Courseiva

Google Professional Cloud Architect (PCA) — Questions 376–450

807 questions total · 11pages · All types, answers revealed

Page 5

Page 6 of 11

Page 7
376
MCQeasy

A company has a Cloud Run service that processes images uploaded by users. The service reads the images from a Cloud Storage bucket and writes processed images to another bucket. The team recently updated the service to use a custom service account named 'image-processor-sa' with minimal permissions. After the update, the service fails with permission errors when trying to read from the source bucket. The team verified that the service account has the Storage Object Viewer role on the source bucket and Storage Object Creator role on the destination bucket. What should the architect do to resolve the issue?

A.Ensure the Cloud Run service uses the correct service account by redeploying with the --service-account flag set to 'image-processor-sa@project-id.iam.gserviceaccount.com'.
B.Grant the service account the Cloud Run Invoker role on the Cloud Run service.
C.Assign the Storage Admin role to the service account.
D.Enable the Cloud Storage API for the project.
AnswerA

Cloud Run defaults to the Compute Engine default service account unless explicitly overridden, so the new permissions were never applied. Redeploying with the --service-account flag binds the revision to image-processor-sa, letting its Storage Object Viewer role take effect.

Why this answer

The error occurs because the Cloud Run service is not using the custom service account 'image-processor-sa' despite it being created and granted permissions. By default, Cloud Run uses the Compute Engine default service account unless explicitly overridden. Redeploying with the --service-account flag attaches the correct identity to the Cloud Run revision, allowing it to authenticate with Cloud Storage using the minimal permissions already assigned.

Exam trap

Google Cloud often tests the distinction between granting permissions to a service account versus actually attaching that service account to a resource; candidates mistakenly assume that creating and granting roles to a service account automatically makes it the active identity of the Cloud Run service.

How to eliminate wrong answers

Option B is wrong because the Cloud Run Invoker role grants permission to invoke the service (i.e., call its HTTP endpoint), not to read from Cloud Storage; it does not resolve the missing identity binding. Option C is wrong because assigning Storage Admin is an overly permissive solution that violates the principle of least privilege; the service account already has the necessary Object Viewer and Object Creator roles, so the issue is not about missing permissions but about the service not using the correct account. Option D is wrong because the Cloud Storage API is enabled by default when Cloud Storage is used; the error is not due to a disabled API but due to the service running under the wrong identity.

377
MCQeasy

A data scientist needs read-only access to a Cloud Storage bucket containing training data. What is the least privileged IAM role to grant at the bucket level?

A.roles/storage.objectAdmin
B.roles/storage.objectCreator
C.roles/storage.admin
D.roles/storage.objectViewer
AnswerD

roles/storage.objectViewer grants read-only access to objects within a bucket, including listing and getting them, without write or delete permissions. Applied at bucket level it satisfies the least-privilege requirement for reading training data, unlike broader roles such as objectAdmin or storageAdmin.

Why this answer

Roles/storage.objectViewer grants read-only access to objects in a Cloud Storage bucket without allowing any write or administrative actions. This is the least privileged role that satisfies the requirement for read-only access to training data at the bucket level, as it only permits storage.objects.get and storage.objects.list permissions.

Exam trap

The trap here is that candidates often confuse roles/storage.objectViewer with roles/storage.objectAdmin or roles/storage.admin, mistakenly thinking broader roles are needed for read access, or they incorrectly assume roles/storage.objectCreator provides read capabilities.

How to eliminate wrong answers

Option A is wrong because roles/storage.objectAdmin grants full control over objects, including create, delete, and update permissions, which exceeds the read-only requirement. Option B is wrong because roles/storage.objectCreator only allows creating new objects but does not grant read access to existing objects, so it cannot fulfill the read-only need. Option C is wrong because roles/storage.admin provides full administrative control over the bucket, including modifying bucket metadata and IAM policies, which is far more permissive than read-only access.

378
MCQhard

A company is migrating a monolithic application to microservices on Google Cloud. They need to manage service-to-service authentication and authorization. Which service should they use?

A.Cloud NAT
B.Cloud Identity-Aware Proxy
C.Cloud Endpoints
D.Service Mesh (Anthos)
AnswerD

Anthos Service Mesh issues mutual TLS identities to each workload, so service-to-service authentication and authorisation are enforced without application code changes. This satisfies the microservices requirement for cryptographic workload identity and policy-based access control across the mesh.

Why this answer

Service Mesh (Anthos) provides a dedicated infrastructure layer for managing service-to-service communication, including mutual TLS (mTLS) authentication, fine-grained authorization policies, and observability. It uses sidecar proxies (Envoy) to intercept traffic and enforce security policies without modifying application code, making it ideal for microservices authentication and authorization.

Exam trap

The trap here is that candidates often confuse Cloud Endpoints (API management for external clients) with the internal service-to-service security needs of microservices, or assume Cloud IAP can be extended to internal traffic, but IAP only works for user-facing HTTP(S) requests and cannot enforce policies between backend services.

How to eliminate wrong answers

Option A is wrong because Cloud NAT is a network address translation service for outbound internet access from private instances, not for service-to-service authentication or authorization. Option B is wrong because Cloud Identity-Aware Proxy (IAP) is designed for user-to-application authentication and access control at the edge, not for internal service-to-service communication within a VPC. Option C is wrong because Cloud Endpoints is an API management service that handles API keys, authentication, and quotas for external-facing APIs, but it does not provide the sidecar-based, fine-grained service-to-service authentication and authorization needed for microservices.

379
MCQmedium

Your company runs a customer-facing API on Cloud Run with a concurrency setting of 80. The API calls a backend Cloud Function that performs a heavy computation (2–5 seconds). During peak hours, the API experiences increased latency and some requests time out after 60 seconds. Monitoring shows that the Cloud Run max instances is set to 100, and the Cloud Function max instances is set to 10. The timeout for Cloud Run is set to 300 seconds. The Cloud Function's timeout is set to 540 seconds. You need to reduce end-to-end latency and prevent timeouts while minimizing cost. Which action is most effective?

A.Increase Cloud Run max instances from 100 to 500
B.Increase Cloud Run request timeout from 300 to 600 seconds
C.Increase Cloud Function max instances from 10 to 100
D.Reduce Cloud Run concurrency from 80 to 10
AnswerC

Correct: removes backend capacity bottleneck.

Why this answer

The bottleneck is the Cloud Function's low max instances (10), causing queuing. Increasing Cloud Function max instances allows more concurrent requests to be processed, reducing latency and timeouts. Option A is wrong because concurrency on Cloud Run is separate from backend; reducing concurrency would require more Cloud Run containers and increase cost.

Option B is wrong because increasing Cloud Run max instances alone doesn't help if Cloud Function capacity is the limit. Option D is wrong because increasing Cloud Run timeout doesn't reduce latency; it just keeps the connection alive longer.

380
MCQhard

A financial services company must store customer data in a GCP region that is certified for FedRAMP High. They also need to ensure that only authorized personnel can access the data, and that access logs are kept for 10 years. Which combination of services meets these requirements?

A.Cloud HSM and Cloud Audit Logs
B.VPC Service Controls with Cloud DLP
C.Cloud KMS with CMEK and Cloud Audit Logs
D.Assured Workloads with Cloud Audit Logs and IAM
AnswerD

Assured Workloads enforces FedRAMP High controls within a compliant GCP region, satisfying the certification constraint. IAM restricts data access to authorised personnel only, while Cloud Audit Logs captures administrative and data-access activity, retained for 10 years via a custom log bucket retention policy. Together they meet all three requirements.

Why this answer

Assured Workloads is the GCP service designed to enforce regulatory compliance frameworks such as FedRAMP High by applying policy controls, restricting data residency to compliant regions, and enforcing personnel access controls (including support access restrictions). Combining it with Cloud Audit Logs (for the 10-year retention requirement via log sinks to a long-term bucket) and IAM (for least-privilege access) directly satisfies all three stated requirements.

Exam trap

The trap here is assuming that encryption services (Cloud KMS, Cloud HSM) or perimeter services (VPC Service Controls) satisfy regulatory compliance requirements — the PCA exam expects candidates to recognize that Assured Workloads is the dedicated service for enforcing compliance frameworks like FedRAMP High, HIPAA, and IL4.

How to eliminate wrong answers

Option A is wrong because Cloud HSM provides FIPS 140-2 Level 3 key protection but does not enforce FedRAMP High data residency or personnel access controls, and Cloud Audit Logs alone does not guarantee 10-year retention without a configured log sink. Option B is wrong because VPC Service Controls provides perimeter security against data exfiltration and Cloud DLP classifies sensitive data, but neither enforces FedRAMP High region certification or personnel access restrictions. Option C is wrong because Cloud KMS with CMEK gives customer-managed encryption keys and Cloud Audit Logs provides logging, but neither addresses FedRAMP High compliance boundaries or the personnel access requirement — CMEK is about key control, not regulatory workload isolation.

381
MCQmedium

A company is deploying a new application on Compute Engine and wants to automate the installation of a custom agent on every newly created VM in a specific project. Which Google Cloud service should they use?

A.VM Manager (OS Config) with a guest policy to install the agent.
B.Instance templates with startup scripts.
C.Deployment Manager with a template that includes the agent installation.
D.Cloud Build triggered on new VM creation events.
AnswerA

VM Manager's OS Config agent executes guest policies on Compute Engine instances, letting a policy assignment target the project so the custom agent installs automatically at each VM's creation. This directly satisfies the requirement for automated installation across every newly created VM in that specific project.

Why this answer

VM Manager (OS Config) with a guest policy is the correct choice because it provides a native, agent-based configuration management service that can enforce the installation of a custom agent on all existing and newly created VMs in a project without requiring changes to instance templates or startup scripts. Guest policies are evaluated and applied at VM boot time and periodically thereafter, ensuring consistent agent deployment across the fleet.

Exam trap

The trap here is that candidates often confuse configuration management (OS Config guest policies) with provisioning-time automation (startup scripts in instance templates), assuming that startup scripts are sufficient for fleet-wide enforcement when they only apply at creation time and are not re-evaluated.

How to eliminate wrong answers

Option B is wrong because instance templates with startup scripts only apply to VMs created from that specific template; they do not automatically cover VMs created from other templates, images, or via other methods, and they do not enforce the agent on existing VMs. Option C is wrong because Deployment Manager is an infrastructure-as-code tool for deploying resources, not a configuration management service; it cannot automatically apply agent installation to VMs created outside its deployment scope. Option D is wrong because Cloud Build is a CI/CD service for building and testing artifacts, and it cannot be triggered directly by new VM creation events; there is no native event trigger for Compute Engine VM creation in Cloud Build.

382
MCQeasy

A company is deploying a web application on Compute Engine. They want to ensure that only authenticated users can access the application. Which Google Cloud service should they use?

A.Identity-Aware Proxy
B.Cloud Load Balancing
C.Cloud CDN
D.Cloud DNS
AnswerA

Identity-Aware Proxy performs authentication and authorisation at the application layer before requests reach the Compute Engine backend, verifying user identity and context. This enforces that only authenticated users access the application, satisfying the stated access constraint without network-level controls.

Why this answer

Identity-Aware Proxy (IAP) is the correct choice because it enforces access control at the edge of Google's network, verifying user identity and context before allowing traffic to reach the Compute Engine instance. IAP uses OAuth 2.0 and signed headers to authenticate users, ensuring only authorized requests are forwarded to the backend, without requiring any changes to the application itself.

Exam trap

The trap here is that candidates often confuse network-level services like Cloud Load Balancing or Cloud CDN with security controls, assuming they provide authentication simply because they sit in front of the application, but they lack any identity verification mechanism.

How to eliminate wrong answers

Option B (Cloud Load Balancing) is wrong because it distributes traffic across instances but does not authenticate users; it operates at Layer 4 or Layer 7 without any built-in identity verification. Option C (Cloud CDN) is wrong because it caches content at edge locations to reduce latency, but it does not enforce user authentication; it can be combined with IAP but alone provides no access control. Option D (Cloud DNS) is wrong because it translates domain names to IP addresses and has no mechanism for user authentication or authorization.

383
MCQmedium

A company is deploying a new application on Google Kubernetes Engine (GKE). They need to ensure that pods can only pull container images from a private Artifact Registry repository and that images are scanned for vulnerabilities before deployment. They also want to prevent pods from being scheduled if they use images from public registries. What should they do?

A.Enable Container Analysis API and use an admission controller to block images from public registries.
B.Configure a private GKE cluster and use network policies to block egress to public registries.
C.Use Binary Authorization with a policy that requires attestations from a vulnerability scanner, and configure the GKE cluster to only allow images from the private Artifact Registry.
D.Use Anthos Config Management with a policy that denies pods using public images, and enable vulnerability scanning in Artifact Registry.
AnswerC

Binary Authorization enforces deploy-time policies, such as requiring attestations that images have been scanned. It can also restrict images to specific registries. Configuring the cluster to only allow images from the private registry ensures pods cannot use public images. This combination meets both the scanning and registry restriction requirements.

Why this answer

Binary Authorization is the managed service for enforcing deploy-time policies on GKE, including requiring attestations from vulnerability scanners and restricting images to trusted registries. Configuring the cluster to only allow images from the private Artifact Registry ensures that public images cannot be used. Together, they meet the security requirements.

Exam trap

The trap here is assuming that vulnerability scanning alone prevents deployment of vulnerable images, when enforcement requires Binary Authorization attestations.

384
MCQhard

A healthcare company runs a critical application on Google Kubernetes Engine (GKE) that processes patient data. The compliance team requires that all container images be scanned for vulnerabilities before deployment, and that only images from a trusted registry be allowed. The security team wants to enforce this policy across all clusters in the organization. They also need to audit any attempts to deploy untrusted images. Which combination of Google Cloud services should they use?

A.Enable GKE Sandbox on all nodes and use Anthos Config Management to apply a policy that restricts image registries.
B.Use Container Analysis to scan images and configure a GKE admission controller to reject images with vulnerabilities.
C.Use Artifact Registry with vulnerability scanning enabled and configure IAM policies to restrict which projects can pull images.
D.Use Binary Authorization with a policy that requires attestations from a trusted authority, and enable audit logging for GKE.
AnswerD

Binary Authorization enforces deploy-time policies on GKE by requiring attestations that prove an image was built by a trusted builder and scanned for vulnerabilities. By configuring a policy that requires attestations from a trusted authority, the company ensures only compliant images are deployed. Enabling audit logging captures attempts to deploy non-compliant images, satisfying the audit requirement. This combination directly addresses both enforcement and auditing across all clusters in the organization.

Why this answer

Binary Authorization is the Google Cloud service designed to enforce deploy-time policies on GKE by requiring attestations. By setting a policy that requires attestations from a trusted authority, the company ensures that only images that have been built and scanned by trusted processes are admitted. Enabling audit logging provides a record of all deployment attempts, including those that violate the policy.

This satisfies both the enforcement and auditing requirements across all clusters in the organization.

Exam trap

The trap here is confusing vulnerability scanning with policy enforcement; scanning alone does not prevent deployment of vulnerable images.

385
MCQhard

An application running on GKE Autopilot is experiencing intermittent failures due to resource limits. The team wants to ensure that the application always has enough CPU and memory without manual node management. What should they do?

A.Use horizontal pod autoscaling only
B.Increase the resource requests and limits in the pod specification
C.Create a new node pool with larger machine types
D.Switch to GKE Standard and manage node pools manually
AnswerB

Raising resource requests and limits in the pod specification directly addresses the intermittent failures by guaranteeing the scheduler reserves sufficient CPU and memory for each pod. On GKE Autopilot, nodes are provisioned automatically to match those requests, so adequate values remove throttling and OOM evictions without any manual node management.

Why this answer

In GKE Autopilot, nodes are fully managed by Google, so the team cannot create or resize node pools. The correct lever is to set appropriate CPU and memory requests (and limits) in the pod specification so the scheduler and Autopilot's autoscaler provision nodes with sufficient capacity. Autopilot uses the requests to bin-pack pods and to decide when to add nodes, so undersized requests cause intermittent failures under load.

Exam trap

The trap is treating GKE Autopilot like GKE Standard — candidates pick 'create a larger node pool' or 'switch to Standard' because that is the Standard-mode answer, forgetting that Autopilot hides node management and the only correct lever is pod resource requests/limits.

How to eliminate wrong answers

Option A is wrong because horizontal pod autoscaling only adjusts the number of pod replicas based on metrics; it does not address per-pod resource limits and can even worsen failures if pods are OOM-killed due to insufficient memory requests. Option C is wrong because GKE Autopilot does not expose node pools for manual creation or machine-type selection — that is a GKE Standard capability. Option D is wrong because switching to GKE Standard and managing node pools manually abandons the Autopilot operational model the team is using and is unnecessary to solve the problem.

386
MCQeasy

Which Google Cloud service allows you to create alerting policies based on log entries?

A.Cloud Logging
B.Cloud Audit Logs
C.Error Reporting
D.Cloud Monitoring
AnswerD

Cloud Monitoring creates alerting policies from log-based metrics, which are counters derived from log entries via log-based metric filters. This satisfies the stem's requirement to alert on log entries, since the metric is generated directly from matching log data rather than from infrastructure measurements alone.

Why this answer

Cloud Monitoring (formerly Stackdriver) is the Google Cloud service that lets you create alerting policies, including log-based alerts that trigger on specific log entries. You define a query against Cloud Logging data, and Cloud Monitoring evaluates it and fires alerts when matching entries appear. This is the correct service for alerting based on log content.

Exam trap

PCA often tests the distinction between Cloud Logging (stores and queries logs) and Cloud Monitoring (creates alerts and dashboards) — candidates pick Cloud Logging because the question mentions log entries, missing that alerting policies live in Cloud Monitoring.

How to eliminate wrong answers

Option A is wrong because Cloud Logging is the service that stores and queries logs, but it does not itself create alerting policies — it is the data source, not the alerting engine. Option B is wrong because Cloud Audit Logs are a specific category of logs (admin activity, data access, system events) stored in Cloud Logging, not an alerting service. Option C is wrong because Error Reporting aggregates and displays application errors but does not create configurable alerting policies based on arbitrary log entries — it is a specialized error-viewing tool.

387
MCQeasy

A healthcare company is planning to store sensitive patient records in Cloud Storage. They need to ensure that the data is encrypted at rest with keys that they control and can rotate on demand. They also want to maintain an audit trail of key usage. Which Google Cloud service should they use?

A.Cloud HSM with a hardware security module for key storage.
B.Customer-supplied encryption keys (CSEK) stored on-premises.
C.Cloud Key Management Service (Cloud KMS) with customer-managed encryption keys (CMEK).
D.Cloud Storage default encryption with Google-managed keys.
AnswerC

Cloud KMS allows you to create and manage encryption keys, including customer-managed keys. You can rotate these keys on demand and integrate with Cloud Audit Logs to track key usage. This meets the requirements for controlling keys and maintaining an audit trail.

Why this answer

Cloud KMS with customer-managed encryption keys gives the company full control over key creation, rotation, and usage. It integrates with Cloud Audit Logs to record key operations. The other options either do not provide customer control, lack auditability, or are not specific to the requirement.

Exam trap

The trap here is confusing customer-supplied encryption keys with customer-managed keys; the former does not provide audit logs because Google never sees the keys.

388
MCQeasy

A company has a Cloud SQL for PostgreSQL instance that experiences high connection overhead. Developers frequently open and close connections. Which solution reduces connection overhead without code changes?

A.Increase max_connections in Cloud SQL
B.Configure PgBouncer as a sidecar
C.Switch to Private IP
D.Use Cloud SQL Auth Proxy
AnswerB

PgBouncer pools and reuses backend PostgreSQL connections, so frequent open/close cycles from developers hit the pooler rather than Cloud SQL directly. This satisfies the no-code-changes constraint because applications connect to PgBouncer's endpoint transparently, while transaction pooling cuts the per-connection authentication and process-fork overhead that caused the bottleneck.

Why this answer

PgBouncer is a lightweight connection pooler that sits between the application and Cloud SQL for PostgreSQL, maintaining a pool of persistent backend connections and multiplexing many short-lived client connections onto them. This eliminates the TCP/TLS handshake and PostgreSQL authentication overhead per request without any application code changes, since the app simply connects to PgBouncer's endpoint instead of directly to the database.

Exam trap

PCA often tests the confusion between authentication/security proxies (Cloud SQL Auth Proxy) and connection poolers (PgBouncer) — candidates pick Auth Proxy thinking it reduces overhead, but it only secures the connection, it does not pool it.

How to eliminate wrong answers

Option A is wrong because increasing max_connections only raises the ceiling on concurrent connections — it does not reduce the per-connection setup cost, and it can actually worsen memory pressure on the instance. Option C is wrong because switching to Private IP changes the network path (no public internet) but does not address connection churn or handshake overhead. Option D is wrong because Cloud SQL Auth Proxy provides secure IAM-based authentication and encryption, but it still establishes a new connection per client session — it is not a connection pooler.

389
MCQhard

A company has a VPC Service Perimeter that protects a project containing BigQuery datasets. They want to allow an external customer's BigQuery job to query data across the perimeter boundary using a private connection. Which configuration is required?

A.Remove the project from the service perimeter temporarily.
B.Create an ingress rule in the service perimeter that allows access from the external customer's VPC network.
C.Use Access Transparency to log cross-perimeter access.
D.Grant the external customer's service account the BigQuery User role.
AnswerB

An ingress rule in the VPC Service Perimeter explicitly permits access from the external customer's VPC network, allowing their BigQuery job to cross the perimeter boundary over a private connection while keeping the perimeter enforced for all other traffic.

Why this answer

VPC Service Controls perimeters block access to protected services (like BigQuery) from outside the perimeter by default. To allow an external customer's BigQuery job to query data across the boundary using a private connection, you must create an ingress rule in the service perimeter that specifies the source (the external VPC network or project) and the allowed identities, services, and resources. Ingress rules are the designed mechanism for permitting inbound cross-perimeter access without removing the project from protection.

Exam trap

PCA often tests the distinction between IAM roles and VPC Service Controls, so the trap is assuming that granting an IAM role alone can bypass a service perimeter.

How to eliminate wrong answers

Option A is wrong because removing the project from the perimeter eliminates the protection entirely and is not a targeted, auditable solution — it defeats the purpose of the perimeter. Option C is wrong because Access Transparency logs access by Google personnel, not cross-perimeter customer access, so it does not enable the connection. Option D is wrong because granting the BigQuery User role is an IAM permission, not a perimeter control; IAM alone cannot bypass VPC Service Controls, which operate at a different layer.

390
MCQmedium

A developer wants to store a database password securely and have it automatically rotated every 30 days. The password is used by a Compute Engine instance. Which Google Cloud service should they use?

A.Secret Manager
B.Cloud Storage with customer-supplied encryption keys
C.Cloud Key Management Service (Cloud KMS)
D.Environment variables in Compute Engine
AnswerA

Secret Manager stores credentials as versioned secrets and supports rotation schedules, satisfying the 30-day automatic rotation constraint. Compute Engine instances retrieve the password via the API using their attached service account, so no credential is hard-coded. Rotation creates a new version while the prior version remains accessible, avoiding downtime.

Why this answer

Secret Manager is purpose-built for storing, versioning, and rotating secrets such as database passwords, API keys, and certificates. It supports automatic rotation via Cloud Functions or Pub/Sub triggers on a schedule (e.g., every 30 days), and Compute Engine instances can retrieve secrets at runtime using the Secret Manager API with IAM-controlled access. This directly satisfies both the secure storage and automatic rotation requirements.

Exam trap

The PCA exam often tests the confusion between Cloud KMS (encryption key management) and Secret Manager (application secret storage and rotation) — candidates must recognize that database passwords and API keys belong in Secret Manager, while encryption keys belong in KMS.

How to eliminate wrong answers

Option B is wrong because Cloud Storage with customer-supplied encryption keys stores objects but does not provide secret versioning, rotation, or runtime retrieval APIs designed for credentials — CSEK is about encryption key control, not secret lifecycle management. Option C is wrong because Cloud KMS manages encryption keys (used to encrypt data), not application secrets like passwords; KMS keys can be rotated, but that rotates the encryption key, not the database password itself. Option D is wrong because environment variables in Compute Engine store values in instance metadata or startup scripts in plaintext, are visible to anyone with metadata access, and have no rotation or versioning capability — a well-known anti-pattern for secrets.

391
MCQeasy

An engineer needs to create a custom dashboard in Cloud Monitoring to track the 99th percentile latency of their application over the last 7 days. Which type of metric should they use?

A.Distribution metric
B.Delta metric
C.Cumulative metric
D.Gauge metric
AnswerA

Distribution metrics record a histogram of values across a time window, letting Cloud Monitoring compute percentiles such as p99 directly. This satisfies the requirement to track 99th percentile latency over seven days, which a gauge or counter cannot represent.

Why this answer

Distribution metrics capture a histogram of values across a population of samples, preserving the full value distribution rather than collapsing it to a single number. This is essential for computing percentile aggregations like p99, since percentiles require the underlying histogram buckets to be calculated. Cloud Monitoring's distribution metrics (e.g., from OpenCensus/OpenTelemetry or load balancer latency) support aligner/aggregation functions such as percentile, count, and mean over a time window.

Exam trap

PCA often tests the confusion between metric kinds — candidates pick gauge because they think 'latency is a single value,' forgetting that percentiles require the distribution kind to be computed at all.

How to eliminate wrong answers

Option B is wrong because delta metrics record the change in a cumulative counter between samples, which is useful for rate calculations but cannot produce percentile statistics. Option C is wrong because cumulative metrics monotonically increase from a start time and are designed for rate/derivative operations, not distribution analysis. Option D is wrong because gauge metrics represent a single instantaneous value (like current CPU usage) and have no distribution to compute percentiles from.

392
MCQhard

A financial services company runs a critical PostgreSQL database on Cloud SQL. They need to ensure automatic failover to a replica in another zone within the same region with minimal data loss. What configuration should they choose?

A.Use Database Migration Service to replicate to a second Cloud SQL instance
B.Enable point-in-time recovery (PITR) and increase backup retention
C.Create a cross-region read replica and manually promote it on failure
D.Configure a Cloud SQL HA instance with a failover replica in a different zone
AnswerD

A Cloud SQL HA instance maintains a standby in a different zone with synchronous replication, so failover is automatic and data loss is minimal. This satisfies the stem's requirement for cross-zone automatic failover within the same region.

Why this answer

Cloud SQL High Availability (HA) provisions a standby instance in a different zone within the same region and performs automatic failover with synchronous replication, giving near-zero RPO and minimal downtime. This directly satisfies the requirement for automatic cross-zone failover with minimal data loss.

Exam trap

The trap is conflating 'replica' with 'HA failover' — candidates pick a cross-region read replica thinking it provides automatic failover, but read replicas are asynchronous and require manual promotion, unlike the synchronous HA standby.

How to eliminate wrong answers

Option A is wrong because Database Migration Service is for one-time or continuous migration into Cloud SQL, not for providing an automatic failover target. Option B is wrong because PITR and backup retention only enable point-in-time restore after an incident — recovery is manual and can take many minutes, with data loss up to the last WAL/binlog. Option C is wrong because a cross-region read replica requires manual promotion and is asynchronous, so it does not meet the 'automatic failover within the same region with minimal data loss' requirement.

393
MCQeasy

When creating a Compute Engine instance from a custom image stored in another project, which gcloud flag is required?

A.--image-project
B.--source-instance
C.--image
D.--image-family
AnswerA

The --image-project flag specifies which project owns the custom image, satisfying the requirement to create an instance from an image stored in another project. Without it, gcloud searches only the instance's own project and fails to resolve the image reference.

Why this answer

When creating a Compute Engine instance from a custom image stored in another project, the `--image-project` flag is required to specify the project that contains the image. Without this flag, gcloud defaults to the current project and will not find the image. The `--image` flag is also required to specify the image name, but the question specifically highlights the cross-project situation, making `--image-project` the distinctive required flag.

Exam trap

Candidates often think that `--image` is sufficient, but when using an image from another project, `--image-project` is mandatory; otherwise the instance creation will fail.

How to eliminate wrong answers

Option A is wrong because `--image-project` is not required when using a custom image from another project; it is only needed when specifying a public image from a different project (e.g., `--image-project debian-cloud`). Option B is wrong because `--source-instance` is used to create an image from an existing instance, not to specify an image when creating a new instance. Option D is wrong because `--image-family` is used to select the latest non-deprecated image from a family (e.g., `ubuntu-2204-lts`), not to reference a specific custom image by name.

394
MCQmedium

A developer ran the above command to create a health check for a backend service. Which of the following should they do to resolve the error?

A.Change the request-path to a different value.
B.Delete the existing health check and recreate it.
C.Add the --global flag to the command.
D.Use --load-balancer-type internal to create a new health check with the same name.
E.Use a different name for the health check.
AnswerE

The error stems from a naming collision: a health check with that identifier already exists on the backend service. Supplying a unique name satisfies the API's uniqueness constraint, allowing the new health check to be created without altering its configuration.

Why this answer

The error indicates that a health check with the same name already exists. In Google Cloud, health check names must be unique within a project (or within a region for regional health checks). By using a different name, the developer can create a new health check without conflicting with the existing one.

Exam trap

Google Cloud often tests the misconception that modifying parameters like request-path or load balancer type can resolve naming conflicts, when in fact the core issue is a duplicate name that must be changed.

How to eliminate wrong answers

Option A is wrong because changing the request-path does not resolve a naming conflict; it only alters the path used for health checks. Option B is wrong because deleting and recreating the health check with the same name would still fail if the name is already in use. Option C is wrong because the --global flag is used for global accelerators, not for resolving health check naming conflicts.

Option D is wrong because --load-balancer-type internal specifies the load balancer type, not the health check name; it does not address the duplicate name error.

395
MCQmedium

A company wants to use BigQuery with a predictable monthly cost, regardless of query volume. They have a steady state of around 500 concurrent slots. Which pricing model should they choose?

A.Sustained use discounts
B.Committed use discounts for BigQuery
C.Slot reservations (flat-rate)
D.On-demand pricing
AnswerC

Slot reservations, billed as flat-rate capacity, provision a fixed number of slots for a committed period, so cost stays constant regardless of query volume. This satisfies the predictable monthly cost requirement, matching the steady 500-slot workload without on-demand per-query charges.

Why this answer

BigQuery slot reservations (flat-rate) provide a fixed monthly cost based on reserved slots, suitable for predictable workloads. On-demand pricing charges per query and can vary.

396
MCQhard

Your company runs a data pipeline on Google Cloud using Cloud Dataflow for streaming processing from Pub/Sub to BigQuery. The pipeline writes to a BigQuery table partitioned by day. The data is used for real-time dashboards. Recently, a spike in traffic caused the Dataflow pipeline to fall behind, and the dashboard displayed stale data. You need to design the pipeline to handle traffic spikes without data loss or long delays. The pipeline must be cost-efficient and use defaults where possible. Which solution should you implement?

A.Enable autoscaling in the Dataflow pipeline and use Streaming Engine to handle larger throughput
B.Modify the pipeline to use a batch (non-streaming) approach, writing hourly batches from Pub/Sub to BigQuery
C.Create a Cloud Scheduler job that increases the number of Dataflow workers every 5 minutes based on Pub/Sub subscription backlog
D.Change the Dataflow worker machine type from n1-standard-4 to n1-highmem-8
AnswerA

Autoscaling adds workers dynamically as Pub/Sub backlog grows, while Streaming Engine offloads pipeline state and shuffle processing to a managed service, raising throughput without the cost of permanently over-provisioned workers. Together they absorb traffic spikes with default settings, avoiding stale dashboards and data loss.

Why this answer

Enabling autoscaling in Dataflow allows the pipeline to dynamically adjust the number of workers based on the processing backlog, while Streaming Engine offloads the shuffle and state storage to Google-managed resources, reducing the impact of traffic spikes. This combination ensures the pipeline can scale up quickly to handle increased throughput without data loss or long delays, and it remains cost-efficient by scaling down when demand decreases.

Exam trap

Google Cloud often tests the misconception that manual scaling (Option C) or static resource changes (Option D) are sufficient for handling spikes, when in fact Dataflow's built-in autoscaling and Streaming Engine are the designed, cost-efficient solutions for dynamic workloads.

How to eliminate wrong answers

Option B is wrong because switching to a batch approach introduces inherent latency (hourly batches) that would make the real-time dashboard stale, violating the requirement for minimal delays; it also does not handle spikes within the batch window. Option C is wrong because using Cloud Scheduler to manually adjust worker count every 5 minutes is reactive, not adaptive, and cannot respond quickly enough to sudden spikes; Dataflow's native autoscaling is designed to adjust more granularly and efficiently. Option D is wrong because simply changing the worker machine type to a larger instance (n1-highmem-8) does not address the need for dynamic scaling; it increases cost without guaranteeing sufficient capacity during spikes and does not leverage Dataflow's autoscaling capabilities.

397
MCQhard

A healthcare analytics company ingests HL7 messages into Pub/Sub and processes them with a Dataflow streaming pipeline that writes results to BigQuery. During a regional outage, the pipeline stopped and the team discovered that unacknowledged messages were lost after the retention window expired. The company needs a design where a single-region failure does not cause message loss and the pipeline can resume with minimal manual intervention. What should the architect recommend?

A.Increase the Pub/Sub message retention duration to the maximum and add a dead-letter topic so failed messages are preserved for later reprocessing.
B.Replace Pub/Sub with a Cloud Storage bucket in dual-region mode and have Dataflow read new objects with a streaming pipeline triggered by Eventarc notifications.
C.Run the Dataflow pipeline in a single region but enable autoscaling and set the maximum number of workers higher so it drains the backlog faster after an outage.
D.Deploy the Dataflow pipeline as a regional job in two regions with a Pub/Sub subscription in each, and configure the topic to store messages in a second region using message storage policy or a global endpoint.
AnswerD

Pub/Sub already replicates message data within a region, and a message storage policy or global endpoint lets you keep data in additional regions so a topic survives a regional failure. Running the Dataflow job regionally in two locations with a subscription each means one pipeline keeps draining messages while the other region is down, satisfying both durability and low-touch recovery.

Why this answer

The failure mode is losing messages when a single region is unavailable and the retention window closes. Keeping Pub/Sub message data in more than one region through a message storage policy or global endpoint, plus running the Dataflow job regionally in two locations each with its own subscription, gives both durability of the messages and a surviving processing path. Retention tuning, object storage substitution, and autoscaling do not remove the single-region dependency.

Exam trap

The trap here is treating longer retention or a dead-letter topic as disaster recovery, when both remain bound to a single regional topic and cannot survive that region becoming unavailable.

398
MCQmedium

A company uses Cloud SQL for MySQL for its transactional database. They need to ensure automatic failover in case of a zonal outage with minimal data loss. What configuration should they use?

Answer options not yet available.

Why this answer

Cloud SQL High Availability (HA) configuration creates a standby instance in a different zone within the same region. If the primary fails, it automatically fails over to the standby, minimizing downtime. Backup and PITR help with data loss but do not provide automatic failover.

399
MCQhard

A company runs a stateful application on Google Kubernetes Engine (GKE) that requires persistent storage and low-latency access across multiple zones. The application needs to perform well even during zonal failures. Which storage solution should they use?

A.Zonal persistent disk with snapshots to another zone
B.Local SSDs attached to nodes
C.Cloud Filestore
D.Regional persistent disk
AnswerD

Regional persistent disks synchronously replicate data across two zones within a region, so the stateful workload survives a zonal failure while retaining low-latency block access. This satisfies the stem's simultaneous multi-zone durability and zonal-failure performance constraints.

Why this answer

Regional persistent disks (RPDs) synchronously replicate data across two zones in the same region, providing both the persistent storage and low-latency access required by the stateful application. This ensures that if one zone fails, the disk can be attached to a pod in the surviving zone without data loss or significant performance degradation, meeting the high-availability and multi-zone access requirements.

Exam trap

The trap here is that candidates confuse high-availability features like snapshots or local SSDs with true synchronous replication, overlooking that only regional persistent disks provide both persistence and zero-RPO failover across zones without manual restore steps.

How to eliminate wrong answers

Option A is wrong because zonal persistent disks with snapshots to another zone introduce recovery time (snapshot restore) and potential data loss (snapshot frequency), failing to provide the synchronous, low-latency multi-zone access needed during zonal failures. Option B is wrong because local SSDs are ephemeral and tied to a specific node; data is lost if the node or zone fails, and they cannot be shared across zones, violating the persistent storage requirement. Option C is wrong because Cloud Filestore is a managed NFS file storage service designed for shared file systems, not for low-latency block storage access required by stateful applications on GKE, and it introduces network latency compared to directly attached persistent disks.

400
MCQhard

A healthcare analytics firm processes patient records in a Dataflow streaming pipeline that writes enriched events to BigQuery. The pipeline currently uses a fixed number of workers sized for peak load, and utilization is low for most of the day. The team wants the pipeline to scale with incoming volume while keeping late-arriving events correct and bounded in cost. What should they do?

A.Convert the pipeline to batch mode and run it hourly with a Cloud Scheduler trigger, writing each batch to BigQuery.
B.Increase the number of workers permanently and enable disk-based shuffle to give the pipeline more headroom for late data.
C.Keep the fixed worker pool but switch the pipeline to use Streaming Engine and enable the Dataflow Shuffle service.
D.Enable autoscaling on the pipeline and set a windowing strategy with allowed lateness, using accumulation mode to emit updated results.
AnswerD

Autoscaling adjusts worker count to the backlog, so idle capacity during low-volume periods is removed while peak bursts are absorbed. Windowing with allowed lateness and accumulating mode lets late records update previously emitted windows instead of being dropped, preserving correctness for patient events that arrive out of order.

Why this answer

Autoscaling lets Dataflow add and remove workers as the backlog changes, removing the idle capacity of a peak-sized fixed pool. Windowing with allowed lateness and accumulation mode keeps late records correct by updating previously emitted results, so the pipeline scales with volume while bounded cost and data correctness are both preserved.

Exam trap

The trap here is treating Streaming Engine or extra workers as a substitute for autoscaling plus windowing, when only autoscaling addresses idle cost and only allowed lateness preserves late-arriving records.

401
MCQeasy

A company needs to retain object versions in Cloud Storage for 90 days to protect against accidental deletion or modification. After 90 days, versions should be deleted. What feature should they enable?

A.Object versioning only
B.Retention policy
C.Object holds
D.Object lifecycle management with a rule to delete versions after 90 days
AnswerD

Object lifecycle management applies age-based rules to noncurrent object versions, automatically deleting them once they pass 90 days. This satisfies the stem's requirement to retain versions for 90 days and then remove them, which a retention policy alone cannot do.

Why this answer

Object Lifecycle Management lets you define rules to automatically delete object versions after a specified age (90 days). Combined with Object Versioning enabled on the bucket, this retains noncurrent versions for 90 days and then deletes them, protecting against accidental deletion or modification while controlling storage costs.

Exam trap

The trap is confusing Retention Policy (which locks objects and prevents deletion) with Lifecycle Management (which deletes versions) — candidates may pick Retention Policy thinking it deletes after the period, but it does the opposite.

How to eliminate wrong answers

Option A is wrong because Object Versioning alone retains versions indefinitely, causing unbounded storage growth and cost. Option B is wrong because a Retention Policy locks objects for a period but does not delete them after the period; it also prevents deletion, which is the opposite of the requirement to delete after 90 days. Option C is wrong because Object Holds (temporary or event-based) prevent deletion until released, but do not automatically delete after 90 days.

402
Multi-Selectmedium

An organization wants to use VPC Service Controls to protect a Cloud Storage bucket and a BigQuery dataset from data exfiltration. They want to allow access from a specific on-premises network via a Cloud VPN. Which TWO components are required? (Choose 2)

Select 2 answers
A.A service perimeter that includes the Cloud Storage bucket and BigQuery dataset
B.An access level that includes the IP range of the on-premises network
C.Cloud Interconnect (Dedicated or Partner)
D.VPC firewall rules allowing traffic from on-premises
E.Private Google Access enabled on the VPC subnet
AnswersA, B

A service perimeter defines the security boundary that encloses both the Cloud Storage bucket and BigQuery dataset, preventing data exfiltration across its edge. Including these resources satisfies the stem's requirement to protect them, since VPC Service Controls only enforces restrictions on services listed within the perimeter's protected resources.

Why this answer

Option A is correct because a service perimeter is the fundamental VPC Service Controls construct that defines the boundary around protected resources; the Cloud Storage bucket and BigQuery dataset must be enclosed within the perimeter for VPC Service Controls to restrict access to them and prevent data exfiltration. Option B is correct because access levels define the conditions under which requests from outside the perimeter are allowed; to permit the specific on-premises network, an access level must include that network's IP range (CIDR), which is then bound to the perimeter via ingress rules. Option C is not required because Cloud VPN already provides the connectivity; Cloud Interconnect is an alternative dedicated/partner connection and is not mandated by VPC Service Controls.

Option D is not required because VPC firewall rules govern VM-level traffic and do not control access to Google APIs protected by VPC Service Controls. Option E is not required because Private Google Access only affects how VMs reach Google APIs internally and is unrelated to authorizing on-premises access through a service perimeter.

Exam trap

The trap is that candidates assume network connectivity components (Cloud VPN, Interconnect, firewall rules) are part of VPC Service Controls, when in fact only the service perimeter and access level are the required logical constructs.

403
MCQhard

A financial services company needs to ensure that all outbound traffic from its Compute Engine instances to the internet goes through a dedicated IP address for allowlisting by a partner. The instances are in a private subnet with no external IP addresses. The company wants to minimize management overhead and avoid single points of failure. Which solution should the architect implement?

A.Assign external IP addresses to all instances and use Cloud DNS to map them to a single hostname for the partner.
B.Configure a Cloud NAT gateway with a manual IP address allocation and attach it to the VPC network in the region where the instances reside.
C.Create a VPN tunnel to the partner's network and route all internet-bound traffic through the partner's gateway.
D.Deploy a third-party firewall appliance on a Compute Engine instance with an external IP and route all outbound traffic through it using a custom route.
AnswerB

Cloud NAT with manual IP allocation lets you reserve specific external IP addresses that are used for all outbound traffic from the private instances. It is a regional, managed service that scales automatically and avoids single points of failure, meeting the allowlisting requirement with minimal management overhead.

Why this answer

Cloud NAT with manual IP allocation is the correct solution because it provides a managed, regional service that uses reserved external IP addresses for outbound traffic from private instances. It scales automatically, has no single point of failure, and requires minimal operational effort, directly satisfying the partner allowlisting requirement.

Exam trap

The trap here is thinking that a self-managed NAT instance or VPN is needed for a dedicated egress IP, when Cloud NAT with manual IP allocation provides this as a managed service.

404
MCQmedium

A healthcare company is migrating a legacy on-premises Oracle database to Google Cloud. The database is used for a patient records application that requires strong consistency, ACID transactions, and a relational schema with complex joins. The company wants a fully managed, highly available relational database service that minimizes administrative overhead while supporting their existing SQL workloads. Which Google Cloud service should they choose?

A.Cloud Spanner
B.Bigtable
C.Firestore
D.Cloud SQL for PostgreSQL
AnswerD

Cloud SQL for PostgreSQL is a fully managed relational database service that supports ACID transactions, complex joins, and strong consistency, making it ideal for migrating Oracle workloads that require a relational schema. It handles replication, backups, and patching automatically, reducing administrative overhead. The service supports high availability configurations with automatic failover, aligning with the healthcare application's requirements for uptime and data integrity.

Why this answer

Cloud SQL for PostgreSQL is the best choice because it provides a fully managed relational database with ACID compliance, strong consistency, and support for complex SQL queries, matching the legacy Oracle workload's needs. It reduces operational burden with automated backups, replication, and high availability. Other options are either NoSQL databases lacking relational features or overly complex for the required scale.

Exam trap

The trap here is assuming that a globally distributed database like Cloud Spanner is always the best choice for relational workloads, when in fact it may be overkill and incompatible with existing Oracle SQL syntax.

405
MCQeasy

A company wants to provision multiple similar environments (dev, test, prod) with consistent networking configurations. Which approach is a best practice for infrastructure as code?

A.Use Ansible playbooks to run ad-hoc commands.
B.Use a single Terraform configuration with workspaces.
C.Run separate gcloud commands for each environment.
D.Use Cloud Deployment Manager templates with environment-specific parameters.
AnswerB

Workspaces allow reusable configuration across environments.

Why this answer

Terraform workspaces allow you to manage multiple distinct environments (e.g., dev, test, prod) from a single configuration by maintaining separate state files. This ensures consistent networking configurations across environments while avoiding duplication of code, which is a core best practice for infrastructure as code.

Exam trap

Google Cloud often tests the misconception that environment-specific parameters in Deployment Manager templates are equivalent to Terraform workspaces, but the trap is that Terraform's workspace feature provides native state isolation and multi-cloud portability, whereas Deployment Manager is GCP-specific and lacks the same level of abstraction for consistent multi-environment management.

How to eliminate wrong answers

Option A is wrong because Ansible playbooks are primarily for configuration management and ad-hoc command execution, not for declaratively provisioning cloud infrastructure with state management and drift detection. Option C is wrong because running separate gcloud commands for each environment is imperative, error-prone, and lacks version control and repeatability, violating IaC principles. Option D is wrong because Cloud Deployment Manager templates with environment-specific parameters can work but are less portable and flexible than Terraform workspaces, and Terraform is the more widely adopted multi-cloud IaC tool for consistent provisioning.

406
MCQhard

A financial services firm runs a regulated workload in a Google Cloud organization. Compliance requires that no resource in any project can be created outside a defined set of approved regions, and that violations are blocked before resource creation rather than reported afterward. The organization has many projects and new projects are created frequently. Which approach should the architect implement?

A.Deploy an organization policy using compute.restrictVpcPeering and rely on network topology to limit regions
B.Enable VPC Service Controls perimeters around each project and restrict egress to unapproved regions
C.Write a Cloud Asset Inventory feed that triggers a Cloud Function to delete non-compliant resources
D.Create an organization policy with the location restriction constraint (constraints/gcp.resourceLocations) applied at the organization node
AnswerD

An organization policy using the location restriction constraint inherits down the resource hierarchy, so every current and future project in the organization is covered without per-project configuration. It enforces the allowed regions at resource-creation time, which is exactly the preventive control the compliance team requires rather than a detective control.

Why this answer

Organization policies are preventive controls that inherit through the resource hierarchy, so a location restriction set at the organization node automatically applies to every existing and future project. VPC Service Controls, VPC peering constraints, and asset-based remediation either govern the wrong thing or act only after the fact, so none of them blocks resource creation in a prohibited region.

Exam trap

The trap here is confusing VPC Service Controls, which govern data access and exfiltration, with organization policies, which govern resource configuration and placement.

407
MCQhard

A financial services company runs a latency-sensitive trading application on GKE. The platform team must guarantee that the application can be recovered within a 15-minute recovery time objective (RTO) and a 5-minute recovery point objective (RPO) after a regional failure. They use a multi-region Cloud Storage bucket for configuration and a regional GKE cluster. Which additional design element is required to meet both objectives?

A.Enable GKE cluster autoscaling and configure a horizontal pod autoscaler for the trading pods.
B.Configure the existing regional GKE cluster with a node pool in each of the three zones of its region and enable pod anti-affinity.
C.Use Anthos Config Management to sync configurations to the existing cluster and enable Binary Authorization for the trading images.
D.Deploy a second regional GKE cluster in another region and use a multi-region Cloud Storage bucket for shared configuration, with a documented failover runbook.
AnswerD

A standby regional GKE cluster in a different region provides compute capacity to restart workloads when the primary region fails. Because configuration is stored in a multi-region Cloud Storage bucket, it remains accessible during the failover, supporting a short RPO. A documented runbook ensures the team can perform failover within the 15-minute RTO.

Why this answer

Meeting a 15-minute RTO and 5-minute RPO after a regional failure requires compute capacity and configuration data available outside the failed region. A standby GKE cluster in another region supplies the compute, while a multi-region Cloud Storage bucket keeps configuration accessible. A rehearsed failover runbook ensures the team can switch over quickly enough to satisfy the RTO.

Exam trap

The trap here is treating multi-zone node pools within a single region as sufficient for a regional failure, when they only protect against zone-level outages.

408
MCQmedium

A company has a Cloud SQL for PostgreSQL instance in a single zone. To achieve high availability, they want to ensure automatic failover with zero data loss and minimal downtime. Which configuration should they use?

A.Deploy a read replica in the same zone and enable automatic failover
B.Enable automatic backups and point-in-time recovery
C.Add a cross-region read replica and configure failover manually
D.Configure a Cloud SQL regional instance with a failover replica in a different zone
AnswerD

A Cloud SQL regional instance maintains a synchronous standby replica in a different zone within the same region. Synchronous replication guarantees zero data loss (RPO of zero), while automatic failover to the standby delivers minimal downtime, satisfying both the high availability and no-data-loss constraints in the stem.

Why this answer

A Cloud SQL regional instance provisions a standby replica in a different zone within the same region and performs automatic failover with synchronous replication, ensuring zero data loss (RPO=0) and minimal downtime. This is the standard HA configuration for Cloud SQL for PostgreSQL.

Exam trap

PCA often tests the misconception that read replicas provide HA failover; in Cloud SQL, only a regional instance with a standby replica delivers automatic zero-data-loss failover.

How to eliminate wrong answers

Option A is wrong because read replicas use asynchronous replication and cannot be promoted automatically as an HA failover target — they are for read scaling, not HA. Option B is wrong because backups and PITR address data recovery after corruption or deletion, not automatic failover; they involve restore downtime and potential data loss up to the last backup/binlog. Option C is wrong because cross-region read replicas are for disaster recovery and read offload, and failover (promotion) is a manual operation with asynchronous replication, so it does not meet zero-data-loss or automatic failover requirements.

409
MCQhard

A data engineer needs to automatically detect and redact sensitive data such as credit card numbers from text files uploaded to Cloud Storage before the data is loaded into BigQuery. Which GCP service should be used?

A.Cloud Data Loss Prevention (DLP) API
B.Cloud KMS
C.Cloud Audit Logs
D.Cloud Vision API
AnswerA

The Cloud DLP API inspects content using infoType detectors, identifying credit card numbers and other sensitive patterns, then applies de-identification transforms such as redaction. It integrates with Cloud Storage and BigQuery pipelines, so text files can be sanitised before loading, satisfying the automatic detection-and-redaction requirement.

Why this answer

Cloud Data Loss Prevention (DLP) API is purpose-built to discover, classify, and redact sensitive data such as credit card numbers, social security numbers, and other PII from text and structured content. It can be integrated into a pipeline that scans files in Cloud Storage before loading into BigQuery, applying de-identification transformations like masking or tokenization. No other listed service provides sensitive-data detection and redaction capabilities.

Exam trap

The trap is confusing security services: candidates may pick Cloud KMS thinking encryption equals redaction, or Cloud Audit Logs thinking auditing equals data protection; the key is recognizing that only DLP performs content inspection and de-identification.

How to eliminate wrong answers

Option B is wrong because Cloud KMS manages encryption keys and performs cryptographic operations; it does not inspect content for sensitive data patterns or redact them. Option C is wrong because Cloud Audit Logs record administrative and data access activity for auditing; they do not scan or transform data content. Option D is wrong because Cloud Vision API performs image analysis tasks such as label detection and OCR; it is not designed for PII detection or redaction in text files.

410
MCQhard

An organization requires that all Compute Engine instances in a project must have a specific tag for firewall rule compliance. How can they enforce this?

A.Use IAM roles to restrict instance creation
B.Use a startup script to add the tag
C.Use a mandatory tag via organization policy
D.Use Cloud Asset Inventory
AnswerC

Organization policies can enforce constraints like `compute.requireTags`.

Why this answer

Organization Policies in Google Cloud can enforce constraints that require resources, including Compute Engine instances, to have specific labels or tags. The `compute.requireOsLogin` or custom constraint `compute.requireInstanceTag` can be used to mandate that all instances must have a particular tag, and any instance creation that violates this policy will be denied at the API level, ensuring compliance without relying on user behavior.

Exam trap

The trap here is that candidates often confuse IAM roles with Organization Policies, thinking that restricting creation permissions (Option A) is sufficient, but IAM cannot enforce resource-level attributes like tags, which is a common misconception in policy-based governance questions.

How to eliminate wrong answers

Option A is wrong because IAM roles control who can create instances, not what tags are applied to the instances; they cannot enforce a specific tag value. Option B is wrong because a startup script runs after the instance is created, so it cannot prevent the creation of an instance without the required tag, and the instance would already exist in violation of the firewall rule compliance. Option D is wrong because Cloud Asset Inventory is a service for discovering and monitoring cloud resources, not for enforcing policies or preventing non-compliant resource creation.

411
MCQhard

A healthcare company stores patient records in Cloud Storage buckets across multiple projects. An audit reveals that several buckets containing protected health information are publicly accessible. The security team wants a centralized, automated way to detect and remediate public access across all current and future projects, with minimal operational effort. Which solution should the architect recommend?

A.Deploy a Forseti Security instance to scan all projects and automatically remove public IAM bindings.
B.Use Security Command Center with the built-in Cloud Storage public access finding and configure automated remediation via Cloud Functions.
C.Create an organization policy constraint that disables public access on all Cloud Storage buckets.
D.Enable uniform bucket-level access on all buckets and rely on Cloud Audit Logs to detect public access.
AnswerB

Security Command Center detects publicly accessible Cloud Storage buckets as a built-in finding and can aggregate findings across all projects in an organization. Automated remediation can be triggered from the finding using Pub/Sub and Cloud Functions to remove public IAM bindings or apply public access prevention. This provides centralized detection and remediation with minimal operational effort.

Why this answer

Security Command Center provides centralized, organization-wide detection of publicly accessible Cloud Storage buckets through built-in findings. By routing findings to Pub/Sub and triggering Cloud Functions, the team can automatically remediate public access across all current and future projects. Organization policy constraints prevent new exposures but do not detect or fix existing ones, and legacy tools like Forseti are deprecated.

Exam trap

The trap here is confusing prevention controls like organization policy constraints with detection and remediation capabilities, when the scenario explicitly requires both detection and automated remediation.

412
MCQeasy

Which Google Cloud service automatically computes the optimal size or tier for underutilized Compute Engine instances and generates recommendations to reduce cost?

A.Cloud Monitoring
B.Cloud Profiler
C.Cost Management
D.Recommender (Active Assist)
AnswerD

Recommender, part of Active Assist, analyses Compute Engine utilisation metrics and generates rightsizing recommendations for underutilised instances. It automatically computes the optimal machine type or tier, directly satisfying the requirement to reduce cost through sizing guidance.

Why this answer

Recommender (part of Active Assist) analyzes Compute Engine utilization and automatically generates rightsizing recommendations to reduce cost by resizing underutilized VMs. It is the GCP service specifically built to surface optimal machine type and size suggestions.

Exam trap

PCA often tests the difference between monitoring, cost reporting, and recommendation engines — candidates pick Cost Management because it 'reduces cost,' but only Recommender (Active Assist) computes optimal sizes and tiers.

How to eliminate wrong answers

Option A is wrong because Cloud Monitoring collects metrics and creates dashboards/alerts but does not generate rightsizing recommendations. Option B is wrong because Cloud Profiler analyzes application CPU and memory usage at the code level for performance tuning, not VM rightsizing for cost. Option C is wrong because Cost Management (Cloud Billing reports and budgets) shows spend and forecasts but does not compute optimal instance sizes or tiers.

413
MCQhard

An e-commerce platform uses Cloud Spanner in a multi-region configuration. They want to achieve the highest possible availability SLA. Which deployment configuration should they choose?

Answer options not yet available.

Why this answer

Cloud Spanner offers a 99.999% SLA for multi-region configurations. To achieve this, you must use a multi-region instance (e.g., nam3, eur3) that replicates data across at least three regions. A single-region configuration only offers 99.99% SLA.

414
MCQhard

Your company uses Cloud Monitoring to track the performance of a microservices application. The SRE team wants to define an SLO for the latency of a critical API. They need to measure the proportion of requests that complete within 200 ms over a rolling 30-day window. Which approach should they use to implement this SLO?

A.Configure a log-based metric that counts requests with latency under 200 ms, then create an alert if the count drops.
B.Use Cloud Monitoring's SLO monitoring feature to define a latency SLO with a distribution cut based on a histogram metric.
C.Set up an uptime check that measures the API response time and alerts if it exceeds 200 ms.
D.Create a custom metric that logs each request latency, then use a dashboard to manually calculate the percentage within 200 ms.
AnswerB

Cloud Monitoring's SLO monitoring allows you to define service level objectives based on metrics. For latency, you can use a distribution cut on a histogram metric to specify the threshold (200 ms) and calculate the ratio of good requests to total requests over a rolling window. This provides automated tracking, error budget calculation, and alerting.

Why this answer

Cloud Monitoring's SLO monitoring is designed for defining and tracking SLOs. Using a distribution cut on a histogram metric allows precise measurement of the proportion of requests within the latency threshold over a rolling period. It also provides error budget and alerting, which are essential for SRE practices.

Exam trap

The trap here is confusing uptime checks with latency SLOs; uptime checks measure availability from external probes, not the latency distribution of actual user requests.

415
MCQmedium

Your team uses Cloud SQL for PostgreSQL for an e-commerce application. You want to perform point-in-time recovery (PITR) to recover from a logical error that occurred 10 minutes ago. Which prerequisites are required?

A.Automated backups must be enabled, and the instance must be using the InnoDB storage engine
B.Automated backups and binary logging must be enabled
C.Point-in-time recovery is not supported for Cloud SQL PostgreSQL
D.Automated backups must be enabled, and write-ahead logging (WAL) must be active
AnswerD

Automated backups and write-ahead logging are the two prerequisites Cloud SQL for PostgreSQL requires for point-in-time recovery. WAL archiving captures continuous transaction logs, while automated backups supply the base snapshot; together they let you restore to any moment within the retention window, satisfying the 10-minute recovery target.

Why this answer

For Cloud SQL for PostgreSQL, point-in-time recovery (PITR) requires that automated backups are enabled and that write-ahead logging (WAL) is active. WAL archiving captures all changes, allowing recovery to any point within the retention period. Automated backups provide the base backup from which WAL is replayed.

Exam trap

The trap is confusing MySQL terminology (binary logging, InnoDB) with PostgreSQL (WAL), or assuming PITR is not supported for PostgreSQL.

How to eliminate wrong answers

Option A is wrong because InnoDB is a MySQL storage engine, not PostgreSQL. Option B is wrong because binary logging is a MySQL concept; PostgreSQL uses WAL. Option C is wrong because PITR is supported for Cloud SQL PostgreSQL when prerequisites are met.

416
MCQhard

A logistics company runs a latency-sensitive order-tracking service on Compute Engine instances spread across three zones in one region. They need the architecture to survive the loss of an entire zone while keeping inter-instance latency low, and they want automatic failover without manual intervention. Which design should the architects implement?

A.Deploy a managed instance group in each of the three zones separately, and place a global external Application Load Balancer in front of all three groups.
B.Deploy a managed instance group with regional distribution across the three zones, front it with a regional external Application Load Balancer, and configure health checks with autoscaling.
C.Deploy standalone Compute Engine instances in each of the three zones with static external IPs and use DNS round-robin to distribute client traffic.
D.Deploy a managed instance group in a single zone, front it with a global external Application Load Balancer, and rely on the load balancer to fail over across regions.
AnswerB

A regional managed instance group spreads instances across zones, so losing one zone leaves capacity in the others. A regional load balancer with health checks automatically stops sending traffic to unhealthy instances and resumes when they recover, delivering unattended failover while keeping traffic within the region for low latency.

Why this answer

Spreading a regional managed instance group across three zones means a zone outage only removes a fraction of capacity, and health-checked load balancing automatically diverts traffic from failed instances and restores it on recovery. This delivers unattended, in-region failover with low latency, unlike single-zone groups, unmanaged instances, or global routing that can add distance.

Exam trap

The trap here is assuming a global load balancer provides zone resilience even when the backend instances all live in a single zone, where there is nothing to fail over to.

417
MCQmedium

The exhibit shows the output of a 'gcloud compute instances describe' command for an instance. What is the most likely impact on reliability if the host machine needs maintenance?

A.The instance will be terminated and then restarted, causing a brief downtime.
B.The instance will not be affected because automatic restart is enabled.
C.The instance will be backed up automatically before maintenance.
D.The instance will be live migrated to another host without interruption.
AnswerA

With TERMINATE, the instance is shut down and later restarted on a healthy host, resulting in downtime.

Why this answer

When a host machine requires maintenance, Google Compute Engine instances that are not configured for live migration will be terminated and then restarted on another host. This behavior is determined by the 'onHostMaintenance' setting; if it is set to 'TERMINATE' (the default for instances with GPUs or preemptible VMs), the instance stops and restarts, causing brief downtime. The exhibit likely shows 'onHostMaintenance: TERMINATE' or the instance lacks live migration support, making termination and restart the expected outcome.

Exam trap

Google Cloud often tests the distinction between 'automatic restart' (which handles crash recovery) and 'onHostMaintenance' (which handles planned maintenance), causing candidates to mistakenly think automatic restart prevents downtime during maintenance.

How to eliminate wrong answers

Option B is wrong because 'automatic restart' is a separate setting that controls whether an instance restarts after a failure or crash, not how it behaves during host maintenance; it does not prevent downtime from maintenance events. Option C is wrong because Google Compute Engine does not automatically back up instances before host maintenance; backups must be configured separately via snapshots or images. Option D is wrong because live migration is only possible if the instance has 'onHostMaintenance' set to 'MIGRATE' and does not have GPUs, local SSDs, or preemptible status; the exhibit likely shows a configuration that disables live migration, such as a GPU attached or the setting explicitly set to 'TERMINATE'.

418
MCQmedium

A security team needs to detect and redact personally identifiable information (PII) from documents uploaded to Cloud Storage before they are stored. Which GCP service should they use?

A.Cloud Audit Logs
B.Cloud Data Loss Prevention (DLP) API
C.Security Command Center
D.Access Transparency
AnswerB

Cloud DLP API inspects and de-identifies sensitive data such as PII, satisfying the requirement to redact before storage. Its `deidentify` method applies infoType detectors and transformation techniques like masking or tokenisation directly to uploaded content, so documents reach Cloud Storage already sanitised rather than relying on post-storage scanning.

Why this answer

Cloud Data Loss Prevention (DLP) API is purpose-built to inspect, classify, and de-identify sensitive data such as PII, PHI, and credentials. It can scan Cloud Storage objects and apply infoType detectors (e.g., US_SOCIAL_SECURITY_NUMBER, EMAIL_ADDRESS) with redaction, masking, tokenization, or bucketing transforms before the data is persisted. This directly matches the requirement to detect and redact PII prior to storage.

Exam trap

PCA often tests the misconception that Cloud Audit Logs or Security Command Center can inspect and redact data content, when in fact only DLP performs content-level PII detection and de-identification.

How to eliminate wrong answers

Option A is wrong because Cloud Audit Logs only record administrative and data-access activity (who did what, when, where) — they do not inspect content or redact PII. Option C is wrong because Security Command Center aggregates findings and posture data across GCP assets but does not perform content-level PII detection or redaction on uploaded objects. Option D is wrong because Access Transparency provides logs about Google personnel access to customer data, not a data-inspection or redaction engine.

419
MCQeasy

A retail company runs a stateless web tier on a managed instance group (MIG) of Compute Engine VMs behind an external Application Load Balancer. Traffic spikes every evening and the operations team currently resizes the MIG manually. They want the group to add and remove VMs automatically based on CPU utilization without changing the instance template. What should the architect configure?

A.A Cloud Scheduler job that calls the Compute Engine API to resize the managed instance group every evening.
B.A network endpoint group (NEG) that automatically registers new VM instances when CPU usage rises.
C.A preemptible VM pool that the load balancer adds to the backend service during peak hours.
D.An autoscaling policy on the managed instance group using a CPU utilization target.
AnswerD

Autoscaling policies on a MIG add or remove instances based on signals such as average CPU utilization across the group. Because the web tier is stateless and already sits behind a load balancer, scaling the MIG horizontally is the intended pattern and requires no changes to the instance template.

Why this answer

A managed instance group autoscaling policy is the native mechanism for adding and removing Compute Engine VMs in response to load signals such as CPU utilization. Because the web tier is stateless and already behind a load balancer, horizontal scaling is safe and does not require rebuilding the instance template.

Exam trap

The trap here is assuming that scheduling a resize or using preemptible capacity counts as autoscaling, when only a MIG autoscaling policy reacts automatically to utilization metrics.

420
MCQhard

An engineer is troubleshooting a Cloud Build trigger that fails with the error 'PERMISSION_DENIED: Cloud Build service account does not have permission to access Artifact Registry'. The build needs to push a Docker image to Artifact Registry. What is the correct IAM role to assign to the Cloud Build service account?

A.roles/artifactregistry.writer
B.roles/artifactregistry.viewer
C.roles/editor
D.roles/storage.objectAdmin
AnswerA

Granting roles/artifactregistry.writer provides the write permissions Cloud Build requires to push Docker images into Artifact Registry, satisfying the PERMISSION_DENIED constraint. This role permits uploading and creating repository content without granting broader administrative capabilities, so the build service account can complete its image push securely.

Why this answer

Cloud Build's service account needs to push images to Artifact Registry, which requires write access to repositories. The predefined role roles/artifactregistry.writer grants exactly the permissions needed to upload and delete artifacts (including Docker image push) within Artifact Registry repositories. Assigning this role to the Cloud Build service account resolves the PERMISSION_DENIED error while following least privilege.

Exam trap

The trap is assuming that a broad role like roles/editor or a storage-related role will cover Artifact Registry access — the exam expects you to know the service-specific predefined roles and to apply least privilege.

How to eliminate wrong answers

Option B is wrong because roles/artifactregistry.viewer only allows reading and listing artifacts, not pushing or writing them, so the build would still fail with PERMISSION_DENIED. Option C is wrong because roles/editor is a broad basic role that grants excessive permissions across many services and violates least privilege; while it may technically allow the push, it is not the correct or recommended answer for this scenario. Option D is wrong because roles/storage.objectAdmin applies to Cloud Storage buckets, not Artifact Registry repositories, so it does not grant the required artifactregistry.* permissions.

421
Multi-Selectmedium

Which TWO actions are required to allow a private GKE cluster to pull container images from Artifact Registry in the same project?

Select 2 answers
A.Create a firewall rule allowing outbound traffic to Artifact Registry IP ranges.
B.Set up VPC Network Peering with the Artifact Registry service.
C.Configure Cloud NAT for the GKE cluster.
D.Enable Private Google Access on the subnet where the GKE nodes are deployed.
E.Grant the Artifact Registry Reader role to the GKE service account.
AnswersD, E

Private Google Access allows nodes without external IPs to reach Google APIs.

Why this answer

Private Google Access enables GKE nodes with only internal IP addresses to reach Google APIs and services, including Artifact Registry, over Google's private network rather than the public internet. Option E is correct because the GKE node's service account must have the Artifact Registry Reader role (roles/artifactregistry.reader) to authenticate and pull container images from the registry.

Exam trap

Google Cloud often tests the misconception that Cloud NAT is required for private clusters to access Google APIs, but Private Google Access is the correct mechanism for reaching Google-managed services like Artifact Registry without public IPs.

422
MCQmedium

A company needs to connect their on-premises data center to Google Cloud with a dedicated, low-latency, and highly available connection. They require at least 10 Gbps throughput and want to avoid internet-based VPN. Which connectivity option should they choose?

A.Dedicated Cloud Interconnect
B.Partner Cloud Interconnect
C.Classic VPN
D.HA VPN
AnswerA

Dedicated Cloud Interconnect provisions a private physical circuit into Google's network, delivering the 10 Gbps minimum with low latency and redundancy. It bypasses the public internet entirely, unlike HA VPN, meeting the dedicated and highly available requirements.

Why this answer

Dedicated Cloud Interconnect provides a direct physical connection between the on-premises network and Google Cloud, bypassing the public internet. It supports high bandwidth (10 Gbps and 100 Gbps circuits) with low latency and can be provisioned redundantly for high availability, meeting the 10 Gbps and dedicated requirements. Partner Interconnect goes through a service provider and may not guarantee the same dedicated path.

Exam trap

PCA often tests the confusion between Dedicated and Partner Interconnect, and the misconception that HA VPN satisfies a 'dedicated, non-internet' requirement when it is still internet-based.

How to eliminate wrong answers

Option B is wrong because Partner Cloud Interconnect connects through a supported service provider rather than a direct Google facility, which may not meet the dedicated, low-latency requirement and typically offers lower maximum bandwidth per connection. Option C is wrong because Classic VPN is an internet-based IPsec VPN and explicitly violates the 'avoid internet-based VPN' requirement. Option D is wrong because HA VPN, while highly available, is still an internet-based VPN and does not provide dedicated private connectivity.

423
Multi-Selectmedium

A company runs a web application on GKE and wants to expose it to the internet using a global HTTP(S) load balancer with Cloud CDN. Which TWO GCP resources are required to configure this setup? (Choose TWO.)

Select 2 answers
A.Kubernetes Ingress resource with a GCE ingress controller
B.Cloud NAT gateway
C.Backend service with health check configuration
D.A Kubernetes Service of type LoadBalancer
E.Cloud VPN tunnel
AnswersA, C

A Kubernetes Ingress with the GCE ingress controller provisions the external HTTP(S) load balancer and wires GKE services to it. It satisfies the requirement to expose the application globally, and its annotations enable Cloud CDN on the resulting load balancer.

Why this answer

Option A is correct because a Kubernetes Ingress resource managed by the GCE ingress controller is what triggers GKE to provision a global external HTTP(S) load balancer and wire it to the application's Service; the ingress annotations (e.g., kubernetes.io/ingress.class: gce) and BackendConfig enable Cloud CDN on the resulting backend. Option C is correct because the global HTTP(S) load balancer requires a backend service that defines the instance groups/NEGs and a health check to determine which backends are healthy and eligible to receive traffic. Option B is not needed because Cloud NAT provides outbound internet access for private instances, not inbound load balancing.

Option D is not required because a ClusterIP Service is sufficient as the Ingress backend; a Service of type LoadBalancer would instead provision a separate network load balancer and is not how GCE Ingress exposes apps. Option E is not relevant because Cloud VPN provides encrypted connectivity between networks, not internet-facing HTTP(S) load balancing.

Exam trap

The trap here is that candidates often confuse a Kubernetes Service of type LoadBalancer (which creates a regional Layer 4 load balancer) with the need for a global HTTP(S) load balancer, failing to recognize that only an Ingress with the GCE controller can provide the global, Layer 7 load balancing required for Cloud CDN.

424
MCQmedium

An organization has multiple GCP projects managed by a central operations team. They want to define a common VPC configuration in a host project and allow service projects to use it. Which networking feature should they use?

A.Shared VPC
B.Private Service Connect
C.Cloud VPN
D.VPC peering
AnswerA

Shared VPC lets a host project export subnets to service projects, so the central team retains control of the VPC configuration while each service project deploys its own resources into those shared subnets. This directly satisfies the requirement for one common VPC defined centrally and reused across multiple GCP projects.

Why this answer

Shared VPC allows an organization to designate a host project that owns the VPC network and subnets, and then attach service projects so their resources (VMs, GKE clusters, etc.) can use that shared network. This centralizes network administration under the operations team while letting service teams deploy workloads in their own projects. It is the canonical GCP feature for exactly this host-project/service-project pattern.

Exam trap

The trap is confusing VPC peering with Shared VPC — peering connects two independently managed VPCs, whereas Shared VPC centralizes ownership in a host project, which is what the question's 'host project / service project' wording demands.

How to eliminate wrong answers

Option B is wrong because Private Service Connect is used to privately access Google APIs or third-party services via internal IP endpoints, not to share a VPC network across projects. Option C is wrong because Cloud VPN provides encrypted tunnels between on-premises or other clouds and a VPC, not cross-project VPC sharing. Option D is wrong because VPC peering connects two separate VPC networks so they can communicate, but each project still owns and manages its own VPC — it does not provide the centralized host-project ownership model the question requires.

425
Multi-Selectmedium

A team is deploying a stateful application on GKE. They want to ensure that the application's pods are distributed across different zones for high availability and that during cluster upgrades, at least one pod remains available. Which THREE features should they configure?

Select 3 answers
A.Pod topology spread constraints
B.StatefulSet for the application
C.Cluster autoscaler
D.Horizontal Pod Autoscaler
E.PodDisruptionBudget
AnswersA, B, E

Pod topology spread constraints control how pods are distributed across topology domains such as zones, letting you require even spreading so replicas land in different zones. This satisfies the high-availability requirement by preventing all pods being scheduled into a single zone.

Why this answer

Option A (Pod topology spread constraints) is correct because topologySpreadConstraints with topologyKey set to topology.kubernetes.io/zone (and a whenUnsatisfiable policy such as DoNotSchedule or ScheduleAnyway) explicitly spreads pods evenly across zones, which is exactly what the team needs for zonal high availability. Option B (StatefulSet) is correct because a stateful application requires stable network identities, ordered deployment/scaling, and persistent volume claims per replica, all of which StatefulSet provides via its governing Service and volumeClaimTemplates. Option E (PodDisruptionBudget) is correct because a PDB with minAvailable: 1 (or maxUnavailable: 0) ensures that during voluntary disruptions such as node drains in a cluster upgrade, at least one pod remains running.

Option C (Cluster autoscaler) is not correct because it only adds or removes nodes based on pending pods and resource pressure; it does not control zonal pod distribution or guarantee availability during upgrades. Option D (Horizontal Pod Autoscaler) is not correct because it scales replica counts based on metrics like CPU or custom metrics, which addresses load-based scaling rather than zonal spreading or upgrade-time availability guarantees.

Exam trap

The trap is picking autoscaling features (Cluster Autoscaler, HPA) as if they provide HA — they scale capacity, not placement or disruption protection, which is what the question actually asks for.

426
MCQmedium

A financial services company runs a regulated workload on Compute Engine in a single project. Auditors require that all data written to persistent disks, including boot disks, is encrypted with keys the company controls and can revoke on demand, without the company operating its own key management infrastructure. The security lead must choose an encryption approach that satisfies this requirement with the least operational overhead. What should the security lead do?

A.Enable Confidential VM on all instances so that memory and disk contents are protected by encryption keys generated and held inside the hardware.
B.Rely on Google-managed encryption keys, which rotate automatically, and use Cloud External Key Manager to wrap the keys after the fact.
C.Configure customer-managed encryption keys (CMEK) in Cloud KMS and set the project-level default key so new persistent disks are encrypted with the company's key.
D.Use customer-supplied encryption keys (CSEK) passed to the Compute Engine API so the company holds the raw key material outside of Google Cloud.
AnswerC

CMEK lets the company own and rotate the key material in Cloud KMS while Google manages the HSM-backed infrastructure. Setting a project-level default key ensures every newly created persistent disk, including boot disks, is encrypted with that key, and disabling or destroying the key version makes the data unreadable, satisfying revocability without the company running its own key infrastructure.

Why this answer

CMEK in Cloud KMS is the correct fit because the company retains ownership and control of the key while Google operates the HSM-backed key infrastructure. Setting a project-level default key ensures new persistent disks and boot disks use the company's key automatically, and disabling a key version immediately makes the data inaccessible, meeting the revocability requirement with minimal operational effort.

Exam trap

The trap here is assuming that Confidential VM or CSEK provides revocable company-controlled disk encryption, when only CMEK with a project default key satisfies both control and low overhead.

427
MCQmedium

A company is migrating its on-premises Oracle database to Cloud SQL for PostgreSQL. The database team wants to minimize downtime during migration. Which approach should they use?

A.Set up Oracle GoldenGate to replicate to Cloud SQL.
B.Use Database Migration Service for PostgreSQL with continuous migration from Oracle via Homogeneous Migration.
C.Take a physical backup of Oracle and restore to Cloud SQL.
D.Export the database as a dump file, upload to Cloud Storage, and import into Cloud SQL.
AnswerB

DMS supports minimal downtime via continuous replication.

Why this answer

Database Migration Service (DMS) for PostgreSQL with continuous migration is the correct approach because it supports ongoing change data capture (CDC) from Oracle to Cloud SQL for PostgreSQL, enabling near-zero downtime. DMS handles schema conversion and data replication continuously, allowing the target to stay synchronized until a cutover, which minimizes downtime compared to batch methods.

Exam trap

Google Cloud often tests the misconception that any 'migration service' automatically supports heterogeneous migrations, but here the trap is that Database Migration Service for PostgreSQL is specifically designed for PostgreSQL targets and includes built-in schema conversion from Oracle, whereas options like GoldenGate or dump/restore are either too complex or cause downtime.

How to eliminate wrong answers

Option A is wrong because Oracle GoldenGate is a third-party tool that requires separate licensing, complex configuration, and is not natively integrated with Cloud SQL for PostgreSQL; it is overkill and not the recommended Google Cloud service for this migration. Option C is wrong because a physical backup of Oracle (e.g., RMAN) is platform-specific and cannot be directly restored to Cloud SQL for PostgreSQL, which uses a different database engine and storage format. Option D is wrong because exporting as a dump file and importing is a one-time, offline process that requires the source database to be quiesced or taken offline, causing significant downtime, and does not support continuous replication.

428
MCQhard

A financial services company uses VPC Service Controls to protect their project containing BigQuery datasets and Cloud Storage buckets. They have a perimeter that includes the BigQuery service. Users report that they cannot export data from BigQuery to Cloud Storage using the web console. The export job fails with an access denied error. The team needs to allow exports while maintaining data exfiltration prevention. The users have the necessary IAM permissions (BigQuery Data Editor, Storage Object Admin) on the appropriate resources. What should the architect do?

A.Add Cloud Storage to the same VPC Service Controls perimeter.
B.Remove BigQuery from the VPC Service Controls perimeter.
C.Create an access level that permits exports during business hours.
D.Grant the users the Storage Object Admin role at the bucket level.
AnswerA

VPC Service Controls blocks cross-perimeter data movement, so the BigQuery-to-Cloud-Storage export is denied because Cloud Storage sits outside the perimeter. Adding Cloud Storage to the same perimeter authorises that API path while preserving exfiltration prevention, satisfying the requirement to allow exports without weakening controls.

Why this answer

VPC Service Controls perimeters enforce data exfiltration prevention by default, blocking egress from protected services (like BigQuery) to unprotected services (like Cloud Storage). Adding Cloud Storage to the same perimeter allows BigQuery to export data to Cloud Storage while still preventing data from leaving the perimeter. The users already have the necessary IAM roles (BigQuery Data Editor and Storage Object Admin), so the issue is solely the perimeter boundary, not permissions.

Exam trap

The trap here is that candidates often confuse IAM permissions with VPC Service Controls boundaries, assuming that granting the correct IAM roles (like Storage Object Admin) will resolve the access denied error, when in fact the error is caused by the perimeter blocking cross-service egress, not by insufficient IAM privileges.

How to eliminate wrong answers

Option B is wrong because removing BigQuery from the perimeter would disable all VPC Service Controls protections for BigQuery, exposing the datasets to data exfiltration risks, which contradicts the requirement to maintain data exfiltration prevention. Option C is wrong because access levels control ingress based on client attributes (e.g., IP address, device state) and do not affect egress permissions between services within a perimeter; the export failure is a perimeter boundary issue, not an access level restriction. Option D is wrong because the users already have the Storage Object Admin role at the bucket level (as stated in the question), and the error is an access denied from the perimeter, not from IAM; granting the same role again does not resolve the VPC Service Controls boundary.

429
MCQeasy

A healthcare company needs to run a stateful, containerized electronic medical records application that requires a stable network identity and persistent disk storage per replica. The operations team is already fluent with Kubernetes. Which Google Cloud service should they choose?

A.Cloud Functions
B.Google Kubernetes Engine with a StatefulSet
C.App Engine flexible environment
D.Cloud Run
AnswerB

GKE with a StatefulSet provides stable, unique network identities and stable per-pod persistent storage through PersistentVolumeClaims, which is exactly what a stateful containerized database-style application needs. Since the operations team already knows Kubernetes, GKE offers the right primitives without requiring them to learn a new platform.

Why this answer

Stateful containerized workloads requiring stable identity and persistent storage per replica map directly to Kubernetes StatefulSets, and the team's existing Kubernetes skills make GKE the natural fit. Serverless container and function platforms abstract away the instance, so they cannot provide per-replica persistent disks or stable network identities.

Exam trap

The trap here is treating any container platform as interchangeable, when only an orchestrator exposing StatefulSets provides stable identity and per-pod persistent storage.

430
MCQeasy

Which IAM role should be granted to a user who needs to view but not modify resources in a project?

A.roles/editor
B.roles/viewer
C.roles/owner
D.roles/browser
AnswerB

roles/viewer grants read-only access to all project resources, satisfying the requirement to view without modifying. It excludes write permissions such as create, update or delete, so the user cannot alter resources. This is the most basic predefined role providing the least privilege needed for the stated task.

Why this answer

The roles/viewer role grants read-only access to all resources within a project, allowing the user to view but not modify them. This aligns with the principle of least privilege for a user who only needs to inspect resources. It includes permissions to list and get resources but not to create, update, or delete.

Exam trap

PCA often tests the distinction between primitive roles, and candidates may incorrectly choose roles/browser thinking it provides view access, but it lacks permissions to view resource contents.

How to eliminate wrong answers

Option A is wrong because roles/editor grants read-write access, allowing modification of resources, which exceeds the requirement. Option C is wrong because roles/owner grants full control, including managing access and billing, which is far beyond viewing. Option D is wrong because roles/browser is a basic role that grants read access to browse resources but does not include permissions to view all resource details (e.g., it lacks get permissions on some resource types), so it is not sufficient for viewing all resources in a project.

431
Multi-Selecthard

Which THREE factors should be considered when choosing a Google Cloud region for deploying a low-latency application serving global users? (Choose three.)

Select 3 answers
A.Proximity to your user base to minimize network latency.
B.Availability of the specific Google Cloud services required by the application.
C.Pricing differences between regions due to variations in compute and storage costs.
D.Compliance with data residency requirements (e.g., GDPR, CCPA).
E.Number of zones in the region to ensure high availability.
AnswersA, B, D

Placing the region close to users shortens the physical network path, directly reducing round-trip latency for a global low-latency application. Distance is the dominant factor because light-speed propagation through fibre cannot be optimised away by configuration.

Why this answer

Option A is correct because placing the region close to the user base reduces round-trip network latency, which is the primary driver of perceived responsiveness for a low-latency application serving global users. Option B is correct because not every Google Cloud service or machine type is available in every region, so you must confirm the required services (for example, specific compute SKUs or managed services) exist in the chosen region before deploying. Option D is correct because data residency and privacy regulations such as GDPR or CCPA can legally require that user data be stored and processed within specific jurisdictions, directly constraining which regions are permissible.

Option C is not among the marked answers because, while regional pricing differences exist, cost optimization is secondary to latency, service availability, and legal compliance when the explicit goal is low-latency global service. Option E is not among the marked answers because the number of zones affects fault tolerance and high availability rather than the latency experienced by global users, and zone count is not the deciding factor for region selection in this scenario.

Exam trap

This exam often tests the misconception that high availability (zones) is equivalent to low latency for global users, but zones only provide redundancy within a region, not reduced network distance for geographically distributed users.

432
MCQhard

An organization has a VPC with two subnets: subnet-a (10.0.1.0/24) and subnet-b (10.0.2.0/24). They launched a Compute Engine instance in subnet-a with an internal IP 10.0.1.2 and a public IP. They want the instance to only allow HTTPS traffic from the internet. Which firewall rule should they create?

A.Ingress rule: allow tcp:0-65535, source 0.0.0.0/0, target tag 'https-server'
B.Egress rule: allow tcp:443, destination 0.0.0.0/0, target tag 'https-server'
C.Ingress rule: allow tcp:443, source 10.0.0.0/16, target tag 'https-server'
D.Ingress rule: allow tcp:443, source 0.0.0.0/0, target tag 'https-server'
AnswerD

An ingress rule permitting tcp:443 from 0.0.0.0/0 satisfies the HTTPS-only requirement, since Google Cloud VPC firewall rules are stateful and default-deny, so all other inbound ports remain blocked. Applying the target tag 'https-server' scopes the rule to the tagged Compute Engine instance in subnet-a, leaving other instances unaffected.

Why this answer

The instance needs to accept incoming HTTPS traffic (TCP port 443) from the internet. An ingress firewall rule with source 0.0.0.0/0 allows traffic from any external IP, and applying it to instances with the target tag 'https-server' ensures only tagged instances are affected. This matches the requirement to allow only HTTPS from the internet.

Exam trap

The trap here is that candidates often confuse ingress vs. egress rules or mistakenly restrict the source to the VPC range (10.0.0.0/16) thinking it includes the internet, when in fact it only allows traffic from within the VPC.

How to eliminate wrong answers

Option A is wrong because it allows all TCP ports (0-65535) from the internet, which violates the requirement to allow only HTTPS traffic (port 443). Option B is wrong because it is an egress rule, which controls outbound traffic from the instance, not inbound HTTPS traffic from the internet. Option C is wrong because it restricts the source to the internal VPC range (10.0.0.0/16), which blocks all internet traffic and does not meet the requirement for allowing HTTPS from the internet.

433
MCQeasy

A developer accidentally deleted a bucket in Cloud Storage. The bucket had object versioning enabled. How can the bucket and its objects be restored?

A.Contact Cloud Support to restore the bucket from the undisclosed backup within a limited time window.
B.Restore the bucket from the Trash in the Cloud Console.
C.Enable bucket lock and then undo deletion.
D.Use the gsutil ls -a command to list deleted buckets and gsutil cp to restore.
AnswerA

Object versioning preserves noncurrent object versions, but deleting the bucket itself removes the container. Only Cloud Support can restore the entire bucket from Google's undisclosed internal backup within the limited window, after which the versioned objects return.

Why this answer

When a Cloud Storage bucket is deleted, even with versioning enabled, the bucket itself is removed along with its objects. Google Cloud does not provide a self-service restore option for deleted buckets; instead, it maintains an internal, undisclosed backup for a limited time (typically 7 days). Only Cloud Support can initiate the restoration process from this backup, making Option A the correct approach.

Exam trap

Google Cloud often tests the misconception that versioning provides a safety net for bucket deletion, but versioning only protects objects within an existing bucket—it does not prevent or undo the deletion of the bucket itself.

How to eliminate wrong answers

Option B is wrong because Cloud Storage does not have a 'Trash' feature for buckets; the Trash in Cloud Console is for Compute Engine resources like VM instances, not for storage buckets. Option C is wrong because bucket lock is a feature for retention policies (e.g., preventing object deletion or modification), not for undoing a bucket deletion; once a bucket is deleted, there is no 'undo deletion' operation. Option D is wrong because the `gsutil ls -a` command lists object versions within an existing bucket, not deleted buckets; there is no `gsutil` command to list or restore a deleted bucket.

434
Matchingmedium

Match each GCP data processing service to its use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Stream and batch data processing (Apache Beam)

Managed Hadoop and Spark clusters

Asynchronous messaging for event ingestion

Visual data integration pipelines

Workflow orchestration (Apache Airflow)

Why these pairings

Dataflow is for unified stream/batch processing, Dataproc manages Spark/Hadoop, BigQuery is a serverless data warehouse, Pub/Sub is for messaging. Common confusions include mixing Dataflow with Dataproc and BigQuery with Pub/Sub.

435
MCQeasy

A small development team is deploying a stateless containerized API on Google Cloud. They want the simplest possible way to run containers without managing servers or Kubernetes clusters, and they want the service to scale to zero when there is no traffic to minimize cost. The API receives HTTP requests from external clients. Which Google Cloud service should the architect recommend?

A.Cloud Run with a container image deployed from Artifact Registry.
B.Google Kubernetes Engine (GKE) Autopilot with a Horizontal Pod Autoscaler.
C.Compute Engine managed instance groups with an autoscaler and an external HTTP(S) load balancer.
D.App Engine standard environment with a custom runtime.
AnswerA

Cloud Run runs containers in a fully managed serverless environment, scales automatically including to zero when there are no requests, and exposes an HTTPS endpoint for external clients. It requires no cluster or node management. This matches the requirement for simplicity, HTTP ingress, and cost minimization through scale-to-zero.

Why this answer

Cloud Run is a fully managed serverless platform for containers. It accepts container images from Artifact Registry, provides an HTTPS endpoint for external clients, and scales instances automatically, including down to zero when idle. This eliminates server and cluster management and directly addresses the cost-minimization goal.

It is the simplest fit among the options for a stateless containerized HTTP API.

Exam trap

The trap here is equating GKE Autopilot with serverless simplicity, when it still requires Kubernetes constructs and does not scale to zero by default.

436
MCQeasy

A developer needs to store a database password securely and access it from a Cloud Run service. Which Google Cloud service should they use?

A.Cloud Storage
B.Firestore
C.Secret Manager
D.Cloud KMS
AnswerC

Secret Manager stores sensitive values such as database passwords encrypted at rest, and Cloud Run can retrieve them at runtime via mounted secrets or the API. This satisfies the requirement to keep the credential secure rather than embedding it in code or environment variables.

Why this answer

Secret Manager is Google Cloud's dedicated service for storing, managing, and accessing sensitive data such as API keys, passwords, and certificates. It provides versioning, IAM-based access control, audit logging, and automatic rotation, and Cloud Run can mount secrets as environment variables or volumes. This makes it the correct choice for storing a database password securely.

Exam trap

The trap is confusing Secret Manager with Cloud KMS — candidates often pick KMS because it deals with keys and encryption, but KMS manages encryption keys, not application secrets like database passwords.

How to eliminate wrong answers

Option A is wrong because Cloud Storage is object storage for files and blobs, not a secrets management service — storing a password there lacks versioning, rotation, and fine-grained secret-specific access controls. Option B is wrong because Firestore is a NoSQL document database for application data, not a secure secret store. Option D is wrong because Cloud KMS manages encryption keys used to encrypt data, but it does not store application secrets like passwords; you would use KMS to encrypt a secret, but Secret Manager is the store.

437
MCQhard

A global gaming company deploys a leaderboard service using Cloud Spanner with a single-region configuration. They need a Recovery Point Objective (RPO) of 5 seconds and a Recovery Time Objective (RTO) of 1 minute in the event of a regional outage. What should they do?

A.Set up a cross-region read replica using Cloud SQL.
B.Use Compute Engine instances in multiple zones with a global load balancer to replicate data.
C.Configure cross-region backups with a 5-second recovery window.
D.Deploy Cloud Spanner in a multi-region configuration.
AnswerD

Multi-region configuration replicates data synchronously across regions, giving a sub-5-second RPO and rapid failover well within the 1-minute RTO. A single-region setup cannot meet these targets, since a regional outage would halt the service entirely.

Why this answer

Cloud Spanner multi-region configuration replicates data synchronously across regions and provides automatic failover with strong consistency, meeting an RPO of 5 seconds and RTO of 1 minute for a regional outage. A single-region Spanner instance does not survive a regional failure, so moving to multi-region is the correct fix. Multi-region also preserves the leaderboard's low-latency reads and writes globally.

Exam trap

PCA often tests the misconception that backups or read replicas from other database engines can meet tight RPO/RTO for Spanner, when only a multi-region Spanner configuration provides synchronous replication and automatic failover.

How to eliminate wrong answers

Option A is wrong because Cloud SQL is a different database engine and cannot serve as a read replica for Cloud Spanner; cross-engine replication is not supported. Option B is wrong because Compute Engine instances with a global load balancer do not replicate Cloud Spanner data; Spanner manages its own replication and cannot be replicated by external VMs. Option C is wrong because cross-region backups provide data recovery but not a 5-second RPO or 1-minute RTO — backups are periodic and restore takes far longer than a minute.

438
MCQeasy

A company needs to store secrets such as API keys and database passwords securely and access them from Compute Engine instances. Which service provides secret storage with built-in IAM integration and automatic rotation?

A.Secret Manager
B.Cloud HSM
C.Cloud Storage
D.Cloud KMS
AnswerA

Secret Manager stores API keys and database passwords encrypted, integrates natively with IAM for least-privilege access from Compute Engine instances, and supports automatic rotation. It satisfies the secure storage, IAM integration and rotation requirements in one managed service.

Why this answer

Google Cloud Secret Manager is a secure and convenient storage system for API keys, passwords, certificates, and other sensitive data. It provides built-in IAM integration for access control and supports automatic rotation of secrets via Cloud Functions or other mechanisms, making it the correct choice for storing and accessing secrets from Compute Engine instances.

Exam trap

PCA often tests the distinction between Secret Manager, Cloud KMS, and Cloud HSM, where candidates may confuse key management with secret storage; Secret Manager is specifically for storing and rotating secrets, while KMS manages encryption keys.

How to eliminate wrong answers

Option B is wrong because Cloud HSM is a hardware security module service for cryptographic key operations, not a secret storage service with automatic rotation for application secrets. Option C is wrong because Cloud Storage is an object storage service for unstructured data, not designed for secure secret storage with IAM integration and rotation. Option D is wrong because Cloud KMS is a key management service for encryption keys, not for storing arbitrary secrets like API keys and passwords; it manages cryptographic keys but does not provide secret storage with rotation of application secrets.

439
MCQhard

An engineer is designing a Bigtable schema for time-series data consisting of sensor readings. Each sensor emits a reading every second. The access pattern is to retrieve all readings for a specific sensor within a time range. Which row key design will provide the best performance?

A.Use row key: [sensor_id]#[reverse_timestamp]
B.Use a single row per sensor with column qualifiers as timestamps
C.Use timestamp as the row key and sensor ID as column qualifier
D.Use a random prefix to distribute writes evenly
AnswerA

Reversing the timestamp places the newest reading first within each sensor's contiguous row range, so a time-range scan reads sequential rows without hotspots. Prefixing sensor_id keeps each sensor's data co-located, matching the access pattern exactly.

Why this answer

Bigtable stores rows sorted by key. A row key structured as [sensor_id]#[reverse_timestamp] ensures that all data for a sensor is contiguous, and sorting by reverse timestamp allows recent data to be retrieved first. A single row key per sensor with column qualifiers would cause hotspots and limit scalability.

440
MCQmedium

An online retailer is deploying a new order-processing system on Google Cloud. The system consists of a regional managed instance group (MIG) of Compute Engine VMs that read from and write to a Cloud SQL for MySQL instance. The database must tolerate the loss of an entire zone within the region with minimal downtime and no manual failover steps, while keeping costs predictable. Which Cloud SQL configuration should the architect recommend?

A.A Cloud SQL read replica in a second region that the application promotes to primary during an outage.
B.A zonal Cloud SQL instance with automated backups and binary logging enabled, restored manually during an outage.
C.A Cloud SQL instance with a larger machine type and increased storage to improve throughput and resilience.
D.A Cloud SQL instance configured with high availability (regional) and a standby instance in a second zone.
AnswerD

Cloud SQL high availability provisions a standby instance in a different zone and synchronously replicates to it. If the primary zone fails, Cloud SQL automatically promotes the standby, so the application reconnects with minimal downtime and no manual steps. This directly satisfies the zone-failure tolerance and predictable cost of a single regional instance pair.

Why this answer

Zone-level resilience for Cloud SQL comes from high availability mode, which maintains a standby in a separate zone and performs automatic failover without operator intervention. Read replicas address regional disasters and require manual promotion, while zonal deployments and vertical scaling leave the database exposed to a single-zone failure. The regional HA configuration matches the availability and operational requirements at a predictable cost.

Exam trap

The trap here is assuming that automated backups or a cross-region read replica provide automatic zone failover, when only Cloud SQL high availability does.

441
MCQmedium

A company is using Cloud SQL for PostgreSQL and needs to run a one-time heavy analytical query that takes over 30 minutes and uses 100% CPU. The production database is serving user traffic with high QPS. What should the company do to run the query without impacting production?

A.Run the query directly on the primary instance during low traffic hours.
B.Create a read replica of the production instance and run the query on the replica.
C.Use Cloud SQL's pgBouncer to pool connections and queue the query.
D.Create a clone of the production instance and run the query on the clone.
AnswerB

A read replica receives its own compute and storage, so the 30-minute analytical query consumes replica CPU without competing with production traffic. Replication is asynchronous, so the query reads slightly stale data, which is acceptable for analytics.

Why this answer

A read replica in Cloud SQL for PostgreSQL is a separate instance that asynchronously replicates data from the primary. Running the heavy analytical query on the replica offloads the CPU-intensive workload from the production primary, ensuring user-facing traffic with high QPS is not impacted. The replica can handle read-only queries without affecting the primary's performance or availability.

Exam trap

Google Cloud often tests the distinction between a read replica (which offloads read traffic) and a clone (which is a point-in-time copy not kept in sync), leading candidates to choose the clone option because they confuse it with a replica's ability to handle production queries without impact.

How to eliminate wrong answers

Option A is wrong because even during low traffic hours, a query using 100% CPU on the primary instance will still degrade performance for any concurrent user requests, risking latency spikes or timeouts. Option C is wrong because pgBouncer is a connection pooler that manages database connections, not a query scheduler or resource isolator; it cannot queue or throttle a single heavy query to prevent CPU saturation. Option D is wrong because a clone creates a new primary instance from a snapshot, which requires provisioning time and does not provide ongoing replication; it is suitable for testing or development but not for running a one-time query without impacting production, as the clone is not kept in sync and the heavy query still runs on a separate instance that does not offload the primary's workload.

442
MCQeasy

Your company runs a critical application on Compute Engine instances in a managed instance group across three zones. The application writes logs to local disk. You are asked to improve the reliability of log retention and ensure logs are available in case of instance failure. You have already configured a health check that automatically recreates instances. However, after a recent zonal outage, logs from the affected instances were lost. You need to implement a solution that preserves logs even when instances are terminated. What should you do?

A.Increase the size of the local SSD to accommodate more logs and set a longer retention period.
B.Configure each instance to write logs to a persistent disk that is retained after instance deletion.
C.Install the Cloud Logging agent on each instance and configure it to stream application logs to Cloud Logging.
D.Mount a Cloud Storage bucket using gcsfuse on each instance and write logs directly to the bucket.
AnswerC

Local disk logs are lost when an instance is terminated or recreated. Streaming them off-instance to Cloud Logging decouples retention from instance lifecycle, so logs survive zonal outages and instance failure, satisfying the requirement to preserve logs even when instances are terminated.

Why this answer

The Cloud Logging agent streams logs directly to Cloud Logging (now part of Google Cloud's operations suite), which stores logs independently of the Compute Engine instances. This ensures logs are preserved even if instances are terminated due to a zonal outage or health check recreation, as logs are sent to a centralized, durable logging service rather than being stored on local disk.

Exam trap

Google Cloud often tests the misconception that persistent disks or Cloud Storage buckets are sufficient for log durability, but the key requirement is centralized log management with automatic streaming, which only Cloud Logging provides without additional complexity or latency.

How to eliminate wrong answers

Option A is wrong because increasing local SSD size and retention period does not protect logs from instance termination; local SSDs are ephemeral and their data is lost when an instance is deleted or recreated. Option B is wrong because persistent disks are not automatically retained after instance deletion unless the 'delete-on-terminate' flag is set to false, and even then, logs would be tied to a specific disk that may not survive a zonal outage if not replicated; the question requires a solution that works across instance failures, not just disk retention. Option D is wrong because while gcsfuse can mount a Cloud Storage bucket, writing logs directly to a bucket introduces latency and potential consistency issues, and the bucket is not a log management solution; Cloud Logging is purpose-built for log ingestion, analysis, and retention.

443
MCQeasy

A startup is deploying a new web application on Compute Engine. The architect needs to ensure that the application can automatically recover from a zone failure and that the instances are distributed across multiple zones within a region. The application must also scale automatically based on traffic. Which Compute Engine feature should the architect use?

A.Sole-tenant nodes with autoscaling.
B.Preemptible VMs with a managed instance group.
C.Unmanaged instance group with instances in a single zone.
D.Managed instance group with regional distribution and autoscaling.
AnswerD

A regional managed instance group distributes instances across multiple zones within a region, providing resilience to zone failures. It supports autoscaling based on metrics like CPU utilization or load balancing capacity. This directly meets the requirements for automatic recovery from zone failure and automatic scaling based on traffic, making it the appropriate choice for the web application.

Why this answer

A regional managed instance group spreads instances across multiple zones, ensuring that the application survives a zone failure. It also supports autoscaling based on traffic, allowing the application to handle varying loads. The other options either lack zone distribution, automatic scaling, or reliability, making them unsuitable for the startup's requirements.

Exam trap

The trap here is confusing a managed instance group with an unmanaged one; only managed instance groups support autoscaling and autohealing.

444
MCQeasy

You want to create a log-based alert in Cloud Logging that triggers when a specific error message appears in application logs. What is the first step?

A.Create a logs-based metric that filters for the error message
B.Configure a Pub/Sub notification channel for alerts
C.Create a log sink to export logs to Cloud Storage
D.Set up an alerting policy directly on the log entries without a metric
AnswerA

A logs-based metric counts matching log entries, and an alerting policy can only fire against such a metric. Creating it first, filtered on the specific error message, satisfies the trigger requirement before any notification channel or alert policy is configured.

Why this answer

To create a log-based alert, you first define a logs-based metric that counts occurrences of the error pattern. Then you create an alerting policy that monitors this metric and triggers when the count exceeds a threshold. Notifications are configured in the alerting policy, not the metric.

445
MCQmedium

A company runs a web application on Google Kubernetes Engine (GKE) with Cluster Autoscaler enabled. During a traffic spike, the application becomes slow and some requests timeout. The cluster has sufficient CPU and memory headroom. What is the most likely cause and solution?

A.Increase the node pool's machine type to a larger size.
B.Enable Cluster Autoscaler to add more nodes.
C.Deploy the application in a regional cluster for higher availability.
D.Configure Horizontal Pod Autoscaler (HPA) based on CPU utilization or custom metrics.
AnswerD

Cluster Autoscaler only adds nodes when pods are pending; with CPU and memory headroom already available, no new nodes are needed. The bottleneck is pod count, so Horizontal Pod Autoscaler must scale replicas based on CPU or custom metrics to absorb the traffic spike.

Why this answer

The cluster has sufficient CPU and memory headroom, indicating that the issue is not about cluster capacity but about pod-level scaling. The Horizontal Pod Autoscaler (HPA) automatically scales the number of pod replicas based on observed CPU utilization or custom metrics, which directly addresses the application slowdown and timeouts during traffic spikes by distributing the load across more pods.

Exam trap

Google Cloud often tests the distinction between node-level scaling (Cluster Autoscaler) and pod-level scaling (HPA), trapping candidates who assume that adding more nodes is the solution when the cluster already has headroom, whereas the real issue is insufficient pod replicas to handle the load.

How to eliminate wrong answers

Option A is wrong because increasing the node pool's machine type addresses node-level resource constraints, but the cluster already has sufficient CPU and memory headroom, so the bottleneck is at the pod level, not the node level. Option B is wrong because Cluster Autoscaler is already enabled and the cluster has headroom, so adding more nodes would not solve the problem of insufficient pod replicas to handle the traffic spike. Option C is wrong because deploying in a regional cluster improves availability and resilience to zone failures, but does not directly address the performance degradation and timeouts caused by insufficient application instances during a traffic spike.

446
Multi-Selectmedium

Your organization is moving a legacy monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single virtual machine with a local MySQL database. You need to design a cloud-native architecture that improves scalability and reliability. Which two actions should you take? (Choose TWO.)

Select 2 answers
A.Deploy the entire application in a single container with a large custom machine type to handle load.
B.Refactor the application into microservices and deploy each as a separate deployment in GKE.
C.Expose the application using a simple Service of type LoadBalancer with round-robin distribution.
D.Use Cloud SQL for MySQL instead of running the database in the same cluster.
E.Use a single Pod with multiple containers that communicate via localhost to reduce latency.
AnswersB, D

Splitting the monolith into microservices, each deployed as its own GKE Deployment, lets components scale and fail independently, directly addressing the scalability and reliability constraints of the single-VM legacy design. Independent Deployments also enable rolling updates per service rather than whole-application redeployment.

Why this answer

Option B is correct because refactoring the monolith into microservices and deploying each as a separate Deployment in GKE enables independent scaling, rolling updates, and fault isolation, which directly improves scalability and reliability in a cloud-native architecture. Option D is correct because moving the local MySQL database to Cloud SQL for MySQL provides a managed, highly available, and automatically backed-up database service, decoupling state from the cluster and allowing the application tier to scale independently. Option A is not appropriate because a single large container on a custom machine type preserves the monolithic scaling and single-point-of-failure limitations rather than adopting cloud-native elasticity.

Option C is not the best choice because a basic LoadBalancer Service only provides L4 round-robin distribution and does not by itself deliver the architectural scalability and reliability improvements required. Option E is incorrect because a single Pod with multiple containers communicating via localhost tightly couples the components, prevents independent scaling, and keeps the database co-located with the application, undermining reliability.

Exam trap

Google Cloud often tests the misconception that simply containerizing a monolith or using a larger machine type is sufficient for cloud-native scalability, when in fact true scalability requires decoupling components into independently scalable units and separating stateful services like databases.

447
MCQmedium

A company runs a critical application on Compute Engine. The operations team wants to improve the mean time to recovery (MTTR) for incidents. They currently use manual runbooks stored in a wiki. You need to recommend a solution that automates incident response and integrates with existing monitoring. What should you do?

A.Deploy a third-party AIOps platform on Compute Engine.
B.Implement Cloud Monitoring alerting policies that trigger Cloud Functions to execute remediation steps.
C.Migrate the application to GKE and use liveness probes for automatic restarts.
D.Use Cloud Scheduler to run a script every 5 minutes that checks for issues and fixes them.
AnswerB

Cloud Monitoring alerting policies can send notifications to Pub/Sub, which can trigger Cloud Functions. This allows automated remediation such as restarting a VM or scaling a deployment. It integrates with existing monitoring and reduces MTTR by removing manual steps. This is a native, serverless approach that requires no additional infrastructure.

Why this answer

Cloud Monitoring alerting policies can trigger Pub/Sub, which invokes Cloud Functions to perform automated remediation. This is a native, serverless, event-driven approach that integrates with existing monitoring and reduces MTTR. Other options either require architectural changes, are not event-driven, or add unnecessary complexity.

Exam trap

The trap here is assuming that scheduled scripts or platform migrations are needed, when the goal is event-driven automation integrated with monitoring.

448
MCQhard

A media company stores millions of small image files in a Cloud Storage bucket in the us-central1 region. Users in Europe and Asia report slow image load times. The company wants to improve read latency globally while keeping write operations in us-central1 for cost and simplicity. Which storage configuration should you recommend?

A.Change the bucket to a multi-region location such as US and enable Turbo Replication.
B.Keep the regional bucket in us-central1 and enable Cloud CDN on an external Application Load Balancer serving the images.
C.Move the images to a bucket in the asia-southeast1 region and use a global external Application Load Balancer to route users.
D.Recreate the bucket as a dual-region bucket with us-central1 and europe-west1, then serve images directly from the bucket.
AnswerB

Cloud CDN caches the images at Google's global edge locations, so users in Europe and Asia retrieve them from a nearby point of presence instead of crossing the ocean to us-central1. Writes continue to go to the regional bucket, preserving the simple write model. This directly addresses global read latency without changing the bucket location.

Why this answer

Cloud CDN caches content at Google's globally distributed edge points of presence, so readers in Europe and Asia are served from nearby locations while the authoritative data stays in the us-central1 regional bucket. Writes remain simple and centralized. Changing the bucket to a multi-region or dual-region location does not cover all three continents, and moving the origin to Asia violates the write-location requirement.

Exam trap

The trap here is assuming that changing the bucket's location or enabling replication automatically speeds up global reads, when edge caching through Cloud CDN is what actually reduces read latency.

449
MCQeasy

A multinational retailer must comply with a regulation stating that customer personal data collected in the European Union may not be stored or processed outside the EU, including by support staff. The company uses Google Cloud and wants a platform-level mechanism that enforces this at the data-residency level while still allowing the global analytics team to query aggregated, non-personal results. Which Google Cloud capability should the architect use as the foundation?

A.Assured Workloads with the EU data boundary and data residency controls enabled on the folder
B.Cloud KMS CMEK keys stored in an EU region and bound to all datasets
C.Cloud Data Loss Prevention templates applied to all BigQuery datasets holding customer data
D.VPC Service Controls perimeters around each EU project with restricted egress
AnswerA

Assured Workloads applies a compliance regime, such as data residency for the EU, to a folder and its child projects. It enforces controls including regional restrictions and personnel access limits so that data stays within the specified jurisdiction, while aggregated outputs can still be shared with the global team under the company's own controls.

Why this answer

Assured Workloads is purpose-built to apply regulatory compliance regimes, including data residency, to a folder of projects. It enforces location restrictions and personnel access controls for the chosen jurisdiction, which directly addresses the legal requirement. Data Loss Prevention, VPC Service Controls, and regional CMEK keys are useful supporting controls but none of them establishes or enforces residency on their own.

Exam trap

The trap here is choosing an encryption or network control because it sounds like it keeps data local, when residency is a policy and personnel-access problem that Assured Workloads is designed to solve.

450
MCQhard

A company uses Cloud Armor to protect their HTTP Load Balancer from DDoS attacks. Recently, they experienced a targeted attack that bypassed Cloud Armor's predefined rules. The attack involved a high rate of legitimate-looking requests from a small set of IPs that made the application unresponsive. The team needs to block the attack quickly without affecting legitimate users. What should they do?

A.Increase the load balancer's capacity to absorb the attack.
B.Configure rate limiting with a threshold based on the normal traffic pattern.
C.Enable Google Cloud Armor Adaptive Protection.
D.Add the attacking IPs to a Cloud Armor deny list.
AnswerC

Adaptive Protection applies machine-learning baselining to detect Layer 7 volumetric anomalies, such as the legitimate-looking request flood from few IPs, and generates a tailored WAF rule to block it. Predefined rules cannot profile this behaviour, so this satisfies the requirement to block quickly without affecting legitimate users.

Why this answer

Cloud Armor Adaptive Protection uses machine learning to analyze traffic patterns and automatically create tailored rules to block application-layer DDoS attacks that bypass predefined rules. In this scenario, the attack consists of legitimate-looking requests from a small set of IPs, which Adaptive Protection can detect as anomalous and generate a custom signature to block without manual intervention, preserving access for legitimate users.

Exam trap

The trap here is that candidates may choose Option D (adding IPs to a deny list) because it seems like a quick fix, but Google Cloud tests the understanding that Cloud Armor Adaptive Protection is the correct automated solution for application-layer DDoS attacks with legitimate-looking traffic, not manual IP blocking.

How to eliminate wrong answers

Option A is wrong because increasing the load balancer's capacity only absorbs volumetric attacks but does not address the application-layer nature of this attack; the high rate of legitimate-looking requests will still exhaust application resources regardless of capacity. Option B is wrong because configuring rate limiting with a threshold based on normal traffic patterns requires prior knowledge of those patterns and may inadvertently block legitimate users if the threshold is set too low, or fail to block the attack if the threshold is too high; it also does not leverage Cloud Armor's adaptive capabilities. Option D is wrong because adding the attacking IPs to a deny list is reactive and assumes the IPs are static; the attack may use rotating IPs or spoofed addresses, making manual deny lists ineffective and unsustainable for a rapid response.

Page 5

Page 6 of 11

Page 7

All pages