Google Cloud · Free Practice Questions · Last reviewed May 2026
60real exam-style questions organised by domain, each with the correct answer highlighted and a plain-English explanation of why it's right — and why the others are wrong.
8% of exam · 6 sample questions below
A company wants to reduce costs for a batch analytics job that runs nightly for 4 hours on Compute Engine VMs. The job is fault-tolerant and can handle instance restarts. Which Compute Engine VM pricing model is MOST cost-effective?
3-year committed use discount (CUD)
1-year committed use discount (CUD)
Sustained use discounts
Preemptible VMs
Preemptible VMs suit this fault-tolerant nightly batch job because they cost up to 80% less than standard instances, and the workload already tolerates restarts. The 24-hour maximum lifetime exceeds the 4-hour runtime, so forced preemption risk is acceptable, satisfying the cost-reduction constraint without disrupting analytics.
A company is migrating an on-premises PostgreSQL database (5 TB) to Cloud SQL. They need minimal downtime and automated schema conversion if needed. Which GCP service should they use?
Database Migration Service (DMS)
Database Migration Service performs continuous replication from the on-premises PostgreSQL source to Cloud SQL, keeping downtime to a minimum during cutover. Its built-in schema conversion handles incompatible objects automatically, satisfying the automated conversion requirement for the 5 TB migration.
Datastream
Migrate for Compute Engine (formerly Velostrata)
Transfer Appliance
A company runs a web application on Compute Engine behind a Global HTTPS Load Balancer. Users report slow page loads, especially for static assets. The development team wants to cache content closer to users without modifying code. Which GCP service should they enable?
Cloud CDN
Cloud CDN caches static assets at Google edge points of presence, so repeated requests terminate near users rather than traversing to the Compute Engine backends. Enabling it on the existing Global HTTPS Load Balancer requires no application code changes, directly addressing the slow static asset loads.
Cloud NAT
Cloud Armor
Cloud DNS
A company is migrating a 200 TB on-premises file server to Cloud Storage. The network bandwidth is limited to 100 Mbps. The migration must complete within 30 days. Which approach should they use?
Use Storage Transfer Service from another cloud
Use gsutil rsync over the network
Use Cloud Data Fusion
Use Transfer Appliance
At 100 Mbps, transferring 200 TB over the network would take roughly 200 days, far exceeding the 30-day deadline. Transfer Appliance ships data physically via a rackable appliance, sidestepping the bandwidth constraint and completing the migration within the required window.
A company is planning to migrate a large on-premises Oracle database (10 TB) to Cloud SQL for PostgreSQL. They need to minimise downtime and ensure data integrity. Which TWO services or tools should they use? (Choose TWO.)
Migrate for Compute Engine
Cloud Dataflow
Cloud Scheduler
Database Migration Service (DMS)
Database Migration Service (DMS) supports online migration from Oracle to Cloud SQL for PostgreSQL with minimal downtime.
Cloud SQL Auth Proxy
A company runs a batch processing job that uses preemptible VMs. The job occasionally fails due to VM preemption. They want to improve reliability without significantly increasing cost. Which TWO actions should they take? (Choose TWO.)
Use a managed instance group with autoscaling and preemptible VMs
A managed instance group automatically recreates preempted VMs, directly addressing the reliability constraint while retaining preemptible pricing. Autoscaling maintains capacity by adding instances when demand rises, so the batch job recovers without manual intervention. This satisfies the requirement to improve resilience without significantly increasing cost, since preemptible rates still apply.
Use sole-tenant nodes to reduce risk of preemption
Switch to regular (non-preemptible) VMs
Implement a retry mechanism in the job to re-run failed tasks
Preemption terminates tasks mid-execution, so a retry mechanism re-runs failed tasks once replacement VMs appear. This directly addresses the intermittent failure mode without changing the compute tier, preserving the cost constraint while improving job completion reliability.
Increase the number of preemptible VMs
Want more Analysing and Optimising Technical and Business Processes practice?
Practice this domain12% of exam · 6 sample questions below
A company wants to connect their on-premises data center to Google Cloud with a dedicated private connection that provides 99.99% availability and supports up to 100 Gbps bandwidth. They have a colocation facility near a Google Cloud region. Which connectivity option should they choose?
Partner Interconnect
Direct Peering
Dedicated Interconnect
Dedicated Interconnect provides a direct physical link between the on-premises network and Google's edge at a colocation facility, delivering the 99.99% availability and up to 100 Gbps capacity the stem requires. Partner Interconnect and Cloud VPN cannot meet those combined bandwidth and SLA constraints.
HA VPN
An organization needs to run a stateful application on Google Kubernetes Engine (GKE) where the nodes are fully managed by Google and the application workload SLAs are guaranteed. They want to minimize operational overhead. Which GKE mode should they use?
GKE Standard with Cluster Autoscaler
GKE Standard with node auto-provisioning
GKE Standard with sole-tenant nodes
GKE Autopilot
GKE Autopilot provisions and manages the node infrastructure itself, including scaling, patching and node pool configuration, while enforcing workload resource requests and SLA-backed reliability. This removes node-level operational overhead, satisfying the requirement for fully Google-managed nodes with guaranteed workload SLAs.
A financial services company runs a critical PostgreSQL database on Cloud SQL. They need to ensure automatic failover to a replica in another zone within the same region with minimal data loss. What configuration should they choose?
Use Database Migration Service to replicate to a second Cloud SQL instance
Enable point-in-time recovery (PITR) and increase backup retention
Create a cross-region read replica and manually promote it on failure
Configure a Cloud SQL HA instance with a failover replica in a different zone
A Cloud SQL HA instance maintains a standby in a different zone with synchronous replication, so failover is automatic and data loss is minimal. This satisfies the stem's requirement for cross-zone automatic failover within the same region.
An engineer needs to create a custom dashboard in Cloud Monitoring to track the 99th percentile latency of their application over the last 7 days. Which type of metric should they use?
Distribution metric
Distribution metrics record a histogram of values across a time window, letting Cloud Monitoring compute percentiles such as p99 directly. This satisfies the requirement to track 99th percentile latency over seven days, which a gauge or counter cannot represent.
Delta metric
Cumulative metric
Gauge metric
An organization wants to receive alerts when their Cloud SQL instance's CPU utilization exceeds 80% for 5 minutes. They want to send the alert to both email and a Pub/Sub topic for further processing. What should they do?
Configure a Cloud Scheduler job to check CPU utilization and publish to Pub/Sub
Create a log-based alert for CPU utilization using Logging and route to email and Pub/Sub
Create a Cloud Monitoring alerting policy with a metric threshold condition on CPU utilization and add both email and Pub/Sub notification channels
A Cloud Monitoring alerting policy with a metric threshold condition evaluates CPU utilisation against 80% for the five-minute duration. Attaching both email and Pub/Sub notification channels delivers the alert to each destination, satisfying the dual-delivery requirement without custom code.
Use Cloud Functions to poll the Cloud Monitoring API every minute and send notifications
A company needs to retain object versions in Cloud Storage for 90 days to protect against accidental deletion or modification. After 90 days, versions should be deleted. What feature should they enable?
Object versioning only
Retention policy
Object holds
Object lifecycle management with a rule to delete versions after 90 days
Object lifecycle management applies age-based rules to noncurrent object versions, automatically deleting them once they pass 90 days. This satisfies the stem's requirement to retain versions for 90 days and then remove them, which a retention policy alone cannot do.
Want more Managing Implementation and Ensuring Solution and Operations Reliability practice?
Practice this domain9% of exam · 6 sample questions below
A company uses Cloud Deployment Manager to manage infrastructure. They want to roll back to a previous deployment state after a failed update. What is the recommended approach?
Use gcloud deployment-manager deployments rollback --deployment <name>
Use the --update-policy=PARTIAL flag to selectively revert changes
Delete the deployment and recreate it from the previous template
Run gcloud deployment-manager deployments update --config <previous_manifest>
Redeploying the previous manifest restores the last known-good configuration, satisfying the rollback requirement after a failed update. Deployment Manager is declarative, so reapplying the prior manifest reconciles resources back to that state rather than attempting an in-place undo.
An organization has multiple GCP projects managed by a central operations team. They want to define a common VPC configuration in a host project and allow service projects to use it. Which networking feature should they use?
Shared VPC
Shared VPC lets a host project export subnets to service projects, so the central team retains control of the VPC configuration while each service project deploys its own resources into those shared subnets. This directly satisfies the requirement for one common VPC defined centrally and reused across multiple GCP projects.
Private Service Connect
Cloud VPN
VPC peering
A Cloud Run service needs to connect to a Cloud SQL MySQL instance privately without using public IP. What must be configured?
Set up VPC Network Peering between Cloud Run and Cloud SQL
Enable Private Google Access on the VPC subnet
Use Cloud SQL Proxy as a sidecar container
Deploy a VPC connector and attach it to the Cloud Run service
A Serverless VPC Access connector gives Cloud Run a private network path, letting it reach the Cloud SQL instance over its internal IP. Attaching the connector to the service satisfies the no-public-IP constraint, since traffic never traverses the internet.
Which GCP service should be used to automatically scale a GKE cluster's number of nodes based on pending pods?
Vertical Pod Autoscaler (VPA)
Cluster Autoscaler
Cluster Autoscaler adds or removes nodes in a GKE node pool when pods remain pending due to insufficient allocatable resources, directly satisfying the stem's requirement to scale node count from pending pods. It watches the scheduler's unschedulable queue, unlike Horizontal Pod Autoscaler, which only adjusts replica counts of workloads.
Node Auto-Provisioning
Horizontal Pod Autoscaler (HPA)
An engineer is troubleshooting a Cloud Build trigger that fails with the error 'PERMISSION_DENIED: Cloud Build service account does not have permission to access Artifact Registry'. The build needs to push a Docker image to Artifact Registry. What is the correct IAM role to assign to the Cloud Build service account?
roles/artifactregistry.writer
Granting roles/artifactregistry.writer provides the write permissions Cloud Build requires to push Docker images into Artifact Registry, satisfying the PERMISSION_DENIED constraint. This role permits uploading and creating repository content without granting broader administrative capabilities, so the build service account can complete its image push securely.
roles/artifactregistry.viewer
roles/editor
roles/storage.objectAdmin
Which GCP service provides distributed tracing to help analyze latency in microservices applications?
Cloud Profiler
Cloud Trace
Cloud Trace collects and correlates latency data across microservice calls, producing distributed traces that pinpoint slow spans in request paths. This directly satisfies the need to analyse latency in microservices applications, unlike logging or monitoring services that lack span-level tracing.
Cloud Logging
Cloud Monitoring
Want more Managing and Provisioning a Solution Infrastructure practice?
Practice this domain9% of exam · 6 sample questions below
A company wants to control which resources can be accessed by a service account in a specific project. Which IAM policy binding approach should be used?
Use VPC Service Controls to restrict the service account
Grant the service account a role at the project or resource level
Binding a role to the service account at the project or specific resource level scopes its permissions precisely, so access is limited to the intended resources. IAM policies attached at those levels define exactly which actions the service account may perform.
Add the service account to a Cloud Identity group and grant the group a role
Grant the service account a role at the organization level
An organization requires that all container images deployed to GKE be signed and verified before deployment. Which GCP service should be used?
Container Registry vulnerability scanning
Binary Authorization
Binary Authorization enforces deploy-time attestation on GKE, blocking unsigned or unverified container images before they reach the cluster. It satisfies the stem's requirement for signature verification at deployment by validating attestations from trusted authorities, unlike vulnerability scanning or registry-level controls, which cannot gate admission.
Cloud Build
Artifact Registry
A security team wants to prevent data exfiltration from a GKE cluster to external storage. They need to restrict access to Cloud Storage buckets from the cluster without using private IPs. Which solution should they implement?
Configure firewall rules to block outbound traffic to Cloud Storage
Enable Cloud Armor on the GKE cluster
Use Private Google Access for on-premises access
Implement VPC Service Controls with a service perimeter
VPC Service Controls builds a service perimeter around the GKE cluster's project, blocking Cloud Storage access from outside the perimeter even over public IPs. This satisfies the no-private-IP constraint by enforcing an identity- and network-independent boundary against exfiltration.
A company uses Cloud KMS with CMEK to encrypt data stored in BigQuery. They need to audit who has used the encryption key and when. Which type of audit log should they enable?
Network Security audit logs
Admin Activity audit logs
System Event audit logs
Data Access audit logs
Data Access audit logs record every read, write, and cryptographic operation against BigQuery data, including Cloud KMS key usage for CMEK decryption. Admin Activity logs only capture configuration changes, not key use. Enabling Data Access logging therefore reveals who used the key and when, satisfying the audit requirement.
An engineer needs to grant a user the ability to create and manage service accounts in a project. Which predefined IAM role provides these permissions?
roles/owner
roles/iam.serviceAccountAdmin
roles/iam.serviceAccountAdmin grants the full set of service account management permissions — creating, deleting, updating and viewing service accounts, plus binding IAM policies on them — matching the requirement to create and manage service accounts within the project.
roles/editor
roles/iam.workloadIdentityUser
A company wants to enforce that all API calls to GCP services from outside their corporate network come through a specific Cloud VPN tunnel. Which GCP service can enforce this policy?
VPC Service Controls
VPC Service Controls creates a service perimeter that restricts API access to authorised networks, so requests from outside the corporate network are denied unless they traverse the specified Cloud VPN tunnel. This satisfies the stem's requirement to enforce tunnel-only access to GCP service APIs.
Cloud NAT
Identity-Aware Proxy
Cloud Armor
Want more Designing for Security and Compliance practice?
Practice this domain9% of exam · 6 sample questions below
A company is migrating sensitive customer data to Google Cloud. They need to ensure data is encrypted at rest and in transit. Which Google Cloud service provides a centralized way to manage encryption keys used by Google Cloud services?
Cloud HSM
Cloud External Key Manager (Cloud EKM)
Cloud Key Management Service (Cloud KMS)
Cloud KMS centralises creation, rotation and access control of customer-managed encryption keys, and integrates with Google Cloud services for envelope encryption at rest and in transit. This satisfies the requirement for one centralised key management service.
Secret Manager
A financial services company runs a multi-tier application on Compute Engine. They need to restrict network access so that only the web tier can communicate with the application tier, and only the application tier can access the database tier. All VMs are in the same VPC network. What is the most secure way to implement this?
Use Identity-Aware Proxy (IAP) to manage network access between tiers.
Use VPC firewall rules with target tags to allow traffic between specific tiers.
VPC firewall rules with target tags apply ingress rules only to VMs carrying the specified tag, so the application tier accepts traffic solely from the web tier's tag and the database tier solely from the application tier, enforcing tier isolation within one VPC network.
Create separate VPC networks for each tier and use VPC peering.
Assign a unique service account to each tier and use IAM conditions to restrict traffic.
A healthcare organization uses Cloud Storage to store protected health information (PHI). They have a compliance requirement to ensure that all objects in the bucket are encrypted with a customer-managed key (CMK) that is rotated every 90 days. They also need to log all access to the bucket and detect anomalous access patterns. Which combination of Google Cloud services should they use?
Cloud Storage with default encryption, Cloud Audit Logs, and Security Command Center
Cloud Storage with CMEK via Cloud HSM, Cloud Audit Logs, and Cloud DLP
Cloud Storage with CSEK, Cloud Audit Logs, and Security Command Center
Cloud Storage with CMEK via Cloud KMS, Cloud Audit Logs, and Chronicle
CMEK via Cloud KMS supplies the customer-managed key with configurable 90-day rotation, satisfying the encryption constraint. Cloud Audit Logs capture every bucket access for compliance evidence, while Chronicle ingests those logs to detect anomalous access patterns through its security analytics. Together these three services meet each stated requirement.
A multinational corporation operates in multiple regions and must comply with GDPR. They use Cloud Load Balancing to distribute traffic across regional backends. Their security team wants to block traffic from specific countries (e.g., non-EU countries) at the edge. What should they use?
Configure Cloud CDN to serve content only to EU-based users.
Use Cloud Armor security policies with geographic-based denylist rules.
Cloud Armor security policies attach to the load balancer's backend service and evaluate rules at the edge, including geographic denylists keyed on source country. This blocks non-EU traffic before it reaches regional backends, satisfying the GDPR constraint.
Set VPC firewall rules to allow traffic only from EU IP ranges.
Configure Identity-Aware Proxy (IAP) to require user authentication from allowed countries.
Which TWO are recommended practices for securing a Kubernetes Engine (GKE) cluster?
Disable HTTP load balancing to reduce attack surface.
Enable Binary Authorization to ensure only signed container images are deployed.
Binary Authorization enforces a deploy-time admission check, permitting only container images that carry a valid signature from an attested authority. Unsigned or tampered images are rejected before scheduling, preventing supply-chain compromise of the GKE cluster.
Use the default Compute Engine service account for all GKE nodes.
Use Workload Identity to bind Kubernetes service accounts to IAM service accounts.
Workload Identity binds a Kubernetes service account to a Google Cloud IAM service account, letting pods obtain short-lived IAM credentials instead of static JSON keys stored in Secrets. This satisfies the stem's recommended-practice requirement by removing long-lived credentials, the primary leak vector in GKE clusters.
Enable basic authentication for easier access management.
A company is migrating its on-premises workloads to Google Cloud. They have strict compliance requirements that all data at rest must be encrypted with customer-managed encryption keys (CMEK). Which Google Cloud service should they use to manage the lifecycle of these keys?
Secret Manager
Cloud External Key Manager (Cloud EKM)
Cloud Key Management Service (Cloud KMS)
Cloud KMS creates, stores, rotates and controls customer-managed encryption keys, and integrates with Google Cloud services so data at rest is encrypted under CMEK. It directly satisfies the compliance requirement for managing key lifecycle rather than relying on Google-managed keys.
Cloud Hardware Security Module (Cloud HSM)
Want more Design for security and compliance practice?
Practice this domain25% of exam · 6 sample questions below
A company is migrating on-premises workloads to Google Cloud. They have a critical application that requires consistent low-latency access to a database, with read replicas in multiple regions for disaster recovery. The application is expected to grow by 10x over the next year. Which database service and configuration should the architect choose to meet these requirements?
Use Cloud Bigtable with multi-region replication
Use Cloud SQL for PostgreSQL with cross-region read replicas
Use Cloud Spanner with multi-region configuration
Cloud Spanner's multi-region configuration synchronously replicates data across regions using TrueTime, delivering strong consistency with low read latency and automatic failover for disaster recovery. Its horizontally scalable architecture handles 10x growth without manual sharding, satisfying the stem's combined demands for consistent low latency, multi-region replicas and elastic scale.
Use Firestore in native mode with multi-region location
A company is migrating a legacy monolithic application to Google Cloud. The application currently runs on a single on-premises server and uses a local MySQL database. The company wants to minimize changes to the application code while improving scalability and reliability. Which migration strategy should the architect recommend?
Refactor the application into microservices and deploy on Google Kubernetes Engine.
Rehost the application on Compute Engine and use Cloud SQL for MySQL as the database.
Rehosting on Compute Engine with Cloud SQL for MySQL lifts and shifts the application with minimal code change, satisfying the minimise-changes constraint. Cloud SQL adds managed backups and high availability, improving reliability and scalability over the single on-premises server.
Containerize the application with Docker and run it on Cloud Run.
Migrate the database to Firestore and rewrite the application to use Firestore APIs.
A global e-commerce platform is experiencing intermittent latency spikes during flash sales. The application is deployed on Google Kubernetes Engine (GKE) with a regional cluster. The architecture includes a frontend service, a product catalog service using Cloud Spanner, and an order processing service using Cloud Pub/Sub. During high load, the catalog service shows increased query latency, and some requests time out. What should the architect prioritize to address the issue?
Use Cloud CDN to cache product catalog responses.
Increase the number of nodes in the GKE node pool.
Enable Cloud Spanner interleaved tables and add secondary indexes for common query filters.
Cloud Spanner query latency under flash-sale load stems from scanning non-interleaved tables and full-table reads. Interleaving co-locates child rows with parents, and secondary indexes accelerate the catalog's common filter queries, cutting the data scanned and reducing timeouts at the database layer.
Migrate the catalog service from Cloud Spanner to Cloud Bigtable for better read performance.
A startup is developing a real-time analytics dashboard that ingests data from IoT devices. The data volume is unpredictable but can spike to millions of events per second. The dashboard must display near real-time aggregations with sub-second latency. Which Google Cloud architecture should the architect recommend?
Ingest via Cloud IoT Core directly to Cloud Bigtable, then query with BigQuery.
Ingest via Cloud Pub/Sub, process with Cloud Dataproc, store in Cloud Storage, and query with BigQuery.
Ingest via Cloud Pub/Sub, store raw data in Cloud Storage, and use Cloud SQL for aggregations.
Ingest via Cloud Pub/Sub, process with Cloud Dataflow, store in Cloud Bigtable, and query from the dashboard.
Cloud Pub/Sub absorbs unpredictable spikes to millions of events per second without backpressure, while Dataflow provides streaming windowed aggregations. Bigtable's row-key design delivers the low-latency point and range reads the dashboard needs, satisfying the sub-second latency constraint that batch warehouses such as BigQuery cannot meet for continuous refreshes.
A company wants to restrict access to a Cloud Storage bucket so that only a specific service account can read objects. The bucket contains sensitive data. Which identity and access management (IAM) approach should the architect use?
Grant the service account roles/iam.serviceAccountUser on the bucket.
Use a signed URL to allow access for the service account.
Grant the service account roles/storage.admin on the bucket.
Grant the service account roles/storage.objectViewer on the bucket and remove all other bindings.
Granting `roles/storage.objectViewer` at bucket level binds the service account directly to the resource, satisfying the least-privilege constraint. Removing every other binding ensures no principal inherits access via project-level or inherited roles, so only that service account can read objects. This is the precise mechanism for restricting a sensitive bucket to a single identity.
Drag and drop the steps to set up a VPC network peering between two projects in Google Cloud into the correct order.
1. Verify that the VPC networks have non-overlapping IP ranges. 2. Create a VPC peering connection from Project A to Project B. 3. Create a VPC peering connection from Project B to Project A. 4. Verify the peering status and network connectivity.
This order ensures prerequisites are met (non-overlapping IPs), then establishes both directions of peering, which is required for bidirectional communication. Finally, verification confirms success.
1. Verify that the VPC networks have non-overlapping IP ranges. 2. Create a VPC peering connection from Project A to Project B. 3. Verify the peering status and network connectivity. (No peering from Project B to Project A)
1. Create a VPC peering connection from Project A to Project B. 2. Create a VPC peering connection from Project B to Project A. 3. Verify that the VPC networks have non-overlapping IP ranges. 4. Verify the peering status and network connectivity.
1. Create a VPC peering connection from Project B to Project A. 2. Create a VPC peering connection from Project A to Project B. 3. Verify that the VPC networks have non-overlapping IP ranges. 4. Verify the peering status and network connectivity.
Want more Design and plan a cloud solution architecture practice?
Practice this domain9% of exam · 6 sample questions below
A company is deploying a new application on Compute Engine. They need to ensure that the application can automatically recover from a zone failure. What is the best approach?
Create a managed instance group with instances in multiple zones.
A managed instance group spanning multiple zones maintains capacity when one zone fails, satisfying the automatic zone-failure recovery requirement. The group's regional distribution and autohealing replace unhealthy instances in surviving zones, unlike a single-zone group or manual restart, which cannot survive zone loss.
Use a global load balancer in front of a single instance.
Create a single VM in a single zone and rely on live migration.
Use Cloud Storage to store application state and restore from a snapshot.
An organization has multiple projects in Google Cloud and wants to centralize logging and monitoring for all projects. They need to aggregate logs from all projects into a single project for analysis. Which approach should they use?
Export logs from each project to a Cloud Storage bucket and then import them into BigQuery.
Enable Cloud Audit Logs for all projects and view them from the central project.
Install the Stackdriver agent on all VMs and point them to the central project.
Create a logs sink in each project that exports logs to a BigQuery dataset in the central project.
A logs sink in each project routes log entries to a BigQuery dataset hosted in the central project, aggregating all projects' logs for centralised analysis. This satisfies the requirement to consolidate logs into a single project without per-project querying.
A developer needs to deploy a containerized application on Google Kubernetes Engine (GKE) with minimal operational overhead. They want to automatically scale the number of pods based on CPU utilization. Which GKE feature should they use?
Horizontal Pod Autoscaler.
The Horizontal Pod Autoscaler adjusts the replica count of a workload based on observed CPU utilisation, satisfying the automatic scaling requirement with minimal operational overhead. It reads metrics from the metrics server and scales pods directly, unlike cluster-level node autoscaling.
Node auto-repair.
Vertical Pod Autoscaler.
Cluster Autoscaler.
A company is deploying a web application on Compute Engine behind a global HTTP(S) load balancer. They want to restrict access to only traffic from specific IP ranges. Which load balancer feature should they use?
Cloud Armor security policies.
Cloud Armor security policies attach directly to the global HTTP(S) load balancer's backend service, letting you define allow or deny rules matching source IP ranges. This satisfies the requirement to restrict access to specific IP ranges at the edge, before traffic reaches Compute Engine instances.
VPC firewall rules.
Identity-Aware Proxy (IAP).
Cloud CDN.
A company has a production database running on Cloud SQL. They need to ensure high availability with automatic failover in the event of a zone outage. What should they do?
Export the database to Cloud Storage and import in another region.
Enable Cloud SQL High Availability (HA) configuration.
Cloud SQL High Availability provisions a standby instance in a separate zone with synchronous replication, enabling automatic failover during a zone outage. This directly satisfies the stated availability constraint, whereas read replicas and backups do not provide automatic failover.
Create a cross-region read replica.
Configure automated backups.
A developer wants to store and retrieve non-relational data with flexible schema and automatic scaling. Which Google Cloud service should they use?
Cloud Bigtable.
Cloud SQL.
Firestore.
Firestore is a serverless NoSQL document database offering flexible schemas and automatic horizontal scaling, matching the non-relational, flexible-schema, auto-scaling requirement. It suits application data needing real-time sync and scales without manual sharding, unlike Cloud SQL's fixed relational schema.
Cloud Spanner.
Want more Manage and provision cloud infrastructure practice?
Practice this domain7% of exam · 6 sample questions below
A company is migrating its on-premises Oracle database to Cloud SQL for PostgreSQL. The database team wants to minimize downtime during migration. Which approach should they use?
Set up Oracle GoldenGate to replicate to Cloud SQL.
Use Database Migration Service for PostgreSQL with continuous migration from Oracle via Homogeneous Migration.
DMS supports minimal downtime via continuous replication.
Take a physical backup of Oracle and restore to Cloud SQL.
Export the database as a dump file, upload to Cloud Storage, and import into Cloud SQL.
An e-commerce platform uses Cloud Spanner for order processing. Recently, latency spikes have occurred during flash sales. The team suspects hot spots due to monotonically increasing order IDs. Which table design change would best solve this?
Remove the primary key and let Spanner auto-generate it.
Use interleaved tables to store orders under customers.
Add a random prefix to the order ID primary key.
Randomising the leading key bytes spreads sequential inserts across multiple Spanner splits, eliminating the hot spot caused by monotonically increasing order IDs during flash sales. This directly addresses the stem's constraint: write contention concentrated on the trailing split. Range scans by order ID still work, though they now require prefix-aware query design.
Create a secondary index on the timestamp column.
A company uses BigQuery for analytics. They have a large partitioned table that is queried frequently. The query performance has degraded over time. Which optimization should they try first?
Create a materialized view for each frequent query.
Increase the number of slots for the project.
Apply clustering on frequently filtered columns.
Clustering physically co-locates rows sharing the clustered column values, so filters on those columns scan fewer blocks. On a frequently queried partitioned table, clustering the common filter columns prunes data within each partition, improving performance without restructuring partitions.
Denormalize the table to reduce joins.
An organization runs a Kubernetes cluster on GKE with cluster autoscaling enabled. They notice that pods are frequently in 'Pending' state due to insufficient CPU, but the cluster autoscaler does not add nodes quickly enough. What is the most likely cause?
The cluster autoscaler is using the 'least-waste' expander.
The horizontal pod autoscaler (HPA) is misconfigured.
The pod disruption budget (PDB) is too restrictive.
The node pool has reached the maximum node count limit.
When the node pool hits its maximum node count, the cluster autoscaler cannot provision further nodes regardless of pending pods. Pods remain Pending because no capacity is added, explaining the slow scaling despite autoscaling being enabled.
Your company runs a multi-tier web application on Google Kubernetes Engine (GKE). The application consists of a frontend service, a backend API service, and a PostgreSQL database deployed using a StatefulSet with persistent volumes. The backend service exposes a gRPC endpoint. Recently, the team noticed that the backend service experiences intermittent high latency and occasional timeouts. The frontend service is stateless and scales well. The backend service is CPU-bound. The database is not the bottleneck. The cluster has three nodes of type n1-standard-4. The backend service is deployed with 10 replicas, each requesting 1 CPU and 2 Gi memory. Node utilization is around 70% CPU. The team suspects the network is the issue. However, after reviewing the GKE monitoring dashboard, they see that the network bytes sent/received per second for the backend pods is well below the node's network bandwidth limit. The latency spikes seem correlated with periods of high CPU throttling on the backend pods. The backend service's gRPC requests are small (under 1 KB), and the responses are also small. The team has already optimized the application code. What should the team do to reduce latency?
Increase the number of nodes in the cluster to reduce network contention.
Increase the number of backend replicas to 20.
Increase the CPU request for the backend pods to 2 CPUs.
CPU throttling, not network bandwidth, causes the latency spikes. Raising each backend pod's CPU request to 2 CPUs gives the CPU-bound gRPC service enough quota to avoid throttling, directly removing the constraint correlated with the observed timeouts.
Increase the memory request for the backend pods to 4 Gi.
A company runs a monolithic application on Compute Engine. They want to modernize by moving to microservices on Google Kubernetes Engine (GKE) to improve deployment frequency and resource utilization. However, they are concerned about the increased operational complexity. Which approach best balances modernization benefits with operational overhead?
Keep the monolithic application on Compute Engine and use Cloud Monitoring to optimize resource utilization.
Migrate all application components to Cloud Run and use Cloud Tasks for asynchronous communication.
Rewrite the entire application as microservices and deploy on GKE with Istio for service mesh.
Identify stateless components to migrate to Cloud Run, and keep stateful components on GKE with managed services like Cloud Spanner.
Cloud Run removes cluster management for stateless components, cutting operational overhead, while GKE with managed Spanner keeps stateful workloads reliable. This split directly balances the stated modernization benefits against the concern about increased operational complexity, rather than migrating everything wholesale.
Want more Analyze and optimize technical and business processes practice?
Practice this domain6% of exam · 6 sample questions below
A company runs a critical application on Compute Engine instances in a managed instance group (MIG) with autoscaling. During a traffic spike, some instances become unhealthy but are not automatically replaced. What is the most likely cause?
The MIG is regional and one zone failed.
The autohealing health check is misconfigured.
Autohealing relies on a health check to detect and recreate unhealthy instances. If that health check is misconfigured — wrong path, port, or thresholds — the MIG never marks instances unhealthy, so no automatic replacement occurs despite the traffic spike.
The instance template has a startup script error.
The HTTP load balancer's health check is failing.
A company uses Cloud Spanner for a global financial application. They experience increased latency and transaction aborts during peak hours. Which measure should they take first to improve reliability?
Increase the number of nodes in the Spanner instance.
Reduce the number of indexes on frequently updated columns.
Optimize transactions to reduce lock contention.
Reducing lock contention directly addresses the transaction aborts and latency spikes. Cloud Spanner aborts transactions when locks conflict, so shortening transactions and ordering reads and writes to minimise overlapping access lowers abort rates and improves throughput during peak load.
Use interleaved tables to co-locate related data.
A company deploys a microservices application on Google Kubernetes Engine (GKE). Pods in one deployment are frequently OOMKilled. The team sets memory requests and limits, but pods still crash. What is the most likely remaining cause?
CPU requests are too low, causing throttling and eventual crash.
The node pool is too small, causing memory pressure on the node.
Memory limits are set higher than the node's allocatable memory.
The application has a memory leak that eventually exceeds the limit.
Requests and limits only cap consumption; they cannot prevent a leak from growing until the container exceeds its limit and is OOMKilled. Since configuration is already correct, the remaining cause is application-level: unbounded allocation that eventually surpasses the configured memory limit.
An organization uses Cloud Functions (2nd gen) for event-driven processing. They notice that some functions fail with 'memory limit exceeded' errors during peak load. The function processes messages from Pub/Sub and writes to Firestore. What should they do to improve reliability without sacrificing throughput?
Increase the maximum number of concurrent function instances.
Increase the memory allocated to the Cloud Function.
Memory limit exceeded errors mean the function's allocated memory is exhausted during peak concurrency. Raising the memory allocation gives each instance more headroom to process Pub/Sub messages and write to Firestore, restoring reliability while preserving throughput, since Cloud Functions scales instances independently of the memory setting.
Enable Pub/Sub batching to reduce the number of function invocations.
Split the function into multiple smaller functions, each handling a subset of the data.
A company monitors their application with Cloud Monitoring. They set up an alerting policy to notify the on-call team when the 99th percentile latency exceeds 500 ms for 5 minutes. However, they receive false positive alerts due to short bursts. How should they refine the policy?
Set up alerting on each data point individually.
Decrease the threshold to 400 ms.
Change the metric to average latency instead of 99th percentile.
Increase the evaluation window to 10 minutes.
Extending the evaluation window to 10 minutes requires latency to breach 500 ms across a longer sustained period, filtering out brief spikes that triggered false positives. This directly addresses the stem's short-burst problem while retaining detection of genuine sustained degradation.
A company runs a web application on Google Kubernetes Engine (GKE) with Cluster Autoscaler enabled. During a traffic spike, the application becomes slow and some requests timeout. The cluster has sufficient CPU and memory headroom. What is the most likely cause and solution?
Increase the node pool's machine type to a larger size.
Enable Cluster Autoscaler to add more nodes.
Deploy the application in a regional cluster for higher availability.
Configure Horizontal Pod Autoscaler (HPA) based on CPU utilization or custom metrics.
Cluster Autoscaler only adds nodes when pods are pending; with CPU and memory headroom already available, no new nodes are needed. The bottleneck is pod count, so Horizontal Pod Autoscaler must scale replicas based on CPU or custom metrics to absorb the traffic spike.
Want more Ensure solution and operations reliability practice?
Practice this domain6% of exam · 6 sample questions below
Your team has deployed a microservices application on Google Kubernetes Engine (GKE) with multiple services communicating via internal ClusterIP services. You notice that some requests between services are failing intermittently with 'connection refused' errors. The services are defined with readiness probes. What is the most likely cause?
The readiness probes are not passing, causing the service endpoints to be removed.
Failing readiness probes cause the pod to be removed from service endpoints, leading to connection refused.
The services are not exposed via a VPC peering connection to the client's VPC.
The services are using NodePort instead of LoadBalancer type, causing port conflicts.
The services are not associated with an Ingress resource.
A company is planning to deploy a global web application on Google Cloud. They expect low latency for users worldwide and need to serve static content (images, CSS) as well as dynamic API responses. Which architecture should they use?
Use Cloud CDN in front of an external HTTPS Load Balancer with backend services in multiple regions.
Cloud CDN caches static assets at edge locations, while the external HTTPS Load Balancer with multi-region backends routes dynamic API traffic to the nearest healthy region, satisfying the worldwide low-latency requirement for both content types.
Use Cloud NAT to allow egress traffic from instances and distribute static content via a shared VPC.
Use Cloud DNS with geo-routing to direct users to the closest regional Cloud Run service.
Use VPC Network Peering to connect multiple regional VPCs and serve content from a central location.
A startup wants to deploy a web application on Google Cloud with a MySQL database. They anticipate low traffic initially but want the ability to scale seamlessly. They also want to minimize operational overhead. Which combination of services should they choose?
Compute Engine with a self-managed MySQL instance.
Cloud Run with Cloud Spanner.
App Engine Standard Environment with Cloud SQL.
App Engine Standard automatically scales instances with traffic and requires no server management, while Cloud SQL provides a managed MySQL database, together minimising operational overhead. This pairing satisfies the low-traffic start, seamless scaling, and reduced administration constraints.
Google Kubernetes Engine (GKE) with Cloud SQL.
Your organization has a policy that all Compute Engine instances must have specific labels (env, team, cost-center) applied. You want to enforce this automatically when instances are created. What should you do?
Enable Cloud Audit Logs and set up a metric-based alert to detect instances without labels.
Create a Cloud Function that listens for instance creation events and adds labels automatically.
Assign a custom IAM role that includes permission to label instances, and remove the default compute.instances.create permission.
Use the Organization Policy service with a custom constraint to require labels on Compute Engine instances.
Organization Policy custom constraints let you define and enforce label requirements across the project hierarchy, blocking non-compliant instance creation at the API level. This satisfies the policy's demand for automatic enforcement at creation time, rather than relying on manual labelling or post-hoc auditing.
Which THREE actions can help reduce costs for a BigQuery workload that runs frequent, ad-hoc analytical queries on a large dataset?
Enable automatic schema detection to avoid manual schema definition.
Partition the table by a date or timestamp column.
Partitioning by date or timestamp prunes scanned data, so ad-hoc analytical queries read only relevant partitions rather than the full table. This directly reduces bytes processed, and BigQuery bills on-demand queries by data scanned, satisfying the cost-reduction requirement for frequent large-dataset analysis.
Create materialized views for common aggregation queries.
Materialised views precompute and persistently store aggregation results, so repeated ad-hoc queries scan the small view rather than the full large dataset. BigQuery bills on bytes processed, so this directly cuts query cost for the frequent common aggregations described in the stem. Automatic refresh keeps results current without manual intervention.
Use clustering on columns frequently used in filter clauses.
Clustering physically sorts data by the chosen columns, so filters on those columns skip irrelevant blocks. Queries scan fewer bytes, and BigQuery bills on-demand by bytes processed, directly reducing cost for frequently filtered ad-hoc workloads.
Use flat-rate pricing with reserved slots.
An engineer runs the command above. A few days later, the instance becomes unresponsive. Upon investigation, you find that the boot disk is 100 GB and 95% full. The data disk is 500 GB and only 20% full. What is the most likely cause of the unresponsiveness?
The boot disk is too small and has run out of space.
The boot disk holds the operating system, logs, and temporary files. At 95% of 100 GB, it lacks space for normal writes, causing the instance to hang. The data disk's free capacity is irrelevant because the OS cannot use it for boot-volume operations.
The data disk is pd-standard, which is causing I/O bottlenecks for the OS.
The boot disk is pd-ssd, which is too slow for the workload.
The instance has run out of IOPS on the boot disk.
Want more Manage implementation of cloud architecture practice?
Practice this domainThe PCA exam has 60 questions and must be completed in 120 minutes. The passing score is 720/1000.
Architecture design scenario questions covering GCP services, reliability, security, cost optimisation, and migration strategies.
The exam covers 10 domains: Analysing and Optimising Technical and Business Processes, Managing Implementation and Ensuring Solution and Operations Reliability, Managing and Provisioning a Solution Infrastructure, Designing for Security and Compliance, Design for security and compliance, Design and plan a cloud solution architecture, Manage and provision cloud infrastructure, Analyze and optimize technical and business processes, Ensure solution and operations reliability, Manage implementation of cloud architecture. Questions are weighted by domain — higher-weight domains appear more on your actual exam.
No. These are original exam-style practice questions written against the official Google Cloud PCA exam objectives. They are not copied from the real exam. Courseiva focuses on genuine understanding, not memorisation of braindumps.
Courseiva tracks your accuracy per domain and routes you toward weak areas automatically. Free, no account required.