Courseiva

Google Professional Cloud Architect (PCA) — Questions 76–150

807 questions total · 11pages · All types, answers revealed

Page 1

Page 2 of 11

Page 3
76
MCQeasy

A small e-commerce team wants to deploy a containerized storefront to Google Cloud with minimal operational overhead. Traffic is steady, the team has no Kubernetes expertise, and they want to pay only for what they use while the service scales automatically. Which compute option should the architect recommend?

A.Cloud Run services with request-based autoscaling and scale-to-zero enabled.
B.Compute Engine managed instance groups with an autoscaling policy based on CPU utilization.
C.Google Kubernetes Engine Autopilot cluster with a Horizontal Pod Autoscaler.
D.App Engine standard environment with automatic scaling and an instance class sized for peak traffic.
AnswerA

Cloud Run runs container images on a fully managed platform, scales instances automatically with incoming requests, and can scale to zero so the team pays only for requests actually served. There are no clusters or nodes to manage, and the developer workflow is a simple container push and deploy. This directly matches the requirements for minimal operations, automatic scaling, and consumption-based cost.

Why this answer

The deciding factors are the containerized workload, the lack of Kubernetes skills, and the desire for consumption-based pricing with automatic scaling. Cloud Run accepts a container image, manages all infrastructure, and scales instances up and down with request load, including down to zero when idle. That removes cluster operations entirely while still billing per use, which is exactly the profile the team described.

Exam trap

The trap here is equating any autoscaling service with zero operational overhead, when managed instance groups and Kubernetes still require the team to run infrastructure.

77
Multi-Selectmedium

A company has deployed a critical application on Google Kubernetes Engine (GKE) with a Regional cluster (us-central1). The application uses a Cloud SQL for PostgreSQL database with a cross-region replica for disaster recovery. The SRE team needs to ensure that the application can survive a regional outage with minimal data loss. Which TWO actions should the team take to improve the reliability of the solution?

Select 2 answers
A.Configure the application to automatically promote the Cloud SQL cross-region replica to a primary instance when the primary region is unavailable.
B.Configure Cloud SQL cross-region replication to be synchronous to ensure zero data loss during failover.
C.Configure an external HTTP(S) load balancer with a backend service pointing to both the primary and secondary GKE clusters, and use a DNS failover policy to route traffic to the secondary region if the primary region becomes unhealthy.
D.Deploy a secondary GKE cluster in the same region as the primary to provide a hot standby that can take over immediately.
E.Use a TCP/UDP load balancer to route traffic to both regions based on latency.
AnswersA, C

Correct. Promoting a Cloud SQL cross-region replica to a primary instance is the standard DR procedure. Automation via Cloud Functions or Cloud Run reduces RTO. However, cross-region replication is asynchronous, so some data loss is possible.

Why this answer

To survive a regional outage with minimal data loss, two key actions are needed: (1) Automate promotion of the Cloud SQL cross-region replica to primary when the primary region fails (Option A) – this is the standard Cloud SQL DR procedure; automation via Cloud Functions/Cloud Run reduces RTO. Note that cross-region replication is asynchronous, so some data loss (replication lag) is possible. (2) Deploy a multi-region GKE cluster pair (primary and secondary) and use an external HTTP(S) load balancer with a backend service pointing to both clusters, combined with a DNS failover policy (Option C) – this allows the load balancer to detect primary region health and route traffic to the secondary region if needed. Options B is wrong because cross-region replication cannot be synchronous.

Option D is wrong because a secondary cluster in the same region does not help during a regional outage. Option E is wrong because a TCP/UDP load balancer with latency-based routing does not provide failover based on region health.

Exam trap

The trap here is that candidates often assume synchronous replication is possible across regions for zero data loss, but in practice, cross-region replication is always asynchronous due to the speed of light and network latency constraints.

78
MCQeasy

A company commits to using Compute Engine for 3 years and wants the maximum discount. Which purchasing option should they use?

A.3-year committed use discount.
B.Pay-as-you-go pricing.
C.Sustained use discounts.
D.1-year committed use discount.
AnswerA

A 3-year committed use discount applies to Compute Engine vCPU and memory spend, delivering the deepest discount (up to 57%) for a fixed three-year term. It directly satisfies the stem's maximum-discount constraint, unlike sustained use discounts, which accrue automatically but cap at 30% and require no commitment.

Why this answer

A 3-year committed use discount (CUD) offers the highest discount rate (up to 57% for most machine types) compared to 1-year CUDs (up to 37%) or pay-as-you-go pricing. By committing to a consistent resource usage for the full 3-year term, the company maximizes the discount on Compute Engine costs.

Exam trap

Google Cloud often tests the misconception that sustained use discounts provide the best long-term savings, but they are automatic and capped at 30%, whereas committed use discounts require a contractual commitment but offer significantly higher discounts for longer terms.

How to eliminate wrong answers

Option B is wrong because pay-as-you-go pricing provides no discount and is the most expensive option for long-term usage. Option C is wrong because sustained use discounts are automatic per-month discounts for running instances over 25% of a month, but they max out at 30% and do not require a commitment; they cannot match the deeper discount of a 3-year CUD. Option D is wrong because a 1-year committed use discount offers a lower discount rate (up to 37%) than a 3-year CUD (up to 57%), so it does not provide the maximum discount.

79
MCQhard

A healthcare company runs a critical patient portal on Compute Engine. The portal uses a Cloud SQL for PostgreSQL database. The company needs to perform a major version upgrade of the database with minimal downtime and wants to minimize the risk of data loss. They also want to be able to roll back quickly if issues arise. Which approach should they take?

A.Use Cloud SQL's in-place major version upgrade feature during a maintenance window, and rely on automated backups for rollback.
B.Export the database to a Cloud Storage bucket, create a new instance with the new version, and import the data.
C.Create a read replica, promote it to primary, and then upgrade the original instance.
D.Use Database Migration Service to migrate to a new Cloud SQL instance with the desired major version, then switch over.
AnswerD

Database Migration Service (DMS) can perform a minimal-downtime migration to a new Cloud SQL instance with a different major version. It continuously replicates data, allowing a quick cutover and keeping the original instance intact for rollback if needed. This meets the requirements for minimal downtime, low data loss risk, and quick rollback.

Why this answer

Database Migration Service enables a minimal-downtime migration to a new Cloud SQL instance with the desired major version. It continuously replicates data, so the cutover is quick and the original instance remains available for rollback. This approach minimizes data loss risk and downtime, unlike in-place upgrades or export/import.

Exam trap

The trap here is assuming that in-place major version upgrades are always safe and reversible, when they can cause downtime and are not easily rolled back.

80
MCQhard

Your company runs a stateful application on Compute Engine instances in a managed instance group. The application requires that each instance maintains a unique identity and persistent storage. You need to ensure that instances can be recreated without data loss and that they retain their identities. What should you do?

A.Configure the MIG to use preemptible instances and attach a local SSD to each instance.
B.Create a separate unmanaged instance group and manually attach persistent disks to each instance.
C.Use a stateless MIG and store application state in a shared Cloud Storage bucket.
D.Use a stateful managed instance group (MIG) with instance names and persistent disks.
AnswerD

A stateful MIG allows you to preserve instance names, persistent disks, and metadata when instances are recreated or restarted. This ensures that each instance maintains its unique identity and persistent storage. It is designed for stateful workloads and supports autohealing and updates without losing state. This directly meets the requirements for identity and data persistence.

Why this answer

A stateful managed instance group (MIG) preserves instance names, persistent disks, and metadata across recreations, ensuring that each instance retains its identity and data. It is the recommended solution for stateful workloads on Compute Engine. Other options either use ephemeral storage, lack automation, or do not preserve identity.

Exam trap

The trap here is assuming that a stateless MIG with shared storage can replace a stateful MIG, but it does not preserve instance identity or provide the same persistence guarantees.

81
MCQmedium

A company has two VPC networks in the same project: 'vpc-prod' and 'vpc-dev'. They want to allow communication between instances in both VPCs. What is the simplest method?

A.Create a VPC Network Peering connection between them
B.Set up a Cloud VPN tunnel between the two VPCs
C.Configure a custom route in each VPC pointing to the other's subnet
D.Add firewall rules allowing traffic between the VPCs
AnswerA

VPC Network Peering enables direct, private connectivity.

Why this answer

VPC Network Peering is the simplest method because it directly connects two VPCs using Google's internal infrastructure, allowing private RFC 1918 IP communication across the networks without requiring external gateways, VPN tunnels, or additional bandwidth costs. It requires no routes to be manually configured—Google automatically adds the necessary routes for each peered VPC's subnets—and only a single firewall rule to permit traffic between the instances.

Exam trap

Google Cloud often tests the misconception that firewall rules alone can enable inter-VPC communication, but candidates must remember that firewall rules are only effective after a connectivity mechanism (like peering or VPN) is in place.

How to eliminate wrong answers

Option B is wrong because a Cloud VPN tunnel introduces unnecessary complexity and latency by routing traffic over the public internet or through Cloud VPN gateways, whereas VPC peering uses Google's internal backbone with lower latency and no per-tunnel charges. Option C is wrong because custom routes alone cannot enable inter-VPC communication; routes only direct traffic to a next hop, but without a peering connection or VPN tunnel, there is no path for the packets to travel between the VPCs. Option D is wrong because firewall rules only control allowed traffic within a VPC or between VPCs that already have a connectivity mechanism (like peering or VPN); they do not establish the underlying network link required for packets to leave one VPC and enter another.

82
MCQmedium

A company runs a web application on Compute Engine behind a HTTP(S) Load Balancer. They want to reduce latency for users worldwide. Which Google Cloud service should they use?

A.Cloud CDN
B.Cloud Armor
C.Cloud NAT
D.Cloud VPN
AnswerA

Cloud CDN caches HTTP(S) load balancer responses at Google's globally distributed edge points of presence, serving repeat requests close to users. This directly reduces round-trip latency for worldwide users, the stated constraint, without changing the existing Compute Engine backend.

Why this answer

Cloud CDN caches content at Google's globally distributed edge points of presence, reducing latency by serving requests from locations closer to users. It integrates directly with HTTP(S) Load Balancer to accelerate web application delivery worldwide.

Exam trap

PCA often tests the distinction between services that improve performance (Cloud CDN) and those that provide security (Cloud Armor) or connectivity (Cloud VPN, Cloud NAT), causing candidates to select a security service for latency reduction.

How to eliminate wrong answers

Option B is wrong because Cloud Armor provides DDoS protection and WAF capabilities, not content caching or latency reduction. Option C is wrong because Cloud NAT enables outbound internet access for private instances, not content delivery. Option D is wrong because Cloud VPN provides secure connectivity between on-premises and GCP, not global content acceleration.

83
Multi-Selecteasy

Which TWO statements about Google Cloud VPC networks are true? (Choose two.)

Select 2 answers
A.Subnets are regional resources.
B.VPC networks are global resources.
C.VPC networks are project-level resources.
D.Firewall rules are regional.
E.Subnets are zonal resources.
AnswersA, B

Subnets are regional and can span zones.

Why this answer

Subnets in Google Cloud VPC are regional resources. When you create a subnet, you specify a region and a CIDR block, and the subnet spans all zones within that region. This allows resources in different zones of the same region to use the same subnet without additional configuration.

Exam trap

The trap here is that candidates often confuse subnets as zonal resources (like in AWS or on-premises networking) and firewall rules as regional, but Google Cloud VPC treats subnets as regional and firewall rules as global, which is a key differentiator tested on the PCA exam.

84
MCQmedium

A company runs a microservices application on Google Kubernetes Engine (GKE). Each service is deployed as a Deployment with resource requests and limits. After deploying a new version of a service, the pods start crashing with OOMKilled. The team increased the memory limits in the Deployment manifest, but the pods still crash after a few minutes. The cluster has cluster autoscaling enabled. The node pool has sufficient capacity. What is the most likely cause of the issue?

A.The Horizontal Pod Autoscaler is configured with a wrong target metric
B.The cluster autoscaler is not scaling up quickly enough
C.The application has a memory leak
D.The pods are hitting the node's ephemeral storage limit
AnswerC

Raising memory limits only delays OOMKilled termination; pods still crash once consumption exceeds the new ceiling. Steadily growing memory that eventually exhausts any limit indicates a leak in the application code, not insufficient node capacity or autoscaling.

Why this answer

The pods are crashing with OOMKilled even after increasing memory limits, and the node pool has sufficient capacity. This indicates the application itself has a memory leak, where memory usage grows unbounded over time until it exceeds the new limit, causing the OOMKiller to terminate the pod. Increasing limits only delays the crash if the leak persists.

Exam trap

The trap here is that candidates confuse resource limits with scaling mechanisms, assuming that increasing limits or enabling autoscaling fixes memory exhaustion, rather than recognizing the application-level memory leak as the root cause.

How to eliminate wrong answers

Option A is wrong because the Horizontal Pod Autoscaler (HPA) scales the number of pods based on CPU/memory utilization, but it does not prevent individual pods from being OOMKilled; the issue is per-pod memory exhaustion, not scaling. Option B is wrong because cluster autoscaler scales node count when pods are unschedulable due to resource shortage, but the node pool has sufficient capacity, so the autoscaler is not the bottleneck. Option D is wrong because ephemeral storage limits affect disk space, not memory; OOMKilled is a memory-related termination, not a storage issue.

85
MCQmedium

A financial analytics firm is deploying a new batch reporting platform on Google Cloud. The platform runs on a Managed Instance Group (MIG) of Compute Engine VMs and reads source data from a single Cloud Storage bucket. The security team requires that the VMs access the bucket without using long-lived service account keys, and that the identity be scoped specifically to this workload. They also want the permission to be automatically revoked when the VMs are deleted. Which approach should you recommend?

A.Use the Compute Engine default service account, which already has the Editor role, and add an IAM condition limiting access to the reporting project.
B.Create a dedicated service account, grant it roles/storage.objectViewer on the bucket, and attach it to the MIG as the instance service account.
C.Enable Cloud Storage public access prevention and make the bucket readable by allAuthenticatedUsers, then restrict network access with VPC firewall rules.
D.Create a service account, generate a JSON key, store it in Secret Manager, and have the application mount it at runtime.
AnswerB

Attaching a dedicated service account to the MIG makes every VM in the group use that identity. Application Default Credentials on the VMs automatically obtain short-lived access tokens from the metadata server, so no keys are stored. Because the identity is tied to the instance template, deleting the VMs removes the workload's ability to authenticate, satisfying the revocation requirement.

Why this answer

Workload-scoped, keyless authentication on Compute Engine is achieved by attaching a dedicated service account to the instance template used by the MIG. The metadata server issues short-lived tokens to the application, so no static keys exist to leak or rotate, and the identity disappears with the instances. Granting only roles/storage.objectViewer on the specific bucket enforces least privilege for the reporting workload.

Exam trap

The trap here is assuming that storing a service account key in Secret Manager makes it a short-lived or keyless credential.

86
MCQmedium

A company is using Cloud Load Balancing to distribute traffic to a managed instance group (MIG) of web servers. The web servers are currently running in us-central1. To improve availability, the company plans to add a second MIG in us-west1. What must be done to ensure traffic is automatically routed to the closest healthy backend?

A.Use a Network Load Balancer in us-central1 and configure a redirect to the new MIG.
B.Use a global external HTTP(S) load balancer and add both MIGs as backends.
C.Use an internal TCP/UDP load balancer in each region and configure DNS-based routing.
D.Use an external TCP/UDP Network Load Balancer with the new MIG as an additional backend.
AnswerB

A global external HTTP(S) load balancer provides a single anycast VIP with Google's global frontend, so it can route each user to the closest healthy backend across both us-central1 and us-west1 MIGs. A regional load balancer cannot span regions.

Why this answer

A global external HTTP(S) load balancer can route traffic to backends in multiple regions and automatically directs requests to the closest healthy backend based on the client's geographic location and backend health. Adding both MIGs as backends to this single anycast IP ensures traffic is distributed to the nearest region without additional DNS-based routing or redirects.

Exam trap

The trap here is that candidates confuse regional load balancers (Network Load Balancer, TCP/UDP Proxy) with global load balancers, assuming any external load balancer can span regions, but only the global external HTTP(S) load balancer (and the global external SSL proxy) support multi-region backends with automatic proximity-based routing.

How to eliminate wrong answers

Option A is wrong because a Network Load Balancer is regional and cannot route traffic across regions; a redirect would introduce a single point of failure and latency, not automatic closest-backend routing. Option C is wrong because internal TCP/UDP load balancers are regional and cannot be used for external traffic; DNS-based routing would require manual configuration and does not provide automatic proximity-based routing with health-aware failover. Option D is wrong because an external TCP/UDP Network Load Balancer is regional (not global) and cannot distribute traffic to backends in multiple regions; it only supports backends within a single region.

87
MCQhard

A global e-commerce platform is experiencing intermittent latency spikes during flash sales. The application is deployed on Google Kubernetes Engine (GKE) with a regional cluster. The architecture includes a frontend service, a product catalog service using Cloud Spanner, and an order processing service using Cloud Pub/Sub. During high load, the catalog service shows increased query latency, and some requests time out. What should the architect prioritize to address the issue?

A.Use Cloud CDN to cache product catalog responses.
B.Increase the number of nodes in the GKE node pool.
C.Enable Cloud Spanner interleaved tables and add secondary indexes for common query filters.
D.Migrate the catalog service from Cloud Spanner to Cloud Bigtable for better read performance.
AnswerC

Cloud Spanner query latency under flash-sale load stems from scanning non-interleaved tables and full-table reads. Interleaving co-locates child rows with parents, and secondary indexes accelerate the catalog's common filter queries, cutting the data scanned and reducing timeouts at the database layer.

Why this answer

The issue is specifically with Cloud Spanner query latency under high load. Enabling interleaved tables and adding secondary indexes optimizes data locality and query performance, reducing the need for expensive cross-table joins and full table scans. This directly addresses the root cause of increased latency and timeouts in the catalog service.

Exam trap

The trap here is that candidates often confuse horizontal scaling (adding nodes) with database optimization, overlooking that Cloud Spanner performance issues require schema-level tuning rather than infrastructure scaling.

How to eliminate wrong answers

Option A is wrong because Cloud CDN caches static content at edge locations, but the product catalog service uses Cloud Spanner for dynamic, frequently updated data; caching would serve stale data and not resolve database query latency. Option B is wrong because increasing GKE nodes adds compute capacity but does not fix the underlying database query performance issue; the bottleneck is in Cloud Spanner, not in pod scheduling or node resources. Option D is wrong because Cloud Bigtable is optimized for high-throughput, low-latency key-value lookups, not for complex queries with secondary filters or joins; migrating would require significant architectural changes and may not support the catalog service's query patterns.

88
MCQmedium

Your team runs a stateful analytics workload on a Managed Instance Group (MIG) of Compute Engine VMs. The VMs write intermediate results to local SSD scratch disks. During a recent incident, an autoscaling event terminated VMs and the intermediate data was lost, causing hours of recomputation. You need to change the deployment so that when a VM is terminated by the autoscaler, a shutdown script has enough time to flush the intermediate results to a Cloud Storage bucket before the VM is deleted. What should you do?

A.Replace the local SSD scratch disks with Persistent Disk volumes and rely on the autoscaler to detach them before deleting the VM.
B.Enable live migration on the MIG and set the autoscaler to scale in only during off-peak hours.
C.Set the MIG autoscaler's scale-in control to a longer cool-down period, and increase the instance template's minimum CPU utilization target.
D.Configure the instance template with a shutdown script and set the instance's shutdown duration metadata key to a value that gives the script enough time to flush data.
AnswerD

Compute Engine supports a per-instance shutdown duration, specified through the shutdown-duration metadata key, which extends the time the instance stays in the STOPPING state so a shutdown script can complete. Setting this on the instance template ensures every VM created by the MIG, including autoscaler-created ones, has enough time to flush intermediate results to Cloud Storage.

Why this answer

The shutdown duration metadata key is the supported mechanism to extend the STOPPING state so a shutdown script can finish. Because the MIG creates instances from the instance template, placing the key in the template guarantees that autoscaler-created VMs inherit the behavior. Autoscaler tuning and disk-type changes do not bound the time between the shutdown signal and instance deletion.

Exam trap

The trap here is assuming that autoscaler cool-down or scheduling controls how long a terminating VM stays alive, when only the shutdown duration setting actually extends that window.

89
MCQhard

During a load test, an application running on GKE experiences high latency and errors. You suspect the issue is due to insufficient cluster resources. Which gcloud command should you use to quickly check the current resource utilization of all nodes in the cluster?

A.gcloud container clusters describe
B.gcloud container clusters list
C.gcloud container clusters get-credentials
D.gcloud compute instances list
AnswerD

This command lists all compute instances, including GKE cluster nodes, and shows their status. While it does not display real-time CPU/memory usage, it quickly provides a list of nodes and their current state, which can help identify if nodes are down or overutilized based on status. However, for exact resource utilization, you would use kubectl top nodes.

Why this answer

None of the listed gcloud commands shows current resource utilization of GKE nodes. gcloud container clusters describe shows configuration, gcloud container clusters list lists clusters, gcloud container clusters get-credentials retrieves credentials, and gcloud compute instances list only lists instances and their status. The correct command for current CPU/memory utilization is kubectl top nodes.

Exam trap

Do not assume that gcloud container clusters describe or gcloud compute instances list shows resource utilization. They do not provide current CPU/memory metrics; use kubectl top nodes for that.

90
Multi-Selecthard

A healthcare company runs a patient portal on Google Kubernetes Engine (GKE). Auditors require that all container images be scanned for vulnerabilities before deployment and that only images from a trusted registry be admitted to the cluster. You are configuring Binary Authorization. Which TWO actions should you take to meet these requirements? (Choose two.)

Select 2 answers
A.Enable the Container Analysis API and configure a vulnerability scanning policy so that images pushed to Artifact Registry are analyzed automatically.
B.Create a Binary Authorization attestor and require an attestation from a trusted build pipeline before images can be deployed.
C.Apply a Kubernetes NetworkPolicy that allows egress only to the trusted registry so nodes cannot pull other images.
D.Configure a PodSecurityPolicy that restricts images to those hosted in Artifact Registry.
E.Set the cluster's default namespace to use the kube-system service account for all workloads so admission checks are bypassed.
AnswersA, B

Container Analysis performs automated vulnerability scanning on images in Artifact Registry and records findings as metadata. Binary Authorization attestations can be based on the results of that analysis, so enabling scanning is a prerequisite for enforcing that only scanned images are admitted. Without scanning, there is no vulnerability signal for the policy to evaluate.

Why this answer

Binary Authorization enforces deploy-time policy based on attestations. Enabling Container Analysis provides automated vulnerability scanning of registry images, and defining an attestor that your trusted build pipeline signs ensures only verified images are admitted. Together they create a verifiable chain from scanning to admission, which satisfies the auditors' requirements.

Exam trap

The trap here is assuming that Kubernetes PodSecurityPolicy or NetworkPolicy can restrict image sources, when only Binary Authorization evaluates image provenance at admission time.

91
MCQeasy

A developer needs to programmatically create and manage Compute Engine instances. Which Google Cloud service should they use to authenticate and authorize service accounts?

A.Cloud Audit Logs
B.Cloud Key Management Service (KMS)
C.Cloud Scheduler
D.Cloud IAM
AnswerD

Cloud IAM provides the identity and access management layer for Google Cloud, letting code authenticate as a service account and receive scoped permissions to create and manage Compute Engine instances. It satisfies the stem's need for both authentication and authorisation of programmatic service account access.

Why this answer

Cloud IAM is the correct service because it provides the identity and access management framework for authenticating and authorizing service accounts. When a developer creates Compute Engine instances, they must attach a service account and grant IAM roles (e.g., roles/compute.instanceAdmin) to define what actions that service account can perform. Cloud IAM handles the authentication via OAuth 2.0 tokens and authorization via role-based access control (RBAC), making it the foundational service for managing service account permissions.

Exam trap

Google Cloud often tests the misconception that Cloud Audit Logs or Cloud KMS can handle authentication/authorization, but candidates must remember that only Cloud IAM manages identities and permissions, while the other options serve logging or encryption purposes.

How to eliminate wrong answers

Option A is wrong because Cloud Audit Logs is a logging service that records API calls and administrative actions, not a service for authenticating or authorizing service accounts. Option B is wrong because Cloud Key Management Service (KMS) manages cryptographic keys for encryption, not identity or permission management for service accounts. Option C is wrong because Cloud Scheduler is a cron-job service for triggering tasks on a schedule, and it has no role in authentication or authorization of service accounts.

92
MCQeasy

An organization wants to enforce that all container images deployed to Google Kubernetes Engine (GKE) clusters are signed by an authorized authority and only those images are allowed to run. Which GCP service should they use?

A.Cloud Key Management Service (Cloud KMS)
B.Binary Authorization
C.Cloud Build
D.Artifact Registry
AnswerB

Binary Authorization enforces deploy-time attestation, admitting only container images whose signatures match an authorised attestor policy. It intercepts the GKE admission path, so unsigned or unauthorised images are rejected before running. This satisfies the stem's requirement that only images signed by an authorised authority execute.

Why this answer

Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed on GKE. It works by enforcing attestations that are created by authorized authorities after verifying the image's signature. This allows you to enforce that only images signed by an authorized authority are allowed to run.

Exam trap

The trap is confusing Binary Authorization with Cloud KMS or Artifact Registry. Candidates might think that signing images with Cloud KMS is enough, but enforcement requires Binary Authorization. Also, Cloud Build can sign but not enforce.

How to eliminate wrong answers

Option A is wrong because Cloud KMS is a key management service used to create and manage cryptographic keys, but it does not enforce deployment policies. Option C is wrong because Cloud Build is a CI/CD service that can build and sign images, but it does not enforce that only signed images run. Option D is wrong because Artifact Registry is a repository for container images, but it does not enforce signing or deployment policies.

93
MCQeasy

A company is planning to deploy a global web application on Google Cloud. They expect low latency for users worldwide and need to serve static content (images, CSS) as well as dynamic API responses. Which architecture should they use?

A.Use Cloud CDN in front of an external HTTPS Load Balancer with backend services in multiple regions.
B.Use Cloud NAT to allow egress traffic from instances and distribute static content via a shared VPC.
C.Use Cloud DNS with geo-routing to direct users to the closest regional Cloud Run service.
D.Use VPC Network Peering to connect multiple regional VPCs and serve content from a central location.
AnswerA

Cloud CDN caches static assets at edge locations, while the external HTTPS Load Balancer with multi-region backends routes dynamic API traffic to the nearest healthy region, satisfying the worldwide low-latency requirement for both content types.

Why this answer

Cloud CDN in front of an external HTTPS Load Balancer with backend services in multiple regions is correct because it provides global anycast IP termination, low-latency content delivery via Google's edge cache for static content, and dynamic API requests are forwarded to the nearest healthy backend in the closest region. This architecture meets both the low-latency requirement for users worldwide and the need to serve both static and dynamic content efficiently.

Exam trap

Google Cloud often tests the misconception that DNS geo-routing alone (Option C) can provide low-latency global content delivery, but it lacks caching and introduces DNS resolution delays, making it unsuitable for static content without a CDN.

How to eliminate wrong answers

Option B is wrong because Cloud NAT is used for outbound internet access from private instances, not for distributing static content or reducing latency for global users; it does not provide any caching or global load balancing. Option C is wrong because Cloud DNS with geo-routing directs traffic based on DNS resolution, but it cannot cache static content and introduces DNS propagation delays; Cloud Run services alone do not include a CDN for static assets. Option D is wrong because VPC Network Peering connects VPCs for private networking but does not provide global load balancing, caching, or low-latency content delivery; serving from a central location would increase latency for distant users.

94
MCQeasy

A company wants to set a monthly spending limit for their Compute Engine usage and receive alerts when spending exceeds a threshold. Which tool should they use?

A.Cloud Monitoring
B.Cloud Budget alerts
C.Cloud Logging
D.Cloud Armor
AnswerB

Cloud Budget alerts let you set a monthly spend threshold scoped to a billing account or project and trigger notifications when actual or forecast spend exceeds it. This directly satisfies the stem's requirement for a spending limit with threshold-based alerts, which Compute Engine quotas cannot provide.

Why this answer

Budget alerts in Cloud Billing allow you to set a spending budget and receive notifications when actual spending exceeds thresholds. They can be scoped to projects or services.

95
MCQmedium

A media company's analytics team runs a nightly Apache Spark ETL job on a Dataproc cluster with 20 worker nodes. The job processes raw logs from Cloud Storage and writes Parquet files back to Cloud Storage. The cluster is created before the job starts and deleted after the job finishes, taking about 90 minutes total. The team wants to reduce the cost of this workload without changing the Spark code or increasing job runtime. What should they do?

A.Move the Spark job to a Dataproc Serverless for Spark workload to eliminate cluster management.
B.Replace the 20 n1-standard-4 workers with 10 n1-standard-8 workers to reduce node count.
C.Enable Dataproc's autoscaling policy on the cluster so worker nodes scale down during idle periods.
D.Use Spot VMs for the Dataproc worker nodes and set a graceful decommissioning timeout.
AnswerD

Spot VMs cost substantially less than standard VMs, and Dataproc supports them natively for worker nodes with graceful decommissioning so preempted nodes finish in-flight tasks before removal. Since the cluster is ephemeral and Spark can retry tasks, preemption risk is acceptable, directly lowering compute cost without touching code or extending runtime.

Why this answer

Spot VMs are the standard cost lever for fault-tolerant, ephemeral Dataproc batch workloads. Because the cluster exists only for the job duration and Spark tolerates task retries, preemption is an acceptable risk that is offset by a large discount. Autoscaling and resizing do not reduce the per-hour price of compute for a continuously busy job, and moving to Serverless changes the execution model rather than guaranteeing savings.

Exam trap

The trap here is assuming that autoscaling always saves money, when a short-lived, continuously busy batch cluster has no idle capacity for scale-down to reclaim.

96
MCQmedium

A developer needs to securely store a database password that will be used by a Compute Engine instance. The password must be rotated automatically every 30 days. Which service should they use?

A.Cloud KMS
B.Cloud Storage with encryption
C.Environment variables
D.Secret Manager
AnswerD

Secret Manager stores the database password as a versioned secret and supports rotation schedules, satisfying the 30-day automatic rotation constraint. A Compute Engine instance retrieves it at runtime via its service account, so the credential never sits in code or instance metadata.

Why this answer

Google Cloud Secret Manager is designed to store, manage, and rotate secrets such as database passwords, API keys, and certificates. It supports automatic rotation schedules via Pub/Sub notifications and Cloud Functions or Cloud Run, making it the correct choice for a password that must rotate every 30 days. Cloud KMS manages encryption keys, not application secrets.

Exam trap

PCA often tests the confusion between Cloud KMS (encryption key management) and Secret Manager (application secret storage and rotation), trapping candidates who pick KMS for password storage.

How to eliminate wrong answers

Option A is wrong because Cloud KMS manages cryptographic keys for encryption/decryption, not arbitrary application secrets like database passwords, and it does not provide secret rotation scheduling. Option B is wrong because Cloud Storage with encryption stores objects but does not provide secret management, versioning of secrets, or automatic rotation. Option C is wrong because environment variables are not secure storage — they can be exposed in logs, process listings, and crash dumps, and they offer no rotation mechanism.

97
Multi-Selecthard

A company wants to implement a CI/CD pipeline for a Java application that will be deployed to Cloud Run. They use Cloud Build and Artifact Registry. The pipeline must compile the Java code, run unit tests, build a container image, and deploy to Cloud Run. Which THREE steps are required in the cloudbuild.yaml? (Choose 3)

Select 3 answers
A.Step with image 'gcloud' and entrypoint: 'gcloud', args: ['container', 'clusters', 'get-credentials']
B.Step with image 'docker' and args: ['build', '-t', '...']
C.Step with image 'maven' and args: ['mvn', 'compile', 'test']
D.Step with image 'node' and entrypoint: 'npm', args: ['test']
E.Step with image 'gcloud' and entrypoint: 'gcloud', args: ['run', 'deploy', ...]
AnswersB, C, E

The docker builder executes the container image build, tagging the artefact that Artifact Registry will store. This satisfies the pipeline's requirement to produce a deployable image from the application source before the Cloud Run deployment step runs.

Why this answer

Option B is correct because building the container image for the Java application requires a Docker build step (e.g., image 'docker' with args ['build', '-t', '...']), which produces the image that will later be pushed to Artifact Registry and deployed to Cloud Run. Option C is correct because compiling the Java code and running unit tests is done with Maven, so a step using the 'maven' image with args ['mvn', 'compile', 'test'] satisfies the compile-and-test requirement of the pipeline. Option E is correct because deploying the built image to Cloud Run requires a gcloud step invoking 'gcloud run deploy' with the appropriate service, image, region, and platform flags.

Option A is not needed because 'gcloud container clusters get-credentials' configures kubectl access to a GKE cluster, which is irrelevant when the target is Cloud Run. Option D is not needed because an npm test step applies to Node.js projects, not a Java application built with Maven.

Exam trap

PCA often tests the confusion between GKE and Cloud Run deployment steps, leading candidates to select GKE-specific commands like 'get-credentials' when Cloud Run is the target.

98
MCQmedium

A company stores sensitive customer data in Cloud Storage buckets. They want to ensure that access to these buckets is only allowed from within their VPC network. Which configuration should they use?

A.Bucket IAM policies with condition on service account
B.Cloud Armor WAF rules
C.Private Google Access for on-premises
D.VPC Service Controls with a service perimeter
AnswerD

VPC Service Controls perimeters restrict Cloud Storage access to authorised VPC networks, blocking requests originating outside the perimeter even with valid credentials. This directly enforces the requirement that bucket access occur only from within the company's VPC network, mitigating data exfiltration.

Why this answer

D is correct because VPC Service Controls (VPC-SC) allow you to define a service perimeter that restricts access to Google Cloud Storage (and other managed services) to only requests originating from a specified VPC network. This ensures that data exfiltration and unauthorized access from outside the VPC are blocked, even if the bucket is publicly accessible or IAM allows broader access.

Exam trap

The trap here is that candidates often confuse VPC Service Controls with Private Google Access or IAM conditions, not realizing that VPC-SC is the only option that enforces network-level boundaries for Google-managed services like Cloud Storage.

How to eliminate wrong answers

Option A is wrong because Bucket IAM policies with a condition on a service account can restrict which service account can access the bucket, but they do not limit access to only requests from within a VPC network; the request could still come from outside the VPC if the service account is used elsewhere. Option B is wrong because Cloud Armor WAF rules are designed to protect HTTP(S) load-balanced applications from web attacks, not to enforce network-level access controls for Cloud Storage buckets accessed via gRPC or REST APIs. Option C is wrong because Private Google Access for on-premises allows on-premises hosts (using private IPs) to reach Google APIs and services, but it does not restrict access to only within a VPC; it actually enables access from outside the VPC, which is the opposite of the requirement.

99
MCQhard

An organization has multiple projects in Google Cloud and wants to centralize logging and monitoring for all projects. They need to aggregate logs from all projects into a single project for analysis. Which approach should they use?

A.Export logs from each project to a Cloud Storage bucket and then import them into BigQuery.
B.Enable Cloud Audit Logs for all projects and view them from the central project.
C.Install the Stackdriver agent on all VMs and point them to the central project.
D.Create a logs sink in each project that exports logs to a BigQuery dataset in the central project.
AnswerD

A logs sink in each project routes log entries to a BigQuery dataset hosted in the central project, aggregating all projects' logs for centralised analysis. This satisfies the requirement to consolidate logs into a single project without per-project querying.

Why this answer

Google Cloud's logs sink feature allows you to route logs from multiple source projects to a centralized BigQuery dataset in a single destination project. This approach aggregates logs efficiently without requiring agents or manual import steps, and it supports real-time log export for analysis.

Exam trap

The trap here is that candidates confuse the Stackdriver agent (which collects logs from VMs) with the logs sink feature (which routes logs from projects), leading them to choose Option C instead of the correct centralized export method.

How to eliminate wrong answers

Option A is wrong because exporting logs to Cloud Storage and then importing them into BigQuery adds unnecessary latency and complexity; logs sinks can export directly to BigQuery. Option B is wrong because Cloud Audit Logs are enabled per project and cannot be centrally viewed without aggregation; they must be exported via sinks to a central project. Option C is wrong because the Stackdriver agent (now legacy) is used for collecting VM metrics and logs, but it cannot aggregate logs from multiple projects into a single central project; logs sinks are the correct mechanism for cross-project log aggregation.

100
MCQmedium

A global e-commerce company is designing a multi-region architecture on Google Cloud to ensure high availability and low latency for users worldwide. They want to use a global load balancer that can route traffic to the closest healthy backend and support HTTP(S) and TCP traffic. Which Google Cloud load balancing option should they use?

A.Global external HTTP(S) load balancer with TCP proxy
B.Global external TCP/UDP load balancer
C.Global external HTTP(S) load balancer and global external TCP proxy load balancer
D.Global external HTTP(S) load balancer
AnswerC

To support both HTTP(S) and TCP traffic with global load balancing and proximity routing, you can use two separate load balancers: the global external HTTP(S) load balancer for HTTP(S) traffic and the global external TCP proxy load balancer for TCP traffic. Both are global and route to the closest healthy backend. This combination meets all requirements.

Why this answer

Google Cloud offers separate global load balancers for different protocols. The global external HTTP(S) load balancer handles HTTP(S) traffic with proximity-based routing, while the global external TCP proxy load balancer handles TCP traffic with global anycast IP and proximity routing. Using both together provides the required support for both protocols in a multi-region architecture.

Exam trap

The trap here is assuming a single load balancer can handle both HTTP(S) and TCP traffic globally, but Google Cloud separates these into different load balancer types.

101
MCQhard

A healthcare organization uses Cloud Storage to store protected health information (PHI). They have a compliance requirement to ensure that all objects in the bucket are encrypted with a customer-managed key (CMK) that is rotated every 90 days. They also need to log all access to the bucket and detect anomalous access patterns. Which combination of Google Cloud services should they use?

A.Cloud Storage with default encryption, Cloud Audit Logs, and Security Command Center
B.Cloud Storage with CMEK via Cloud HSM, Cloud Audit Logs, and Cloud DLP
C.Cloud Storage with CSEK, Cloud Audit Logs, and Security Command Center
D.Cloud Storage with CMEK via Cloud KMS, Cloud Audit Logs, and Chronicle
AnswerD

CMEK via Cloud KMS supplies the customer-managed key with configurable 90-day rotation, satisfying the encryption constraint. Cloud Audit Logs capture every bucket access for compliance evidence, while Chronicle ingests those logs to detect anomalous access patterns through its security analytics. Together these three services meet each stated requirement.

Why this answer

Cloud Storage with CMEK via Cloud KMS allows the organization to use a customer-managed key that can be rotated every 90 days, meeting the compliance requirement. Cloud Audit Logs capture all access to the bucket, and Chronicle provides advanced security analytics to detect anomalous access patterns, fulfilling the logging and detection needs.

Exam trap

The trap here is confusing the key management options (CMEK vs. CSEK vs. default encryption) and the security analytics tools (Security Command Center vs. Chronicle), where candidates often pick Security Command Center for anomaly detection when Chronicle is specifically designed for log-based threat detection.

How to eliminate wrong answers

Option A is wrong because default encryption uses Google-managed keys, not a customer-managed key (CMK), and Security Command Center provides vulnerability scanning but not the specific anomalous access pattern detection required. Option B is wrong because Cloud HSM is a hardware security module service for key management, but the question specifies CMEK via Cloud KMS, and Cloud DLP is for data loss prevention, not for logging or detecting anomalous access patterns. Option C is wrong because CSEK (customer-supplied encryption keys) requires the customer to manage the key material directly, which does not support automatic rotation every 90 days as needed, and Security Command Center is not designed for real-time anomalous access pattern detection like Chronicle.

102
MCQmedium

A company monitors their application with Cloud Monitoring. They set up an alerting policy to notify the on-call team when the 99th percentile latency exceeds 500 ms for 5 minutes. However, they receive false positive alerts due to short bursts. How should they refine the policy?

A.Set up alerting on each data point individually.
B.Decrease the threshold to 400 ms.
C.Change the metric to average latency instead of 99th percentile.
D.Increase the evaluation window to 10 minutes.
AnswerD

Extending the evaluation window to 10 minutes requires latency to breach 500 ms across a longer sustained period, filtering out brief spikes that triggered false positives. This directly addresses the stem's short-burst problem while retaining detection of genuine sustained degradation.

Why this answer

Increasing the evaluation window to 10 minutes smooths out short bursts of high latency, ensuring the alert triggers only when the 99th percentile latency exceeds 500 ms for a sustained period. Cloud Monitoring evaluates metrics over the specified window, so a longer window reduces false positives from transient spikes while still detecting genuine degradation.

Exam trap

Google Cloud often tests the misconception that lowering thresholds or changing percentiles reduces false positives, when in reality the evaluation window duration is the key lever for filtering out short-lived bursts without sacrificing sensitivity to sustained issues.

How to eliminate wrong answers

Option A is wrong because setting up alerting on each data point individually would make the policy hypersensitive to every single spike, increasing false positives rather than reducing them. Option B is wrong because decreasing the threshold to 400 ms would cause the alert to fire even more frequently, including during normal operation, exacerbating the false positive problem. Option C is wrong because changing the metric to average latency masks tail latency issues; the 99th percentile is specifically used to catch outliers, and averaging would hide the very bursts they want to monitor, potentially missing real problems.

103
MCQhard

A financial services firm runs a global trading platform on Google Cloud. The architecture must survive the loss of an entire region with a recovery point objective of zero and a recovery time objective of under one minute, and it must keep strong consistency for order records. Which design should the architect recommend?

A.Deploy the application in two regions behind a global external Application Load Balancer, and store order records in Cloud Spanner with a multi-region instance configuration.
B.Deploy the application in two regions behind a global external Application Load Balancer, and store order records in a Cloud SQL for PostgreSQL instance with a cross-region read replica promoted on failover.
C.Deploy the application in two regions behind a global external Application Load Balancer, and store order records in a Bigtable instance with a multi-cluster routing policy.
D.Deploy the application in two regions behind a global external Application Load Balancer, and store order records in a multi-region Cloud Storage bucket mounted as a file system on the application VMs.
AnswerA

A multi-region Cloud Spanner configuration replicates data synchronously across regions and provides external consistency, so no committed order is lost when a region fails, satisfying the zero RPO. Spanner redirects traffic to surviving replicas automatically, and the global external Application Load Balancer steers users to healthy backends within seconds, meeting the sub-minute RTO. This combination is the standard design for globally consistent, region-fault-tolerant transactional systems on Google Cloud.

Why this answer

Zero RPO with sub-minute RTO for transactional records requires synchronous replication plus automated failover. Cloud Spanner multi-region configurations replicate synchronously and expose externally consistent reads and writes, so a committed order survives a full region outage. The global external Application Load Balancer provides anycast front ends and health-check-based failover to the surviving region.

Together they deliver the availability and consistency guarantees the trading platform needs without manual intervention.

Exam trap

The trap here is treating any multi-region data service as equivalent, when replicas that are asynchronous cannot satisfy a zero recovery point objective.

104
MCQeasy

A startup wants to deploy a web application on Google Cloud with a MySQL database. They anticipate low traffic initially but want the ability to scale seamlessly. They also want to minimize operational overhead. Which combination of services should they choose?

A.Compute Engine with a self-managed MySQL instance.
B.Cloud Run with Cloud Spanner.
C.App Engine Standard Environment with Cloud SQL.
D.Google Kubernetes Engine (GKE) with Cloud SQL.
AnswerC

App Engine Standard automatically scales instances with traffic and requires no server management, while Cloud SQL provides a managed MySQL database, together minimising operational overhead. This pairing satisfies the low-traffic start, seamless scaling, and reduced administration constraints.

Why this answer

App Engine Standard Environment provides a fully managed, autoscaling platform for web applications, while Cloud SQL offers a managed MySQL database with automatic replication and backups. This combination minimizes operational overhead because Google handles infrastructure provisioning, patching, and scaling, and Cloud SQL integrates natively with App Engine via the Cloud SQL proxy or Unix socket, requiring no manual configuration for connectivity.

Exam trap

Google Cloud often tests the misconception that Kubernetes (GKE) is always the best choice for scalability, but the trap here is that for a low-traffic application with minimal operational overhead requirements, a fully managed platform like App Engine Standard Environment is more appropriate than the complex orchestration overhead of GKE.

How to eliminate wrong answers

Option A is wrong because Compute Engine with a self-managed MySQL instance requires the startup to manually handle OS patching, database backups, replication, and scaling, which increases operational overhead and contradicts the goal of minimizing it. Option B is wrong because Cloud Spanner is a globally distributed, strongly consistent relational database designed for high-throughput, horizontal scaling, which is overkill and more expensive for a low-traffic web application that only needs a MySQL-compatible database. Option D is wrong because Google Kubernetes Engine (GKE) introduces significant operational complexity for managing container orchestration, node pools, and networking, which is unnecessary for a low-traffic application that could be served by a simpler, fully managed platform like App Engine.

105
MCQeasy

A startup wants to deploy a containerized application with minimal operational overhead. They expect variable traffic. Which compute option should they choose?

A.App Engine Flexible Environment
B.Cloud Run
C.Compute Engine single VM
D.Google Kubernetes Engine (GKE)
AnswerB

Cloud Run abstracts all infrastructure, scaling containers to zero when idle and automatically with demand, which directly satisfies the minimal operational overhead and variable traffic constraints. Unlike GKE, no cluster nodes require patching or capacity planning, and billing occurs only per request, suiting unpredictable startup workloads.

Why this answer

Cloud Run is the correct choice because it is a fully managed serverless compute platform that automatically scales from zero based on traffic, charges only for resources used during request processing, and eliminates all infrastructure management. This aligns perfectly with the startup's requirement for minimal operational overhead and handling variable traffic patterns without provisioning or scaling concerns.

Exam trap

The trap here is that candidates often confuse Cloud Run with App Engine Flexible Environment, assuming both are fully managed, but App Engine Flexible Environment does not scale to zero and requires VM-level management, making Cloud Run the only option that truly minimizes operational overhead for variable traffic.

How to eliminate wrong answers

Option A is wrong because App Engine Flexible Environment requires you to manage the underlying VM instances and does not scale to zero, incurring costs even when idle, which contradicts the goal of minimal operational overhead and cost efficiency for variable traffic. Option C is wrong because a single Compute Engine VM provides no autoscaling, requires manual capacity planning and maintenance, and cannot handle variable traffic without manual intervention or over-provisioning, leading to either downtime or wasted resources. Option D is wrong because Google Kubernetes Engine (GKE) introduces significant operational overhead for cluster management, node scaling, and Kubernetes configuration, which is excessive for a simple containerized application with variable traffic and contradicts the 'minimal operational overhead' requirement.

106
MCQhard

You are responsible for ensuring the reliability of a high-traffic web application running on Google Kubernetes Engine (GKE). You need to implement a monitoring strategy that alerts you when the application's error rate exceeds 1% over a 5-minute window. You want to minimize false positives and ensure alerts are actionable. What should you do?

A.Configure a log-based metric in Cloud Logging that counts log entries with severity ERROR, and create an alerting policy if the count exceeds a threshold.
B.Create a Cloud Monitoring alerting policy based on the HTTP load balancer's 5xx error rate metric, with a threshold of 1% and a duration of 5 minutes.
C.Use Prometheus to scrape application metrics and configure an alert in Prometheus Alertmanager for error rate > 1% over 5 minutes.
D.Create an uptime check in Cloud Monitoring that checks the application's health endpoint and alerts if it fails for 5 minutes.
AnswerB

The HTTP(S) load balancer exposes metrics such as request count and error count, which can be used to compute a 5xx error rate. An alerting policy with a 1% threshold over a 5-minute duration matches the requirement. Using the load balancer metric is reliable because it captures errors at the edge and is not affected by pod restarts or internal issues.

Why this answer

Using the HTTP(S) load balancer's 5xx error rate metric provides a direct measure of errors as seen by clients. An alerting policy with a 1% threshold over 5 minutes aligns with the requirement. This approach is managed, reliable, and minimizes false positives because it uses a consistent metric from the load balancer, not application logs or internal metrics.

Exam trap

The trap here is relying on log-based metrics or uptime checks, which may not accurately reflect the actual error rate experienced by users.

107
MCQeasy

To achieve a 99.999% availability SLA for a globally distributed application using Cloud Spanner, which configuration is required?

A.Multi-region instance configuration
B.Fine-grained access control
C.Single-region instance configuration
D.Customer-managed encryption keys (CMEK)
AnswerA

A multi-region instance configuration replicates data across regions with synchronous quorum writes, which is the only Spanner topology whose SLA reaches 99.999%. Regional configurations cap at 99.99%, so multi-region satisfies the availability constraint in the stem.

Why this answer

Cloud Spanner multi-region configuration provides 99.999% SLA. Single-region offers 99.99%. Fine-grained access control and customer-managed encryption keys (CMEK) do not affect availability SLA.

108
MCQmedium

A company runs batch analytics workloads on Compute Engine that can tolerate interruptions. They want to reduce compute costs by up to 60-90%. Which compute option is the most cost-effective?

A.On-demand VMs
B.Committed use discounts (1-year)
C.Preemptible VMs
D.Sustained use discounts
AnswerC

Preemptible VMs offer up to 80% discounts versus standard instances, directly meeting the 60–90% cost-reduction constraint. They suit interruption-tolerant batch analytics because Compute Engine terminates them after 24 hours maximum, with 30-second preemption notice. This makes them the cheapest option for workloads that can checkpoint and resume.

Why this answer

Preemptible VMs are Google's spot-equivalent instances that can be terminated at any time when resources are needed elsewhere, and they offer discounts of up to 60-91% compared to on-demand pricing. Since the batch analytics workloads are explicitly described as interruption-tolerant, they are the ideal fit for preemptible VMs, which is why they deliver the greatest cost savings here.

Exam trap

PCA often tests the distinction between discount mechanisms — candidates confuse sustained use discounts (automatic, ~30%) and committed use discounts (contractual, ~57%) with preemptible/spot pricing (up to 91%), and forget that preemptible VMs require fault-tolerant workloads.

How to eliminate wrong answers

Option A is wrong because on-demand VMs are the baseline full-price option with no discount, so they cannot reduce costs by 60-90%. Option B is wrong because committed use discounts only save roughly 20-57% and require a 1- or 3-year commitment, which is less than the 60-90% target and locks in spend. Option D is wrong because sustained use discounts apply automatically to long-running on-demand VMs (up to ~30%) and do not reach the 60-90% savings level.

109
Multi-Selectmedium

An organization needs to implement a change management process for a mission-critical application on GKE. They want to validate performance before full rollout and be able to roll back quickly. Which THREE practices should they adopt? (Choose THREE.)

Select 3 answers
A.Deploy changes directly to production
B.Implement canary deployments with traffic splitting
C.Use feature flags to enable/disable features dynamically
D.Manually monitor and roll back if issues appear
E.Define automated rollback policies in Cloud Deploy
AnswersB, C, E

Canary deployments with traffic splitting route a small percentage of live requests to the new revision, letting the team measure real performance before full rollout. If metrics degrade, shifting traffic back to the stable revision provides near-instant rollback.

Why this answer

Option B is correct because canary deployments with traffic splitting (e.g., via GKE Ingress, Anthos Service Mesh, or Istio VirtualService weights) let the team expose a new version to a small percentage of traffic, validating performance on real workloads before full rollout. Option C is correct because feature flags decouple deployment from release, allowing features to be toggled dynamically without redeploying, which supports fast rollback by disabling a flag rather than reverting a build. Option E is correct because Cloud Deploy supports automated rollback policies tied to rollout failures or verification results, enabling rapid, deterministic rollback of a bad release.

Option A is wrong because deploying directly to production bypasses validation and contradicts the requirement to test performance before full rollout. Option D is wrong because manual monitoring and rollback is slow, error-prone, and does not meet the goal of rolling back quickly compared to automated policies.

110
MCQeasy

Which Google Cloud service provides a fully managed, auto-scaling environment for running stateless HTTP(S) web applications using a variety of supported programming languages?

A.Cloud Functions
B.Google Kubernetes Engine
C.Compute Engine
D.App Engine Standard
AnswerD

App Engine Standard runs stateless HTTP(S) applications on a fully managed platform that scales instances automatically, including down to zero, and supports runtimes for Java, Python, Go, Node.js, PHP and others. This matches the stem's managed, auto-scaling, multi-language requirements.

Why this answer

App Engine Standard is the correct choice because it is a fully managed, auto-scaling platform specifically designed for stateless HTTP(S) web applications. It supports multiple programming languages (e.g., Python, Java, Go, PHP, Node.js) and automatically handles scaling, load balancing, and patching, allowing developers to focus on code without managing infrastructure.

Exam trap

The trap here is that candidates often confuse App Engine Standard with App Engine Flexible, which offers more customization but is not fully managed in the same way, or they mistakenly think Cloud Functions can serve persistent web applications, but Cloud Functions is limited to stateless, event-driven functions with a maximum timeout of 9 minutes and no support for persistent HTTP sessions.

How to eliminate wrong answers

Option A is wrong because Cloud Functions is a serverless compute service for event-driven, short-lived functions, not designed for persistent web applications requiring HTTP(S) request handling with full web frameworks. Option B is wrong because Google Kubernetes Engine (GKE) provides a managed Kubernetes cluster but requires manual configuration of auto-scaling, node pools, and cluster management, not a fully managed environment where the platform handles scaling automatically without user intervention. Option C is wrong because Compute Engine offers virtual machines with full control over the OS and scaling, but it is not fully managed—users must configure auto-scaling groups, health checks, and load balancers themselves, and it does not provide a built-in runtime for web applications.

111
MCQhard

Refer to the exhibit. A developer is trying to connect to the Kubernetes API server from their workstation using the master IP (34.67.89.12) but receives a timeout. The developer can reach other external IPs. What is the most likely reason for the timeout?

A.The cluster is in a different region than the developer's VPC.
B.The developer's workstation does not have the required firewall rule to allow traffic to the master IP.
C.The private cluster is configured with a private endpoint and public endpoint disabled, so the master IP is not accessible from outside the VPC.
D.The Kubernetes Engine API is not enabled in the developer's project.
AnswerC

A private endpoint with public endpoint disabled removes the externally routable master IP entirely, so packets to 34.67.89.12 are dropped before reaching the control plane. The developer's workstation sits outside the VPC, satisfying the stem's constraint that other external IPs remain reachable while the API server times out.

Why this answer

A private GKE cluster with a private endpoint and public endpoint disabled means the Kubernetes API server is only reachable from within the cluster's VPC network. The developer's workstation is outside the VPC, so attempts to reach the master IP (34.67.89.12) will time out, even though other external IPs are reachable. This is a common configuration for security-sensitive workloads that require the API server to be isolated from the public internet.

Exam trap

Google PCA often tests the distinction between a private GKE cluster with public endpoint disabled versus a cluster that is simply in a different region or has firewall issues, leading candidates to overlook the fact that a timeout from outside the VPC indicates the endpoint is not publicly accessible.

How to eliminate wrong answers

Option A is wrong because the cluster being in a different region than the developer's VPC does not inherently cause a timeout; cross-region connectivity is possible via public internet or VPN, and the developer can reach other external IPs, so region mismatch is not the issue. Option B is wrong because the developer's workstation firewall rules are irrelevant if the cluster's API server endpoint is not exposed to the public internet; the timeout occurs at the network level before any firewall on the workstation is evaluated. Option D is wrong because if the Kubernetes Engine API were not enabled, the developer would likely receive an API error (e.g., 403 or 404) rather than a timeout; a timeout indicates a network connectivity issue, not a disabled API.

112
MCQmedium

A company is planning a phased migration of their on-premises database to Cloud SQL. They want to minimize downtime and ensure data consistency. Which approach should they use?

A.Use Database Migration Service (DMS)
B.Lift and shift the database server to Compute Engine
C.Export the database to a SQL dump file and import into Cloud SQL
D.Use VM migration to move the database server
AnswerA

Database Migration Service performs continuous replication from the source into Cloud SQL, keeping the target synchronised until cutover. This minimises downtime and preserves consistency during the phased migration, unlike a one-off dump and load, which requires pausing writes.

Why this answer

Database Migration Service (DMS) supports continuous replication with minimal downtime. Export and import involves downtime. Lift-and-shift is not a GCP service.

VM migration is for servers, not databases.

113
MCQhard

A healthcare analytics company stores protected health information in Cloud Storage buckets. Auditors require that data be encrypted with customer-managed encryption keys (CMEK) and that key usage be logged separately from data access. The security team wants the ability to revoke access to the data by disabling a single key without deleting the data. Which configuration should the architect recommend?

A.Enable Bucket Lock on the bucket and configure a retention policy, then use Google-managed keys with Object Lifecycle Management to transition objects to Coldline storage.
B.Use Google-managed encryption keys and enable Data Access audit logs on the bucket to record every object read and write.
C.Create a Cloud KMS key ring and key in the same region as the bucket, set the bucket's default KMS key to that key, and enable Cloud KMS Data Access audit logs.
D.Store the data in a Cloud Storage bucket encrypted with a customer-supplied encryption key (CSEK) and rotate the key by re-uploading all objects with a new key each quarter.
AnswerC

CMEK on a Cloud Storage bucket is configured by setting a default KMS key, which must be in the same location as the bucket. Cloud KMS Data Access audit logs record every cryptographic operation separately from Cloud Storage data access logs, satisfying the separation requirement. Disabling the key version or the key itself renders the data unreadable without deleting objects, enabling revocation.

Why this answer

Customer-managed encryption keys in Cloud KMS let the organization control key lifecycle, and setting a bucket's default KMS key applies CMEK to every object automatically. Cloud KMS Data Access audit logs capture cryptographic operations independently of Cloud Storage access logs, meeting the separation requirement. Disabling the key version immediately makes objects unreadable, achieving revocation without deleting data, which is exactly the auditor's ask.

Exam trap

The trap here is confusing CSEK with CMEK, since both involve customer-supplied key material but only Cloud KMS CMEK provides centralized audit logging and disable-to-revoke behavior.

114
MCQmedium

A company has a global user base and wants to serve static content (images, videos, CSS) with low latency from edge locations. They also want to protect their origin server from traffic spikes. Which combination of services should they use?

A.Cloud Armor with Cloud CDN
B.Cloud CDN with an internal TCP/UDP load balancer
C.Cloud CDN with an external HTTP(S) Load Balancer
D.Cloud Functions to serve static content
AnswerC

Cloud CDN caches static assets at Google's edge locations, cutting latency for the global user base, while the external HTTP(S) Load Balancer absorbs and distributes traffic spikes, shielding the origin server. Together they satisfy both the latency and origin-protection constraints.

Why this answer

Cloud CDN caches static content at Google's global edge locations to reduce latency, and it must be fronted by an external HTTP(S) Load Balancer, which provides the anycast IP, health checking, and origin shielding that Cloud CDN relies on. Together they serve static assets from edge caches and absorb traffic spikes before they reach the origin. This is the standard GCP pattern for global static content delivery with origin protection.

Exam trap

The trap is forgetting that Cloud CDN cannot stand alone — it must be attached to an external HTTP(S) Load Balancer, so options pairing it with internal LBs or omitting the LB entirely are wrong.

How to eliminate wrong answers

Option A is wrong because Cloud Armor is a WAF/DDoS protection service, not a CDN — pairing it with Cloud CDN omits the required external HTTP(S) Load Balancer that Cloud CDN depends on. Option B is wrong because an internal TCP/UDP load balancer is for internal, non-HTTP traffic and cannot front Cloud CDN, which requires an external HTTP(S) load balancer. Option D is wrong because Cloud Functions is a serverless compute service, not a CDN — it does not provide edge caching or global low-latency static delivery.

115
MCQeasy

A company is using Cloud NAT to allow private instances to access the internet. They notice that outbound connections are failing intermittently. What is the most likely cause?

A.The private instances are using the wrong DNS server.
B.The VPC firewall rules are blocking egress traffic.
C.Cloud NAT does not support TCP connections.
D.The number of concurrent connections exceeds the Cloud NAT source port capacity for the assigned NAT IPs.
AnswerD

Cloud NAT allocates a finite pool of source ports per NAT IP address, and each connection consumes one tuple. When concurrent outbound connections exceed that capacity, new connections cannot be translated and fail intermittently, matching the reported symptom.

Why this answer

Cloud NAT uses source network address translation (SNAT) to map private instance IPs to a single public IP address. Each NAT IP has a limited pool of source ports (typically 64,512 per IP for TCP/UDP). When concurrent connections exceed this capacity, new outbound connections are dropped, causing intermittent failures.

This is the most likely cause given the symptom of intermittent failures.

Exam trap

The trap here is that candidates confuse intermittent failures with firewall misconfigurations or DNS issues, but the key clue is 'intermittent'—which points to a resource exhaustion problem like port capacity, not a static policy or configuration error.

How to eliminate wrong answers

Option A is wrong because DNS server misconfiguration would cause name resolution failures, not intermittent connection drops after resolution; Cloud NAT operates at the network layer and is independent of DNS. Option B is wrong because VPC firewall rules blocking egress traffic would cause consistent, not intermittent, failures; the question states failures are intermittent, which points to resource exhaustion rather than a static rule. Option C is wrong because Cloud NAT explicitly supports TCP, UDP, and ICMP connections; it performs SNAT for all these protocols.

116
MCQhard

A company uses Cloud Storage for analytics data with lifecycle policies to move objects from Standard to Coldline after 30 days and delete after 365 days. They notice that objects are being deleted after 30 days instead of 365. What is the most likely cause?

A.An IAM policy is inadvertently allowing users to delete objects.
B.The Coldline storage class has a minimum storage duration of 30 days, causing immediate deletion.
C.The bucket is using a uniform bucket-level access policy.
D.The lifecycle rule is set to delete objects after 30 days instead of transitioning to Coldline.
AnswerD

A lifecycle rule configured to delete after 30 days removes objects before the intended Coldline transition at 30 days and deletion at 365 days ever apply. The rule's action is wrong, not its age condition, so objects vanish a full 335 days early.

Why this answer

Lifecycle rules apply in order; if a rule is set to delete after 30 days, it will delete regardless of earlier transitions. The most likely issue is that the rules are configured incorrectly: there may be a delete rule with age 30 days overriding the transition rule. The correct order should be: transition to Coldline at 30 days, then delete at 365 days.

117
MCQhard

Your company runs a containerized microservices application on Google Kubernetes Engine (GKE) with a regional cluster. The application consists of a frontend service, a backend API service, and a background worker service that processes messages from Cloud Pub/Sub. The worker service uses a Deployment with 3 replicas. Recently, the team noticed that the worker service is frequently failing with 'ContainerCreating' errors. The error message in the pod events is: 'Failed to pull image "gcr.io/my-project/my-worker:latest": rpc error: code = DeadlineExceeded desc = context deadline exceeded'. The image is stored in Container Registry in the same project. The cluster nodes are n1-standard-2 VMs with 10 GB of disk space. The team has confirmed that the image exists and that the nodes have internet access. What is the most likely cause of the issue?

A.The worker pods require node affinity to a specific node pool that is not configured.
B.The nodes have insufficient disk space to pull the new image, causing the pull to time out.
C.The nodes do not have the necessary permissions to access Container Registry.
D.The cluster is a regional cluster, but the worker pods are all scheduled in the same zone, causing resource contention.
AnswerB

With only 10 GB of node disk, image layers plus container runtime and logs exhaust available space, so the kubelet cannot pull the new image before the deadline, producing the DeadlineExceeded ContainerCreating failure despite the image existing.

Why this answer

The error 'context deadline exceeded' when pulling an image indicates that the kubelet timed out while trying to download the container image. With only 10 GB of disk space on n1-standard-2 nodes, the node's disk may be nearly full, causing the image pull to stall or fail due to insufficient space to unpack the layers. This is the most likely cause because the image exists and internet access is confirmed, ruling out authentication or connectivity issues.

Exam trap

Google Cloud often tests the distinction between image pull errors that are due to permissions (e.g., 'unauthorized') versus resource exhaustion (e.g., disk full), and candidates mistakenly assume internet connectivity or permissions are the issue when the error message explicitly mentions a deadline exceeded.

How to eliminate wrong answers

Option A is wrong because node affinity is used to constrain pod scheduling to specific nodes, but the error is about pulling an image, not scheduling; the pods are already being created but fail during container setup. Option C is wrong because if nodes lacked permissions to access Container Registry, the error would be 'unauthorized' or 'access denied', not a deadline exceeded timeout; the team confirmed the image exists and nodes have internet access. Option D is wrong because a regional cluster distributes pods across zones by default, and even if all pods were in one zone, resource contention would manifest as 'Unschedulable' or 'CPU/memory pressure', not a pull timeout.

118
MCQeasy

A company uses Cloud Storage for backup data. They want to protect against accidental deletion. Which option is best?

A.Enable object versioning.
B.Use a lifecycle policy.
C.Set a retention policy.
D.Use object holds.
AnswerA

Preserves noncurrent versions for recovery.

Why this answer

Object versioning in Cloud Storage preserves every version of an object, including overwrites and deletions. When versioning is enabled, a delete operation creates a delete marker instead of permanently removing the object, allowing easy recovery. This directly protects against accidental deletion by retaining all previous object versions.

Exam trap

Google Cloud often tests the distinction between versioning (which allows recovery from accidental deletion) and retention policies (which prevent deletion but do not provide recovery after the fact), leading candidates to confuse compliance protection with accidental deletion protection.

How to eliminate wrong answers

Option B is wrong because lifecycle policies automate transitions or deletions based on age or conditions, but they do not prevent accidental deletion; they can actually cause deletion if misconfigured. Option C is wrong because retention policies (e.g., Bucket Lock) prevent object modification or deletion for a fixed period, but they are designed for compliance and data retention, not for recovering from accidental deletion after the fact. Option D is a duplicate of the correct answer and is not a separate option; the question lists two identical 'Enable object versioning' entries, but only one is correct.

119
MCQmedium

A team is deploying a microservice on Cloud Run that needs to access a Cloud SQL database securely. They want to avoid using public IPs and ensure traffic stays within Google's network. Which configuration should they use?

A.Configure Cloud SQL with a public IP and use Cloud SQL Proxy in the Cloud Run service
B.Enable Private Google Access on the VPC subnet
C.Use Serverless VPC Access and assign a private IP to the Cloud SQL instance
D.Create a VPC network peering between the Cloud Run tenant project and the Cloud SQL project
AnswerC

Serverless VPC Access routes Cloud Run egress through a VPC connector, reaching Cloud SQL via its private IP entirely within Google's network. This satisfies the no-public-IP constraint, unlike the Cloud SQL Auth Proxy, which secures connectivity but still requires a public IP or private path.

Why this answer

To keep Cloud Run traffic private and avoid public IPs, you use Serverless VPC Access to connect the Cloud Run service to a VPC, and the Cloud SQL instance is configured with a private IP in that VPC. This keeps all traffic within Google's network and avoids exposing the database publicly. The connector allows the serverless service to reach internal resources by IP.

Exam trap

PCA often tests the confusion between Private Google Access (for Google APIs) and Serverless VPC Access (for reaching VPC resources like Cloud SQL private IPs), leading candidates to pick the wrong connectivity mechanism.

How to eliminate wrong answers

Option A is wrong because using a public IP on Cloud SQL, even with the Cloud SQL Proxy, still exposes the instance to the public internet (the proxy encrypts but does not eliminate the public endpoint), violating the requirement to avoid public IPs. Option B is wrong because Private Google Access only allows VMs without external IPs to reach Google APIs and services; it does not provide connectivity from Cloud Run to a private Cloud SQL instance. Option D is wrong because VPC network peering between the Cloud Run tenant project and the Cloud SQL project is not a supported or necessary configuration — Cloud Run uses Serverless VPC Access connectors, not direct peering, to reach VPC resources.

120
MCQeasy

A company runs a global e-commerce site on GKE. They want to ensure disaster recovery with multi-region deployment. What is the best practice for configuring GKE clusters?

A.Deploy separate regional clusters in two or more regions.
B.Use a single zonal cluster with node auto-repair.
C.Deploy a single cluster with multi-master setup.
D.Use a single regional cluster with multiple zones.
AnswerA

Separate regional clusters place control planes and nodes in distinct regions, so a single region's failure leaves the other serving traffic. This satisfies the multi-region disaster recovery constraint, unlike zonal clusters or single-region node pools.

Why this answer

For disaster recovery with a multi-region deployment, the best practice is to deploy separate regional clusters in two or more regions. This ensures that if an entire region fails, traffic can be redirected to the other region's cluster, providing true geographic redundancy. A single cluster, whether zonal or regional, cannot survive a regional outage because it is bound to a single control plane location.

Exam trap

Google Cloud often tests the misconception that a regional cluster with multiple zones is sufficient for disaster recovery, but the trap here is that a regional cluster is still confined to a single region and cannot survive a full regional outage.

How to eliminate wrong answers

Option B is wrong because a single zonal cluster with node auto-repair only protects against node-level failures within that single zone, not against a full zone or regional outage, and thus does not meet multi-region disaster recovery requirements. Option C is wrong because GKE does not support a multi-master setup; each cluster has a single control plane, and multi-master is not a valid configuration for GKE. Option D is wrong because a single regional cluster with multiple zones provides high availability within a single region but cannot survive a regional failure, as the control plane is still regional and would be unavailable if the entire region goes down.

121
MCQeasy

A logistics company runs a Cloud Run service that processes shipment events. They want to be notified and to trigger an automated rollback when the error rate of a new revision exceeds a threshold shortly after deployment. Which Google Cloud feature should they use?

A.Use Error Reporting to group exceptions and configure a Pub/Sub notification that emails the on-call engineer to perform a rollback.
B.Enable Cloud Run's built-in automatic rollback by setting a maximum error rate in the service YAML.
C.Configure Cloud Run gradual rollout with canary traffic splitting and manually monitor the revision before shifting all traffic.
D.Create a Cloud Monitoring alerting policy on the Cloud Run error rate and use Cloud Deploy with a deployment verification and automated rollback.
AnswerD

Cloud Deploy supports deployment strategies with verification, where a Cloud Monitoring alert or custom job evaluates the new revision and, on failure, automatically rolls back to the previous stable release. This provides both the notification via the alerting policy and the automated rollback the team wants, without manual intervention, matching the stated requirement precisely.

Why this answer

Cloud Deploy deployment verification evaluates a new Cloud Run revision against defined criteria, such as a Cloud Monitoring alert on error rate, and automatically rolls back to the prior stable release when verification fails. Pairing it with a Cloud Monitoring alerting policy delivers both the notification and the automated rollback the logistics team requires.

Exam trap

The trap here is assuming Cloud Run has a native error-rate-based automatic rollback, when automated rollback is orchestrated through Cloud Deploy verification instead.

122
Multi-Selecteasy

A company is designing a data pipeline to ingest streaming data from IoT devices and store it in BigQuery for analysis. They need to minimize latency and operational overhead. Which two Google Cloud services should they use? (Choose two.)

Select 2 answers
A.Cloud Dataflow
B.Cloud Pub/Sub
C.Cloud Dataproc
D.Cloud Storage
E.Cloud Functions
AnswersA, B

Cloud Dataflow provides serverless, autoscaling stream processing with exactly-once semantics, satisfying the low operational overhead constraint. It reads from Pub/Sub and writes into BigQuery using built-in connectors, so no cluster management is needed to meet the latency requirement.

Why this answer

Cloud Pub/Sub is the recommended service for ingesting streaming data, and Cloud Dataflow can process the data and write it directly to BigQuery with low latency. Cloud Storage is for batch uploads, Cloud Functions is event-driven but not ideal for high-throughput streaming, and Cloud Dataproc is for batch processing.

123
MCQeasy

Your company runs a stateless web application on Compute Engine. You want to ensure that if a zone fails, the application continues to serve traffic with minimal manual intervention. What should you do?

A.Schedule regular snapshots of each instance's persistent disk to a regional bucket.
B.Create a regional managed instance group with an autoscaling policy and use a global Cloud Load Balancer.
C.Use a global Cloud Load Balancer and enable Cloud CDN.
D.Create an instance template and manually deploy instances in another zone.
AnswerB

A regional managed instance group spreads instances across multiple zones, so a zone failure leaves capacity elsewhere, while the global Cloud Load Balancer directs traffic to healthy backends. Autoscaling maintains capacity, meeting the minimal-manual-intervention requirement for the stateless application.

Why this answer

A regional managed instance group (MIG) distributes instances across multiple zones within a region, ensuring that if one zone fails, the remaining zones continue serving traffic. Combined with a global Cloud Load Balancer, traffic is automatically routed to healthy instances in any zone, providing high availability with minimal manual intervention. Autoscaling further ensures that new instances are created to handle load, even if a zone becomes unavailable.

Exam trap

Google Cloud often tests the distinction between data backup (snapshots) and compute redundancy (MIGs), leading candidates to choose backup solutions when the question asks for continuous traffic serving during a zone failure.

How to eliminate wrong answers

Option A is wrong because scheduling snapshots to a regional bucket provides data backup and disaster recovery for persistent disks, but does not automatically redirect traffic or maintain application availability during a zone failure; it requires manual restoration and reconfiguration. Option C is wrong because enabling Cloud CDN caches static content at edge locations, which improves performance and reduces load on origin servers, but does not provide zone-level redundancy or automatic failover for the compute instances themselves. Option D is wrong because manually deploying instances in another zone is a manual, slow process that does not provide automated failover or load balancing; it also lacks autoscaling and health checking, leading to potential downtime and increased operational overhead.

124
Multi-Selecteasy

A company uses Cloud Storage to store user-uploaded content. They want to ensure that the data is highly durable and protected against accidental deletion. Which two features should they enable? (Choose two.)

Select 2 answers
A.Requester pays.
B.Lifecycle management.
C.Object versioning.
D.Bucket retention policy.
E.Uniform bucket-level access.
AnswersC, D

Object versioning preserves every revision of an object, so overwrites and deletions create non-current versions rather than destroying data. This directly satisfies the accidental-deletion protection requirement, allowing recovery of prior content. Combined with retention or lifecycle rules, it guards against both user error and malicious removal.

Why this answer

Object versioning (C) is correct because it keeps prior versions of objects when they are overwritten or deleted, so an accidentally deleted or replaced object can be recovered rather than permanently lost. Bucket retention policy (D) is correct because it enforces a retention period during which objects cannot be deleted or overwritten, directly protecting data against accidental or premature deletion. Together these features address the durability and deletion-protection requirement for user-uploaded content in Cloud Storage.

Requester pays (A) only shifts data-access and egress costs to the requester and provides no deletion protection. Lifecycle management (B) automates actions such as deleting or transitioning objects and can actually cause deletion, so it does not protect against accidental loss. Uniform bucket-level access (E) simplifies permission management by applying IAM uniformly at the bucket level, but it does not prevent accidental object deletion.

125
MCQeasy

A developer needs to deploy a Python script that processes images uploaded to a Cloud Storage bucket. The script should run only when new objects are created, and should scale automatically with no idle costs. Which GCP service is most appropriate?

A.Cloud Functions
B.App Engine Standard Environment
C.Compute Engine with a startup script
D.Cloud Run
AnswerA

Cloud Functions is event-driven: a Cloud Storage trigger fires on object creation, invoking the script only when new images arrive. It scales automatically per event and bills per invocation, so no idle costs accrue, satisfying both the trigger and cost constraints.

Why this answer

Cloud Functions is an event-driven serverless compute service that can be triggered by Cloud Storage events (e.g., object finalize). It scales automatically, runs only when triggered, and has no idle cost. Cloud Run also works for containers, but the script is lightweight and can be written as a function.

App Engine requires manual scaling setup. Compute Engine would have idle cost.

126
MCQhard

A financial services company requires that all audit logs be retained for 7 years in a cost-effective, immutable storage. They also need to run ad-hoc SQL queries on the logs. Which configuration should they use?

A.Create a log sink to BigQuery with a 7-year partition expiration and use BigQuery's SQL capabilities
B.Use Cloud Logging's default retention and set up a log-based metric to trigger a Cloud Function that copies logs to BigQuery
C.Export logs to Cloud Storage with a retention policy set to 7 years and use Cloud Storage SQL interface
D.Create two log sinks: one to BigQuery for querying, and one to Cloud Storage with object retention policy for immutable storage
AnswerD

BigQuery provides the ad-hoc SQL querying the logs require, while a Cloud Storage bucket with an object retention policy enforces immutability for the full 7-year period. Splitting the sinks lets each backend serve its purpose, and Cloud Storage's low cost per gigabyte satisfies the cost-effectiveness constraint.

Why this answer

The requirement has two parts: immutable 7-year retention and ad-hoc SQL querying. A dual-sink approach satisfies both: one sink to BigQuery for SQL analysis, and one sink to Cloud Storage with an object retention policy (or bucket lock) for immutable, cost-effective long-term storage. This separates query and archival concerns while meeting compliance.

Exam trap

PCA often tests the misconception that BigQuery or Cloud Storage alone can satisfy both immutability and SQL querying, when in fact a dual-sink architecture is required.

How to eliminate wrong answers

Option A is wrong because BigQuery partition expiration deletes data after the period, which is the opposite of immutable 7-year retention, and BigQuery alone does not provide immutable storage guarantees. Option B is wrong because Cloud Logging's default retention is only 30 days, and a log-based metric triggering a Cloud Function is an unreliable, complex pattern that does not guarantee immutability or complete log capture. Option C is wrong because Cloud Storage does not have a native SQL interface for ad-hoc queries; you would need to load data into BigQuery or use external tables, and a retention policy alone does not make objects immutable (you need object retention or bucket lock).

127
MCQeasy

A startup is deploying a new web application on Google Cloud. They want to minimize infrastructure management and focus on writing code. The application consists of a frontend and a backend API, and they expect variable traffic. They also want to pay only for what they use. Which Google Cloud service should the solutions architect recommend for deploying the application?

A.Google Kubernetes Engine (GKE) with Autopilot.
B.App Engine standard environment.
C.Cloud Run.
D.Compute Engine with managed instance groups.
AnswerC

Cloud Run is a fully managed serverless platform that runs containers and automatically scales based on traffic, including scaling to zero. It abstracts away all infrastructure, allowing the startup to focus on code. It charges only for resources used during request handling, matching the pay-per-use requirement.

Why this answer

Cloud Run is a serverless compute platform that runs stateless containers, scales automatically with traffic, and charges only for resources consumed during request processing. It eliminates infrastructure management, letting the startup focus on code. Its ability to scale to zero and handle variable traffic makes it ideal for a frontend and backend API with unpredictable load.

Exam trap

The trap here is assuming that a managed Kubernetes service like GKE Autopilot is the most serverless option, when Cloud Run requires even less management and is better suited for simple containerized applications.

128
MCQmedium

Your team is deploying a new internal web application on Compute Engine. The security team requires that all outbound internet traffic from the instances be inspected by a third-party firewall appliance running on a separate VM. You need to implement this with minimal changes to the application instances. What should you do?

A.Configure a custom route in the VPC that sends all traffic destined for 0.0.0.0/0 to the internal IP address of the firewall appliance. Enable IP forwarding on the firewall instance and configure it to forward traffic to the internet.
B.Use VPC peering to connect the application subnet to the firewall appliance's subnet. Configure the application instances to send all traffic to the firewall's IP by setting a static route on each instance's operating system.
C.Create a new VPC network with a global external HTTP(S) load balancer and set the backend service to the firewall appliance. Configure the application instances to use the load balancer's IP as their default gateway.
D.Deploy the firewall appliance as a managed instance group and configure an internal TCP/UDP load balancer. Set the application instances' default gateway to the load balancer's IP address using a startup script.
AnswerA

This approach uses a custom static route to redirect all default internet-bound traffic to the firewall appliance's internal IP. Enabling IP forwarding on the appliance allows it to act as a next-hop and forward packets to the internet, satisfying the inspection requirement without modifying the application instances.

Why this answer

Routing outbound traffic through a third-party firewall is typically done by creating a custom route for 0.0.0.0/0 with the firewall's internal IP as the next hop, and enabling IP forwarding on the firewall VM. This transparently redirects traffic without modifying application instances. Other options involve services not designed for this purpose or require unsupported configuration changes.

Exam trap

The trap here is assuming that a load balancer can act as a default gateway for outbound traffic, when it is only for inbound or internal distribution.

129
Multi-Selecthard

An engineering team is deploying a microservices application on Google Cloud. They want to use a service mesh for observability, traffic management, and security. They are considering Anthos Service Mesh (ASM). Which THREE components are part of ASM? (Choose THREE.)

Select 3 answers
A.Cloud Endpoints
B.Envoy sidecar proxies
C.Cloud Monitoring and Cloud Logging
D.Google Kubernetes Engine (GKE)
E.Istio control plane
AnswersB, C, E

Envoy sidecar proxies are injected alongside each workload, intercepting all inbound and outbound traffic to enforce mTLS, collect telemetry, and apply routing rules. This satisfies the stem's observability, traffic management, and security requirements, since ASM's data plane is built entirely on Envoy.

Why this answer

Anthos Service Mesh is Google's managed Istio-based service mesh, so its data plane consists of Envoy sidecar proxies (option B) injected alongside workloads to intercept and manage all service-to-service traffic. The Istio control plane (option E) is the core of ASM, providing the configuration, certificate authority, and policy enforcement that drive the mesh's traffic management and security features. ASM integrates with Cloud Monitoring and Cloud Logging (option C) to deliver the observability the team wants, exporting mesh telemetry, metrics, and logs to Google Cloud's operations suite.

Cloud Endpoints (option A) is a separate API management product, not a component of ASM, and GKE (option D) is the underlying Kubernetes platform that can host ASM but is not itself a service mesh component.

Exam trap

The trap is including the hosting platform (GKE) or adjacent services (Cloud Endpoints) as ASM components — candidates must distinguish the mesh's own control plane, data plane, and telemetry integrations from the infrastructure it runs on.

130
MCQmedium

Your company runs a microservices application on Google Kubernetes Engine (GKE). The development team complains that they lack visibility into which service is causing latency spikes during peak hours. You need to implement a solution that provides distributed tracing and service-level metrics without modifying application code. Which approach should you use?

A.Install the Cloud Logging agent on each node and create log-based metrics for latency.
B.Use Cloud Profiler to continuously profile the application and identify latency bottlenecks.
C.Deploy Anthos Service Mesh and enable its built-in telemetry features, including Cloud Trace and Cloud Monitoring integration.
D.Enable Cloud Trace on the GKE cluster and instrument each service with the OpenTelemetry SDK.
AnswerC

Anthos Service Mesh (ASM) provides automatic distributed tracing and service-level metrics without requiring application code changes. It uses sidecar proxies to capture telemetry and integrates with Cloud Trace and Cloud Monitoring. This meets the requirement for visibility into service latency without modifying code, making it the correct solution.

Why this answer

Anthos Service Mesh provides automatic telemetry collection, including distributed tracing and service-level metrics, without requiring changes to application code. It leverages sidecar proxies to capture traffic and integrates with Cloud Trace and Cloud Monitoring, giving the needed visibility into latency spikes. Other options either require code instrumentation or do not provide the necessary tracing and metrics.

Exam trap

The trap here is assuming that Cloud Trace alone can provide service-level metrics without code changes, when it actually requires instrumentation and does not offer metrics out of the box.

131
MCQmedium

Your team is deploying a new three-tier application to Google Cloud. The security team requires that the application's Compute Engine instances never receive public IP addresses, yet the instances must still download OS patches from the public internet and reach a third-party REST API over HTTPS. You need to implement this with the least operational overhead. What should you do?

A.Configure Cloud NAT on a Cloud Router in the region, and create a route so instances without external IP addresses can reach the internet.
B.Create a VPN tunnel from the VPC to an on-premises network and route all internet-bound traffic through that network.
C.Assign each instance an ephemeral external IP address and use firewall rules to block all inbound traffic on every port.
D.Deploy a third-party forward proxy on a Compute Engine instance with an external IP address and point all instances at it.
AnswerA

Cloud NAT lets instances with only internal IP addresses initiate outbound connections to the internet without exposing them to inbound traffic. Attaching it to a Cloud Router in the same region and VPC supports patch downloads and third-party API calls while satisfying the no-public-IP requirement, with no per-instance agents or proxies to maintain.

Why this answer

Cloud NAT provides managed, regional outbound internet access for instances that have no external IP address. It satisfies both the security constraint and the functional need for patch downloads and third-party API calls, without introducing proxy servers, ephemeral public addresses, or on-premises dependencies. This is the lowest-overhead native option.

Exam trap

The trap here is assuming that firewall rules can substitute for removing a public IP address, when the requirement is about address assignment rather than traffic filtering.

132
MCQeasy

Your organization is using Google Cloud to host a web application that experiences unpredictable traffic spikes. You need to ensure the application scales automatically and maintains high availability across multiple zones. The application runs on Compute Engine instances behind a load balancer. What should you do?

A.Create a managed instance group with an autoscaling policy based on CPU utilization, and configure the group to span multiple zones. Place the instance group behind an external HTTP(S) load balancer.
B.Create an unmanaged instance group with instances in multiple zones, and manually add or remove instances based on traffic. Use a network load balancer to distribute traffic.
C.Deploy the application on a single Compute Engine instance with a powerful machine type, and use a global load balancer to direct traffic to it. Configure a health check to restart the instance if it fails.
D.Use a regional managed instance group with autoscaling, and place it behind an internal TCP/UDP load balancer. Configure the load balancer to distribute traffic across zones.
AnswerA

A managed instance group with autoscaling automatically adjusts the number of instances based on load, and spanning multiple zones ensures high availability. An external HTTP(S) load balancer distributes traffic across instances and provides a single global IP, making this the correct solution for scaling and availability.

Why this answer

A managed instance group with autoscaling and multi-zone deployment provides automatic scaling and high availability. An external HTTP(S) load balancer is designed for web traffic, offering global distribution and SSL termination. This combination meets the requirements for unpredictable traffic and multi-zone availability.

Exam trap

The trap here is confusing internal and external load balancers, or assuming that an unmanaged instance group can autoscale.

133
MCQeasy

An organization wants to enforce that all container images deployed to Google Kubernetes Engine (GKE) are signed and approved via an attestation authority. Which GCP service should they use?

A.Binary Authorization
B.Container Registry
C.Cloud Armor
D.Cloud Security Scanner
AnswerA

Binary Authorization enforces deploy-time admission control on GKE, verifying cryptographic signatures and attestations produced by trusted authorities before a container image is admitted. This directly satisfies the stem's requirement that images be signed and approved via an attestation authority, blocking unsigned or unapproved images at deployment.

Why this answer

Binary Authorization is the Google Cloud service that enforces deploy-time security controls on GKE by allowing only container images that are signed and attested by trusted authorities. It integrates with GKE admission controllers to block unsigned or unattested images. This directly matches the requirement to enforce signed and approved images via an attestation authority.

Exam trap

The trap is confusing image storage (Container Registry) with image admission control (Binary Authorization); candidates often pick the registry because it is where images live, but it does not enforce signing.

How to eliminate wrong answers

Option B is wrong because Container Registry (now Artifact Registry) is a storage and management service for container images; it does not enforce signing or attestation policies at deployment. Option C is wrong because Cloud Armor is a WAF and DDoS protection service for HTTP(S) load balancing; it does not validate container image signatures. Option D is wrong because Cloud Security Scanner (now Web Security Scanner) scans web applications for vulnerabilities; it does not enforce image signing or attestation.

134
MCQmedium

A developer is using Cloud Build to automate deployments. The build fails with an error: 'Permission 'iam.serviceAccounts.actAs' denied.' What is the most likely cause?

A.The developer does not have iam.serviceAccounts.actAs permission on the project
B.The build configuration is missing a required step
C.The Cloud Build service account is not enabled
D.The Cloud Build service account does not have the Service Account User role on the service account used in the build steps
AnswerD

The `iam.serviceAccounts.actAs` permission is granted by the Service Account User role (`roles/iam.serviceAccountUser`), which Cloud Build's service account requires to impersonate the service account specified in build steps. Without it on that target service account, Cloud Build cannot act as it, producing exactly this denial.

Why this answer

The error 'Permission iam.serviceAccounts.actAs denied' occurs when a Cloud Build build step tries to impersonate a service account (e.g., to deploy resources) but the Cloud Build service account lacks the Service Account User role on that target service account. Option D correctly identifies that the Cloud Build service account does not have the `roles/iam.serviceAccountUser` role on the service account used in the build steps, which is required to delegate access.

Exam trap

Google Cloud often tests the distinction between granting permissions to a user versus granting roles to a service account, and the trap here is that candidates mistakenly think the developer needs the `actAs` permission directly (Option A), when in fact it is the Cloud Build service account that requires the Service Account User role on the target service account.

How to eliminate wrong answers

Option A is wrong because the `iam.serviceAccounts.actAs` permission is not granted directly to the developer; it is granted to a service account (the Cloud Build service account) on another service account. The error is about the Cloud Build service account lacking this permission, not the developer. Option B is wrong because a missing build step would typically cause a syntax or execution error, not a specific IAM permission denial.

Option C is wrong because the Cloud Build service account is enabled by default when Cloud Build is used; the error is about missing IAM roles on that service account, not its existence.

135
MCQeasy

A developer needs to cache session state for a web application to reduce latency. The cache must be highly available and support sub-millisecond access times. Which Google Cloud service should they use?

A.Firestore
B.Cloud Storage
C.Bigtable
D.Memorystore for Redis
AnswerD

Memorystore for Redis delivers sub-millisecond latency through in-memory storage, and its standard tier provides automatic failover across zones, satisfying the high-availability constraint. Persistent disk options such as Filestore or Cloud SQL cannot match in-memory read speeds, so Redis is the only listed service meeting both the latency and availability requirements.

Why this answer

Memorystore for Redis is a fully managed in-memory data store service on Google Cloud, providing sub-millisecond latency for read and write operations. It supports high availability through replication and automatic failover, making it ideal for caching session state in web applications. Other options like Firestore, Cloud Storage, and Bigtable are not in-memory and cannot guarantee sub-millisecond access times.

Exam trap

PCA often tests the distinction between in-memory caching services and persistent databases, so candidates might incorrectly choose Firestore or Bigtable due to familiarity, overlooking the sub-millisecond latency requirement that only Memorystore for Redis satisfies.

How to eliminate wrong answers

Option A is wrong because Firestore is a document database with latency typically in the tens of milliseconds, not sub-millisecond, and it is not designed for caching. Option B is wrong because Cloud Storage is an object storage service with higher latency and is not suitable for session state caching. Option C is wrong because Bigtable is a wide-column NoSQL database optimized for high throughput but with millisecond latency, not sub-millisecond, and it is not an in-memory cache.

136
MCQhard

An application running on Compute Engine is experiencing increased latency. You suspect a network bottleneck due to high egress traffic. Which gcloud command can you use to quickly check the network egress traffic for a specific VM instance?

A.gcloud logging read 'resource.type=gce_instance AND jsonPayload.egress_bytes'
B.gcloud compute instances list --format='value(networkInterfaces[0].networkIP)'
C.gcloud compute instances get-serial-port-output
D.gcloud monitoring metrics list
AnswerA

gcloud logging read with the specified filter queries Cloud Logging for egress bytes logs from Compute Engine instances, making it the correct choice.

Why this answer

The gcloud logging read command allows you to query Cloud Logging for specific log entries. For a Compute Engine instance, the resource type is gce_instance. You can filter for egress bytes by using the query 'resource.type=gce_instance AND jsonPayload.egress_bytes'. This will return log entries containing egress bytes information, assuming your VM is configured to send these logs (e.g., via the monitoring agent or VPC flow logs). This is the quickest way among the given options to check network egress traffic for a specific VM using a native gcloud command.

Option B is incorrect: gcloud compute instances list only displays the network IP of instances, not egress traffic metrics.

Option C is incorrect: gcloud compute instances get-serial-port-output shows the serial console output, which does not include network traffic data.

Option D is incorrect: gcloud monitoring metrics list just lists available metrics but does not retrieve the actual traffic data for a specific instance. To get the data you would need to use gcloud monitoring metric descriptors or gcloud monitoring dashboards, but the command as given does not return traffic.

Thus, A is the best choice.

Exam trap

Students may think that Cloud Monitoring is the only way to view metrics, but Cloud Logging can also be used to query specific data like egress bytes if logs are collected. They might also incorrectly choose D because monitoring sounds relevant, but the command 'gcloud monitoring metrics list' only lists metric descriptors, not actual data.

137
Drag & Dropmedium

Drag and drop the steps to set up a VPC network peering between two projects in Google Cloud into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

VPC peering requires bidirectional connections; both sides must initiate peering. IP ranges must not overlap.

138
MCQhard

A company is deploying a global web application on Google Cloud. The application serves static content from a Cloud Storage bucket and dynamic content from a managed instance group backend. They want to use a single global IP address and provide low latency to users worldwide. They also want to protect the application from DDoS attacks. Which solution should they implement?

A.Configure an external HTTP(S) load balancer with a global anycast IP address, a backend service for the managed instance group, and a backend bucket for the Cloud Storage bucket. Enable Cloud CDN and Google Cloud Armor.
B.Use a global external HTTP(S) load balancer with a single backend service that points to both the managed instance group and the Cloud Storage bucket using a hybrid connectivity network endpoint group (NEG).
C.Deploy a third-party DDoS protection service in front of the application, and use a network load balancer with a global IP address for both backends.
D.Create a global TCP proxy load balancer with a global IP address, and configure backends for the managed instance group and Cloud Storage bucket.
AnswerA

An external HTTP(S) load balancer provides a single global anycast IP address and can route traffic to both a managed instance group backend and a Cloud Storage backend bucket. Cloud CDN caches static content at the edge for low latency, and Cloud Armor provides DDoS protection and WAF capabilities. This meets all requirements.

Why this answer

The external HTTP(S) load balancer provides a global anycast IP and supports both backend services and backend buckets, allowing static and dynamic content to be served from the same IP. Cloud CDN caches static content for low latency, and Cloud Armor protects against DDoS and other attacks. This integrated solution meets all the requirements without third-party dependencies.

Exam trap

The trap here is assuming that a TCP proxy load balancer can serve HTTP(S) traffic and integrate with Cloud CDN; it operates at layer 4 and lacks these features.

139
Multi-Selecthard

An organization is implementing a data loss prevention (DLP) strategy for sensitive data stored in Cloud Storage. They want to automatically detect and redact credit card numbers in CSV files uploaded to a specific bucket. Which TWO Google Cloud services should they combine to achieve this?

Select 2 answers
A.Cloud Dataflow
B.Cloud Run
C.Cloud DLP
D.Cloud Functions
E.BigQuery
AnswersC, D

Cloud DLP supplies the infoType detectors that identify credit card numbers and the de-identification transforms that redact them. This satisfies the detection and redaction constraint, since it recognises sensitive data patterns rather than relying on filenames or metadata.

Why this answer

Cloud DLP (option C) is correct because it provides native content inspection and de-identification (redaction) of sensitive data like credit card numbers using built-in infoType detectors. Cloud Functions (option D) is correct because it can be triggered by Cloud Storage events (e.g., finalize/create) to invoke the DLP API on newly uploaded CSV files, enabling serverless, event-driven processing without managing infrastructure.

Exam trap

The trap here is that candidates may choose Cloud Dataflow (option A) thinking it is required for large-scale DLP processing, but the question specifies 'uploaded to a specific bucket' which implies per-file, event-driven processing where Cloud Functions is the simpler and correct serverless choice.

140
MCQhard

Your organization operates a multi-project Google Cloud environment. A security team requires that any new Compute Engine instance created in the production folder must have OS Login enabled and must not use project-wide SSH keys. You want to enforce this centrally with the least operational overhead and ensure that non-compliant creation attempts are denied. What should you do?

A.Create an Organization Policy constraint for compute.requireOsLogin and compute.disableProjectSshKeys, and apply them at the production folder.
B.Create an Organization Policy constraint for compute.requireOsLogin and compute.skipDefaultNetworkCreation, and apply it at the production folder.
C.Apply a custom IAM deny policy on compute.instances.create for all principals except the security team, and require them to create instances on behalf of others.
D.Grant the security team the Compute Security Admin role and schedule a Cloud Scheduler job that audits instances with project-wide SSH keys.
AnswerA

Organization Policy constraints compute.requireOsLogin and compute.disableProjectSshKeys are designed exactly for this requirement. Applying them at the production folder enforces OS Login and blocks project-wide SSH keys for all projects under that folder, denying non-compliant instance creation without per-project scripting or IAM churn.

Why this answer

Organization Policy constraints applied at the folder level enforce configuration rules across all descendant projects. compute.requireOsLogin forces OS Login for instances, and compute.disableProjectSshKeys blocks adding project-wide SSH keys. Applying both at the production folder denies non-compliant creation centrally with minimal operational overhead, unlike audits or IAM restrictions that do not enforce the desired configuration.

Exam trap

The trap here is confusing an audit-and-alert approach or an IAM restriction with preventive configuration enforcement, which only Organization Policy constraints provide.

141
Multi-Selecthard

A multinational retailer is planning its Google Cloud landing zone. Each of the company's business units must be able to create projects and manage billing independently, but the central platform team must retain the ability to enforce network and security guardrails across everything. The company also wants to minimize the number of distinct IAM policy bindings it maintains at the top of the hierarchy. Which two design choices should the architect make? (Choose two.)

Select 2 answers
A.Grant each business unit's administrators the Organization Administrator role so they can create projects anywhere in the hierarchy
B.Create every project directly under the organization node and attach a distinct billing account to each project for isolation
C.Apply organization policies such as constraints on allowed resource locations and external IP addresses at the organization node so they are inherited by all folders and projects
D.Use a shared VPC host project per business unit and grant the central team Compute Network Admin on each host project only
E.Create a separate folder per business unit under the organization node and grant each business unit's administrators project creator and billing roles at the folder level
AnswersC, E

Organization policies applied at the organization node are inherited by every descendant folder and project, which enforces guardrails centrally without per-project configuration. This directly supports the requirement that the central platform team retains control while business units operate independently, and it avoids duplicating policy definitions across many projects.

Why this answer

Delegating project creation and billing to folder-level roles gives each business unit autonomy while keeping the grant in one place per unit. Applying organization policies at the organization node enforces network and security guardrails through inheritance, so the central team controls every descendant without per-project work. Together these choices satisfy autonomy, central control, and a small number of top-level IAM bindings.

Exam trap

The trap here is solving delegation by granting a powerful organization-wide role instead of scoping permissions at a folder.

142
MCQhard

You are deploying a new version of a microservice to Google Kubernetes Engine (GKE). The service must remain available during the rollout, and you need to minimize the risk of exposing bugs to all users at once. You want to gradually shift traffic to the new version while monitoring key metrics. Which strategy should you use?

A.Implement a canary deployment using Istio or Anthos Service Mesh to route a small percentage of traffic to the new version.
B.Perform a rolling update by changing the Deployment's pod template.
C.Use a blue/green deployment by creating a new Deployment and switching the Service selector.
D.Create a new GKE cluster and deploy the new version there, then update DNS to point to the new cluster.
AnswerA

A canary deployment with a service mesh like Istio allows you to route a small percentage of traffic to the new version, monitor metrics, and gradually increase traffic or roll back if issues arise. This minimizes risk and keeps the service available. It provides the fine-grained control needed for safe rollouts.

Why this answer

A canary deployment using a service mesh allows you to route a small portion of traffic to the new version, monitor its behavior, and then gradually increase traffic or roll back if problems occur. This minimizes risk and maintains availability. Other strategies either switch all traffic at once or lack the granular control needed for gradual, metric-based rollouts.

Exam trap

The trap here is confusing a rolling update with a canary deployment; rolling updates replace pods but do not control traffic percentages or support metric-based analysis.

143
MCQhard

A company has a Shared VPC with a service project hosting GKE clusters. The GKE nodes need to access Cloud SQL instances in the host project. The team wants to avoid public IP and use Private Service Access. They have configured a VPC peering between the host VPC and the service producer VPC for Cloud SQL. However, the GKE pods cannot reach the Cloud SQL instance. What is the most likely cause?

A.The Cloud SQL instance is not configured with a private IP
B.The service project needs a Private Service Connect endpoint to access the Cloud SQL instance
C.The service project is not authorized in the Cloud SQL instance
D.The firewall rules in the host VPC block egress from the service project
AnswerC

Correct. After setting up VPC peering with Private Service Access, you must also authorize the service project's VPC network in the Cloud SQL instance's private network settings. Without this authorization, the Cloud SQL instance rejects connections from the GKE pods.

Why this answer

The most likely cause is that the service project is not authorized in the Cloud SQL instance. After configuring Private Service Access (VPC peering) between the host VPC and the service producer VPC, you must explicitly authorize the service project's VPC network in the Cloud SQL instance's private network configuration. Without this authorization, connection attempts from GKE pods will fail.

Option B is incorrect because Private Service Connect is not required; VPC peering is sufficient for connectivity once authorization is granted. Option A is incorrect because the Cloud SQL instance is configured with a private IP via Private Service Access. Option D is incorrect because firewall rules in the host VPC do not block traffic over VPC peering by default; the issue is authorization, not firewall rules.

144
MCQhard

A company is migrating its on-premises MongoDB database to Google Cloud. They want a fully managed, highly available NoSQL database that is compatible with MongoDB drivers. Which Google Cloud service should they choose?

A.Cloud Firestore
B.MongoDB Atlas on Google Cloud Marketplace
C.Cloud Bigtable
D.Cloud SQL
AnswerB

MongoDB Atlas is a fully managed service that preserves native MongoDB wire-protocol compatibility, so existing drivers connect unchanged. Running it via Google Cloud Marketplace satisfies the managed, highly available requirement while avoiding the operational burden of self-managed MongoDB on Compute Engine.

Why this answer

MongoDB Atlas on Google Cloud Marketplace is the correct choice because it is a fully managed MongoDB service that is wire-protocol compatible with native MongoDB drivers, allowing the company to migrate its on-premises MongoDB workload with minimal application changes. It provides high availability, automated backups, and scaling while running on Google Cloud infrastructure.

Exam trap

PCA often tests the distinction between fully managed third-party services available on Google Cloud Marketplace (like MongoDB Atlas) and native Google Cloud databases (Firestore, Bigtable), tricking candidates into choosing a native service that is not driver-compatible.

How to eliminate wrong answers

Option A is wrong because Cloud Firestore is a proprietary Google NoSQL document database that uses its own API and is not compatible with MongoDB drivers or query language. Option C is wrong because Cloud Bigtable is a wide-column NoSQL database designed for high-throughput analytical workloads and does not support MongoDB drivers or document data model. Option D is wrong because Cloud SQL is a managed relational database service (MySQL, PostgreSQL, SQL Server) and cannot host MongoDB workloads.

145
MCQmedium

An organization uses Active Directory (AD) on-premises. They want to synchronize user accounts and groups to Google Cloud Identity so that users can sign in with their existing AD credentials. Which service should they use?

A.Cloud Identity Platform
B.Google Cloud Directory Sync
C.Cloud Identity-Aware Proxy
D.Security Command Center
AnswerB

Google Cloud Directory Sync provisions users and groups from on-premises Active Directory into Cloud Identity, letting accounts authenticate with existing AD credentials. It synchronises directory data rather than federating sign-in, which suits the stated requirement to mirror accounts and groups.

Why this answer

Google Cloud Directory Sync (GCDS) is the official tool for synchronizing users, groups, and other directory data from an on-premises Active Directory or LDAP directory to Google Cloud Identity or Google Workspace. It runs on-premises, reads from AD, and provisions accounts in Google Cloud, allowing users to sign in with their existing AD credentials (often via SAML federation or password sync).

Exam trap

PCA often tests the distinction between directory synchronization (GCDS) and authentication federation (SAML), and candidates may choose Cloud Identity Platform or IAP thinking they handle AD sync.

How to eliminate wrong answers

Option A is wrong because Cloud Identity Platform is a customer identity and access management (CIAM) service for building authentication into applications, not for directory synchronization from AD. Option C is wrong because Cloud Identity-Aware Proxy (IAP) is a zero-trust access control service for applications running on Google Cloud, not a directory sync tool. Option D is wrong because Security Command Center is a security and risk management platform, not an identity synchronization service.

146
Drag & Dropmedium

Drag and drop the steps to set up a Cloud VPN tunnel between Google Cloud and an on-premises network into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Cloud Router is used for dynamic routing. The tunnel requires the on-premises public IP and pre-shared key.

147
MCQeasy

A company is running a web application on Compute Engine instances that average 20% CPU utilization. They want to reduce costs without impacting performance. What is the most effective action?

A.Rightsize instances to a smaller machine type based on usage metrics.
B.Change instance type to e2-standard-4.
C.Purchase 3-year committed use discounts.
D.Use preemptible instances for all traffic.
AnswerA

Rightsizing selects a smaller machine type whose vCPU and memory match the observed 20% utilisation, so the workload runs on cheaper instances without performance loss. This directly removes the cost of over-provisioned capacity identified by the usage metrics.

Why this answer

The instances are averaging only 20% CPU utilization, indicating they are over-provisioned. Rightsizing to a smaller machine type directly reduces the compute cost per instance while maintaining adequate performance for the current workload, as the smaller instance can handle the existing load without degradation.

Exam trap

The trap here is that candidates often choose committed use discounts (Option C) as a quick cost-saving measure, failing to realize that rightsizing first yields greater savings without long-term commitment, and that preemptible instances (Option D) are not viable for production traffic due to their ephemeral nature.

How to eliminate wrong answers

Option B is wrong because it specifies a particular machine type (e2-standard-4) without considering the current usage metrics; this is a generic recommendation that may not be the optimal size and could still be over-provisioned or under-provisioned. Option C is wrong because purchasing 3-year committed use discounts locks in a long-term commitment for the current instance types, which may still be over-provisioned; rightsizing first then applying commitments is more cost-effective. Option D is wrong because preemptible instances can be terminated at any time by Google Cloud, making them unsuitable for handling all traffic in a production web application that requires reliability and availability.

148
MCQmedium

A company hosts a web application on Compute Engine behind a global HTTP(S) load balancer. They notice that some users experience high latency from certain regions. They want to improve performance without adding complexity. What should they do?

A.Add more instances in the same region
B.Use Premium Tier networking
C.Enable Cloud Armor
D.Enable Cloud CDN
AnswerD

Cloud CDN caches content at Google's globally distributed edge points of presence, so users in distant regions fetch objects from a nearby cache rather than the origin. This reduces latency without adding architectural complexity, satisfying the stem's constraint.

Why this answer

Enabling Cloud CDN caches content at Google's globally distributed edge caches, reducing latency for users in regions far from the origin Compute Engine instances. This directly addresses the high-latency issue without adding complexity, as it requires no changes to the application architecture and is a simple configuration toggle on the load balancer backend bucket or backend service.

Exam trap

The trap here is that candidates may confuse network optimization (Premium Tier) with content caching (CDN), assuming that faster routing alone solves geographic latency, but only caching eliminates the need for long-distance round trips.

How to eliminate wrong answers

Option A is wrong because adding more instances in the same region does not reduce latency for users in distant regions; it only increases capacity within that region, leaving cross-continental network hops unchanged. Option B is wrong because Premium Tier networking improves routing performance by using Google's global fiber network, but it does not cache content; it still requires a full round trip to the origin for every request, so it does not eliminate latency from geographic distance. Option C is wrong because Cloud Armor provides security protections like DDoS mitigation and WAF rules; it does not cache or accelerate content delivery, so it has no effect on latency for static or cacheable responses.

149
MCQhard

A company is migrating a legacy e-commerce platform to GKE. The application consists of several stateless microservices and a stateful database. They want to minimize operational overhead for the database while ensuring high availability across zones. Which database option should they choose?

A.Cloud SQL for MySQL with regional high availability
B.Deploy MySQL on GKE StatefulSet with persistent volumes
C.Cloud Firestore
D.Cloud Spanner
AnswerA

Cloud SQL for MySQL with regional high availability replicates synchronously across two zones with automatic failover, minimising operational overhead for the stateful database while meeting the cross-zone availability requirement. A self-managed database on GKE would add significant administration.

Why this answer

Cloud SQL for MySQL with regional high availability minimizes operational overhead because it is a fully managed database service that handles replication, failover, and maintenance automatically, while regional HA ensures synchronous replication across multiple zones for high availability. The application's stateful database component can be migrated with minimal changes, and Google manages patching, backups, and failover. This directly meets the requirements of minimizing operational overhead and ensuring cross-zone high availability.

Exam trap

The trap is confusing high availability with global scalability; candidates may pick Cloud Spanner because it sounds more robust, but it introduces unnecessary complexity and cost for a single-region e-commerce platform, while Cloud SQL regional HA directly addresses the stated requirements.

How to eliminate wrong answers

Option B is wrong because deploying MySQL on GKE StatefulSet with persistent volumes requires the team to manage the database themselves, including replication, failover, backups, and upgrades, which increases operational overhead and does not guarantee cross-zone HA without additional configuration. Option C is wrong because Cloud Firestore is a NoSQL document database, not a relational database suitable for a legacy e-commerce platform that likely relies on MySQL schemas and transactions. Option D is wrong because Cloud Spanner is a globally distributed relational database that offers high availability but is significantly more expensive and complex to migrate to, and it may be overkill for a single-region e-commerce platform; it also requires schema and query changes.

150
MCQhard

A company is migrating a monolithic application to Google Cloud. The application consists of a stateful service that writes to local disk and a stateless web server. They want to minimize changes to the code. Which architecture should they use?

A.Run the entire application on Cloud Run and use Cloud Filestore for shared state
B.Use App Engine Flexible Environment for the web server and Cloud SQL for state
C.Refactor the application into microservices and deploy on GKE with StatefulSets
D.Lift and shift to Compute Engine instances with persistent disks for stateful service
AnswerD

Lift and shift preserves the existing monolithic code, satisfying the minimal-change constraint. Compute Engine persistent disks provide durable block storage that survives instance restarts, so the stateful service's local disk writes remain intact without refactoring into Cloud Storage or a managed database.

Why this answer

It represents a lift-and-shift migration that minimizes code changes by running the monolithic application on Compute Engine instances. The stateful service can use persistent disks for local disk writes, while the stateless web server runs on the same or separate instances, preserving the existing architecture without refactoring.

Exam trap

The trap here is that candidates often over-engineer the solution by choosing cloud-native options (like Cloud Run or GKE) that require code changes, ignoring the explicit requirement to minimize changes and the suitability of a simple lift-and-shift with persistent disks.

How to eliminate wrong answers

Option A is wrong because Cloud Run is stateless and does not support local disk writes; Cloud Filestore is a network file system that would require code changes to replace local disk I/O. Option B is wrong because App Engine Flexible Environment does not support local disk writes for stateful services, and migrating to Cloud SQL would require significant code changes to replace local disk-based state. Option C is wrong because refactoring into microservices and using GKE with StatefulSets contradicts the requirement to minimize code changes, as it requires substantial application restructuring.

Page 1

Page 2 of 11

Page 3

All pages