Courseiva

CCNA Planning and Configuring a Cloud Solution Questions

61 questions · Planning and Configuring a Cloud Solution · All types, answers revealed

1
MCQmedium

A company wants to use Cloud Run to deploy a containerized API that requires up to 8 GB of memory per request. The API experiences unpredictable traffic spikes. They want to minimize cost while ensuring fast cold starts. Which configuration should they use?

A.Use Cloud Run jobs instead of Cloud Run service
B.Deploy the container to GKE Autopilot with a single pod
C.Set max-instances to a high number and min-instances to 0 with CPU always allocated
D.Set min-instances to 1 and max-instances to a value that handles peak traffic with CPU throttled
AnswerD

Setting min-instances to 1 keeps one container instance always warm, eliminating the cold start for the first request after idle periods. A max-instances value calibrated to peak traffic caps both concurrent capacity and monthly cost, preventing unbounded scaling. CPU throttled (the default) charges only for CPU time used while processing requests, so the idle warm instance costs nothing for CPU, making this configuration both cost-effective and responsive to unpredictable traffic spikes.

Why this answer

Cloud Run supports up to 8 GB memory per container (as of 2024). Setting min-instances to a small number (e.g., 1) reduces cold starts, while max-instances limits costs during spikes. CPU boost can also speed up cold starts.

Using CPU always allocated increases costs, so CPU throttled (default) is fine. The question emphasizes cost minimization, so setting a minimal min-instances is appropriate.

2
MCQmedium

A company wants to set up a hybrid network between their on-premises data center and Google Cloud. They need a highly available VPN connection with 99.99% SLA. Which VPN solution should they choose?

A.Classic VPN
B.HA VPN
C.Cloud Interconnect
D.Cloud NAT
AnswerB

HA VPN uses two external IP addresses and two tunnels to the same on-premises peer, and when paired with two on-premises VPN gateways, it achieves a 99.99% SLA. It relies on BGP to automatically fail over if one tunnel or gateway becomes unavailable, providing true high availability and making it the correct choice here.

Why this answer

HA VPN is the only Google Cloud VPN solution that provides a 99.99% availability SLA when configured with two or more tunnels across two interfaces. It uses two or more external IP addresses on the Cloud VPN gateway, and each tunnel connects to a separate on-premises peer, enabling active-active or active-passive redundancy. Classic VPN offers only 99.9% SLA and does not support the same high-availability topology.

Exam trap

ACE often tests the misconception that any HA VPN configuration automatically grants 99.99% SLA, but the SLA depends on using two interfaces and two tunnels; a single-interface HA VPN only provides 99.9%.

How to eliminate wrong answers

Option A is wrong because Classic VPN provides a 99.9% SLA and uses a single external IP address, so it cannot achieve 99.99% availability. Option C is wrong because Cloud Interconnect is a dedicated private connection, not a VPN, and while it offers high availability, it is not a VPN solution and typically has a different SLA (99.9% or 99.99% depending on configuration). Option D is wrong because Cloud NAT is a service for outbound internet access from private instances, not a site-to-site VPN.

3
MCQeasy

A company wants to run a stateless containerized web application that scales to zero when not in use. The application receives HTTP requests and must be billed only for the resources consumed during request processing. Which Google Cloud compute service is most appropriate?

A.Google Kubernetes Engine (GKE) Standard
B.Cloud Run
C.Cloud Functions
D.Compute Engine
AnswerB

Cloud Run is correct because it runs stateless container images on a fully managed, serverless platform that scales automatically from zero to thousands of instances based on HTTP traffic. You only pay for requests while the container is processing, and you don't manage servers or clusters, so a stateless containerized web application can be deployed with a single command.

Why this answer

Cloud Run is a serverless container platform that scales to zero and charges per request, CPU, and memory used during request processing. It is ideal for stateless HTTP-triggered workloads.

4
MCQmedium

A company is migrating a legacy monolithic application to Google Cloud. The application has unpredictable traffic patterns and long-running connections. The team wants to minimize operational overhead and only pay for resources when the application is processing requests. Which compute option should they choose?

A.Google Kubernetes Engine (GKE) Autopilot cluster
B.Compute Engine with managed instance groups and autoscaling
C.Google Kubernetes Engine (GKE) Standard cluster with node autoscaling
D.Cloud Run
AnswerD

Cloud Run runs stateless containers in a fully managed environment that scales from zero to the number of concurrent requests and bills only for the CPU, memory, and requests consumed during a request. There is no infrastructure to provision, no idle capacity to pay for, and the platform enforces a request deadline, making it ideal for an HTTP-driven legacy application with unpredictable traffic. Its per-request billing and automatic scaling mean you pay nothing when the service is not being called.

Why this answer

Cloud Run is a fully managed serverless container platform that scales to zero when idle and bills only for actual request processing time (down to 100ms granularity). It handles unpredictable traffic and long-running HTTP/gRPC connections natively, with no cluster or node management. This matches the requirements of minimal operational overhead and pay-per-use.

Exam trap

The trap is assuming Kubernetes (GKE) is always the answer for 'containers on Google Cloud' — but the question's keywords 'minimize operational overhead' and 'only pay when processing requests' point specifically to serverless Cloud Run, not GKE.

How to eliminate wrong answers

Option A is wrong because GKE Autopilot still runs a Kubernetes cluster with nodes (managed by Google) and bills for provisioned pod resources, not purely per-request — it does not scale to zero and incurs baseline cost. Option B is wrong because Compute Engine with MIGs requires managing VMs, images, and autoscaling policies, and VMs bill per-second while running, not per-request. Option C is wrong because GKE Standard requires the team to manage node pools, upgrades, and scaling — the opposite of minimal operational overhead — and also does not scale to zero.

5
MCQeasy

An organization needs a NoSQL document database with real-time synchronization across multiple client devices. Which Google Cloud service should they use?

A.Firestore
B.Cloud SQL
C.Cloud Bigtable
D.Cloud Datastore
AnswerA

Firestore is a fully managed NoSQL document database that stores data in documents organized into collections. It provides built-in real-time synchronization through client-side listeners, automatically pushing updates to subscribed apps whenever data changes, making it ideal for live, collaborative applications. It also includes offline support and strong consistency, which are key differentiators for real-time use cases.

Why this answer

Firestore is a NoSQL document database with real-time synchronization across client devices, making it ideal for mobile and web apps that need live updates. It provides SDKs for offline support and automatic data sync.

Exam trap

ACE often tests the distinction between Firestore and Cloud Datastore; candidates may choose Datastore, but Firestore is the service with real-time synchronization and is the modern replacement.

How to eliminate wrong answers

Option B is wrong because Cloud SQL is a managed relational database (MySQL, PostgreSQL, SQL Server) and does not provide real-time sync across clients. Option C is wrong because Cloud Bigtable is a wide-column NoSQL database optimized for large analytical workloads, not real-time client synchronization. Option D is wrong because Cloud Datastore is the older NoSQL datastore; while it is a document database, it lacks the real-time synchronization features of Firestore, and Firestore is the recommended successor.

6
MCQeasy

A user wants to estimate the monthly cost of running a Compute Engine VM with 8 vCPUs, 32 GB of memory, and a 100 GB persistent disk in us-central1 for one year. They plan to use the VM 24/7. Which tool should they use?

A.Google Cloud Pricing Calculator
B.Cloud Asset Inventory
C.Cloud Billing reports
D.Cloud Monitoring
AnswerA

The Google Cloud Pricing Calculator is the correct tool for estimating monthly costs before deployment. You can select specific Google Cloud products and configure parameters such as region, VM machine type, RAM, storage class, and committed usage discounts to generate a projected total. It accepts hypothetical inputs and even provides a machine configurator for GKE and Compute Engine, producing a line-itemized estimate suitable for budgeting and capacity planning.

Why this answer

The Google Cloud Pricing Calculator is the official tool for estimating future costs of GCP resources before deployment. It lets you configure VM machine type, region, disk size, and committed-use or sustained-use discounts to produce a monthly and yearly estimate. Cloud Billing reports, by contrast, show historical actual spend, not projections.

Exam trap

ACE often tests the confusion between cost estimation (Pricing Calculator) and cost analysis (Billing reports), causing candidates to pick Billing reports for a forward-looking estimate.

How to eliminate wrong answers

Option B is wrong because Cloud Asset Inventory is a metadata inventory service for listing and monitoring resources, not a cost estimation tool. Option C is wrong because Cloud Billing reports display past and current charges from actual usage, not forward-looking estimates for a hypothetical VM. Option D is wrong because Cloud Monitoring collects metrics, logs, and uptime data, and has no cost estimation capability.

7
MCQeasy

A company wants to run a stateful application that requires persistent storage on individual VMs. The VMs are not part of a managed instance group. Which Google Cloud storage option is best for this use case?

A.Local SSD
B.Cloud Storage
C.Filestore
D.Persistent Disk
AnswerD

Persistent Disk provides durable, block-level storage that behaves like a physical disk attached to your VM. It survives VM stops and deletions, supports snapshots, and offers zonal or regional redundancy for high availability. With performance tiers like pd-standard, pd-balanced, and pd-ssd, Persistent Disk directly meets the persistence and I/O requirements of a stateful application.

Why this answer

Persistent disks are durable block storage that can be attached to a single VM and persist independently of the VM lifecycle. Cloud Storage is object storage; Filestore is file storage; local SSDs are ephemeral and lose data on VM stop/termination.

8
MCQmedium

A DevOps engineer is using the Google Cloud Pricing Calculator to estimate the monthly cost of a Compute Engine VM running 24/7 for one month. The engineer selects a machine type and adds sustained use discounts. What is the correct way to apply sustained use discounts in the calculator?

A.Manually enter a discount percentage
B.The calculator automatically applies sustained use discounts based on monthly usage
C.Select 'Sustained Use Discount' checkbox
D.Sustained use discounts are not applicable to Compute Engine
AnswerB

When you configure Compute Engine resources in the Google Cloud Pricing Calculator, the tool estimates the monthly run time for each VM and automatically applies the applicable sustained use discount. SUD tiers are calculated without any user action: resources running more than 25% of the month receive a discount that increases incrementally until reaching a maximum of 20% off for the portion of the month after a full month of usage. This auto-application makes the estimate reflect actual billing.

Why this answer

Sustained use discounts are automatically applied by Google Cloud based on the number of hours a VM runs per month. The calculator includes them automatically when you specify the monthly usage.

9
MCQeasy

An engineer needs to create a Cloud Storage bucket for storing archival data that will be accessed less than once a year. The data must be stored durably and cost-effectively. Which storage class should the engineer use?

A.Coldline
B.Standard
C.Archive
D.Nearline
AnswerC

Archive is correct because it is the only Google Cloud storage class specifically designed for data accessed less than once a year, offering the lowest storage cost. It is ideal for long-term retention, regulatory archives, or disaster recovery backups, with the trade-off of higher retrieval fees and a 365-day minimum storage duration before deletion or class change.

Why this answer

Archive is the correct choice because it is Google Cloud's lowest-cost storage class, designed for data accessed less than once per year. It offers the same 99.999999999% (11 nines) durability as other Cloud Storage classes, so the archival data remains highly durable. Its retrieval costs and minimum storage duration (365 days) align with the infrequent access pattern, making it the most cost-effective option for this use case.

Exam trap

ACE often tests the confusion between storage classes based on access frequency, where candidates might pick Coldline or Nearline because they are also 'cold' options, but the key differentiator is the specific access frequency (less than once a year) and the 365-day minimum duration of Archive.

How to eliminate wrong answers

Option A is wrong because Coldline is intended for data accessed less than once per quarter (90-day minimum storage duration), so it is more expensive than Archive for data accessed less than once a year. Option B is wrong because Standard is optimized for frequently accessed data and has the highest storage cost, making it unsuitable for archival data. Option D is wrong because Nearline is designed for data accessed less than once per month (30-day minimum storage duration), which is far more frequent than the stated access pattern and thus not cost-effective.

10
MCQmedium

A company needs to provide outbound internet access to private Compute Engine instances that do not have external IP addresses. The instances must be able to download updates from the internet. Which service should be configured?

A.VPC peering
B.Cloud VPN
C.Cloud NAT
D.Private Google Access
AnswerC

Cloud NAT is a managed source network address translation service that enables instances without external IP addresses to make outbound connections to the internet while allowing only corresponding return traffic. It works with Cloud Router to automatically configure NAT for a VPC network and supports mapping of private IPs to a set of external IP addresses, making it the correct solution for this requirement.

Why this answer

Cloud NAT enables private instances to access the internet for outbound connections while blocking inbound connections from the internet.

11
MCQmedium

An organization stores sensitive data in Cloud Storage. They need to ensure that objects are encrypted at rest using a key that they manage and rotate themselves. Which Cloud Storage encryption option should they use?

A.Use customer-supplied encryption keys (CSEK)
B.Use customer-managed encryption keys (CMEK)
C.Use client-side encryption
D.Use Google-managed encryption keys
AnswerB

CMEK lets you create and manage encryption keys in Cloud KMS, and Cloud Storage uses them to encrypt your objects server-side. You control the key lifecycle, including automatic rotation periods, and can grant or revoke access through IAM identities and conditions. This provides a central audit trail and the ability to disable or destroy keys instantly, which is exactly what the organization needs for sensitive data.

Why this answer

Customer-managed encryption keys (CMEK) in Cloud Storage let the customer create, manage, and rotate keys via Cloud KMS while Google handles the actual encryption and decryption of objects at rest. This satisfies the requirement for customer-controlled key management and rotation without the customer handling raw key material directly.

Exam trap

ACE often tests the distinction between CMEK (Google performs encryption, customer manages keys in KMS) and CSEK (customer supplies raw keys per request), causing candidates to pick CSEK when rotation and KMS integration are required.

How to eliminate wrong answers

Option A is wrong because CSEKs are supplied by the customer on each request and are not stored by Google, so rotation and lifecycle management are entirely the customer's burden and not integrated with Cloud KMS. Option C is wrong because client-side encryption means data is encrypted before it reaches Google, which changes the trust model and is not the Cloud Storage at-rest encryption option being asked about. Option D is wrong because Google-managed keys are fully controlled by Google, giving the customer no control over rotation or lifecycle.

12
MCQeasy

A developer needs to run a one-time SQL query against a large dataset stored in Cloud Storage in Parquet format. The query result will be used for ad-hoc analysis. They want to minimize cost and avoid provisioning any servers. Which service should they use?

A.Cloud SQL import
B.Dataproc cluster
C.BigQuery external table query
D.Compute Engine with Apache Spark installed
AnswerC

BigQuery external tables query Parquet data directly in Cloud Storage without loading or provisioning servers, so you pay only for the query bytes processed. This satisfies the one-time, ad-hoc, serverless and cost-minimising constraints, unlike loading into native tables or running Dataproc clusters.

Why this answer

BigQuery external table query allows you to query data stored in Cloud Storage (including Parquet) directly without loading it, using BigQuery's serverless infrastructure. This minimizes cost because you only pay for the data scanned by the query, and you avoid provisioning any servers. It is ideal for one-time ad-hoc analysis of large datasets.

Exam trap

Google Cloud often tests the distinction between serverless query services (BigQuery) and managed compute services (Dataproc, Compute Engine), where candidates mistakenly choose Dataproc thinking it is 'serverless' because it can be ephemeral, but it still requires provisioning VMs.

How to eliminate wrong answers

Option A is wrong because Cloud SQL import is designed for importing data into a relational database (MySQL, PostgreSQL, SQL Server) from a file, not for querying Parquet files in Cloud Storage directly, and it requires a running Cloud SQL instance (provisioned server). Option B is wrong because Dataproc clusters require provisioning and managing virtual machines (even if ephemeral), incurring compute costs for the cluster lifetime, and are not serverless; they are overkill for a one-time query. Option D is wrong because Compute Engine with Apache Spark installed requires provisioning a virtual machine, installing software, and managing the environment, which violates the 'avoid provisioning any servers' requirement and incurs costs even when idle.

13
MCQmedium

An organization has a VPC with private instances that need outbound internet access for software updates. The instances have no external IP addresses. Which Google Cloud service should be configured?

A.VPC firewall rules
B.Cloud NAT
C.Cloud Load Balancing
D.Cloud VPN
AnswerB

Cloud NAT provides outbound internet connectivity for private instances lacking external IP addresses, translating their internal addresses to a shared external one. It satisfies the stem's constraint of no external IPs while enabling software update downloads without inbound exposure.

Why this answer

To enable outbound internet access for private VM instances that have no external IP addresses, you configure Cloud NAT. Cloud NAT uses a NAT gateway to provide source network address translation (SNAT) so that instances can reach the internet for updates while remaining unreachable from the internet.

14
Multi-Selectmedium

A company has a Compute Engine instance that needs to access the internet for software updates, but the instance only has an internal IP address. Which TWO steps are required to enable outbound internet connectivity while keeping the instance private?

Select 2 answers
A.Create a VPC peering connection to a network with internet access
B.Create a firewall rule that allows egress traffic to the internet
C.Create a Cloud NAT gateway in the same region and VPC as the instance
D.Attach the instance to a load balancer
E.Assign a public IP address to the instance
AnswersB, C

A firewall rule that allows egress traffic to the internet is mandatory for any outbound connectivity, even when Cloud NAT is used. Cloud NAT only translates the source IP, but the VPC firewall still evaluates all traffic and drops it unless a rule permits traffic to destination 0.0.0.0/0 with a source tag or service account you apply to the instance. Without an egress allow rule, the NAT translation never gets the chance to send packets, because the firewall is applied before the packet leaves the instance's VPC network.

Why this answer

Cloud NAT allows instances with only internal IP addresses to access the internet for outbound connections. You also need to configure firewall rules to allow egress traffic (e.g., allow HTTP/HTTPS). A NAT gateway without firewall rules will not work.

15
MCQmedium

A company is planning a lift-and-shift migration of an on-premises monolithic application to Google Cloud. The application runs on a single server and requires a specific kernel module that is not supported by Google Cloud's container-optimized OS. Which compute service should they use?

A.Compute Engine
B.Google Kubernetes Engine (GKE)
C.Cloud Run
D.Cloud Functions
AnswerA

Compute Engine is the correct choice because it provides unmodified, full control over the virtual machine, including the guest OS kernel. You can install custom kernel modules, load them via modprobe, and configure kernel parameters exactly as required by the legacy monolithic application. This is essential for a lift-and-shift migration where the application depends on specific low-level OS features or hardware drivers that cannot be abstracted away by a managed platform.

Why this answer

Compute Engine offers full control over the VM, including choice of OS and kernel modules. GKE and Cloud Run use container-optimized OS, and Cloud Functions is serverless and unsuitable for a monolithic app.

16
Multi-Selecthard

A company wants to migrate a large on-premises MySQL database to Cloud SQL with minimal downtime. Which TWO steps should they take?

Select 2 answers
A.Set up a Cloud VPN connection between on-premises and Google Cloud
B.Use Database Migration Service (DMS) with continuous replication
C.Configure a read replica on-premises and promote it in Google Cloud
D.Use gcloud sql import command for the final migration
E.Export the database to a SQL dump file and import it to Cloud SQL
AnswersA, B

A Cloud VPN tunnel is a prerequisite, not an alternative to DMS: Database Migration Service connects to your on-premises MySQL over a private IP address, and the VPN provides the secure, encrypted network path across the public internet. Without this connectivity, DMS cannot establish the replication channel needed for continuous sync. High-bandwidth, low-latency Interconnect is the alternative when VPN bandwidth is insufficient.

Why this answer

Database Migration Service (DMS) can migrate with minimal downtime using CDC. For the final cutover, a brief write-stop is required to ensure consistency.

17
Multi-Selecthard

A company needs to store and analyze large amounts of log data (hundreds of terabytes) with occasional SQL queries. The data is rarely accessed after 30 days and must be kept for compliance for 7 years. They want to minimize storage costs. Which three actions should they take? (Choose THREE.)

Select 3 answers
A.Use Cloud Storage Object Lifecycle Management to move objects to Nearline after 30 days, then to Coldline after 90 days, then to Archive after 1 year
B.Store the data in BigQuery and use clustering on frequently filtered columns
C.Export older partitions from BigQuery to Cloud Storage and delete them from BigQuery after 30 days
D.Store the data in BigQuery and set an expiration on the table to delete data after 30 days
E.Use BigQuery partitions based on ingestion time and set partition expiration to 30 days
AnswersA, B, C

Cloud Storage Object Lifecycle Management lets you define age-based rules that automatically transition objects from Standard to Nearline after 30 days, to Coldline after 90 days, and to Archive after 365 days. This reduces storage costs progressively while still making the logs retrievable for the required 7-year compliance window. Because objects remain in the bucket throughout, no data is deleted, and Archive class is specifically designed for long-term retention with the lowest per-GB cost.

Why this answer

BigQuery is ideal for log analysis. For historical data, moving older data to lower-cost storage classes like NEARLINE or COLDLINE reduces cost. Partitioning and clustering improve query performance and reduce costs.

Cloud Storage is an alternative, but BigQuery is better for SQL queries.

18
MCQmedium

A company has a private VPC with instances that have only internal IP addresses. These instances need to download updates from the internet. Which Google Cloud service should they use to provide outbound internet connectivity?

A.Cloud NAT
B.Cloud VPN
C.Assign public IP addresses to the instances
D.Identity-Aware Proxy (IAP)
AnswerA

Cloud NAT uses a Cloud Router to provide a managed Network Address Translation service that gives private instances (those with internal IPs only) a secure path to the internet for outbound connections. It maintains stateful sessions so return traffic is allowed, but unsolicited inbound connections are blocked, preserving the private nature of the network.

Why this answer

Cloud NAT (Network Address Translation) allows instances with only internal IP addresses to initiate outbound connections to the internet without exposing them to inbound traffic. It performs many-to-one IP translation and is the Google-recommended service for egress-only internet access from private VPC subnets.

Exam trap

The trap is thinking 'internet access requires a public IP'; GCP's design separates egress (Cloud NAT) from ingress (load balancers/public IPs), and candidates often pick the public IP option.

How to eliminate wrong answers

Option B is wrong because Cloud VPN provides encrypted connectivity between on-premises networks and GCP, not outbound internet access for private instances. Option C is wrong because assigning public IPs exposes instances to inbound internet traffic and defeats the purpose of keeping them private; it also doesn't scale well. Option D is wrong because Identity-Aware Proxy (IAP) is for secure access to internal applications (e.g., SSH/RDP via TCP forwarding), not for general outbound internet downloads.

19
MCQhard

A company is running a stateful application on a Compute Engine instance with a 200 GB persistent disk. They want to reduce costs by moving the disk to a lower-cost storage class, but the disk is currently in use. They plan to take a snapshot of the disk and create a new disk from the snapshot with the new storage class. However, they need minimal downtime. What is the correct approach?

A.Use the 'gcloud compute disks update' command to change the storage class while the disk is attached to a running VM
B.Create a new disk with the new storage class and use rsync to copy data from the old disk while both are attached to the same VM
C.Take a snapshot of the disk, create a new disk from the snapshot with the new storage class, then detach the old disk and attach the new disk to the same VM
D.Stop the VM, take a snapshot, create a new disk with the new storage class, and start the VM with the new disk
AnswerC

Take a snapshot of the disk while the VM is running to obtain a crash-consistent image of the filesystem; persistent disk snapshots are computed online and do not require stopping the instance. From that snapshot, create a new persistent disk with the desired storage class (for example, pd-balanced or pd-ssd). Then unmount the old disk, detach it from the VM, attach the newly created disk, and remount it at the same mount point; this limits downtime to the brief unmount/detach/attach/remount window rather than the entire snapshot and disk creation time.

Why this answer

To change the storage class of a persistent disk, you cannot directly change it; you must create a new disk from a snapshot. To minimize downtime, you can create a snapshot while the VM is running (crash-consistent if on a live instance), then create a new disk with the desired storage class, stop the VM, detach the old disk, attach the new disk, and start the VM. This results in a brief downtime but is the standard method.

20
MCQhard

An engineer is designing a VPC for a multi-tier application. The application has web servers that need direct internet access, and a private database tier that must not have public IP addresses. The database tier needs outbound internet access to download updates. Which network configuration should the engineer implement?

A.Place web servers in a subnet with Cloud NAT, and database servers in the same subnet without public IP
B.Place web servers in a subnet with public IPs, and database servers in a separate subnet with Cloud NAT and no public IP
C.Place both tiers in the same subnet with no public IPs and use Cloud NAT for all outbound traffic
D.Place web servers in a subnet with Cloud NAT, and database servers in a subnet with public IPs and firewall rules to restrict inbound
AnswerB

This is the recommended design because web servers get public IPs (or are behind an external load balancer) to accept inbound user connections, while database servers remain in a separate private subnet with no public IP, preventing direct internet access. Cloud NAT on the database subnet allows outbound internet requests for updates or external APIs without exposing the database to inbound traffic. Separate subnets also enable granular VPC firewall rules and routing policies between tiers, reducing the blast radius if the web tier is compromised.

Why this answer

The correct design places web servers in a public subnet with public IPs (or an internet gateway) for direct inbound access, and database servers in a private subnet with no public IPs but with Cloud NAT for outbound-only internet access. This satisfies both requirements: web servers are reachable from the internet, and database servers can download updates without being publicly addressable.

Exam trap

ACE often tests the misconception that Cloud NAT can provide inbound internet access, causing candidates to place web servers behind NAT instead of in a public subnet.

How to eliminate wrong answers

Option A is wrong because placing web servers behind Cloud NAT prevents inbound internet access — Cloud NAT is for outbound-only traffic, so web servers would not be reachable. Option C is wrong because placing both tiers in a subnet with no public IPs and using Cloud NAT for all outbound traffic means web servers cannot receive inbound connections from the internet. Option D is wrong because assigning public IPs to database servers violates the requirement that they must not have public IP addresses, even if firewall rules restrict inbound.

21
Multi-Selectmedium

A company is migrating a legacy monolithic application to Google Cloud. The application consists of a web frontend, a business logic layer, and a MySQL database. They want to minimise operational overhead and use managed services where possible. Which two services should they choose? (Choose TWO.)

Select 2 answers
A.Cloud Functions for the business logic
B.Cloud SQL for MySQL to host the database
C.Cloud Run for the frontend and business logic
D.Compute Engine to host the frontend and business logic
E.Cloud Spanner for the database
AnswersB, C

Cloud SQL for MySQL is a fully managed relational database service that provides automated backups, patching, replication, and high availability without requiring you to run MySQL yourself. It is a direct drop-in replacement for an existing MySQL database, preserving compatibility while eliminating the administrative burden of managing database infrastructure. This aligns with the migration goal of reducing operational overhead.

Why this answer

Cloud SQL for MySQL (option B) is correct because it is a fully managed relational database service that supports MySQL, letting the company lift and shift its existing MySQL database with minimal code changes while offloading patching, backups, and replication to Google. Cloud Run (option C) is correct because it is a fully managed serverless container platform that can host both the web frontend and the business logic layer as containerized services, scaling automatically and requiring no server or cluster management, which directly minimizes operational overhead. Cloud Functions (option A) is not suitable because it is an event-driven FaaS environment best for short, single-purpose functions rather than a full business logic layer of a monolithic application.

Compute Engine (option D) is incorrect because managing VMs still requires significant operational effort (OS patching, scaling, capacity), contradicting the goal of minimizing overhead. Cloud Spanner (option E) is incorrect because it is a globally distributed, horizontally scalable database that is overkill and requires schema/application changes, whereas the existing MySQL workload maps directly to Cloud SQL.

Exam trap

ACE often tests the misconception that serverless functions like Cloud Functions can replace any application tier, but they are limited to event-driven, short-lived tasks and cannot host a full business logic layer.

22
MCQmedium

A company wants to run a batch job that processes files from a Cloud Storage bucket and writes results to BigQuery. The job runs once daily and can take up to 30 minutes. Which compute option is the most cost-effective and requires the least operational overhead?

A.GKE Autopilot cluster
B.Cloud Functions (2nd gen)
C.Cloud Run jobs
D.Compute Engine with a preemptible VM
AnswerC

Cloud Run jobs directly execute a containerized batch process to completion, scaling to zero immediately after the job finishes, so you pay only for the duration of execution (per-second billing). It supports long-running jobs (up to 24 hours), can be scheduled via Cloud Scheduler, and provides automatic retries, environment configuration, and VPC connectivity without managing servers or clusters. This makes it the most operationally simple and cost-effective option for a daily 30-minute file processing job.

Why this answer

Cloud Run jobs is designed for containerized batch workloads that run to completion, scaling to zero when idle, so you pay only for the compute consumed during the 30-minute daily run. It requires no cluster management, no VM provisioning, and no function-level timeout concerns, giving the lowest operational overhead and cost for a once-daily batch.

Exam trap

ACE often tests the distinction between serverless compute options, and candidates mistakenly choose Cloud Functions for any event-driven or scheduled task without considering execution duration limits and batch-oriented design.

How to eliminate wrong answers

Option A is wrong because GKE Autopilot still requires cluster configuration, node pool management, and ongoing Kubernetes operational overhead that is unnecessary for a simple daily batch job. Option B is wrong because Cloud Functions (2nd gen) is event-driven and has execution time limits (up to 60 minutes for 2nd gen but designed for short-lived functions), making it a poor fit for a 30-minute batch file-processing job and lacking native batch job semantics. Option D is wrong because Compute Engine with a preemptible VM requires manual provisioning, OS patching, and job orchestration, and preemptible VMs can be terminated at any time, risking job failure.

23
MCQmedium

A developer is using Cloud Functions (Gen 2) which is based on Cloud Run. They need to handle events from Cloud Storage when a new object is uploaded. Which event type should they use?

A.google.cloud.storage.object.v1.metadataUpdated
B.google.cloud.storage.object.v1.finalized
C.google.cloud.storage.object.v1.deleted
D.google.cloud.storage.object.v1.archived
AnswerB

google.cloud.storage.object.v1.finalized is the correct Eventarc event type for Cloud Functions (2nd gen) that corresponds to a new object being uploaded or an existing object being overwritten in Cloud Storage. It is the standard event for processing a newly created object, matching the legacy 'object finalized' event but now delivered through Eventarc for 2nd gen functions.

Why this answer

In Cloud Functions Gen 2, the event type for Cloud Storage object finalization is 'google.cloud.storage.object.v1.finalized'.

24
MCQmedium

A company needs to store petabytes of time-series IoT sensor data and query it with single-digit millisecond latency at millions of reads per second. The data has a simple key-value structure with timestamps. Which Google Cloud database is MOST appropriate?

A.Cloud Bigtable
B.BigQuery
C.Firestore
D.Cloud Spanner
AnswerA

Cloud Bigtable is a sparse, wide-column NoSQL store engineered for petabyte-scale time-series workloads, delivering consistent single-digit millisecond latency and linear horizontal scaling to millions of reads per second. Its row-key design suits the simple key-value timestamp structure, satisfying the stem's throughput and latency constraints.

Why this answer

Cloud Bigtable is a fully managed, high-performance NoSQL wide-column database designed for massive analytical and operational workloads. It excels at storing petabytes of data and delivering single-digit millisecond latency for high-throughput reads/writes (millions of ops/sec) when using row-key based access. Its sparse table design and automatic sharding make it ideal for time-series IoT data where the row key can incorporate a timestamp for efficient range scans.

Exam trap

ACE often tests the distinction between Bigtable and BigQuery for time-series data: candidates may choose BigQuery for its scalability, but BigQuery is not designed for single-digit millisecond latency at millions of reads per second; Bigtable is the correct choice for high-throughput, low-latency key-value access.

How to eliminate wrong answers

Option B is wrong because BigQuery is a serverless data warehouse optimized for analytical queries over large datasets, not for low-latency point reads at millions of reads per second; it typically returns results in seconds, not milliseconds. Option C is wrong because Firestore is a document database with strong consistency and real-time sync, but it scales to millions of concurrent connections and offers millisecond latency only for small documents; it is not designed for petabyte-scale time-series data and high-throughput reads. Option D is wrong because Cloud Spanner is a globally distributed relational database with strong consistency and horizontal scaling, but it is not optimized for time-series key-value workloads; it provides millisecond latency but at a higher cost and with less efficient storage for massive time-series data compared to Bigtable.

25
MCQeasy

Which Google Cloud service is a fully managed, serverless data warehouse for analytics at petabyte scale, with built-in machine learning capabilities and automatic scaling?

A.Cloud Storage
B.Dataproc
C.Cloud SQL
D.BigQuery
AnswerD

BigQuery is the correct answer because it is a fully managed, serverless data warehouse designed for petabyte-scale analytics using standard SQL. It automatically handles infrastructure provisioning, scaling, and high availability, with a columnar storage format and a powerful distributed query engine (Dremel). BigQuery also includes built-in features like BigQuery ML for in-database machine learning, partitioning/clustering for performance, and a pay-per-query pricing model, making it a true serverless data warehouse rather than a provisioning-based service.

Why this answer

BigQuery is Google Cloud's fully managed, serverless data warehouse designed for petabyte-scale analytics. It offers built-in machine learning through BigQuery ML and automatically scales compute and storage resources without manual intervention. This makes it the correct choice for analytics at scale with ML capabilities.

Exam trap

ACE often tests the confusion between data warehousing (BigQuery) and data processing (Dataproc) or relational databases (Cloud SQL), so candidates must distinguish serverless analytics from other data services.

How to eliminate wrong answers

Option A is wrong because Cloud Storage is an object storage service, not a data warehouse; it lacks querying and analytics capabilities. Option B is wrong because Dataproc is a managed Hadoop/Spark service for big data processing, not a serverless data warehouse with built-in ML. Option C is wrong because Cloud SQL is a managed relational database service for transactional workloads, not designed for petabyte-scale analytics.

26
MCQmedium

A company is migrating a legacy monolithic application to Google Cloud. The application requires persistent storage and must be highly available with automatic failover across zones. The workload has a moderate number of reads and writes. Which storage solution meets these requirements?

A.Compute Engine persistent disk attached to a VM in a managed instance group
B.Cloud Storage with object versioning
C.Cloud SQL with a regional (HA) configuration
D.Cloud Spanner
AnswerC

Cloud SQL with a regional (HA) configuration is the correct choice because it provides a fully managed relational database with automatic failover to a standby instance in a different zone within the same region. Data is synchronously replicated to the standby, so if the primary zone experiences an outage, Google Cloud promotes the standby with minimal disruption and no manual intervention. This gives the legacy monolithic application the ACID transactions, relational queries, and high availability it needs, at a cost and complexity level appropriate for moderate workloads.

Why this answer

Cloud SQL with a regional (HA) configuration provides a managed relational database with a primary instance in one zone and a standby in another, with automatic failover if the primary fails. It offers persistent storage, cross-zone high availability, and is well-suited to moderate read/write workloads typical of a migrated monolithic application. This matches the requirement for automatic failover across zones without the operational overhead of self-managed options.

Exam trap

The trap is over-engineering the answer — candidates see 'highly available' and jump to Spanner, but Spanner is for massive global scale, while Cloud SQL regional HA is the right fit for moderate workloads needing zonal failover.

How to eliminate wrong answers

Option A is wrong because a persistent disk attached to a VM in a managed instance group is zonal (or regional PD requires replication setup) and does not provide automatic database-level failover — it is infrastructure-level, not a managed HA database solution. Option B is wrong because Cloud Storage with object versioning is object storage, not a relational database, and does not provide the transactional persistence or failover semantics a legacy monolith requires. Option D is wrong because Cloud Spanner is a globally distributed, horizontally scalable relational database designed for massive scale and high throughput — it is overkill and more expensive for a moderate read/write monolithic workload.

27
MCQeasy

A developer needs to deploy a containerized web application that experiences unpredictable traffic patterns, including long periods of no traffic. They want to minimize costs and only pay for resources when the application is serving requests. Which Google Cloud compute service is most suitable?

A.Cloud Run
B.Google Kubernetes Engine (GKE) Standard
C.Compute Engine with managed instance groups
D.Cloud Functions
AnswerA

Cloud Run scales container instances to zero when no requests arrive, billing only per request and consumed CPU/memory during execution. This satisfies the unpredictable-traffic and pay-only-when-serving constraints, unlike GKE node pools or Compute Engine VMs, which incur cost while idle.

Why this answer

Cloud Run is a serverless container platform that scales to zero when not in use, charging only for resources during request processing.

28
MCQhard

An organization needs to run a batch analytics job daily that processes 500 GB of data stored in Cloud Storage. The job runs for 2 hours each day and can tolerate occasional failures. The team wants to minimize compute costs. Which compute option is most cost-effective?

A.Compute Engine with sole-tenant nodes
B.Compute Engine with preemptible VMs
C.Compute Engine with standard VMs and sustained use discount
D.Compute Engine with committed use discount for 1 year
AnswerB

Preemptible VMs are Compute Engine instances that are up to 80% cheaper than standard VMs and are ideal for fault-tolerant, batch workloads. They can be terminated by Google at any time within their maximum runtime of 24 hours, so the job must be checkpointed or designed to restart gracefully. Since the batch job runs daily and is inherently tolerant of interruption, using preemptible VMs maximizes cost savings without sacrificing correctness, making this the most cost-effective choice.

Why this answer

Preemptible VMs are correct because they cost up to 80% less than standard VMs and are ideal for fault-tolerant batch jobs that can tolerate occasional failures and run for a bounded 2-hour window. The workload's tolerance for interruption and its daily, non-continuous schedule align exactly with the preemptible VM use case, minimizing compute cost.

Exam trap

ACE often tests the distinction between discounts: candidates pick committed use discounts because they sound cheapest, but commitments require steady usage, and only preemptible/spot VMs match interruptible, short-duration batch workloads.

How to eliminate wrong answers

Option A is wrong because sole-tenant nodes are priced at a premium for physical isolation and compliance requirements, not cost optimization. Option C is wrong because standard VMs with sustained use discounts still cost significantly more than preemptible VMs and the discount only applies after substantial monthly usage. Option D is wrong because a 1-year committed use discount requires a continuous commitment and is designed for steady-state workloads, not a 2-hour daily batch job that would waste most of the commitment.

29
MCQmedium

A team needs to deploy a microservice that processes events from Pub/Sub and writes the results to Firestore. The service is stateless and should not incur cost when idle. The expected load is low but can spike unpredictably. Which compute service is the most cost-effective and operationally simple?

A.GKE Standard with a cluster autoscaler and a Pub/Sub sidecar
B.Compute Engine with a managed instance group and autoscaling based on Pub/Sub queue depth
C.Cloud Run for Anthos on-premises
D.Cloud Functions (2nd gen) triggered by Pub/Sub
AnswerD

Cloud Functions (2nd gen) is a fully managed, event-driven compute service that can be triggered directly by Pub/Sub messages via Eventarc. It scales automatically from zero to thousands of concurrent invocations and bills only for the time your code runs, so there is no idle capacity or cluster infrastructure to manage. This makes it the most cost-effective and operationally simple choice for processing sporadic events.

Why this answer

Cloud Functions (2nd gen) is a fully managed, event-driven serverless compute service that scales to zero when idle and is triggered natively by Pub/Sub. It is stateless by design, requires no cluster or instance management, and charges only for invocations and compute time, making it the most cost-effective and operationally simple choice for low, spiky workloads.

Exam trap

ACE often tests serverless selection by including managed-but-not-serverless options (GKE, MIGs) that sound operationally simple but still incur idle cost, so candidates must verify the 'scale to zero' and 'no cost when idle' requirements.

How to eliminate wrong answers

Option A is wrong because GKE Standard requires managing node pools, cluster upgrades, and a Pub/Sub sidecar, and it does not scale to zero — you pay for nodes even when idle, which violates the 'no cost when idle' requirement. Option B is wrong because a Compute Engine managed instance group still runs VMs (minimum instance count) and requires autoscaling configuration based on queue depth, incurring cost when idle and adding operational complexity. Option C is wrong because Cloud Run for Anthos on-premises runs on your own infrastructure, not in GCP, so it does not meet the serverless, pay-per-use cloud requirement and adds on-prem management overhead.

30
MCQeasy

A developer wants to deploy a containerized web application that receives HTTP requests and can scale to zero when not in use. The application is stateless and has a startup time of less than 2 seconds. Which Google Cloud compute option is the most cost-effective?

A.Compute Engine with managed instance group and autoscaling
B.Google Kubernetes Engine (GKE) Standard
C.App Engine Standard with manual scaling
D.Cloud Run
AnswerD

Cloud Run executes stateless containers on a fully managed platform, where each instance only receives compute billing while actually processing a request and the service can scale down to zero when no traffic arrives. It automatically provisions instances based on concurrency and can start many instances to handle bursts, with optional min instances for latency-sensitive workloads. A containerized web application is an ideal fit because Cloud Run accepts any container image that listens on a port, and integrates directly with Cloud Build and Artifact Registry.

Why this answer

Cloud Run is a fully managed serverless platform that runs stateless containers and automatically scales to zero when there is no traffic, meaning you pay nothing when idle. It natively handles HTTP requests and supports rapid scaling based on incoming requests, making it ideal for a stateless web app with sub-2-second startup. The other options either do not scale to zero or require manual scaling configuration, leading to higher costs for sporadic workloads.

Exam trap

ACE often tests the misconception that any autoscaling solution can scale to zero, but only serverless platforms like Cloud Run and App Engine Standard (with automatic scaling) truly scale to zero; managed instance groups and GKE Standard always maintain a minimum capacity.

How to eliminate wrong answers

Option A is wrong because Compute Engine with a managed instance group and autoscaling does not scale to zero; at least one VM instance must always be running, incurring continuous costs even when idle. Option B is wrong because GKE Standard charges for the control plane (unless on Autopilot, but even then nodes may persist) and typically does not scale to zero by default; it requires managing node pools and cluster infrastructure, adding cost and complexity. Option C is wrong because App Engine Standard with manual scaling requires you to specify the number of instances, which means you cannot scale to zero automatically and will pay for idle instances.

31
MCQmedium

A company has a VPC with custom mode and needs to connect to an on-premises network via HA VPN. They have two on-premises VPN devices, each with a static public IP address. What is the correct way to configure the HA VPN gateway on Google Cloud?

A.Create one classic VPN gateway with two tunnels to the two on-premises devices
B.Create one HA VPN gateway with two interfaces in the same region, and create two tunnels, each connecting one cloud interface to one on-premises device
C.Create two separate VPN gateways, each with one interface, and assign each to a different region
D.Create one HA VPN gateway in one region and one classic VPN gateway in another region
AnswerB

This is the exact HA VPN architecture: one regional HA VPN gateway exposes two external IP addresses (called interfaces) in the same region, and each interface forms its own IPsec tunnel to a different on-premises device. The two tunnels run as an active/active or active/standby pair using BGP dynamic routing, so if one on-premises device or tunnel fails, the Cloud Router can withdraw routes and send traffic through the surviving tunnel. This configuration is required to meet the 99.99% availability SLA for Cloud VPN.

Why this answer

For HA VPN with two on-premises devices, you create one HA VPN gateway with two interfaces in the same region, and then create two tunnels, each connecting one cloud interface to one on-premises device. This provides redundancy and meets the HA requirements.

Exam trap

The trap is assuming that HA VPN requires multiple gateways or that interfaces can be in different regions. Candidates often confuse the HA VPN architecture with other VPN types.

How to eliminate wrong answers

Option A is wrong because Classic VPN does not support HA and has only one interface. Option C is wrong because HA VPN gateway interfaces must be in the same region; creating two gateways in different regions is not the standard HA VPN configuration. Option D is wrong because mixing HA VPN and Classic VPN does not provide the required redundancy and is not a supported HA configuration.

32
MCQhard

A financial services company is designing its Google Cloud landing zone. Auditors require that all resources be created in approved regions only, that no external IP addresses be assignable to Compute Engine instances, and that any new project automatically inherit these restrictions. The security team wants to enforce this centrally without relying on application teams to configure each project correctly. What should the company implement?

A.Deploy a Cloud Asset Inventory feed and a Cloud Function that deletes any resource created outside approved regions or with an external IP.
B.Use IAM deny policies at the organization node to block the compute.instances.create permission for all principals except the security team.
C.Configure a Shared VPC host project and grant the application teams the Compute Network User role on specific subnets in approved regions.
D.Create an organization policy with constraints for resource locations and VM external IP access, and attach it at the organization node so all projects inherit it.
AnswerD

Organization policies applied at the organization node are inherited by every folder and project, so new projects automatically receive the location and external IP restrictions. This central enforcement does not depend on application teams and satisfies the auditor requirement that all resources comply without per-project configuration.

Why this answer

Organization policies are the centralized preventive control that applies at the organization node and is inherited by all current and future projects. Constraints for resource locations and VM external IP access directly encode the auditors' requirements, so no application team can create a noncompliant resource even if they try.

Exam trap

The trap here is treating IAM deny policies or Shared VPC as equivalent to organization policy constraints, when only organization policies can restrict resource locations and external IP assignment across all projects.

33
Multi-Selectmedium

A company is planning to deploy a batch processing workload on Google Cloud. The workload runs for several hours each night, can tolerate interruptions, and must be cost-optimized. The operations team wants to minimize management effort and ensure the workload automatically restarts if a VM is preempted. Which TWO actions should the company take? (Choose two.)

Select 2 answers
A.Create a managed instance group using Spot VMs as the instance template and configure it to automatically recreate instances.
B.Deploy the workload on sole-tenant nodes to guarantee physical isolation from other customers.
C.Configure the workload to run on a single large standard VM with a local SSD for temporary data.
D.Use standard Compute Engine VMs with committed use discounts for a three-year term.
E.Set up a Cloud Scheduler job that starts the batch process on a schedule and stores checkpoints in Cloud Storage.
AnswersA, E

Spot VMs offer deep discounts for interruptible workloads, and a managed instance group with automatic recreation replaces preempted instances so the batch job can resume. This combination matches the tolerance for interruptions, the cost goal, and the requirement to restart automatically with minimal manual effort.

Why this answer

Spot VMs in a managed instance group deliver the required cost savings for interruptible batch work, and automatic recreation keeps the job running after preemption. Adding Cloud Scheduler for nightly starts and Cloud Storage checkpoints makes restarts efficient, so the workload completes with minimal operational effort.

Exam trap

The trap here is assuming that committed use discounts are always the cheapest option, when they only pay off for continuous usage and this workload runs just a few hours per night.

34
MCQhard

A company is migrating a PostgreSQL database to Cloud SQL. They need high availability with automatic failover and a read replica for reporting queries that must not impact the primary. Which Cloud SQL configuration should they choose?

A.High Availability (HA) configuration with automatic storage increase
B.High Availability (HA) configuration with a read replica
C.Single zone instance with a failover replica
D.Single zone instance with cross-region replication
AnswerB

Cloud SQL HA automatically fails over to a synchronous standby in a different zone, protecting against zonal outages. A read replica, created using binary log replication, serves read-only queries like reporting without burdening the primary. Together, these features satisfy both availability and performance needs, allowing the reporting workload to run in parallel with production.

Why this answer

Cloud SQL High Availability (HA) configuration provides a standby instance in a different zone with automatic failover, satisfying the HA requirement. Adding a read replica offloads reporting queries from the primary, ensuring they do not impact production performance. This combination meets both the HA and read-scaling needs.

Exam trap

ACE often tests the misconception that a failover replica is the same as a read replica; candidates must remember that HA provides automatic failover, while read replicas are for scaling reads and do not failover.

How to eliminate wrong answers

Option A is wrong because automatic storage increase addresses storage capacity, not read scaling or reporting isolation. Option C is wrong because a single-zone instance with a failover replica is the legacy HA configuration (now replaced by the regional HA setup) and does not provide a read replica for reporting. Option D is wrong because cross-region replication is for disaster recovery or read scaling across regions, but it does not provide automatic failover within a region and is not the standard HA configuration.

35
MCQmedium

An organization has a VPC with instances in two subnets: subnet-a (10.0.1.0/24) and subnet-b (10.0.2.0/24). They want to allow HTTP traffic from any instance in subnet-a to any instance in subnet-b. What firewall rule should be created?

A.An egress rule on subnet-b allowing traffic to 10.0.1.0/24 on TCP port 80
B.An ingress rule on subnet-a allowing traffic to 10.0.2.0/24 on TCP port 80
C.An ingress rule on subnet-b allowing traffic from 10.0.1.0/24 on TCP port 80
D.An egress rule on subnet-a allowing traffic to 10.0.2.0/24 on TCP port 80
AnswerC

This is correct because the HTTP request travels from an instance in subnet-a (source 10.0.1.0/24) to an instance in subnet-b (destination) on TCP port 80. An ingress rule on subnet-b with the source range set to 10.0.1.0/24 explicitly allows that inbound connection at the destination. In GCP, the destination subnet's ingress rules are the primary gate for allowing traffic to reach the target instance.

Why this answer

Firewall rules are defined with direction and source/target. To allow inbound traffic to subnet-b from subnet-a, an ingress rule with source range 10.0.1.0/24 is needed.

36
MCQeasy

A startup is planning its first Google Cloud deployment for a stateless containerized API. The team has no Kubernetes experience and wants to minimize operational overhead while paying only for resources used during requests. The API must scale automatically, including down to zero when there is no traffic. Which Google Cloud service should they choose?

A.App Engine flexible environment
B.Compute Engine managed instance group with autoscaling
C.Google Kubernetes Engine Autopilot
D.Cloud Run
AnswerD

Cloud Run runs stateless containers in a fully managed serverless environment, scales automatically based on requests, and can scale to zero instances when idle so no cost accrues. It requires no Kubernetes knowledge and bills per request and resource usage, directly matching the startup's operational and cost constraints.

Why this answer

Cloud Run is the serverless container platform that scales to zero and bills only for request handling and resources consumed, with no cluster or VM management. It fits a stateless API that has idle periods and a team without Kubernetes skills, satisfying both the operational and cost requirements.

Exam trap

The trap here is equating reduced node management in GKE Autopilot with full serverless scale-to-zero, when Autopilot still requires a running cluster with baseline cost.

37
Multi-Selecteasy

A company is deploying a web application on Compute Engine and wants to distribute traffic across multiple instances in different zones for high availability. They also need to terminate SSL/TLS at the load balancer. Which TWO services should they use together?

Select 2 answers
A.Managed instance group
B.External HTTP(S) load balancer
C.Cloud CDN
D.Internal TCP/UDP load balancer
E.Cloud NAT
AnswersA, B

A managed instance group (MIG) is the correct backend infrastructure because it maintains a pool of identical VM instances across multiple zones, enabling the HTTP(S) load balancer to distribute traffic and automatically heal failed instances. MIGs support autoscaling based on load, which is essential for a scalable web application, and they provide the instance-level health checking that the load balancer relies on to route requests only to healthy VMs.

Why this answer

Option A, a managed instance group, is correct because it provides the pool of identical Compute Engine instances spread across multiple zones that the load balancer distributes traffic to, and it also enables autohealing and autoscaling for high availability. Option B, an external HTTP(S) load balancer, is correct because it is a global, layer 7 load balancer that spreads client traffic across instances in multiple zones/regions and supports SSL/TLS termination at the load balancer via its target HTTPS proxy and SSL certificates. Option C, Cloud CDN, is not required here because it is a content-caching layer that integrates with the HTTP(S) load balancer but does not itself distribute traffic across instances or terminate SSL/TLS.

Option D, an internal TCP/UDP load balancer, is wrong because it is a regional, layer 4 load balancer for internal traffic and does not terminate SSL/TLS or serve public web traffic. Option E, Cloud NAT, is wrong because it provides outbound internet access for instances without external IPs and has nothing to do with inbound traffic distribution or SSL/TLS termination.

Exam trap

ACE often tests the combination of a managed instance group with an external load balancer for HA and SSL termination, while candidates may incorrectly choose Cloud CDN or internal load balancer for external SSL termination.

38
MCQeasy

A startup wants to run a small, event-driven application that processes files uploaded to Cloud Storage. The function should be triggered by object finalize events and should have a maximum execution time of 10 minutes. Which compute option is most cost-effective and easy to manage?

A.Compute Engine with a startup script
B.App Engine Standard
C.Cloud Run jobs
D.Cloud Functions (Gen 2)
AnswerD

Cloud Functions (Gen 2) is the right choice because it offers first-class event triggers from Cloud Storage through Eventarc, letting you run code directly when an object is finalized or deleted. It is fully serverless, scales automatically from zero, and you only pay for execution time, which is ideal for a small startup. The maximum timeout of 60 minutes comfortably covers the stated 10-minute processing requirement, and the function is invoked automatically without any polling or VM management.

Why this answer

Cloud Functions (Gen 2) is the most cost-effective and easy-to-manage option for event-driven applications triggered by Cloud Storage object finalize events, with a maximum execution time of 10 minutes. It provides serverless execution, automatic scaling, and native integration with Cloud Storage events. Gen 2 offers longer execution times (up to 60 minutes) and improved performance compared to Gen 1.

Exam trap

The trap is overlooking Cloud Functions' native event triggers and selecting other compute options that require more management or are not designed for event-driven workloads.

How to eliminate wrong answers

Option A is wrong because Compute Engine requires managing VMs, configuring triggers, and handling scaling, which is not cost-effective or easy to manage for a small event-driven app. Option B is wrong because App Engine Standard is designed for web applications and does not natively support Cloud Storage event triggers; it would require additional components. Option C is wrong because Cloud Run jobs are designed for batch or long-running containerized tasks, not for event-driven functions triggered by Cloud Storage events; Cloud Run services could be used but require more setup and are less integrated.

39
MCQeasy

A team is building a mobile app backend that requires real-time data synchronization across devices and offline support. The data model is simple and document-based. Which database service should they use?

A.Cloud Bigtable
B.BigQuery
C.Cloud SQL
D.Firestore
AnswerD

Firestore is a flexible, scalable NoSQL document database designed natively for mobile app development, with real-time listeners that push data changes to clients instantly and offline data persistence that automatically syncs when connectivity returns. Its client SDKs for iOS, Android, and web handle multi-device synchronization, conflict resolution, and data integrity out of the box, making it the ideal choice for this real-time mobile backend use case.

Why this answer

Firestore is a NoSQL document database that provides real-time synchronization and offline support for mobile and web applications. It is designed for mobile app backends with simple document-based data models, offering automatic scaling and strong consistency. Firestore's real-time listeners and offline persistence make it ideal for this use case.

Exam trap

ACE often tests the distinction between Firestore and Firebase Realtime Database; candidates might confuse the two, but Firestore is the newer, more scalable option with richer querying and offline support.

How to eliminate wrong answers

Option A is wrong because Cloud Bigtable is a high-performance NoSQL database for large analytical workloads, not for mobile app real-time synchronization; it lacks built-in offline support and real-time features. Option B is wrong because BigQuery is a serverless data warehouse for analytics, not a transactional database for mobile apps. Option C is wrong because Cloud SQL is a relational database that does not natively support real-time synchronization or offline support for mobile apps.

40
MCQhard

An organization needs to deploy a microservices application on Google Kubernetes Engine. Each microservice has different resource requirements, and the team wants to optimize costs by using a mix of spot (preemptible) and regular nodes. They also need to ensure that critical services run on regular nodes. Which GKE feature allows this separation?

A.Use resource quotas to limit namespace resource usage
B.Use separate clusters for critical and non-critical services
C.Use node pools with taints and tolerations on the pods
D.Use vertical pod autoscaling
AnswerC

Create two node pools, e.g. a regular pool for critical services and a spot/preemptible pool for non-critical work, then taint the spot pool with a key such as spot=true:NoSchedule. Critical pods are deployed without the matching toleration, so the Kubernetes scheduler will never place them on spot nodes; non-critical pods include the toleration and can use the cheaper spot capacity. This precisely controls placement while keeping a single cluster and simplifying operations.

Why this answer

Node pools with taints and tolerations allow you to dedicate a pool of regular (non-preemptible) nodes to critical services by applying a taint to those nodes and a matching toleration only to the critical pods. Non-critical pods without the toleration will be scheduled onto spot node pools, achieving both cost optimization and workload separation.

Exam trap

The trap is choosing 'separate clusters' because it sounds like the cleanest separation — but the question asks for a GKE feature that enables separation within a deployment, and taints/tolerations with node pools is the native, cost-effective answer.

How to eliminate wrong answers

Option A is wrong because resource quotas limit aggregate CPU/memory/object counts per namespace — they do not control which node type a pod lands on. Option B is wrong because separate clusters for critical and non-critical services is operationally heavier and does not leverage GKE's native scheduling controls; it also increases management overhead and cost, defeating the optimization goal. Option D is wrong because vertical pod autoscaling adjusts a pod's CPU/memory requests based on usage — it has nothing to do with node selection or spot vs. regular node placement.

41
MCQeasy

An organization wants to run a stateless HTTP-based containerized application that scales to zero when not in use and charges only for request processing time. They do not want to manage any underlying infrastructure. Which compute option should they choose?

A.Compute Engine with managed instance group
B.Cloud Run
C.Cloud Functions
D.Google Kubernetes Engine (GKE) Standard
AnswerB

Cloud Run is the correct choice because it directly runs stateless HTTP container images in a fully managed, serverless environment, scaling from zero to handle traffic and back to zero when idle. You are billed only for compute resources used during request processing, not for paused instances, and it handles TLS, revisions, and autoscaling natively.

Why this answer

Cloud Run is a fully managed serverless platform for containerized HTTP applications that scales to zero when idle and bills only for request processing time (CPU/memory allocated during requests). It requires no infrastructure management and supports any containerized HTTP workload. This matches the requirement exactly.

Exam trap

ACE often tests the distinction between serverless containers (Cloud Run) and serverless functions (Cloud Functions), and whether candidates realize that GKE and MIGs do not scale to zero — pick the option that explicitly bills only for request processing.

How to eliminate wrong answers

Option A is wrong because Compute Engine with a managed instance group requires you to manage VMs, and it does not scale to zero — you pay for instances even when idle. Option C is wrong because Cloud Functions is for event-driven functions, not arbitrary containerized HTTP applications, and it has runtime restrictions. Option D is wrong because GKE Standard requires cluster and node management and does not scale to zero by default (nodes run continuously).

42
Multi-Selectmedium

A company plans to deploy a containerized application on GKE Autopilot. They want to ensure high availability by running multiple replicas across different zones. They also need to expose the application via a load balancer with SSL termination. Which THREE resources should they create?

Select 3 answers
A.Service
B.StatefulSet
C.Ingress
D.ConfigMap
E.Deployment
AnswersA, C, E

A Service provides the stable virtual IP and load-balancing layer that distributes traffic across the application's pods, and it is the resource an Ingress or external load balancer targets for SSL termination, satisfying the exposure requirement in the stem.

Why this answer

A Deployment (E) is the correct workload controller for a stateless containerized application, allowing the company to declare multiple replicas that GKE Autopilot spreads across zones for high availability. A Service (A) is required to provide a stable virtual IP and load-balance traffic to those pod replicas, and on GKE it also provisions the underlying Google Cloud load balancer. An Ingress (C) is needed to expose the application externally and to configure SSL/TLS termination using a managed certificate or a TLS secret, which is exactly the load-balancer-with-SSL requirement.

A StatefulSet (B) is not appropriate because it is designed for stateful workloads needing stable network identities and persistent storage, which this stateless app does not require. A ConfigMap (D) only supplies non-sensitive configuration data and does not provide high availability, load balancing, or SSL termination.

Exam trap

The trap here is selecting StatefulSet instead of Deployment for stateless applications, or forgetting that Ingress is needed for SSL termination and external load balancing, while Service alone may not provide SSL termination.

43
Multi-Selecthard

An organization needs to run a batch analytics job on BigQuery every night that processes terabytes of data. The job is critical and must complete within a specific time window. To optimize costs, they are considering using flat-rate pricing but want to minimize commitment risk. Which THREE factors should they evaluate?

Select 3 answers
A.The number of Cloud Storage buckets used for data staging
B.The cost of on-demand query pricing for the same workload
C.The cost of reserving dedicated hardware for Compute Engine
D.The number of slots needed to complete the job within the required time window
E.The availability of flex slots for short-term capacity needs
AnswersB, D, E

Comparing on-demand query pricing for the identical workload establishes the break-even baseline: if on-demand costs less than the flat-rate commitment, committing wastes money. This directly addresses minimising commitment risk by quantifying whether reserved capacity is justified for the nightly batch job.

Why this answer

The organization should evaluate B, the cost of on-demand query pricing for the same workload, because comparing on-demand BigQuery pricing against flat-rate commitment costs is the baseline needed to determine whether a reservation actually saves money for this nightly terabyte-scale job. They should also evaluate D, the number of slots needed to complete the job within the required time window, since flat-rate capacity is measured in slots and the reservation size must be sufficient to finish the batch analytics within the critical window. They should evaluate E, the availability of flex slots for short-term capacity needs, because flex slots provide a low-commitment, short-duration way to obtain dedicated BigQuery capacity, which directly addresses the goal of minimizing commitment risk.

Options A and C do not belong: the number of Cloud Storage buckets used for staging is irrelevant to BigQuery flat-rate slot commitment decisions, and reserving dedicated Compute Engine hardware is a different compute service and does not address BigQuery slot capacity or pricing.

Exam trap

Google Cloud often tests the misconception that storage infrastructure (like Cloud Storage buckets) or unrelated compute services (like Compute Engine) influence BigQuery pricing decisions, when in fact the focus should be on slot allocation and cost comparison with on-demand pricing.

44
MCQeasy

A company wants to store event logs from multiple applications in a centralized location for future analysis. The logs are written frequently (thousands per second) and need to be retained for 90 days. The data is write-once, read-rarely. Which storage class and lifecycle rule combination is most cost-effective?

A.Set default storage class to Archive and use lifecycle rule to delete after 90 days
B.Set default storage class to Standard and use lifecycle rule to delete after 90 days
C.Set default storage class to Coldline and use lifecycle rule to delete after 90 days
D.Set default storage class to Nearline and use lifecycle rule to delete after 90 days
AnswerC

Coldline storage is designed for data that is expected to be accessed at most once per 90 days, making it a perfect match for a 90-day retention period. The lower per-GiB storage price compared to Standard and Nearline, combined with lifecycle deletion at 90 days, minimizes cost without incurring early deletion fees (Coldline has a 90-day minimum storage duration). This directly satisfies the requirement to store event logs for 90 days and then delete them.

Why this answer

For write-once, read-rarely data, Coldline storage class is cost-effective for data accessed less than once per 90 days. Set a lifecycle rule to delete objects after 90 days. Alternatively, use Standard for the first 30 days then move to Coldline, but the question asks for a combination.

The simplest is to set the default storage class to Coldline and a lifecycle rule to delete at 90 days.

45
MCQhard

A company wants to migrate an on-premises PostgreSQL database to Google Cloud. They need a managed database service with high availability and automatic failover. The application uses many stored procedures and extensions specific to PostgreSQL. Which service should they choose?

A.Cloud Spanner
B.Bare Metal Solution
C.Cloud SQL for PostgreSQL
D.Firestore
AnswerC

Cloud SQL for PostgreSQL is a fully managed, PostgreSQL-compatible database service that supports the same SQL dialect, extensions, and client protocols as standard PostgreSQL. It enables a straightforward migration path for on-premises PostgreSQL databases using tools like Database Migration Service or pg_dump/pg_restore. Cloud SQL also provides automated backups, high availability, and scaling, making it the optimal choice for a direct PostgreSQL migration without application code changes.

Why this answer

Cloud SQL for PostgreSQL supports many PostgreSQL extensions and stored procedures. Cloud Spanner is not PostgreSQL-compatible; Firestore is NoSQL; Bare Metal Solution is for on-premises-like deployments, not managed.

46
Multi-Selecteasy

A developer wants to deploy a new application on Google Cloud. The application consists of a frontend service that serves web traffic and a backend service that processes images. Both services need to be containerized. Which two compute options are serverless and support container deployment? (Choose 2)

Select 2 answers
A.Google Kubernetes Engine (GKE)
B.Cloud Functions (2nd gen)
C.Cloud Run
D.Compute Engine
E.Cloud Functions (1st gen)
AnswersB, C

Cloud Functions (2nd gen) is built on Cloud Run infrastructure and, unlike the 1st gen, supports deploying custom container images directly. It provides a fully managed, event-driven serverless execution environment that scales to zero and brings the same container runtime benefits as Cloud Run, while adding event-triggering capabilities like Pub/Sub, Cloud Storage, and HTTP invocations.

Why this answer

Cloud Run and Cloud Functions (2nd gen) both support container images and are serverless (no server management, scale automatically). GKE and Compute Engine are not serverless. Cloud Functions (1st gen) does not support containers.

47
MCQmedium

A company wants to migrate an on-premises PostgreSQL database to Google Cloud. They require automated backups, point-in-time recovery, and a 99.95% availability SLA. Which service should they choose?

A.Compute Engine with self-managed PostgreSQL
B.Cloud SQL for PostgreSQL
C.Cloud SQL for MySQL
D.Cloud Spanner
AnswerB

Cloud SQL for PostgreSQL is the managed relational database service natively compatible with PostgreSQL, so your existing schema, queries, and tools carry over. It automates daily backups with transaction log-based PITR by default, offers high availability via a regional failover replica, and carries a 99.95% SLA for the Standard and Enterprise editions. This directly satisfies the stated requirements without requiring you to operate the database infrastructure.

Why this answer

Cloud SQL for PostgreSQL is a fully managed database service that supports automated backups, point-in-time recovery (PITR), and offers a 99.95% availability SLA when configured with high availability (HA). It is specifically designed for PostgreSQL workloads, making it the ideal choice for migrating an on-premises PostgreSQL database to Google Cloud while meeting the stated requirements. The service handles routine tasks like patching, replication, and backups, allowing the company to focus on their application.

Exam trap

ACE often tests the distinction between managed and self-managed database services, and candidates may incorrectly assume that Compute Engine with self-managed PostgreSQL can meet the SLA and automation requirements without additional management overhead.

How to eliminate wrong answers

Option A is wrong because Compute Engine with self-managed PostgreSQL requires the company to manually configure and manage backups, PITR, and HA, and does not provide a managed SLA for the database. Option C is wrong because Cloud SQL for MySQL supports a different database engine (MySQL) and cannot run PostgreSQL workloads without migration and compatibility issues. Option D is wrong because Cloud Spanner is a globally distributed, horizontally scalable relational database that is not PostgreSQL-compatible and is overkill for a simple migration; it also does not support PostgreSQL syntax or tools natively.

48
MCQeasy

A data analyst needs to run complex analytical queries on a large dataset (10 TB) stored in Cloud Storage. They want to use a serverless query engine that charges based on the amount of data processed. Which Google Cloud service should they use?

A.Cloud SQL
B.BigQuery
C.Bigtable
D.Dataproc
AnswerB

BigQuery is Google Cloud's serverless, highly scalable data warehouse optimized for analytical queries on massive datasets. It separates storage from compute, uses columnar storage and a distributed query engine, and offers pay-per-query pricing, so you only pay for the data scanned. With features like partitioning, clustering, and BI Engine, it is the ideal choice for complex analytical workloads without managing infrastructure.

Why this answer

BigQuery is Google Cloud's fully managed, serverless data warehouse that supports ANSI SQL analytical queries over petabyte-scale datasets and charges on-demand based on bytes processed. It is designed exactly for the scenario of running complex analytics on large datasets without provisioning infrastructure. Its columnar storage and Dremel engine deliver high-performance queries at scale.

Exam trap

ACE often tests the confusion between serverless analytics (BigQuery) and cluster-based processing (Dataproc) or NoSQL stores (Bigtable), so candidates must match the 'serverless, per-byte pricing, complex SQL' keywords to BigQuery.

How to eliminate wrong answers

Option A is wrong because Cloud SQL is a managed relational database for OLTP workloads and cannot efficiently scan 10 TB analytical datasets. Option C is wrong because Bigtable is a wide-column NoSQL store for low-latency transactional access, not a SQL analytical query engine. Option D is wrong because Dataproc is a managed Hadoop/Spark service that requires provisioning clusters and is not serverless with per-byte query pricing.

49
MCQhard

A team is using BigQuery for analytics. They have a constant query workload and want to reduce costs by switching from on-demand pricing to a flat-rate reservation. They have purchased a BigQuery flat-rate reservation. What additional step is required to use the reservation?

A.Enable flat-rate billing in the BigQuery settings
B.Assign the reservation to the desired projects using an assignment
C.No additional steps; flat-rate is automatically applied to all queries
D.Create a new dataset and move all tables into it
AnswerB

After purchasing a capacity commitment, you must create a reservation and then create an assignment that associates that reservation with specific projects (or folders/organizations). Once the assignment is in place, query jobs issued from those assigned projects consume the reserved slots, and their usage is billed at the flat-rate, on-demand pricing no longer applies.

Why this answer

The reservation must be assigned to a project, folder, or organization via a reservation assignment. Without assignment, the reservation is not used, and queries continue to be billed on-demand.

50
MCQeasy

An engineer needs to deploy a containerized web application that receives HTTP requests and should scale to zero when not in use. The application is stateless and has a lightweight container image. Which Google Cloud compute service should be used?

A.Compute Engine with a single VM
B.Cloud Functions
C.Cloud Run
D.Google Kubernetes Engine (GKE) Standard cluster
AnswerC

Cloud Run is a managed serverless container platform that executes your container image on demand, automatically scaling instances from zero to thousands based on incoming HTTP traffic and billing only for resources used during request processing. It is purpose-built for stateless HTTP workloads and supports common features like health checks, environment variables, secrets, and gRPC, all without requiring you to provision or manage any servers. For a containerized web application, this directly satisfies the requirement with minimal operational effort and can scale to zero when idle.

Why this answer

Cloud Run is a fully managed serverless platform that scales to zero when no requests are coming in, and bills per request. It is ideal for stateless HTTP-triggered container workloads.

51
MCQeasy

An engineer is tasked with creating a new VPC network for a production environment. The company requires the VPC to support multiple regions and allow custom IP address ranges for each subnet. Which VPC network mode should the engineer use?

A.Shared VPC
B.Custom mode VPC
C.Auto mode VPC
D.Legacy mode VPC
AnswerB

Custom mode VPC is the correct choice because it begins with no subnets and lets the engineer explicitly define each subnet's IP CIDR range and region. This provides full control over the address space, including private or publicly routable blocks, to avoid conflicts and meet design requirements. For a task that requires setting custom subnet IP ranges per region, this mode is the only way to do so natively.

Why this answer

Custom mode VPC is correct because it allows the engineer to create subnets with user-defined IP address ranges in each region, giving full control over the network topology. Unlike auto mode, custom mode does not automatically create subnets in every region, so the engineer can tailor subnet placement and CIDR blocks to production requirements. This flexibility is essential for multi-region deployments where specific IP ranges are needed for each subnet.

Exam trap

ACE often tests the distinction between auto mode and custom mode VPCs, and candidates may incorrectly assume that auto mode allows custom IP ranges or that shared VPC is a network mode rather than a sharing mechanism.

How to eliminate wrong answers

Option A is wrong because Shared VPC is a feature that allows an organization to share a VPC network across multiple projects, not a mode for defining custom IP ranges; it does not inherently provide custom subnet IP control. Option C is wrong because Auto mode VPC automatically creates one subnet per region with predefined IP ranges, offering no customization of subnet IP ranges. Option D is wrong because Legacy mode VPC is an older network type that only supports a single subnet and does not allow multiple regions or custom IP ranges.

52
MCQmedium

A company runs a batch job every night that processes data from a Cloud Storage bucket and writes results to BigQuery. The job runs on a Compute Engine VM. To minimize costs, what is the best practice for the VM?

A.Use a VM with GPUs for faster processing
B.Use a VM with local SSD for temporary storage
C.Use a standard VM and commit to a 1-year commitment
D.Use a preemptible VM
AnswerD

Preemptible VMs cost up to 60–80% less than standard on-demand VMs and are explicitly designed for fault-tolerant, batch workloads that can be interrupted. Compute Engine can terminate a preemptible VM at any time, but it will always run for at least 30 seconds, and the job should be coded to handle early termination by persisting progress to durable storage. Because this nightly batch job is by nature interruptible and short-lived, preemptible VMs are the cost-optimal choice and align with Google's best practices for batch processing.

Why this answer

Preemptible VMs are up to 80% cheaper and can be terminated at any time, which is acceptable for batch jobs that can be checkpointed or restarted from the beginning.

53
MCQmedium

A company needs to connect their on-premises data center to Google Cloud via a dedicated, high-bandwidth connection with low latency. They anticipate consistent high traffic. Which connectivity option should they use?

A.Carrier Peering
B.Cloud VPN
C.VPC peering
D.Dedicated Interconnect
AnswerD

Dedicated Interconnect provides a direct, private physical connection between an on-premises data center and Google Cloud, typically via a co-location facility with one or more 10 Gbps or 100 Gbps links. This dedicated, high-bandwidth link bypasses the public internet, delivering more consistent latency, higher throughput, and an SLA covering availability (up to 99.99% when configured with redundant connections). It is the correct choice here because it is purpose-built for hybrid cloud connectivity that requires reliable, secure, and dedicated bandwidth between a data center and Google Cloud.

Why this answer

Dedicated Interconnect provides direct physical connections between on-premises and Google Cloud, offering high bandwidth and low latency. Cloud VPN is over the internet; Carrier Peering is for enterprise customers; VPC peering is for connecting VPCs within Google Cloud.

54
MCQhard

A company wants to use Google Cloud Pricing Calculator to estimate the monthly cost of running a Compute Engine instance for a web server. They plan to use a n2-standard-4 machine with a 100 GB SSD persistent disk and commit to a 1-year term. Which discount type should they include in the estimate?

A.No discount is needed; the price shown is final
B.Committed use discount (1 year)
C.Free tier discount
D.Sustained use discount only
AnswerB

Committed use discount (1 year) is the correct choice because it aligns with the scenario of running an n2-standard-4 instance consistently over a year. In the Google Cloud Pricing Calculator, selecting a 1-year CUD for compute resources like vCPUs and memory typically yields a discount of approximately 20-30% compared to on-demand pricing. The calculator has a dedicated field to add this commitment, and choosing it directly answers the question by reducing the estimated cost. This is the best option among the list since other discounts either do not apply or are automatically included.

Why this answer

Google Cloud offers committed use discounts (CUDs) for Compute Engine when you commit to a 1-year or 3-year term in exchange for significant discounts (up to 57% for 3-year, ~37% for 1-year on n2). Since the company is committing to a 1-year term, the correct discount type to include in the Pricing Calculator estimate is the 1-year committed use discount. The calculator has a specific option to apply CUDs to the estimate.

Exam trap

The trap is mixing up sustained use discounts (automatic, usage-based) with committed use discounts (contractual, term-based); candidates see '1-year term' and may still pick SUD because they forget SUD is not a term commitment.

How to eliminate wrong answers

Option A is wrong because the price shown without any discount is the on-demand rate; the question explicitly states a 1-year commitment, so a discount must be applied to reflect the actual cost. Option C is wrong because the free tier applies only to specific always-free usage limits (e.g., e2-micro in us-west1), not to an n2-standard-4 instance with a 100 GB SSD. Option D is wrong because sustained use discounts are automatic and apply to on-demand usage that runs for a significant portion of the month; they are not the same as committed use discounts and are not selected as a term-based discount in the calculator.

55
MCQmedium

An organisation requires a managed relational database for an online transaction processing (OLTP) application with strong consistency, automated backups, and a 99.95% SLA. The database size is expected to be under 10 TB. Which service meets these requirements at the lowest cost?

A.Bare Metal Solution
B.Cloud Bigtable
C.Cloud SQL
D.Cloud Spanner
AnswerC

Cloud SQL is a fully managed relational database service offering MySQL, PostgreSQL, and SQL Server engines with automated backups, point-in-time recovery, and integrated high availability, making it ideal for OLTP workloads using SQL. It provides strong ACID consistency and a 99.95% SLA at a predictable price point for databases under 10 TB, which fits the stated need without over-provisioning. This combination of managed operations, relational features, and reasonable cost makes Cloud SQL the correct choice.

Why this answer

Cloud SQL is a fully managed relational database service supporting MySQL, PostgreSQL, and SQL Server, offering strong consistency (ACID), automated backups, and a 99.95% SLA on the Enterprise edition. For OLTP workloads under 10 TB, Cloud SQL provides the best price-to-performance among the listed options. Cloud Spanner and Bigtable are significantly more expensive and designed for different scales and access patterns.

Exam trap

ACE often tests the cost-versus-scale trade-off between Cloud SQL and Cloud Spanner, so candidates over-select Spanner for 'strong consistency' without weighing the 10 TB size and cost constraint.

How to eliminate wrong answers

Option A is wrong because Bare Metal Solution is for lifting-and-shifting specialised workloads (e.g., Oracle, SAP) requiring physical hardware, not a managed relational database with automated backups and an SLA. Option B is wrong because Cloud Bigtable is a NoSQL wide-column store optimised for high-throughput analytical and time-series workloads, not OLTP with strong relational consistency. Option D is wrong because Cloud Spanner, while relational and strongly consistent, is far more expensive and is designed for horizontally scalable, globally distributed workloads exceeding what a sub-10 TB OLTP app requires.

56
MCQmedium

A company needs to store and serve user-generated content such as images and videos. The data must be accessible globally with low latency. Which Google Cloud storage service should they use?

A.Persistent Disk
B.Cloud Filestore
C.Cloud Storage
D.Local SSD
AnswerC

Cloud Storage is the correct choice because it is a durable, highly available object storage service with a global namespace and public HTTPS ingestion and serving endpoints. It provides strong consistency, configurable permissions, and can integrate with Cloud CDN for low-latency delivery of cached content, making it ideal for user-generated photos, videos, and documents. Lifecycle policies can cost-effectively archive older content, and resumable uploads support large files from mobile and web clients.

Why this answer

Cloud Storage is correct because it is Google Cloud's object storage service, designed to store and serve unstructured content like images and videos at global scale with low latency via edge caching and multi-region buckets. It offers HTTP/HTTPS access, signed URLs, and integration with Cloud CDN, making it the standard choice for user-generated media. No other listed service provides globally distributed object storage with this accessibility.

Exam trap

ACE often tests the difference between block storage (Persistent Disk, Local SSD), file storage (Filestore), and object storage (Cloud Storage) — candidates who focus on 'low latency' may wrongly pick Local SSD, ignoring the global accessibility and durability requirements.

How to eliminate wrong answers

Option A is wrong because Persistent Disk is block storage attached to a single Compute Engine VM in one zone — it is not globally accessible and is unsuitable for serving media to users worldwide. Option B is wrong because Cloud Filestore is a managed NFS file system for shared file access within a VPC, not a globally distributed object store for web-served content. Option D is wrong because Local SSD is ephemeral, high-performance block storage physically attached to a single VM; it is not durable, not shared, and not globally accessible.

57
Multi-Selectmedium

A company needs to deploy a web application on Google Cloud that requires high availability across multiple regions. Select TWO services that can help achieve this.

Select 2 answers
A.Global HTTP(S) Load Balancing
B.Cloud VPN
C.Cloud SQL with cross-region replication
D.Cloud NAT
E.Cloud CDN
AnswersA, C

Global HTTP(S) Load Balancing is a correct choice because it uses a single anycast IP to route user traffic to the closest healthy backend across multiple Google Cloud regions. It automatically detects and drains unhealthy backends, supports autoscaling, and provides layer 7 content-based routing. This service delivers the required high availability for the web application's compute and network layer.

Why this answer

Global HTTP(S) Load Balancing distributes traffic across regions, and Cloud SQL with cross-region replication provides database redundancy. Compute Engine instances in multiple regions serve traffic, and load balancing handles failover.

58
MCQmedium

A team is setting up a new project and wants to estimate the monthly cost of running a Compute Engine VM with 4 vCPUs, 16 GB memory, and a 100 GB persistent disk, using the Google Cloud Pricing Calculator. The VM will run for 12 hours every day for a month. Which discount type will automatically apply to reduce the cost based on usage?

A.Preemptible VM discount
B.Sustained use discount
C.Committed use discount
D.Free tier discount
AnswerB

Sustained use discounts are applied automatically when a VM runs for more than 25% of a billing month (approximately 186 hours), without requiring any upfront commitment or configuration. For a VM running 12 hours daily, monthly usage is roughly 360 hours, so the discount kicks in automatically after the threshold is crossed, reducing the bill by up to 20-30% based on the on-demand price — exactly the kind of predictable, usage-based discount this team can estimate.

Why this answer

Sustained use discounts (SUDs) are automatic discounts that Google Cloud applies to Compute Engine instances that run for a significant portion of the billing month. Because the VM runs 12 hours per day every day, it accumulates enough usage to qualify for SUDs without any commitment or action from the team. The discount is applied automatically to the invoice.

Exam trap

ACE often tests the confusion between automatic discounts (sustained use) and opt-in discounts (committed use, preemptible), catching candidates who assume any discount requires a commitment.

How to eliminate wrong answers

Option A is wrong because preemptible VMs are a separate, cheaper VM type that can be terminated at any time — they are not a discount that automatically applies to a standard VM. Option C is wrong because committed use discounts require an explicit 1- or 3-year commitment in exchange for a discount; they are not applied automatically based on usage. Option D is wrong because the free tier applies only to specific always-free resource limits (e.g., one e2-micro instance in select regions), not to a 4-vCPU/16 GB VM.

59
MCQeasy

A developer needs to create a Cloud Storage bucket that stores data for only 30 days and then automatically deletes it. Which feature should be used to achieve this?

A.Object versioning
B.Requester pays
C.Object lifecycle management
D.Bucket lock
AnswerC

Object Lifecycle Management is a native Cloud Storage feature that lets you define rules to automatically delete or transition objects based on conditions like age. A rule with action 'Delete' and condition 'Age: 30 days' will remove objects that are at least 30 days old. This directly satisfies the developer's requirement for scheduled deletion, making it the correct choice.

Why this answer

Object Lifecycle Management lets you define rules that automatically transition or delete objects based on age, creation date, or other conditions. Setting a lifecycle rule with an Age condition of 30 days and a Delete action causes Cloud Storage to automatically remove objects after 30 days, exactly matching the requirement.

Exam trap

ACE often tests the confusion between Bucket Lock (prevents deletion for retention) and Object Lifecycle Management (automates deletion), catching candidates who pick the retention feature when deletion is required.

How to eliminate wrong answers

Option A is wrong because Object Versioning keeps multiple versions of an object to protect against accidental deletion or overwrite — it does not delete data and would actually increase storage usage. Option B is wrong because Requester Pays shifts the cost of data access and egress to the requester; it has nothing to do with automatic deletion. Option D is wrong because Bucket Lock enforces a retention policy that prevents deletion for a specified period — it is the opposite of automatic deletion and is used for compliance (e.g., WORM).

60
MCQhard

A company runs a global web application with a Cloud SQL (MySQL) database in the us-east1 region. To improve read performance for users in Europe, they want to offload read traffic to a replica in europe-west1. The replica must be kept in sync with the primary within seconds. Which Cloud SQL configuration should be used?

A.Enable automatic failover to a replica in europe-west1
B.Create a cross-region read replica in europe-west1
C.Configure Cloud SQL for multi-region deployment
D.Create an external replica in europe-west1
AnswerB

Creating a cross-region read replica in europe-west1 is correct because Cloud SQL supports read-only replicas in a different region, using asynchronous replication to serve queries close to the users. This reduces read latency for European users while keeping writes on the primary instance. The replica can also be manually promoted to a standalone primary for disaster recovery, but it does not require an HA configuration or additional on-premises infrastructure.

Why this answer

A cross-region read replica in europe-west1 is the correct configuration because it creates a replica of the primary Cloud SQL instance in a different region, allowing read traffic to be served locally in Europe. Cloud SQL supports cross-region read replicas for MySQL, which are kept in sync with the primary via asynchronous replication, typically within seconds. This improves read performance for European users by reducing latency.

Exam trap

The trap is confusing high-availability failover replicas with read replicas for performance; failover replicas are for redundancy and do not serve read traffic, while read replicas are specifically for scaling reads.

How to eliminate wrong answers

Option A is wrong because automatic failover to a replica in europe-west1 is for high availability, not for offloading read traffic; failover replicas are typically in the same region or configured for disaster recovery, and they do not serve reads unless promoted. Option C is wrong because Cloud SQL does not support multi-region deployment in the sense of a single instance spanning multiple regions; it offers regional instances with optional cross-region replicas. Option D is wrong because an external replica is for replicating from an external MySQL server, not for creating a replica of a Cloud SQL instance in another region.

61
MCQmedium

A company wants to run a stateless HTTP web application that experiences highly variable traffic, including periods of zero traffic. The application is packaged as a Docker container. The team wants to minimize operational overhead and pay only for resources consumed during request processing. Which Google Cloud compute service is the best fit?

A.Cloud Functions
B.Cloud Run
C.GKE Standard
D.Compute Engine with managed instance group
AnswerB

Cloud Run is Google Cloud's fully managed serverless container platform that executes stateless containers on a Knative-based infrastructure, making it ideal for an HTTP web application. It automatically scales to zero when there is no traffic, so you pay nothing during idle periods, and it scales up to thousands of concurrent instances based on incoming requests, with per-request billing that only charges from the moment a request starts to when it finishes. Cloud Run supports any OCI-container image, meaning you can package a web server (e.g., Nginx, Express, Django) and it will handle TLS certificates, domain mapping, and load balancing natively. For variable traffic patterns of a stateless HTTP app, Cloud Run offers the perfect balance of elasticity, cost-efficiency, and operational simplicity.

Why this answer

Cloud Run is serverless, scales to zero, charges per request, and runs containers from container images. Cloud Functions is for event-driven functions, not full web apps. GKE Standard and Compute Engine require managing servers and do not scale to zero.

Ready to test yourself?

Try a timed practice session using only Planning and Configuring a Cloud Solution questions.