Courseiva

Google Professional Cloud Architect (PCA) — Questions 226–300

807 questions total · 11pages · All types, answers revealed

Page 3

Page 4 of 11

Page 5
226
MCQeasy

A retail company runs a Black Friday promotion and expects a burst of read traffic against a product-catalog database. The application is read-heavy, tolerates slightly stale data, and the team wants to scale reads horizontally without changing application code. They are using Cloud SQL for MySQL. Which design should the architect recommend?

A.Enable Cloud SQL high availability by adding a standby instance and send read queries to the standby
B.Increase the primary instance's vCPU count and memory to absorb the read burst
C.Migrate the catalog to Firestore in Native mode and let the client SDK cache reads
D.Configure a Cloud SQL read replica in the same region and point read queries at its IP address
AnswerD

Cloud SQL for MySQL supports read replicas that receive asynchronous replication from the primary. Pointing read-only traffic at the replica IP offloads the primary and scales reads horizontally. The application tolerates slight staleness, which matches asynchronous replication, and no schema or code changes are needed beyond routing read connections.

Why this answer

Read replicas are the native Cloud SQL for MySQL mechanism for horizontal read scaling with asynchronous replication. Because the application tolerates slightly stale data, the replication lag is acceptable, and no code changes are needed beyond pointing read connections at the replica. A high-availability standby is not readable, Firestore requires a rewrite, and vertical scaling does not scale reads horizontally.

Exam trap

The trap here is assuming the high-availability standby can serve reads, when it is a non-readable failover target only.

227
MCQmedium

A security engineer wants to prevent data exfiltration from a project 'prod-data' by ensuring that only approved VPC networks can access BigQuery datasets. Which GCP service should be used?

A.Private Google Access
B.Cloud Armor
C.Cloud NAT
D.VPC Service Controls
AnswerD

VPC Service Controls builds a service perimeter around BigQuery, restricting access to approved VPC networks and blocking data exfiltration even by authorised identities. This directly enforces the network-origin constraint on the prod-data project's datasets, which IAM alone cannot achieve.

Why this answer

VPC Service Controls create a service perimeter around GCP resources such as BigQuery datasets, restricting access to only approved VPC networks and identities. By placing the 'prod-data' project inside a perimeter and defining access levels, the engineer can block data exfiltration from unapproved networks. This is the GCP-native control designed specifically for this scenario.

Exam trap

The trap is confusing network-level controls (Private Google Access, Cloud NAT) with API-level perimeter controls (VPC Service Controls) that actually restrict data access to approved networks.

How to eliminate wrong answers

Option A is wrong because Private Google Access only allows VM instances without external IPs to reach Google APIs; it does not restrict which networks can access BigQuery. Option B is wrong because Cloud Armor protects HTTP(S) load-balanced applications from web attacks, not BigQuery data access. Option C is wrong because Cloud NAT provides outbound internet access for private instances; it has no role in restricting BigQuery access.

228
MCQhard

Your company uses a CI/CD pipeline that builds container images and stores them in Artifact Registry. The images are deployed to Google Kubernetes Engine (GKE). You need to ensure that only images that have been scanned for vulnerabilities and approved by a security team can be deployed to the production GKE cluster. You want to enforce this policy automatically without modifying the CI/CD pipeline. What should you do?

A.Configure a Kubernetes admission webhook that calls the security team's API to validate each image before deployment.
B.Restrict Artifact Registry permissions so that only the security team can push images to the production repository.
C.Enable Binary Authorization on the GKE cluster and configure a policy that requires attestations from the security team's attestor.
D.Use Container Analysis to scan images and set a vulnerability threshold that blocks deployment if any critical vulnerability is found.
AnswerC

Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed on GKE. By configuring a policy that requires an attestation from the security team's attestor, only images that have been scanned and approved can be admitted. This enforcement happens at the cluster level without changing the CI/CD pipeline.

Why this answer

Binary Authorization enforces deploy-time policies on GKE by requiring cryptographic attestations that prove an image was scanned and approved. The security team can sign attestations after scanning, and the GKE cluster will only admit images with valid attestations. This meets the requirement without altering the CI/CD pipeline and provides automated enforcement.

Exam trap

The trap here is confusing vulnerability scanning with deployment enforcement; scanning alone does not block unapproved images from being deployed.

229
MCQmedium

A company uses Terraform to manage Google Cloud infrastructure. They want to store the Terraform state file in a remote backend with state locking to prevent concurrent modifications. Which Google Cloud service supports this natively?

A.Cloud Firestore
B.Cloud Spanner
C.Bigtable
D.Cloud Storage
E.Cloud SQL
AnswerD

Correct. Cloud Storage is the native Terraform backend for GCP.

Why this answer

Google Cloud Storage (GCS) is the only option that natively supports Terraform's remote state backend with state locking. Terraform uses GCS's object versioning and a write-lock mechanism via a separate lock file (e.g., `default.tflock`) stored in the same bucket, leveraging GCS's strong consistency for atomic operations. This prevents concurrent `terraform apply` commands from corrupting the state.

Exam trap

Google Cloud often tests the misconception that any database with locking (like Cloud Spanner or Cloud SQL) can serve as a Terraform backend, but the exam requires knowing that only services with a native Terraform backend implementation—specifically Cloud Storage—are supported for state locking.

How to eliminate wrong answers

Option A is wrong because Cloud Firestore is a NoSQL document database designed for mobile/web apps, not for Terraform state locking; it lacks native Terraform backend support. Option B is wrong because Cloud Spanner is a globally distributed relational database with strong consistency, but Terraform does not provide a native Spanner backend for state storage. Option C is wrong because Bigtable is a wide-column NoSQL database optimized for high-throughput analytics, not for Terraform state management; it has no native Terraform backend integration.

Option E is wrong because Cloud SQL is a managed relational database service (MySQL/PostgreSQL/SQL Server) that Terraform does not support as a native state backend; it would require custom tooling for locking.

230
MCQmedium

A retail company runs a web application on Compute Engine instances behind an external HTTP(S) load balancer. During a flash sale, the operations team notices that the load balancer is returning HTTP 502 errors for a subset of requests. The backend service health checks are passing, and the instances are not under heavy CPU load. The team wants to identify the root cause quickly and prevent recurrence. Which action should they take first?

A.Configure a Cloud Armor security policy to block traffic from suspicious IP addresses.
B.Review the load balancer's logs in Cloud Logging for HTTP 502 status codes and examine the backend service's health check logs.
C.Enable Cloud CDN on the backend service to cache static content and reduce load on the instances.
D.Increase the backend service's timeout setting from 30 seconds to 60 seconds.
AnswerB

The first step in troubleshooting is to gather data. Cloud Logging captures load balancer logs that include the status code, backend instance, and error details. By filtering for 502 errors, the team can identify patterns such as a specific instance or a particular request path. Examining health check logs can reveal if health checks are flapping or if instances are being marked unhealthy intermittently. This data-driven approach identifies the root cause before making changes.

Why this answer

The most effective first step is to use Cloud Logging to examine load balancer logs and health check logs. These logs provide detailed information about the 502 errors, including which backend instances are involved and any error messages. By analyzing this data, the team can pinpoint the root cause, such as a misconfigured backend, an application error, or a network issue.

Only after identifying the cause should they take corrective action to prevent recurrence.

Exam trap

The trap here is jumping to configuration changes like increasing timeouts or enabling CDN without first diagnosing the actual cause of the 502 errors.

231
MCQmedium

Your team is deploying a stateful web application on Google Kubernetes Engine (GKE). The application requires each replica to have a stable network identity and its own persistent disk that survives pod restarts. You also need to ensure that the persistent disk is automatically provisioned and attached. Which GKE feature should you use?

A.DaemonSet with hostPath volumes
B.Deployment with a PersistentVolumeClaim
C.StatefulSet with a PersistentVolumeClaim template
D.CronJob with a PersistentVolumeClaim
AnswerC

StatefulSets are designed for stateful applications, providing stable network identities and persistent storage. The volumeClaimTemplates automatically create a PersistentVolumeClaim for each replica, which dynamically provisions a PersistentVolume (e.g., a Compute Engine persistent disk) and attaches it to the pod. This meets the requirement for stable identity and persistent storage that survives pod restarts.

Why this answer

StatefulSets are the correct choice for stateful applications on GKE because they provide stable network identities and persistent storage per replica. The volumeClaimTemplates automatically create PVCs, which dynamically provision persistent disks. Deployments, DaemonSets, and CronJobs lack these features, making them unsuitable for this scenario.

Exam trap

The trap here is assuming that a Deployment with a PersistentVolumeClaim can provide stable network identities and per-replica storage, but Deployments are designed for stateless workloads and do not offer these guarantees.

232
MCQeasy

Which GCP service can be used to detect and redact sensitive data such as credit card numbers in text files stored in Cloud Storage?

A.Security Command Center
B.Cloud Key Management Service
C.Cloud Audit Logs
D.Cloud Data Loss Prevention (DLP)
AnswerD

Cloud DLP inspects Cloud Storage objects using infoType detectors that recognise credit card numbers and other sensitive patterns, then redacts or masks the matches. It satisfies the detection-and-redaction requirement directly, unlike encryption or access-control services that never examine file contents.

Why this answer

Cloud Data Loss Prevention (DLP) is a fully managed service designed to discover, classify, and protect sensitive data. It uses built-in infoType detectors (e.g., CREDIT_CARD_NUMBER, US_SOCIAL_SECURITY_NUMBER) to scan text files in Cloud Storage and can redact or mask the findings. The other services do not provide data inspection and redaction capabilities.

Exam trap

PCA often tests the misconception that security management tools like Security Command Center or audit logs can detect and redact sensitive data, when in fact only Cloud DLP provides data inspection and de-identification capabilities.

How to eliminate wrong answers

Option A is wrong because Security Command Center is a security posture management and threat detection service that aggregates findings from other tools; it does not scan file contents for sensitive data or perform redaction. Option B is wrong because Cloud Key Management Service manages encryption keys and cryptographic operations, not data inspection or redaction. Option C is wrong because Cloud Audit Logs record administrative and data access activities for auditing purposes; they do not analyze file contents for sensitive information.

233
MCQhard

A healthcare company is designing a system to process sensitive patient records on Google Cloud. They need to ensure that data is encrypted at rest with keys they control and can rotate on demand. They also require that the encryption keys are stored in a hardware security module (HSM) that is FIPS 140-2 Level 3 validated. Which Google Cloud service should they use?

A.Cloud HSM with Cloud KMS
B.Google-managed encryption keys
C.Customer-managed encryption keys (CMEK) with Cloud KMS
D.Customer-supplied encryption keys (CSEK)
AnswerA

Cloud HSM is a cloud-hosted HSM that is FIPS 140-2 Level 3 validated. When used with Cloud KMS, you can create and manage keys in an HSM, control rotation, and use them for encryption at rest. This meets all requirements: customer-controlled keys, on-demand rotation, and HSM storage with FIPS 140-2 Level 3. It integrates with many Google Cloud services for CMEK.

Why this answer

Cloud HSM with Cloud KMS provides hardware security module-backed keys that are FIPS 140-2 Level 3 validated. It allows you to control key rotation and use them for encryption at rest across Google Cloud services. Google-managed keys do not give customer control, CMEK with standard Cloud KMS does not guarantee HSM storage, and CSEK requires external key management without HSM integration.

Exam trap

The trap here is assuming that CMEK alone provides HSM storage, but only Cloud HSM offers FIPS 140-2 Level 3 validated hardware security modules.

234
Multi-Selectmedium

Your company is deploying a new application on Google Cloud and needs to ensure that it can meet a 99.9% availability SLA. You are designing the architecture for high availability. Which two practices should you implement? (Choose two.)

Select 2 answers
A.Implement health checks and autohealing for managed instance groups.
B.Use a single global load balancer to distribute traffic across all instances.
C.Deploy the application across multiple zones within a single region.
D.Use a single zone with a high-capacity machine type to reduce complexity.
E.Store application state on a local SSD attached to each instance.
AnswersA, C

Health checks and autohealing ensure that unhealthy instances are automatically recreated. This maintains the desired capacity and availability of the application. When combined with multi-zone deployment, autohealing helps recover from instance failures quickly, contributing to meeting high availability SLAs.

Why this answer

To achieve high availability, you should deploy across multiple zones within a region to survive zone failures and implement health checks with autohealing to automatically recover from instance failures. These two practices together ensure that the application remains available even when individual instances or zones fail, helping to meet a 99.9% SLA.

Exam trap

The trap here is assuming that a global load balancer alone provides high availability, when it must be paired with multi-zone deployment and autohealing to be effective.

235
Multi-Selecthard

Which TWO of the following are valid methods to control access to Google Cloud resources using Identity and Access Management (IAM)?

Select 2 answers
A.Attach an IAM policy to an organization
B.Attach an IAM policy to a project
C.Attach an IAM policy to a user
D.Assign an IAM role directly to a user
E.Attach an IAM policy to a service account
AnswersA, B

IAM policies can be attached at the organisation node, and these inherit downward to all folders, projects and resources beneath it. This satisfies centralised control across the entire resource hierarchy rather than a single project scope.

Why this answer

Option A is correct because IAM policies can be attached at the organization node in the resource hierarchy, allowing centralized control over all projects, folders, and resources beneath it. Option B is correct because IAM policies can be attached to a project, which is a fundamental resource container in Google Cloud where allow policies bind principals to roles. Options C and E are incorrect because IAM policies are attached to resources (like organizations, folders, projects, and individual resources), not directly to users or service accounts; users and service accounts are principals that appear inside a policy binding.

Option D is incorrect because IAM roles are not assigned directly to a user as a standalone object; instead, a role is granted to a principal through a policy binding on a resource.

Exam trap

Google Cloud often tests the distinction between attaching a policy to a resource versus assigning a role to an identity, where candidates mistakenly think that attaching a policy to a user or service account is valid, when in fact policies are always attached to resources, not to identities.

236
MCQhard

A team is running a GKE cluster with a workload that has variable CPU and memory usage. They want to automatically adjust pod resource requests and limits based on historical usage to improve resource efficiency. Which feature should they use?

A.Vertical Pod Autoscaler (VPA)
B.PodDisruptionBudget (PDB)
C.Horizontal Pod Autoscaler (HPA)
D.Cluster Autoscaler
AnswerA

Vertical Pod Autoscaler continuously analyses historical CPU and memory consumption from the metrics pipeline, then recalculates and applies pod resource requests and limits automatically. This directly satisfies the stem's requirement to right-size requests and limits from observed usage, rather than scaling replica counts horizontally or reacting only to live thresholds.

Why this answer

The Vertical Pod Autoscaler (VPA) automatically adjusts pod resource requests and limits based on historical usage, right-sizing workloads to improve resource efficiency. It observes CPU and memory consumption over time and updates the pod's resource specifications, either by restarting pods (Recreate mode) or, in newer versions, by in-place updates. This directly matches the requirement to adjust requests and limits based on historical usage.

Exam trap

PCA often tests the VPA vs. HPA distinction — candidates see 'variable CPU and memory' and pick HPA, but the key phrase is 'adjust pod resource requests and limits,' which is VPA's job, not HPA's.

How to eliminate wrong answers

Option B is wrong because PodDisruptionBudget (PDB) limits the number of pods that can be voluntarily disrupted during maintenance or scaling — it does not adjust resource requests or limits. Option C is wrong because Horizontal Pod Autoscaler (HPA) scales the number of pod replicas based on metrics like CPU utilization, not the resource requests/limits of individual pods. Option D is wrong because Cluster Autoscaler adjusts the number of nodes in the cluster based on pending pods, not pod-level resource specifications.

237
MCQmedium

A media company stores large video files that are accessed infrequently (once a quarter) and must be retained for 10 years for compliance. They want to minimize storage cost. Which Cloud Storage class should they use?

A.Standard storage class
B.Archive storage class
C.Coldline storage class
D.Nearline storage class
AnswerB

Archive storage suits data accessed roughly once a quarter and retained for a decade, since its low storage price offsets higher retrieval costs and minimum storage duration. It satisfies the stem's cost-minimisation constraint for cold, compliance-bound video files, unlike Nearline or Coldline, which cost more per gigabyte stored.

Why this answer

Archive storage is the lowest-cost class for data accessed less than once a year. It is ideal for long-term archival with 10-year retention. Standard is for frequent access, Nearline for 30 days, Coldline for 90 days.

Archive is the cheapest for infrequent access.

238
MCQmedium

A company is migrating its on-premises data warehouse to BigQuery. The security team requires that all data at rest in BigQuery is encrypted with keys that the company controls, and that key usage is logged for auditing. They also need to be able to revoke access to the data by disabling the key. Which configuration should they implement?

A.Use BigQuery default encryption and enable Cloud Audit Logs for BigQuery.
B.Use Customer-Supplied Encryption Keys (CSEK) for BigQuery, and store the keys in a secure vault.
C.Use Cloud HSM to generate keys, and configure BigQuery to use those keys for encryption.
D.Use Customer-Managed Encryption Keys (CMEK) for BigQuery, and enable Cloud KMS audit logs.
AnswerD

CMEK allows you to use your own keys in Cloud KMS to encrypt BigQuery data. Enabling Cloud KMS audit logs records all key usage, including encryption and decryption operations. Disabling the key immediately revokes access to the data. This meets all requirements: customer-controlled keys, key usage logging, and revocation capability.

Why this answer

Customer-Managed Encryption Keys (CMEK) for BigQuery allow you to use your own keys in Cloud KMS to encrypt data at rest. Enabling Cloud KMS audit logs records all key usage, satisfying the auditing requirement. Disabling the key revokes access to the data.

This configuration meets all security requirements.

Exam trap

The trap here is thinking BigQuery supports Customer-Supplied Encryption Keys (CSEK); it does not, and CMEK is the correct mechanism for customer-controlled keys.

239
MCQmedium

A media company runs a batch transcoding job on Compute Engine. The job pulls source files from a Cloud Storage bucket in the same project. Security policy forbids assigning external IP addresses to any VM. The VMs must reach the Cloud Storage API without traversing the public internet. What should the architect configure?

A.Enable Private Google Access on the subnet used by the VMs and ensure the VMs have no external IP addresses.
B.Create a Cloud NAT gateway and route all VM egress through it.
C.Assign the VMs an internal IP address and add a static route to the default internet gateway for the Cloud Storage IP ranges.
D.Configure the VMs to use the restricted.googleapis.com VIP and add a firewall rule allowing egress to 199.36.153.4/30.
AnswerA

Private Google Access lets VMs without external IP addresses reach Google APIs and services, including Cloud Storage, using the internal IP address and Google's internal routing. Enabling it on the subnet is sufficient for the transcoding VMs to read source objects without public internet exposure. This directly satisfies the policy against external IPs while keeping API traffic on Google's network.

Why this answer

Private Google Access allows instances that only have internal IP addresses to reach Google APIs and services such as Cloud Storage over Google's internal network. Enabling it on the subnet is the supported, low-overhead way to let the transcoding VMs read source objects while complying with the no-external-IP policy, without introducing NAT or custom routing.

Exam trap

The trap here is reaching for Cloud NAT as the default way to give private VMs outbound connectivity, when Private Google Access is the specific mechanism for reaching Google APIs without external IPs.

240
MCQmedium

A company needs to encrypt data at rest in Cloud Storage using their own keys. They require that the keys are stored in a hardware security module (HSM) that is FIPS 140-2 Level 3 certified. Which key management option should they choose?

A.Google-managed encryption keys
B.Customer-Supplied Encryption Keys (CSEK)
C.Customer-Managed Encryption Keys (CMEK) with Cloud HSM
D.Customer-Managed Encryption Keys (CMEK) with Cloud KMS
AnswerC

CMEK with Cloud HSM lets the customer retain control of the key while Cloud HSM stores it in a hardware security module validated to FIPS 140-2 Level 3. This satisfies the explicit HSM and certification constraint that software-backed or Google-managed keys cannot meet.

Why this answer

CMEK with Cloud HSM is correct because it lets the customer own and control the key while the key material is generated, stored, and used inside a FIPS 140-2 Level 3 validated hardware security module managed by Google Cloud. This satisfies both the 'customer-managed keys' requirement and the explicit HSM/FIPS 140-2 Level 3 mandate. Cloud KMS software keys (option D) are FIPS 140-2 Level 1/2 only, so they fail the HSM requirement.

Exam trap

PCA often tests the distinction between 'customer-managed' and 'hardware-backed' — candidates see 'CMEK' in option D and pick it, forgetting that Cloud KMS software keys do not meet FIPS 140-2 Level 3, which only Cloud HSM provides.

How to eliminate wrong answers

Option A is wrong because Google-managed encryption keys are fully controlled by Google, so the customer has no ownership or rotation control and cannot meet the 'their own keys' requirement. Option B is wrong because CSEK keys are supplied by the customer at request time and are never stored in Cloud KMS or an HSM — they are held in memory by the client, so they cannot satisfy a FIPS 140-2 Level 3 HSM storage requirement. Option D is wrong because standard Cloud KMS software-protected keys are not backed by an HSM and only meet FIPS 140-2 Level 1 (with some Level 2 aspects), not Level 3.

241
MCQmedium

A retail company uses a Cloud SQL for MySQL instance with a single zone. The database is critical for order processing, and the company wants to minimize downtime if the zone hosting the instance fails. They also want to ensure that the application can continue to write data during a zonal failure without manual intervention. What should they do?

A.Migrate the database to a Compute Engine instance with a regional persistent disk.
B.Create a read replica in another zone and promote it if the primary fails.
C.Enable high availability by configuring the instance as regional.
D.Take regular automated backups and restore to a new instance in another zone.
AnswerC

Configuring a Cloud SQL instance as regional creates a standby replica in a different zone. If the primary zone fails, Cloud SQL automatically fails over to the standby, allowing writes to continue with minimal downtime. This matches the requirement for automatic failover and continued write availability during a zonal failure.

Why this answer

Configuring Cloud SQL as regional provides a synchronous standby in another zone and automatic failover. This ensures that writes can continue with minimal downtime during a zonal failure, satisfying the business requirement. Other options either require manual intervention, result in data loss, or do not provide automatic failover.

Exam trap

The trap here is assuming that a read replica can provide high availability, but read replicas do not offer automatic failover and are intended for read scaling.

242
MCQeasy

A company wants to migrate an on-premises MySQL database to GCP with minimal downtime and support for automated failover in case of a zone outage. Which GCP service should they use?

A.Cloud SQL for PostgreSQL
B.Cloud SQL for MySQL
C.Cloud Bigtable
D.Firestore
AnswerB

Cloud SQL for MySQL is a managed service supporting cross-zone high availability with automatic failover, and its Database Migration Service enables minimal-downtime replication from on-premises MySQL. This directly satisfies the automated failover and low-downtime migration constraints.

Why this answer

Cloud SQL for MySQL is the managed relational database service on GCP that supports MySQL, offers high availability with automatic failover across zones, and enables minimal-downtime migration via Database Migration Service (DMS) or replication-based approaches. It directly matches the requirement of migrating an existing MySQL workload while preserving engine compatibility. The other options either use a different engine (PostgreSQL), a NoSQL wide-column store (Bigtable), or a document database (Firestore), none of which support MySQL workloads.

Exam trap

PCA often tests engine compatibility — candidates see 'MySQL' in the question but must not be distracted by other managed database services that sound similar or offer HA, since only Cloud SQL for MySQL preserves the MySQL engine.

How to eliminate wrong answers

Option A is wrong because Cloud SQL for PostgreSQL runs the PostgreSQL engine, not MySQL, so the existing MySQL schema, queries, and stored procedures would not be directly compatible without a costly engine conversion. Option C is wrong because Cloud Bigtable is a petabyte-scale NoSQL wide-column store designed for low-latency analytics and time-series data, not relational MySQL workloads with ACID transactions. Option D is wrong because Firestore is a serverless document NoSQL database for mobile/web apps, lacking relational schema, joins, and MySQL compatibility.

243
MCQhard

An organization wants to enforce a policy that prohibits the creation of Cloud Storage buckets with uniform bucket-level access disabled. What should they use?

A.Organization policy with a list constraint.
B.IAM roles with custom permissions to deny bucket creation.
C.Cloud Audit Logs to monitor bucket creation.
D.Cloud Armor security policies.
AnswerA

An organisation policy with a list constraint enforces exactly this prohibition: the constraint `storage.uniformBucketLevelAccess` accepts allowed values, and denying `false` blocks bucket creation where uniform bucket-level access is disabled. This satisfies the stem's requirement to prevent, rather than merely detect, non-compliant buckets across the organisation.

Why this answer

Organization policies can enforce constraints like constraints/storage.uniformBucketLevelAccess to require uniform bucket-level access. Option B (IAM roles with custom permissions) cannot deny bucket creation with specific settings. Option C (Cloud Audit Logs) is for logging, not enforcement.

Option D (Cloud Armor) is for security policies at the edge.

244
MCQeasy

Which GCP service provides distributed tracing to help analyze latency in microservices applications?

A.Cloud Profiler
B.Cloud Trace
C.Cloud Logging
D.Cloud Monitoring
AnswerB

Cloud Trace collects and correlates latency data across microservice calls, producing distributed traces that pinpoint slow spans in request paths. This directly satisfies the need to analyse latency in microservices applications, unlike logging or monitoring services that lack span-level tracing.

Why this answer

Cloud Trace is Google Cloud's distributed tracing service, designed to collect latency data across microservices and display it as traces and spans. It helps identify performance bottlenecks in distributed applications. Cloud Profiler, Logging, and Monitoring serve different observability roles and do not provide distributed tracing.

Exam trap

PCA often tests the difference between observability tools — candidates confuse Cloud Trace (distributed tracing) with Cloud Profiler (code profiling) or Cloud Monitoring (metrics) when the question specifically asks for latency analysis across microservices.

How to eliminate wrong answers

Option A is wrong because Cloud Profiler is a continuous CPU and heap profiler for application code, not a distributed tracing system. Option C is wrong because Cloud Logging aggregates and queries log entries but does not provide trace spans or latency waterfall views. Option D is wrong because Cloud Monitoring collects metrics, dashboards, and alerts, but distributed tracing is handled by Cloud Trace (though Monitoring can surface Trace-derived metrics).

245
MCQeasy

A security engineer needs to restrict access to a Google Cloud project so that only a specific set of IP addresses can reach Cloud Storage buckets. Which feature should be configured?

A.VPC Service Controls
B.IAM Conditions
C.Firewall Rules
D.Cloud Armor
AnswerA

VPC Service Controls create a service perimeter around the project, blocking access from outside approved networks regardless of IAM permissions. This satisfies the IP-based restriction requirement by enforcing perimeter ingress rules, though note that Cloud Storage access via the Google Cloud console or APIs is contained within the perimeter boundary.

Why this answer

VPC Service Controls creates a service perimeter around Google Cloud resources like Cloud Storage buckets, enforcing context-aware access based on attributes such as the source IP address of the caller. By defining an access level that includes only the specified IP ranges and binding it to the perimeter, requests from outside those IPs are denied even if the caller has valid IAM permissions. This is the only option that provides network-origin-based restriction at the project/service level for Cloud Storage.

Exam trap

The trap here is confusing network-layer controls (firewall rules, Cloud Armor) with service-level perimeter controls (VPC Service Controls) that can enforce IP-based access to managed services like Cloud Storage.

How to eliminate wrong answers

Option B is wrong because IAM Conditions can only evaluate attributes of the principal, resource, or request (e.g., time, resource name, tags) and cannot restrict based on the caller's source IP address. Option C is wrong because VPC firewall rules apply only to traffic within a VPC network and do not govern access to Google Cloud managed services like Cloud Storage, which are accessed via public APIs outside the VPC. Option D is wrong because Cloud Armor protects HTTP(S) load balancer backends against web attacks and cannot restrict access to Cloud Storage buckets.

246
Multi-Selectmedium

A company stores large amounts of data in Cloud Storage and wants to reduce costs. Which two actions should they take? (Choose two.)

Select 2 answers
A.Disable object versioning to prevent multiple versions.
B.Enable object versioning and configure lifecycle rules to delete noncurrent versions after 90 days.
C.Add bucket labels to track cost by department.
D.Configure lifecycle management to transition objects to Nearline or Coldline storage classes after 30 days.
E.Change the default storage class to Standard for all buckets.
AnswersB, D

Object versioning retains every overwrite and delete, which silently multiplies storage charges. A lifecycle rule that deletes noncurrent versions after 90 days bounds that accumulation while preserving a recovery window, directly reducing the bucket's storage cost.

Why this answer

Option B is correct because enabling object versioning while adding a lifecycle rule to delete noncurrent versions after 90 days prevents old object versions from accumulating indefinitely, which directly reduces storage costs from versioned data. Option D is correct because lifecycle management can automatically transition objects to colder storage classes such as Nearline or Coldline after 30 days, and these classes have lower storage pricing than Standard for infrequently accessed data. Option A is not appropriate because disabling object versioning removes data protection and recovery capability rather than being a cost-optimization best practice.

Option C does not reduce costs; bucket labels only improve cost tracking and reporting by department. Option E would likely increase costs because Standard is the most expensive default storage class for long-term or infrequently accessed data.

Exam trap

Google Cloud often tests the distinction between cost allocation (labels) and direct cost reduction (lifecycle rules), leading candidates to mistakenly choose labeling as a cost-saving measure.

247
Multi-Selecthard

A company wants to allow a Kubernetes pod in GKE to authenticate to Google Cloud APIs without storing service account keys in the cluster. Which three components need to be configured to enable Workload Identity? (Choose three.)

Select 3 answers
A.Google Cloud service account
B.Kubernetes service account with annotation
C.Firewall rule to allow traffic to metadata server
D.IAM policy binding granting the GCP SA roles/iam.workloadIdentityUser on the GCP SA
E.Cloud NAT for outbound access
AnswersA, B, D

The Google Cloud service account is the identity the pod impersonates to call Google Cloud APIs. It must exist and be granted the required IAM roles, forming the target of the Workload Identity mapping that removes the need for downloaded keys.

Why this answer

Workload Identity requires: (1) a Google Cloud IAM service account (GCP SA), (2) a Kubernetes service account (KSA) annotated with the GCP SA email, and (3) an IAM policy binding between the KSA and GCP SA to allow impersonation.

248
MCQeasy

A user runs the gsutil command shown in the exhibit and gets an AccessDenied error. The user is not authenticated with gcloud. What should the user do first?

A.Create a service account and download a JSON key.
B.Grant public write access to the bucket.
C.Use gcloud config set project my-project to set the project.
D.Run gcloud auth login to authenticate with their Google account.
AnswerD

gsutil relies on credentials from gcloud authentication. Since the user is not authenticated, no access token exists, so the request fails with AccessDenied. Running gcloud auth login establishes the Google account credentials gsutil then uses, resolving the authentication failure before any permission check occurs.

Why this answer

The error occurs because the user is not authenticated with gcloud. The gsutil command requires valid authentication credentials to access Google Cloud Storage resources. Running `gcloud auth login` initiates the OAuth 2.0 flow, which authenticates the user with their Google account and generates the access token that gsutil uses for API calls.

This is the prerequisite step before any gsutil operation can succeed.

Exam trap

Google Cloud often tests the distinction between authentication (who you are) and authorization (what you can do); the trap here is that candidates may confuse the AccessDenied error with a bucket permission issue and jump to granting public access or setting a project, when the root cause is simply missing authentication credentials.

How to eliminate wrong answers

Option A is wrong because creating a service account and downloading a JSON key is an alternative authentication method, but it is not the first step; the user must first authenticate with gcloud (either via user account or service account) before gsutil can use those credentials. Option B is wrong because granting public write access to the bucket would bypass authentication entirely, which is a severe security misconfiguration and not a solution for an unauthenticated user; the error is about missing credentials, not bucket permissions. Option C is wrong because `gcloud config set project my-project` only sets the default project for gcloud commands but does not authenticate the user; without authentication, gsutil still cannot access any bucket regardless of the project setting.

249
MCQhard

A financial services company is designing a multi-region application on Google Kubernetes Engine (GKE) for high availability. They need to serve user requests from the closest region and automatically failover if a region becomes unavailable. Which architecture should they use?

A.Use a global external HTTP(S) load balancer with a single backend service pointing to one regional cluster.
B.Use Cloud CDN in front of a single regional GKE cluster to cache content.
C.Use a single regional GKE cluster with auto-scaling across zones.
D.Deploy GKE clusters in multiple regions and use a multicluster ingress with an external HTTP(S) load balancer set up with the global external backend.
AnswerD

Regional GKE clusters behind a multicluster ingress and global external HTTP(S) load balancer give anycast-style entry, directing users to the nearest healthy region and rerouting automatically when a region fails, meeting both the proximity and failover constraints.

Why this answer

Deploying GKE clusters in multiple regions and using a multicluster ingress with a global external HTTP(S) load balancer enables traffic routing to the closest healthy backend cluster based on latency or geography, and automatically fails over to another region if one becomes unavailable. The global external backend configuration allows the load balancer to distribute traffic across multiple regional GKE clusters, providing both proximity-based routing and high availability.

Exam trap

The trap here is that candidates often confuse zonal high availability (auto-scaling across zones within one region) with regional high availability (multi-region failover), and overlook that a global load balancer with multiple regional backends is required for true multi-region traffic steering and failover.

How to eliminate wrong answers

Option A is wrong because a single backend service pointing to one regional cluster cannot provide multi-region failover or route users to the closest region; it only supports a single region. Option B is wrong because Cloud CDN caches content but does not provide active failover or multi-region traffic steering; it only reduces latency for cached content from a single origin. Option C is wrong because a single regional GKE cluster with auto-scaling across zones provides zonal high availability within one region but cannot serve requests from the closest region or failover to another region if the entire region becomes unavailable.

250
Multi-Selectmedium

An organization wants to protect an HTTPS load-balanced web application from common web attacks, such as SQL injection and cross-site scripting (XSS), as well as rate-limit traffic from specific IPs. Which three capabilities should they use together? (Choose three.)

Select 3 answers
A.Cloud Armor rate limiting
B.Cloud CDN
C.Cloud Armor WAF rules
D.Cloud Load Balancing logging
E.Cloud Armor IP blacklist/whitelist
AnswersA, C, E

Cloud Armor rate limiting enforces per-IP throttling at the Google Cloud edge, satisfying the requirement to restrict traffic from specific addresses. Combined with its preconfigured WAF rules for SQL injection and XSS, it addresses the attack-mitigation constraint directly, protecting the HTTPS load-balanced backend without application changes.

Why this answer

Cloud Armor WAF rules (C) are correct because Cloud Armor's preconfigured WAF rulesets, based on the ModSecurity core rule set, are specifically designed to detect and block common web attacks like SQL injection and XSS at the load balancer edge. Cloud Armor rate limiting (A) is correct because it lets you define rate-based rules that throttle or ban clients exceeding a request threshold, which directly addresses rate-limiting traffic from specific IPs. Cloud Armor IP blacklist/whitelist (E) is correct because it allows allow/deny rules scoped to specific source IP addresses or CIDR ranges, which is needed to block or permit traffic from particular IPs.

Cloud CDN (B) is not correct because it is a content caching and delivery service, not a security control for WAF or rate limiting. Cloud Load Balancing logging (D) is not correct because it only records request data for visibility and auditing; it does not block attacks or enforce rate limits.

251
MCQhard

A large enterprise is migrating their on-premises data center to Google Cloud. They have hundreds of VMs and need to minimize network latency between on-prem and cloud during migration. They have high bandwidth requirements. Which connectivity solution should they use?

A.Cloud Interconnect
B.Cloud VPN
C.Cloud NAT
D.Peering with Google
AnswerA

Cloud Interconnect provides dedicated private connectivity at 10 Gbps or 100 Gbps per attachment, bypassing the public internet. This satisfies the high-bandwidth, low-latency requirement for migrating hundreds of VMs, unlike VPN tunnels which traverse shared internet paths.

Why this answer

Cloud Interconnect provides a dedicated, high-bandwidth, low-latency connection between on-premises data centers and Google Cloud, bypassing the public internet. This is ideal for large-scale migrations with hundreds of VMs where minimizing latency and ensuring consistent throughput is critical.

Exam trap

The trap here is that candidates often confuse Cloud VPN with Cloud Interconnect, assuming VPN is sufficient for high-bandwidth, low-latency needs, but VPN's reliance on the public internet introduces jitter and bandwidth constraints that make it unsuitable for large-scale migrations.

How to eliminate wrong answers

Option B (Cloud VPN) is wrong because it uses IPSec tunnels over the public internet, which introduces variable latency, lower throughput limits, and no SLA for bandwidth, making it unsuitable for high-bandwidth, latency-sensitive migrations. Option C (Cloud NAT) is wrong because it is used to enable outbound internet access for private VMs without public IPs, not for establishing a private, low-latency connection between on-prem and cloud. Option D (Peering with Google) is wrong because it provides connectivity to Google services (e.g., YouTube, Gmail) via public peering points, not a dedicated private connection to a specific VPC network, and lacks SLA-backed bandwidth and latency guarantees required for enterprise migration.

252
MCQeasy

An organization wants to manage DNS records for a domain they own (e.g., example.com) and use Google Cloud for authoritative DNS. They also need to resolve internal hostnames for resources within their VPC. Which Cloud DNS configuration should they use?

A.Create a single public managed zone and use DNS peering for internal resolution
B.Create a single private managed zone for both external and internal DNS resolution
C.Use Google Groups DNS to manage both public and private records
D.Create a public managed zone for example.com and a private managed zone for internal VPC resources
AnswerD

A public managed zone serves authoritative answers for example.com to internet resolvers, while a private managed zone scoped to the VPC resolves internal hostnames for resources inside that network. Two zones satisfy both the public authoritative and internal resolution requirements.

Why this answer

To serve authoritative public DNS for example.com and resolve internal VPC hostnames, the correct design is a public managed zone for example.com and a separate private managed zone associated with the VPC for internal names. This separation ensures public queries resolve to public records while internal queries resolve to private records, and it avoids exposing internal names publicly.

Exam trap

PCA often tests whether candidates understand that public and private DNS zones are separate constructs — a common mistake is assuming a single private zone can serve public authoritative DNS or that DNS peering replaces public zones.

How to eliminate wrong answers

Option A is wrong because DNS peering is used to forward queries between VPCs or to on-premises, not to serve public authoritative DNS for a domain. Option B is wrong because a single private managed zone cannot serve public authoritative DNS for example.com — private zones are only visible within associated VPCs. Option C is wrong because 'Google Groups DNS' is not a Google Cloud DNS feature; Google Groups is for mailing lists and permissions, not DNS management.

253
MCQmedium

A financial services company runs a PCI-DSS regulated workload on Compute Engine. Auditors require that all administrative access to the VMs is brokered through a single, auditable control plane with short-lived credentials, and that no external IP addresses are assigned to the VMs. Which Google Cloud feature should the architect implement to meet these requirements?

A.Cloud Interconnect with a dedicated VLAN attachment and firewall rules restricting SSH to the corporate CIDR
B.Cloud VPN with Cloud NAT configured for outbound-only access to the VMs
C.Identity-Aware Proxy (IAP) TCP forwarding with OS Login and IAM-based SSH access
D.Shielded VM with vTPM and UEFI Secure Boot enabled on all instances
AnswerC

IAP TCP forwarding tunnels SSH over HTTPS through Google's edge, so VMs need no external IP. Combined with OS Login, IAM policies control SSH access per user or group, credentials are ephemeral, and every session is logged to Cloud Audit Logs, satisfying the auditable single control plane requirement.

Why this answer

Identity-Aware Proxy TCP forwarding tunnels SSH through Google's HTTPS edge after evaluating IAM policies, eliminating external IPs on the VMs. Paired with OS Login, it converts SSH access into IAM-governed, short-lived credentials and logs every session, giving auditors one brokered, centralized control plane with no public endpoints.

Exam trap

The trap here is assuming that private network connectivity alone (VPN, Interconnect, or NAT) satisfies an auditing requirement for identity-brokered, short-lived administrative access.

254
MCQmedium

An organization needs to store API keys and database passwords securely in Google Cloud. They want to automatically rotate secrets every 30 days. Which service should they use?

A.Cloud Storage with bucket-level encryption
B.Cloud Key Management Service (Cloud KMS)
C.Secret Manager
D.Cloud Runtime Configurator
AnswerC

Secret Manager stores API keys and database passwords as versioned secrets, and its rotation schedules trigger Pub/Sub notifications every 30 days so rotation can be automated. This directly satisfies the stem's requirement for secure storage plus automatic 30-day rotation, unlike Cloud KMS, which manages encryption keys rather than application credentials.

Why this answer

Secret Manager supports automatic rotation with a rotation period and can trigger a Cloud Function to generate a new secret version.

255
MCQeasy

A logistics company is planning its first Google Cloud landing zone. It has three business units that must be billed separately, a central network team that manages shared VPCs, and a security team that needs to apply guardrails across everything. Which resource hierarchy design should the architect recommend?

A.Create one project per business unit, place all projects directly under the organization node, and use labels to separate billing and security policies.
B.Create folders per business unit and per environment under the organization, place application projects inside those folders, and create a separate shared networking project owned by the central network team.
C.Create a single project for the whole company and use IAM roles and labels to separate business units, environments, and network administration.
D.Create one organization per business unit, each with its own projects, and link them with VPC peering for shared network services.
AnswerB

Folders allow policies and IAM to be inherited and scoped per business unit and environment, satisfying the security team's need for guardrails. Placing application projects inside environment folders keeps production and non-production separated. A dedicated shared networking project, owned centrally, is the standard pattern for shared VPC host projects and keeps network administration distinct from application ownership, supporting separate billing.

Why this answer

The scenario calls for delegated administration, separate billing, central networking, and organization-wide guardrails. A hierarchy of folders by business unit and environment lets policy and IAM inherit cleanly, projects give billing and isolation boundaries, and a dedicated shared networking project is the canonical host for shared VPC. Flattening everything, collapsing into one project, or splitting into multiple organizations each breaks at least one of these requirements.

Exam trap

The trap here is assuming labels can substitute for folders when scoping security policies, but labels do not participate in policy inheritance.

256
MCQhard

A security team wants to audit all IAM role assignments in an organization. They need a historical record of changes. Which tool should they use?

A.Cloud Asset Inventory
B.Access Transparency
C.Cloud Audit Logs
D.Security Command Center
AnswerC

Cloud Audit Logs records IAM policy and role binding changes as immutable, timestamped Admin Activity entries retained for the project or organisation. This provides the historical change record the audit requires, unlike current-state views such as IAM policy queries.

Why this answer

Cloud Audit Logs (specifically Admin Activity audit logs) record all API calls that modify IAM policies, including role assignments. These logs are immutable and retained for the default retention period (400 days for Admin Activity logs), providing a historical record of changes. Cloud Asset Inventory (A) shows the current state but not historical changes, Access Transparency (B) logs Google staff access to your data, and Security Command Center (D) provides security findings and posture, not a change history.

Exam trap

Google Cloud often tests the distinction between tools that show current state (Cloud Asset Inventory) versus tools that record historical changes (Cloud Audit Logs), leading candidates to pick Cloud Asset Inventory because it 'audits' resources, but it does not provide a change history.

How to eliminate wrong answers

Option A is wrong because Cloud Asset Inventory provides a snapshot of current IAM role assignments and other resources, but it does not maintain a historical record of changes; it lacks the audit trail capability. Option B is wrong because Access Transparency logs actions performed by Google personnel when accessing your data, not IAM role assignment changes made by your own users or services. Option D is wrong because Security Command Center is a security and risk management platform that aggregates findings and vulnerabilities, but it does not natively record a chronological history of IAM policy modifications.

257
MCQhard

An organization needs to encrypt data at rest in BigQuery using keys that are rotated every 90 days. They want to manage the keys themselves but cannot store keys on-premises. Which encryption approach should they use?

A.Default Google-managed encryption
B.Customer-Managed Encryption Keys (CMEK) with Cloud KMS
C.Cloud HSM
D.Customer-Supplied Encryption Keys (CSEK)
AnswerB

CMEK with Cloud KMS lets the organisation generate, rotate and manage its own key material inside Google Cloud, satisfying the 90-day rotation requirement without on-premises key storage. BigQuery decrypts data using these keys, so control stays with the customer while keys never leave Cloud KMS.

Why this answer

CMEK with Cloud KMS lets the organization own and control the key material while Google Cloud stores and manages the keys in KMS, satisfying the requirement to manage keys themselves without on-premises storage. Cloud KMS supports automatic rotation schedules (e.g., every 90 days) and integrates natively with BigQuery so that data at rest is encrypted with the customer's key. This gives the customer control over key lifecycle, access, and revocation while meeting the no-on-premises constraint.

Exam trap

PCA often tests the distinction between CMEK (customer controls key lifecycle in Cloud KMS) and CSEK (customer supplies and stores raw keys), so candidates who see 'manage keys themselves' and jump to CSEK miss the 'cannot store keys on-premises' constraint.

How to eliminate wrong answers

Option A is wrong because default Google-managed encryption does not give the customer control over keys or the ability to rotate them on a customer-defined 90-day schedule. Option C is wrong because Cloud HSM is a hardware security module offering within Cloud KMS for FIPS 140-2 Level 3 key protection, not a separate encryption approach for BigQuery data at rest; it can be used with CMEK but is not the answer by itself. Option D is wrong because Customer-Supplied Encryption Keys (CSEK) require the customer to supply and store the raw key material themselves (typically on-premises or in their own vault), which directly violates the constraint that keys cannot be stored on-premises.

258
MCQmedium

A company wants to allow a Kubernetes pod in GKE to access a Cloud Storage bucket using a specific service account without storing long-lived credentials. Which method should be used?

A.Assign the service account directly to the GKE node pool
B.Create a JSON key for a service account and mount it as a secret in the pod
C.Use Workload Identity to bind the Kubernetes service account to a Google Cloud service account
D.Use Application Default Credentials on the pod
AnswerC

Workload Identity federates a Kubernetes service account with a Google Cloud service account via the cluster's workload identity pool, issuing short-lived tokens. The pod therefore accesses Cloud Storage without any long-lived service account key stored in the cluster.

Why this answer

Workload Identity is the recommended way to allow a Kubernetes pod in GKE to access Google Cloud services like Cloud Storage using a specific service account without long-lived credentials. It binds a Kubernetes service account to a Google Cloud service account, and the pod uses the Kubernetes service account to obtain short-lived credentials via the GKE metadata server. This eliminates the need for JSON keys.

Exam trap

PCA often tests the misconception that mounting service account keys is acceptable, but the exam emphasizes keyless authentication via Workload Identity.

How to eliminate wrong answers

Option A is wrong because assigning the service account to the node pool grants all pods on that node the same permissions, violating least privilege and not allowing per-pod service accounts. Option B is wrong because creating and mounting JSON keys introduces long-lived credentials that must be managed and rotated, which is insecure. Option D is wrong because Application Default Credentials on the pod would still require a service account key or the node's service account, not a specific service account without long-lived credentials.

259
MCQmedium

Your team manages a production web application on Compute Engine behind an external Application Load Balancer. During a recent incident, the load balancer's backend service marked all instances as unhealthy because the health check endpoint returned HTTP 200 but the application was actually in a degraded state. You need Cloud Monitoring to alert the operations team when the application's error rate exceeds 5% over a 5-minute window. You also need to ensure that the alert does not fire during planned maintenance windows. Which approach should you take?

A.Use Cloud Trace to sample requests and create an alerting policy based on the latency of traces that return errors, triggering when error traces exceed 5% of total traces.
B.Create an uptime check that sends HTTP requests to the application's health endpoint every minute and alerts when the check fails from more than one region.
C.Configure a custom health check on the load balancer that returns HTTP 500 when the application is degraded, and create an alerting policy on the backend service's unhealthy instance count.
D.Create a log-based metric that counts HTTP 5xx responses from the load balancer logs, then create an alerting policy on that metric with a threshold of 5% error rate and configure a maintenance window for planned downtime.
AnswerD

Log-based metrics derive values from log entries, and the load balancer logs include status details for each request. By counting 5xx responses and dividing by total requests, you can compute an error rate. Alerting policies can use such metrics with threshold conditions, and maintenance windows suppress alerts during planned downtime. This directly addresses the requirement to monitor application-level errors rather than infrastructure health, and respects maintenance periods.

Why this answer

The requirement is to alert on application error rate exceeding 5% over 5 minutes, with suppression during maintenance. A log-based metric from load balancer logs captures every request's status, enabling an accurate error rate calculation. Alerting policies on such metrics support threshold conditions and maintenance windows.

The other options either alter health checks in a harmful way, rely on uptime checks that miss application-level errors, or use sampled trace data that is not representative.

Exam trap

The trap here is assuming that a health check endpoint returning HTTP 200 means the application is healthy and that uptime checks or health check status can measure error rate.

260
MCQmedium

A company is migrating an on-premises Oracle database to Google Cloud. They want to minimize application changes and need a fully managed, PostgreSQL-compatible database with high performance for OLTP workloads. Which service is MOST suitable?

A.Bigtable
B.AlloyDB
C.Cloud SQL for PostgreSQL
D.Cloud Spanner
AnswerB

AlloyDB provides a fully managed, PostgreSQL-compatible engine with a columnar acceleration layer, delivering the high OLTP throughput the stem demands. Its compatibility allows the Oracle application to migrate with minimal code changes, satisfying both the performance and low-modification constraints simultaneously.

Why this answer

AlloyDB for PostgreSQL is Google Cloud's fully managed, PostgreSQL-compatible database engine purpose-built for high-performance OLTP, offering up to 4x faster transactional throughput than standard PostgreSQL and a columnar engine for analytics. Because it is wire-compatible with PostgreSQL, applications using standard drivers and SQL need minimal changes, satisfying the migration goal. Its managed nature offloads backups, replication, and patching, which fits the 'fully managed' requirement.

Exam trap

PCA often tests the distinction between Cloud SQL (general-purpose, smaller workloads) and AlloyDB (high-performance OLTP), tricking candidates into choosing Cloud SQL simply because it is also PostgreSQL-compatible and fully managed.

How to eliminate wrong answers

Option A is wrong because Bigtable is a wide-column NoSQL store for massive analytical and time-series workloads, not a relational PostgreSQL-compatible OLTP database, so it would require a full application rewrite. Option C is wrong because Cloud SQL for PostgreSQL, while managed and PostgreSQL-compatible, is positioned for smaller, general-purpose workloads and does not deliver the high-performance OLTP throughput AlloyDB provides. Option D is wrong because Cloud Spanner, though horizontally scalable and strongly consistent, uses GoogleSQL/PostgreSQL dialect variants and a different architecture, requiring schema and application changes that violate the 'minimize application changes' constraint.

261
MCQhard

Your company runs a production application on Compute Engine instances behind a managed instance group (MIG). You need to perform a rolling update with canary testing, gradually shifting traffic to the new version only if performance metrics are healthy. Which approach should you use?

A.Use Cloud Deploy with a deployment strategy that includes a canary phase and automated verification
B.Create a new MIG with the new template and use a Cloud Load Balancer's traffic splitting
C.Manually update each instance by SSH'ing and running a script
D.Use gcloud compute instance-groups managed rolling-action start-update with a maxSurge of 0
AnswerA

Cloud Deploy orchestrates the progressive rollout across the MIG, defining a canary phase that shifts a percentage of traffic, then runs automated verification against your defined metrics before promoting or rolling back. This satisfies the requirement to advance only when performance stays healthy.

Why this answer

Cloud Deploy is Google Cloud's managed continuous delivery service that natively supports progressive rollout strategies including canary deployments with automated verification against SLOs or custom metrics. It integrates with Cloud Monitoring to pause or roll back a rollout if health checks fail, which directly satisfies the requirement of gradually shifting traffic only when performance metrics are healthy. This is the intended Google-recommended pattern for canary releases on GCE MIGs.

Exam trap

The trap here is assuming that a MIG rolling update alone provides canary behavior; in reality, rolling updates replace instances without traffic-based verification, so candidates who pick the gcloud rolling-action option miss the automated canary requirement.

How to eliminate wrong answers

Option B is wrong because a second MIG plus load balancer traffic splitting requires manual orchestration of the split percentages and does not provide automated verification or rollback based on metrics. Option C is wrong because SSH-based manual updates are not rolling, not canary, and provide no automated health gating. Option D is wrong because 'rolling-action start-update' performs an in-place rolling replacement of instances but does not perform canary traffic shifting or metric-based verification — maxSurge of 0 also forces downtime-style replacement.

262
MCQmedium

A company wants to run batch processing workloads that can be interrupted and resumed, at the lowest possible cost. The jobs are fault-tolerant and can handle preemption. They also need predictable pricing for a baseline amount of compute. Which combination of compute options should they use?

A.Use spot VMs for all workloads and rely on automatic restart
B.Use standard VMs with sustained use discounts
C.Use only preemptible VMs for all workloads
D.Use committed use discounts for baseline capacity and preemptible VMs for additional burst capacity
AnswerD

Committed use discounts lock in predictable pricing for the steady baseline compute, while preemptible VMs supply cheap burst capacity. Since the jobs are fault-tolerant and resumable, preemption causes no data loss, meeting the lowest-cost requirement.

Why this answer

Committed use discounts (CUDs) provide predictable, discounted pricing for a baseline amount of compute that the company commits to using over a one- or three-year term. Preemptible (spot) VMs are significantly cheaper for the burst capacity that can tolerate interruption. Combining the two gives the lowest overall cost while maintaining predictable pricing for the baseline and flexibility for the fault-tolerant batch workloads.

Exam trap

PCA often tests the confusion between sustained use discounts (automatic, no commitment) and committed use discounts (contractual, deeper discount), and candidates may incorrectly choose sustained use discounts when the scenario explicitly asks for predictable pricing for a baseline.

How to eliminate wrong answers

Option A is wrong because relying solely on spot VMs for all workloads, even with automatic restart, does not provide predictable pricing for a baseline and exposes the entire workload to preemption risk. Option B is wrong because standard VMs with sustained use discounts are more expensive than committed use discounts and do not leverage the fault-tolerant nature of the batch jobs to reduce cost. Option C is wrong because using only preemptible VMs for all workloads sacrifices the predictable baseline pricing the company requires and increases the risk of job interruptions without a committed discount.

263
Multi-Selecthard

Which THREE steps can reduce processing costs in a Dataflow streaming pipeline? (Choose three.)

Select 3 answers
A.Use side inputs instead of a cross join.
B.Use a batch pipeline for non-critical data.
C.Minimize the use of GroupByKey in streaming mode.
D.Use a custom runner.
E.Increase the number of workers.
AnswersA, B, C

Side inputs broadcast a small lookup dataset to each worker, letting the pipeline enrich events locally instead of performing a cross join. A cross join forces every element to pair with every other, exploding shuffle volume; replacing it with side inputs removes that multiplication, cutting processing cost.

Why this answer

Option A is correct because replacing a cross join with side inputs avoids the expensive fan-out of every element being paired with every element of the other collection, which drastically reduces the number of elements processed and shuffled in the streaming pipeline. Option B is correct because running non-critical data through a batch pipeline lets Dataflow use cheaper batch pricing and more efficient batch-optimized execution rather than paying for continuously running streaming workers. Option C is correct because GroupByKey in streaming mode forces a shuffle and holds state for each key until the window fires, so minimizing it (for example by using Combine or pre-aggregation) lowers shuffle volume, state storage, and processing cost.

Option D is not correct because a custom runner does not reduce Dataflow processing costs and is not a cost-optimization step. Option E is not correct because increasing the number of workers raises the amount of compute used and therefore increases, rather than reduces, processing costs.

Exam trap

Google Cloud often tests the misconception that scaling out (increasing workers) always reduces costs, when in fact it increases costs unless the pipeline is bottlenecked; the trap is to confuse throughput optimization with cost reduction.

264
MCQeasy

A company wants to connect their on-premises network to Google Cloud with a dedicated, high-bandwidth, low-latency connection that supports Service Level Agreements (SLAs) up to 99.99% availability. Which connectivity option should they choose?

A.Classic VPN
B.Partner Interconnect
C.Dedicated Interconnect
D.Cloud VPN (IPsec VPN)
AnswerC

Dedicated Interconnect provides a private physical link between on-premises and Google Cloud, delivering high bandwidth, low latency and an SLA of up to 99.99%. This satisfies the dedicated, SLA-backed requirement, unlike Partner Interconnect or VPN options.

Why this answer

Dedicated Interconnect provides a direct, private physical connection between your on-premises network and Google Cloud, offering high bandwidth (up to 100 Gbps per link), low latency, and support for SLAs up to 99.99% availability. This option meets the requirement for a dedicated, high-bandwidth, low-latency connection with the highest SLA, unlike VPN-based or partner-mediated solutions.

Exam trap

The trap here is that candidates often confuse Partner Interconnect with Dedicated Interconnect, overlooking that Partner Interconnect does not offer a direct physical connection and has a lower SLA (99.9% vs. 99.99%), which fails the requirement for a dedicated, high-bandwidth, low-latency link with the highest availability guarantee.

How to eliminate wrong answers

Option A is wrong because Classic VPN uses IPsec tunnels over the public internet, which cannot guarantee dedicated bandwidth, low latency, or SLAs up to 99.99% availability. Option B is wrong because Partner Interconnect relies on a third-party service provider's network and does not provide a direct physical connection, typically offering SLAs up to 99.9% rather than 99.99%. Option D is wrong because Cloud VPN (IPsec VPN) also uses the public internet and cannot provide dedicated bandwidth, low latency, or the high SLA required.

265
MCQhard

A company has Compute Engine instances that need to access the internet for updates but should not be reachable from the internet. They also need to access Google APIs and services like Cloud Storage. Which configuration meets these requirements?

A.Use Cloud NAT for outbound internet and enable Private Google Access on the subnet.
B.Assign external IPs to all instances and configure firewall rules to block inbound traffic.
C.Configure a VPN tunnel to an on-premises proxy server for internet access.
D.Use Cloud NAT for outbound internet and use external IPs for Google API access.
AnswerA

Cloud NAT provides outbound internet access for instances lacking external IP addresses, while Private Google Access lets those instances reach Google APIs and Cloud Storage internally. Together they satisfy both requirements without exposing instances to inbound internet traffic.

Why this answer

Cloud NAT provides outbound internet connectivity for instances without external IPs, while Private Google Access allows those same instances to reach Google APIs and services (like Cloud Storage) using internal IPs via the subnet's default route. This combination ensures instances can initiate outbound connections to the internet and Google services but remain unreachable from the internet, meeting both security and functional requirements.

Exam trap

The trap here is that candidates often think Cloud NAT alone is sufficient for Google API access, but they miss that Private Google Access must be explicitly enabled on the subnet for instances without external IPs to reach Google APIs and services.

How to eliminate wrong answers

Option B is wrong because assigning external IPs makes instances directly reachable from the internet, even with firewall rules blocking inbound traffic; the external IP itself exposes the instance to potential attacks (e.g., DDoS) and violates the requirement that instances should not be reachable from the internet. Option C is wrong because a VPN tunnel to an on-premises proxy server adds unnecessary complexity, latency, and dependency on on-premises infrastructure; it does not directly address the need for Google API access, which is better served by Private Google Access. Option D is wrong because using external IPs for Google API access defeats the purpose of Cloud NAT; instances with external IPs are still reachable from the internet (even if only for API calls), and the requirement explicitly states instances should not be reachable from the internet.

266
MCQmedium

A Cloud Run service frequently fails with 502 errors when making requests to a backend service running on Compute Engine. The two services are in the same VPC network. The Cloud Run service is configured with a VPC connector. What is the most likely cause?

A.The Cloud Run service needs to be peered with the VPC using VPC Network Peering.
B.The VPC connector is set to a low number of instances, causing traffic throttling.
C.The VPC connector is not attached to the correct subnet, or the firewall rules are blocking traffic from the connector's IP range.
D.The Cloud Run service's service account lacks the roles/compute.instanceAdmin role.
AnswerC

Serverless VPC access routes Cloud Run egress through the connector's own subnet and IP range, not the service's. If the connector sits in the wrong subnet or firewall rules omit its range, Compute Engine silently drops packets, surfacing as 502 responses.

Why this answer

Cloud Run uses a VPC connector to send requests to resources in a VPC. If the connector is attached to the wrong subnet, its egress traffic may not reach the Compute Engine instance, or firewall rules may block traffic from the connector's IP range (e.g., 10.8.0.0/28). This results in 502 errors from the backend, as the Cloud Run service cannot establish a TCP connection to the Compute Engine instance.

Exam trap

The trap here is that candidates confuse VPC Network Peering (used for inter-VPC connectivity) with the VPC connector (used for serverless-to-VPC access), and they overlook the firewall rules that must explicitly allow traffic from the connector's IP range.

How to eliminate wrong answers

Option A is wrong because VPC Network Peering is used to connect two separate VPC networks, not to connect a serverless service to its own VPC; Cloud Run uses a VPC connector, not peering. Option B is wrong because a low number of VPC connector instances causes throttling or increased latency, not 502 errors; 502 errors indicate a failure to reach or get a valid response from the backend, not a capacity issue. Option D is wrong because the roles/compute.instanceAdmin role grants permissions to manage Compute Engine instances, but Cloud Run does not need that role to make HTTP requests to a backend; it only needs network connectivity via the VPC connector.

267
MCQmedium

A company operates a critical application on Google Cloud and wants to define a Service Level Objective (SLO) for its latency. They need to measure the proportion of requests that complete within 200 ms over a 28-day rolling window. They also want to alert when the error budget is being consumed too quickly. What should they use?

A.Cloud Trace with analysis reports and custom alerts.
B.Cloud Monitoring SLOs with error budget burn rate alerts.
C.Cloud Logging with log-based metrics and custom dashboards.
D.Cloud Monitoring with uptime checks and alerting policies based on latency thresholds.
AnswerB

Cloud Monitoring allows you to define SLOs based on latency distributions, set a performance goal (e.g., 99% of requests under 200 ms), and create alerting policies based on error budget burn rates. This directly meets the requirement to measure the proportion and alert on rapid consumption.

Why this answer

Cloud Monitoring SLOs allow you to define service level objectives based on metrics like latency, set a goal, and monitor error budgets. Burn rate alerts notify when the error budget is consumed faster than desired, enabling proactive response.

Exam trap

The trap here is thinking that uptime checks or log-based metrics can serve as SLOs, but they lack the integrated error budget and burn rate alerting that Cloud Monitoring SLOs provide.

268
MCQhard

A company uses Shared VPC. A project admin in a service project tries to create a subnet in the shared VPC network but receives a permission denied error. What is the most likely cause?

A.Only the Shared VPC host project admin can create subnets.
B.The service project admin lacks the compute.subnetworks.create permission on the host project.
C.The Shared VPC is not enabled for the service project.
D.Subnets must be created in the service project, not the host project.
AnswerB

In Shared VPC, subnet creation rights reside with the host project, not the service project. The service project admin needs the compute.subnetworks.create permission granted on the host project, which explains the permission denied error when attempting to create the subnet.

Why this answer

In a Shared VPC architecture, subnet creation is a privileged operation that can only be performed by a user with the compute.subnetworks.create permission on the host project. The service project admin, by default, does not have this permission in the host project, which is why the permission denied error occurs. Granting this permission to the service project admin at the host project level would resolve the issue.

Exam trap

Google Cloud often tests the misconception that service project admins have full control over the shared network, when in reality they only have usage permissions unless explicitly granted administrative permissions on the host project.

How to eliminate wrong answers

Option A is wrong because it is not strictly 'only the host project admin' who can create subnets; any user with the compute.subnetworks.create permission on the host project can do so, including a service project admin if that permission is explicitly granted. Option C is wrong because the Shared VPC being enabled for the service project is a prerequisite for using the shared network, but the error here is about permissions, not about the feature being disabled. Option D is wrong because subnets in a Shared VPC must be created in the host project, not the service project; the service project consumes subnets from the host project.

269
MCQmedium

A team runs periodic BigQuery queries on a large dataset. They notice high costs due to full table scans. They want to reduce costs and improve query performance. Which two actions should they take? (Choose two options that best fit the scenario.)

A.Use SELECT * only when necessary
B.Partition the table by a date/timestamp column
C.Use materialized views to pre-aggregate data
D.Cluster the table on frequently filtered columns
AnswerB, D

Partitioning splits the table by date or timestamp, so a query with a date filter prunes irrelevant partitions and scans only the matching ones. This reduces bytes processed, lowering cost and improving performance versus full table scans.

Why this answer

The correct actions are B (partition the table by a date/timestamp column) and D (cluster the table on frequently filtered columns). Partitioning restricts scans to only the relevant date partitions, and clustering physically sorts data by the filtered columns so BigQuery prunes blocks it doesn't need, both directly cutting bytes scanned and cost. Option A (avoiding SELECT *) is a general best practice but doesn't address full table scans on a large dataset, and option C (materialized views) helps only for recurring aggregate patterns, not the broad scan-cost problem described.

270
MCQhard

Your organization is deploying a global e-commerce platform on Google Cloud. The platform uses a microservices architecture running on GKE, and you need to route external HTTP(S) traffic to different services based on URL paths and also provide global load balancing with low latency. You also want to offload SSL/TLS termination and protect against DDoS attacks. Which Google Cloud service should you use?

A.Internal HTTP(S) Load Balancer with a URL map and Google-managed SSL certificates, integrated with Cloud Armor.
B.TCP Proxy Load Balancer with a backend service and Google-managed SSL certificates, integrated with Cloud Armor.
C.Global external HTTP(S) Load Balancer with a URL map and Google-managed SSL certificates, integrated with Cloud Armor.
D.Regional external HTTP(S) Load Balancer with a URL map and self-managed SSL certificates, integrated with Cloud CDN.
AnswerC

The global external HTTP(S) Load Balancer provides global anycast IP, low-latency routing, and URL path-based routing via URL maps. It supports Google-managed SSL certificates for TLS termination and integrates with Cloud Armor for DDoS protection and WAF rules. This meets all requirements: global load balancing, path-based routing, SSL offload, and DDoS mitigation.

Why this answer

The global external HTTP(S) Load Balancer is the only option that provides global anycast load balancing, URL path-based routing, Google-managed SSL certificates for TLS termination, and integration with Cloud Armor for DDoS protection. It is designed for external HTTP(S) traffic and meets all the stated requirements for a global e-commerce platform.

Exam trap

The trap here is assuming that a regional load balancer or a TCP proxy can provide global HTTP(S) routing with path-based rules, when only the global external HTTP(S) Load Balancer offers all these features together.

271
Multi-Selecthard

A company is designing a highly available architecture for a web application using Google Cloud. They need to ensure that the application remains available even if an entire Google Cloud region experiences an outage. Which THREE components should they include in their architecture? (Choose THREE.)

Select 3 answers
A.Cloud Spanner multi-region configuration
B.Cloud SQL with a cross-region read replica
C.Global external HTTP(S) load balancer
D.Cloud CDN
E.Regional managed instance groups in multiple regions
AnswersA, C, E

Cloud Spanner multi-region configuration synchronously replicates data across regions with strong consistency, so the database survives a full regional outage. This satisfies the stem's requirement that the application remain available despite an entire Google Cloud region failing.

Why this answer

Option A (Cloud Spanner multi-region configuration) is correct because a multi-region instance replicates data synchronously across regions with 99.999% availability, so the database survives a full regional outage without data loss. Option C (Global external HTTP(S) load balancer) is correct because it is a global anycast service that routes users to the nearest healthy backend and automatically fails over to backends in other regions when one region becomes unavailable. Option E (Regional managed instance groups in multiple regions) is correct because deploying regional MIGs in at least two regions provides compute capacity that keeps serving traffic when one region fails, and it pairs with the global load balancer for automatic failover.

Option B is not sufficient because Cloud SQL cross-region read replicas are asynchronous and require manual or scripted promotion, so they do not provide automatic, zero-data-loss regional failover. Option D is not correct because Cloud CDN only caches content at edge locations; it improves latency and offloads origin traffic but does not by itself provide regional failover for dynamic application workloads.

272
MCQhard

A healthcare company runs a three-tier application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier. All tiers are in the same VPC in project prod-apps. The security team requires that rules be evaluated by source identity rather than IP ranges, and that no instance can reach the database unless explicitly allowed. Which configuration should the architect use?

A.Use VPC firewall rules with target tags and source tags, assigning matching tags to instances in each tier.
B.Deploy all tiers into a single managed instance group and use instance group membership as the source selector in firewall rules.
C.Create ingress firewall rules using source IP ranges for each tier, and apply them with network tags on the instances.
D.Assign each tier a unique service account and create ingress firewall rules that specify those service accounts as sources, along with the appropriate target service accounts.
AnswerD

Firewall rules on VPC networks can use service accounts as both source and target, which authorizes traffic based on the identity attached to the instance rather than its IP. Unique service accounts per tier plus service-account-based rules enforce least privilege and satisfy the identity-based evaluation requirement without depending on address ranges.

Why this answer

VPC firewall rules support service accounts as source and target selectors, so attaching a distinct service account to each tier and referencing those accounts in ingress rules authorizes traffic by workload identity. This enforces that only the application tier can reach the database and only the web tier can reach the application tier, without relying on IP ranges or tags.

Exam trap

The trap here is treating network tags and service accounts as interchangeable firewall selectors, when only service accounts provide identity-based authorization for the source.

273
Matchingmedium

Match each GCP monitoring/logging tool to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Metrics, dashboards, alerts

Centralized log storage and analysis

Distributed tracing for latency analysis

Inspect code behavior in production

CPU and memory profiling

Why these pairings

Correct matches: Cloud Monitoring monitors performance, Cloud Logging manages logs, Error Reporting tracks errors. Confusion often arises between logging and monitoring roles.

274
MCQmedium

A company runs a critical application on Compute Engine instances. They want to automatically patch the operating system on a weekly schedule to meet compliance requirements. Which Google Cloud service should they use?

A.Cloud Monitoring
B.Cloud Security Command Center
C.Cloud Build
D.OS Config
AnswerD

OS Config's patch management applies OS updates to Compute Engine instances on a schedule you define, satisfying the weekly compliance requirement without manual intervention. It targets the guest OS directly, unlike image-level tooling, and reports patch compliance per instance, which is exactly what the stem demands.

Why this answer

OS Config, part of VM Manager, provides patch management capabilities including scheduled patching and compliance reporting.

275
MCQhard

A financial services company runs a critical application on a managed instance group (MIG) of Compute Engine instances. The application must be highly available and able to survive a zone failure without manual intervention. The company wants to ensure that the MIG automatically recovers from zone failures and maintains capacity. They also want to minimize latency for users across the United States. Which configuration should they use?

A.Regional MIG with autoscaling enabled and a load balancer with a single backend service
B.Regional MIG with autoscaling enabled and a global external HTTP(S) load balancer
C.Regional MIG with autoscaling enabled and an internal TCP/UDP load balancer
D.Zonal MIG with autoscaling enabled and a global external HTTP(S) load balancer
AnswerB

A regional MIG spreads instances across multiple zones in a region, so if one zone fails, instances in other zones continue to serve traffic. Autoscaling ensures capacity is maintained. A global external HTTP(S) load balancer provides a single anycast IP and routes users to the closest healthy backend, minimizing latency across the US. This combination meets high availability and low latency requirements.

Why this answer

A regional managed instance group distributes instances across multiple zones, ensuring that a zone failure does not take down the application. Autoscaling maintains capacity. A global external HTTP(S) load balancer uses a single anycast IP and routes traffic to the nearest healthy backend, reducing latency for users across the United States.

This combination provides both high availability and low latency.

Exam trap

The trap here is confusing internal and external load balancers, or assuming that a zonal MIG with a global load balancer can survive a zone failure.

276
MCQhard

A healthcare company runs a patient portal on Cloud Run services in the us-central1 region. The compliance team requires that the portal remain readable during a regional outage and that failover to a secondary region occur without changing the public hostname. The portal's data is stored in Cloud SQL for PostgreSQL. Which design should the architect recommend?

A.Deploy the Cloud Run services in both regions and use Cloud DNS geolocation routing with a 300-second TTL to direct users to the healthy region.
B.Deploy the Cloud Run services in us-central1 only and front them with a regional external Application Load Balancer and a Cloud DNS failover routing policy pointing to a static IP.
C.Deploy the Cloud Run services in both regions behind a global external Application Load Balancer, and rely on Cloud SQL's automatic regional failover of the primary instance.
D.Deploy the Cloud Run services in us-central1 and us-east1 behind a global external Application Load Balancer with a serverless network endpoint group per region, and use a Cloud SQL cross-region replica promoted on failover.
AnswerD

A global external Application Load Balancer provides a single anycast hostname and can route to serverless network endpoint groups in multiple regions, so failover happens without DNS changes. A Cloud SQL cross-region replica keeps a warm copy of the data that can be promoted if the primary region fails, satisfying the readability requirement during a regional outage.

Why this answer

A global external Application Load Balancer with serverless network endpoint groups in two regions gives a stable anycast hostname that keeps working when one region fails, and Cloud Run's multi-region deployment provides compute in both places. For the data tier, a Cloud SQL cross-region replica must be promoted during regional failover, since Cloud SQL does not automatically fail over across regions.

Exam trap

The trap here is assuming Cloud SQL performs automatic cross-region failover like its within-region high availability mode, when cross-region recovery requires promoting a replica.

277
Multi-Selectmedium

A company wants to deploy a web application behind an HTTPS Load Balancer and only allow authenticated users from their corporate Active Directory. Which two services should they use together? (Choose two.)

Select 2 answers
A.Identity-Aware Proxy (IAP)
B.VPC Service Controls
C.Cloud NAT
D.Cloud Identity
E.Cloud Armor
AnswersA, D

Identity-Aware Proxy enforces authentication and authorisation at the load balancer layer, verifying user identity before granting access to the backend application. It integrates with external identity providers, satisfying the requirement to restrict access to authenticated corporate Active Directory users.

Why this answer

Identity-Aware Proxy (IAP) [CORRECT] is the right choice because it enforces authentication and authorization at the application layer for HTTPS Load Balancer backends, verifying user identity before any request reaches the web application. Cloud Identity [CORRECT] is also correct because it can federate with the corporate Active Directory (via SAML or secure LDAP), providing the identity source that IAP uses to authenticate and authorize corporate users. Together, IAP and Cloud Identity let the company restrict access to authenticated AD users without exposing the app publicly.

VPC Service Controls is incorrect because it guards GCP API/service perimeters rather than end-user web application authentication. Cloud NAT is incorrect because it provides outbound internet access for private instances, not user authentication. Cloud Armor is incorrect because it provides WAF/DDoS protection and IP-based rules, not identity-based authentication against Active Directory.

Exam trap

PCA often tests the combination of IAP and Cloud Identity for AD-integrated access — candidates may pick Cloud Armor thinking it handles authentication, but Cloud Armor is a WAF, not an identity provider.

278
MCQmedium

A company is migrating its on-premises data center to Google Cloud. They need a dedicated, low-latency, high-bandwidth connection between their on-premises network and VPC. They anticipate consistent traffic above 10 Gbps. Which connectivity option should they choose?

A.Partner Interconnect
B.Dedicated Interconnect
C.HA VPN
D.Classic VPN
AnswerB

Dedicated Interconnect provides a private physical circuit between the on-premises network and Google's VPC, delivering consistent high bandwidth beyond 10 Gbps with low latency. Partner Interconnect and VPN options cannot guarantee the sustained throughput the stem requires.

Why this answer

Dedicated Interconnect provides a direct physical connection with bandwidth up to 100 Gbps per circuit, ideal for high-throughput, low-latency requirements. Partner Interconnect relies on a service provider and typically offers lower bandwidth. HA VPN is over the public internet and may not meet high bandwidth or low latency.

Classic VPN is a single tunnel without high availability.

279
MCQeasy

A retail company is planning to migrate its on-premises data warehouse to Google Cloud. They want a fully managed, petabyte-scale, and highly scalable analytics data warehouse that supports ANSI SQL and integrates with their existing BI tools. Which Google Cloud service should they choose?

A.Cloud Spanner
B.BigQuery
C.Cloud SQL
D.Cloud Bigtable
AnswerB

BigQuery is a fully managed, petabyte-scale analytics data warehouse that supports ANSI SQL and integrates with many BI tools. It is designed for high-performance analytics and can scale seamlessly. It is serverless and allows you to run fast SQL queries on large datasets. This makes it the ideal choice for migrating an on-premises data warehouse and supporting BI workloads.

Why this answer

BigQuery is Google Cloud's fully managed, petabyte-scale analytics data warehouse that supports ANSI SQL and integrates with BI tools. It is serverless, highly scalable, and designed for analytical workloads. Cloud SQL is for transactional databases, Cloud Spanner is for global transactional consistency, and Cloud Bigtable is a NoSQL database for high-throughput applications, none of which are optimized for petabyte-scale SQL analytics.

Exam trap

The trap here is assuming that any managed database service can serve as a data warehouse, but only BigQuery is purpose-built for petabyte-scale analytics with ANSI SQL support.

280
MCQmedium

A data analytics company runs nightly batch jobs using Compute Engine instances. The jobs can tolerate interruptions, and the company wants to minimize costs. What should they do?

A.Use preemptible VMs for the batch jobs.
B.Use C2 high-CPU machine types for faster processing.
C.Use standard (on-demand) VMs and commit to a 1-year resource-based commitment.
D.Deploy VMs on Sole-tenant nodes for cost isolation.
AnswerA

Preemptible VMs cost substantially less than standard instances but can be reclaimed at any time, with a 24-hour maximum runtime. The batch jobs tolerate interruptions, so this constraint is satisfied. Combining them with a managed instance group and restart logic keeps the nightly workload completing despite preemption.

Why this answer

Preemptible VMs (now called Spot VMs) are Compute Engine instances that last up to 24 hours and can be terminated at any time by Google Cloud. Because the batch jobs are interruptible, using preemptible VMs reduces compute costs by up to 60-91% compared to standard on-demand VMs, directly meeting the goal of minimizing costs.

Exam trap

The trap here is that candidates may confuse preemptible VMs with standard VMs and assume they are unreliable for any workload, but the question explicitly states the jobs can tolerate interruptions, making preemptible VMs the correct cost-saving choice.

How to eliminate wrong answers

Option B is wrong because C2 high-CPU machine types are optimized for compute-intensive workloads, not for cost minimization; they are more expensive per hour than standard machine types and do not address the interruptible nature of the jobs. Option C is wrong because committing to a 1-year resource-based commitment locks the company into a fixed cost for on-demand VMs, which is more expensive than preemptible VMs and unnecessary for interruptible batch jobs that do not require guaranteed availability. Option D is wrong because Sole-tenant nodes provide hardware isolation for compliance or licensing needs, not cost reduction; they actually increase costs due to premium pricing for dedicated hardware.

281
MCQmedium

Your organization runs a customer-facing web application on a managed instance group of Compute Engine VMs behind an HTTP(S) load balancer. The monthly bill shows that the VMs are running at only 15% average CPU utilization, yet the team insists they need the current number of VMs to handle peak traffic. You want to reduce compute costs without risking performance during traffic spikes. What should you do?

A.Move the application to a single large Compute Engine instance to reduce the number of VMs.
B.Purchase committed use discounts for all current VM instances for a one-year term.
C.Enable autoscaling on the managed instance group based on CPU utilization, and set the minimum number of instances to a lower value.
D.Change the machine type of all instances to a smaller size that matches the average CPU utilization.
AnswerC

Autoscaling adjusts the number of VM instances in the group based on load, so you pay only for what you need. Setting a lower minimum reduces cost during low-traffic periods, while the autoscaler adds instances when CPU or other metrics rise, preserving performance during peaks. This directly addresses the low average utilization without manual intervention.

Why this answer

The managed instance group is overprovisioned for average load but sized for peak. Autoscaling with a lower minimum lets the group shrink during low demand and expand during spikes, aligning cost with actual usage. The other options either reduce peak capacity, lock in excess capacity, or remove redundancy, none of which solve the cost problem while preserving performance.

Exam trap

The trap here is assuming that committed use discounts or smaller machine types automatically optimize cost, when the real issue is the fixed number of instances that never scales down.

282
MCQhard

A retail company runs a customer-facing API on GKE Autopilot in a single region. During a quarterly sales event, traffic triples for six hours and then returns to baseline. The SRE team wants to keep the API responsive during the spike, control spend, and avoid manual intervention. They have already configured a Horizontal Pod Autoscaler based on CPU utilization with a target of 60%. Which additional action best addresses the remaining scaling bottleneck?

A.Add a PodDisruptionBudget and increase the minimum replica count in the Deployment.
B.Expose a custom metric such as requests per second and configure the HPA to scale on it.
C.Configure a Vertical Pod Autoscaler in recommendation mode to right-size pod requests.
D.Increase the HPA target CPU utilization to 80% so pods are added more aggressively.
AnswerB

CPU utilization lags behind actual request load, especially for I/O-bound APIs that block on downstream calls while CPU stays moderate. Scaling on a request-rate metric lets the HPA add replicas as soon as traffic climbs, matching the sales-event pattern. This reduces latency risk and avoids over-provisioning between events, directly addressing the bottleneck.

Why this answer

CPU-based autoscaling reacts after CPU rises, which is too late for a sudden threefold traffic surge, particularly when the API spends time waiting on network or database calls. Scaling on a request-oriented custom metric tied to actual load lets the HPA add pods proactively. This keeps latency stable during the event and lets replicas fall back to baseline afterward, satisfying responsiveness, cost control, and automation goals together.

Exam trap

The trap here is treating CPU utilization as a universal autoscaling signal, when request-driven workloads often saturate on concurrency or downstream latency before CPU becomes the limiting factor.

283
MCQhard

An organization needs to audit all changes to network firewall rules in a GCP project. Which service should be used to capture these changes?

A.Cloud Logging
B.Cloud Monitoring
C.Cloud Audit Logs
D.VPC Flow Logs
AnswerC

Cloud Audit Logs records Admin Activity and Data Access entries, including firewall rule insertions, updates and deletions in a GCP project. It is the native service that captures these configuration changes for audit, satisfying the requirement to track all firewall rule modifications.

Why this answer

Cloud Audit Logs (specifically Admin Activity audit logs) record all API calls that modify the configuration or metadata of resources, including changes to firewall rules. When a firewall rule is created, updated, or deleted, an audit log entry is automatically generated with details such as the user, timestamp, and the change made. This makes Cloud Audit Logs the correct service for auditing changes to network firewall rules in a GCP project.

Exam trap

The trap here is that candidates confuse Cloud Logging (which is a general log storage and analysis platform) with Cloud Audit Logs (which is a specific type of log that records administrative actions), leading them to pick A instead of C.

How to eliminate wrong answers

Option A is wrong because Cloud Logging is a service for ingesting, storing, and analyzing log data from various sources, but it does not natively capture configuration changes to firewall rules; it would require custom log sinks or agents to collect such data. Option B is wrong because Cloud Monitoring focuses on metrics, uptime checks, and alerting based on performance and health indicators, not on recording API-driven configuration changes. Option D is wrong because VPC Flow Logs capture network traffic metadata (e.g., source/destination IPs, ports, protocols) for flow-level analysis, not the administrative changes to firewall rule definitions.

284
Multi-Selecthard

A security team wants to monitor and audit all changes to IAM policies in a Google Cloud organization. They need to set up real-time alerts when a new binding is added. Which THREE services should they combine to achieve this?

Select 3 answers
A.Cloud Scheduler
B.Cloud Pub/Sub
C.Cloud Functions
D.Cloud Audit Logs
E.Cloud Storage
AnswersB, C, D

Cloud Pub/Sub carries the audit log events onward, letting a subscriber receive IAM policy change notifications in real time. Combined with Cloud Logging log sinks and a notification channel, it delivers the alerting pipeline the security team requires for new bindings.

Why this answer

Cloud Audit Logs (D) is correct because Admin Activity audit logs automatically record IAM policy changes such as SetIamPolicy events, which capture when a new binding is added, providing the source of truth for auditing and monitoring. Cloud Pub/Sub (B) is correct because a log sink can route those filtered audit log entries to a Pub/Sub topic in real time, decoupling log ingestion from downstream processing. Cloud Functions (C) is correct because a function can be triggered by messages published to that Pub/Sub topic to evaluate the new binding and send real-time alerts.

Cloud Scheduler (A) is not needed since it only runs jobs on a time schedule and does not provide event-driven, real-time reaction to IAM changes. Cloud Storage (E) is not needed because it is object storage for retaining or archiving data, not a real-time alerting or event-processing service.

285
MCQeasy

A company runs a batch processing workload on Compute Engine instances in a managed instance group (MIG). The job is CPU-intensive and takes approximately 4 hours to complete. The company wants to reduce costs without sacrificing performance. Which action should they take?

A.Purchase committed use discounts for the instance type.
B.Change the machine series to a smaller machine type.
C.Use preemptible VMs for the MIG and implement a checkpointing mechanism to handle interruptions.
D.Provision additional reserved VMs to ensure capacity.
AnswerC

Preemptible VMs cost substantially less than standard instances but can be reclaimed at any time, so checkpointing preserves progress across interruptions. This suits the four-hour CPU-intensive batch job, cutting cost while the MIG restarts reclaimed instances to maintain throughput.

Why this answer

Preemptible VMs are significantly cheaper than standard VMs but can be terminated at any time. For a batch processing workload that is CPU-intensive and runs for 4 hours, using preemptible VMs in a MIG with a checkpointing mechanism allows the job to resume from the last saved state after an interruption, thus reducing costs without sacrificing performance.

Exam trap

Google Cloud often tests the misconception that committed use discounts are the best cost-saving option for any workload, but they are only cost-effective for predictable, always-on instances, not for batch jobs that can leverage preemptible VMs.

How to eliminate wrong answers

Option A is wrong because committed use discounts require a 1- or 3-year commitment and do not reduce costs for short-lived or interruptible workloads; they are best for steady-state, always-on instances. Option B is wrong because changing to a smaller machine type would reduce performance, potentially increasing job duration and negating cost savings. Option D is wrong because provisioning additional reserved VMs increases costs without addressing the need to reduce them, and reserved VMs are not cost-effective for batch jobs that can tolerate interruptions.

286
MCQeasy

A company wants to connect their on-premises network to Google Cloud with a 99.99% SLA using encrypted tunnels over the public internet. Which connectivity solution should they choose?

A.HA VPN
B.Standard VPN with single tunnel
C.Partner Interconnect
D.Dedicated Interconnect
AnswerA

HA VPN provides two tunnels across two interfaces, delivering a 99.99% availability SLA when configured with two external IP addresses. It encrypts traffic over the public internet, matching both the SLA and encryption constraints in the stem.

Why this answer

HA VPN provides a 99.99% SLA when configured with two VPN gateways and four tunnels over the public internet. Dedicated Interconnect is a private connection with higher bandwidth but not over the public internet. Partner Interconnect uses a partner's network, not the public internet.

Standard VPN does not offer a 99.99% SLA.

287
MCQeasy

A developer needs to secure secrets (API keys, passwords) used in a Cloud Function. What is the recommended approach?

A.Store secrets in environment variables
B.Store in Cloud Storage and download at runtime
C.Use Secret Manager
D.Hard-code in the function code
AnswerC

Secret Manager stores API keys and passwords encrypted at rest, granting the Cloud Function access through IAM roles rather than embedding credentials in code or environment variables. This satisfies the stem's requirement to secure secrets, since versioned, audited retrieval replaces hard-coded values that leak through source control or function configuration.

Why this answer

Secret Manager is the recommended approach for securing sensitive data like API keys and passwords in Cloud Functions because it provides encrypted storage, fine-grained access control via IAM, and automatic rotation. Unlike environment variables, which are visible in the Cloud Console and logs, Secret Manager ensures secrets are never exposed in plaintext and are injected securely at runtime.

Exam trap

Google Cloud often tests the misconception that environment variables are a secure way to store secrets because they are 'hidden' from code, but in reality they are plaintext and accessible via the Cloud Console and logs.

How to eliminate wrong answers

Option A is wrong because environment variables are not encrypted by default and can be viewed in the Cloud Console, logs, or by anyone with access to the function's configuration, making them insecure for secrets. Option B is wrong because storing secrets in Cloud Storage requires managing bucket permissions and encryption keys manually, and downloading at runtime introduces latency and potential exposure if the bucket is misconfigured. Option D is wrong because hard-coding secrets in function code exposes them in source control, build artifacts, and logs, violating security best practices and making rotation nearly impossible.

288
MCQeasy

You are the lead cloud architect for a startup that runs a web application on Google Kubernetes Engine (GKE) with a standard (zonal) cluster. The application is deployed with 3 replicas of a stateless frontend service. During a recent incident, a zone outage caused all GKE nodes to become unavailable, leading to application downtime of 45 minutes. You need to redesign the cluster to tolerate a single zone failure with no more than 5 minutes of downtime. Your budget allows for at most a 20% increase in compute costs. Which approach should you take?

A.Increase the number of replicas from 3 to 9 and keep the zonal cluster
B.Change the frontend deployment to use regional persistent disks
C.Deploy second GKE cluster in another region and use global load balancer for failover
D.Migrate the cluster to a regional GKE cluster with nodes in 3 zones and distribute replicas across zones
AnswerD

Correct: regional cluster survives zone failure.

Why this answer

D is correct because a regional GKE cluster distributes nodes across three zones, ensuring that if one zone fails, the remaining two zones continue serving traffic. By spreading the 3 replicas across zones (e.g., one per zone), the application tolerates a single zone outage with near-zero downtime, and the 20% cost increase covers the additional node pool overhead without exceeding the budget.

Exam trap

The trap here is that candidates confuse increasing replica count with achieving zone redundancy, failing to realize that replicas must be distributed across failure domains (zones) to survive a zone outage, and that regional persistent disks are irrelevant for stateless workloads.

How to eliminate wrong answers

Option A is wrong because increasing replicas to 9 in a zonal cluster does not provide zone redundancy; all nodes remain in a single zone, so a zone outage still takes down all replicas. Option B is wrong because regional persistent disks are used for stateful workloads (e.g., databases) and do not help with zone-level node failure for a stateless frontend; the frontend does not require persistent disks. Option C is wrong because deploying a second cluster in another region introduces cross-region latency and failover complexity, and the 5-minute downtime target cannot be met with DNS propagation or global load balancer failover; it also likely exceeds the 20% cost increase due to full cluster duplication.

289
MCQeasy

A financial services company is migrating a sensitive customer data application to Google Cloud. The application runs on Compute Engine VMs in a VPC. The security team requires that all data at rest in Cloud Storage and BigQuery must be encrypted with customer-managed encryption keys (CMEK). Additionally, the keys must be stored in a different project than the data, and access to the keys must be audited. The operations team has set up a CMEK key in Cloud KMS in a separate project, assigned the Cloud KMS CryptoKey Encrypter/Decrypter role to the data project's Compute Engine service account, and enabled Cloud Storage and BigQuery to use CMEK. However, when the application tries to read from Cloud Storage, it fails with 'Access Denied.' The Cloud KMS key is in project 'kms-proj' and the data is in project 'data-proj'. What is the most likely cause?

A.The Compute Engine service account used by the VM does not have the Cloud KMS Decrypter role.
B.The VPC firewall rules are blocking egress to Cloud KMS.
C.The Cloud KMS key has been disabled due to an Organization Policy.
D.The Cloud Storage service agent in 'data-proj' does not have the Cloud KMS CryptoKey Encrypter/Decrypter role.
AnswerD

Cloud Storage performs CMEK envelope encryption through its per-project service agent, not the Compute Engine service account. The service agent `service-<project-number>@gs-project-accounts.iam.gserviceaccount.com` in `data-proj` requires the Cloud KMS CryptoKey Encrypter/Decrypter role on the key in `kms-proj`; without it, reads fail with Access Denied.

Why this answer

Cloud Storage uses a Google-managed service agent (not the Compute Engine service account) to interact with CMEK keys. When Cloud Storage is configured to use CMEK, its service agent in the data project must be granted the Cloud KMS CryptoKey Encrypter/Decrypter role on the key in the KMS project. Without this permission, Cloud Storage cannot decrypt the key to access the data, resulting in an 'Access Denied' error even though the VM's service account has the correct role.

Exam trap

A common trap on Google Cloud exams is the distinction between the service account used by the compute resource (e.g., Compute Engine VM) and the service agent used by the Google Cloud service (e.g., Cloud Storage), leading candidates to incorrectly assume the VM's service account handles all encryption operations.

How to eliminate wrong answers

Option A is wrong because the Compute Engine service account does not directly decrypt Cloud Storage data; Cloud Storage uses its own service agent for CMEK operations, and the VM's service account only needs the role for operations like signing URLs or accessing KMS directly, not for reading CMEK-encrypted objects. Option B is wrong because VPC firewall rules blocking egress to Cloud KMS would cause a timeout or connection error, not an 'Access Denied' response from Cloud Storage; the error is a permission issue, not a network connectivity issue. Option C is wrong because a disabled key would produce a different error (e.g., 'Key disabled' or 'CryptoKey not found'), and the question states the key was set up and assigned roles, with no indication of an Organization Policy disabling it.

290
MCQhard

A global SaaS company wants to reduce the latency of its API for users in Asia, Europe, and North America. The API is stateless and runs on GKE in a single region. The company wants a solution that improves latency for all users without changing the application code. Which approach should the architect recommend?

A.Use Traffic Director with a global load balancing policy to distribute traffic across regional backends.
B.Deploy the API to GKE clusters in multiple regions and use a global external Application Load Balancer with a single anycast IP address.
C.Enable Cloud CDN on the existing regional load balancer and cache API responses at the edge.
D.Increase the machine type of the GKE nodes in the single region to handle more concurrent requests.
AnswerB

A global external Application Load Balancer provides a single anycast IP and routes each user to the closest healthy backend based on latency and health. By deploying the stateless API in multiple regions behind this load balancer, users in each geography are served from a nearby region, reducing latency without code changes. This is the standard global serving pattern in Google Cloud.

Why this answer

To reduce latency for a global user base without code changes, the application must run close to users and be fronted by a global entry point. Deploying the stateless API in multiple regions and placing a global external Application Load Balancer in front provides a single anycast IP that directs users to the nearest healthy backend. CDN, Traffic Director, and vertical scaling do not achieve this global proximity for dynamic API traffic.

Exam trap

The trap here is assuming that caching at the edge or scaling up a single region will fix global latency, when the real fix is to serve from multiple regions behind a global anycast load balancer.

291
MCQhard

A financial services company must comply with PCI DSS. They use Cloud SQL for MySQL for transaction processing. They need to ensure that all data at rest is encrypted with keys generated and stored in a Hardware Security Module (HSM) and that key rotation occurs every 90 days. Which configuration should they use?

A.Use Cloud External Key Manager (EKM) to integrate with on-premises HSM
B.Use Cloud SQL with customer-supplied encryption keys (CSEK) and automate rotation with Cloud Scheduler
C.Use Cloud SQL with CMEK backed by Cloud HSM, and set automatic rotation period of 90 days
D.Use Cloud SQL's default encryption with organization policy requiring rotation
AnswerC

CMEK with Cloud HSM provides customer-controlled, HSM-backed keys with automatic rotation.

Why this answer

Cloud SQL with CMEK backed by Cloud HSM meets the requirement for keys generated and stored in an HSM, and Cloud HSM supports automatic key rotation with a configurable period, including 90 days. CMEK allows you to manage and rotate the key used to encrypt data at rest, while Cloud HSM provides FIPS 140-2 Level 3 validated HSM for key storage. The automatic rotation period can be set to 90 days via the key rotation policy in Cloud KMS, satisfying the compliance mandate.

Exam trap

The trap here is that candidates confuse CSEK with CMEK, assuming CSEK provides HSM-backed keys, but CSEK keys are stored in Cloud KMS software, not in an HSM, and cannot be automatically rotated for Cloud SQL.

How to eliminate wrong answers

Option A is wrong because Cloud EKM integrates with an external key management system outside Google Cloud, but the requirement specifies keys generated and stored in an HSM, and EKM does not use Cloud HSM; it relies on an external partner HSM, which may not meet the 'stored in an HSM' requirement if the on-premises HSM is not Cloud HSM. Option B is wrong because Cloud SQL with CSEK uses customer-supplied encryption keys that are stored in Cloud KMS, not in an HSM, and CSEK does not support automatic rotation via Cloud Scheduler; you would need to manually re-encrypt the data, which is impractical and not supported for Cloud SQL. Option D is wrong because Cloud SQL's default encryption uses Google-managed keys, which are not generated or stored in a customer-controlled HSM, and organization policies cannot enforce key rotation on default encryption keys.

292
MCQmedium

A retail company is designing a new order-processing system on Google Cloud. The system must expose a REST API that is reachable from the public internet over a custom hostname, must terminate TLS at the edge, and must route requests to different backend services based on URL path prefixes such as /orders and /inventory. The platform team wants a fully managed, globally distributed solution that scales automatically and does not require managing reverse-proxy VMs. Which Google Cloud component should they place in front of the backends?

A.Traffic Director with Envoy sidecars deployed on each backend instance
B.Regional external passthrough Network Load Balancer with backend services in two zones
C.Global external Application Load Balancer with a URL map and a Google-managed SSL certificate
D.Cloud CDN with a signed URL key attached directly to the backend instance groups
AnswerC

The global external Application Load Balancer is a managed Layer 7 proxy that terminates TLS at Google's edge, supports custom hostnames through Google-managed certificates, and uses a URL map to route by path prefix to different backends. It scales globally without reverse-proxy VMs, which matches every stated requirement.

Why this answer

The global external Application Load Balancer is the only listed option that combines managed edge TLS termination, custom hostname support through Google-managed certificates, and URL-map-based path routing to multiple backends. Because it is a fully managed global proxy, it scales automatically and removes the operational burden of running reverse-proxy VMs, satisfying both the functional and operational requirements.

Exam trap

The trap here is assuming that any load balancer can perform HTTP path-based routing, when Layer 4 passthrough network load balancers only forward TCP connections.

293
Multi-Selectmedium

A healthcare analytics team must run a stateless containerized API on Google Cloud. The platform must scale to zero when there is no traffic, expose an HTTPS endpoint with a managed certificate, and require no cluster or node management by the team. The architect is choosing among Google Cloud container platforms. Which two characteristics make Cloud Run the appropriate choice here? (Choose two.)

Select 2 answers
A.Cloud Run scales the service to zero instances when no requests arrive, and bills only for resources consumed while handling requests.
B.Cloud Run allows the team to choose and manage the operating system image and patch cadence of the worker nodes running the containers.
C.Cloud Run supports persistent local SSD storage attached to each instance for stateful session data across requests.
D.Cloud Run manages the underlying infrastructure entirely, so the team never provisions, patches, or sizes cluster nodes or node pools.
E.Cloud Run requires a GKE cluster in the same project so the service can schedule pods onto managed node pools.
AnswersA, D

Cloud Run's request-driven autoscaling can reduce the service to zero instances during idle periods, which removes idle infrastructure cost entirely. That directly satisfies the requirement to scale to zero when no traffic exists, and the consumption-based billing model means the team pays only for the CPU and memory used while requests are being processed, which is exactly the economic behavior the scenario demands.

Why this answer

Cloud Run fits because it scales to zero when idle, charging only for request-driven consumption, and because it fully abstracts the compute layer so no cluster or node administration is needed. Those two properties align with the stateless, low-traffic API and the team's desire to avoid managing infrastructure.

Exam trap

The trap here is conflating Cloud Run with GKE-based container hosting and assuming the team must still manage nodes or choose node images.

294
Multi-Selecthard

A company runs a web application on App Engine Standard environment. The application experiences downtime during deployments due to traffic shifting. Which two strategies should they implement to improve reliability? (Choose two.)

Select 2 answers
A.Use Cloud Endpoints to manage API traffic and route deployments.
B.Increase the number of idle instances to handle traffic during deployment.
C.Use traffic splitting to gradually migrate traffic to the new version.
D.Deploy to a separate version and then shift traffic using the App Engine console or gcloud.
E.Set manual scaling to avoid autoscaling delays.
AnswersC, D

Traffic splitting routes a configurable percentage of requests to the new version while the old version keeps serving the remainder. If the new version fails, traffic shifts back without downtime, satisfying the reliability requirement during deployments.

Why this answer

Option C is correct because App Engine traffic splitting lets you migrate user traffic to a new version gradually (for example, by IP address, cookie, or random percentage), so the new version can be validated with a small share of requests before full cutover, avoiding the all-at-once downtime caused by abrupt traffic shifting. Option D is correct because deploying the new code as a separate App Engine version keeps the currently serving version live and healthy, and then you shift traffic to the new version via the App Engine console or gcloud commands (such as gcloud app services set-traffic), which is the standard zero-downtime deployment pattern. Option A is not appropriate because Cloud Endpoints is an API management layer for authentication, monitoring, and quotas, not a mechanism for shifting App Engine version traffic during deployments.

Option B is not appropriate because idle instances only reduce instance startup latency; they do not prevent downtime caused by traffic shifting between versions. Option E is not appropriate because manual scaling disables autoscaling and does not address the deployment traffic-shifting problem, and could actually reduce reliability under load.

Exam trap

Google Cloud often tests the distinction between deployment strategies (traffic splitting/version shifting) and scaling or API management features, leading candidates to confuse operational scaling fixes with deployment reliability improvements.

295
Multi-Selecthard

A company wants to centrally manage firewall rules for all projects in an organization using hierarchical firewall policies. Which three resources can be used in conjunction with hierarchical firewall policies? (Choose three.)

Select 3 answers
A.Compute Engine instance
B.Organization node
C.Project
D.VPC network
E.Folder
AnswersB, C, E

Hierarchical firewall policies are defined at the organisation node, which is the root of the resource hierarchy. Attaching policy there lets rules cascade to every folder and project beneath it, satisfying the requirement for centralised firewall management across all projects.

Why this answer

Hierarchical firewall policies in Google Cloud are attached at nodes of the resource hierarchy, and the three valid attachment points are the organization node (B), folders (E), and projects (C). Option B is correct because an organization-level policy applies to all resources beneath the organization and serves as the topmost layer of hierarchical firewall rules. Option E is correct because folders sit between the organization and projects, allowing policies to be scoped to a subset of projects within the hierarchy.

Option C is correct because a project-level policy applies to that project's resources and is evaluated after organization and folder policies. Options A and D are not valid attachment points: a Compute Engine instance (A) is a compute resource governed by the policies, not a node where a hierarchical firewall policy is attached, and a VPC network (D) is associated with VPC firewall rules, not hierarchical firewall policies.

Exam trap

PCA often tests the misconception that hierarchical firewall policies can be applied to VPC networks or instances directly, confusing them with VPC firewall rules.

296
MCQeasy

A startup is migrating a monolithic application to Google Cloud. They want to minimize operational overhead and auto-scale based on HTTP request load. Which compute solution should they choose?

A.Compute Engine managed instance groups with autoscaling
B.Google Kubernetes Engine (GKE)
C.Cloud Functions
D.Cloud Run
AnswerD

Cloud Run is fully managed and scales to zero, removing cluster and node operational overhead entirely. It autoscales on HTTP request concurrency, directly satisfying the startup's requirement to scale with request load without managing infrastructure.

Why this answer

Cloud Run is the best choice because it is a fully managed serverless platform that automatically scales from zero based on HTTP request load, minimizing operational overhead. It abstracts away infrastructure management, supports containerized applications, and charges only for resources used during request processing, aligning perfectly with the requirement to auto-scale based on HTTP traffic.

Exam trap

The trap here is that candidates often choose GKE or Compute Engine for 'auto-scaling' without recognizing that serverless options like Cloud Run offer the same capability with significantly less operational overhead for HTTP-based workloads.

How to eliminate wrong answers

Option A is wrong because Compute Engine managed instance groups with autoscaling require managing virtual machines, patching OS, and configuring scaling policies, which increases operational overhead compared to serverless options. Option B is wrong because Google Kubernetes Engine (GKE) introduces cluster management, node patching, and container orchestration complexity, which is not minimal operational overhead for a simple HTTP workload. Option C is wrong because Cloud Functions is designed for event-driven, short-lived functions, not for running a monolithic application that typically requires a persistent runtime environment and longer request handling.

297
Multi-Selectmedium

A retail company is designing a Google Cloud landing zone for a regulated workload. They must ensure that encryption keys for Cloud Storage and BigQuery are generated and stored outside Google's infrastructure, with the ability to revoke access immediately. They also must retain detailed records of who accessed the data and when, for seven years. Which TWO configurations should the architect include? (Choose two.)

Select 2 answers
A.Use Cloud External Key Manager (Cloud EKM) with an external key manager reachable over the internet or Interconnect
B.Enable default encryption with Google-managed keys on all storage buckets
C.Configure Cloud KMS with HSM protection level for all customer-managed encryption keys
D.Enable VPC Service Controls perimeters around the storage and analytics projects
E.Enable Data Access audit logs for Cloud Storage and BigQuery and route them to a log bucket with a seven-year retention lock
AnswersA, E

Cloud EKM lets Cloud KMS call an external key manager you control, so key material resides outside Google and never enters Google's infrastructure. Revoking the external key immediately renders wrapped data keys unusable, satisfying both the external custody and rapid revocation requirements for Cloud Storage and BigQuery.

Why this answer

Cloud EKM places key custody in an external manager you operate, letting you revoke keys instantly and keeping key material outside Google, which covers the encryption requirement. Enabling Data Access audit logs and routing them into a locked, seven-year retention bucket creates the immutable access record the regulation demands.

Exam trap

The trap here is treating Cloud KMS HSM keys or VPC Service Controls as sufficient for external key custody and long-term access auditing, when neither places key material outside Google or produces the required access records.

298
Matchingmedium

Match each GCP compute service to its characteristic.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Virtual machines with full control

Managed Kubernetes clusters

Serverless containers

Platform as a Service (PaaS)

Event-driven serverless functions

Why these pairings

Compute Engine provides IaaS virtual machines; GKE offers managed Kubernetes; Cloud Run enables serverless containers; App Engine is a PaaS for web apps. Common confusions include mixing serverless and Kubernetes features.

299
Matchingmedium

Match each GCP migration term to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Move workloads without modification

Tool to migrate VMs to GCP

Physical device for large data transfer

Online data transfer from other clouds or on-prem

Migrate databases to Cloud SQL with minimal downtime

Why these pairings

Correct matches: Migrate for Compute Engine migrates VMs; Cloud Storage Transfer Service handles online data transfers; Transfer Appliance is a physical device for large datasets; Database Migration Service migrates databases to Cloud SQL. Common confusions include swapping the roles of these services.

300
MCQmedium

A company is deploying a new application on Compute Engine. They need to ensure that the application can automatically recover from a zone failure. What is the best approach?

A.Create a managed instance group with instances in multiple zones.
B.Use a global load balancer in front of a single instance.
C.Create a single VM in a single zone and rely on live migration.
D.Use Cloud Storage to store application state and restore from a snapshot.
AnswerA

A managed instance group spanning multiple zones maintains capacity when one zone fails, satisfying the automatic zone-failure recovery requirement. The group's regional distribution and autohealing replace unhealthy instances in surviving zones, unlike a single-zone group or manual restart, which cannot survive zone loss.

Why this answer

A managed instance group (MIG) with instances in multiple zones provides automatic recovery from a zone failure by distributing instances across zones and using auto-healing to recreate failed instances. If one zone becomes unavailable, the load balancer routes traffic to healthy instances in other zones, ensuring high availability without manual intervention.

Exam trap

Google Cloud often tests the distinction between live migration (which handles host maintenance but not zone failures) and multi-zone MIGs (which handle zone failures), leading candidates to mistakenly choose live migration as a recovery mechanism.

How to eliminate wrong answers

Option B is wrong because a global load balancer in front of a single instance does not provide zone-level redundancy; if the zone fails, the single instance becomes unavailable, and the load balancer has no healthy backend to route traffic to. Option C is wrong because live migration only protects against host maintenance events, not zone failures; if the entire zone fails, the VM is lost and cannot be recovered automatically. Option D is wrong because storing application state in Cloud Storage and restoring from a snapshot is a disaster recovery approach, not an automatic recovery mechanism; it requires manual steps to recreate the VM and does not provide seamless failover.

Page 3

Page 4 of 11

Page 5

All pages