Courseiva

CCNA Cdl Google Cloud Products Questions

75 of 126 questions · Page 1/2 · Cdl Google Cloud Products topic · Answers revealed

1
MCQeasy

Which Google Cloud service is used for monitoring and alerting on the performance and health of cloud resources?

A.Cloud Monitoring
B.Cloud Logging
C.Cloud Profiler
D.Cloud Trace
AnswerA

Cloud Monitoring is Google Cloud's primary service for operational visibility and alerting. It ingests metrics from GCP and external sources, stores them in a time-series database, and evaluates alerting policies that can trigger notifications via email, SMS, Pub/Sub, or webhooks. It also offers built-in dashboards and the Metrics Explorer for real-time and historical performance analysis, making it the correct answer for monitoring and alerting.

Why this answer

Cloud Monitoring is Google Cloud's service for collecting metrics, creating dashboards, and configuring alerts on the performance and health of cloud resources. It integrates with services like Compute Engine, GKE, and Cloud Run to provide visibility and proactive notifications. This directly matches the requirement for monitoring and alerting.

Exam trap

The trap is confusing Cloud Monitoring with Cloud Logging or Cloud Trace — candidates often pick Logging because logs also indicate health, but the question specifically asks for monitoring and alerting on performance metrics.

How to eliminate wrong answers

Option B is wrong because Cloud Logging is designed for storing, searching, and analyzing log data, not for metric-based monitoring and alerting on resource health. Option C is wrong because Cloud Profiler continuously analyzes CPU and memory usage of applications to identify performance bottlenecks in code, not infrastructure health monitoring. Option D is wrong because Cloud Trace is a distributed tracing system for latency analysis across microservices, not a monitoring and alerting platform for resource health.

2
MCQmedium

A financial services company needs a relational database with global strong consistency, horizontal scaling, and 99.999% availability SLA. Which database should they choose?

A.Cloud Bigtable
B.Cloud Spanner
C.Cloud SQL
D.Firestore
AnswerB

Cloud Spanner is the only Google Cloud relational database that combines global scalability with strong consistency and ACID transactions, using synchronous replication and Paxos consensus across regions. It is specifically designed to deliver 99.999% availability SLA, meeting the financial services requirement for a globally distributed, strongly consistent relational database. With horizontal scaling and automatic sharding, it can handle massive transaction loads while maintaining external consistency.

Why this answer

Cloud Spanner is Google's globally distributed, horizontally scalable relational database that offers external consistency (strong consistency) and a 99.999% availability SLA for multi-region configurations. It is the only GCP database that combines relational semantics, horizontal scale, and global strong consistency at that SLA level.

Exam trap

GCDL often tests the SLA and consistency matrix across GCP databases — the trap is picking Bigtable for 'horizontal scale' or Firestore for 'global' without checking that only Spanner delivers relational + strong consistency + 99.999% SLA together.

How to eliminate wrong answers

Option A is wrong because Cloud Bigtable is a wide-column NoSQL store with single-row atomicity but no multi-row transactions or SQL relational semantics, and its SLA is 99.9% (or 99.99% for some configurations), not 99.999%. Option C is wrong because Cloud SQL is a managed MySQL/PostgreSQL/SQL Server instance that scales vertically, not horizontally, and its SLA is 99.95% with HA — it cannot provide global horizontal scale. Option D is wrong because Firestore is a document NoSQL database with strong consistency within a region but eventual consistency in multi-region modes for some query types, and it lacks relational joins and the 99.999% SLA.

3
MCQmedium

A company is migrating a PostgreSQL database to Google Cloud. They want high performance, AI-optimized capabilities, and compatibility with existing PostgreSQL tools. Which service should they choose?

A.Cloud Spanner
B.AlloyDB
C.Cloud SQL for PostgreSQL
D.Cloud Bigtable
AnswerB

AlloyDB satisfies the AI-optimised and high-performance constraints while remaining wire-compatible with PostgreSQL tooling. Its columnar engine and integrated Vertex AI extensions deliver the required analytical and AI capabilities, unlike standard Cloud SQL, which lacks these optimisations.

Why this answer

AlloyDB is a PostgreSQL-compatible database optimized for high performance and AI workloads, with built-in ML integration. Cloud SQL for PostgreSQL provides compatibility but lacks AI optimization. Spanner is a different architecture.

Bigtable is NoSQL.

4
MCQhard

A data scientist wants to train a custom machine learning model using their own data and deploy it for online predictions. They want a unified platform that manages the entire ML lifecycle from data preparation to model serving. Which service should they use?

A.Cloud Functions
B.Vertex AI
C.AutoML
D.AI Platform (Unified)
AnswerB

Vertex AI is the correct choice because it is Google Cloud's unified platform for building, training, and deploying ML models at scale. It provides a custom training service where you can launch training jobs with your own code, containers, and hardware accelerator configurations, and it manages compute clusters and automatically handles node provisioning. It also offers persistent online prediction endpoints, batch prediction, and integration with Vertex AI Pipelines for orchestration, making it ideal for a data scientist who needs full control.

Why this answer

Vertex AI is Google Cloud's unified machine learning platform that manages the entire ML lifecycle, including data preparation, training (custom or AutoML), model management, and deployment for online predictions. It provides a single environment for data scientists to build, deploy, and scale ML models. Unlike other options, Vertex AI integrates all necessary components such as Vertex AI Workbench, Training, Predictions, and Pipelines, making it the correct choice for end-to-end ML workflows.

Exam trap

GCDL often tests the distinction between unified ML platforms and individual services, causing candidates to confuse AutoML as a complete solution or overlook that AI Platform (Unified) is deprecated.

How to eliminate wrong answers

Option A is wrong because Cloud Functions is a serverless compute service for event-driven functions, not designed for ML lifecycle management or model serving. Option C is wrong because AutoML is a subset of Vertex AI that automates model building but does not provide a unified platform for the entire ML lifecycle, especially custom training and serving. Option D is wrong because AI Platform (Unified) was the previous name for Vertex AI; it is now deprecated and replaced by Vertex AI, so it is not the current service to use.

5
MCQhard

A company runs a global web application hosted on Compute Engine behind a Cloud Load Balancer. They want to protect against DDoS attacks and filter incoming traffic based on IP reputation and geolocation. Which Google Cloud service should they use?

A.Cloud CDN
B.Cloud NAT
C.Cloud Armor
D.VPC firewall rules
AnswerC

Cloud Armor is a managed edge security service that works directly with external HTTP(S) load balancers to protect applications from DDoS attacks and web-based threats. It provides a customizable Web Application Firewall (WAF) with OWASP Top 10 rules, IP allow/deny lists, rate limiting, IP reputation filters, and geography-based access control, making it the appropriate choice for blocking malicious traffic and enforcing regional access policies on a global web application.

Why this answer

Cloud Armor is a web application firewall (WAF) and DDoS protection service that integrates with Cloud Load Balancing. It allows IP allow/deny lists, rate limiting, and predefined rules to block traffic based on geo-location and threat intelligence. VPC firewall rules operate at the network level but cannot inspect application-layer traffic or use IP reputation.

Cloud CDN caches content but does not filter traffic. Cloud NAT provides outbound connectivity only.

6
MCQhard

An organization needs to run a batch process every night that analyzes terabytes of data from Cloud Storage and writes results back to BigQuery. The job is not time-sensitive and can be preempted. Which compute approach is most cost-effective?

A.Cloud Functions with background trigger
B.Compute Engine with preemptible VMs
C.Google Kubernetes Engine with standard nodes
D.Cloud Run with manual scaling
AnswerB

Preemptible VMs on Compute Engine are the right choice for a nightly batch process because they are up to 80% cheaper than standard VMs, which directly reduces operational cost for a recurring, interruptible workload. Since batch jobs are inherently fault-tolerant—they can be checkpointed or simply rerun from the start—the risk of preemption is acceptable, and Google Cloud automatically restarts the VM if capacity is available. For a simple scheduled job, a preemptible VM is a low-complexity, high-savings solution.

Why this answer

Preemptible VMs on Compute Engine offer the lowest cost for fault-tolerant batch workloads because they are up to 80% cheaper than regular VMs but can be terminated at any time. Cloud Run has a request timeout limit and is not ideal for long-running batch jobs. GKE with preemptible nodes is also cost-effective but requires Kubernetes expertise and is more complex than simply using preemptible VMs.

Cloud Functions has a timeout limit.

7
Multi-Selectmedium

A company wants to deploy a web application that automatically scales based on traffic, and they do not want to manage infrastructure. The application is written in Python and uses a Flask framework. Which TWO Google Cloud services could they use?

Select 2 answers
A.Google Kubernetes Engine
B.Cloud Functions
C.Cloud Run
D.Compute Engine
E.App Engine Standard
AnswersC, E

Cloud Run is a fully managed serverless container platform that can run any containerized HTTP service, including a Flask web application. It automatically scales from zero to handle traffic, scaling up as requests increase and scaling down to zero when idle, so you only pay for resources used during request processing. Unlike GKE, Cloud Run abstracts away cluster management entirely, making it ideal for a containerized Flask app that needs automatic scaling with minimal operational effort.

Why this answer

Cloud Run (C) is correct because it is a fully managed serverless platform that runs containerized applications, automatically scales out and back to zero based on traffic, and requires no infrastructure management, making it ideal for a Python Flask app packaged in a container. App Engine Standard (E) is also correct because it is a fully managed serverless PaaS that natively supports Python and Flask, automatically scales instances with traffic, and abstracts away all server management. The other options do not fit: Google Kubernetes Engine (A) requires managing cluster infrastructure and nodes, Compute Engine (D) is raw IaaS where the company must manage VMs and scaling itself, and Cloud Functions (B) is designed for event-driven, single-purpose functions rather than hosting a full Flask web application.

Exam trap

GCDL often tests the distinction between serverless and managed services, tricking candidates into selecting GKE or Compute Engine when the requirement is to avoid infrastructure management.

8
MCQmedium

A data scientist wants to train a custom machine learning model using a large dataset stored in BigQuery. They need a managed service that supports distributed training with GPU accelerators. Which service should they use?

A.Dataflow
B.Cloud Functions
C.AutoML (within Vertex AI)
D.Vertex AI Training
AnswerD

Vertex AI Training is a fully managed service that runs arbitrary custom training code in containers, with support for distributed training, GPU/TPU accelerators, hyperparameter tuning, and job orchestration. It lets the data scientist define their own model architecture using any ML framework (TensorFlow, PyTorch, JAX) and scale seamlessly from a single VM to large clusters. This directly fulfills the requirement of training a custom model with full control, while offloading infrastructure management to Vertex AI.

Why this answer

Vertex AI Training is Google Cloud's managed service for training custom machine learning models, supporting distributed training across multiple machines and GPU/TPU accelerators. It integrates with BigQuery for data access and allows custom training code in containers, making it the right choice for training a custom model on a large BigQuery dataset with GPUs.

Exam trap

The trap is selecting AutoML because it is part of Vertex AI and sounds managed, but the question specifies custom model training with distributed training and GPUs — that requires Vertex AI Training, not AutoML.

How to eliminate wrong answers

Option A is wrong because Dataflow is a data processing service for batch and stream pipelines, not a model training service. Option B is wrong because Cloud Functions is a serverless compute service for event-driven functions, not for distributed ML training. Option C is wrong because AutoML within Vertex AI automates model selection and training but does not support custom training code or the same level of control over distributed training with GPUs as Vertex AI Training.

9
MCQhard

An engineer needs to deploy a containerized application on Google Kubernetes Engine (GKE) and ensure that each pod gets a static IP address that persists across rescheduling. Which networking approach should they use?

A.Use a VPC-native cluster and assign a static internal IP using the `networking.gke.io/static-ip` annotation.
B.Use a load balancer service of type LoadBalancer.
C.Use a DaemonSet to ensure one pod per node.
D.Use a StatefulSet with a headless service.
AnswerA

A VPC-native cluster assigns pod IPs directly from the VPC subnet, allowing the `networking.gke.io/static-ip` annotation to reserve a specific internal IP for a pod. This annotation binds that IP to the pod's network interface, ensuring the pod keeps the same address even after rescheduling. The reservation is managed by GKE and persists until the annotation is removed, making it ideal for workloads that require a fixed internal endpoint.

Why this answer

GKE supports static IP addresses for pods using VPC-native clusters and alias IP ranges. By reserving a static internal IP address and assigning it to the pod via a Kubernetes annotation, the IP persists even if the pod is rescheduled.

10
MCQhard

A company wants to store archived data that must be retained for 10 years. They expect to access it less than once a year. Which Cloud Storage class is the MOST cost-effective?

A.Standard
B.Coldline
C.Archive
D.Nearline
AnswerC

The Archive storage class is designed for data accessed less than once a year, with a minimum 180-day retention period that aligns with the 10-year requirement. Its retrieval cost is high, but the lowest storage price among classes makes it most cost-effective when access is rare, satisfying the constraint of infrequent retrieval.

Why this answer

Archive storage is designed for data accessed less than once a year, with the lowest storage cost but higher retrieval fees and a 365-day minimum storage duration. Coldline has a 90-day minimum and higher cost. Nearline and Standard are more expensive and have shorter minimums.

11
MCQmedium

A data engineer needs to process a continuous stream of clickstream events from a website, perform real-time aggregations (e.g., counts per page per minute), and write the results to BigQuery for dashboarding. Which combination of services should they use?

A.Pub/Sub, Cloud Functions, Cloud SQL
B.Cloud Storage, Dataflow, Cloud SQL
C.Pub/Sub, Dataflow, BigQuery
D.Pub/Sub, Cloud Functions, BigQuery
AnswerC

Pub/Sub + Dataflow + BigQuery is the correct streaming pipeline. Pub/Sub is a fully managed, durable message ingestion service that decouples producers from consumers and supports exactly-once delivery semantics in combination with Dataflow. Dataflow (Apache Beam runner) provides unified batch and stream processing with built-in windowing, stateful aggregations, and exactly-once guarantees, enabling real-time click aggregation. BigQuery is a serverless, columnar data warehouse optimized for scanning large volumes of data with high concurrency, making it ideal for serving a live dashboard with sub-second SQL queries on aggregated results.

Why this answer

Pub/Sub ingests the stream, Dataflow processes real-time aggregations using Apache Beam, and BigQuery stores results. Cloud Functions is not suitable for streaming aggregations. Cloud Storage is for batch, not real-time.

Cloud SQL is not for streaming analytics.

12
Multi-Selecteasy

A developer wants to build a mobile app backend that uses a real-time database for chat messages, user profiles, and file storage for images. They want a fully managed, serverless solution. Which THREE Google Cloud services should they use? (Choose three.)

Select 3 answers
A.Cloud SQL
B.Cloud Functions
C.Firestore
D.Cloud Storage
E.App Engine
AnswersB, C, D

Cloud Functions is a serverless execution environment that runs backend logic in response to Firestore and Cloud Storage events, so you can handle message processing, profile updates, and media metadata without provisioning servers. It naturally complements the mobile backend by creating a scalable, event-driven pipeline that charges only when code runs, and it provides a secure way to perform privileged operations that should not run on the client device.

Why this answer

Firestore (C) is the correct choice for the real-time database because it is a fully managed, serverless NoSQL document database that supports real-time synchronization for chat messages and user profiles. Cloud Functions (B) is correct because it provides serverless, event-driven compute that can run backend logic (e.g., triggered by Firestore writes or HTTP requests) without managing servers. Cloud Storage (D) is correct because it is the fully managed, serverless object storage service designed for storing and serving images and other files.

Cloud SQL (A) is not appropriate because it is a managed relational database that is not serverless in the same sense and does not natively provide real-time sync for mobile clients. App Engine (E) is a managed application platform, but it is not a database or object storage service and is not needed for this serverless backend architecture.

Exam trap

GCDL often tests whether candidates pick Cloud SQL for mobile backends out of relational habit; the trap is that real-time sync and serverless scale require Firestore, not a managed relational instance.

13
Multi-Selectmedium

A data engineering team needs to process streaming data from IoT devices, perform real-time transformations, and load the results into BigQuery for analysis. Which TWO Google Cloud services should they use?

Select 2 answers
A.Pub/Sub
B.Cloud Scheduler
C.Dataproc
D.Dataflow
E.Cloud Functions
AnswersA, D

Pub/Sub is a fully managed, globally distributed messaging and ingestion service built for real-time event streaming. It reliably captures high-volume data from IoT devices via pull or push subscriptions, decouples producers from downstream consumers, and provides at-least-once delivery without requiring any server provisioning. As the entry point in a streaming data pipeline, it buffers and routes telemetry so that downstream systems like Dataflow can process it without data loss.

Why this answer

Pub/Sub (A) is correct because it is Google Cloud's fully managed, globally scalable messaging service designed to ingest high-volume streaming data from IoT devices, decoupling producers from consumers. Dataflow (D) is correct because it provides a fully managed Apache Beam runner for real-time (streaming) transformations with exactly-once processing, and it has a native BigQueryIO connector for loading results into BigQuery. Together, Pub/Sub ingests the IoT stream and Dataflow transforms it and writes to BigQuery.

Cloud Scheduler (B) is only a cron-based job trigger, not a streaming data processor. Dataproc (C) is a managed Hadoop/Spark service better suited to batch processing rather than low-latency streaming pipelines. Cloud Functions (E) is an event-driven serverless compute service for short-lived functions, not a scalable stream-processing framework for continuous IoT transformations.

Exam trap

GCDL often tests whether candidates confuse Dataproc (batch Spark/Hadoop) with Dataflow (streaming Beam), so picking Dataproc for 'real-time transformations' is the classic wrong answer.

14
MCQmedium

A developer wants to trigger a serverless function in response to a file being uploaded to a Cloud Storage bucket. Which Google Cloud service should they use?

A.Compute Engine
B.Cloud Functions
C.Cloud Run
D.App Engine
AnswerB

Cloud Functions is Google Cloud's fully managed, event-driven serverless compute platform designed specifically for single-purpose functions that respond to Cloud Storage events, HTTP triggers, Pub/Sub messages, and other event sources. It automatically scales to zero when no events occur, eliminating idle cost, and executes code only when a trigger fires, making it the ideal lightweight choice for a developer who wants to run a snippet of code without provisioning or managing infrastructure. Its runtime model directly matches the requirement for a serverless function triggered by a Cloud Storage upload.

Why this answer

Cloud Functions is Google Cloud's serverless compute service designed for event-driven workloads. It can be triggered by Cloud Storage events such as object finalization (file upload), making it the correct choice for running code in response to a file being uploaded to a bucket.

Exam trap

GCDL often tests the distinction between serverless compute options — candidates may choose Cloud Run or App Engine for event-driven tasks, but Cloud Functions is the canonical service for simple storage-triggered functions.

How to eliminate wrong answers

Option A is wrong because Compute Engine provides virtual machines, which are not serverless and require manual management of triggers and scaling. Option C is wrong because Cloud Run is a serverless container platform that runs stateless containers, but it does not natively trigger on Cloud Storage events without additional eventing setup (e.g., Eventarc), and it is not the primary service for simple function triggers. Option D is wrong because App Engine is a platform for building web applications and APIs, not for event-driven functions triggered by storage events.

15
MCQmedium

A data engineering team wants to process continuous streams of real-time events from millions of devices, perform transformations, and load the results into BigQuery for analysis. They need a fully managed, serverless solution. Which service should they use?

A.Dataproc
B.Cloud Pub/Sub
C.Cloud Functions
D.Cloud Dataflow
AnswerD

Cloud Dataflow is a fully managed, serverless service that unifies stream and batch data processing using the Apache Beam model. It auto-scales, provides exactly-once semantics, and natively integrates with BigQuery, Pub/Sub, and other GCP services. Its support for event-time processing, watermarks, and stateful aggregations makes it the correct choice for building scalable, real-time stream processing pipelines.

Why this answer

Cloud Dataflow is a fully managed, serverless service for both batch and stream processing, built on Apache Beam. It can ingest continuous streams from Pub/Sub, apply transformations, and write results to BigQuery with automatic scaling and no infrastructure management. This matches the requirement for a serverless solution to process real-time events from millions of devices and load them into BigQuery.

Exam trap

GCDL often tests the difference between ingestion (Pub/Sub), serverless compute (Cloud Functions), and data processing (Dataflow), so the trap is choosing Pub/Sub for processing or Cloud Functions for high-volume streams.

How to eliminate wrong answers

Option A is wrong because Dataproc is a managed Hadoop and Spark service that requires cluster provisioning and management, so it is not serverless and adds operational overhead. Option B is wrong because Cloud Pub/Sub is a messaging and ingestion service, not a data processing engine; it can receive events but does not perform transformations or load into BigQuery by itself. Option C is wrong because Cloud Functions is designed for lightweight, event-driven functions with limited execution time and resources, making it unsuitable for high-throughput stream processing at millions of events.

16
Multi-Selectmedium

A company wants to migrate its on-premises PostgreSQL database to Google Cloud with minimal downtime. They also need the ability to perform point-in-time recovery. Which TWO services or features should they use? (Choose two.)

Select 2 answers
A.Cloud SQL for PostgreSQL
B.Cloud Spanner
C.Cloud SQL for MySQL
D.Database Migration Service
E.Cloud Dataflow
AnswersA, D

Cloud SQL for PostgreSQL is the correct target because it is Google Cloud's fully managed relational database service that is natively compatible with the PostgreSQL engine. This means your existing schema, queries, stored procedures, and database tools can be used with minimal modification, providing a straightforward lift-and-shift path from on-premises PostgreSQL to a managed cloud environment. It also offers automated backups, high availability, and scaling, which are key benefits for production migrations.

Why this answer

Cloud SQL for PostgreSQL supports database migration and point-in-time recovery. Database Migration Service provides for minimal-downtime migrations.

17
Multi-Selecthard

A company runs a critical application on Compute Engine. They need a backup and disaster recovery strategy that includes automated backups and the ability to restore in a different region. Which TWO services should they use together? (Select 2)

Select 2 answers
A.Cloud Run
B.Persistent Disk snapshots
C.Dataflow
D.Cloud SQL
E.Cloud Storage
AnswersB, E

Persistent Disk snapshots are the direct, native mechanism for backing up Compute Engine disks. A snapshot captures the exact state of a disk at a specific time, and subsequent snapshots are incremental, storing only changed blocks for cost efficiency. You can automate snapshot creation with Cloud Scheduler and the Cloud Pub/Sub notifications, or use the Backup and DR service, and these snapshots can be restored to create new disks or be used to migrate the VM to another region.

Why this answer

Persistent Disk snapshots can be used for automated backups. Cloud Storage can store these snapshots in a different region for DR. Cloud SQL is not relevant if the application runs on Compute Engine.

Cloud Run is a compute service, not backup. Dataflow is processing.

18
MCQmedium

A team wants to use a managed MySQL database that offers automatic failover, backups, and read replicas. They also need to connect from Compute Engine instances in the same region. Which service should they use?

A.Bigtable
B.Cloud SQL for MySQL
C.Cloud Spanner
D.Firestore
AnswerB

Cloud SQL for MySQL is a fully managed relational database service that provides automated backups, failover, read replicas, and vertical/horizontal scaling. It is specifically engineered to be compatible with standard MySQL clients and tools, offering a familiar SQL interface and transactional guarantees. This makes it the ideal choice for teams that want a managed MySQL database without operational overhead.

Why this answer

Cloud SQL for MySQL is a fully managed relational database service that supports MySQL, automatic failover, backups, and read replicas. It integrates natively with Compute Engine instances in the same region via private IP or Cloud SQL Auth Proxy. This matches all stated requirements.

Exam trap

The trap is confusing managed MySQL with other Google Cloud databases; candidates may pick Cloud Spanner for its relational features, but it is not MySQL-compatible and has different scaling characteristics.

How to eliminate wrong answers

Option A is wrong because Bigtable is a NoSQL wide-column database for large analytical workloads, not a managed MySQL service, and it lacks MySQL compatibility. Option C is wrong because Cloud Spanner is a globally distributed relational database with its own SQL dialect, not MySQL, and it is overkill for this use case. Option D is wrong because Firestore is a NoSQL document database, not a relational MySQL database, and does not support SQL or read replicas in the same way.

19
MCQhard

A security team wants to restrict access to a Cloud Storage bucket so that only Compute Engine VMs in the same VPC network can read objects. The VMs do not have public IP addresses. Which configuration should they use?

A.Assign external IPs to the VMs and use firewall rules.
B.Create a bucket with uniform bucket-level access and grant the `storage.objectViewer` role to `allUsers`.
C.Use a Cloud VPN to connect the VMs to the bucket.
D.Enable Private Google Access on the subnet and use VPC Service Controls to limit bucket access to the VPC.
AnswerD

Enabling Private Google Access on the VM's subnet allows instances with only internal IPs to reach Google APIs and services, including Cloud Storage, through the VPC's internal routing and the default gateway. VPC Service Controls add a security perimeter that explicitly restricts bucket access to the VPC network, preventing access from the public internet or other networks within the organization. Together they enforce the requirement: the VMs remain without public IPs, and the bucket's access is limited to the VPC, not just any Google-authenticated identity.

Why this answer

Private Google Access allows VMs without external IPs to access Google APIs and services via the VPC network. Combined with VPC Service Controls and bucket IAM, this ensures only VMs in the VPC can access the bucket.

20
MCQeasy

Which Google Cloud service is a fully managed, serverless data warehouse for running SQL queries on petabyte-scale datasets?

A.Cloud SQL
B.Cloud Dataflow
C.Cloud Dataproc
D.BigQuery
AnswerD

BigQuery is a fully managed, serverless data warehouse that separates compute from storage, enabling petabyte-scale SQL analytics without provisioning infrastructure. It uses a columnar storage format and a distributed query engine that dynamically allocates slots, making it ideal for interactive BI and large data aggregations. BigQuery also includes built-in features like partitioning, clustering, and automatic recompression of data, and it supports standard SQL, which is why it is the correct answer for a serverless analytics warehouse.

Why this answer

BigQuery is the serverless data warehouse for analytics SQL queries. Dataflow is for stream processing, Dataproc for Hadoop/Spark, and Cloud SQL for OLTP.

21
Multi-Selecthard

A company has a multi-regional deployment of a web application on Compute Engine. They want to improve latency for users worldwide and reduce load on the origin servers. They also need to protect against SQL injection and cross-site scripting attacks. Which TWO Google Cloud services should they implement?

Select 2 answers
A.Cloud DNS
B.Cloud Armor
C.Cloud NAT
D.Cloud CDN
AnswersB, D

Cloud Armor is Google Cloud's web application firewall (WAF) that provides configurable security policies for HTTP(S) load balancing. It includes pre-configured rules from the ModSecurity Core Rule Set to block SQL injection, cross-site scripting, and other OWASP Top 10 threats. Cloud Armor also supports IP allow/deny lists, geo-based access controls, and rate limiting, making it the precise service to protect a web application from the stated attacks.

Why this answer

Cloud Armor (B) is correct because it is Google Cloud's edge security service that provides WAF capabilities, including preconfigured rules to block SQL injection (e.g., sqli-v33-stable) and cross-site scripting (e.g., xss-v33-stable) attacks against HTTP(S) load-balanced backends. Cloud CDN (D) is correct because caching content at Google's globally distributed edge points of presence reduces latency for worldwide users and offloads requests from the Compute Engine origin servers. Cloud DNS (A) only provides authoritative DNS resolution and does not cache HTTP content or inspect application-layer attacks.

Cloud NAT (C) provides outbound internet connectivity for private instances and offers no latency or WAF benefits. Cloud Load Balancing (E) distributes traffic but does not itself cache content or provide WAF protection, so it does not satisfy both requirements.

Exam trap

GCDL often tests service-purpose pairing; candidates pick Cloud Load Balancing as an answer because it is 'needed,' but the question asks for the services that provide caching and WAF, which are Cloud CDN and Cloud Armor respectively.

22
MCQeasy

Which Google Cloud service provides a serverless data warehouse for running SQL queries on petabyte-scale data with no need to manage infrastructure?

A.Cloud SQL
B.Dataflow
C.BigQuery
D.Pub/Sub
AnswerC

BigQuery is Google Cloud's serverless, fully managed analytics warehouse that runs ANSI SQL over petabyte-scale datasets using its Dremel engine and columnar storage, with no clusters to provision or tune. This directly satisfies the stem's no-infrastructure-management constraint.

Why this answer

BigQuery is a fully managed, serverless data warehouse that supports SQL queries on massive datasets.

23
Multi-Selectmedium

A company is building a real-time leaderboard for an online game using Google Cloud. They need a database that can handle millions of updates per second with low latency and serve the current top scores. Which TWO services should they use together? (Choose 2)

Select 2 answers
A.Cloud SQL
B.Firestore
C.Cloud Bigtable
D.Memorystore for Redis
E.BigQuery
AnswersC, D

Cloud Bigtable is a NoSQL wide-column database engineered for high-throughput, low-latency writes of millions of rows per second when scaling with CPU and storage nodes. Its distributed storage engine appends writes to SSTables with memtable buffering, giving consistent single-digit-millisecond latencies and linear write scaling across a cluster without a single bottleneck. For a real-time leaderboard, Bigtable's row-key design (like inverted scores or user IDs) paired with its massive write capacity makes it a proven choice for globally hot update streams.

Why this answer

Cloud Bigtable (C) is correct because it is a fully managed, horizontally scalable NoSQL database designed for high-throughput, low-latency workloads, making it suitable for ingesting millions of score updates per second and durably storing the leaderboard data. Memorystore for Redis (D) is correct because it provides an in-memory data store with sub-millisecond latency, ideal for serving the current top scores in real time and handling rapid ranking operations. Together, Bigtable handles massive write throughput while Redis serves the hot leaderboard reads.

Cloud SQL (A) is not appropriate because it is a relational database that cannot scale to millions of updates per second with low latency. Firestore (B) is not ideal because, while it is a NoSQL document database, it is optimized for mobile/web app synchronization rather than extreme write throughput. BigQuery (E) is not suitable because it is an analytics data warehouse designed for large-scale queries, not real-time transactional updates.

Exam trap

GCDL often tests whether candidates recognize that Bigtable alone cannot serve sorted leaderboard queries efficiently, so answers that omit Redis (or substitute Firestore/BigQuery) fail the low-latency read requirement.

24
Multi-Selecteasy

A company wants to store archival data that is accessed less than once a year and needs the lowest storage cost. Which TWO Cloud Storage classes are most cost-effective for this use case?

Select 2 answers
A.Regional
B.Nearline
C.Standard
D.Archive
E.Coldline
AnswersD, E

Archive is the correct answer because it is Google Cloud's lowest-cost storage class, explicitly intended for data accessed less than once a year. It has the cheapest storage price but charges high retrieval fees and requires a minimum storage duration of 365 days. This matches the described access pattern of archival data, making it the most cost-effective option.

Why this answer

Coldline (E) and Archive (D) are the two lowest-cost Cloud Storage classes and are explicitly designed for data accessed less than once a year, making them the most cost-effective choices for this archival scenario. Coldline is intended for data accessed at most once per quarter and offers very low storage pricing with a 90-day minimum storage duration, while Archive is the cheapest class for data accessed less than once a year, with a 365-day minimum storage duration. Both classes charge higher retrieval and early-deletion fees, which is acceptable here because the data is rarely read.

Regional (A) and Standard (C) are hot-access classes with the highest storage prices, so they are not cost-effective for archival data. Nearline (B) is cheaper than Standard but is optimized for data accessed about once a month, so it costs more than Coldline and Archive for this less-than-annual access pattern.

Exam trap

The trap is confusing Nearline and Coldline thresholds — candidates pick Nearline for 'less than once a year' when Nearline is actually for less than once a month, making it more expensive than needed.

25
MCQmedium

A DevOps team wants to automatically build a Docker image from a GitHub repository and store it in a private registry whenever a new tag is pushed. Which Google Cloud services should they combine?

A.Cloud Build and Container Registry
B.Cloud Source Repositories and Container Registry
C.Cloud Functions and Artifact Registry
D.Cloud Build and Artifact Registry
AnswerD

Cloud Build natively supports build triggers tied to GitHub events, including tag push events, making it ideal for automatically building a Docker image when a tag is pushed. The built image can then be securely pushed to Artifact Registry, which is the fully managed, regional container registry with IAM integration, vulnerability scanning, and support for Docker and OCI artifacts. This combination is the recommended, maintainable CI/CD approach for tag-driven image builds.

Why this answer

Cloud Build is Google Cloud's fully managed CI/CD service that can be triggered by GitHub tag pushes via Cloud Build triggers. Artifact Registry is the modern, recommended private registry for storing Docker images (and other artifacts), replacing the older Container Registry. Together, they provide an automated build-and-store pipeline: Cloud Build builds the image from the GitHub repo, and Artifact Registry stores it privately.

Exam trap

GCDL often tests the distinction between Container Registry (legacy) and Artifact Registry (current), and candidates may pick Container Registry out of familiarity, missing that Artifact Registry is the recommended service for new deployments.

How to eliminate wrong answers

Option A is wrong because while Cloud Build and Container Registry can work together, Container Registry is deprecated and lacks the advanced features (e.g., multi-format support, fine-grained IAM) of Artifact Registry; the question asks for the best combination, and Artifact Registry is the current standard. Option B is wrong because Cloud Source Repositories is a private Git repository service, not a build service; it cannot automatically build Docker images from GitHub. Option C is wrong because Cloud Functions is a serverless compute service for event-driven functions, not for building Docker images; it cannot perform Docker builds.

26
MCQeasy

An organization needs to apply security policies to protect their web application from DDoS attacks and SQL injection. Which Google Cloud service should they use?

A.Cloud NAT
C.Cloud Armor
D.Cloud CDN
AnswerC

Cloud Armor is Google Cloud's web application firewall (WAF) and DDoS protection service, which integrates with Cloud Load Balancing to protect services at the edge. It enables fine-grained security policies based on IP addresses, geographic location, and preconfigured or custom rules that filter OWASP Top 10 threats like SQL injection and cross-site scripting. Cloud Armor also mitigates volumetric DDoS attacks with adaptive protection and scale, making it the correct service for applying security policies.

Why this answer

Cloud Armor is a web application firewall (WAF) that provides DDoS protection and security rules to block threats like SQL injection. Cloud CDN is for content caching. Load Balancing distributes traffic.

Cloud NAT is for outbound connectivity.

27
Multi-Selecthard

A company runs a containerized microservices application on Google Kubernetes Engine (GKE). They want to expose a set of services externally with a single IP address, implement SSL termination, and protect against DDoS attacks. Which THREE Google Cloud services should they use together?

Select 3 answers
A.Cloud Armor
B.Cloud NAT
D.Cloud VPN
E.Cloud CDN
AnswersA, C, E

Cloud Armor is Google Cloud's distributed denial-of-service (DDoS) protection and web application firewall (WAF) service. It attaches to an HTTP(S) Load Balancer and filters incoming traffic based on preconfigured or custom rules, mitigating OWASP Top 10 threats, IP-based blocklists, and rate-limiting before requests hit backend services. This makes it the decisive security layer for a containerized microservices application exposed to the internet, blocking malicious traffic at the edge.

Why this answer

Cloud Load Balancing (C) is correct because an external Application Load Balancer (HTTP(S)) provides a single global anycast IP address, routes traffic to GKE services via Ingress/BackendConfig, and performs SSL/TLS termination using Google-managed or self-managed certificates. Cloud Armor (A) is correct because it attaches security policies to the load balancer's backend service to filter and mitigate DDoS and Layer 7 attacks (e.g., via preconfigured WAF rules and rate limiting). Cloud CDN (E) is correct because enabling it on the load balancer's backend service caches content at Google's edge points of presence, absorbing traffic and adding another layer of DDoS resilience while reducing origin load.

Cloud NAT (B) is not appropriate because it provides outbound internet access for private instances, not inbound external exposure or SSL termination. Cloud VPN (D) is not appropriate because it only establishes encrypted tunnels between networks and does not provide public load balancing, SSL termination, or DDoS protection.

Exam trap

GCDL often tests the misconception that Cloud NAT or Cloud VPN provides inbound protection or external exposure; candidates must recognize that only Cloud Load Balancing + Cloud Armor + Cloud CDN form the ingress/edge security stack.

28
MCQmedium

An organisation is migrating its on-premises Oracle database to Google Cloud. They need a fully managed, PostgreSQL-compatible database with high performance for transaction processing and built-in AI capabilities for predictive analytics. Which database service should they choose?

A.Bare Metal Solution for Oracle
B.Cloud SQL for PostgreSQL
C.Cloud Spanner
D.AlloyDB
AnswerD

AlloyDB is a fully managed, PostgreSQL-compatible database service architected for high performance, delivering up to 4x faster transactional throughput and up to 100x faster analytical queries compared to standard PostgreSQL. It includes AlloyDB AI with vector similarity search, predictive autoscaling, and columnar engine, making it ideal for migrating Oracle workloads while adding artificial intelligence features. This aligns exactly with the requirement for a managed, compatible database with built-in AI.

Why this answer

AlloyDB is a fully managed PostgreSQL-compatible database that offers high performance (4x faster than standard PostgreSQL) and integrated AI capabilities for vector search and predictive analytics. Cloud SQL for PostgreSQL is also managed but lacks the AI optimisations. Cloud Spanner is globally distributed but not PostgreSQL-compatible.

Bare Metal Solution runs Oracle on dedicated hardware, not managed.

29
Multi-Selectmedium

A data analytics team wants to analyze large datasets using SQL and create dashboards with minimal latency. They need a serverless data warehouse and a BI tool. Which two services should they use? (Choose exactly 2.)

Select 2 answers
A.Dataflow
B.Looker Studio
C.Cloud Storage
D.Looker
E.BigQuery
AnswersD, E

Looker is an enterprise business intelligence and data analytics platform that provides a semantic modeling layer (LookML) to define business logic, enabling consistent and reusable metrics across the organization. It allows analysts to explore large datasets through a governed interface and create interactive dashboards, and it ties into cloud data warehouses like BigQuery for query execution. Looker is designed specifically for large-scale business analytics and is a correct choice for this use case.

Why this answer

BigQuery is a serverless data warehouse for SQL analytics. Looker is a BI platform integrated with BigQuery for dashboards. Dataflow is for data processing, not storage.

Cloud Storage is for object storage, not SQL analytics. Looker Studio is free but less feature-rich for enterprise needs.

30
MCQeasy

Which Google Cloud service provides a managed Redis or Memcached in-memory data store for caching and low-latency data access?

A.Firestore
B.Bigtable
C.Cloud SQL
D.Memorystore
AnswerD

Memorystore delivers fully managed Redis and Memcached engines on Google Cloud, removing patching, failover and scaling overhead. It satisfies the stem's requirement for a managed in-memory data store serving caching and low-latency access, unlike persistent disk or relational alternatives.

Why this answer

Memorystore is Google Cloud's fully managed in-memory data store service that supports Redis and Memcached. It provides low-latency caching and data access, making it ideal for applications requiring high-speed data retrieval.

Exam trap

GCDL often tests the confusion between Memorystore and other data services like Firestore or Bigtable; candidates may incorrectly choose a database service when the question specifically asks for an in-memory data store.

How to eliminate wrong answers

Option A is wrong because Firestore is a NoSQL document database, not an in-memory cache; it provides persistent storage with higher latency than in-memory solutions. Option B is wrong because Bigtable is a wide-column NoSQL database for large analytical workloads, not an in-memory data store. Option C is wrong because Cloud SQL is a managed relational database service (MySQL, PostgreSQL, SQL Server) that stores data on disk, not in memory.

31
MCQeasy

A startup wants to deploy a containerised web application that scales automatically from zero to handle traffic spikes and charges only for the resources used during request processing. They want to avoid managing servers or Kubernetes clusters. Which compute service should they choose?

A.Compute Engine
B.Cloud Run
C.Google Kubernetes Engine (GKE)
D.App Engine Standard
AnswerB

Cloud Run is a fully managed, Knative-based serverless platform that executes stateless containers in a scale-to-zero model: when there are no incoming requests, it shuts down all instances and you pay nothing. Each request is billed in 100-millisecond increments of compute time plus a minimal per-request charge, and it automatically scales to handle variable traffic, including bursting to thousands of concurrent requests. It accepts any container image that uses an HTTP server, which directly matches the need to deploy a containerised web application without managing any underlying nodes or clusters.

Why this answer

Cloud Run is a serverless compute platform that runs containers, scales to zero when not in use, and charges for resources used during request processing. It fits the description perfectly.

32
MCQmedium

A company is migrating a legacy monolithic application to Google Cloud. They want to reduce operational overhead by eliminating server management while keeping the ability to run containers. The application has unpredictable traffic patterns and needs to scale to zero when idle. Which compute option is the best fit?

A.Cloud Run
B.Google Kubernetes Engine (GKE)
C.App Engine Flexible Environment
D.Compute Engine with managed instance groups
AnswerA

Cloud Run is a fully managed serverless compute platform that executes stateless containers delivered via a requests URL. It automatically scales your container from zero to whatever number of instances are needed to handle incoming traffic, and you are billed only for the resources consumed during request processing—when idle, you pay nothing. This makes it exceptionally well-suited for unpredictable traffic patterns without requiring any cluster or infrastructure management.

Why this answer

Cloud Run is a serverless container platform that automatically scales to zero when idle, eliminating server management and cost during idle periods. GKE requires cluster management, Compute Engine is not serverless, and App Engine Flex requires VMs always running.

33
MCQhard

A company runs a globally distributed application with users in North America, Europe, and Asia. They need to serve static content (images, videos) with low latency from edge locations. They also need to protect against DDoS attacks. Which combination of services should they use?

A.Cloud CDN and Cloud NAT
B.Cloud Load Balancing and Cloud CDN
C.Cloud CDN and Cloud Armor
D.Cloud Armor and Cloud Interconnect
AnswerC

Cloud CDN offloads static content delivery to Google's global edge cache, absorbing sudden spikes in traffic and reducing origin load. Cloud Armor enforces security policies at the edge, offering HTTP(S) L3-7 DDoS protection, WAF rules, and per-user rate limits. Together, they provide both acceleration and protection: Cloud CDN handles legitimate cacheable content at scale, while Cloud Armor filters out attack traffic before it reaches Cloud CDN or the backend.

Why this answer

Cloud CDN caches static content at edge locations for low latency, and Cloud Armor provides DDoS protection and WAF capabilities.

34
Multi-Selectmedium

A company wants to implement a data pipeline that ingests streaming events from a global user base, processes them in real-time to detect anomalies, and stores the results in a database for low-latency querying. The solution must be fully managed. Which THREE services should they use? (Choose 3)

Select 3 answers
A.Dataflow
B.Cloud Storage
C.Cloud Bigtable
D.Pub/Sub
E.Cloud Functions
AnswersA, C, D

Dataflow is a fully managed, unified stream and batch data processing service based on Apache Beam. It performs real-time stream processing, including event-time windowing, aggregation, and anomaly detection with exactly-once semantics, auto-scaling, and low latency. It is the correct choice for the processing stage because it can consume from Pub/Sub, apply transformations (including anomaly detection), and write results to Bigtable.

Why this answer

Option D (Pub/Sub) is correct because it is a fully managed, globally scalable messaging service designed to ingest high-volume streaming events from a worldwide user base and reliably deliver them to downstream processing systems. Option A (Dataflow) is correct because it is a fully managed, serverless stream and batch processing service that can consume Pub/Sub messages and perform real-time anomaly detection using Apache Beam pipelines. Option C (Cloud Bigtable) is correct because it is a fully managed, low-latency NoSQL database that scales horizontally and is well suited for storing and querying the pipeline's results with millisecond latency.

Option B (Cloud Storage) is not appropriate as the primary sink for low-latency querying, since it is object storage optimized for large blobs rather than fast row-level reads. Option E (Cloud Functions) is not suitable as the core stream-processing engine here, because it is an event-driven serverless function service with execution time and concurrency limits, not a managed pipeline for continuous, high-throughput stream analytics.

Exam trap

GCDL often tests the difference between batch and streaming services, tricking candidates into selecting Cloud Storage or Cloud Functions for real-time processing when Dataflow is the correct managed stream-processing service.

35
MCQeasy

A developer wants to deploy a containerized web application that can automatically scale to zero when there are no requests, and charges only for resources used during request processing. Which Google Cloud compute service should they use?

A.Compute Engine
B.Google Kubernetes Engine (GKE)
C.Cloud Run
D.App Engine Standard Environment
AnswerC

Cloud Run is a fully managed serverless container platform that executes your container only when a request arrives. It automatically scales down to zero instances during idle periods, meaning you pay nothing when there is no traffic, and it scales up instantly to handle incoming requests. Because it directly supports container images and abstracts all infrastructure, it is the simplest and most cost-efficient choice for deploying a containerized web application.

Why this answer

Cloud Run is a serverless container platform that scales to zero and charges per request. Google Kubernetes Engine and Compute Engine require running instances, and App Engine Standard is a platform as a service but not container-based.

36
MCQeasy

A company uses Google Workspace for email, documents, and meetings. They want to leverage an AI assistant that can help draft emails, create slides, and summarise meeting notes. Which product provides this functionality?

A.Vertex AI
B.Cloud Natural Language
C.Dialogflow
D.Gemini for Workspace
AnswerD

Gemini for Workspace, formerly Duet AI, is the generative AI assistant natively integrated into Google Workspace applications such as Gmail, Docs, Sheets, and Meet. It leverages the Gemini model family and is grounded in the user's Workspace content to summarize threads, draft documents, and automate tasks, while inheriting Workspace's enterprise-grade security and data governance. It is designed specifically as the AI companion for Workspace users, requiring no custom ML development.

Why this answer

Gemini for Workspace is an AI assistant integrated into Google Workspace applications like Gmail, Docs, Slides, and Meet. It can help draft emails, create slides, and summarise meeting notes, directly leveraging the context of the user's Workspace data.

Exam trap

GCDL often tests the distinction between Google's AI products, and candidates might confuse Gemini for Workspace with Vertex AI or other standalone AI services.

How to eliminate wrong answers

Option A is wrong because Vertex AI is a platform for building and deploying custom machine learning models, not a ready-to-use assistant for Workspace. Option B is wrong because Cloud Natural Language is an API for text analysis, not an integrated assistant. Option C is wrong because Dialogflow is for building conversational interfaces like chatbots, not for drafting emails or summarising meetings.

37
MCQeasy

A company needs to perform interactive SQL analytics on petabytes of data without managing any infrastructure. They need to query data stored in Cloud Storage and want the fastest query performance. Which Google Cloud service should they use?

A.BigQuery
B.Looker
C.Dataflow
D.Cloud SQL
AnswerA

BigQuery is a fully managed, serverless data warehouse that separates storage from compute, enabling interactive SQL queries over petabytes of data via a high-speed columnar execution engine. Its architecture, using the Dremel query engine, distributes queries across thousands of nodes, delivering sub-second to seconds response times on massive datasets without requiring infrastructure provisioning. This makes it the ideal choice for running ad-hoc, interactive analytics on petabyte-scale data.

Why this answer

BigQuery is a serverless, highly scalable data warehouse that supports SQL queries on data stored in Cloud Storage (external tables) or natively. It provides fast performance on petabyte-scale data without infrastructure management. Dataflow is for ETL, not ad-hoc analytics; Cloud SQL is for OLTP; Looker is a BI layer on top of a data warehouse.

38
MCQmedium

A company wants to use a pre-trained model to extract text from scanned invoices. They need a fully managed API that can be called via REST. Which Google Cloud service should they use?

A.Document AI
B.Vision AI
C.Natural Language AI
D.Vertex AI
AnswerA

Document AI is the correct choice because it provides purpose-built pre-trained processors such as the Invoice Parser, which are specifically designed to extract structured fields like vendor name, invoice number, due date, and line items from scanned or digital documents. These processors combine OCR with a domain-aware NLP model, so they understand document layouts and key-value pair conventions unique to invoices without any custom training.

Why this answer

Document AI is a fully managed service for document processing, including OCR and extraction from invoices. Vision AI is for general image analysis. Natural Language AI handles text sentiment/entities.

Vertex AI is a platform for custom models, not pre-built API for invoices.

39
MCQmedium

A startup is building a mobile app backend that requires a scalable NoSQL database with real-time synchronisation across devices. The database should support offline access and automatic conflict resolution. Which Google Cloud database service meets these requirements?

A.Cloud Spanner
B.Cloud SQL
C.Cloud Bigtable
D.Firestore
AnswerD

Firestore is a mobile-first document database with built-in offline persistence: data is stored locally on the device, enabling reads and writes without connectivity. When the device reconnects, Firestore automatically synchronizes local changes to the server and resolves conflicts using deterministic rules (e.g., last-write-wins by server timestamp). Its SDK offers real-time listeners that push updates to clients, making it ideal for chat, collaboration, and other interactive mobile features. Firestore's security rules and transaction support further streamline mobile backend development.

Why this answer

Firestore is Google Cloud's serverless document NoSQL database with built-in real-time listeners, offline persistence on mobile/web SDKs, and automatic conflict resolution via last-write-wins semantics. These features map directly to the mobile backend requirements of real-time sync, offline access, and conflict handling without custom code. Cloud Spanner, Cloud SQL, and Bigtable do not provide native mobile SDKs with offline sync.

Exam trap

The trap here is conflating 'scalable NoSQL on GCP' with Bigtable or Spanner — candidates who focus only on scale miss that the question's real signal is mobile offline sync and real-time listeners, which only Firestore provides.

How to eliminate wrong answers

Option A is wrong because Cloud Spanner is a globally distributed, strongly consistent relational database — it has no mobile SDK, no offline mode, and no real-time listener API, so it cannot satisfy the sync requirements. Option B is wrong because Cloud SQL is a managed MySQL/PostgreSQL/SQL Server relational service with no built-in real-time sync or offline capability for mobile clients. Option C is wrong because Cloud Bigtable is a wide-column NoSQL store optimised for high-throughput analytics and time-series workloads, not for mobile client synchronisation — it lacks document semantics, listeners, and offline support.

40
MCQmedium

A data analyst needs to create interactive dashboards and reports from data stored in BigQuery. They want a fully managed business intelligence platform without building custom applications. Which Google Cloud product should they use?

A.Looker Studio
B.Looker (Google Cloud's BI platform)
C.Vertex AI
D.Data Studio
AnswerB

Looker is Google Cloud's enterprise BI platform, purpose-built for interactive dashboards and governed reporting directly on BigQuery. It uses LookML, a semantic modeling language that defines business logic and metrics in a central repository, ensuring consistent, version-controlled definitions across all dashboard consumers. With embedded analytics, scheduled reports, and row-level security, Looker is the correct fit for this analyst's requirements.

Why this answer

Looker is a BI platform that connects to BigQuery and provides interactive dashboards, reports, and embedded analytics. Looker Studio is a free tool for simple visualizations. Data Studio is the old name.

Vertex AI is for ML.

41
MCQhard

An engineer is troubleshooting a Cloud SQL instance that is running out of memory. They want to reduce memory usage without changing the machine type. Which action would help?

A.Reduce the max_connections flag
B.Enable automatic storage increase
C.Add a read replica
D.Switch from InnoDB to MyISAM
AnswerA

Lowering `max_connections` caps the number of concurrent client sessions, and each session reserves per-thread memory for sort buffers, join buffers, and temporary tables. Reducing this flag therefore directly bounds the aggregate connection-level memory consumption on the instance, preventing memory exhaustion and out-of-memory restarts. It is the correct remediation because the symptom is memory pressure, not disk capacity or query routing.

Why this answer

In Cloud SQL, each database connection consumes memory for session state, buffers, and per-connection overhead. Reducing the max_connections flag lowers the maximum number of simultaneous connections, directly reducing the memory footprint of the database instance without changing the machine type. This is the most direct lever for memory reduction in this scenario.

Exam trap

GCDL often tests whether candidates confuse storage scaling (disk) with memory scaling (RAM) — automatic storage increase sounds like it helps 'running out of memory' but only addresses disk space.

How to eliminate wrong answers

Option B is wrong because enabling automatic storage increase affects disk capacity, not RAM usage — it has no impact on memory consumption. Option C is wrong because adding a read replica adds another instance (and more total memory usage across the deployment) rather than reducing memory on the primary. Option D is wrong because switching from InnoDB to MyISAM is a storage engine change that affects features like transactions and crash recovery, not a supported or effective way to reduce memory in Cloud SQL (and Cloud SQL for MySQL defaults to InnoDB).

42
MCQeasy

A developer wants to deploy a containerised microservice that can scale to zero when not in use and automatically scale up based on HTTP requests. The microservice is stateless and runs a custom Docker image. Which Google Cloud compute service is BEST suited for this workload?

A.Google Kubernetes Engine (GKE)
B.Cloud Run
C.Compute Engine with managed instance groups
D.App Engine Standard environment
AnswerB

Cloud Run is a serverless compute platform that executes stateless HTTP-driven containers on demand. When no requests are in flight, the service scales down to zero instances, so you are not billed for idle resources. It automatically provisions and scales instances up to handle spikes, supports any language and arbitrary Docker images, and only charges for the exact number of requests processed, making it a natural fit for a containerized microservice with intermittent traffic.

Why this answer

Cloud Run is a serverless compute platform that runs stateless containers and can scale to zero when idle. It automatically scales based on incoming requests, making it ideal for event-driven microservices. GKE requires a cluster to run even when idle, Compute Engine VMs are always on, and App Engine Standard does not support custom containers.

43
MCQmedium

An organisation needs to block common web attacks like SQL injection and cross-site scripting (XSS) at the edge of Google's network, before traffic reaches their applications. Which Google Cloud service should they use?

A.Cloud Armor
B.Cloud CDN
C.Cloud IDS
AnswerA

Cloud Armor is Google Cloud's Web Application Firewall (WAF) service that provides edge-based protection against application-layer attacks such as SQL injection and cross-site scripting (XSS). It uses pre-configured rules, including the OWASP Top 10 rule set, as well as custom rules in Common Expression Language (CEL) to filter malicious traffic before it reaches backend instances. Cloud Armor integrates with Cloud Load Balancing and can also provide DDoS protection with adaptive protection and rate limiting. This makes it the correct choice for blocking common web attacks.

Why this answer

Cloud Armor is Google's web application firewall (WAF) service that protects against web attacks at the edge. It integrates with Cloud Load Balancing and Cloud CDN. Cloud CDN caches content, Cloud Load Balancing distributes traffic, and Cloud IDS is for network threat detection.

44
MCQhard

A company has a batch processing job that reads data from Cloud Storage, transforms it, and writes to BigQuery. The job runs nightly and takes approximately 2 hours. The team wants to reduce costs by using a managed service that automatically provisions and de-provisions resources. Which service should they use?

A.Cloud Composer
B.Cloud Functions
C.Dataflow
D.Dataproc
AnswerC

Dataflow, Google Cloud's fully managed stream and batch processing service, runs the job in batch mode using Apache Beam, automatically scaling workers based on input size and processing needs. It reads from Cloud Storage, applies the required transformation logic, writes to BigQuery with exactly-once semantics, and then scales to zero after completion, so you only pay for the active compute during those 2 hours.

Why this answer

Dataflow is a fully managed, serverless Apache Beam service that automatically provisions and de-provisions workers based on the job's workload, making it the best fit for a nightly 2-hour batch job where the team wants to avoid managing infrastructure. It supports batch and streaming, integrates natively with Cloud Storage and BigQuery, and charges only for the resources used during execution. This aligns exactly with the requirement to reduce cost through automatic resource lifecycle management.

Exam trap

GCDL often tests the confusion between orchestration (Cloud Composer) and execution (Dataflow), and between serverless (Dataflow, Cloud Functions) and cluster-based (Dataproc) services — candidates must match the 'automatically provisions and de-provisions' requirement to Dataflow.

How to eliminate wrong answers

Option A is wrong because Cloud Composer is a managed Apache Airflow orchestration service — it schedules and coordinates workflows but does not itself perform the data transformation, and it runs continuously on GKE nodes, incurring cost even when no job is running. Option B is wrong because Cloud Functions is an event-driven serverless compute service with a 60-minute maximum execution timeout and limited memory, making it unsuitable for a 2-hour batch transformation job. Option D is wrong because Dataproc is a managed Spark/Hadoop service that requires the cluster to be provisioned and typically kept running (or explicitly configured with ephemeral clusters), so it does not automatically de-provision resources the way Dataflow does.

45
MCQeasy

A startup wants to run a Node.js web application with zero server management and automatic scaling. They expect unpredictable traffic and want to minimise costs. Which Google Cloud service should they choose?

A.Google Kubernetes Engine (GKE)
B.Compute Engine
C.App Engine Standard Environment
D.App Engine Flexible Environment
AnswerC

App Engine Standard Environment is a serverless platform that automatically scales your Node.js application from zero instances during idle periods to many during traffic spikes. It fully manages the underlying infrastructure, including load balancing, health checks, and runtime isolation, so you only pay for the resources your app actually consumes. This aligns perfectly with the startup's need for zero server management and cost efficiency under variable traffic.

Why this answer

App Engine Standard Environment is a fully managed, serverless platform that automatically scales instances up and down (including to zero) based on traffic, requires no server management, and bills only for resources consumed — ideal for unpredictable traffic and cost minimisation. It supports Node.js runtimes and is purpose-built for exactly this use case.

Exam trap

GCDL often tests the App Engine Standard vs Flexible distinction, so candidates who see 'Node.js' and 'automatic scaling' pick Flexible — the trap is that Flexible does not scale to zero and is not the cost-minimising choice for unpredictable traffic.

How to eliminate wrong answers

Option A is wrong because GKE requires the team to manage cluster infrastructure (nodes, upgrades, networking) or at least pay for a cluster control plane and node pools, which contradicts 'zero server management' and is more expensive for unpredictable, low-baseline traffic. Option B is wrong because Compute Engine provides raw VMs that the team must patch, scale, and manage — the opposite of serverless. Option D is wrong because App Engine Flexible Environment runs on VMs (managed but always-on instances), does not scale to zero, and is more expensive than Standard for spiky workloads; it is suited to custom runtimes and longer-running processes, not cost-minimised unpredictable traffic.

46
MCQmedium

A developer needs to trigger a serverless function whenever a new file is uploaded to a Cloud Storage bucket. The function will process the file and store results in Firestore. Which Google Cloud service should they use for the function?

A.App Engine
B.Compute Engine
C.Cloud Run
D.Cloud Functions
AnswerD

Cloud Functions is a purpose-built, event-driven serverless compute platform that natively responds to GCP events, including Cloud Storage object finalization (e.g., the 'google.storage.object.finalize' trigger). When an object is uploaded, Cloud Functions automatically invokes the function with the event metadata, scaling to zero when idle and managing all infrastructure transparently. This aligns exactly with the requirement to trigger a single-purpose serverless function on a storage event, without needing a container runtime, a web server, or an intermediary like Pub/Sub.

Why this answer

Cloud Functions is an event-driven serverless compute service that can be triggered by Cloud Storage events.

47
MCQmedium

A security team needs to protect a web application behind an HTTP(S) Load Balancer from SQL injection and cross-site scripting (XSS) attacks. Which Google Cloud service provides these protections?

A.Cloud CDN
B.VPC firewall rules
C.Cloud DNS
D.Cloud Armor
AnswerD

Cloud Armor is the correct answer because it is Google Cloud's managed Web Application Firewall (WAF) service that provides application-layer (L7) protection for services behind Cloud Load Balancing. It includes pre-configured rules from the OWASP ModSecurity Core Rule Set, which specifically detects and blocks SQL injection and cross-site scripting patterns in HTTP headers, query parameters, and request bodies. Cloud Armor also offers adaptive protection, rate limiting, and geo-based access controls, making it the appropriate tool for defending a web application against these common web exploits.

Why this answer

Cloud Armor is Google Cloud's edge security service that attaches to HTTP(S) Load Balancers and provides WAF capabilities, including preconfigured rules for SQL injection and XSS (the OWASP ModSecurity core rule set). It inspects requests at the load balancer before they reach the backend, blocking malicious payloads.

Exam trap

GCDL often tests whether candidates know Cloud Armor requires an HTTP(S) Load Balancer and provides WAF (SQLi/XSS) protection, versus VPC firewall rules which only filter L3/L4 traffic.

How to eliminate wrong answers

Option A is wrong because Cloud CDN caches and accelerates content delivery; it does not inspect or block application-layer attacks like SQLi or XSS. Option B is wrong because VPC firewall rules operate at L3/L4 (IP, port, protocol) and cannot inspect HTTP payloads for injection attacks. Option C is wrong because Cloud DNS is a managed DNS service for name resolution and routing — it has no WAF or application-layer inspection capability.

48
MCQeasy

Which Google Cloud service provides a fully managed, scalable NoSQL document database suitable for mobile and web applications with real-time data synchronization?

A.Cloud Bigtable
B.Firestore
C.Cloud SQL
D.Memorystore
AnswerB

Firestore is Google Cloud's fully managed, scalable NoSQL document database designed for mobile and web applications, offering real-time listeners, offline persistence, and automatic multi-region replication. Data is stored in documents organized into collections, with flexible schema and powerful querying, making it ideal for user profiles, chat messages, and other semi-structured data. Its serverless scaling and client SDKs are optimized for direct app-to-database access, which distinguishes it from the alternatives.

Why this answer

Firestore is Google Cloud's fully managed, scalable NoSQL document database designed for mobile and web applications, with built-in real-time synchronization across clients. It supports offline persistence and live updates, making it ideal for apps that need real-time data sync. Firestore is the direct successor to the original Cloud Datastore and is optimized for these use cases.

Exam trap

GCDL often tests the confusion between Firestore (document DB with real-time sync) and Bigtable (wide-column analytics DB), causing candidates to pick Bigtable when the question emphasizes mobile/web real-time synchronization.

How to eliminate wrong answers

Option A is wrong because Cloud Bigtable is a wide-column NoSQL database optimized for high-throughput analytics and time-series data, not for mobile/web real-time sync. Option C is wrong because Cloud SQL is a managed relational database (MySQL, PostgreSQL, SQL Server), not a NoSQL document store. Option D is wrong because Memorystore is a managed Redis/Memcached in-memory cache, not a document database with real-time sync.

49
MCQmedium

A data engineer needs to process a continuous stream of events from a global user base, perform real-time transformations, and write the results to both Cloud Storage and BigQuery. The solution must handle sudden traffic spikes and be fully managed (no server management). Which combination of services should the engineer use?

A.Pub/Sub, Cloud Functions, Cloud Storage
B.Pub/Sub, Dataflow, Cloud Functions
C.Cloud Scheduler, Cloud Functions, BigQuery
D.Pub/Sub, Dataflow, Cloud Storage, BigQuery
AnswerD

This pipeline uses Pub/Sub for asynchronous ingestion, then Dataflow (the fully managed Apache Beam runner) to read the unbounded stream, apply transforms, and write to two complementary sinks: Cloud Storage for durable raw data or archives, and BigQuery for interactive analytics. Dataflow handles the challenges of streaming—windowing, triggering, exactly-once processing, and auto-scaling—so all services are purpose-built for their roles and form a complete, production-ready architecture.

Why this answer

Pub/Sub ingests the continuous global event stream, Dataflow performs the real-time transformations in a fully managed, autoscaling way, and the pipeline can write results to both Cloud Storage and BigQuery as sinks. This combination meets every requirement: global ingestion, real-time processing, dual output, spike handling via autoscaling, and no server management. Dataflow is the only option that natively supports streaming transformations with exactly-once semantics and writes to multiple sinks.

Exam trap

The trap is picking Cloud Functions as the transformation engine because it is serverless and easy, but the exam expects you to know Dataflow is the managed service for continuous stream processing with multiple sinks.

How to eliminate wrong answers

Option A is wrong because Cloud Functions is event-driven and not designed for continuous stream transformations with windowing and autoscaling; it also lacks a native BigQuery sink in this pipeline. Option B is wrong because Cloud Functions cannot serve as the transformation engine for a continuous stream and does not write to both Cloud Storage and BigQuery as required. Option C is wrong because Cloud Scheduler is for cron-based batch triggers, not continuous streaming, and Cloud Functions cannot handle the real-time transformation workload.

Option D is correct because it includes Pub/Sub for ingestion, Dataflow for transformation, and both Cloud Storage and BigQuery as sinks.

50
MCQeasy

A developer wants to deploy a containerised web application that can scale to zero when not in use, and only pay for actual request processing time. Which Google Cloud compute service should they choose?

A.App Engine Standard Environment
B.Google Kubernetes Engine (GKE)
C.Cloud Run
D.Compute Engine with Preemptible VMs
AnswerC

Cloud Run is a fully managed serverless container platform that executes stateless HTTP/S containers on demand, automatically scaling from zero to handle traffic spikes and back down to zero when requests stop. It accepts any container image that listens on HTTP/HTTPS, pulled from Artifact Registry or Container Registry, and you are billed only for the resources used during request processing (increments of 100ms) with no charge for idle instances. This makes it a direct fit for a containerized web application that needs elastic scaling and pay-per-use pricing without the need to manage clusters or nodes.

Why this answer

Cloud Run is a serverless compute platform that runs containers, scales to zero when idle, and charges per request and CPU/memory usage only during request handling. App Engine Standard can scale to zero but does not support arbitrary containers. GKE and Compute Engine are provisioned infrastructure that does not scale to zero.

51
Multi-Selectmedium

A developer wants to build a CI/CD pipeline that automatically builds a Docker container from a GitHub repository, stores the image securely, and deploys it to Cloud Run. Which THREE services should they integrate? (Select 3)

Select 3 answers
A.Cloud Build
B.Artifact Registry
C.Cloud Storage
D.Cloud Run
E.Cloud Source Repositories
AnswersA, B, D

Cloud Build ingests source code from GitHub and executes a series of build steps, including compiling code and building a Docker image using a Dockerfile. Because it is a managed service, it scales automatically and can trigger builds on commits or PRs, making it the core automation engine of this CI/CD pipeline.

Why this answer

Cloud Build (A) is the correct service to define and execute the CI/CD pipeline that pulls the source from GitHub and runs the docker build steps to produce the container image. Artifact Registry (B) is the secure, recommended place to store and manage the resulting Docker images (replacing the deprecated Container Registry), and Cloud Run can natively pull images from it. Cloud Run (D) is the deployment target where the built image is served as a fully managed serverless container, completing the pipeline.

Cloud Storage (C) is not appropriate because it stores objects/blobs rather than container images with registry semantics, and Cloud Source Repositories (E) is a Git hosting service that would duplicate GitHub rather than build or deploy anything.

Exam trap

The trap here is confusing Cloud Storage with Artifact Registry for container image storage — candidates who have not worked with GCP container workflows often assume any storage service can hold a Docker image.

52
MCQeasy

A startup wants to deploy a containerized web application that can scale to zero during periods of no traffic, and they want to minimize operational overhead. Which Google Cloud compute service is the BEST fit?

A.App Engine Flexible Environment
B.Google Kubernetes Engine (GKE)
C.Cloud Run
D.Compute Engine with managed instance groups
AnswerC

Cloud Run runs stateless containers on a fully managed, serverless platform that automatically scales from zero to thousands of instances based on incoming traffic, and you pay only for the processing time during active requests. It eliminates infrastructure management entirely—no cluster, VMs, or capacity planning—and supports fine-grained revisioning and traffic splitting. This makes it the ideal choice for a containerized web app that must scale to zero during idle periods.

Why this answer

Cloud Run is a serverless container platform that automatically scales your containers up and down, including scaling to zero when there is no traffic. It abstracts away infrastructure management, making it ideal for this use case.

53
Multi-Selectmedium

A company wants to implement a serverless event-driven architecture where object uploads to Cloud Storage trigger a function that processes the file and stores results in Firestore. The function needs to be written in Python. Which three Google Cloud services are required?

Select 3 answers
A.Pub/Sub
B.Cloud Functions
C.Cloud Build
D.Cloud Storage
E.Firestore
AnswersB, D, E

Cloud Functions is the serverless compute layer that runs the Python code when a file is uploaded; the Cloud Storage event (object.finalize) triggers the function with event metadata like bucket and object name. It automatically scales to zero when idle, handles the processing synchronously or asynchronously, and integrates seamlessly with GCP services. Since the requirement specifies running Python code in an event-driven way, Cloud Functions is the correct service for executing the logic.

Why this answer

Cloud Functions (B) is correct because it is the serverless compute service that runs the Python function in response to the event, and it natively supports Python runtimes. Cloud Storage (D) is correct because it is the source of the event: object uploads (finalize events) to a bucket trigger the function, typically via an Eventarc or Cloud Storage trigger. Firestore (E) is correct because it is the destination datastore where the function writes the processing results, as required by the scenario.

Pub/Sub (A) is not required because Cloud Storage events can trigger Cloud Functions directly without an explicit Pub/Sub topic, and Cloud Build (C) is a CI/CD service for building and deploying code, not a runtime component of this event-driven flow.

Exam trap

GCDL often tests whether candidates add Pub/Sub reflexively to any event-driven design; the trap is that Cloud Storage can trigger Cloud Functions directly, so Pub/Sub is not required unless multiple subscribers or decoupling is explicitly needed.

54
MCQeasy

A startup wants to deploy a containerized web application that can scale to zero when not in use and automatically scale based on request traffic. They have limited DevOps experience and want minimal infrastructure management. Which compute service should they choose?

A.App Engine Standard
B.Google Kubernetes Engine
C.Compute Engine
D.Cloud Run
AnswerD

Cloud Run is a fully managed serverless compute platform that executes stateless containers from a Docker image, automatically scaling each instance in response to incoming HTTP requests. It scales to zero when there is no traffic, meaning you pay only for requests actually being processed, with no cluster or VM to manage. This makes it ideal for a startup's containerized web application, providing built-in HTTPS, high availability, and request-based billing without any underlying infrastructure to operate.

Why this answer

Cloud Run is a serverless container platform that scales to zero, automatically scales based on requests, and requires no cluster management, making it ideal for this scenario.

55
Multi-Selectmedium

A company is building a data pipeline that ingests events from multiple sources, processes them in real-time, and stores the results in a data warehouse for analysis. They need a fully managed, serverless solution for stream processing. Which THREE Google Cloud services should they use?

Select 3 answers
A.Dataproc
B.Pub/Sub
C.Dataflow
D.Cloud Functions
E.BigQuery
AnswersB, C, E

Pub/Sub is the correct foundational service for ingesting streaming events because it is a scalable, durable, asynchronous messaging middleware that decouples event producers from consumers. It provides at-least-once delivery, supports push and pull subscriptions, and can buffer spikes in event volume, ensuring that events are not lost before downstream processing. As the entry point of a data pipeline, Pub/Sub is specifically designed to receive high-throughput event streams and make them available to streaming processors like Dataflow.

Why this answer

Pub/Sub (B) is correct because it is the fully managed, serverless messaging service used to ingest events from multiple sources into the pipeline with at-least-once delivery and automatic scaling. Dataflow (C) is correct because it provides fully managed, serverless stream processing with Apache Beam, handling real-time transformations, windowing, and exactly-once processing. BigQuery (E) is correct because it is the serverless data warehouse where the processed results are stored for analysis via SQL.

Dataproc (A) is not appropriate because it is a managed Hadoop/Spark service requiring cluster provisioning, not serverless stream processing. Cloud Functions (D) is event-driven compute for lightweight functions, not a stream-processing engine for continuous pipelines.

Exam trap

GCDL often tests the distinction between 'fully managed' and 'serverless' — candidates may incorrectly select Dataproc because it is a managed service, but it is not serverless, and may overlook Cloud Functions as a stream processor when it is only suitable for lightweight event handling.

56
MCQeasy

A data analyst wants to create interactive dashboards and reports using data from BigQuery, without writing code. Which Google Cloud BI tool should they use?

A.Data Studio
B.Looker Studio
C.Dataflow
D.Looker
AnswerB

Looker Studio (formerly Data Studio) is a free, self-service BI and data visualization platform that lets analysts build interactive dashboards and reports entirely through a drag-and-drop interface, with no code required. It connects directly to data sources such as BigQuery, Google Sheets, and many other databases, and supports shared, embeddable, and scheduled reports. Because the analyst explicitly wants to avoid writing code, Looker Studio's WYSIWYG editor and pre-built connectors make it the correct choice for this requirement.

Why this answer

Looker Studio is a free, self-service BI tool that allows users to create interactive dashboards and reports from various data sources including BigQuery, with a drag-and-drop interface. Looker is a more advanced enterprise BI platform. Data Studio is the former name; it is now Looker Studio.

Dataflow is for data processing.

57
MCQhard

A DevOps engineer wants to automatically delete a Cloud Storage object after 30 days from creation. The object is stored in a bucket with the 'Standard' storage class. Which approach should the engineer use?

A.Set a retention policy on the bucket with a 30-day retention period
B.Change the storage class to 'Archive' which automatically deletes after 30 days
C.Enable object versioning and set a noncurrent time deletion of 30 days
D.Add a lifecycle rule to delete objects after 30 days
AnswerD

A bucket lifecycle rule supports an age-based Delete action, which automatically removes objects after a specified number of days from their creation time. By setting 'age: 30' in the Delete action, Cloud Storage will delete the objects exactly at the 30-day mark during its daily lifecycle evaluation. This is the native, recommended mechanism for automatic object expiration and directly fulfills the requirement.

Why this answer

A lifecycle rule in Cloud Storage allows automatic deletion of objects after a specified age, such as 30 days from creation. This is the standard method to manage object lifecycle and reduce storage costs. The rule can be applied to a bucket and will delete objects matching the criteria.

Exam trap

GCDL often tests the confusion between retention policies (which prevent deletion) and lifecycle rules (which perform deletion), leading candidates to choose retention when deletion is required.

How to eliminate wrong answers

Option A is wrong because a retention policy prevents deletion until the retention period expires; it does not delete objects. Option B is wrong because changing storage class to Archive does not automatically delete objects; it only changes storage class for cost savings. Option C is wrong because object versioning with noncurrent time deletion only deletes noncurrent versions after a period, not the live object.

58
MCQmedium

A development team runs a web application on Cloud Run. They need to store session state across requests. Which Google Cloud service should they use?

A.Memorystore for Redis
B.Cloud Storage
C.Cloud SQL
D.Cloud Pub/Sub
AnswerA

Memorystore for Redis is a fully managed in-memory data store compatible with the Redis protocol, offering sub-millisecond latency for key-value lookups—exactly what session state requires. Cloud Run instances are stateless and ephemeral, scaling to zero when idle, so placing sessions in a shared cache like Memorystore ensures user state survives individual instance lifecycles and remains accessible across autoscaled replicas. Furthermore, Redis-native features such as TTLs, atomic increments, and SETNX are ideal for session expiry, rotation, and concurrency control, making it the correct choice for low-latency session persistence.

Why this answer

Cloud Run instances are stateless; for session state, use an external caching layer like Memorystore (Redis). Pub/Sub is for messaging, Cloud SQL for relational data, and Cloud Storage for objects.

59
MCQmedium

A company wants to migrate its on-premises PostgreSQL database to Google Cloud with minimal application changes. They need high availability and want to leverage AI-powered optimizations for performance. Which service should they choose?

A.Bigtable
B.Cloud SQL for PostgreSQL
C.AlloyDB
D.Cloud Spanner
AnswerC

AlloyDB is purpose-built for PostgreSQL workloads and is fully PostgreSQL-compatible, enabling most applications to migrate without changing code or SQL syntax. It delivers enterprise-grade high availability and performance with a columnar engine that speeds up analytical queries, adaptive indexes that learn from access patterns, and AI-driven optimization features that automatically fine-tune database settings—capabilities that Cloud SQL and other managed PostgreSQL services lack, making it the correct answer for this scenario.

Why this answer

AlloyDB for PostgreSQL is a fully managed, PostgreSQL-compatible database service on Google Cloud that offers high availability and uses AI-powered optimizations for performance, such as adaptive caching and automated tuning. It is designed for minimal application changes because it is wire-compatible with PostgreSQL. This makes it the best fit for migrating an on-premises PostgreSQL database with high availability and AI-driven performance.

Exam trap

GCDL often tests the confusion between Cloud SQL and AlloyDB, where candidates may choose Cloud SQL for PostgreSQL due to familiarity, missing the AI-powered optimizations and higher performance of AlloyDB.

How to eliminate wrong answers

Option A is wrong because Bigtable is a NoSQL wide-column database, not compatible with PostgreSQL, and would require significant application rewrites. Option B is wrong because Cloud SQL for PostgreSQL is a managed service but does not include AI-powered optimizations like AlloyDB; it is more suitable for smaller workloads. Option D is wrong because Cloud Spanner is a globally distributed relational database that is not PostgreSQL-compatible (though it has a PostgreSQL interface, it requires changes and is not a drop-in replacement).

60
MCQmedium

An e-commerce company needs a globally distributed relational database with strong consistency and 99.999% SLA to handle customer orders and inventory across multiple regions. They require SQL compatibility and automatic replication. Which database should they use?

A.Cloud Spanner
B.Bigtable
C.Cloud SQL
D.Firestore
AnswerA

Cloud Spanner is a fully managed relational database that combines the semantics of traditional SQL with horizontal scaling across regions. Using TrueTime, it provides external consistency (strong global consistency) while replicating data across continents, and it offers a 99.999% multi-region SLA. For an e-commerce platform needing global transactions on relational tables, Spanner uniquely satisfies both relational constraints and global distribution.

Why this answer

Cloud Spanner is Google Cloud's globally distributed, horizontally scalable relational database that provides strong consistency (external consistency via TrueTime) and a 99.999% availability SLA for multi-region configurations. It supports ANSI SQL and automatic synchronous replication across regions, which matches the e-commerce requirement for SQL compatibility, global distribution, and strong consistency for orders and inventory. No other option combines relational SQL, global scale, strong consistency, and a five-nines SLA.

Exam trap

GCDL often tests the trade-off between relational consistency and global scale — the trap is selecting Cloud SQL because it is 'SQL,' ignoring that it cannot deliver multi-region strong consistency or the 99.999% SLA.

How to eliminate wrong answers

Option B is wrong because Bigtable is a wide-column NoSQL database with eventual consistency and no SQL support — it is designed for high-throughput analytical and time-series workloads, not relational transactions. Option C is wrong because Cloud SQL is a regional (or HA within a region) managed MySQL/PostgreSQL/SQL Server instance; it does not provide global multi-region strong consistency or a 99.999% SLA. Option D is wrong because Firestore is a document NoSQL database with eventual consistency in multi-region mode and no relational SQL or multi-row ACID transactions across arbitrary queries at global scale.

61
Multi-Selectmedium

A company wants to run a critical stateful application on Compute Engine with the highest availability. The application requires block storage that can survive a zone failure. Which TWO actions should they take? (Choose TWO)

Select 2 answers
A.Use regional Persistent Disk
B.Place instances in a zonal managed instance group
C.Enable object versioning on a Cloud Storage bucket
D.Place instances in a regional managed instance group
E.Use zonal Persistent Disk
AnswersA, D

Regional Persistent Disk synchronously replicates data across two zones in the selected region, providing zone-failure resilience with write-consistent, read-after-write semantics. This makes it the correct choice for a critical stateful application because VM instances can be recreated or failed over to another zone while retaining the same disk data. It supports live migration, snapshots, and resizing, and is the recommended block storage for applications that require high availability without sacrificing durability.

Why this answer

Regional Persistent Disk replicates data across zones synchronously, surviving a zone failure. The instances should be in a regional managed instance group to distribute across zones. Zonal PD and single-zone MIG would not survive zone failure.

62
Multi-Selecteasy

A developer wants to deploy a serverless application that runs code in response to HTTP requests and events from other Google Cloud services. They also need to store configuration and session data in a fast, in-memory data store. Which TWO services should they use? (Choose TWO)

Select 2 answers
A.Cloud Functions
B.Cloud SQL
C.Memorystore
D.Cloud Bigtable
E.Cloud Storage
AnswersA, C

Cloud Functions is Google Cloud's serverless compute service, executing code in response to HTTP requests and events from other Google Cloud services without server management. It satisfies the stem's event-driven, serverless requirement directly, pairing with Memorystore for in-memory session data.

Why this answer

Cloud Functions handles HTTP and event-driven triggers serverlessly. Memorystore provides managed Redis/Memcached for caching and session storage. Cloud SQL is relational and not in-memory.

Cloud Storage is object storage. Bigtable is NoSQL but not in-memory.

63
MCQmedium

A developer wants to deploy a Python script that runs in response to new files uploaded to a Cloud Storage bucket. The script performs simple image transformations. Which compute service is the BEST fit?

A.App Engine
B.Cloud Functions
C.Compute Engine
D.Cloud Run
AnswerB

Cloud Functions is Google Cloud's event-driven serverless compute platform that runs Python code in response to specific triggers, including Cloud Storage events like object finalization. With a Storage trigger, the function is automatically invoked with the object metadata, eliminating the need to manage infrastructure or a web server. This matches the requirement to react to file uploads with low operational overhead and automatic scaling.

Why this answer

Cloud Functions is event-driven and designed for lightweight code that runs in response to events like Cloud Storage object changes.

64
MCQmedium

A company wants to analyse streaming data from IoT devices in real time with sub-second latency, using SQL queries. Which combination of services should they use?

A.Cloud IoT Core + Cloud Functions + Bigtable
B.Cloud Pub/Sub + Dataproc + Cloud Storage
C.Cloud Pub/Sub + Cloud Functions + Cloud SQL
D.Cloud Pub/Sub + Dataflow + BigQuery
AnswerD

Pub/Sub ingests the IoT data stream durably and asynchronously, Dataflow (Apache Beam) processes it in a fully managed, autoscaling manner with sub-second latency, exactly-once semantics, and support for event-time windows, filters, and enrichments, then writes results to BigQuery using the Storage Write API. BigQuery is a fully managed, serverless, columnar data warehouse that provides native SQL analytics over the streamed data, making this combination the canonical GCP architecture for real-time streaming SQL.

Why this answer

Dataflow with unbounded sources (like Pub/Sub) and SQL via Beam SQL or Dataflow SQL can process streaming data with low latency. BigQuery can also stream data but with higher latency (seconds). Cloud Functions is not ideal for real-time SQL analytics.

Dataproc is for batch processing.

65
MCQmedium

A team needs to run a machine learning model using custom code in Python with TensorFlow, and they want to train it at scale on GPU hardware without managing infrastructure. Which Google Cloud service is best suited?

A.Vertex AI
B.Cloud Run
C.Compute Engine
D.Cloud Functions
AnswerA

Vertex AI is a fully managed machine learning platform that supports custom container training, allowing you to bring your own model code and dependencies while leveraging managed GPU and TPU clusters. It provides automatic scaling, hyperparameter tuning, and integrated MLOps tools like model versioning, monitoring, and Vertex Pipelines, which drastically reduce operational overhead compared to raw compute. This makes it the ideal choice for running custom ML models at scale without manually provisioning infrastructure.

Why this answer

Vertex AI is Google Cloud's unified ML platform that supports custom Python code with frameworks like TensorFlow and provides managed training on GPU hardware without infrastructure management. It offers Vertex AI Training with pre-built containers or custom containers, auto-scaling, and integration with GPUs/TPUs. This directly matches the requirement to train at scale on GPUs with custom code.

Exam trap

GCDL often tests the distinction between managed ML platforms and raw compute, and candidates pick Compute Engine because it 'supports GPUs'—missing that the requirement for no infrastructure management points to Vertex AI.

How to eliminate wrong answers

Option B is wrong because Cloud Run is a serverless container platform for stateless HTTP services, not designed for GPU-accelerated ML training jobs or long-running training workloads. Option C is wrong because Compute Engine provides raw VMs where the team would have to manage infrastructure, install drivers, and orchestrate training—contradicting the 'without managing infrastructure' requirement. Option D is wrong because Cloud Functions is an event-driven serverless compute service for short-lived functions, with no GPU support and execution time limits that make it unsuitable for ML training.

66
MCQmedium

A team is developing a machine learning model using TensorFlow. They want to train the model on a large dataset stored in Cloud Storage, using GPUs, and then deploy the trained model for online predictions with autoscaling. Which GCP service should they use for the entire workflow?

A.Vertex AI
B.AI Platform (legacy)
C.Cloud Functions
D.Compute Engine with pre-installed ML frameworks
AnswerA

Vertex AI provides a unified managed platform that covers the full ML lifecycle: training with custom or pre-built containers on GPU/TPU, versioning in a Model Registry, and deployment to prediction endpoints with built-in autoscaling based on traffic. It eliminates the need to manually configure infrastructure, allows custom model serving for any framework, and offers MLOps capabilities like monitoring and drift detection. This makes it the recommended service for training and serving TensorFlow models.

Why this answer

Vertex AI is Google Cloud's unified machine learning platform that supports the entire ML workflow: data ingestion from Cloud Storage, training with GPUs, model deployment for online predictions, and autoscaling. It integrates with TensorFlow and provides managed services for each stage. AI Platform (legacy) is deprecated and lacks the full unified experience.

Exam trap

The trap is confusing Vertex AI with legacy AI Platform or assuming that raw Compute Engine is sufficient; the exam tests that Vertex AI is the current, unified service for end-to-end ML workflows.

How to eliminate wrong answers

Option B is wrong because AI Platform (legacy) is an older, deprecated service that does not offer the same integrated workflow or autoscaling capabilities as Vertex AI. Option C is wrong because Cloud Functions is a serverless compute service for event-driven functions, not for training or deploying ML models. Option D is wrong because Compute Engine with pre-installed ML frameworks requires manual setup, scaling, and management, and does not provide a unified workflow for training and deployment.

67
MCQeasy

A company wants to migrate its on-premises MySQL database to Google Cloud with minimal changes to the application. Which managed database service should they use?

A.Cloud Spanner
B.Cloud Bigtable
C.Cloud SQL for MySQL
D.Firestore
AnswerC

Cloud SQL for MySQL is Google Cloud's fully managed service that is natively compatible with the MySQL engine, including support for MySQL 5.7, 8.0, and 8.4. It provides the same SQL syntax, stored procedures, triggers, and InnoDB storage engine, so existing applications can connect with standard MySQL drivers and require minimal to no code changes. With automated backups, high availability, read replicas, and straightforward import tools, it is the correct and lowest-risk choice for migrating an on-premises MySQL database.

Why this answer

Cloud SQL provides managed MySQL, PostgreSQL, and SQL Server databases. It is compatible with existing MySQL applications. Cloud Spanner is globally distributed but not drop-in MySQL.

Firestore and Bigtable are NoSQL.

68
MCQhard

A company wants to migrate its on-premises Oracle database to Google Cloud. They need PostgreSQL compatibility with high performance for transaction processing and built-in support for AI-driven optimisations. Which database service should they choose?

A.Cloud Spanner
B.Bigtable
C.Cloud SQL for PostgreSQL
D.AlloyDB
AnswerD

AlloyDB is a fully managed, PostgreSQL-compatible database service engineered for high performance and scalability, with AI-driven optimizations such as adaptive caching and an integrated columnar engine. It provides up to 4x faster transactional performance and 10x faster analytical queries than standard PostgreSQL, and its compatibility layer supports Oracle-like data types, functions, and SQL syntax, easing migration from Oracle. These capabilities directly align with the company's requirement for a PostgreSQL-compatible database with intelligent performance enhancements.

Why this answer

AlloyDB is Google Cloud's fully managed PostgreSQL-compatible database designed for high-performance transactional workloads, with built-in AI-driven optimizations such as adaptive indexing and automatic query tuning. It offers superior performance compared to standard Cloud SQL for PostgreSQL while maintaining full PostgreSQL compatibility.

Exam trap

The trap is confusing Cloud SQL for PostgreSQL with AlloyDB — both are PostgreSQL-compatible, but only AlloyDB provides the high-performance, AI-driven optimizations described in the question.

How to eliminate wrong answers

Option A is wrong because Cloud Spanner is a globally distributed, horizontally scalable relational database but is not PostgreSQL-compatible in the traditional sense and is not optimized for AI-driven optimizations. Option B is wrong because Bigtable is a NoSQL wide-column store, not a relational PostgreSQL-compatible database. Option C is wrong because Cloud SQL for PostgreSQL is PostgreSQL-compatible but does not provide the high-performance, AI-driven optimizations that AlloyDB offers for demanding transactional workloads.

69
Multi-Selecthard

A company runs a batch processing job every hour using Cloud Dataflow. They notice increasing costs and want to optimize. Which three actions would reduce cost? (Choose exactly 3.)

Select 3 answers
A.Use preemptible VMs for worker nodes
B.Shut down the Dataflow job between runs
C.Switch from batch to streaming mode
D.Set autoscaling to a lower maximum number of workers
E.Use flexible resource scheduling (batch mode)
AnswersA, D, E

Preemptible VMs (now called spot VMs in Google Cloud) provide a significantly discounted price (typically 60-80% off on-demand pricing) for worker nodes in a Dataflow batch pipeline. Because Dataflow is designed to handle worker loss through checkpointing and automatic restart of tasks, batch jobs are generally resilient to the occasional termination that preemptible VMs may undergo. This directly reduces the compute cost of the worker pool without changing the pipeline logic or delivery time, making it the most straightforward way to cut costs for a recurring batch job.

Why this answer

Option A is correct because Dataflow batch jobs can run on preemptible VMs (now called Spot VMs), which cost substantially less than standard Compute Engine instances; Dataflow handles preemption by rescheduling work, making this a standard cost optimization for batch pipelines. Option D is correct because capping the autoscaling maximum number of workers prevents the job from over-provisioning workers during demand spikes, directly limiting the compute cost incurred per run. Option E is correct because Flexible Resource Scheduling (FlexRS) in batch mode uses a mix of preemptible and standard VMs with a delayed, lower-cost scheduling window, reducing the effective cost of batch processing.

Option B is not appropriate because a batch Dataflow job terminates on its own when the pipeline finishes, so there is no running job to shut down between hourly runs. Option C is incorrect because switching from batch to streaming keeps workers running continuously and typically increases cost, the opposite of the goal.

Exam trap

GCDL often tests the misconception that streaming mode is cheaper or that stopping jobs saves money — candidates pick 'switch to streaming' or 'shut down between runs' without realizing streaming is more expensive and batch jobs already terminate.

70
MCQeasy

A company wants to monitor the CPU and memory utilisation of their Compute Engine instances and set up alerts when utilisation exceeds 80%. Which Google Cloud service should they use?

A.Cloud Monitoring
B.Cloud Logging
C.Cloud Error Reporting
D.Cloud Trace
AnswerA

Cloud Monitoring is the correct service because it is purpose-built to ingest and store numeric time-series metrics, such as CPU utilization and memory usage, from resources like Compute Engine and Kubernetes. It provides alerting policies that trigger notifications when these metrics cross user-defined thresholds, and offers dashboards and querying via MQL or PromQL. This is the standard GCP tool for real-time infrastructure observability, not just logging or error tracking.

Why this answer

Cloud Monitoring collects metrics from Compute Engine instances via the Ops Agent (or legacy monitoring agent) and provides alerting policies based on metric thresholds. CPU utilization and memory utilization are standard metrics (compute.googleapis.com/instance/cpu/utilization and memory/utilization) that can be charted and alerted on when exceeding 80%. This is the native GCP service for metric-based monitoring and alerting.

Exam trap

The trap is confusing monitoring with logging or tracing — candidates may pick Cloud Logging because they think alerts come from logs, but metric-based threshold alerts belong to Cloud Monitoring.

How to eliminate wrong answers

Option B is wrong because Cloud Logging is for ingesting, storing, and analyzing log data, not for metric-based threshold alerting on resource utilization. Option C is wrong because Cloud Error Reporting aggregates and displays application errors from logs, not infrastructure metrics. Option D is wrong because Cloud Trace is a distributed tracing system for latency analysis of requests, not resource utilization monitoring.

71
MCQeasy

Which Google Cloud service is a managed platform for building, training, and deploying ML models, including support for AutoML and custom models?

A.BigQuery ML
B.AI Platform (legacy)
C.Cloud TPU
D.Vertex AI
AnswerD

Vertex AI is Google Cloud's unified, end-to-end managed ML platform that covers the full model lifecycle, from data preparation and feature engineering to AutoML or custom training, hyperparameter tuning, model validation, deployment, and continuous monitoring. It provides a single API and workflow that integrates with Cloud Storage, BigQuery, and other Google Cloud services, while also offering advanced MLOps components like Vertex AI Pipelines, Model Registry, and Vertex AI Feature Store. As a fully managed service, Vertex AI abstracts infrastructure management, enabling automated autoscaling for prediction endpoints, security policies, and versioning, making it the correct answer to the question.

Why this answer

Vertex AI is a unified ML platform that combines AutoML and custom model training, tuning, and serving.

72
MCQeasy

Which Google Cloud service provides a fully managed, serverless data warehouse for petabyte-scale analytics with SQL?

A.Cloud SQL
B.BigQuery
C.Dataproc
D.Dataflow
AnswerB

BigQuery is Google Cloud's serverless, highly scalable, SQL-based data warehouse. It automatically manages infrastructure and scales compute and storage independently, using a columnar storage format and a distributed query engine (Dremel) to run analytics on petabytes of data. With a pay-per-query pricing model and no clusters to provision, BigQuery is the definitive choice for a fully managed data warehouse on Google Cloud.

Why this answer

BigQuery is Google Cloud's fully managed, serverless data warehouse. It supports SQL queries at petabyte scale with no infrastructure to manage. Cloud SQL is for OLTP, Dataproc is for Hadoop/Spark, and Dataflow is for stream/batch processing.

73
Multi-Selecthard

A company wants to reduce costs for its batch processing jobs that run nightly on Compute Engine. The jobs are fault-tolerant and can be interrupted. They are considering using preemptible VMs. Which THREE statements about preemptible VMs are true?

Select 3 answers
A.Preemptible VMs can be migrated to regular VMs if preemption occurs.
B.Preemptible VMs do not offer live migration.
C.Preemptible VMs provide the same SLA as standard VMs.
D.Preemptible VMs can run for up to 24 hours before they may be terminated.
E.Preemptible VMs are significantly cheaper than standard VMs.
AnswersB, D, E

Unlike standard Compute Engine VMs, which benefit from live migration during infrastructure maintenance, preemptible VMs are not live-migrated. If the underlying host needs maintenance or Google reclaims capacity, the VM is immediately terminated within 30 seconds of the preemption notice. This means the VM's state is lost unless you have explicitly saved it elsewhere.

Why this answer

Preemptible VMs can be terminated at any time within 24 hours (typical max 24h). They are significantly cheaper than regular VMs. They cannot be migrated to regular VMs; you must recreate them.

They do not offer live migration. They are suitable for fault-tolerant batch jobs.

74
Multi-Selecthard

A company is building a microservices architecture on Google Kubernetes Engine (GKE). They need to expose services externally with HTTPS, distribute traffic across the cluster, and protect against DDoS attacks. Which THREE Google Cloud services should they combine? (Choose THREE)

Select 3 answers
A.Cloud DNS
B.VPC firewall rules
C.Cloud CDN
D.Cloud Armor
AnswersC, D, E

Cloud CDN caches content at Google's global edge points of presence, absorbing volumetric traffic before it reaches your GKE backends. This directly satisfies the DDoS protection constraint: attack requests terminate at edge locations rather than consuming cluster resources, while also reducing origin load and latency for externally exposed HTTPS services.

Why this answer

Cloud Load Balancing (E) is correct because it provides the external HTTPS load balancer that fronts the GKE services, terminates TLS, and distributes incoming traffic across the cluster's nodes and pods. Cloud Armor (D) is correct because it attaches to the external load balancer's backend service to provide WAF rules and Layer 3/4/7 DDoS protection, including Google Cloud's edge-based network DDoS mitigation. Cloud CDN (C) is correct because it caches content at Google's global edge locations, reducing origin load and absorbing traffic spikes, which complements the load balancer and helps mitigate volumetric attacks.

Cloud DNS (A) is not required for this scenario since it only resolves domain names and does not distribute traffic or provide DDoS protection, and VPC firewall rules (B) operate at the network level within the VPC but do not expose services externally over HTTPS or defend against DDoS at the edge.

Exam trap

The trap is including Cloud DNS or VPC firewall rules as part of the traffic distribution and protection solution; candidates must distinguish name resolution and network-level filtering from the edge services that actually load balance, cache, and defend against DDoS.

75
Multi-Selectmedium

A company is building a real-time analytics pipeline on Google Cloud. They need to ingest streaming data from IoT devices, process it with low latency, and then store the results for real-time querying. Which TWO services should they use? (Choose TWO.)

Select 2 answers
A.Cloud Pub/Sub
B.Cloud Storage
C.Cloud Dataflow
D.Cloud Functions
E.BigQuery
AnswersA, C

Cloud Pub/Sub provides the durable, globally scalable messaging layer that ingests streaming telemetry from IoT devices, decoupling producers from consumers. It satisfies the ingestion stage of the pipeline, buffering events until Dataflow processes them with low latency.

Why this answer

Cloud Pub/Sub (A) is correct because it is Google Cloud's fully managed, globally scalable messaging service designed for ingesting high-volume streaming data from sources such as IoT devices, decoupling producers from consumers with low-latency, at-least-once delivery. Cloud Dataflow (C) is correct because it is a fully managed Apache Beam runner that performs stream and batch processing with low latency, including windowing, aggregations, and exactly-once semantics, making it the right choice to transform the Pub/Sub stream before writing results downstream. Cloud Storage (B) is not appropriate as the primary ingestion or processing layer for real-time streaming, since it is object storage optimized for durable blobs rather than low-latency event streams.

Cloud Functions (D) is event-driven and serverless but is intended for lightweight, short-lived functions, not sustained low-latency stream processing pipelines. BigQuery (E) is a powerful analytics warehouse for real-time querying of stored results, but it is a destination/serving layer rather than the ingestion or stream-processing service the scenario requires.

Exam trap

The trap is selecting BigQuery as a processing service — it is the analytics destination, not the stream processor; candidates also confuse Cloud Functions with Dataflow for stream processing.

Page 1 of 2 · 126 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Cdl Google Cloud Products questions.