Google PCA Design and plan a cloud solution architecture Practice Question
A healthcare analytics company ingests HL7 messages into Pub/Sub and processes them with a Dataflow streaming pipeline that writes results to BigQuery. During a regional outage, the pipeline stopped and the team discovered that unacknowledged messages were lost after the retention window expired. The company needs a design where a single-region failure does not cause message loss and the pipeline can resume with minimal manual intervention. What should the architect recommend?
⚠ Common exam trap
The trap here is treating longer retention or a dead-letter topic as disaster recovery, when both remain bound to a single regional topic and cannot survive that region becoming unavailable.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Deploy the Dataflow pipeline as a regional job in two regions with a Pub/Sub subscription in each, and configure the topic to store messages in a second region using message storage policy or a global endpoint.
The failure mode is losing messages when a single region is unavailable and the retention window closes. Keeping Pub/Sub message data in more than one region through a message storage policy or global endpoint, plus running the Dataflow job regionally in two locations each with its own subscription, gives both durability of the messages and a surviving processing path. Retention tuning, object storage substitution, and autoscaling do not remove the single-region dependency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase the Pub/Sub message retention duration to the maximum and add a dead-letter topic so failed messages are preserved for later reprocessing.
Why it's wrong here
Extending retention and adding a dead-letter topic improve recoverability from processing failures, but both remain tied to a single regional topic. If that region is unavailable, the subscription cannot deliver and the retention clock still runs out. Neither change provides a surviving copy in another region or automatic failover for the streaming pipeline.
- ✗
Replace Pub/Sub with a Cloud Storage bucket in dual-region mode and have Dataflow read new objects with a streaming pipeline triggered by Eventarc notifications.
Why it's wrong here
Cloud Storage dual-region does provide geographic redundancy, but it is object storage, not a messaging system: ordering, per-message acknowledgment, and backpressure semantics that the HL7 ingestion relies on are lost. Eventarc notifications are at-least-once and can duplicate or reorder, and reworking the ingestion contract is a large redesign rather than a targeted fix.
- ✗
Run the Dataflow pipeline in a single region but enable autoscaling and set the maximum number of workers higher so it drains the backlog faster after an outage.
Why it's wrong here
Autoscaling and a higher worker cap improve throughput during normal operation and shorten backlog drain time, but they do nothing for a regional failure of the topic or the pipeline. If the region hosting the job is unavailable, more workers in that same region cannot run. This addresses performance, not durability or availability.
- ✓
Deploy the Dataflow pipeline as a regional job in two regions with a Pub/Sub subscription in each, and configure the topic to store messages in a second region using message storage policy or a global endpoint.
Why this is correct
Pub/Sub already replicates message data within a region, and a message storage policy or global endpoint lets you keep data in additional regions so a topic survives a regional failure. Running the Dataflow job regionally in two locations with a subscription each means one pipeline keeps draining messages while the other region is down, satisfying both durability and low-touch recovery.
Go deeper
Related to this question
Learn chapter
Cloud Storage: Objects and Buckets
Key term
Dataflow
Dataflow is a Google Cloud managed service that processes and transforms data in real-time or batch mode using Apache Beam pipelines.
Key term
Pub/Sub
Pub/Sub is a messaging pattern where publishers send messages without knowing who receives them, and subscribers receive only the messages they care about.
About these practice questions
One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.