be encrypted. They also need dedicated bandwidth. Which Google Cloud service should the solutions architect use?
42A retail company operates a global e-commerce platform on Google Cloud. Their architects need to choose a load balancing solution that terminates TLS at the edge, provides a single global anycast IP address, and automatically routes users to the closest healthy backend. Which Google Cloud load balancing product should they select?
43A financial services firm must design a data residency solution. Regulators require that customer personal data never leaves the country of origin, but the firm wants to use a single centralized analytics project for aggregated, non-personal reporting. Which Google Cloud architecture best satisfies both requirements?
44A startup is deploying a new web application on Google Cloud. They want to minimize infrastructure management and focus on writing code. The application consists of a frontend and a backend API, and they expect variable traffic. They also want to pay only for what they use. Which Google Cloud service should the solutions architect recommend for deploying the application?
45An online retailer is deploying a new order-processing system on Google Cloud. The system consists of a regional managed instance group (MIG) of Compute Engine VMs that read from and write to a Cloud SQL for MySQL instance. The database must tolerate the loss of an entire zone within the region with minimal downtime and no manual failover steps, while keeping costs predictable. Which Cloud SQL configuration should the architect recommend?
46A healthcare company needs to run a stateful, containerized electronic medical records application that requires a stable network identity and persistent disk storage per replica. The operations team is already fluent with Kubernetes. Which Google Cloud service should they choose?
47A financial services firm is designing a new analytics platform on Google Cloud. Regulatory requirements mandate that data must never be replicated or processed outside the European Union, and the company wants to prevent accidental resource creation in non-EU regions regardless of which engineer is deploying. Which mechanism should the architect use to enforce this constraint?
48A financial services company runs a regulated trading platform in a single Google Cloud region. Regulators require that the platform survive the loss of an entire region with a recovery point objective of zero and a recovery time objective of under one minute. The database is Cloud Spanner, and the application tier runs on Google Kubernetes Engine. Which design should the architect choose?
49A retail company runs a Java-based order service on Compute Engine. The service currently reads its database credentials from a plaintext file on the boot disk. A security review requires that the credentials be removed from disk, be automatically rotated every 30 days, and be retrievable by the application through a single API call. You want the least operational overhead. What should you do?
50A multinational enterprise is designing its Google Cloud resource hierarchy. They want to enforce centrally managed policies, delegate administration to regional business units, and isolate billing. Which two design choices should the architects make? (Choose two.)
51A healthcare company is designing a new patient-records API on Google Cloud. The API must serve read-heavy traffic globally with low latency, tolerate the failure of an entire region, and keep operational overhead low. The data is stored in Cloud Spanner. Which design should the architect recommend?
52A healthcare analytics company ingests continuous streams of device telemetry that must be processed in near real time, enriched with reference data from a Cloud SQL for MySQL instance, and written into BigQuery for analyst queries. The team wants minimal operational overhead and wants to use managed Google Cloud services. Which combination should the architect select?
53A financial services firm is designing the network for a new payment processing platform on Google Cloud. Regulatory rules require that no workload can reach the public internet, that all egress to an on-premises fraud-detection system stay off the public internet, and that Google APIs such as Cloud Storage and BigQuery remain reachable without exposing the workloads. The platform runs on Compute Engine VMs in a single VPC. Which two design elements must the architect include? (Choose two.)
54A logistics company is planning to migrate a batch ETL pipeline from on-premises Hadoop to Google Cloud. The pipeline processes several terabytes nightly, and the team wants to minimize infrastructure management while keeping the ability to tune the cluster for cost and performance. The data currently resides in an on-premises HDFS cluster. Which combination of services should the architect recommend?
55A logistics company runs a latency-sensitive order-tracking service on Compute Engine instances spread across three zones in one region. They need the architecture to survive the loss of an entire zone while keeping inter-instance latency low, and they want automatic failover without manual intervention. Which design should the architects implement?
56A financial services company runs a payment processing platform on Compute Engine. Compliance requires that all data at rest be encrypted with keys the company controls and that key material never leave their on-premises HSM appliances. They must also minimize operational overhead for key rotation. Which Google Cloud solution should the architect recommend?
57A retail company runs a batch analytics workload on Compute Engine. Jobs run nightly, are fault-tolerant, and can be preempted. Finance wants to minimize compute cost while ensuring the jobs still complete each night. The jobs are managed by a Managed Instance Group (MIG) template that must stay within a single zone for data locality compliance. Which configuration should you recommend?
58A multinational retailer is planning its Google Cloud landing zone. Each of the company's business units must be able to create projects and manage billing independently, but the central platform team must retain the ability to enforce network and security guardrails across everything. The company also wants to minimize the number of distinct IAM policy bindings it maintains at the top of the hierarchy. Which two design choices should the architect make? (Choose two.)
59A media company is designing a hybrid architecture that connects its on-premises data center to a Google Cloud VPC. The company needs high-bandwidth, low-latency, private connectivity that does not traverse the public internet, and it wants redundancy so that a single link failure does not interrupt traffic. The architect is evaluating interconnect options. Which two characteristics apply to Dedicated Interconnect in this scenario? (Choose two.)
60A financial services firm runs a global trading platform on Google Cloud. The architecture must survive the loss of an entire region with a recovery point objective of zero and a recovery time objective of under one minute, and it must keep strong consistency for order records. Which design should the architect recommend?
61A financial services firm is designing a new payment processing system on Google Cloud. The system must expose a single global anycast IP address, terminate TLS at the edge, and route requests to the nearest healthy backend across three regions. The backend services run on Compute Engine and must be protected from volumetric DDoS attacks. Which product should you place in front of the backends?
62An IoT company ingests telemetry from 40,000 devices spread across three continents. The architecture team wants a single logical endpoint that automatically routes each device's writes to the nearest healthy Google Cloud region, and they want to avoid managing per-region DNS records or load-balancer IPs. Which design should the architect choose?
63A media company stores millions of video master files in a Cloud Storage bucket in the us-central1 region. Files are written once, accessed frequently for the first 30 days during editing and publishing, and then almost never accessed again, though they must remain retrievable for seven years. The company wants to minimize storage cost without changing the objects' names or the way applications read them. Which approach should the architect recommend?
64A small e-commerce team wants to deploy a containerized storefront to Google Cloud with minimal operational overhead. Traffic is steady, the team has no Kubernetes expertise, and they want to pay only for what they use while the service scales automatically. Which compute option should the architect recommend?
65A retail company runs a monolithic Java application on Compute Engine instances in a single managed instance group behind an external Application Load Balancer. During a flash sale, the application becomes unresponsive, and the operations team observes that the CPU utilization of all instances reaches 100%. The team wants to ensure that the application remains available during similar events. They need a solution that automatically adjusts capacity based on demand and minimizes manual intervention. Which approach should they take?
66A healthcare company is planning a Google Cloud landing zone for a new regulated workload. They must enforce organization-wide guardrails, centralize billing visibility, and give each business unit autonomy over its own projects. The security team needs to apply policies that cannot be overridden by project owners. Which two design choices should you recommend? (Choose two.)
67An enterprise is migrating a latency-sensitive trading application from an on-premises data centre to Google Cloud. The application's components exchange hundreds of thousands of small messages per second and require sub-millisecond inter-process communication. The architect must choose a compute and networking design. What should the architect recommend?
68A healthcare analytics company is designing the Google Cloud landing zone for a new HIPAA-regulated workload. The security team requires that no project in the organization can enable a public Cloud Storage bucket by accident, and that all data-at-rest in BigQuery is encrypted with keys the company rotates on its own schedule. Which two design decisions should the architect include? (Choose two.)
69A retail company is designing a new order-processing system on Google Cloud. The system must expose a REST API that is reachable from the public internet over a custom hostname, must terminate TLS at the edge, and must route requests to different backend services based on URL path prefixes such as /orders and /inventory. The platform team wants a fully managed, globally distributed solution that scales automatically and does not require managing reverse-proxy VMs. Which Google Cloud component should they place in front of the backends?
70A healthcare analytics company ingests HL7 messages into Pub/Sub and processes them with a Dataflow streaming pipeline that writes results to BigQuery. During a regional outage, the pipeline stopped and the team discovered that unacknowledged messages were lost after the retention window expired. The company needs a design where a single-region failure does not cause message loss and the pipeline can resume with minimal manual intervention. What should the architect recommend?
71A retail company runs a Black Friday promotion and expects a burst of read traffic against a product-catalog database. The application is read-heavy, tolerates slightly stale data, and the team wants to scale reads horizontally without changing application code. They are using Cloud SQL for MySQL. Which design should the architect recommend?
72A healthcare company is deploying a new patient portal on Google Cloud. The portal must be accessible globally with low latency, must survive a single region failure, and must use a single anycast IP address. The backend runs on managed instance groups in two regions. Which Google Cloud product should the architect use to expose the service?
73An online retailer runs a stateless containerized API on Google Kubernetes Engine. Traffic is highly seasonal, spiking sharply during flash sales and dropping to near zero overnight. The operations team wants the cluster to add and remove nodes automatically based on pod demand while keeping costs low during idle periods. What should the architect recommend?
74An analytics team runs a batch pipeline that reads several terabytes of data from a Cloud Storage bucket in us-central1 every night. To reduce egress and improve throughput, they decide to run the pipeline on Compute Engine VMs in the same region and want the traffic to stay on Google's internal network without traversing the public internet. They also want the VMs to reach Google APIs such as Cloud Storage and BigQuery. Which configuration should the architect recommend?
75A media company is preparing to migrate a batch reporting application to Google Cloud. The application currently runs on physical servers that are used at about 20 percent CPU on average, but it has two short month-end peaks each quarter when utilization reaches 90 percent for about six hours. The company wants to reduce infrastructure cost while guaranteeing the application always has enough capacity during the peaks. What should the architect recommend?
76A logistics company runs a batch route-optimization job that reads 50 TB from Cloud Storage, performs CPU-intensive computation, and writes results back to Cloud Storage. The job runs for about four hours each night and must finish before the morning dispatch window. The team wants the lowest cost while guaranteeing completion within the window. Which compute design should the architect choose?
77A healthcare company is planning to store sensitive patient records in Cloud Storage. They need to ensure that the data is encrypted at rest with keys that they control and can rotate on demand. They also want to maintain an audit trail of key usage. Which Google Cloud service should they use?
78A financial services firm is planning its Google Cloud resource hierarchy before migrating production workloads. The architecture team wants to enforce separation between business units, centralize network administration, and apply consistent IAM and policy controls across many projects. Which two design choices should the architect recommend? (Choose two.)
79A global e-commerce company is designing its application architecture on Google Cloud. The application must serve users from multiple regions with low latency and must be able to fail over between regions automatically in case of a regional outage. The company wants to minimize operational overhead and ensure that the database layer supports multi-region writes with strong consistency. Which database solution should they choose?
80A small development team is prototyping a containerized application on Google Cloud. They want the least operational overhead for running containers, automatic scaling based on incoming requests, and the ability to scale to zero when there is no traffic. They do not need Kubernetes APIs or custom networking. Which compute option should the architect recommend?
81A financial analytics firm is deploying a new batch reporting platform on Google Cloud. The platform runs on a Managed Instance Group (MIG) of Compute Engine VMs and reads source data from a single Cloud Storage bucket. The security team requires that the VMs access the bucket without using long-lived service account keys, and that the identity be scoped specifically to this workload. They also want the permission to be automatically revoked when the VMs are deleted. Which approach should you recommend?
82A media company stores millions of small image files in a Cloud Storage bucket in the us-central1 region. Users in Europe and Asia report slow image load times. The company wants to improve read latency globally while keeping write operations in us-central1 for cost and simplicity. Which storage configuration should you recommend?
83A company is planning to migrate a batch processing workload to Google Cloud. The workload runs nightly and can be interrupted without impacting the business. The company wants to minimize compute costs. Which Google Cloud service should they use?
84A healthcare company must store patient records on Google Cloud. Regulatory requirements mandate that the data encryption keys be generated and stored outside Google Cloud, that the company control key rotation, and that access to the data be denied if the external key is unavailable. The data will be stored in Cloud Storage and BigQuery. Which approach should the architect recommend?
85A company is deploying a new microservices application on Google Kubernetes Engine (GKE). They need to ensure that each microservice can be independently scaled and updated without affecting other services. They also want to minimize the blast radius of a failure in one microservice. Which design approach should they use?
86A healthcare company is designing a new patient portal on Google Cloud. Regulatory requirements mandate that all data at rest be encrypted with keys the company controls and can rotate on its own schedule, and that the keys never leave a hardware security module (HSM). The security team also wants to retain the ability to revoke Google's access to the data if the external key becomes unavailable. Which key management design should you recommend?
87A logistics company runs a latency-sensitive inventory service on Compute Engine in us-central1. The service writes to a Cloud SQL for MySQL instance and reads from a Memorystore for Redis cache. The architect must design for a zone failure in us-central1 with minimal data loss and automatic failover, without changing the application's connection strings. Which design should the architect choose?
88A retail company is designing a new microservices architecture on Google Cloud. They want to minimize operational overhead, enable independent deployment of services, and ensure that a failure in one service does not cascade to others. They also want to use managed services where possible. Which two design choices should the architect recommend? (Choose two.)
89A retail company is planning a Google Cloud organization structure for a new e-commerce platform. They want to isolate production from non-production, allow central network and security teams to apply guardrails across all projects, and give application teams self-service within their own boundaries. Which two design choices support these goals? (Choose two.)
90Your organization runs a batch analytics platform that ingests data from a Pub/Sub topic into Cloud Storage, then loads it into BigQuery using a Dataflow streaming pipeline. The pipeline must handle sudden bursty traffic during month-end reporting, and you want to minimize operational overhead while ensuring the pipeline scales automatically. Which architectural approach should you choose?
91A media company is designing a new content delivery architecture on Google Cloud. Users worldwide download large video files, and the company wants to serve them from a global edge cache while keeping the origin bucket private. They also want to reduce egress cost by caching at the edge. Which Google Cloud service should you recommend as the front end for this architecture?
92Your company is deploying a multi-tier application on Google Cloud. The application consists of a web frontend running on Compute Engine instances, a backend API running on Google Kubernetes Engine (GKE), and a Cloud SQL for MySQL database. You need to design the network architecture to ensure that the web frontend can communicate with the backend API, and the backend API can access the Cloud SQL database, while minimizing exposure to the public internet. Which two design choices should you implement? (Choose two.)
93A retail company runs its order-processing platform on Compute Engine instances in a single managed instance group (MIG) spread across three zones in us-central1. During seasonal peaks, the application must handle up to 10x normal traffic while keeping median request latency under 200 ms. The architecture team wants to add a caching layer that can absorb repeated catalogue reads and survive the loss of an entire zone without manual intervention. Which design should they choose?
94A retail company runs its e-commerce checkout service on a single Compute Engine instance in us-central1. The service must survive a zonal outage with minimal data loss and automatic failover, but the operations team is small and does not want to manage replication or failover scripts themselves. Which design should the architect recommend?
95A financial services firm is designing a new payment-processing platform on Google Cloud. Regulatory requirements mandate that data never leaves the European Union, that encryption keys are generated and stored on hardware the firm controls inside its own data center, and that the firm can revoke key access instantly. The security team wants to use Cloud KMS but is unsure it meets all three requirements. Which combination of services should the architect recommend?
96A retail company is planning to move its on-premises data warehouse to Google Cloud. They need a fully managed, petabyte-scale analytics database that supports standard SQL and can ingest data in real time from Pub/Sub. They also want to minimize administration and cost. Which Google Cloud service should they choose?
97A retail company is deploying a customer-facing API on Google Cloud. The API must survive the loss of an entire region with minimal data loss and must serve users in North America, Europe, and Asia with low latency. The database layer must support strongly consistent reads and writes. Which design should the architect choose for the data tier?
98A logistics company is planning its first Google Cloud landing zone. It has three business units that must be billed separately, a central network team that manages shared VPCs, and a security team that needs to apply guardrails across everything. Which resource hierarchy design should the architect recommend?
99Your organization is deploying a global e-commerce platform on Google Cloud. The platform uses a microservices architecture running on GKE, and you need to route external HTTP(S) traffic to different services based on URL paths and also provide global load balancing with low latency. You also want to offload SSL/TLS termination and protect against DDoS attacks. Which Google Cloud service should you use?
100A multinational manufacturer is planning its first Google Cloud landing zone. The security team requires that no data be stored outside approved European regions, that all workloads authenticate using short-lived credentials tied to their Google identities, and that network egress to the public internet be centrally inspected and logged. The platform team wants to minimize per-project configuration. Which two design elements should the architect include in the landing zone? (Choose two.)
101A healthcare analytics company is designing a BigQuery-based data warehouse that ingests patient records from multiple hospitals. Regulatory requirements mandate that queries never move data across regional boundaries and that only authorized analysts can access patient-identifiable columns. The architects want to enforce these controls at the platform level rather than relying on application code. Which combination of Google Cloud features should they design into the solution?
102A healthcare analytics company must build a data platform on Google Cloud that stores patient records subject to strict privacy rules. The design must ensure that analysts can query aggregated data without being able to read individual patient identifiers, and that all access to the raw records is logged for audit. Which two design choices should the architect include? (Choose two.)
103A financial services company is designing a hybrid cloud architecture. They have an on-premises data center and want to extend their VPC network to Google Cloud. They require a dedicated, high-bandwidth, low-latency connection with a SLA, and they need to encrypt traffic in transit. They also want to avoid using the public internet. Which connectivity option should they choose?
104A small development team is deploying a stateless containerized API on Google Cloud. They want the simplest possible way to run containers without managing servers or Kubernetes clusters, and they want the service to scale to zero when there is no traffic to minimize cost. The API receives HTTP requests from external clients. Which Google Cloud service should the architect recommend?
105A financial services company is designing a Google Cloud landing zone. Regulators require that production workloads be isolated from non-production workloads, that each business unit control its own billing and quotas, and that a central team enforce network and security policies across everything. The company wants to minimize the number of projects it must manage manually. Which structure should the architect propose?
106A logistics company is planning a new order-tracking platform on Google Cloud. The platform must handle sudden, unpredictable spikes from holiday promotions, keep costs low during idle periods, and provide a relational store that scales reads without the team managing replication. The architect is choosing between fully managed services and self-managed alternatives. Which two design choices meet these requirements? (Choose two.)
Be able to map requirements to concrete GCP services and configurations, justifying cost, availability, and security choices. The single most important thing: match the workload's tolerance for interruption and its availability target to the right compute, storage, and security building blocks.
The Courseiva PCA question bank contains 106 questions in the Design and plan a cloud solution architecture domain, covering the 25% of the exam attributed to this domain in the official Google Cloud blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Design and plan a cloud solution architecture domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included