Courseiva

Google Professional Cloud Architect (PCA) — Questions 676–750

807 questions total · 11pages · All types, answers revealed

Page 9

Page 10 of 11

Page 11
676
MCQeasy

A security team wants to receive alerts when a user attempts to grant the 'roles/owner' role to a member outside of the organization's domain. Which log filter should they use to create a log-based metric?

A.Filter on Admin Activity log type with 'protoPayload.methodName="SetIamPolicy" AND protoPayload.serviceName="cloudresourcemanager.googleapis.com" AND NOT protoPayload.request.policy.bindings: member: "example.com"'.
B.Filter on Data Access log type with 'protoPayload.methodName="google.iam.v1.IAMPolicy.SetIamPolicy"'.
C.Filter on Admin Activity logs for 'resource.type="gce_instance" AND protoPayload.methodName="compute.instances.setServiceAccount"'.
D.Filter on System Event logs with a query for 'resource.type="project" AND protoPayload.response.status.code=7'.
AnswerA

This filter catches IAM policy changes where members are not from the allowed domain.

Why this answer

It uses the Admin Activity audit log type, which captures IAM policy changes, and filters for the SetIamPolicy method on the cloudresourcemanager service. The condition NOT protoPayload.request.policy.bindings: member: "example.com" ensures alerts are triggered only when the owner role is granted to a member outside the organization's domain, matching the security requirement exactly.

Exam trap

In the Google PCA exam, the distinction between Admin Activity logs (for configuration changes like IAM) and Data Access logs (for data reads) is often tested. Candidates mistakenly choose Data Access logs because they associate IAM with 'access control' rather than administrative operations.

How to eliminate wrong answers

Option B is wrong because Data Access logs record read operations on resource data, not IAM policy modifications; SetIamPolicy is an administrative write operation and appears only in Admin Activity logs. Option C is wrong because it filters on compute.instances.setServiceAccount, which changes the service account attached to a VM instance, not the IAM policy granting the owner role to a user. Option D is wrong because System Event logs track Google Cloud system actions (e.g., maintenance events), not user-driven IAM policy changes, and the filter for response.status.code=7 (PERMISSION_DENIED) would only catch failed attempts, not successful grants.

677
Multi-Selectmedium

Your company is designing a new application on Google Cloud. The security team requires that all data at rest be encrypted with customer-managed encryption keys (CMEK) and that access to these keys be audited. You need to implement a solution that meets these requirements. (Choose two.)

Select 2 answers
A.Use Cloud KMS to create a key ring and crypto key, and grant the Cloud KMS CryptoKey Encrypter/Decrypter role to the service account used by the application.
B.Enable VPC Service Controls to restrict access to Cloud KMS resources.
C.Use customer-supplied encryption keys (CSEK) for all Google Cloud services that support them.
D.Enable Cloud Audit Logs for Cloud KMS and configure log sinks to export logs to a central logging project.
E.Configure default encryption at rest using Google-managed encryption keys for all services.
AnswersA, D

Cloud KMS allows you to create and manage customer-managed encryption keys (CMEK). By granting the appropriate IAM role to the service account, the application can use the key to encrypt and decrypt data. This meets the requirement for CMEK. Additionally, Cloud KMS integrates with Cloud Audit Logs to track key usage, satisfying the auditing requirement.

Why this answer

Using Cloud KMS to create and manage CMEK, and granting the application's service account the CryptoKey Encrypter/Decrypter role, ensures data is encrypted with customer-managed keys. Enabling Cloud Audit Logs for Cloud KMS and exporting them to a central project provides the required auditing of key access. Together, these meet the security requirements.

Exam trap

The trap here is confusing customer-supplied encryption keys (CSEK) with customer-managed encryption keys (CMEK); CSEK does not provide Cloud KMS auditing.

678
MCQhard

A company is designing a disaster recovery strategy for a critical application running on Compute Engine with a regional managed instance group (MIG) and an HTTP load balancer. They require an RTO of 10 minutes and RPO of 1 hour. The application state is stored in Cloud SQL for PostgreSQL. What is the most cost-effective approach?

A.Deploy an active-active configuration across two regions using Cloud Spanner
B.Configure a cold standby with a Cloud SQL backup and MIG template in another region
C.Take daily exports of Cloud SQL to Cloud Storage and restore in another region
D.Use Cloud SQL cross-region replica with a warm standby MIG in the secondary region
AnswerD

A cross-region replica provides asynchronous replication meeting the one-hour RPO, while the warm standby MIG in the secondary region can be promoted within the ten-minute RTO. This pairing is cheaper than a hot active-active deployment yet satisfies both recovery targets.

Why this answer

Cloud SQL for PostgreSQL supports cross-region replication with a default replication lag typically under 1 hour. For RPO of 1 hour, cross-region replica is sufficient. For RTO of 10 minutes, having a warm standby in another region with a MIG and load balancer configuration that can be promoted quickly meets the requirement.

Full active-active is more expensive; restoring from backups is slower; a cold standby may not meet RTO.

679
MCQmedium

A retail company runs a monolithic Java application on Compute Engine instances in a single managed instance group behind an external Application Load Balancer. During a flash sale, the application becomes unresponsive, and the operations team observes that the CPU utilization of all instances reaches 100%. The team wants to ensure that the application remains available during similar events. They need a solution that automatically adjusts capacity based on demand and minimizes manual intervention. Which approach should they take?

A.Increase the size of each Compute Engine instance to a larger machine type to handle the peak load.
B.Set up a Cloud Monitoring alert that notifies the operations team when CPU utilization exceeds 80%, so they can manually add instances.
C.Deploy the application to a Google Kubernetes Engine cluster with a Horizontal Pod Autoscaler based on CPU utilization.
D.Configure an autoscaler on the managed instance group to scale based on CPU utilization with a target of 60%.
AnswerD

An autoscaler on the managed instance group can automatically add or remove instances based on CPU utilization. Setting a target of 60% ensures that the group scales out before CPU saturation causes unresponsiveness. This is the standard, low-effort solution for handling variable load on Compute Engine and directly addresses the observed 100% CPU condition.

Why this answer

The managed instance group autoscaler with a CPU utilization target automatically adjusts the number of instances to maintain performance. It is the native, direct solution for scaling Compute Engine workloads based on demand, requiring no application changes. The other options either do not provide automatic scaling, require significant re-architecture, or rely on manual actions that cannot respond quickly enough.

Exam trap

The trap here is assuming that a notification alert or vertical scaling solves the scaling problem, when the requirement explicitly calls for automatic capacity adjustment with minimal manual intervention.

680
MCQhard

An e-commerce company runs its order-processing service on Cloud Run. During flash sales, the service experiences sudden traffic spikes, and the operations team observes that new instances take too long to start, causing elevated latency and some request failures. The service has a large container image and initializes database connection pools at startup. Which configuration change should the team make to reduce cold-start impact while controlling cost?

A.Enable Cloud CDN for the Cloud Run service and set a long cache TTL for order-processing responses.
B.Move the service to a GKE cluster with cluster autoscaling and a horizontal pod autoscaler.
C.Set the minimum number of instances to a value greater than zero and enable CPU always allocated for the service.
D.Increase the maximum number of instances and set the container concurrency to one.
AnswerC

Setting a minimum instance count keeps warm instances ready to serve traffic, eliminating cold starts for the baseline load. Enabling CPU always allocated ensures those instances retain CPU outside request processing, which is necessary for background initialization and connection pool maintenance. Together they reduce latency during spikes while allowing the maximum instance count to scale for peak demand.

Why this answer

Cold starts occur when Cloud Run must start a new instance, and the large image plus startup initialization makes this slow. Keeping a minimum number of instances warm removes startup latency for baseline traffic, and allocating CPU outside requests lets those instances maintain connection pools. The service can still scale to the maximum instance count during peaks, so cost stays proportional to actual demand beyond the warm baseline.

Exam trap

The trap here is trying to solve startup latency by increasing maximum instances or concurrency settings, which affect scaling capacity rather than the time a new instance needs to become ready.

681
MCQhard

A retail company runs a legacy order-processing system on a single Compute Engine VM with a local SSD. The system is business-critical and must be migrated to Google Cloud with minimal downtime and no data loss. The database is PostgreSQL, and the company wants to move to a managed service. The cutover window is only 30 minutes. Which migration approach should the architect recommend?

A.Take a cold backup of the PostgreSQL database, transfer it to Cloud Storage, and restore it to a new Cloud SQL instance during the cutover window.
B.Use Database Migration Service to perform a continuous replication from the source PostgreSQL to Cloud SQL for PostgreSQL, then promote during the cutover window.
C.Lift and shift the VM to a Compute Engine instance with a persistent disk, then convert it to a Cloud SQL instance later.
D.Create a Cloud SQL read replica from the on-premises PostgreSQL using native replication, then promote the replica during cutover.
AnswerB

Database Migration Service supports continuous replication from a self-managed PostgreSQL source to Cloud SQL, keeping the target in sync until cutover. This minimizes downtime because only the final promotion and connection switch are needed during the 30-minute window. It also avoids data loss by replicating ongoing changes, making it the best fit for the requirements.

Why this answer

Database Migration Service provides continuous replication from a self-managed PostgreSQL source to Cloud SQL, enabling a short cutover window with minimal downtime and no data loss. The other options either require significant downtime, are unsupported, or do not result in a managed service. For a business-critical system with a tight cutover window, continuous replication is the recommended approach.

Exam trap

The trap here is assuming that a cold backup and restore or a lift-and-shift can meet a 30-minute cutover with no data loss, when continuous replication is required for minimal downtime.

682
Multi-Selecthard

A financial services firm is deploying a three-tier application on Google Cloud. The web tier runs on managed instance groups behind an external HTTP(S) load balancer, the application tier runs on GKE, and the database tier runs on Cloud SQL. Security requires that the database tier accept connections only from the application tier and that no component be reachable from the public internet except the web tier. The architect must design the network and firewall configuration. (Choose two.)

Select 2 answers
A.Place the web tier and application tier in the same subnet and use a single firewall rule that allows all internal traffic between them to simplify management.
B.Attach an external IP to each GKE node and rely on Kubernetes NetworkPolicy to block inbound traffic from the internet.
C.Deploy the GKE cluster with private nodes and use a VPC-native cluster so pods receive IP addresses from a secondary range in the VPC.
D.Create a VPC firewall rule that allows ingress to the Cloud SQL instance's private IP on port 5432 only from the GKE pods' secondary IP range used for pods.
E.Configure the Cloud SQL instance with a public IP and add authorized networks for the GKE node external IPs so the application tier can connect.
AnswersC, D

A VPC-native cluster assigns pod IPs from a secondary range, making pods first-class VPC endpoints that firewall rules can target. Private nodes remove external IPs from nodes, so the application tier is not directly reachable from the internet. This supports the firewall rule scoped to the pod range and satisfies the requirement that only the web tier be public.

Why this answer

Private connectivity plus precise firewall scoping achieves the required segmentation. Giving Cloud SQL a private IP and allowing only the GKE pods' secondary range on the database port ensures the application tier alone reaches the database. Making the GKE cluster VPC-native with private nodes gives pods routable VPC addresses and removes node external IPs, so only the web tier behind the load balancer is internet-facing.

Together these satisfy both constraints.

Exam trap

The trap here is treating Kubernetes NetworkPolicy as equivalent to VPC firewall rules, when NetworkPolicy governs pod-to-pod traffic and cannot prevent internet ingress to nodes with external IPs.

683
MCQmedium

A financial services company is designing a hybrid cloud architecture. They have an on-premises data center and want to extend their VPC network to Google Cloud. They require a dedicated, high-bandwidth, low-latency connection with a SLA, and they need to encrypt traffic in transit. They also want to avoid using the public internet. Which connectivity option should they choose?

A.Cloud Interconnect - Partner Interconnect
B.Cloud VPN with HA VPN
C.Cloud Interconnect - Dedicated Interconnect
D.Cloud CDN with Cloud VPN
AnswerC

Dedicated Interconnect provides a direct physical connection between the on-premises network and Google Cloud, offering high bandwidth, low latency, and an SLA. It does not traverse the public internet, and traffic can be encrypted with application-level encryption or MACsec. This meets the requirements for a dedicated, high-bandwidth, low-latency connection with SLA and no public internet usage.

Why this answer

Dedicated Interconnect is the correct choice because it offers a direct, dedicated physical connection with high bandwidth, low latency, and an SLA, and it does not use the public internet. It can be encrypted with MACsec or application-level encryption, satisfying the security requirement. Partner Interconnect and HA VPN do not provide the same dedicated, high-performance characteristics.

Exam trap

The trap here is assuming that HA VPN or Partner Interconnect can match Dedicated Interconnect's dedicated bandwidth and low latency, when they either use the public internet or involve third-party networks with less predictable performance.

684
MCQeasy

What is the purpose of a Pod Disruption Budget (PDB) in GKE?

A.To automatically scale pods based on CPU usage
B.To distribute pods across different zones
C.To ensure a minimum number of pods are always available during voluntary disruptions
D.To prevent any pod from being terminated
AnswerC

A PDB defines the minimum available replicas that must remain during voluntary disruptions such as node drains or upgrades, so GKE blocks eviction requests that would breach that threshold. This directly satisfies the stem's requirement for guaranteed availability during planned, administrator-initiated disruptions.

Why this answer

A Pod Disruption Budget (PDB) in GKE (and Kubernetes generally) limits the number of pods of a replicated application that can be voluntarily disrupted at once, ensuring a minimum number (minAvailable) or maximum unavailable (maxUnavailable) is maintained. It applies to voluntary disruptions like node drains during upgrades, not involuntary ones like node crashes. This keeps the application highly available during maintenance operations.

Exam trap

PCA often tests the distinction between voluntary and involuntary disruptions — candidates who think a PDB prevents all pod termination (including crashes) pick the 'prevent any pod from being terminated' option.

How to eliminate wrong answers

Option A is wrong because automatic scaling based on CPU is the job of the Horizontal Pod Autoscaler (HPA), not a PDB — PDBs do not scale anything. Option B is wrong because distributing pods across zones is achieved via topology spread constraints or anti-affinity rules, not PDBs; a PDB only constrains how many pods can be taken down at once. Option D is wrong because a PDB does not prevent pod termination entirely — setting minAvailable equal to replicas can block voluntary evictions, but it does not stop involuntary disruptions (node failure, OOM kill) or direct pod deletion via kubectl delete.

685
MCQhard

A multinational corporation must comply with GDPR and requires that all customer data stored in BigQuery be encrypted using customer-managed encryption keys (CMEK) and that the keys are stored in a specific region. Which combination of steps should they take?

A.Enable default encryption at rest in BigQuery and use Organization Policies to restrict key location
B.Create a Cloud KMS key ring and crypto key in the desired region, then associate the BigQuery dataset with the CMEK key using DDL
C.Create a Cloud HSM key, then use Cloud DLP to automatically encrypt the data before loading into BigQuery
D.Use Cloud External Key Manager (EKM) to integrate with an on-premises key management system
AnswerB

Creating the Cloud KMS key ring and crypto key in the required region, then associating the BigQuery dataset with that CMEK key via DDL, satisfies both GDPR constraints: customer-managed keys and regional key residency. BigQuery then encrypts data with that key.

Why this answer

It directly fulfills the requirement: creating a Cloud KMS key ring and crypto key in the desired region, then associating the BigQuery dataset with that CMEK key using DDL (e.g., `ALTER SCHEMA mydataset SET OPTIONS(kms_key_name='...')`). This ensures that all data at rest in BigQuery is encrypted with a customer-managed key stored in a specific regional location, as mandated by GDPR for data residency and control.

Exam trap

A common pitfall is that candidates may confuse Cloud DLP or EKM as valid methods for BigQuery encryption at rest, when only CMEK via Cloud KMS with DDL association meets the specific requirement of regional key storage and customer control.

How to eliminate wrong answers

Option A is wrong because enabling default encryption at rest in BigQuery uses Google-managed keys, not customer-managed encryption keys (CMEK), and Organization Policies can restrict key location but do not enforce CMEK usage or provide customer-managed key control. Option C is wrong because Cloud HSM keys are a type of CMEK, but using Cloud DLP to encrypt data before loading into BigQuery is not the correct method; DLP is for data classification and de-identification, not for native BigQuery encryption at rest with CMEK, and it does not associate the key with the dataset. Option D is wrong because Cloud External Key Manager (EKM) integrates with an external key management system, but it does not store the keys in a specific Google Cloud region; the keys remain external, and BigQuery CMEK requires keys to be in Cloud KMS (including HSM) to enforce regional key location.

686
MCQmedium

An organization is migrating a MySQL database to Cloud SQL. They require automatic failover with zero data loss in the event of a zone outage. Which configuration should they use?

A.Cloud SQL with a cross-region replica.
B.Cloud SQL with automated backups and binary logging.
C.Cloud SQL with a read replica in a different zone.
D.Cloud SQL with high availability (HA) configuration.
AnswerD

High availability configuration provisions a standby instance in a second zone with synchronous replication to the primary. Automatic failover promotes the standby during a zone outage, and synchronous replication ensures zero data loss, meeting both stated requirements.

Why this answer

Cloud SQL's high availability (HA) configuration uses a synchronous write to a standby instance in a different zone within the same region. This ensures that every transaction committed on the primary is also committed on the standby before acknowledging the client, guaranteeing zero data loss during a zone outage. Automatic failover to the standby occurs with no manual intervention, meeting both the automatic failover and zero data loss requirements.

Exam trap

The trap here is that candidates often confuse a read replica (which uses asynchronous replication and requires manual promotion) with an HA standby (which uses synchronous replication and automatic failover), leading them to incorrectly select Option C.

How to eliminate wrong answers

Option A is wrong because a cross-region replica uses asynchronous replication, which can result in data loss of up to several seconds of transactions during a failover, failing the zero data loss requirement. Option B is wrong because automated backups and binary logging provide point-in-time recovery from a backup, but they do not provide automatic failover; recovery requires manual intervention and can lose transactions committed after the last backup. Option C is wrong because a read replica in a different zone is designed for read scaling, not for automatic failover; promoting a read replica to primary is a manual process and the replica uses asynchronous replication, risking data loss.

687
MCQmedium

A healthcare company stores patient records in Cloud Storage buckets across several projects. Compliance auditors require that no object can ever be made publicly readable, even by a project Owner, and that any attempt to do so must be blocked centrally. The security team must enforce this without breaking existing application access. What should they do?

A.Create an organization policy with the `storage.publicAccessPrevention` constraint set to enforced at the organization node.
B.Grant the `roles/storage.admin` role only to a dedicated security group and remove it from all project Owners.
C.Enable uniform bucket-level access on every bucket and rely on IAM conditions to deny public members.
D.Configure VPC Service Controls perimeters around each project to restrict access to Cloud Storage.
AnswerA

The `storage.publicAccessPrevention` organization policy constraint, enforced at the organization node, blocks any attempt to grant `allUsers` or `allAuthenticatedUsers` access to Cloud Storage buckets and objects, including by project Owners. Because it is inherited downward, it protects every project without altering existing IAM bindings for legitimate service accounts and users, so application access continues to work.

Why this answer

The `storage.publicAccessPrevention` organization policy constraint is the only mechanism here that centrally and preventively blocks public access grants at the organization level, regardless of a principal's project-level permissions. Because organization policies are inherited, enforcing it once at the org node covers all current and future projects while leaving legitimate IAM bindings untouched.

Exam trap

The trap here is assuming that removing broad IAM roles or enabling uniform bucket-level access prevents public exposure, when only the public access prevention organization policy constraint actively blocks public grants.

688
MCQhard

A company is designing a VPC architecture for a multi-tenant SaaS platform. Each tenant has isolated workloads that must not communicate with each other. They also need centralized network security and logging. Which VPC design meets these requirements?

A.Dedicated Cloud VPN connections per tenant
B.Use a Shared VPC with separate subnets for each tenant and firewall rules to enforce isolation
C.Single VPC with network tags and IAP tunnels
D.Peered VPCs for each tenant with Cloud NAT
AnswerB

A Shared VPC centralises firewall rules and logging in the host project while separate subnets per tenant, combined with firewall rules, prevent cross-tenant traffic. This satisfies both the isolation requirement and the demand for centralised network security and logging across the multi-tenant platform.

Why this answer

Option B is correct because a Shared VPC in Google Cloud lets a host project centrally own and manage the VPC network, subnets, firewall rules, and logging while each tenant's service project gets its own subnet; firewall rules scoped to those subnets or service accounts enforce isolation so tenant workloads cannot communicate with each other. This design also satisfies the centralized network security and logging requirement, since the host project retains control of firewall policies and VPC Flow Logs across all tenant subnets. Option A does not provide tenant isolation or centralized logging, as Cloud VPN only establishes encrypted tunnels to on-premises or remote networks.

Option C is unsuitable because a single VPC with network tags and IAP tunnels does not create hard tenant boundaries and IAP is for identity-based TCP access, not tenant segmentation. Option D is wrong because VPC peering connects networks rather than isolating tenants, and Cloud NAT only provides outbound internet access, not centralized security or logging.

Exam trap

Candidates may incorrectly think that VPC peering (Option D) provides the same isolation and centralization as Shared VPC, but peering still requires management of multiple VPCs and does not offer a single point for logging and security policies.

689
MCQeasy

A company runs a critical application on Compute Engine instances in a managed instance group (MIG) with autoscaling. Users report intermittent 503 errors during traffic spikes. Which action should the company take to improve reliability?

A.Change the load balancer from regional to global
B.Configure a health check with a sufficient initial delay (grace period) in the MIG
C.Increase the autoscaling cool-down period from 60s to 120s
D.Increase the maximum number of instances in the MIG
AnswerB

During autoscaling spikes, new instances need time to boot before serving. A health check with a sufficient initial delay prevents the MIG from marking them unhealthy and removing them prematurely, eliminating the 503 errors caused by premature traffic routing.

Why this answer

Intermittent 503 errors during traffic spikes often indicate that new VM instances are being started but are not yet ready to serve traffic, causing the load balancer to forward requests to them prematurely. Configuring a health check with a sufficient initial delay (grace period) in the MIG ensures that newly created instances are given time to fully initialize and pass health checks before they receive traffic, preventing 503 errors. This directly addresses the root cause by allowing the application to become healthy before being added to the load balancer's backend.

Exam trap

Google Cloud often tests the misconception that scaling-related errors are always solved by increasing capacity or adjusting scaling parameters, when in fact the root cause is often a misconfigured health check or insufficient initialization time for new instances.

How to eliminate wrong answers

Option A is wrong because changing the load balancer from regional to global does not address the timing issue of new instances being marked healthy before they are ready; global load balancers improve cross-region routing but do not affect instance readiness. Option C is wrong because increasing the autoscaling cool-down period from 60s to 120s only delays the scaling decision after a scale-out event, but does not prevent the load balancer from sending traffic to instances that are still initializing; the cool-down period controls how often autoscaler evaluates metrics, not instance readiness. Option D is wrong because increasing the maximum number of instances in the MIG allows more capacity but does not fix the problem of instances being added to the backend pool before they are ready; it may even exacerbate the issue by creating more unhealthy instances.

690
Multi-Selecteasy

A company is building a web application on GKE. They want to automatically scale the number of pods based on HTTP request rate. Which TWO resources should they configure?

Select 2 answers
A.Cluster Autoscaler (Node Auto-scaling)
B.Custom Metrics API (e.g., Stackdriver Adapter)
C.GKE Ingress
D.Horizontal Pod Autoscaler (HPA)
E.Vertical Pod Autoscaler (VPA)
AnswersB, D

The Custom Metrics API exposes external metrics such as HTTP request rate to the HPA, enabling scaling on application-level signals rather than CPU or memory, which satisfies the requirement to scale pods by request rate.

Why this answer

Option D, the Horizontal Pod Autoscaler (HPA), is correct because it is the Kubernetes controller that automatically scales the number of pod replicas in a Deployment, ReplicaSet, or StatefulSet based on observed metrics, which is exactly what is needed to scale pods by HTTP request rate. Option B, the Custom Metrics API (e.g., Stackdriver Adapter), is correct because HTTP request rate is not a built-in resource metric like CPU or memory; the HPA must retrieve such application-level metrics through the Custom Metrics API (implemented by an adapter such as the Stackdriver/Cloud Monitoring adapter) to drive scaling decisions. Option A, Cluster Autoscaler, is not correct because it scales the number of nodes in the cluster, not the number of pods, and node scaling is a separate concern from request-rate-based pod scaling.

Option C, GKE Ingress, is not correct because Ingress manages external HTTP(S) routing and load balancing to Services, not pod replica counts. Option E, Vertical Pod Autoscaler, is not correct because VPA adjusts CPU and memory requests/limits of existing pods rather than scaling the number of pods based on HTTP request rate.

691
MCQeasy

Your organization requires that all production changes to Google Cloud resources be auditable and that you can identify who made a change and when. You need to configure logging to meet this requirement. What should you do?

A.Enable Admin Activity audit logs, which are enabled by default, and export them to a centralized logging project or Cloud Storage bucket with retention policies.
B.Configure VPC Flow Logs to capture network traffic and analyze it for unauthorized changes.
C.Enable Data Access audit logs for all services and export them to Cloud Storage for long-term retention.
D.Use Cloud Monitoring to create alerting policies for resource changes and send notifications to a team email.
AnswerA

Admin Activity audit logs record administrative changes to resources and are enabled by default. They include information about who made the change, what was changed, and when. Exporting them to a centralized location ensures long-term retention and auditability. This meets the requirement to identify who made a change and when.

Why this answer

Admin Activity audit logs are enabled by default and record administrative changes, including the identity of the caller and the timestamp. Exporting these logs to a centralized project or Cloud Storage with retention policies ensures they are preserved for auditing. This satisfies the requirement to audit production changes.

Exam trap

The trap here is confusing Data Access audit logs with Admin Activity audit logs; the former are for data reads/writes and are not enabled by default.

692
MCQeasy

A company is using Cloud Storage for backups and wants to minimize costs. The backups are accessed infrequently and can tolerate retrieval delays. Which storage class is most appropriate?

A.Standard
B.Archive
C.Coldline
D.Nearline
AnswerB

Archive storage has the lowest per-gigabyte price of any Cloud Storage class and is designed for data accessed less than once a year. It matches the infrequent access and tolerance for retrieval delays stated in the stem, minimising backup storage cost where latency is acceptable.

Why this answer

Archive storage class is the most cost-effective option for backups that are accessed infrequently and can tolerate retrieval delays. It offers the lowest storage cost among Google Cloud Storage classes, with a default retrieval time of minutes to hours, making it ideal for long-term backup data that does not require immediate access.

Exam trap

Google Cloud often tests the misconception that 'Coldline' is the cheapest storage class, but Archive is actually the lowest-cost option for data that can tolerate retrieval delays of minutes to hours, not just for data that is rarely accessed.

How to eliminate wrong answers

Option A is wrong because Standard storage class is designed for frequently accessed data with no retrieval delay, and its higher cost makes it unsuitable for infrequently accessed backups. Option C is wrong because Coldline storage, while cheaper than Standard, is still more expensive than Archive and has a 90-day minimum storage duration, which may not be optimal for long-term backups with very low access frequency. Option D is wrong because Nearline storage is intended for data accessed less than once a month, but it has a 30-day minimum storage duration and higher cost compared to Archive, making it less cost-efficient for backups that can tolerate retrieval delays.

693
MCQmedium

An e-commerce company exposes a public API through an external HTTP(S) load balancer on Google Cloud. The security team wants to block traffic from known malicious IP ranges and apply rate limiting per client IP, while keeping legitimate customers unaffected. They want the least operational overhead and no changes to backend applications. What should they do?

A.Deploy Cloud Armor security policies with IP deny rules and a rate-based ban rule, and attach the policy to the load balancer's backend service.
B.Configure Cloud CDN with signed URLs and require all API clients to authenticate before reaching the backend.
C.Use Identity-Aware Proxy to require Google account authentication for all API requests.
D.Create a VPC firewall rule that denies traffic from the malicious IP ranges to the load balancer's backend instances.
AnswerA

Cloud Armor security policies attach to the backend service of an external HTTP(S) load balancer and can combine IP denylists with rate-based ban rules that throttle abusive clients per source IP. This requires no backend changes, is managed centrally, and blocks malicious ranges while allowing legitimate traffic, matching the least-overhead requirement.

Why this answer

Cloud Armor is the native edge security service for external HTTP(S) load balancers, attaching at the backend service where it can evaluate client IP rules and rate-based bans before traffic reaches backends. This satisfies both blocking malicious ranges and per-client-IP throttling without touching application code or managing instance-level firewalls.

Exam trap

The trap here is reaching for VPC firewall rules, which operate on backend instances and cannot see the original client IP behind an HTTP(S) load balancer, instead of edge-level Cloud Armor policies.

694
MCQeasy

A company is migrating sensitive customer data to Google Cloud. They need to ensure data is encrypted at rest and in transit. Which Google Cloud service provides a centralized way to manage encryption keys used by Google Cloud services?

A.Cloud HSM
B.Cloud External Key Manager (Cloud EKM)
C.Cloud Key Management Service (Cloud KMS)
D.Secret Manager
AnswerC

Cloud KMS centralises creation, rotation and access control of customer-managed encryption keys, and integrates with Google Cloud services for envelope encryption at rest and in transit. This satisfies the requirement for one centralised key management service.

Why this answer

Cloud KMS is the correct choice because it provides a centralized, managed service for creating, rotating, and destroying encryption keys used by Google Cloud services. It integrates directly with services like Cloud Storage, BigQuery, and Compute Engine to enforce encryption at rest, and it supports customer-managed encryption keys (CMEK) for granular control. For data in transit, Cloud KMS can be used to manage keys for TLS or application-level encryption, though Google Cloud automatically encrypts all network traffic by default.

Exam trap

Google Cloud often tests the distinction between Cloud KMS as the centralized key management service and Cloud HSM as a hardware-backed option within Cloud KMS, leading candidates to choose Cloud HSM when the question asks for the centralized service.

How to eliminate wrong answers

Option A is wrong because Cloud HSM is a hardware security module service that provides dedicated, FIPS 140-2 Level 3 validated hardware for key operations, but it is not the centralized key management service; it is an option within Cloud KMS for higher security requirements. Option B is wrong because Cloud External Key Manager (Cloud EKM) allows you to manage keys outside of Google Cloud using an external key management partner, but it is not a centralized Google Cloud service for managing encryption keys used by Google Cloud services; it is for keys stored externally. Option D is wrong because Secret Manager is designed to store and manage secrets such as API keys, passwords, and certificates, not encryption keys for encrypting data at rest or in transit across Google Cloud services.

695
Multi-Selectmedium

Which TWO are required to allow on-premises hosts to access Google APIs using internal IP addresses (Private Google Access)? (Choose 2)

Select 2 answers
A.A Cloud Interconnect or Cloud VPN connection between on-premises and VPC
B.A Cloud Router instance configured in the on-premises network
C.VPC Service Controls enabled
D.Private Google Access enabled on the subnet that the on-premises traffic will use
E.A private DNS zone for googleapis.com
AnswersA, D

On-premises hosts need a private path into the VPC. Cloud Interconnect or Cloud VPN provides that hybrid connectivity, carrying traffic to the subnet where Private Google Access is enabled, so Google APIs are reachable using internal addresses.

Why this answer

Option A is correct because Private Google Access for on-premises hosts requires a hybrid connectivity path — either Cloud Interconnect or Cloud VPN — to carry traffic from the on-premises network into the VPC, where it can then reach Google APIs via internal IP addresses. Option D is correct because Private Google Access must be enabled on the specific subnet that the on-premises traffic will use; this setting allows resources in that subnet to reach Google APIs using internal IP addresses rather than external ones. Option B is incorrect because Cloud Router is a Google Cloud resource used for dynamic routing (e.g., BGP) within the VPC, not something configured in the on-premises network.

Option C is incorrect because VPC Service Controls is a security perimeter feature for mitigating data exfiltration, not a requirement for Private Google Access. Option E is incorrect because a private DNS zone for googleapis.com is not required; Google provides the necessary DNS resolution for private.googleapis.com and restricted.googleapis.com automatically when Private Google Access is configured.

Exam trap

Google Cloud often tests the misconception that a Cloud Router or DNS zone is required for Private Google Access, but the core requirement is simply the private network connectivity (Cloud Interconnect or Cloud VPN) and the subnet-level feature enablement.

696
MCQeasy

A company wants to store backup data that is accessed rarely but must be available for retrieval within minutes. Which Cloud Storage class is appropriate?

A.Standard
B.Nearline
C.Coldline
D.Archive
AnswerB

Nearline suits data accessed less than once a month but requiring retrieval within seconds, offering lower storage cost than Standard while meeting the minutes-level availability constraint; Coldline and Archive impose longer minimum durations and higher retrieval latency.

Why this answer

Nearline storage is designed for data accessed less than once a month but requires retrieval within minutes, making it ideal for backup data that needs quick availability. It offers lower cost than Standard storage while still supporting sub-minute retrieval times, aligning with the scenario's access and latency requirements.

Exam trap

Google Cloud often tests the distinction between 'retrieval within minutes' and 'retrieval within hours' to confuse candidates into selecting Coldline or Archive, assuming 'rarely accessed' automatically means the cheapest option, but the key is the specific retrieval time requirement.

How to eliminate wrong answers

Option A is wrong because Standard storage is for frequently accessed data (e.g., multiple times per month) and costs more, making it unsuitable for rarely accessed backups. Option C is wrong because Coldline storage is for data accessed less than once a quarter, with retrieval times that can be minutes to hours, but it is optimized for even colder data than Nearline, and its cost structure (including retrieval fees) is less appropriate for backups needing consistent minute-level access. Option D is wrong because Archive storage is for long-term retention with retrieval times typically in hours (e.g., 1-12 hours), not minutes, and is intended for data that is accessed extremely rarely, such as regulatory archives.

697
MCQeasy

A company wants to run a legacy application on Google Cloud that requires a specific operating system version and kernel tuning. The application is not containerised and cannot be easily modified. Which compute service should they use?

A.Cloud Run
B.App Engine Flexible Environment
C.Google Kubernetes Engine (GKE)
D.Compute Engine
AnswerD

Compute Engine provides full control over the guest OS and kernel, satisfying the legacy application's requirement for a specific OS version and kernel tuning. Unlike container-based services, it runs unmodified non-containerised workloads directly on persistent VMs, so no application changes are needed.

Why this answer

Compute Engine provides full control over the virtual machine, including the OS and kernel parameters, making it ideal for legacy applications that require custom configurations.

698
MCQmedium

Refer to the exhibit. An engineer deploys this Terraform configuration. After deployment, they can SSH into the VM using its public IP. However, they want to restrict SSH access to only a specific IP range (203.0.113.0/24). What change is required?

A.Change the 'source_ranges' in the firewall rule to ['203.0.113.0/24']. The instance already has the required tag.
B.Modify the instance to use a network tag 'restricted-ssh' and update the firewall rule target_tags accordingly.
C.Add a new firewall rule with higher priority allowing SSH from 203.0.113.0/24, and keep the existing rule but change its priority to 100.
D.Update the 'source_ranges' in the firewall rule to ['203.0.113.0/24'] and remove the 'ssh-allowed' tag from the instance.
AnswerA

Editing the firewall rule's `source_ranges` to `['203.0.113.0/24']` narrows the permitted source addresses at the VPC firewall layer, satisfying the requirement to restrict SSH to that range. Because the instance already carries the matching target tag, the rule continues to apply, so no other configuration change is needed.

Why this answer

The firewall rule already targets the instance via the 'ssh-allowed' tag, so the only change needed is to narrow the source_ranges from the current open range (e.g., 0.0.0.0/0) to ['203.0.113.0/24']. Since the instance already carries the required tag, no tag modification is necessary — just update the source range in the existing rule. This is the minimal, correct change to restrict SSH to the specified CIDR.

Exam trap

PCA often tests whether candidates over-engineer the fix by adding tags or new rules when the existing rule already targets the instance correctly and only the source range needs tightening.

How to eliminate wrong answers

Option B is wrong because it proposes changing the instance's network tag to 'restricted-ssh' and updating target_tags, which is unnecessary since the existing tag already matches the firewall rule — this adds complexity without solving the source-range problem. Option C is wrong because adding a new higher-priority allow rule for 203.0.113.0/24 while keeping the existing open rule (even at priority 100) still permits SSH from anywhere via the original rule, defeating the restriction. Option D is wrong because removing the 'ssh-allowed' tag from the instance would cause the firewall rule to no longer apply to the instance at all, potentially blocking all SSH rather than restricting it to the desired range.

699
MCQhard

A retail company runs a stateful batch application on a managed instance group. The application writes intermediate results to the boot disk of each VM and takes several hours to complete. The operations team wants rolling updates that replace instances with a new image, but must guarantee that no in-flight job is interrupted. Which configuration should you recommend?

A.Set the update type to proactive, configure a maximum surge, and rely on the managed instance group's health checks to drain connections.
B.Convert the workload to a regional managed instance group and enable autoscaling based on CPU utilization during the rollout.
C.Set the update type to opportunistic and rely on the instance template's automatic restart policy.
D.Use stateful managed instance group configuration with a replacement policy, and set the update type to opportunistic so instances are only replaced when you deliberately delete them.
AnswerD

Stateful MIGs preserve per-instance names, disks, and metadata, and with an opportunistic update the group does not automatically replace instances during a rollout. You control replacement timing by deleting or recreating specific instances after their jobs complete, which guarantees no in-flight batch work is interrupted while still allowing eventual image updates.

Why this answer

A stateful managed instance group combined with an opportunistic update gives the operations team explicit control over when each instance is replaced. Because replacements occur only when an instance is deliberately deleted or recreated, the team can wait for each batch job to finish, update the image on the template, and then replace instances one at a time without interrupting work.

Exam trap

The trap here is thinking that proactive rolling updates plus health checks will gracefully wait for long-running work, when health checks only govern traffic serving and not job completion.

700
MCQmedium

An e-commerce company uses Cloud SQL for MySQL for their transactional database. During a recent load test, the database experienced high latency under write-heavy workloads. The team needs to improve write performance without changing the application. Which action is most effective?

A.Enable binary logging to improve write performance
B.Increase the machine type of the primary instance
C.Migrate to Cloud Spanner
D.Add multiple read replicas
AnswerB

Increasing the primary instance's machine type adds vCPUs and memory, raising write throughput and InnoDB buffer pool capacity so dirty pages flush less often. This directly relieves the write-heavy latency bottleneck while requiring no application changes, satisfying the stem's constraint of improving write performance transparently.

Why this answer

Cloud SQL for MySQL supports read replicas for read scalability, but for write-heavy workloads you need a larger machine type (scale up) or use memory optimized. Adding read replicas does not help writes. Enabling binary logging adds overhead.

Vertically scaling (increasing vCPUs and RAM) directly improves write throughput. Using Cloud Spanner would require application changes.

701
Multi-Selecteasy

A DevOps team is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that the pods can securely access Google Cloud APIs (e.g., Cloud Storage) without managing service account keys. Which TWO steps should they take? (Choose two.)

Select 2 answers
A.Create a dedicated GCP service account with necessary roles and bind it to Kubernetes service accounts via Workload Identity.
B.Use the Compute Engine default service account on each node.
C.Use a secrets management solution like HashiCorp Vault to store service account keys and retrieve them at runtime.
D.Enable Workload Identity on the GKE cluster.
E.Store service account keys in a Kubernetes Secret and mount them into pods.
AnswersA, D

Workload Identity federates Kubernetes service accounts to a Google Cloud service account, so pods obtain short-lived credentials from the metadata server. Creating the dedicated service account with the required roles and binding it to the Kubernetes service account removes the need for exported, long-lived keys.

Why this answer

Option A is correct because Workload Identity requires creating a dedicated Google Cloud service account with the necessary IAM roles and binding it to a Kubernetes service account (via an IAM policy binding with roles/iam.workloadIdentityUser), which lets the pod impersonate the GCP service account without keys. Option D is correct because Workload Identity must first be enabled on the GKE cluster (e.g., with gcloud container clusters update --workload-pool=PROJECT_ID.svc.id.goog), which sets up the cluster's identity pool and OIDC issuer so Kubernetes service accounts can federate to Google Cloud IAM. Option B is wrong because using the Compute Engine default service account on nodes grants broad, shared credentials to every pod and does not provide per-pod identity or keyless access.

Option C is wrong because storing service account keys in Vault still involves managing long-lived keys, which is exactly what the team wants to avoid. Option E is wrong because mounting service account keys from a Kubernetes Secret also relies on static, manually managed credentials rather than keyless Workload Identity.

Exam trap

Google Cloud often tests the misconception that storing keys in Kubernetes Secrets or using node-level default service accounts is acceptable for secure API access, when in fact Workload Identity is the recommended, keyless approach for GKE.

702
MCQmedium

A security admin wants to audit all 'create' and 'delete' operations on Compute Engine instances in a project for the last 90 days. Which type of audit log should they query?

A.Data Access audit logs
B.Admin Activity audit logs
C.System Event audit logs
D.Policy Denied audit logs
AnswerB

Admin Activity audit logs capture permanent metadata writes such as instance creation and deletion, and are always enabled with 400-day retention, satisfying the 90-day requirement. Data Access logs record reads and are disabled by default, so they cannot reliably supply this Compute Engine administrative history.

Why this answer

Admin Activity audit logs record all write operations (create, update, delete) on project resources, including Compute Engine instances, and are always enabled with a 400-day retention. Querying Admin Activity logs for the last 90 days will show all create and delete operations on instances. Data Access logs, by contrast, record read operations and are disabled by default.

Exam trap

The trap is conflating Admin Activity with Data Access logs; candidates may think Data Access logs capture all operations, but they only capture reads and are off by default, while Admin Activity logs capture writes and are always on.

How to eliminate wrong answers

Option A is wrong because Data Access audit logs record read operations (e.g., get, list) and are not enabled by default; they would not capture create/delete operations. Option C is wrong because System Event audit logs record Google-initiated system events like live migration or maintenance, not user-initiated create/delete operations. Option D is wrong because Policy Denied audit logs record when a request is denied by a security policy (e.g., VPC Service Controls), which is not the same as auditing successful create/delete operations.

703
MCQmedium

Refer to the exhibit. An engineer deployed this Terraform configuration and can SSH to the instance using the external IP. However, they notice that the instance has a public IP address even though they intended to have no public IP. What change should be made to the configuration to ensure the instance does not get a public IP?

A.Change the metadata key enable-oslogin to FALSE.
B.Remove the entire access_config block from the network_interface configuration.
C.Set access_config = [] instead of leaving it empty.
D.Set the network to a custom VPC that does not have external internet access.
AnswerB

In Google Compute Engine, a public IP is assigned only when the network_interface contains an access_config block. Removing it entirely leaves the interface with no external address, satisfying the requirement that the instance have no public IP.

Why this answer

The `access_config` block in a Terraform `google_compute_instance` resource is what assigns a public (external) IP address to the instance's network interface. By removing the entire `access_config` block, the instance will only receive a private IP address, fulfilling the requirement of no public IP. Leaving the block empty (as in option C) still creates an ephemeral external IP by default, so it does not solve the problem.

Exam trap

A common trap in Google PCA is that an empty `access_config` block in Terraform for GCP still provisions a public IP, tricking candidates into thinking it means 'no public IP' when the correct fix is to remove the block entirely.

How to eliminate wrong answers

Option A is wrong because `enable-oslogin` controls OS Login authentication, not public IP assignment; disabling it has no effect on whether an external IP is provisioned. Option C is wrong because setting `access_config = []` is syntactically equivalent to an empty block and still triggers the creation of an ephemeral external IP; the block must be entirely absent to avoid a public IP. Option D is wrong because using a custom VPC without external internet access does not prevent the instance from being assigned a public IP; the `access_config` block directly controls that assignment, regardless of the VPC's routing or internet access capabilities.

704
MCQhard

A company runs a large-scale data processing pipeline using Dataflow with streaming data from Pub/Sub. They notice increasing costs due to high data shuffle operations. They want to optimize the pipeline performance and cost. Which approach should they take?

A.Use a larger machine type for workers.
B.Increase the number of workers to reduce shuffle.
C.Optimize the pipeline by partitioning data and using Combine transforms.
D.Switch to batch mode overnight.
AnswerC

Partitioning spreads keys across workers so shuffle no longer funnels everything through single keys, and Combine transforms perform partial aggregation per key before the shuffle. This reduces the volume of data moved between workers, directly addressing the high shuffle cost that is inflating the streaming pipeline's bill.

Why this answer

Optimizing the pipeline by partitioning data and using Combine transforms reduces the amount of data shuffled across workers. Partitioning groups related data together, and Combine performs associative reductions per key, minimizing the data that needs to be moved. This directly addresses high shuffle costs and improves performance.

Exam trap

PCA often tests the misconception that adding more workers or larger machines solves performance issues: candidates may choose to increase workers, but that can worsen shuffle; the correct approach is to optimize the pipeline logic to reduce shuffle.

How to eliminate wrong answers

Option A is wrong because using a larger machine type may provide more resources but does not reduce shuffle operations; it can increase costs without addressing the root cause. Option B is wrong because increasing the number of workers can actually increase shuffle overhead due to more data movement across the network, and it doesn't optimize the pipeline logic. Option D is wrong because switching to batch mode overnight changes the processing paradigm and may not be feasible for streaming data; it doesn't optimize shuffle within the streaming pipeline.

705
MCQhard

A security team wants to enforce that only container images signed by their internal CI/CD pipeline can run on GKE clusters. They also need to ensure that unsigned images are rejected at admission time. Which combination of services and configurations should they use?

A.GKE PodSecurityPolicy with allowed registries
B.Binary Authorization with Cloud KMS for signing
C.Cloud Build with Container Analysis
D.Artifact Registry vulnerability scanning and IAM roles
AnswerB

Binary Authorization enforces admission-time policy on GKE, verifying image signatures against attestors before pods deploy. Cloud KMS holds the asymmetric signing key the CI/CD pipeline uses to sign images, so only pipeline-signed images pass and unsigned ones are rejected at admission.

Why this answer

Binary Authorization is the GKE feature that enforces admission-time policies requiring container images to be signed by trusted authorities. Cloud KMS provides the signing keys used by the CI/CD pipeline to create attestations. Together they ensure only images signed by the internal pipeline are admitted to the cluster.

Exam trap

PCA often tests the difference between vulnerability scanning (Container Analysis/Artifact Registry) and admission-time signature enforcement (Binary Authorization) — candidates pick scanning options thinking they enforce signing.

How to eliminate wrong answers

Option A (GKE PodSecurityPolicy with allowed registries) is wrong because PSP controls pod security context and can restrict registries, but it does not verify image signatures and is deprecated in favor of Pod Security Admission. Option C (Cloud Build with Container Analysis) is wrong because Cloud Build builds images and Container Analysis scans for vulnerabilities and metadata; neither enforces signature verification at admission. Option D (Artifact Registry vulnerability scanning and IAM roles) is wrong because vulnerability scanning and IAM control access to the registry, not admission of signed images to the cluster.

706
MCQhard

A company is using Cloud Storage to store sensitive data. They need to enforce that objects are deleted exactly 30 days after creation. Which object lifecycle rule should they configure?

A.AbortIncompleteMultipartUpload after 30 days.
B.Delete action with condition daysFromNonCurrentTime: 30.
C.Delete action with condition age: 30.
D.SetStorageClass to Nearline after 30 days.
AnswerC

An age condition measures time since each object's creation, and the delete action removes the object once that threshold is reached. Setting age: 30 therefore deletes every object exactly 30 days after creation, matching the stated retention requirement without relying on other conditions.

Why this answer

The 'Delete action with condition age: 30' directly instructs Cloud Storage to remove objects 30 days after their creation time. The 'age' condition is measured from the object's creation timestamp, which aligns perfectly with the requirement to delete objects exactly 30 days after creation.

Exam trap

Google Cloud often tests the distinction between 'age' (based on creation time) and 'daysFromNonCurrentTime' (based on versioning status), leading candidates to confuse deletion of current objects with cleanup of older versions.

How to eliminate wrong answers

Option A is wrong because AbortIncompleteMultipartUpload is used to cancel incomplete multipart uploads after a specified number of days, not to delete completed objects. Option B is wrong because 'daysFromNonCurrentTime' applies to non-current object versions in a versioned bucket, not to the creation time of the current object. Option D is wrong because SetStorageClass to Nearline changes the storage class to a colder tier but does not delete the object; it only modifies the cost and retrieval latency.

707
Multi-Selectmedium

An organization wants to monitor network traffic between VMs in a VPC for troubleshooting. Which TWO services can provide this?

Select 2 answers
A.Cloud Audit Logs
B.Packet Mirroring (Network Intelligence Center)
C.VPC Flow Logs
D.Cloud Monitoring
E.Cloud Logging
AnswersB, C

Packet Mirroring clones selected VM instance traffic, including full packet payloads, and forwards it to a collector for deep inspection. This satisfies the troubleshooting requirement because it exposes actual packet contents between VMs, unlike metadata-only flow records.

Why this answer

Packet Mirroring (Network Intelligence Center) (B) is correct because it captures full packet payloads from specified VM instances in a VPC and forwards them to a collector instance for deep troubleshooting and analysis of traffic between VMs. VPC Flow Logs (C) is correct because it records IP flow information (5-tuple, bytes, packets, timestamps) for traffic to and from VM instances, subnets, and VPCs, providing visibility into network traffic patterns for troubleshooting. Cloud Audit Logs (A) only records administrative and data-access API activity, not network traffic between VMs.

Cloud Monitoring (D) collects metrics and uptime checks but does not capture network flow or packet-level traffic data. Cloud Logging (E) stores and queries log entries but is not itself a network traffic capture service.

Exam trap

Google Cloud often tests the distinction between services that capture raw packet data (Packet Mirroring) versus those that log only metadata or metrics (VPC Flow Logs). Candidates may incorrectly think only one is correct, but both can be used for troubleshooting network traffic between VMs, depending on the depth of information needed.

708
MCQmedium

Your company uses Cloud VPN (HA VPN) to connect to Google Cloud. You need to achieve a 99.99% SLA for the VPN connection. What configuration is required?

A.One VPN gateway with four tunnels to different on-premises devices
B.Two VPN gateways, each with two tunnels, totaling four tunnels
C.Two VPN gateways, each with one tunnel, using two different edge availability domains
D.One VPN gateway with two tunnels to the same on-premises device
AnswerB

Four tunnels across two HA VPN gateways satisfy the 99.99% SLA, since Google requires at least two tunnels on distinct gateways to guarantee that tier. Each gateway provides redundancy, so a single gateway or tunnel failure does not drop the connection, meeting the stem's availability constraint.

Why this answer

To achieve the 99.99% SLA for HA VPN, Google Cloud requires two VPN gateways, each with two tunnels, for a total of four tunnels. This configuration provides redundancy across both gateways and tunnels, satisfying the availability requirement defined by Google's HA VPN SLA. A single gateway, even with multiple tunnels, cannot meet the 99.99% SLA.

Exam trap

The trap is assuming that more tunnels on a single gateway equals higher availability — candidates must remember that the 99.99% SLA specifically requires two gateways with two tunnels each, not just four tunnels anywhere.

How to eliminate wrong answers

Option A is wrong because a single VPN gateway with four tunnels does not provide gateway-level redundancy — if the gateway fails, all tunnels fail, capping the SLA at 99.9%. Option C is wrong because two gateways with only one tunnel each provides gateway redundancy but not tunnel redundancy within each gateway; the 99.99% SLA requires two tunnels per gateway. Option D is wrong because a single gateway with two tunnels to the same on-premises device offers no gateway redundancy and no peer redundancy, yielding at most 99.9%.

709
MCQmedium

A company needs to protect an HTTPS load-balanced web application from OWASP Top 10 attacks, including SQL injection and cross-site scripting. Which GCP service should they enable?

A.Cloud NAT
B.Cloud CDN
C.Identity-Aware Proxy
D.Cloud Armor
AnswerD

Cloud Armor provides web application firewall filtering at the load balancer, inspecting HTTP traffic to block SQL injection and cross-site scripting. This satisfies the requirement to defend the HTTPS application against OWASP Top 10 attacks.

Why this answer

Cloud Armor is Google Cloud's web application firewall (WAF) and DDoS protection service that provides protection against OWASP Top 10 attacks, including SQL injection and cross-site scripting. It integrates with external HTTP(S) load balancers to filter malicious traffic at the edge. Enabling Cloud Armor security policies allows you to block or allow requests based on preconfigured WAF rules.

Exam trap

The trap is confusing Cloud Armor with other GCP services like Cloud CDN or IAP, which serve different purposes (content delivery and access control, respectively).

How to eliminate wrong answers

Option A is wrong because Cloud NAT is a network address translation service for outbound internet access, not for protecting inbound web traffic. Option B is wrong because Cloud CDN is a content delivery network that caches content at edge locations, but it does not provide WAF capabilities. Option C is wrong because Identity-Aware Proxy (IAP) provides authentication and authorization for applications, but it does not protect against OWASP Top 10 attacks like SQL injection or XSS.

710
MCQeasy

A developer wants to deploy a stateless web application that automatically scales based on HTTP traffic. The application should be cost-effective and require minimal configuration. Which compute option is best?

A.App Engine Standard Environment
B.Cloud Functions
C.Compute Engine managed instance group
D.Cloud Run
E.Google Kubernetes Engine
AnswerD

Correct. Cloud Run scales automatically and is simple to deploy.

Why this answer

Cloud Run is the best choice because it automatically scales to zero when idle, scales up to handle HTTP traffic spikes, and requires minimal configuration—just deploy a container. It is cost-effective as you pay only for resources used during request processing, and it supports stateless web applications natively without managing servers or clusters.

Exam trap

The trap here is that candidates often confuse Cloud Run with Cloud Functions, thinking both are equivalent for web applications, but Cloud Functions is limited to event-driven triggers and cannot serve a full web app with persistent HTTP connections.

How to eliminate wrong answers

Option A is wrong because App Engine Standard Environment, while serverless, has more restrictive runtime environments and may require code modifications to fit its sandbox, whereas Cloud Run offers more flexibility with any container. Option B is wrong because Cloud Functions is designed for event-driven, short-lived functions, not for a full stateless web application that handles continuous HTTP traffic. Option C is wrong because Compute Engine managed instance groups require manual configuration of autoscaling policies, instance templates, and health checks, and do not scale to zero, leading to higher costs during idle periods.

Option E is wrong because Google Kubernetes Engine requires cluster management, node configuration, and more operational overhead, making it less minimal in configuration compared to Cloud Run's fully managed serverless container platform.

711
MCQhard

A financial services company runs workloads on GKE and wants to ensure only container images that have been approved by the security team can be deployed. The approval process involves signing images after vulnerability scanning. Which GCP service should be integrated with GKE to enforce this policy?

A.Cloud Key Management Service (Cloud KMS)
B.Cloud Build
C.Artifact Registry
D.Binary Authorization
AnswerD

Binary Authorization enforces deploy-time admission control on GKE by verifying cryptographic signatures (attestations) created after vulnerability scanning, blocking any image lacking a valid attestor signature. This directly satisfies the stem's requirement that only security-team-approved, signed images reach the cluster, rather than merely scanning or storing them.

Why this answer

Binary Authorization is a GCP service that enforces deploy-time security policies on GKE clusters. It ensures that only container images that have been signed by trusted authorities (after vulnerability scanning) are deployed. By integrating Binary Authorization with GKE, the company can enforce that only approved images are deployed.

Exam trap

PCA often tests the distinction between services that build, store, and enforce policies on container images; candidates may confuse Artifact Registry (storage) with Binary Authorization (enforcement), but Binary Authorization is specifically for deploy-time policy enforcement.

How to eliminate wrong answers

Option A is wrong because Cloud KMS is a key management service used to create and manage cryptographic keys, but it does not enforce deployment policies on GKE. Option B is wrong because Cloud Build is a CI/CD service that can build and test images, but it does not enforce deployment admission control. Option C is wrong because Artifact Registry is a repository for container images, but it does not enforce that only signed images are deployed; it can store images but not control deployment.

712
MCQhard

Your organization runs a critical application on Google Cloud that uses Cloud SQL for PostgreSQL. The database is in us-central1. The business requires a recovery point objective (RPO) of 5 minutes and a recovery time objective (RTO) of 1 hour in case of a regional failure. What should you do?

A.Use Cloud SQL point-in-time recovery (PITR) to restore to a specific time in another region.
B.Configure a cross-region read replica and promote it in case of regional failure.
C.Enable high availability (HA) for the Cloud SQL instance, which provides a standby in another zone.
D.Export the database to Cloud Storage every 5 minutes and import it into a new instance in another region during a disaster.
AnswerB

A cross-region read replica replicates asynchronously to another region. In a regional failure, you can promote the replica to a standalone instance. This provides an RPO of typically less than 5 minutes and an RTO of under 1 hour, meeting the requirements. It is the recommended approach for regional disaster recovery.

Why this answer

A cross-region read replica asynchronously replicates data to a different region. In a regional failure, promoting the replica provides a recovery point close to the failure time (RPO within minutes) and can be done quickly (RTO under 1 hour). This is the standard solution for regional DR with Cloud SQL.

Exam trap

The trap here is assuming that HA protects against regional failures, but HA only provides zonal redundancy within a region.

713
MCQhard

A financial services company stores regulated data in BigQuery datasets. Auditors require that all data access be logged with the identity of the user, the query text, and the timestamp, and that logs be retained for 365 days and be immutable. The security team wants to use Google Cloud-native tools with minimal operational overhead. What should they implement?

A.Enable BigQuery Data Access audit logs in Cloud Audit Logs, then create a log sink to a Cloud Storage bucket with a 365-day retention policy and a Bucket Lock.
B.Enable BigQuery Data Access audit logs and configure a log sink to a BigQuery dataset with a 365-day partition expiration and table-level IAM restrictions.
C.Use BigQuery's INFORMATION_SCHEMA.JOBS_BY_PROJECT view to query historical job metadata, and export results to Cloud Storage on a daily schedule via a Cloud Scheduler job.
D.Enable VPC Service Controls for BigQuery and configure access levels that log all API calls to Cloud Logging with a 365-day retention period.
AnswerA

BigQuery Data Access audit logs capture the identity, query text, and timestamp for data access. Sinking them to a Cloud Storage bucket with a retention policy and Bucket Lock makes the logs immutable for the required period. This uses native Cloud Audit Logs and Cloud Storage features with minimal operational overhead, meeting all auditor requirements.

Why this answer

BigQuery Data Access audit logs provide the required identity, query text, and timestamp for every data access. Routing them through a log sink to a Cloud Storage bucket with a retention policy and Bucket Lock ensures immutability for 365 days. This combination uses native Google Cloud services and requires no custom code or third-party tooling, minimizing operational overhead.

Exam trap

The trap here is confusing BigQuery INFORMATION_SCHEMA job history or VPC Service Controls logs with Cloud Audit Logs, which are the only native source that captures full Data Access audit records with query text.

714
MCQhard

A financial services company runs a high-volume transaction processing system on Google Cloud. They need to ensure that the system can handle sudden spikes in traffic during market open and close. The system uses a managed instance group of Compute Engine VMs behind a load balancer. They want to optimize costs while maintaining performance during peak hours. Which approach should the architect recommend?

A.Use a managed instance group with autoscaling based on CPU utilization, and set a minimum size to handle baseline traffic.
B.Use preemptible VMs in the managed instance group to reduce compute costs.
C.Use a managed instance group with autoscaling based on a custom metric that tracks queue depth, and set a minimum size of zero.
D.Use a managed instance group with a fixed size large enough to handle peak traffic at all times.
AnswerA

Autoscaling based on CPU utilization allows the instance group to add VMs during traffic spikes and remove them when demand drops. Setting a minimum size ensures baseline capacity is always available. This directly addresses both performance during peaks and cost optimization by scaling down during off-peak times.

Why this answer

Autoscaling based on CPU utilization with a minimum instance count provides elasticity to handle traffic spikes while ensuring baseline capacity. This allows the system to scale out during market open and close and scale in during quieter periods, optimizing costs without sacrificing performance. Other options either over-provision, use unreliable preemptible VMs, or risk cold starts.

Exam trap

The trap here is assuming that aggressive cost-saving measures like preemptible VMs or scaling to zero will work for a critical, latency-sensitive system, when a baseline of reliable instances is needed.

715
MCQhard

You are responsible for incident management for a production service. You want to reduce manual toil during the initial response to common issues like high latency. What is the best approach?

A.Use Cloud Monitoring to trigger a Cloud Function that performs automated checks and rolls back the last deployment if latency spikes.
B.Set up Cloud Monitoring alerts with email notifications to the on-call engineer.
C.Create detailed runbooks and require the on-call to follow them step by step.
D.Enable Cloud Logging and set up a custom dashboard for the on-call.
AnswerA

Cloud Monitoring alerting policies detect the latency spike and invoke a Cloud Function that runs automated diagnostics and rolls back the last deployment, removing manual toil from initial response. This closed-loop remediation satisfies the stem's requirement to automate first response to common incidents.

Why this answer

It directly reduces manual toil by automating the initial response to common issues like high latency. Cloud Monitoring triggers a Cloud Function that performs automated checks and, if latency spikes, rolls back the last deployment, eliminating the need for human intervention during the critical first response phase.

Exam trap

Google Cloud often tests the distinction between 'alerting' (which still requires manual action) and 'automated remediation' (which reduces toil), so candidates mistakenly choose options that provide visibility or documentation instead of automation.

How to eliminate wrong answers

Option B is wrong because email notifications alone still require the on-call engineer to manually investigate and respond, which does not reduce toil; it merely alerts them. Option C is wrong because requiring the on-call to follow runbooks step by step still involves manual effort and does not automate the response, leaving toil unchanged. Option D is wrong because enabling Cloud Logging and setting up a custom dashboard provides visibility but does not automate any action, so the on-call must still manually diagnose and respond to the issue.

716
MCQmedium

A cloud architect is designing a CI/CD pipeline for a microservices application. Each service is deployed to Cloud Run. They want to use Cloud Build to automate building and deploying services only when changes occur in their respective directories. Which Cloud Build feature should they configure?

A.Build steps in cloudbuild.yaml
B.Build triggers with included files filter
C.Cloud Build's 'includedFiles' option in the build configuration
D.Artifact Registry triggers
AnswerB

Cloud Build triggers support an included files filter, so a trigger fires only when commits touch paths matching the specified glob patterns. This satisfies the stem's requirement to build and deploy each service only when its own directory changes, avoiding unnecessary builds.

Why this answer

Build triggers with an included files filter is correct because Cloud Build triggers support an 'includedFiles' field that uses glob patterns to fire a build only when files in specified paths change. This lets a monorepo deploy each microservice independently — for example, a trigger scoped to 'services/payments/**' runs only when payment-service code is modified. This is the native, supported mechanism for path-based CI/CD in Cloud Build.

Exam trap

The trap is confusing build configuration (what runs) with trigger configuration (when it runs) — candidates pick 'includedFiles in cloudbuild.yaml' because the name sounds right, but the filter belongs on the trigger.

How to eliminate wrong answers

Option A is wrong because build steps in cloudbuild.yaml define what the build does, not when it runs — they cannot by themselves restrict execution to changes in specific directories. Option C is wrong because 'includedFiles' is a property of a build trigger, not a standalone option inside the build configuration file; placing it in cloudbuild.yaml has no effect. Option D is wrong because Artifact Registry triggers do not exist as a Cloud Build trigger type — Artifact Registry stores and scans artifacts, it does not initiate builds based on source changes.

717
MCQmedium

A company is designing a microservices architecture on Google Kubernetes Engine (GKE) for a global user base. They require high availability across multiple zones, automatic scaling, and rolling updates without downtime. Which Kubernetes workload resource should they use for each service?

A.StatefulSet with volumeClaimTemplates for persistent storage
B.Deployment with pod anti-affinity rules spread across zones
C.Job for batch processing
D.DaemonSet to ensure one pod per node
AnswerB

A Deployment manages stateless replicas and performs rolling updates, satisfying the no-downtime requirement. Pod anti-affinity rules spread those replicas across zones, delivering the multi-zone high availability the stem demands, while the Horizontal Pod Autoscaler handles automatic scaling.

Why this answer

The correct option is B: a Deployment with pod anti-affinity rules spread across zones. Deployments are the standard GKE workload for stateless microservices, providing declarative rolling updates (via RollingUpdate strategy with maxSurge/maxUnavailable) and integration with the Horizontal Pod Autoscaler for automatic scaling, while pod anti-affinity (or topologySpreadConstraints) spreads replicas across multiple zones for high availability. StatefulSet (A) is designed for stateful workloads needing stable network identities and per-pod PersistentVolumes, not for stateless services requiring rolling updates and autoscaling.

Job (C) runs finite batch tasks to completion rather than long-running services, and DaemonSet (D) schedules one pod per node for node-level agents, not scalable service replicas.

718
Multi-Selecthard

A company is designing a highly available web application on Google Cloud. The application consists of stateless compute instances behind a global HTTP(S) Load Balancer. The compute instances must be able to handle sudden spikes in traffic. Which TWO strategies should the company implement? (Choose two.)

Select 2 answers
A.Use Cloud CDN to cache all responses from the application servers.
B.Use a managed instance group with autoscaling based on CPU utilization.
C.Use a single Compute Engine instance in a single zone with a large machine type.
D.Use a global HTTP(S) Load Balancer with backends in multiple regions.
E.Use vertical scaling by selecting a machine type with more vCPUs and memory.
AnswersB, D

A managed instance group with CPU-based autoscaling adds or removes instances automatically as load changes, absorbing sudden traffic spikes behind the global HTTP(S) load balancer. This satisfies the requirement that stateless compute handle rapid demand increases.

Why this answer

Option B is correct because a managed instance group (MIG) with autoscaling based on CPU utilization automatically adds or removes VM instances in response to traffic spikes, which directly satisfies the requirement that stateless compute instances handle sudden load increases. Option D is correct because a global HTTP(S) Load Balancer with backends in multiple regions distributes traffic across regional MIGs, providing high availability and resilience if one region fails, and it is the appropriate front end for stateless instances. Option A is not correct because Cloud CDN caches content at edge locations but does not by itself provide compute autoscaling or high availability for dynamic application responses, and caching all responses is not a general HA strategy.

Option C is not correct because a single instance in a single zone is a single point of failure and cannot scale horizontally. Option E is not correct because vertical scaling (larger machine type) has limits, requires downtime or restart, and does not provide the elasticity or multi-zone availability needed for sudden traffic spikes.

Exam trap

The trap here is that candidates often confuse caching (Cloud CDN) with compute scaling, or assume vertical scaling (larger machine types) is sufficient for sudden spikes, ignoring the need for horizontal elasticity and multi-zone redundancy in a highly available architecture.

719
MCQmedium

A company wants to automatically move data from Cloud Storage Standard to Nearline after 30 days and to Archive after 90 days. Which approach should they use?

A.Write a custom script using Cloud Functions triggered by Pub/Sub to move objects
B.Use Object Versioning to automatically change storage class
C.Set up a Cloud Storage lifecycle policy with rules to transition to Nearline after 30 days and to Archive after 90 days
D.Enable Requester Pays on the bucket to reduce storage costs
AnswerC

A lifecycle policy applies rule-based transitions based on object age, moving data from Standard to Nearline at 30 days and to Archive at 90 days automatically. This satisfies the stem's requirement for scheduled storage-class transitions without manual intervention.

Why this answer

Cloud Storage lifecycle policies are the native, automated way to transition objects between storage classes based on age. A single lifecycle rule can specify a transition to Nearline after 30 days and another transition to Archive after 90 days, applied to the bucket or specific prefixes. This eliminates the need for custom code and ensures cost optimization automatically.

Exam trap

PCA often tests whether candidates know that lifecycle policies are the native, no-code solution for storage class transitions — many pick custom scripts or confuse versioning with class changes.

How to eliminate wrong answers

Option A is wrong because writing a custom Cloud Function with Pub/Sub is over-engineered and unnecessary when lifecycle policies natively support time-based transitions. Option B is wrong because Object Versioning is for retaining object versions, not for changing storage classes. Option D is wrong because Requester Pays shifts egress costs to the requester and does not transition storage classes.

720
MCQmedium

Your organization uses Cloud Spanner for a customer database with a 99.999% availability SLA. You need a Disaster Recovery plan that ensures data consistency with zero RPO in case of a region failure. What should you do?

A.Use a single-region instance configuration and enable read replicas.
B.Export the database periodically to Cloud Storage and set up a cross-region load balancer.
C.Configure daily backups and store them in Cloud Storage in a different region.
D.Use a multi-region instance configuration (e.g., nam-eur-asia) for the Spanner instance.
AnswerD

A multi-region instance configuration synchronously replicates data across regions using Paxos consensus, so committed writes survive a regional failure with zero data loss. This directly satisfies the stem's zero RPO and consistency requirements, and the 99.999% SLA is only achievable with multi-region configurations, not regional ones.

Why this answer

Cloud Spanner multi-region instance configurations (e.g., nam-eur-asia) provide synchronous replication across multiple regions, ensuring strong global consistency and zero RPO. This architecture uses Paxos-based replication to commit writes only after they are durably stored in a majority of regions, so a region failure does not lose any committed data. The 99.999% availability SLA is met by automatic failover within the multi-region setup without manual intervention.

Exam trap

Google Cloud often tests the misconception that read replicas or periodic exports can achieve zero RPO, but only synchronous multi-region replication (as in Spanner's multi-region configurations) guarantees no data loss during a region failure.

How to eliminate wrong answers

Option A is wrong because single-region instance configurations with read replicas are not supported in Cloud Spanner; Spanner uses writable replicas, not read replicas, and a single-region setup cannot survive a full region failure, thus cannot achieve zero RPO. Option B is wrong because exporting the database periodically to Cloud Storage introduces a non-zero RPO (the time between exports) and does not guarantee data consistency at the point of failure; cross-region load balancers do not handle Spanner's transactional consistency. Option C is wrong because daily backups stored in a different region provide point-in-time recovery with a minimum RPO of 24 hours (or more), not zero RPO, and cannot ensure data consistency for transactions in flight at the time of failure.

721
Drag & Dropmedium

Drag and drop the steps to configure a Cloud Load Balancer with a backend service consisting of Compute Engine instances into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Health checks ensure traffic only goes to healthy instances; URL map defines routing; forwarding rule exposes the IP.

722
MCQmedium

An organization wants to receive alerts when their Cloud SQL instance's CPU utilization exceeds 80% for 5 minutes. They want to send the alert to both email and a Pub/Sub topic for further processing. What should they do?

A.Configure a Cloud Scheduler job to check CPU utilization and publish to Pub/Sub
B.Create a log-based alert for CPU utilization using Logging and route to email and Pub/Sub
C.Create a Cloud Monitoring alerting policy with a metric threshold condition on CPU utilization and add both email and Pub/Sub notification channels
D.Use Cloud Functions to poll the Cloud Monitoring API every minute and send notifications
AnswerC

A Cloud Monitoring alerting policy with a metric threshold condition evaluates CPU utilisation against 80% for the five-minute duration. Attaching both email and Pub/Sub notification channels delivers the alert to each destination, satisfying the dual-delivery requirement without custom code.

Why this answer

Cloud Monitoring alerting policies support metric threshold conditions (e.g., CPU utilization > 80% for 5 minutes) and allow multiple notification channels, including email and Pub/Sub. Creating an alerting policy with a metric threshold condition on the Cloud SQL CPU metric and adding both email and Pub/Sub channels satisfies the requirement directly. This is the native, event-driven approach in Google Cloud.

Exam trap

PCA often tests whether candidates confuse log-based alerts (which trigger on log entries) with metric-based alerting policies (which trigger on metric thresholds), leading them to pick the log-based option for a CPU metric.

How to eliminate wrong answers

Option A is wrong because Cloud Scheduler is a cron service, not a monitoring/alerting system, and polling CPU utilization manually is inefficient and not the intended design. Option B is wrong because log-based alerts trigger on log entries, not on metric thresholds like CPU utilization, so they cannot directly alert on a CPU metric. Option D is wrong because polling the Monitoring API with Cloud Functions is a custom, fragile workaround that duplicates functionality already provided by alerting policies.

723
MCQeasy

A developer needs to deploy a containerized application on Google Kubernetes Engine (GKE) with minimal operational overhead. They want to automatically scale the number of pods based on CPU utilization. Which GKE feature should they use?

A.Horizontal Pod Autoscaler.
B.Node auto-repair.
C.Vertical Pod Autoscaler.
D.Cluster Autoscaler.
AnswerA

The Horizontal Pod Autoscaler adjusts the replica count of a workload based on observed CPU utilisation, satisfying the automatic scaling requirement with minimal operational overhead. It reads metrics from the metrics server and scales pods directly, unlike cluster-level node autoscaling.

Why this answer

The Horizontal Pod Autoscaler (HPA) is the correct choice because it automatically scales the number of pod replicas in a GKE deployment based on observed CPU utilization (or other custom metrics). This directly meets the requirement of scaling pods with minimal operational overhead, as HPA is a native Kubernetes resource that requires no manual intervention once configured.

Exam trap

Google Cloud often tests the distinction between horizontal scaling (HPA) and vertical scaling (VPA), where candidates mistakenly choose VPA when the question explicitly asks for scaling the number of pods based on CPU utilization.

How to eliminate wrong answers

Option B (Node auto-repair) is wrong because it automatically repairs unhealthy nodes in the node pool, not scales pods based on CPU utilization. Option C (Vertical Pod Autoscaler) is wrong because it adjusts the CPU and memory requests/limits of existing pods (vertical scaling), not the number of pod replicas (horizontal scaling). Option D (Cluster Autoscaler) is wrong because it adds or removes nodes from the cluster based on pod scheduling needs, not directly scaling pods based on CPU utilization.

724
MCQmedium

A retail company runs a customer-facing API on a managed instance group (MIG) of Compute Engine VMs behind an external Application Load Balancer. The SRE team wants the load balancer to stop sending traffic to a VM as soon as the local application health endpoint starts returning HTTP 500, even before the VM is fully unresponsive. Which load balancer component must be configured to achieve this?

A.Set the MIG's autoscaling policy to scale in when CPU utilization drops below a target threshold.
B.Enable Cloud CDN on the backend service so that failing responses are cached and served from edge locations.
C.Create an uptime check in Cloud Monitoring against the API endpoint and rely on its alerting policy to failover.
D.Configure an HTTP health check with a check interval and unhealthy threshold on the backend service, and attach it to the MIG.
AnswerD

The backend service's health check is exactly what drives traffic steering for the external Application Load Balancer. Pointing the health check at the application's health endpoint means a VM returning HTTP 500 is marked unhealthy after the unhealthy threshold is reached, so the load balancer drains it from rotation while the VM is still running.

Why this answer

For an external Application Load Balancer, the backend service's health check is the mechanism that determines which instances receive traffic. By pointing an HTTP health check at the application's health endpoint, a VM that begins returning HTTP 500 is marked unhealthy once the unhealthy threshold is met and is removed from rotation, so users are not routed to a failing instance while it is still alive.

Exam trap

The trap here is assuming monitoring uptime checks or autoscaling policies steer load balancer traffic, when only the backend service health check actually controls instance rotation.

725
MCQmedium

A company uses BigQuery for analytics. They have a large partitioned table that is queried frequently. The query performance has degraded over time. Which optimization should they try first?

A.Create a materialized view for each frequent query.
B.Increase the number of slots for the project.
C.Apply clustering on frequently filtered columns.
D.Denormalize the table to reduce joins.
AnswerC

Clustering physically co-locates rows sharing the clustered column values, so filters on those columns scan fewer blocks. On a frequently queried partitioned table, clustering the common filter columns prunes data within each partition, improving performance without restructuring partitions.

Why this answer

Clustering on frequently filtered columns reorganizes the data within partitions based on the values of those columns, which allows BigQuery to prune blocks more effectively during queries. This directly addresses the performance degradation by reducing the amount of data scanned, without requiring additional storage or compute resources.

Exam trap

Google Cloud often tests the misconception that adding more slots (Option B) is the default performance fix, when in reality the first step should be to reduce data scanned through clustering or partitioning optimization.

How to eliminate wrong answers

Option A is wrong because creating materialized views for each frequent query would increase storage costs and maintenance overhead, and they are not the first optimization to try for a partitioned table with degraded performance; clustering addresses the root cause of excessive data scanning. Option B is wrong because increasing the number of slots only improves concurrency and throughput, not the efficiency of individual queries; it does not reduce the amount of data read per query. Option D is wrong because denormalizing the table to reduce joins is a schema design change that may help with join-heavy workloads, but it does not address the core issue of scanning too many rows in a large partitioned table; clustering is a more targeted and less disruptive first step.

726
MCQeasy

A developer needs to deploy a stateful application that requires persistent storage across pod restarts in Google Kubernetes Engine. Which resource should they use?

A.ConfigMap
B.EmptyDir
C.Secret
D.PersistentVolumeClaim
AnswerD

A PersistentVolumeClaim requests durable storage from a PersistentVolume, decoupling the pod lifecycle from the data. This satisfies the stem's requirement that storage survive pod restarts, unlike emptyDir or container filesystems, which are ephemeral and lose contents when a pod is terminated or rescheduled.

Why this answer

A PersistentVolumeClaim (PVC) is the correct resource because it allows a pod to request persistent storage that survives pod restarts. In GKE, a PVC binds to a PersistentVolume (PV), which can be backed by Compute Engine persistent disks, ensuring data remains available even if the pod is rescheduled or restarted.

Exam trap

The trap here is that candidates confuse ephemeral volumes (EmptyDir) with persistent storage, or assume ConfigMaps/Secrets can store application data, when in fact they are for configuration and secrets only.

How to eliminate wrong answers

Option A is wrong because a ConfigMap is used to inject configuration data (e.g., environment variables, files) into pods, not for persistent storage. Option B is wrong because an EmptyDir volume is ephemeral—it is created when a pod starts and is deleted when the pod is removed, so data does not persist across pod restarts. Option C is wrong because a Secret is designed to store sensitive data (e.g., passwords, tokens) and is not a storage volume for application data.

727
MCQhard

A global e-commerce site uses an external HTTPS load balancer with a backend service pointing to a managed instance group. Some users report 503 errors during peak traffic. The backend instances are healthy and not overloaded. What is the most likely cause?

A.The CDN cache is not warming up properly
B.The backend service's health check interval is too short
C.The SSL certificate is expired
D.The load balancer's max rate per backend is configured too low
AnswerD

The max rate per backend setting caps requests per second sent to each instance; when set too low, the load balancer sheds excess traffic and returns 503s even though instances are healthy. Raising this limit resolves the throttling-induced errors during peak load.

Why this answer

A 503 error from an external HTTPS load balancer with healthy backends typically indicates that the load balancer is throttling requests. The 'max rate per backend' setting limits the number of requests per second that the load balancer forwards to each backend instance. When this limit is exceeded, the load balancer returns 503 errors even though the instances themselves are not overloaded, which matches the scenario of peak traffic.

Exam trap

Google Cloud often tests the misconception that 503 errors always indicate backend overload or health check failures, when in fact the load balancer's rate limiting configuration can cause 503s with perfectly healthy instances.

How to eliminate wrong answers

Option A is wrong because CDN cache warming affects cache hit ratios and latency, not 503 errors from the load balancer; a cold cache would cause more origin requests but not throttling. Option B is wrong because a health check interval that is too short could cause flapping or false unhealthy status, but the question states backend instances are healthy and not overloaded, so health checks are passing. Option C is wrong because an expired SSL certificate would cause TLS handshake failures (e.g., ERR_CERT_DATE_INVALID) and 502 or connection errors, not 503 errors from the load balancer itself.

728
MCQmedium

A team wants to collect and analyze logs from multiple projects into a centralized BigQuery dataset for long-term retention and SQL querying. They want to exclude health check logs to reduce costs. Which approach should they use?

A.Use Cloud Monitoring to exclude health check logs
B.Create a log metric for health check logs and filter in BigQuery
C.Create a log sink to BigQuery and add a log exclusion filter for health check logs
D.Set up a Cloud Function to delete health check logs from BigQuery
AnswerC

A BigQuery log sink routes selected log entries into a dataset for SQL querying and retention, while an exclusion filter drops health check entries before ingestion. It satisfies both the centralisation and cost-reduction constraints in the stem.

Why this answer

A log sink routes log entries from Cloud Logging to a destination such as BigQuery, and an exclusion filter on the sink prevents matching entries (health check logs) from being exported, reducing cost. This is the native, supported way to centralize logs in BigQuery while filtering out unwanted entries at the source. The sink can be created at the organization or folder level to aggregate multiple projects.

Exam trap

PCA often tests the difference between log metrics and log sinks; candidates mistakenly think a log metric can exclude logs from export, but only a sink exclusion filter prevents export.

How to eliminate wrong answers

Option A is wrong because Cloud Monitoring is for metrics and alerting, not for excluding logs from export; it cannot filter logs destined for BigQuery. Option B is wrong because a log metric does not remove logs from export; it only creates a metric, and filtering in BigQuery after ingestion still incurs storage and query costs. Option D is wrong because a Cloud Function that deletes logs from BigQuery is an anti-pattern: it adds latency, cost, and complexity, and does not prevent the logs from being written in the first place.

729
MCQeasy

A company wants to minimize egress costs for data transferred between Compute Engine instances in the same region but different zones. What is the best practice?

A.Use a VPN connection.
B.Use internal IPs and ensure they are in the same VPC.
C.Use Cloud NAT.
D.Use external IPs for all instances.
AnswerB

Internal IP traffic within the same VPC and region is free.

Why this answer

B is correct because data transfer between Compute Engine instances in the same region but different zones uses internal IP addresses within the same VPC, which incurs no egress costs. Google Cloud does not charge for traffic between instances using internal IPs within the same region, regardless of zone, as long as they are in the same VPC network. This is the most cost-effective approach for minimizing egress costs.

Exam trap

The trap here is that candidates often confuse 'different zones' with 'different regions' and assume egress costs apply, or they mistakenly think that using external IPs or NAT is necessary for inter-instance communication, when in fact internal IPs within the same VPC and region are free and optimal.

How to eliminate wrong answers

Option A is wrong because using a VPN connection introduces additional complexity and does not reduce egress costs; VPN traffic still traverses the internet or uses Cloud VPN tunnels, which incur egress charges. Option C is wrong because Cloud NAT is used for outbound internet access from private instances and does not affect inter-instance traffic costs within the same region; it would add unnecessary overhead and potential costs. Option D is wrong because using external IPs for all instances forces traffic to go through the internet or Google's external network, incurring egress charges even within the same region, which is the opposite of minimizing costs.

730
MCQmedium

A retail company runs its order-processing platform on Compute Engine instances in a single managed instance group (MIG) spread across three zones in us-central1. During seasonal peaks, the application must handle up to 10x normal traffic while keeping median request latency under 200 ms. The architecture team wants to add a caching layer that can absorb repeated catalogue reads and survive the loss of an entire zone without manual intervention. Which design should they choose?

A.Deploy Memorystore for Redis in Standard Tier with a replica in a second zone and configure the application to read from the Redis endpoint.
B.Deploy Memorystore for Redis in Basic Tier and place the instance in the same zone as the majority of the MIG instances to reduce network latency.
C.Deploy a self-managed Redis cluster on Compute Engine instances distributed across three zones and manage replication and failover with your own scripts.
D.Enable Cloud CDN with a backend service pointed at the MIG, and rely on edge caching to serve repeated catalogue reads.
AnswerA

Memorystore for Redis Standard Tier provides automatic replication to a replica in a different zone and failover if the primary zone is lost, which satisfies the zone-survival requirement. Redis itself absorbs repeated catalogue reads at sub-millisecond latency, offloading the MIG instances. Because the service endpoint is stable, the application needs no manual reconfiguration when failover occurs, matching the no-manual-intervention constraint.

Why this answer

The requirement combines zone-level resilience, low-latency repeated reads, and no manual failover. A managed in-memory cache with automatic cross-zone replication satisfies all three simultaneously: replication handles the zone loss, in-memory storage handles the latency, and the managed endpoint removes manual steps. Options that lack a replica or that push orchestration onto the team fail at least one stated constraint, and edge HTTP caching does not fit dynamic internal reads.

Exam trap

The trap here is assuming that any in-memory cache is equally resilient, when the Basic Tier is single-node and cannot survive the loss of a zone.

731
MCQhard

Your company runs a microservices application on GKE. The development team wants to adopt a progressive delivery strategy to reduce the risk of new releases. They need to route a small percentage of production traffic to a new version, monitor key metrics, and automatically roll back if errors increase. Which approach should you recommend?

A.Implement a canary deployment using Istio with traffic splitting and Prometheus-based analysis.
B.Configure a rolling update on the Kubernetes Deployment with a maxSurge and maxUnavailable setting.
C.Use a blue/green deployment by creating a full second environment and switching all traffic at once after testing.
D.Deploy the new version to a separate namespace and use a Kubernetes Ingress with weight-based routing.
AnswerA

Istio provides fine-grained traffic splitting to route a percentage of traffic to the canary. Combined with Prometheus metrics and analysis, you can automatically promote or roll back based on error rates. This directly supports progressive delivery with automated rollback, meeting the requirement for risk reduction and monitoring.

Why this answer

A canary deployment with Istio allows you to route a small percentage of traffic to the new version and monitor metrics. Prometheus can feed analysis into an automated process that rolls back if error rates exceed a threshold. This provides the progressive delivery and automated risk mitigation the team needs, unlike blue/green, rolling updates, or basic Ingress.

Exam trap

The trap here is thinking that a rolling update or blue/green deployment provides canary-style traffic splitting and automated rollback, which they do not.

732
Multi-Selectmedium

A data engineering team wants to ingest streaming data from Pub/Sub, transform it using Apache Beam, and load it into BigQuery for real-time analytics. They need a fully managed solution that handles autoscaling and does not require managing servers. Which TWO Google Cloud services should they use?

Select 2 answers
A.Cloud Dataproc
B.Cloud Dataflow
C.Cloud Dataprep
D.Cloud Composer
E.Cloud Pub/Sub
AnswersB, E

Cloud Dataflow is the fully managed, serverless runner for Apache Beam pipelines, providing the autoscaling the team requires. It executes the transform stage and writes results into BigQuery, so no compute infrastructure needs provisioning or management.

Why this answer

Option B, Cloud Dataflow, is correct because it is Google Cloud's fully managed, serverless runner for Apache Beam pipelines, automatically handling autoscaling of worker instances and eliminating server management for the transform-and-load stage into BigQuery. Option E, Cloud Pub/Sub, is correct because it is the fully managed, serverless messaging service used to ingest the streaming data that Dataflow then reads and processes. Together, Pub/Sub provides the ingestion layer and Dataflow provides the managed Beam processing that writes results to BigQuery for real-time analytics.

Option A, Cloud Dataproc, is not appropriate because it is a managed Spark/Hadoop cluster service that still requires cluster provisioning and management rather than being serverless. Option C, Cloud Dataprep, is a data-wrangling UI for preparing data, not a streaming Beam execution engine. Option D, Cloud Composer, is a managed Apache Airflow workflow orchestrator for scheduling batch pipelines, not a streaming data processing service.

Exam trap

PCA often tests the difference between Dataflow (serverless Beam) and Dataproc (managed Spark/Hadoop), catching candidates who assume any data processing service is serverless.

733
MCQhard

A multinational corporation needs to comply with data residency requirements for EU customer data. They want to ensure that data stored in Cloud Storage, BigQuery, and Cloud SQL for EU customers never leaves the European Union, even by administrators. They also want to detect and remediate any configuration drift that could violate this policy. What should they implement?

A.Deploy all workloads in EU regions and use a custom Terraform module that validates region parameters before deployment.
B.Create an organization policy constraint 'constraints/gcp.resourceLocations' with allowed values set to EU regions, and apply it at the organization level. Use Security Command Center to monitor for violations.
C.Configure VPC Service Controls perimeters around EU projects and use Access Context Manager to restrict access to EU-based identities.
D.Use Cloud KMS with EU-based key rings to encrypt all EU customer data, and rely on key location to enforce data residency.
AnswerB

The organization policy constraint 'constraints/gcp.resourceLocations' restricts where resources can be created to specified locations, such as EU regions. Applying it at the organization level ensures all projects inherit the restriction. Security Command Center can detect violations and misconfigurations, providing the required monitoring and remediation capability.

Why this answer

The organization policy constraint 'constraints/gcp.resourceLocations' is the native Google Cloud control that restricts resource creation to specified locations. Applied at the organization level, it ensures all projects inherit the EU-only restriction, preventing administrators from creating resources outside the EU. Security Command Center provides continuous monitoring and can detect any drift or violations, enabling remediation.

Exam trap

The trap here is assuming that VPC Service Controls or Cloud KMS key location enforces data residency, when only the 'constraints/gcp.resourceLocations' organization policy constraint restricts where resources can be physically created.

734
MCQmedium

You are responsible for a Cloud Run service that experiences occasional cold starts, causing increased latency. You want to minimize cold starts while keeping costs under control. What should you do?

A.Set the minimum number of instances to a value greater than zero.
B.Increase the maximum number of instances.
C.Use a larger container image.
D.Deploy the service with a higher CPU limit.
AnswerA

Setting the minimum number of instances ensures that at least that many instances are always running, eliminating cold starts for the baseline traffic. You can set it to a low value, such as 1 or 2, to balance cost and performance. This is the recommended approach to reduce cold starts while controlling costs.

Why this answer

To minimize cold starts in Cloud Run, set the minimum number of instances to a value greater than zero. This keeps a baseline of warm instances ready to serve requests, reducing latency. Increasing the maximum instances or CPU limit does not prevent cold starts, and a larger container image would exacerbate them.

Exam trap

The trap here is thinking that increasing the maximum instances or CPU will prevent cold starts, but cold starts are only mitigated by keeping instances warm via minimum instances.

735
MCQhard

A global e-commerce company is designing its application architecture on Google Cloud. The application must serve users from multiple regions with low latency and must be able to fail over between regions automatically in case of a regional outage. The company wants to minimize operational overhead and ensure that the database layer supports multi-region writes with strong consistency. Which database solution should they choose?

A.Cloud SQL for PostgreSQL with cross-region read replicas.
B.Cloud Bigtable with a multi-region cluster.
C.Cloud Spanner with a multi-region configuration.
D.Firestore in Datastore mode with multi-region replication.
AnswerC

Cloud Spanner is a globally distributed, horizontally scalable database that supports multi-region configurations with strong consistency. It provides automatic failover and low-latency reads and writes across regions. This meets the requirements for multi-region writes, strong consistency, and minimal operational overhead.

Why this answer

Cloud Spanner is the only Google Cloud database that offers multi-region writes with strong consistency and automatic failover. It is designed for global applications requiring low latency and high availability. The other options either do not support multi-region writes or do not provide strong consistency across regions.

Exam trap

The trap here is assuming that cross-region read replicas or NoSQL databases can handle multi-region writes with strong consistency, when they typically offer read-only replicas or eventual consistency.

736
Multi-Selectmedium

A media company uses a multi-project Google Cloud organization. They want to optimize their cloud spend across all projects without sacrificing performance or reliability. They have already implemented committed use discounts for Compute Engine. Which two additional actions should the architect recommend to reduce costs? (Choose two.)

Select 2 answers
A.Use preemptible VMs for all production workloads to reduce compute costs.
B.Implement automatic resource scheduling to shut down non-production VMs during off-hours.
C.Purchase additional committed use discounts for all remaining on-demand instances.
D.Migrate infrequently accessed Cloud Storage data to Nearline or Coldline storage classes.
E.Enable billing export to BigQuery and create cost anomaly detection dashboards.
AnswersB, D

Automatic resource scheduling stops non-production VMs when they are not needed, such as nights and weekends. This directly reduces Compute Engine costs without affecting production performance or reliability. It is a common and effective cost-optimization practice, especially for development and test environments that do not require 24/7 uptime.

Why this answer

Shutting down non-production VMs during off-hours directly cuts compute costs without impacting production reliability. Moving infrequently accessed data to Nearline or Coldline storage reduces storage costs while maintaining low-latency access when needed. Both actions are practical, low-risk optimizations that address different parts of the bill.

Visibility tools and preemptible VMs for production do not meet the requirement, and additional commitments should be based on careful analysis.

Exam trap

The trap here is assuming that any cost-related action, such as enabling billing export or buying more commitments, will reduce spend, when only actions that change resource usage or storage class directly lower the bill.

737
MCQmedium

A company has a Cloud SQL for MySQL instance with automated backups enabled. They need to recover the database to a specific point in time within the last hour. Which feature should they use?

A.Failover replica
B.Point-in-time recovery (PITR)
C.Automated backup restore
D.Import using the mysqldump file
AnswerB

Point-in-time recovery uses binary logs to restore a Cloud SQL for MySQL instance to a specific timestamp, not just the last automated backup. This satisfies the requirement to recover to a point within the last hour.

Why this answer

Point-in-time recovery (PITR) lets Cloud SQL for MySQL restore to a specific timestamp within the retention window by combining automated backups with binary logs. It is the only option that supports recovery to an arbitrary point within the last hour. Automated backup restore only returns the database to the time of the last backup, not an arbitrary point.

Exam trap

The trap here is confusing high-availability features like failover replicas with backup and recovery features; PCA candidates often pick failover replica when the scenario is about restoring to a past point in time.

How to eliminate wrong answers

Option A is wrong because a failover replica is for high availability during a zone or instance failure, not for recovering to a past point in time. Option C is wrong because restoring an automated backup recovers only to the backup's creation time, which may be hours old and cannot target a specific minute. Option D is wrong because mysqldump is a logical export/import tool and is not the mechanism for point-in-time recovery; it also requires a pre-existing dump file.

738
MCQmedium

An organization requires that all container images deployed to GKE be signed and verified before deployment. Which GCP service should be used?

A.Container Registry vulnerability scanning
B.Binary Authorization
C.Cloud Build
D.Artifact Registry
AnswerB

Binary Authorization enforces deploy-time attestation on GKE, blocking unsigned or unverified container images before they reach the cluster. It satisfies the stem's requirement for signature verification at deployment by validating attestations from trusted authorities, unlike vulnerability scanning or registry-level controls, which cannot gate admission.

Why this answer

Binary Authorization is a GCP service that enforces deploy-time security controls on GKE by ensuring only trusted container images are deployed. It uses attestations created by trusted authorities to verify that an image has been signed and meets specific criteria before allowing deployment. This directly satisfies the requirement for signed and verified images.

Exam trap

PCA often tests the difference between image scanning (vulnerability detection) and image signing/verification (policy enforcement). Candidates may confuse vulnerability scanning with Binary Authorization's enforcement role.

How to eliminate wrong answers

Option A is wrong because Container Registry vulnerability scanning only identifies vulnerabilities in images; it does not enforce signing or verification. Option C is wrong because Cloud Build is a CI/CD service for building and deploying containers, not for enforcing deployment policies. Option D is wrong because Artifact Registry is a repository for storing and managing container images, not for policy enforcement.

739
Multi-Selectmedium

A company runs a high-traffic web application on Google Kubernetes Engine (GKE). The application uses a Cloud SQL for MySQL instance as its backend. The operations team wants to optimize the cost of the GKE cluster and the Cloud SQL instance without sacrificing performance or availability. Which two actions should they take? (Choose two.)

Select 2 answers
A.Use preemptible VMs for the GKE nodes to reduce compute costs.
B.Purchase committed use discounts for the GKE nodes' underlying Compute Engine instances.
C.Configure Cloud SQL to use a shared-core machine type to reduce database costs.
D.Schedule regular backups of the Cloud SQL instance to reduce storage costs.
E.Enable GKE cluster autoscaler to automatically adjust the number of nodes based on workload demand.
AnswersB, E

Committed use discounts (CUDs) provide significant savings for steady-state usage by committing to a certain amount of resources for 1 or 3 years. For a high-traffic application with predictable baseline load, purchasing CUDs for the GKE nodes can reduce compute costs without affecting performance or availability.

Why this answer

Enabling cluster autoscaler ensures the GKE cluster scales dynamically with demand, reducing costs during idle periods while maintaining performance. Purchasing committed use discounts for the underlying Compute Engine instances provides cost savings for the baseline load. Together, these actions optimize costs without compromising performance or availability.

Exam trap

The trap here is assuming that preemptible VMs are suitable for all cost-saving scenarios, but they can be terminated and are not appropriate for high-availability production workloads.

740
MCQhard

A logistics company runs a batch route-optimization job that reads 50 TB from Cloud Storage, performs CPU-intensive computation, and writes results back to Cloud Storage. The job runs for about four hours each night and must finish before the morning dispatch window. The team wants the lowest cost while guaranteeing completion within the window. Which compute design should the architect choose?

A.A managed instance group of preemptible VMs with an instance template that runs the batch job
B.A Cloud Run service with 8 vCPU and 32 GiB memory processing the job on a nightly Cloud Scheduler trigger
C.A Dataproc cluster with autoscaling enabled and secondary workers on preemptible VMs
D.A Batch job with a task group that specifies a machine type and a maximum run duration, using standard provisioning
AnswerD

Batch provisions Compute Engine capacity for the task group, supports specifying machine type and a maximum run duration, and can use standard (non-preemptible) VMs, which guarantees the resources are not reclaimed mid-run. It handles job scheduling, retries, and Cloud Storage staging, and the four-hour window fits comfortably within standard VM availability.

Why this answer

Batch is the managed service for running containerized batch workloads on Compute Engine. Specifying a task group with standard provisioning and a maximum run duration guarantees capacity for the four-hour job, and Batch handles Cloud Storage staging, retries, and job lifecycle. Preemptible options risk termination, Dataproc targets Spark and Hadoop, and Cloud Run timeouts prevent long-running jobs.

Exam trap

The trap here is optimizing for the lowest raw compute price with preemptible VMs, while ignoring that a hard completion deadline rules out reclaimable capacity.

741
Multi-Selectmedium

A retail company is planning a Google Cloud organization structure for a new e-commerce platform. They want to isolate production from non-production, allow central network and security teams to apply guardrails across all projects, and give application teams self-service within their own boundaries. Which two design choices support these goals? (Choose two.)

Select 2 answers
A.Use a Shared VPC host project owned by the central network team, with application projects attached as service projects.
B.Create separate folders for production and non-production under the organization node, and apply organization policies at the folder level.
C.Place every project directly under the organization node and manage IAM individually per project.
D.Assign each application team the Project Creator role at the organization node so they can create projects anywhere.
E.Grant the central network team the Organization Administrator role so they can manage all projects directly.
AnswersA, B

Shared VPC centralizes subnet, firewall, and routing control in a host project managed by the network team, while service projects consume those networks. Application teams can deploy resources into their own service projects without managing network topology, giving them self-service within boundaries and allowing the central team to apply consistent network guardrails across all workloads.

Why this answer

A folder hierarchy with production and non-production branches lets central teams apply organization policies and IAM that inherit downward, while application teams create projects inside their assigned folder. Pairing that with a Shared VPC host project centralizes network control and lets service projects consume the network, so application teams get self-service deployment without owning network topology.

Exam trap

The trap here is equating central control with granting broad organization-level roles instead of using folder-scoped policies and Shared VPC.

742
MCQeasy

A startup wants to run a containerized web application that scales to zero when not in use and charges only for request processing time. Which compute service is most appropriate?

A.Google Kubernetes Engine (Autopilot)
B.Compute Engine with preemptible VMs
C.Cloud Run
D.App Engine Standard
AnswerC

Cloud Run runs containerised workloads on a fully managed, request-driven model, scaling to zero instances when idle and billing only for CPU and memory consumed during request processing. This directly satisfies the startup's two constraints: zero-cost idle periods and per-request charging, without cluster or node management overhead.

Why this answer

Cloud Run is a fully managed serverless container platform that scales to zero when idle and bills only for request processing time (and CPU/memory during request handling). It is purpose-built for containerized HTTP workloads with automatic scaling, making it the exact match for the startup's requirements.

Exam trap

PCA often tests the confusion between serverless container platforms that scale to zero (Cloud Run) and managed Kubernetes or VM offerings that bill for provisioned capacity even when idle.

How to eliminate wrong answers

Option A is wrong because GKE Autopilot still runs a Kubernetes cluster with at least a minimal node footprint and does not scale to zero; it bills for provisioned pods/nodes, not per-request. Option B is wrong because Compute Engine preemptible VMs are always-on (or manually started) instances billed per second of VM uptime, not per request, and they do not scale to zero automatically. Option D is wrong because App Engine Standard runs source code in language-specific runtimes, not arbitrary containers, and its scaling behavior differs — it can scale to zero but does not support custom container images the way Cloud Run does.

743
Multi-Selectmedium

Your organization is adopting Google Cloud and wants to establish a cost governance framework. You need to implement mechanisms that provide visibility into spending and allow proactive control over costs. (Choose two.)

Select 2 answers
A.Set up budget alerts in Cloud Billing to notify stakeholders when spending exceeds a defined threshold.
B.Assign the Billing Account Administrator role to all project owners to ensure they can view and manage costs.
C.Use the Pricing Calculator to estimate costs before deploying new resources.
D.Enable committed use discounts for all Compute Engine instances to reduce the effective cost per hour.
E.Export billing data to BigQuery and create custom dashboards in Looker Studio to analyze cost trends by project and label.
AnswersA, E

Budget alerts provide proactive notifications when costs approach or exceed predefined limits. They do not stop spending, but they enable timely action. This is a core cost governance mechanism that increases awareness and allows teams to react before costs escalate. It complements detailed analysis by providing early warnings.

Why this answer

Cost governance requires both visibility and proactive control. Exporting billing data to BigQuery with Looker Studio dashboards provides deep visibility into spending patterns, while budget alerts notify stakeholders when thresholds are breached. Together, they enable analysis and timely intervention.

The other options are either optimization tactics, overly broad permissions, or planning tools that lack ongoing monitoring.

Exam trap

The trap here is equating cost optimization techniques like committed use discounts with governance, which actually requires visibility and alerting.

744
MCQmedium

An organization uses Cloud Storage to store critical documents. They want to protect against accidental deletion or overwriting of objects. Which feature should they enable?

A.Uniform bucket-level access
B.Object lifecycle management rules
C.Object versioning and retention policies
D.Customer-managed encryption keys (CMEK)
AnswerC

Versioning preserves every prior generation of an object, so an overwrite creates a new version rather than destroying the original, and deletion only adds a delete marker. Retention policies add immutability, satisfying the requirement to protect critical documents from accidental deletion or overwriting.

Why this answer

Object versioning and retention policies together protect against accidental deletion and overwrites. Versioning keeps multiple versions of objects, and retention policies prevent deletion until a specified time. Uniform bucket-level access is for access control, not protection.

Object lifecycle management automates transitions/deletion, not protection. Encryption protects data at rest.

745
MCQeasy

A company wants to migrate a MySQL database running on-premises to Cloud SQL with minimal downtime. Which GCP service should they use?

A.Migrate for Compute Engine
B.Storage Transfer Service
C.Transfer Appliance
D.Database Migration Service
AnswerD

Database Migration Service performs continuous, near-zero-downtime replication from on-premises MySQL into Cloud SQL, then promotes the replica at cutover. This directly satisfies the stem's minimal-downtime constraint, unlike dump-and-restore approaches that require taking the source offline.

Why this answer

Database Migration Service (DMS) is purpose-built for migrating MySQL, PostgreSQL, and SQL Server databases to Cloud SQL with minimal downtime. It handles continuous replication and cutover, which is exactly what's needed for a live database migration.

Exam trap

The trap is confusing data transfer services (Storage Transfer Service, Transfer Appliance) with database migration services; the exam expects you to know that DMS is the only GCP service designed for live database migration with minimal downtime.

How to eliminate wrong answers

Option A is wrong because Migrate for Compute Engine is for migrating VMs, not databases. Option B is wrong because Storage Transfer Service moves object data between storage buckets, not relational databases. Option C is wrong because Transfer Appliance is a physical appliance for bulk data transfer to GCP, not for database migration with minimal downtime.

746
MCQmedium

A company wants to restrict access to a Cloud Storage bucket so that only objects encrypted with a specific Cloud KMS key can be read. Which approach should they use?

A.Enable Key Access Justifications on the Cloud KMS key and allow access only for justified requests.
B.Set a bucket policy that denies access if the object's encryption type is not CMEK.
C.Use IAM conditions with the resource name condition 'resource.name.startsWith("projects/_/buckets/example-bucket/objects/")' and 'resource.hasTag("kmsKeyName", "projects/p/locations/l/keyRings/kr/cryptoKeys/ck")'.
D.Configure VPC Service Controls to include the bucket and the Cloud KMS key resource.
AnswerA

Incorrect. Key Access Justifications provide logging and justification for key usage but do not control read access to objects based on encryption key.

Why this answer

To restrict access to a Cloud Storage bucket so that only objects encrypted with a specific Cloud KMS key can be read, the company should enable Key Access Justifications (KAJ) on the Cloud KMS key and allow access only for justified requests. KAJ provides the ability to enforce access policies based on the justification provided for a key operation, effectively tying object access to the specific key. Option B is incorrect because Cloud Storage bucket policies do not support conditions on `request.object.encryption.type`; that attribute is not a valid IAM condition for Cloud Storage.

Option C is incorrect because `resource.hasTag` is not a valid IAM condition attribute for Cloud Storage objects. Option D is incorrect because VPC Service Controls provide perimeter-based security but do not restrict access based on the encryption key of individual objects.

Exam trap

The trap is that candidates may think a bucket policy can enforce encryption-key-based access using a condition like `request.object.encryption.type`, but Cloud Storage IAM conditions do not support that attribute. The correct mechanism is Key Access Justifications on the Cloud KMS key.

How to eliminate wrong answers

Option A is wrong because Key Access Justifications (KAJ) are used to provide justifications for Cloud KMS key access requests, not to restrict bucket access based on encryption key type; KAJ does not filter object-level access. Option B is wrong because bucket policies cannot directly inspect or condition on the encryption type of individual objects; the condition 'object's encryption type is not CMEK' is not a supported attribute in bucket policy conditions. Option D is wrong because VPC Service Controls (VPC-SC) control network-level access to services and resources, but they cannot enforce that only objects encrypted with a specific KMS key are readable; VPC-SC operates on service perimeters, not object-level encryption attributes.

747
MCQmedium

A company is building a microservices architecture on Google Kubernetes Engine (GKE) and needs to ensure each microservice can only access specific Cloud Storage buckets. IAM permissions should be assigned at the pod level, not at the node level. What is the recommended approach?

A.Store service account keys in Kubernetes secrets and mount them into each pod
B.Use a CSI driver to mount IAM credentials into pods
C.Use Workload Identity to bind a Kubernetes service account to a GCP service account
D.Assign a service account to each node pool and configure pod security policies
AnswerC

Workload Identity maps a Kubernetes service account to a Google service account, so pods obtain that identity's IAM permissions via metadata server federation. This satisfies pod-level, not node-level, access control to specific Cloud Storage buckets.

Why this answer

Workload Identity is the recommended approach because it allows you to bind a Kubernetes service account (KSA) to a Google Cloud service account (GSA), enabling pods to authenticate to Google Cloud APIs without managing or storing service account keys. This satisfies the requirement for pod-level IAM permissions, as each pod can inherit the GSA's roles (e.g., roles/storage.objectViewer) for specific Cloud Storage buckets, while avoiding node-level assignment.

Exam trap

A common misconception tested on the Google PCA exam is that storing service account keys in Kubernetes secrets (Option A) is acceptable for production. However, the trap here is that Workload Identity eliminates the need for static keys entirely, aligning with Google's security best practices and the requirement for pod-level identity.

How to eliminate wrong answers

Option A is wrong because storing service account keys in Kubernetes secrets and mounting them into pods introduces security risks (key exposure, rotation complexity) and violates the principle of avoiding static credentials; it also does not leverage GKE's native identity integration. Option B is wrong because while a CSI driver can mount secrets or certificates, there is no standard CSI driver for mounting IAM credentials directly into pods; this approach is not a recommended or supported pattern for GKE identity management. Option D is wrong because assigning a service account to each node pool and configuring pod security policies grants permissions at the node level, not the pod level, which contradicts the requirement and can lead to over-privileged pods sharing the same node-level identity.

748
MCQmedium

Your company has a production Cloud SQL for PostgreSQL instance in us-central1 with automated backups enabled. You need to ensure that if the zone fails, the database automatically fails over to a standby in a different zone with minimal downtime. What should you do?

A.Enable deletion protection on the instance.
B.Create a cross-region read replica and manually promote it during a failure.
C.Configure the instance as a highly available (regional) instance.
D.Enable point-in-time recovery (PITR) and keep 30 days of transaction logs.
AnswerC

Configuring a highly available (regional) instance provisions a standby in a different zone within the same region, with automatic failover and synchronous replication. This satisfies the stem's requirement for automatic zone-failure failover with minimal downtime, which a single-zone instance with backups alone cannot provide.

Why this answer

Configuring the Cloud SQL instance as a highly available (regional) instance provisions a standby in a different zone within the same region and automatically fails over during a zone failure with minimal downtime. This is the native HA mechanism for Cloud SQL and directly satisfies the requirement.

Exam trap

PCA often tests the difference between HA (automatic zone failover) and read replicas (manual promotion for DR) — candidates pick the cross-region replica thinking it provides automatic failover, but it requires manual intervention.

How to eliminate wrong answers

Option A is wrong because deletion protection only prevents accidental instance deletion — it has nothing to do with zone failover or availability. Option B is wrong because a cross-region read replica requires manual promotion and is designed for regional disaster recovery, not automatic zone-level failover with minimal downtime. Option D is wrong because point-in-time recovery restores data to a prior moment by replaying transaction logs — it is a data recovery feature, not an availability or failover mechanism.

749
MCQmedium

A retail company runs a Java-based order service on Compute Engine. The service currently reads its database credentials from a plaintext file on the boot disk. A security review requires that the credentials be removed from disk, be automatically rotated every 30 days, and be retrievable by the application through a single API call. You want the least operational overhead. What should you do?

A.Encrypt the credentials file with a Cloud KMS key, keep it on the boot disk, and grant the VM's service account roles/cloudkms.cryptoKeyDecrypter so the application can decrypt it at startup.
B.Store the credentials in a Cloud Storage bucket with uniform bucket-level access and grant the VM's service account roles/storage.objectViewer, then have the application download the file at startup.
C.Store the credential in a custom metadata key on the instance and grant the VM's service account the compute.instanceAdmin.v1 role so it can read its own metadata.
D.Store the credential as a version in Secret Manager, grant the VM's service account roles/secretmanager.secretAccessor on that secret, and configure a rotation schedule that publishes to a Pub/Sub topic.
AnswerD

Secret Manager is the managed service for this exact requirement: the secret never needs to live on disk, access is granted per-secret through IAM to the VM's attached service account, and a rotation schedule with a Pub/Sub notification lets a Cloud Function rotate the database password automatically. The application fetches the current version through one API call.

Why this answer

The requirements point to a managed secret store with per-secret IAM and built-in rotation. Secret Manager keeps the credential off disk, lets the application retrieve it with one API call, and supports a rotation schedule that notifies a Pub/Sub topic so an automated workflow can update the underlying database password. Object storage, metadata, and KMS-wrapped files all leave the credential materialized on the instance or require custom rotation logic.

Exam trap

The trap here is assuming that encrypting a credential with Cloud KMS satisfies a requirement to remove it from disk and rotate it, when KMS rotates the wrapping key rather than the credential itself.

750
MCQeasy

A multinational e-commerce company needs a globally distributed database that provides strong consistency and transactional support for order processing. Which Google Cloud database service should they use?

A.Cloud SQL
B.Cloud Spanner
C.Cloud Bigtable
D.Cloud Firestore
AnswerB

Cloud Spanner satisfies both constraints simultaneously: global distribution and strong consistency with ACID transactions. Its TrueTime-based synchronisation delivers external consistency across regions, unlike Cloud SQL (regional) or Firestore, which offers strong consistency only within limited configurations.

Why this answer

Cloud Spanner is the correct choice because it is a globally distributed, horizontally scalable relational database service that provides strong consistency and full ACID transactional support across regions. Unlike other Google Cloud databases, Spanner uses synchronous replication and the TrueTime API to guarantee external consistency, making it ideal for order processing systems that require both global scale and transactional integrity.

Exam trap

The trap here is that candidates often confuse Cloud Spanner with Cloud SQL, assuming that a traditional relational database like Cloud SQL can be scaled globally by adding replicas, but they miss that Cloud SQL replicas are read-only and cannot provide the strong consistency and write scalability needed for a globally distributed transactional system.

How to eliminate wrong answers

Option A is wrong because Cloud SQL is a regional, single-writer database that cannot scale horizontally across multiple regions, and it does not provide the global strong consistency needed for a globally distributed order processing system. Option C is wrong because Cloud Bigtable is a NoSQL wide-column database designed for high-throughput analytical workloads, not for transactional order processing that requires strong consistency and ACID transactions. Option D is wrong because Cloud Firestore is a NoSQL document database that offers eventual consistency by default (unless using transactions in a single region) and is not designed for the complex, strongly consistent transactional workloads of a global e-commerce order processing system.

Page 9

Page 10 of 11

Page 11

All pages