Courseiva

Google Professional Cloud Architect (PCA) — Questions 751–807

807 questions total · 11pages · All types, answers revealed

Page 10

Page 11 of 11

751
MCQmedium

A company uses Cloud Deploy for continuous delivery. They have a delivery pipeline with multiple targets: dev, staging, and prod. They want to require manual approval before deploying to prod. How should they configure this?

A.Add a Cloud Build trigger that pauses and waits for approval
B.Use IAM conditions to restrict deployment to prod
C.Configure an approval gate on the prod target in the delivery pipeline
D.Set up a Pub/Sub notification and a Cloud Function to approve
AnswerC

Approval gates are defined per target within the delivery pipeline, pausing a rollout before it advances. Placing a gate on the prod target blocks promotion until a human approves, satisfying the manual-approval constraint without altering dev or staging.

Why this answer

Google Cloud Deploy supports approval gates on targets, which pause a rollout and require manual approval before proceeding to the next target. Configuring an approval gate on the prod target in the delivery pipeline enforces the manual approval requirement natively.

Exam trap

The trap is overcomplicating the solution with custom Pub/Sub or Cloud Functions, when Cloud Deploy has a native approval gate feature on targets.

How to eliminate wrong answers

Option A is wrong because Cloud Build triggers are for building and testing, not for gating deployments; using a trigger to pause would be a custom workaround, not the intended mechanism. Option B is wrong because IAM conditions restrict who can perform actions but do not provide a manual approval step in the deployment flow. Option D is wrong because Pub/Sub and Cloud Functions could be used to build a custom approval system, but Cloud Deploy already provides a built-in approval gate, making this unnecessarily complex.

752
MCQmedium

Your company has a complex legacy application that runs on a single large VM. The application is stateful and has a monolithic architecture. You are tasked with migrating it to Google Cloud with minimal changes, but you also want to improve its reliability and scalability over time. Which migration strategy should you initially recommend?

A.Refactor the application into microservices on GKE to improve scalability and reliability.
B.Replatform the application by moving it to a managed database service and modifying the code to use cloud-native APIs.
C.Repurchase by replacing the application with a SaaS solution that provides similar functionality.
D.Rehost the application by moving the VM to Compute Engine using Migrate for Compute Engine.
AnswerD

Rehosting (lift and shift) moves the application with minimal changes, often using Migrate for Compute Engine to replicate the VM to Google Cloud. This meets the immediate goal of minimal modification. It also provides a foundation for later optimization, such as refactoring or replatforming, once the application is running in the cloud.

Why this answer

Rehosting with Migrate for Compute Engine allows you to move the VM to Compute Engine with minimal changes, satisfying the immediate requirement. Once in the cloud, you can take advantage of reliability features like snapshots and managed instance groups, and later consider refactoring or replatforming. The other strategies involve significant changes or replacements that contradict the minimal-change constraint.

Exam trap

The trap here is opting for a more modern architecture like microservices when the requirement explicitly asks for minimal changes initially.

753
MCQeasy

An administrator is configuring firewall rules in a VPC. Two rules apply to the same traffic: rule 1 allows ingress from 0.0.0.0/0 on TCP 80, rule 2 denies ingress from 10.0.0.0/8 on TCP 80. Rule 1 has priority 1000, rule 2 has priority 500. What is the effective behavior for traffic from 10.0.0.1?

A.The result is unpredictable without knowing the rule creation order.
B.Traffic is allowed because allow rules override deny rules.
C.Traffic is denied because rule 2 has higher priority.
D.Traffic is allowed because rule 1 has a lower priority number.
AnswerC

VPC firewall rules are evaluated by priority, where the lowest numeric value wins; rule 2's priority 500 beats rule 1's 1000. Because 10.0.0.1 falls inside 10.0.0.0/8, the deny rule matches first and takes effect, so the connection is blocked despite the broader allow.

Why this answer

In Google Cloud VPC firewall rules, rules are evaluated in priority order, with lower numbers having higher priority. Rule 2 (priority 500) is evaluated before rule 1 (priority 1000), and since rule 2 explicitly denies ingress from 10.0.0.0/8 on TCP 80, traffic from 10.0.0.1 is denied. Google Cloud firewall rules are stateful, and the first matching rule determines the outcome; there is no implicit override between allow and deny.

Exam trap

Google Cloud PCA often tests the misconception that allow rules override deny rules or that rule creation order matters, but the trap here is that candidates confuse priority numbers (lower = higher priority) and assume a higher number means higher priority.

How to eliminate wrong answers

Option A is wrong because rule creation order does not affect evaluation; only the priority number matters. Option B is wrong because allow rules do not inherently override deny rules; the rule with the highest priority (lowest number) that matches the traffic is applied. Option D is wrong because a lower priority number means higher priority, not lower; rule 1 has a higher priority number (1000) and thus lower priority, so it is not evaluated before rule 2.

754
MCQhard

You are investigating a Vertex AI Workbench instance (instance-2) that is showing UNHEALTHY status. Based on the exhibit, what is the most likely cause of the issue?

A.The container image gcr.io/my-project/my-image:latest does not exist, or the service account used by the Workbench instance does not have storage.objectViewer access to the container registry.
B.The container registry endpoint is blocked by a firewall rule that does not allow egress to gcr.io.
C.The instance's underlying Compute Engine resources are exhausted, causing the container creation to timeout.
D.The Workbench instance is using an outdated custom image that is not compatible with the latest runtime version.
AnswerA

The container image gcr.io/my-project/my-image:latest does not exist, or the service account used by the Workbench instance does not have storage.objectViewer access to the container registry. This would prevent the instance from pulling the image, causing an UNHEALTHY status.

Why this answer

The UNHEALTHY status in Vertex AI Workbench typically occurs when the instance fails to start its container. Option A is correct because the most likely cause is that the specified container image (gcr.io/my-project/my-image:latest) does not exist in Container Registry, or the service account attached to the instance lacks the storage.objectViewer role on the registry bucket. Without this permission, the instance cannot pull the image, leading to a container creation failure and an UNHEALTHY state.

Options B, C, and D are less likely given the focus on the container image in the exhibit.

Exam trap

Google Cloud often tests the distinction between container image availability/permissions and network-level issues; the trap here is that candidates may assume a firewall or resource exhaustion is the cause, but the exhibit's focus on a specific container image points directly to a missing image or insufficient IAM permissions on the Container Registry.

How to eliminate wrong answers

Option B is wrong because while a firewall blocking egress to gcr.io could cause a pull failure, the exhibit does not mention any firewall rules, and the question asks for the 'most likely' cause based on the exhibit—lack of image existence or permissions is a more common and direct issue. Option C is wrong because Compute Engine resource exhaustion (e.g., CPU/memory) would typically cause a timeout or error during instance creation, not a persistent UNHEALTHY status after the instance is running; Vertex AI Workbench handles resource allocation separately. Option D is wrong because an outdated custom image would likely cause compatibility warnings or startup failures, but the exhibit shows a specific container image reference (gcr.io/my-project/my-image:latest), not a custom image issue; the UNHEALTHY status is tied to container pull failures, not image version mismatches.

755
MCQeasy

A company wants to control which resources can be accessed by a service account in a specific project. Which IAM policy binding approach should be used?

A.Use VPC Service Controls to restrict the service account
B.Grant the service account a role at the project or resource level
C.Add the service account to a Cloud Identity group and grant the group a role
D.Grant the service account a role at the organization level
AnswerB

Binding a role to the service account at the project or specific resource level scopes its permissions precisely, so access is limited to the intended resources. IAM policies attached at those levels define exactly which actions the service account may perform.

Why this answer

Granting the service account a role at the project or resource level follows the principle of least privilege by scoping permissions to only the resources the service account needs to access. This is the standard IAM policy binding approach in Google Cloud for controlling access within a specific project. It avoids over-privileged access and aligns with security best practices.

Exam trap

The trap is choosing organization-level grants or VPC Service Controls because they sound more secure or comprehensive, but the exam expects you to apply least privilege by scoping the role to the project or resource level.

How to eliminate wrong answers

Option A is wrong because VPC Service Controls are used to define security perimeters around Google Cloud services to mitigate data exfiltration risks, not to grant or restrict IAM permissions for a service account. Option C is wrong because adding the service account to a Cloud Identity group and granting the group a role is an indirect method that can work but is not the primary or most direct policy binding approach for scoping access to a specific project — it adds unnecessary complexity and doesn't inherently limit scope to the project. Option D is wrong because granting a role at the organization level gives the service account access to all projects in the organization, violating least privilege and the requirement to restrict access to a specific project.

756
Multi-Selecthard

A company is designing a highly available architecture for a stateful application on Compute Engine. They need to protect against zonal failures. Which THREE steps should they take?

Select 3 answers
A.Store session state in memory
B.Use a global load balancer with health checks
C.Use a single zone instance group
D.Use persistent disks with regional persistent disks
E.Use a managed instance group across multiple zones
AnswersB, D, E

A global external load balancer with health checks distributes traffic across healthy backends in multiple zones, automatically removing instances from a failed zone. This satisfies the zonal-failure requirement by redirecting users to surviving zones without manual intervention.

Why this answer

Option B is correct because a global external Application Load Balancer (or global external proxy Network Load Balancer) with health checks distributes traffic across healthy backends in multiple zones and automatically stops routing to unhealthy instances, providing resilience against a zonal failure. Option D is correct because regional persistent disks synchronously replicate data between two zones in the same region, so a stateful application's data remains available if one zone fails. Option E is correct because a managed instance group (MIG) spread across multiple zones maintains capacity and automatically recreates instances in surviving zones when a zone becomes unavailable.

Option A is wrong because storing session state only in memory ties the state to a single instance and is lost on failure, breaking high availability. Option C is wrong because a single-zone instance group has no protection against a zonal outage.

Exam trap

A common misconception is that in-memory session state (Option A) is sufficient for high availability, but it fails because state is lost on instance failure; instead, external session stores (e.g., Cloud Memorystore or Cloud Spanner) are needed for stateful applications on Google Cloud.

757
MCQeasy

A developer is trying to deploy a Compute Engine instance from a Cloud Build step. The build fails with the above error. What is the problem?

A.The project has exceeded its service account quota.
B.The Cloud Build service account lacks 'compute.instances.create' permission.
C.Cloud Build does not have the 'iam.serviceAccounts.actAs' permission on the default compute service account.
D.The developer's personal account does not have permission to use Cloud Build.
AnswerC

Creating an instance that runs as the default compute service account requires the caller to hold iam.serviceAccounts.actAs on that account. Cloud Build's service account lacks this binding, so the deployment step fails authorisation even though other Compute permissions may be present.

Why this answer

The error occurs because Cloud Build needs to impersonate the Compute Engine default service account to create a VM instance. The Cloud Build service account requires the 'iam.serviceAccounts.actAs' permission on the target service account to delegate its identity. Without this permission, the build step fails even if the Cloud Build service account has 'compute.instances.create' permission.

Exam trap

Google Cloud often tests the subtle distinction between having resource-level permissions (like 'compute.instances.create') and the 'actAs' permission required to impersonate a service account, leading candidates to incorrectly choose the missing resource permission.

How to eliminate wrong answers

Option A is wrong because service account quotas are separate from IAM permissions; exceeding a quota would produce a different error (e.g., 'quota exceeded'), not a permission denied error. Option B is wrong because the error message specifically indicates an 'actAs' permission issue, not a missing 'compute.instances.create' permission; if that were the problem, the error would reference 'compute.instances.create' directly. Option D is wrong because Cloud Build uses its own service account for execution, not the developer's personal account; the error is about the Cloud Build service account's permissions, not the developer's.

758
MCQeasy

A developer needs to grant a Compute Engine instance the ability to read from a Cloud Storage bucket. The instance does not have a service account attached. What should the developer do?

A.Create a service account and assign it the Storage Object Viewer role, then attach the service account to the instance.
B.Add the instance's external IP to the bucket permissions.
C.Generate a JSON key for a user account and store it on the instance.
D.Create a firewall rule to allow access to Cloud Storage.
AnswerA

A service account supplies the identity the instance lacks; granting it roles/storage.objectViewer authorises reads from the bucket, and attaching it to the instance lets applications obtain credentials automatically via the metadata server. Without an attached service account, no workload identity exists to authorise the request.

Why this answer

A Compute Engine instance must have a service account attached to obtain Google Cloud credentials for API calls. The developer should create a service account, grant it the Storage Object Viewer role (or a custom role with storage.objects.get/list), and attach it to the instance. The instance can then use the metadata server to obtain short-lived tokens and read the bucket.

Exam trap

PCA often tests whether candidates confuse network-level controls (firewall rules, external IPs) with IAM authorization, or recommend insecure JSON keys instead of attaching a service account.

How to eliminate wrong answers

Option B is wrong because Cloud Storage IAM does not grant access based on an instance's external IP address; IP-based rules apply to firewall rules, not bucket IAM. Option C is wrong because generating a JSON key for a user account and storing it on the instance is an insecure anti-pattern that violates least privilege and key management best practices. Option D is wrong because firewall rules control network traffic to VMs, not IAM authorization to Cloud Storage APIs.

759
MCQmedium

Your team operates a production e-commerce application on a managed instance group (MIG) that serves traffic through a global external Application Load Balancer. During a new release, the team wants to deploy the new version to a small subset of instances and then progressively increase traffic to it while monitoring error rates, with the ability to immediately roll back if errors spike. The new version is already built as a custom image. Which approach should you use?

A.Create a new global external Application Load Balancer with a separate backend service pointing only to the new image, and use Cloud DNS weighted routing to send 10% of users to the new load balancer.
B.Create a second MIG with the new image, add it as a backend to the existing backend service with a small capacity, and gradually shift traffic between the two MIGs using weighted traffic distribution in the backend service.
C.Perform an in-place update of the MIG template to the new image with a very small maxUnavailable, and rely on the load balancer health checks to remove unhealthy instances automatically.
D.Use a rolling update with maxSurge and maxUnavailable set to 50% so that half the instances are replaced at once, then wait for health checks to pass before continuing.
AnswerB

Weighted traffic distribution on a backend service lets you send a controlled percentage of user traffic to a new MIG while keeping the rest on the stable version. Monitoring error rates and adjusting weights gives progressive rollout and instant rollback by setting the new backend weight to zero. This matches canary release requirements without rebuilding instances.

Why this answer

The requirement is a controlled canary with progressive traffic shifting and fast rollback. Weighted traffic distribution on a backend service allows two MIGs, each running a different image, to receive defined percentages of live traffic. You can start small, watch error rates, increase the weight, and set it back to zero if problems appear.

Other approaches either replace instances in place or rely on DNS, which lacks the precision and quick reversibility needed.

Exam trap

The trap here is assuming that a rolling update with maxSurge and maxUnavailable is equivalent to a canary release, when rolling updates replace instances in place and cannot route a precise percentage of user traffic to a new version.

760
MCQhard

An analytics team runs a batch pipeline that reads several terabytes of data from a Cloud Storage bucket in us-central1 every night. To reduce egress and improve throughput, they decide to run the pipeline on Compute Engine VMs in the same region and want the traffic to stay on Google's internal network without traversing the public internet. They also want the VMs to reach Google APIs such as Cloud Storage and BigQuery. Which configuration should the architect recommend?

A.Configure the VMs without external IPs and enable Private Google Access on the subnet
B.Assign external IP addresses to the VMs and rely on default internet routing to reach Google APIs
C.Deploy a NAT gateway on a separate VM and route all API traffic through it
D.Create a VPC peering connection between the project and the googleapis.com service project
AnswerA

Private Google Access allows VMs with only internal IP addresses to reach Google APIs and services through internal routing, keeping traffic off the public internet. This satisfies both the private connectivity goal and the requirement to access Cloud Storage and BigQuery from the same-region VMs without assigning external addresses.

Why this answer

Private Google Access on the subnet is the supported mechanism that lets VMs with internal-only addresses reach Google APIs and services over Google's internal network. Because the VMs and the Cloud Storage bucket are in the same region, this configuration also keeps traffic local, reduces public internet exposure, and avoids the cost and complexity of NAT gateways or external IP addresses.

Exam trap

The trap here is conflating internet access for VMs with private access to Google APIs, when Private Google Access specifically enables the latter without external IPs.

761
Multi-Selecthard

Which THREE Google Cloud services can be used to implement a zero-trust architecture for network security? (Choose three.)

Select 3 answers
A.Cloud Armor
B.Access Context Manager (ACM)
C.Identity-Aware Proxy (IAP)
D.VPC Networks
E.Cloud VPN
AnswersA, B, C

Cloud Armor provides WAF and DDoS protection at the edge, enforcing security policies.

Why this answer

Cloud Armor is correct because it provides web application firewall (WAF) and DDoS protection at the edge of Google's network, enforcing security policies based on IP addresses, geo-locations, and Layer 7 attributes. This aligns with zero-trust principles by inspecting and filtering traffic before it reaches the application, ensuring that only authorized requests are allowed, regardless of the network perimeter.

Exam trap

The trap here is that candidates often confuse network-level connectivity services (like VPC Networks and Cloud VPN) with security controls, mistakenly thinking that encrypting traffic or segmenting networks alone satisfies zero-trust requirements, when zero-trust actually demands identity- and context-aware access enforcement at the application layer.

762
Multi-Selectmedium

A company is designing a disaster recovery strategy for a Cloud SQL for PostgreSQL database with a Recovery Point Objective (RPO) of 1 hour and a Recovery Time Objective (RTO) of 2 hours. They are using the Regional Cloud SQL tier. Which TWO actions should they take? (Choose TWO.)

Select 2 answers
A.Increase the number of CPUs on the primary instance.
B.Create a read replica in the same region.
C.Configure cross-region replication by creating a cross-region replica.
D.Enable deletion protection on the database.
E.Enable automated backups and point-in-time recovery.
AnswersC, E

A cross-region replica continuously replicates data to a different region, giving an RPO well under one hour and enabling promotion within the two-hour RTO. This satisfies both objectives when the primary region fails, unlike same-region options that cannot survive regional outages.

Why this answer

Option C is correct because a cross-region replica protects against a regional outage, which the Regional tier alone cannot survive; promoting the cross-region replica gives a failover target that can meet the 2-hour RTO, and Cloud SQL's asynchronous replication keeps replica lag well within the 1-hour RPO. Option E is correct because automated backups combined with point-in-time recovery let you restore the instance to any moment within the retention window (transaction logs are retained, typically up to 7 days by default), which is essential for recovering from data corruption or accidental deletion within the 1-hour RPO. Option A is not correct because adding CPUs only improves performance and does not provide any recovery capability or reduce RPO/RTO.

Option B is not correct because a read replica in the same region shares the same regional failure domain as the primary, so it cannot satisfy a disaster recovery strategy for a regional outage. Option D is not correct because deletion protection only prevents accidental instance deletion; it does not provide backup, replication, or recovery capability to meet the stated RPO and RTO.

763
MCQeasy

A service account needs to be able to start and stop Compute Engine instances in a specific project. Which IAM role should be assigned at the project level?

A.roles/iam.serviceAccountUser
B.roles/editor
C.roles/compute.viewer
D.roles/compute.instanceAdmin.v1
AnswerD

roles/compute.instanceAdmin.v1 grants permissions to start, stop, reset and manage Compute Engine instances, including instance-level operations, at the project scope. That matches the requirement precisely, unlike narrower roles such as compute.viewer or instance-specific permissions that omit start and stop.

Why this answer

Roles/compute.instanceAdmin.v1, because this role grants the necessary permissions to start, stop, and manage Compute Engine instances, including operations like instances.start and instances.stop, at the project level. This role is specifically designed for managing compute resources without granting broader project-level access like editing all resources.

Exam trap

Google Cloud often tests the distinction between primitive roles (like roles/editor) and predefined roles (like roles/compute.instanceAdmin.v1), where candidates mistakenly choose the broader role due to its apparent convenience, overlooking the principle of least privilege and the specific permissions required for the task.

How to eliminate wrong answers

Option A is wrong because roles/iam.serviceAccountUser grants permission to impersonate service accounts, not to manage Compute Engine instances; it allows attaching a service account to a resource but does not include compute.instance.start or compute.instance.stop. Option B is wrong because roles/editor is a broad, primitive role that grants full edit access to all resources in the project, including Compute Engine, but it violates the principle of least privilege by providing excessive permissions beyond what is needed for instance management. Option C is wrong because roles/compute.viewer only provides read-only permissions to view Compute Engine resources (e.g., compute.instances.list, compute.instances.get) and does not include any write or action permissions like starting or stopping instances.

764
Multi-Selecteasy

A development team uses BigQuery for analytical queries. They want to reduce query costs for a large table that is frequently filtered by a date column and a customer_id column. Which TWO table design strategies will reduce the amount of data scanned? (Choose 2)

Select 2 answers
A.Partition the table by date.
B.Create an index on customer_id.
C.Use wildcard tables with date suffixes.
D.Normalize the table into multiple tables.
E.Cluster the table on customer_id.
AnswersA, E

Partitioning by date divides the table into segments, so queries filtering on the date column prune irrelevant partitions and scan only matching ones. This directly reduces bytes scanned, satisfying the cost-reduction goal for date-filtered analytical queries.

Why this answer

Option A is correct because partitioning the table by the date column means BigQuery only scans the partitions that match the query's date filter, dramatically reducing bytes processed for date-filtered queries. Option E is correct because clustering on customer_id physically sorts and co-locates data by that column, so filters on customer_id prune blocks within partitions and further cut data scanned. Together, partitioning by date and clustering by customer_id directly address the two frequent filter columns in this scenario.

Option B is incorrect because BigQuery does not support traditional secondary indexes on columns like customer_id; clustering is the equivalent mechanism. Option C is incorrect because wildcard tables with date suffixes are a query-time convenience for sharding, not a table design that reduces scanned data by itself. Option D is incorrect because normalizing into multiple tables does not inherently reduce bytes scanned and may even require more joins and data reads.

765
Multi-Selectmedium

A logistics company is deploying a new three-tier application on Google Cloud. The architecture team must choose a managed database for the order-processing tier that provides automatic failover across zones with no application connection string changes, and they must also ensure that the database can scale read traffic independently of writes. (Choose two.)

Select 2 answers
A.Use Cloud SQL for PostgreSQL with a regional instance and a high-availability configuration.
B.Attach read replicas to the Cloud SQL instance to serve read-heavy reporting queries.
C.Use a Memorystore for Redis instance as the primary order database and persist snapshots to Cloud Storage.
D.Use Cloud SQL for MySQL with a single-zone instance and configure a read replica in another zone for failover.
E.Use Cloud Spanner with a regional configuration and rely on its built-in replication for failover.
AnswersA, B

A regional Cloud SQL instance maintains a standby in a second zone and performs automatic failover to it if the primary zone fails, while the application keeps using the same connection endpoint. This satisfies the automatic cross-zone failover and no connection string change requirement, and read replicas can be added separately to offload read traffic.

Why this answer

A regional Cloud SQL instance with high availability keeps a standby in a second zone and fails over automatically while the application continues using the same connection endpoint. Adding read replicas lets reporting and read-heavy queries run against separate copies, scaling reads independently of writes. Together these two choices meet the failover, connection stability, and read-scaling requirements without over-engineering the deployment.

Exam trap

The trap here is confusing asynchronous read replicas with a synchronous high-availability standby, so a replica is mistakenly treated as an automatic failover target.

766
Multi-Selecthard

Your company wants to implement a canary deployment for a microservice running on GKE. You need to gradually shift traffic from the stable version to the canary version while monitoring error rates. Which THREE components or practices should you use? (Choose 3)

Select 3 answers
A.Cloud Deploy with an automated canary strategy and verification
B.Cloud Monitoring to track error rates and trigger rollback
C.Cloud CDN for caching responses
D.Feature flags in the application code
E.Istio for traffic splitting between versions
AnswersA, B, E

Cloud Deploy's automated canary strategy progressively shifts traffic percentages between GKE revisions and runs verification steps, halting or rolling back when analysis fails. It directly provides the staged rollout and metric-gated promotion the scenario demands.

Why this answer

Option A is correct because Cloud Deploy natively supports canary deployment strategies with configurable phases (for example, 50% then 100%) and automated verification that can advance or halt a rollout based on analysis results. Option B is correct because Cloud Monitoring collects the error-rate metrics (such as HTTP 5xx ratios from the service) that Cloud Deploy's verification step or alerting policies use to detect failures and trigger a rollback. Option E is correct because Istio on GKE provides fine-grained traffic splitting via VirtualService weights, letting you shift a precise percentage of requests from the stable to the canary version while observing behavior.

Option C is not appropriate because Cloud CDN caches responses at the edge and does not perform version-based traffic shifting or canary analysis. Option D is not appropriate because feature flags toggle functionality inside a single deployed version and do not by themselves implement gradual traffic shifting between two separately deployed versions.

Exam trap

PCA often tests the confusion between feature flags and canary deployments; candidates pick feature flags because they sound like gradual rollout, but feature flags do not shift traffic between deployed versions.

767
MCQeasy

A company stores sensitive data in Cloud Storage and wants to enforce encryption at rest using customer-managed keys. Which Google Cloud service should they use to manage the keys?

A.Cloud HSM
B.Secret Manager
C.Cloud KMS
D.IAM
AnswerC

Cloud KMS provides customer-managed encryption keys (CMEK) that satisfy the requirement for encryption at rest with keys the company controls. It integrates directly with Cloud Storage, letting you manage key rotation, IAM permissions and audit logging through a centralised keyring, rather than relying on Google-managed keys.

Why this answer

Cloud KMS (Key Management Service) is the correct choice because it is the native Google Cloud service for managing cryptographic keys, including customer-managed encryption keys (CMEK). It allows you to create, rotate, and control access to keys used to encrypt data at rest in Cloud Storage, and it integrates directly with Cloud Storage's CMEK feature. Cloud HSM is a hardware-backed key management option but is built on top of Cloud KMS, not a separate service for key management.

Exam trap

The trap here is that candidates confuse Cloud HSM as a separate key management service, but Cloud HSM is actually a hardware-backed key storage option that requires Cloud KMS for key management, not a replacement for it.

How to eliminate wrong answers

Option A is wrong because Cloud HSM is a hardware security module service that provides FIPS 140-2 Level 3 validated key storage, but it is an add-on to Cloud KMS, not a standalone key management service; you still use Cloud KMS to manage the keys stored in HSM. Option B is wrong because Secret Manager is designed to store and manage secrets such as API keys, passwords, and certificates, not for managing encryption keys used for data at rest in Cloud Storage. Option D is wrong because IAM (Identity and Access Management) is a service for managing access control and permissions, not for creating, storing, or managing encryption keys.

768
MCQhard

An organization wants to export their Cloud Logging logs to a centralized BigQuery dataset for long-term analysis. They also need to exclude logs from a specific source (e.g., a test project) to reduce costs. How should they set this up?

A.Disable logging in the test project
B.Create a log sink to BigQuery and add a log exclusion filter that excludes the test project's logs
C.Create two separate sinks: one for production logs to BigQuery and another for test logs to Cloud Storage
D.Create a log sink to BigQuery and use IAM to restrict access to the test project's logs
AnswerB

A log sink routes matching entries to the BigQuery dataset, while the exclusion filter prevents the test project's logs from being exported at all, so they are never billed for BigQuery ingestion or storage. Both the destination and the cost-reducing exclusion are satisfied in one sink configuration.

Why this answer

A log sink to BigQuery with an exclusion filter is the correct way to export logs to a centralized dataset while excluding logs from a specific source. The exclusion filter is applied at the sink level, so logs from the test project are not exported, reducing costs. This setup can be created at the organization level to aggregate logs from multiple projects.

Exam trap

The trap is thinking that IAM or separate sinks can exclude logs from export; only a sink exclusion filter prevents logs from being written to the destination, which is what reduces cost.

How to eliminate wrong answers

Option A is wrong because disabling logging in the test project stops all logging there, which may be undesirable and does not centralize logs. Option B is wrong because creating two separate sinks does not exclude test logs from BigQuery; it just routes them elsewhere, and the question asks to exclude them to reduce costs. Option D is wrong because IAM restricts access to logs but does not prevent them from being exported and stored in BigQuery, so costs are not reduced.

769
MCQmedium

Your organization runs a microservices application on Google Kubernetes Engine (GKE). You need to ensure that the application can be rolled back quickly if a new deployment causes errors. You want to use a deployment strategy that allows you to shift traffic back to the previous version with minimal downtime. Which approach should you use?

A.Use a blue/green deployment by creating a new deployment with the new version, then switch the Service selector to point to the new version's pods. To roll back, switch the selector back.
B.Use a canary deployment by creating a new deployment with a small number of replicas, then gradually increase traffic to the new version using Istio. To roll back, delete the canary deployment.
C.Use a rolling update with a large maxSurge and maxUnavailable, and set the revisionHistoryLimit to a high value so you can roll back using kubectl rollout undo.
D.Use a Recreate strategy by setting the deployment strategy to Recreate, which terminates all old pods before creating new ones. To roll back, redeploy the previous version.
AnswerA

Blue/green deployment involves running two identical environments (blue and green). You deploy the new version to the green environment, test it, then switch traffic by updating the Service selector. If issues arise, you can quickly revert by switching the selector back to the blue environment. This provides near-instant rollback with minimal downtime, as both environments are already running.

Why this answer

Blue/green deployment allows you to have both versions running simultaneously. By switching the Service selector, you can instantly direct traffic to the new version or back to the old version. This provides minimal downtime and quick rollback.

Other strategies like rolling update or canary may involve gradual traffic shifts and take longer to roll back, while Recreate causes downtime.

Exam trap

The trap here is assuming that rolling updates with kubectl rollout undo provide instant rollback, but they require recreating old pods, which takes time.

770
MCQmedium

An application running on Compute Engine frequently makes connection requests to a Cloud SQL for PostgreSQL instance. The connections are short-lived and many are created per second. What should be implemented to reduce latency and connection overhead?

A.Deploy PgBouncer on the application server or as a sidecar
B.Increase the number of vCPUs on the Cloud SQL instance
C.Enable connection scaling in Cloud SQL
D.Use Cloud SQL Auth Proxy with private IP
AnswerA

PgBouncer pools and reuses backend connections, so many short-lived client connections multiplex onto a small set of persistent Cloud SQL connections. This removes per-request connection setup overhead, directly addressing the stem's high connection rate and latency constraint.

Why this answer

Connection pooling reuses database connections instead of creating new ones for each request. PgBouncer is a lightweight connection pooler for PostgreSQL. Cloud SQL Auth Proxy is for secure connections but does not pool.

771
MCQhard

An e-commerce platform uses Cloud Spanner for order processing. Recently, latency spikes have occurred during flash sales. The team suspects hot spots due to monotonically increasing order IDs. Which table design change would best solve this?

A.Remove the primary key and let Spanner auto-generate it.
B.Use interleaved tables to store orders under customers.
C.Add a random prefix to the order ID primary key.
D.Create a secondary index on the timestamp column.
AnswerC

Randomising the leading key bytes spreads sequential inserts across multiple Spanner splits, eliminating the hot spot caused by monotonically increasing order IDs during flash sales. This directly addresses the stem's constraint: write contention concentrated on the trailing split. Range scans by order ID still work, though they now require prefix-aware query design.

Why this answer

Monotonically increasing primary keys (like sequential order IDs) cause hot spots in Cloud Spanner because all writes are directed to a single split (tablet), overwhelming that node. Adding a random prefix (e.g., a hash of the customer ID) distributes writes across multiple splits, eliminating the hot spot and reducing latency spikes during high-throughput flash sales.

Exam trap

Google Cloud often tests the misconception that secondary indexes or interleaved tables can fix write hot spots, when in reality only primary key distribution strategies (like hash prefixes) address the root cause of split-level contention.

How to eliminate wrong answers

Option A is wrong because removing the primary key and relying on auto-generation still produces monotonically increasing values (e.g., Spanner's auto-generated keys are sequential), which does not solve the hot spot issue. Option B is wrong because interleaved tables organize child rows under a parent row, but if the parent key is monotonically increasing, writes still concentrate on the same split, failing to distribute load. Option D is wrong because a secondary index on the timestamp column does not affect the distribution of primary key writes; it only helps query performance, not write hot spots.

772
MCQmedium

An e-commerce application uses Firestore for product catalog. They need to run complex analytical queries on the catalog data, such as aggregations and joins, without impacting production performance. What is the best approach?

A.Create a second Firestore database for analytics
B.Use Cloud SQL to query Firestore directly
C.Use Firestore `!=` operator to filter data
D.Export Firestore data to BigQuery for analytics
AnswerD

Exporting Firestore data to BigQuery satisfies the isolation constraint: BigQuery runs aggregations and joins on a columnar engine, separate from Firestore's document-oriented production workload. Firestore natively lacks joins and efficient aggregation, so offloading analytics prevents read contention and preserves catalog latency.

Why this answer

The best approach is to export Firestore data to BigQuery for analytics. BigQuery is a columnar, serverless analytics warehouse designed for aggregations and joins at scale, and it can query exported Firestore data without touching the production Firestore instance. This isolates analytical workloads from production traffic and provides the SQL capabilities Firestore lacks.

Exam trap

PCA often tests the misconception that Firestore can be queried like a relational database, tempting candidates to pick a second Firestore database or Cloud SQL federation instead of the correct export-to-BigQuery pattern.

How to eliminate wrong answers

Option A is wrong because creating a second Firestore database still leaves you with a document store that cannot perform efficient aggregations or joins, and it duplicates operational overhead without solving the analytical query problem. Option B is wrong because Cloud SQL cannot query Firestore directly — they are separate database engines with no native query federation. Option C is wrong because the Firestore `!=` operator is a simple inequality filter, not an analytical capability; it cannot perform aggregations or joins and would still run against production.

773
Multi-Selecthard

Your company is designing a secure architecture for a new application on Google Cloud. They need to ensure that service accounts used by the application have only the necessary permissions, and that any use of those service accounts is auditable. Which two actions should they take? (Choose two.)

Select 2 answers
A.Create a custom role that includes all permissions the application might need in the future, to avoid frequent updates.
B.Use service account keys and rotate them every 90 days to ensure secure authentication.
C.Assign the service accounts the Project Editor role to simplify permission management.
D.Grant the service accounts predefined roles that include only the required permissions, and avoid using basic roles like Editor.
E.Enable Data Access audit logs for all services used by the application to capture service account activity.
AnswersD, E

Using predefined roles that contain only the necessary permissions follows the principle of least privilege. Basic roles like Editor grant broad permissions across many services, violating least privilege. This action reduces the risk of excessive access and is a recommended practice for secure architecture.

Why this answer

Least privilege is achieved by granting only the necessary predefined roles and avoiding basic roles. Auditability of service account usage requires enabling Data Access audit logs, which are not enabled by default. Together, these actions ensure that service accounts have minimal permissions and that their actions are logged for auditing.

Exam trap

The trap here is assuming that Admin Activity audit logs capture all service account usage, when Data Access logs are needed for read/write operations.

774
MCQmedium

A company uses Cloud Logging to monitor their application logs. They notice that some logs from their Compute Engine instances are missing. The instances have the required logging permission. What is the most likely cause?

A.The log sink is not configured correctly.
B.The logging agent is not configured to send logs to Cloud Logging.
C.The instances are using a custom image without the logging agent.
D.The log bucket is in a different project.
E.The log entries are being filtered by the exclusion filter.
AnswerB

Compute Engine instances need the Cloud Logging agent installed and configured to forward logs; permissions alone do not transmit them. Without that agent configuration, logs remain local and never reach Cloud Logging, explaining the missing entries despite adequate IAM permissions.

Why this answer

Compute Engine instances do not automatically send logs to Cloud Logging. They require the Cloud Logging agent (based on fluentd) to be installed and configured to forward logs. Even with correct IAM permissions, without the agent, logs will not be collected.

Option B correctly identifies this missing agent as the most likely cause.

Exam trap

Google Cloud often tests the distinction between log collection (agent) and log routing (sinks) — the trap here is that candidates assume IAM permissions alone are sufficient, overlooking the mandatory agent installation and configuration step.

How to eliminate wrong answers

Option A is wrong because a log sink controls where logs are routed (e.g., to BigQuery or Pub/Sub), not whether logs are collected from instances; missing logs are a collection issue, not a routing issue. Option C is wrong because while a custom image might lack the agent, the question states the instances have the required logging permission, implying the agent could be installed separately; the most likely cause is the agent not being configured, not the image itself. Option D is wrong because log buckets in a different project would still receive logs if the sink is configured correctly; the issue is logs not appearing at all, not appearing in the wrong project.

Option E is wrong because exclusion filters remove logs after they are ingested; if logs are missing entirely, they were never ingested, so exclusion is not the cause.

775
Multi-Selecteasy

A cloud architect needs to implement a CI/CD pipeline for a team developing a Python-based microservice. The team uses GitHub as their source repository. The pipeline should automatically run unit tests and deploy the service to Cloud Run when changes are pushed to the main branch. Which THREE Google Cloud services should they use?

Select 3 answers
A.Artifact Registry
B.Cloud Run
C.Cloud Deploy
D.Cloud Source Repositories
E.Cloud Build
AnswersA, B, E

Artifact Registry stores the container images built from the Python microservice, providing the repository Cloud Run pulls from during deployment. It satisfies the pipeline's need for a managed Docker image store integrated with Cloud Build, distinct from source hosting in GitHub and from Cloud Run's runtime itself.

Why this answer

Cloud Build (E) is the correct CI/CD engine here: it can be triggered by GitHub pushes to the main branch, run the Python unit tests in a build step, and then deploy the resulting container to Cloud Run. Artifact Registry (A) is needed to store and version the container images that Cloud Build builds, since Cloud Run pulls its images from a registry rather than building them itself. Cloud Run (B) is the target compute platform for the microservice, hosting the containerized Python service that the pipeline deploys.

Cloud Deploy (C) is not required because it is a managed continuous-delivery service for GKE and Cloud Run that adds release/pipeline abstractions, which is unnecessary for this simple test-and-deploy flow. Cloud Source Repositories (D) does not belong because the team already uses GitHub as its source repository, so a second Google-hosted Git repo is redundant.

Exam trap

PCA often tests whether candidates over-engineer the pipeline by including Cloud Deploy or Cloud Source Repositories — the trap is adding tools that are not required for the stated GitHub-to-Cloud-Run flow.

776
MCQhard

An organization runs workloads in multiple Google Cloud projects and wants a single, consistent way to detect and respond to threats such as compromised service accounts and anomalous API calls across all of them. The security operations team needs findings aggregated in one place and wants to reduce the effort of correlating events from Cloud Audit Logs, VPC Flow Logs, and Cloud DNS logs. Which Google Cloud service should the architect recommend?

A.VPC Service Controls perimeters around each project with access levels tied to the corporate network.
B.Cloud Logging with log-based metrics and alerting policies that trigger when error rates exceed a threshold.
C.Security Command Center with the Premium tier enabled at the organization level, using its built-in detectors and Event Threat Detection.
D.Cloud Monitoring dashboards combined with uptime checks on each project's API endpoints.
AnswerC

Security Command Center Premium aggregates findings at the organization level across all projects. Event Threat Detection analyzes Cloud Audit Logs, VPC Flow Logs, and Cloud DNS logs to surface issues like compromised service accounts and anomalous API activity, providing a single consolidated view and reducing manual correlation, which matches the stated need.

Why this answer

Security Command Center Premium is the centralized security posture and threat detection service for Google Cloud. Enabled at the organization level, it continuously evaluates resources across projects and Event Threat Detection consumes Cloud Audit Logs, VPC Flow Logs, and Cloud DNS logs to identify compromised service accounts, anomalous API calls, and similar threats, consolidating findings so the security operations team does not have to correlate sources manually.

Exam trap

The trap here is assuming that log-based metrics, monitoring dashboards, or preventive perimeter controls provide built-in cross-project threat detection, which only Security Command Center Premium delivers.

777
MCQmedium

A company uses Cloud Deployment Manager to manage infrastructure. They want to roll back to a previous deployment state after a failed update. What is the recommended approach?

A.Use gcloud deployment-manager deployments rollback --deployment <name>
B.Use the --update-policy=PARTIAL flag to selectively revert changes
C.Delete the deployment and recreate it from the previous template
D.Run gcloud deployment-manager deployments update --config <previous_manifest>
AnswerD

Redeploying the previous manifest restores the last known-good configuration, satisfying the rollback requirement after a failed update. Deployment Manager is declarative, so reapplying the prior manifest reconciles resources back to that state rather than attempting an in-place undo.

Why this answer

Cloud Deployment Manager does not provide a native rollback command; the documented way to revert to a prior state is to re-run an update using the previous configuration and manifest files. Running 'gcloud deployment-manager deployments update --config <previous_manifest>' reapplies the earlier desired state, effectively rolling the deployment back to that point.

Exam trap

PCA often tests whether candidates invent CLI subcommands — the trap is assuming a 'rollback' verb exists because other tools have one, when Deployment Manager requires re-applying a prior manifest.

How to eliminate wrong answers

Option A is wrong because there is no 'rollback' subcommand in the gcloud deployment-manager CLI — this command does not exist and would fail. Option B is wrong because '--update-policy=PARTIAL' is not a valid rollback mechanism; update policies control how resources are previewed or applied, not how to revert to a prior state. Option C is wrong because deleting and recreating the deployment destroys resource history and can cause downtime or orphaned resources, and it is not the recommended approach.

778
MCQmedium

A company wants to migrate on-premises workloads to Google Cloud. They need to assess the existing infrastructure, plan the migration, and track progress. Which tool should they use?

A.Cloud Endpoints.
B.Cloud Deployment Manager.
C.Cloud Foundation Toolkit.
D.Migrate for Compute Engine.
AnswerD

Provides assessment and migration capabilities.

Why this answer

Migrate for Compute Engine (formerly Velostrata) is the correct tool because it is specifically designed to assess, plan, and migrate on-premises workloads to Google Cloud. It provides discovery of existing infrastructure, generates migration plans, and tracks progress through a dashboard, directly addressing the need for assessment, planning, and tracking.

Exam trap

The trap here is that candidates may confuse Cloud Foundation Toolkit (a foundation setup tool) with a migration tool, or assume Cloud Deployment Manager can handle migration planning, when in fact only Migrate for Compute Engine provides the full assessment-to-tracking workflow.

How to eliminate wrong answers

Option A is wrong because Cloud Endpoints is an API management service for securing and monitoring APIs, not a migration assessment or planning tool. Option B is wrong because Cloud Deployment Manager is an infrastructure-as-code tool for deploying Google Cloud resources using templates, not for assessing or migrating on-premises workloads. Option C is wrong because Cloud Foundation Toolkit provides Terraform templates and best practices for setting up a Google Cloud foundation (e.g., projects, networking), but it does not include discovery, assessment, or migration tracking for existing on-premises workloads.

779
MCQmedium

An organization deploys a web application on Compute Engine behind a global HTTPS load balancer. They want to reduce latency for users worldwide and minimize load on backend instances. Which GCP service should they use?

A.Cloud Armor
B.Cloud NAT
C.Cloud CDN
D.VPC Network Peering
AnswerC

Cloud CDN caches content at Google's globally distributed edge points of presence, serving repeated requests close to users. This directly reduces latency for worldwide users and offloads origin traffic, satisfying the requirement to minimise load on the Compute Engine backend instances behind the global HTTPS load balancer.

Why this answer

Cloud CDN uses Google's global edge caches to serve content closer to users, reducing latency and backend load. Cloud Armor provides security, Cloud NAT is for outbound connectivity, and VPC peering is for network connectivity, not caching.

780
MCQmedium

An e-commerce company uses Cloud SQL for MySQL for its transactional database. They need to run complex analytical queries on the same data without impacting OLTP performance. The analytical queries should be run on a read replica with minimal lag. Which solution is BEST?

A.Use Data Studio directly on Cloud SQL primary instance
B.Migrate to Cloud Spanner to handle both workloads
C.Create a Cloud SQL read replica and run analytical queries on it
D.Export the database to BigQuery and run queries there
AnswerC

A Cloud SQL read replica receives asynchronous replication from the primary, so analytical queries execute on separate compute and storage, leaving the primary's OLTP capacity untouched. Replication lag is typically seconds, satisfying the minimal-lag requirement while isolating the analytical workload.

Why this answer

Creating a Cloud SQL read replica allows you to offload analytical queries to a separate instance that replicates from the primary using MySQL's native asynchronous replication. This isolates the OLTP workload from heavy analytical queries, and with proper configuration (e.g., using a higher machine type and enabling InnoDB buffer pool tuning on the replica), you can achieve minimal replication lag. The read replica supports the same MySQL engine, so complex analytical queries run without schema changes or data movement.

Exam trap

Candidates often mistakenly think exporting to BigQuery is the best solution for analytics on Cloud SQL data, but the trap is that the question explicitly requires 'minimal lag' and 'without impacting OLTP performance,' which a read replica achieves directly, whereas BigQuery introduces data movement delays and pipeline complexity.

How to eliminate wrong answers

Option A is wrong because Data Studio is a visualization tool, not a query engine; running analytical queries directly on the Cloud SQL primary instance would compete for CPU, memory, and I/O with OLTP transactions, causing performance degradation. Option B is wrong because Cloud Spanner is a globally distributed, strongly consistent relational database designed for horizontal scaling, not for running complex analytical queries on the same data without impacting OLTP; it also requires schema and application changes, and does not provide a read replica for analytics. Option D is wrong because exporting the database to BigQuery introduces significant latency (data must be exported, transformed, and loaded), and the export process itself can impact the primary instance's performance; it also requires managing a separate pipeline and does not provide near-real-time analytics with minimal lag.

781
MCQmedium

A company is migrating a 200 TB on-premises file server to Cloud Storage. The network bandwidth is limited to 100 Mbps. The migration must complete within 30 days. Which approach should they use?

A.Use Storage Transfer Service from another cloud
B.Use gsutil rsync over the network
C.Use Cloud Data Fusion
D.Use Transfer Appliance
AnswerD

At 100 Mbps, transferring 200 TB over the network would take roughly 200 days, far exceeding the 30-day deadline. Transfer Appliance ships data physically via a rackable appliance, sidestepping the bandwidth constraint and completing the migration within the required window.

Why this answer

Transfer Appliance is a physical device shipped to the customer, loaded with data, and shipped back to Google, making it ideal for large datasets (200 TB) over limited bandwidth (100 Mbps). At 100 Mbps, transferring 200 TB would take far longer than 30 days, so a physical transfer method is required.

Exam trap

PCA often tests whether candidates can calculate transfer time versus bandwidth; the trap is choosing an online transfer tool without realizing that 200 TB over 100 Mbps cannot meet a 30-day deadline.

How to eliminate wrong answers

Option A is wrong because Storage Transfer Service from another cloud is designed for online transfers between cloud storage systems and is still constrained by network bandwidth. Option B is wrong because gsutil rsync over the network is also limited by the 100 Mbps link and would take months for 200 TB. Option C is wrong because Cloud Data Fusion is a data integration service for ETL pipelines, not a bulk migration tool for file servers.

782
Multi-Selecthard

A media company is designing a hybrid architecture that connects its on-premises data center to a Google Cloud VPC. The company needs high-bandwidth, low-latency, private connectivity that does not traverse the public internet, and it wants redundancy so that a single link failure does not interrupt traffic. The architect is evaluating interconnect options. Which two characteristics apply to Dedicated Interconnect in this scenario? (Choose two.)

Select 2 answers
A.It can be created entirely over the public internet using IPsec tunnels between the customer gateway and a Cloud VPN gateway.
B.It automatically encrypts all traffic with MACsec at the link layer without any customer configuration.
C.It requires the customer to establish a minimum of two Interconnect attachments in different edge availability domains to achieve 99.99% availability.
D.It provides a direct physical connection between the customer's network and Google's network at a supported colocation facility.
E.It is provisioned through a third-party service provider that already has connectivity to Google, without the customer needing colocation space.
AnswersC, D

Google's 99.99% availability SLA for Dedicated Interconnect requires at least two attachments in two different edge availability domains, which map to distinct Google network locations. A single attachment provides 99.9% at best and represents a single point of failure. This redundancy requirement matches the company's goal of surviving a single link failure.

Why this answer

Dedicated Interconnect provides a private physical connection at a supported colocation facility and offers a 99.99% SLA only when at least two attachments are placed in different edge availability domains. Partner Interconnect, HA VPN, and automatic MACsec encryption describe different products or optional features, so they do not accurately characterize Dedicated Interconnect for this hybrid design.

Exam trap

The trap here is conflating Dedicated Interconnect with Partner Interconnect, or assuming traffic on a dedicated circuit is encrypted by default when MACsec must be configured explicitly.

783
MCQmedium

A security engineer wants to ensure that all admin activity in their GCP organization is logged and retained for 3 years. They also need to be alerted if a new firewall rule is created. Which logs should they enable?

A.Data Access audit logs
B.Admin Activity audit logs
C.VPC flow logs
D.Cloud DNS logging
AnswerB

Admin Activity audit logs record configuration and administrative changes, including firewall rule creation, and are always enabled. Routing them to a log bucket with a three-year retention lock preserves the history, while log-based alerts fire when a new firewall rule appears.

Why this answer

Admin Activity audit logs record all administrative actions that modify configuration or metadata in GCP, including creating firewall rules, changing IAM policies, and modifying resources. They are always enabled and retained, but to retain for 3 years you must route them to a log sink (e.g., Cloud Storage or BigQuery) with a retention policy. Alerting on new firewall rule creation is done via a log-based alert on the Admin Activity log for compute.firewalls.create.

Exam trap

PCA often tests the distinction between Admin Activity logs (always on, config changes) and Data Access logs (off by default, data reads/writes), tricking candidates into selecting Data Access for an admin-action requirement.

How to eliminate wrong answers

Option A is wrong because Data Access audit logs record reads/writes of user data (e.g., reading a storage object) and are disabled by default; they are not needed to capture admin actions like firewall rule creation. Option C is wrong because VPC flow logs capture network traffic metadata (IP, port, protocol) for subnets or VMs, not administrative API calls. Option D is wrong because Cloud DNS logging captures DNS queries, not admin activity or firewall changes.

784
MCQmedium

A web application running on Compute Engine behind a global HTTP(S) load balancer experiences high latency during traffic spikes. Which quick fix would best address this issue without changing the architecture?

A.Configure managed instance group autoscaling to add more instances.
B.Enable Cloud CDN on the load balancer.
C.Switch to a regional load balancer to reduce latency.
D.Increase the machine type of the backend instances.
AnswerA

Autoscaling the managed instance group adds Compute Engine instances when load rises, spreading traffic across more backends. This directly relieves the CPU or capacity bottleneck causing high latency during spikes, and it requires no architectural change, satisfying the stem's quick-fix constraint.

Why this answer

Managed instance group (MIG) autoscaling dynamically adds more instances when CPU utilization or other metrics exceed a threshold, directly absorbing the increased traffic during spikes. This is the quickest fix because it requires no architectural changes—just configuring autoscaling parameters on the existing MIG. By scaling out horizontally, the load balancer can distribute requests across more backends, reducing per-instance load and latency.

Exam trap

Google Cloud often tests the distinction between horizontal scaling (autoscaling) and vertical scaling (increasing machine type) or caching solutions, leading candidates to choose Cloud CDN or machine type changes as a 'quick fix' when the real issue is insufficient compute capacity to handle dynamic request spikes.

How to eliminate wrong answers

Option B is wrong because enabling Cloud CDN caches static content at edge locations, which does not help with high latency caused by dynamic request processing during traffic spikes—CDN only reduces latency for cacheable content, not for the dynamic workload that is overwhelming the backend. Option C is wrong because switching to a regional load balancer would actually increase latency for global users, as it lacks the anycast IP and global distribution of the global HTTP(S) load balancer, and it requires architectural changes (e.g., changing the load balancer type). Option D is wrong because increasing the machine type (vertical scaling) is not a quick fix—it requires instance recreation or rolling update, and it does not scale as elastically as horizontal autoscaling; it also may not handle sudden spikes as effectively as adding more instances.

785
MCQeasy

A company is adopting Site Reliability Engineering (SRE) practices. After a major incident, they want to conduct a review to understand what went wrong and how to prevent recurrence, without blaming individuals. Which SRE practice should they follow?

A.Define SLOs and SLIs
B.Create an error budget policy
C.Perform capacity planning
D.Conduct a blameless postmortem
AnswerD

A blameless postmortem examines the systemic and process failures behind an incident, documenting contributing causes and corrective actions without attributing fault to individuals. This directly satisfies the stem's dual requirement: understanding what went wrong and preventing recurrence, while preserving the psychological safety that encourages honest reporting.

Why this answer

A blameless postmortem focuses on learning from incidents without assigning blame. Error budgets are for measuring reliability, SLOs/SLIs are for defining targets, and capacity planning is for scaling.

786
MCQmedium

A media company runs a batch transcoding pipeline on Google Kubernetes Engine. Jobs read input from a Cloud Storage bucket and write output to a second bucket. The team wants the pipeline to keep processing through transient Cloud Storage 429 and 503 errors without losing work, and they want the pods to stop being killed mid-job during node upgrades. Which combination should the architect implement?

A.Increase the Cloud Storage bucket's requester pays setting and enable Object Versioning on both buckets.
B.Add exponential backoff retries with jitter in the application's Cloud Storage client, and configure a PodDisruptionBudget for the job pods.
C.Move the pipeline to a DaemonSet so one pod runs on every node and is not subject to eviction.
D.Set the pods' restartPolicy to Always and rely on the default pod eviction behavior during node upgrades.
AnswerB

Client-side retries with exponential backoff and jitter handle transient 429 and 503 responses from Cloud Storage without failing the unit of work, and a PodDisruptionBudget limits how many job pods can be voluntarily evicted at once during node upgrades. Together they address both the API flakiness and the mid-job termination risk during planned maintenance.

Why this answer

Reliability for this pipeline requires handling transient Cloud Storage errors at the client layer and protecting pods from simultaneous voluntary disruption. Exponential backoff with jitter retries 429 and 503 responses without overwhelming the service, while a PodDisruptionBudget constrains how many job pods are evicted during node upgrades, letting the pipeline drain gracefully instead of losing work.

Exam trap

The trap here is assuming pod restart policies or bucket-level durability features handle transient API errors, when retry logic must live in the client and eviction must be bounded by a PodDisruptionBudget.

787
MCQmedium

A company needs to ensure that only approved container images can be deployed to a GKE cluster. They already use Binary Authorization. What additional step is required to enforce this policy?

A.Configure a VPC Service Perimeter
B.Enable Container Registry vulnerability scanning
C.Create an attestor and attach it to a Binary Authorization policy
D.Assign the container.deployer role to the GKE service account
AnswerC

Binary Authorization enforces admission only when a policy references at least one attestor; without one, the default policy permits all images. Creating an attestor and attaching it to the policy lets the attestation authority sign verified images, so GKE admits only images carrying a valid attestation.

Why this answer

Binary Authorization requires attestors to verify that an image meets specific criteria. An attestor is a trusted authority that signs attestations, and it must be attached to a Binary Authorization policy to enforce that only images with valid attestations are deployed. Without creating an attestor and attaching it to the policy, the policy cannot verify image signatures.

Exam trap

PCA often tests the steps to enforce Binary Authorization, and candidates may overlook the need to create an attestor and attach it to the policy, thinking that enabling Binary Authorization alone is sufficient.

How to eliminate wrong answers

Option A is wrong because a VPC Service Perimeter controls access to GCP services at the network level, not container image deployment policies. Option B is wrong because enabling vulnerability scanning does not enforce deployment policies; it only provides scan results. Option D is wrong because assigning the container.deployer role grants permission to deploy, but does not enforce image approval policies.

788
MCQeasy

A company wants to run a containerized web application that experiences unpredictable traffic spikes. They want to pay only for resources used during request processing, with no idle cost. Which compute service should they choose?

A.Google Kubernetes Engine (GKE) Autopilot
B.Cloud Run
C.App Engine Standard
D.Compute Engine with managed instance groups
AnswerB

Cloud Run scales to zero when no requests arrive and bills per request plus consumed resources, so idle periods incur no charge. This request-driven model matches unpredictable spikes, unlike always-on compute where capacity sits idle between bursts.

Why this answer

Cloud Run is a fully managed serverless platform that runs containers and automatically scales based on traffic, including scaling to zero when there are no requests. This means you pay only for resources used during request processing, with no idle cost, making it ideal for unpredictable traffic spikes.

Exam trap

PCA often tests the misconception that GKE Autopilot or App Engine Standard have no idle costs, when only Cloud Run offers true scale-to-zero with request-based billing.

How to eliminate wrong answers

Option A is wrong because GKE Autopilot, while managed, still provisions nodes that may incur costs even when idle, and it is not purely request-based pricing. Option C is wrong because App Engine Standard has idle costs for instances unless you configure scaling to zero, but it is not containerized by default. Option D is wrong because Compute Engine with managed instance groups always has at least some running instances, incurring idle costs.

789
MCQhard

An organization needs to store secrets used by multiple GCP services. They require automatic rotation of secrets every 30 days and integration with Cloud Functions. Which service should they use?

A.Cloud HSM
B.Cloud KMS
C.Cloud Asset Inventory
D.Secret Manager
AnswerD

Secret Manager stores credentials centrally and supports automatic rotation schedules, meeting the 30-day rotation requirement. Its native integration with Cloud Functions lets workloads retrieve secrets at runtime, satisfying the constraint that multiple GCP services consume the same secrets securely.

Why this answer

Secret Manager is a GCP service designed to store, manage, and access secrets such as API keys, passwords, and certificates. It supports automatic rotation of secrets via integration with Cloud Functions and other services, and provides versioning and audit logging.

Exam trap

PCA often tests the difference between Cloud KMS (encryption keys) and Secret Manager (application secrets). Candidates may confuse the two, especially when rotation is mentioned, as KMS also supports rotation but for keys, not arbitrary secrets.

How to eliminate wrong answers

Option A is wrong because Cloud HSM is a hardware security module service for cryptographic key operations, not for storing arbitrary secrets with rotation. Option B is wrong because Cloud KMS is for managing encryption keys, not for storing application secrets like passwords. Option C is wrong because Cloud Asset Inventory is for inventorying GCP resources, not for secret storage.

790
Multi-Selecthard

A company runs a latency-sensitive web application on Compute Engine in us-east1. They want to improve response times for users in Europe and Asia without changing the application architecture. Which TWO actions should they take? (Choose 2.)

Select 2 answers
A.Use preemptible VMs to reduce cost
B.Enable Cloud CDN on the load balancer
C.Deploy additional instances in us-west1
D.Create a multi-region load balancer and deploy backends in europe-west1 and asia-east1
E.Use Cloud Armor to block high-latency requests
AnswersB, D

Cloud CDN caches static and cacheable responses at edge points of presence near European and Asian users, cutting round-trip latency to the us-east1 origin. This satisfies the stem's latency goal without altering application architecture, since caching happens transparently at the load balancer layer.

Why this answer

Option B is correct because enabling Cloud CDN on the load balancer caches static and cacheable content at Google's globally distributed edge points of presence, so users in Europe and Asia are served from nearby edge locations instead of being backhauled to us-east1, reducing latency without any application changes. Option D is correct because a multi-region (global external) load balancer with backends in europe-west1 and asia-east1 places compute capacity close to those user populations, and the global anycast VIP routes each user to the nearest healthy backend, directly cutting round-trip time while preserving the existing architecture. Option A is not appropriate because preemptible VMs only reduce cost and can be terminated at any time, which harms latency-sensitive availability rather than improving response times.

Option C does not help because us-west1 is on the US West Coast, which is not closer to European or Asian users than us-east1. Option E is wrong because Cloud Armor is a WAF/DDoS protection service that filters malicious traffic and cannot reduce network latency for legitimate users.

Exam trap

The trap here is that candidates pick cost or security options (preemptible VMs, Cloud Armor) because they sound operationally relevant, missing that the question is strictly about reducing geographic latency for global users.

791
MCQeasy

A company wants to use Cloud Armor to protect their HTTP load balancer from SQL injection attacks. Which rule action should they configure to block malicious requests?

A.Use a pre-configured WAF rule that includes 'evaluatePreconfiguredExpr('sqli-stable')' with action 'deny(403)'.
B.Configure a rate-limiting rule with action 'rateLimit' to throttle traffic from suspicious IPs.
C.Create a rule that redirects traffic to a reCAPTCHA challenge for validation.
D.Set a security policy rule with action 'deny(403)' and a simple condition on the user-agent header.
AnswerA

Cloud Armor's pre-configured WAF rules use ModSecurity-style expressions; 'sqli-stable' targets SQL injection signatures, and the 'deny(403)' action blocks matching requests at the load balancer edge. This satisfies the requirement to block, rather than merely log, malicious SQL injection traffic.

Why this answer

Cloud Armor's pre-configured WAF rules include 'evaluatePreconfiguredExpr('sqli-stable')', which specifically detects SQL injection patterns in HTTP requests. Applying the 'deny(403)' action blocks malicious requests by returning a 403 Forbidden status, preventing the attack from reaching the backend. This is the correct approach because Cloud Armor WAF rules are purpose-built for application-layer threats like SQL injection.

Exam trap

Candidates often mistakenly think that any 'deny' action or generic security policy can block SQL injection, but the key is using Cloud Armor's pre-configured WAF rule specifically designed to inspect for injection patterns, not just a blanket deny on headers or rate limits.

How to eliminate wrong answers

Option B is wrong because rate-limiting throttles traffic volume but does not inspect request content for SQL injection patterns, so it cannot block specific malicious payloads. Option C is wrong because redirecting to a reCAPTCHA challenge adds friction for users but does not filter SQL injection attempts; it is designed for bot mitigation, not content-based attack detection. Option D is wrong because a simple condition on the user-agent header is a basic filter that cannot identify SQL injection syntax; it lacks the signature-based or behavioral analysis needed to detect injection attacks.

792
MCQeasy

A company runs a web application on Compute Engine instances behind a global HTTP(S) Load Balancer. The application uses Cloud SQL for MySQL for user data. Users report that during peak hours, the page load times increase significantly. The development team notices that the number of database connections exceeds the maximum allowed, causing some requests to fail. The application is designed to use connection pooling with a maximum pool size of 100 connections per instance. There are currently 10 instances. The Cloud SQL instance is configured with 4 vCPUs and 15 GB memory, and the maximum connections is set to 400. The application team wants to minimize cost while resolving the issue. What should the architect recommend?

A.Reduce the max pool size per instance to 40 connections.
B.Increase the Cloud SQL instance tier to have more vCPUs and memory.
C.Implement connection pooling at the global HTTP(S) Load Balancer level.
D.Use Cloud SQL Proxy with connection pooling.
AnswerA

Ten instances at 100 pooled connections each demand 1,000 connections, far exceeding the 400 limit. Lowering the pool to 40 caps demand at exactly 400, matching the configured maximum without resizing the costly Cloud SQL instance, directly resolving the connection exhaustion at minimum cost.

Why this answer

With 10 instances each configured for a max pool of 100 connections, the theoretical peak is 1,000 connections — far exceeding Cloud SQL's 400-connection limit. Reducing the pool to 40 per instance yields a maximum of 400 connections, which fits within the limit and resolves the failures without any cost increase. This is the only option that addresses the root cause (over-provisioned pools) while honoring the 'minimize cost' constraint.

Exam trap

The trap is that candidates instinctively choose 'scale up the database' (Option B) because it sounds like the obvious fix, ignoring the explicit 'minimize cost' constraint and the fact that the pool size is the actual misconfiguration.

How to eliminate wrong answers

Option B is wrong because increasing the Cloud SQL tier adds cost and only raises the connection ceiling — it does not fix the fundamental mismatch between 1,000 potential connections and the application's actual concurrency needs. Option C is wrong because a global HTTP(S) Load Balancer operates at Layer 7 for HTTP traffic and has no awareness of MySQL connection pooling; it cannot pool database connections. Option D is wrong because Cloud SQL Proxy provides secure IAM-based connectivity, not connection pooling — it does not reduce the number of connections the application opens.

793
MCQhard

An organization runs a Kubernetes cluster on GKE with cluster autoscaling enabled. They notice that pods are frequently in 'Pending' state due to insufficient CPU, but the cluster autoscaler does not add nodes quickly enough. What is the most likely cause?

A.The cluster autoscaler is using the 'least-waste' expander.
B.The horizontal pod autoscaler (HPA) is misconfigured.
C.The pod disruption budget (PDB) is too restrictive.
D.The node pool has reached the maximum node count limit.
AnswerD

When the node pool hits its maximum node count, the cluster autoscaler cannot provision further nodes regardless of pending pods. Pods remain Pending because no capacity is added, explaining the slow scaling despite autoscaling being enabled.

Why this answer

The cluster autoscaler cannot add new nodes if the node pool has already reached its maximum node count limit. This limit is configured at the node pool level in GKE, and once reached, the autoscaler will not scale up further, leaving pods in 'Pending' state due to insufficient CPU resources.

Exam trap

Google Cloud often tests the distinction between pod-level scaling (HPA) and node-level scaling (cluster autoscaler), and the trap here is that candidates confuse a restrictive PDB with a node pool limit, or assume the expander strategy directly causes scaling delays.

How to eliminate wrong answers

Option A is wrong because the 'least-waste' expander selects a node pool that minimizes resource waste after scaling, but it does not prevent the autoscaler from adding nodes; it only affects which node pool is chosen. Option B is wrong because the HPA scales pods based on CPU or memory utilization, not nodes; a misconfigured HPA would cause incorrect pod scaling, not a delay in node addition by the cluster autoscaler. Option C is wrong because a pod disruption budget (PDB) controls the number of pods that can be voluntarily disrupted during maintenance or upgrades, not the ability of the cluster autoscaler to add nodes.

794
Multi-Selectmedium

A team is building a CI/CD pipeline for a Java application that will run on GKE. They want to automatically build the application, run unit tests, create a Docker image, push it to Artifact Registry, and deploy to GKE. Which two GCP services should be combined? (Choose two.)

Select 2 answers
A.Cloud Functions
B.Compute Engine
C.Cloud Run
D.Cloud Deploy
E.Cloud Build
AnswersD, E

Cloud Deploy provides the managed continuous delivery layer that handles progressive rollout of the containerised Java application to GKE clusters, satisfying the deployment stage of the pipeline after the image is pushed to Artifact Registry.

Why this answer

Cloud Build (E) is the correct service for the build-and-test stage: it can compile the Java application, run unit tests, build the Docker image, and push it to Artifact Registry as part of a CI pipeline defined in cloudbuild.yaml. Cloud Deploy (D) is the correct service for the delivery/deployment stage: it is a managed continuous delivery service that takes the built image and progressively deploys it to GKE targets (with rollout and approval controls). Together, Cloud Build handles CI and Cloud Deploy handles CD to GKE, matching the requested pipeline.

Cloud Functions (A) is for event-driven serverless functions, not container image builds or GKE deployments. Compute Engine (B) provides VMs and is not the managed CI/CD service needed here. Cloud Run (C) runs containerized services serverlessly but does not build images or deploy workloads to GKE.

795
MCQmedium

Your organization stores critical financial data in Cloud Storage. You need to ensure that if an object is deleted or overwritten, you can recover it within 30 days. What feature should you enable?

A.Set a retention policy with a 30-day retention period
B.Configure lifecycle management to delete objects after 30 days
C.Enable object versioning on the bucket
D.Enable Bucket Lock with a retention policy
AnswerC

Object versioning retains prior generations of each object, so deleted or overwritten data remains recoverable within the bucket's retention window. This directly satisfies the 30-day recovery requirement for critical financial data without relying on separate backup copies.

Why this answer

Object versioning preserves every version of an object, including prior versions created before an overwrite and the last version before deletion. When an object is deleted, a delete marker is placed, but the underlying versions remain recoverable. This directly satisfies the requirement to recover deleted or overwritten objects within 30 days.

Exam trap

The trap is confusing Bucket Lock retention policies (which prevent deletion for compliance) with versioning (which enables recovery after deletion or overwrite) — candidates often pick the retention policy because it mentions '30 days' matching the requirement.

How to eliminate wrong answers

Option A is wrong because a retention policy (via Bucket Lock) prevents deletion or modification for a fixed period but does not help recover objects that were already deleted or overwritten before the policy was applied, and it is designed for compliance immutability, not recovery. Option B is wrong because lifecycle management deletes objects after 30 days, which is the opposite of the requirement. Option D is wrong because Bucket Lock with a retention policy enforces immutability and prevents deletion, but it does not provide a recovery mechanism for objects that were deleted or overwritten — it simply blocks those operations.

796
MCQeasy

A company needs to store archival data that is accessed less than once a year and must be retained for 10 years for compliance. The data retrieval time is not critical. Which Cloud Storage class is MOST cost-effective?

A.Coldline storage class
B.Standard storage class
C.Nearline storage class
D.Archive storage class
AnswerD

Archive storage offers the lowest per-gigabyte cost and is designed for data accessed less than once a year with a 365-day minimum storage duration, matching the compliance retention and rare-access pattern. Retrieval latency is irrelevant here, so cheaper cold tiers beat Nearline or Coldline.

Why this answer

Archive storage class is the most cost-effective option for data accessed less than once a year with a 10-year retention requirement and non-critical retrieval time. It has the lowest storage cost of all Cloud Storage classes, designed specifically for long-term archival with a minimum storage duration of 365 days. Coldline and Nearline have higher storage costs and shorter minimum durations (90 and 30 days respectively), making them less economical for this use case.

Exam trap

PCA often tests the confusion between Coldline and Archive storage classes, where candidates may choose Coldline thinking it is the cheapest archival option, but Archive is actually the lowest-cost class for data accessed less than once a year.

How to eliminate wrong answers

Option A is wrong because Coldline storage is designed for data accessed less than once a quarter (90-day minimum), and its storage cost is higher than Archive, making it less cost-effective for annual access over 10 years. Option B is wrong because Standard storage is optimized for frequently accessed data and has the highest storage cost, which is inappropriate for archival data accessed less than once a year. Option C is wrong because Nearline storage is for data accessed less than once a month (30-day minimum) and costs more than Archive, so it does not meet the cost-effectiveness requirement for annual access.

797
Multi-Selecthard

A team is designing a disaster recovery (DR) plan for a critical application. Which THREE components are essential for a robust DR plan? (Choose 3)

Select 3 answers
A.Failover procedures and runbooks
B.Regular backups to a separate region
C.A single-region deployment for consistency
D.Monitoring and alerting for disaster events
E.Load testing to validate performance
AnswersA, B, D

Well-documented failover steps ensure quick recovery.

Why this answer

Failover procedures and runbooks (A) are essential because they provide step-by-step instructions for executing a controlled transition to the secondary site, ensuring minimal downtime and consistent recovery actions. Without documented runbooks, teams risk misconfigurations during a disaster, which can extend recovery time objectives (RTO) beyond acceptable limits.

Exam trap

Google Cloud often tests the misconception that a single-region deployment is acceptable for DR if it has high availability within that region, but the exam emphasizes that DR requires geographic separation to survive a full regional failure.

798
MCQmedium

A financial services company requires a globally distributed relational database with strong consistency and horizontal scalability to serve a multi-region banking application. Write conflicts are rare. Which database should they choose?

A.Firestore in Native mode
B.Cloud SQL with cross-region replication
C.Cloud Bigtable
D.Cloud Spanner
AnswerD

Cloud Spanner is a globally distributed relational database offering external consistency and horizontal scalability through TrueTime, meeting the strong-consistency and multi-region requirements. Cloud SQL and Cloud Bigtable lack either global relational semantics or strong consistency.

Why this answer

Cloud Spanner is Google's globally distributed, horizontally scalable, strongly consistent relational database. It uses TrueTime and Paxos to provide external consistency across regions, making it the only option that meets all three requirements: global distribution, strong consistency, and horizontal scalability for a relational workload.

Exam trap

The trap is confusing 'globally distributed' with 'eventually consistent' — candidates may pick Cloud SQL with replication or Bigtable, missing that only Spanner offers strong consistency plus horizontal scalability in a relational model.

How to eliminate wrong answers

Option A is wrong because Firestore in Native mode is a NoSQL document database, not relational, and does not provide the same strong consistency guarantees for multi-region relational transactions. Option B is wrong because Cloud SQL with cross-region replication is not horizontally scalable for writes (single primary) and cross-region replication is asynchronous, so it does not provide strong consistency globally. Option C is wrong because Cloud Bigtable is a NoSQL wide-column store optimized for high-throughput analytics, not a relational database with strong consistency for transactional banking workloads.

799
MCQeasy

A company wants to automatically rotate cryptographic keys on a schedule without manual intervention. Which service should they use?

A.Cloud Key Management Service (KMS)
B.Secret Manager
C.Cloud Audit Logs
D.Cloud IAM
AnswerA

Cloud KMS supports automatic, scheduled rotation of cryptographic keys, satisfying the requirement for rotation without manual intervention. You configure a rotation period and the service generates new key versions on that schedule, while older versions remain available for decryption. This removes the operational burden of manual rotation entirely.

Why this answer

Cloud KMS provides built-in key rotation capabilities that allow you to automatically rotate cryptographic keys on a schedule (e.g., every 90 days) without manual intervention. You define a rotation period, and KMS automatically generates a new primary key version while retaining older versions for decryption of existing data. This is the correct service because it is specifically designed for managing encryption keys with automated lifecycle policies.

Exam trap

Google often tests the distinction between key management (KMS) and secret storage (Secret Manager), leading candidates to confuse automated key rotation with simple secret versioning.

How to eliminate wrong answers

Option B (Secret Manager) is wrong because Secret Manager is designed to store and manage secrets like API keys, passwords, and certificates, not to perform automated cryptographic key rotation; it lacks native key rotation scheduling. Option C (Cloud Audit Logs) is wrong because Cloud Audit Logs records API activities and access logs but does not manage or rotate cryptographic keys. Option D (Cloud IAM) is wrong because Cloud IAM controls access permissions and identities but has no capability to rotate keys; it is a policy engine, not a key management service.

800
Multi-Selectmedium

A team needs to set up alerting for a production service. They want to receive notifications when the 99th percentile latency exceeds 500ms for 5 minutes. Which two Cloud Monitoring components are required? (Choose two.)

Answer options not yet available.

Why this answer

The two required components are an alerting policy and a notification channel. The alerting policy (Option A) is what defines the condition — here, a threshold on the 99th percentile latency metric exceeding 500ms sustained for a 5-minute duration — and evaluates it against the monitored time series. The notification channel (Option D) is what actually delivers the alert, such as email, SMS, Slack, or PagerDuty, and must be attached to the policy for anyone to be notified.

Without the policy there is no condition to evaluate, and without a channel the policy fires but sends no notification, so both are mandatory. The unmarked options do not belong because they are not required components for this scenario: a dashboard only visualizes metrics and does not trigger alerts, and other items such as uptime checks or log-based metrics are unrelated to latency threshold alerting.

Exam trap

PCA often tests the distinction between monitoring components: candidates might confuse dashboards or uptime checks with alerting requirements, or forget that a notification channel is mandatory for alerts to be delivered.

How to eliminate wrong answers

Option B is wrong because a dashboard is for visualization, not alerting. Option C is wrong because a log-based metric is for extracting metrics from logs, not for defining alert conditions on existing metrics. Option E is wrong because an uptime check monitors availability, not latency percentiles.

801
MCQeasy

A user wants to store a database password that will be used by a Compute Engine instance. What is the most secure and manageable approach?

A.Use Secret Manager and grant the instance's service account access to the secret
B.Set the password as an environment variable in instance metadata
C.Store the password in Cloud Storage bucket metadata
D.Store the password in a file on the instance's boot disk
AnswerA

Secret Manager stores the credential encrypted and versioned, and IAM on the Compute Engine service account grants retrieval at runtime, so the password never sits in instance metadata, startup scripts or source code. This satisfies the secure and manageable requirement without manual rotation.

Why this answer

Secret Manager is the most secure and manageable approach because it provides encrypted storage, automatic rotation, and fine-grained access control via IAM. By granting the Compute Engine instance's service account access to the secret, the password is never exposed in plaintext metadata, logs, or disk files, and access can be audited and revoked independently of the instance lifecycle.

Exam trap

Google Cloud often tests the misconception that instance metadata is a secure place for secrets because it is 'internal' to the project, but in reality, metadata is accessible to any process on the instance and is logged, making it unsuitable for sensitive data.

How to eliminate wrong answers

Option B is wrong because setting the password as an environment variable in instance metadata exposes it in the metadata server, which can be accessed by any process on the instance or via the metadata API, and it is logged in Cloud Audit Logs. Option C is wrong because Cloud Storage bucket metadata is not designed for secrets; it is unencrypted at rest by default, accessible via the Storage API, and lacks IAM-level access control for individual metadata entries. Option D is wrong because storing the password in a file on the instance's boot disk persists the secret in the filesystem, making it vulnerable to snapshot exports, disk cloning, and unauthorized OS-level access, and it cannot be centrally managed or rotated.

802
MCQmedium

A company uses Google Cloud Armor to protect their HTTP load balancer from OWASP Top 10 attacks. After deploying a security policy with pre-configured WAF rules, they notice that some legitimate user requests are being blocked because they match a rule incorrectly. The security team wants to fine-tune the rules to reduce false positives while maintaining strong protection. They also want to evaluate the impact of changes before enforcing them. What should they do?

A.Disable the WAF rules entirely and implement IP-based allowlists.
B.Set the WAF rules to 'preview' mode to test their impact without blocking traffic, then adjust thresholds or exclusions based on logs.
C.Add a higher priority allow rule to permit the traffic that is being incorrectly blocked.
D.Remove the WAF rules and rely solely on rate limiting to protect the application.
AnswerB

Preview mode logs which requests would have been blocked without enforcing the action, letting the team measure false positives and tune thresholds or exclusions before enforcement. This satisfies both the fine-tuning and pre-enforcement evaluation requirements while preserving protection.

Why this answer

Google Cloud Armor's 'preview' mode allows you to apply a security policy to a backend service or load balancer without actually blocking traffic. Instead, all matched requests are logged, enabling you to analyze false positives in the logs before enforcing the rules. This approach lets you fine-tune thresholds, add exclusions, or adjust rule priorities based on real traffic patterns, reducing false positives while maintaining strong protection.

Exam trap

The trap here is that candidates may think adding a higher priority allow rule (Option C) is a valid fine-tuning approach, but it actually creates a security bypass rather than reducing false positives through proper rule adjustment.

How to eliminate wrong answers

Option A is wrong because disabling WAF rules entirely removes protection against OWASP Top 10 attacks, and IP-based allowlists only permit specific source IPs, which is not a scalable or effective defense against application-layer attacks. Option C is wrong because adding a higher priority allow rule would permit the traffic unconditionally, bypassing the WAF rules and potentially allowing malicious requests that match the same pattern, thus weakening security. Option D is wrong because removing WAF rules and relying solely on rate limiting does not protect against OWASP Top 10 attacks such as SQL injection or cross-site scripting, which require content inspection.

803
MCQmedium

A company hosts a web application on Google Kubernetes Engine (GKE) and wants to protect against SQL injection attacks. Which service should they configure?

A.Identity-Aware Proxy (IAP)
B.Cloud Armor
C.Cloud Audit Logs
D.Container Analysis
AnswerB

Cloud Armor is Google Cloud's edge security service, applying WAF rules to external HTTP(S) load balancers in front of GKE workloads, and its preconfigured SQL injection ruleset blocks malicious query strings before they reach the application.

Why this answer

Cloud Armor is the correct choice because it provides web application firewall (WAF) capabilities that can inspect HTTP/HTTPS traffic and block SQL injection attempts using preconfigured rules (e.g., the OWASP Top 10 rule set). It integrates directly with GKE via HTTP(S) Load Balancing, allowing you to enforce security policies at the edge before requests reach your application.

Exam trap

Candidates often confuse identity-based access controls (IAP) with content-based threat detection (Cloud Armor). IAP controls who can access the application, while Cloud Armor protects against attacks like SQL injection at the web application firewall layer.

How to eliminate wrong answers

Option A is wrong because Identity-Aware Proxy (IAP) controls access based on user identity and context, not traffic content; it cannot inspect payloads for SQL injection patterns. Option C is wrong because Cloud Audit Logs record API operations and access events for compliance, but they do not actively filter or block malicious requests. Option D is wrong because Container Analysis scans container images for vulnerabilities (e.g., in OS packages or libraries), but it does not protect against runtime application-layer attacks like SQL injection.

804
Multi-Selectmedium

A financial services firm is planning its Google Cloud resource hierarchy before migrating production workloads. The architecture team wants to enforce separation between business units, centralize network administration, and apply consistent IAM and policy controls across many projects. Which two design choices should the architect recommend? (Choose two.)

Select 2 answers
A.Grant the roles/owner role to each business unit's administrators at the organization level to simplify management
B.Use a Shared VPC host project to centralize network administration while service projects host the workloads
C.Place all projects directly under the organization node and manage permissions only at the project level
D.Create a separate organization node for each business unit to isolate billing and IAM
E.Create a folder per business unit under the organization node and apply IAM policies and Organization Policy constraints at the folder level
AnswersB, E

Shared VPC allows a host project to own the VPC network and subnets while service projects attach their resources to those subnets. Network administration stays centralized with the host project's administrators, and service project teams can deploy workloads without managing network topology, matching the separation and centralization requirements.

Why this answer

A folder-based hierarchy with inherited IAM and Organization Policy constraints gives centralized, consistent governance while separating business units. A Shared VPC host project centralizes network administration so service projects can consume subnets without owning network topology. Together these choices provide the separation, centralization, and consistent controls the firm requires while avoiding the risks of flat hierarchies or excessive organization-level permissions.

Exam trap

The trap here is treating the organization node as something that can be created per business unit, when it actually maps to a single identity domain and is created once.

805
MCQeasy

A company wants to run a containerized application that scales down to zero when not in use and only incurs costs when requests are being processed. They do not want to manage infrastructure. Which compute service should they use?

A.Cloud Functions
B.Compute Engine
C.Cloud Run
D.Google Kubernetes Engine (GKE) Standard
AnswerC

Cloud Run is a fully managed serverless container platform that scales to zero instances when idle and bills only for request processing. It removes node and cluster management, matching both the scale-to-zero and no-infrastructure constraints.

Why this answer

Cloud Run is a fully managed serverless container platform that scales to zero and charges only for resources used during request processing. GKE Autopilot manages infrastructure but does not scale to zero (has a minimum node). Cloud Functions scales to zero but is for functions, not containers.

Compute Engine always has running VMs.

806
MCQhard

A company runs a critical application on a managed instance group (MIG) with autoscaling enabled. The application experiences sudden traffic spikes, and the team wants to ensure that new instances are added quickly while maintaining cost efficiency. They also want to avoid over-provisioning. Which autoscaling metric should they use?

A.CPU utilization
B.Custom metric based on memory usage
C.Cloud Pub/Sub queue depth
D.HTTP load balancing serving capacity
AnswerD

HTTP load balancing serving capacity is a metric that measures the utilization of the load balancer's backend capacity. It directly reflects the incoming traffic and can trigger scaling based on the actual load, allowing quick response to traffic spikes. This metric is ideal for web applications behind an HTTP(S) load balancer, as it scales based on the number of requests and avoids over-provisioning by matching capacity to demand.

Why this answer

HTTP load balancing serving capacity is the best metric for scaling a web application behind an HTTP(S) load balancer because it directly measures the load on the backend instances. It enables rapid scaling in response to traffic spikes and helps maintain cost efficiency by avoiding over-provisioning. Other metrics may not accurately reflect the incoming traffic or may introduce delays.

Exam trap

The trap here is assuming that CPU utilization is always the most responsive metric for autoscaling, but for web applications behind a load balancer, serving capacity provides a more direct and immediate signal of traffic load.

807
MCQeasy

A developer wants to monitor the CPU usage of a single Compute Engine VM and receive alerts when it exceeds 80%. What is the simplest way to achieve this?

A.Query the Compute Engine API periodically and check CPU usage.
B.Configure a Cloud Logging sink to BigQuery and set a scheduled query to detect high CPU.
C.Install the Cloud Monitoring agent and create an alerting policy based on the metric 'cpu.utilization'.
D.Use the managed instance group's autoscaling metric to trigger a notification.
AnswerC

The Monitoring agent collects CPU utilization from the OS and sends it to Cloud Monitoring, where you can set alerts.

Why this answer

The Cloud Monitoring agent (formerly Stackdriver agent) collects CPU utilization metrics from Compute Engine VMs and sends them to Cloud Monitoring. You can then create an alerting policy directly on the metric 'cpu.utilization' with a threshold of 80% without any custom scripting or additional infrastructure. This is the simplest and most native approach for a single VM.

Exam trap

Google Cloud often tests the misconception that you need to export logs to BigQuery or query APIs manually, when in fact the Cloud Monitoring agent provides a built-in, agent-based metric that can be alerted on directly.

How to eliminate wrong answers

Option A is wrong because periodically querying the Compute Engine API for CPU usage is inefficient, requires custom code, and does not provide real-time alerting; the API does not expose high-frequency CPU metrics natively. Option B is wrong because exporting logs to BigQuery and running scheduled queries adds unnecessary complexity, latency, and cost; Cloud Logging sinks are for log data, not for real-time metric-based alerting. Option D is wrong because managed instance group autoscaling metrics are designed for scaling groups of VMs, not for alerting on a single VM's CPU usage; they do not trigger notifications directly.

Page 10

Page 11 of 11

All pages