Courseiva

Google Professional Cloud Architect (PCA) — Questions 301–375

807 questions total · 11pages · All types, answers revealed

Page 4

Page 5 of 11

Page 6
301
MCQmedium

A company is performing a TCO analysis to compare on-premises costs with Google Cloud. Which cost should they include as a hidden operational cost on-premises?

A.Compute Engine instance costs
B.Power, cooling, and physical security
C.Egress charges
D.Software license costs
AnswerB

Power, cooling, and physical security are ongoing operational costs rarely captured in on-premises hardware quotes, so including them gives a truer TCO comparison against Google Cloud's consumption pricing, where the provider absorbs these facilities costs.

Why this answer

On-premises hidden costs include facility costs (power, cooling, space), hardware maintenance, personnel for patching and upgrades. Egress costs are cloud costs, not on-prem. Compute Engine instance cost is a direct cloud cost.

Software licenses depend on licensing model.

302
Multi-Selecthard

Which THREE are best practices for designing a highly available application on Compute Engine?

Select 3 answers
A.Use local SSDs for stateful data
B.Use a single large machine type
C.Use managed instance groups with autoscaling
D.Use an external load balancer with health checks
E.Distribute instances across multiple zones
AnswersC, D, E

Managed instance groups with autoscaling maintain instances across multiple zones, automatically replacing failed VMs and scaling capacity to match demand. This directly satisfies the high-availability requirement by eliminating single points of failure and absorbing load spikes without manual intervention, ensuring continuous service during zone outages or traffic surges.

Why this answer

Option C is correct because a managed instance group (MIG) with autoscaling automatically maintains the desired number of healthy VM instances and replaces failed ones, which is fundamental to high availability on Compute Engine. Option D is correct because an external load balancer with health checks only routes traffic to healthy backends and removes unhealthy instances from rotation, preventing users from hitting failed VMs. Option E is correct because distributing instances across multiple zones protects the application from a single-zone failure, since zonal outages do not affect instances in other zones within the same region.

Option A is not appropriate because local SSDs are ephemeral and tied to a single VM, so they cannot store durable stateful data for a highly available design. Option B is not appropriate because a single large machine type creates a single point of failure and cannot provide redundancy or fault tolerance.

Exam trap

Google Cloud often tests the misconception that local SSDs are suitable for stateful data in HA designs, but the trap is that local SSDs are ephemeral and data is lost on instance failure, so they should only be used for cache or temporary data, not for persistent state.

303
MCQmedium

You are the architect for a company that runs a three-tier web application on Compute Engine. The CTO wants to reduce the monthly cloud bill without impacting performance or availability. You review the billing export in BigQuery and notice that the VMs are sized for peak load, but CPU utilization rarely exceeds 20% on weekdays and 5% on weekends. The application is stateless and uses an external Cloud SQL database. Which cost optimization strategy should you implement first?

A.Create a managed instance group with autoscaling and right-size the instance template based on actual utilization.
B.Purchase a 3-year commitment for the current VM sizes.
C.Move the application to Cloud Run.
D.Enable committed use discounts for the VMs.
AnswerA

This directly addresses the overprovisioning by scaling the number of instances to match demand and using a smaller machine type that fits actual CPU usage. It maintains availability because the managed instance group can span zones and replace unhealthy instances, and it does not require application changes since the app is stateless.

Why this answer

The application is stateless and overprovisioned, so the most effective first step is to right-size instances and use autoscaling to match capacity to demand. This reduces cost while maintaining performance and availability. Committed use discounts and long-term commitments only make sense after you have optimized the instance shape and quantity.

Exam trap

The trap here is assuming that committed use discounts or long-term commitments are the primary cost optimization, when in fact they should be applied only after right-sizing.

304
MCQmedium

Your organization is adopting a multi-cloud strategy and wants to ensure consistent security policies across Google Cloud and another cloud provider. You need to centrally manage and enforce security policies, such as preventing public access to storage buckets, across both environments. What should you do?

A.Use Google Cloud's Organization Policy Service to define constraints and apply them to all projects.
B.Configure VPC Service Controls in Google Cloud and replicate the same configuration in the other cloud.
C.Use Terraform to define infrastructure as code and apply the same policies to both clouds.
D.Implement a third-party cloud security posture management (CSPM) tool that supports multi-cloud policy enforcement.
AnswerD

A multi-cloud CSPM tool can provide a single pane of glass to define, monitor, and enforce security policies across Google Cloud and other providers. It can detect and remediate misconfigurations like public storage buckets consistently. This meets the requirement for centralized management across multiple clouds.

Why this answer

For multi-cloud security policy management, a third-party CSPM tool is designed to work across different cloud providers, offering centralized policy definition, monitoring, and enforcement. Google Cloud native tools like Organization Policy Service and VPC Service Controls are limited to Google Cloud, and Terraform is for provisioning, not continuous enforcement.

Exam trap

The trap here is assuming that Google Cloud's native security tools can manage policies in other clouds, but they are limited to Google Cloud resources.

305
Drag & Dropmedium

Drag and drop the steps to recover a Cloud SQL instance from a backup into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Restoring to an existing instance may overwrite data; best practice is to restore to a new instance.

306
MCQeasy

An organization wants to reduce costs for a batch data processing job that runs nightly and is resilient to interruptions. The job can be restarted from checkpoints. Which Compute Engine VM pricing model should be used?

A.On-demand VMs
B.Sustained use discounts
C.Committed use discounts (1-year)
D.Preemptible VMs
AnswerD

Preemptible VMs cost substantially less than standard instances but can be terminated at any time with a 30-second warning. Because the nightly batch job is resilient to interruptions and restarts from checkpoints, this pricing model satisfies the stem's cost-reduction goal without risking data loss.

Why this answer

Preemptible VMs and Spot VMs are significantly cheaper than standard VMs and can be terminated by Google Cloud at any time. Since the job is batch and can resume from checkpoints, interruptions are acceptable. Sustained use discounts apply automatically to standard VMs, but preemptible/spot VMs offer the lowest cost for fault-tolerant workloads.

307
MCQeasy

A startup deploys a containerized web application on Cloud Run. They want to release a new revision to a small percentage of users before promoting it to all traffic, and they need the ability to roll back instantly if errors increase. Which Cloud Run feature should they use?

A.Use Cloud Deploy with a canary deployment strategy targeting the Cloud Run service and rely on its automatic rollback on failure.
B.Enable session affinity on the Cloud Run service and deploy the new revision so existing sessions stay on the old revision.
C.Create a second Cloud Run service for the new version and use a global external HTTP(S) load balancer with weighted backends to split traffic.
D.Deploy the new revision with --no-traffic, then use traffic splitting to send a percentage of requests to it, and adjust or roll back by changing the traffic allocation.
AnswerD

Cloud Run supports deploying a revision without traffic and then splitting traffic by percentage across revisions. This enables a canary release to a small share of users, and rollback is immediate by routing all traffic back to the previous revision. It requires no extra infrastructure and uses built-in revision management.

Why this answer

Cloud Run revisions are immutable and traffic can be split by percentage across them. Deploying with no traffic, then assigning a small percentage, implements a canary, and setting the previous revision to 100 percent rolls back instantly. This built-in capability avoids external load balancers or delivery pipelines for a straightforward canary and rollback.

Exam trap

The trap here is assuming a load balancer or a separate service is required for canary releases, when Cloud Run traffic splitting already provides percentage-based routing and instant rollback.

308
MCQmedium

A company is deploying a multi-tier web application on Google Cloud. The application must comply with PCI DSS. Which combination of Google Cloud services should be used to restrict access to the database tier to only the application tier, while also encrypting data at rest and in transit?

A.Use Cloud Spanner with private IP and SSL/TLS, and enable Google-managed encryption keys
B.Use Cloud SQL with public IP and SSL/TLS, and enable Google-managed encryption keys
C.Use Cloud Datastore with secure WebSocket connections and enable customer-managed encryption keys
D.Use Cloud SQL with private IP and SSL/TLS, and enable Cloud Key Management Service (KMS) to create a key ring and customer-managed encryption key (CMEK)
AnswerD

Private IP keeps the Cloud SQL instance off the public internet, so only the application tier's VPC can reach it, while SSL/TLS encrypts data in transit and CMEK via Cloud KMS encrypts data at rest, meeting PCI DSS constraints.

Why this answer

It meets all PCI DSS requirements: Cloud SQL with private IP ensures the database tier is not exposed to the public internet, restricting access to only the application tier within the same VPC. SSL/TLS encrypts data in transit, and using Cloud KMS with a customer-managed encryption key (CMEK) provides control over encryption keys for data at rest, which is often required for compliance.

Exam trap

The trap here is that candidates often assume Google-managed encryption keys are sufficient for PCI DSS, but the standard often requires customer-managed keys (CMEK) to demonstrate control over key lifecycle, and they overlook that public IP (even with SSL) fails the network access restriction requirement.

How to eliminate wrong answers

Option A is wrong because Cloud Spanner with private IP and SSL/TLS does encrypt data in transit and restricts network access, but it uses Google-managed encryption keys by default, which may not satisfy PCI DSS requirements for customer control over encryption keys. Option B is wrong because Cloud SQL with public IP exposes the database to the internet, violating the requirement to restrict access to only the application tier, even with SSL/TLS. Option C is wrong because Cloud Datastore is a NoSQL document database that does not support secure WebSocket connections for encryption in transit (it uses gRPC/HTTP with TLS), and customer-managed encryption keys are not available for Cloud Datastore; it uses Google-managed keys only.

309
Multi-Selecthard

A company is migrating a legacy on-premises application to Google Cloud. The application has strict low-latency requirements between its components and requires stateful TCP sessions. Which TWO design decisions should the architect recommend?

Select 2 answers
A.Use regional managed instance groups with internal load balancing.
B.Use Cloud NAT for outbound connectivity.
C.Use global load balancing with Cloud CDN.
D.Use Cloud VPN for on-premises connectivity.
E.Place all components in the same VPC network.
AnswersA, E

Supports session affinity and preserves source IP for stateful protocols.

Why this answer

Regional managed instance groups (MIGs) with internal load balancing are correct because they keep all compute instances within a single region, minimizing network hops and latency between components. Internal load balancing provides a single IP address for stateful TCP sessions without introducing the latency of a global proxy, and it supports session affinity (e.g., client IP affinity) to maintain stateful connections.

Exam trap

The trap here is that candidates often confuse global load balancing (which is for external, stateless, HTTP-based traffic) with internal load balancing, and mistakenly think Cloud CDN or Cloud NAT can help with latency or stateful sessions, when they actually break TCP state or add unnecessary hops.

310
MCQhard

A healthcare analytics company is designing a BigQuery-based data warehouse that ingests patient records from multiple hospitals. Regulatory requirements mandate that queries never move data across regional boundaries and that only authorized analysts can access patient-identifiable columns. The architects want to enforce these controls at the platform level rather than relying on application code. Which combination of Google Cloud features should they design into the solution?

A.BigQuery dataset location set to a single region, authorized views that exclude patient-identifiable columns, and Cloud Armor security policies on the BigQuery API endpoint.
B.BigQuery multi-region dataset, Cloud IAM basic roles for analysts, and Cloud DLP inspection jobs scheduled daily.
C.BigQuery dataset location set to a single region, IAM conditions based on resource names, and customer-managed encryption keys in Cloud KMS.
D.BigQuery dataset location set to a single region, VPC Service Controls perimeter around the project, and column-level security using policy tags in Data Catalog.
AnswerD

BigQuery dataset location pins data to a region, satisfying the no-cross-region requirement. A VPC Service Controls perimeter prevents data exfiltration and restricts access to only authorized networks and identities. Policy tags in Data Catalog enable column-level access control so only approved analysts can read patient-identifiable columns. Together these enforce controls at the platform level without application changes.

Why this answer

Data residency is enforced by pinning the BigQuery dataset to a single region. Preventing exfiltration and restricting access to authorized identities and networks is the role of VPC Service Controls. Column-level least privilege for patient-identifiable fields is achieved with policy tags in Data Catalog, which BigQuery enforces natively.

This trio addresses residency, perimeter, and column-level authorization at the platform layer.

Exam trap

The trap here is treating Cloud DLP as an access-control mechanism, when it only discovers and classifies sensitive data and does not restrict who can query specific columns.

311
MCQeasy

A startup wants to deploy a stateless containerized API that must scale automatically from zero and be billed only when requests are processed. The team has no Kubernetes expertise and wants minimal operational overhead. Which Google Cloud service should the architect recommend?

A.App Engine flexible environment with automatic scaling.
B.Compute Engine managed instance group behind an external Application Load Balancer.
C.Google Kubernetes Engine with a cluster autoscaler and Horizontal Pod Autoscaler.
D.Cloud Run with the container image deployed as a service.
AnswerD

Cloud Run runs stateless containers, scales automatically including down to zero when there is no traffic, and bills per request and resource usage. It abstracts away cluster and node management, so a team without Kubernetes expertise can deploy a container image and get a managed HTTPS endpoint. This matches the scaling, billing, and low-overhead requirements precisely.

Why this answer

Cloud Run is the managed serverless container platform that scales to zero, bills per request and resource consumption, and removes cluster and node operations. Deploying the container image as a Cloud Run service gives the startup an HTTPS endpoint with automatic scaling and no idle cost, matching the stateless API, minimal operations, and pay-per-use requirements.

Exam trap

The trap here is equating autoscaling with scale-to-zero, when GKE, managed instance groups, and App Engine flexible all keep minimum capacity running and bill for it even with no traffic.

312
MCQmedium

A company is migrating its on-premises workloads to Google Cloud. They have strict compliance requirements that all data at rest must be encrypted with customer-managed encryption keys (CMEK). Which Google Cloud service should they use to manage the lifecycle of these keys?

A.Secret Manager
B.Cloud External Key Manager (Cloud EKM)
C.Cloud Key Management Service (Cloud KMS)
D.Cloud Hardware Security Module (Cloud HSM)
AnswerC

Cloud KMS creates, stores, rotates and controls customer-managed encryption keys, and integrates with Google Cloud services so data at rest is encrypted under CMEK. It directly satisfies the compliance requirement for managing key lifecycle rather than relying on Google-managed keys.

Why this answer

Cloud KMS is the correct service because it provides centralized management of customer-managed encryption keys (CMEK) for Google Cloud services. It allows you to create, rotate, destroy, and set permissions on symmetric and asymmetric keys, and integrates directly with services like Cloud Storage, BigQuery, and Compute Engine to enforce encryption at rest with keys you control.

Exam trap

The trap here is that candidates often confuse Cloud HSM as a key management service, but Cloud HSM is a key storage backend for Cloud KMS, not a replacement for lifecycle management; you must use Cloud KMS to control key creation, rotation, and destruction even when using HSM-backed keys.

How to eliminate wrong answers

Option A is wrong because Secret Manager is designed to store and manage secrets such as API keys, passwords, and certificates, not to manage encryption keys for data-at-rest encryption under CMEK. Option B is wrong because Cloud External Key Manager (Cloud EKM) allows you to manage keys using an external key management system outside Google Cloud, but it does not provide native lifecycle management within Google Cloud; it relies on an external partner for key operations. Option D is wrong because Cloud HSM is a hardware security module service that provides FIPS 140-2 Level 3 validated key storage and cryptographic operations, but it is an additional protection layer for keys stored in Cloud KMS, not a standalone key lifecycle management service; you still use Cloud KMS to manage the key lifecycle.

313
MCQhard

A financial services company runs a regulated trading platform in a single Google Cloud region. Regulators require that the platform survive the loss of an entire region with a recovery point objective of zero and a recovery time objective of under one minute. The database is Cloud Spanner, and the application tier runs on Google Kubernetes Engine. Which design should the architect choose?

A.Deploy Cloud Spanner as a regional instance and take scheduled backups exported to a Cloud Storage bucket in another region
B.Deploy Cloud Spanner as a multi-region instance and run GKE regional clusters in two regions behind a global external Application Load Balancer
C.Deploy Cloud Spanner as a multi-region instance and run a single GKE zonal cluster with node pools spread across three zones in the primary region
D.Deploy Cloud Spanner as a regional instance with read replicas in a second region and use change streams to replay writes into the second region after failover
AnswerB

A multi-region Cloud Spanner instance synchronously replicates data across regions with strong consistency, giving a recovery point objective of zero. Regional GKE clusters in two regions behind a global external Application Load Balancer provide health-checked failover with sub-minute recovery. Together they meet both the zero data loss and under-one-minute recovery targets for a region loss.

Why this answer

Zero recovery point objective demands synchronous cross-region replication, which only a multi-region Cloud Spanner instance provides. Sub-minute recovery demands application compute already running in a second region with automated traffic failover. Combining a multi-region Spanner instance with regional GKE clusters in two regions behind a global external Application Load Balancer satisfies both constraints simultaneously.

Exam trap

The trap here is treating backups, change streams, or zone redundancy as substitutes for synchronous cross-region replication and pre-provisioned compute in a second region.

314
MCQmedium

A company is migrating an on-premises PostgreSQL database (5 TB) to Cloud SQL. They need minimal downtime and automated schema conversion if needed. Which GCP service should they use?

A.Database Migration Service (DMS)
B.Datastream
C.Migrate for Compute Engine (formerly Velostrata)
D.Transfer Appliance
AnswerA

Database Migration Service performs continuous replication from the on-premises PostgreSQL source to Cloud SQL, keeping downtime to a minimum during cutover. Its built-in schema conversion handles incompatible objects automatically, satisfying the automated conversion requirement for the 5 TB migration.

Why this answer

Database Migration Service (DMS) is the correct choice because it is a fully managed GCP service designed to migrate databases to Cloud SQL with minimal downtime, supporting continuous replication and automated schema conversion via the Database Migration Service conversion workspace. It handles homogeneous migrations like PostgreSQL to Cloud SQL for PostgreSQL and can perform schema conversion when needed. Datastream is a change data capture service, not a full migration tool, and the other options are for different migration scenarios.

Exam trap

The trap here is confusing Datastream (CDC only) with Database Migration Service (full migration with schema conversion), so candidates must remember that DMS is the end-to-end migration service while Datastream is for replication.

How to eliminate wrong answers

Option B is wrong because Datastream is a serverless change data capture (CDC) and replication service for streaming data into BigQuery, Cloud SQL, or Cloud Storage, but it does not perform schema conversion or manage the full database migration lifecycle. Option C is wrong because Migrate for Compute Engine is for migrating VMs from on-premises or other clouds to Compute Engine, not for database migrations to Cloud SQL. Option D is wrong because Transfer Appliance is a physical appliance for transferring large datasets to Cloud Storage, not a database migration service.

315
MCQeasy

An engineer wants to migrate an on-premises MySQL database (5.6) to Cloud SQL for MySQL with minimal downtime. Which service should they use?

A.Migrate for Compute Engine (formerly Velostrata)
B.Storage Transfer Service
C.BigQuery Data Transfer Service
D.Database Migration Service
AnswerD

Database Migration Service performs continuous, log-based replication from the on-premises MySQL 5.6 source to Cloud SQL, keeping the target synchronised until cutover. This satisfies the minimal-downtime constraint, since only a brief final promotion is needed rather than a full dump-and-restore outage.

Why this answer

Database Migration Service (DMS) is purpose-built for migrating relational databases like MySQL 5.6 to Cloud SQL with minimal downtime. It performs an initial full load followed by continuous change data capture (CDC) replication from the source, allowing cutover with seconds of downtime. DMS natively supports MySQL, PostgreSQL, and SQL Server sources into Cloud SQL and AlloyDB.

Exam trap

PCA often tests whether candidates confuse data-movement services — the trap is picking Storage Transfer Service or BigQuery Data Transfer Service for a database migration when only Database Migration Service handles schema + CDC replication into Cloud SQL.

How to eliminate wrong answers

Option A is wrong because Migrate for Compute Engine (Velostrata) migrates VM workloads to Compute Engine, not managed database schemas into Cloud SQL. Option B is wrong because Storage Transfer Service moves object/blob data between storage buckets, not relational database contents. Option C is wrong because BigQuery Data Transfer Service loads data into BigQuery for analytics, not into Cloud SQL for MySQL.

316
MCQmedium

A company stores backup data in Cloud Storage. They observe high egress costs when clients download backups. Additionally, they must retain backups for 7 years for compliance. Which optimization should they implement first?

A.Use lifecycle rules to transition to Archive after 30 days and delete after 7 years
B.Enable requester pays on the bucket
C.Set up a Cloud CDN for backup downloads
D.Move the backup data to Archive storage class
AnswerB

Requester pays shifts egress charges to the downloading clients, directly addressing the high egress cost constraint. Since backups must still be retained for seven years, this preserves the data unchanged while eliminating the company's own retrieval fees.

Why this answer

High egress costs occur when clients download backups, and enabling requester pays shifts these costs to the clients. This directly addresses the cost issue without changing storage class or retention. Requester pays is the first optimization because it resolves the immediate cost problem while lifecycle rules or storage class changes address separate concerns like retention or storage cost.

Exam trap

Google Cloud often tests the misconception that changing storage class (e.g., to Archive) reduces egress costs, when in fact egress costs are independent of storage class and requester pays is the direct solution for shifting download costs.

How to eliminate wrong answers

Option A is wrong because lifecycle rules manage storage cost and retention, not egress costs; transitioning to Archive after 30 days reduces storage cost but does not shift or reduce the egress charges incurred during downloads. Option C is wrong because Cloud CDN caches content to reduce latency and origin load, but it does not eliminate egress costs from Cloud Storage; egress from Cloud CDN still incurs charges, and backups are typically not cacheable due to infrequent access. Option D is wrong because moving to Archive storage class reduces storage cost but does not affect egress costs; Archive has higher retrieval fees and minimum retention periods that could conflict with the 7-year compliance requirement.

317
MCQmedium

A company is migrating a monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single Compute Engine instance and stores session state in local memory. The migration must support horizontal scaling and high availability. What should the company do to manage session state in the new architecture?

A.Refactor the application to store session state in Cloud Memorystore for Redis and make the application stateless.
B.Use a StatefulSet with a headless service to assign stable network identities to pods.
C.Use GKE Ingress with session affinity (sticky sessions) to route requests to the same pod.
D.Store session state in Cloud SQL using a replicated database.
AnswerA

Storing session state in Cloud Memorystore for Redis externalises it from pod memory, so any replica can serve any request and pods can scale or restart freely, satisfying the horizontal scaling and high availability constraints of the GKE migration.

Why this answer

Migrating to a stateless architecture with Cloud Memorystore for Redis allows the application to scale horizontally without session state being tied to any single pod. By externalizing session state to a managed, highly available Redis service, any pod can handle any request, which is essential for high availability and autoscaling in GKE.

Exam trap

Google Cloud often tests the distinction between 'making the application stateless' versus 'using sticky sessions or StatefulSets'—the trap here is that candidates may think session affinity (Option C) is sufficient for high availability, but it actually creates a single point of failure at the pod level.

How to eliminate wrong answers

Option B is wrong because StatefulSets with headless services are designed for stateful workloads that require stable network identities and persistent storage, not for managing session state in a horizontally scalable stateless application. Option C is wrong because GKE Ingress with session affinity (sticky sessions) ties a client to a specific pod, which prevents true horizontal scaling and high availability—if that pod fails, the session is lost. Option D is wrong because Cloud SQL is a relational database not optimized for high-speed session state access; using it for session storage would introduce latency and unnecessary overhead compared to an in-memory data store like Redis.

318
Multi-Selecthard

You are designing a multi-region deployment for a critical application on GKE. The application must withstand a regional outage and automatically redirect traffic to the healthy region. Which THREE components must be configured? (Choose 3)

Select 3 answers
A.Cloud Spanner
B.Global HTTP(S) Load Balancer
C.Regional Cloud SQL
D.Multi-cluster Ingress
E.Cloud NAT
AnswersA, B, D

Cloud Spanner provides a globally distributed, strongly consistent database with multi-region replication, so application data survives a full regional outage. Its synchronous replication across regions satisfies the durability constraint that the critical application must keep serving from the healthy region.

Why this answer

Option A (Cloud Spanner) is correct because it is a globally distributed, strongly consistent, multi-region database with automatic synchronous replication and 99.999% SLA, which lets the application survive a full regional outage without data loss or manual failover. Option B (Global HTTP(S) Load Balancer) is correct because it provides a single global anycast IP, health-check-based backend selection, and automatic traffic redirection to the healthy region when a regional backend fails. Option D (Multi-cluster Ingress) is correct because it is the GKE feature that registers multiple regional GKE clusters as backends of a Global HTTP(S) Load Balancer and performs cross-region failover based on cluster health.

Option C (Regional Cloud SQL) is not appropriate because a regional instance is confined to one region and cannot serve traffic after that region fails. Option E (Cloud NAT) is not relevant because it only provides outbound internet access for private GKE nodes and does not contribute to cross-region failover or traffic redirection.

Exam trap

The trap is assuming that a regional database like Cloud SQL can be made multi-region or that Cloud NAT provides high availability. Candidates must recognize that true multi-region resilience requires globally distributed data and traffic management.

319
MCQmedium

A DevOps team uses Cloud Build to deploy Docker images to GKE. They want to ensure that only images that have passed a vulnerability scan and been signed by a trusted authority can be deployed. Which service should they integrate with Cloud Build and GKE?

A.Artifact Analysis
B.Cloud Security Scanner
C.Cloud Key Management Service
D.Binary Authorization
AnswerD

Binary Authorization enforces deploy-time admission control on GKE, permitting only images with valid attestations from trusted authorities. Cloud Build creates attestations after the vulnerability scan and signing steps, satisfying the stem's requirement that solely scanned, signed images reach the cluster.

Why this answer

Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed to GKE. It integrates with Cloud Build to sign images after vulnerability scanning and with GKE to enforce policies that only allow signed images. This directly meets the requirement of ensuring only scanned and signed images are deployed.

Exam trap

The trap is confusing vulnerability scanning (Artifact Analysis) with enforcement (Binary Authorization). Candidates might think that scanning alone is sufficient, but enforcement requires a policy engine like Binary Authorization.

How to eliminate wrong answers

Option A is wrong because Artifact Analysis provides vulnerability scanning but does not enforce deployment policies or signing. Option B is wrong because Cloud Security Scanner is for scanning web applications, not container images. Option C is wrong because Cloud KMS manages encryption keys but does not enforce deployment policies or image signing by itself.

320
Multi-Selecthard

A company uses Cloud KMS to encrypt sensitive data. They need to ensure that encryption key usage is audited and that keys are rotated automatically every 30 days. Which two actions should they take? (Choose two.)

Select 2 answers
A.Enable Data Access audit logs for the Cloud KMS API
B.Create a Cloud Trigger to manually rotate the key every month
C.Enable Cloud Key Management Service's key usage monitoring
D.Use Cloud External Key Manager to rotate keys externally
E.Enable key rotation on the key by setting a rotation period of 30 days
AnswersA, E

Data Access audit logs record every encrypt/decrypt operation for compliance.

Why this answer

Enabling Data Access audit logs for the Cloud KMS API captures detailed information about every encryption key usage, including who accessed the key, when, and what operation was performed. This meets the auditing requirement by recording all key usage events in Cloud Audit Logs, which can be reviewed for compliance and security analysis.

Exam trap

The trap here is that candidates often confuse 'key rotation' with 'key usage monitoring' or assume that manual triggers or external managers can satisfy the automatic rotation requirement, when in fact Cloud KMS provides a native rotation period setting that must be used.

321
MCQmedium

Refer to the exhibit. A Cloud Storage bucket has this IAM policy. What security recommendation should be made?

A.Remove the `allUsers` member and use signed URLs for public access.
B.Change `allUsers` to `allAuthenticatedUsers` to allow only authenticated users.
C.Enable uniform bucket-level access and update the IAM policy.
D.Remove the `roles/storage.objectViewer` role binding entirely.
AnswerA

Removing `allUsers` eliminates anonymous, unauthenticated access to every object, satisfying the least-privilege constraint. Signed URLs instead grant time-limited, cryptographically authenticated access to specific objects, so public distribution still works without exposing the entire bucket's contents to enumeration or unintended reads.

Why this answer

The IAM policy grants `roles/storage.objectViewer` to `allUsers`, which makes the bucket's objects publicly readable by anyone on the internet. This is a security risk because it allows anonymous access without authentication or logging. The recommended practice is to remove the `allUsers` member and instead use signed URLs (which embed a time-limited access token) to grant temporary, controlled access to specific objects.

Exam trap

Google Cloud often tests the misconception that `allAuthenticatedUsers` is a secure alternative to `allUsers`, but the trap is that it still allows any authenticated identity (including attackers) to access the data, whereas signed URLs provide granular, revocable, and auditable access.

How to eliminate wrong answers

Option B is wrong because changing `allUsers` to `allAuthenticatedUsers` still allows any authenticated Google account (including attackers with a free account) to read the objects, which does not provide fine-grained access control and still exposes the data broadly. Option C is wrong because enabling uniform bucket-level access only ensures that all access is governed by IAM policies rather than ACLs, but it does not address the underlying problem of granting public access via `allUsers`. Option D is wrong because simply removing the role binding without replacing it with a secure access method (like signed URLs) would break all access to the objects, which is not a security recommendation but a denial of service.

322
Multi-Selectmedium

Which TWO statements are true about Google Cloud VPC networks? (Select exactly 2.)

Select 2 answers
A.Each VPC network is regional in scope.
B.By default, no firewall rules are created in a new VPC.
C.Subnets are regional resources and can span zones.
D.VPC Peering allows private RFC 1918 connectivity across VPCs.
E.VPC Peering supports transitive routing.
AnswersC, D

Subnets are regional and each subnet can have IP ranges across zones.

Why this answer

Google Cloud VPC subnets are regional resources that can span multiple zones within the same region. This allows resources in different zones to use the same subnet without requiring additional routing or VPN configuration, providing high availability and fault tolerance within a region.

Exam trap

The trap here is that candidates often confuse VPC scope with subnet scope, assuming VPCs are regional like in AWS, but Google Cloud VPCs are global, and they may also mistakenly believe VPC Peering supports transitive routing, which it explicitly does not.

323
MCQeasy

A small startup wants to deploy a containerized web application that scales automatically and only charges for resources used. They have limited operational experience. Which compute solution should they choose?

A.App Engine Standard Environment with a custom runtime.
B.Google Kubernetes Engine (GKE) with a multi-node pool.
C.Compute Engine with a managed instance group.
D.Cloud Run (fully managed).
AnswerD

Cloud Run is fully managed, scaling container instances to zero when idle, so billing follows actual request usage. It removes cluster and node management, matching the startup's limited operational experience while satisfying automatic scaling and pay-per-use.

Why this answer

Cloud Run (fully managed) is the right choice because it runs containerized applications on a fully managed serverless platform that automatically scales instances up and down (including to zero) based on traffic, and it bills only for the CPU, memory, and request resources actually consumed. This matches the startup's needs: containers, automatic scaling, pay-per-use pricing, and minimal operational overhead since Google manages the underlying infrastructure. App Engine Standard with a custom runtime is more restrictive and less container-native, while GKE with a multi-node pool and Compute Engine with a managed instance group both require the team to manage clusters, nodes, or instances and typically incur costs for provisioned capacity even when idle, which does not fit a low-ops, usage-based model.

324
MCQhard

The exhibit shows a managed instance group configuration. What is the primary purpose of the 'autoHealingPolicies' section?

A.Distribute incoming traffic evenly across the instances.
B.Automatically add more instances when CPU utilization exceeds 60%.
C.Automatically replace instances that are deemed unhealthy based on the health check.
D.Automatically update instances to a new instance template.
AnswerC

Autohealing policies continuously run the specified health check against each instance; any instance failing it is deleted and recreated by the managed instance group, restoring the desired capacity. This directly satisfies the stem's requirement to remediate unhealthy instances automatically, rather than merely scaling or distributing traffic.

Why this answer

The 'autoHealingPolicies' section in a managed instance group configuration is specifically designed to automatically replace instances that are deemed unhealthy based on a configured health check. When a health check probe (e.g., HTTP, TCP, or SSL) fails for a sustained period, the managed instance group terminates the unhealthy instance and creates a new one from the instance template, ensuring the desired number of healthy instances is maintained. This is distinct from autoscaling, which adjusts instance count based on load metrics.

Exam trap

Google Cloud often tests the distinction between 'autohealing' (health-based instance replacement) and 'autoscaling' (metric-based instance count adjustment), causing candidates to confuse the purpose of the 'autoHealingPolicies' section with scaling policies.

How to eliminate wrong answers

Option A is wrong because distributing incoming traffic evenly across instances is the function of a load balancer (e.g., HTTP(S) Load Balancer or Network Load Balancer) and its backend service, not the 'autoHealingPolicies' section of a managed instance group. Option B is wrong because automatically adding instances when CPU utilization exceeds 60% is a function of the 'autoscaling' policy (based on a CPU utilization metric), not the 'autoHealingPolicies' section, which only reacts to health check failures. Option D is wrong because automatically updating instances to a new instance template is achieved through a 'rolling update' or 'canary update' strategy (e.g., using the 'updatePolicy' section), not through 'autoHealingPolicies', which only replaces unhealthy instances with the current template.

325
Multi-Selectmedium

A company is migrating a legacy monolithic application to Google Cloud. They want to minimise changes while taking advantage of cloud benefits. Which TWO migration strategies are most appropriate? (Choose TWO.)

Select 2 answers
A.Re-architect (refactor) into microservices
B.Lift-and-shift (rehost) to Compute Engine
C.Retire the application
D.Replace (repurchase) with SaaS
E.Replatform (e.g., use Cloud SQL instead of self-managed MySQL)
AnswersB, E

Rehosting moves the workload unchanged onto Compute Engine virtual machines, satisfying the stem's constraint of minimising code changes while still gaining cloud elasticity and reduced data-centre overhead. Because no refactoring occurs, the legacy monolith runs as-is, making this the fastest path to cloud benefits during migration.

Why this answer

Option B (Lift-and-shift/rehost to Compute Engine) is correct because it moves the legacy monolith to Google Cloud with minimal code or architectural changes, typically via VM migration tools, letting the company gain cloud benefits like scalability and reduced data-center overhead without a costly rewrite. Option E (Replatform, e.g., using Cloud SQL instead of self-managed MySQL) is correct because it makes targeted, low-effort changes—such as swapping a self-managed database for a managed service—to capture cloud operational benefits while preserving the application's core architecture, which aligns with minimizing changes. Option A (Re-architect into microservices) is not appropriate here because it requires substantial redesign and development effort, contradicting the goal of minimizing changes.

Option C (Retire the application) is wrong because the company is migrating the application, not decommissioning it. Option D (Replace with SaaS) is wrong because repurchasing a SaaS solution would mean abandoning the legacy application rather than migrating it with minimal changes.

Exam trap

PCA often tests the misconception that any cloud migration must involve modernization or refactoring — candidates overlook that rehost and replatform are valid, lower-effort strategies when the question emphasizes minimal change.

326
MCQmedium

A retail company runs its e-commerce checkout service on a single Compute Engine instance in us-central1. The service must survive a zonal outage with minimal data loss and automatic failover, but the operations team is small and does not want to manage replication or failover scripts themselves. Which design should the architect recommend?

A.Deploy the checkout service as a regional managed instance group across three zones in us-central1 behind a global external Application Load Balancer, and store session state in a regional Cloud SQL for PostgreSQL instance with automatic failover.
B.Create a snapshot schedule for the instance boot disk and a Cloud Scheduler job that recreates the VM in a different zone when a Cloud Monitoring uptime check fails.
C.Keep the single instance but attach a regional persistent disk, and add a second instance in another zone that mounts the same disk read-only for reporting.
D.Move the service to two standalone Compute Engine instances in different zones and use a network load balancer with a health check, keeping the database on the original instance's local SSD.
AnswerA

A regional managed instance group spreads instances across three zones and automatically recreates capacity when a zone fails, while the global external Application Load Balancer routes only to healthy backends. A regional Cloud SQL instance maintains a standby in another zone and promotes it automatically, so both compute and data tiers survive a zonal outage without custom failover scripting.

Why this answer

Surviving a zonal outage with minimal data loss and no custom failover logic requires managed, zone-redundant building blocks at every tier. A regional managed instance group combined with a global external Application Load Balancer keeps serving traffic when a zone disappears, and a regional Cloud SQL instance promotes its standby automatically. Together these services remove the need for the small operations team to write or run replication and failover scripts.

Exam trap

The trap here is assuming that a regional persistent disk alone provides automatic failover, when it actually permits only one writer at a time and still requires a manual detach and reattach.

327
MCQhard

A healthcare company must store patient records on Google Cloud. Regulatory requirements mandate that the data encryption keys be generated and stored outside Google Cloud, that the company control key rotation, and that access to the data be denied if the external key is unavailable. The data will be stored in Cloud Storage and BigQuery. Which approach should the architect recommend?

A.Create Cloud KMS keys in a dedicated project and grant the services access to them
B.Encrypt data client-side with a locally stored key before uploading to Cloud Storage and BigQuery
C.Use Google-managed encryption keys and enable default encryption at rest for all services
D.Configure Customer-Managed Encryption Keys by using Cloud KMS with an external key manager via Cloud EKM
AnswerD

Cloud External Key Manager lets Cloud KMS use keys that are generated and stored in an external key management system outside Google Cloud. Access to the data depends on the external key being available, and the company controls rotation, which satisfies all the regulatory constraints for both Cloud Storage and BigQuery.

Why this answer

Cloud External Key Manager allows Cloud KMS to wrap data encryption keys with key material held in an external key management system outside Google Cloud. Because access to the wrapped keys requires the external system, the company controls generation and rotation and can deny access by making the external key unavailable, meeting the regulatory requirements for both Cloud Storage and BigQuery.

Exam trap

The trap here is equating customer-managed Cloud KMS keys with external key custody, when CMEK keys are still generated and stored inside Google Cloud.

328
MCQeasy

Your company has a Service Level Objective (SLO) of 99.9% availability for a web application running on Google Cloud. You want to create an alert that notifies the on-call team when the error budget is being consumed too quickly. Which Google Cloud service should you use?

A.Cloud Logging with a log-based metric and an alerting policy.
B.Cloud Monitoring with an SLO and a burn rate alert.
C.Cloud Monitoring with an alerting policy based on a metric threshold for error rate.
D.Cloud Trace with latency thresholds and alerts.
AnswerB

Cloud Monitoring allows you to define an SLO and create burn rate alerts. Burn rate alerts notify when the error budget is being consumed at a rate that would exhaust it faster than desired. This directly addresses the requirement to alert on rapid error budget consumption.

Why this answer

Cloud Monitoring supports defining SLOs and creating burn rate alerts. Burn rate alerts fire when the rate of error budget consumption is too high, helping teams respond before the budget is exhausted. This is the native, recommended way to alert on SLO violations.

Exam trap

The trap here is thinking that a simple error rate threshold alert is sufficient, but it does not account for the SLO and burn rate, which are essential for proactive alerting.

329
MCQhard

A company uses Cloud Armor to protect an HTTPS Load Balancer. They want to allow traffic only from users who have passed a reCAPTCHA challenge. Cloud Armor supports which feature for this?

A.WAF rules with reCAPTCHA
B.Preconfigured WAF rules
C.Adaptive Protection
D.Rate limiting
AnswerA

Cloud Armor's reCAPTCHA integration is configured through WAF rules using the recaptcha action, which challenges or redirects clients to a reCAPTCHA assessment before allowing traffic to the HTTPS Load Balancer. This enforces the requirement that only users passing the challenge reach the backend.

Why this answer

Cloud Armor supports reCAPTCHA integration through WAF rules that use the 'token.recaptcha_session.score' or 'token.recaptcha_action.score' attributes to allow, deny, or redirect traffic based on the reCAPTCHA assessment score. This is configured as a security policy rule with a reCAPTCHA challenge action, enabling the load balancer to enforce human verification before granting access.

Exam trap

PCA often tests whether candidates confuse Cloud Armor's reCAPTCHA enforcement with Adaptive Protection or preconfigured WAF rules; the key is recognizing that only WAF rules with reCAPTCHA token attributes can enforce human verification.

How to eliminate wrong answers

Option B is wrong because preconfigured WAF rules are OWASP ModSecurity-style signatures (e.g., for SQLi, XSS, LFI) and do not perform reCAPTCHA challenges. Option C is wrong because Adaptive Protection uses ML to detect and mitigate Layer 7 DDoS and application attacks; it does not enforce reCAPTCHA verification. Option D is wrong because rate limiting throttles request volume per client (e.g., per IP or header) and cannot verify that a user passed a reCAPTCHA challenge.

330
MCQhard

A financial services company needs a globally distributed relational database that supports strong consistency across regions, with multi-region writes and sub-10ms latency for most queries. The database must also support SQL and ACID transactions. Which database should they choose?

A.Cloud SQL
B.Firestore
C.Bigtable
D.Cloud Spanner
AnswerD

Cloud Spanner is the only Google Cloud relational database offering synchronous, externally consistent multi-region writes with automatic replication, satisfying the strong consistency and multi-region write constraints. Its TrueTime-based commit timestamps deliver ACID transactions and SQL, while globally distributed reads typically return in single-digit milliseconds.

Why this answer

Cloud Spanner is the only Google Cloud database that offers global distribution, strong consistency, multi-region writes, SQL support, and ACID transactions. Cloud SQL is single-region. Bigtable is NoSQL and does not support SQL or ACID.

Firestore is NoSQL with limited transactional support.

331
MCQhard

A financial services firm is designing a new payment-processing platform on Google Cloud. Regulatory requirements mandate that data never leaves the European Union, that encryption keys are generated and stored on hardware the firm controls inside its own data center, and that the firm can revoke key access instantly. The security team wants to use Cloud KMS but is unsure it meets all three requirements. Which combination of services should the architect recommend?

A.Customer-managed encryption keys (CMEK) stored in a Cloud KMS key ring in europe-west1, with Cloud HSM backing.
B.Cloud External Key Manager (Cloud EKM) with a supported external key manager in the firm's data center, plus organization policy constraints to restrict resource locations.
C.Cloud KMS with CMEK and a key ring in europe-west4, combined with VPC Service Controls perimeters around all data services.
D.Cloud KMS with a multi-region key ring in europe, plus organization policy constraints to restrict resource locations.
AnswerB

Cloud EKM lets Cloud KMS call out to a supported external key manager that the firm operates, so keys are generated and stored on hardware inside its own data center while Google services use them through the KMS interface. If the firm cuts connectivity or disables the external key, Google loses the ability to unwrap data encryption keys, giving effectively instant revocation. Organization policy keeps resources in EU locations.

Why this answer

The three requirements are EU data residency, self-controlled key hardware, and instant revocation. Only an external key manager integration satisfies all three because the keys physically live in the firm's data center and Google must reach out to them for every unwrap operation. Location constraints in organization policy handle the residency requirement, and severing the external key path provides the immediate revocation the security team wants.

Exam trap

The trap here is treating Cloud HSM or CMEK as equivalent to holding keys in your own data center, when Google still operates that hardware.

332
MCQhard

A financial services company is designing a new application on Google Cloud. The application must comply with PCI DSS and internal policies that require strict separation of duties and least privilege. The security team wants to ensure that developers cannot modify production resources, but they need to deploy code frequently. Which approach should the cloud architect recommend to meet these requirements while supporting continuous deployment?

A.Use Google Cloud Deploy to manage deployments. Grant developers the roles/clouddeploy.developer role in the production project, and configure approval gates before production deployment. Developers can approve their own deployments.
B.Use a single Google Cloud project with IAM conditions that restrict developers to only modify resources with a specific label (e.g., env=dev). Grant developers roles/editor, and use a Cloud Build service account with roles/owner to deploy to production.
C.Create separate Google Cloud projects for development and production. Grant developers the roles/editor role in the development project and roles/viewer in the production project. Use Cloud Build with a service account that has the necessary permissions to deploy to production.
D.Implement a CI/CD pipeline using Cloud Build and Artifact Registry. Grant developers the roles/cloudbuild.builds.editor role to trigger builds. Store production deployment credentials in Secret Manager and allow developers to access them.
AnswerC

Separate projects enforce isolation. Developers have editor in dev (can deploy and test) but only viewer in prod (cannot modify). Cloud Build uses a dedicated service account with least privilege to deploy to production, ensuring developers cannot directly modify prod. This meets separation of duties and least privilege while enabling CI/CD through automation.

Why this answer

Separate projects provide strong isolation. Developers with editor in dev can work freely, but viewer in prod prevents direct modifications. Cloud Build with a least-privilege service account automates deployments, so developers cannot directly change production.

This enforces separation of duties and least privilege while enabling frequent deployments via CI/CD.

Exam trap

The trap here is using a single project with IAM conditions or granting developers production roles with approval gates, which may seem sufficient but fails to enforce strict separation of duties and least privilege.

333
MCQeasy

Refer to the exhibit. The output is from `gcloud compute instances describe instance-1 --format=json`. What can you conclude from this output?

A.The instance is billed based on the n1-standard-2 machine type.
B.The instance is using a custom machine type.
C.The instance is using committed use discounts.
D.The instance has a GPU attached.
AnswerA

The JSON output includes the machineType field referencing n1-standard-2, which defines the instance's CPU and memory allocation. Billing for Compute Engine instances derives from the machine type specified at creation, so the exhibited value confirms the instance is charged according to n1-standard-2 pricing.

Why this answer

The output from `gcloud compute instances describe instance-1 --format=json` would include a `machineType` field that specifies the full URL of the machine type, such as `https://www.googleapis.com/compute/v1/projects/.../zones/.../machineTypes/n1-standard-2`. This confirms the instance is using the predefined n1-standard-2 machine type, which has 2 vCPUs and 7.5 GB of memory, and billing is based on that predefined type. The absence of a `custom` suffix or custom CPU/memory values in the machine type field indicates it is not a custom machine type.

Exam trap

Google Cloud often tests the distinction between predefined and custom machine types by hiding the machine type in the `machineType` URL, and candidates mistakenly think any non-standard name implies a custom type, but the key is checking for the `custom-` prefix or explicit CPU/memory fields.

How to eliminate wrong answers

Option B is wrong because a custom machine type would be indicated by a machine type URL ending with `custom-<vCPUs>-<memory>` (e.g., `custom-2-8192`) or by the presence of `custom` in the machine type name, which is not the case for `n1-standard-2`. Option C is wrong because committed use discounts are a billing-level commitment, not visible in the `gcloud compute instances describe` output; they would be shown in billing reports or the `gcloud compute commitments` command, not in instance metadata. Option D is wrong because a GPU attachment would be visible in the `accelerators` field of the instance description, which would list the GPU type and count; its absence means no GPU is attached.

334
MCQhard

A healthcare company stores sensitive patient data in Cloud Storage buckets. The company must ensure that data is encrypted at rest with keys that are automatically rotated every 90 days and that the keys are managed by the company itself, not by Google. The company also needs to maintain full control over key lifecycle and access policies. Which encryption option should the architect recommend?

A.Cloud External Key Manager (Cloud EKM) with keys stored in a third-party HSM.
B.Google-managed encryption keys (GMEK) with default encryption.
C.Customer-managed encryption keys (CMEK) using Cloud KMS with a 90-day rotation schedule.
D.Customer-supplied encryption keys (CSEK) provided with each request.
AnswerC

Customer-managed encryption keys in Cloud KMS allow the company to create and manage keys, set rotation schedules (e.g., every 90 days), and define access policies via IAM. CMEK integrates with Cloud Storage to encrypt data at rest, and the company retains full control over key lifecycle. This meets all requirements: encryption at rest, automatic rotation, and self-management.

Why this answer

Customer-managed encryption keys (CMEK) in Cloud KMS allow the healthcare company to manage its own encryption keys, set a 90-day rotation schedule, and control access via IAM. This satisfies the requirements for encryption at rest, automatic key rotation, and full control over key lifecycle. Other options either do not provide self-management or lack automatic rotation.

Exam trap

The trap here is confusing customer-managed encryption keys (CMEK) with customer-supplied encryption keys (CSEK); CSEK are not stored in Cloud KMS and do not support automatic rotation.

335
MCQmedium

A company uses Cloud Composer to manage Apache Airflow workflows. They want to optimize costs. Which practice is most effective?

A.Configure auto scaling for the Cloud Composer environment
B.Use preemptible VMs for Airflow schedulers
C.Replace Cloud Composer with Cloud Functions for all workflows
D.Use small machine types for all Composer components
AnswerA

Auto scaling adjusts the number of worker nodes to match Airflow workload demand, so idle capacity is not billed during quiet periods. This directly targets the cost optimisation goal without reducing the environment's ability to run scheduled workflows.

Why this answer

Cloud Composer supports autoscaling for its workers, which dynamically adjusts the number of worker pods based on the Airflow task queue depth. This directly optimizes costs by scaling down during low-load periods and scaling up only when needed, avoiding over-provisioning.

Exam trap

The trap here is that candidates often assume preemptible VMs are always the best cost-saving measure, but they fail to recognize that Airflow schedulers and other critical components require persistent, reliable compute resources, making autoscaling a safer and more effective optimization.

How to eliminate wrong answers

Option B is wrong because preemptible VMs cannot be used for Airflow schedulers; schedulers must be reliable and stateful, and preemptible VMs can be terminated at any time, causing workflow failures. Option C is wrong because Cloud Functions is not a replacement for Cloud Composer; Cloud Functions is designed for event-driven, short-lived tasks, not for orchestrating complex, long-running, or dependency-heavy workflows that Airflow handles. Option D is wrong because using small machine types for all components, especially the scheduler and database, can lead to performance bottlenecks, task queuing, and failures, ultimately increasing costs due to retries and delays.

336
MCQmedium

A company runs batch analytics workloads each night on Compute Engine VMs. The workloads are fault-tolerant and can be interrupted. The finance team wants to reduce compute costs. Which Compute Engine pricing model should they use?

A.Committed use discounts (1-year or 3-year)
B.Preemptible VMs
C.Sustained use discounts
D.Sole-tenant nodes
AnswerB

Preemptible VMs suit fault-tolerant batch jobs because they cost up to 80% less than standard instances, though Compute Engine may terminate them within 24 hours. Since the nightly analytics workloads can be interrupted without harm, this discount directly satisfies the finance team's cost-reduction constraint.

Why this answer

Preemptible VMs are short-lived, heavily discounted Compute Engine instances (up to ~80% off) that can be terminated by Google at any time with a 30-second notice. They are ideal for fault-tolerant, interruptible batch workloads like nightly analytics jobs, which is exactly the scenario described.

Exam trap

PCA often tests the difference between sustained use discounts (automatic, for long-running VMs) and committed use discounts (contractual, for steady-state) versus preemptible/Spot VMs (for interruptible workloads) — candidates frequently pick CUDs when the workload is clearly interruptible.

How to eliminate wrong answers

Option A is wrong because committed use discounts require a 1- or 3-year commitment and are best for steady-state, always-on workloads — not interruptible nightly batch jobs. Option C is wrong because sustained use discounts apply automatically to long-running VMs that run for a significant portion of the month; nightly batch jobs do not run long enough to earn meaningful SUDs. Option D is wrong because sole-tenant nodes are for physical isolation and compliance/licensing requirements, and they are more expensive, not a cost-reduction mechanism.

337
Multi-Selectmedium

Which TWO are best practices when designing a VPC network for a multi-tier application in Google Cloud?

Select 2 answers
A.Disable VPC Flow Logs to reduce cost.
B.Create separate subnets for each application tier.
C.Use firewall rules to restrict traffic between tiers to only necessary ports.
D.Use a single subnet for all tiers to simplify IP management.
E.Rely on the default priority of firewall rules to ensure proper ordering.
AnswersB, C

Subnets allow segmentation and granular firewall rules.

Why this answer

Creating separate subnets for each application tier (e.g., web, application, database) allows you to apply granular firewall rules and routing policies per tier. This segmentation improves security by isolating traffic between tiers and aligns with Google Cloud's best practices for multi-tier architectures. It also simplifies network troubleshooting and scaling by keeping each tier's IP space distinct.

Exam trap

The trap here is that candidates assume a single subnet simplifies management (Option D) or that disabling flow logs is a harmless cost-saving measure (Option A), but the exam expects you to prioritize security and observability over minor cost savings or administrative convenience.

338
MCQeasy

An organization wants to ensure that only container images signed by an authorized CI/CD pipeline can be deployed to their GKE clusters. Which GCP service should they use?

A.Artifact Registry
B.Binary Authorization
C.Cloud Security Scanner
D.Cloud Build
AnswerB

Binary Authorization enforces deploy-time attestations, admitting only images whose signatures originate from your authorised CI/CD attestor. This directly satisfies the stem's constraint that solely pipeline-signed container images reach GKE clusters, blocking unsigned or tampered images before admission.

Why this answer

Binary Authorization is the GCP service that enforces deploy-time attestation, ensuring that only container images signed by trusted authorities (such as an authorized CI/CD pipeline) can be deployed to GKE clusters. It uses attestors and attestations created via Container Analysis, and policies can be set to allow only images with valid attestations. This directly satisfies the requirement to restrict deployments to pipeline-signed images.

Exam trap

PCA often tests whether candidates confuse Artifact Registry (storage) with Binary Authorization (admission control); the trap is picking Artifact Registry because it sounds like it controls image provenance, when only Binary Authorization enforces signed-image deployment.

How to eliminate wrong answers

Option A is wrong because Artifact Registry is a container image repository for storing and managing images; it does not enforce deployment admission control or signature verification. Option C is wrong because Cloud Security Scanner (now Web Security Scanner) scans App Engine, Compute, and GKE web apps for vulnerabilities; it does not gate image deployment. Option D is wrong because Cloud Build is a CI/CD service that builds images; while it can sign images, it does not enforce that only signed images are deployed to GKE.

339
Multi-Selectmedium

A company wants to set up monitoring and alerting for their application running on GKE. They need to receive alerts via email and also trigger an automated remediation workflow. Which TWO components should they use? (Choose two.)

Select 2 answers
A.Notification channels (email)
B.Alerting policies
C.Cloud Shell
D.Cloud Logging
E.Pub/Sub
AnswersA, B

Notification channels define the delivery mechanism, so an email channel satisfies the requirement to receive alerts by email. Alerting policies detect the condition, but the channel is what actually routes the notification to the recipient's inbox.

Why this answer

Option A, Notification channels (email), is correct because in Cloud Monitoring a notification channel defines the destination and delivery mechanism for alerts, and an email-type channel is exactly what is needed to receive alert notifications via email. Option B, Alerting policies, is correct because alerting policies define the conditions (metrics, thresholds, filters) that determine when an alert fires and which notification channels are used, making them the core component for monitoring and alerting on the GKE application. Together, an alerting policy detects the condition and routes it to the email notification channel, satisfying the email alerting requirement.

Option C, Cloud Shell, is just an interactive command-line environment and provides no monitoring or alerting capability. Option D, Cloud Logging, stores and queries logs but does not itself define alert conditions or deliver email notifications. Option E, Pub/Sub, can be used as a notification channel for automation, but it is not required to receive email alerts and is not one of the two components needed for the stated email alerting requirement.

Exam trap

PCA often tests the distinction between the alerting policy (the 'what/when') and the notification channel (the 'where'), and candidates mistakenly pick Pub/Sub or Cloud Logging as the alerting component instead of recognizing them as transport/storage layers.

340
MCQeasy

A startup is deploying a new web application on Google Cloud. They want to use a fully managed, serverless platform that automatically scales and requires no infrastructure management. The application is containerized and listens on HTTP. Which Google Cloud service should they use?

A.Cloud Run
B.Google Kubernetes Engine (GKE)
C.Compute Engine
D.App Engine flexible environment
AnswerA

Cloud Run is a fully managed serverless platform that runs containerized applications. It automatically scales based on traffic, including scaling to zero when there is no traffic. It abstracts away all infrastructure management. It supports HTTP and gRPC, making it ideal for this web application. This meets all requirements.

Why this answer

Cloud Run is a fully managed serverless platform that runs containers and automatically scales, including to zero. It requires no infrastructure management, making it ideal for a startup wanting to deploy a containerized web application. Compute Engine and GKE require more management, and App Engine flexible environment is not fully serverless.

Exam trap

The trap here is confusing GKE Autopilot or App Engine flexible with a fully serverless platform that scales to zero and requires no infrastructure management.

341
MCQhard

A financial services company runs a payment API on Compute Engine behind an internal passthrough Network Load Balancer. The compliance team requires that all administrative actions on the project be attributable to a named human, that production changes be reviewed before taking effect, and that no single engineer can delete the production database. Which combination of Google Cloud controls should the cloud architect implement?

A.Require all engineers to use hardware security keys for two-factor authentication, enable Identity-Aware Proxy for SSH access to instances, and create an alerting policy that notifies the security team when the database is deleted.
B.Assign least-privilege predefined roles to engineers, require all production changes to go through a CI/CD pipeline that uses a dedicated service account in a separate project, and protect the production database with a resource-level deny policy and separation of duties.
C.Grant the Project Owner role to all senior engineers, enable Cloud Audit Logs for Admin Activity, and require them to use a shared break-glass account for emergency changes.
D.Enable VPC Service Controls around the production project, grant engineers the Editor role, and configure Cloud Logging sinks to export audit logs to a separate project for long-term retention.
AnswerB

Least-privilege roles limit what each engineer can do, and a pipeline with a dedicated service account in a separate project ensures changes are reviewed and executed by automation rather than directly by humans. A deny policy on the database prevents even privileged users from deleting it, and separation of duties keeps one person from both proposing and approving. This gives attribution, review, and protection.

Why this answer

The compliance demands map to preventive controls: least privilege to limit permissions, a reviewed CI/CD pipeline with a dedicated service account in a separate project to enforce change review and attribution, and a resource-level deny policy plus separation of duties to stop any one engineer from deleting the production database. Detective measures like audit logging and alerting are useful but insufficient on their own. The combination of IAM restrictions, automation, and deny policies satisfies all three requirements.

Exam trap

The trap here is treating detective controls such as audit log exports or deletion alerts as sufficient, when the compliance requirements demand preventive controls that stop unauthorized or unreviewed actions before they occur.

342
MCQmedium

A healthcare company is deploying a new patient portal on Google Cloud. The portal must be accessible globally with low latency, must survive a single region failure, and must use a single anycast IP address. The backend runs on managed instance groups in two regions. Which Google Cloud product should the architect use to expose the service?

A.Global external HTTP(S) Load Balancing
B.Internal HTTP(S) Load Balancer with global access
C.Regional external TCP/SSL proxy load balancer
D.Cloud DNS with geo-routing and health checks
AnswerA

Global external HTTP(S) Load Balancing provides a single anycast IP address, terminates HTTP(S) at Google's edge, and routes users to the closest healthy backend. It supports multi-region managed instance groups and automatically fails over if a region becomes unhealthy. This meets the global low-latency, single IP, and cross-region survivability requirements for the patient portal without additional DNS-based failover mechanisms.

Why this answer

Global external HTTP(S) Load Balancing is the only option that provides a single global anycast IP, edge termination, and automatic multi-region failover for HTTP(S) workloads. Regional proxies lack global anycast, Cloud DNS geo-routing introduces DNS caching delays and multiple IPs, and internal load balancing is not internet-facing. The chosen design satisfies global low latency and region-failure survivability.

Exam trap

The trap here is assuming that Cloud DNS geo-routing with health checks can replace a global load balancer, when DNS TTLs and client caching prevent instant failover and do not provide a single anycast IP.

343
MCQmedium

A logistics company runs a latency-sensitive inventory service on Compute Engine in us-central1. The service writes to a Cloud SQL for MySQL instance and reads from a Memorystore for Redis cache. The architect must design for a zone failure in us-central1 with minimal data loss and automatic failover, without changing the application's connection strings. Which design should the architect choose?

A.Deploy the service in a managed instance group across three zones, use a Cloud SQL for MySQL regional instance with a primary and standby, and configure Memorystore for Redis in Standard Tier with automatic failover.
B.Deploy the service in a multi-region managed instance group, use Cloud Spanner instead of Cloud SQL, and use Memorystore for Redis in Basic Tier.
C.Deploy the service across two zones, use a Cloud SQL for MySQL regional instance, and run a self-managed Redis cluster on Compute Engine with Sentinel.
D.Deploy the service in a zonal managed instance group, use a Cloud SQL for MySQL zonal instance, and enable Memorystore for Redis Basic Tier with read replicas.
AnswerA

A regional managed instance group spreads VMs across zones so a single zone failure does not take down the service. A Cloud SQL regional instance maintains a standby in another zone and fails over automatically with minimal data loss. Memorystore for Redis Standard Tier provides a replica and automatic failover. The application connects through stable endpoints, so no connection string changes are needed.

Why this answer

Spreading the service across zones with a regional managed instance group, pairing it with a Cloud SQL regional instance that has a standby in another zone, and using Memorystore Standard Tier with automatic failover together address zone failure at every tier. Each component exposes stable endpoints, so the application keeps its existing connection strings.

Exam trap

The trap here is assuming that read replicas or a multi-zone application tier alone provide high availability, when the database and cache tiers must also have automatic failover.

344
Multi-Selectmedium

You are designing a disaster recovery plan for a critical application running on GKE. You need to back up the cluster's state and application data. Which TWO services should you use together? (Choose 2)

Select 2 answers
A.Velero (formerly Heptio Ark)
B.Pub/Sub
C.Cloud SQL
D.Filestore
E.Cloud Storage
AnswersA, E

Velero backs up Kubernetes cluster state and persistent volume data, capturing the GKE resources and application data the plan requires. It satisfies the cluster-state constraint by exporting API objects and volume snapshots together for later restore.

Why this answer

Velero (A) is correct because it is the standard open-source tool for backing up and restoring Kubernetes cluster state, including namespaces, deployments, services, and persistent volume snapshots, making it ideal for GKE disaster recovery. Cloud Storage (E) is correct because Velero stores its backups and volume snapshots in an object storage backend, and Google Cloud Storage is the native, durable, and highly available GCS bucket option for GKE environments. Together, Velero orchestrates the backup and restore operations while Cloud Storage provides the persistent, off-cluster repository for those backups.

Pub/Sub (B) is a messaging service, not a backup or storage solution, so it does not back up cluster state or application data. Cloud SQL (C) is a managed relational database service that could host application data but does not back up GKE cluster state, and Filestore (D) is a managed NFS file share for persistent volumes, not a backup repository for cluster-wide state.

Exam trap

The trap is picking GCP-native services like Cloud SQL or Filestore because they sound data-related, when the question is specifically about backing up GKE cluster state and application data, which requires a Kubernetes-aware tool plus object storage.

345
MCQhard

A financial services firm must design a data residency solution. Regulators require that customer personal data never leaves the country of origin, but the firm wants to use a single centralized analytics project for aggregated, non-personal reporting. Which Google Cloud architecture best satisfies both requirements?

A.Deploy a Shared VPC host project spanning multiple regions and use firewall rules to restrict which regions instances can reach, keeping all data logically within one network.
B.Store all data in a multi-region Cloud Storage bucket and rely on customer-managed encryption keys to satisfy residency, aggregating data in the central project.
C.Use a global BigQuery dataset with column-level security and authorized views, then copy personal data into the central analytics project for processing.
D.Store personal data in regional Cloud Storage buckets and BigQuery datasets located only in the required country, and use VPC Service Controls perimeters to prevent data egress, while aggregating anonymized metrics into the central analytics project.
AnswerD

This design keeps personal data in regionally scoped resources within the mandated country, uses VPC Service Controls to block egress of that data across perimeter boundaries, and only moves aggregated, anonymized metrics to the centralized project. It directly satisfies the residency rule while still enabling centralized reporting on non-personal data.

Why this answer

Data residency is about where bytes are physically stored and replicated, so the architecture must pin personal data to regionally scoped datasets and buckets in the required country and use VPC Service Controls to stop egress. Encryption keys and network topology do not constrain physical location. Only anonymized aggregates may cross into the central analytics project.

Exam trap

The trap here is believing that customer-managed encryption keys or column-level security satisfy data residency, when only the physical location of the stored data and enforced egress controls do.

346
MCQmedium

A developer notices that web-server-1 is preemptible. They want to ensure their application remains available even if this instance is terminated. What should they do?

A.Modify the instance's preemptible flag to false.
B.Create a managed instance group for web-server-1 and set an autoscaler.
C.Create a load balancer pointing to web-server-1's external IP.
D.Create a snapshot schedule for web-server-1.
AnswerB

A managed instance group replaces the single preemptible VM with multiple identical instances, so termination of one does not cause an outage. The autoscaler maintains capacity and recreates instances automatically, satisfying the availability requirement despite preemption.

Why this answer

A managed instance group (MIG) with an autoscaler ensures that if the preemptible instance is terminated, the MIG automatically recreates it to maintain the desired number of instances. This provides resilience against preemption by restoring capacity without manual intervention. The load balancer can then distribute traffic across healthy instances in the group.

Exam trap

Google Cloud often tests the misconception that a load balancer alone provides high availability, but without a managed instance group to recreate terminated instances, the load balancer has no healthy backends to route traffic to.

How to eliminate wrong answers

Option A is wrong because modifying the preemptible flag to false would make the instance a standard (non-preemptible) instance, but this does not address availability during termination—it only prevents future preemption, and the instance could still fail for other reasons. Option C is wrong because a load balancer pointing to a single instance's external IP does not provide high availability; if the instance is terminated, the load balancer has no healthy backend and traffic is lost. Option D is wrong because a snapshot schedule only backs up persistent disks, it does not recreate the instance or maintain application availability after termination.

347
MCQeasy

A company needs to ensure that all data stored in Cloud Storage is encrypted at rest with keys that they control and can rotate on demand. They also need to maintain an audit trail of key usage. Which Google Cloud service should they use?

A.Google-managed encryption keys
B.Customer-managed encryption keys (CMEK) in Cloud KMS
C.Customer-supplied encryption keys (CSEK)
D.Cloud HSM
AnswerB

CMEK in Cloud KMS allows the company to create, rotate, and manage their own keys. Cloud KMS logs key usage through Cloud Audit Logs, providing an audit trail. This option satisfies both the control and audit requirements for data at rest in Cloud Storage.

Why this answer

Customer-managed encryption keys (CMEK) in Cloud KMS give the company full control over key creation, rotation, and usage. Cloud KMS integrates with Cloud Audit Logs to record all key operations, providing the required audit trail. Google-managed keys offer no customer control, CSEK lack integrated auditing, and Cloud HSM is a backing option for CMEK rather than a standalone solution.

Exam trap

The trap here is confusing CSEK with CMEK; CSEK are not stored in Cloud KMS and do not provide an audit trail.

348
Multi-Selectmedium

A company wants to migrate a large on-premises relational database to Cloud SQL for PostgreSQL with minimal downtime. They need to ensure data consistency during the migration. Which THREE steps should they take?

Select 3 answers
A.Set up a VPN or Cloud Interconnect between on-premises and GCP
B.Create a read replica of the source database in Cloud SQL
C.Switch traffic to Cloud SQL immediately after the initial import
D.Use Database Migration Service to start continuous replication from the source
E.Perform an initial export of the source database and import into Cloud SQL
AnswersA, D, E

A VPN or Cloud Interconnect provides the private, stable network path required for continuous replication traffic between the on-premises source and Google Cloud. Without it, Database Migration Service cannot stream changes reliably, undermining the minimal-downtime and consistency goals.

Why this answer

Option A is correct because a reliable, low-latency private network path via Cloud VPN or Cloud Interconnect is required for the initial bulk data transfer and for Database Migration Service's continuous replication to keep the on-premises source and Cloud SQL in sync with minimal downtime. Option D is correct because Database Migration Service (DMS) for PostgreSQL supports continuous replication (change data capture) from the on-premises source to Cloud SQL, which is the key mechanism for minimizing downtime and maintaining data consistency until cutover. Option E is correct because performing an initial export/import (for example, using pg_dump and pg_restore) seeds Cloud SQL with the existing dataset before continuous replication begins, so DMS only has to apply ongoing changes rather than the entire database.

Option B is not appropriate because Cloud SQL read replicas replicate from a Cloud SQL primary, not from an external on-premises PostgreSQL source, so they cannot serve as the migration replication mechanism. Option C is not appropriate because switching traffic immediately after the initial import would cause data written to the source during and after the import to be lost, breaking consistency; traffic should only be cut over after replication has caught up and the systems are synchronized.

349
Multi-Selectmedium

A company runs a stateful workload on Compute Engine with regional persistent disks (PD). They need to implement a disaster recovery (DR) plan with a Recovery Point Objective (RPO) of less than 1 hour and Recovery Time Objective (RTO) of less than 4 hours. Which THREE steps should they include in their DR plan? (Choose three.)

Select 3 answers
A.Take snapshots of the persistent disk every 30 minutes and copy them to a Cloud Storage bucket in another region
B.Create a snapshot schedule for the persistent disk every 4 hours
C.Create a custom machine image of the instance and store it in a Cloud Storage bucket in the DR region
D.Use regional persistent disks to automatically replicate data to a second zone
E.Test the failover procedure quarterly to validate RTO and RPO
AnswersA, C, E

Correct: meets RPO and protects against regional failure.

Why this answer

Taking snapshots every 30 minutes meets the RPO of less than 1 hour. By copying these snapshots to a Cloud Storage bucket in another region, you ensure data is available in a DR region for recovery, which is essential for cross-region disaster recovery.

Exam trap

The trap here is confusing zonal replication (regional PD) with cross-region disaster recovery; regional PDs only protect against zonal failures, not regional outages, so they cannot meet a cross-region DR requirement.

350
MCQeasy

A startup wants to grant a new employee read-only access to view all Compute Engine instances in a project. What is the minimum IAM role they should assign?

A.roles/owner
B.roles/compute.viewer
C.roles/iam.securityReviewer
D.roles/compute.admin
AnswerB

roles/compute.viewer grants read-only permission to list and get Compute Engine instances, resources, and related metadata across the project. It satisfies the least-privilege requirement without granting the modify or delete capabilities included in broader roles such as compute.admin.

Why this answer

The roles/compute.viewer role grants read-only access to Compute Engine resources, including the ability to list and view instances, without allowing modifications. This is the minimum IAM role that satisfies the requirement for read-only access to all Compute Engine instances in a project, as it provides the necessary permissions (e.g., compute.instances.list, compute.instances.get) without granting broader project-level or write permissions.

Exam trap

The trap here is that candidates may confuse roles/compute.viewer with roles/iam.securityReviewer, thinking the latter provides broader read access, but it lacks the specific Compute Engine permissions needed to view instances.

How to eliminate wrong answers

Option A is wrong because roles/owner grants full access to all resources in the project, including the ability to modify and delete instances, which far exceeds the required read-only access and violates the principle of least privilege. Option C is wrong because roles/iam.securityReviewer provides read access to IAM policies and security-related resources, but does not include the compute.instances.list or compute.instances.get permissions needed to view Compute Engine instances. Option D is wrong because roles/compute.admin grants full control over Compute Engine resources, including create, update, and delete operations, which is more permissive than the required read-only access.

351
MCQeasy

An organization requires that only container images signed by a trusted authority can be deployed on Google Kubernetes Engine (GKE). Which Google Cloud service should they implement?

A.Artifact Registry
B.Binary Authorization
C.Secret Manager
D.Cloud Deploy
AnswerB

Binary Authorization enforces deploy-time attestation on GKE, admitting only container images whose signatures match trusted attestors. This directly satisfies the requirement that solely images signed by a trusted authority can be deployed, blocking unsigned or tampered images before they reach the cluster.

Why this answer

Binary Authorization is a Google Cloud service that enforces deploy-time policies on GKE, allowing only container images signed by trusted authorities to be deployed. It integrates with Container Analysis and attestations to verify signatures before admission.

Exam trap

PCA often tests the confusion between Artifact Registry (storage) and Binary Authorization (policy enforcement), causing candidates to pick the repository service when the requirement is signature-based admission control.

How to eliminate wrong answers

Option A is wrong because Artifact Registry is a repository for storing and managing container images and packages; it does not enforce signing or admission policies. Option C is wrong because Secret Manager stores sensitive data like API keys and passwords; it has no role in image signing or deployment admission. Option D is wrong because Cloud Deploy is a continuous delivery service for deploying to GKE and other targets; it orchestrates deployments but does not itself enforce image signature verification.

352
MCQhard

An organization uses Cloud Functions (2nd gen) for event-driven processing. They notice that some functions fail with 'memory limit exceeded' errors during peak load. The function processes messages from Pub/Sub and writes to Firestore. What should they do to improve reliability without sacrificing throughput?

A.Increase the maximum number of concurrent function instances.
B.Increase the memory allocated to the Cloud Function.
C.Enable Pub/Sub batching to reduce the number of function invocations.
D.Split the function into multiple smaller functions, each handling a subset of the data.
AnswerB

Memory limit exceeded errors mean the function's allocated memory is exhausted during peak concurrency. Raising the memory allocation gives each instance more headroom to process Pub/Sub messages and write to Firestore, restoring reliability while preserving throughput, since Cloud Functions scales instances independently of the memory setting.

Why this answer

The 'memory limit exceeded' error indicates that the function's allocated memory is insufficient for the workload during peak load. Increasing the memory allocation (Option B) directly resolves this by providing more RAM for processing larger messages or concurrent operations, without altering the invocation pattern or throughput. Cloud Functions (2nd gen) allow memory to be set up to 32 GiB, and this change does not reduce the number of events processed per second.

Exam trap

Google Cloud often tests the misconception that scaling out (more instances) solves memory issues, but the trap here is that memory limits are per-instance, so only increasing the per-instance memory allocation directly resolves the error.

How to eliminate wrong answers

Option A is wrong because increasing the maximum number of concurrent instances does not address the per-instance memory limit; it may actually worsen the problem by allowing more instances to hit the same memory ceiling simultaneously. Option C is wrong because Pub/Sub batching reduces the number of function invocations but does not increase the memory available per invocation; it could also increase latency and does not fix the root cause of memory exhaustion. Option D is wrong because splitting the function into multiple smaller functions does not increase the memory per function instance; it adds complexity and may reduce throughput due to additional overhead, without guaranteeing that each smaller function avoids memory limits.

353
MCQhard

A healthcare organization is storing sensitive patient data in Cloud Storage. They need to ensure that all objects are encrypted with a key managed by their on-premises HSM. Which encryption approach should they use?

A.Use Customer-Supplied Encryption Keys (CSEK) and store the key in a Secret Manager accessible only from the on-premises HSM.
B.Use Cloud External Key Manager (EKM) with a key hosted on the on-premises HSM.
C.Use Customer-Managed Encryption Keys (CMEK) with a Cloud KMS key that is generated from the on-premises HSM.
D.Encrypt each object client-side with a key from the on-premises HSM before uploading to Cloud Storage.
AnswerB

Cloud External Key Manager lets Cloud Storage use a customer-managed key held in the on-premises HSM, so the key never leaves the organisation's hardware. This satisfies the requirement that encryption keys remain managed by the on-premises HSM.

Why this answer

Cloud External Key Manager (EKM) allows you to use an external key management system, such as an on-premises HSM, to manage encryption keys for Google Cloud services. This approach meets the requirement because the key never leaves the HSM, and Cloud Storage uses the key via the EKM integration, ensuring the organization retains full control over the key lifecycle.

Exam trap

In Google PCA, the trap here is that candidates confuse CMEK with EKM: CMEK keys are stored in Cloud KMS, not on an external HSM. EKM allows using an external key manager like an on-premises HSM.

How to eliminate wrong answers

Option A is wrong because Customer-Supplied Encryption Keys (CSEK) require you to supply the raw key material with each API call, and storing the key in Secret Manager does not keep it exclusively on the on-premises HSM; the key must be provided to Google Cloud, which violates the requirement of key management solely by the on-premises HSM. Option C is wrong because Customer-Managed Encryption Keys (CMEK) use Cloud KMS to generate and manage the key, and while you can import a key from an on-premises HSM, the key is then stored and managed within Cloud KMS, not exclusively on the on-premises HSM. Option D is wrong because client-side encryption before upload does not use Cloud Storage's native encryption integration; it requires the organization to manage encryption and decryption outside of Cloud Storage, which is not the same as ensuring Cloud Storage encrypts objects with a key managed by the on-premises HSM.

354
MCQhard

A company is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that each microservice can only communicate with specific other microservices, and they need to enforce this at the network level. They also want to minimize operational overhead. Which approach should they use?

A.Configure VPC firewall rules to allow or deny traffic between GKE nodes.
B.Use Kubernetes NetworkPolicies to define ingress and egress rules between pods.
C.Use Google Cloud Armor security policies to restrict traffic between services.
D.Implement a service mesh like Istio to manage service-to-service communication.
AnswerB

Kubernetes NetworkPolicies allow you to specify which pods can communicate with each other based on labels and namespaces. They are enforced by the container network interface (CNI) plugin, such as Calico, which is available in GKE. This approach provides fine-grained control at the pod level and is native to Kubernetes, minimizing operational overhead compared to custom solutions.

Why this answer

Kubernetes NetworkPolicies are the native, low-overhead way to enforce pod-level network segmentation in GKE. They allow you to define which pods can communicate based on labels and namespaces, and they are enforced by the CNI plugin. This meets the requirement for fine-grained control with minimal operational effort compared to a service mesh or node-level firewall rules.

Exam trap

The trap here is assuming that VPC firewall rules can provide pod-level isolation, but they operate at the node level and cannot distinguish between pods.

355
MCQmedium

A media company stores video files in Cloud Storage for streaming. Infrequently accessed videos older than 90 days are currently in Standard storage. To reduce costs, they want to automatically move these files to a lower-cost storage class and delete them after 3 years. Which configuration should they use?

A.Configure a Pub/Sub notification on object changes and process via Dataflow.
B.Use gsutil rewrite command with -s option manually for each file.
C.Use a lifecycle rule with condition 'age > 90 days' to set storage class to Nearline, and another rule with 'age > 1095 days' to delete.
D.Create a Cloud Function that moves objects monthly using a cron job.
AnswerC

Object Lifecycle Management transitions objects between storage classes and deletes them based on age conditions, applied automatically without manual intervention. Setting Nearline at 90 days and deletion at 1095 days matches both the cost-reduction and three-year retention requirements for the infrequently accessed videos.

Why this answer

Cloud Storage lifecycle rules are the native, automated way to transition objects between storage classes and delete them based on age. A rule with condition 'age > 90 days' setting storage class to Nearline (or Coldline) reduces cost for infrequent access, and a second rule with 'age > 1095 days' (3 years) deletes the objects. This is declarative, server-side, and requires no custom code.

Exam trap

PCA often tests whether candidates recognize that lifecycle rules are the built-in, automated solution for storage class transitions and deletions, rather than custom code or manual commands.

How to eliminate wrong answers

Option A is wrong because Pub/Sub + Dataflow is an event-driven processing pipeline, not a lifecycle management solution; it adds complexity and cost without providing automatic storage class transitions or deletions. Option B is wrong because gsutil rewrite with -s manually changes storage class per file, which is not automated and does not handle deletion. Option D is wrong because a Cloud Function with a cron job is a custom, maintenance-heavy approach that duplicates functionality already provided by lifecycle rules.

356
MCQeasy

A company uses Cloud Spanner for a global financial application. They experience increased latency and transaction aborts during peak hours. Which measure should they take first to improve reliability?

A.Increase the number of nodes in the Spanner instance.
B.Reduce the number of indexes on frequently updated columns.
C.Optimize transactions to reduce lock contention.
D.Use interleaved tables to co-locate related data.
AnswerC

Reducing lock contention directly addresses the transaction aborts and latency spikes. Cloud Spanner aborts transactions when locks conflict, so shortening transactions and ordering reads and writes to minimise overlapping access lowers abort rates and improves throughput during peak load.

Why this answer

Transaction aborts and latency in Cloud Spanner are most commonly caused by lock contention during peak hours. By optimizing transactions—such as reducing their scope, using read-only transactions where possible, and avoiding hot-spot writes—you directly address the root cause of contention without incurring additional cost or schema changes. This aligns with Google's best practices for Spanner reliability.

Exam trap

Google Cloud often tests the misconception that scaling nodes (Option A) is the universal fix for performance issues, but the trap here is that Spanner's horizontal scaling does not resolve lock contention—it only increases parallelism, which can worsen contention if transactions are not optimized.

How to eliminate wrong answers

Option A is wrong because increasing nodes primarily improves throughput and storage capacity, not latency or abort rates caused by lock contention; adding nodes can even increase distributed transaction overhead. Option B is wrong because reducing indexes on frequently updated columns may reduce write amplification but does not address the immediate issue of lock contention and aborts; indexes are not the primary cause of transaction conflicts. Option D is wrong because interleaved tables co-locate parent-child rows for faster joins and lower latency, but they do not reduce lock contention; in fact, they can increase contention if the parent row becomes a hot spot.

357
MCQeasy

A developer wants to monitor a custom application metric from their application running on GKE. What should they use?

A.Cloud Logging
B.Cloud Trace
C.Cloud Debugger
D.Cloud Monitoring custom metrics API
AnswerD

Cloud Monitoring's custom metrics API accepts user-defined time series from GKE workloads, satisfying the requirement to monitor an application-specific metric rather than built-in system telemetry. The developer writes metric descriptors and time-series data via the API, which Cloud Monitoring then charts and alerts on.

Why this answer

Cloud Monitoring custom metrics API (option D) is the correct choice because it allows a developer to push custom application-specific metrics (e.g., request latency, queue depth) from a GKE pod using the `custom.googleapis.com` metric domain. This integrates directly with Cloud Monitoring for alerting and dashboards, whereas Cloud Logging is for log data, not metrics.

Exam trap

The trap here is that candidates confuse Cloud Logging (for logs) with Cloud Monitoring (for metrics), or assume that Cloud Trace can handle custom metrics because it deals with application performance data.

How to eliminate wrong answers

Option A is wrong because Cloud Logging ingests log entries (text-based events), not numeric metric data points; it cannot be used to monitor custom application metrics like counters or gauges. Option B is wrong because Cloud Trace is a distributed tracing system for latency analysis of requests, not for publishing custom numeric metrics. Option C is wrong because Cloud Debugger is used for inspecting application state at specific code points without stopping the app, not for collecting or monitoring time-series metrics.

358
MCQmedium

Your company plans to connect an on-premises data center to Google Cloud with a Dedicated Interconnect. You need to ensure high availability for the connection. What is the minimum configuration required to meet a 99.99% SLA for Dedicated Interconnect?

A.Two Dedicated Interconnect circuits, each in a different edge availability domain, with a Cloud Router for each connection
B.A single Dedicated Interconnect circuit with a Cloud Router configured for BGP advertisements
C.One Dedicated Interconnect circuit and one Partner Interconnect connection as a backup
D.One Dedicated Interconnect circuit with two VLAN attachments on the same circuit
AnswerA

Two circuits in separate edge availability domains give physical path redundancy, and a Cloud Router per connection satisfies the topology requirement for the 99.99% Dedicated Interconnect SLA. A single circuit or shared router only reaches 99.9%.

Why this answer

To achieve the 99.99% availability SLA for Dedicated Interconnect, Google requires at least two Dedicated Interconnect connections in two different edge availability domains (metro availability zones), each terminating on a separate Cloud Router. This topology ensures that a single circuit or router failure does not take down connectivity. The 99.99% SLA is explicitly tied to this redundant, diverse-path configuration.

Exam trap

The trap is assuming that any two connections (e.g., one Dedicated plus one Partner, or two VLAN attachments on one circuit) satisfy the redundancy requirement; the exam expects you to know that the 99.99% SLA specifically requires two Dedicated Interconnect circuits in different edge availability domains with separate Cloud Routers.

How to eliminate wrong answers

Option B is wrong because a single Dedicated Interconnect circuit with one Cloud Router provides only the 99.9% SLA — there is a single point of failure at both the circuit and router level. Option C is wrong because mixing one Dedicated Interconnect with one Partner Interconnect does not meet the documented topology for the 99.99% Dedicated Interconnect SLA; the SLA tiers are defined per product and per redundancy configuration, and this hybrid does not qualify. Option D is wrong because two VLAN attachments on the same physical circuit still share the same circuit and edge availability domain, so a circuit failure takes down both attachments — this is not redundancy at the physical layer.

359
Multi-Selecteasy

Which TWO of the following are benefits of using a VPC Service Controls perimeter?

Select 2 answers
A.Prevent data exfiltration from managed services like BigQuery and Cloud Storage
B.Act as a network firewall for Compute Engine instances
C.Provide encryption of data in transit between on-premises and Google Cloud
D.Replace Identity and Access Management (IAM) for service access control
E.Allow access to Google Cloud services only from within an authorized VPC network
AnswersA, E

VPC Service Controls builds a security perimeter around Google-managed services, restricting data movement across its boundary. This directly blocks exfiltration paths such as copying BigQuery datasets or Cloud Storage objects to unauthorised projects, satisfying the containment requirement.

Why this answer

VPC Service Controls perimeters are designed to mitigate data exfiltration risks for managed services such as BigQuery, Cloud Storage, and other Google Cloud APIs, so option A is correct because the perimeter restricts data movement across its boundary even when credentials are valid. Option E is also correct because a perimeter defines an authorized boundary (based on VPC networks, projects, and access levels) from which managed services can be reached, effectively allowing access only from authorized VPC networks. Option B is wrong because VPC Service Controls is not a network firewall for Compute Engine instances; that role belongs to VPC firewall rules and hierarchical firewall policies.

Option C is wrong because encryption in transit between on-premises and Google Cloud is handled by mechanisms such as Cloud VPN, Cloud Interconnect with MACsec, or application-layer TLS, not by VPC Service Controls. Option D is wrong because VPC Service Controls complements rather than replaces IAM; IAM still governs identities and permissions, while the perimeter adds an independent context-aware boundary.

Exam trap

Google Cloud often tests the misconception that VPC Service Controls are a firewall or encryption mechanism, when in fact they are a context-aware access boundary that works alongside IAM and network controls.

360
MCQmedium

You are deploying a new version of a microservices application to a GKE cluster. The deployment must be released to a small subset of users first, and if errors occur, traffic must automatically revert to the previous version. You also need to monitor the error rate and latency of the new version. Which approach should you use?

A.Create two separate GKE clusters, one for the old version and one for the new version, and use a global load balancer to split traffic 50/50. Monitor errors and manually shift traffic back if needed.
B.Deploy the new version as a separate Kubernetes Service and use an Ingress with session affinity to route a percentage of users to the new version. Monitor errors and adjust the Ingress configuration manually.
C.Use a Kubernetes Deployment with a rolling update and configure readiness probes; use kubectl rollout undo if errors occur.
D.Use Anthos Service Mesh to implement a canary deployment with traffic splitting, and configure automatic rollback based on error rate metrics.
AnswerD

Anthos Service Mesh provides traffic splitting, allowing you to send a percentage of traffic to the new version. It integrates with Cloud Monitoring to automatically roll back if error rates exceed thresholds. This directly satisfies the canary release and automatic revert requirements, and provides observability for latency and errors.

Why this answer

Anthos Service Mesh offers advanced traffic management, including canary deployments with precise traffic splitting and automated rollback triggered by monitoring metrics. This aligns with the need to release to a subset, monitor, and revert automatically. The other options lack either the fine-grained traffic control or the automation required.

Exam trap

The trap here is assuming that a Kubernetes rolling update or Ingress can perform canary releases with automatic rollback, but they lack native traffic splitting and metric-based automation.

361
MCQmedium

A company wants to restrict network access to Cloud SQL instances such that only applications running in a specific VPC can connect. Which GCP feature should they use?

A.Private Service Connect
B.Private Service Access
C.VPC peering
D.Private Services Access
AnswerB

Private Service Access enables private connectivity to Google-managed services such as Cloud SQL from a VPC using private IP addresses. This is the recommended approach.

Why this answer

Private Service Access (PSA) is the GCP feature that allows private connectivity from a VPC network to Google-managed services like Cloud SQL. It uses VPC peering with the Google-managed service's VPC to enable private IP communication. Private Service Connect, on the other hand, is used for publishing services to consumers, not for consuming services like Cloud SQL.

362
Multi-Selectmedium

Which TWO options are valid ways to connect an on-premises network to a VPC in Google Cloud? (Choose two.)

Select 2 answers
A.Cloud VPN.
B.Dedicated Interconnect.
C.Cloud NAT.
D.VPC Network Peering.
E.Private Google Access.
AnswersA, B

Cloud VPN provides IPsec tunnels to on-premises.

Why this answer

Cloud VPN is a valid way to connect an on-premises network to a VPC in Google Cloud. It uses IPsec (IKEv1 or IKEv2) to create an encrypted tunnel over the public internet between your on-premises VPN gateway and a Cloud VPN gateway in your VPC. This allows secure communication between your on-premises resources and your VPC subnets, making it a standard hybrid connectivity option.

Exam trap

Google Cloud often tests the distinction between services that provide connectivity to a VPC (like VPN and Interconnect) versus services that only enable outbound internet access or internal VPC-to-VPC peering, leading candidates to mistakenly select Cloud NAT or VPC Network Peering.

363
MCQmedium

A company wants to connect their on-premises data center to Google Cloud with a dedicated private connection that provides 99.99% availability and supports up to 100 Gbps bandwidth. They have a colocation facility near a Google Cloud region. Which connectivity option should they choose?

A.Partner Interconnect
B.Direct Peering
C.Dedicated Interconnect
D.HA VPN
AnswerC

Dedicated Interconnect provides a direct physical link between the on-premises network and Google's edge at a colocation facility, delivering the 99.99% availability and up to 100 Gbps capacity the stem requires. Partner Interconnect and Cloud VPN cannot meet those combined bandwidth and SLA constraints.

Why this answer

Dedicated Interconnect provides a direct physical connection between the customer's colocation facility and Google's network, supporting up to 100 Gbps per link (with 10 Gbps or 100 Gbps circuits) and offering a 99.99% SLA when configured with redundant connections. Because the company already has a colocation facility near a Google region, Dedicated Interconnect is the correct fit for the stated bandwidth and availability requirements.

Exam trap

The trap is confusing Dedicated Interconnect with Partner Interconnect; candidates may pick Partner because it also uses a colocation facility, but only Dedicated Interconnect meets the 100 Gbps and direct-connection requirements.

How to eliminate wrong answers

Option A is wrong because Partner Interconnect goes through a supported service provider and typically supports lower bandwidth tiers (up to 50 Gbps per connection) and is chosen when the customer cannot meet Google at a colocation facility. Option B is wrong because Direct Peering is a BGP peering relationship for exchanging traffic, not a dedicated private connection with an SLA, and it does not provide the 99.99% availability guarantee. Option D is wrong because HA VPN is an IPsec VPN over the public internet with a 99.99% SLA but maximum throughput of 3 Gbps per tunnel, far below the 100 Gbps requirement.

364
MCQhard

A company runs a global SaaS application on Google Cloud using Cloud Spanner. They need to ensure disaster recovery with a Recovery Time Objective (RTO) of less than 5 seconds and a Recovery Point Objective (RPO) of zero. Which configuration should they use?

A.Deploy Cloud Spanner in a multi-region configuration
B.Enable point-in-time recovery (PITR)
C.Use read replicas in another region
D.Configure automated backups with a 1-hour backup frequency
AnswerA

Multi-region Cloud Spanner synchronously replicates writes across regions using Paxos quorums, so committed data survives a regional failure with zero data loss (RPO 0). Failover to a surviving replica is automatic and typically completes within seconds, satisfying the sub-5-second RTO without manual intervention.

Why this answer

Cloud Spanner multi-region configurations synchronously replicate data across regions using Paxos, giving an RPO of zero (no committed data is ever lost) and an RTO of seconds because a regional failure triggers automatic leader re-election without manual intervention. This is the only option that satisfies both the zero-RPO and sub-5-second RTO requirements simultaneously.

Exam trap

PCA often tests the confusion between backup/restore features (PITR, automated backups) and true high-availability replication (multi-region Spanner), tricking candidates into selecting a backup option when the question demands zero RPO and near-instant RTO.

How to eliminate wrong answers

Option B is wrong because PITR only allows restoring a database to a past timestamp (up to 1 hour of version retention by default, extendable to 7 days) — it is a data-corruption recovery tool, not a live failover mechanism, and it cannot deliver zero RPO or sub-5-second RTO. Option C is wrong because Spanner does not offer cross-region read replicas as a DR failover mechanism; reads in a multi-region instance are already served from nearby replicas, and standalone read replicas cannot be promoted to serve writes. Option D is wrong because automated backups with a 1-hour frequency produce an RPO of up to 60 minutes and a restore-based RTO measured in minutes to hours, both far outside the stated objectives.

365
MCQeasy

An organization is planning to move 500 TB of archival data from on-premises to Cloud Storage. The data is not frequently accessed, and the network bandwidth is limited to 100 Mbps. What is the most efficient migration approach?

A.Use Transfer Appliance
B.Use gsutil rsync with parallel composite uploads
C.Use Migrate for Compute Engine
D.Use Storage Transfer Service over the internet
AnswerA

Transfer Appliance bypasses the 100 Mbps network constraint entirely by shipping encrypted physical hardware, making it far faster than any online transfer for 500 TB. Its suitability for infrequently accessed archival data matches the stem's access pattern, whereas Storage Transfer Service or gsutil would take months over the limited link.

Why this answer

Transfer Appliance is a physical device for shipping large amounts of data when bandwidth is low. At 100 Mbps, 500 TB would take over 500 days; Transfer Appliance bypasses network constraints.

366
MCQmedium

A company migrated their on-premises database to Cloud SQL and now experiences high latency for read-heavy workloads. How can they optimize performance?

A.Switch to a higher machine type.
B.Enable automatic storage increase.
C.Use connection pooling.
D.Add read replicas.
AnswerD

Read replicas serve read-only queries from separate database instances, offloading SELECT traffic from the primary. Distributing read-heavy workloads across replicas reduces contention and latency on the primary instance, directly addressing the high read latency described after the Cloud SQL migration.

Why this answer

Adding read replicas is the correct optimization because Cloud SQL read replicas offload read traffic from the primary instance, reducing latency for read-heavy workloads. Read replicas asynchronously replicate data from the primary using MySQL or PostgreSQL native replication, allowing queries to be distributed across multiple instances. This directly addresses the high latency by scaling read capacity horizontally without impacting write performance.

Exam trap

Google Cloud often tests the misconception that vertical scaling (higher machine type) is the universal fix for performance issues, but the trap here is that read-heavy workloads require horizontal scaling via read replicas to distribute the read load, not just a more powerful single instance.

How to eliminate wrong answers

Option A is wrong because switching to a higher machine type (vertical scaling) may improve performance but does not specifically address read-heavy workloads; it increases cost without distributing the read load, and latency improvements are limited by the single instance's resources. Option B is wrong because enabling automatic storage increase only prevents storage-full errors and does not affect query latency or read throughput; it is a capacity management feature, not a performance optimization. Option C is wrong because connection pooling reduces the overhead of establishing new database connections but does not reduce latency for read-heavy workloads; it improves connection management efficiency, not query execution speed or read distribution.

367
MCQmedium

Your company is using Cloud Storage to store sensitive customer data. The security team requires that all objects be encrypted with a customer-managed encryption key (CMEK) and that the key be automatically rotated every 90 days. You need to implement this without changing the application code. You have created a Cloud KMS key ring and a key with rotation period set to 90 days. What additional configuration is required?

A.Set a bucket lifecycle rule to transition objects to a different storage class.
B.Create a custom customer-supplied encryption key (CSEK) and provide it in each request.
C.Grant the Cloud KMS CryptoKey Encrypter/Decrypter role to the Cloud Storage service account.
D.Set the default encryption key of the Cloud Storage bucket to the Cloud KMS key.
AnswerD

Setting the bucket's default encryption key to the Cloud KMS key applies CMEK automatically to every newly written object, satisfying the customer-managed key requirement without application changes. Cloud KMS handles the 90-day rotation transparently, since rotation generates new key versions while the key resource name stays constant, so existing object references remain valid.

Why this answer

Setting the default encryption key of the Cloud Storage bucket to the Cloud KMS key ensures that all objects written to the bucket are automatically encrypted with that CMEK, without requiring any application code changes. The Cloud KMS key's rotation period of 90 days is already configured, so the key will be rotated automatically, meeting the security team's requirement.

Exam trap

The trap here is that candidates may think granting the Cloud KMS role to the Cloud Storage service account (Option C) is sufficient, but they overlook the critical step of actually setting the key as the default encryption key on the bucket to enforce automatic encryption.

How to eliminate wrong answers

Option A is wrong because bucket lifecycle rules manage object transitions between storage classes or deletion, not encryption key configuration or rotation. Option B is wrong because CSEK requires providing the key in each request, which would necessitate changing application code, and CSEK keys cannot be automatically rotated by Cloud KMS. Option C is wrong because granting the Cloud KMS CryptoKey Encrypter/Decrypter role to the Cloud Storage service account is necessary for the service account to use the key, but it is not the additional configuration required to enforce encryption on the bucket; the key must also be set as the default encryption key on the bucket.

368
MCQhard

The exhibit shows a command to create a Compute Engine instance. The instance is intended to run a web server that needs to access Cloud Storage buckets using its service account. However, the web server fails to read from a storage bucket. What is the most likely cause?

A.The service account is not attached to the instance
B.The tags http-server and https-server block outbound traffic
C.The boot disk type is SSD, which is not compatible with Cloud Storage
D.The service account lacks IAM permissions to read from Cloud Storage
AnswerD

The instance's attached service account has no IAM role granting storage.objects.get on the bucket, so Cloud Storage returns 403 regardless of network or scope settings. Access scopes only gate the API surface; IAM bindings authorise the actual read, making missing permissions the direct cause of the failure.

Why this answer

The correct answer is D: the service account lacks IAM permissions to read from Cloud Storage. Even when a service account is properly attached to a Compute Engine instance, the instance's applications can only access Cloud Storage buckets if that service account has been granted the appropriate IAM roles (for example, roles/storage.objectViewer) on the bucket or project. The failure to read from the bucket is therefore most likely an authorization issue at the IAM layer rather than a configuration problem with the instance itself.

Option A is not the cause because the scenario states the instance uses its service account, and even a missing attachment would be a different setup issue. Option B is incorrect because firewall tags like http-server and https-server govern inbound HTTP/HTTPS traffic, not outbound access to the Cloud Storage API. Option C is incorrect because the boot disk type (SSD vs. standard) has no bearing on Cloud Storage access.

369
MCQhard

A healthcare company runs a critical patient portal on Google Kubernetes Engine. The security team requires that all container images be scanned for vulnerabilities before deployment, that only images from a trusted registry be admitted to the cluster, and that any attempt to deploy an untrusted image be blocked and logged. Which Google Cloud feature should the cloud architect implement to enforce these admission requirements?

A.GKE network policies that restrict egress from the cluster to only the trusted registry, preventing pods from pulling images from unapproved sources.
B.GKE Sandbox with gVisor runtime enabled on all node pools to isolate containers and reduce the impact of vulnerable images.
C.Binary Authorization with a policy that requires attestations from a trusted vulnerability scanner and allows only images from the approved registry, integrated with GKE admission control.
D.Artifact Registry vulnerability scanning with automatic scanning enabled on push for all repositories.
AnswerC

Binary Authorization enforces deploy-time policies on GKE by requiring cryptographic attestations that prove an image passed the required scanning step and came from an approved registry. When a deployment violates the policy, admission is denied and the attempt is logged. This directly meets the need to block and record untrusted image deployments.

Why this answer

Binary Authorization is the GKE-native admission control that enforces policies at deploy time using attestations. A policy can require that images be attested by a trusted scanner and originate from an approved registry, and violations are denied and logged. Vulnerability scanning alone detects but does not block, network policies do not govern kubelet image pulls, and sandboxing hardens runtime without validating provenance.

Exam trap

The trap here is assuming that enabling vulnerability scanning on a registry is enough to prevent vulnerable images from running, when scanning only reports findings and requires an admission controller to enforce them.

370
MCQeasy

A company uses Cloud Logging to capture application logs. They need to alert when the number of errors exceeds 100 in a 5-minute window. Which type of alert should they create?

A.Notification channel with email integration
B.Cloud Logging sink to a Pub/Sub topic
C.Log-based metric with an alerting policy
D.SLO alerting policy
AnswerC

A log-based metric counts matching log entries, such as errors, and an alerting policy on that metric triggers when the count exceeds 100 within the 5-minute window. This satisfies the threshold condition on error volume.

Why this answer

To alert on the count of error log entries exceeding 100 in a 5-minute window, the engineer must first create a log-based metric that counts matching log entries, then attach an alerting policy with a threshold condition on that metric. Cloud Logging alone cannot alert on log content; it must be converted into a metric that Cloud Monitoring can evaluate. This is the standard pattern for log-driven alerting in Google Cloud.

Exam trap

PCA often tests whether candidates know that Cloud Logging cannot alert directly on log content and that a log-based metric plus an alerting policy is required.

How to eliminate wrong answers

Option A is wrong because a notification channel only defines where alerts are sent; it does not define the condition or the metric, so it cannot trigger on error counts by itself. Option B is wrong because a log sink to Pub/Sub routes log entries for downstream processing but does not evaluate thresholds or generate alerts. Option D is wrong because an SLO alerting policy is based on service-level objectives (error budgets, burn rates) and is not designed to count raw error log entries in a 5-minute window.

371
MCQeasy

A media company stores millions of video master files in a Cloud Storage bucket in the us-central1 region. Files are written once, accessed frequently for the first 30 days during editing and publishing, and then almost never accessed again, though they must remain retrievable for seven years. The company wants to minimize storage cost without changing the objects' names or the way applications read them. Which approach should the architect recommend?

A.Configure an Object Lifecycle Management rule on the bucket that transitions objects to Nearline Storage after 30 days and to Coldline Storage after 365 days
B.Create a second bucket with the Coldline storage class and rewrite each object into it after 30 days using a scheduled job
C.Set the bucket's default storage class to Archive and enable Autoclass so objects are promoted on access
D.Keep objects in Standard storage and enable Turbo Replication to improve read performance across regions
AnswerA

Object Lifecycle Management changes the storage class of existing objects in place, so object names and read paths stay identical. Transitioning to Nearline after the editing window and to Coldline later matches the access pattern and lowers cost. This meets the seven-year retention requirement while minimizing spend during the long low-access period.

Why this answer

The access pattern is predictable: hot for 30 days, then cold for years. Object Lifecycle Management transitions objects between storage classes in place, so applications keep reading the same object names while the per-gigabyte cost drops as access frequency falls. Approaches that move objects to another bucket or change the default class either break read paths or fail to reclassify existing data.

Exam trap

The trap here is choosing to move objects into a cheaper bucket instead of transitioning their storage class in place.

372
MCQeasy

A company runs a batch processing job that runs daily and can handle interruptions. The job runs on a single Compute Engine instance. Which machine configuration is the most cost-effective?

A.A n2-standard-4 VM with sustained use discount
B.A standard n1-standard-4 VM
C.A preemptible n1-standard-4 VM
D.A n1-standard-4 VM with a GPU
AnswerC

Preemptible VMs cost up to 80% less than standard instances, and the batch job tolerates interruption, satisfying the stem's fault-tolerance constraint. A 24-hour maximum runtime suits a daily job. The n1-standard-4 provides four vCPUs and 15 GB memory, adequate for batch processing without over-provisioning.

Why this answer

A preemptible VM costs significantly less than a standard VM (up to 80% discount) and is ideal for batch processing jobs that can handle interruptions. The job runs daily and can tolerate being stopped, so the lower cost of a preemptible instance provides the most cost-effective solution without sacrificing functionality.

Exam trap

Google Cloud often tests the misconception that sustained use discounts are the most cost-effective option, but the trap here is that preemptible VMs provide a much deeper discount for fault-tolerant workloads, and candidates may overlook the 'can handle interruptions' requirement in the question.

How to eliminate wrong answers

Option A is wrong because a n2-standard-4 VM with sustained use discount is more expensive than a preemptible VM; sustained use discounts apply automatically for running instances over a month, but they do not match the deep discount of preemptible instances, and the n2 series is a newer, higher-performance generation that is unnecessary for a batch job that can handle interruptions. Option B is wrong because a standard n1-standard-4 VM incurs full on-demand pricing, which is not cost-effective for a fault-tolerant batch job that can use cheaper preemptible instances. Option D is wrong because adding a GPU to an n1-standard-4 VM increases cost significantly and provides no benefit for a batch processing job that does not require GPU acceleration, making it the least cost-effective option.

373
Multi-Selectmedium

A multinational enterprise is designing its Google Cloud resource hierarchy. They want to enforce centrally managed policies, delegate administration to regional business units, and isolate billing. Which two design choices should the architects make? (Choose two.)

Select 2 answers
A.Create folders per business unit under the organization node and apply organization policies at the appropriate folder level.
B.Create a single project for all business units and use labels to separate their resources.
C.Use a single Shared VPC in the organization host project for all business units without folders.
D.Assign each business unit its own Cloud Billing account and link their projects to that account.
E.Grant every business unit administrator the Organization Administrator role so they can manage their own projects.
AnswersA, D

Folders let you group projects by business unit and apply organization policies and IAM inheritance at the folder level, so central teams enforce guardrails while regional units manage their own projects beneath. This cleanly supports delegated administration and centralized policy control, matching the stated governance goals.

Why this answer

Folders under the organization node enable policy inheritance and delegated administration, letting central teams set guardrails while business units own their projects. Separate Cloud Billing accounts per business unit isolate costs and budgets. Labels, over-broad organization roles, and networking alone do not deliver the required policy control and billing separation.

Exam trap

The trap here is assuming labels or a shared network can substitute for folders and separate billing accounts when enforcing governance and cost isolation.

374
MCQmedium

A company needs to ensure that only applications running in a specific GKE namespace can access a Cloud Storage bucket. Which approach should they use?

A.Use Workload Identity to bind the Kubernetes service account to a GCP service account with appropriate IAM roles
B.Use VPC Service Controls to restrict the bucket to only the GKE cluster's VPC
C.Use firewall rules to allow traffic only from the GKE cluster's pod CIDR
D.Use Cloud Armor to restrict access based on source IP
AnswerA

Workload Identity federates a Kubernetes service account to a Google Cloud service account, so pods in that namespace receive the service account's IAM permissions when accessing Cloud Storage. This satisfies the namespace-scoped constraint, since only workloads using the bound Kubernetes service account obtain the bucket's IAM roles.

Why this answer

Workload Identity allows binding a Kubernetes service account to a GCP service account. Then, IAM can be granted to that GCP service account for the Cloud Storage bucket.

375
MCQhard

A healthcare company is designing a new patient portal on Google Cloud. Regulatory requirements mandate that all data at rest be encrypted with keys the company controls and can rotate on its own schedule, and that the keys never leave a hardware security module (HSM). The security team also wants to retain the ability to revoke Google's access to the data if the external key becomes unavailable. Which key management design should you recommend?

A.Create a Cloud KMS key ring with HSM protection level and use customer-managed encryption keys (CMEK) for the services.
B.Encrypt data with application-level keys stored in Secret Manager and decrypt in the application before writing to Cloud Storage.
C.Use Google-managed encryption keys (GMEK) with default Cloud KMS encryption for all services.
D.Use Cloud External Key Manager (Cloud EKM) with a supported external key management partner and an HSM-backed external key.
AnswerD

Cloud EKM lets the customer hold key material in an external, partner-hosted HSM while Google Cloud services call out to wrap and unwrap data encryption keys. The customer controls rotation on their own schedule, key material never resides in Google's infrastructure, and disabling or revoking the external key immediately prevents Google from decrypting the data, satisfying the revocation requirement.

Why this answer

Cloud External Key Manager is the only option that keeps key material outside Google Cloud in a partner HSM while still integrating with Google Cloud services for encryption at rest. It supports customer-controlled rotation and, critically, allows the customer to revoke Google's access by disabling the external key. CMEK and GMEK keep key custody inside Google, which does not meet the external control and revocation mandate.

Exam trap

The trap here is treating Cloud KMS CMEK with HSM protection level as equivalent to externally held keys, when the key material still resides in Google Cloud.

Page 4

Page 5 of 11

Page 6

All pages