Courseiva

Google Professional Cloud Architect (PCA) — Questions 451–525

807 questions total · 11pages · All types, answers revealed

Page 6

Page 7 of 11

Page 8
451
MCQmedium

A company is deploying a web application on Compute Engine behind a global HTTP(S) load balancer. They want to restrict access to only traffic from specific IP ranges. Which load balancer feature should they use?

A.Cloud Armor security policies.
B.VPC firewall rules.
C.Identity-Aware Proxy (IAP).
D.Cloud CDN.
AnswerA

Cloud Armor security policies attach directly to the global HTTP(S) load balancer's backend service, letting you define allow or deny rules matching source IP ranges. This satisfies the requirement to restrict access to specific IP ranges at the edge, before traffic reaches Compute Engine instances.

Why this answer

Cloud Armor security policies are the correct choice because they allow you to define IP-based allow/deny rules at the edge of Google's network, directly integrated with the global HTTP(S) load balancer. This provides granular access control based on source IP ranges before traffic reaches your backend instances, which is exactly what the requirement specifies.

Exam trap

The trap here is that candidates often confuse VPC firewall rules with Cloud Armor, assuming that firewall rules can filter on the original client IP behind a load balancer, but in reality, VPC firewall rules only see the load balancer's proxy IPs, making Cloud Armor the only viable option for IP-based access control at the edge.

How to eliminate wrong answers

Option B is wrong because VPC firewall rules operate at the instance level (network interface) and cannot filter traffic based on the original client IP when a global HTTP(S) load balancer is used, as the load balancer's health check and proxy IPs are seen instead. Option C is wrong because Identity-Aware Proxy (IAP) controls access based on user identity and context (e.g., Google accounts, OAuth), not on source IP ranges, and is designed for application-layer authentication, not network-layer IP filtering. Option D is wrong because Cloud CDN is a content delivery network that caches content at edge locations to improve latency and reduce load, and it does not provide any IP-based access control or security policy enforcement.

452
MCQmedium

A team is using Cloud Build to deploy a microservice to Cloud Run. They want to ensure that only containers built from a specific trusted branch in their source repository are deployed to production. Which Cloud Build feature should they use?

A.Binary Authorization attestors
B.Cloud Build trigger branch filtering
C.Cloud Deploy delivery pipeline approvals
D.Artifact Registry IAM permissions
AnswerB

Branch filtering restricts a trigger to builds originating from a named branch, so only commits from the trusted branch fire the deploy pipeline. This directly enforces the stem's constraint that production deploys come solely from that trusted source branch.

Why this answer

Cloud Build triggers support branch filtering via the 'Branch' field (regex) in the trigger configuration, so a trigger can be scoped to only fire on pushes to a specific branch such as 'refs/heads/main' or 'release/*'. This ensures that only builds originating from the trusted branch proceed to the deploy step, satisfying the requirement with a native Cloud Build feature.

Exam trap

PCA often tests the difference between source-side controls (trigger branch filtering) and deploy-side controls (Binary Authorization, Cloud Deploy approvals) — candidates frequently pick Binary Authorization because it sounds more 'secure' but it does not filter by branch.

How to eliminate wrong answers

Option A is wrong because Binary Authorization attestors verify container image provenance at deploy time (via a signed attestation), but they do not restrict which source branch produced the image — you still need a trigger-level filter to control the source. Option C is wrong because Cloud Deploy approvals gate promotion between environments in a delivery pipeline, not the source branch of the build. Option D is wrong because Artifact Registry IAM controls who can push or pull images, not which branch a build originated from.

453
MCQeasy

A company wants to restrict access to a Cloud Storage bucket so that only a specific service account can read objects. The bucket contains sensitive data. Which identity and access management (IAM) approach should the architect use?

A.Grant the service account roles/iam.serviceAccountUser on the bucket.
B.Use a signed URL to allow access for the service account.
C.Grant the service account roles/storage.admin on the bucket.
D.Grant the service account roles/storage.objectViewer on the bucket and remove all other bindings.
AnswerD

Granting `roles/storage.objectViewer` at bucket level binds the service account directly to the resource, satisfying the least-privilege constraint. Removing every other binding ensures no principal inherits access via project-level or inherited roles, so only that service account can read objects. This is the precise mechanism for restricting a sensitive bucket to a single identity.

Why this answer

The principle of least privilege dictates that the service account should be granted only the minimal permissions required to read objects, which is roles/storage.objectViewer. By removing all other bindings, the bucket becomes accessible exclusively to that service account, ensuring that no other identities (users, groups, or other service accounts) can read the sensitive data. This approach directly enforces the requirement using IAM roles on the bucket resource.

Exam trap

Google Cloud often tests the misconception that granting a broad role like roles/storage.admin is acceptable for simplicity, but the trap here is that candidates overlook the principle of least privilege and the specific read-only requirement, leading them to choose an overly permissive role.

How to eliminate wrong answers

Option A is wrong because roles/iam.serviceAccountUser grants permission to impersonate the service account (e.g., to run jobs as that account), not to read objects from a Cloud Storage bucket; it does not provide any storage access. Option B is wrong because signed URLs are used to grant temporary access to specific objects for any user (including non-Google accounts) via a cryptographic signature, not to restrict access to a specific service account; they are not an IAM-based access control mechanism. Option C is wrong because roles/storage.admin grants full control over the bucket, including the ability to delete objects and modify bucket metadata, which violates the principle of least privilege and exceeds the read-only requirement.

454
MCQeasy

A developer wants to store and retrieve non-relational data with flexible schema and automatic scaling. Which Google Cloud service should they use?

A.Cloud Bigtable.
B.Cloud SQL.
C.Firestore.
D.Cloud Spanner.
AnswerC

Firestore is a serverless NoSQL document database offering flexible schemas and automatic horizontal scaling, matching the non-relational, flexible-schema, auto-scaling requirement. It suits application data needing real-time sync and scales without manual sharding, unlike Cloud SQL's fixed relational schema.

Why this answer

Firestore is a NoSQL document database that supports flexible schema and automatic scaling, making it ideal for non-relational data. It offers real-time synchronization, offline support, and serverless scaling, which aligns with the requirement for storing and retrieving data without manual sharding or capacity planning.

Exam trap

Google Cloud often tests the distinction between NoSQL databases by presenting Cloud Bigtable as a trap for 'non-relational' requirements, but candidates overlook that Bigtable is optimized for analytical workloads with fixed column families, not for flexible schema and automatic scaling in transactional applications.

How to eliminate wrong answers

Option A is wrong because Cloud Bigtable is a wide-column NoSQL database designed for large analytical workloads (e.g., time-series, IoT) with high throughput, but it does not support flexible schema in the same way as Firestore (it requires predefined column families) and is not optimized for transactional, real-time client-side access. Option B is wrong because Cloud SQL is a fully managed relational database service (MySQL, PostgreSQL, SQL Server) that enforces a fixed schema and does not automatically scale beyond its instance limits without manual resizing or read replicas. Option D is wrong because Cloud Spanner is a globally distributed relational database that provides strong consistency and horizontal scaling, but it requires a predefined schema and SQL-based relational model, making it unsuitable for non-relational data with flexible schema.

455
MCQhard

A media company uses Cloud CDN with an HTTP(S) Load Balancer to serve video content from Cloud Storage. After a month, they notice increased costs due to high cache miss rates. Analysis shows that many requests include a unique query parameter for analytics tracking. What is the most effective way to improve cache hit ratio while preserving analytics data?

A.Configure a custom cache key on the backend bucket to exclude the analytics parameter
B.Move the content to a different Cloud Storage bucket with no caching
C.Increase the minimum TTL on the backend bucket to 1 hour
D.Disable caching for requests with query parameters
AnswerA

A custom cache key lets the backend bucket ignore the analytics query parameter when computing the cache key, so requests differing only by tracking value share one cached object. Hit ratio rises while the parameter still reaches analytics logging.

Why this answer

When query parameters are unique per request (like tracking IDs), they cause cache misses. The solution is to define a cache key that ignores that specific parameter, so the same content is cached once. Setting a custom cache key on the backend bucket is the correct approach.

Disabling CDN or increasing TTL does not solve the parameter issue. Removing caching altogether would hurt performance and increase egress costs.

456
MCQmedium

A company runs a monolithic application on Compute Engine. They want to modernize by moving to microservices on Google Kubernetes Engine (GKE) to improve deployment frequency and resource utilization. However, they are concerned about the increased operational complexity. Which approach best balances modernization benefits with operational overhead?

A.Keep the monolithic application on Compute Engine and use Cloud Monitoring to optimize resource utilization.
B.Migrate all application components to Cloud Run and use Cloud Tasks for asynchronous communication.
C.Rewrite the entire application as microservices and deploy on GKE with Istio for service mesh.
D.Identify stateless components to migrate to Cloud Run, and keep stateful components on GKE with managed services like Cloud Spanner.
AnswerD

Cloud Run removes cluster management for stateless components, cutting operational overhead, while GKE with managed Spanner keeps stateful workloads reliable. This split directly balances the stated modernization benefits against the concern about increased operational complexity, rather than migrating everything wholesale.

Why this answer

It pragmatically balances modernization benefits with operational overhead by migrating only stateless components to Cloud Run (a fully managed serverless platform that reduces operational complexity) while keeping stateful components on GKE with managed services like Cloud Spanner. This approach improves deployment frequency and resource utilization without requiring a full rewrite, and it leverages Cloud Run's automatic scaling and zero infrastructure management to minimize operational burden.

Exam trap

Google Cloud often tests the misconception that full microservices migration (Option C) is always the best modernization path, but the trap here is that candidates overlook the operational overhead of service mesh and full rewrites, failing to recognize that a hybrid approach using serverless for stateless components reduces complexity while still achieving modernization goals.

How to eliminate wrong answers

Option A is wrong because it fails to modernize the architecture—keeping the monolithic application on Compute Engine does not improve deployment frequency or resource utilization, and Cloud Monitoring alone cannot address the core issues of monolithic scaling and slow deployments. Option B is wrong because migrating all application components to Cloud Run is impractical for stateful workloads (Cloud Run is stateless by design, with no persistent local storage), and Cloud Tasks alone does not solve the complexity of managing stateful services or inter-service communication in a microservices architecture. Option C is wrong because rewriting the entire application as microservices and deploying on GKE with Istio introduces significant operational overhead (service mesh configuration, sidecar proxies, and increased complexity) that contradicts the goal of balancing modernization benefits with operational overhead, and it ignores the possibility of a phased migration.

457
Multi-Selecthard

A multinational manufacturer is planning its first Google Cloud landing zone. The security team requires that no data be stored outside approved European regions, that all workloads authenticate using short-lived credentials tied to their Google identities, and that network egress to the public internet be centrally inspected and logged. The platform team wants to minimize per-project configuration. Which two design elements should the architect include in the landing zone? (Choose two.)

Select 2 answers
A.Enable Cloud Armor on each project's load balancers and rely on its logging for internet egress visibility.
B.Deploy a centralized Shared VPC host project with a firewall policy and Cloud NAT in a spoke architecture, routing egress through a central inspection project.
C.Apply the constraints/gcp.resourceLocations organization policy at the organization node with an allow list of approved European regions.
D.Configure Cloud Identity-Aware Proxy on every project and require users to authenticate with long-lived service account keys.
E.Grant the Editor role to all developers at the organization node so they can create resources without per-project IAM changes.
AnswersB, C

Shared VPC centralizes network administration in a host project, and combining hierarchical firewall policies with a central inspection project lets the platform team enforce and log egress once rather than per project. This satisfies the centralized inspection requirement while reducing per-project configuration.

Why this answer

The landing zone needs organization-level enforcement that propagates automatically. A resource location organization policy at the root keeps data in approved European regions, and a Shared VPC host project with hierarchical firewall policies and a central inspection project centralizes and logs egress. Together these meet the security requirements while minimizing per-project work.

Exam trap

The trap here is satisfying the security goals with per-project controls such as Cloud Armor or IAP, which do not scale to a landing zone and miss the centralized enforcement the requirements imply.

458
Multi-Selectmedium

A company wants to monitor the performance of their microservices deployed on Cloud Run. They need to capture request latencies and error rates, and also trace requests across services. Which TWO services should they use?

Select 2 answers
A.Cloud Trace
B.Error Reporting
C.Cloud Profiler
D.Cloud Logging
E.Cloud Monitoring
AnswersA, E

Cloud Trace captures distributed traces across microservices, satisfying the requirement to trace requests spanning services. It records per-request latency data, letting you pinpoint slow spans within a call chain. Error rates, however, come from Cloud Monitoring, so Trace alone covers only the tracing and latency constraints in the stem.

Why this answer

Cloud Trace (A) is correct because it is Google Cloud's distributed tracing service, which collects and correlates latency data across microservices so a single request can be followed from one Cloud Run service to the next. Cloud Monitoring (E) is correct because it ingests Cloud Run request metrics such as request count, latency, and error rates, and lets you build dashboards and alerting policies on them. Together they satisfy the stated requirements of capturing request latencies and error rates while tracing requests across services.

Error Reporting (B) only aggregates and groups application exceptions, Cloud Profiler (C) analyzes CPU and memory usage of running code, and Cloud Logging (D) stores log entries; none of these provide distributed tracing or the request-level latency and error-rate metrics required here.

Exam trap

PCA often tests the distinction between logging, monitoring, and tracing services; candidates might confuse Cloud Logging with Cloud Monitoring or overlook Cloud Trace for distributed tracing.

459
MCQmedium

A data engineer needs to scan a Cloud Storage bucket for personally identifiable information (PII) and de-identify the data before loading it into BigQuery. Which Google Cloud service should they use?

A.Cloud DLP
B.Cloud Dataprep
C.Cloud Composer
D.Cloud Data Fusion
AnswerA

Cloud DLP's infoType detectors scan Cloud Storage objects directly, identifying PII such as names, emails and credit card numbers. Its de-identification transforms — masking, tokenisation, bucketing — then redact or replace those findings before the data lands in BigQuery, satisfying the stem's requirement to de-identify prior to loading.

Why this answer

Cloud DLP (Data Loss Prevention) is the correct service because it is specifically designed to scan, classify, and de-identify sensitive data such as PII. It can inspect data in Cloud Storage and apply de-identification transformations like masking, tokenization, or redaction before loading into BigQuery. This is a core use case for Cloud DLP.

Exam trap

PCA often tests the distinction between data integration and data security services; candidates may choose Cloud Dataprep or Data Fusion for PII tasks, but Cloud DLP is the dedicated service for detection and de-identification.

How to eliminate wrong answers

Option B is wrong because Cloud Dataprep is a data preparation tool for cleaning and transforming data, but it does not have built-in PII detection and de-identification capabilities like Cloud DLP. Option C is wrong because Cloud Composer is a workflow orchestration service (managed Apache Airflow) and does not perform data scanning or de-identification itself. Option D is wrong because Cloud Data Fusion is a data integration service for building ETL pipelines, but it relies on other services like Cloud DLP for PII detection; it is not the primary service for that purpose.

460
MCQeasy

Refer to the exhibit. A DevOps engineer created this Terraform configuration to deploy a Compute Engine instance. After applying, they notice the instance is not accessible from the internet. What is the most likely cause?

A.The machine type e2-medium does not support public IP addresses.
B.The instance is not attached to a VPC network.
C.No firewall rule allows ingress traffic to the instance.
D.The boot disk size is too small to run the operating system.
AnswerC

Compute Engine instances have no implicit internet ingress; traffic is blocked unless a VPC firewall rule explicitly permits it. Since the configuration defines only the instance, the absence of an ingress rule allowing the required ports is what prevents external access, regardless of external IP assignment.

Why this answer

The most likely cause is that no firewall rule allows ingress traffic to the instance. By default, GCP instances are created with a VPC network that has implied deny-all ingress rules, and unless a specific firewall rule (e.g., allowing tcp:22 for SSH or tcp:80 for HTTP) is applied to the instance's network tags or service account, all inbound traffic from the internet is blocked. The Terraform configuration shown in the exhibit likely omitted a `google_compute_firewall` resource or did not assign the necessary network tags to the instance.

Exam trap

Google Cloud often tests the misconception that assigning a public IP automatically makes an instance internet-accessible, but the trap here is that without a corresponding ingress firewall rule, the instance remains isolated regardless of the public IP.

How to eliminate wrong answers

Option A is wrong because the machine type e2-medium fully supports public IP addresses; public IP assignment is controlled by the `access_config` block in the Terraform resource, not by the machine type. Option B is wrong because every Compute Engine instance is automatically attached to a default VPC network unless explicitly overridden; the exhibit does not indicate any misconfiguration that would leave the instance networkless. Option D is wrong because the boot disk size (e.g., 10 GB default) is sufficient for most operating systems; the issue is about network accessibility, not disk capacity.

461
MCQmedium

A company needs to store petabytes of time-series IoT sensor data and query it with single-digit millisecond latency at millions of reads per second. The data has a simple key-value structure with timestamps. Which Google Cloud database is MOST appropriate?

A.Firestore
B.Cloud Bigtable
C.Cloud Spanner
D.BigQuery
AnswerB

Cloud Bigtable is a wide-column NoSQL store designed for petabyte-scale time-series data, delivering consistent single-digit millisecond latency at millions of reads per second. Its sparse key-value structure with timestamp row keys matches the schema described.

Why this answer

Cloud Bigtable is Google's petabyte-scale, low-latency NoSQL wide-column store, purpose-built for time-series and IoT workloads with single-digit millisecond latency at millions of reads/writes per second. Its row-key design supports efficient range scans by timestamp, and it scales horizontally by adding nodes, making it the best fit for high-throughput sensor data with simple key-value access.

Exam trap

PCA often tests the distinction between Bigtable (low-latency, high-throughput NoSQL) and BigQuery (analytics warehouse) — candidates must match the latency and throughput requirements to the right service.

How to eliminate wrong answers

Option A is wrong because Firestore is a document database optimized for mobile/web app data with strong consistency and real-time sync, but it does not scale to petabytes or millions of reads per second at low latency — it has document size and write-rate limits. Option C is wrong because Cloud Spanner is a globally distributed relational database with strong consistency and horizontal scaling, but it is far more expensive and overkill for simple key-value time-series data; it's designed for transactional relational workloads. Option D is wrong because BigQuery is an analytics data warehouse optimized for large-scale SQL queries, not for single-digit millisecond point reads at millions of QPS — its latency is seconds, not milliseconds.

462
Multi-Selecthard

A financial services firm is designing the network for a new payment processing platform on Google Cloud. Regulatory rules require that no workload can reach the public internet, that all egress to an on-premises fraud-detection system stay off the public internet, and that Google APIs such as Cloud Storage and BigQuery remain reachable without exposing the workloads. The platform runs on Compute Engine VMs in a single VPC. Which two design elements must the architect include? (Choose two.)

Select 2 answers
A.Configure a Cloud NAT gateway with a manual IP address allocation on the VPC so the VMs can reach the fraud-detection system.
B.Deploy a Squid proxy on a VM with an external IP and route all VPC egress through it using a custom route with the proxy as the next hop.
C.Assign ephemeral external IP addresses to the VMs and protect them with a firewall rule that allows only the fraud-detection system's source range.
D.Create the subnet with the --enable-private-ip-google-access option so the VMs can reach Google APIs and services without external IP addresses.
E.Establish a Cloud VPN tunnel or Cloud Interconnect attachment from the VPC to the on-premises network, with routes exchanged over Cloud Router using BGP.
AnswersD, E

Private Google Access lets a VM with only an internal IP address reach the external IP addresses of Google APIs and services. Because the traffic stays on Google's network rather than traversing the internet, it satisfies the requirement to keep Google APIs reachable without giving the workloads public addresses. Without it, a VM lacking an external IP cannot resolve or route to those APIs.

Why this answer

Two independent constraints must be satisfied: Google APIs stay reachable while workloads have no public addresses, and on-premises traffic stays off the internet. Private Google Access on the subnet handles the first by routing API traffic internally, and a Cloud VPN or Interconnect link with Cloud Router BGP handles the second by providing private connectivity to the fraud-detection system. Cloud NAT, external IPs, and proxy VMs all push traffic onto the public internet.

Exam trap

The trap here is reaching for Cloud NAT as the default answer for private workloads, when NAT provides internet egress and does nothing for private on-premises connectivity or Google API access.

463
MCQmedium

A company wants to implement an event-driven architecture where uploads to a Cloud Storage bucket trigger processing in a serverless function. The function must process each object within a few seconds and handle bursts of thousands of uploads. Which service should they use?

A.Google Kubernetes Engine
B.Cloud Run for Anthos
C.Compute Engine with autoscaling
D.Cloud Functions
AnswerD

Cloud Functions scales automatically per event, invoking once per object upload and completing within seconds, which satisfies the burst requirement of thousands of concurrent uploads. Its event-driven trigger integrates natively with Cloud Storage object-finalise notifications, avoiding polling overhead and keeping per-invocation cost low.

Why this answer

Cloud Functions is the correct choice because it is a fully managed, event-driven serverless compute service that natively triggers on Cloud Storage bucket events (e.g., object finalize/create). It automatically scales from zero to thousands of concurrent invocations within seconds, meeting the burst requirement, and has a maximum timeout of 9 minutes (well above the 'few seconds' requirement).

Exam trap

Candidates often mistakenly think that container-based or VM-based services like GKE, Cloud Run for Anthos, or Compute Engine can handle event-driven bursts as efficiently as Cloud Functions, ignoring the cold-start latency and management overhead.

How to eliminate wrong answers

Option A is wrong because Google Kubernetes Engine (GKE) is a container orchestration platform that requires cluster management, node autoscaling, and is not event-driven by default; it would need additional components like Cloud Storage triggers and Pub/Sub to achieve the same result, adding latency and complexity. Option B is wrong because Cloud Run for Anthos is a hybrid/multi-cloud container platform that runs on GKE clusters, inheriting the same overhead and not providing native Cloud Storage event triggers without extra configuration. Option C is wrong because Compute Engine with autoscaling requires managing virtual machine instances, installing runtime dependencies, and configuring scaling policies; it cannot scale from zero to thousands in seconds due to instance startup times (typically 30-90 seconds) and is not event-driven without additional polling or Pub/Sub integration.

464
MCQmedium

Your organization runs a global e-commerce platform on Google Kubernetes Engine (GKE). The security team requires that all container images deployed to the cluster are scanned for vulnerabilities and that deployments are blocked if critical vulnerabilities are found. They also want to minimize operational overhead. What should you do?

A.Configure a Kubernetes admission controller that calls the Container Analysis API to check for vulnerabilities and rejects pods with critical findings.
B.Enable Pod Security Policies to restrict images to those from trusted registries, and rely on registry scanning to prevent vulnerable images.
C.Use Cloud Build to scan images with Container Analysis, and manually review the scan results before approving each deployment.
D.Enable Binary Authorization in the cluster and configure a policy that requires attestations from a vulnerability scanner before deployment.
AnswerD

Binary Authorization enforces deploy-time security controls by verifying attestations. You can integrate a vulnerability scanner (e.g., Container Analysis) to create attestations only for images that pass scanning. This blocks non-compliant images and reduces manual effort, aligning with the requirement to block critical vulnerabilities with minimal overhead.

Why this answer

Binary Authorization is a Google Cloud service that enforces deploy-time policies by requiring attestations. By integrating with Container Analysis, you can automatically attest only images that pass vulnerability scanning, and the policy blocks images without attestations. This automates enforcement and reduces manual review, satisfying both security and operational efficiency.

Exam trap

The trap here is assuming that vulnerability scanning alone can block deployments, when in fact scanning only reports findings and requires an enforcement mechanism like Binary Authorization to prevent deployment.

465
MCQeasy

A company wants to connect their on-premises data center to Google Cloud with a dedicated, low-latency, and highly available connection. They need bandwidth of 10 Gbps. Which option should they choose?

A.Classic VPN
B.HA VPN over the public internet
C.Partner Cloud Interconnect
D.Dedicated Cloud Interconnect
AnswerD

Dedicated Cloud Interconnect provides a direct physical connection via a colocation facility, delivering the 10 Gbps bandwidth, low latency and high availability the stem demands. Partner Interconnect cannot guarantee that capacity, and VPNs traverse the public internet with variable latency.

Why this answer

Dedicated Cloud Interconnect provides direct physical connections between on-premises and Google's network with speeds up to 100 Gbps per link. It offers high availability and low latency. HA VPN is over the public internet, Partner Interconnect depends on a partner, and Classic VPN is older.

466
Multi-Selectmedium

A company is migrating an on-premises application to Google Cloud. The application consists of a web front end and a backend that uses a relational database. The company wants to minimize downtime during the migration and ensure that the database remains consistent. They plan to use a phased approach. Which TWO steps should they take to achieve a successful migration? (Choose two.)

Select 2 answers
A.Use Database Migration Service to continuously replicate data from the on-premises database to a Cloud SQL instance, then perform a cutover.
B.Configure Cloud SQL read replicas in multiple regions to ensure high availability and offload read traffic.
C.Set up a Cloud VPN or Dedicated Interconnect between on-premises and Google Cloud to establish a secure network connection.
D.Deploy the web front end on Compute Engine instances and use a managed instance group with autoscaling to handle traffic.
E.Export the on-premises database to a CSV file, upload it to Cloud Storage, and import it into Cloud SQL during a maintenance window.
AnswersA, C

Database Migration Service supports continuous replication from various sources to Cloud SQL, allowing you to keep the target in sync with minimal downtime. After initial load, it replicates ongoing changes, and you can promote the Cloud SQL instance during a short cutover window. This directly addresses the requirement for minimal downtime and data consistency.

Why this answer

Establishing a secure network connection and using Database Migration Service for continuous replication are critical for a low-downtime migration. The network connection enables data transfer, and Database Migration Service keeps the target in sync until cutover. These steps ensure minimal downtime and data consistency, unlike manual export/import or unrelated scaling measures.

Exam trap

The trap here is focusing on post-migration scaling or high availability features instead of the core steps needed to perform the migration with minimal downtime.

467
MCQmedium

A company deploys a web application on Compute Engine behind a Global HTTPS Load Balancer. They need to restrict access to the application based on the client's IP address. Which Google Cloud service should they use?

A.VPC firewall rules
B.Identity-Aware Proxy (IAP)
C.Cloud Armor
D.Cloud CDN
AnswerC

Cloud Armor attaches security policies to the Global HTTPS Load Balancer's backend service, filtering requests by source IP address at the edge. This satisfies the client-IP restriction requirement, which VPC firewall rules cannot enforce for external clients.

Why this answer

Cloud Armor is the correct choice because it provides IP-based access control at the edge of Google's network, integrated directly with the Global HTTPS Load Balancer. It allows you to create security policies with IP allow/deny rules that are evaluated before traffic reaches your Compute Engine instances, making it the appropriate service for client IP restriction at the load balancer level.

Exam trap

The trap here is that candidates often confuse VPC firewall rules with edge security, not realizing that VPC firewall rules cannot see the original client IP when a Global Load Balancer is in front, making Cloud Armor the only option for IP-based access control at the load balancer level.

How to eliminate wrong answers

Option A is wrong because VPC firewall rules operate at the instance network interface level, not at the load balancer edge, and they cannot inspect the original client IP address when traffic passes through a Global HTTPS Load Balancer (the source IP becomes the load balancer's IP). Option B is wrong because Identity-Aware Proxy (IAP) controls access based on user identity and context (e.g., OAuth2, device security), not on client IP addresses; it is designed for authentication and authorization, not network-layer IP filtering. Option D is wrong because Cloud CDN is a content delivery network service that caches content at edge locations to improve latency and reduce load; it does not provide IP-based access control or security policy enforcement.

468
Multi-Selecteasy

An engineer needs to troubleshoot a production issue on a Compute Engine instance. They suspect the instance is running out of memory. Which THREE actions should they take to diagnose the problem? (Choose THREE.)

Select 3 answers
A.SSH into the instance and run 'free -m' to check memory usage
B.Check Cloud Logging for OOM (out-of-memory) kernel messages
C.Increase the instance's memory by changing the machine type
D.Create a snapshot of the boot disk
E.View the instance's memory utilization metric in Cloud Monitoring
AnswersA, B, E

Running 'free -m' over SSH reads the instance's actual memory counters, showing total, used, free and swap usage plus buffer/cache. This directly confirms or rules out memory exhaustion on the guest OS, which external metrics alone cannot attribute to specific processes.

Why this answer

Option A is correct because running 'free -m' over SSH directly reports the instance's current RAM and swap usage in megabytes, immediately confirming whether memory is exhausted. Option B is correct because when the Linux kernel OOM killer terminates processes, it logs messages such as 'Out of memory: Killed process' to the kernel log, which is captured by the Cloud Logging agent and searchable in Logs Explorer. Option E is correct because the Cloud Monitoring agent (or Ops Agent) publishes the 'memory/utilization' metric, letting the engineer review historical memory trends and correlate spikes with the incident.

Option C is not a diagnostic action but a remediation that changes the machine type and requires a stop/start, so it does not help identify the cause. Option D is also not diagnostic; creating a boot disk snapshot only preserves disk state and does not reveal memory consumption.

469
MCQmedium

A company runs a web application on Compute Engine behind a Global HTTPS Load Balancer. Users report slow page loads, especially for static assets. The development team wants to cache content closer to users without modifying code. Which GCP service should they enable?

A.Cloud CDN
B.Cloud NAT
C.Cloud Armor
D.Cloud DNS
AnswerA

Cloud CDN caches static assets at Google edge points of presence, so repeated requests terminate near users rather than traversing to the Compute Engine backends. Enabling it on the existing Global HTTPS Load Balancer requires no application code changes, directly addressing the slow static asset loads.

Why this answer

Cloud CDN is the correct service because it caches HTTP(S) load balancer content at Google's globally distributed edge points of presence, reducing latency for static assets without any application code changes. It integrates directly with the Global HTTPS Load Balancer, so enabling it requires only a checkbox or gcloud command on the backend service. This satisfies the requirement to cache content closer to users while keeping the existing architecture intact.

Exam trap

The trap is assuming that any network-related GCP service can improve latency — candidates may pick Cloud DNS or Cloud NAT thinking they accelerate traffic, but only Cloud CDN caches content at the edge.

How to eliminate wrong answers

Option B is wrong because Cloud NAT provides outbound internet access for private instances, not content caching or edge delivery. Option C is wrong because Cloud Armor is a WAF/DDoS protection service, not a caching layer. Option D is wrong because Cloud DNS is a managed DNS service that resolves names; it does not cache HTTP content or reduce asset latency.

470
MCQmedium

A company uses preemptible VMs for batch processing. They notice that during peak hours, many instances are terminated before finishing their tasks. The operations team observes the output shown in the exhibit. Which action would best improve job completion rates without significantly increasing costs?

A.Increase the number of instances to compensate for terminations
B.Use sole-tenant nodes for these instances
C.Use instance groups with a mix of preemptible and regular VMs
D.Use committed use discounts for 1 year
E.Switch to regular VMs for critical jobs
AnswerC

Mixing preemptible and regular VMs in a managed instance group lets batch workloads continue on standard instances when preemptible capacity is reclaimed, directly addressing the premature termination constraint. Autoscaling and instance templates maintain throughput during peak hours, while the preemptible portion keeps costs low.

Why this answer

Using a mixed instance group with both preemptible and regular VMs allows the batch processing job to continue on regular VMs when preemptible VMs are terminated during peak hours. This balances cost and reliability: preemptible VMs handle most of the workload at low cost, while regular VMs act as a fallback to ensure job completion without the full expense of switching entirely to regular VMs.

Exam trap

Google Cloud often tests the misconception that simply adding more preemptible VMs or switching entirely to regular VMs is the solution, but the correct answer requires a hybrid approach that balances cost and reliability using instance groups with a mix of VM types.

How to eliminate wrong answers

Option A is wrong because simply increasing the number of preemptible instances does not address the root cause of terminations during peak hours; it only increases the likelihood of more terminations and may lead to higher costs from repeated restarts. Option B is wrong because sole-tenant nodes provide dedicated hardware but do not prevent preemption; they are used for compliance or licensing, not for improving job completion rates of preemptible VMs. Option D is wrong because committed use discounts require a 1-year commitment and apply to regular VMs, not preemptible VMs, so they would increase costs without solving the termination issue.

Option E is wrong because switching all critical jobs to regular VMs would significantly increase costs, as regular VMs are more expensive than preemptible VMs, and the question asks for an improvement without significantly increasing costs.

471
MCQmedium

A DevOps engineer needs to grant a CI/CD pipeline (running in a different Google Cloud project) the ability to deploy resources into a target project. The pipeline uses a service account. What is the best way to grant this access?

A.Use VPC peering to allow cross-project access.
B.Use Cloud NAT to enable communication.
C.Add the service account email as a member of the target project with appropriate roles.
D.Create a new service account in the target project and share the key with the pipeline.
AnswerC

Why this answer

Cross-project IAM access in Google Cloud is granted by adding the service account's email as a principal (member) on the target project and binding it to the required roles. IAM is global and project-scoped, so the pipeline's service account in Project A can be granted roles/editor or specific deploy roles in Project B without any network-level configuration. This is the canonical, least-privilege approach for CI/CD cross-project deployments.

Exam trap

PCA often tests the misconception that cross-project access requires network plumbing (VPC peering, Cloud NAT) or a duplicate service account, when IAM principal binding on the target project is the correct and simplest answer.

How to eliminate wrong answers

Option A is wrong because VPC peering only connects network routes between VPCs; it does not grant IAM permissions and is irrelevant to service account authorization. Option B is wrong because Cloud NAT provides outbound internet address translation for private instances and has nothing to do with cross-project IAM access. Option D is wrong because creating a new service account in the target project and sharing its key violates key-management best practices, creates credential sprawl, and is unnecessary when IAM allows direct cross-project principal binding.

472
Multi-Selectmedium

A company runs a latency-sensitive web application on Compute Engine with a managed instance group (MIG) behind an HTTP load balancer. They want to reduce latency for users in Europe and Asia. Which THREE actions should they take?

Select 3 answers
A.Use a regional external load balancer for each region
B.Enable Cloud CDN to cache static content
C.Use a global external HTTP(S) Load Balancer
D.Use preemptible VMs to reduce costs in non-primary regions
E.Deploy managed instance groups in multiple regions (e.g., europe-west1, asia-east1)
AnswersB, C, E

Cloud CDN caches static assets at Google's edge points of presence, so European and Asian users fetch content from nearby locations rather than the origin MIG. This directly reduces round-trip latency for cacheable content, satisfying the stem's requirement to cut latency for those user regions.

Why this answer

Option B is correct because enabling Cloud CDN on the HTTP(S) load balancer caches static content at Google's globally distributed edge points of presence, serving users in Europe and Asia from nearby locations and reducing round-trip latency. Option C is correct because a global external HTTP(S) Load Balancer uses a single global anycast IP and routes each user to the closest healthy backend region, which is the standard architecture for lowering latency for a geographically dispersed audience. Option E is correct because deploying managed instance groups in multiple regions such as europe-west1 and asia-east1 places application capacity close to European and Asian users, so requests terminate in-region instead of crossing the globe.

Option A is not appropriate because separate regional external load balancers would fragment traffic across multiple IPs and lack the global anycast routing and single-IP simplicity of a global load balancer. Option D is not appropriate because preemptible VMs are a cost optimization, not a latency optimization, and their preemption can hurt the availability of a latency-sensitive application.

Exam trap

PCA often tests the distinction between regional and global load balancers — candidates pick regional LBs thinking 'closer to users,' but only a global external HTTP(S) LB with multi-region backends actually routes users to the nearest region.

473
MCQeasy

A company wants to restrict data exfiltration from its Google Cloud projects by preventing resources from copying data to external IP addresses. Which service should they use?

A.HTTPS Load Balancer
B.VPC Service Controls
C.Cloud Armor
D.Cloud NAT
AnswerB

VPC Service Controls create a security perimeter around resources to prevent data exfiltration.

Why this answer

VPC Service Controls is the correct choice because it creates a security perimeter around Google Cloud resources, such as BigQuery or Cloud Storage, and prevents data exfiltration by blocking access from outside the perimeter or to external IP addresses. It enforces context-aware access policies that can deny egress traffic to non-permitted destinations, directly addressing the requirement to restrict copying data to external IPs.

Exam trap

A common misconception is that Cloud NAT provides security for outbound traffic, but it actually enables outbound connectivity and does not prevent data exfiltration to external IPs. Candidates often confuse outbound internet access with exfiltration prevention.

How to eliminate wrong answers

Option A is wrong because an HTTPS Load Balancer distributes incoming traffic and does not enforce egress data exfiltration controls; it operates at Layer 7 for ingress only. Option C is wrong because Cloud Armor provides web application firewall (WAF) and DDoS protection for incoming HTTP/S traffic, not egress data exfiltration prevention. Option D is wrong because Cloud NAT allows resources without external IPs to initiate outbound connections to the internet, which would actually facilitate data exfiltration rather than prevent it.

474
MCQmedium

A company wants to encrypt data at rest in Cloud Storage using a key that they generate and manage themselves, not stored in Google Cloud. Which encryption type should they use?

A.Default encryption
B.Cloud HSM
C.CSEK
D.CMEK with Cloud KMS
AnswerC

Customer-supplied encryption keys (CSEKs) let you generate and manage the key material yourself; Google Cloud never stores it, satisfying the requirement that the key not reside in Google Cloud. The key is supplied per request and used transiently, unlike CMEK, where key material lives in Cloud KMS.

Why this answer

Customer-Supplied Encryption Keys (CSEK) allow you to provide your own AES-256 key with each Cloud Storage request; Google Cloud uses the key to encrypt/decrypt data but does not store the key. This matches the requirement of a self-generated, self-managed key not stored in Google Cloud. CMEK, by contrast, stores the key in Cloud KMS.

Exam trap

PCA often tests the distinction between CMEK (key stored in Cloud KMS) and CSEK (key supplied per request, never stored by Google) — candidates frequently pick CMEK thinking 'customer-managed' means 'not stored in Google Cloud.'

How to eliminate wrong answers

Option A is wrong because default encryption uses Google-managed keys that Google generates, rotates, and stores — the customer has no control over the key. Option B is wrong because Cloud HSM stores keys in a hardware security module managed by Google Cloud, which contradicts 'not stored in Google Cloud.' Option D is wrong because CMEK with Cloud KMS stores the customer-managed key in Cloud KMS, which is inside Google Cloud — the key is customer-managed but still stored by Google.

475
Multi-Selecteasy

A company is designing a data processing pipeline in Google Cloud that must be HIPAA compliant. Which three security features should they implement? (Choose three.)

Select 3 answers
A.Encrypt data in transit using TLS
B.Enable Data Loss Prevention (DLP) for data classification
C.Use Cloud CDN for faster delivery
D.Implement VPC Service Controls to prevent data exfiltration
E.Use Cloud HSM for encryption keys
AnswersA, D, E

Required by HIPAA for data in transit.

Why this answer

Encrypting data in transit using TLS is a mandatory security control for HIPAA compliance because it protects electronic protected health information (ePHI) from interception during transmission over networks. TLS 1.2 or higher ensures that data moving between clients, services, and Google Cloud endpoints is encrypted, meeting the HIPAA Security Rule requirement for integrity and confidentiality of ePHI in transit.

Exam trap

The trap here is that candidates confuse data classification tools like DLP with mandatory security controls, or mistake performance features like Cloud CDN for compliance requirements, when HIPAA specifically requires encryption, access controls, and audit trails.

476
MCQmedium

A company stores infrequently accessed data in Cloud Storage Standard class. To reduce costs, they want to automatically move objects older than 90 days to a lower-cost storage class. Which approach should they use?

A.Configure a lifecycle policy to transition to Archive class
B.Use gsutil rewrite to manually change storage class
C.Set up Pub/Sub notifications for object changes
D.Enable object versioning
AnswerA

A lifecycle policy applies transition rules based on object age, automatically moving objects from Standard to Archive after 90 days without manual intervention. This directly satisfies the requirement to reduce storage costs for infrequently accessed data through automated class transitions.

Why this answer

Object Lifecycle Management in Cloud Storage is designed exactly for this use case: automatically transitioning objects to lower-cost storage classes based on age or other conditions. Configuring a lifecycle rule to transition objects older than 90 days to the Archive class (A) reduces cost while preserving durability and access when needed. Lifecycle policies run asynchronously and are the standard, supported mechanism for automated class transitions.

Exam trap

PCA often tests whether candidates confuse manual class-change commands (gsutil rewrite) with automated lifecycle policies, or mistakenly believe Pub/Sub notifications or versioning can drive cost-optimization transitions.

How to eliminate wrong answers

Option B is wrong because gsutil rewrite is a manual, one-off operation that changes an object's storage class but does not automate the process based on object age — it would require scripting and repeated execution, defeating the purpose. Option C is wrong because Pub/Sub notifications merely alert on object changes; they do not perform storage class transitions and would require custom code to act on the events. Option D is wrong because object versioning retains multiple versions of objects for recovery purposes; it increases storage cost rather than reducing it and does nothing to change storage class.

477
MCQhard

A company uses Assured Workloads to meet FedRAMP compliance. They need to ensure that only authorized personnel can access data access audit logs for their projects. Which IAM role should they grant to the security team?

A.roles/logging.privateLogViewer
B.roles/logging.viewer
C.roles/iam.securityReviewer
D.roles/logging.admin
AnswerA

roles/logging.privateLogViewer grants access to data access audit logs, which are otherwise restricted to project owners by default. Assigning it to the security team satisfies the FedRAMP requirement that only authorised personnel can read those logs, without granting broader logging permissions.

Why this answer

roles/logging.privateLogViewer grants read access to private logs, which includes Data Access audit logs, and is the least-privilege role designed for viewing sensitive audit data. Data Access logs are classified as private logs in Cloud Logging, so the security team needs a role that explicitly includes logging.privateLogs.view permission. This satisfies the FedRAMP requirement that only authorized personnel can view data access audit logs.

Exam trap

The trap here is confusing roles/logging.viewer with roles/logging.privateLogViewer — candidates assume 'viewer' covers all logs, but Data Access audit logs require the privateLogViewer role specifically.

How to eliminate wrong answers

Option B is wrong because roles/logging.viewer grants access to _Default and _Required log buckets but explicitly excludes private logs such as Data Access audit logs. Option C is wrong because roles/iam.securityReviewer only allows viewing IAM policies and roles; it does not grant any log-reading permissions. Option D is wrong because roles/logging.admin grants full administrative control over logging (creating sinks, deleting logs, managing exclusions), which violates least privilege for a team that only needs to read audit logs.

478
MCQeasy

A company is migrating a legacy monolithic application to Google Cloud. The application currently runs on a single on-premises server and uses a local MySQL database. The company wants to minimize changes to the application code while improving scalability and reliability. Which migration strategy should the architect recommend?

A.Refactor the application into microservices and deploy on Google Kubernetes Engine.
B.Rehost the application on Compute Engine and use Cloud SQL for MySQL as the database.
C.Containerize the application with Docker and run it on Cloud Run.
D.Migrate the database to Firestore and rewrite the application to use Firestore APIs.
AnswerB

Rehosting on Compute Engine with Cloud SQL for MySQL lifts and shifts the application with minimal code change, satisfying the minimise-changes constraint. Cloud SQL adds managed backups and high availability, improving reliability and scalability over the single on-premises server.

Why this answer

Rehosting (lift-and-shift) the monolithic application to Compute Engine with Cloud SQL for MySQL minimizes code changes while improving scalability and reliability. Cloud SQL provides managed MySQL with automated backups, replication, and failover, addressing the need for reliability without requiring application refactoring.

Exam trap

The trap here is that candidates often over-engineer the solution by choosing containerization or microservices, forgetting that the primary constraint is minimizing code changes, not modernizing the architecture.

How to eliminate wrong answers

Option A is wrong because refactoring into microservices and deploying on GKE introduces significant code changes and complexity, contradicting the requirement to minimize changes. Option C is wrong because containerizing with Docker and running on Cloud Run requires the application to be stateless and HTTP-driven, which a legacy monolithic app with a local MySQL database typically is not; Cloud Run also does not support stateful workloads or persistent MySQL connections natively. Option D is wrong because migrating to Firestore and rewriting the application to use Firestore APIs requires substantial code changes and a shift from SQL to NoSQL, violating the minimize-changes constraint.

479
MCQhard

A healthcare company stores PHI in BigQuery. Compliance requires that analysts see masked values for patient names and MRNs, while a small data-engineering group must see unmasked values for pipeline troubleshooting. The policy must be enforced by BigQuery itself, independent of any application code. Which approach should the architect implement?

A.Create two separate datasets and grant analysts access only to the masked dataset, applying a view that selects hashed columns
B.Enable VPC Service Controls around the BigQuery project so only the data-engineering group can query the dataset
C.Apply row-level security filters on the table so analysts only see rows belonging to their region
D.Use BigQuery column-level security with policy tags in Data Catalog, granting the data-engineering group the Fine-Grained Reader role on the sensitive tags
AnswerD

Policy tags attached to columns enforce masking or denial at query time inside BigQuery, independent of application code. Analysts without the Fine-Grained Reader role on the tag receive masked or denied values, while the data-engineering group granted that role on the tag sees raw values, satisfying the split-visibility requirement declaratively.

Why this answer

BigQuery column-level security with Data Catalog policy tags enforces per-column access in the query engine. Sensitive columns are tagged, and only principals granted the Fine-Grained Reader role on that tag can read raw values. Analysts without the role receive masked or denied results, and engineers with the role see clear text, with no application changes needed.

Exam trap

The trap here is reaching for row-level security or dataset duplication when the requirement is specifically per-column value masking for different principals on the same table.

480
MCQhard

An organization wants to enforce that all Compute Engine VMs are created with specific disk encryption keys. Which policy mechanism should they use?

A.Organization policies with constraints/compute.restrictDiskEncryptionKeyTypes
B.IAM roles with compute.diskEncryptionKey permissions
C.VPC Service Controls
D.Cloud Scheduler to check compliance
AnswerA

Organization policies with `constraints/compute.restrictDiskEncryptionKeyTypes` enforce CMEK requirements at the resource hierarchy level, blocking VM creation that lacks customer-managed encryption keys. This satisfies the stem's constraint that all Compute Engine VMs must be created with specific disk encryption keys, applying prevention rather than detection.

Why this answer

The Organization Policy constraint `constraints/compute.restrictDiskEncryptionKeyTypes` allows administrators to enforce that all Compute Engine VMs must use specific disk encryption key types (e.g., CMEK or CSEK). This policy is evaluated at resource creation time and blocks any VM that does not comply with the allowed key types, providing a preventive control rather than a reactive one.

Exam trap

The trap here is confusing IAM permissions (who can do something) with Organization Policy constraints (what is allowed to be done), leading candidates to choose IAM roles instead of the correct policy mechanism.

How to eliminate wrong answers

Option B is wrong because IAM roles with `compute.diskEncryptionKey` permissions control who can set or view encryption keys, but they do not enforce which key types must be used on VMs; IAM is an authorization mechanism, not a policy enforcement mechanism. Option C is wrong because VPC Service Controls are designed to protect data exfiltration by controlling access to Google Cloud APIs from outside a VPC perimeter, not to enforce disk encryption key types on Compute Engine VMs. Option D is wrong because Cloud Scheduler is a cron-like job scheduler that can trigger compliance checks, but it is a reactive, after-the-fact mechanism and cannot prevent non-compliant VM creation in real time.

481
MCQhard

An organization uses Cloud SQL for MySQL in a production environment. They need to ensure high availability with automatic failover in case of a zonal failure. Which configuration should they use?

A.Create a read replica in a different region.
B.Create a regional Cloud SQL instance with automatic failover.
C.Export the database daily and import into a new instance if failure occurs.
D.Deploy Cloud SQL across multiple regions using cross-region replication.
AnswerB

A regional instance replicates synchronously across two zones in the same region and promotes the standby automatically on zonal failure, satisfying the automatic failover requirement. A zonal instance offers no standby, so it cannot meet the stated high-availability constraint.

Why this answer

A regional Cloud SQL instance with automatic failover uses a primary and a standby zone within the same region, with synchronous replication between them. If the primary zone fails, Cloud SQL automatically promotes the standby to primary, ensuring high availability without data loss. This configuration meets the requirement for automatic failover during a zonal failure.

Exam trap

The trap here is that candidates confuse cross-region replication (available for other database engines) with the zonal high-availability feature for Cloud SQL for MySQL, or assume that a read replica can be used for automatic failover when it requires manual promotion.

How to eliminate wrong answers

Option A is wrong because a read replica in a different region provides read scalability and disaster recovery across regions, but it does not support automatic failover for the primary instance; failover would require manual promotion, which is not automatic. Option C is wrong because daily exports and manual imports are a backup and restore strategy, not a high-availability solution; it introduces significant downtime and potential data loss, failing the automatic failover requirement. Option D is wrong because Cloud SQL for MySQL does not support cross-region replication for automatic failover; cross-region replication is available for Cloud SQL for PostgreSQL and SQL Server, but for MySQL, it is limited to read replicas, which do not provide automatic failover.

482
MCQmedium

A company wants to enforce that all API calls to GCP services from outside their corporate network come through a specific Cloud VPN tunnel. Which GCP service can enforce this policy?

A.VPC Service Controls
B.Cloud NAT
C.Identity-Aware Proxy
D.Cloud Armor
AnswerA

VPC Service Controls creates a service perimeter that restricts API access to authorised networks, so requests from outside the corporate network are denied unless they traverse the specified Cloud VPN tunnel. This satisfies the stem's requirement to enforce tunnel-only access to GCP service APIs.

Why this answer

VPC Service Controls lets you define a service perimeter around GCP resources (such as Cloud Storage, BigQuery, and APIs) and restrict access so that requests must originate from within an authorized network — including a specific Cloud VPN tunnel or VPC network. By configuring an access level based on the VPN tunnel's source IP range or network, you can enforce that API calls to protected services from outside the corporate network are denied unless they traverse the specified VPN.

Exam trap

PCA often tests the distinction between network-layer controls (firewall, Cloud NAT) and service-perimeter controls (VPC Service Controls), catching candidates who pick Cloud NAT or Cloud Armor for API access enforcement.

How to eliminate wrong answers

Option B is wrong because Cloud NAT provides outbound internet connectivity for private instances — it does not enforce access policies on inbound API calls. Option C is wrong because Identity-Aware Proxy controls access to web applications and VMs based on identity, not network path enforcement for API calls to GCP services. Option D is wrong because Cloud Armor protects against DDoS and web attacks at the edge (HTTP/S load balancer level) and does not enforce service-level API access based on network origin.

483
Multi-Selectmedium

A team is designing a disaster recovery plan for a critical application. They need to ensure RPO of less than 1 hour and RTO of less than 4 hours. The application runs on Compute Engine with persistent disks and uses Cloud SQL for MySQL. Which THREE actions should they take? (Choose 3.)

Select 3 answers
A.Deploy a Transfer Appliance to copy data to another region weekly
B.Use a regional managed instance group and rely on Google's automatic failover
C.Store application configuration and scripts in a multi-regional Cloud Storage bucket
D.Configure Cloud SQL cross-region replication to a replica in another region
E.Take regular snapshots of Compute Engine persistent disks and replicate them to another region using Cloud Storage
AnswersC, D, E

Multi-regional Cloud Storage provides durable, geo-redundant storage for configuration and deployment scripts, so rebuilds after a regional failure can retrieve them without depending on the failed region. This supports the four-hour RTO by accelerating Compute Engine re-provisioning.

Why this answer

Option C is correct because storing application configuration and scripts in a multi-regional Cloud Storage bucket ensures they remain available even if one region fails, supporting recovery within the 4-hour RTO without manual rebuild delays. Option D is correct because Cloud SQL cross-region replication continuously replicates the MySQL database to a replica in another region, enabling a low RPO (well under 1 hour) and a fast promotion/failover path to meet the 4-hour RTO. Option E is correct because regular persistent disk snapshots replicated to another region via Cloud Storage provide a restorable copy of Compute Engine disk data in the DR region, which is necessary to rebuild instances within the RTO and keep data loss under the RPO.

Option A is not appropriate because Transfer Appliance is an offline, batch data-transfer appliance with weekly cadence, which cannot meet an RPO under 1 hour or an RTO under 4 hours. Option B is not sufficient because a regional managed instance group only provides automatic failover across zones within a single region, not cross-region disaster recovery, so a region-wide outage would still exceed the required RTO/RPO.

484
MCQmedium

A company is migrating an on-premises PostgreSQL database to Cloud SQL with minimal downtime. The database is 1 TB and the network link has 500 Mbps bandwidth. Which migration approach is most appropriate?

A.Set up a Compute Engine instance with PostgreSQL replication and switch over.
B.Use BigQuery Data Transfer Service to replicate data.
C.Export the database as a SQL dump, transfer it to Cloud Storage, and import into Cloud SQL.
D.Use Database Migration Service to perform continuous replication and then promote Cloud SQL.
AnswerD

Database Migration Service performs continuous replication from the on-premises PostgreSQL instance to Cloud SQL, keeping changes synchronised over the 500 Mbps link. Promoting Cloud SQL after replication catches up minimises downtime, unlike a one-off dump and load of 1 TB.

Why this answer

Database Migration Service (DMS) supports continuous replication from on-premises PostgreSQL to Cloud SQL using native PostgreSQL logical replication (pglogical or native publication/slot). This allows near-zero downtime by keeping the target in sync until promotion, which is ideal for a 1 TB database over a 500 Mbps link where a full dump/restore would take hours.

Exam trap

Google Cloud often tests the misconception that a simple dump-and-import (Option C) is acceptable for large databases, but the trap here is ignoring the 'minimal downtime' requirement, which demands a continuous replication solution like DMS rather than a batch export/import.

How to eliminate wrong answers

Option A is wrong because setting up a Compute Engine instance with PostgreSQL replication requires manual configuration of replication slots, failover scripts, and does not integrate with Cloud SQL's managed service, adding operational overhead and risk. Option B is wrong because BigQuery Data Transfer Service is designed for loading data into BigQuery, not for replicating PostgreSQL databases to Cloud SQL; it cannot perform continuous replication or handle transactional consistency. Option C is wrong because exporting a 1 TB database as a SQL dump and transferring it over a 500 Mbps link would take approximately 4.5 hours (1 TB * 8 / 500 Mbps) plus import time, causing significant downtime, and it does not support continuous replication for minimal downtime.

485
MCQhard

A multinational corporation needs to ensure that data stored in Cloud Storage buckets in their Google Cloud organization cannot be accessed from outside their corporate network, even if IAM policies are misconfigured. They want to enforce this at the organization level with minimal administrative overhead. What should they do?

A.Create a VPC Service Controls perimeter that includes the Cloud Storage service and the projects containing the buckets, and configure access levels to allow only corporate IP ranges.
B.Enable Cloud Armor security policies on all Cloud Storage buckets to block external IPs.
C.Use IAM Conditions on all Cloud Storage IAM bindings to allow access only from corporate IP ranges.
D.Apply an organization policy constraint `storage.publicAccessPrevention` to all buckets.
AnswerA

VPC Service Controls create a security perimeter around Google Cloud services, preventing data exfiltration even if IAM is misconfigured. By including Cloud Storage and configuring access levels based on corporate IP ranges, access from outside the network is blocked. This is enforced at the organization level and requires minimal per-project configuration, meeting the requirement for centralized control.

Why this answer

VPC Service Controls provide a centralized, organization-level security perimeter that prevents access to Cloud Storage from outside authorized networks, even if IAM policies are misconfigured. By defining access levels based on corporate IP ranges, the organization can ensure that only requests from the corporate network are allowed. This is the most effective and least administrative approach compared to per-binding IAM Conditions or bucket-level constraints.

Exam trap

The trap here is assuming that IAM Conditions or public access prevention alone can enforce network-based access control at scale.

486
MCQhard

An IoT company ingests telemetry from 40,000 devices spread across three continents. The architecture team wants a single logical endpoint that automatically routes each device's writes to the nearest healthy Google Cloud region, and they want to avoid managing per-region DNS records or load-balancer IPs. Which design should the architect choose?

A.A global external Application Load Balancer with a single anycast IP fronting regional backends
B.Cloud Interconnect attachments from each continent into a single regional VPC with a regional internal passthrough Network Load Balancer
C.Cloud DNS with a geolocation routing policy pointing to regional external passthrough Network Load Balancer IPs
D.A global external proxy Network Load Balancer with a single anycast IP and a TCP proxy target proxy
AnswerD

A global external proxy Network Load Balancer exposes one anycast IP and terminates TCP or SSL sessions at the Google edge, then routes to the closest healthy backend service. It supports arbitrary TCP ports, including MQTT over TLS on 8883, and health-checks backends across regions, giving the single logical endpoint with automatic nearest-region routing the team wants.

Why this answer

The requirement is one logical anycast endpoint that terminates arbitrary TCP and picks the nearest healthy region. A global external proxy Network Load Balancer does exactly that, with SSL or TCP proxy target proxies and health-checked regional backends. Application Load Balancers are HTTP(S)-only, DNS geolocation needs per-region records, and Interconnect plus an internal passthrough load balancer cannot accept public device traffic.

Exam trap

The trap here is confusing the global external Application Load Balancer, which is HTTP(S)-only, with the global external proxy Network Load Balancer that handles arbitrary TCP.

487
Multi-Selectmedium

A company is deploying a new application on Google Kubernetes Engine (GKE). They need to ensure that the application can automatically scale based on custom metrics, such as the number of pending requests in a queue. They also want to minimize operational overhead. Which TWO actions should they take? (Choose two.)

Select 2 answers
A.Use a Kubernetes Cluster Autoscaler to add nodes when pods are pending.
B.Configure a Vertical Pod Autoscaler (VPA) to adjust resource requests.
C.Deploy the application as a DaemonSet to ensure one pod per node.
D.Export the custom metric to Cloud Monitoring using the Cloud Monitoring API or a sidecar.
E.Enable Horizontal Pod Autoscaler (HPA) with custom metrics from Cloud Monitoring.
AnswersD, E

For HPA to use custom metrics, they must be available in Cloud Monitoring. This can be done via the Cloud Monitoring API or by using a sidecar like the Stackdriver adapter. Exporting the metric is a prerequisite for HPA to scale based on it. This action, combined with enabling HPA, fulfills the requirement.

Why this answer

To scale based on custom metrics in GKE, the metrics must be exported to Cloud Monitoring, and then the Horizontal Pod Autoscaler can be configured to use those metrics. This approach leverages managed GKE features, minimizing operational overhead. Cluster Autoscaler and VPA address different scaling dimensions and are not required for custom metric scaling.

Exam trap

The trap here is confusing Horizontal Pod Autoscaler with Vertical Pod Autoscaler or Cluster Autoscaler, and forgetting that custom metrics must be exported to Cloud Monitoring first.

488
MCQeasy

A media company stores finished video masters in a Cloud Storage bucket. Legal requires that every object be retained for exactly seven years and that no user, including project owners, be able to delete or overwrite an object before that period ends. Which bucket configuration should the architect apply?

A.Enable Uniform Bucket-Level Access and grant the Storage Object Admin role only to the security team.
B.Apply a bucket lock with a retention policy of seven years and grant users the Storage Object Creator role.
C.Enable Object Versioning on the bucket and grant users only the Storage Object Viewer role.
D.Configure a lifecycle rule that moves objects to Archive storage after 30 days and deletes them after 2,555 days.
AnswerB

A retention policy blocks deletion or replacement of objects until the retention period elapses, and locking the bucket makes the policy permanent so that even a project owner cannot shorten or remove it. Setting the period to seven years satisfies the legal hold exactly, and restricting users to object creation prevents them from altering existing masters while still allowing new uploads.

Why this answer

Immutability for a fixed period is delivered by a bucket retention policy, and locking the bucket makes that policy irreversible so no principal can shorten it or delete protected objects early. Seven years expressed as a retention duration plus restricted write access satisfies the legal hold while still permitting new masters to be uploaded to the bucket.

Exam trap

The trap here is confusing versioning or lifecycle management with true immutability, when only a locked retention policy prevents early deletion by privileged users.

489
MCQmedium

A developer wants to deploy a Cloud Function that is triggered whenever a new object is created in a Cloud Storage bucket. Which trigger type should they choose?

A.Firestore trigger
B.Cloud Storage trigger
C.Pub/Sub trigger
D.HTTP trigger
AnswerB

A Cloud Storage trigger fires on object events such as finalise or create, which is precisely the event the stem requires. It is delivered through Eventarc, so the function runs whenever a new object lands in the bucket, satisfying the "new object created" constraint without polling.

Why this answer

A Cloud Storage trigger is specifically designed to invoke a Cloud Function in response to object events in a Cloud Storage bucket, such as object creation (google.storage.object.finalize). This is the direct and native trigger type for 'new object created in a bucket' scenarios. It eliminates the need for additional event routing or polling.

Exam trap

PCA often tests the distinction between direct Cloud Storage triggers and indirect Pub/Sub triggers, so candidates must recognize that the native trigger for bucket object events is Cloud Storage trigger.

How to eliminate wrong answers

Option A is wrong because a Firestore trigger responds to document changes in Firestore, not to Cloud Storage object events. Option C is wrong because a Pub/Sub trigger responds to messages published to a Pub/Sub topic; while Cloud Storage can publish events to Pub/Sub, using a Pub/Sub trigger directly is an indirect approach and not the primary trigger type for bucket object creation. Option D is wrong because an HTTP trigger invokes the function via an HTTP request, which is unrelated to bucket object creation events.

490
MCQhard

A media company streams video from a global user base. The architect must provision a load balancer that terminates TLS, routes requests by URL path to different backend services, and provides a single global anycast IP address. The backend services run on managed instance groups in three regions. Which Google Cloud load balancer should the architect deploy?

A.External passthrough Network Load Balancer
B.Regional external Application Load Balancer
C.Global external Application Load Balancer
D.Internal TCP/UDP Load Balancer
AnswerC

The global external Application Load Balancer is a layer 7 proxy that terminates TLS at the edge, supports URL map path-based routing to multiple backend services, and exposes a single global anycast IP. Backends in multiple regions are reached through the Google front end, so it matches every stated requirement for this global video workload.

Why this answer

A single global anycast IP, edge TLS termination, and URL path routing to backends in three regions all point to the global external Application Load Balancer. Its layer 7 proxy architecture inspects HTTP requests and uses URL maps to direct traffic, while the Google front end absorbs TLS and distributes requests across regional managed instance groups without requiring a separate IP per region.

Exam trap

The trap here is confusing the regional and global Application Load Balancer tiers, since both terminate TLS and route by URL path, but only the global tier provides a single anycast IP spanning multiple regions.

491
Multi-Selectmedium

Which TWO services can be used to create a CI/CD pipeline for a containerized application on Google Cloud? (Choose 2)

Select 2 answers
A.Cloud Deploy
B.Cloud Functions
C.Cloud Build
D.Cloud Scheduler
E.Cloud Run
AnswersA, C

Cloud Deploy is Google Cloud's managed continuous delivery service, orchestrating progressive rollouts to GKE, Cloud Run and Anthos targets via declarative delivery pipelines and targets. It supplies the deployment stage of the CI/CD pipeline, satisfying the continuous-delivery half of the requirement.

Why this answer

Cloud Build (C) is correct because it is Google Cloud's managed CI service that executes build steps defined in a cloudbuild.yaml (or Dockerfile) to build, test, and push container images to Artifact Registry, and it can trigger pipelines from Cloud Source Repositories, GitHub, or Bitbucket. Cloud Deploy (A) is correct because it is Google Cloud's managed continuous delivery service that takes a built container image and progressively rolls it out to GKE, Cloud Run, or Anthos target environments using declarative delivery pipelines and promotion/approval stages. Together they form the CI (Cloud Build) and CD (Cloud Deploy) halves of a containerized CI/CD pipeline.

Cloud Functions (B) is a serverless event-driven compute service for running code snippets, not a pipeline orchestrator. Cloud Scheduler (D) is a cron-based job scheduler that can trigger jobs but does not build or deploy containers. Cloud Run (E) is a serverless container runtime that hosts the application, not a service for constructing the CI/CD pipeline itself.

Exam trap

PCA often tests the CI versus CD split — candidates pick Cloud Run thinking it 'runs the pipeline', but Cloud Run is the runtime target, not the pipeline service.

492
Multi-Selectmedium

A logistics company is planning a new order-tracking platform on Google Cloud. The platform must handle sudden, unpredictable spikes from holiday promotions, keep costs low during idle periods, and provide a relational store that scales reads without the team managing replication. The architect is choosing between fully managed services and self-managed alternatives. Which two design choices meet these requirements? (Choose two.)

Select 2 answers
A.Use Cloud Spanner with a regional instance configuration, which scales reads and writes horizontally and replicates automatically.
B.Deploy the API tier on a Compute Engine managed instance group with a fixed size sized for peak holiday traffic.
C.Run PostgreSQL on Compute Engine with streaming replication to a standby VM, and use a load balancer to split reads.
D.Use Cloud SQL for PostgreSQL with read replicas, and have the team script replica promotion for failover.
E.Run the API tier on Cloud Run, which scales to zero when idle and scales out automatically under load.
AnswersA, E

Cloud Spanner is a fully managed, horizontally scalable relational database that handles read and write scaling automatically through its regional configuration and synchronous replication. It provides strong consistency and requires no replica management or promotion scripts, satisfying the relational store requirement that scales reads without operational replication work.

Why this answer

Cloud Run scales to zero and then out automatically, which matches unpredictable promotional spikes while keeping idle cost near zero. Cloud Spanner provides a managed relational store that scales reads and writes horizontally with automatic replication, so the team never manages replicas or failover. Together they cover the compute and data tiers without the operational overhead of self-managed alternatives.

Exam trap

The trap here is reading fully managed as merely hosted, when services like Cloud SQL with read replicas still require the team to size, monitor, and promote replicas.

493
MCQeasy

An engineer needs to list all Compute Engine instances in a project using the command line. Which gcloud command should they use?

A.gcloud compute instances describe
B.gcloud compute instances list
C.gcloud compute instance-groups list
D.gcloud compute machine-types list
AnswerB

The gcloud compute instances list command queries the Compute Engine API and returns every instance in the active project, with optional filtering by zone or name. It directly satisfies the stem's requirement to enumerate all Compute Engine instances from the command line.

Why this answer

The correct command to list Compute Engine instances is 'gcloud compute instances list'. The other options are incorrect: 'gcloud compute machine-types list' lists machine types, 'gcloud compute instance-groups list' lists instance groups, and 'gcloud compute instances describe' describes a specific instance.

494
MCQeasy

A development team wants to automate the process of building container images from their GitHub repository and storing them in Artifact Registry. Which Google Cloud service should they use to create a build trigger that runs on every push to the main branch?

A.Container Registry
B.Cloud Build
C.Artifact Registry
D.Cloud Deploy
AnswerB

Cloud Build provides build triggers that watch a connected GitHub repository and execute a build on each push, then push the resulting image to Artifact Registry. Artifact Registry itself only stores images, and other services do not offer repository-triggered builds.

Why this answer

Cloud Build is the correct service because it provides build triggers that can be configured to automatically build container images from source repositories like GitHub. When a push to the main branch occurs, Cloud Build can execute a build using a Dockerfile or buildpack, and then push the resulting image to Artifact Registry. This directly addresses the requirement to automate image building and storage.

Exam trap

PCA often tests the distinction between building and storing container images, so candidates might confuse Artifact Registry (storage) with Cloud Build (building).

How to eliminate wrong answers

Option A is wrong because Container Registry is a deprecated service for storing container images, not for building them; it lacks build trigger capabilities. Option C is wrong because Artifact Registry is a repository service for storing and managing container images and other artifacts, but it does not provide build automation or triggers. Option D is wrong because Cloud Deploy is a service for continuous delivery to GKE and other targets, not for building container images from source code.

495
Multi-Selectmedium

A company is planning to migrate a large on-premises Oracle database (10 TB) to Cloud SQL for PostgreSQL. They need to minimise downtime and ensure data integrity. Which TWO services or tools should they use? (Choose TWO.)

Select 1 answer
A.Migrate for Compute Engine
B.Cloud Dataflow
C.Cloud Scheduler
D.Database Migration Service (DMS)
E.Cloud SQL Auth Proxy
AnswersD

Database Migration Service (DMS) supports online migration from Oracle to Cloud SQL for PostgreSQL with minimal downtime.

Why this answer

Database Migration Service (DMS) supports online migration from Oracle to Cloud SQL for PostgreSQL with minimal downtime by using continuous replication. Cloud SQL Auth Proxy is a tool for secure client connections to Cloud SQL instances; it is not required for the migration process itself. Cloud Dataflow is for data processing, Cloud Scheduler for job scheduling, and Migrate for Compute Engine for VM migration.

Exam trap

Candidates may think Cloud SQL Auth Proxy is needed for migration because it is commonly used with Cloud SQL, but it is only for client-side secure connectivity, not for the migration process itself.

496
MCQhard

Your company runs a multi-tier web application on Google Kubernetes Engine (GKE). The application consists of a frontend service, a backend API service, and a PostgreSQL database deployed using a StatefulSet with persistent volumes. The backend service exposes a gRPC endpoint. Recently, the team noticed that the backend service experiences intermittent high latency and occasional timeouts. The frontend service is stateless and scales well. The backend service is CPU-bound. The database is not the bottleneck. The cluster has three nodes of type n1-standard-4. The backend service is deployed with 10 replicas, each requesting 1 CPU and 2 Gi memory. Node utilization is around 70% CPU. The team suspects the network is the issue. However, after reviewing the GKE monitoring dashboard, they see that the network bytes sent/received per second for the backend pods is well below the node's network bandwidth limit. The latency spikes seem correlated with periods of high CPU throttling on the backend pods. The backend service's gRPC requests are small (under 1 KB), and the responses are also small. The team has already optimized the application code. What should the team do to reduce latency?

A.Increase the number of nodes in the cluster to reduce network contention.
B.Increase the number of backend replicas to 20.
C.Increase the CPU request for the backend pods to 2 CPUs.
D.Increase the memory request for the backend pods to 4 Gi.
AnswerC

CPU throttling, not network bandwidth, causes the latency spikes. Raising each backend pod's CPU request to 2 CPUs gives the CPU-bound gRPC service enough quota to avoid throttling, directly removing the constraint correlated with the observed timeouts.

Why this answer

The latency spikes correlate with CPU throttling, and increasing the CPU request to 2 CPUs ensures that each backend pod receives a guaranteed CPU share, reducing throttling under load. Since the backend is CPU-bound and node utilization is 70%, the current 1 CPU request may be insufficient, causing the Kubernetes CPU manager to throttle the pods when the node's CPU is contended. This directly addresses the root cause without adding unnecessary replicas or memory.

Exam trap

The trap here is that candidates may focus on network or scaling solutions (A or B) because the symptom is latency, but the monitoring data explicitly points to CPU throttling, not network saturation, making CPU request adjustment the precise fix.

How to eliminate wrong answers

Option A is wrong because network contention is not the issue—monitoring shows network bytes are well below node bandwidth limits, and the problem is CPU throttling, not network. Option B is wrong because increasing replicas to 20 would increase CPU contention on the existing nodes, worsening throttling and latency, and the frontend already scales well. Option D is wrong because the backend is CPU-bound, not memory-bound; increasing memory does not alleviate CPU throttling and would waste resources.

497
MCQeasy

A company runs batch machine learning training jobs that can be interrupted. They want to reduce compute costs. Which Compute Engine VM pricing model is MOST cost-effective?

A.Preemptible VMs
B.Standard VMs
C.Sustained use discounts
D.Committed use discounts
AnswerA

Preemptible VMs cost up to 80% less than standard instances, satisfying the cost-reduction constraint. Because the batch training jobs tolerate interruption, the 24-hour maximum lifespan and abrupt termination risk are acceptable. Spot VMs offer similar discounts but with different eviction behaviour; preemptible suits this workload's fault tolerance.

Why this answer

Preemptible VMs are the most cost-effective for interruptible batch ML training jobs because they offer up to 80% discount compared to standard VMs. They can be terminated at any time by Compute Engine, but since the jobs can be interrupted, this is acceptable. Other pricing models like sustained use discounts apply automatically to standard VMs but offer smaller discounts, and committed use discounts require a 1- or 3-year commitment, which may not be suitable for temporary or variable workloads.

Exam trap

PCA often tests the distinction between preemptible VMs and committed use discounts, and candidates may incorrectly choose committed use discounts for cost savings without considering the interruptible nature of the workload.

How to eliminate wrong answers

Option B is wrong because standard VMs are priced at full rate and do not provide the deep discounts needed for cost reduction. Option C is wrong because sustained use discounts are automatic discounts for running VMs for a significant portion of the month, but they are less aggressive than preemptible discounts and do not require interruptibility. Option D is wrong because committed use discounts require a long-term commitment (1 or 3 years) and are best for steady-state workloads, not interruptible batch jobs.

498
MCQhard

A healthcare company is designing a new patient-records API on Google Cloud. The API must serve read-heavy traffic globally with low latency, tolerate the failure of an entire region, and keep operational overhead low. The data is stored in Cloud Spanner. Which design should the architect recommend?

A.Deploy a regional Cloud Spanner instance and run the API on Compute Engine managed instance groups in two zones behind a regional external Application Load Balancer.
B.Deploy a multi-region Cloud Spanner instance and use Cloud DNS with a geoproximity routing policy that resolves clients to a regional external Application Load Balancer in the closest region.
C.Deploy a multi-region Cloud Spanner instance and run the API on a global external Application Load Balancer with serverless NEGs pointing to Cloud Run services in multiple regions.
D.Deploy a multi-region Cloud Spanner instance and run the API on Compute Engine VMs in two regions, using a global external proxy Network Load Balancer with a single global backend service.
AnswerC

A multi-region Cloud Spanner instance replicates data across regions with strong consistency and automatic failover, while a global external Application Load Balancer routes users to the nearest healthy Cloud Run backend. This combination delivers low-latency global reads, regional failure tolerance, and minimal operational burden because both services are managed. It directly satisfies all three stated requirements.

Why this answer

Global external Application Load Balancers route HTTP traffic to the nearest healthy backend across regions and support serverless NEGs for Cloud Run, while multi-region Cloud Spanner provides strongly consistent, automatically replicated data with regional failover. Together they meet the global latency, regional resilience, and low-overhead goals. Regional load balancers, proxy network load balancers, and DNS-based routing each fall short on at least one requirement.

Exam trap

The trap here is treating a regional load balancer with multi-zone backends as sufficient for regional failure tolerance, when only a global load balancer plus multi-region data layer survives a full region outage.

499
MCQmedium

An application uses Cloud Bigtable and experiences high latency for reads. The row key is a timestamp prefix followed by a random ID. Queries often scan a range of timestamps for a specific ID. What design change would MOST improve read performance?

A.Change the row key to start with the random ID followed by timestamp
B.Add more Bigtable nodes
C.Use a separate column family for the ID
D.Enable Bigtable replication
AnswerA

Cloud Bigtable sorts rows lexicographically by row key, so a timestamp prefix scatters a single ID's rows across the entire table, forcing wide scans. Leading with the random ID groups all of one ID's rows contiguously, letting queries read a narrow, adjacent range.

Why this answer

For Bigtable, row key design is critical. Scanning a range of timestamps for a specific ID is inefficient if the key starts with timestamp (scans across all IDs). Prepending the ID ensures all data for that ID is contiguous, making range scans efficient.

Adding nodes increases throughput but doesn't fix the key design issue. Using a column family is about grouping columns, not performance.

500
MCQmedium

A company is migrating on-premises workloads to Google Cloud. They have a critical application that requires consistent low-latency access to a database, with read replicas in multiple regions for disaster recovery. The application is expected to grow by 10x over the next year. Which database service and configuration should the architect choose to meet these requirements?

A.Use Cloud Bigtable with multi-region replication
B.Use Cloud SQL for PostgreSQL with cross-region read replicas
C.Use Cloud Spanner with multi-region configuration
D.Use Firestore in native mode with multi-region location
AnswerC

Cloud Spanner's multi-region configuration synchronously replicates data across regions using TrueTime, delivering strong consistency with low read latency and automatic failover for disaster recovery. Its horizontally scalable architecture handles 10x growth without manual sharding, satisfying the stem's combined demands for consistent low latency, multi-region replicas and elastic scale.

Why this answer

Cloud Spanner with a multi-region configuration is the correct choice because it provides strong global consistency, low-latency reads and writes across regions, and automatic horizontal scaling to handle a 10x growth in workload. Its multi-region replication ensures synchronous replication for disaster recovery while maintaining ACID transactions, which is critical for a database requiring consistent low-latency access.

Exam trap

The trap here is that candidates often confuse Cloud Spanner's multi-region capabilities with simpler replication options like Cloud SQL read replicas or Bigtable's eventual consistency, failing to recognize that only Spanner provides strong global consistency and horizontal scaling for transactional workloads.

How to eliminate wrong answers

Option A is wrong because Cloud Bigtable is a NoSQL wide-column database designed for high-throughput analytical workloads, not for transactional applications requiring strong consistency and low-latency access to a single database; its multi-region replication is asynchronous and does not guarantee strong consistency. Option B is wrong because Cloud SQL for PostgreSQL supports cross-region read replicas, but the primary database is single-region and cannot scale horizontally to handle a 10x growth; read replicas are asynchronous and do not provide strong consistency for writes, making it unsuitable for a critical application requiring consistent low-latency access. Option D is wrong because Firestore in native mode is a NoSQL document database with eventual consistency by default (unless using transactions) and does not support the strong global consistency and horizontal scaling needed for a relational database workload with 10x growth; its multi-region location provides replication but not the ACID transactional guarantees required.

501
MCQeasy

A company wants to automatically apply security patches to Compute Engine instances running Windows Server. They need a solution that can schedule patch installations and report compliance. Which service should they use?

A.OS Config
B.Cloud Monitoring
C.Cloud Deploy
D.Cloud Build
AnswerA

OS Config provides patch management for Windows Server and Linux VMs, letting you create patch jobs on a schedule and view compliance reports per instance. It satisfies both the scheduling and reporting requirements without custom scripting.

Why this answer

OS Config (now part of VM Manager) provides patch management for Compute Engine instances, including Windows Server, with the ability to schedule patch jobs, define patch windows, and report compliance through the OS Config API and Cloud Console. It is the native Google Cloud service designed for OS patch deployment and compliance reporting across fleets of VMs.

Exam trap

PCA often tests the difference between observability (Cloud Monitoring) and configuration management (OS Config) — the trap is selecting Cloud Monitoring because it can show patch-related metrics, when only OS Config can actually schedule and apply patches.

How to eliminate wrong answers

Option B is wrong because Cloud Monitoring is an observability service for metrics, logs, and alerts — it can report on patch status if metrics are exported, but it cannot schedule or apply patches. Option C is wrong because Cloud Deploy is a continuous delivery service for deploying applications to GKE and other targets, not for OS patch management. Option D is wrong because Cloud Build is a CI/CD service for building and testing software artifacts, not for patching VM operating systems.

502
Multi-Selectmedium

A healthcare analytics company must build a data platform on Google Cloud that stores patient records subject to strict privacy rules. The design must ensure that analysts can query aggregated data without being able to read individual patient identifiers, and that all access to the raw records is logged for audit. Which two design choices should the architect include? (Choose two.)

Select 2 answers
A.Use Sensitive Data Protection (Cloud DLP) to de-identify or tokenize patient identifiers before loading records into the analytics dataset.
B.Store raw records in a Cloud Storage bucket with uniform bucket-level access and rely on object versioning for protection.
C.Encrypt the raw records with customer-managed encryption keys in Cloud KMS and rotate the keys every 90 days.
D.Enable Cloud Audit Logs Data Access logging on the services that store or serve the raw patient records.
E.Grant all analysts the BigQuery Data Viewer role at the project level so they can explore datasets efficiently.
AnswersA, D

Sensitive Data Protection can detect and transform identifiable fields such as names and medical record numbers, producing de-identified or tokenized output that analysts can query without seeing raw identifiers. This directly satisfies the requirement that aggregated analysis be possible while individual identifiers remain unreadable, and it can be applied during ingestion so the analytics layer never holds the original values.

Why this answer

The two goals are preventing analysts from reading identifiers and logging all access to raw records. De-identifying or tokenizing identifiers before the analytics layer sees them meets the first goal, and enabling Data Access audit logs on the services holding raw records meets the second. Broad viewer grants, generic storage protections, and encryption alone do not de-identify data or provide the necessary read-level audit trail.

Exam trap

The trap here is believing encryption at rest hides data from authorized users, when keys and IAM still allow plaintext reads.

503
MCQhard

A government agency must retain Cloud Storage objects for seven years in a bucket that also serves live traffic. Regulators require that no user, including project owners, can delete or shorten retention during that period. The architect needs a control that satisfies this. Which should the architect configure?

A.A bucket lock applied after configuring a retention policy on the bucket.
B.Object Versioning combined with a lifecycle rule that deletes noncurrent versions after seven years.
C.A Cloud Storage retention policy set to seven years without locking the bucket.
D.A bucket-level IAM condition that denies storage.objects.delete when the request comes from outside the agency's VPC.
AnswerA

Setting a retention policy prevents object deletion until the retention period elapses, and locking the bucket makes the policy permanent so that no principal, including project owners, can remove or reduce it. This directly satisfies the regulatory requirement that retention cannot be shortened by anyone during the seven-year window.

Why this answer

A Cloud Storage retention policy enforces a minimum age before objects can be deleted or overwritten, and locking the bucket makes that policy permanent and irreversible. Locking removes the ability of any principal, including project owners, to delete the policy or shorten the retention period, which is exactly the immutability regulators require for the seven-year window.

Exam trap

The trap here is believing that an unlocked retention policy is sufficient for compliance, when without the bucket lock any administrator can remove or shorten the policy at will.

504
MCQeasy

A team is adopting a DevOps model and wants to reduce the risk of configuration drift between environments. They deploy the same application to development, staging, and production projects on Google Cloud. Which practice should they adopt to ensure consistent, repeatable deployments across all environments?

A.Manually apply changes in each project and record them in a shared spreadsheet for audit purposes.
B.Use Cloud Console to configure each project and rely on Cloud Asset Inventory to detect differences after deployment.
C.Grant all engineers Owner role on each project so they can quickly recreate resources when drift is detected.
D.Define infrastructure as code using Terraform with separate variable files per environment, and store the configuration in a version control system.
AnswerD

Infrastructure as code with Terraform makes deployments declarative and repeatable. Separate variable files let the same modules target development, staging, and production with environment-specific values, while version control provides history, review, and rollback. This approach minimizes drift because the desired state is defined once and applied consistently.

Why this answer

Repeatable deployments across environments require a declarative, versioned definition of infrastructure. Terraform with per-environment variable files lets one set of modules produce consistent resources in development, staging, and production, while version control records changes and enables review and rollback. This prevents configuration drift far more effectively than manual changes or post-hoc detection.

Exam trap

The trap here is confusing drift detection with drift prevention, assuming that inventory or audit tools alone can keep environments consistent.

505
MCQeasy

A company wants to ensure that their development teams follow best practices for cost optimization. They want to implement a process that reviews architecture decisions before deployment and provides recommendations. Which Google Cloud tool should they use to get automated cost recommendations for their existing resources?

A.Cloud Billing reports
B.Active Assist
C.Cloud Asset Inventory
D.Cloud Monitoring
AnswerB

Active Assist uses machine learning to analyze resource usage and provide recommendations, such as identifying idle VMs, unattached disks, or overprovisioned instances. It can also recommend committed use discounts. This directly meets the requirement for automated cost recommendations and helps teams follow best practices.

Why this answer

Active Assist is a suite of tools that provides automated recommendations for cost, security, and performance. It analyzes resource usage and suggests optimizations such as right-sizing or deleting idle resources. This directly supports the goal of implementing a process for cost optimization recommendations.

Exam trap

The trap here is confusing cost visibility tools like Cloud Billing reports with recommendation engines like Active Assist.

506
Multi-Selectmedium

A company is migrating to Google Cloud and needs to implement a least-privilege access model. Which THREE Google Cloud services or features support this goal? (Choose three.)

Select 3 answers
A.Cloud IAM Conditions
B.Cloud Audit Logs
C.VPC Service Controls
D.Cloud NAT
E.Organization Policy Service
AnswersA, C, E

Allow access based on attributes like time, IP, or resource type, enabling least privilege.

Why this answer

Cloud IAM Conditions allow you to define and enforce attribute-based, context-aware access control policies on Google Cloud resources. By specifying conditions such as time, resource type, or IP address in IAM policies, you can grant temporary or scoped permissions, ensuring users have only the access necessary for their specific task. This directly supports least-privilege by reducing standing privileges and preventing over-permissioning.

Exam trap

The trap here is confusing auditing and monitoring services (like Cloud Audit Logs) with access control mechanisms, leading candidates to select Cloud Audit Logs as a least-privilege tool when it only records actions without enforcing permissions.

507
MCQeasy

A media startup wants to give its data science team isolated environments for experimentation while keeping billing and user management under one organization. Each environment must have its own quotas and IAM boundary, and the team wants to add or remove environments quickly without renegotiating billing. Which Google Cloud resource hierarchy construct should the architect use for each environment?

A.A single project with separate VPC networks and firewall rules for each environment.
B.A separate Google Cloud organization for each environment, each linked to its own billing account.
C.A folder under the organization, with one project per environment and IAM policies inherited from the folder.
D.A standalone project not attached to the organization, with billing enabled directly on the project.
AnswerC

Folders let an organization group projects and apply IAM and organization policies that are inherited by all contained projects, creating a clean boundary per environment. Projects give each environment its own quotas and resource namespace, and the whole structure stays under the single organization and billing account, so environments can be created or removed quickly.

Why this answer

Folders sit between the organization and projects and let administrators apply IAM and organization policies that projects inherit, giving each environment a consistent administrative boundary. Each project supplies its own quotas, APIs, and resource namespace, so experiments stay isolated. Because everything remains inside one organization and billing account, environments can be spun up or torn down quickly without touching billing or identity setup.

Exam trap

The trap here is assuming that separate VPC networks inside one project provide the same isolation as separate projects, when IAM and quotas remain shared.

508
MCQhard

An application uses Cloud SQL (PostgreSQL) and experiences high connection overhead, often exhausting the max connections limit. The team wants to maintain a pool of persistent connections without modifying application code. Which solution should they implement?

A.Use Cloud Memorystore as a connection cache
B.Increase the max connections flag in Cloud SQL
C.Configure Cloud SQL Auth Proxy with max connections
D.Deploy PgBouncer on a Compute Engine instance
AnswerD

PgBouncer sits between the application and Cloud SQL, multiplexing many client connections onto a small pool of persistent backend connections. This satisfies the no-code-change constraint and relieves connection overhead, since the application still connects normally to the proxy.

Why this answer

PgBouncer is a lightweight connection pooler that sits between the application and Cloud SQL, maintaining a pool of persistent connections and multiplexing many client connections onto a smaller number of database connections. This reduces connection overhead and prevents exhausting the max_connections limit without requiring application code changes. Cloud SQL Auth Proxy is for secure authentication, not pooling, and increasing max_connections only postpones the problem.

Exam trap

PCA often tests the misconception that Cloud SQL Auth Proxy provides connection pooling; it does not—it only handles authentication and encryption.

How to eliminate wrong answers

Option A is wrong because Cloud Memorystore is a Redis/Memcached service, not a PostgreSQL connection pooler. Option B is wrong because increasing max_connections does not reduce connection overhead and can lead to resource exhaustion. Option C is wrong because Cloud SQL Auth Proxy provides secure access but does not pool connections; it still creates a new connection per client.

509
Multi-Selecthard

A company runs a batch analytics job every hour on BigQuery. The job processes terabytes of data and the results are stored in Cloud Storage. The job must complete within 30 minutes. Which TWO actions can reduce query execution time? (Choose 2)

Select 2 answers
A.Use cached results from the previous run
B.Use a partitioned table based on the timestamp column
C.Convert the query to use legacy SQL
D.Export the data to Cloud Storage and query with an external table
E.Increase the number of BigQuery slots assigned to the project
AnswersB, E

Partitioning on the timestamp column lets BigQuery prune irrelevant partitions, scanning only the hour's data rather than the full table. This directly cuts the bytes read, which is the dominant cost driver for a terabyte-scale batch job, helping the query finish inside the 30-minute window.

Why this answer

Option B is correct because partitioning the table on the timestamp column lets BigQuery prune irrelevant partitions, so each hourly run scans only the data for the relevant time range instead of the full multi-terabyte table, dramatically reducing bytes processed and execution time. Option E is correct because increasing the number of BigQuery slots allocated to the project provides more compute capacity (slots) for the query, allowing BigQuery to parallelize the work across more workers and finish the batch job faster. Option A is not reliable here because cached results are invalidated whenever the underlying tables change, and an hourly job over freshly arriving data will almost never hit a valid cache.

Option C is wrong because legacy SQL is a deprecated dialect with no performance advantage over GoogleSQL. Option D is wrong because querying data in Cloud Storage via an external table typically performs worse than querying native BigQuery storage, since it lacks BigQuery's columnar storage and optimization.

510
MCQmedium

Your team has deployed a microservices application on Google Kubernetes Engine (GKE) with multiple services communicating via internal ClusterIP services. You notice that some requests between services are failing intermittently with 'connection refused' errors. The services are defined with readiness probes. What is the most likely cause?

A.The readiness probes are not passing, causing the service endpoints to be removed.
B.The services are not exposed via a VPC peering connection to the client's VPC.
C.The services are using NodePort instead of LoadBalancer type, causing port conflicts.
D.The services are not associated with an Ingress resource.
AnswerA

Failing readiness probes cause the pod to be removed from service endpoints, leading to connection refused.

Why this answer

The 'connection refused' error indicates that the client is attempting to connect to a port on which no process is listening. In GKE, when a readiness probe fails, Kubernetes removes the pod's IP from the corresponding ClusterIP service's endpoints. If all pods for a service fail their readiness probes, the service has no healthy endpoints, and any request to the ClusterIP will be refused because there is no backend to accept the connection.

This matches the intermittent nature of the issue, as pods may temporarily fail the probe and then recover.

Exam trap

Google Cloud often tests the distinction between readiness and liveness probes, where candidates may incorrectly assume that a failing liveness probe (which restarts the pod) is the cause of 'connection refused', but the key is that readiness probes control endpoint membership, directly causing the error when all endpoints are removed.

How to eliminate wrong answers

Option B is wrong because VPC peering is used for connectivity between separate VPC networks, not for internal service-to-service communication within the same GKE cluster; ClusterIP services are inherently reachable within the cluster without any peering. Option C is wrong because NodePort and LoadBalancer are service types for external exposure, not for internal pod-to-pod communication; port conflicts are not a typical cause of 'connection refused' errors within a cluster, and NodePort does not affect internal ClusterIP functionality. Option D is wrong because an Ingress resource is used for external HTTP/S traffic routing to services, not for internal service-to-service communication; the absence of an Ingress has no impact on direct ClusterIP-based communication between microservices.

511
MCQmedium

A startup is developing a real-time analytics dashboard that ingests data from IoT devices. The data volume is unpredictable but can spike to millions of events per second. The dashboard must display near real-time aggregations with sub-second latency. Which Google Cloud architecture should the architect recommend?

A.Ingest via Cloud IoT Core directly to Cloud Bigtable, then query with BigQuery.
B.Ingest via Cloud Pub/Sub, process with Cloud Dataproc, store in Cloud Storage, and query with BigQuery.
C.Ingest via Cloud Pub/Sub, store raw data in Cloud Storage, and use Cloud SQL for aggregations.
D.Ingest via Cloud Pub/Sub, process with Cloud Dataflow, store in Cloud Bigtable, and query from the dashboard.
AnswerD

Cloud Pub/Sub absorbs unpredictable spikes to millions of events per second without backpressure, while Dataflow provides streaming windowed aggregations. Bigtable's row-key design delivers the low-latency point and range reads the dashboard needs, satisfying the sub-second latency constraint that batch warehouses such as BigQuery cannot meet for continuous refreshes.

Why this answer

Cloud Pub/Sub provides scalable, asynchronous ingestion for unpredictable IoT data spikes, Cloud Dataflow enables stream processing for near real-time aggregations with sub-second latency, and Cloud Bigtable offers low-latency, high-throughput storage ideal for serving aggregated results directly to a dashboard. This combination meets the requirements of unpredictable volume, real-time processing, and low-latency queries.

Exam trap

The trap here is that candidates often choose batch-oriented services like BigQuery or Dataproc for real-time requirements, overlooking that Cloud Dataflow's stream processing and Cloud Bigtable's low-latency storage are specifically designed for sub-second, high-throughput dashboard use cases.

How to eliminate wrong answers

Option A is wrong because Cloud IoT Core directly to Cloud Bigtable lacks a buffering layer for unpredictable spikes, and BigQuery is not designed for sub-second query latency on real-time dashboards. Option B is wrong because Cloud Dataproc is batch-oriented and introduces higher latency for stream processing, and Cloud Storage with BigQuery adds significant query latency unsuitable for sub-second dashboard responses. Option C is wrong because Cloud SQL cannot handle millions of events per second for real-time aggregations and lacks native stream processing capabilities.

512
MCQeasy

A company wants to automate the deployment of their infrastructure on Google Cloud using a declarative approach. They need to manage resources such as VPCs, subnets, and Compute Engine instances in a repeatable and version-controlled manner. They also want to preview changes before applying them. Which tool should they use?

A.Ansible with the Google Cloud collection
B.Google Cloud Deployment Manager
C.Google Cloud Console and gcloud CLI scripts
D.Terraform with the Google Cloud provider
AnswerD

Terraform is a declarative infrastructure as code tool that supports version control and provides a 'terraform plan' command to preview changes before applying. The Google Cloud provider allows management of all GCP resources. This meets the requirements for repeatability, version control, and change preview.

Why this answer

Terraform is the industry-standard declarative infrastructure as code tool that supports version control and provides a plan phase to preview changes. The Google Cloud provider enables management of all relevant resources, ensuring repeatability and safety.

Exam trap

The trap here is assuming that Deployment Manager is the only Google-native option and that it provides preview capabilities; actually, Terraform is more widely used and supports preview via plan.

513
MCQhard

An enterprise is migrating a latency-sensitive trading application from an on-premises data centre to Google Cloud. The application's components exchange hundreds of thousands of small messages per second and require sub-millisecond inter-process communication. The architect must choose a compute and networking design. What should the architect recommend?

A.Deploy the components on GKE Autopilot pods spread across three zones with a PodDisruptionBudget and topology spread constraints.
B.Deploy the components on Cloud Run services in the same region and connect them through a Serverless VPC Access connector to a shared VPC.
C.Deploy the components on Compute Engine VMs in the same zone with compact placement, and enable high-priority network traffic using the `--network-performance-configs` total-egress-bandwidth-tier setting.
D.Deploy the components on Compute Engine VMs in different zones of the same region and connect them with a global VPC using external IP addresses for direct communication.
AnswerC

Compact placement policies pack instances onto the same rack and physical network segment, which minimizes network hops between them and supports the low-latency, high-message-rate requirement. Setting the total egress bandwidth tier to the higher tier raises the VM network throughput ceiling so the small-message flood is not throttled. Keeping everything in one zone eliminates inter-zone round trips, making this the appropriate design for tightly coupled latency-sensitive components.

Why this answer

Ultra-low latency between tightly coupled components depends on physical proximity and adequate network throughput. Compact placement policies schedule instances close together on the same rack, reducing switch hops and jitter, while the higher total egress bandwidth tier removes the default throughput cap that would otherwise throttle a heavy small-message workload. Keeping all components in a single zone avoids inter-zone round trips entirely, which is essential for the stated sub-millisecond requirement.

Exam trap

The trap here is optimizing for availability with multi-zone spread when the workload's dominant constraint is deterministic, sub-millisecond latency between components.

514
MCQmedium

Your organization runs a production Cloud SQL for PostgreSQL instance. You need to ensure that if the primary zone fails, the database automatically fails over to a standby with no data loss. Which configuration should you use?

A.Enable point-in-time recovery (PITR)
B.Configure a cross-region replica
C.Deploy a regional Cloud SQL instance with high availability
D.Create a read replica and promote it on failure
AnswerC

A regional Cloud SQL instance with high availability maintains a standby in a separate zone and performs automatic failover with synchronous replication, ensuring no data loss when the primary zone fails. Zonal instances lack this standby capability.

Why this answer

A regional Cloud SQL instance with high availability provisions a standby in a different zone within the same region and performs automatic failover via a regional persistent disk, with synchronous replication ensuring zero data loss (RPO ≈ 0). This is the only option that combines automatic failover with no data loss for a single-region production database.

Exam trap

PCA often tests the distinction between HA (automatic, synchronous, zero data loss, same region) and replicas/PITR (asynchronous or manual, potential data loss), so candidates who pick 'read replica and promote' or 'PITR' for failover fall into the trap.

How to eliminate wrong answers

Option A is wrong because point-in-time recovery only lets you restore to an earlier timestamp after the fact; it does not provide automatic failover and typically incurs data loss up to the last recoverable point. Option B is wrong because a cross-region replica is asynchronous, so failover would lose recent transactions and it is not an automatic HA mechanism. Option D is wrong because a read replica is asynchronous and promotion is a manual, lossy operation, not automatic failover.

515
MCQeasy

You are designing a solution to store and serve static web content for a global audience. The content consists of HTML, CSS, JavaScript, and images. You need to ensure low latency and high availability. Which Google Cloud service should you use?

A.Cloud Storage with a multi-region bucket and Cloud CDN.
B.Compute Engine instances in multiple regions behind a global load balancer.
C.Cloud Run services deployed in multiple regions with a global load balancer.
D.App Engine standard environment with a custom domain and Cloud CDN.
AnswerA

Cloud Storage multi-region buckets provide high availability and geo-redundancy, and Cloud CDN caches content at edge locations worldwide, reducing latency. This combination is ideal for serving static web content globally. It requires minimal configuration and scales automatically.

Why this answer

Cloud Storage with a multi-region bucket provides durable, highly available storage, and Cloud CDN caches content globally to reduce latency. This is the simplest and most cost-effective solution for static web content. The other options involve unnecessary compute resources or management overhead.

Exam trap

The trap here is overcomplicating the solution by using compute services when a simple storage and CDN combination suffices.

516
Multi-Selectmedium

A healthcare company runs a regulated patient-portal application on Google Cloud. Auditors require evidence that infrastructure changes are reviewed before they reach production and that production access is limited. The platform team currently applies Terraform changes directly from engineer laptops using personal credentials. Which two practices should the team adopt to satisfy the auditors while keeping delivery efficient? (Choose two.)

Select 2 answers
A.Disable Cloud Audit Logs for Terraform-related API calls to reduce log volume and cost.
B.Grant all platform engineers the Project Editor role so they can resolve production incidents quickly without approval delays.
C.Store Terraform state in a Cloud Storage bucket with versioning and Object Versioning enabled, and grant write access only to the CI/CD service account.
D.Use Cloud Build triggers on pull requests to run terraform plan, require peer review, and apply only from an approved branch using a dedicated service account.
E.Run terraform apply from each engineer's laptop but require them to commit the plan output to Git afterward.
AnswersC, D

Centralizing state in a versioned Cloud Storage bucket with restricted write access prevents engineers from mutating production state locally and creates an auditable history of state changes. This supports the review requirement because all applies flow through a controlled service account, and versioning provides recoverability and evidence for auditors.

Why this answer

Auditors want a controlled, reviewable path to production and a clear record of who deployed what. Running plan in CI on pull requests with mandatory peer review, then applying from an approved branch with a dedicated service account, creates that path. Backing it with a locked-down, versioned remote state bucket prevents out-of-band changes and preserves history.

Together these practices keep delivery automated while producing the evidence and access controls the auditors require.

Exam trap

The trap here is equating documentation with control, assuming that committing plans after a local apply provides the same assurance as enforcing review and apply through a pipeline.

517
MCQmedium

Your company runs a stateful application on GKE that stores data in persistent volumes backed by Compute Engine persistent disks. You need to back up the application data and the Kubernetes resource configurations (deployments, services, etc.) for disaster recovery. Which tool should you use?

A.Velero
B.gcloud container clusters create --async
C.Cloud SQL for MySQL
D.Cloud Storage with object versioning and lifecycle policies
AnswerA

Velero backs up both Kubernetes resource configurations and persistent volume data, integrating with Compute Engine persistent disk snapshots. That combination satisfies the disaster recovery requirement to restore deployments, services and application data together on GKE.

Why this answer

Velero is the standard open-source tool for backing up and restoring Kubernetes cluster resources and persistent volumes. It can snapshot Compute Engine persistent disks and also back up Kubernetes objects like deployments and services, which matches the requirement to protect both application data and resource configurations.

Exam trap

PCA often tests the misconception that generic storage versioning or database backups cover Kubernetes disaster recovery, when the exam expects a Kubernetes-aware tool like Velero for both resources and persistent volumes.

How to eliminate wrong answers

Option B is wrong because gcloud container clusters create --async creates a new cluster asynchronously and has nothing to do with backup or disaster recovery. Option C is wrong because Cloud SQL for MySQL is a managed relational database service and cannot back up GKE persistent volumes or Kubernetes manifests. Option D is wrong because Cloud Storage with object versioning and lifecycle policies stores objects but does not natively back up Kubernetes resources or persistent disk snapshots in a restorable, cluster-aware way.

518
MCQmedium

A healthcare analytics company ingests continuous streams of device telemetry that must be processed in near real time, enriched with reference data from a Cloud SQL for MySQL instance, and written into BigQuery for analyst queries. The team wants minimal operational overhead and wants to use managed Google Cloud services. Which combination should the architect select?

A.Cloud Tasks for ingestion, Cloud Functions for processing, Cloud SQL for storage and analytics
B.Pub/Sub for ingestion, Dataflow for stream processing and enrichment, BigQuery for storage and analytics
C.Pub/Sub for ingestion, Dataproc with Spark Streaming for processing, Cloud Storage for storage and analytics
D.Pub/Sub for ingestion, Dataflow for stream processing, Bigtable for storage and analytics
AnswerB

Pub/Sub durably buffers the telemetry stream and decouples producers from consumers. Dataflow provides managed, autoscaling stream processing with exactly-once semantics and can join against Cloud SQL reference data. BigQuery ingests the processed records and serves analyst queries at scale. This pipeline is fully managed, matching the low operational overhead goal and the near real-time requirement.

Why this answer

The pipeline needs durable stream ingestion, managed stream processing with enrichment, and a warehouse for analyst SQL. Pub/Sub absorbs bursts and decouples producers, Dataflow handles autoscaling stream transforms and joins, and BigQuery stores and queries the results. Alternatives either require cluster management, cannot run analytics at scale, or use services not intended for continuous streaming.

Exam trap

The trap here is pairing a correct streaming ingestion service with a storage service that cannot serve analytical SQL queries.

519
MCQhard

A healthcare company runs a multi-tenant SaaS platform on Google Cloud. Each tenant has a dedicated folder inside a single organization, with projects for each environment. A recent audit found that a compromised service account in one tenant's dev project could enumerate and read Cloud Storage buckets belonging to other tenants because the service account had been granted roles/storage.admin at the organization level by mistake. The security team wants a preventive control that blocks any future IAM binding that grants a role to a principal at a scope broader than a single project, unless the principal is part of a small break-glass group. They also want the control to apply automatically to all new projects. What should the architect implement?

A.Create an organization policy with the iam.allowedPolicyMemberDomains constraint set to the company's Cloud Identity domain, and apply it to the organization node.
B.Enable IAM Conditions on all role bindings and require a condition that the resource name matches the tenant's folder path.
C.Create an organization policy with the iam.disablePolicyMemberDomainCheck constraint and apply it to the organization node.
D.Configure an organization policy using a custom constraint on the iam.googleapis.com/AllowPolicy resource, denying bindings where the resource scope is the organization or a folder unless the principal is in the break-glass group.
AnswerD

Custom organization policy constraints can evaluate IAM allow policies and deny bindings based on the resource hierarchy level and the principal. By scoping the constraint to the organization node it is inherited by all current and future projects and folders, blocking the exact misconfiguration that allowed the compromised service account to reach other tenants' buckets while permitting the break-glass group.

Why this answer

The requirement is a preventive, hierarchy-wide guardrail against overly broad IAM grants. Custom organization policy constraints on the IAM allow policy resource can inspect both the binding's scope and the principal, so a rule that denies organization- and folder-level grants except for a designated break-glass group enforces least privilege automatically for existing and new projects. Domain-based and condition-based approaches either do not address scope breadth or rely on per-binding correctness, so they would not have prevented the audit finding.

Exam trap

The trap here is assuming that iam.allowedPolicyMemberDomains or IAM Conditions provide preventive scope guardrails, when domain constraints only limit identity domains and conditions must be attached correctly to every binding.

520
Multi-Selectmedium

A company wants to implement a disaster recovery (DR) strategy for their Cloud SQL for MySQL databases. They need to be able to recover to a specific point in time (within seconds) in case of accidental data deletion. Which TWO actions should they take? (Choose TWO.)

Select 2 answers
A.Enable binary logging (binlog)
B.Configure a failover replica in another zone
C.Create a cross-region read replica
D.Enable automated backups
E.Export the database daily to Cloud Storage
AnswersA, D

Binary logging captures every committed transaction, enabling Cloud SQL point-in-time recovery to a chosen timestamp within seconds of accidental deletion. This satisfies the seconds-level recovery objective, which automated backups alone cannot meet because they restore only to fixed snapshot times.

Why this answer

Option A is correct because Cloud SQL for MySQL point-in-time recovery (PITR) relies on binary logging (binlog) to capture all data changes, allowing recovery to a specific moment within seconds. Option D is correct because automated backups provide the base backup that, combined with binlog, enables PITR; without automated backups enabled, PITR cannot function. Option B is incorrect because a failover replica provides high availability within a region, not point-in-time recovery from accidental deletion.

Option C is incorrect because a cross-region read replica is for read scaling and regional DR, not for recovering to a specific point in time. Option E is incorrect because daily exports to Cloud Storage are manual/periodic snapshots and cannot achieve second-level point-in-time recovery.

Exam trap

PCA often tests the confusion between high availability (failover replicas) and point-in-time recovery, tricking candidates into selecting HA features that replicate — rather than protect against — accidental data deletion.

521
MCQhard

Your company uses Cloud Spanner in a multi-region configuration to achieve 99.999% availability. You need to understand the impact of a regional failure on read and write availability. Which statement is correct?

A.Both reads and writes are fully available as long as at least one region remains healthy
B.Reads and writes remain fully available because Cloud Spanner uses synchronous replication across all regions
C.Writes are unavailable if the region containing the leader replica fails, but reads remain available
D.Writes are always available, but reads may be unavailable if the region with the closest replica fails
AnswerC

Cloud Spanner's leader replica handles all writes, so a regional failure affecting that leader halts writes until a new leader is elected. Reads, however, are served by any replica, so they continue from surviving regions, satisfying the stem's read-versus-write availability distinction.

Why this answer

Cloud Spanner multi-region configurations use a leader replica in one region and read-only replicas in others. Writes must go through the leader (Paxos quorum), so if the region hosting the leader fails, writes are unavailable until a new leader is elected — typically within seconds to minutes depending on the config. Reads, however, can be served from any healthy replica (strong or stale reads), so read availability is preserved as long as at least one replica region survives.

Exam trap

PCA often tests the misconception that synchronous replication equals write availability everywhere — candidates forget that only the leader accepts writes and pick 'both reads and writes fully available'.

How to eliminate wrong answers

Option A is wrong because it claims writes remain fully available during any single-region failure, ignoring the leader-election dependency — writes stall during leader failover. Option B is wrong because synchronous replication does not mean every region can accept writes; only the leader does, and synchronous replication is precisely why writes pause during leader failover. Option D is wrong because it inverts the model: reads are the more available operation (any replica can serve them), while writes are the constrained operation tied to the leader.

522
Multi-Selectmedium

A retail company runs its order-processing system on Google Kubernetes Engine (GKE). The operations team wants to improve the reliability and cost efficiency of the cluster. They observe that several workloads have no resource requests or limits set, and some nodes are consistently underutilised while others are overcommitted. Which two actions should the architect recommend to address these issues? (Choose two.)

Select 2 answers
A.Disable the horizontal pod autoscaler to avoid fluctuating replica counts.
B.Migrate all workloads to a single, larger node pool with no autoscaling.
C.Configure resource requests and limits for all pods based on observed usage.
D.Enable the cluster autoscaler on all node pools with appropriate minimum and maximum sizes.
E.Set the pod disruption budget for all deployments to zero.
AnswersC, D

Setting requests and limits gives the scheduler accurate information to place pods and prevents noisy-neighbour problems. It also enables the cluster autoscaler to make better scaling decisions and allows vertical pod autoscaling to right-size workloads. Without them, the scheduler cannot bin-pack efficiently, leading to the underutilisation and overcommitment described.

Why this answer

The core problems are inaccurate resource signalling and static node capacity. Defining requests and limits lets the scheduler place pods correctly and enables autoscaling features to work effectively. Enabling the cluster autoscaler then adjusts node pool size to match actual demand, adding capacity when pods are pending and removing idle nodes.

Together they improve reliability during peaks and reduce cost during low usage.

Exam trap

The trap here is thinking that simply adding more nodes or disabling autoscalers will fix utilisation, when the underlying issue is that pods lack the resource requests the scheduler needs.

523
Multi-Selecthard

A financial services company runs a latency-sensitive trading application on Compute Engine. The operations team needs to detect performance regressions and correlate them with recent deployments without instrumenting application code. They want to use Cloud Monitoring and Cloud Logging features that work automatically for Compute Engine VMs. (Choose two.)

Select 2 answers
A.Install the Cloud Profiler agent on each VM to capture CPU and memory profiles of the application.
B.Create log-based metrics in Cloud Logging from VM logs and chart them alongside metrics in Cloud Monitoring dashboards.
C.Enable Data Access audit logs for Compute Engine and analyze them to identify slow API calls.
D.Use the Ops Agent to collect host metrics such as CPU, memory, and disk I/O, and to send application logs to Cloud Logging.
E.Enable Cloud Trace auto-instrumentation by setting the GOOGLE_CLOUD_TRACE environment variable on each VM.
AnswersB, D

Log-based metrics turn log entries into time-series data that Cloud Monitoring can chart and alert on. Combined with the Ops Agent's log collection, this lets the team correlate application log patterns with performance metrics over time without modifying application code, which directly supports detecting regressions relative to deployments.

Why this answer

The Ops Agent provides automatic host metrics and log collection for Compute Engine, and log-based metrics let those logs be charted and alerted in Cloud Monitoring. Together they deliver the telemetry to detect performance regressions and correlate them with deployments without touching application code. Tracing, profiling, and audit logs either require code changes or capture different data than runtime performance.

Exam trap

The trap here is assuming that enabling tracing or profiling is automatic on Compute Engine, when those require application-level instrumentation and do not satisfy the no-code-change constraint.

524
Multi-Selecthard

A finance company needs to ensure that all compute instances in their VPC can only communicate with Google APIs (e.g., Cloud Storage) over internal IPs. Additionally, instances without external IPs should be able to access the internet for updates. Which TWO configurations should they implement?

Select 2 answers
A.Configure Cloud NAT
B.Create a firewall rule allowing egress to 0.0.0.0/0
C.Enable Private Google Access on the subnet
D.Assign external IPs to all instances
E.Use VPC peering with Google's public network
AnswersA, C

Cloud NAT lets instances lacking external IPs reach the internet for updates, satisfying that requirement without exposing them publicly. It complements Private Google Access, which handles the internal-IP path to Google APIs; NAT alone cannot provide that private API connectivity.

Why this answer

Option A (Configure Cloud NAT) is correct because Cloud NAT lets instances that have no external IP addresses initiate outbound connections to the internet for updates, while keeping them unreachable from inbound internet traffic. Option C (Enable Private Google Access on the subnet) is correct because it allows instances without external IPs to reach Google APIs and services such as Cloud Storage using internal IP addresses rather than public ones. Together these two settings satisfy both requirements: private access to Google APIs and outbound internet access without external IPs.

Option B is not needed because a firewall egress rule to 0.0.0.0/0 only permits traffic and does not by itself provide NAT or a route to the internet for instances lacking external IPs. Option D is wrong because assigning external IPs contradicts the goal of using internal IPs for Google API access and exposes instances to the internet. Option E is wrong because VPC peering connects VPC networks to each other and does not provide access to Google's public APIs or general internet connectivity.

Exam trap

PCA often tests the difference between Private Google Access and Cloud NAT, and candidates might think that one alone can handle both Google APIs and internet access, but they serve different purposes.

525
MCQhard

A company requires a globally distributed relational database with strong consistency across regions and automatic replication. They need to support SQL queries and have a write throughput of 100,000 writes per second. Which Google Cloud database meets these requirements?

A.Cloud Spanner
B.Cloud Bigtable
C.BigQuery
D.Cloud SQL with cross-region replication
AnswerA

Cloud Spanner is the only Google Cloud relational database delivering strong global consistency through TrueTime, with horizontal write scaling that handles 100,000 writes per second and automatic multi-region replication, while still supporting standard SQL queries.

Why this answer

Cloud Spanner is a globally distributed, strongly consistent relational database that supports SQL and can scale to millions of writes per second. Cloud SQL is regional, Bigtable is NoSQL and not relational, BigQuery is an analytics warehouse.

Page 6

Page 7 of 11

Page 8

All pages