You must be able to choose and configure the right Google Cloud service for declarative infrastructure and automated delivery. The single most important thing is matching the requirement—templating language, image signing, or manual approval—to the correct product, not a similar-sounding one.
Start practicing
Managing and Provisioning a Solution Infrastructure — choose a session length
Free · No account required
Domain overview
This domain covers provisioning and managing Google Cloud infrastructure declaratively and through automated pipelines. Expect scenario questions on choosing between Terraform, Config Connector, and Deployment Manager, securing GKE with Binary Authorization, and configuring Cloud Build triggers and Cloud Deploy approvals. You must match the right service to requirements like templating language, image signing, and per-service change detection.
Exam objectives
Selecting Terraform or Config Connector for infrastructure as code with Python and Jinja templating
Configuring Cloud Build triggers with included files or path filters for per-service builds
Enforcing Binary Authorization attestations so only signed container images deploy to GKE
Setting up Cloud Deploy delivery pipelines with manual approval before production targets
Choosing Deployment Manager for Python/Jinja templating when Terraform is the supported declarative IaC tool with those languages.
Assuming Cloud Build triggers automatically detect changed subdirectories without configuring included files or path filters.
Confusing Binary Authorization with Container Analysis or Artifact Registry scanning, which report vulnerabilities but do not block unsigned deployments.
Click any question to see the full explanation and answer options, or start a focused practice session above.
A company uses Cloud Deployment Manager to manage infrastructure. They want to roll back to a previous deployment state after a failed update. What is the recommended approach?
2An organization has multiple GCP projects managed by a central operations team. They want to define a common VPC configuration in a host project and allow service projects to use it. Which networking feature should they use?
3A Cloud Run service needs to connect to a Cloud SQL MySQL instance privately without using public IP. What must be configured?
4Which GCP service should be used to automatically scale a GKE cluster's number of nodes based on pending pods?
5An engineer is troubleshooting a Cloud Build trigger that fails with the error 'PERMISSION_DENIED: Cloud Build service account does not have permission to access Artifact Registry'. The build needs to push a Docker image to Artifact Registry. What is the correct IAM role to assign to the Cloud Build service account?
6Which GCP service provides distributed tracing to help analyze latency in microservices applications?
7A developer wants to deploy a Cloud Function that is triggered whenever a new object is created in a Cloud Storage bucket. Which trigger type should they choose?
8An engineer wants to store a database password securely and allow a Cloud Run service to access it. Which GCP service should they use?
9A team is building a CI/CD pipeline for a Java application that will run on GKE. They want to automatically build the application, run unit tests, create a Docker image, push it to Artifact Registry, and deploy to GKE. Which two GCP services should be combined? (Choose two.)
10An organization wants to monitor and alert on custom application metrics from a GKE cluster. They also need to view logs in real-time and create metrics from log content. Which two GCP services should they use? (Choose two.)
11A DevOps team wants to automate the deployment of infrastructure on Google Cloud using a declarative configuration language. They need to support Python and Jinja templates for reusable modules. Which service should they use?
12A team is using Cloud Build to deploy a microservice to Cloud Run. They want to ensure that only containers built from a specific trusted branch in their source repository are deployed to production. Which Cloud Build feature should they use?
13A company runs a stateful application on GKE that requires persistent storage. They want to ensure that during cluster upgrades, pods are not disrupted and storage is preserved. Which configuration should they use?
14A security team wants to enforce that only container images signed by their internal CI/CD pipeline can run on GKE clusters. They also need to ensure that unsigned images are rejected at admission time. Which combination of services and configurations should they use?
15A developer wants to deploy a containerized web application on Google Cloud that can scale to zero when not in use and charges only for resources consumed during request processing. Which compute service should they choose?
16A company has a Cloud Run service that processes high-throughput requests. They want to reduce latency by keeping a baseline of warm instances always ready to handle traffic. Which Cloud Run configuration parameters should they adjust?
17A team is deploying a microservice on Cloud Run that needs to access a Cloud SQL database securely. They want to avoid using public IPs and ensure traffic stays within Google's network. Which configuration should they use?
18A financial services company requires that all audit logs be retained for 7 years in a cost-effective, immutable storage. They also need to run ad-hoc SQL queries on the logs. Which configuration should they use?
19An organization wants to manage DNS records for a domain they own (e.g., example.com) and use Google Cloud for authoritative DNS. They also need to resolve internal hostnames for resources within their VPC. Which Cloud DNS configuration should they use?
20A company uses Cloud Build to deploy a Java application to Artifact Registry. They want to automatically trigger a build only when changes are pushed to the 'main' branch in their Cloud Source Repository. Which configuration should they use?
21A team is running a GKE cluster with a workload that has variable CPU and memory usage. They want to automatically adjust pod resource requests and limits based on historical usage to improve resource efficiency. Which feature should they use?
22A company wants to grant a service account in Project A the ability to push containers to Artifact Registry in Project B. They want to follow the principle of least privilege. Which IAM roles should they assign?
23A company is deploying a critical application on GKE and wants to ensure high availability during node upgrades and failures. Which TWO configurations should they implement? (Choose 2.)
24A development team wants to automate the process of building container images from their GitHub repository and storing them in Artifact Registry. Which Google Cloud service should they use to create a build trigger that runs on every push to the main branch?
25An organization wants to manage Google Cloud infrastructure as code using declarative configuration files. They need a solution that supports Python and Jinja templating languages. Which service should they choose?
26A company runs a critical application on Compute Engine instances. They want to automatically patch the operating system on a weekly schedule to meet compliance requirements. Which Google Cloud service should they use?
27You need to create a private GKE cluster with Workload Identity enabled to allow pods to access Google Cloud APIs without static service account keys. What must you configure for the cluster?
28A Cloud Run service needs to access resources in a VPC network (e.g., a Cloud SQL instance). The service should be able to send requests to the VPC and receive responses. What is the correct configuration?
29Your organization requires all container images deployed to GKE to be signed by an approved authority. Which service enforces that only signed images are allowed to run?
30A GKE cluster has a Horizontal Pod Autoscaler (HPA) configured for CPU utilization. The pods are not scaling up even though CPU usage is high. What could be the reason?
31You want to monitor the latency of an application running on Compute Engine and create an alert if the 99th percentile latency exceeds 500ms for more than 5 minutes. Which approach should you use?
32A company needs to store secrets such as API keys and database passwords securely and access them from Compute Engine instances. Which service provides secret storage with built-in IAM integration and automatic rotation?
33Which TWO services can be used to create a CI/CD pipeline for a containerized application on Google Cloud? (Choose 2)
34You are designing a multi-region deployment for a critical application on GKE. The application must withstand a regional outage and automatically redirect traffic to the healthy region. Which THREE components must be configured? (Choose 3)
35A company wants to deploy a microservice on Cloud Run that requires high throughput and low latency. The service processes requests that can spike unpredictably. The team wants to minimize cold starts and ensure availability during traffic bursts. Which combination of Cloud Run settings should they configure?
36What is the purpose of a Pod Disruption Budget (PDB) in GKE?
37A company wants to enforce that only container images built and signed by their CI/CD pipeline can be deployed in their GKE cluster. Which Google Cloud service should they use?
38An engineer needs to share a VPC network across multiple projects in an organization while maintaining centralized network administration. Which approach should they use?
39Which Google Cloud service allows you to create alerting policies based on log entries?
40A company wants to use Cloud Deploy to automate deployments to GKE. They need to configure an approval gate that requires manual approval before promoting a release to a production cluster. Where is this approval gate defined?
41An organization wants to export their Cloud Logging logs to a centralized BigQuery dataset for long-term analysis. They also need to exclude logs from a specific source (e.g., a test project) to reduce costs. How should they set this up?
42A developer needs to store a database password securely and access it from a Cloud Run service. Which Google Cloud service should they use?
43A company wants to monitor the performance of their microservices deployed on Cloud Run. They need to capture request latencies and error rates, and also trace requests across services. Which TWO services should they use?
44A finance company needs to ensure that all compute instances in their VPC can only communicate with Google APIs (e.g., Cloud Storage) over internal IPs. Additionally, instances without external IPs should be able to access the internet for updates. Which TWO configurations should they implement?
45A team is deploying a stateful application on GKE. They want to ensure that the application's pods are distributed across different zones for high availability and that during cluster upgrades, at least one pod remains available. Which THREE features should they configure?
46A DevOps team uses Cloud Build to deploy Docker images to GKE. They want to ensure that only images that have passed a vulnerability scan and been signed by a trusted authority can be deployed. Which service should they integrate with Cloud Build and GKE?
47A company uses Cloud Deploy for continuous delivery. They have a delivery pipeline with multiple targets: dev, staging, and prod. They want to require manual approval before deploying to prod. How should they configure this?
48A developer is writing a Cloud Function that processes files uploaded to a Cloud Storage bucket. Which trigger should they use?
49A company has a Shared VPC with a service project hosting GKE clusters. The GKE nodes need to access Cloud SQL instances in the host project. The team wants to avoid public IP and use Private Service Access. They have configured a VPC peering between the host VPC and the service producer VPC for Cloud SQL. However, the GKE pods cannot reach the Cloud SQL instance. What is the most likely cause?
50A team wants to collect and analyze logs from multiple projects into a centralized BigQuery dataset for long-term retention and SQL querying. They want to exclude health check logs to reduce costs. Which approach should they use?
51An organization runs a stateful application on GKE that must not lose data during cluster upgrades or node repairs. The application uses persistent volumes with ReadWriteOnce access mode. The team wants to ensure pods are not evicted simultaneously. Which Kubernetes resource should they configure?
52A team wants to deploy a microservice on Cloud Run that needs to access a Cloud Memorystore for Redis instance in the same region. The Redis instance is in a VPC network. Which configuration is required for Cloud Run to reach the Redis instance?
53A company wants to automatically apply security patches to Compute Engine instances running Windows Server. They need a solution that can schedule patch installations and report compliance. Which service should they use?
54A company is migrating a legacy application that uses a file server to GCP. The application requires a shared file system that supports the NFS protocol and can be mounted by multiple Compute Engine instances. The team also needs to use Cloud NAT to allow the instances to download updates. Which TWO services should they use? (Choose 2)
55A company wants to implement a CI/CD pipeline for a Java application that will be deployed to Cloud Run. They use Cloud Build and Artifact Registry. The pipeline must compile the Java code, run unit tests, build a container image, and deploy to Cloud Run. Which THREE steps are required in the cloudbuild.yaml? (Choose 3)
56An organization requires that only container images signed by a trusted authority can be deployed on Google Kubernetes Engine (GKE). Which Google Cloud service should they implement?
57A cloud architect is designing a CI/CD pipeline for a microservices application. Each service is deployed to Cloud Run. They want to use Cloud Build to automate building and deploying services only when changes occur in their respective directories. Which Cloud Build feature should they configure?
58A company is migrating its on-premises MongoDB database to Google Cloud. They want a fully managed, highly available NoSQL database that is compatible with MongoDB drivers. Which Google Cloud service should they choose?
59An organization wants to ensure that all Compute Engine instances in a project are patched with the latest security updates. They also want to enforce a custom configuration (e.g., disable root SSH login) across all instances. Which TWO Google Cloud services should they use together?
60A data engineering team wants to ingest streaming data from Pub/Sub, transform it using Apache Beam, and load it into BigQuery for real-time analytics. They need a fully managed solution that handles autoscaling and does not require managing servers. Which TWO Google Cloud services should they use?
61A company has a legacy application that runs on a single Compute Engine VM and expects to use a fixed IP address. They want to migrate the VM to a different region with minimal downtime. Which TWO actions should they take?
62A security team wants to monitor and audit all changes to IAM policies in a Google Cloud organization. They need to set up real-time alerts when a new binding is added. Which THREE services should they combine to achieve this?
63A cloud architect needs to implement a CI/CD pipeline for a team developing a Python-based microservice. The team uses GitHub as their source repository. The pipeline should automatically run unit tests and deploy the service to Cloud Run when changes are pushed to the main branch. Which THREE Google Cloud services should they use?
64A healthcare company is migrating a legacy on-premises Oracle database to Google Cloud. The database is used for a patient records application that requires strong consistency, ACID transactions, and a relational schema with complex joins. The company wants a fully managed, highly available relational database service that minimizes administrative overhead while supporting their existing SQL workloads. Which Google Cloud service should they choose?
65A retail company runs a stateful PostgreSQL database on a Compute Engine VM in project prod-db. The database writes nightly backups to a regional Cloud Storage bucket in a separate project, backup-archive. The security team requires that the VM's service account can upload objects but must not be able to delete or overwrite existing backups. Which IAM configuration should the architect implement?
66A media company streams video from a global user base. The architect must provision a load balancer that terminates TLS, routes requests by URL path to different backend services, and provides a single global anycast IP address. The backend services run on managed instance groups in three regions. Which Google Cloud load balancer should the architect deploy?
67A healthcare company must store patient documents in Cloud Storage. Compliance requires that the data be encrypted with keys the company controls and that key usage be centrally audited and revocable. The architect plans to use Cloud KMS. Which two actions should the architect take to meet these requirements? (Choose two.)
68A retail company runs a stateless web tier on a managed instance group (MIG) of Compute Engine VMs behind an external Application Load Balancer. Traffic spikes every evening and the operations team currently resizes the MIG manually. They want the group to add and remove VMs automatically based on CPU utilization without changing the instance template. What should the architect configure?
69A startup wants to deploy a containerized web application that must scale automatically based on incoming request concurrency. The team wants to avoid managing Kubernetes nodes or clusters and prefers a fully managed serverless platform with per-request billing. Which Google Cloud service should the architect recommend?
70A healthcare analytics company must store patient records in Cloud Storage. Compliance requires that the data be encrypted with keys the company generates and rotates itself, and that the company retain the ability to revoke access by disabling the key. The data must remain readable by authorized applications in the same project. What should the architect implement?
71A retail company runs a stateless web front end on a managed instance group of Compute Engine VMs behind an external Application Load Balancer. Traffic has grown, and the operations team wants to reduce the cost of idle capacity while still absorbing sharp, unpredictable spikes in user requests. They also want to avoid managing a separate autoscaling policy for each instance group. Which provisioning approach should the architect recommend?
72A media company stores finished video masters in a Cloud Storage bucket. Legal requires that every object be retained for exactly seven years and that no user, including project owners, be able to delete or overwrite an object before that period ends. Which bucket configuration should the architect apply?
73A healthcare analytics team must run a stateless containerized API on Google Cloud. The platform must scale to zero when there is no traffic, expose an HTTPS endpoint with a managed certificate, and require no cluster or node management by the team. The architect is choosing among Google Cloud container platforms. Which two characteristics make Cloud Run the appropriate choice here? (Choose two.)
74A healthcare analytics company stores sensitive patient datasets in a Cloud Storage bucket in the us-central1 region. A new regulation requires that the data never leave the United States and that access be restricted to a defined set of projects. The security team wants a guardrail that prevents any future project from reading the bucket unless it is explicitly authorized, while keeping administration simple. What should the architect implement?
75A global logistics company runs a three-tier application on Compute Engine in a single region. The database tier must survive the loss of an entire zone without data loss, and the application tier must continue serving traffic with minimal disruption during a zonal failure. The architect wants the smallest operational change that satisfies both requirements. Which design should the architect implement?
76A logistics company is deploying a new three-tier application on Google Cloud. The architecture team must choose a managed database for the order-processing tier that provides automatic failover across zones with no application connection string changes, and they must also ensure that the database can scale read traffic independently of writes. (Choose two.)
77A healthcare company runs a three-tier application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier. All tiers are in the same VPC in project prod-apps. The security team requires that rules be evaluated by source identity rather than IP ranges, and that no instance can reach the database unless explicitly allowed. Which configuration should the architect use?
78A media startup wants to give its data science team isolated environments for experimentation while keeping billing and user management under one organization. Each environment must have its own quotas and IAM boundary, and the team wants to add or remove environments quickly without renegotiating billing. Which Google Cloud resource hierarchy construct should the architect use for each environment?
79A healthcare analytics company stores protected health information in Cloud Storage buckets. Auditors require that data be encrypted with customer-managed encryption keys (CMEK) and that key usage be logged separately from data access. The security team wants the ability to revoke access to the data by disabling a single key without deleting the data. Which configuration should the architect recommend?
80A media company runs a batch transcoding job on Compute Engine. The job pulls source files from a Cloud Storage bucket in the same project. Security policy forbids assigning external IP addresses to any VM. The VMs must reach the Cloud Storage API without traversing the public internet. What should the architect configure?
81A startup wants to deploy a stateless containerized API that must scale automatically from zero and be billed only when requests are processed. The team has no Kubernetes expertise and wants minimal operational overhead. Which Google Cloud service should the architect recommend?
82A startup runs a batch analytics job on a single Compute Engine instance that takes about nine hours and reads 2 TB from a Cloud Storage bucket each run. The team wants to reduce cost without changing the application code, and the job can be interrupted and resumed from checkpoints. Which machine configuration should the architect recommend?
83A startup is deploying a new containerized web application to Google Cloud. The team wants the simplest way to run containers without managing Kubernetes nodes, needs automatic scaling from zero, and wants to pay only when requests are being handled. Which Google Cloud service should the architect recommend?
84A financial services firm is deploying a three-tier application on Google Cloud. The web tier runs on managed instance groups behind an external HTTP(S) load balancer, the application tier runs on GKE, and the database tier runs on Cloud SQL. Security requires that the database tier accept connections only from the application tier and that no component be reachable from the public internet except the web tier. The architect must design the network and firewall configuration. (Choose two.)
You must be able to choose and configure the right Google Cloud service for declarative infrastructure and automated delivery. The single most important thing is matching the requirement—templating language, image signing, or manual approval—to the correct product, not a similar-sounding one.
The Courseiva PCA question bank contains 84 questions in the Managing and Provisioning a Solution Infrastructure domain, covering the 9% of the exam attributed to this domain in the official Google Cloud blueprint. Click any question to see the full explanation and answer breakdown.
Start with a 10-question focused session to identify your baseline accuracy in this domain. Read every explanation — even for questions you answer correctly — to understand the reasoning. Once you score consistently above 80%, move to a 20–30 question session to confirm depth before moving to the next domain.
Yes — the session launcher on this page draws questions exclusively from the Managing and Provisioning a Solution Infrastructure domain. Choose 10, 20, 30, or 50 questions for a focused session, or click individual questions to review them one by one.
Save your results, see per-domain analytics, and get readiness scores — free, for every certification.
Sign Up FreeFree forever · Every certification included