Google PCA Design and plan a cloud solution architecture Practice Question
A company is deploying a new microservices application on Google Kubernetes Engine (GKE). They need to ensure that each microservice can be independently scaled and updated without affecting other services. They also want to minimize the blast radius of a failure in one microservice. Which design approach should they use?
⚠ Common exam trap
The trap here is assuming that grouping containers in a single pod or using a StatefulSet simplifies management, when it actually reduces isolation and independent scalability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy each microservice as a separate Deployment with its own Horizontal Pod Autoscaler and use separate namespaces for isolation.
Using separate Deployments for each microservice enables independent scaling and rolling updates. Each Deployment can have its own HPA, and namespaces provide isolation. This design minimizes the impact of a failure in one service and aligns with microservices best practices. The other options either couple services together or lack automation and resilience.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Deploy all microservices in a single Deployment with multiple containers per pod.
Why it's wrong here
A single Deployment with multiple containers in a pod couples the lifecycle of all microservices; scaling and updating one would affect all. This increases the blast radius and does not allow independent scaling. It also violates the microservices principle of independent deployability.
- ✗
Deploy each microservice as a separate pod without a controller, and manage them manually.
Why it's wrong here
Pods without a controller are not rescheduled if they fail, and they cannot be easily scaled or updated. This approach lacks the automation and resilience of Deployments and would increase operational overhead. It also does not provide isolation or independent scaling.
- ✗
Use a single StatefulSet for all microservices to maintain persistent identities.
Why it's wrong here
A StatefulSet is designed for stateful applications that require stable network identities and persistent storage. Using it for all microservices would couple them and make independent scaling and updates difficult. It also does not provide isolation between services, increasing the blast radius.
- ✓
Deploy each microservice as a separate Deployment with its own Horizontal Pod Autoscaler and use separate namespaces for isolation.
Why this is correct
Separate Deployments allow independent scaling and updates. Each can have its own Horizontal Pod Autoscaler based on its specific metrics. Using separate namespaces provides logical isolation, reducing the blast radius of failures and simplifying resource management. This is a standard GKE design for microservices.
Quick reference
AAA Protocol Comparison
| Protocol | Port(s) | Encryption | Transport | Primary Use |
|---|---|---|---|---|
| RADIUS | 1812 / 1813 | Password only | UDP | Network access control |
| TACACS+ | 49 | Full packet | TCP | Device administration |
| Diameter | 3868 | Full session | TCP / SCTP | Carrier / mobile networks |
| 802.1X | — | EAP-based | Layer 2 | Port-based access control |
TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.
Go deeper
Related to this question
Learn chapter
Virtual Machine Instances in Compute Engine
Key term
CAN
A CAN (Controller Area Network) is a robust vehicle bus standard designed to allow microcontrollers and devices to communicate with each other without a host computer.
Key term
Service
A service is a software component or system that performs a specific function and is available to be used by other programs or users over a network.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.