Courseiva

Google Professional Cloud Architect (PCA) — Questions 151–225

807 questions total · 11pages · All types, answers revealed

Page 2

Page 3 of 11

Page 4
151
MCQmedium

A financial services company must run a PostgreSQL database with strong consistency across three regions. They need to support high write throughput and require automatic failover with zero data loss. Which database service should they choose?

A.AlloyDB for PostgreSQL
B.Bigtable
C.Cloud SQL for PostgreSQL with cross-region replication
D.Cloud Spanner
AnswerD

Cloud Spanner provides externally consistent reads and writes globally through TrueTime, synchronising clocks via GPS and atomic clocks. Its synchronous replication across regions guarantees zero recovery point objective, satisfying the zero data loss constraint, while horizontal sharding supports the required high write throughput with automatic regional failover.

Why this answer

Cloud Spanner is Google Cloud's globally distributed, strongly consistent relational database that supports horizontal scaling for high write throughput and provides automatic failover with zero data loss (RPO=0) via synchronous replication. It is the only option that meets all requirements across three regions.

Exam trap

PCA often tests the trade-off between consistency and availability; candidates may pick Cloud SQL for PostgreSQL familiarity, but only Spanner offers global strong consistency with zero data loss.

How to eliminate wrong answers

Option A is wrong because AlloyDB is regional and does not provide multi-region strong consistency with automatic failover. Option B is wrong because Bigtable is a NoSQL wide-column store, not relational, and does not offer strong consistency across regions for transactions. Option C is wrong because Cloud SQL cross-region replication is asynchronous, leading to potential data loss on failover, and does not support high write throughput across regions.

152
MCQeasy

A company is planning to migrate a batch processing workload to Google Cloud. The workload runs nightly and can be interrupted without impacting the business. The company wants to minimize compute costs. Which Google Cloud service should they use?

A.Google Kubernetes Engine (GKE) with Autopilot
B.Compute Engine committed use discounts (CUDs)
C.Compute Engine preemptible VMs
D.Compute Engine Spot VMs
AnswerD

Spot VMs offer significant discounts (up to 91%) compared to on-demand VMs and can be preempted when resources are needed. They are ideal for batch processing that can tolerate interruptions. Unlike preemptible VMs, Spot VMs do not have a 24-hour maximum runtime, making them more flexible for longer jobs. This minimizes compute costs while meeting the workload's requirements.

Why this answer

Spot VMs provide the deepest discounts for interruptible workloads and have no maximum runtime limit, unlike preemptible VMs. They are perfect for batch processing that can be paused or restarted. Committed use discounts require long-term commitments, and GKE Autopilot adds unnecessary complexity for a simple batch job.

Spot VMs minimize compute costs while meeting the workload's tolerance for interruptions.

Exam trap

The trap here is selecting preemptible VMs instead of Spot VMs, as preemptible VMs have a 24-hour limit and are being deprecated in favor of Spot VMs.

153
MCQmedium

A developer runs the command above. The instance is created successfully, but cannot be reached via HTTP from the internet. What is the most likely cause?

A.There is no firewall rule allowing ingress traffic on ports 80 and 443.
B.The machine type n1-standard-2 is not suitable for HTTP.
C.The image family debian-10 does not support HTTP.
D.The boot disk type pd-standard is too slow.
AnswerA

Compute Engine instances have no implicit inbound access; the default network's firewall rules govern traffic. Without an ingress rule permitting TCP 80 and 443 from the relevant source ranges, HTTP requests from the internet are dropped before reaching the instance, even though it booted successfully.

Why this answer

The most likely cause is that there is no firewall rule allowing ingress traffic on ports 80 and 443. By default, Google Cloud Platform (GCP) firewall rules block all incoming traffic from the internet. Even though the instance is created successfully, HTTP/HTTPS traffic cannot reach it unless a firewall rule explicitly permits ingress on TCP ports 80 and 443, typically via a target tag like 'http-server' or 'https-server'.

Exam trap

Google Cloud often tests the misconception that creating a VM with a public IP automatically makes it reachable from the internet, when in reality GCP's default firewall rules block all ingress traffic until explicitly opened.

How to eliminate wrong answers

Option B is wrong because the machine type n1-standard-2 is a general-purpose machine that fully supports HTTP traffic; machine type does not affect protocol support. Option C is wrong because the image family debian-10 is a standard Linux distribution that supports HTTP out of the box; the OS image does not determine network reachability. Option D is wrong because the boot disk type pd-standard (standard persistent disk) provides sufficient I/O for basic HTTP serving; disk speed does not prevent the instance from being reached via HTTP from the internet.

154
Multi-Selectmedium

A company has a legacy application that runs on a single Compute Engine VM and expects to use a fixed IP address. They want to migrate the VM to a different region with minimal downtime. Which TWO actions should they take?

Select 2 answers
A.Use gcloud compute instances move command
B.Delete the original VM before creating the new one
C.Convert the VM to a managed instance group
D.Reserve a static external IP address in the target region
E.Create a snapshot of the boot disk and create a new VM from the snapshot in the target region
AnswersD, E

A static external IP is regional, so the address must be reserved in the destination region before the new VM exists. This satisfies the fixed-IP constraint, letting the migrated instance retain a predictable address after cutover.

Why this answer

Option D is correct because a static external IP address is region-scoped in Google Cloud, so to keep the legacy application's fixed IP behavior in the new region, a static external IP must be reserved in the target region and attached to the new VM. Option E is correct because creating a snapshot of the boot disk and then creating a new VM from that snapshot in the target region is the standard way to relocate a single Compute Engine VM's disk and data with minimal downtime. Option A is incorrect because gcloud compute instances move only moves an instance between zones within the same region, not to a different region.

Option B is incorrect because deleting the original VM before creating the new one increases downtime and risks losing the working instance. Option C is incorrect because converting to a managed instance group changes the architecture and does not by itself provide a fixed IP or a cross-region migration path.

Exam trap

PCA often tests the regional scope of external IP addresses — candidates assume an IP can be moved across regions like a global resource, but static external IPs are region-bound and must be re-reserved.

155
MCQmedium

A company is migrating 50 on-premises VMs to Compute Engine. They need to minimise downtime and want an automated lift-and-shift migration that replicates disks incrementally. Which Google Cloud service should be used?

A.Database Migration Service
B.Migrate for Compute Engine
C.Storage Transfer Service
D.Transfer Appliance
AnswerB

Migrate for Compute Engine performs automated lift-and-shift replication of on-premises VM disks to Compute Engine, continuously syncing changes so cutover downtime is minimal. This satisfies the incremental disk replication and low-downtime constraints for the 50 VMs without manual rebuilds.

Why this answer

Migrate for Compute Engine (formerly Velostrata) performs agentless, incremental replication of VM disks to Compute Engine, enabling minimal downtime migrations.

156
Drag & Dropmedium

Drag and drop the steps to deploy a containerized application to Google Kubernetes Engine (GKE) using a Deployment into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The image must be in a registry before the Deployment can reference it. The Service provides external access.

157
MCQeasy

A startup wants to deploy a containerized web application that must scale automatically based on incoming HTTP request volume and must be reachable at a stable HTTPS endpoint. The team has no Kubernetes experience and wants to minimize infrastructure management. Which Google Cloud service should they use?

A.Google Kubernetes Engine Autopilot with a HorizontalPodAutoscaler and an Ingress resource.
B.Compute Engine managed instance groups with an HTTP(S) load balancer and autoscaling based on CPU.
C.App Engine flexible environment with automatic scaling enabled and a custom runtime.
D.Cloud Run, with the container deployed as a service and request concurrency used to drive automatic scaling.
AnswerD

Cloud Run runs containers on a fully managed platform, scales instances automatically based on incoming requests and concurrency, and provides an HTTPS endpoint out of the box. It requires no cluster or VM management, which directly matches the team's lack of Kubernetes experience and their goal of minimizing infrastructure work.

Why this answer

Cloud Run is a fully managed container platform that scales automatically in response to request volume and exposes an HTTPS endpoint by default. Because it abstracts away clusters and VMs, it fits a team without Kubernetes skills that wants to minimize infrastructure management while still running a containerized web application.

Exam trap

The trap here is equating containers with Kubernetes, when a managed serverless container platform can run the same image with far less operational effort.

158
MCQeasy

A company wants to give a new employee read-only access to all projects in their GCP organization. Which IAM role should they assign at the organization level to grant this access?

A.roles/owner
B.roles/editor
C.roles/viewer
D.roles/orgadmin
AnswerC

roles/viewer grants read-only access to all GCP resources within the organisation, including every project beneath it. Assigning it at the organisation level satisfies the stem's requirement for organisation-wide read-only visibility, since the role inherits down the resource hierarchy to all current and future projects.

Why this answer

The roles/viewer role grants read-only access to all resources within the organization, including all projects, making it the correct choice for a new employee who needs read-only access across all projects. Assigning it at the organization level ensures the permission is inherited by all projects, folders, and resources beneath. This follows the principle of least privilege for read-only access.

Exam trap

PCA often tests the difference between basic roles (viewer, editor, owner) and their scope — candidates may pick roles/editor thinking it is needed to 'access' projects, but editor grants write access, violating the read-only requirement, while roles/viewer is the correct least-privilege choice.

How to eliminate wrong answers

Option A is wrong because roles/owner grants full control over all resources, including the ability to manage IAM policies and billing — far more than read-only access and a violation of least privilege. Option B is wrong because roles/editor grants read and write access (create, modify, delete resources) but not IAM management — still excessive for a read-only requirement. Option D is wrong because roles/orgadmin is a role for managing organization-level IAM policies and administrative settings, not for reading project resources; it is an administrative role, not a data-access role.

159
Multi-Selectmedium

A company wants to run containerized applications on Google Cloud with minimal operational overhead. They prefer to use a serverless container platform. Which TWO compute options should they consider? (Choose 2.)

Select 2 answers
A.Compute Engine
B.GKE Standard
C.Cloud Functions
D.GKE Autopilot
E.Cloud Run (fully managed)
AnswersD, E

GKE Autopilot provisions and manages the cluster's nodes, scaling and patching them automatically, so teams deploy pods without handling node operations. It runs containers natively, satisfying the serverless preference and the minimal-operational-overhead constraint, unlike standard GKE where you manage node pools yourself.

Why this answer

GKE Autopilot (D) is correct because it is a fully managed, serverless-style Kubernetes mode in which Google provisions and manages the nodes, scaling, and cluster infrastructure, letting the company run containerized workloads with minimal operational overhead. Cloud Run (fully managed) (E) is correct because it is a serverless container platform that abstracts away all infrastructure, scales automatically (including to zero), and bills only for resources used, directly matching the requirement to run containers with minimal operations. Compute Engine (A) is not appropriate because it provides raw VMs that the company must patch, scale, and manage itself, which is high operational overhead and not serverless.

GKE Standard (B) is not the best fit because, although it runs containers, the company remains responsible for node pools, upgrades, and cluster operations. Cloud Functions (C) is incorrect because it runs event-driven functions rather than arbitrary containerized applications, so it does not satisfy the containerized-application requirement.

160
MCQeasy

A company wants to monitor their Cloud Run services for errors and latency. Which Google Cloud product should they use?

A.Cloud Trace
B.Cloud Monitoring
C.Cloud Logging
D.Error Reporting
AnswerB

Cloud Monitoring natively ingests Cloud Run request metrics, error rates and latency percentiles, letting the company alert on them without custom instrumentation. It satisfies the stated requirement to monitor errors and latency across their services, unlike logging-only or CI/CD tools.

Why this answer

Cloud Monitoring (formerly Stackdriver Monitoring) provides comprehensive observability for Cloud Run services, including built-in dashboards for request latency, error rates, and resource utilization. It collects metrics like request count, request latencies, and container instance counts, and allows you to set alerting policies based on these metrics. While Cloud Trace can help with latency analysis and Cloud Logging captures logs, Cloud Monitoring is the primary product for monitoring both errors and latency in a unified view.

Exam trap

The trap here is that candidates often confuse Cloud Trace (for latency) or Error Reporting (for errors) as standalone solutions, but the question asks for a single product that monitors both errors and latency, which is Cloud Monitoring's role as the central metrics and alerting platform.

How to eliminate wrong answers

Option A is wrong because Cloud Trace is a distributed tracing tool focused on analyzing latency across service requests, but it does not provide a unified dashboard for error rates or resource metrics for Cloud Run. Option C is wrong because Cloud Logging is for storing, searching, and analyzing log data, not for monitoring metrics like latency percentiles or error counts in real-time dashboards. Option D is wrong because Error Reporting aggregates and analyzes application errors from logs, but it does not monitor latency or provide a holistic view of service health.

161
Multi-Selecthard

Your service has a 99.99% uptime SLO (monthly error budget ~ 4 minutes). Which TWO monitoring practices best support this SLO? (Choose 2)

Select 2 answers
A.Monitor CPU utilization and alert when average exceeds 80%.
B.Use a combination of availability (e.g., HTTP 200 rate) and latency (e.g., p99) as SLIs.
C.Use only synthetic monitoring from multiple locations.
D.Alert on every 5xx error immediately.
E.Track error budget consumption and alert when burn rate exceeds a threshold.
AnswersB, E

Availability alone misses degraded-but-successful responses, which still breach user expectations on a 99.99% target. Pairing HTTP 200 rate with p99 latency captures both failure and slowness, so the SLI reflects the actual user experience the SLO promises.

Why this answer

Option B is correct because a 99.99% uptime SLO is best measured with SLIs that reflect user-perceived health, so combining an availability SLI (the proportion of successful HTTP 200 responses) with a latency SLI (such as p99 request duration) captures both whether requests succeed and whether they are served acceptably fast. Option E is correct because with a monthly error budget of roughly 4 minutes, tracking error budget consumption and alerting on a burn rate threshold (for example, a fast-burn alert at 14.4x over 1 hour or a slow-burn alert at 6x over 6 hours) detects when the budget is being exhausted too quickly and enables timely action. Option A is not correct because CPU utilization is a resource metric, not a direct SLI for an uptime SLO, and an 80% average threshold does not reliably indicate user-visible failures.

Option C is not correct because relying only on synthetic monitoring from multiple locations omits real user traffic and can miss failures that affect actual customers. Option D is not correct because alerting on every 5xx error immediately is too noisy and does not account for error budget policy or burn rate.

Exam trap

PCA often tests the difference between resource metrics (CPU, memory) and user-centric SLIs — candidates pick CPU alerts because they are familiar, missing that SLOs must be measured with user-facing indicators and error budget burn.

162
MCQeasy

A company wants to migrate its on-premises monolithic application to Google Cloud with minimal changes. They plan to run it on a virtual machine with a predictable workload that runs 24/7 for a one-year commitment. Which compute option is MOST cost-effective?

A.Spot VMs
B.On-demand VMs
C.Committed use discounts
D.Preemptible VMs
AnswerC

Committed use discounts apply to Compute Engine vCPU and memory for a one- or three-year term, cutting cost substantially versus on-demand for steady 24/7 workloads. This matches the stem's predictable, year-long commitment with minimal application change.

Why this answer

Committed use discounts (CUDs) provide significant discounts (up to 57% for most services) in exchange for committing to a specific amount of resources for a 1- or 3-year term. For a predictable, 24/7 workload running for one year, CUDs are the most cost-effective option because they offer a lower price than on-demand and do not carry the risk of interruption like Spot or Preemptible VMs. Spot VMs are cheaper but can be preempted, making them unsuitable for a steady, always-on application.

Exam trap

The trap is assuming that Spot or Preemptible VMs are always the cheapest and therefore best, but they are unsuitable for workloads that cannot tolerate interruptions; the question specifies a predictable 24/7 workload, which points to CUDs.

How to eliminate wrong answers

Option A is wrong because Spot VMs are subject to preemption and are not suitable for a predictable 24/7 workload; they are best for fault-tolerant, batch, or stateless workloads. Option B is wrong because on-demand VMs are the most expensive option for long-term, steady usage; they offer no discount for commitment. Option D is wrong because Preemptible VMs (now largely replaced by Spot VMs) are also interruptible and not appropriate for a 24/7 application that must run continuously.

163
MCQeasy

A startup runs a batch analytics job on a single Compute Engine instance that takes about nine hours and reads 2 TB from a Cloud Storage bucket each run. The team wants to reduce cost without changing the application code, and the job can be interrupted and resumed from checkpoints. Which machine configuration should the architect recommend?

A.A Spot VM with local SSD scratch space, since the job reads data from Cloud Storage and can resume from checkpoints.
B.A sole-tenant node with a custom machine type sized to the job's peak memory usage.
C.A standard predefined machine type with a balanced persistent disk, billed on demand.
D.A committed use discount for a one-year term on a memory-optimized machine type.
AnswerA

Spot VMs offer deep discounts over on-demand pricing and can be preempted at any time, which is acceptable because the job checkpoints and resumes. Reading source data from Cloud Storage means local SSD is only scratch space, so losing it on preemption does not threaten the workload, making this the most cost-effective fit.

Why this answer

Spot VMs provide the largest discount available on Compute Engine and are appropriate when a workload can tolerate preemption and resume from checkpoints. Because the job reads its source data from Cloud Storage and only uses local SSD as scratch, losing the instance mid-run does not corrupt results, so the cost reduction comes with acceptable risk.

Exam trap

The trap here is assuming preemptible capacity is unsafe for long jobs, when checkpointing and external data storage make interruption harmless.

164
MCQhard

A GKE cluster has a Horizontal Pod Autoscaler (HPA) configured for CPU utilization. The pods are not scaling up even though CPU usage is high. What could be the reason?

A.The cluster autoscaler is disabled
B.The HPA is configured with the wrong metric name
C.The node pool is out of capacity
D.The pods do not have resource requests defined
AnswerD

Without CPU resource requests, the HPA cannot calculate utilisation as a percentage of the requested amount, so it treats the metric as unavailable and refuses to scale. Defining requests on the container spec satisfies the HPA's prerequisite for computing the target utilisation ratio.

Why this answer

HPA for CPU utilization calculates utilization as a percentage of the pod's CPU request, not of the node or a raw usage value. If pods have no resource requests defined, the HPA cannot compute a utilization percentage and will not scale, even when CPU usage is high. Defining CPU requests on the pods resolves this.

Exam trap

PCA often tests the HPA utilization formula — candidates assume HPA scales on raw CPU usage, but it actually scales on usage relative to the pod's CPU request, so missing requests silently break scaling.

How to eliminate wrong answers

Option A is wrong because the cluster autoscaler scales nodes, not pods; HPA scaling decisions are independent of node capacity, and disabling it would not prevent HPA from calculating desired replicas. Option B is wrong because a wrong metric name would typically cause the HPA to report an error or unknown metric, not silently fail to scale while CPU is high. Option C is wrong because node pool capacity affects whether new pods can be scheduled, but HPA would still attempt to scale and show pending pods — the root cause here is the missing request that blocks utilization calculation.

165
MCQmedium

A logistics company has a BigQuery dataset that is queried heavily by scheduled reports each morning. Finance wants predictable monthly spend and the ability to attribute query cost to each department. Analysts currently run ad hoc queries against on-demand pricing, and costs vary widely month to month. What should the architect recommend?

A.Set a custom quota on bytes billed per day for each department's service account and let queries fail when the quota is reached.
B.Create a separate project per department and enable BigQuery reservations with slot commitments assigned to each project.
C.Enable the BigQuery flat-rate legacy pricing model by purchasing a fixed number of slots per project.
D.Move the dataset to Cloud Bigtable and run the scheduled reports with a Dataflow job each morning.
AnswerB

BigQuery reservations with committed slots convert variable on-demand query charges into a fixed monthly cost, and assigning reservations per project gives each department an attributable capacity pool. This matches the finance requirement for predictability and per-department attribution, while scheduled reports draw from dedicated slots instead of competing for shared on-demand capacity.

Why this answer

Reservations with committed slots turn variable on-demand query charges into a fixed, forecastable monthly figure, and assigning capacity per project makes each department's usage attributable. This satisfies the finance requirement directly, whereas quotas merely cap usage and alternative engines add complexity without solving the predictability and attribution goals.

Exam trap

The trap here is choosing a quota or a deprecated flat-rate purchase when the requirement is predictable spend plus per-department attribution, which reservations and assignments provide.

166
MCQmedium

An engineer needs to share a VPC network across multiple projects in an organization while maintaining centralized network administration. Which approach should they use?

A.Shared VPC
B.VPC peering between all projects
C.Private Google Access
D.Cloud VPN between projects
AnswerA

Shared VPC lets a host project's network be shared into service projects, so subnets, firewall rules and routes stay centrally administered by the host project's admins while each service project's resources attach to it. This directly satisfies the requirement to share one VPC across projects with centralised network administration.

Why this answer

Shared VPC in Google Cloud lets an organization designate a host project whose VPC network is shared with multiple service projects. This centralizes network administration (subnets, firewall rules, routes managed in the host project) while allowing teams in service projects to deploy resources into the shared network. It is the canonical answer for cross-project network sharing with centralized control.

Exam trap

PCA often tests the distinction between Shared VPC (centralized admin, host/service projects) and VPC peering (decentralized, non-transitive) — candidates may pick peering thinking it achieves the same centralized control.

How to eliminate wrong answers

Option B is wrong because VPC peering connects separate VPC networks but does not centralize administration — each project still manages its own VPC, and peering is non-transitive, complicating many-project topologies. Option C is wrong because Private Google Access only allows VM instances without external IPs to reach Google APIs and services; it does not share a VPC across projects. Option D is wrong because Cloud VPN provides encrypted connectivity between networks (on-prem or other clouds), not intra-organization VPC sharing with centralized admin.

167
Multi-Selectmedium

An e-commerce platform uses Cloud SQL (MySQL) for its transactional database. They are experiencing performance degradation during peak hours due to high read traffic. They need to improve read throughput without modifying the application code. Which TWO actions should they take? (Choose 2)

Select 2 answers
A.Add a Cloud SQL Auth Proxy with connection pooling
B.Increase the number of vCPUs on the primary instance
C.Use Cloud Memorystore for caching session data
D.Enable query caching in Cloud SQL
E.Enable read replicas
AnswersB, E

Increasing vCPUs scales the primary instance vertically, allowing it to handle more read queries concurrently, improving throughput without application modification.

Why this answer

To improve read throughput without modifying application code, the best approaches are increasing the number of vCPUs on the primary instance (B) to handle more concurrent read operations, and enabling read replicas (E) to offload read traffic from the primary instance. Cloud SQL Auth Proxy (A) only provides a secure tunnel and does not offer connection pooling; connection pooling requires separate middleware. Using Memorystore (C) for session data caching reduces database load but does not directly improve read throughput for transactional queries, and query caching (D) is deprecated and not recommended.

168
MCQeasy

A startup is building a serverless application that processes events from Cloud Storage buckets. Each event triggers a Python function that resizes images. Which GCP compute service is MOST suitable for this event-driven workload?

A.Cloud Run
B.Compute Engine
C.App Engine
D.Cloud Functions
AnswerD

Cloud Functions executes single-purpose Python handlers in response to Cloud Storage object-finalise events, with no server or cluster management. Its native eventarc trigger binding satisfies the stem's event-driven, serverless constraint directly, scaling per event and billing only for invocation time.

Why this answer

Cloud Functions is designed for event-driven, serverless compute. It can be triggered directly by Cloud Storage events (object finalize/create). Cloud Run requires HTTP invocation, App Engine is for web apps, and Compute Engine VMs require management.

169
MCQhard

A media company stores 400 TB of video assets in a Cloud Storage bucket in the europe-west1 region. Editors in Tokyo and São Paulo complain about slow first-byte times when previewing assets. The architect must improve read latency for these global users while keeping a single canonical copy of each object and avoiding application changes that rewrite object paths. Which approach best meets these requirements?

A.Enable Cloud CDN on a global external Application Load Balancer with a backend bucket pointing at the existing Cloud Storage bucket.
B.Use Storage Transfer Service to copy objects into regional buckets in asia-northeast1 and southamerica-east1, and update the application to select the closest bucket.
C.Change the bucket's default storage class to Standard and enable Autoclass so objects are served from the nearest edge cache.
D.Create a multi-region bucket and migrate the objects, then serve reads from the same object names in the new bucket.
AnswerA

A backend bucket on a global external Application Load Balancer with Cloud CDN caches objects at Google's global edge, so editors in Tokyo and São Paulo fetch from a nearby point of presence. The bucket remains the single canonical source, object paths are unchanged, and no application rewrite is needed.

Why this answer

Cloud CDN attached to a global external Application Load Balancer with a backend bucket serves Cloud Storage content from Google's globally distributed edge caches. Readers in Tokyo and São Paulo are answered by a nearby point of presence, improving first-byte latency, while the europe-west1 bucket remains the sole origin and canonical copy. Because requests still use the same object paths through the load balancer, no application rewrite is required.

Exam trap

The trap here is confusing Cloud Storage location options such as multi-region with actual edge caching, when only Cloud CDN places content near global readers.

170
MCQhard

A security engineer is configuring VPC Service Controls to protect a project containing BigQuery datasets with PII. They want to prevent data exfiltration while allowing authorized users to query the data from outside the perimeter. Which configuration meets these requirements?

A.Create a perimeter that includes the project, and set the 'allowed external access' flag to true.
B.Create a perimeter and enable the 'exfiltration exception' for BigQuery.
C.Create a perimeter that includes only Compute Engine instances, and use a separate perimeter for BigQuery.
D.Create a perimeter that includes the project, and use an access level from Access Context Manager to grant access to authorized users.
AnswerD

A VPC Service Controls perimeter around the project blocks data exfiltration, while an Access Context Manager access level defines the trusted conditions under which authorised identities may reach BigQuery from outside the perimeter. Both are required to permit legitimate queries without opening the boundary.

Why this answer

VPC Service Controls use Access Context Manager (ACM) access levels to define granular, identity-based access conditions. By including the project in a perimeter and applying an access level that specifies authorized users (e.g., based on IP ranges, device state, or identity), you can allow those users to query BigQuery from outside the perimeter while blocking all other external traffic, preventing data exfiltration.

Exam trap

A common mistake in Google PCA exams is thinking VPC Service Controls have a simple 'allow external access' toggle or a dedicated 'exfiltration exception' flag, when in reality the only way to grant external access is through Access Context Manager access levels or ingress/egress rules.

How to eliminate wrong answers

Option A is wrong because VPC Service Controls do not have an 'allowed external access' flag; the correct mechanism is to use access levels from Access Context Manager to grant exceptions. Option B is wrong because there is no 'exfiltration exception' for BigQuery; VPC Service Controls block all data exfiltration by default, and exceptions are made via access levels or ingress/egress rules, not a dedicated flag. Option C is wrong because VPC Service Controls protect services like BigQuery by including the project containing the datasets, not by using separate perimeters for Compute Engine and BigQuery; Compute Engine instances are not the target resource here.

171
Multi-Selecthard

Which THREE of the following are recommended practices when designing a highly available architecture on Google Cloud using multiple regions?

Select 3 answers
A.Deploy Compute Engine instances in a single regional managed instance group
B.Use a global external HTTP(S) load balancer with backend services in multiple regions
C.Use Cloud Spanner or cross-region replication for databases
D.Implement health checks and automated failover using Cloud DNS with weighted routing
E.Use a single Cloud VPN tunnel for connectivity between regions
AnswersB, C, D

A global external HTTP(S) load balancer uses a single anycast IP and routes users to the nearest healthy regional backend. This satisfies the multi-region availability requirement by failing over automatically when a regional backend becomes unhealthy.

Why this answer

Option B is correct because a global external HTTP(S) load balancer uses a single anycast IP and automatically routes users to the closest healthy backend service across multiple regions, providing global failover and low-latency access. Option C is correct because Cloud Spanner offers a multi-region configuration with synchronous replication and strong consistency, and cross-region replication for databases ensures data survives a regional outage. Option D is correct because health checks detect unhealthy endpoints and Cloud DNS weighted routing (or failover routing policies) can automatically direct traffic away from a failed region.

Option A is not recommended because a single regional managed instance group confines instances to one region, so a regional outage takes down the whole workload. Option E is not recommended because a single Cloud VPN tunnel is a single point of failure; highly available designs require redundant tunnels or Cloud Interconnect with multiple paths.

Exam trap

Google Cloud often tests the misconception that a single regional managed instance group or a single VPN tunnel is sufficient for multi-region high availability, but the exam expects you to recognize that redundancy across regions and elimination of single points of failure are mandatory.

172
MCQhard

A Cloud Spanner instance is experiencing high latency for point reads. The instance has 5 nodes and the read throughput is moderate. The table has a primary key with monotonically increasing values. What is the most likely cause and optimization?

A.Use interleaved tables to reduce the number of index lookups.
B.The instance is underprovisioned; add more nodes.
C.The primary key design causes hotspotting; use a hash prefix or add a leading random value.
D.The instance has too many nodes causing transaction conflicts; reduce nodes.
AnswerC

Monotonically increasing keys concentrate all writes on the final key range, so a single split absorbs the load. Adding a hash prefix or leading random value distributes writes across splits, removing the hotspot and restoring point-read latency.

Why this answer

The monotonically increasing primary key causes all writes to be directed to the last tablet (splitting point), creating a hotspot on one node. This hotspot leads to high latency for point reads because that node becomes a bottleneck. Adding a hash prefix or a leading random value distributes writes and reads evenly across all nodes, resolving the hotspotting issue.

Exam trap

Google Cloud often tests the misconception that adding more nodes solves all performance issues, but here the problem is a design flaw (hotspotting) that requires a key distribution strategy, not more capacity.

How to eliminate wrong answers

Option A is wrong because interleaved tables reduce join latency by colocating parent-child rows, but they do not address the root cause of hotspotting from a monotonically increasing primary key. Option B is wrong because the instance has moderate throughput and 5 nodes, so underprovisioning is not indicated; adding more nodes would not fix the hotspotting and could increase costs unnecessarily. Option D is wrong because having too many nodes does not cause transaction conflicts; Cloud Spanner uses a distributed transaction protocol (Paxos-based) that scales with nodes, and reducing nodes would not resolve the hotspotting issue.

173
MCQmedium

A retail company runs a batch analytics workload on Compute Engine. Jobs run nightly, are fault-tolerant, and can be preempted. Finance wants to minimize compute cost while ensuring the jobs still complete each night. The jobs are managed by a Managed Instance Group (MIG) template that must stay within a single zone for data locality compliance. Which configuration should you recommend?

A.Create a zonal MIG with E2 standard VMs and configure a sustained use discount to lower the price.
B.Create a regional MIG with committed use discounts applied to the template and scale across three zones.
C.Create a zonal MIG with custom machine types and use the committed use discount for one-year terms.
D.Create a zonal MIG with a spot VM instance template and set the autoscaler to scale based on CPU utilization.
AnswerD

Spot VMs provide up to 60-91% discount versus standard VMs and are ideal for fault-tolerant, preemptible batch jobs. A zonal MIG keeps instances in one zone, satisfying the data locality requirement, and the autoscaler adds capacity when CPU rises during the nightly run. The job must tolerate preemption, which it does, so spot VMs directly minimize cost without violating the stated constraints.

Why this answer

Spot VMs offer the largest discount for fault-tolerant, preemptible workloads, and a zonal MIG preserves the single-zone data locality requirement. The autoscaler ensures the nightly job has enough instances to finish on time. Committed use and sustained use discounts target steady-state or long-running workloads, so they do not fit a short nightly batch window.

The combination of spot VMs, zonal placement, and CPU-based autoscaling meets both the cost and compliance constraints.

Exam trap

The trap here is assuming that committed use discounts are always the cheapest option, when they only pay off for steady, long-running workloads rather than nightly preemptible batch jobs.

174
Multi-Selecthard

A company wants to use Binary Authorization to enforce that only images signed by their internal CI/CD pipeline can be deployed to their GKE clusters. They have set up Cloud Build to sign images. Which THREE steps are required to configure this? (Choose 3)

Select 3 answers
A.Create an attestation for each container image using Cloud Build
B.Create a Binary Authorization policy that requires attestations for the GKE cluster
C.Create an attestor in Binary Authorization
D.Store the signing keys in Cloud HSM
E.Grant the GKE service account the roles/container.deployer role
AnswersA, B, C

Cloud Build must generate a cryptographic attestation (a signed note stored in Artifact Registry) for each image, proving it passed the pipeline. Binary Authorization then verifies this attestor signature at admission time, satisfying the constraint that only CI/CD-signed images deploy to GKE.

Why this answer

Option C is correct because Binary Authorization requires an attestor resource, which defines the cryptographic key pair (via Cloud KMS) and is used to verify attestations; without creating an attestor, no attestation can be validated. Option A is correct because the CI/CD pipeline (Cloud Build) must create a signed attestation for each container image after building it, proving the image was produced by the trusted pipeline. Option B is correct because a Binary Authorization policy must be configured to require attestations from that attestor for the GKE cluster, otherwise the cluster will not enforce the signature requirement.

Option D is not required: signing keys can be managed in Cloud KMS, and Cloud HSM is only an optional key protection level, not a mandatory step. Option E is not required: roles/container.deployer is unrelated to Binary Authorization enforcement and does not configure attestation verification.

Exam trap

PCA often tests the three required components of attestation-based Binary Authorization — candidates add optional hardening steps like Cloud HSM key storage or IAM role grants, mistaking them for mandatory configuration steps.

175
MCQmedium

A company uses Cloud Storage to store sensitive customer data. They must ensure that data at rest is encrypted with a customer-managed key that is automatically rotated every 90 days. Which Cloud Storage configuration should they use?

A.Use customer-supplied encryption keys (CSEK) and rotate them manually
B.Enable default encryption with a customer-managed key (CMEK) from Cloud KMS with automatic rotation set to 90 days
C.Use Cloud HSM to create a key and set the bucket to use that key without rotation policy
D.Use Google-managed encryption keys (SSE-GM)
AnswerB

A CMEK from Cloud KMS with a 90-day rotation schedule encrypts objects at rest under a key the customer controls and rotates, meeting both the customer-managed and automatic rotation constraints. Google-managed keys cannot satisfy the rotation requirement.

Why this answer

Option B is correct because Cloud KMS customer-managed encryption keys (CMEK) can be configured as the default encryption key for a Cloud Storage bucket, and Cloud KMS supports automatic rotation schedules (e.g., every 90 days). This satisfies both requirements: customer-managed key and automatic 90-day rotation, with no manual intervention.

Exam trap

PCA often tests the distinction between CMEK (customer-managed, Cloud KMS-rotatable) and CSEK (customer-supplied, not stored, not auto-rotatable), as well as the misconception that key rotation re-encrypts existing objects.

How to eliminate wrong answers

Option A is wrong because CSEK keys are supplied by the customer on every request and are not stored in Cloud KMS, so they cannot be automatically rotated — rotation would be entirely manual and error-prone. Option C is wrong because using a Cloud HSM key without a rotation policy fails the 90-day automatic rotation requirement, even though the key is customer-managed. Option D is wrong because Google-managed encryption keys (SSE-GM) are not customer-managed — Google owns and rotates them, violating the customer-managed key requirement.

176
MCQeasy

A retail company is planning to move its on-premises data warehouse to Google Cloud. They need a fully managed, petabyte-scale analytics database that supports standard SQL and can ingest data in real time from Pub/Sub. They also want to minimize administration and cost. Which Google Cloud service should they choose?

A.Bigtable
B.Cloud SQL for PostgreSQL
C.BigQuery
D.Cloud Spanner
AnswerC

BigQuery is a fully managed, petabyte-scale analytics data warehouse that supports standard SQL and integrates natively with Pub/Sub for real-time ingestion via the BigQuery Storage Write API or Dataflow. It eliminates infrastructure management and offers cost-effective pricing models. This directly matches the requirements for a managed, scalable analytics database with real-time ingestion.

Why this answer

BigQuery is the correct choice because it is a fully managed, petabyte-scale analytics database that supports standard SQL and integrates with Pub/Sub for real-time data ingestion. It minimizes administration and offers cost-effective pricing, making it ideal for moving an on-premises data warehouse to Google Cloud.

Exam trap

The trap here is confusing a transactional database like Cloud Spanner with an analytical data warehouse, or assuming that any scalable database can serve as a data warehouse.

177
MCQhard

Refer to the exhibit. A subnet was created with the `--enable-private-ip-google-access` flag. What does this flag enable for instances in this subnet?

A.Instances can use direct peering to connect to on-premises networks.
B.Instances automatically receive internal DNS names for Google services.
C.Instances can access Google APIs and services without requiring an external IP address.
D.Instances can route traffic to the internet through a Cloud NAT gateway.
AnswerC

Private Google Access lets instances with only internal IP addresses reach Google APIs and services through Google's internal network. It removes the need for an external IP or NAT gateway to reach those endpoints, satisfying the subnet's private-only addressing.

Why this answer

The `--enable-private-ip-google-access` flag allows VM instances in a subnet to reach Google APIs and services (such as Cloud Storage, BigQuery, and Cloud Pub/Sub) using only their internal (private) IP addresses, without needing an external IP address. This works by routing traffic through Google's internal network to the Google Front End (GFE), bypassing the public internet.

Exam trap

Google Cloud often tests the distinction between private Google access (which only covers Google APIs and services) and Cloud NAT (which provides outbound internet access for private instances), leading candidates to confuse the two or assume private Google access enables general internet connectivity.

How to eliminate wrong answers

Option A is wrong because direct peering to on-premises networks is enabled by setting up a dedicated interconnect or partner interconnect, not by the `--enable-private-ip-google-access` flag. Option B is wrong because internal DNS names for Google services are automatically provided by the Cloud DNS service for resources within the VPC, not by this subnet-level flag. Option D is wrong because routing traffic to the internet through a Cloud NAT gateway is a separate configuration that requires a Cloud NAT resource and a router, and it is not enabled by this flag; the flag specifically enables access to Google APIs and services, not general internet access.

178
MCQeasy

An organization wants to enforce that all container images deployed to their Google Kubernetes Engine (GKE) clusters are signed and have passed a vulnerability scan. Which GCP service should they use to enforce this policy?

A.Cloud Build
B.Artifact Registry
C.IAM
D.Binary Authorization
AnswerD

Binary Authorization enforces deploy-time attestations on GKE, admitting only images signed by trusted authorities and carrying vulnerability-scan attestations. This directly satisfies the stem's requirement that images be both signed and scanned before deployment, blocking non-compliant images at admission rather than merely detecting them afterwards.

Why this answer

Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed to GKE or Cloud Run. It works by requiring attestations (cryptographically signed proofs) that images have been built by a trusted builder and passed required checks such as vulnerability scanning. If an image lacks the required attestation, the admission controller rejects the deployment.

Exam trap

PCA often tests the difference between services that scan images (Artifact Registry/Container Analysis) and the service that enforces deployment-time policy (Binary Authorization); candidates frequently pick the scanning service instead of the enforcement service.

How to eliminate wrong answers

Option A is wrong because Cloud Build is a CI/CD service that builds and tests images but does not enforce admission policies at deploy time. Option B is wrong because Artifact Registry stores and scans container images but does not block deployments based on attestations. Option C is wrong because IAM controls who can perform actions on GCP resources, not whether a specific container image meets security attestation requirements.

179
MCQmedium

A company runs batch processing jobs nightly that can tolerate interruptions. They want to minimize compute costs for these jobs. Which Compute Engine machine type and provisioning model is most cost-effective?

A.E2 custom VMs with sole-tenant nodes
B.N2 standard VMs with committed use discounts
C.Preemptible VMs with custom machine types
D.GPU-accelerated VMs
AnswerC

Preemptible VMs suit interruptible batch workloads because they cost substantially less than standard instances, and Google forcibly stops them after 24 hours. Custom machine types let you match vCPU and memory precisely to the job, avoiding waste from oversized predefined shapes. Together they satisfy the stem's dual constraints: tolerance of interruptions and minimised compute cost.

Why this answer

Preemptible VMs are up to 80% cheaper than standard VMs and are ideal for fault-tolerant, interruptible batch jobs. Custom machine types allow tailoring CPU and memory to the workload, avoiding over-provisioning and further reducing cost.

Exam trap

PCA often tests the difference between committed use discounts (for steady-state) and preemptible/spot VMs (for interruptible); candidates may incorrectly choose CUDs for batch jobs.

How to eliminate wrong answers

Option A is wrong because sole-tenant nodes are for compliance and physical isolation, not cost savings; they are more expensive. Option B is wrong because committed use discounts require a 1- or 3-year commitment and are better for steady-state workloads, not interruptible nightly jobs. Option D is wrong because GPU-accelerated VMs are expensive and unnecessary for typical batch processing unless the job requires GPU.

180
MCQeasy

A developer wants to allow a Compute Engine VM to authenticate to Google Cloud APIs without embedding service account keys in the VM image. What is the recommended approach?

A.Use Cloud KMS to encrypt a service account key and store it in a bucket
B.Use a service account impersonation flow
C.Attach a service account to the VM instance
D.Create a service account key and store it in the VM's startup script
AnswerC

Attaching a service account to the VM lets Compute Engine supply short-lived credentials through the instance metadata server, so applications call Google Cloud APIs without embedded keys. This removes the key distribution and rotation risk that static service account keys in images create.

Why this answer

Attaching a service account to a Compute Engine VM instance is the recommended approach because it provides the VM with automatically rotated, short-lived credentials via the metadata server. Applications on the VM can call the metadata server to obtain access tokens without any key files. This eliminates the risk of key leakage and manual rotation.

Exam trap

The trap here is confusing service account impersonation with direct attachment; candidates may think impersonation is needed for VMs, but impersonation is for users or services acting as another identity, not for a VM's native authentication.

How to eliminate wrong answers

Option A is wrong because encrypting a service account key with Cloud KMS and storing it in a bucket still requires the VM to retrieve and decrypt the key, which introduces key management overhead and potential exposure. Option B is wrong because service account impersonation is typically used by human users or services that need to act as another service account, not as the primary method for a VM to authenticate to APIs. Option D is wrong because embedding a service account key in a startup script exposes the key in instance metadata and logs, which is a security anti-pattern.

181
MCQeasy

A company wants to reduce costs for a batch analytics job that runs nightly for 4 hours on Compute Engine VMs. The job is fault-tolerant and can handle instance restarts. Which Compute Engine VM pricing model is MOST cost-effective?

A.3-year committed use discount (CUD)
B.1-year committed use discount (CUD)
C.Sustained use discounts
D.Preemptible VMs
AnswerD

Preemptible VMs suit this fault-tolerant nightly batch job because they cost up to 80% less than standard instances, and the workload already tolerates restarts. The 24-hour maximum lifetime exceeds the 4-hour runtime, so forced preemption risk is acceptable, satisfying the cost-reduction constraint without disrupting analytics.

Why this answer

Preemptible VMs offer the lowest cost (up to 80% discount) and are ideal for fault-tolerant, short-lived batch workloads that can handle interruptions. Sustained use discounts apply automatically but require running a VM for at least 25% of a month. Committed use discounts require a 1- or 3-year commitment and are not as flexible for a short nightly job.

182
MCQeasy

A DevOps team wants to automate the deployment of infrastructure on Google Cloud using a declarative configuration language. They need to support Python and Jinja templates for reusable modules. Which service should they use?

A.Config Connector
B.Terraform on Google Cloud
C.Cloud Deployment Manager
D.Cloud Build
AnswerC

Cloud Deployment Manager uses YAML or Python plus Jinja templates, satisfying the declarative configuration and reusable-module constraints. Unlike Terraform's HCL or Config Connector's Kubernetes-style resources, its native Python and Jinja support directly matches the team's stated templating requirement.

Why this answer

Cloud Deployment Manager is Google Cloud's native infrastructure as code service that uses declarative YAML or Python/Jinja templates. It supports Python and Jinja templates for reusable modules, making it the correct choice for automating infrastructure deployment with those requirements.

Exam trap

PCA often tests the difference between infrastructure as code tools, and candidates may confuse Cloud Deployment Manager with Config Connector or Terraform, especially regarding template languages.

How to eliminate wrong answers

Option A is wrong because Config Connector is a Kubernetes add-on that allows you to manage Google Cloud resources through Kubernetes manifests, not a standalone declarative language with Python/Jinja templates. Option B is wrong because Terraform on Google Cloud uses HashiCorp Configuration Language (HCL), not Python or Jinja templates. Option D is wrong because Cloud Build is a CI/CD service that can run builds and deployments, but it is not a declarative infrastructure configuration language itself.

183
MCQeasy

A startup is deploying a new web application on Compute Engine. The application runs on a managed instance group and must be accessible from the internet over HTTP and HTTPS. The security team requires that the application be protected against common web attacks such as SQL injection and cross-site scripting. Which Google Cloud service should the architect use to meet these requirements?

A.Identity-Aware Proxy (IAP) with OAuth consent screen and context-aware access policies.
B.Cloud Armor with a security policy attached to the backend service of an external HTTP(S) load balancer.
C.VPC firewall rules that allow only HTTP and HTTPS traffic to the managed instance group.
D.Cloud CDN with signed URLs and origin access identity to restrict access to the backend instances.
AnswerB

Cloud Armor security policies can be attached to the backend service of an external HTTP(S) load balancer. It provides preconfigured WAF rules for SQL injection and cross-site scripting, as well as IP allowlisting and denylisting. This directly meets the requirement to protect the application from common web attacks.

Why this answer

Cloud Armor is the correct service because it provides a web application firewall with preconfigured rules for SQL injection and cross-site scripting, and it integrates directly with external HTTP(S) load balancers. Attaching a security policy to the backend service enforces these protections at the edge before traffic reaches the application.

Exam trap

The trap here is confusing network-layer firewall rules or identity-based access controls with application-layer WAF protection, which Cloud Armor specifically provides.

184
MCQmedium

Your team is deploying a new version of a microservices application on Google Kubernetes Engine (GKE). You want to gradually shift traffic to the new version while monitoring key performance indicators (KPIs) such as error rate and latency. If KPIs degrade, you need to automatically roll back. Which approach should you use?

A.Use GKE rolling updates with maxSurge and maxUnavailable set to 25%, and monitor KPIs manually.
B.Implement a canary deployment using Istio with Flagger, which automates traffic shifting and rollback based on Prometheus metrics.
C.Configure a GKE Ingress with two backends and use traffic splitting based on weights, then manually adjust weights based on monitoring.
D.Use Blue/Green deployment by creating a second deployment and switching the Service selector to the new version after manual testing.
AnswerB

Flagger is a progressive delivery tool that integrates with Istio to automate canary releases. It gradually shifts traffic, monitors Prometheus metrics for KPIs, and automatically rolls back if metrics breach thresholds. This matches the requirement for automated rollback based on KPIs.

Why this answer

Flagger with Istio automates canary deployments by incrementally shifting traffic, analyzing Prometheus metrics, and rolling back automatically if KPIs degrade. This provides safe, gradual rollout with minimal manual intervention. Other options either lack automation, do not support gradual traffic shifting, or require manual monitoring.

Exam trap

The trap here is confusing rolling updates with canary deployments; rolling updates replace pods but do not control traffic splitting or provide automated rollback based on metrics.

185
MCQmedium

A retail company runs a stateless web front end on a managed instance group of Compute Engine VMs behind an external Application Load Balancer. Traffic has grown, and the operations team wants to reduce the cost of idle capacity while still absorbing sharp, unpredictable spikes in user requests. They also want to avoid managing a separate autoscaling policy for each instance group. Which provisioning approach should the architect recommend?

A.Configure the existing managed instance group with a CPU utilization autoscaling policy and set the minimum replicas to the peak observed load.
B.Deploy the front end on Cloud Run with a serverless network endpoint group as the Application Load Balancer backend, letting Cloud Run scale instances automatically from zero request-based capacity.
C.Create a second managed instance group in a different region and use an external proxy Network Load Balancer to split traffic manually.
D.Replace the managed instance group with a single large Compute Engine VM using a committed use discount to lower the hourly rate.
AnswerB

Cloud Run scales stateless containers automatically based on incoming requests, including scaling from zero when idle, which removes the cost of idle VMs. A serverless network endpoint group lets the existing external Application Load Balancer route to Cloud Run, so the team keeps one front door while gaining request-driven elasticity and no per-group autoscaling policy to maintain.

Why this answer

The requirement is to cut idle capacity cost while absorbing unpredictable spikes without maintaining per-group autoscaling policies. Cloud Run provides request-driven autoscaling that can scale to zero and back out rapidly, and a serverless network endpoint group lets the existing external Application Load Balancer keep fronting the service. This removes idle VM cost and centralizes elasticity in the platform rather than in hand-tuned policies.

Exam trap

The trap here is assuming that a CPU-based autoscaling policy on the managed instance group is equivalent to request-driven serverless scaling, when CPU is a lagging signal that cannot react fast enough to sharp spikes.

186
Multi-Selecthard

A company runs a stateful application on GKE using StatefulSets. Which THREE practices improve reliability?

Select 3 answers
A.Use headless services.
B.Use horizontal autoscaling based on disk usage.
C.Use volume snapshots for backup.
D.Use pod disruption budgets.
E.Use persistent volumes with reclaim policy Delete.
AnswersA, C, D

Provides stable network identities for stateful workloads.

Why this answer

A headless service (clusterIP: None) allows direct pod-to-pod communication without load balancing, which is essential for stateful applications like databases that require stable network identities. Each pod in a StatefulSet gets a unique DNS name (e.g., pod-0.service.namespace.svc.cluster.local), enabling reliable discovery and ordering for replication, leader election, and failover. This ensures that clients always reach the correct pod instance, improving overall reliability.

Exam trap

Google Cloud often tests the misconception that horizontal autoscaling can be based on any arbitrary metric like disk usage, but the HPA only supports CPU, memory, and custom/external metrics that must be exposed through the Metrics Server or a custom metrics adapter.

187
MCQhard

Your company runs a stateful web application on Compute Engine instances in a managed instance group (MIG) with autoscaling based on CPU utilization. The application maintains session state in memory on each instance. Recently, users have been experiencing session timeouts and data loss during scaling events. Additionally, the application's performance degrades under load due to frequent database queries for session data. You need to design a solution that ensures session persistence, improves performance, and minimizes application changes. The application is written in Java and uses Tomcat. Which of the following should you do?

A.Rewrite the application to be stateless by moving all state to the frontend using JWT tokens, eliminating the need for server-side sessions.
B.Deploy Cloud Memorystore for Redis as a session store, and configure Tomcat to use Redis-backed session persistence using the Redisson or Spring Session framework.
C.Configure the load balancer to use session affinity (sticky sessions) and increase the instance size to handle more sessions per instance.
D.Store session data in Cloud SQL using Spring Session JDBC, and configure the application to retrieve sessions from the database.
AnswerB

Cloud Memorystore for Redis externalises session state, so instances in the MIG share sessions and survive scaling or restarts. Tomcat integrates via Redisson or Spring Session with minimal code changes, and Redis caching reduces the frequent database queries degrading performance.

Why this answer

It introduces an external, highly available, in-memory session store (Cloud Memorystore for Redis) that decouples session state from individual Compute Engine instances. This eliminates session loss during autoscaling events and reduces database load by serving session data from fast Redis memory, all while requiring minimal application changes via Tomcat's built-in session persistence or Spring Session integration.

Exam trap

The trap here is that candidates often choose session affinity (sticky sessions) thinking it solves session persistence, but it only routes traffic to the same instance and does not protect against session loss when that instance is terminated during autoscaling or maintenance.

How to eliminate wrong answers

Option A is wrong because rewriting the application to be stateless with JWT tokens moves session state to the frontend, which requires significant application changes and does not address the existing Tomcat session management; it also shifts security and token management complexity without solving the immediate session persistence issue. Option C is wrong because session affinity (sticky sessions) ties a user to a specific instance, which does not prevent session loss when that instance is terminated during autoscaling; increasing instance size only delays the problem and does not provide a shared, durable session store. Option D is wrong because storing session data in Cloud SQL (a relational database) introduces latency and contention for frequent session reads/writes, degrading performance under load, and it does not leverage the in-memory speed needed for session persistence; it also requires more application changes than using Redis with Tomcat.

188
MCQeasy

A startup is setting up a CI/CD pipeline for their web application using Cloud Build and Cloud Deploy. They have configured a Cloud Build trigger that executes on pushes to the main branch of a Cloud Source Repositories repository. The trigger runs a build step that builds a Docker image and pushes it to Artifact Registry, then creates a release using Cloud Deploy. The pipeline fails with an error message indicating that the Cloud Build service account does not have permission to create releases. What should the architect do to resolve the issue?

A.Add the Cloud Deploy Developer IAM role to the Cloud Build service account.
B.Verify that the cloudbuild.yaml file contains the correct steps.
C.Enable the Cloud Deploy API for the project.
D.Grant the Cloud Build service account the Cloud Run Admin role.
AnswerA

Granting the Cloud Deploy Developer role to the Cloud Build service account supplies the missing `clouddeploy.releases.create` permission, which the trigger's build step requires when invoking Cloud Deploy to create a release. This directly satisfies the stem's constraint: the service account currently lacks permission to create releases.

Why this answer

The Cloud Build service account (typically the Compute Engine default service account or a custom service account) needs the Cloud Deploy Developer IAM role (roles/clouddeploy.developer) to create releases in Cloud Deploy. This role grants the necessary permissions, such as clouddeploy.releases.create, which are required for the Cloud Build trigger to successfully create a release after building and pushing the Docker image. Without this role, the pipeline fails with a permission error, making option A the correct resolution.

Exam trap

The trap here is that candidates might assume the Cloud Build service account has sufficient permissions by default (e.g., via the Editor role) or confuse Cloud Deploy permissions with Cloud Run permissions, leading them to select the Cloud Run Admin role instead of the specific Cloud Deploy Developer role.

How to eliminate wrong answers

Option B is wrong because the cloudbuild.yaml file's correctness is irrelevant to the permission error; the error explicitly states the Cloud Build service account lacks permissions, not that the build steps are misconfigured. Option C is wrong because if the Cloud Deploy API were not enabled, the error would typically indicate that the API is not available or that the resource is not found, not a specific permission denied error for creating releases. Option D is wrong because the Cloud Run Admin role (roles/run.admin) grants permissions for Cloud Run services, not for Cloud Deploy release creation; Cloud Deploy uses its own IAM roles (e.g., Cloud Deploy Developer) to manage releases and delivery pipelines.

189
MCQmedium

A company runs a Kubernetes cluster on GKE. They need to ensure that pods cannot access Google Cloud APIs unless explicitly allowed through a service account. Which GKE feature should they use?

A.Network Policies
B.Pod Security Policies
C.Cloud Audit Logs
D.Workload Identity
AnswerD

Workload Identity binds a Kubernetes service account to a Google Cloud service account via IAM, so pods receive federated credentials only when explicitly mapped. This removes node-level credential inheritance, ensuring pods cannot reach Google Cloud APIs unless a binding is granted.

Why this answer

Workload Identity is the correct choice because it allows pods in GKE to authenticate to Google Cloud APIs using a specific Google service account, rather than the default Compute Engine service account. This ensures that pods cannot access any Google Cloud APIs unless explicitly granted permission via IAM roles bound to that service account, meeting the requirement for least-privilege access.

Exam trap

The trap here is that candidates often confuse network-level controls (Network Policies) with identity-based access controls, or they assume that Pod Security Policies can restrict API access, when in fact only Workload Identity provides the mechanism to explicitly bind pod identity to a specific Google service account for API authorization.

How to eliminate wrong answers

Option A is wrong because Network Policies control traffic flow between pods and external endpoints at the network layer (e.g., using IP addresses and ports), but they do not manage authentication or authorization to Google Cloud APIs. Option B is wrong because Pod Security Policies (now replaced by Pod Security Admission in GKE) enforce security constraints on pod specifications (e.g., privileged containers, host namespaces), but they do not control which Google Cloud APIs a pod can call. Option C is wrong because Cloud Audit Logs record API calls and activities for auditing purposes, but they do not restrict or prevent pods from accessing Google Cloud APIs.

190
MCQhard

Refer to the exhibit. A Cloud Deployment Manager deployment fails with the error 'Resource 'my-firewall' already exists'. What is the most likely cause?

A.The user lacks IAM permissions to create firewall rules.
B.The network reference in the firewall rule is incorrect.
C.A firewall rule with the name 'my-firewall' already exists in the project.
D.The deployment does not include a 'delete' policy for existing resources.
AnswerC

A pre-existing firewall rule named 'my-firewall' in the project directly triggers the "already exists" conflict, because Cloud Deployment Manager refuses to create a resource whose name is already taken. The stem's constraint is a naming collision within the target project, so the deployment cannot proceed until that rule is renamed or removed.

Why this answer

The error message 'Resource 'my-firewall' already exists' directly indicates that a firewall rule with the exact name 'my-firewall' is already present in the project. Cloud Deployment Manager creates resources by name, and if a resource with the same name exists (even if it was created outside the deployment), the deployment will fail unless the deployment is configured to adopt or manage that existing resource. The error is not about permissions, network references, or missing delete policies—it is a name collision.

Exam trap

Google Cloud often tests the distinction between resource name conflicts and other common errors (permissions, invalid references) to see if candidates can interpret the exact error message rather than guessing based on general troubleshooting.

How to eliminate wrong answers

Option A is wrong because an IAM permission issue would produce an error like 'Permission denied' or 'Required permission compute.firewalls.create', not a 'Resource already exists' error. Option B is wrong because an incorrect network reference would cause a validation error such as 'Invalid value for field 'network'' or a 400 Bad Request, not a resource name conflict. Option D is wrong because Deployment Manager does not require a 'delete' policy for existing resources; the 'delete' policy controls what happens to resources when the deployment is deleted, not whether a deployment can create a resource with a duplicate name.

191
MCQhard

An e-commerce company uses Cloud SQL for MySQL to handle user sessions. During Black Friday sales, the database experiences high read latency and connection timeouts. The traffic pattern shows 95% read operations and 5% write operations. They need to improve read performance without significant architectural changes. Which action should they take?

A.Enable Cloud SQL Proxy to reduce connection overhead.
B.Migrate from Cloud SQL to Cloud Spanner for better scalability.
C.Add Cloud SQL read replicas and configure the application to use them for read operations.
D.Enable automatic storage increases and increase the machine type of the primary instance.
AnswerC

Read replicas offload the 95% read traffic from the primary instance, cutting read latency and connection timeouts during peak load. Writes still go to the primary, and the application needs no architectural change beyond routing reads to replica endpoints.

Why this answer

Adding Cloud SQL read replicas and routing read traffic to them offloads the primary instance, which is the standard, low-disruption way to scale read-heavy workloads. With 95% reads, this directly addresses the bottleneck without architectural changes. Cloud SQL Proxy, Spanner migration, and storage/machine-type increases do not solve read contention as directly or with as little disruption.

Exam trap

PCA often tests whether candidates choose the least-disruptive, purpose-built solution — read replicas for read scaling — versus over-engineered migrations (Spanner) or tangential fixes (Proxy, storage increases) that sound plausible but miss the actual bottleneck.

How to eliminate wrong answers

Option A is wrong because Cloud SQL Proxy improves connection security and management but does not reduce read latency or offload read queries from the primary instance. Option B is wrong because migrating to Cloud Spanner is a significant architectural change, contradicting the requirement to avoid significant changes, and is overkill for a read-scaling problem. Option D is wrong because increasing storage and machine type scales vertically but does not distribute read load — it may delay the problem but does not address the 95% read pattern efficiently, and vertical scaling has hard limits.

192
Multi-Selectmedium

You are responsible for operations reliability of a production service running on Google Cloud. The service is deployed on GKE and exposes an external HTTPS endpoint through an external Application Load Balancer. You need to implement monitoring that detects when the service is unhealthy from the user's perspective and alerts the on-call team. (Choose two.)

Select 2 answers
A.Create an alerting policy on the Application Load Balancer's request count metric to fire when traffic drops below a static threshold.
B.Enable Cloud Trace on the GKE workloads and alert when the number of spans per minute exceeds a fixed value.
C.Set up an alerting policy on the load balancer's 5xx error rate and on backend latency, with thresholds tied to the service level objective.
D.Configure a log-based alert on GKE node system logs for the keyword 'OOMKilled'.
E.Create an uptime check in Cloud Monitoring that targets the external HTTPS URL and verifies the expected response code and content.
AnswersC, E

Load balancer 5xx rates and backend latency metrics capture server-side failures and performance degradation as seen at the edge. Alerting on these signals against SLO-derived thresholds detects when users experience errors or slow responses. Combined with an uptime check, this provides both external probing and internal telemetry for reliable detection.

Why this answer

Detecting user-facing unhealthiness requires probing the service as users reach it and monitoring the error and latency signals that reflect their experience. An uptime check from multiple locations validates the public endpoint and response content, while alerting on load balancer 5xx rates and backend latency ties detection to SLO thresholds. Together they catch both total outages and degraded performance.

Exam trap

The trap here is choosing internal resource metrics, such as OOMKilled logs or span counts, as the primary health signal instead of external probes and edge-level error and latency metrics.

193
MCQeasy

A startup runs a customer-facing web application on Cloud Run. The operations team needs to know when the service's request latency exceeds a threshold so they can respond before users complain. They want to be notified by email and also want a record of the incident for later review. Which Google Cloud service should they use to define the alerting policy?

A.Cloud Trace analysis reports scheduled to run daily and emailed to the operations team.
B.Cloud Monitoring alerting policies with a notification channel for email.
C.Cloud Run revision traffic splitting combined with a health check endpoint that returns an error when latency is high.
D.Cloud Logging log-based alerts with a notification channel for email.
AnswerB

Cloud Monitoring alerting policies evaluate metrics such as request latency against thresholds and trigger notifications through configured channels like email. They also record incidents and their state transitions, giving the team both immediate notification and a historical record. This is the native, integrated way to alert on Cloud Run latency metrics.

Why this answer

Cloud Monitoring alerting policies are designed to evaluate metrics like request latency against thresholds and to notify through channels such as email. They also track incidents over time, satisfying the need for both immediate notification and a reviewable record. Log-based alerts, Cloud Trace reports, and traffic splitting serve different purposes and do not provide threshold-based latency alerting with email notification.

Exam trap

The trap here is choosing log-based alerting for a numeric metric threshold, when log-based alerts fire on matching log entries rather than on values crossing a latency threshold.

194
MCQmedium

Your company runs a multi-region Cloud Spanner instance for a global financial application. The SLA requirement is 99.999% availability. You need to ensure that the database remains available during a regional outage. What configuration should you use?

A.Use a dual-region configuration with two regions but only one for writes.
B.Use a single-region configuration with a read replica in another region.
C.Use a multi-region configuration (e.g., nam3) with automatic replication across multiple regions.
D.Configure a single-region instance and create periodic backups to restore in another region.
AnswerC

Multi-region configurations such as nam3 replicate synchronously across regions, so a single regional outage does not interrupt reads or writes. This satisfies the 99.999% SLA, which a regional or single-region instance cannot deliver during regional failure.

Why this answer

Cloud Spanner multi-region configurations (e.g., nam3, eur3) automatically replicate data across regions within a continent. They provide 99.999% availability SLA. A single-region configuration offers 99.99% SLA.

Read replicas (as in Cloud SQL) are not a concept in Spanner. Multi-region configs use multiple read-write regions.

195
MCQhard

You are running a Kubernetes cluster in GKE with the default node pool configuration shown in the exhibit. Your application requires high disk I/O performance. You notice that the application is experiencing high latency for disk operations. What is the most likely cause?

A.Node auto-repair is causing disk contention.
B.The default node pool uses pd-standard disks, which have low IOPS.
C.The OAuth scopes restrict disk access, causing high latency.
D.The machine type n1-standard-2 does not have enough CPU.
AnswerB

GKE's default node pool provisions pd-standard persistent disks, which cap IOPS far below pd-ssd or pd-balanced. Since the stem specifies high disk I/O demand and observed latency, the storage class backing the nodes is the bottleneck. Upgrading the node pool to pd-ssd resolves the constraint.

Why this answer

The default node pool in GKE uses pd-standard (standard persistent disk) which provides lower IOPS compared to pd-ssd. For applications requiring high disk I/O performance, pd-standard disks become a bottleneck, causing high latency. Upgrading to pd-ssd or using local SSDs would resolve this issue.

Exam trap

Google Cloud often tests the distinction between storage performance (disk type) and other operational features (auto-repair, scopes, machine type), leading candidates to confuse node health mechanisms or permission settings with actual I/O performance bottlenecks.

How to eliminate wrong answers

Option A is wrong because node auto-repair is a GKE feature that automatically repairs unhealthy nodes (e.g., if the node fails health checks), but it does not cause disk contention; it operates at the node level, not by interfering with disk I/O. Option C is wrong because OAuth scopes control API access permissions (e.g., read/write to Cloud Storage), not the performance characteristics of persistent disk operations; disk I/O latency is a storage performance issue, not an authorization issue. Option D is wrong because n1-standard-2 (2 vCPUs, 7.5 GB memory) is a general-purpose machine type that can handle moderate workloads; insufficient CPU would manifest as high CPU utilization or scheduling delays, not specifically high disk I/O latency.

196
MCQeasy

Your company has a service running on Google Kubernetes Engine (GKE) that experiences occasional spikes in traffic. You need to ensure that the service remains available during these spikes by automatically scaling the number of pods based on CPU utilization. You also want to minimize cost by scaling down when traffic decreases. Which Kubernetes resource should you configure?

A.A Cluster Autoscaler with a node pool that has a minimum of 2 nodes and a maximum of 10 nodes.
B.A VerticalPodAutoscaler with a target CPU utilization of 80%.
C.A HorizontalPodAutoscaler with a target CPU utilization of 80% and a minimum of 2 replicas and a maximum of 10 replicas.
D.A PodDisruptionBudget with minAvailable set to 80%.
AnswerC

HorizontalPodAutoscaler automatically scales the number of pods in a Deployment or ReplicaSet based on observed CPU utilization or other metrics. Setting a target CPU utilization of 80% ensures that when average CPU exceeds 80%, more pods are added, and when it drops, pods are removed down to the minimum. This directly addresses traffic spikes and cost optimization.

Why this answer

HorizontalPodAutoscaler is the Kubernetes resource designed to scale the number of pods based on metrics like CPU utilization. By setting a target CPU utilization and replica bounds, it can automatically add pods during spikes and remove them when demand drops, ensuring availability and cost efficiency. The other options either adjust resources vertically, scale nodes, or manage disruptions, none of which directly scale pods based on CPU.

Exam trap

The trap here is confusing VerticalPodAutoscaler with HorizontalPodAutoscaler; vertical scaling adjusts resources per pod and does not add pods.

197
MCQeasy

A startup runs a stateless web front end on a managed instance group in a single zone. Traffic is unpredictable, and the team wants the instance group to add or remove instances automatically based on CPU utilization without manual intervention. The architect must choose the simplest managed approach. Which option should the architect configure?

A.Replace the managed instance group with a single large Compute Engine instance and enable live migration for maintenance events.
B.Deploy the front end to a second zone and use a global external Application Load Balancer to distribute traffic between the two instance groups.
C.Attach an autoscaling policy based on CPU utilization to the managed instance group and set minimum and maximum instance counts.
D.Create a Cloud Scheduler job that calls the Compute Engine API every five minutes to resize the managed instance group based on a Cloud Monitoring metric.
AnswerC

Managed instance group autoscaling natively supports CPU utilization policies and respects minimum and maximum replica bounds, adding or removing instances automatically as load changes. It requires no custom code or external scheduler and is the simplest managed mechanism for scaling a stateless front end.

Why this answer

A managed instance group supports autoscaling policies directly, including CPU utilization targets, and honors minimum and maximum instance counts so capacity tracks demand automatically. This is a built-in, fully managed capability that requires no custom scheduler or external automation, making it the simplest way to scale a stateless front end in response to unpredictable traffic.

Exam trap

The trap here is assuming you must script scaling through Cloud Scheduler and the Compute Engine API when managed instance group autoscaling already performs that loop natively.

198
MCQeasy

A media company runs a public web application behind a global external Application Load Balancer. They need to block traffic from specific countries subject to sanctions and rate-limit abusive clients, all without changing application code. Which Google Cloud service should the architect configure?

A.VPC firewall rules applied to the load balancer's backend instances
B.Identity-Aware Proxy with context-aware access levels based on device and location
C.Cloud Armor security policies with geographic-based rules and rate-based ban rules attached to the backend service
D.Cloud CDN with signed URLs and cache key policies
AnswerC

Cloud Armor attaches to the load balancer's backend service and evaluates requests at Google's edge. Geographic rules can deny traffic from sanctioned regions, and rate-based ban rules throttle or block clients exceeding configured thresholds, all declaratively and without application changes, matching the requirement exactly.

Why this answer

Cloud Armor security policies bind to the backend service of an external Application Load Balancer and inspect requests at Google's edge. Geographic rules deny traffic by source region, and rate-based ban rules throttle or temporarily ban clients exceeding thresholds, delivering sanctions blocking and abuse mitigation without modifying the application.

Exam trap

The trap here is assuming that VPC firewall rules, which operate on IP and port, can enforce country-based blocking or per-client HTTP rate limiting for a proxied load balancer.

199
MCQeasy

A startup is deploying a new web application on Google Cloud. They want to minimize operational overhead and ensure the application scales automatically based on traffic. They also want to pay only for what they use. Which Google Cloud service should the architect recommend?

A.Compute Engine managed instance groups with autoscaling.
B.Cloud Run.
C.App Engine standard environment.
D.Google Kubernetes Engine (GKE) with cluster autoscaler.
AnswerB

Cloud Run is a fully managed serverless platform that automatically scales containers based on traffic, including scaling to zero when there is no traffic. It abstracts away infrastructure management, so the startup only pays for resources used during request processing. This minimizes operational overhead and aligns with the pay-per-use requirement.

Why this answer

Cloud Run is a fully managed serverless platform that automatically scales based on traffic, scales to zero, and charges only for resources used during request processing. It requires no infrastructure management, making it ideal for minimizing operational overhead while meeting autoscaling and pay-per-use requirements.

Exam trap

The trap here is assuming that managed instance groups or GKE are less operational overhead because they are managed, but they still require significant configuration and maintenance.

200
MCQmedium

A gaming company needs to store player session data that is frequently updated and requires strong consistency within a single region. The data model is simple key-value with few attributes. They expect up to 1 million concurrent players, each performing 10 writes per second. Which database is most suitable?

A.Cloud SQL
B.Firestore
C.Cloud Bigtable
D.Memorystore
AnswerC

Cloud Bigtable delivers high-throughput, low-latency reads and writes for simple key-value data, scaling linearly to millions of operations per second. Its single-cluster routing provides strong consistency within one region, satisfying the gaming company's 10 million writes per second and simple-schema constraints.

Why this answer

Cloud Bigtable is a fully managed, high-throughput, low-latency NoSQL wide-column store designed for massive-scale workloads with simple key-value access patterns. It scales linearly to handle millions of operations per second and provides strong consistency for single-row reads/writes within a region, matching the gaming session use case. Its row-key design supports the 10 writes/sec per player at 1M concurrent players without the relational overhead of Cloud SQL.

Exam trap

PCA often tests the distinction between Bigtable (high-throughput, single-row strong consistency, NoSQL) and Firestore (document store with per-document write limits), causing candidates to pick Firestore for 'NoSQL key-value' scenarios.

How to eliminate wrong answers

Option A is wrong because Cloud SQL is a relational database with vertical scaling limits and is not designed for millions of concurrent high-write key-value operations. Option B is wrong because Firestore, while a NoSQL document store, has per-document write throughput limits (~1 write/sec per document) and is optimized for mobile/web sync rather than sustained high-volume session writes. Option D is wrong because Memorystore (Redis/Memcached) is an in-memory cache, not a durable primary database, and lacks the persistence and scale-out characteristics needed for player session data.

201
MCQhard

Your company runs a critical multi-tier application: a global HTTP(S) load balancer, multiple regional managed instance groups (MIGs) for the web tier, and Cloud Spanner for the data tier. You need to design for zone-level and region-level failures. What architecture ensures the highest availability?

A.Use a global HTTP(S) load balancer with a single global MIG and a multi-region Cloud Spanner instance.
B.Use a global HTTP(S) load balancer with a single zonal MIG and Cloud Spanner single-region.
C.Use a global HTTP(S) load balancer with regional MIGs in multiple regions, each spanning zones, and a multi-region Cloud Spanner instance.
D.Use a regional HTTP(S) load balancer with a regional MIG and Cloud SQL with cross-region replication.
AnswerC

Regional MIGs spanning zones absorb zone-level failures, while distributing them across multiple regions satisfies region-level resilience. The global HTTP(S) load balancer anycasts traffic to the nearest healthy backend, and the multi-region Cloud Spanner instance provides synchronous cross-region replication with automatic failover, meeting both failure scopes in the stem.

Why this answer

It combines a global HTTP(S) load balancer (which can route traffic to healthy backends across regions), regional MIGs that span multiple zones within each region (providing zone-level redundancy), and a multi-region Cloud Spanner instance (which provides synchronous replication across regions for strong consistency and automatic failover). This architecture ensures that if an entire zone or region fails, traffic is automatically redirected to healthy backends in other zones/regions, and Spanner continues to serve reads and writes without manual intervention.

Exam trap

Google Cloud often tests the distinction between 'regional' and 'global' load balancers, and the trap here is that candidates might choose a regional load balancer (Option D) thinking it is sufficient, but it cannot route traffic across regions, making it unsuitable for region-level failure recovery.

How to eliminate wrong answers

Option A is wrong because a single global MIG (even if multi-zonal) is still deployed within a single region; if that entire region fails, the application becomes unavailable. Option B is wrong because a single zonal MIG cannot survive even a zone failure, and a single-region Cloud Spanner instance cannot survive a regional failure. Option D is wrong because a regional HTTP(S) load balancer cannot distribute traffic across multiple regions, and Cloud SQL with cross-region replication does not provide the same strong consistency and automatic failover as multi-region Spanner; also, Cloud SQL cross-region replication is asynchronous and may lose data during a failover.

202
MCQmedium

A company has a fleet of Compute Engine instances that need to access a Cloud Storage bucket. The security team requires that only instances in specific VPC networks can access the bucket, and that the data is encrypted in transit. How can this be achieved?

A.Use a Cloud Storage bucket with encryption at rest using CSEK.
B.Use Cloud Armor with IP allowlists and enable TLS for the bucket.
C.Create a VPC Service Controls perimeter with access levels, and require HTTPS for the bucket.
D.Use a Cloud Storage bucket with encryption at rest using CMEK.
AnswerC

VPC Service Controls restrict access by network, and HTTPS ensures encryption in transit.

Why this answer

VPC Service Controls allows you to define a security perimeter around Cloud Storage, restricting access to only requests originating from specific VPC networks. By configuring an access level that requires HTTPS, you enforce encryption in transit, meeting both the network restriction and data-in-transit encryption requirements.

Exam trap

In the Google PCA exam, a common trap is confusing encryption at rest (CSEK/CMEK) with encryption in transit (HTTPS/TLS), and the fact that VPC Service Controls is the only option that combines network-level access restrictions with transport encryption enforcement.

How to eliminate wrong answers

Option A is wrong because encryption at rest using CSEK (Customer-Supplied Encryption Keys) does not restrict access to specific VPC networks nor does it enforce encryption in transit; it only protects data at rest. Option B is wrong because Cloud Armor is a web application firewall for HTTP(S) load balancing, not a mechanism to restrict Cloud Storage bucket access to specific VPC networks; IP allowlists alone cannot enforce VPC-level network boundaries. Option D is wrong because encryption at rest using CMEK (Customer-Managed Encryption Keys) similarly only protects data at rest and does not provide network-level access controls or enforce encryption in transit.

203
MCQhard

A company runs a microservices application on Google Kubernetes Engine (GKE). They want to ensure that each service can only communicate with the services it explicitly depends on, and they need to enforce this at the network layer without modifying application code. They also want to monitor allowed and denied traffic. What should they do?

A.Use Istio service mesh with mutual TLS and authorization policies.
B.Implement Kubernetes Network Policies and enable GKE network policy logging.
C.Use Anthos Service Mesh with access logging and policy enforcement.
D.Configure firewall rules in the VPC to allow only specific traffic between nodes.
AnswerB

Kubernetes Network Policies allow you to define ingress and egress rules for pods, enforcing communication only with specified services. GKE supports network policy logging, which provides visibility into allowed and denied traffic. This meets the requirement without modifying application code, as policies are applied at the network layer.

Why this answer

Kubernetes Network Policies provide pod-level network segmentation and are enforced by the container network interface (CNI) plugin. GKE supports network policy logging, which records allowed and denied connections. This approach does not require application code changes and operates at the network layer.

Exam trap

The trap here is confusing service mesh capabilities with network policy enforcement; service meshes operate at Layer 7 and often require sidecars, while Network Policies work at Layer 3/4 without code changes.

204
MCQmedium

A financial services firm stores sensitive customer transaction data in Cloud Storage buckets. The security team wants to ensure that the data is encrypted at rest with a key that the firm controls, and that the key is automatically rotated every 90 days. They also need to be able to revoke access to the data immediately by disabling the key. Which Google Cloud service and configuration should they use?

A.Use Customer-Managed Encryption Keys (CMEK) with Cloud KMS, set a rotation period of 90 days, and disable the key to revoke access.
B.Use Customer-Supplied Encryption Keys (CSEK) and store the keys in a secure vault, rotating them manually every 90 days.
C.Use Google-managed encryption keys and configure a Cloud Scheduler job to rotate the keys every 90 days.
D.Use Cloud HSM to generate keys, and configure Cloud Storage to use those keys with a 90-day rotation policy.
AnswerA

CMEK allows you to use your own keys in Cloud KMS to encrypt data in Cloud Storage. You can configure automatic rotation every 90 days, and disabling the key immediately prevents decryption, effectively revoking access. This meets all requirements: control over encryption, automatic rotation, and immediate revocation.

Why this answer

Customer-Managed Encryption Keys (CMEK) with Cloud KMS allow organizations to control the encryption keys used for data at rest in Cloud Storage. You can set an automatic rotation period, such as 90 days, and disabling the key immediately revokes access to the data. This satisfies the requirements for control, automatic rotation, and immediate revocation.

Exam trap

The trap here is confusing CMEK with CSEK; CSEK requires you to manage keys entirely, without Cloud KMS rotation or disablement features.

205
MCQmedium

A company wants to use Cloud Deploy to automate deployments to GKE. They need to configure an approval gate that requires manual approval before promoting a release to a production cluster. Where is this approval gate defined?

A.In the delivery pipeline YAML under the 'target' definition
B.In the Cloud Scheduler job
C.In the GKE cluster as a constraint
D.In the cloudbuild.yaml file
AnswerA

Cloud Deploy approval gates are declared within the delivery pipeline YAML, attached to the relevant target definition, so promotion to the production cluster pauses for manual approval. Defining it elsewhere, such as the Skaffold manifest or release notes, would not enforce the gate.

Why this answer

In Google Cloud Deploy, approval gates are defined within the delivery pipeline configuration, specifically under the target definition. The target represents a deployment environment (e.g., production cluster) and can include a 'requireApproval' field to enforce manual approval before any release is promoted to that target. This ensures that promotions to sensitive environments are gated by human intervention.

Exam trap

PCA often tests the misconception that approval gates are configured in Cloud Build or GKE, when they are actually part of the Cloud Deploy delivery pipeline's target definition.

How to eliminate wrong answers

Option B is wrong because Cloud Scheduler is used to schedule jobs, not to define deployment approval gates; it has no role in Cloud Deploy's promotion workflow. Option C is wrong because GKE cluster constraints (such as network policies or resource quotas) are unrelated to deployment approval; Cloud Deploy approvals are not enforced at the cluster level. Option D is wrong because cloudbuild.yaml is used by Cloud Build to define build steps, not to configure Cloud Deploy pipelines or approval gates.

206
Multi-Selecthard

Your company is deploying a multi-tier application on Google Cloud. The application consists of a web frontend running on Compute Engine instances, a backend API running on Google Kubernetes Engine (GKE), and a Cloud SQL for MySQL database. You need to design the network architecture to ensure that the web frontend can communicate with the backend API, and the backend API can access the Cloud SQL database, while minimizing exposure to the public internet. Which two design choices should you implement? (Choose two.)

Select 2 answers
A.Place the web frontend and backend API in the same VPC network but different subnets, and configure firewall rules to allow traffic only from the frontend subnet to the backend API on the required port.
B.Enable Private Service Access for Cloud SQL so that the backend API can connect to the database using a private IP address within the VPC.
C.Use Cloud VPN to connect the web frontend and backend API over an encrypted tunnel, even though they are in the same Google Cloud region.
D.Assign external IP addresses to all Compute Engine instances and GKE nodes, and use firewall rules to restrict access to specific source IP ranges.
E.Create a separate VPC network for each tier and use VPC peering to connect them, then configure firewall rules to allow traffic between the peered networks.
AnswersA, B

Placing both tiers in the same VPC network allows internal communication using private IP addresses, and firewall rules can restrict access to only the necessary source subnet and port. This minimizes public exposure because the backend API does not need a public IP. It also simplifies routing and security management within a single network.

Why this answer

The correct choices are to place both tiers in the same VPC with firewall rules restricting traffic, and to enable Private Service Access for Cloud SQL. This ensures internal communication without public internet exposure. Using a single VPC simplifies security, and Private Service Access provides private connectivity to Cloud SQL, meeting the requirement to minimize public exposure.

Exam trap

The trap here is thinking that additional network isolation (like separate VPCs or VPNs) automatically improves security, when it often adds complexity and does not reduce public exposure more than proper firewall rules and private service access.

207
MCQhard

A company has a production database running on Cloud SQL. They need to ensure high availability with automatic failover in the event of a zone outage. What should they do?

A.Export the database to Cloud Storage and import in another region.
B.Enable Cloud SQL High Availability (HA) configuration.
C.Create a cross-region read replica.
D.Configure automated backups.
AnswerB

Cloud SQL High Availability provisions a standby instance in a separate zone with synchronous replication, enabling automatic failover during a zone outage. This directly satisfies the stated availability constraint, whereas read replicas and backups do not provide automatic failover.

Why this answer

Enabling Cloud SQL High Availability (HA) configuration provisions a standby instance in a different zone within the same region, using synchronous replication to ensure zero data loss. In the event of a zone outage, Cloud SQL automatically fails over to the standby instance, typically within 60 seconds, providing high availability without manual intervention.

Exam trap

Google Cloud often tests the distinction between high availability (automatic failover within a region) and disaster recovery (cross-region replication or backups), leading candidates to confuse read replicas or backups with HA solutions.

How to eliminate wrong answers

Option A is wrong because exporting to Cloud Storage and importing in another region is a manual, disaster recovery process that does not provide automatic failover and incurs significant downtime. Option C is wrong because a cross-region read replica is designed for read scaling and asynchronous replication, not for automatic failover; promoting a read replica requires manual steps and may result in data loss. Option D is wrong because automated backups protect against data corruption or accidental deletion but do not provide a standby instance for automatic failover during a zone outage.

208
MCQeasy

An organization wants to manage Google Cloud infrastructure as code using declarative configuration files. They need a solution that supports Python and Jinja templating languages. Which service should they choose?

A.Cloud Composer
B.Terraform on Google Cloud
C.Cloud Deployment Manager
D.Cloud Build
AnswerC

Cloud Deployment Manager consumes YAML or Python configuration plus Jinja templates, matching the stem's Python and Jinja requirement for declarative Google Cloud infrastructure as code. Unlike Terraform's HCL or Config Connector's Kubernetes-style manifests, it natively supports both templating languages, satisfying the stated constraint directly.

Why this answer

Cloud Deployment Manager is Google Cloud's native infrastructure-as-code service that uses YAML declarative configuration files and explicitly supports Python and Jinja2 templating for parameterization and reuse. It integrates directly with GCP IAM and APIs, making it the correct choice when the requirement calls out Python and Jinja support. Terraform uses HCL, not Python/Jinja, so it fails the stated requirement.

Exam trap

PCA often tests the distinction between IaC tools by their templating language — candidates see 'Python and Jinja' and incorrectly jump to Terraform or Cloud Build instead of recognizing Deployment Manager as the GCP-native option.

How to eliminate wrong answers

Option A is wrong because Cloud Composer is a managed Apache Airflow workflow orchestration service for data pipelines, not an infrastructure-as-code provisioning tool. Option B is wrong because Terraform on Google Cloud uses HashiCorp Configuration Language (HCL) and its own templating, not Python or Jinja. Option D is wrong because Cloud Build is a CI/CD service that executes build steps from a cloudbuild.yaml, not a declarative IaC manager for GCP resources.

209
MCQmedium

A company wants to allow users to authenticate to a web application running on Compute Engine using their existing corporate Active Directory credentials without exposing the application to the public internet. Which approach should they use?

A.Configure a Cloud VPN and allow only corporate IP addresses in firewall rules
B.Set up Identity-Aware Proxy (IAP) and sync Active Directory to Cloud Identity
C.Use Cloud Load Balancing with SSL and client certificates
D.Configure Cloud NAT and assign static IPs to users
AnswerB

IAP enforces identity verification at the load balancer, letting corporate Active Directory users reach the private Compute Engine app without a public IP. Syncing AD to Cloud Identity federates those credentials, satisfying both the authentication and no-public-exposure constraints.

Why this answer

Identity-Aware Proxy (IAP) provides zero-trust access control to applications without exposing them to the public internet, and it integrates with Cloud Identity. By syncing on-premises Active Directory to Cloud Identity (via GCDS or federation), users can authenticate with their corporate credentials through IAP, which enforces IAM policies before allowing access to the Compute Engine-hosted app.

Exam trap

PCA often tests whether candidates confuse network-level access controls (VPN, firewall rules, client certs) with identity-based zero-trust access (IAP), and whether they understand that IAP requires Cloud Identity integration for AD credentials.

How to eliminate wrong answers

Option A is wrong because a Cloud VPN with IP-based firewall rules exposes the application to anyone on the corporate network and does not provide identity-based authentication — it's network-level, not user-level, access control. Option C is wrong because SSL with client certificates provides mutual TLS authentication but does not integrate with Active Directory credentials and still requires exposing the load balancer publicly. Option D is wrong because Cloud NAT provides outbound internet access for private instances and static IPs for egress — it has nothing to do with inbound user authentication or AD integration.

210
MCQmedium

Your organization runs a critical application on Compute Engine. The monthly bill shows sustained use discounts but the finance team wants to reduce costs further. The workload runs 24/7 with predictable usage for at least the next 12 months. You need to achieve the maximum possible discount without affecting performance or availability. What should you do?

A.Switch all instances to preemptible VMs to get the largest discount.
B.Enable automatic sustained use discounts by ensuring instances run for the full month.
C.Migrate the workload to a managed instance group with autoscaling.
D.Purchase a 1-year commitment for the specific vCPU and memory machine types used.
AnswerD

Committed use discounts (CUDs) provide up to 57% discount for a 1-year commitment on Compute Engine resources. Since the workload is predictable and runs 24/7 for at least 12 months, purchasing a commitment for the exact resources used is the most cost-effective option. It does not affect performance or availability because the resources remain dedicated to your project.

Why this answer

Committed use discounts offer substantial savings for predictable workloads. Because the application runs continuously for at least a year, committing to the specific resources ensures the highest discount without impacting performance or availability. Other options either compromise reliability or do not provide additional savings beyond existing discounts.

Exam trap

The trap here is assuming that preemptible VMs are always the cheapest option, but they are unsuitable for critical always-on workloads because they can be terminated.

211
MCQmedium

A company is migrating a stateful application to Google Cloud. The application requires persistent disks with low latency and high IOPS for database workloads. They plan to use Compute Engine instances with SSD persistent disks. However, the database performance is lower than expected. Which action should the company take to improve disk performance?

A.Change the persistent disk type to standard persistent disk.
B.Increase the disk size to increase baseline IOPS.
C.Use local SSDs with RAID 0 configuration for the database data.
D.Enable disk encryption to improve I/O throughput.
AnswerC

Local SSDs attach directly to the host, delivering far lower latency and higher IOPS than persistent SSD disks. RAID 0 stripes data across multiple local SSDs, multiplying throughput to meet the database workload's performance requirement.

Why this answer

Local SSDs provide the highest IOPS and lowest latency of any disk option on Compute Engine, and striping them with RAID 0 aggregates their performance. This directly addresses the need for high IOPS and low latency for database workloads, unlike persistent disks which have performance ceilings tied to disk size and instance limits.

Exam trap

The trap here is that candidates often assume increasing persistent disk size is the only way to improve IOPS, overlooking that local SSDs provide dramatically higher performance by being directly attached to the instance, and that RAID 0 is a common technique to aggregate their performance.

How to eliminate wrong answers

Option A is wrong because standard persistent disks have lower IOPS and higher latency than SSD persistent disks, which would worsen performance, not improve it. Option B is wrong because while increasing disk size does increase baseline IOPS for SSD persistent disks, the performance gain is limited by the persistent disk's architecture and does not match the raw throughput of local SSDs; it also increases cost without solving the latency issue. Option D is wrong because enabling disk encryption (e.g., using CMEK or CSEK) does not improve I/O throughput; encryption adds a small CPU overhead for encryption/decryption operations and can slightly reduce performance.

212
MCQmedium

Your team is responsible for a production service running on Google Cloud. You need to define Service Level Objectives (SLOs) and monitor them using Cloud Monitoring. You want to be alerted when the service's error budget is being consumed too quickly. Which approach should you take?

A.Use Cloud Monitoring's SLO monitoring to define an SLO with a 99.9% availability target, and create an alerting policy based on the burn rate of the error budget.
B.Set up a log-based metric that counts errors, and create an alert when the count exceeds a certain number within a 5-minute window.
C.Configure a dashboard in Cloud Monitoring that displays the error rate and set up a cron job to check the dashboard every hour and send an email if the error rate is high.
D.Create an alerting policy that triggers when the error rate exceeds a threshold of 1% over a 1-hour window.
AnswerA

Cloud Monitoring allows you to define SLOs and then create alerting policies that trigger based on the burn rate of the error budget. This is the recommended practice for alerting on SLO violations. You can set thresholds for burn rates over different windows (e.g., 2% in 1 hour) to detect both fast and slow burns, enabling proactive response before the budget is exhausted.

Why this answer

Cloud Monitoring's SLO monitoring feature allows you to define SLOs and then create alerting policies based on error budget burn rates. This is the most effective way to alert on SLO violations because it considers both the error rate and the time window, and it can detect when the budget is being consumed too quickly. Other methods lack the direct integration with SLOs and error budgets.

Exam trap

The trap here is assuming that a simple error rate threshold is sufficient, without considering the error budget burn rate and the SLO target.

213
Multi-Selectmedium

Which TWO are recommended practices for securing a Kubernetes Engine (GKE) cluster?

Select 2 answers
A.Disable HTTP load balancing to reduce attack surface.
B.Enable Binary Authorization to ensure only signed container images are deployed.
C.Use the default Compute Engine service account for all GKE nodes.
D.Use Workload Identity to bind Kubernetes service accounts to IAM service accounts.
E.Enable basic authentication for easier access management.
AnswersB, D

Binary Authorization enforces a deploy-time admission check, permitting only container images that carry a valid signature from an attested authority. Unsigned or tampered images are rejected before scheduling, preventing supply-chain compromise of the GKE cluster.

Why this answer

Option B is correct because Binary Authorization is a GKE security control that enforces deploy-time verification, allowing only container images that are attested or signed by trusted authorities to be admitted to the cluster, which prevents untrusted or tampered images from running. Option D is correct because Workload Identity is the recommended way to let GKE workloads access Google Cloud services: it binds a Kubernetes service account to an IAM service account via IAM policy bindings and the GKE metadata server, eliminating the need to export long-lived service account keys. The other options are not recommended: disabling HTTP load balancing (A) is not a standard GKE hardening practice and does not meaningfully reduce the cluster's attack surface, using the default Compute Engine service account for all nodes (C) grants overly broad, shared permissions and violates least privilege, and enabling basic authentication (E) is deprecated and insecure because it relies on static username/password credentials rather than modern identity-based access.

Exam trap

Google Cloud often tests the misconception that disabling features like HTTP load balancing is a security best practice, when in reality it breaks functionality and security should be layered (e.g., using HTTPS, IAP, or network policies) rather than removing features.

214
MCQmedium

A company is using Cloud Load Balancing to expose a web application. They want to protect against common web attacks like SQL injection and cross-site scripting. Which Google Cloud service should they configure?

A.VPC Firewall rules
B.Identity-Aware Proxy
C.Cloud Armor
D.Cloud CDN
AnswerC

Cloud Armor is Google Cloud's edge security service, providing WAF rules that filter SQL injection and cross-site scripting at the external load balancer. Attaching a security policy to the load balancer's backend service satisfies the requirement to block common web attacks.

Why this answer

Cloud Armor is the correct service because it provides Web Application Firewall (WAF) capabilities that can inspect HTTP/HTTPS traffic and filter out common web attacks such as SQL injection and cross-site scripting (XSS). It integrates directly with Cloud Load Balancing to apply pre-configured or custom rules at the edge, blocking malicious requests before they reach the backend.

Exam trap

The trap here is confusing network-layer security (VPC Firewall rules) with application-layer security (Cloud Armor), leading candidates to pick VPC Firewall rules because they sound like a general security measure.

How to eliminate wrong answers

Option A is wrong because VPC Firewall rules operate at the network layer (L3/L4) and cannot inspect application-layer payloads like HTTP requests, so they cannot detect or block SQL injection or XSS. Option B is wrong because Identity-Aware Proxy (IAP) controls access based on user identity and context, not by inspecting traffic for attack signatures; it is an authentication/authorization layer, not a WAF. Option D is wrong because Cloud CDN is a content delivery network that caches static content to improve performance and reduce latency; it does not provide any security filtering against web application attacks.

215
MCQeasy

A developer wants to deploy a containerized web application on Google Cloud that can scale to zero when not in use and charges only for resources consumed during request processing. Which compute service should they choose?

A.Cloud Run
B.Google Kubernetes Engine (GKE)
C.App Engine Flexible Environment
D.Compute Engine instance group
AnswerA

Cloud Run runs stateless containers on a fully managed, request-driven platform that scales to zero when idle, billing only per request and consumed CPU/memory. This directly satisfies the stem's constraints: containerised deployment, automatic scale-to-zero, and pay-only-during-request-processing charging.

Why this answer

Cloud Run is a fully managed serverless container platform that scales to zero when there is no traffic and bills only for CPU/memory consumed during request processing (and optionally during background work). It runs any containerized HTTP application, making it the exact match for the stated requirements. GKE and Compute Engine do not scale to zero, and App Engine Flexible keeps at least one instance running.

Exam trap

PCA often tests the difference between serverless container options — candidates confuse App Engine Flexible (always-on instances) with Cloud Run (true scale-to-zero, per-request billing) when the question emphasizes cost only during request processing.

How to eliminate wrong answers

Option B is wrong because GKE clusters always have at least one node running (unless using Autopilot with scale-to-zero on specific workloads, but the cluster itself incurs cost), so it does not truly scale to zero. Option C is wrong because App Engine Flexible Environment requires a minimum of one instance and bills for the underlying VM even when idle. Option D is wrong because a Compute Engine instance group maintains a minimum instance count and bills for VMs continuously, not per request.

216
MCQhard

A media streaming company wants to serve video content globally with low latency. They plan to cache static objects (thumbnails, manifest files) at edge locations, while dynamic API requests are handled by a backend in a single region. Which combination should they use?

A.Cloud CDN with an external HTTP(S) load balancer
B.Cloud CDN with an internal TCP/UDP load balancer
C.Cloud Armor with a TCP/SSL proxy load balancer
D.VPC peering with Cloud NAT
AnswerA

Cloud CDN caches static objects at Google edge locations, while an external HTTP(S) load balancer fronts the single-region backend and routes dynamic API requests. Together they satisfy both the global caching and single-region dynamic handling constraints.

Why this answer

Cloud CDN integrates with an external HTTP(S) load balancer to cache static content at Google edge locations while forwarding dynamic API requests to the backend in a single region. The external HTTP(S) load balancer provides a global anycast IP, terminates client connections at the edge, and routes requests to the backend based on URL maps. This combination is the standard Google Cloud architecture for global content delivery with low latency for static assets and centralized dynamic processing.

Exam trap

The trap is confusing Cloud CDN with security or internal load balancing services, or assuming that an internal load balancer can be used for external content delivery — Cloud CDN requires an external HTTP(S) load balancer.

How to eliminate wrong answers

Option B is wrong because an internal TCP/UDP load balancer is for internal traffic within a VPC and does not provide external client access or integrate with Cloud CDN for edge caching. Option C is wrong because Cloud Armor is a security service (WAF/DDoS protection) and a TCP/SSL proxy load balancer is for non-HTTP(S) traffic; neither provides CDN caching for static objects. Option D is wrong because VPC peering and Cloud NAT are networking constructs for private connectivity and outbound internet access, not for content delivery or load balancing.

217
MCQhard

Your organization runs a microservices application on Google Kubernetes Engine (GKE). Each microservice has its own deployment and horizontal pod autoscaler. You want to implement a robust cost governance process that provides chargeback to each team and prevents budget overruns. You need to attribute costs accurately without modifying application code. What should you do?

A.Deploy a third-party cost monitoring agent as a DaemonSet on each node.
B.Enable GKE cost allocation and use labels on namespaces to map costs to teams.
C.Create a separate GKE cluster for each team and enable billing export to BigQuery.
D.Use Kubernetes resource quotas and limit ranges to enforce budgets.
AnswerB

GKE cost allocation uses a combination of resource requests and actual usage to distribute cluster costs to namespaces, and you can apply labels to namespaces for team attribution. This requires no application changes and provides accurate chargeback data in Cloud Billing. It also supports budget alerts by label, enabling proactive governance.

Why this answer

GKE cost allocation is designed to break down cluster costs by namespace and label, enabling accurate chargeback without code changes. By labeling namespaces with team identifiers, you can generate reports and budget alerts per team. Other options either increase cost, do not provide attribution, or require additional tooling.

Exam trap

The trap here is thinking that resource quotas or separate clusters solve cost attribution, when they actually address consumption limits or isolation, not chargeback.

218
MCQeasy

A startup wants to grant a contractor limited access to a single Cloud Storage bucket. The contractor should be able to view and download objects, but not delete or overwrite them. Which IAM role should be assigned?

A.roles/storage.admin
B.roles/storage.objectAdmin
C.roles/storage.objectCreator
D.roles/storage.objectViewer
AnswerD

roles/storage.objectViewer grants read-only access to objects, permitting viewing and downloading but excluding delete or overwrite permissions. This satisfies the least-privilege constraint of limiting the contractor to a single bucket without mutation rights, unlike objectAdmin or objectCreator.

Why this answer

The roles/storage.objectViewer role grants read-only access to objects in a bucket, including listing and downloading objects, but does not allow modification or deletion.

219
MCQmedium

A Cloud Run service needs to connect to a Cloud SQL MySQL instance privately without using public IP. What must be configured?

A.Set up VPC Network Peering between Cloud Run and Cloud SQL
B.Enable Private Google Access on the VPC subnet
C.Use Cloud SQL Proxy as a sidecar container
D.Deploy a VPC connector and attach it to the Cloud Run service
AnswerD

A Serverless VPC Access connector gives Cloud Run a private network path, letting it reach the Cloud SQL instance over its internal IP. Attaching the connector to the service satisfies the no-public-IP constraint, since traffic never traverses the internet.

Why this answer

To connect a Cloud Run service to a Cloud SQL instance privately without using public IP, you must deploy a Serverless VPC Access connector and attach it to the Cloud Run service. This connector allows Cloud Run to route traffic to the VPC network, where Cloud SQL's private IP resides. The connection uses the VPC's internal IP range, ensuring private communication.

Exam trap

The trap is confusing VPC peering with Serverless VPC Access connectors; candidates may think peering directly connects Cloud Run to Cloud SQL, but Cloud Run requires a connector to join the VPC network.

How to eliminate wrong answers

Option A is wrong because VPC Network Peering is used between VPC networks, not between Cloud Run (a serverless product) and Cloud SQL; Cloud Run does not have a VPC network to peer. Option B is wrong because Private Google Access allows VMs without external IPs to reach Google APIs, but it does not enable Cloud Run to reach Cloud SQL private IPs. Option C is wrong because Cloud SQL Proxy is typically used for external connections or from Compute Engine; while it can be used as a sidecar in GKE, Cloud Run does not support sidecar containers natively in the same way, and the standard private connection method is a VPC connector.

220
MCQmedium

A company is designing a disaster recovery (DR) plan for their Cloud SQL for PostgreSQL instance. They need to recover the database to a specific point in time within the last 7 days, with a Recovery Point Objective (RPO) of less than 1 hour. Which feature should they use?

A.Exporting the database daily to Cloud Storage
B.Point-in-time recovery (PITR)
C.Failover replica
D.Automated backups only
AnswerB

PITR continuously archives transaction logs, letting Cloud SQL for PostgreSQL restore to any second within the retention window. This meets the sub-one-hour RPO and the seven-day recovery target, unlike daily automated backups, which cap recovery granularity at 24 hours.

Why this answer

Point-in-time recovery (PITR) for Cloud SQL for PostgreSQL lets you restore an instance to any specific timestamp within a configurable retention window (up to 7 days), using write-ahead log (WAL) archiving combined with automated backups. This directly satisfies the requirement to recover to a specific point in time within the last 7 days with an RPO under 1 hour, because WAL segments are continuously shipped and enable granular recovery. Automated backups alone only allow restore to the backup's snapshot time, which would not meet a sub-hour RPO.

Exam trap

PCA often tests the difference between HA (failover replica) and DR (PITR/backups) — the trap is choosing 'failover replica' because it sounds resilient, when it actually propagates logical corruption instead of enabling recovery to an earlier point.

How to eliminate wrong answers

Option A is wrong because daily exports to Cloud Storage only capture a point-in-time snapshot once per day, yielding an RPO of up to 24 hours and no ability to recover to an arbitrary point within the day. Option C is wrong because a failover replica provides high availability (automatic failover to a standby in another zone) but does not enable point-in-time recovery to an earlier timestamp — it mirrors the current state, including any logical corruption. Option D is wrong because automated backups alone restore only to the time the backup was taken (typically daily), which cannot meet a sub-1-hour RPO or a specific point-in-time requirement.

221
Multi-Selectmedium

Which THREE of the following are best practices when using Deployment Manager to manage infrastructure? (Choose three.)

Select 3 answers
A.Use raw REST API calls in templates.
B.Use templates to define resources modularly.
C.Use only YAML configuration files.
D.Use imports to reference shared configurations.
E.Use composite types to bundle related resources.
AnswersB, D, E

Templates decompose infrastructure into reusable, independently deployable modules, satisfying Deployment Manager's requirement for modular resource definitions. This enables consistent parameterised deployments across environments, reduces duplication, and supports version control of individual components rather than monolithic configurations.

Why this answer

Option B is correct because Deployment Manager templates let you define resources modularly, so reusable building blocks (for example a VM template) can be instantiated multiple times with different properties instead of duplicating configuration. Option D is correct because imports allow a configuration or template to reference shared, external templates (such as a common network or firewall template), promoting reuse and consistent configuration across deployments. Option E is correct because composite types bundle multiple related resources into a single reusable type, which simplifies managing and repeating multi-resource patterns.

Option A is not a best practice: raw REST API calls inside templates bypass the declarative template model and make configurations harder to maintain and reuse. Option C is not a best practice: Deployment Manager supports both YAML and Jinja/Python templates, so restricting yourself to only YAML configuration files unnecessarily limits templating and logic capabilities.

Exam trap

The trap here is assuming that only YAML is supported or that raw API calls are acceptable for advanced use. Candidates may overlook that Deployment Manager supports Python and Jinja2, and that modularity via imports and composite types is encouraged.

222
MCQmedium

A Cloud Function fails to connect to a Cloud SQL instance. The Cloud SQL instance has a private IP. What should the developer check?

A.Ensure the Cloud SQL Proxy is running and configured.
B.Verify the Cloud Function's network settings.
C.Ensure either Cloud SQL Proxy is running or a VPC connector is configured, and IAM permissions are correct.
D.Configure a VPC connector for the Cloud Function.
AnswerC

Both connectivity and authorization must be in place.

Why this answer

A Cloud Function with a private IP Cloud SQL instance requires either the Cloud SQL Proxy (which uses the Cloud SQL Auth proxy to establish an encrypted connection via the public IP, but if the instance has only a private IP, the proxy must be run within the same VPC) or a VPC connector to enable private networking. Additionally, proper IAM permissions (e.g., Cloud SQL Client role) are necessary for the proxy or connector to authenticate and connect. Without both the network path and IAM permissions, the connection will fail.

Exam trap

Google Cloud often tests the misconception that either a VPC connector or the Cloud SQL Proxy alone is sufficient, when in fact both the network path (via VPC connector or proxy in the VPC) and correct IAM permissions are required for private IP connectivity.

How to eliminate wrong answers

Option A is wrong because simply ensuring the Cloud SQL Proxy is running and configured is insufficient if the Cloud Function is not in the same VPC or lacks a VPC connector; the proxy alone cannot reach a private IP Cloud SQL instance from outside the VPC. Option B is wrong because verifying the Cloud Function's network settings is too vague and does not address the specific requirement of establishing a private network path via a VPC connector or proxy within the VPC. Option D is wrong because configuring a VPC connector alone is not enough; the Cloud SQL Proxy must also be running (or the connector must be paired with proper IAM permissions and the Cloud SQL Auth proxy) to handle authentication and encryption, and IAM permissions must be correct.

223
MCQmedium

A media company runs a stateless web application on Compute Engine behind an HTTP(S) load balancer. They want to automatically replace unhealthy VMs and maintain a fixed number of running instances across two zones. What should they use?

A.An unmanaged instance group with health checks
B.A zonal managed instance group with autoscaling
C.Compute Engine with instance templates and no group
D.A regional managed instance group with a fixed target size and autohealing
AnswerD

A regional managed instance group spreads instances across two zones, satisfying the multi-zone requirement, while its fixed target size maintains the exact instance count. Autohealing health checks detect and recreate unhealthy VMs automatically, meeting the self-healing constraint without manual intervention or external orchestration.

Why this answer

A regional managed instance group with a fixed target size and autohealing automatically replaces unhealthy VMs and maintains the specified number of instances across multiple zones. This meets the requirements of automatic replacement and fixed instance count across two zones. Autohealing uses health checks to detect and recreate unhealthy instances, ensuring high availability.

Exam trap

PCA often tests the difference between zonal and regional MIGs, and candidates may overlook the need for multi-zone distribution when the requirement specifies 'across two zones'.

How to eliminate wrong answers

Option A is wrong because an unmanaged instance group does not provide autohealing or autoscaling; it is just a collection of instances that you manage individually. Option B is wrong because a zonal managed instance group is confined to a single zone, so it cannot maintain instances across two zones. Option C is wrong because using instance templates without a group does not provide automatic replacement or scaling; you would have to manage instances manually.

Option D is correct.

224
MCQmedium

Your company runs a production microservices application on GKE Standard. The operations team wants to be notified when any pod in the cluster is repeatedly restarting, indicating a potential CrashLoopBackOff. They want to use Cloud Monitoring to create an alert that fires when a container restarts more than 5 times in a 10-minute window. Which metric should they use as the basis for the alerting policy?

A.kubernetes.io/container/cpu/core_usage_time
B.kubernetes.io/container/restart_count
C.kubernetes.io/pod/status
D.logging.googleapis.com/user/restart_count
AnswerB

This metric is a cumulative counter that tracks the number of times a container has restarted. By using a rate or delta alignment over a 10-minute window, you can detect when restarts exceed a threshold of 5, directly matching the requirement. It is the standard metric for container restarts in GKE and is available in Cloud Monitoring without additional setup.

Why this answer

The kubernetes.io/container/restart_count metric directly tracks container restarts and is the correct choice for alerting on repeated restarts. It is a cumulative counter, so you must apply a rate or delta alignment to detect increases over time. Other metrics like CPU usage or pod status do not provide restart counts, and log-based metrics require extra setup and may be less reliable.

Exam trap

The trap here is assuming that pod status or CPU metrics can indicate restarts, when only the dedicated restart count metric provides the necessary data.

225
MCQmedium

A team uses Cloud CDN to cache static assets. They update assets by deploying new versions with new URLs. However, sometimes they need to invalidate the cache for a critical fix immediately without changing the URL. What should they do?

A.Increase the TTL to max
B.Change the URL to a new version
C.Use cache invalidation to remove the cached objects
D.Set a short TTL (e.g., 1 minute)
AnswerC

Cache invalidation removes specific cached objects from Cloud CDN edge servers, forcing subsequent requests to fetch fresh content from the origin. This directly satisfies the stem's requirement to purge a critical fix immediately without altering the URL, unlike versioned deployments which rely on new URLs to bypass cached entries.

Why this answer

Cache invalidation is the correct mechanism when content must be refreshed immediately without changing the URL. Cloud CDN supports explicit invalidation requests that purge cached objects from edge locations, forcing subsequent requests to fetch fresh content from the origin. This is the only option that removes already-cached content on demand rather than waiting for TTL expiry or relying on URL changes.

Exam trap

The trap here is confusing TTL tuning with immediate cache control — candidates pick 'short TTL' thinking it approximates invalidation, but only explicit invalidation purges content on demand.

How to eliminate wrong answers

Option A is wrong because increasing the TTL extends how long stale content remains cached, directly worsening the problem. Option B is wrong because changing the URL is the versioning strategy already in use and does not address the scenario where the URL must stay the same. Option D is wrong because a short TTL only reduces the maximum staleness window; it does not guarantee immediate removal of the currently cached object.

Page 2

Page 3 of 11

Page 4

All pages