Courseiva

Google Professional Cloud Architect (PCA) — Questions 1–75

807 questions total · 11pages · All types, answers revealed

Page 1 of 11

Page 2
1
MCQhard

A company uses BigQuery for large-scale analytics. They have a fixed monthly budget and want to ensure predictable costs for query processing, even when many users run concurrent queries. Which BigQuery pricing model should they use?

A.On-demand pricing with flat-rate discounts
B.Autoscaling slot reservations
C.Flat-rate pricing with slot reservations
D.On-demand pricing with committed use discounts
AnswerC

Flat-rate pricing with slot reservations provisions dedicated query-processing capacity for a fixed monthly fee, decoupling cost from query volume. This satisfies the stem's requirement for predictable spend under concurrent workloads, unlike on-demand pricing, which scales with bytes processed.

Why this answer

Flat-rate pricing with slot reservations is correct because it provides a fixed monthly cost for a committed number of slots, making query processing costs predictable regardless of concurrent query volume. This aligns with a fixed budget and many concurrent users, since slots are dedicated capacity rather than per-query billing.

Exam trap

PCA often tests the difference between on-demand and flat-rate pricing — candidates pick autoscaling or committed-use discounts, but only flat-rate reservations give a truly fixed monthly cost.

How to eliminate wrong answers

Option A is wrong because on-demand pricing with flat-rate discounts is not a real BigQuery model; on-demand is per-TB scanned and inherently variable. Option B is wrong because autoscaling slot reservations adjust capacity dynamically, which can increase costs beyond a fixed budget. Option D is wrong because on-demand pricing with committed use discounts still bills per query and does not guarantee predictable monthly costs under concurrent load.

2
MCQmedium

Refer to the exhibit. A cloud administrator is attempting to grant the BigQuery Data Viewer role to an external user (user@example.com) but receives the error shown. What is the most likely cause?

A.The organization policy constraints/iam.allowedPolicyMemberDomains blocks external domains.
B.The BigQuery dataset requires domain-wide delegation.
C.The user does not have the resourcemanager.projects.setIamPolicy permission.
D.The external user must first be added to a Google Group.
AnswerA

The constraint `constraints/iam.allowedPolicyMemberDomains` restricts which identity domains may appear in IAM policy bindings. Because `user@example.com` sits outside the permitted Workspace or Cloud Identity customer, the binding is rejected outright, matching the stem's failure to grant BigQuery Data Viewer to that external account.

Why this answer

The error indicates that the organization's policy constraints/iam.allowedPolicyMemberDomains is blocking the addition of an external user. This constraint restricts IAM policy bindings to only allow members from specified domains, and since user@example.com is from an external domain, the binding is denied. The error message directly references this constraint, making it the most likely cause.

Exam trap

Google often tests the distinction between IAM permission errors and organization policy constraints, where candidates mistakenly focus on the administrator's permissions (Option C) rather than the broader policy that blocks external members.

How to eliminate wrong answers

Option B is wrong because domain-wide delegation is a Google Workspace feature for service accounts to access user data, not related to granting IAM roles to external users. Option C is wrong because the error message does not indicate a permissions issue for the administrator; the error is about policy constraints, not missing IAM permissions. Option D is wrong because Google Groups are not required for granting IAM roles to external users; the constraint blocks any external member regardless of group membership.

3
MCQeasy

A company needs to store archival data that is accessed less than once a year. They want the lowest storage cost possible, but they can accept a retrieval time of up to 24 hours. Which Cloud Storage class should they use?

A.Nearline
B.Archive
C.Standard
D.Coldline
AnswerB

Archive is the coldest Cloud Storage class, priced lowest per gigabyte, and its retrieval latency of hours up to roughly a day fits the acceptable 24-hour window. Nearline and Coldline cost more and retrieve faster than this rarely accessed archival data requires.

Why this answer

Archive storage is the lowest-cost storage class for long-term archival with retrieval times in hours (typically 24 hours). Coldline is for data accessed less than once a quarter. Nearline is for monthly access.

Standard is for frequently accessed data.

4
Multi-Selectmedium

A company is deploying a microservices application on Google Kubernetes Engine (GKE). The architect needs to ensure that the cluster can automatically scale nodes based on pod resource requests and that pods are scheduled efficiently across nodes. The company also wants to minimize costs by scaling down when demand is low. Which two configurations should the architect implement? (Choose two.)

Select 2 answers
A.Enable Cluster Autoscaler on the node pool with a minimum and maximum node count.
B.Configure Horizontal Pod Autoscaler (HPA) based on CPU utilization.
C.Set pod resource requests and limits for CPU and memory.
D.Use a regional cluster with multiple zones.
E.Enable node auto-provisioning for the cluster.
AnswersA, C

Cluster Autoscaler automatically adjusts the number of nodes in a node pool based on the resource requests of pending pods. It scales up when pods cannot be scheduled due to insufficient resources and scales down when nodes are underutilized. Setting a minimum and maximum node count ensures cost control and availability. This directly addresses the need to scale nodes based on pod demands and minimize costs during low demand.

Why this answer

Cluster Autoscaler scales the number of nodes in a node pool based on pending pod resource requests, and setting pod resource requests ensures that the scheduler and autoscaler have accurate information to make scaling decisions. Together, they enable automatic node scaling and efficient scheduling while allowing scale-down to reduce costs. The other options either address pod scaling, add unnecessary complexity, or improve availability without meeting the core requirements.

Exam trap

The trap here is assuming that Horizontal Pod Autoscaler alone can scale nodes; it only scales pod replicas, not the underlying node pool.

5
Multi-Selectmedium

A security team needs to detect and redact personally identifiable information (PII) in documents stored in Cloud Storage before sharing them with external partners. Which two Google Cloud services should they use together? (Choose two.)

Select 2 answers
A.Cloud Data Loss Prevention (DLP) API
B.Cloud Storage
C.Cloud KMS
D.Cloud Dataflow
E.Cloud NAT
AnswersA, B

The Cloud DLP API inspects content, identifies PII using infoType detectors, and performs de-identification such as redaction or masking. It satisfies the detection and redaction requirement directly, providing the inspection engine that processes documents before external sharing.

Why this answer

The Cloud Data Loss Prevention (DLP) API (A) is the correct service for detecting and redacting personally identifiable information, since it provides infoType detectors and de-identification transforms such as redaction, masking, and tokenization that can scan and sanitize sensitive data. Cloud Storage (B) is also correct because the documents being scanned and shared reside in Cloud Storage buckets, and DLP integrates directly with Cloud Storage to inspect and de-identify objects in place or on export. Together, DLP performs the PII detection and redaction while Cloud Storage holds the source and destination documents, matching the scenario's requirement to sanitize files before external sharing.

Cloud KMS (C) only manages encryption keys and cannot detect or redact PII content. Cloud Dataflow (D) is a data processing pipeline service that could orchestrate jobs but does not itself provide PII detection or redaction logic. Cloud NAT (E) is a networking service for outbound internet access and is unrelated to data inspection or redaction.

Exam trap

PCA often tests whether candidates confuse the service that detects/redacts sensitive data (DLP) with services that merely move, encrypt, or process it (Dataflow, KMS, Storage).

6
MCQeasy

An engineer needs to view the logs of a specific Compute Engine instance in near real-time from the command line. Which gcloud command should they use?

Answer options not yet available.

Why this answer

gcloud logging tail streams logs in near real-time. gcloud compute ssh gives shell access, not logs. gcloud logging read queries past logs. gcloud app logs tail is for App Engine.

7
MCQhard

A healthcare organization stores Protected Health Information (PHI) in Cloud SQL. They have implemented encryption at rest using CMEK and enforce TLS for all connections. To meet HIPAA compliance, they need to ensure that PHI cannot be exfiltrated from the Cloud SQL instance even if an application is compromised. The Cloud SQL instance is accessed by Compute Engine instances in the same VPC using private IPs. The security team wants to add an additional layer of defense against data exfiltration. What should they do?

A.Deploy Cloud Armor and apply a WAF rule to block suspicious traffic to the Cloud SQL instance.
B.Use the Cloud SQL Auth proxy from all applications to enforce IAM-based authentication.
C.Configure VPC Service Controls with a service perimeter that includes the Cloud SQL instance and uses Private Service Connect.
D.Enable customer-managed encryption keys (CMEK) on the Cloud SQL instance.
AnswerC

VPC Service Controls perimeters restrict data movement across project boundaries, and Private Service Connect keeps Cloud SQL traffic on private endpoints, blocking exfiltration even if the application is compromised. This adds the required defence layer beyond CMEK and TLS.

Why this answer

VPC Service Controls with a service perimeter that includes the Cloud SQL instance and uses Private Service Connect prevents data exfiltration by creating a security boundary around the Cloud SQL instance. Even if an application is compromised, the service perimeter blocks unauthorized copying or movement of PHI outside the perimeter, and Private Service Connect ensures traffic stays within Google's network without traversing the public internet. This directly addresses the requirement for an additional layer of defense against exfiltration beyond encryption and TLS.

Exam trap

In Google PCA exams, the trap is that candidates confuse encryption (CMEK) or secure connectivity (Auth proxy) with exfiltration prevention, not realizing that VPC Service Controls is the only option that creates a data boundary to block unauthorized data movement even from compromised applications.

How to eliminate wrong answers

Option A is wrong because Cloud Armor is a web application firewall (WAF) that protects HTTP(S) load-balanced traffic, but Cloud SQL uses private IPs within a VPC and does not have a public HTTP endpoint, so Cloud Armor cannot inspect or block traffic to the Cloud SQL instance directly. Option B is wrong because the Cloud SQL Auth proxy enforces IAM-based authentication and encrypts connections, but it does not prevent data exfiltration; if an application is compromised, the proxy still allows the attacker to query and extract PHI using valid credentials. Option D is wrong because CMEK is already implemented for encryption at rest, and encryption alone does not prevent data exfiltration—it only protects data if the storage media is stolen, not if an application is compromised and actively queries the database.

8
MCQmedium

Your company's global e-commerce platform uses a managed instance group (MIG) in us-central1 and a Cloud Load Balancer. Traffic has grown, and you want to improve availability by distributing load across multiple regions. What should you do?

A.Increase the machine type of the existing instances to handle more traffic.
B.Enable Cloud CDN to cache content closer to users.
C.Create MIGs in additional regions and add them as backends to the existing global load balancer.
D.Change the load balancer to global and configure a single backend.
AnswerC

Adding regional managed instance groups as backends to the existing global load balancer satisfies the multi-region availability requirement. A global external Application Load Balancer routes users to the closest healthy backend and performs cross-region failover, so capacity in additional regions absorbs traffic when one region degrades.

Why this answer

A global external HTTP(S) load balancer can have backends in multiple regions. By creating managed instance groups (MIGs) in additional regions and adding them as backends to the existing global load balancer, you distribute traffic across regions, improving availability and reducing latency for users worldwide. This approach leverages the load balancer's anycast IP and cross-region load balancing capabilities.

Exam trap

The trap here is that candidates confuse Cloud CDN (which caches content) with multi-region backend distribution, or think that simply making the load balancer 'global' with a single backend achieves regional redundancy, when in fact you must add backends in multiple regions to distribute load and improve availability.

How to eliminate wrong answers

Option A is wrong because increasing the machine type of existing instances only scales vertically within a single region, which does not address multi-region availability or distribute load geographically. Option B is wrong because Cloud CDN caches static content at edge locations but does not distribute compute load across regions; it reduces latency for cached content but does not improve availability for dynamic requests or handle regional failures. Option D is wrong because changing the load balancer to global and configuring a single backend (a single MIG) still limits compute resources to one region, failing to provide multi-region distribution or fault isolation.

9
MCQeasy

Refer to the exhibit. A user (ops@example.com) is unable to create a new VPC network in the project. What should the administrator verify first?

A.The user has been granted roles/compute.admin.
B.The user has the project owner role.
C.The user has the roles/storage.admin role.
D.The user has appropriate IAM roles such as roles/compute.networkAdmin.
AnswerD

Verify that ops@example.com holds roles/compute.networkAdmin or equivalent permissions on the project. VPC network creation requires compute.networks.create, granted through IAM roles rather than Microsoft Entra ID directory roles. Checking this binding first confirms whether the authorisation failure stems from missing project-level permissions.

Why this answer

To create a VPC network in Google Cloud, the user needs the compute.networks.create permission. The roles/compute.networkAdmin IAM role includes this permission, along with others needed to manage VPC networks. Option D correctly identifies that the user must have appropriate IAM roles, specifically roles/compute.networkAdmin or a custom role with the necessary compute.networks.create permission.

Exam trap

Google Cloud often tests the principle of least privilege and the specific IAM roles required for VPC operations, trapping candidates who assume that a broad role like compute.admin or owner is the first thing to verify, rather than the more specific networkAdmin role.

How to eliminate wrong answers

Option A is wrong because roles/compute.admin is a highly privileged role that includes all compute permissions, but it is not the minimum required role; the question asks what the administrator should verify first, and checking for a more specific role like roles/compute.networkAdmin is more appropriate. Option B is wrong because the project owner role (roles/owner) includes all permissions, but it is overly broad and not the first thing to verify; the administrator should check for the specific network admin role first. Option C is wrong because roles/storage.admin grants permissions for Cloud Storage, not for VPC network creation, which requires compute.networks.* permissions.

10
MCQhard

Refer to the exhibit. All five nginx pods are scheduled on the same node (default-pool-1). What is the most likely reason?

A.The node auto-scaler has not created additional nodes yet, but the other nodes are present.
B.The pods have a nodeSelector that matches only default-pool-1.
C.The other nodes have taints that the pods do not tolerate.
D.The resource requests are too high, so the scheduler packed pods onto one node due to resource constraints on the others.
AnswerC

Taints on other nodes repel pods lacking matching tolerations, so the scheduler cannot place them there. With no tolerations defined in the pod spec, every other node rejects the nginx pods, leaving default-pool-1 as the only viable target and concentrating all five replicas on it.

Why this answer

Taints on nodes prevent pods from being scheduled unless the pods have corresponding tolerations. If the other nodes have taints that the nginx pods do not tolerate, the scheduler will only place them on nodes without those taints, which in this case is default-pool-1. This is a common scenario when nodes are dedicated to specific workloads or have special hardware.

Exam trap

This question tests the distinction between taints/tolerations and nodeSelector/affinity in Kubernetes on Google Cloud. Candidates often overlook that taints can silently exclude pods from all but one node, and assume only nodeSelector restricts pod placement.

How to eliminate wrong answers

Option A is wrong because the node auto-scaler adds nodes when pods are unschedulable due to resource constraints, but here all pods are scheduled on one node, indicating the scheduler deliberately chose that node, not that other nodes are missing. Option B is wrong because if a nodeSelector matched only default-pool-1, the pods would be scheduled exclusively there, but the question asks for the 'most likely reason' and taints are a more common cause for pods being forced onto a single node when other nodes exist. Option D is wrong because if resource requests were too high, the scheduler would leave pods pending or spread them across nodes that can fit them, not pack them all onto one node; packing suggests the other nodes are intentionally excluded.

11
MCQeasy

An online retailer runs a stateless containerized API on Google Kubernetes Engine. Traffic is highly seasonal, spiking sharply during flash sales and dropping to near zero overnight. The operations team wants the cluster to add and remove nodes automatically based on pod demand while keeping costs low during idle periods. What should the architect recommend?

A.Deploy the API on Cloud Run and remove the GKE cluster entirely, relying on request-based scaling.
B.Configure a regional managed instance group with a fixed size and enable autoscaling on the deployment only.
C.Set the node pool to a large fixed size sized for peak flash-sale traffic and rely on the scheduler to pack pods efficiently.
D.Enable cluster autoscaler on the node pools and configure a HorizontalPodAutoscaler on the API deployment.
AnswerD

Cluster autoscaler adds nodes when pods cannot be scheduled and removes underutilized nodes when demand falls, directly addressing seasonal spikes and idle overnight periods. The HorizontalPodAutoscaler scales the number of pods based on metrics such as CPU or custom metrics, which in turn drives cluster autoscaler to provision capacity. Together they deliver both pod-level and node-level elasticity for a stateless workload.

Why this answer

Cluster autoscaler and HorizontalPodAutoscaler are complementary controls: the HPA adjusts replica count based on demand signals, and the cluster autoscaler provisions or removes nodes to match the resulting scheduling pressure. This combination gives the retailer elasticity during flash sales and near-zero node cost overnight without manual intervention.

Exam trap

The trap here is confusing pod autoscaling with node autoscaling, when in fact both are required for a workload whose node capacity must also track demand.

12
MCQeasy

A team uses Cloud Build for CI/CD. The builds are taking longer than expected due to dependency downloads. What is the best practice to speed up builds?

A.Increase the machine type to e2-highcpu-32 to speed up compilation.
B.Use Docker layer caching with Cloud Build by specifying a cache image or using Kaniko cache.
C.Use Artifact Registry to store built packages and pull them during build.
D.Store dependencies in Cloud Source Repositories and fetch them during build.
AnswerB

Kaniko or Docker layer caching stores previously built layers in a cache image, so Cloud Build reuses unchanged dependency layers instead of re-downloading and rebuilding them each run. This directly cuts the dependency-download time lengthening builds.

Why this answer

Docker layer caching allows Cloud Build to reuse previously built layers, significantly reducing the time spent re-downloading and re-installing dependencies. By specifying a cache image or using Kaniko's built-in cache, only changed layers are rebuilt, while unchanged dependency layers are pulled from the cache instead of being fetched from the internet each time.

Exam trap

The trap here is that candidates confuse increasing compute resources (Option A) with solving a network-bound problem, or they mistakenly think storing dependencies in a repository (Options C and D) eliminates the need to download them, when in fact only layer caching avoids re-downloading by reusing previously built layers.

How to eliminate wrong answers

Option A is wrong because increasing the machine type to e2-highcpu-32 primarily speeds up CPU-bound compilation tasks, not network-bound dependency downloads; the bottleneck here is network latency and download throughput, not CPU cores. Option C is wrong because Artifact Registry stores built packages (e.g., container images, Maven artifacts), not raw dependency files; pulling pre-built packages from Artifact Registry does not address the initial download of dependencies during the build process. Option D is wrong because Cloud Source Repositories is a Git repository hosting service, not a dependency cache; storing dependencies there would require manual management and does not integrate with standard package managers (e.g., pip, npm, Maven) to avoid re-downloading.

13
MCQhard

A financial services firm runs batch risk calculations nightly using a large Compute Engine VM with a GPU. Jobs complete in 4 hours but are not time-sensitive. To reduce costs without sacrificing reliability, the firm enables preemptible VMs but finds that jobs are interrupted and restarting from scratch causes delays. What is the best approach to improve reliability while maintaining cost savings?

A.Request a committed use discount for the GPU and use a standard VM without preemptible.
B.Use a non-preemptible VM but downgrade the GPU type to reduce cost.
C.Use a spot VM with a high availability SLA, relying on low preemption rates.
D.Use a managed instance group with preemptible VMs and implement checkpointing to save progress periodically.
AnswerD

A managed instance group with preemptible VMs plus periodic checkpointing preserves completed work to persistent storage, so an interrupted job resumes from the last checkpoint rather than restarting. This maintains preemptible cost savings while satisfying the reliability requirement.

Why this answer

Preemptible VMs are up to 80% cheaper but can be terminated at any time with only a 30-second warning, so long-running jobs must be resilient to interruption. Combining a managed instance group (MIG) with preemptible VMs allows automatic recreation of terminated instances, and implementing checkpointing lets the batch job resume from the last saved state rather than restarting from zero. This preserves the cost savings while dramatically improving reliability for the 4-hour nightly job.

Exam trap

PCA often tests the misconception that spot/preemptible VMs come with any availability guarantee — candidates pick 'spot VM with HA SLA' believing Google provides reliability assurances, when in fact no SLA exists for spot VMs.

How to eliminate wrong answers

Option A is wrong because committed use discounts still require paying for standard (non-preemptible) VMs, which eliminates the cost savings the firm is trying to achieve — it solves reliability by abandoning the cost optimization entirely. Option B is wrong because downgrading the GPU reduces performance and may not even be possible for the workload, and it still uses non-preemptible VMs, so no cost savings from preemption are realized. Option C is wrong because spot VMs (the successor to preemptible VMs) do not come with a high availability SLA — Google explicitly does not offer an SLA for spot VMs, and relying on 'low preemption rates' is not a reliability strategy.

14
MCQhard

The firewall rule 'allow-ssh' was not created. According to the audit log, what is the most likely reason?

A.The user is not authenticated.
B.The user has the compute.securityAdmin role but not compute.firewalls.create.
C.The user does not have the compute.firewalls.create permission.
D.The firewall rule already exists and cannot be duplicated.
AnswerC

AuthorizationInfo shows granted: false for that permission.

Why this answer

The audit log indicates the firewall rule 'allow-ssh' was not created because the user lacks the specific permission required to create firewall rules in Google Cloud. The correct permission is `compute.firewalls.create`, which is part of the `compute.securityAdmin` role but not automatically granted with it; the `compute.securityAdmin` role includes `compute.firewalls.create`, so Option B is factually incorrect. The most likely reason is that the user does not have the `compute.firewalls.create` permission, which is a prerequisite for creating firewall rules.

Exam trap

The trap here is that candidates assume the `compute.securityAdmin` role does not include `compute.firewalls.create`, when in fact it does, leading them to incorrectly select Option B.

How to eliminate wrong answers

Option A is wrong because the audit log would show an authentication failure (e.g., 'unauthenticated' or 'login failed') if the user were not authenticated, but the scenario states the rule was not created, implying the user was authenticated but lacked authorization. Option B is wrong because the `compute.securityAdmin` role actually includes the `compute.firewalls.create` permission; if the user had that role, they would have the necessary permission, so this option presents a false contradiction. Option D is wrong because the audit log would show a 'resource already exists' error (HTTP 409 Conflict) if the rule already existed, but the question states the rule was not created, not that creation was attempted and failed due to duplication.

15
MCQhard

A financial services firm is designing a new payment processing system on Google Cloud. The system must expose a single global anycast IP address, terminate TLS at the edge, and route requests to the nearest healthy backend across three regions. The backend services run on Compute Engine and must be protected from volumetric DDoS attacks. Which product should you place in front of the backends?

A.Global external Proxy Network Load Balancer with Google Cloud Armor attached to the target proxy.
B.Regional external Application Load Balancer in each region with Cloud CDN enabled for caching.
C.External passthrough Network Load Balancer with a global forwarding rule and Cloud Armor on the backend.
D.Global external Application Load Balancer with Cloud Armor security policies attached to the backend service.
AnswerD

The global external Application Load Balancer provides a single global anycast IP, terminates TLS at Google's edge, and routes to the nearest healthy backend using the premium network tier. Cloud Armor attaches to the backend service to filter and absorb volumetric and application-layer attacks. This combination satisfies the anycast, TLS termination, cross-region routing, and DDoS protection requirements in one architecture.

Why this answer

A global external Application Load Balancer delivers a single global anycast IP, terminates TLS at Google's edge, and uses health-checked backends to route to the nearest region. Cloud Armor security policies attach to the backend service and provide DDoS and web application firewall protection. Regional load balancers cannot offer one global IP, and Layer 4 proxy or passthrough load balancers do not terminate HTTP(S) at the edge or support Cloud Armor in the required way.

Exam trap

The trap here is confusing Layer 4 network load balancing with Layer 7 application load balancing, and assuming Cloud Armor can attach to any load balancer type.

16
MCQeasy

A startup is deploying a new web application on Google Cloud. The application runs in containers on Google Kubernetes Engine (GKE) and uses a Cloud SQL for MySQL instance. The team wants to follow the principle of least privilege for the application's access to Cloud SQL. Which method should the architect recommend for authenticating the application to Cloud SQL?

A.Use Cloud SQL IAM database authentication with a dedicated service account for the application.
B.Configure a Cloud VPN tunnel between the GKE cluster and Cloud SQL, and use IP allowlisting.
C.Create a MySQL user with a strong password and store the password in a Kubernetes Secret.
D.Enable the Cloud SQL Admin API and use the default compute service account for authentication.
AnswerA

Cloud SQL IAM database authentication allows the application to authenticate using a service account's identity, eliminating static passwords. The service account can be granted minimal database roles, following least privilege. This integrates with IAM and provides short-lived credentials, which is the recommended approach for GKE workloads.

Why this answer

Cloud SQL IAM database authentication lets the application authenticate with a service account, removing static passwords and enabling fine-grained IAM roles. This follows least privilege by granting only the necessary database permissions to a dedicated service account. Storing passwords in Kubernetes Secrets, using the default compute service account, or relying on network controls do not provide identity-based least-privilege access.

Exam trap

The trap here is assuming that network-level controls like VPN or IP allowlisting provide authentication and least privilege, when they only restrict network paths.

17
MCQeasy

A company wants to deploy a containerized application on Google Cloud and needs persistent storage that can be accessed by multiple pods in a GKE cluster concurrently. Which storage solution should they use?

A.Persistent Disk with ReadWriteMany access mode
B.Cloud Storage via Storage FUSE
C.Compute Engine persistent disk attached to each node
D.Filestore
AnswerD

Filestore provides a fully managed NFS file share, so multiple GKE pods can mount the same volume concurrently across nodes. This satisfies the stem's requirement for shared persistent storage, unlike zonal persistent disks, which support only ReadWriteOnce attachment to a single node.

Why this answer

Filestore is the correct choice because it provides a managed NFS file server that supports the ReadWriteMany (RWX) access mode, allowing multiple pods in a GKE cluster to concurrently read from and write to the same persistent storage volume. This is essential for workloads like content management systems or shared data processing that require simultaneous access from multiple pods.

Exam trap

The trap here is that candidates often confuse Persistent Disk's ReadWriteOnce capability with ReadWriteMany, or incorrectly assume that Cloud Storage FUSE provides the same concurrent POSIX access as a true shared filesystem like NFS.

How to eliminate wrong answers

Option A is wrong because Persistent Disk volumes in GKE support only ReadWriteOnce (RWO) access mode, meaning they can be mounted by only a single pod at a time, not multiple pods concurrently. Option B is wrong because Cloud Storage via Storage FUSE provides a file-system interface to object storage, but it does not offer true POSIX-compliant concurrent read-write access from multiple pods and introduces latency and consistency limitations. Option C is wrong because Compute Engine persistent disks attached to each node are local to that node and cannot be shared across multiple nodes or pods; they also default to ReadWriteOnce mode.

18
MCQmedium

A financial services company runs a multi-tier application on Compute Engine. They need to restrict network access so that only the web tier can communicate with the application tier, and only the application tier can access the database tier. All VMs are in the same VPC network. What is the most secure way to implement this?

A.Use Identity-Aware Proxy (IAP) to manage network access between tiers.
B.Use VPC firewall rules with target tags to allow traffic between specific tiers.
C.Create separate VPC networks for each tier and use VPC peering.
D.Assign a unique service account to each tier and use IAM conditions to restrict traffic.
AnswerB

VPC firewall rules with target tags apply ingress rules only to VMs carrying the specified tag, so the application tier accepts traffic solely from the web tier's tag and the database tier solely from the application tier, enforcing tier isolation within one VPC network.

Why this answer

VPC firewall rules with target tags allow you to precisely control ingress and egress traffic between VM instances based on their assigned tags. By tagging web tier VMs with a tag like 'web-tier' and application tier VMs with 'app-tier', you can create a firewall rule that allows traffic from 'web-tier' to 'app-tier' on the required port (e.g., TCP 8080) and another rule allowing traffic from 'app-tier' to 'db-tier' on the database port (e.g., TCP 3306). This approach enforces the principle of least privilege within a single VPC network without introducing unnecessary complexity or breaking network isolation.

Exam trap

The trap here is that candidates often confuse IAM conditions or service accounts with network-layer access control, or they overcomplicate the solution by suggesting separate VPC networks when the simplest and most secure method within a single VPC is using firewall rules with target tags.

How to eliminate wrong answers

Option A is wrong because Identity-Aware Proxy (IAP) is designed for user-level authentication and authorization to access applications and VMs via HTTPS or SSH/RDP tunnels, not for controlling network traffic between VM tiers within a VPC. Option C is wrong because creating separate VPC networks for each tier and using VPC peering would allow all traffic between the peered networks unless additional firewall rules are applied, and it adds unnecessary complexity; the question explicitly states all VMs are in the same VPC network, making this approach less secure and more complex than using tags. Option D is wrong because service accounts and IAM conditions control API-level permissions (e.g., who can create or delete resources), not network-layer traffic between VM instances; they cannot restrict which VMs can communicate with each other over the network.

19
MCQeasy

A startup is deploying a new web application on Google Kubernetes Engine (GKE). They want to expose the application to the internet with a single global IP address and automatically route users to the closest regional cluster. They also want to minimize operational overhead. Which GKE feature should they use?

A.GKE Ingress with a global external Application Load Balancer
B.GKE Gateway with a regional gateway class
C.GKE Network Endpoint Groups (NEGs) with a standalone global load balancer
D.GKE Service of type LoadBalancer with a regional external passthrough Network Load Balancer
AnswerA

GKE Ingress automatically creates a global external Application Load Balancer when you create an Ingress resource. This provides a single global IP address and routes traffic to the closest backend service across multiple regional clusters. It integrates with GKE and requires minimal operational overhead, as the load balancer is managed by GKE. This meets the requirement for global exposure and low management effort.

Why this answer

GKE Ingress automatically provisions a global external Application Load Balancer, providing a single global IP and intelligent routing to the closest regional backends. It is fully integrated with GKE and requires minimal operational effort. The other options either provide regional load balancing or require manual configuration, which does not meet the requirement for minimal overhead and global reach.

Exam trap

The trap here is assuming that a Service of type LoadBalancer provides a global IP, when it actually creates a regional load balancer, or that GKE Gateway with a regional class is global.

20
Multi-Selecthard

A company has set up an external HTTP(S) load balancer with a backend service pointing to a managed instance group. Some instances are failing health checks. Which TWO actions should the company take to troubleshoot the issue?

Select 2 answers
A.Ensure the health check path specified in the backend service returns a 200 OK status.
B.Verify that the firewall rules allow traffic from the load balancer health check IP ranges.
C.Disable session affinity to allow better distribution of traffic.
D.Change the health check interval from 5 seconds to 30 seconds.
E.Increase the number of instances in the instance group to distribute the load.
AnswersA, B

A failing health check often stems from the probe path returning a non-200 response, so verifying it returns 200 OK directly addresses the backend service's health check configuration. Google Cloud load balancer health checks mark instances unhealthy on any other status code, removing them from rotation, so confirming the path's response satisfies the stem's troubleshooting requirement.

Why this answer

Option A is correct because the health check probe only marks an instance healthy when the configured request path returns an HTTP 200 OK response; if the path returns 404, 500, or a redirect, the instance will be flagged unhealthy, so verifying the path is a primary troubleshooting step. Option B is correct because Google Cloud external HTTP(S) load balancer health checks originate from specific Google health check source IP ranges (e.g., 35.191.0.0/16 and 130.211.0.0/22), and firewall rules must permit ingress from these ranges to the instances on the health check port, otherwise probes are dropped and instances fail. Option C is not relevant because session affinity affects how client traffic is routed, not whether health check probes succeed.

Option D is not a fix because lengthening the interval only delays detection and does not resolve the underlying cause of failed probes. Option E is not appropriate because adding instances does not correct failing health checks and may simply add more unhealthy instances.

Exam trap

The trap here is that candidates often focus on load distribution or scaling solutions (options C and E) rather than the fundamental connectivity and application-level checks (options A and B) that directly determine health check success.

21
MCQmedium

A media company stores millions of video files in a Cloud Storage bucket and serves them to users worldwide. Users in Asia report slow download speeds, while users in North America are satisfied. The files are immutable after upload and are read frequently for the first 30 days, then almost never. You want to improve global performance while minimizing cost. What should you do?

A.Move the files to a bucket in the asia-east1 region and serve them directly from that location.
B.Create a Cloud CDN distribution with the Cloud Storage bucket as the backend, and add a lifecycle rule to move objects to Nearline Storage after 30 days.
C.Recreate the bucket as a multi-region bucket and enable Autoclass to manage storage classes automatically.
D.Enable Object Versioning on the bucket and create a Cloud CDN distribution backed by the bucket.
AnswerB

Cloud CDN caches immutable objects at edge locations, so users in Asia are served from nearby points of presence instead of the origin bucket. A lifecycle rule transitioning objects to Nearline after 30 days matches the access pattern and lowers storage cost. Because the files are immutable, caching is safe and effective, making this the best performance-and-cost combination.

Why this answer

Serving immutable objects through Cloud CDN puts copies at Google's edge points of presence, which directly improves download speeds for users far from the origin. Pairing that with a lifecycle rule that transitions rarely accessed objects to Nearline Storage after 30 days aligns storage cost with the actual access pattern, so performance improves without unnecessary expense.

Exam trap

The trap here is reaching for multi-region storage to fix latency, when multi-region placement improves durability and availability rather than edge delivery to end users.

22
MCQmedium

A company wants to grant a service account in Project A the ability to push containers to Artifact Registry in Project B. They want to follow the principle of least privilege. Which IAM roles should they assign?

A.Grant the service account the Storage Object Admin role (roles/storage.objectAdmin) on Project B
B.Grant the service account the Artifact Registry Writer role (roles/artifactregistry.writer) on the repository in Project B
C.Grant the service account the Artifact Registry Admin role (roles/artifactregistry.admin) on the repository in Project B
D.Grant the service account the Artifact Registry Reader role (roles/artifactregistry.reader) on the repository in Project B
AnswerB

Granting roles/artifactregistry.writer on the specific repository in Project B satisfies least privilege: the role permits pushing and reading artifacts but not deleting repositories or managing IAM, and scoping the binding to the repository rather than the whole project limits the service account to exactly the target it needs.

Why this answer

The Artifact Registry Writer role (roles/artifactregistry.writer) grants permissions to push and pull artifacts, which is exactly what the service account needs to push containers. Assigning it at the repository level in Project B follows least privilege by limiting access to only that repository. This role includes the necessary permissions like artifactregistry.repositories.uploadArtifacts without granting broader admin rights.

Exam trap

PCA often tests the difference between project-level and repository-level IAM, and candidates may choose Admin or Reader roles instead of the precise Writer role for push access.

How to eliminate wrong answers

Option A is wrong because Storage Object Admin is for Cloud Storage buckets, not Artifact Registry; Artifact Registry uses its own IAM roles. Option C is wrong because Artifact Registry Admin grants full control, including delete and manage permissions, which violates least privilege. Option D is wrong because Artifact Registry Reader only allows pulling, not pushing, so the service account could not upload containers.

23
MCQeasy

An online learning platform runs its API on a regional managed instance group behind an external Application Load Balancer. The operations team wants to release new versions with the ability to shift a small percentage of user traffic to the new version first, then increase it gradually, and roll back instantly if error rates rise. What should they implement?

A.Configure Cloud CDN with a cache key that includes the application version header and purge the cache after each deployment.
B.Enable autoscaling on the existing managed instance group and set the target CPU utilization lower during the release window.
C.Use an internal passthrough Network Load Balancer in front of the managed instance group and switch the target pool during the release.
D.Create a second managed instance group for the new version and use the load balancer's backend service with a small weight on the new group.
AnswerD

Two managed instance groups registered as backends of the same backend service let the Application Load Balancer distribute traffic by capacity or weight, enabling a canary release. Shifting weight gradually controls exposure, and setting the new group's weight back to zero reverts traffic immediately without redeploying, which matches the rollback requirement.

Why this answer

The Application Load Balancer supports multiple backends per backend service and can distribute traffic by weight or capacity, so registering a second managed instance group for the new version enables a canary. Adjusting weights shifts exposure gradually, and returning the new group's weight to zero restores the previous version immediately.

Exam trap

The trap here is confusing autoscaling or CDN caching with traffic splitting, when only the load balancer's backend weighting controls the share of requests each version receives.

24
MCQmedium

An e-commerce company is experiencing traffic spikes during flash sales. Their application runs on Compute Engine instances behind a TCP load balancer. They want to automatically scale the number of instances based on CPU utilization. Which configuration is required?

A.Configure Cloud Run for autoscaling and rewrite the application to run in containers.
B.Create an unmanaged instance group with a static number of instances and configure Cloud CDN.
C.Use Cloud Functions to handle traffic spikes and redirect traffic from the load balancer.
D.Create a managed instance group (MIG) with an autoscaling policy based on CPU utilization.
AnswerD

Autoscaling only applies to managed instance groups; a MIG with a CPU utilisation policy adds or removes instances automatically during flash-sale spikes, which an unmanaged group or standalone instances behind the TCP load balancer cannot do.

Why this answer

Managed Instance Groups (MIGs) with autoscaling based on CPU utilization is the correct approach. Cloud Functions and Cloud Run are not Compute Engine instance scaling. A global HTTP(S) Load Balancer is not required for TCP traffic.

25
MCQmedium

An organization runs a stateful application on GKE that must not lose data during cluster upgrades or node repairs. The application uses persistent volumes with ReadWriteOnce access mode. The team wants to ensure pods are not evicted simultaneously. Which Kubernetes resource should they configure?

A.PodDisruptionBudget
B.ClusterAutoscaler
C.HorizontalPodAutoscaler
D.VerticalPodAutoscaler
AnswerA

A PodDisruptionBudget (PDB) specifies the minimum number or percentage of replicas that must remain available during voluntary disruptions, such as cluster upgrades or node repairs. By setting `maxUnavailable: 0` or `minAvailable: 1`, the PDB prevents the simultaneous eviction of pods using ReadWriteOnce persistent volumes, thereby satisfying the requirement that no data be lost and pods are not evicted concurrently.

Why this answer

A PodDisruptionBudget (PDB) limits how many pods of a given workload can be voluntarily disrupted at once, ensuring that during node drains (cluster upgrades, node repairs) not all replicas of a stateful application are evicted simultaneously. By setting minAvailable or maxUnavailable, the PDB forces the eviction API to respect availability constraints, protecting data integrity for ReadWriteOnce volumes that cannot be mounted by multiple pods at once.

Exam trap

The trap is confusing autoscaling resources (HPA, VPA, ClusterAutoscaler) with disruption-control resources; candidates often pick HPA because it 'manages pods,' but only PDB governs eviction during maintenance.

How to eliminate wrong answers

Option B is wrong because ClusterAutoscaler adjusts the number of nodes in the cluster based on pending pods — it does not control pod eviction ordering or protect against simultaneous disruption. Option C is wrong because HorizontalPodAutoscaler scales the number of pod replicas based on metrics like CPU or custom metrics; it does not govern eviction during node drains. Option D is wrong because VerticalPodAutoscaler adjusts CPU/memory requests and limits of existing pods, potentially restarting them, but it does not prevent simultaneous eviction during maintenance.

26
MCQmedium

You need to create a private GKE cluster with Workload Identity enabled to allow pods to access Google Cloud APIs without static service account keys. What must you configure for the cluster?

A.Enable Binary Authorization on the cluster
B.Enable Workload Identity on the cluster and set the --workload-pool flag at cluster creation
C.Create a node pool with a service account that has the necessary IAM roles and assign that SA to pods
D.Use Cloud NAT to allow pods to communicate with Google APIs
AnswerB

Workload Identity binds Kubernetes service accounts to Google Cloud service accounts, letting pods obtain short-lived credentials without static keys. Setting --workload-pool at creation links the cluster to the identity pool, satisfying the keyless access requirement.

Why this answer

To enable Workload Identity on a GKE cluster, you must enable it at the cluster level and specify the workload pool using the --workload-pool flag (e.g., PROJECT_ID.svc.id.goog) during cluster creation. This establishes the trust relationship between Kubernetes service accounts and Google Cloud IAM, allowing pods to impersonate IAM service accounts without static keys.

Exam trap

PCA often tests Workload Identity setup, and candidates frequently choose the node pool service account option because it sounds like it grants pods access — but that approach does not eliminate static keys and is the legacy method.

How to eliminate wrong answers

Option A is wrong because Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed; it has nothing to do with Workload Identity or eliminating static keys. Option C is wrong because assigning a node pool service account to pods is the legacy approach that grants all pods on the node the same permissions and still relies on the node's service account, not Workload Identity. Option D is wrong because Cloud NAT provides outbound internet access for private nodes; it does not enable pods to authenticate to Google Cloud APIs.

27
Multi-Selecteasy

A company is deploying a web application on Compute Engine. They want to automatically scale the number of instances based on CPU utilization. Which two components are required to set up autoscaling? (Choose two.)

Select 2 answers
A.Cloud Functions
B.Cloud Load Balancing
C.Instance template
D.Managed instance group
E.Cloud Monitoring
AnswersC, D

An instance template defines the machine type, boot disk image, and startup configuration used to create each replica. Autoscaling needs it so the managed instance group can provision identical new VMs when CPU utilisation crosses the target threshold.

Why this answer

Option C (Instance template) is correct because a managed instance group requires an instance template to define the machine type, boot disk image, network, and other configuration used when automatically creating new VM instances during scaling. Option D (Managed instance group) is correct because autoscaling in Compute Engine operates on a managed instance group (MIG), where the autoscaler adds or removes instances based on the specified CPU utilization target. Cloud Functions (A) is a serverless event-driven compute service and plays no role in Compute Engine autoscaling.

Cloud Load Balancing (B) is commonly used to distribute traffic to the instances but is not a required component to configure the autoscaling policy itself. Cloud Monitoring (E) can surface metrics and alerts, but the autoscaler uses the MIG's built-in CPU utilization signal and does not require a separate Monitoring configuration.

Exam trap

The trap here is that candidates often think Cloud Monitoring is required because autoscaling uses CPU metrics, but the autoscaler automatically accesses those metrics without requiring Cloud Monitoring to be separately configured.

28
Multi-Selecteasy

A company wants to monitor the health of their Cloud Run services. Which THREE metrics should they use to define a comprehensive health SLI? (Choose 3)

Select 3 answers
A.Latency (e.g., p99 response time)
B.CPU utilization
C.Request count
D.Instance count
E.Error rate (percentage of 5xx responses)
AnswersA, C, E

Latency is a key performance SLI for user experience.

Why this answer

Latency (p99 response time) is a critical metric for Cloud Run because it measures the end-to-end request processing time, directly reflecting user experience. In a serverless environment, high latency can indicate cold starts, insufficient concurrency, or downstream service bottlenecks, making it essential for a comprehensive health SLI.

Exam trap

Google Cloud often tests the misconception that infrastructure-level metrics like CPU or instance count are valid health SLIs for serverless services, when in fact user-facing metrics (latency, errors, request count) are the correct choices for a comprehensive health SLI.

29
MCQeasy

An organization wants to connect their on-premises data center to Google Cloud with a dedicated 10 Gbps link. They require high availability and have budget for two physically diverse connections. Which solution should they choose?

A.Use Partner Interconnect with a single 10 Gbps connection.
B.Configure a single Dedicated Interconnect connection and use Cloud VPN as backup.
C.Provision two Cloud Dedicated Interconnect connections from diverse peering points.
D.Deploy a single HA VPN tunnel.
AnswerC

Two Dedicated Interconnect connections terminating at diverse peering points provide physically separate 10 Gbps paths, so a single facility or link failure does not drop connectivity. This satisfies both the dedicated bandwidth and high availability constraints.

Why this answer

Two Dedicated Interconnect connections from diverse peering points provide the required 10 Gbps dedicated bandwidth with high availability, since each connection is physically separate and can fail independently. This is the standard Google-recommended topology for production Dedicated Interconnect with redundancy.

Exam trap

PCA often tests whether candidates conflate 'high availability' with 'backup' and pick a single Dedicated Interconnect plus VPN, so the trap is missing that true HA for Dedicated Interconnect requires two physically diverse dedicated connections.

How to eliminate wrong answers

Option A is wrong because a single Partner Interconnect connection does not provide the redundancy required for high availability, and Partner Interconnect is delivered through a partner rather than a direct dedicated link. Option B is wrong because a single Dedicated Interconnect with Cloud VPN backup provides only one dedicated 10 Gbps path; the VPN backup is lower bandwidth and does not meet the two physically diverse dedicated connections requirement. Option D is wrong because a single HA VPN tunnel is an encrypted internet-based solution, not a dedicated 10 Gbps interconnect, and a single tunnel does not provide the required diversity.

30
Multi-Selectmedium

A media company runs a video transcoding service on GKE Standard. The service experiences sudden traffic spikes, and the operations team wants to ensure that the cluster can scale nodes automatically and that pods are rescheduled quickly when a node fails. The team also wants to monitor and alert on resource saturation. Which two actions should the cloud architect take to meet these requirements? (Choose two.)

Select 2 answers
A.Enable cluster autoscaler on the node pools and set appropriate minimum and maximum node counts based on expected peak load.
B.Create a HorizontalPodAutoscaler based on CPU utilization for the transcoding deployment to add more pods when demand increases.
C.Enable Cloud CDN in front of the transcoding service to cache video segments and reduce load on the GKE pods.
D.Configure pod disruption budgets for the transcoding deployment to guarantee a minimum number of available pods during voluntary disruptions.
E.Set resource requests and limits on the transcoding pods so the scheduler and autoscaler can make accurate decisions about capacity and placement.
AnswersA, E

Cluster autoscaler adjusts the number of nodes in a node pool when pods cannot be scheduled due to insufficient resources, and it removes underutilized nodes when demand falls. Setting minimum and maximum counts bounds cost and capacity. This directly addresses automatic node scaling during traffic spikes and is a core reliability control for GKE workloads.

Why this answer

Automatic node scaling requires cluster autoscaler on the node pools, and it works correctly only when pods declare accurate resource requests and limits so the scheduler and autoscaler can size capacity. Together these ensure nodes are added during spikes and pods are placed and rescheduled efficiently. Pod disruption budgets, Cloud CDN, and HorizontalPodAutoscaler address different concerns and do not provide node-level scaling or rapid recovery from node failure.

Exam trap

The trap here is confusing pod-level scaling with node-level scaling, assuming that a HorizontalPodAutoscaler alone will add capacity when in fact cluster autoscaler is what provisions new nodes.

31
MCQeasy

Your company runs a critical application on Compute Engine instances in us-central1. The application requires low latency between instances that are all in the same region. You notice that network latency between instances varies and sometimes spikes. You want to ensure consistent low-latency communication. You currently use external IP addresses for communication between instances. What should you do?

A.Move instances to the same zone to reduce network hops.
B.Upgrade to larger machine types to improve network bandwidth.
C.Use internal IP addresses instead of external IPs for inter-instance communication.
D.Set up a Cloud VPN connection between instances.
AnswerC

External IP traffic between instances traverses Google's edge network and public routing, adding variable hops that cause latency spikes. Internal IP addresses stay on the regional VPC network, giving direct, consistent paths between instances in us-central1 and satisfying the consistent low-latency requirement.

Why this answer

Using internal IP addresses (RFC 1918) for inter-instance communication avoids the overhead of NAT, external routing, and potential egress bottlenecks. Traffic stays within Google's internal network fabric, reducing latency variability and eliminating spikes caused by external internet path fluctuations.

Exam trap

The trap here is that candidates assume moving to the same zone or upgrading machine types will fix latency, but the root cause is the external IP routing path, not proximity or bandwidth.

How to eliminate wrong answers

Option A is wrong because moving instances to the same zone reduces physical distance but does not address the fundamental issue of using external IPs, which still forces traffic through external gateways and can introduce latency spikes. Option B is wrong because larger machine types increase network bandwidth (throughput) but do not reduce latency or eliminate the variability caused by external IP routing. Option D is wrong because Cloud VPN is designed for secure connectivity between on-premises and VPC, not for inter-instance communication within the same region; it adds encryption overhead and does not solve the external IP latency problem.

32
MCQeasy

Which Google Cloud service provides a fully managed, serverless data warehouse for petabyte-scale analytics using SQL?

A.Firestore
B.Cloud Spanner
C.Cloud SQL
D.BigQuery
AnswerD

BigQuery delivers serverless, petabyte-scale analytics through its Dremel-based execution engine and columnar Capacitor storage, so no infrastructure provisioning is needed. It satisfies the stem's fully managed and serverless constraints while accepting standard SQL, making it the fitting choice for large-scale warehousing workloads.

Why this answer

BigQuery is Google Cloud's fully managed, serverless data warehouse designed for petabyte-scale analytics using standard SQL. It automatically handles infrastructure scaling, partitioning, and query optimization, allowing users to run fast SQL queries on massive datasets without managing servers or clusters.

Exam trap

Google often tests the distinction between transactional databases (like Cloud SQL, Spanner) and analytical data warehouses (like BigQuery), where candidates mistakenly choose a familiar SQL database service for analytics without recognizing the petabyte-scale, serverless requirement.

How to eliminate wrong answers

Option A is wrong because Firestore is a NoSQL document database for mobile and web app development, not a data warehouse for analytics. Option B is wrong because Cloud Spanner is a globally distributed, strongly consistent relational database service for transactional workloads, not for petabyte-scale analytics. Option C is wrong because Cloud SQL is a managed relational database service for MySQL, PostgreSQL, and SQL Server, designed for OLTP workloads and limited in scale compared to BigQuery's petabyte analytics.

33
MCQhard

An engineer runs the command above. A few days later, the instance becomes unresponsive. Upon investigation, you find that the boot disk is 100 GB and 95% full. The data disk is 500 GB and only 20% full. What is the most likely cause of the unresponsiveness?

A.The boot disk is too small and has run out of space.
B.The data disk is pd-standard, which is causing I/O bottlenecks for the OS.
C.The boot disk is pd-ssd, which is too slow for the workload.
D.The instance has run out of IOPS on the boot disk.
AnswerA

The boot disk holds the operating system, logs, and temporary files. At 95% of 100 GB, it lacks space for normal writes, causing the instance to hang. The data disk's free capacity is irrelevant because the OS cannot use it for boot-volume operations.

Why this answer

The boot disk is 95% full, which leaves insufficient free space for the operating system to write temporary files, logs, or perform essential system operations. When a Linux or Windows boot disk runs out of space, the OS can become unresponsive because critical processes (e.g., systemd, journald, or the Windows Registry) cannot write to disk. In Google Cloud, the boot disk is the root device (typically /dev/sda1), and filling it to 95% on a 100 GB disk means only 5 GB remains, which is easily exhausted by normal system activity.

Exam trap

Google Cloud often tests the distinction between disk space exhaustion and performance bottlenecks; the trap here is that candidates may focus on disk type (pd-standard vs pd-ssd) or IOPS limits instead of recognizing that a nearly full boot disk directly causes OS unresponsiveness.

How to eliminate wrong answers

Option B is wrong because pd-standard disks are HDD-based and can cause I/O bottlenecks, but the data disk is only 20% full and the question states the instance became unresponsive due to disk space, not I/O performance. Option C is wrong because pd-ssd is a high-performance SSD type, not too slow for typical workloads; the issue is space exhaustion, not speed. Option D is wrong because running out of IOPS would cause performance degradation or throttling, not unresponsiveness due to disk space; the boot disk is nearly full, which is a capacity problem, not an IOPS limit.

34
MCQmedium

A company runs a multi-tier web application on Google Kubernetes Engine (GKE) with a frontend service, a backend service, and a Cloud SQL for PostgreSQL database. During peak hours, the frontend pod CPU usage is high (consistently above 80%), while the backend service shows moderate CPU usage (around 50%). Response times for user requests increase significantly, often exceeding the 200ms p99 latency target. Cloud SQL metrics show low query latency and no contention. The team wants to improve performance in a cost-effective manner. Which initial step should they take?

A.Add a read replica for Cloud SQL to offload read queries.
B.Migrate the backend service to a custom machine type with more vCPUs.
C.Enable vertical pod autoscaling for the backend service.
D.Increase the number of frontend pods by adjusting the horizontal pod autoscaler's target CPU utilization.
AnswerD

Frontend CPU is high, so scaling out frontend pods will help handle the load and reduce latency. This is cost-effective as it adds only needed capacity.

Why this answer

The frontend pods are CPU-bound during peak hours, causing increased response times. Increasing the number of frontend pods via the Horizontal Pod Autoscaler (HPA) by lowering the target CPU utilization threshold distributes the load across more replicas, directly addressing the bottleneck without additional infrastructure cost. This is the most cost-effective initial step because it leverages existing resources and autoscaling capabilities.

Exam trap

Google Cloud often tests the misconception that backend or database changes are needed when the bottleneck is clearly at the frontend tier, leading candidates to choose expensive or irrelevant scaling options like read replicas or vertical scaling.

How to eliminate wrong answers

Option A is wrong because Cloud SQL metrics show low query latency and no contention, so a read replica would not resolve the frontend CPU bottleneck and would add unnecessary cost. Option B is wrong because the backend service shows only moderate CPU usage (50%), so migrating to a custom machine type with more vCPUs would be over-provisioning and not cost-effective; the bottleneck is the frontend, not the backend. Option C is wrong because vertical pod autoscaling (VPA) adjusts CPU/memory requests for existing pods, but the frontend pods are already CPU-saturated; scaling up vertically would require pod restarts and may hit node limits, whereas horizontal scaling is more appropriate for stateless web tiers.

35
MCQhard

A global logistics company runs a three-tier application on Compute Engine in a single region. The database tier must survive the loss of an entire zone without data loss, and the application tier must continue serving traffic with minimal disruption during a zonal failure. The architect wants the smallest operational change that satisfies both requirements. Which design should the architect implement?

A.Deploy the application tier in a regional managed instance group across three zones and move the database to a Cloud SQL for PostgreSQL instance with high availability enabled.
B.Deploy the application tier in a zonal managed instance group and replicate the database to a read replica in a second zone using asynchronous replication.
C.Deploy the application tier in a regional managed instance group across three zones and keep the database on a single-zone Cloud SQL instance with daily automated backups.
D.Deploy the application tier in a zonal managed instance group and configure Cloud SQL with automated backups and point-in-time recovery enabled.
AnswerA

A regional managed instance group distributes application instances across zones and replaces failed members automatically, so a zonal outage leaves serving capacity intact. Cloud SQL high availability maintains a standby in a different zone and fails over automatically, providing synchronous replication with no committed data loss. Together they meet both the compute continuity and database durability requirements with minimal re-architecture of the existing three-tier application.

Why this answer

A regional managed instance group spreads application instances across zones and self-heals when a zone fails, while Cloud SQL high availability keeps a synchronized standby in another zone and fails over automatically without losing committed transactions. That pairing satisfies both continuity and durability with minimal change to the existing three-tier design.

Exam trap

The trap here is treating backups, point-in-time recovery, or an asynchronous read replica as equivalent to synchronous high availability for a no-data-loss requirement.

36
MCQmedium

A security team wants to prevent data exfiltration from a GKE cluster to external storage. They need to restrict access to Cloud Storage buckets from the cluster without using private IPs. Which solution should they implement?

A.Configure firewall rules to block outbound traffic to Cloud Storage
B.Enable Cloud Armor on the GKE cluster
C.Use Private Google Access for on-premises access
D.Implement VPC Service Controls with a service perimeter
AnswerD

VPC Service Controls builds a service perimeter around the GKE cluster's project, blocking Cloud Storage access from outside the perimeter even over public IPs. This satisfies the no-private-IP constraint by enforcing an identity- and network-independent boundary against exfiltration.

Why this answer

VPC Service Controls use service perimeters to protect resources and prevent data exfiltration from authorized networks, including GKE clusters, to external resources.

37
MCQhard

A financial services firm runs a regulated workload on Compute Engine. Auditors require that all data at rest on persistent disks be encrypted with keys the firm controls and can revoke, and that key usage be logged independently of the project's Cloud Audit Logs. The firm's security policy forbids storing key material in the same project as the workload. Which approach meets these requirements?

A.Encrypt the disks with customer-supplied encryption keys stored in a Cloud Storage bucket in the workload project.
B.Use Confidential VMs with encrypted persistent disks and rely on the hypervisor to manage disk keys.
C.Use Google-managed encryption keys and enable Data Access audit logs for Compute Engine in the workload project.
D.Create a Cloud KMS key ring in a separate security project, grant the workload's service account `roles/cloudkms.cryptoKeyEncrypterDecrypter`, and attach a customer-managed encryption key to the disks.
AnswerD

Customer-managed encryption keys stored in a dedicated security project give the firm control over rotation and revocation, and placing the key ring in a different project satisfies the separation requirement. Granting only `roles/cloudkms.cryptoKeyEncrypterDecrypter` to the workload's service account follows least privilege, and Cloud KMS key usage is logged in the key project's audit logs, independent of the workload project.

Why this answer

Customer-managed encryption keys in Cloud KMS let the firm rotate and revoke key material, and hosting the key ring in a separate security project enforces separation of duties. Cloud KMS logs key operations in the key's own project, giving auditors independent visibility that is not tied to the workload project's audit configuration.

Exam trap

The trap here is conflating Confidential VMs, which protect data in use, with customer control over data-at-rest keys, which requires Cloud KMS customer-managed encryption keys.

38
Multi-Selecthard

A company uses Cloud Armor to protect their HTTP load balancer. They need to block traffic from a specific set of IP addresses and also prevent SQL injection attacks. Which two configurations should they use? (Choose TWO.)

Select 2 answers
A.IAM roles to restrict access
B.Firewall rules on the VM instances
C.Ingress rules on the VPC network
D.Security policies with IP deny rules
E.Web Application Firewall (WAF) rules with SQL injection preconfigured rules
AnswersD, E

IP deny rules in a Cloud Armor security policy match source addresses at the edge, dropping packets from the specified set before they reach the load balancer. This directly satisfies the requirement to block traffic from named IP addresses, independently of the SQL injection filtering handled by WAF rules.

Why this answer

Option D is correct because Cloud Armor security policies support IP deny rules (e.g., a rule with action 'deny(403)' and a srcIpRanges match condition) that block traffic from a specified set of source IP addresses at the HTTP(S) load balancer edge. Option E is correct because Cloud Armor provides preconfigured WAF rules, including the 'sqli' (SQL injection) rule set based on ModSecurity CRS signatures, which detect and block SQL injection attempts when attached to the backend service. Options A, B, and C are incorrect: IAM roles govern identity and API access rather than filtering malicious HTTP traffic, VM firewall rules and VPC ingress rules operate at Layers 3/4 on instances or subnets and cannot inspect HTTP payloads for SQL injection, and they are not the Cloud Armor mechanism for protecting an HTTP(S) load balancer.

Exam trap

The trap here is that candidates confuse network-layer controls (firewall rules, VPC ingress) with application-layer protection (WAF), or think IAM roles can filter traffic, when in fact Cloud Armor is the only service that combines IP-based deny rules with WAF capabilities for HTTP load balancers.

39
MCQeasy

A media company is designing a new content delivery architecture on Google Cloud. Users worldwide download large video files, and the company wants to serve them from a global edge cache while keeping the origin bucket private. They also want to reduce egress cost by caching at the edge. Which Google Cloud service should you recommend as the front end for this architecture?

A.Cloud CDN with a global external Application Load Balancer and a Cloud Storage backend bucket.
B.A regional external Application Load Balancer in front of a Managed Instance Group that serves the video files from local SSD.
C.Cloud Storage with a multi-region bucket and signed URLs generated per user request.
D.Cloud Interconnect between the company's data center and a Google Cloud region, with the bucket served from that region.
AnswerA

Cloud CDN caches content at Google's globally distributed edge points of presence, reducing latency for worldwide users and offloading repeated requests from the origin. A global external Application Load Balancer can front a Cloud Storage bucket as a backend, and the bucket can remain private because only the load balancer's service account needs read access. This directly meets the global edge caching and cost-reduction goals.

Why this answer

Cloud CDN integrated with a global external Application Load Balancer and a Cloud Storage backend bucket delivers content from Google's global edge, cutting latency for worldwide users and reducing origin egress by serving cached responses. The bucket stays private because only the load balancer's service account is granted read access, so the architecture meets both the caching and privacy requirements.

Exam trap

The trap here is assuming that a multi-region Cloud Storage bucket alone provides edge caching for global users.

40
MCQmedium

Your company uses Cloud SQL for PostgreSQL to support a web application. During peak hours, the database experiences high read load, causing slow query responses. You need to improve read performance while ensuring data consistency. What should you do?

A.Increase the machine type of the Cloud SQL instance to a larger size with more vCPUs and memory.
B.Enable high availability (HA) on the Cloud SQL instance to distribute read traffic across multiple zones.
C.Configure Cloud SQL to use SSD storage instead of HDD to improve read throughput.
D.Create a read replica and configure the application to send read queries to the replica.
AnswerD

Creating a read replica offloads read traffic from the primary instance, improving read performance. Cloud SQL read replicas are asynchronously replicated, which may introduce slight replication lag, but for many read-heavy workloads, this is acceptable. The application can be configured to direct read queries to the replica, reducing load on the primary and improving response times. This approach maintains data consistency for reads that can tolerate eventual consistency.

Why this answer

Creating a read replica allows read queries to be offloaded from the primary instance, directly addressing high read load and improving performance. It scales reads horizontally and is a standard pattern for read-heavy applications. Other options either do not distribute read traffic or provide only temporary vertical scaling.

Exam trap

The trap here is assuming that high availability (HA) can be used for read scaling; HA provides failover, not additional read capacity.

41
MCQeasy

A developer wants to store a database password that is used by a Cloud Function. The password must be automatically rotated every 30 days and accessed securely without storing it in the source code. Which GCP service should they use?

A.Cloud KMS
B.Cloud Runtime Configuration
C.Secret Manager
D.Firestore
AnswerC

Secret Manager stores the password securely and supports automatic rotation schedules, so the Cloud Function retrieves it at runtime rather than embedding it in source code. This satisfies both the 30-day rotation and secure-access constraints.

Why this answer

Secret Manager is the GCP service purpose-built for storing, accessing, and rotating secrets like database passwords. It supports automatic rotation schedules (including 30-day intervals) via Cloud Functions or Pub/Sub notifications, and Cloud Functions can access secrets at runtime using the Secret Manager API with IAM controls, keeping credentials out of source code.

Exam trap

PCA often tests the distinction between Cloud KMS (encryption keys) and Secret Manager (application secrets), so candidates who see 'password' and think 'encryption' incorrectly choose Cloud KMS.

How to eliminate wrong answers

Option A is wrong because Cloud KMS is for managing encryption keys (CMEK), not for storing and rotating application secrets like passwords; it does not provide secret versioning or rotation of arbitrary secret values. Option B is wrong because Cloud Runtime Configuration (Runtime Configurator) is deprecated and was intended for dynamic configuration, not secure secret storage with rotation. Option D is wrong because Firestore is a NoSQL document database and storing passwords there lacks the security, audit, and rotation features of Secret Manager.

42
MCQeasy

An engineer needs to grant a user the ability to create and manage service accounts in a project. Which predefined IAM role provides these permissions?

A.roles/owner
B.roles/iam.serviceAccountAdmin
C.roles/editor
D.roles/iam.workloadIdentityUser
AnswerB

roles/iam.serviceAccountAdmin grants the full set of service account management permissions — creating, deleting, updating and viewing service accounts, plus binding IAM policies on them — matching the requirement to create and manage service accounts within the project.

Why this answer

The predefined role roles/iam.serviceAccountAdmin provides permissions to create and manage service accounts within a project. It includes actions like creating, deleting, and updating service accounts, as well as managing their IAM policies. This role is specifically designed for service account administration.

Exam trap

The trap is confusing serviceAccountAdmin with serviceAccountUser or owner. Candidates might think owner is needed, but it's over-privileged. The key is to know the specific predefined role for managing service accounts.

How to eliminate wrong answers

Option A is wrong because roles/owner grants full control over all resources in the project, which is excessive and violates least privilege. Option C is wrong because roles/editor allows broad edit access but does not include the specific permissions to manage service accounts. Option D is wrong because roles/iam.workloadIdentityUser is used to allow a service account to impersonate another service account, not to manage service accounts.

43
MCQmedium

An organization uses Active Directory (AD) on-premises and wants to synchronize user identities to Google Cloud Identity so that users can access G Suite and GCP resources with their existing credentials. Which service should they use?

A.Cloud Identity-Aware Proxy (IAP)
B.Federation with Google Identity Platform
C.Cloud Directory Sync
D.SAML SSO
AnswerC

Cloud Directory Sync reads users and groups from on-premises Active Directory via LDAP, then provisions and updates matching identities in Cloud Identity, letting users authenticate to G Suite and GCP with existing credentials. It satisfies the synchronisation requirement without federation.

Why this answer

Google Cloud Directory Sync (GCDS) is the tool designed to synchronize users, groups, and organizational units from on-premises Active Directory (or LDAP) to Google Cloud Identity or Google Workspace. It runs on-premises, reads from AD via LDAP, and provisions matching identities in Google, enabling users to sign in with existing credentials.

Exam trap

PCA often tests the difference between directory synchronization (GCDS) and authentication federation (SAML SSO), so candidates who focus on 'existing credentials' pick SAML SSO instead of the sync tool.

How to eliminate wrong answers

Option A is wrong because Cloud Identity-Aware Proxy (IAP) is an access control layer for applications, not an identity synchronization service. Option B is wrong because Federation with Google Identity Platform is for federating authentication (e.g., SAML/OIDC) rather than synchronizing directory objects like users and groups from AD. Option D is wrong because SAML SSO enables single sign-on but does not synchronize user identities into Cloud Identity; it relies on the IdP for authentication without provisioning directory entries.

44
MCQhard

A company's BigQuery costs are higher than expected. They run many ad-hoc queries with filters on the 'transaction_date' column and 'customer_id' column. They also have a materialized view that is rarely used. Which combination of actions will MOST effectively reduce query costs?

A.Convert to a clustered table on transaction_date and disable caching
B.Use flat-rate pricing for all queries and cluster on transaction_date
C.Partition on customer_id and use materialized views for all queries
D.Partition on transaction_date, cluster on customer_id, and drop the unused materialized view
AnswerD

Partitioning on transaction_date enables partition pruning for date filters, clustering on customer_id co-locates rows for that filter, and dropping the unused materialized view removes its storage and refresh costs. Together these cut bytes scanned, the dominant BigQuery cost driver.

Why this answer

Partitioning by transaction_date reduces scanned data for date filters. Clustering by customer_id further reduces bytes billed for queries filtering on that column. Dropping unused materialized views avoids storage costs.

45
MCQmedium

An organization uses Cloud Deployment Manager to manage infrastructure as code. They need to ensure that changes to production resources are reviewed and approved before deployment. What should they do?

A.Use Cloud Scheduler to run deployment configs and review logs after deployment
B.Integrate Cloud Deployment Manager with Cloud Build and add a manual approval step in the Cloud Build pipeline
C.Create a Cloud Deployment Manager preview deployment and manually approve it
D.Use Cloud Build with a trigger on a branch that requires pull request approval before merging
AnswerB

Cloud Build triggers can pause on a manual approval gate before executing the Deployment Manager template, ensuring production changes are reviewed and authorised. Deployment Manager alone has no native approval workflow, so the pipeline supplies the required control.

Why this answer

Integrating Cloud Deployment Manager with Cloud Build allows you to create a CI/CD pipeline that includes a manual approval step. This ensures that changes to production resources are reviewed and approved before the deployment config is applied, meeting the requirement for change control.

Exam trap

The trap here is that candidates often confuse code review (pull request approval) with deployment approval, thinking that merging code with approval automatically ensures deployment approval, but Cloud Deployment Manager requires a separate approval step in the deployment pipeline to control when infrastructure changes are actually applied.

How to eliminate wrong answers

Option A is wrong because Cloud Scheduler is a cron job service for triggering actions on a schedule; it does not provide any review or approval mechanism, and reviewing logs after deployment does not prevent unapproved changes. Option C is wrong because a Cloud Deployment Manager preview deployment only shows what changes would be made without actually applying them, but it does not enforce a formal review and approval workflow; manual approval of a preview is not a built-in feature of Deployment Manager. Option D is wrong because while using Cloud Build with a trigger on a branch that requires pull request approval before merging enforces code review, it does not directly integrate with Cloud Deployment Manager to control the deployment of infrastructure; it only controls the merge of code, not the deployment of resources.

46
MCQmedium

You need to monitor the performance of a production Cloud Run service and set an alert when the p99 latency exceeds 500 ms over a 5-minute window. Which combination of Cloud Monitoring resources should you use?

A.Define an alerting policy using the metric 'run.googleapis.com/request_latencies' with a percentile aggregator and threshold condition
B.Create a log-based metric for latency and an alerting policy with a condition on the count of logs
C.Use Cloud Logging to export logs to BigQuery and run a scheduled query to check latency
D.Create an uptime check and set an alert on the check response time
AnswerA

Cloud Run exports request latency as a distribution metric, so a percentile aggregator is required to derive p99 rather than an average. Pairing that aggregator with a 500 ms threshold over a five-minute alignment window satisfies the stem's latency alerting condition.

Why this answer

Cloud Run exposes request latency as the built-in metric run.googleapis.com/request_latencies, which can be aggregated with a percentile aligner (e.g., 99th percentile) over a 5-minute window and used in a Cloud Monitoring alerting policy with a threshold of 500 ms. This is the native, lowest-latency path for p99 latency alerting on Cloud Run.

Exam trap

PCA often tests the misconception that log-based metrics or uptime checks can substitute for native latency metrics — the exam expects you to know that request_latencies with a percentile aggregator is the correct primitive for p99 alerting.

How to eliminate wrong answers

Option B is wrong because log-based metrics count log entries, not latency distributions — you cannot compute a p99 from log counts, and latency is already a first-class metric. Option C is wrong because exporting logs to BigQuery and running scheduled queries introduces significant delay and complexity, and logs do not contain structured latency percentiles suitable for real-time alerting. Option D is wrong because uptime checks measure availability and response time from external probes at a coarse interval, not the service's internal p99 request latency distribution.

47
MCQeasy

A startup is deploying a containerized application on Google Kubernetes Engine (GKE). The development team wants to minimize operational overhead for managing the Kubernetes control plane and nodes. They also want to ensure that nodes are automatically upgraded and repaired. Which GKE mode should they use?

A.GKE Standard mode with a regional cluster and node auto-repair enabled.
B.GKE Autopilot mode with a regional cluster.
C.GKE Standard mode with a zonal cluster and manually managed node pools.
D.GKE Autopilot mode with a zonal cluster.
AnswerB

GKE Autopilot mode provides a fully managed control plane and node management, including automatic upgrades and repairs. It minimizes operational overhead by handling node provisioning, scaling, and security. A regional cluster provides high availability across zones. This mode directly satisfies the requirements of reduced overhead and automatic node lifecycle management.

Why this answer

GKE Autopilot mode is designed to minimize operational overhead by fully managing the control plane and nodes, including automatic upgrades and repairs. A regional cluster provides high availability across multiple zones. Together, they meet the startup's requirements for reduced management and automatic node lifecycle operations.

Exam trap

The trap here is assuming that enabling node auto-repair in Standard mode is equivalent to the fully managed node lifecycle in Autopilot.

48
MCQeasy

A small startup is deploying a new application on Google Cloud. They want to ensure that they can monitor the application's performance and receive alerts when certain thresholds are exceeded. They have limited operational staff and want a managed solution that requires minimal configuration. Which Google Cloud service should they use?

A.Cloud Logging with log sinks to BigQuery and custom scripts to analyze logs.
B.Cloud Monitoring with alerting policies based on metrics and log-based alerts.
C.Cloud Trace with custom instrumentation and manual analysis of trace data.
D.Cloud Profiler with continuous profiling and manual review of profiles.
AnswerB

Cloud Monitoring is a managed service that collects metrics, logs, and events from Google Cloud resources and applications. It allows you to create alerting policies that trigger notifications when metrics cross thresholds. It also supports log-based alerts for specific log patterns. With minimal configuration, the startup can set up dashboards and alerts without managing any infrastructure. This directly meets the requirement for a managed monitoring and alerting solution.

Why this answer

Cloud Monitoring is the managed service on Google Cloud for collecting metrics, creating dashboards, and setting up alerting policies. It integrates with many Google Cloud services and can send notifications via email, SMS, Slack, PagerDuty, and more. For a startup with limited staff, it requires minimal setup and no infrastructure management.

Log-based alerts extend its capabilities to specific log events. This makes it the ideal choice for monitoring performance and receiving alerts.

Exam trap

The trap here is confusing monitoring with logging, tracing, or profiling; only Cloud Monitoring provides alerting based on metrics and thresholds out of the box.

49
MCQmedium

A company is migrating its on-premises data warehouse to BigQuery. The data is currently stored in several CSV files on a Compute Engine instance. The company needs to load the data into BigQuery once and then perform complex analytical queries. The data volume is about 10 TB, and the company wants to minimize cost and loading time. Which approach should the architect recommend?

A.Create a Dataproc cluster and run a Spark job to read the CSV files and write them to BigQuery.
B.Use BigQuery Data Transfer Service to schedule a recurring transfer from the Compute Engine instance.
C.Upload the CSV files to a Cloud Storage bucket, then use a BigQuery load job to load the data from Cloud Storage into a BigQuery table.
D.Use the bq command-line tool to load the CSV files directly from the Compute Engine instance into BigQuery.
AnswerC

Uploading the CSV files to Cloud Storage and then using a BigQuery load job is the recommended approach. BigQuery load jobs from Cloud Storage are fast, support parallel loading, and are free for loading data (you only pay for storage and queries). This minimizes loading time and cost for a 10 TB dataset.

Why this answer

A BigQuery load job from Cloud Storage is the most efficient and cost-effective method for a one-time load of 10 TB. It leverages massively parallel loading, has no loading charges, and avoids the overhead of managing additional services. Uploading to Cloud Storage first is a standard best practice for large-scale data ingestion into BigQuery.

Exam trap

The trap here is assuming that a direct load from Compute Engine or a custom Dataproc job is needed, when the native Cloud Storage to BigQuery load job is simpler, faster, and cheaper.

50
Multi-Selecteasy

Which two GCP audit log types are available by default? (Choose TWO).

Select 2 answers
A.Admin Activity audit logs
B.System Event audit logs
C.Cloud Audit Logs
D.Policy Denied audit logs
E.Data Access audit logs
AnswersA, B

Admin Activity audit logs record API calls that modify resource configuration or metadata, and GCP writes them automatically for every project at no cost. They are always enabled and cannot be disabled, satisfying the requirement for a log type available by default.

Why this answer

Admin Activity audit logs (A) are enabled by default and always written for free, capturing administrative operations that modify resource configurations or metadata, such as creating a VM or changing IAM policies. System Event audit logs (B) are also enabled by default and record Google Cloud system-generated actions that modify resources, such as live migration of a VM or automatic restart by a scheduler, and they cannot be disabled. Cloud Audit Logs (C) is not a log type but the overall umbrella service comprising Admin Activity, Data Access, System Event, and Policy Denied logs, so it is not one of the two default types.

Policy Denied audit logs (D) are only written when a security policy such as VPC Service Controls denies a request, and Data Access audit logs (E) are disabled by default (except for BigQuery) and must be explicitly enabled per service, so neither is available by default.

Exam trap

PCA often tests the distinction between always-on audit logs (Admin Activity, System Event) and opt-in logs (Data Access, Policy Denied), tricking candidates into selecting Data Access because it sounds fundamental.

51
MCQeasy

A startup wants to deploy a containerised web application that auto-scales based on HTTP request traffic, with no infrastructure management. They expect unpredictable traffic spikes. Which compute service is most suitable?

A.Cloud Run
B.Compute Engine with managed instance groups
C.Cloud Functions
D.Google Kubernetes Engine (GKE) Autopilot
AnswerA

Cloud Run is fully managed and scales container instances automatically from zero based on incoming HTTP request volume, so unpredictable spikes are absorbed without provisioning or managing servers. It satisfies the no-infrastructure-management and traffic-driven autoscaling constraints directly.

Why this answer

Cloud Run is a fully managed serverless container platform that automatically scales container instances based on incoming HTTP requests (including scale-to-zero), requires no cluster or VM management, and is purpose-built for stateless containerised web workloads with unpredictable traffic. It handles HTTP load balancing, TLS, and concurrency tuning natively, matching the startup's requirements exactly.

Exam trap

PCA often tests the distinction between serverless containers (Cloud Run) and serverless functions (Cloud Functions) — candidates wrongly pick Cloud Functions for 'containerised' workloads or GKE Autopilot when 'no infrastructure management' is the key phrase.

How to eliminate wrong answers

Option B is wrong because Compute Engine managed instance groups still require the customer to manage VM images, patching, autoscaling policies, and load balancer configuration — it is IaaS, not 'no infrastructure management'. Option C is wrong because Cloud Functions runs event-driven function code (single-purpose snippets), not arbitrary containerised web applications, and has runtime/language constraints unsuitable for a full web app. Option D is wrong because GKE Autopilot, while reducing node management, still requires Kubernetes manifests, cluster concepts, and operational knowledge — it is not the lowest-management option for a simple containerised HTTP service.

52
Drag & Dropmedium

Drag and drop the steps to implement a disaster recovery plan using Cloud Storage and Cloud Functions in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Versioning protects against accidental deletion. The Cloud Function copies objects to the DR bucket.

53
Multi-Selecthard

Which THREE are best practices for managing secrets (e.g., API keys, passwords) in Google Cloud? (Select exactly 3.)

Select 3 answers
A.Rotate secrets regularly and automatically where possible.
B.Encrypt secrets and store them in source code repositories.
C.Use Secret Manager to store and version secrets.
D.Grant access to secrets using IAM roles at the project or secret level.
E.Pass secrets as environment variables to Compute Engine instances.
AnswersA, C, D

Regular rotation reduces the risk of compromised secrets.

Why this answer

Regular, automated rotation of secrets limits the window of exposure if a secret is compromised. Secret Manager supports automatic rotation policies with a rotation period and next rotation time, and can trigger a Cloud Function or Cloud Run service to generate a new secret version, ensuring secrets are rotated without manual intervention.

Exam trap

Google Cloud often tests the misconception that encrypting secrets before storing them in code repositories is acceptable, when in fact any storage in source control violates the principle of separation of secrets from code, and that environment variables are a secure method for passing secrets to Compute Engine instances, whereas they are easily exposed through metadata endpoints or process inspection.

54
MCQmedium

A healthcare company stores patient records in Cloud Storage and BigQuery. Auditors require that cryptographic keys used to protect this data are generated and stored on hardware security modules, that key material never leaves Google's infrastructure, and that the company retains the ability to control key rotation and revocation. The security team wants the least operational overhead while meeting these requirements. Which key management approach should the architect select?

A.Google-managed encryption keys with default encryption at rest
B.Customer-supplied encryption keys (CSEK) managed in the company's own on-premises key vault
C.Client-side encryption performed by the application before writing objects to Cloud Storage
D.Customer-managed encryption keys (CMEK) backed by Cloud KMS with a Cloud HSM protection level
AnswerD

CMEK with a Cloud HSM protection level generates and stores key material inside FIPS 140-2 Level 3 validated hardware security modules, and the key never leaves Google infrastructure. The organization controls rotation schedules, IAM bindings on the key, and can disable or destroy the key to revoke access, satisfying the auditors with minimal operational burden.

Why this answer

Customer-managed encryption keys using Cloud KMS with the Cloud HSM protection level satisfy all three auditor conditions: hardware security module key generation and storage, key material confined to Google infrastructure, and customer control over rotation and revocation. CSEK and client-side encryption move key custody to the customer and add heavy operational cost, while Google-managed keys remove the customer control the auditors demanded.

Exam trap

The trap here is assuming that any customer-controlled key option satisfies the hardware security module requirement, when CSEK and client-side keys are customer-held software keys with no HSM backing.

55
MCQeasy

A company wants to analyze their Google Cloud spending and receive recommendations for rightsizing resources. Which tool provides this functionality?

A.BigQuery Reservations
B.Active Assist
C.Google Cloud Pricing Calculator
D.Cloud Billing reports
AnswerB

Active Assist applies Google Cloud's recommender engine to analyse usage telemetry and surface rightsizing recommendations, directly satisfying the stem's requirement for spend analysis plus resource optimisation guidance. It covers idle resource detection, committed use discounts and machine-type adjustments natively, unlike generic billing exports or third-party cost tools that lack built-in recommendation logic.

Why this answer

Active Assist includes recommendations for rightsizing Compute Engine VMs, Cloud SQL instances, and more. BigQuery Reservations is for slot management. Cloud Billing reports show costs but not recommendations.

Pricing Calculator estimates costs.

56
MCQhard

A company deploys a Kubernetes workload in GKE that needs to access Cloud Storage. They want to avoid managing service account keys. What is the recommended approach?

A.Use the default Compute Engine service account on the node.
B.Store a service account key in a Kubernetes secret and mount it.
C.Use Workload Identity to map the Kubernetes service account to a GCP service account.
D.Use Cloud Key Management Service to encrypt the service account key.
AnswerC

Workload Identity federates Kubernetes service accounts to GCP service accounts via the GKE metadata server, issuing short-lived credentials automatically. This removes the need to create, distribute, or rotate service account keys, meeting the keyless requirement.

Why this answer

Workload Identity is the recommended way for GKE workloads to authenticate to Google Cloud services without managing long-lived service account keys. It binds a Kubernetes service account (KSA) to a Google Cloud service account (GSA) via IAM, and the GKE metadata server issues short-lived credentials to the pod automatically. This eliminates key rotation, storage, and leakage risks.

Exam trap

PCA often tests the misconception that encrypting or storing a service account key (KMS or Kubernetes secret) is a secure alternative — the exam wants you to recognize that eliminating keys entirely via Workload Identity is the only keyless option.

How to eliminate wrong answers

Option A is wrong because using the node's default Compute Engine service account grants every pod on the node the same broad permissions, violating least privilege and still relying on node-level credentials. Option B is wrong because storing a service account key in a Kubernetes secret reintroduces the exact key-management problem the company wants to avoid — keys are long-lived, can leak, and require rotation. Option D is wrong because KMS encrypts the key but does not eliminate it; the key still exists, must be decrypted by the workload, and remains a long-lived credential to manage.

57
MCQeasy

A developer is migrating a stateful application to GKE. The application requires persistent storage with high IOPS for a database. Which storage option is most suitable?

A.Local SSD
B.Persistent Disk SSD
C.Cloud Storage Fuse
D.Persistent Disk Standard
AnswerB

Persistent Disk SSD provides block storage backed by solid-state media, delivering the high IOPS a database demands. It supports ReadWriteOnce access for a single stateful pod, matching the persistent, high-performance storage requirement of the migrated application.

Why this answer

Persistent Disk SSD (pd-ssd) is the most suitable option for a stateful database on GKE requiring high IOPS because it provides block storage with consistent, high-performance IOPS and can be dynamically provisioned via PersistentVolumeClaims. Unlike Local SSD, pd-ssd persists data independently of the node lifecycle, ensuring data durability during pod rescheduling or node failures.

Exam trap

Google Cloud often tests the misconception that Local SSD is suitable for stateful workloads because of its high IOPS, but the trap is that candidates forget Local SSD is ephemeral and does not survive pod rescheduling or node failures.

How to eliminate wrong answers

Option A is wrong because Local SSD provides high IOPS but is ephemeral—data is lost if the pod is rescheduled or the node is deleted, making it unsuitable for stateful databases that require persistent storage. Option C is wrong because Cloud Storage Fuse is a file-system interface for Cloud Storage objects, not a block device; it introduces latency and lacks the low-level IOPS consistency needed for database workloads. Option D is wrong because Persistent Disk Standard (pd-standard) uses HDD-based storage with significantly lower IOPS and higher latency, which cannot meet the high IOPS requirements of a database.

58
MCQeasy

A company is migrating its on-premises Hadoop cluster to Google Cloud. They want to use a fully managed service that supports HDFS, Hive, and Spark, and allows them to run ephemeral clusters that can be created and deleted on demand. They also want to minimize infrastructure management. Which Google Cloud service should they use?

A.Cloud Bigtable
B.BigQuery
C.Cloud Dataflow
D.Cloud Dataproc
AnswerD

Cloud Dataproc is a fully managed service for running Apache Hadoop, Spark, Hive, and other open-source big data tools. It allows you to create ephemeral clusters that can be spun up quickly, run jobs, and then be deleted, minimizing costs and infrastructure management. It supports HDFS as the distributed storage layer. This meets all the requirements.

Why this answer

Cloud Dataproc is the only service that provides a managed Hadoop and Spark environment with support for HDFS, Hive, and ephemeral clusters. It allows you to create clusters on demand and delete them when jobs are complete, reducing operational overhead. The other services are not Hadoop-compatible or do not support the required tools.

Exam trap

The trap here is assuming that BigQuery or Dataflow can replace Hadoop workloads; they are different paradigms and do not support HDFS or Hive.

59
MCQmedium

A media company runs a monthly batch pipeline that transcodes video uploads stored in Cloud Storage. The pipeline runs on a Managed Instance Group of Compute Engine VMs and typically completes in 6 hours. The VMs are only needed during this window, but the team wants to minimise the operational effort of stopping and starting the group. Which approach best optimises both cost and operational overhead?

A.Move the transcoding workload to a Cloud Run service with a minimum instance count of zero.
B.Create an instance schedule that starts and stops the managed instance group on a recurring monthly calendar.
C.Convert the VMs to preemptible instances and configure a restart policy.
D.Enable autoscaling on the managed instance group based on CPU utilisation.
AnswerB

Instance schedules let you define recurring start and stop times for managed instance groups, so the VMs are not billed outside the transcode window. This directly reduces compute cost without manual intervention, and the schedule is managed centrally in Compute Engine, meeting the low operational effort requirement for a predictable monthly workload.

Why this answer

The workload has a known, recurring schedule, so the most efficient optimisation is to stop paying for VMs when the pipeline is not running. Instance schedules on a managed instance group start and stop instances automatically, which lowers compute cost and removes manual start/stop toil. Autoscaling, preemptible VMs, and Cloud Run do not eliminate the idle monthly window in the same controlled way.

Exam trap

The trap here is assuming that autoscaling or cheaper VM types will address idle time, when the real cost driver is the predictable period when the group is not needed at all.

60
MCQmedium

Your organization requires all container images deployed to GKE to be signed by an approved authority. Which service enforces that only signed images are allowed to run?

A.Binary Authorization
B.Cloud Asset Inventory
C.Artifact Registry
D.Container Analysis
AnswerA

Binary Authorization enforces deploy-time admission control on GKE, verifying cryptographic signatures against attestors you define before permitting a pod to start. This directly satisfies the stem's requirement that only images signed by an approved authority may run, blocking unsigned or unverified images at admission rather than merely scanning them afterwards.

Why this answer

Binary Authorization is a deploy-time security control on GKE and Cloud Run that only permits container images that satisfy a defined policy — typically requiring attestations from trusted authorities (e.g., a vulnerability scanner or a signing step in the CI pipeline). It integrates with Container Analysis, which stores the attestations, but Binary Authorization is the component that actually blocks unsigned or unattested images from being admitted to the cluster.

Exam trap

The trap is conflating the scanner (Container Analysis) with the enforcer (Binary Authorization) — the exam expects you to know that scanning alone does not prevent deployment.

How to eliminate wrong answers

Option B is wrong because Cloud Asset Inventory is a metadata catalog for discovering and monitoring GCP resources — it has no admission-control capability. Option C is wrong because Artifact Registry is a container image repository; it stores images but does not enforce signature verification at deploy time. Option D is wrong because Container Analysis performs vulnerability scanning and stores metadata/attestations, but it does not itself block deployments — it feeds the data that Binary Authorization evaluates.

61
MCQmedium

Your company runs a stateful application on Compute Engine instances in a managed instance group (MIG). The application writes data to a persistent disk attached to each instance. You need to ensure that the application can automatically recover from a zone failure by recreating instances in another zone with their persistent disks. You also want to minimize data loss. Which configuration should you implement?

A.Create a zonal MIG in a single zone and use a snapshot schedule to back up persistent disks every hour to a multi-region bucket. In case of zone failure, manually restore the snapshots to new instances in another zone.
B.Create a regional MIG with instances distributed across multiple zones in the region, and configure each instance to use a regional persistent disk that is replicated across those zones.
C.Create a regional MIG and attach a standard persistent disk to each instance. Configure the MIG to recreate instances in other zones, and rely on the persistent disk's automatic replication across zones.
D.Create a zonal MIG and configure an autoscaler to add instances in other zones when the primary zone fails. Use a Cloud Storage bucket to store application data instead of persistent disks.
AnswerB

A regional MIG automatically distributes instances across zones and can recreate failed instances in other zones. Regional persistent disks are synchronously replicated across two zones in the same region, so if one zone fails, the disk can be attached to an instance in the other zone with minimal data loss. This combination provides automatic recovery and data redundancy.

Why this answer

A regional MIG spreads instances across multiple zones and can automatically recreate instances in healthy zones if one zone fails. Regional persistent disks are replicated across two zones, ensuring that data is available in another zone with minimal loss. Together, they provide automatic recovery and data redundancy.

Zonal MIGs cannot move instances across zones, and standard persistent disks are not replicated.

Exam trap

The trap here is assuming that a zonal MIG can automatically recreate instances in another zone or that standard persistent disks are replicated across zones.

62
Drag & Dropmedium

Drag and drop the steps to configure IAM roles for a service account to access Cloud Storage from a Compute Engine instance into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The service account must be attached to the instance before it can be used. Granting roles is done on the service account.

63
MCQeasy

A company uses Cloud SQL for PostgreSQL. They want to minimize downtime during maintenance. Which feature should they enable?

A.Read replicas.
B.High availability with a standby in another zone.
C.Point-in-time recovery.
D.Automated backups.
AnswerB

High availability provisions a standby replica in a different zone; during maintenance or a zone failure, Cloud SQL fails over automatically, minimising downtime. Read replicas and automated backups do not provide this automatic cross-zone failover, so they cannot satisfy the stem's downtime constraint.

Why this answer

High availability (HA) with a standby in another zone ensures that Cloud SQL for PostgreSQL automatically fails over to a standby instance in a different zone if the primary zone experiences an outage. This minimizes downtime during maintenance because Cloud SQL performs a controlled failover to the standby, typically completing within a few seconds, rather than requiring a full instance restart or rebuild.

Exam trap

The trap here is that candidates often confuse read replicas with high availability, assuming read replicas can automatically take over for the primary, but read replicas require manual promotion and do not provide automatic failover, making HA with a standby the correct choice for minimizing downtime during maintenance.

How to eliminate wrong answers

Option A is wrong because read replicas are designed for offloading read traffic and do not provide automatic failover for the primary instance; they require manual promotion, which introduces downtime. Option C is wrong because point-in-time recovery (PITR) is used for restoring data to a specific timestamp after data corruption or accidental deletion, not for reducing downtime during planned maintenance. Option D is wrong because automated backups protect against data loss by creating periodic backups, but they do not provide a standby instance for failover, so maintenance still requires downtime to restart the primary instance.

64
MCQeasy

Your company runs a critical application on Google Kubernetes Engine (GKE) with 5 nodes. The application experiences intermittent high latency every Friday afternoon. The team has ruled out infrastructure issues and suspects the application logic. You need to instrument the application to identify the root cause. Which approach should you take?

A.Use Cloud Monitoring to create custom metrics for application performance and investigate recent code changes.
B.Increase the number of nodes in the GKE cluster to handle the load.
C.Enable Cloud Logging and analyze logs for error messages during the latency periods.
D.Configure GKE usage metering to track resource consumption by namespace.
AnswerA

Cloud Monitoring custom metrics expose application-level performance signals, letting the team correlate Friday latency spikes with recent code changes rather than infrastructure. This instruments application logic directly, satisfying the need to pinpoint the root cause after infrastructure was ruled out.

Why this answer

The team has already ruled out infrastructure issues and suspects application logic. Creating custom metrics in Cloud Monitoring allows you to instrument the application with key performance indicators (e.g., request latency, error rates) and correlate them with recent code changes to pinpoint the root cause of intermittent high latency. This approach directly addresses the need to monitor application-level behavior rather than infrastructure metrics.

Exam trap

The trap here is that candidates often confuse operational logging (Option C) with performance monitoring, failing to recognize that intermittent latency without errors requires custom metrics to measure application-specific performance indicators.

How to eliminate wrong answers

Option B is wrong because increasing the number of nodes addresses infrastructure capacity, which has already been ruled out as the cause; it does not help identify application logic issues. Option C is wrong because while Cloud Logging can capture error messages, the problem is intermittent high latency without necessarily generating errors; analyzing logs alone may miss performance bottlenecks that require custom metrics. Option D is wrong because GKE usage metering tracks resource consumption by namespace for cost allocation, not application performance or latency issues.

65
MCQeasy

A company needs a relational database that can scale horizontally across multiple regions, supports ACID transactions, and provides strong global consistency. Which Google Cloud database should they choose?

A.BigQuery
B.Cloud SQL
C.Cloud Spanner
D.Firestore
AnswerC

Cloud Spanner is horizontally sharded yet presents a single relational schema with externally consistent reads and ACID transactions across regions, using TrueTime for global ordering. That combination satisfies the stem's simultaneous demands for horizontal scale, multi-region reach and strong global consistency.

Why this answer

Cloud Spanner is the only Google Cloud database that offers horizontal scaling, ACID transactions, and strong global consistency across regions.

66
Matchingmedium

Match each IAM role type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Legacy roles like Owner, Editor, Viewer

Fine-grained roles managed by Google

User-defined roles with specific permissions

Another name for Basic roles

Identity for applications, not users

Why these pairings

In GCP, IAM roles are categorized into basic (broad), predefined (service-specific), and custom (user-defined). Common confusions arise between predefined and custom roles.

67
Multi-Selecthard

Which THREE are required to configure Workload Identity for a GKE cluster? (Choose 3)

Select 3 answers
A.Create a Google Cloud service account
B.Create a Kubernetes service account
C.Enable Workload Identity on the GKE cluster
D.Bind the Kubernetes service account to the Google Cloud service account using a Kubernetes RoleBinding
E.Use a node pool that has Workload Identity enabled
AnswersA, B, C

The GSA is used to grant permissions to the Kubernetes service account.

Why this answer

A Google Cloud service account (GSA) is required to authenticate to Google Cloud APIs from within GKE. Workload Identity maps a Kubernetes service account (KSA) to a GSA, allowing pods to inherit the GSA's IAM permissions without managing static keys. The GSA must be created first to define the identity that workloads will assume.

Exam trap

Google Cloud often tests the distinction between Kubernetes RoleBinding (for RBAC) and IAM policy binding (for Workload Identity), leading candidates to incorrectly select a RoleBinding as the binding mechanism.

68
MCQhard

A company runs a service on Cloud Run that needs to access a Cloud SQL instance via private IP. Both are in the same VPC network. The service cannot connect to the database. What is the most likely cause?

A.Cloud Run must be deployed in the same zone as Cloud SQL.
B.The IAM permissions for Cloud Run to access Cloud SQL are missing.
C.A firewall rule is blocking traffic.
D.Cloud Run needs a Serverless VPC Access connector.
E.The Cloud SQL instance needs a public IP assigned.
AnswerD

Cloud Run egresses through a shared serverless environment, so it cannot reach a private IP inside the VPC without a Serverless VPC Access connector. That connector routes traffic into the VPC, resolving the connection failure.

Why this answer

Cloud Run services run in a Google-managed environment and cannot directly reach resources on a VPC network via private IP. A Serverless VPC Access connector is required to bridge the serverless environment to the VPC, enabling private IP connectivity to Cloud SQL. Without this connector, the Cloud Run service cannot route traffic to the Cloud SQL private IP, even if both are in the same VPC network.

Exam trap

Google Cloud often tests the misconception that being in the same VPC network automatically grants connectivity, but serverless services like Cloud Run require an explicit Serverless VPC Access connector to route traffic into the VPC.

How to eliminate wrong answers

Option A is wrong because Cloud Run is a serverless, zonal-agnostic service; it does not need to be in the same zone as Cloud SQL, and zone affinity does not affect private IP connectivity. Option B is wrong because IAM permissions (e.g., Cloud SQL Client role) control access to the Cloud SQL API for management operations, not network-level connectivity to the database's private IP; the issue is network routing, not authorization. Option C is wrong because firewall rules control traffic at the network layer, but Cloud Run cannot even send traffic into the VPC without a connector, so a firewall rule is not the primary cause.

Option E is wrong because the question specifies that the Cloud SQL instance uses private IP; assigning a public IP would expose the database to the internet and is unnecessary for private connectivity, and the problem is the lack of a routing path, not the IP type.

69
MCQmedium

An organization is using Cloud Interconnect to connect their on-premises network to Google Cloud. They need to ensure 99.99% availability for their connection. Which configuration meets this requirement?

A.A single Partner Interconnect connection at 1Gbps
B.Two Dedicated Interconnect connections from different edge locations
C.A single Dedicated Interconnect connection at 10Gbps
D.High Availability VPN (HA VPN) with two gateways and four tunnels
AnswerB

Two Dedicated Interconnect connections terminating in different Google edge locations provide physically diverse paths, so a single edge or link failure cannot sever connectivity. This redundancy is what satisfies the 99.99% availability requirement, which a single connection or one edge location cannot guarantee.

Why this answer

To achieve 99.99% availability with Cloud Interconnect, Google Cloud requires two Dedicated Interconnect connections in different edge locations (or two Partner Interconnect connections in different metros). This redundant topology eliminates single points of failure at the interconnect level, meeting the SLA for 99.99% availability. A single connection, regardless of bandwidth, cannot meet this SLA.

Exam trap

PCA often tests SLA-to-topology mapping — candidates see '10Gbps' or 'HA VPN' and assume higher bandwidth or the word 'HA' guarantees 99.99%, missing that only redundant Interconnect connections in different edge locations meet the requirement.

How to eliminate wrong answers

Option A is wrong because a single Partner Interconnect connection at 1Gbps is a single point of failure and does not meet the 99.99% availability SLA — Partner Interconnect only reaches 99.99% with redundant connections in different metros. Option C is wrong because a single Dedicated Interconnect connection at 10Gbps, despite higher bandwidth, is still a single point of failure and only qualifies for 99.9% availability. Option D is wrong because HA VPN with two gateways and four tunnels provides 99.99% availability for VPN connectivity, but the question specifies Cloud Interconnect, and HA VPN is a different product that does not satisfy the Interconnect requirement.

70
MCQeasy

After executing the command, a security review reveals that the service account sa-bucket-reader can also list buckets in the project, which was not intended. What is the most likely cause?

A.The etag was incorrect, causing a concurrent modification.
B.The service account has a project-level role that includes storage.list.
C.The policy update failed due to a missing condition.
D.The service account also has bucket-level IAM roles.
AnswerB

Project-level roles like roles/storage.objectAdmin or roles/viewer include storage.buckets.list.

Why this answer

The service account sa-bucket-reader was able to list buckets in the project, which requires the storage.buckets.list permission. This permission is included in several predefined project-level roles, such as roles/storage.objectViewer or roles/storage.legacyBucketReader. If the service account was granted a project-level role that includes storage.buckets.list, it would have the unintended ability to list all buckets in the project, even if bucket-level IAM was configured to restrict access to specific buckets.

Exam trap

In Google PCA exams, the distinction between project-level and resource-level IAM roles is critical. The trap here is that candidates assume bucket-level IAM is the only way to grant bucket access, forgetting that project-level roles can also include bucket-related permissions like storage.buckets.list.

How to eliminate wrong answers

Option A is wrong because an incorrect etag would cause a concurrent modification error during an IAM policy update, but it would not grant additional permissions like storage.buckets.list; the policy would simply fail to apply. Option C is wrong because a missing condition in a policy update would not cause the service account to gain unintended permissions; conditions restrict access, so their absence might allow broader access than intended, but the question states the service account already has the ability to list buckets, implying the permission was granted via a role, not due to a missing condition. Option D is wrong because bucket-level IAM roles are more granular and would not grant the project-level storage.buckets.list permission; bucket-level roles only apply to the specific bucket they are assigned to, not to listing all buckets in the project.

71
Multi-Selecthard

A software company wants to give a third-party analytics vendor read access to a specific BigQuery dataset containing aggregated, non-sensitive sales data, without creating service account keys that the vendor must store and rotate. The security team also wants to be able to revoke access quickly and to see which vendor identities accessed the data. The vendor already uses its own identity provider that supports OpenID Connect. Which TWO approaches together meet these requirements? (Choose two.)

Select 2 answers
A.Grant the federated principal the BigQuery Data Viewer role on the specific dataset rather than at the project level
B.Configure Workload Identity Federation so the vendor's OIDC provider can exchange tokens for short-lived Google credentials
C.Create a service account with a JSON key and share the key file with the vendor through a secure channel
D.Enable VPC Service Controls on the project to prevent the vendor from copying the dataset out
E.Assign the vendor the BigQuery Admin role at the project level to simplify permission management
AnswersA, B

Granting BigQuery Data Viewer at the dataset level follows least privilege by limiting the vendor to exactly the aggregated dataset they need. Combined with workload identity federation, access can be revoked by deleting the dataset-level binding, and Data Access audit logs will record the federated principal's reads.

Why this answer

Workload Identity Federation removes the need for service account keys by exchanging the vendor's OIDC tokens for short-lived Google credentials, and dataset-level BigQuery Data Viewer grants exactly the read access required. Together they deliver keyless authentication, least-privilege access, fast revocation, and attributable audit records. Static keys and broad project roles fail the security and least-privilege requirements.

Exam trap

The trap here is reaching for a service account key as the simplest way to grant external access, when keyless federation plus a narrowly scoped dataset role is the design the scenario is asking for.

72
MCQmedium

A logistics company is planning to migrate a batch ETL pipeline from on-premises Hadoop to Google Cloud. The pipeline processes several terabytes nightly, and the team wants to minimize infrastructure management while keeping the ability to tune the cluster for cost and performance. The data currently resides in an on-premises HDFS cluster. Which combination of services should the architect recommend?

A.BigQuery for storage and analysis, replacing the Spark jobs entirely with SQL.
B.Cloud Storage for durable object storage and Dataproc clusters created per job for processing.
C.Persistent Dataproc clusters with local HDFS storage that run continuously and process jobs on a schedule.
D.Compute Engine VMs running a self-managed Hadoop distribution with Cloud Storage FUSE for input and output.
AnswerB

Cloud Storage provides cheap, durable storage that decouples data from compute, and Dataproc offers managed Spark and Hadoop clusters that can be created for each job and deleted afterward. This pattern eliminates idle cluster costs and reduces operational burden while still allowing the team to choose machine types and cluster sizes per run. It fits the migration and tuning requirements well.

Why this answer

Separating storage from compute with Cloud Storage and using ephemeral Dataproc clusters lets the team process nightly data without paying for idle infrastructure, while still selecting machine types and cluster sizes per job. Persistent clusters, self-managed Hadoop, and a full BigQuery rewrite each fail at least one requirement around management overhead or preserving existing Spark logic.

Exam trap

The trap here is assuming a persistent Dataproc cluster is needed for a recurring batch job, when ephemeral per-job clusters are cheaper and require less management.

73
Multi-Selectmedium

A company wants to implement blameless postmortems as part of their SRE practices. Which THREE principles should they follow?

Select 3 answers
A.Only involve senior management in the review
B.Create actionable recommendations to prevent recurrence
C.Focus on identifying the root cause without blaming individuals
D.Assign responsibility to the team that caused the incident
E.Share findings with all relevant stakeholders
AnswersB, C, E

Blameless postmortems must produce concrete follow-up actions, not just narrative. Actionable recommendations that prevent recurrence close the loop between incident analysis and reliability improvement, satisfying the SRE requirement that postmortems drive measurable change rather than assign fault.

Why this answer

Option B is correct because blameless postmortems must produce concrete, actionable recommendations and follow-up items that reduce the likelihood or impact of recurrence, rather than stopping at description. Option C is correct because the core of blameless postmortems is analyzing systemic and contributing causes of the incident without attributing fault to individuals, which encourages honest reporting. Option E is correct because findings, timelines, and lessons learned should be documented and shared with relevant stakeholders so the whole organization benefits and improves.

Option A is incorrect because limiting participation to senior management excludes the engineers and responders who hold the technical details and undermines learning. Option D is incorrect because assigning responsibility to the team that caused the incident is blame-oriented and contradicts the blameless principle.

Exam trap

The trap here is conflating 'blameless' with 'no accountability' or assuming leadership must be the sole reviewer — candidates pick option A or D because they sound like governance best practices, when they actually undermine the SRE blameless culture.

74
MCQmedium

A company wants to migrate an on-premises Oracle database to Google Cloud. They need high availability and want to minimize application changes. Which service should they use?

A.Cloud SQL for MySQL
B.Bare Metal Solution
C.Cloud Spanner
D.Compute Engine with Oracle license
AnswerB

Bare Metal Solution offers dedicated Oracle-optimized hardware with minimal application changes.

Why this answer

Bare Metal Solution is correct because it provides dedicated physical servers for Oracle workloads, enabling high availability through Oracle RAC or Data Guard while preserving the existing Oracle database architecture. This minimizes application changes since the database remains Oracle-native, unlike managed services that require migration to a different database engine.

Exam trap

The trap here is that candidates often choose Compute Engine with Oracle license (Option D) thinking it is the most flexible, but they overlook the high-availability requirement and the operational overhead of manually configuring Oracle RAC or Data Guard, which Bare Metal Solution simplifies with a managed infrastructure.

How to eliminate wrong answers

Option A is wrong because Cloud SQL for MySQL is a managed MySQL service, not compatible with Oracle databases, requiring a full database migration and application code changes. Option C is wrong because Cloud Spanner is a globally distributed, horizontally scalable relational database that uses a proprietary SQL dialect, not Oracle-compatible, necessitating significant application rewrites. Option D is wrong because Compute Engine with Oracle license requires manual configuration for high availability (e.g., setting up Oracle RAC or Data Guard) and does not provide the same level of managed infrastructure as Bare Metal Solution, increasing operational complexity.

75
MCQhard

A financial services firm runs a latency-sensitive trading API on Google Kubernetes Engine (GKE). During peak market hours, the API occasionally returns errors because pods are evicted when nodes run out of memory. The team wants the workload to be protected from node-level resource pressure and to receive a graceful termination window when the node must be drained. Which configuration should they apply to the Deployment?

A.Configure the pods with Guaranteed QoS by setting requests equal to limits, and set a high priorityClassName so they are evicted last.
B.Set a PodDisruptionBudget with minAvailable equal to the replica count and configure a longer terminationGracePeriodSeconds.
C.Set memory requests equal to limits to achieve Guaranteed QoS, assign a high-priority class, and increase terminationGracePeriodSeconds to allow graceful shutdown.
D.Define resource requests and limits for CPU and memory, and set the pod's priorityClassName to a high-priority class.
AnswerC

Guaranteed QoS makes the pods least likely to be evicted under node memory pressure because they are treated as the highest-priority QoS class. A high-priority class further ensures they are evicted after lower-priority workloads. The longer terminationGracePeriodSeconds gives the container time to finish in-flight trades before SIGKILL, addressing both the eviction protection and graceful-termination requirements in the scenario.

Why this answer

Guaranteed QoS, achieved by setting memory and CPU requests equal to limits, makes pods the last to be evicted when a node is under memory pressure. Pairing that with a high-priority class and a longer terminationGracePeriodSeconds protects the trading API from involuntary eviction and gives it time to drain in-flight requests gracefully, matching both stated requirements.

Exam trap

The trap here is treating a PodDisruptionBudget as protection against node memory-pressure evictions, when it only governs voluntary disruptions such as drains and upgrades.

Page 1 of 11

Page 2

All pages