Courseiva

CCNA Google Cloud Products and Services Questions

51 of 126 questions · Page 2/2 · Google Cloud Products and Services · Answers revealed

76
Multi-Selectmedium

A company is migrating its on-premises PostgreSQL database to Google Cloud. They need a managed service that is fully compatible with PostgreSQL, offers high availability, and provides automated backups. Which TWO Google Cloud services should they consider?

Select 2 answers
A.Cloud SQL
B.Memorystore
C.AlloyDB
D.Filestore
E.Cloud Bigtable
AnswersA, C

Cloud SQL is a fully managed relational database service that supports PostgreSQL, providing automated backups, point-in-time recovery, and high availability with synchronous replication across zones. It offers native PostgreSQL compatibility, so applications can migrate without any changes to their SQL or data access layer. With managed maintenance, scaling, and built-in security features like IAM integration and encryption at rest, Cloud SQL is the pragmatic default choice for most PostgreSQL migrations to Google Cloud.

Why this answer

Cloud SQL (A) is correct because it is a fully managed relational database service that supports PostgreSQL with full compatibility, offers high availability through regional configurations with automatic failover, and provides automated backups and point-in-time recovery. AlloyDB (C) is also correct because it is a fully managed PostgreSQL-compatible database service designed for high availability with a multi-node architecture and automated backups, while offering enhanced performance for demanding workloads. Memorystore (B) is incorrect because it is a managed in-memory data store for Redis and Memcached, not a PostgreSQL-compatible relational database.

Filestore (D) is incorrect because it is a managed network file storage service (NFS) for file-based workloads, not a database service. Cloud Bigtable (E) is incorrect because it is a fully managed NoSQL wide-column database, not PostgreSQL-compatible.

Exam trap

GCDL often tests the confusion between Cloud SQL and AlloyDB, where candidates might think AlloyDB is not PostgreSQL-compatible or that Cloud SQL is not fully managed, when in fact both are valid options for PostgreSQL migration.

77
Multi-Selecthard

A team is designing a CI/CD pipeline for a microservices application. They want to automatically build container images from source code, store them securely, and deploy to GKE. Which THREE services should they include? (Choose three.)

Select 3 answers
A.Cloud Build
B.Cloud Storage
C.Cloud Run
D.Artifact Registry
E.GKE
AnswersA, D, E

Cloud Build is the fully managed CI/CD service that compiles your source code, runs tests, and builds the container image from a Dockerfile or build config. It executes the build steps defined in your pipeline, generating OCI-compliant images that are then pushed to a registry. This makes Cloud Build the correct core engine for the CI/CD pipeline.

Why this answer

Cloud Build (A) is correct because it is Google Cloud's managed CI/CD service that compiles source code and builds container images, and it integrates natively with GKE and Artifact Registry for automated pipelines. Artifact Registry (D) is correct because it securely stores and manages container images (and other artifacts) with IAM-based access control and vulnerability scanning, serving as the image repository the pipeline pushes to and GKE pulls from. GKE (E) is correct because it is the target runtime for deploying the containerized microservices, and it can pull images directly from Artifact Registry within the same project.

Cloud Storage (B) is not the right choice because it is object storage for blobs, not a container image registry with the tagging and vulnerability features needed here. Cloud Run (C) is not correct because it is a serverless container platform, not the GKE deployment target specified in the scenario.

Exam trap

GCDL often tests the confusion between Cloud Run and GKE as deployment targets, or between Cloud Storage and Artifact Registry for storing images; candidates must match the services to the specific requirements of building, storing, and deploying to GKE.

78
Multi-Selectmedium

A company runs a high-performance computing (HPC) workload on Compute Engine that requires low-latency, high-throughput scratch storage. The workload is checkpointed every hour. Which TWO storage options should the engineer consider for the scratch storage? (Choose 2)

Select 2 answers
A.Persistent Disk (HDD)
B.Persistent Disk (SSD)
C.Local SSD
D.Filestore
E.Cloud Storage
AnswersB, C

Persistent Disk (SSD) is a durable, network-attached block storage service that provides consistent, low-latency performance and survives instance termination. For HPC scratch, it can be used when data must persist across restarts or preemption, allowing successful checkpointing and restart without data loss. Its performance scales with provisioned size, and it supports multiple per-instance volumes to meet aggregate throughput needs.

Why this answer

Option B (Persistent Disk SSD) is correct because SSD-backed Persistent Disks deliver the high IOPS and throughput needed for low-latency scratch storage while remaining durable and independent of the VM lifecycle, which suits an HPC workload that checkpoints hourly. Option C (Local SSD) is correct because Local SSDs are physically attached NVMe devices offering the lowest latency and highest throughput per instance, making them ideal for scratch data that is regenerated from checkpoints. Option A (Persistent Disk HDD) is not appropriate because HDD-backed disks have much lower IOPS and higher latency than SSDs.

Option D (Filestore) is a managed NFS file service optimized for shared file access rather than the highest-throughput local scratch storage. Option E (Cloud Storage) is an object store accessed over the network, so it cannot provide the low-latency, high-throughput block-level scratch performance required.

Exam trap

GCDL often tests the misconception that any SSD-backed storage is equally suitable for HPC, ignoring the trade-offs between Local SSD (ephemeral, ultra-low latency) and Persistent Disk SSD (durable, slightly higher latency).

79
MCQmedium

A company runs batch processing jobs on scheduled intervals. They want to minimise costs by using short-lived compute capacity that can be interrupted but offers significant discounts. Which type of Compute Engine VM should they use?

A.E2 high-memory VMs
B.Sole-tenant nodes
C.Preemptible VMs
D.Confidential VMs
AnswerC

Preemptible VMs (and Spot VMs) are Compute Engine instances that can be terminated anywhere anytime due to excess capacity reuse, but they can be used for batch and fault-tolerant workloads. They are up to 60–80% cheaper than standard VMs, making them the ideal choice for a company running scheduled batch processing that can checkpoint and resume. To use them effectively, the application must handle unexpected termination gracefully and be restartable from saved state.

Why this answer

Preemptible VMs are short-lived Compute Engine instances that offer up to 60-91% discounts compared to standard VMs but can be terminated by Google at any time with a 30-second notice. They are ideal for batch processing jobs that are fault-tolerant and can be interrupted, matching the requirement to minimize costs with interruptible capacity.

Exam trap

GCDL often tests the distinction between preemptible/spot VMs and other VM types — candidates may pick high-memory or confidential VMs based on workload characteristics, missing that the key requirement is interruptible, discounted capacity.

How to eliminate wrong answers

Option A is wrong because E2 high-memory VMs are standard on-demand instances optimized for memory-intensive workloads, not discounted interruptible capacity. Option B is wrong because sole-tenant nodes provide physical isolation for compliance or licensing needs and are more expensive, not a cost-saving interruptible option. Option D is wrong because Confidential VMs encrypt data in use with AMD SEV and are priced at a premium for security, not for cost savings on batch jobs.

80
MCQeasy

A developer wants to deploy a containerized application that can scale down to zero when not in use and charges only for the resources consumed during request processing. Which Google Cloud compute service should they choose?

A.Google Kubernetes Engine (GKE)
B.Compute Engine
C.App Engine Flexible Environment
D.Cloud Run
AnswerD

Cloud Run is a fully managed serverless container platform that automatically scales your container from zero instances up to a number sufficient to handle incoming HTTP requests, and then back down to zero when traffic disappears. You are billed only for the exact time spent processing a request, with a minimum granularity of 100 milliseconds, so when there is no request traffic there are zero compute charges. This gives the developer exactly what they asked for: a containerized application that scales to zero, eliminating infrastructure costs during idle periods.

Why this answer

Cloud Run is a fully managed serverless container platform that automatically scales instances down to zero when there is no traffic, and it bills only for CPU/memory consumed during request handling (with per-100ms granularity). This matches the requirement of zero-idle cost and pay-per-request processing exactly. GKE and Compute Engine both require at least one running node/VM, and App Engine Flexible keeps at least one instance running, so none of them can truly scale to zero.

Exam trap

GCDL often tests the distinction between 'serverless' services that still keep a warm instance (App Engine Flexible) versus those that truly scale to zero (Cloud Run, Cloud Functions) — candidates who equate 'serverless' with 'scale-to-zero' pick App Engine Flexible incorrectly.

How to eliminate wrong answers

Option A is wrong because GKE clusters require a node pool with at least one running node, so the cluster never scales to zero and you pay for idle node capacity. Option B is wrong because Compute Engine VMs are always-on resources billed per second while running; they cannot scale to zero without external orchestration and still incur persistent disk costs. Option C is wrong because App Engine Flexible Environment keeps a minimum of one instance running at all times and does not support true scale-to-zero billing.

81
MCQmedium

A data engineering team needs to process streaming data from Cloud Pub/Sub, perform transformations, and write the results to BigQuery. The team requires exactly-once processing semantics and automatic scaling. Which service should they use?

A.Cloud Functions
B.Cloud Dataflow
C.Cloud Dataproc
D.BigQuery
AnswerB

Cloud Dataflow is a fully managed, unified stream and batch processing service built on Apache Beam. It provides exactly-once processing guarantees, automatic scaling, and powerful primitives for event-time processing, windowing, and triggers. With native Pub/Sub and BigQuery I/O connectors, Dataflow can ingest streaming data directly from Pub/Sub, apply complex transformations, and write results to BigQuery without additional glue code, making it the correct choice for this use case.

Why this answer

Dataflow (Apache Beam) provides exactly-once processing, autoscaling, and native integration with Pub/Sub and BigQuery for streaming pipelines. Cloud Dataproc is for batch Spark/Hadoop, not streaming. Cloud Functions processes events one at a time without exactly-once guarantees across a pipeline.

BigQuery itself does not transform streaming data.

82
MCQmedium

A data analyst needs to run ad-hoc SQL queries on a large dataset stored in Cloud Storage. The data is in CSV format and does not require real-time results. Which Google Cloud service should they use?

A.BigQuery
B.Dataflow
C.Cloud SQL
D.Cloud Dataproc
AnswerA

BigQuery is the correct choice because it is a serverless, highly scalable cloud data warehouse that supports standard ANSI SQL. It can query external datasets directly from Cloud Storage using external tables, where you define a table schema pointing to files (CSV, JSON, Parquet, Avro, ORC, etc.) without requiring an ETL pipeline. This makes it ideal for ad hoc SQL analysis on large datasets, since BigQuery automatically manages the underlying compute and parallelizes the query across the data, and you pay only for the data scanned. Additionally, BigQuery supports federated queries across other Google Cloud services, but querying Cloud Storage files is the most direct path for this scenario.

Why this answer

BigQuery supports external data sources; you can create an external table pointing to CSV files in Cloud Storage and run SQL queries without loading the data. This is ideal for ad-hoc analysis on existing data.

83
MCQeasy

Which Google Cloud service can be used to create and manage virtual networks, subnets, firewall rules, and VPN connections?

A.Cloud Armor
B.Cloud Load Balancing
C.Cloud VPC
D.Cloud CDN
AnswerC

Cloud VPC (Virtual Private Cloud) is the correct service for creating and managing a private network in Google Cloud. It lets you define global or regional networks, allocate IP CIDR ranges, create subnetworks, set up firewall rules, dynamic routes (including BGP with Cloud Router), and connect on-premises environments via Cloud VPN or Interconnect. As a foundational networking primitive, Cloud VPC provides full control over routing, addressing, and isolation, directly matching the requirement to create and manage the network itself.

Why this answer

Cloud VPC (Virtual Private Cloud) is the Google Cloud service that provides networking functionality for your resources. It allows you to create and manage virtual networks, subnets, firewall rules, and VPN connections. It is the foundational networking service in GCP, enabling you to define IP ranges, routes, and security policies for your instances and services.

Exam trap

GCDL often tests the distinction between networking services and security or delivery services, causing candidates to confuse Cloud Armor (security) or Cloud CDN (content delivery) with core networking components like VPC.

How to eliminate wrong answers

Option A is wrong because Cloud Armor is a security service that provides DDoS protection and WAF capabilities, not network creation or management. Option B is wrong because Cloud Load Balancing distributes traffic across multiple instances, but it does not create or manage VPC networks, subnets, or VPNs. Option D is wrong because Cloud CDN is a content delivery network that caches content at edge locations, not a service for building virtual networks.

84
MCQmedium

A company runs batch analytics jobs every night using Apache Spark on a cluster. The jobs require 100 vCPUs and run for 3 hours. The cluster must be created, run, and then shut down automatically to minimise cost. Which service should they use?

A.Cloud Dataflow
B.Cloud Dataproc
C.Google Kubernetes Engine (GKE)
D.Compute Engine with managed instance groups
AnswerB

Cloud Dataproc is Google Cloud's managed Spark and Hadoop service, purpose-built to run workloads like Apache Spark directly. You can create a job-scoped cluster that automatically terminates as soon as the batch job finishes, so you only incur compute costs while the job is running, which is ideal for nightly analytics that do not need a persistent cluster. Dataproc also supports custom machine types, preemptible/spot workers, and integration with Cloud Storage, BigQuery, and Cloud Monitoring, making it the lowest-effort, cost-optimized choice.

Why this answer

Cloud Dataproc is a fully managed service for running Apache Spark and Hadoop clusters on Google Cloud. It supports creating clusters with specified vCPU counts, running jobs, and then automatically deleting the cluster after job completion, which minimizes cost for batch workloads. The service is purpose-built for ephemeral Spark jobs, offering fast cluster startup and per-second billing.

Exam trap

GCDL often tests the misconception that Cloud Dataflow is the go-to service for all data processing, but it is specific to Apache Beam, not Spark; candidates must remember that Dataproc is the managed Spark/Hadoop service.

How to eliminate wrong answers

Option A is wrong because Cloud Dataflow is a managed service for Apache Beam, not Spark; it does not natively run Spark jobs. Option C is wrong because GKE is a container orchestration platform; while Spark can run on Kubernetes, it requires manual setup and management of the Spark environment, lacking the automated cluster lifecycle and Spark-specific optimizations of Dataproc. Option D is wrong because Compute Engine with managed instance groups requires manual configuration of the Spark cluster, and automatic shutdown after job completion is not built-in; it would need custom scripting, increasing operational overhead.

85
MCQhard

An organization needs to store archival data that must be retained for 10 years for compliance. Access to this data is expected to be less than once a year, and retrieval can take up to 24 hours. Which Cloud Storage class is the MOST cost-effective for this data?

A.Coldline storage class
B.Nearline storage class
C.Archive storage class
D.Standard storage class
AnswerC

Archive storage offers the lowest per-gigabyte cost, designed for data accessed less than once a year with retrieval times of hours. It satisfies the 10-year retention, sub-annual access and 24-hour retrieval constraints more cheaply than Nearline or Coldline.

Why this answer

Archive storage class (C) is the most cost-effective for data accessed less than once a year with retrieval times up to 24 hours. It has the lowest storage cost and is designed for long-term archival and compliance.

Exam trap

The trap is confusing Coldline and Archive, as both are for infrequent access. Candidates must remember that Archive is the cheapest but has the longest retrieval time (up to 24 hours) and a 365-day minimum storage duration, while Coldline is slightly more expensive but offers faster retrieval.

How to eliminate wrong answers

Option A is wrong because Coldline storage is for data accessed less than once a year, but it has higher storage cost than Archive and retrieval times are typically milliseconds, not up to 24 hours. Option B is wrong because Nearline storage is for data accessed less than once a month, with higher cost and faster retrieval. Option D is wrong because Standard storage is for frequently accessed data and is the most expensive.

86
Multi-Selectmedium

A company runs a stateful web application on Compute Engine. They need to ensure that persistent data is retained if an instance fails, and that traffic is automatically distributed across healthy instances. Which TWO Google Cloud services should they use? (Choose 2)

Select 2 answers
A.Cloud DNS
B.Persistent Disk
C.Cloud Load Balancing
D.Cloud CDN
E.Cloud NAT
AnswersB, C

Persistent Disk stores durable block-level data that exists independently of the virtual machine instance. When an instance is terminated or fails, the disk can be attached to a new instance in the same zone (or across zones with regional persistent disks), allowing the application to recover all state such as user sessions and database files. This independence is exactly what makes a stateful application resilient to instance-level failures.

Why this answer

Persistent Disk (B) is correct because it provides durable, network-attached block storage that persists independently of the Compute Engine instance lifecycle, so data survives an instance failure and can be reattached to a replacement VM. Cloud Load Balancing (C) is correct because it automatically distributes incoming traffic across healthy backend instances using health checks, removing unhealthy instances from rotation. Cloud DNS (A) only resolves domain names to IP addresses and does not provide persistence or health-based traffic distribution.

Cloud CDN (D) caches HTTP(S) content at edge locations to reduce latency, not to persist application data or balance traffic. Cloud NAT (E) provides outbound internet access for private instances and does not address storage durability or load distribution.

Exam trap

GCDL often tests the misconception that any GCP networking service (Cloud DNS, Cloud CDN, Cloud NAT) provides storage or load balancing — candidates must map each service to its actual function.

87
MCQmedium

A data engineer needs to process streaming clickstream data in real-time, apply transformations, and write the output to BigQuery. Which Google Cloud service is built for this use case?

A.Cloud Dataproc
B.Cloud Dataflow
C.Cloud Pub/Sub
D.Cloud Functions
AnswerB

Cloud Dataflow is the correct choice because it is a fully managed, serverless service for both stream and batch processing, built on the Apache Beam model. It provides native, optimized BigQuery I/O with exactly-once processing semantics, event-time windowing, and automatic scaling to handle unbounded clickstream data from Pub/Sub. Dataflow's built-in support for watermarks, triggers, and stateful transformations makes it ideal for running low-latency, continuous ETL pipelines that land directly in BigQuery.

Why this answer

Cloud Dataflow is Google Cloud's fully managed, serverless service for both batch and stream processing, built on Apache Beam. It natively supports reading from Pub/Sub, applying transformations, and writing to BigQuery, making it the correct choice for real-time clickstream processing. Its autoscaling and exactly-once processing capabilities are designed for streaming pipelines like this.

Exam trap

The trap is selecting Pub/Sub because it is the ingestion layer for streaming data, but the question asks for the service that processes and transforms the stream and writes to BigQuery — that is Dataflow, not Pub/Sub.

How to eliminate wrong answers

Option A is wrong because Cloud Dataproc is a managed Hadoop/Spark service intended for batch and cluster-based processing, not the serverless streaming pipeline described. Option C is wrong because Cloud Pub/Sub is a messaging/ingestion service that transports events but does not itself apply transformations or write to BigQuery. Option D is wrong because Cloud Functions is an event-driven serverless compute service for short-lived functions, not a data pipeline framework for continuous stream processing with windowing and transforms.

88
MCQmedium

An analytics team needs to create dashboards and visualizations from data stored in BigQuery. They want a free solution that integrates natively. Which tool should they use?

A.Cloud Dataflow
B.Looker Studio
C.Looker
D.Google Sheets
AnswerB

Looker Studio is Google's free, self-service reporting and visualization tool that natively integrates with BigQuery as a first-class data source. You can connect directly to BigQuery datasets without exporting data, and it automatically handles query pagination and aggregation for fast interactive dashboards. Its cost model (free for creators) and native BigQuery connector make it the ideal choice for an analytics team that needs to build and share visualizations quickly.

Why this answer

Looker Studio (formerly Google Data Studio) is a free, fully managed business intelligence and data visualization tool that natively connects to BigQuery. It allows users to create interactive dashboards and reports without any cost, making it the ideal choice for an analytics team seeking a free, natively integrated solution. Its direct BigQuery connector enables real-time querying and visualization of large datasets.

Exam trap

GCDL often tests the distinction between free and paid Google Cloud data visualization tools, causing candidates to confuse Looker Studio (free) with Looker (paid enterprise solution).

How to eliminate wrong answers

Option A is wrong because Cloud Dataflow is a fully managed data processing service for batch and stream data pipelines, not a dashboarding or visualization tool. Option C is wrong because Looker is a paid enterprise business intelligence platform, not a free solution, and while it integrates with BigQuery, it requires a license. Option D is wrong because Google Sheets is a spreadsheet application that can connect to BigQuery but is not designed for creating advanced dashboards and visualizations; it lacks the native, purpose-built BI features of Looker Studio.

89
MCQmedium

A developer wants to trigger a serverless function whenever a new object is uploaded to a Cloud Storage bucket. Which Google Cloud service should they use?

A.Cloud Functions
B.Cloud Run
C.App Engine
D.Dataflow
AnswerA

Cloud Functions is the correct choice because it is Google Cloud's event-driven serverless compute service designed to respond directly to Cloud Storage events. Specifically, Cloud Functions natively subscribes to the `google.storage.object.finalize` event, which is emitted whenever an object is uploaded or overwritten in a bucket. This background function type requires no custom intermediary, as the event is delivered automatically and the function can immediately process the object, making it the most direct and efficient mechanism for triggering on object uploads.

Why this answer

Cloud Functions is an event-driven serverless compute service that can be triggered by Cloud Storage events such as object finalise/create. Cloud Run can also be triggered by events via Eventarc, but Cloud Functions is the simpler choice for small code snippets triggered by events. Dataflow and App Engine are not designed for event-triggered functions from Cloud Storage.

90
MCQmedium

A company wants to set up a hybrid cloud connection between its on-premises data center and Google Cloud VPC with a dedicated, high-bandwidth, low-latency link. Which service should they use?

A.Cloud VPN
B.Cloud CDN
C.Cloud NAT
D.Cloud Interconnect
AnswerD

Cloud Interconnect provides direct, dedicated network connections between your on-premises network and Google Cloud, either via co-location facilities (Dedicated Interconnect) or through a service provider (Partner Interconnect). These private links offer consistent high bandwidth, low latency, and a guaranteed SLA, making them the correct choice for a hybrid cloud connection.

Why this answer

Cloud Interconnect provides a dedicated, private physical connection between an on-premises network and a Google Cloud VPC, offering high bandwidth (10 Gbps or 100 Gbps per link) and low latency compared to public internet paths. It supports Dedicated Interconnect (direct connection at a Google colocation facility) and Partner Interconnect (via a service provider), both designed for enterprise-grade hybrid cloud connectivity. This meets the requirement for a dedicated, high-bandwidth, low-latency link.

Exam trap

GCDL often tests the misconception that Cloud VPN can provide dedicated, high-bandwidth, low-latency connectivity, but it actually uses the public internet and is not dedicated; candidates must distinguish between VPN (encrypted tunnel over internet) and Interconnect (private dedicated link).

How to eliminate wrong answers

Option A is wrong because Cloud VPN uses IPsec tunnels over the public internet, which introduces variable latency and bandwidth limitations, and is not a dedicated link. Option B is wrong because Cloud CDN is a content delivery network that caches HTTP(S) content at edge locations; it does not provide a network connection between on-premises and VPC. Option C is wrong because Cloud NAT provides outbound internet access for private instances without public IPs; it does not establish a hybrid connection.

91
MCQeasy

Which Google Cloud service provides a unified platform for building, training, and deploying machine learning models at scale?

A.Vertex AI
B.BigQuery ML
C.AutoML
D.Cloud Dataflow
AnswerA

Vertex AI is Google Cloud's unified machine learning platform that integrates the entire ML workflow—from data preparation and feature engineering to model training, hyperparameter tuning, serving, and monitoring—under a single API and console. It consolidates AutoML, custom training, and MLOps tools so teams can manage models consistently. This fits the definition of a "unified platform" for machine learning.

Why this answer

Vertex AI is the unified ML platform covering all stages of ML workflow. AutoML is a component, Dataflow is for data processing, and BigQuery ML runs ML models in SQL.

92
MCQhard

An organisation must store archival data that is accessed less than once a year. They need the lowest storage cost and can tolerate a retrieval time of several hours. Which Cloud Storage class should they use?

A.Coldline
B.Nearline
C.Standard
D.Archive
AnswerD

Archive is the lowest-cost storage class in Google Cloud Storage, specifically designed for long-term backup and archival data that is accessed less than once per year. It offers the cheapest storage price, but retrieval times are typically hours (or even up to 365 days for some operations), and it imposes a 365-day minimum storage duration. For an organization storing archival data that is rarely accessed, Archive provides the optimal balance of cost efficiency and suitability, making it the correct choice.

Why this answer

Archive is the correct choice because it is Google Cloud's lowest-cost storage class, designed for data accessed less than once a year. It offers the cheapest per-GB storage price and a minimum storage duration of 365 days, with retrieval times typically ranging from milliseconds to hours depending on the access method. The organisation's requirement for the lowest cost and tolerance for several hours of retrieval time aligns perfectly with Archive's cost-performance profile.

Exam trap

GCDL often tests the confusion between Coldline and Archive based on access frequency thresholds (quarterly vs. yearly) and the assumption that lower cost always means Archive, but candidates must also consider retrieval time and minimum storage duration.

How to eliminate wrong answers

Option A is wrong because Coldline is designed for data accessed less than once a quarter (90 days), not less than once a year, and it costs more than Archive. Option B is wrong because Nearline is for data accessed less than once a month (30 days) and is more expensive than both Coldline and Archive. Option C is wrong because Standard is for frequently accessed data (multiple times per month) and is the most expensive storage class, unsuitable for archival data with rare access.

93
Multi-Selecthard

A company wants to implement a hybrid cloud architecture connecting their on-premises data center to Google Cloud. They need high bandwidth (10 Gbps), low latency, and a service-level agreement (SLA). Which TWO services can provide dedicated connectivity? (Choose two.)

Select 2 answers
A.HA VPN
B.Cloud CDN
C.Cloud Interconnect (Partner)
D.Cloud Interconnect (Dedicated)
E.Cloud VPN
AnswersC, D

Partner Interconnect establishes a connection between your on-premises network and Google's network via a supported third-party service provider, such as a colocation or network provider. It offers a service-level agreement (up to 99.99%) and can be provisioned at capacities from 50 Mbps to 10 Gbps depending on the partner, making it suitable for hybrid workloads. Unlike VPN, it does not traverse the public internet, providing more reliable, lower-latency connectivity.

Why this answer

Cloud Interconnect (Partner) (C) is correct because it provides dedicated connectivity to Google Cloud through a supported partner, delivering high bandwidth up to 10 Gbps or more with low latency and a Google-backed SLA for hybrid architectures. Cloud Interconnect (Dedicated) (D) is also correct because it offers a direct physical connection between the on-premises data center and Google's network, supporting 10 Gbps or 100 Gbps links with low latency and an SLA, exactly matching the stated requirements. HA VPN (A) and Cloud VPN (E) are incorrect because they are IPsec VPN tunnels over the public internet, which cannot guarantee the dedicated 10 Gbps bandwidth or low-latency SLA required here.

Cloud CDN (B) is incorrect because it is a content delivery network for caching and serving web content at the edge, not a connectivity service between on-premises and Google Cloud.

Exam trap

GCDL often tests the distinction between VPN (which uses public internet) and Interconnect (dedicated private connectivity); candidates may incorrectly select HA VPN or Cloud VPN for dedicated connectivity.

94
MCQhard

A company uses Cloud SQL for MySQL and needs to migrate to a PostgreSQL-compatible database that offers improved performance for AI workloads (e.g., vector embeddings). Which Google Cloud database is MOST suitable?

A.Cloud SQL for PostgreSQL
B.Cloud Spanner
C.AlloyDB
D.Bigtable
AnswerC

AlloyDB is Google Cloud’s fully managed PostgreSQL-compatible database purpose-built for demanding transactional and analytical workloads, and it integrates AI-optimized features directly into the engine. It includes native support for vector embeddings and vector search (AlloyDB AI), plus a columnar engine that accelerates analytical queries and can speed up AI inference pipelines. For a migration from Cloud SQL for MySQL, AlloyDB provides the lowest-friction PostgreSQL-compatible path while adding the AI capabilities your new workload needs.

Why this answer

AlloyDB is a PostgreSQL-compatible database that is optimized for high performance and features like vector embeddings for AI, making it ideal for this migration.

95
MCQhard

A large enterprise is migrating its on-premises data center to Google Cloud. They need a dedicated, low-latency, and highly available connection between their on-premises network and their VPC. Which networking service should they use?

A.Cloud CDN
B.Cloud Interconnect
C.Cloud VPN
D.Cloud Load Balancing
AnswerB

Cloud Interconnect provides dedicated, private network connectivity between your on-premises data center and Google Cloud, using either Dedicated Interconnect or Partner Interconnect. Because traffic is carried over Google's global network rather than the public internet, it offers consistently low latency, high throughput, and a contractually backed availability SLA (up to 99.99% depending on configuration). For a large enterprise migration that requires reliable performance and predictable network behavior, this is the only option that truly meets those requirements.

Why this answer

Cloud Interconnect provides dedicated, high-bandwidth, low-latency connections with SLAs. Cloud VPN is over the public internet and may not meet strict latency/availability requirements. Load Balancing and CDN are not for connectivity to on-premises.

96
MCQhard

A security engineer wants to block malicious traffic patterns at the edge of Google's network before it reaches their application. Which service should they configure?

A.VPC firewall rules
B.Cloud DNS
C.Cloud CDN
D.Cloud Armor
AnswerD

Cloud Armor is a global DDoS mitigation and web application firewall (WAF) service that enforces security policies at the edge of Google's network, in front of load balancers. It supports CEL-based custom rules that can inspect headers, query parameters, and request bodies to block specific malicious patterns like SQL injection, cross-site scripting, or known bot signatures. Because policies are evaluated before traffic reaches your GCE instances or GKE pods, attack traffic can be dropped with minimal latency impact, making it the correct choice for blocking a malicious traffic pattern.

Why this answer

Cloud Armor is Google Cloud's edge security service that provides WAF capabilities and DDoS protection, allowing you to block malicious traffic patterns before they reach your application. It integrates with global load balancing to filter requests at the edge of Google's network. This directly addresses the requirement to block malicious traffic at the edge.

Exam trap

The trap is confusing network-layer firewalls (VPC firewall rules) with application-layer WAF (Cloud Armor). Candidates may pick VPC firewall rules because they think it blocks malicious traffic, but it lacks HTTP inspection and edge enforcement.

How to eliminate wrong answers

Option A is wrong because VPC firewall rules operate at the network layer within a VPC, not at the edge of Google's network; they control traffic to and from instances but do not inspect HTTP(S) patterns or provide WAF functionality. Option B is wrong because Cloud DNS is a scalable DNS service; it does not filter or block malicious traffic. Option C is wrong because Cloud CDN caches content at the edge to improve performance, but it does not provide security filtering or WAF capabilities.

97
MCQmedium

A developer needs to run a small piece of Python code that processes a message from Pub/Sub and stores the result in Firestore. The code runs infrequently (a few hundred times per day) and takes less than a second to execute. Which compute service is most cost-effective and simple to manage?

A.Cloud Functions
B.Cloud Run
C.Compute Engine with preemptible VM
D.App Engine Standard Environment
AnswerA

Cloud Functions is the ideal fit because it is a managed Function-as-a-Service platform that executes code in response to a Pub/Sub event, scaling to zero when idle. It bills only for the actual invocation time, measured in 100ms increments, so a small Python snippet that runs once or twice undergoes no idle cost or container overhead. Its event-driven trigger model and built-in Pub/Sub subscription abstraction remove the need to run a web server or manage infrastructure, making it the most cost-effective and operationally simple choice for this task.

Why this answer

Cloud Functions is the most cost-effective and simple option for infrequent, short-running event-driven code. It automatically scales to zero when not in use, so you only pay for actual execution time and resources consumed. It integrates natively with Pub/Sub and Firestore, requiring minimal configuration.

Exam trap

GCDL often tests the difference between serverless compute options (Cloud Functions vs. Cloud Run vs. App Engine) and when to choose each based on frequency, duration, and management overhead, causing candidates to overlook the cost benefits of scaling to zero.

How to eliminate wrong answers

Option B is wrong because Cloud Run, while serverless, is designed for containerized applications and typically requires more setup; it also may not scale to zero as seamlessly for very infrequent invocations, and it's overkill for a simple function. Option C is wrong because Compute Engine with preemptible VMs requires managing a VM instance, which is not simple and incurs costs even when idle, making it less cost-effective for infrequent tasks. Option D is wrong because App Engine Standard is designed for web applications and services, not for simple event-driven functions; it has a more complex deployment model and may not be as cost-effective for sporadic execution.

98
MCQeasy

Which Google Cloud service is a fully managed, serverless data warehouse for analytics with built-in ML capabilities (e.g., BigQuery ML)?

A.Cloud SQL
B.Firestore
C.Cloud Spanner
D.BigQuery
AnswerD

BigQuery is a serverless data warehouse that uses columnar storage and a distributed query engine to run ANSI SQL analytics on petabytes of data without provisioning infrastructure. It separates storage and compute, allowing independent scaling, and introduces BigQuery ML to create and execute machine learning models directly on SQL queries. The service also integrates with Dataflow, Dataproc, and Looker for end-to-end analytics pipelines.

Why this answer

BigQuery is a serverless data warehouse that supports standard SQL, scales automatically, and includes BigQuery ML for creating ML models using SQL.

99
Multi-Selecthard

A company needs to run a Hadoop/Spark workload on Google Cloud. They must use existing YARN applications and need to optimise for cost by using preemptible VMs for task nodes. Which three services should they use?

Select 3 answers
A.Compute Engine
B.Cloud Dataproc
C.Cloud Storage
D.BigQuery
E.Dataflow
AnswersA, B, C

Compute Engine provides the virtual machines that form the worker and master nodes of a Cloud Dataproc cluster. When you run a Hadoop/Spark workload on Google Cloud, Cloud Dataproc orchestrates the deployment, but the actual CPU, memory, and local storage attached to each cluster node are Compute Engine instances. You can also run Hadoop/Spark directly on your own Compute Engine VMs without Dataproc, making Compute Engine the fundamental compute infrastructure for such workloads.

Why this answer

Cloud Dataproc (B) is the right managed service because it natively runs Hadoop/Spark clusters on Google Cloud and supports existing YARN applications, including the ability to designate preemptible VMs specifically as secondary worker (task) nodes to reduce cost. Compute Engine (A) is correct because Dataproc clusters are provisioned on Compute Engine VM instances, so the underlying compute for master, primary, and preemptible secondary workers is Compute Engine. Cloud Storage (C) is correct because Dataproc uses Cloud Storage (gs://) as its default Hadoop-compatible file system (via the Cloud Storage connector), letting the workload store input/output data durably and cheaply instead of HDFS on persistent disks.

BigQuery (D) is not appropriate here because it is a serverless analytics data warehouse, not a platform for running YARN/Spark applications. Dataflow (E) is also not appropriate because it is a managed Apache Beam runner for data pipelines, not a Hadoop/Spark YARN cluster environment.

Exam trap

GCDL often tests the trap of selecting BigQuery or Dataflow for Hadoop/Spark workloads, when only Dataproc (with Compute Engine and Cloud Storage) supports YARN-based Spark/Hadoop jobs.

100
MCQeasy

Which Google Cloud service allows you to run code in response to events (e.g., file upload to Cloud Storage) without provisioning servers?

A.Cloud Functions
B.App Engine
C.Compute Engine
D.Google Kubernetes Engine
AnswerA

Cloud Functions is a serverless, event-driven compute service that executes code in response to specific triggers. It natively integrates with Google Cloud services such as Cloud Storage, Pub/Sub, and HTTP calls, automatically scaling the function instances as needed. You write and deploy a single-purpose function, and the platform handles the underlying infrastructure, so no server provisioning or cluster management is required. This makes it the direct answer for running code in response to events like a file upload or a message published to a topic.

Why this answer

Cloud Functions is Google Cloud's serverless Functions-as-a-Service (FaaS) platform. It executes small, single-purpose code snippets in response to events from sources like Cloud Storage object finalization, Pub/Sub messages, or HTTP requests, with no server provisioning or management required. The service automatically scales based on event volume and bills only for execution time, making it the canonical answer for event-driven, serverless compute.

Exam trap

The trap here is confusing serverless compute services: candidates may pick App Engine because it is also serverless, but App Engine is for long-running web apps, not event-driven functions; or they may pick GKE because it can run containers, but it requires cluster management.

How to eliminate wrong answers

Option B is wrong because App Engine is a Platform-as-a-Service (PaaS) for deploying full web applications and services; while it is serverless in the sense that it abstracts infrastructure, it is not designed for small, event-triggered functions and does not natively bind to Cloud Storage events as a trigger. Option C is wrong because Compute Engine provides Infrastructure-as-a-Service (IaaS) virtual machines, which require you to provision, configure, and manage the underlying VMs and their operating systems. Option D is wrong because Google Kubernetes Engine is a managed Kubernetes container orchestration service; it requires you to define clusters, nodes, and workloads, and it is not a serverless event-driven function platform.

101
MCQmedium

A media company needs to stream live video to global viewers with low latency. They also want to protect against DDoS attacks. Which combination of Google Cloud networking services should they use?

A.Cloud Interconnect and Cloud VPN
B.Cloud CDN and Cloud Armor
C.Cloud DNS and Cloud Armor
D.Cloud Load Balancing and Cloud NAT
AnswerB

Cloud CDN accelerates live video by caching video segments at Google's hundreds of edge PoPs, minimizing latency for global viewers even during stream spikes. Cloud Armor complements this by enforcing DDoS protection and security policies at the edge, blocking malicious traffic before it reaches the origin. This pairing delivers both performance and security, making it the correct solution for global live streaming.

Why this answer

Cloud CDN and Cloud Armor together provide low-latency global content delivery and DDoS protection. Cloud CDN caches content at edge locations to reduce latency for global viewers, while Cloud Armor provides WAF and DDoS protection at the edge. This combination directly addresses the requirements.

Exam trap

GCDL often tests the confusion between services for private connectivity (Interconnect/VPN) and services for public content delivery and security (CDN/Armor).

How to eliminate wrong answers

Option A is wrong because Cloud Interconnect and Cloud VPN are for private connectivity between on-premises and GCP, not for global content delivery or DDoS protection. Option C is wrong because Cloud DNS and Cloud Armor provide DNS and DDoS protection but do not accelerate content delivery for live video. Option D is wrong because Cloud Load Balancing and Cloud NAT provide load balancing and outbound NAT, but not CDN caching or DDoS protection.

102
MCQhard

A data engineer needs to process a continuous stream of clickstream events from multiple sources, aggregate them into 1-minute windows, and write the results to BigQuery for real-time dashboarding. The solution must handle exactly-once processing semantics. Which combination of services should they use?

A.Pub/Sub -> Dataflow -> BigQuery
B.Pub/Sub -> Cloud Functions -> BigQuery
C.Cloud Storage -> Dataflow -> BigQuery
D.Pub/Sub -> Cloud Dataproc -> BigQuery
AnswerA

Dataflow's unified streaming engine natively supports exactly-once processing via commit-and-finish plus its shuffle, and it provides event-time windowing and trigger strategies for late data. Its built-in BigQuery sink batches streaming records into load jobs, making this pipeline the recommended way to continuously ingest Pub/Sub events into BigQuery for clickstream analytics.

Why this answer

Dataflow (Apache Beam) provides exactly-once processing semantics and can read from Pub/Sub, apply windowed aggregations, and write to BigQuery. Pub/Sub is the ingestion layer for streaming events. Cloud Functions and Cloud Run are not designed for stateful windowed aggregations at scale, and Cloud Dataproc (Hadoop/Spark) would require more overhead.

103
MCQeasy

A developer wants to deploy a containerized web application that can scale to zero when not in use, and only pay for actual request processing time. Which Google Cloud compute service should the developer use?

A.Cloud Functions
B.Cloud Run
C.Compute Engine
D.Google Kubernetes Engine (GKE)
AnswerB

Cloud Run is the correct service because it directly executes any OCI-compliant container image on a fully managed, serverless infrastructure, eliminating the need to manage servers or clusters. It scales from zero to thousands of active instances in response to inbound HTTP requests, and charges only for the compute resources used while each request is being processed, plus a brief instance-startup window. This makes it ideal for a containerized web application: you retain portability and control over the runtime environment while benefiting from automatic TLS termination, revision traffic splitting, and the ability to scale down to literally zero when idle.

Why this answer

Cloud Run is a serverless container runtime that scales to zero and charges per request, ideal for containerized apps with variable traffic. Cloud Functions is for smaller code snippets, not containers. Compute Engine runs VMs continuously, and GKE requires at least one node.

104
MCQmedium

A company runs a batch processing workload every night that can tolerate interruptions. The workload runs on Compute Engine VMs and takes 2 hours to complete. They want to reduce costs. Which VM pricing model should they use?

A.Preemptible VMs
B.Committed use discounts
C.Sole-tenant nodes
D.Sustained use discounts
AnswerA

Preemptible VMs run on Google's surplus compute capacity and are available at up to 60–80% lower per-second cost than standard VMs. They can be reclaimed at any time and have a maximum runtime of 24 hours, making them ideal for idempotent, fault-tolerant batch processing. A nightly job can simply be restarted or resumed from a checkpoint if interrupted.

Why this answer

Preemptible VMs offer significant cost savings (up to 80% discount) but can be terminated at any time. Since the workload is batch and can tolerate interruptions, this is the most cost-effective choice.

105
MCQhard

An online retailer stores product images in a Cloud Storage bucket. Current access patterns: images uploaded once and read frequently for 30 days, then accessed rarely after 90 days, and must be retained for 7 years for compliance. Which storage class transition strategy minimizes cost while meeting requirements?

A.Upload to Nearline, lifecycle rule to Archive at 30 days
B.Upload to Standard, lifecycle rule to Nearline at 30 days, then to Archive at 90 days
C.Upload to Standard, lifecycle rule to Nearline at 30 days, then to Coldline at 90 days
D.Upload to Standard, lifecycle rule to Coldline at 30 days, then to Archive at 90 days
AnswerB

This plan matches lifecycle costs to actual access patterns. Product images are updated and viewed frequently in the first month, making Standard the low-cost choice; between day 30 and day 90, access drops to occasional reporting or past-order lookups, so Nearline reduces storage price while keeping retrieval fees reasonable; after 90 days, images become archival and rarely accessed, and Archive's roughly $0.0012/GB pricing is the cheapest option. Lifecycle rules automate both transitions, minimizing operational overhead.

Why this answer

The optimal strategy is to upload to Standard (for frequent access in the first 30 days), then transition to Nearline at 30 days (for infrequent access but still low latency), and finally to Archive at 90 days (for long-term retention at lowest cost). This matches the access pattern: frequent reads for 30 days, rare access after 90 days, and 7-year retention. Archive is the cheapest storage class for long-term retention, and transitioning at 90 days aligns with the change in access frequency.

Exam trap

GCDL often tests lifecycle transition strategies, and candidates may choose the cheapest storage class immediately without considering access patterns and minimum storage durations.

How to eliminate wrong answers

Option A is wrong because uploading directly to Nearline would incur higher access costs during the first 30 days when images are read frequently; Nearline has lower storage cost but higher access cost and is designed for data accessed less than once per month. Option C is wrong because transitioning to Coldline at 90 days instead of Archive would be more expensive for long-term storage; Coldline is for data accessed less than once per year, but Archive is cheaper for 7-year retention. Option D is wrong because transitioning to Coldline at 30 days would be premature since data is still accessed frequently until 30 days, and Coldline has higher access costs; also, the subsequent transition to Archive at 90 days is not specified, but the initial transition to Coldline at 30 days is suboptimal.

106
MCQhard

A team is using Cloud Build to build container images and push them to Artifact Registry. The build process involves sensitive dependencies that should not be exposed to the internet. The team wants to ensure that all builds execute on a private network without public IP addresses. What should the team configure?

A.Set up Cloud NAT for the Cloud Build workers
B.Configure Artifact Registry with VPC Service Controls
C.Use a private pool in Cloud Build
D.Connect the Cloud Build service account to a shared VPC
AnswerC

A private pool in Cloud Build runs workers in a VPC network that you control, and these worker instances are provisioned without public IP addresses. Because they are internal-only, builds can pull source code from private repositories and push images to Artifact Registry without ever traversing the public internet or exposing the workers. This directly satisfies the requirement to remove public IPs while still allowing secure access to private resources.

Why this answer

Cloud Build supports private pools that provide workers in a customer-managed VPC network, allowing builds to run without public IP addresses and access internal resources. Connecting the project to a shared VPC only enables network access but workers still have public IPs unless private pools are used. Using Artifact Registry VPC-SC perimeters helps secure the registry but not the build workers.

Cloud NAT provides outbound internet but does not remove public IPs from workers.

107
MCQmedium

A company runs a video processing application that triggers a function each time a new video is uploaded to Cloud Storage. The function transcodes the video and stores the result. Which compute service is BEST suited for this event-driven workload?

A.Compute Engine
B.Google Kubernetes Engine (GKE)
C.Cloud Functions
D.Cloud Run
AnswerC

Cloud Functions is a serverless Functions-as-a-Service platform with first-class support for Cloud Storage triggers (e.g., object finalize). When a video file is uploaded, a function is invoked automatically, scales from zero to handle the event, and charges only for execution time. No infrastructure provisioning or 24/7 VM is needed, making it the ideal lightweight, event-driven compute choice for this exact use case.

Why this answer

Cloud Functions is Google Cloud's event-driven FaaS product, natively integrated with Cloud Storage object-finalize events via Eventarc, making it the canonical choice for 'run code when a file lands in a bucket.' It handles the trigger wiring, retries, and scaling automatically, so the developer only writes the transcoding logic. Cloud Run can also be event-driven via Eventarc, but Cloud Functions is the purpose-built, lowest-friction option for this pattern.

Exam trap

The trap here is that Cloud Run also supports event triggers via Eventarc, so candidates who know that fact may second-guess the obvious Cloud Functions answer — but the exam asks for the BEST fit, and Cloud Functions is the purpose-built FaaS for Cloud Storage events.

How to eliminate wrong answers

Option A is wrong because Compute Engine VMs are not event-driven; you would have to build your own polling or webhook listener and manage the OS, which is overkill for a simple object-created trigger. Option B is wrong because GKE is a container orchestration platform that requires you to deploy and manage workloads, node pools, and event plumbing — far more operational overhead than the workload warrants. Option D is wrong because although Cloud Run supports Eventarc triggers, it is a container-based service that requires packaging the function into a container image and is not the 'best' fit when a first-class FaaS trigger already exists.

108
MCQmedium

An engineer needs to distribute incoming HTTP traffic across multiple backend VM instances in different regions, with automatic failover and SSL termination. Which load balancing product should they use?

A.Cloud CDN
B.Cloud Load Balancing
C.Cloud NAT
D.Cloud Armor
AnswerB

Cloud Load Balancing is the correct choice for distributing incoming HTTP traffic across backend instances or services. It provides global, anycast-based HTTP(S) load balancing with a single virtual IP, enabling traffic to be routed to the nearest healthy backend across regions. It also offers SSL/TLS offloading, autoscaling, health checks, and failover, making it the appropriate service for high-availability traffic distribution.

Why this answer

Cloud Load Balancing is Google Cloud's fully managed, software-defined load balancing service that supports global anycast IPs, cross-region backend distribution, automatic failover via health checks, and SSL/TLS termination at the load balancer. It handles HTTP(S) traffic across VM instances in multiple regions with a single global IP, which matches every requirement in the scenario.

Exam trap

The trap here is confusing adjacent networking services — candidates pick Cloud CDN or Cloud Armor because they sound like traffic services, but only Cloud Load Balancing actually distributes and terminates traffic.

How to eliminate wrong answers

Option A is wrong because Cloud CDN is a content delivery/caching layer that sits in front of a load balancer; it does not itself distribute traffic across backends or perform failover. Option C is wrong because Cloud NAT provides outbound internet access for private instances and does not handle inbound HTTP load balancing. Option D is wrong because Cloud Armor is a WAF/DDoS protection service that attaches to a load balancer; it filters traffic but does not balance or terminate SSL.

109
MCQeasy

A developer wants to deploy a containerized web application that automatically scales to zero when not in use, and they want to minimize operational overhead. Which compute service should they use?

A.Google Kubernetes Engine (GKE)
B.Compute Engine
C.Cloud Run
D.App Engine Flexible Environment
AnswerC

Cloud Run is a fully managed, serverless compute platform that executes stateless containers in response to HTTP requests. It automatically scales instances from zero up to handle traffic spikes and back down to zero when idle, so you pay only for the CPU and memory consumed during request processing—with no charge for idle-time zero-instance periods. Because Cloud Run abstracts away all infrastructure, you don't need to manage clusters, nodes, or virtual machines; you simply deploy a container image and let the service handle scaling, availability, and load balancing. This makes Cloud Run the ideal choice for a containerized web application with variable or intermittent traffic, providing minimal operational overhead and granular per-request billing.

Why this answer

Cloud Run is a fully managed serverless container platform that runs containers on demand, scales automatically including to zero when there is no traffic, and requires no cluster or infrastructure management. This directly satisfies the requirements of automatic scale-to-zero and minimal operational overhead. It is the only option purpose-built for serverless container execution.

Exam trap

GCDL often tests the distinction between serverless container platforms and managed Kubernetes, tempting candidates toward GKE because it also runs containers, while overlooking that GKE does not scale to zero and carries significant operational overhead.

How to eliminate wrong answers

Option A is wrong because GKE is a managed Kubernetes service that requires cluster configuration, node pool management, and does not scale to zero by default — it incurs cost and operational overhead even when idle. Option B is wrong because Compute Engine provides raw virtual machines that run continuously, require OS patching and capacity management, and do not scale to zero automatically. Option D is wrong because App Engine Flexible Environment runs containers on managed VMs that do not scale to zero and carry higher baseline cost and slower scaling than the standard serverless model.

110
MCQmedium

A developer is deploying a web application on Compute Engine and needs to distribute traffic across multiple VM instances in different regions. They also need SSL termination and health checks. Which Google Cloud networking service should they use?

A.Cloud Load Balancing
B.VPC peering
C.Cloud Armor
D.Cloud CDN
AnswerA

Cloud Load Balancing, specifically the HTTP(S) Load Balancer, is a global Layer 7 solution that terminates SSL/TLS at Google's edge, distributes traffic across managed instance groups, and performs regular health checks to automatically route around failed backends. It supports content-based routing, autoscaling, and is a fully managed service.

Why this answer

Cloud Load Balancing (HTTP(S) Load Balancer) is a global, scalable load balancing service that distributes traffic across instance groups in multiple regions, provides SSL termination, and performs health checks. Cloud CDN is for caching content; Cloud Armor is for security policies; VPC peering connects networks.

111
MCQmedium

A company needs to store petabytes of time-series IoT sensor data and query it with single-digit millisecond latency at millions of reads per second. The data has a simple key-value structure with timestamps. Which Google Cloud database is MOST appropriate?

A.Cloud Spanner
B.Cloud Bigtable
C.BigQuery
D.Firestore
AnswerB

Cloud Bigtable is a fully managed, wide-column NoSQL database built specifically for large-scale analytical and operational workloads, including time-series and IoT sensor data. It stores data as sparse rows keyed by a row key (typically device ID and timestamp), enabling single-digit millisecond read/write latency at massive scale. Bigtable scales horizontally by adding nodes to handle millions of queries per second without downtime, and its native integration with Cloud BigQuery, Dataflow, and Pub/Sub makes it the ideal choice for petabyte-scale sensor data ingestion and retrieval.

Why this answer

Cloud Bigtable is designed for petabyte-scale, low-latency, high-throughput NoSQL storage for time-series, IoT, and financial data. It scales horizontally by adding nodes.

112
MCQmedium

A data science team needs to train a custom machine learning model using their own data. They want a unified platform that manages the entire ML lifecycle, including data preparation, training, tuning, and deployment. Which service should they use?

A.AutoML
B.Vertex AI
C.AI Platform
D.Cloud Functions
AnswerB

Vertex AI is Google Cloud's unified MLOps platform, designed to handle the entire ML lifecycle: data labeling, feature engineering, custom training with any framework (TensorFlow, PyTorch, etc.), hyperparameter tuning, model versioning, and serving through endpoints. It integrates services like Vertex AI Feature Store, Vertex AI TensorBoard, and Model Monitoring, enabling end-to-end management. For a data science team needing to train and deploy a custom model, Vertex AI provides the essential, scalable infrastructure.

Why this answer

Vertex AI is Google Cloud's unified ML platform that covers the full lifecycle from data to deployment.

113
MCQhard

A company is running a stateful web application on Compute Engine with a SQL database. They want to use Cloud Load Balancing to distribute traffic across multiple instances in different zones. The application stores session state locally on each VM. Users report that after being directed to a different instance, their session is lost. What is the most suitable solution to maintain session persistence?

A.Store session state in Cloud SQL and share across instances
B.Configure Cloud CDN to cache session data
C.Use a global load balancer with HTTP cookies to track sessions
D.Enable session affinity (sticky sessions) on the load balancer
AnswerD

Enabling session affinity (sticky sessions) on the load balancer ensures that all requests from a given client during a session are routed to the same backend instance, as long as that instance remains healthy. This preserves the in-memory session state because the application can store session data locally on the instance, and subsequent requests are consistently directed to that same machine. The load balancer typically uses a hash of the client's IP address or a generated cookie to determine the backend, while still balancing load across different sessions. This directly solves the problem of a stateful web application without needing to externalize or replicate session state.

Why this answer

Cloud Load Balancing supports session affinity (sticky sessions) based on client IP or HTTP cookie, which directs a user to the same backend instance. Moving session state to a central database (Cloud SQL) or Memorystore also works but changes the application. Enabling HTTP cookies is a client-side solution not reliable.

Using a header-based approach is less common.

114
MCQhard

A company uses Cloud Functions to process image uploads. Each image triggers a function that uses Vision API to extract text and stores results in Firestore. The function sometimes fails due to timeout when images are large. How should they redesign for reliability and scale?

A.Use Cloud Tasks with Cloud Run to process images asynchronously
B.Use Cloud Scheduler to trigger the function every minute
C.Increase the function timeout to 60 minutes
D.Use Compute Engine VMs with startup scripts
AnswerA

Cloud Tasks decouples the image processing workload from the Cloud Function trigger, immediately returning a response to the client. Each upload is enqueued as a task that Cloud Run processes asynchronously, allowing you to configure timeouts up to 60 minutes or more. Cloud Run also scales to zero when idle, so you only pay for the processing time, and Cloud Tasks provides automatic retries for transient failures.

Why this answer

Redesigning to use Cloud Tasks with Cloud Run allows asynchronous processing of image uploads. Cloud Tasks can queue the work and trigger Cloud Run services, which can scale independently and have longer timeouts (up to 60 minutes). This decouples the upload from processing, improving reliability and scalability, and avoids Cloud Functions' timeout limits.

Exam trap

GCDL often tests the misconception that increasing timeout on Cloud Functions solves timeout issues, when the correct approach is to use a service with longer timeouts and asynchronous processing like Cloud Run with Cloud Tasks.

How to eliminate wrong answers

Option B is wrong because using Cloud Scheduler to trigger the function every minute does not address the timeout issue; it just polls periodically and may still fail on large images. Option C is wrong because increasing the function timeout to 60 minutes is not possible; Cloud Functions has a maximum timeout of 9 minutes (for 2nd gen, 60 minutes for HTTP functions, but for background functions it's 9 minutes). Even if possible, it's not a scalable solution.

Option D is wrong because using Compute Engine VMs with startup scripts introduces significant operational overhead and does not provide automatic scaling or event-driven processing.

115
MCQmedium

A company wants to analyze petabytes of sales data using SQL queries with sub-second response times for dashboards. They need a fully managed, serverless solution that separates storage and compute. Which service meets these requirements?

A.BigQuery
B.Cloud SQL
C.Cloud Spanner
D.Dataflow
AnswerA

BigQuery is a serverless, fully managed data warehouse with columnar storage and a distributed execution engine, purpose-built for petabyte-scale SQL analytics. It separates compute from storage, enabling sub-second interactive queries over massive datasets without provisioning clusters. Its native support for standard SQL, partitioning, and clustering makes it the ideal service for analyzing petabytes of sales data.

Why this answer

BigQuery is a fully managed, serverless, petabyte-scale data warehouse that separates storage and compute, and supports SQL queries with sub-second response times for dashboards via its columnar storage and slot-based execution. It requires no infrastructure management and scales automatically. These characteristics match the stated requirements exactly.

Exam trap

The trap is confusing OLTP databases (Cloud SQL, Spanner) with OLAP warehouses — candidates may pick Spanner for scale, but it is not an analytics engine and lacks sub-second dashboard query performance for petabyte scans.

How to eliminate wrong answers

Option B is wrong because Cloud SQL is a managed relational database for OLTP workloads, not designed for petabyte-scale analytics or sub-second dashboard queries. Option C is wrong because Cloud Spanner is a globally distributed, strongly consistent OLTP database, not an analytics warehouse, and is not serverless in the same sense. Option D is wrong because Dataflow is a stream/batch processing service, not a SQL query engine for interactive dashboards.

116
MCQmedium

An organisation needs to run a batch analytics job every night that processes terabytes of data stored in Cloud Storage. The job is expected to run for 3 hours and can tolerate interruptions. The compute resources should be as cost-effective as possible. Which Compute Engine VM type should be used?

A.Standard (on-demand) VMs
B.Custom machine types
C.Preemptible VMs
D.Sole-tenant nodes
AnswerC

Preemptible VMs offer up to an 80% discount compared to on-demand instances but may be terminated by Compute Engine at any time, with a maximum runtime of 24 hours. Since the nightly analytics job is batch-oriented and fault-tolerant, it can handle these interruptions via restart or checkpointing, making preemptible VMs the most cost-effective and appropriate choice. This aligns the compute pricing model with the workload's tolerance for interruption.

Why this answer

Preemptible VMs are significantly cheaper than standard VMs and are ideal for batch jobs that can tolerate interruptions. They can be preempted at any time but can be restarted. Standard VMs are for long-running, fault-intolerant workloads.

Sole-tenant nodes are for compliance, not cost savings. Custom machine types allow tailoring resources but do not inherently save cost like preemptible VMs.

117
MCQhard

An engineer is deploying a globally distributed application that requires strong consistency across multiple continents with a 99.999% uptime SLA. The data model is relational with SQL queries. Which database service should they use?

A.Cloud Spanner
B.Firestore in multi-region mode
C.Cloud SQL with cross-region replication
D.Bigtable with replication
AnswerA

Cloud Spanner is a fully managed, horizontally scalable relational database that combines standard SQL transactions with globally distributed replication. It uses TrueTime (a globally synchronized clock) and Paxos consensus to provide strong external consistency across all regions, meaning reads and writes are always linearizable even during failovers. With a 99.999% availability SLA and the ability to write from any region, it is the only option among these that supports globally consistent relational data at scale.

Why this answer

Cloud Spanner is the only Google Cloud database that provides globally distributed, strongly consistent relational data with a 99.999% SLA.

118
MCQhard

A data engineering team is building a streaming pipeline that ingests clickstream events from a website, processes them in real-time (e.g., aggregations, filtering), and loads the results into BigQuery for analysis. They also need the ability to replay events in case of failures. Which combination of services is MOST appropriate for the streaming ingestion and processing?

A.Cloud Storage and Cloud Functions
B.Pub/Sub and Cloud Dataflow
C.Pub/Sub and Cloud Functions
D.Apache Kafka on Compute Engine
AnswerB

Pub/Sub provides a fully managed, asynchronous messaging service with durable message retention, at-least-once delivery, and replay support, enabling reliable, scalable stream ingestion with no operators. Cloud Dataflow, built on Apache Beam, processes streams in real time and supports event-time processing, watermarks, windowing, and exactly-once semantics, making it suitable for complex transformations, aggregations, and stateful analytics. As a fully managed service, it also autoscales and seamlessly integrates with GCP and open-source ecosystems, so this combination is the intended architecture for real-time stream processing on GCP.

Why this answer

Pub/Sub for ingestion allows event replay (by setting a subscription's retention), and Dataflow for stream processing handles real-time transformations and writes to BigQuery.

119
MCQmedium

An organization needs to store archival data that must be retained for 10 years and is accessed less than once a year. Which Cloud Storage class offers the lowest storage cost?

A.Archive
B.Standard
C.Coldline
D.Nearline
AnswerA

Archive is the correct storage class because it is the lowest-cost option for long-term retention, designed specifically for data accessed less than once per year. It enforces a 365-day minimum storage duration, which aligns with archival retention needs where retrieval is rare and latency is acceptable. Its pricing model minimizes storage cost at the expense of higher retrieval fees, making it the most economical choice for compliance or forensic archives.

Why this answer

Archive is the lowest-cost storage class in Google Cloud Storage, designed for data accessed less than once a year and retained for long periods (minimum 365 days). It offers the cheapest storage price per GB, making it ideal for 10-year archival data with rare access.

Exam trap

GCDL often tests the confusion between Coldline and Archive, as both are for infrequent access; candidates may incorrectly choose Coldline thinking it's the cheapest, but Archive is specifically the lowest-cost option for data accessed less than once a year.

How to eliminate wrong answers

Option B is wrong because Standard is the most expensive storage class, optimized for frequently accessed data with no minimum storage duration. Option C is wrong because Coldline is more expensive than Archive and is intended for data accessed less than once a year but with a 90-day minimum; it does not offer the absolute lowest cost. Option D is wrong because Nearline is for data accessed less than once a month, with a 30-day minimum, and is significantly more expensive than Archive.

120
MCQeasy

What is the primary purpose of Google Cloud Armor?

A.To accelerate content delivery globally
B.To protect applications from DDoS attacks and application-level threats
C.To provide outbound internet connectivity to private instances
D.To manage virtual private cloud networking
AnswerB

Cloud Armor provides built-in protections against volumetric DDoS attacks and a web application firewall (WAF) to block OWASP Top 10 threats like SQL injection and cross-site scripting. It uses preconfigured rules and adaptive protection to filter malicious traffic at the edge, only forwarding legitimate requests to backend services. This makes it the primary DDoS and application-layer security service for applications fronted by Cloud Load Balancing.

Why this answer

Google Cloud Armor is a security service that provides DDoS protection and WAF capabilities for applications behind Google Cloud load balancers. It filters malicious traffic at the edge, protecting against Layer 3/4 DDoS and Layer 7 application attacks like SQL injection and XSS. It is the primary tool for edge security in GCP.

Exam trap

GCDL often tests the confusion between Cloud Armor (security/DDoS) and Cloud CDN (performance) or Cloud NAT (outbound connectivity), tricking candidates who associate 'edge' services with content delivery rather than protection.

How to eliminate wrong answers

Option A is wrong because accelerating content delivery globally is the role of Cloud CDN, not Cloud Armor — Cloud Armor focuses on security, not performance. Option C is wrong because providing outbound internet connectivity to private instances is handled by Cloud NAT, which allows instances without public IPs to reach the internet. Option D is wrong because managing VPC networking is the function of VPC, subnets, firewalls, and Cloud Router — Cloud Armor is a security policy layer, not a networking management service.

121
MCQhard

An organization runs a multi-region web application behind a global external HTTP(S) load balancer. They want to protect against DDoS attacks and filter traffic based on IP reputation and request headers. Which service should they integrate with the load balancer?

A.Cloud Armor
B.Cloud CDN
C.VPC firewall rules
D.Cloud NAT
AnswerA

Cloud Armor is the correct choice because it provides web application firewall (WAF) capabilities, DDoS protection, and IP reputation filtering at the global edge, directly integrated with Cloud Load Balancing. It can inspect HTTP(S) traffic, block malicious requests based on Layer 7 attributes like headers and body, and enforce allow/deny lists based on IP addresses and geolocation. This gives the organization precise, policy-based control over incoming traffic before it reaches backend instances.

Why this answer

Cloud Armor is Google Cloud's edge security service that attaches to global external HTTP(S) load balancers and provides WAF rules, IP reputation/denylists, geo-blocking, and header-based filtering. It's the native integration point for DDoS and Layer 7 filtering at the load balancer.

Exam trap

GCDL often tests whether candidates confuse Cloud CDN (caching) with Cloud Armor (security) — both sit at the edge but only Cloud Armor filters traffic.

How to eliminate wrong answers

Option B is wrong because Cloud CDN caches content at the edge — it improves latency and offloads origin traffic but does not filter based on IP reputation or headers. Option C is wrong because VPC firewall rules operate at the network/VPC layer (L3/L4) and cannot inspect HTTP headers or apply IP-reputation logic at the global edge. Option D is wrong because Cloud NAT provides outbound internet access for private instances; it has no inbound filtering role.

122
MCQmedium

A company has a batch processing job that runs once per day and can be interrupted without significant impact. They want to reduce costs by using Google Cloud infrastructure. Which compute option should they choose?

A.Standard persistent disk
B.Preemptible VMs
C.Sustained use discounts
D.Custom machine types
AnswerB

Preemptible VMs are instances that run on Google Cloud's surplus capacity at a fraction of the normal cost, often up to 80% cheaper. They can be terminated abruptly by Google Cloud, but a batch job that runs only once per day and can tolerate interruptions is an ideal candidate. By designing the job to restart or resume from checkpoints, the company can achieve substantial cost savings while maintaining reliability.

Why this answer

Preemptible VMs offer significant cost savings (up to 60-91% discount) but can be terminated at any time by Google. They are ideal for fault-tolerant batch jobs. Spot VMs are similar but with a newer pricing model (no maximum runtime).

Both are good, but Preemptible is the classic answer. Custom machine types are not cost-saving by themselves; standard VMs are more expensive.

123
MCQeasy

Which Google Cloud service provides a fully managed, scalable data warehouse for running SQL queries on petabyte-scale data and supports BI tools like Looker?

A.BigQuery
B.Cloud SQL
C.Cloud Storage
D.Dataflow
AnswerA

BigQuery is Google Cloud's serverless, fully managed data warehouse built on a columnar storage format and the Dremel massively parallel query engine, letting you run SQL over petabytes without provisioning. Its compute and storage are decoupled, so it scales elastically and you pay only for queries and stored data; native Looker integration and BI Engine in-memory acceleration directly support analytical workloads. That combination of serverless scalability, ANSI SQL, and built-in BI connectivity is what makes it the correct answer.

Why this answer

BigQuery is a serverless data warehouse that scales to petabytes and uses SQL for analytics. Cloud SQL is for OLTP, Cloud Storage is object storage, and Dataflow is for data processing pipelines.

124
MCQmedium

A startup is building a mobile app and needs to store user profiles and preferences. The data is hierarchical and the app requires real-time synchronization across devices. Which Google Cloud database should they use?

A.Cloud Spanner
B.Firestore
C.Cloud Bigtable
D.Cloud SQL
AnswerB

Cloud Firestore is a flexible, serverless NoSQL document database designed specifically for mobile and web clients, with real-time synchronization via listen callbacks and automatic offline data persistence. Its hierarchical data model organizes user profiles naturally as documents within collections, and security rules integrate directly with client SDKs. Unlike global SQL options, Firestore provides built-in multi-device sync and conflict handling, making it the ideal fit for a mobile app storing user profiles.

Why this answer

Firestore is a NoSQL document database designed for mobile apps, with real-time sync and offline support. Cloud SQL and Spanner are relational, not ideal for hierarchical data. Bigtable is for time-series/analytics, not mobile app data.

125
MCQeasy

What is the primary benefit of using preemptible VMs on Compute Engine?

A.Support for live migration
B.Higher performance than standard VMs
C.Guaranteed availability of resources
D.Cost savings for fault-tolerant workloads
AnswerD

Preemptible VMs cost up to 80% less than standard VMs, making them ideal for fault-tolerant workloads that can survive instance termination, such as batch data processing, rendering, or stateless web serving. This cost benefit is the primary purpose of using them, not performance or availability, and it enables large-scale compute tasks under a constrained budget.

Why this answer

Preemptible VMs on Compute Engine are deeply discounted (up to 60-91% off on-demand) but can be terminated by Google at any time with a 30-second warning, making them ideal for fault-tolerant, stateless, or batch workloads that can tolerate interruption. The primary benefit is therefore cost savings for workloads designed to handle preemption. They are not for guaranteed-availability or high-performance use cases.

Exam trap

The trap is associating 'preemptible' with performance or availability benefits — candidates who don't know the term may pick 'higher performance' or 'guaranteed availability' instead of recognizing it as a cost-optimization feature for interruptible workloads.

How to eliminate wrong answers

Option A is wrong because live migration is a feature of standard (non-preemptible) VMs that allows Google to migrate a running instance during host maintenance without downtime — preemptible VMs are explicitly terminated rather than migrated. Option B is wrong because preemptible VMs use the same underlying hardware as standard VMs and offer no performance advantage; they are simply cheaper and interruptible. Option C is wrong because preemptible VMs offer the opposite of guaranteed availability — Google can reclaim them at any time, and they are automatically terminated after 24 hours.

126
MCQeasy

A startup is building a mobile app and needs a real-time database that synchronises data across user devices automatically. The data model is document-based, and the app needs offline support. Which database should they use?

A.Cloud Bigtable
B.Cloud SQL
C.Firestore
D.Memorystore
AnswerC

Firestore is a NoSQL document database with real-time synchronization built into its mobile SDKs, automatically pushing data changes to connected clients and persisting a local cache for offline operation. It resolves conflicts and syncs local writes when connectivity returns, enabling responsive, collaborative mobile experiences. Its flexible, schema-less document model maps naturally to app objects, making it the standard choice for real-time mobile apps.

Why this answer

Firestore is Google Cloud's serverless, document-oriented NoSQL database that provides real-time synchronization across devices via listeners, plus built-in offline persistence for mobile and web SDKs. Its document/collection data model and automatic multi-device sync directly match the startup's requirements.

Exam trap

GCDL often tests the difference between Firestore (document, real-time, offline) and Bigtable (wide-column, analytical) — candidates pick Bigtable for 'NoSQL' without checking the real-time sync and offline requirements.

How to eliminate wrong answers

Option A is wrong because Cloud Bigtable is a wide-column, HBase-compatible NoSQL store optimized for massive analytical and time-series workloads (millions of rows, low-latency reads at scale) — it has no real-time sync or offline mobile SDK. Option B is wrong because Cloud SQL is a managed relational database (MySQL, PostgreSQL, SQL Server) with a fixed schema, not a document model, and it lacks native real-time device synchronization. Option D is wrong because Memorystore is a managed Redis/Memcached in-memory cache, not a persistent document database with offline support.

← PreviousPage 2 of 2 · 126 questions total

Ready to test yourself?

Try a timed practice session using only Google Cloud Products and Services questions.