Courseiva

Google PCA Ensure solution and operations reliability Practice Question

A healthcare company runs a patient portal on Cloud Run services in the us-central1 region. The compliance team requires that the portal remain readable during a regional outage and that failover to a secondary region occur without changing the public hostname. The portal's data is stored in Cloud SQL for PostgreSQL. Which design should the architect recommend?

⚠ Common exam trap

The trap here is assuming Cloud SQL performs automatic cross-region failover like its within-region high availability mode, when cross-region recovery requires promoting a replica.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy the Cloud Run services in us-central1 and us-east1 behind a global external Application Load Balancer with a serverless network endpoint group per region, and use a Cloud SQL cross-region replica promoted on failover.

A global external Application Load Balancer with serverless network endpoint groups in two regions gives a stable anycast hostname that keeps working when one region fails, and Cloud Run's multi-region deployment provides compute in both places. For the data tier, a Cloud SQL cross-region replica must be promoted during regional failover, since Cloud SQL does not automatically fail over across regions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Deploy the Cloud Run services in both regions and use Cloud DNS geolocation routing with a 300-second TTL to direct users to the healthy region.

    Why it's wrong here

    Geolocation routing sends users based on where they appear to originate, not on backend health, and a 300-second TTL means clients can cache the stale record long after a region fails. Failover would not be automatic on outage detection, and the delay would likely breach the compliance expectation of continuous readability during a regional failure.

  • ✗

    Deploy the Cloud Run services in us-central1 only and front them with a regional external Application Load Balancer and a Cloud DNS failover routing policy pointing to a static IP.

    Why it's wrong here

    A regional load balancer and a single Cloud Run region keep all compute in one failure domain, so a us-central1 outage takes the portal down entirely. Cloud DNS failover routing changes the answer the resolver returns, which depends on client and resolver TTL caching, so it cannot deliver the near-instant, hostname-preserving failover the requirement implies.

  • ✗

    Deploy the Cloud Run services in both regions behind a global external Application Load Balancer, and rely on Cloud SQL's automatic regional failover of the primary instance.

    Why it's wrong here

    The multi-region load balancing half is sound, but Cloud SQL for PostgreSQL does not perform automatic cross-region failover of a primary instance; high availability configuration protects within a region across zones. Without a cross-region replica to promote, the data tier remains a single-region dependency and the portal cannot serve reads after a regional outage.

  • ✓

    Deploy the Cloud Run services in us-central1 and us-east1 behind a global external Application Load Balancer with a serverless network endpoint group per region, and use a Cloud SQL cross-region replica promoted on failover.

    Why this is correct

    A global external Application Load Balancer provides a single anycast hostname and can route to serverless network endpoint groups in multiple regions, so failover happens without DNS changes. A Cloud SQL cross-region replica keeps a warm copy of the data that can be promoted if the primary region fails, satisfying the readability requirement during a regional outage.

Quick reference

Cloud Service Model Comparison

ModelYou ManageProvider ManagesExamples
IaaSOS, runtime, apps, dataHardware, hypervisor, networkingEC2, Azure VMs, GCP Compute Engine
PaaSApps and dataOS, runtime, middleware, hardwareElastic Beanstalk, Azure App Service
SaaSData and settings onlyEverything elseMicrosoft 365, Salesforce, Workday
FaaS / ServerlessFunction code onlyInfra, scaling, runtimeLambda, Azure Functions, Cloud Run
CaaSContainers and appsKubernetes, OS, hardwareEKS, AKS, GKE

About these practice questions

One of 807 original PCA practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.