Courseiva

Google Professional Cloud Architect (PCA) — Questions 526–600

807 questions total · 11pages · All types, answers revealed

Page 7

Page 8 of 11

Page 9
526
MCQmedium

A team wants to deploy a microservice on Cloud Run that needs to access a Cloud Memorystore for Redis instance in the same region. The Redis instance is in a VPC network. Which configuration is required for Cloud Run to reach the Redis instance?

A.Configure a Cloud NAT gateway
B.Create a Serverless VPC Access connector and configure Cloud Run to use it
C.Use Private Google Access
D.Deploy Cloud Run within a VPC
AnswerB

Serverless VPC Access provides a connector that lets Cloud Run send traffic into the specified VPC, reaching the Redis instance's private IP. Without it, Cloud Run egress cannot route to Memorystore, which has no public endpoint.

Why this answer

Cloud Run is serverless and runs outside the customer VPC by default. To reach a Memorystore Redis instance inside a VPC, you must create a Serverless VPC Access connector and attach it to the Cloud Run service, enabling egress to the VPC. This provides private IP connectivity to Redis.

Exam trap

PCA often tests the misconception that Cloud Run can be placed directly in a VPC — candidates pick 'deploy within a VPC' instead of the correct Serverless VPC Access connector.

How to eliminate wrong answers

Option A is wrong because Cloud NAT provides outbound internet access for private instances, not connectivity into a VPC from serverless. Option C is wrong because Private Google Access allows VMs without external IPs to reach Google APIs, not Memorystore Redis. Option D is wrong because Cloud Run cannot be 'deployed within a VPC' in the traditional sense; it uses Serverless VPC Access connectors for VPC egress.

527
MCQmedium

Your organization has a policy that all Compute Engine instances must have specific labels (env, team, cost-center) applied. You want to enforce this automatically when instances are created. What should you do?

A.Enable Cloud Audit Logs and set up a metric-based alert to detect instances without labels.
B.Create a Cloud Function that listens for instance creation events and adds labels automatically.
C.Assign a custom IAM role that includes permission to label instances, and remove the default compute.instances.create permission.
D.Use the Organization Policy service with a custom constraint to require labels on Compute Engine instances.
AnswerD

Organization Policy custom constraints let you define and enforce label requirements across the project hierarchy, blocking non-compliant instance creation at the API level. This satisfies the policy's demand for automatic enforcement at creation time, rather than relying on manual labelling or post-hoc auditing.

Why this answer

Organization Policy Service with a custom constraint allows you to enforce that all Compute Engine instances must have specific labels (env, team, cost-center) at creation time. This is a preventive control that blocks creation of non-compliant instances, unlike reactive or permission-based approaches. Custom constraints use the `compute.googleapis.com/instance` resource type and can require label keys or values using CEL (Common Expression Language) syntax.

Exam trap

The trap here is that candidates often choose reactive solutions (like Cloud Functions or alerts) because they seem simpler, but the exam emphasizes preventive enforcement using Organization Policy constraints for compliance-driven requirements.

How to eliminate wrong answers

Option A is wrong because Cloud Audit Logs and metric-based alerts are reactive — they only detect non-compliant instances after creation, not prevent them, and do not enforce the policy automatically. Option B is wrong because a Cloud Function that listens for instance creation events and adds labels is also reactive; it can fail or be bypassed, and the instance is created without labels initially, violating the policy. Option C is wrong because removing the default `compute.instances.create` permission would prevent all instance creation, not just unlabeled ones, and a custom IAM role cannot enforce label requirements at creation time — it only controls who can create instances, not what labels they must include.

528
MCQmedium

A company runs a three-tier web application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier on TCP port 8080. The company wants to enforce these requirements at the network level with minimal administrative overhead and without relying on instance-level firewall software. What should they do?

A.Create a VPC firewall rule that allows TCP port 8080 from the web tier's network tag to the application tier's network tag, and another rule that allows the database port from the application tier's network tag to the database tier's network tag.
B.Place the database tier in a separate VPC and use VPC Network Peering to connect it to the application tier's VPC, then allow all traffic between the peered networks.
C.Configure each instance with iptables rules that permit only the required traffic, and disable VPC firewall rules for the project.
D.Create a single VPC firewall rule that allows all TCP traffic between all instances in the VPC, and rely on the application code to restrict access.
AnswerA

VPC firewall rules use source and target tags to scope traffic to specific instances. Allowing TCP 8080 from the web tier tag to the application tier tag enforces the web-to-app path, and allowing the database port from the app tier tag to the database tier tag enforces the app-to-database path. This meets the requirement at the network level without instance-level software.

Why this answer

Tag-based VPC firewall rules are the standard way to enforce tier-to-tier access on Compute Engine. By allowing only TCP 8080 from the web tier tag to the application tier tag, and only the database port from the application tier tag to the database tier tag, the company implements least-privilege network segmentation centrally. This avoids instance-level firewall software and keeps administration simple.

Exam trap

The trap here is assuming that creating separate VPCs or subnets automatically restricts traffic between tiers, when in fact firewall rules must explicitly allow the required flows.

529
MCQmedium

An enterprise is planning to migrate 200 on-premises VMs to Google Cloud. The CIO wants to ensure that the migration aligns with the business goal of reducing IT operational overhead by 30% while maintaining application performance. The team has already completed a technical assessment of the VMs. Which additional step should the cloud architect take to ensure the migration plan is aligned with the stated business goal?

A.Conduct a business impact analysis to map each application to business processes and identify criticality and dependencies.
B.Perform a detailed network latency test between on-premises and Google Cloud to determine the best interconnect option.
C.Develop a detailed total cost of ownership (TCO) model comparing on-premises and Google Cloud costs for all 200 VMs.
D.Create a proof of concept for migrating a single non-critical VM to validate the migration process.
AnswerA

A business impact analysis (BIA) links applications to business processes, revealing criticality, dependencies, and potential operational overhead. This helps prioritize migrations and identify opportunities to reduce overhead, such as retiring redundant applications or consolidating. It ensures the migration plan supports the business goal, not just technical feasibility. Without BIA, the plan may miss cost-saving and risk-reduction opportunities.

Why this answer

The business goal is to reduce IT operational overhead by 30% while maintaining performance. A business impact analysis (BIA) identifies which applications are critical, their dependencies, and how they support business processes. This allows the architect to prioritize migrations, retire redundant systems, and consolidate workloads, directly contributing to overhead reduction.

Technical assessments alone do not ensure business alignment.

Exam trap

The trap here is assuming that technical validation or cost modeling alone satisfies business alignment, when the goal specifically requires understanding application criticality and dependencies to reduce operational overhead.

530
Multi-Selecthard

A healthcare analytics company runs a stateless API on a regional managed instance group behind an external Application Load Balancer. The SRE team wants to improve reliability and reduce customer-visible errors during zonal and instance failures. (Choose two.)

Select 2 answers
A.Set the load balancer's balancing mode to RATE and configure a maximum rate per instance to cap traffic.
B.Configure the load balancer's backend service with a health check that matches the API's readiness endpoint and set a sensible unhealthy threshold.
C.Enable autoscaling on the managed instance group based on CPU utilization and load balancing capacity.
D.Create a second managed instance group in a different region and add it as a backend to the same load balancer.
E.Enable Cloud CDN on the backend service to cache API responses and reduce origin load.
AnswersB, C

An accurate health check lets the load balancer stop sending traffic to instances that cannot serve requests, so users are routed only to healthy backends. Matching the readiness endpoint ensures the check reflects real application health rather than just port availability. This reduces customer-visible errors during instance failures and is a core reliability practice for load-balanced stateless services.

Why this answer

Autoscaling lets the regional managed instance group add or maintain capacity so healthy instances in surviving zones can handle traffic when one zone or instance fails. A health check aligned to the API's readiness endpoint ensures the load balancer routes only to instances that can actually serve requests, cutting customer-visible errors. Together they address zonal and instance failure reliability.

Exam trap

The trap here is reaching for regional expansion or caching when the stated failure domain is zonal and instance-level, where autoscaling and accurate health checking are the targeted fixes.

531
MCQeasy

You need to automatically roll back a GKE deployment if a new version causes a spike in 5xx errors. The deployment uses a canary strategy with Istio traffic splitting. What should you do?

A.Use Cloud Monitoring to watch the canary's error rate and trigger a Cloud Function that updates the Istio VirtualService to route all traffic back to the stable version.
B.Set the canary's traffic weight to 0 in the Istio VirtualService if errors exceed threshold using a Kubernetes Job.
C.Use GKE's built-in auto-repair feature to replace unhealthy pods.
D.Configure an Istio VirtualService with a retry policy that automatically redirects traffic on errors.
AnswerA

Cloud Monitoring detects the canary's elevated 5xx rate, and the triggered Cloud Function rewrites the Istio VirtualService weights, shifting all traffic back to the stable version. This satisfies the automatic rollback requirement without redeploying, since Istio controls routing independently of the GKE workload.

Why this answer

The correct pattern is to monitor the canary's error rate with Cloud Monitoring (using Istio's telemetry metrics like istio_requests_total filtered by response_code=5xx and destination_version=canary), then use an alerting policy to trigger a Cloud Function (or Cloud Run) that patches the Istio VirtualService to shift 100% of traffic back to the stable version. This closes the loop between observability and traffic control, which is exactly what automated canary rollback requires.

Exam trap

PCA often tests the misconception that Kubernetes auto-repair or Istio retries provide application-level rollback — candidates pick them because they sound like resilience features, but neither changes traffic routing based on error rates.

How to eliminate wrong answers

Option B is wrong because a Kubernetes Job is not event-driven — it runs to completion and cannot react to a live error-rate spike without an external trigger, so it cannot perform timely rollback. Option C is wrong because GKE auto-repair only restarts/replaces pods that fail health checks; it does not detect application-level 5xx spikes or change traffic routing, so a canary returning 500s while passing liveness probes would never be rolled back. Option D is wrong because Istio retry policies retry failed requests to the same destination; they do not redirect traffic to a different version and can amplify load during an outage rather than rolling back.

532
Drag & Dropmedium

Drag and drop the steps to set up a shared VPC in Google Cloud for a multi-project environment into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The host project holds the VPC network. Service projects use the subnets. IAM roles control who can use the subnets.

533
MCQmedium

Refer to the exhibit. An application running on a GCE instance (ID: 1234567890) is unable to connect to a database at 10.0.0.1:5432. The logs show repeated 'Connection refused' errors. What is the most likely cause?

A.The firewall rule allowing traffic on port 5432 is missing or misconfigured.
B.The instance is using an outdated SSL certificate.
C.The database service is not running or is not listening on port 5432.
D.The VPC network has no route to the database subnet.
AnswerC

A refused TCP connection means the host is reachable but nothing accepts traffic on port 5432, indicating the database process is stopped or bound elsewhere. Firewall or routing problems would typically produce timeouts, not refusals.

Why this answer

The 'Connection refused' error indicates that the TCP handshake was rejected by the target host, which typically means the database service is not actively listening on port 5432. This is distinct from a firewall block, which would result in a timeout or 'no route to host' error. Since the error is immediate and specific to port 5432, the most likely cause is that the PostgreSQL or other database service is not running or is bound to a different interface/port.

Exam trap

Google PCA exams often test the distinction between firewall blocks (timeout) and service unavailability (connection refused), so the trap here is that candidates confuse a missing firewall rule with a service not listening, even though the error messages are fundamentally different.

How to eliminate wrong answers

Option A is wrong because a missing or misconfigured firewall rule would cause a timeout or 'connection timed out' error, not an immediate 'Connection refused' — the latter requires the host to actively reject the connection. Option B is wrong because SSL certificate issues would manifest as TLS handshake failures or certificate validation errors, not a raw TCP-level 'Connection refused'. Option D is wrong because if there were no route to the database subnet, the error would be 'No route to host' or a network unreachable message, not a port-specific refusal.

534
MCQeasy

A company is migrating to Google Cloud and needs to connect their on-premises network to a VPC. They require high bandwidth and a reliable connection with a Service Level Agreement (SLA). Which solution should they choose?

A.Cloud VPN with dynamic routing
B.Dedicated Interconnect
C.Partner Interconnect via a service provider
D.Direct Peering
AnswerB

Dedicated Interconnect offers high bandwidth and an SLA.

Why this answer

Dedicated Interconnect provides a direct, private physical connection between your on-premises network and Google's network, offering high bandwidth (10 or 100 Gbps per link) and a 99.99% uptime SLA when configured with redundant links. This meets the requirements for high bandwidth and a reliable, SLA-backed connection better than any other option.

Exam trap

The trap here is that candidates often confuse Partner Interconnect with Dedicated Interconnect, assuming any 'Interconnect' offers an SLA, but only Dedicated Interconnect provides a direct physical link with a 99.99% SLA, while Partner Interconnect's SLA depends on the partner's network and is typically lower.

How to eliminate wrong answers

Option A is wrong because Cloud VPN uses the public internet with IPsec tunnels, offering no SLA and limited bandwidth (typically up to 3 Gbps per tunnel), making it unsuitable for high-bandwidth, SLA-backed requirements. Option C is wrong because Partner Interconnect relies on a third-party service provider's network, which may introduce additional latency and does not provide the same direct, dedicated SLA as Dedicated Interconnect; it is designed for cases where a direct physical connection is not feasible. Option D is wrong because Direct Peering is a non-SLA, best-effort connection established via public exchange points, intended for traffic exchange with Google services, not for dedicated, SLA-backed connectivity to a VPC.

535
Multi-Selecthard

A healthcare organization is designing a Google Cloud environment to comply with HIPAA. They need to ensure that all access to sensitive data is logged and that only authorized personnel can access it. They plan to use Cloud Audit Logs and IAM. Which two configurations should they implement? (Choose two.)

Select 2 answers
A.Set the organization policy constraint `iam.disableServiceAccountKeyCreation` to prevent key leakage.
B.Enable Data Access audit logs for all services that store or process ePHI.
C.Enable VPC Service Controls to create a service perimeter around the project containing ePHI.
D.Use IAM Conditions to restrict access to sensitive data based on IP address and device type.
E.Grant the `roles/iam.securityReviewer` role to all employees who need to view audit logs.
AnswersB, D

Data Access audit logs record read and write operations on user data, which is essential for HIPAA compliance to track who accessed ePHI. By default, these logs are disabled for most services, so explicitly enabling them for services like Cloud Storage, BigQuery, and Cloud SQL ensures a complete audit trail. This helps detect unauthorized access and supports forensic investigations, meeting the logging requirement.

Why this answer

Enabling Data Access audit logs ensures that all access to ePHI is recorded, which is a HIPAA requirement. Using IAM Conditions restricts access based on context, ensuring only authorized personnel from trusted environments can access data. Together, these provide both logging and access control.

The other options either over-provision access or address different security concerns not directly tied to the stated needs.

Exam trap

The trap here is assuming that enabling any audit logs by default is sufficient, or that broad roles like securityReviewer are acceptable for compliance.

536
Matchingmedium

Match each GCP storage service to its typical use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Object storage for unstructured data

Managed NFS file server

Block storage for VM instances

NoSQL database for large analytical workloads

Globally distributed relational database

Why these pairings

Cloud Storage is for unstructured object storage, Cloud SQL for relational data, Cloud Bigtable for wide-column NoSQL analytics, and Firestore for document NoSQL apps. Common confusions involve mixing storage types with database services.

537
MCQmedium

A company wants to use Customer-Managed Encryption Keys (CMEK) for data at rest in Cloud Storage, but also needs to ensure that the keys are stored in a hardware security module (HSM) to meet compliance requirements. Which Cloud KMS key type should they choose?

A.Predefined key
B.External key (Cloud External Key Manager)
C.Software-backed key
D.Cloud HSM key
AnswerD

Cloud HSM keys store key material in FIPS 140-2 Level 3 validated hardware security modules, satisfying the compliance requirement for HSM-backed keys. Software and Cloud KMS keys hold material in software, so they fail that constraint. CMEK for Cloud Storage accepts Cloud HSM keys directly.

Why this answer

Cloud HSM keys in Cloud KMS are backed by a FIPS 140-2 Level 3 validated hardware security module, satisfying compliance requirements that mandate HSM-backed key storage. This is the only Cloud KMS key type that provides hardware-backed protection while remaining fully managed within Google Cloud.

Exam trap

PCA often tests the CMEK key-type hierarchy — candidates confuse Cloud EKM (external, sovereignty-focused) with Cloud HSM (hardware-backed, in-GCP), or pick software keys assuming all KMS keys are equally secure.

How to eliminate wrong answers

Option A is wrong because 'predefined key' is not a Cloud KMS key type — it is a distractor term; Cloud KMS offers software, HSM, and external key types. Option B is wrong because Cloud External Key Manager (Cloud EKM) stores keys outside Google Cloud in a third-party KMS (e.g., Thales, Fortanix), which is for sovereignty requirements, not for HSM-backed keys within GCP. Option C is wrong because software-backed keys are stored in software and do not meet HSM compliance mandates.

538
MCQeasy

A retail company runs a public-facing API on Cloud Run in the europe-west1 region. During a marketing campaign, traffic tripled within minutes. The service remained available, but some requests returned HTTP 503 errors. The team wants to reduce the chance of 503 errors during future traffic spikes while keeping the deployment simple. What should they do?

A.Set the Cloud Run service's maximum number of instances to a high value and configure a minimum number of instances greater than zero.
B.Increase the container's allocated memory and CPU limits in the Cloud Run revision settings.
C.Enable Cloud CDN on the Cloud Run service and set a long cache TTL for all responses.
D.Deploy the service to multiple Cloud Run regions and use a global external Application Load Balancer with a serverless network endpoint group.
AnswerA

Cloud Run scales out by adding instances, but if the configured maximum instance count is reached, additional requests can be rejected with 503 errors. Raising the maximum allows more instances to handle the spike, and setting a minimum above zero keeps warm instances ready so cold starts do not contribute to failures during the initial surge. This directly addresses the observed 503 behavior under burst load.

Why this answer

The 503 errors occurred because the service hit its configured maximum instance count during the spike. Raising the maximum instance limit lets Cloud Run create enough instances to absorb the burst, and setting a minimum instance count above zero keeps warm instances available so the initial surge does not fail while new instances start. Resource limits, CDN caching, and multi-region deployment do not directly remove the instance ceiling that caused the rejections.

Exam trap

The trap here is assuming that increasing CPU or memory on a Cloud Run service increases its capacity to handle concurrent requests, when the real constraint during a burst is the maximum instance count.

539
MCQmedium

The exhibit shows a Cloud Storage bucket IAM policy. A developer (admin@example.com) wants to upload a file to the bucket but gets a permission denied error. What is the most likely reason?

A.An organization policy denies all write operations
B.The developer is not a member of the project
C.The service account my-sa overrides the developer's permissions
D.The developer is assigned only the objectViewer role
AnswerD

The objectViewer role grants read-only access to objects, so it cannot authorise uploads. Uploading requires storage.objects.create, which objectViewer excludes. The permission denied error therefore stems from the developer lacking a write-capable role such as objectCreator or objectAdmin, matching the stem's upload constraint.

Why this answer

The correct answer is D: the developer is assigned only the objectViewer role. The objectViewer role (roles/storage.objectViewer) grants read-only access to objects, including listing and downloading, but it does not include storage.objects.create, so any upload attempt will fail with a permission denied error. Options A and B are unlikely because an organization policy denying all writes or project non-membership would typically produce broader failures or different errors, and there is no evidence in the scenario.

Option C is incorrect because IAM permissions are additive; a service account's permissions do not override or reduce a user's granted roles, so my-sa cannot strip the developer's access.

540
MCQmedium

The exhibit shows a Cloud Storage bucket configuration. What does this configuration ensure?

A.Older versions of objects are automatically transferred to a different storage class.
B.Data is replicated to another region for disaster recovery.
C.Objects can only be permanently deleted after the retention period expires.
D.Objects older than 30 days will be automatically deleted.
AnswerC

A bucket retention policy with a set retention period locks each object until that period elapses, so deletion requests are refused beforehand. This directly enforces the configuration's guarantee that permanent deletion is possible only once the retention period expires.

Why this answer

The exhibit shows a bucket configured with a retention policy. When a retention policy is set on a Cloud Storage bucket, objects cannot be deleted or overwritten until the retention period expires. This ensures that objects can only be permanently deleted after the retention period ends, which is exactly what option C describes.

Exam trap

The trap here is that candidates confuse retention policies with lifecycle management rules, mistakenly thinking retention policies automatically delete or transition objects, when in fact they only prevent deletion until the retention period expires.

How to eliminate wrong answers

Option A is wrong because retention policies do not automatically transfer objects to a different storage class; that is the function of lifecycle management rules, not retention policies. Option B is wrong because retention policies do not replicate data to another region; replication is configured separately using object replication or dual-region buckets. Option D is wrong because retention policies do not automatically delete objects after a period; they prevent deletion until the retention period expires, and automatic deletion is achieved via lifecycle rules with a Delete action.

541
MCQhard

A financial services firm runs a three-tier application on Google Cloud. The security team requires that all outbound traffic from the application tier to the internet be inspected by a centralised next-generation firewall appliance, and that the application tier have no public IP addresses. The network team wants to minimise changes to the existing VPC. Which design should the architect recommend?

A.Deploy the firewall appliance as a managed instance group in the application VPC and use a custom route with the appliance as the next hop for the default route.
B.Enable Private Google Access on the application subnet and use Private Service Connect for all external destinations.
C.Configure a Cloud NAT gateway on the application subnet and route all egress through it.
D.Create a separate VPC for the firewall appliance and use VPC peering to connect it to the application VPC.
AnswerA

Placing the appliance in the same VPC and overriding the default route to use the appliance as the next hop forces all egress through it for inspection. Instances keep private IPs and no public IPs, and the existing VPC is reused with only route and firewall rule changes, minimising network redesign. This is the standard hub-and-spoke or inline inspection pattern in a single VPC.

Why this answer

Centralised inspection of internet-bound traffic requires the traffic to traverse the firewall appliance. By deploying the appliance in the same VPC and setting a custom default route whose next hop is the appliance, all egress from the application tier is forced through it. Instances remain private, and the existing VPC is preserved.

Cloud NAT, VPC peering, and Private Service Connect do not insert an inspection middlebox into the egress path.

Exam trap

The trap here is confusing network address translation or private connectivity features with traffic inspection, when only an explicit route through the appliance can force egress through a firewall.

542
MCQmedium

A healthcare analytics company must store patient records in Cloud Storage. Compliance requires that the data be encrypted with keys the company generates and rotates itself, and that the company retain the ability to revoke access by disabling the key. The data must remain readable by authorized applications in the same project. What should the architect implement?

A.Customer-supplied encryption keys (CSEK) passed with every object write and read request.
B.Customer-managed encryption keys (CMEK) in Cloud KMS, referenced by the bucket's default encryption configuration.
C.Google-managed encryption keys, relying on Cloud Storage default encryption.
D.Client-side encryption performed by the analytics application before uploading objects to Cloud Storage.
AnswerB

CMEK lets the organization create and rotate keys in Cloud KMS and control their lifecycle, including disabling a key to revoke access. Configuring the bucket's default encryption with a CMEK key ensures new objects are encrypted with that key, and authorized applications in the project can decrypt through IAM permissions on the key.

Why this answer

Customer-managed encryption keys in Cloud KMS give the organization ownership of key material, rotation control, and the ability to disable a key to revoke access. Setting the bucket default encryption to a CMEK key applies that key to newly written objects, and IAM on the key governs which applications can decrypt.

Exam trap

The trap here is confusing customer-supplied keys, where the raw key never reaches Google, with customer-managed keys in Cloud KMS that still support centralized rotation and disablement.

543
MCQhard

Refer to the exhibit. A Cloud Deploy pipeline has a release with two targets: staging and prod. The staging rollout succeeded, but the prod rollout failed with 'MANIFEST_INVALID'. What is the most likely cause of the failure?

A.The manifest for prod contains a syntax error or references a resource that does not exist in the prod cluster.
B.The prod target's applyManifest has a higher replica count than staging, which violates a cluster quota.
C.The prod cluster does not have the necessary permissions to pull the container image.
D.The release was not approved for the prod target.
AnswerA

A manifest that parses cleanly against staging can still fail validation against prod, because MANIFEST_INVALID is raised when the rendered manifest is syntactically malformed or references resources absent from the target cluster. The prod target's differing namespace, CRDs or API versions therefore satisfy the stem's constraint that staging succeeded while prod alone failed.

Why this answer

The 'MANIFEST_INVALID' error in Cloud Deploy indicates that the Kubernetes manifest provided for the prod target is syntactically incorrect or references a resource (e.g., a ConfigMap, Secret, or custom resource definition) that does not exist in the prod cluster. This is a validation failure that occurs before any deployment attempt, so it is not related to runtime issues like permissions or quotas.

Exam trap

A common trap is confusing 'MANIFEST_INVALID' with permission or quota issues, which are separate failure modes in the deployment pipeline.

How to eliminate wrong answers

Option B is wrong because a replica count exceeding a cluster quota would produce a different error, such as 'QUOTA_EXCEEDED' or a resource allocation failure during rollout, not a manifest validation error. Option C is wrong because insufficient permissions to pull a container image would result in an 'ImagePullBackOff' or 'ErrImagePull' error at the pod level, not a manifest validation error during the deploy step. Option D is wrong because a missing approval for the prod target would cause the rollout to be pending or skipped, not to fail with 'MANIFEST_INVALID'; approval gates are checked before the rollout begins.

544
MCQeasy

A developer needs to pass a startup script to a Compute Engine instance during creation. Which method should be used to ensure the script runs on first boot?

A.Use gcloud compute instances create with --metadata=startup-script=...
B.Create a custom image with the script baked in.
C.Use gcloud compute instances add-metadata after creating the instance.
D.Use gcloud compute instances create with --startup-script flag.
AnswerA

The startup-script metadata key is read by the Compute Engine guest agent, which executes its value on first boot. Passing it via --metadata during instance creation satisfies the requirement that the script run at startup.

Why this answer

The `--metadata=startup-script=...` flag on `gcloud compute instances create` passes the script as instance metadata. Compute Engine automatically executes the value of the `startup-script` metadata key on every boot, including the first boot. This is the standard, documented method for providing a startup script at instance creation time.

Exam trap

The trap here is that candidates confuse the nonexistent `--startup-script` flag with the correct `--metadata=startup-script=...` syntax, or assume that adding metadata after creation will trigger the script on the first boot.

How to eliminate wrong answers

Option B is wrong because baking the script into a custom image makes it part of the image itself, not a dynamically assigned startup script; it would run on every boot of instances created from that image, but the question specifically asks for a method to pass the script during creation, not to embed it in the image. Option C is wrong because `gcloud compute instances add-metadata` modifies metadata on an already-running instance; the script would only run on the next boot, not on the first boot (which has already occurred). Option D is wrong because `gcloud compute instances create` does not support a `--startup-script` flag; the correct flag is `--metadata=startup-script=...`.

545
MCQeasy

A small company wants to store sensitive files in Cloud Storage and ensure they are encrypted with a key that they control and rotate automatically every 90 days. They are currently using the default encryption provided by Google Cloud. They need a solution that is easy to manage and does not require manual key rotation. What should they do?

A.Use Cloud HSM to generate a key and handle encryption outside of Cloud Storage.
B.Create a Cloud KMS key ring and key with CMEK, set a rotation period of 90 days, and configure the bucket to use that key.
C.Use Customer-Supplied Encryption Keys (CSEK) and write a script to rotate the key every 90 days.
D.Continue using default encryption as it is automatically rotated by Google.
AnswerB

CMEK with a Cloud KMS key gives the company sole control of the encryption key, and configuring a 90-day rotation period automates rotation without manual intervention. The bucket references that key, replacing Google's default encryption, which offers no customer-controlled rotation.

Why this answer

Customer-Managed Encryption Keys (CMEK) via Cloud KMS allow the company to control the key while leveraging automatic rotation. By creating a key ring and key with a 90-day rotation period, and configuring the Cloud Storage bucket to use that key, the company meets the requirement for automated rotation without manual intervention. This solution is easy to manage and integrates natively with Cloud Storage, avoiding the complexity of external encryption or scripting.

Exam trap

The trap here is that candidates often confuse CMEK (customer-managed, automatic rotation) with CSEK (customer-supplied, manual rotation) or assume default encryption already meets the control requirement, but the question explicitly demands customer-controlled keys with automatic rotation.

How to eliminate wrong answers

Option A is wrong because Cloud HSM generates keys that are managed by the customer but encryption must be handled outside Cloud Storage, adding operational complexity and violating the 'easy to manage' requirement. Option C is wrong because Customer-Supplied Encryption Keys (CSEK) require the customer to supply the key with each API call and write a script for rotation, which is not automatic and contradicts the 'does not require manual key rotation' requirement. Option D is wrong because default encryption uses Google-managed keys, which the customer does not control, failing the requirement that they control the key.

546
MCQmedium

A company deploys a microservices application on Google Kubernetes Engine (GKE). Pods in one deployment are frequently OOMKilled. The team sets memory requests and limits, but pods still crash. What is the most likely remaining cause?

A.CPU requests are too low, causing throttling and eventual crash.
B.The node pool is too small, causing memory pressure on the node.
C.Memory limits are set higher than the node's allocatable memory.
D.The application has a memory leak that eventually exceeds the limit.
AnswerD

Requests and limits only cap consumption; they cannot prevent a leak from growing until the container exceeds its limit and is OOMKilled. Since configuration is already correct, the remaining cause is application-level: unbounded allocation that eventually surpasses the configured memory limit.

Why this answer

OOMKilled errors occur when a container exceeds its memory limit. Setting memory requests and limits prevents unbounded usage, but if the application has a memory leak, it will continue to consume memory until it hits the configured limit, causing the kernel's Out-Of-Memory (OOM) killer to terminate the pod. The fact that pods still crash after setting limits indicates the application itself is the root cause, not resource configuration.

Exam trap

The trap here is that candidates confuse OOMKilled (per-container limit) with node-pressure eviction (node-level memory), or assume that setting requests/limits automatically fixes all memory issues, ignoring application-level bugs like memory leaks.

How to eliminate wrong answers

Option A is wrong because CPU throttling does not cause OOMKilled; CPU limits throttle performance but do not trigger the OOM killer, which is specific to memory exhaustion. Option B is wrong because node-level memory pressure would cause pods to be evicted (not OOMKilled) or the node to become NotReady, but the question states pods are OOMKilled, which is a per-container limit violation, not a node-level issue. Option C is wrong because setting memory limits higher than the node's allocatable memory would prevent the pod from being scheduled (pending state), not cause it to run and then be OOMKilled.

547
MCQhard

A company with multiple projects must ensure that no data can be exfiltrated from a specific project's Cloud Storage buckets to unauthorized locations outside the organization. They also need to allow access only from a corporate VPN IP range. Which configuration meets these requirements?

A.Configure a VPC Service Controls perimeter with an access level restricted to the corporate VPN IP range.
B.Set firewall rules to block all traffic except from the VPN.
C.Use IAM conditions to restrict access based on IP address.
D.Use Cloud Armor with IP whitelisting.
AnswerA

VPC Service Controls perimeters block data exfiltration from Cloud Storage by restricting access to resources inside the perimeter, and the access level limits entry to the corporate VPN IP range. This satisfies both the exfiltration prevention and VPN-only access constraints.

Why this answer

VPC Service Controls creates a security perimeter around Google Cloud services (including Cloud Storage) that prevents data exfiltration by blocking access from outside the perimeter, even if IAM permissions would otherwise allow it. Access levels within the perimeter can be restricted to specific IP ranges (such as the corporate VPN CIDR), so only requests originating from those IPs can reach the protected resources. This combination of perimeter + access level directly satisfies both requirements: preventing exfiltration to unauthorized locations and limiting access to the VPN range.

Exam trap

The trap here is confusing network-level controls (firewall rules, Cloud Armor) with service-level data exfiltration prevention; candidates often pick firewall rules because they think of 'blocking traffic,' but VPC Service Controls is the only option that creates a data boundary for managed services like Cloud Storage.

How to eliminate wrong answers

Option B is wrong because VPC firewall rules only control traffic to and from VM instances within a VPC; they do not govern access to managed services like Cloud Storage, which are accessed via Google's APIs outside the VPC data path. Option C is wrong because IAM conditions with IP-based restrictions can limit who can call an API from a given IP, but they do not create a data exfiltration boundary — a user with valid credentials and permissions from an allowed IP could still copy data to an external bucket or project. Option D is wrong because Cloud Armor protects HTTP(S) load-balanced applications from web attacks and provides IP allow/deny at the edge, not access control for Cloud Storage APIs or data exfiltration prevention.

548
MCQeasy

A company wants to protect their web application hosted on Google Cloud HTTP(S) Load Balancer from common web attacks like SQL injection and cross-site scripting (XSS). Which GCP service should they use?

A.Identity-Aware Proxy (IAP)
B.Cloud CDN
C.VPC Service Controls
D.Cloud Armor
AnswerD

Cloud Armor provides edge security policies on the HTTP(S) load balancer, with preconfigured WAF rules that block SQL injection and XSS at layer 7. It satisfies the requirement to filter common web attacks before traffic reaches the backend application.

Why this answer

Cloud Armor provides WAF (Web Application Firewall) capabilities including preconfigured rules to block OWASP Top 10 attacks like SQL injection and XSS. IAP is for access control, not attack prevention. VPC Service Controls are for data exfiltration prevention.

Cloud CDN is for caching content.

549
MCQmedium

A Cloud Run service needs to access resources in a VPC network (e.g., a Cloud SQL instance). The service should be able to send requests to the VPC and receive responses. What is the correct configuration?

A.Create a VPC connector and configure the Cloud Run service to use it for egress
B.Place the Cloud Run service in a VPC subnet
C.Use Cloud NAT to allow Cloud Run to access the VPC
D.Use VPC peering between Cloud Run and the VPC
AnswerA

A Serverless VPC Access connector provides a path from Cloud Run into the VPC, letting the service send requests to private resources such as Cloud SQL and receive responses, which is exactly the bidirectional VPC access the scenario requires.

Why this answer

Cloud Run services run outside the customer's VPC by default, so to reach private VPC resources like a Cloud SQL instance with a private IP, you must attach a Serverless VPC Access connector. The connector provides a bridge from the serverless environment into the specified VPC network and subnet, allowing outbound requests to private IPs and return traffic. Configuring the service to use the connector for egress (all traffic or private ranges only) is the documented, supported pattern for this requirement.

Exam trap

PCA often tests the misconception that serverless services like Cloud Run can be 'placed in a subnet' or reached via VPC peering, when in reality they require a Serverless VPC Access connector (or Direct VPC egress) to bridge into the VPC.

How to eliminate wrong answers

Option B is wrong because Cloud Run is a fully managed serverless platform and does not allow you to place a service directly into a VPC subnet; there is no 'deploy into subnet' setting. Option C is wrong because Cloud NAT provides outbound internet access for resources already inside a VPC (such as GCE VMs or GKE nodes) and does nothing to connect a serverless service to private VPC IPs. Option D is wrong because VPC peering connects two VPC networks, and Cloud Run does not expose a VPC network that can be peered; peering cannot bridge the serverless environment to your VPC.

550
MCQmedium

A company runs a global application that requires strong consistency across regions for financial transactions. Which database should they choose?

A.Cloud SQL
B.Cloud Bigtable
C.Firestore
D.Cloud Spanner
AnswerD

Cloud Spanner provides externally consistent reads and linearisable transactions globally, using TrueTime to synchronise commit timestamps across regions. This satisfies the stem's requirement for strong consistency across regions for financial transactions, unlike eventually consistent multi-region databases.

Why this answer

Cloud Spanner is a globally distributed, strongly consistent database service that provides ACID transactions across regions. It is designed for applications that require strong consistency and high availability across multiple regions, making it ideal for financial transactions.

Exam trap

The trap is confusing strong consistency with high availability; Cloud SQL and Firestore can be highly available but do not provide cross-region strong consistency.

How to eliminate wrong answers

Option A is wrong because Cloud SQL is a regional database service that does not provide global strong consistency; it is typically used for single-region applications. Option B is wrong because Cloud Bigtable is a NoSQL database that provides eventual consistency and is optimized for high-throughput analytics, not strong consistency for transactions. Option C is wrong because Firestore is a NoSQL document database that provides strong consistency within a region but not across regions; it is more for mobile and web apps.

551
Multi-Selecthard

A company is planning a hybrid cloud architecture using Anthos to manage workloads across on-premises data centers and Google Cloud. They need to select two key components that enable consistent configuration, policy, and security across environments. Which two should they choose?

Select 2 answers
A.Cloud Interconnect
B.GKE on-prem
C.Cloud Build
D.Config Sync
E.Cloud Load Balancing
AnswersB, D

GKE on-prem extends the Anthos control plane to on-premises data centres, running Kubernetes clusters under the same configuration and policy management as Google Cloud. This directly satisfies the stem's requirement for consistent configuration, policy and security across both environments, since clusters register with Anthos and inherit its governance.

Why this answer

GKE on-prem (B) is correct because it extends the Google Kubernetes Engine control plane to on-premises data centers, letting the company run the same Kubernetes-based workload platform in both environments so configuration and security policies can be applied consistently. Config Sync (D) is correct because it continuously reconciles cluster configuration and policy from a central source of truth (typically a Git repository) across both on-prem and Google Cloud clusters, which is exactly what Anthos uses to enforce consistent configuration, policy, and security at scale. Cloud Interconnect (A) only provides private, high-bandwidth network connectivity between on-premises and Google Cloud and does not manage configuration or policy.

Cloud Build (C) is a CI/CD service for building and deploying artifacts, not a mechanism for enforcing cross-environment configuration or policy. Cloud Load Balancing (E) distributes traffic to backends and provides no configuration, policy, or security consistency across environments.

Exam trap

The trap here is that candidates often confuse connectivity services (Cloud Interconnect) or traffic management (Cloud Load Balancing) with configuration and policy consistency, failing to recognize that Anthos relies on GitOps-based tools like Config Sync and the on-prem Kubernetes runtime (GKE on-prem) to achieve unified management.

552
MCQeasy

Refer to the exhibit. What is the primary benefit of the `--preemptible` flag in this command?

A.Significant cost reduction compared to standard instances.
B.Faster instance startup time due to optimized kernel.
C.Higher availability through automatic restart on failure.
D.Access to specialized hardware like GPUs at no extra cost.
AnswerA

Preemptible instances cost substantially less than standard instances because Compute Engine can reclaim them, so the flag's primary benefit is significant cost reduction. The workload must tolerate interruption, but the flag's purpose is cheaper compute.

Why this answer

The `--preemptible` flag in Google Cloud Platform (GCP) creates preemptible VM instances, which are short-lived, cost-effective instances that can be terminated at any time by GCP. The primary benefit is a significant cost reduction—up to 60-91% lower than standard instances—making them ideal for batch jobs, fault-tolerant workloads, and non-critical tasks. This flag does not affect startup time, availability guarantees, or provide free access to specialized hardware.

Exam trap

Google Cloud often tests the misconception that `--preemptible` provides high availability or automatic restarts, when in reality it sacrifices availability for cost savings, and candidates may confuse it with managed instance groups or autohealing features.

How to eliminate wrong answers

Option B is wrong because the `--preemptible` flag does not optimize the kernel or affect instance startup time; startup time depends on the image and machine type, not the preemptible nature. Option C is wrong because preemptible instances have no automatic restart on failure—they are terminated after 24 hours or when capacity is needed, and they do not offer higher availability; in fact, they have lower availability than standard instances. Option D is wrong because preemptible instances do not provide access to specialized hardware like GPUs at no extra cost; GPUs are still billed separately, and preemptible instances with GPUs are subject to the same preemption risks and cost structure.

553
MCQmedium

Your organization runs a batch analytics platform that ingests data from a Pub/Sub topic into Cloud Storage, then loads it into BigQuery using a Dataflow streaming pipeline. The pipeline must handle sudden bursty traffic during month-end reporting, and you want to minimize operational overhead while ensuring the pipeline scales automatically. Which architectural approach should you choose?

A.Deploy a Compute Engine managed instance group running a custom ingestion script, and configure an autoscaler based on Pub/Sub queue depth.
B.Use a Dataflow streaming pipeline with autoscaling enabled, reading from Pub/Sub and writing to Cloud Storage and BigQuery.
C.Use a Dataproc cluster with autoscaling to run a Spark Streaming job that reads from Pub/Sub and writes to BigQuery.
D.Create a Cloud Function that triggers on each Pub/Sub message and writes directly to BigQuery and Cloud Storage.
AnswerB

Dataflow streaming with autoscaling dynamically adjusts the number of workers based on backlog and CPU utilization, matching bursty Pub/Sub traffic without manual intervention. It natively integrates with Pub/Sub, Cloud Storage, and BigQuery, so you avoid managing infrastructure. This directly satisfies the requirement for automatic scaling and minimal operational overhead for a streaming analytics pipeline.

Why this answer

A Dataflow streaming pipeline with autoscaling is the most suitable choice because it automatically adjusts worker count to handle bursty Pub/Sub traffic, integrates natively with Cloud Storage and BigQuery, and minimizes operational overhead. It provides exactly-once processing and handles backpressure, ensuring reliable and scalable analytics during month-end peaks.

Exam trap

The trap here is assuming that any autoscaling compute service (like managed instance groups or Dataproc) is equally low-overhead, when managed Dataflow specifically abstracts infrastructure and integrates with the data services.

554
MCQhard

A company wants to deploy a microservice on Cloud Run that requires high throughput and low latency. The service processes requests that can spike unpredictably. The team wants to minimize cold starts and ensure availability during traffic bursts. Which combination of Cloud Run settings should they configure?

A.min-instances = 1, max-instances = 1, concurrency = 80
B.min-instances = 0, max-instances = 100, concurrency = 1
C.min-instances = 0, max-instances = 10, concurrency = 80
D.min-instances = 1, max-instances = 100, concurrency = 80
AnswerD

Setting min-instances to 1 keeps one warm instance, eliminating cold starts for the baseline load, while max-instances = 100 caps horizontal scaling during unpredictable spikes. Concurrency = 80 lets each instance handle many simultaneous requests, improving throughput and reducing latency, satisfying the burst-availability constraint.

Why this answer

To minimize cold starts, the team must keep at least one warm instance, so min-instances must be 1 (not 0). To handle unpredictable spikes, max-instances must be high enough to scale out, so 100 is appropriate. Concurrency of 80 allows each instance to handle many simultaneous requests, maximizing throughput per instance and reducing the number of instances needed.

Only option D combines a warm minimum, a high ceiling, and high concurrency.

Exam trap

The trap is equating 'minimize cold starts' with cost optimization and choosing min-instances = 0, or confusing concurrency with instance count — candidates must recognize that a warm minimum plus high concurrency is what actually reduces cold starts and handles bursts.

How to eliminate wrong answers

Option A is wrong because max-instances = 1 caps the service at a single instance, so it cannot scale during traffic bursts and will queue or reject requests. Option B is wrong because min-instances = 0 allows the service to scale to zero, guaranteeing cold starts, and concurrency = 1 severely limits throughput per instance, forcing many instances and increasing latency. Option C is wrong because min-instances = 0 still permits scale-to-zero and cold starts, and max-instances = 10 may be too low for unpredictable high-throughput bursts.

555
MCQmedium

An engineering team runs workloads on Compute Engine instances in a single VPC. The security team wants the instances to reach Google APIs such as Cloud Storage and BigQuery without any traffic traversing the public internet, and without managing service account key files on disk. The architect must choose the configuration that meets both goals. Which approach should the architect recommend?

A.Deploy a third-party NAT gateway and route all Google API traffic through it with static service account keys
B.Configure Cloud VPN to an on-premises proxy that forwards API calls to Google
C.Enable Private Google Access on the subnet and attach a user-managed service account to the instances
D.Assign an external IP to each instance and configure firewall rules to allow egress to Google API IP ranges
AnswerC

Private Google Access lets instances without external IPs reach Google APIs and services using internal routing, so no traffic traverses the public internet. Attaching a user-managed service account lets the instance metadata server issue short-lived credentials, eliminating downloaded key files. Together they satisfy both the network and credential requirements.

Why this answer

Private Google Access allows instances that have no external IP address to reach Google APIs and services through internal Google routing, keeping traffic off the public internet. Attaching a user-managed service account lets the instance obtain short-lived tokens from the metadata server, so no long-lived key files are stored on disk. The other options either route traffic over the internet or retain static keys.

Exam trap

The trap here is treating Private Google Access as a complete solution while forgetting that credential management is a separate requirement, or assuming a NAT gateway keeps Google API traffic off the internet.

556
MCQmedium

An organization is implementing a data loss prevention (DLP) strategy for Cloud Storage. They want to automatically scan new objects uploaded to a specific bucket and redact sensitive data. Which service and configuration should they use?

A.Configure Cloud Armor with a WAF rule to inspect and redact data as it enters the bucket.
B.Enable Security Command Center (SCC) premium tier and configure it to scan the bucket for sensitive data.
C.Use Cloud DLP with a BigQuery external table to scan the bucket contents periodically.
D.Use Cloud Functions triggered by Cloud Storage events to call Cloud DLP API for each new object, and then store the redacted version.
AnswerD

Event-driven Cloud Functions fire on each object finalisation, invoking the Cloud DLP API to inspect and redact sensitive content before writing the sanitised object back. This satisfies automatic scanning of new uploads, which bucket-level DLP inspection alone cannot trigger per object.

Why this answer

It uses Cloud Functions as an event-driven compute service that triggers on Cloud Storage object finalize events. The function then calls the Cloud DLP API to inspect and redact sensitive data from the new object, and writes the redacted version back to the bucket. This provides automatic, near-real-time scanning and redaction for each uploaded object, aligning with the requirement for an automated DLP strategy.

Exam trap

The trap here is that candidates may confuse Cloud DLP's batch scanning capabilities (e.g., via BigQuery or Cloud Storage inspect jobs) with the need for real-time, event-driven processing, leading them to choose Option C instead of recognizing that Cloud Functions provide the necessary automatic trigger for each new object.

How to eliminate wrong answers

Option A is wrong because Cloud Armor is a web application firewall (WAF) that protects HTTP(S) load-balanced traffic, not a service that inspects or redacts data inside Cloud Storage buckets; it operates at the network edge, not on stored objects. Option B is wrong because Security Command Center (SCC) is a security and risk management platform that provides visibility and threat detection, but it does not perform automated redaction of sensitive data in Cloud Storage; it can identify misconfigurations or vulnerabilities but cannot modify object content. Option C is wrong because using Cloud DLP with a BigQuery external table requires periodic batch scanning of the bucket, which does not meet the requirement for automatic scanning of new objects as they are uploaded; it introduces latency and lacks event-driven, per-object processing.

557
MCQhard

An organization wants to deploy a containerized microservices architecture on Google Kubernetes Engine (GKE) and minimize operational overhead. They do not need to manage the node infrastructure and are willing to accept some limitations on node configuration. Which GKE mode should they choose?

A.GKE Standard mode with zonal cluster
B.Compute Engine with container-optimized OS and instance groups
C.Cloud Run for Anthos
D.GKE Autopilot mode
AnswerD

GKE Autopilot provisions and manages the nodes itself, so the organisation never handles node infrastructure, directly satisfying the minimal-operational-overhead constraint. Its trade-off is restricted node configuration, which the stem explicitly accepts, making it the fitting mode.

Why this answer

GKE Autopilot mode is a fully managed Kubernetes experience where Google manages the control plane and the nodes, including provisioning, scaling, and security patching. It minimizes operational overhead because users only deploy workloads and pay for the resources their pods consume, without managing node pools. The scenario explicitly accepts limitations on node configuration, which aligns with Autopilot's opinionated, hardened node management.

Exam trap

The trap is confusing GKE Autopilot with serverless container platforms like Cloud Run — candidates pick Cloud Run for Anthos thinking it is the managed GKE mode, but Autopilot is the GKE-native answer that preserves Kubernetes API compatibility while removing node management.

How to eliminate wrong answers

Option A is wrong because GKE Standard mode with a zonal cluster still requires the customer to manage node pools, scaling, and node-level configuration, which does not minimize operational overhead. Option B is wrong because Compute Engine with container-optimized OS and instance groups is a self-managed approach requiring significant operational effort for node lifecycle, patching, and orchestration. Option C is wrong because Cloud Run for Anthos is a serverless abstraction for running containers on Anthos clusters, not the native GKE mode designed for minimal node management with Kubernetes API compatibility.

558
Multi-Selectmedium

An organization wants to monitor and alert on custom application metrics from a GKE cluster. They also need to view logs in real-time and create metrics from log content. Which two GCP services should they use? (Choose two.)

Select 2 answers
A.Error Reporting
B.Cloud Monitoring
C.Cloud Profiler
D.Cloud Trace
E.Cloud Logging
AnswersB, E

Cloud Monitoring ingests custom application metrics from GKE, evaluates alerting policies against them, and can define log-based metrics from log content. It therefore satisfies both the custom metric alerting and log-derived metric requirements within one service.

Why this answer

Cloud Monitoring (B) is correct because it is the GCP service that ingests custom application metrics, lets you build dashboards, and configure alerting policies on those metrics from GKE workloads. Cloud Logging (E) is correct because it collects and streams logs in real time, and its log-based metrics feature lets you create counter or distribution metrics directly from log content. Together they satisfy both requirements: metric monitoring/alerting and real-time log viewing with metrics derived from logs.

Error Reporting (A) only aggregates and groups application errors, not general metrics or log-based metrics. Cloud Profiler (C) analyzes CPU and heap usage for performance profiling, not metric alerting or log viewing. Cloud Trace (D) captures distributed latency traces across services, which is unrelated to custom metric alerting or log-based metric creation.

559
MCQmedium

A retail company operates a global e-commerce platform on Google Cloud. Their architects need to choose a load balancing solution that terminates TLS at the edge, provides a single global anycast IP address, and automatically routes users to the closest healthy backend. Which Google Cloud load balancing product should they select?

A.Internal Application Load Balancer (HTTP(S))
B.Regional external Application Load Balancer (HTTP(S))
C.Global external Application Load Balancer (HTTP(S))
D.External passthrough Network Load Balancer
AnswerC

The global external Application Load Balancer uses a single global anycast IP, terminates TLS at Google's edge, and routes traffic to the closest healthy backend using Google's global network. This matches all three requirements: edge TLS termination, one global IP, and proximity-based routing for a worldwide e-commerce audience.

Why this answer

The global external Application Load Balancer is built for internet-facing global services: it provides a single anycast IP, terminates TLS at Google's edge, and uses Google's global network to send each user to the nearest healthy backend. A regional load balancer cannot give one global IP, and layer 4 passthrough options do not terminate TLS or perform HTTP-aware global routing.

Exam trap

The trap here is assuming any Application Load Balancer is global, when in fact regional and internal variants exist that lack the single global anycast IP and edge TLS behavior.

560
MCQeasy

A company is migrating a monolithic application to Google Cloud. They want to minimize changes to the application code while taking advantage of Cloud Run for serverless containers. Which approach should they take?

A.Deploy the application to App Engine standard environment with automatic scaling.
B.Lift and shift the application to Compute Engine instances behind a load balancer.
C.Refactor the application into microservices and deploy each as a separate Cloud Run service.
D.Use Cloud Run by packaging the existing application as a container and listening on a web server.
AnswerD

Cloud Run accepts any container listening on the port defined by the PORT environment variable, so packaging the monolith unchanged and binding its existing web server satisfies the minimal-code-change constraint. No rewrite to functions or event-driven handlers is needed; the container contract alone enables serverless hosting.

Why this answer

Cloud Run can run any containerized application that listens on HTTP requests on port 8080. By packaging the existing monolithic application as a container and adding a lightweight web server (e.g., Express, Flask, or Nginx), the company can deploy it to Cloud Run with minimal code changes, leveraging serverless scaling and pay-per-use pricing without refactoring into microservices.

Exam trap

Google Cloud often tests the misconception that serverless containers require microservices architecture, but Cloud Run can run any containerized application, including a monolithic one, as long as it listens for HTTP requests.

How to eliminate wrong answers

Option A is wrong because App Engine standard environment requires the application to conform to specific runtime constraints (e.g., Java Servlet, Python WSGI) and does not support arbitrary containers, so it would likely require significant code changes. Option B is wrong because lifting and shifting to Compute Engine instances behind a load balancer does not minimize changes but also fails to take advantage of serverless containers, requiring manual management of VMs, scaling, and patching. Option C is wrong because refactoring the monolithic application into microservices is a major architectural change that contradicts the requirement to minimize changes to the application code.

561
MCQhard

A company runs a stateful application on a single Compute Engine instance with a persistent disk. They need to ensure that the application can recover quickly in case of a zone failure. The recovery point objective (RPO) is 5 minutes, and the recovery time objective (RTO) is 15 minutes. Which approach should they take?

A.Use a regional persistent disk with the instance, and configure the application to failover to a standby instance in another zone using a startup script that attaches the disk.
B.Create a snapshot schedule for the persistent disk every 5 minutes, and in case of failure, create a new instance from the latest snapshot in another zone.
C.Set up a Cloud SQL instance with high availability, and migrate the application to use Cloud SQL.
D.Use a managed instance group with autoscaling across multiple zones, and store application state on a Cloud Storage bucket mounted via Cloud Storage FUSE.
AnswerA

A regional persistent disk replicates data synchronously across two zones, providing an RPO of near zero. In case of zone failure, you can attach the disk to a standby instance in the other zone. With automation, failover can be achieved within the 15-minute RTO. This meets both RPO and RTO requirements.

Why this answer

A regional persistent disk synchronously replicates data across two zones, ensuring an RPO of zero. By automating failover to a standby instance in the other zone, you can achieve the 15-minute RTO. This is the most suitable solution for a stateful application requiring zone failure recovery.

The other options either do not meet the RPO/RTO or require significant application changes.

Exam trap

The trap here is assuming that frequent snapshots can meet a 5-minute RPO, but snapshot frequency is limited and restore times may exceed the RTO.

562
MCQmedium

A team is migrating a stateful application to GKE. The application requires persistent storage with ReadWriteMany (RWX) access across multiple pods. Which Kubernetes volume type should they use to meet this requirement on GKE?

A.Persistent Disk (Compute Engine persistent disks)
B.Cloud Storage FUSE
C.Filestore
D.ConfigMap
AnswerC

Filestore provides a managed NFS share, which natively supports ReadWriteMany access so multiple pods can mount the same volume concurrently. GKE's persistent disk options (Compute Engine persistent disks) only offer ReadWriteOnce or ReadOnlyMany, so they cannot satisfy the RWX constraint this stateful application requires.

Why this answer

Filestore is Google Cloud's fully managed NFS file service, and the Filestore CSI driver on GKE exposes it as a ReadWriteMany (RWX) PersistentVolume that many pods can mount simultaneously. Persistent Disk is block storage attached to a single node, so it can only support ReadWriteOnce (RWO) or ReadOnlyMany (ROX), not RWX. Cloud Storage FUSE is object storage mounted as a filesystem and is not a native Kubernetes RWX volume type for stateful workloads.

Exam trap

PCA often tests the confusion between Persistent Disk (RWO block storage) and Filestore (RWX NFS), so candidates who see 'persistent storage' and reflexively pick Persistent Disk miss the RWX requirement.

How to eliminate wrong answers

Option A is wrong because Compute Engine Persistent Disks are zonal/regional block devices that can only be attached to one node at a time, so they support RWO (and ROX) but never RWX. Option B is wrong because Cloud Storage FUSE mounts a GCS bucket as a filesystem via a sidecar; it is not a Kubernetes PersistentVolume access mode and lacks POSIX semantics required by stateful apps. Option D is wrong because ConfigMap is for injecting non-confidential configuration data as files or env vars, not for persistent storage.

563
Multi-Selectmedium

A company is migrating a legacy application that uses a file server to GCP. The application requires a shared file system that supports the NFS protocol and can be mounted by multiple Compute Engine instances. The team also needs to use Cloud NAT to allow the instances to download updates. Which TWO services should they use? (Choose 2)

Select 2 answers
A.Cloud NAT
B.Cloud VPN
C.Cloud Storage Fuse
D.Cloud Filestore
E.Private Google Access
AnswersA, D

Cloud NAT provides managed outbound internet connectivity for Compute Engine instances without external IP addresses, letting them download updates. It satisfies the requirement directly and is the correct service pairing alongside the shared NFS file system.

Why this answer

Cloud Filestore (D) is correct because it is GCP's fully managed file storage service that natively supports the NFSv3 protocol and can be mounted simultaneously by multiple Compute Engine instances, which is exactly what the legacy application requires for its shared file system. Cloud NAT (A) is correct because it provides outbound internet access for instances without external IP addresses, allowing them to download updates while remaining unreachable from the internet. Cloud VPN (B) is not appropriate here because it establishes encrypted tunnels to on-premises or other networks, not a shared NFS file system or outbound NAT.

Cloud Storage Fuse (C) is not correct because it mounts Cloud Storage buckets as a local file system via a FUSE adapter, which does not provide a true NFS-protocol shared file system for multiple instances. Private Google Access (E) is not correct because it only enables instances without external IPs to reach Google APIs and services, not general internet downloads, which is what Cloud NAT handles.

Exam trap

The trap is confusing Private Google Access with Cloud NAT — candidates pick Private Google Access for outbound internet, but it only covers Google APIs, while Cloud NAT handles general outbound internet access.

564
MCQmedium

A company has a Cloud Run service that processes high-throughput requests. They want to reduce latency by keeping a baseline of warm instances always ready to handle traffic. Which Cloud Run configuration parameters should they adjust?

A.Set min-instances to 0 and max-instances to 100
B.Set max-instances to a high value and concurrency to 1
C.Set min-instances to 10 and CPU to always-on
D.Set max-instances to 0 (unlimited) and concurrency to 80
AnswerC

Min-instances keeps a baseline of warm instances alive so cold starts do not add latency, while CPU set to always-on prevents throttling between requests. Together they satisfy the requirement for always-ready capacity under high-throughput load.

Why this answer

Setting min-instances to a value greater than zero (e.g., 10) ensures that Cloud Run keeps that many instances warm and ready at all times, eliminating cold-start latency for the baseline traffic. Additionally, setting CPU to 'always-on' (also called 'CPU always allocated') prevents the CPU from being throttled to near-zero when no requests are being processed, which is critical for background work and for maintaining warm instances that can respond immediately. Together, these two parameters directly address the requirement to keep a baseline of warm instances and reduce latency.

Exam trap

PCA often tests the misconception that setting max-instances high or concurrency low will keep instances warm, but only min-instances > 0 and CPU always-on actually guarantee warm instances and eliminate cold starts.

How to eliminate wrong answers

Option A is wrong because setting min-instances to 0 allows Cloud Run to scale down to zero instances when there is no traffic, causing cold starts and increased latency for the next request. Option B is wrong because setting concurrency to 1 forces each instance to handle only one request at a time, which drastically reduces efficiency and increases the number of instances needed, and max-instances alone does not keep instances warm. Option D is wrong because max-instances set to 0 is not a valid configuration (it would mean no instances allowed), and concurrency to 80 does not ensure warm instances; it only controls how many concurrent requests each instance can handle.

565
MCQhard

A healthcare company is designing a solution to ingest and process millions of patient records daily. The data must be stored in a way that supports SQL queries and also allows for real-time analytics. The company wants to minimize operational overhead and needs a fully managed, petabyte-scale data warehouse. Which Google Cloud service should the solutions architect recommend?

A.Cloud Spanner.
B.Cloud Bigtable.
C.BigQuery.
D.Cloud SQL for PostgreSQL.
AnswerC

BigQuery is a fully managed, petabyte-scale data warehouse that supports ANSI SQL and real-time analytics through streaming inserts. It requires no infrastructure management, aligning with the goal of minimizing operational overhead. It can ingest millions of records daily and scale seamlessly, making it ideal for the healthcare company's requirements.

Why this answer

BigQuery is a serverless, highly scalable data warehouse that supports SQL and real-time analytics. It is fully managed, so the healthcare company can focus on analyzing data rather than managing infrastructure. It handles petabyte-scale datasets and daily ingestion of millions of records without manual scaling, making it the best fit for the requirements.

Exam trap

The trap here is assuming that any managed database with SQL support can serve as a petabyte-scale data warehouse, when BigQuery is specifically designed for that purpose while others are optimized for transactional or NoSQL workloads.

566
MCQeasy

A company wants to store customer transaction logs for 7 years for compliance. The logs are accessed rarely but must be retrievable within 24 hours. Which storage option is most cost-effective?

A.Cloud Storage Archive class
B.Cloud Storage Nearline class
C.Cloud Storage Coldline class
D.Cloud Storage Standard class
AnswerA

Archive class offers the lowest storage price for data retained years and rarely read, with retrieval typically within hours, comfortably meeting the 24-hour deadline. Nearline or Coldline cost more per gigabyte for this access pattern.

Why this answer

Cloud Storage Archive class is the most cost-effective option for data that is accessed rarely and requires retrieval within 24 hours. Archive class offers the lowest storage cost among Google Cloud Storage classes, with a default retrieval time of 12 hours, which comfortably meets the 24-hour requirement. This makes it ideal for long-term compliance retention of transaction logs that are infrequently accessed.

Exam trap

Google Cloud often tests the misconception that Coldline is the cheapest storage class, but Archive class actually has the lowest storage cost, with retrieval times up to 24 hours, making it the correct choice for rarely accessed data with flexible retrieval requirements.

How to eliminate wrong answers

Option B (Cloud Storage Nearline class) is wrong because it is designed for data accessed less than once a month, with a 30-day minimum storage duration, and its storage cost is higher than Archive, making it less cost-effective for 7-year retention. Option C (Cloud Storage Coldline class) is wrong because it targets data accessed less than once a quarter, with a 90-day minimum storage duration, and its storage cost is higher than Archive, so it is not the most cost-effective for rarely accessed logs. Option D (Cloud Storage Standard class) is wrong because it is optimized for frequently accessed data with no minimum storage duration and has the highest storage cost, making it prohibitively expensive for long-term archival of rarely accessed logs.

567
MCQeasy

A startup wants to deploy a containerized web application with zero server management and automatic scaling based on HTTP requests. They expect very low traffic initially but want to scale to thousands of requests per second without configuration changes. Which compute service is most appropriate?

A.Compute Engine with managed instance groups
B.Cloud Run
C.Google Kubernetes Engine (GKE) Standard
D.App Engine Standard
AnswerB

Cloud Run scales automatically from zero to thousands of requests per second using request concurrency, with no server management or manual scaling configuration. This matches the low initial traffic and large burst capacity requirements without changes.

Why this answer

Cloud Run is a fully managed serverless container platform that abstracts all infrastructure, scales automatically from zero to thousands of requests per second based on HTTP traffic, and requires no cluster or server management. It directly matches the requirements of zero server management, automatic HTTP-based scaling, and no configuration changes as traffic grows.

Exam trap

PCA often tests the difference between serverless containers (Cloud Run) and orchestrated containers (GKE) — candidates may pick GKE for 'automatic scaling' but overlook that GKE requires cluster management, violating the zero-server-management requirement.

How to eliminate wrong answers

Option A is wrong because Compute Engine with managed instance groups still requires managing VM instances, configuring autoscaling policies, and paying for idle capacity — it is not zero server management. Option C is wrong because GKE Standard requires managing the Kubernetes control plane, node pools, and cluster upgrades, adding operational overhead the startup wants to avoid. Option D is wrong because App Engine Standard supports specific runtimes and has scaling limits and configuration constraints (e.g., instance class, max instances) that may require changes as traffic grows to thousands of requests per second, and it is not container-native in the same flexible way as Cloud Run.

568
MCQmedium

A retail company is deploying a customer-facing API on Google Cloud. The API must survive the loss of an entire region with minimal data loss and must serve users in North America, Europe, and Asia with low latency. The database layer must support strongly consistent reads and writes. Which design should the architect choose for the data tier?

A.Firestore in Datastore mode with a multi-region location and client-side caching of query results.
B.Bigtable with a multi-cluster routing policy and application-level retries for failed writes.
C.Cloud Spanner with a multi-region instance configuration, with application instances reading and writing through regional endpoints.
D.A single Cloud SQL for PostgreSQL instance in us-central1 with cross-region read replicas in europe-west1 and asia-east1.
AnswerC

Cloud Spanner's multi-region configurations replicate synchronously across regions with external consistency, so a region loss does not lose committed data and reads remain strongly consistent. Serving from regional endpoints keeps latency low for users on each continent while the multi-region quorum preserves durability.

Why this answer

Cloud Spanner is the Google Cloud database that provides synchronous multi-region replication with external consistency, so losing a region does not lose committed writes and reads stay strongly consistent. Regional endpoints let each continent's application instances talk to nearby replicas while the multi-region quorum maintains durability and correctness.

Exam trap

The trap here is assuming that cross-region read replicas on a single-primary database provide both regional failover and strongly consistent reads at global scale.

569
MCQhard

A company runs a streaming data pipeline using Dataflow to process real-time data and insert into BigQuery. Recently, workers are frequently failing with out-of-memory errors and the pipeline latency is increasing. What should they do to resolve the issue?

A.Increase the worker machine type and memory
B.Use Cloud Pub/Sub for buffering and then load into BigQuery in batches
C.Enable autoscaling and increase the maximum number of workers
D.Enable Dataflow Streaming Engine
AnswerD

Streaming Engine moves pipeline state and shuffling off the worker VMs to the Dataflow service, so workers no longer hold that memory. This directly removes the out-of-memory cause and reduces latency, satisfying the real-time processing requirement.

Why this answer

Dataflow Streaming Engine offloads the streaming data processing state and shuffle data from worker memory to a backend service, reducing memory pressure on workers. This directly addresses out-of-memory errors and latency increases without requiring manual scaling or machine type changes. It is the recommended solution for streaming pipelines experiencing memory bottlenecks.

Exam trap

Google Cloud often tests the misconception that scaling up resources (more memory or more workers) is the primary fix for streaming pipeline memory issues, when the real solution is to offload state management using Streaming Engine.

How to eliminate wrong answers

Option A is wrong because simply increasing worker machine type and memory does not resolve the root cause of state management overhead in streaming pipelines; it only delays the failure and increases cost without optimizing data flow. Option B is wrong because adding Pub/Sub buffering does not fix the memory issue within Dataflow workers; it shifts the problem to a different layer and may introduce additional latency and complexity. Option C is wrong because enabling autoscaling and increasing max workers can help with throughput but does not reduce per-worker memory consumption; workers may still fail with OOM errors if the pipeline's state or shuffle data exceeds available memory.

570
Drag & Dropmedium

Drag and drop the steps to migrate a Compute Engine VM to a different region using a snapshot into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Snapshots are global resources, but disks are regional. Create the disk in the target region, then create the VM.

571
Multi-Selecteasy

What are two best practices for designing a scalable Kubernetes architecture on GKE?

Select 2 answers
A.Use StatefulSets for stateless applications
B.Disable Cluster Autoscaler
C.Enable horizontal pod autoscaling
D.Use node pools with different machine types
E.Use a single zone cluster
AnswersC, D

Horizontal pod autoscaling adjusts replica counts dynamically based on observed CPU, memory or custom metrics, so the cluster absorbs traffic spikes without manual intervention. This directly satisfies the scalability requirement by matching capacity to demand, preventing both resource starvation under load and idle waste during quiet periods.

Why this answer

Option C is correct because enabling Horizontal Pod Autoscaling (HPA) lets GKE automatically adjust the number of pod replicas based on metrics such as CPU utilization or custom metrics, which is essential for handling variable load in a scalable architecture. Option D is correct because using multiple node pools with different machine types allows you to right-size workloads, isolate resource-intensive or specialized workloads (e.g., GPU, memory-optimized), and scale each pool independently, improving both efficiency and scalability. Option A is incorrect because StatefulSets are designed for stateful applications requiring stable network identities and persistent storage, not stateless workloads, which are better served by Deployments.

Option B is incorrect because disabling the Cluster Autoscaler prevents nodes from being added or removed automatically as demand changes, undermining scalability. Option E is incorrect because a single-zone cluster concentrates resources in one zone, reducing availability and limiting the ability to scale resiliently across zones.

Exam trap

Google Cloud often tests the misconception that StatefulSets are interchangeable with Deployments for stateless apps, or that disabling Cluster Autoscaler simplifies management, but the trap here is that candidates may overlook the need for multi-zonal clusters and autoscaling mechanisms to achieve true scalability and resilience in GKE.

572
MCQeasy

A financial services firm is designing a new application on Google Cloud. The application must store sensitive customer data and comply with regulations that require encryption at rest with keys managed by the company. The company also needs to control key rotation and revocation. Which Google Cloud service should the solutions architect use to meet these requirements?

A.Cloud Key Management Service (Cloud KMS) with customer-managed encryption keys (CMEK).
B.Cloud HSM to provide hardware security modules for key storage.
C.Cloud Data Loss Prevention (DLP) to discover and redact sensitive data.
D.Cloud Identity-Aware Proxy (IAP) to enforce access control and encrypt data in transit.
AnswerA

Cloud KMS with CMEK allows the company to create and manage encryption keys, including rotation and revocation, while Google Cloud services use those keys to encrypt data at rest. This provides the required control over keys for compliance. It is the standard service for managing encryption keys in Google Cloud and integrates with many services like Cloud Storage and BigQuery.

Why this answer

Cloud KMS with customer-managed encryption keys gives the company full control over the lifecycle of encryption keys, including rotation and revocation, while integrating with Google Cloud services to encrypt data at rest. This meets the regulatory requirement for company-managed keys. Other services like IAP or DLP address different aspects of security and do not provide key management.

Exam trap

The trap here is confusing access control or data loss prevention services with encryption key management, when only Cloud KMS with CMEK provides the required control over keys.

573
MCQeasy

A startup is building a mobile app backend that requires real-time data synchronization across multiple users. They need a fully managed, serverless NoSQL database that scales automatically and supports offline persistence. Which database should they choose?

A.Cloud Spanner
B.Cloud Bigtable
C.Cloud SQL
D.Cloud Firestore
AnswerD

Cloud Firestore is a fully managed, serverless NoSQL document database that scales automatically and provides real-time listeners plus native offline persistence via client SDKs. This directly satisfies the startup's requirements for multi-user synchronisation and offline operation without provisioning servers.

Why this answer

Cloud Firestore is a fully managed, serverless NoSQL document database that scales automatically and provides real-time synchronization and offline persistence through client SDKs. These features directly match the mobile app backend requirements for real-time sync across users and offline support.

Exam trap

PCA often tests the confusion between Firestore and Bigtable or Spanner, where candidates pick a scalable database without recognizing that only Firestore offers native real-time sync and offline persistence.

How to eliminate wrong answers

Option A is wrong because Cloud Spanner is a globally distributed relational database with strong consistency, not a serverless NoSQL store, and it does not provide built-in offline persistence for mobile clients. Option B is wrong because Cloud Bigtable is a wide-column NoSQL database optimized for high-throughput analytics, not for mobile real-time sync or offline persistence. Option C is wrong because Cloud SQL is a managed relational database (MySQL, PostgreSQL, SQL Server) and lacks native real-time sync and offline capabilities.

574
MCQhard

A company is using BigQuery for analytics and wants to optimize query costs. They have many ad-hoc queries that scan large tables. What is the best practice?

A.Use clustering and partitioning on tables.
B.Use flat-rate pricing.
C.Use BI Engine.
D.Use materialized views.
AnswerA

Partitioning restricts each ad-hoc query to relevant date or range segments, while clustering sorts storage by filtered columns so block pruning applies. Both cut bytes scanned, and on-demand BigQuery pricing charges per byte, so large-table scans cost less.

Why this answer

Clustering and partitioning reduce the amount of data scanned by BigQuery for each query, directly lowering query costs (which are based on bytes processed). Partitioning allows queries to skip entire partitions based on a date or timestamp column, while clustering sorts data within partitions, enabling block-level pruning for filter predicates. This is the most effective and scalable way to optimize ad-hoc queries on large tables without changing the query logic.

Exam trap

Google Cloud often tests the misconception that flat-rate pricing or BI Engine directly reduce per-query costs, when in fact they address capacity or latency, not the fundamental cost driver of bytes scanned.

How to eliminate wrong answers

Option B is wrong because flat-rate pricing (slot-based reservations) does not reduce the amount of data scanned; it only provides predictable costs for a fixed number of slots, and ad-hoc queries still incur slot usage but do not reduce per-query bytes processed. Option C is wrong because BI Engine is an in-memory acceleration service for interactive dashboards and repeated queries, not for optimizing ad-hoc analytical queries that scan large tables; it caches results but does not reduce scan bytes for new queries. Option D is wrong because materialized views precompute and store query results, which can speed up repeated queries but do not help with arbitrary ad-hoc queries that may not match the view definition; they also incur storage costs and require maintenance.

575
MCQmedium

A company wants to use their existing Active Directory for authentication to Google Cloud. They need to sync user and group identities to Cloud Identity and allow users to log in with their corporate credentials. Which two services should they use together?

A.Cloud Directory Sync and Workload Identity
B.Cloud Directory Sync and SAML SSO
C.SAML SSO and IAP
D.Cloud Identity and IAP
AnswerB

Cloud Directory Sync provisions users and groups from Active Directory into Cloud Identity, keeping identities aligned. SAML SSO then federates authentication so users sign in with corporate credentials, satisfying both the sync requirement and the existing-AD login constraint without duplicating passwords.

Why this answer

Cloud Directory Sync (CDS) syncs users and groups from LDAP/AD to Cloud Identity. SAML SSO allows users to authenticate using their corporate credentials. IAP is for application access, not directory sync.

Cloud Identity as a standalone does not sync automatically. Workload Identity is for Kubernetes.

576
MCQhard

A company wants to enforce that only container images built and signed by their CI/CD pipeline can be deployed in their GKE cluster. Which Google Cloud service should they use?

A.Artifact Analysis
B.Binary Authorization
C.Cloud Audit Logs
D.Cloud Security Command Center
AnswerB

Binary Authorization enforces deploy-time attestations, letting only images signed by your CI/CD pipeline's attestors run in GKE. It satisfies the stem's constraint that solely pipeline-built and pipeline-signed container images be admitted, by validating cryptographic attestations against a defined policy before the admission controller permits the workload.

Why this answer

Binary Authorization is the Google Cloud service that enforces deploy-time policies on GKE, allowing only container images that meet attestation requirements (e.g., signed by the CI/CD pipeline) to be deployed. It integrates with Container Analysis/Artifact Analysis to verify signatures and attestations before admitting a pod.

Exam trap

The trap is confusing Artifact Analysis (scanning/metadata) with Binary Authorization (enforcement) — candidates pick Artifact Analysis because it deals with images, but only Binary Authorization enforces the signed-image policy at deploy time.

How to eliminate wrong answers

Option A (Artifact Analysis) is wrong because it provides vulnerability scanning and metadata storage for container images, not deploy-time admission control — it can supply attestations but does not enforce them. Option C (Cloud Audit Logs) is wrong because it records API activity for auditing, not policy enforcement at deployment time. Option D (Cloud Security Command Center) is wrong because it aggregates security findings and posture management; it does not block unsigned images from being deployed.

577
MCQhard

A financial services company is designing a Google Cloud landing zone. Regulators require that production workloads be isolated from non-production workloads, that each business unit control its own billing and quotas, and that a central team enforce network and security policies across everything. The company wants to minimize the number of projects it must manage manually. Which structure should the architect propose?

A.A flat set of projects directly under the organization node, with a distinct service account per project and firewall rules copied into each project's VPC.
B.A folder per business unit, with production and non-production subfolders under each, projects created inside those subfolders, and organization policies plus shared VPC set at the folder level.
C.One project per environment (production, staging, development) under the organization node, with folders used only for IAM groups.
D.Two folders, one for production and one for non-production, with all business unit projects placed in the matching folder and billing separated by project labels.
AnswerB

Folder-per-business-unit with environment subfolders gives each unit its own projects and billing accounts while letting a central team attach organization policies and Shared VPC host configuration at the folder level, so those controls inherit to every current and future project. This is the recommended resource hierarchy pattern and avoids per-project manual policy assignment as the company grows.

Why this answer

The recommended Google Cloud resource hierarchy nests environment subfolders inside business-unit folders, because organization policies, IAM, and Shared VPC settings attached at a folder are inherited by every project beneath it, including projects created later. This satisfies workload isolation, delegated billing and quota ownership per unit, and centralized policy enforcement while keeping manual per-project work to a minimum as the estate grows.

Exam trap

The trap here is treating billing separation as achievable through labels, when a billing account must be linked to a project or be inherited from a parent, and labels are only metadata.

578
MCQhard

A company runs a critical application on Compute Engine instances in a managed instance group (MIG) across three zones in us-central1. The application uses a Cloud Spanner database. Recently, the application experienced increased latency and timeouts during peak hours. The operations team noticed that the MIG's CPU utilization is consistently above 80% during peak hours, and the autoscaler is configured to scale based on CPU utilization with a target of 60%. However, the autoscaler is not adding new instances quickly enough, causing performance degradation. The team also observed that new instances take over 5 minutes to become healthy and serve traffic. The health check is a simple TCP check on port 8080. The application startup script downloads large configuration files from Cloud Storage. What should the team do to improve the autoscaling response time and reduce latency?

A.Increase the minimum number of instances in the MIG to handle peak load.
B.Reduce the autoscaler target CPU utilization to 40% so it scales earlier.
C.Create a custom Compute Engine image that includes the application and configuration, and use it in the MIG.
D.Change the health check to HTTP and reduce the initial delay and check intervals.
AnswerC

Baking the application and configuration into a custom image removes the startup script's download of large files from Cloud Storage, cutting the over-five-minute initialisation delay. Instances therefore become healthy faster, letting the autoscaler add capacity quickly enough to hold CPU near the 60% target.

Why this answer

The primary bottleneck is the long instance startup time (over 5 minutes) caused by downloading large configuration files from Cloud Storage at boot. By creating a custom Compute Engine image that bakes the application and configuration into the image, new instances can start serving traffic almost immediately, drastically reducing the time before they become healthy and the autoscaler can consider them in scaling decisions. This directly addresses the root cause of slow autoscaling response, as the autoscaler cannot add instances faster than they become healthy.

Exam trap

The trap here is that candidates focus on tuning the autoscaler parameters (CPU target, health check intervals) rather than identifying the actual bottleneck—the instance startup time—which is a common misconception that autoscaling speed is purely a function of scaling policy settings.

How to eliminate wrong answers

Option A is wrong because increasing the minimum number of instances only handles baseline load, not the dynamic scaling speed during peak hours; it does not fix the slow instance startup time that delays autoscaler response. Option B is wrong because reducing the target CPU utilization to 40% would cause the autoscaler to trigger earlier, but it still cannot add instances faster than the 5-minute startup delay; it would only increase the number of pending instances without improving latency. Option D is wrong because changing the health check to HTTP and reducing intervals only affects how quickly the MIG detects an instance as healthy after it starts, but the fundamental problem is the 5-minute startup time itself—no health check tuning can make the instance boot faster.

579
MCQhard

An organization has a security policy that prohibits the use of external IP addresses on Compute Engine instances to reduce attack surface. They want to enforce this policy across all new and existing projects. Which approach should they use?

A.Use Organization Policy with constraint compute.vmExternalIpAccess
B.Use IAM conditions to prevent creation of instances with external IPs
C.Use Cloud Security Command Center to detect and alert on external IPs
D.Use VPC Firewall rules to block traffic to external IPs
AnswerA

The `compute.vmExternalIpAccess` organisation policy constraint directly enforces the no-external-IP requirement across every project in the organisation, denying instance creation or update when an external address is attached. Unlike per-project firewall rules or IAM controls, it applies hierarchically at the organisation node, satisfying the mandate for both new and existing projects.

Why this answer

The Organization Policy constraint `compute.vmExternalIpAccess` is the correct approach because it allows you to set a policy at the organization, folder, or project level that denies the assignment of external IP addresses to Compute Engine instances. This policy is enforced at resource creation time and applies to all new and existing VM instances, ensuring compliance with the security policy across the entire resource hierarchy. It directly prevents the use of external IPs, reducing the attack surface without requiring per-project or per-instance configuration.

Exam trap

The trap here is that candidates often confuse IAM conditions (which control who can perform an action) with Organization Policy constraints (which control what actions are allowed), leading them to choose IAM conditions as a preventive control when they only provide authorization-level restrictions, not resource-level enforcement.

How to eliminate wrong answers

Option B is wrong because IAM conditions can restrict who can create instances with external IPs, but they do not prevent the actual assignment of external IPs; a user with the compute.instances.create permission could still create an instance with an external IP if the condition is not properly scoped, and IAM conditions do not enforce the policy on existing instances. Option C is wrong because Cloud Security Command Center (SCC) is a detection and alerting tool that identifies misconfigurations after they occur, but it does not proactively enforce or prevent the use of external IPs; it only provides visibility and remediation recommendations. Option D is wrong because VPC Firewall rules control traffic to and from IP addresses, but they cannot prevent a VM from being assigned an external IP address; a VM with an external IP will still have that IP regardless of firewall rules, and firewall rules do not block the IP assignment itself.

580
MCQmedium

A financial services company runs a three-tier web application on Compute Engine across three zones in us-central1. Their security team mandates that database traffic must never traverse the public internet, and that the database subnet must be reachable only from the application subnet. The network team has already created a custom VPC named fin-vpc with separate subnets for web, app, and db tiers. Which combination of controls should the architect implement to satisfy these requirements?

A.Create a firewall rule on fin-vpc that allows ingress to the db subnet only from the app subnet's CIDR range, and do not assign external IP addresses to the database instances.
B.Create a second VPC for the database tier and peer it to fin-vpc, then rely on the default firewall rules to block non-app traffic.
C.Enable Private Google Access on the db subnet and remove external IPs from the database instances so all traffic stays internal to Google's network.
D.Assign internal IP addresses to the databases and place them behind an external TCP proxy load balancer so only the app tier can resolve the backend.
AnswerA

Firewall rules in a VPC scope by target and source, so allowing ingress to the db subnet only from the app subnet CIDR restricts reachability to that tier, while omitting external IPs keeps the database off the public internet entirely. Together these satisfy both the isolation and no-public-internet mandates without extra products.

Why this answer

Restricting access at the subnet level with a VPC firewall rule that permits ingress only from the application tier's CIDR, combined with withholding external IP addresses from database instances, directly implements both the least-privilege reachability requirement and the no-public-internet mandate. No additional networking products are needed because VPC firewall rules already scope traffic by source range and target, and internal-only addressing keeps the tier off the public internet.

Exam trap

The trap here is assuming that removing external IP addresses alone isolates a tier, when reachability from other subnets still depends on firewall rule scoping.

581
MCQmedium

A security engineer wants to configure Identity-Aware Proxy (IAP) for an HTTPS load-balanced application to enforce zero-trust access. Users will authenticate with their Google accounts. What is the minimum set of IAM roles needed for a user to access the application behind IAP?

A.roles/iam.serviceAccountUser
B.roles/iap.tunnelResourceAccessor
C.roles/iap.httpsResourceAccessor
D.roles/compute.viewer
AnswerC

roles/iap.httpsResourceAccessor grants a principal the ability to reach an IAP-protected HTTPS resource, satisfying the minimum-access requirement. It is the sole role needed for end users; roles/iap.admin and related roles govern configuration, not access, so they are unnecessary here.

Why this answer

To access an application protected by IAP over HTTPS, a user must have the IAP-secured Web App User role (roles/iap.httpsResourceAccessor) on the resource. This role grants permission to access the resource through IAP. The other roles are not sufficient: roles/iam.serviceAccountUser is for managing service accounts, roles/iap.tunnelResourceAccessor is for TCP forwarding, and roles/compute.viewer only allows viewing Compute Engine resources, not accessing the application.

582
Multi-Selectmedium

An organization wants to ensure that all Compute Engine instances in a project are patched with the latest security updates. They also want to enforce a custom configuration (e.g., disable root SSH login) across all instances. Which TWO Google Cloud services should they use together?

Select 2 answers
A.Cloud Monitoring
B.OS Config patch management
C.Cloud Deployment Manager
D.OS Config OS policies
E.Cloud Asset Inventory
AnswersB, D

OS Config patch management automates security update deployment across Compute Engine instances, satisfying the patching requirement. It operates via the OS Config agent on each VM, applying patch jobs on schedules you define. However, it alone cannot enforce the custom configuration; that needs OS Policy assignment, which is why pairing both services is required.

Why this answer

Option B, OS Config patch management, is correct because it is the Google Cloud service that lets you scan and automatically apply OS security patches to Compute Engine instances across a project, satisfying the requirement to keep all instances patched with the latest security updates. Option D, OS Config OS policies, is correct because it lets you define and enforce a custom desired-state configuration (such as disabling root SSH login via an OS policy assignment) across all instances in the project. Together, patch management handles patching while OS policies enforce the custom configuration, which is exactly the combined outcome the organization wants.

Option A, Cloud Monitoring, is not correct because it only observes metrics, logs, and alerts; it does not patch or enforce configuration. Option C, Cloud Deployment Manager, is not correct because it is an infrastructure-as-code deployment tool for provisioning resources, not for ongoing OS patching or enforcing in-guest configuration. Option E, Cloud Asset Inventory, is not correct because it only inventories and tracks cloud assets and their metadata; it cannot patch instances or apply OS-level policies.

Exam trap

PCA often tests the distinction between infrastructure provisioning (Deployment Manager) and ongoing configuration management (OS Config), causing candidates to pick Deployment Manager for enforcement tasks.

583
MCQmedium

A retail company runs an e-commerce platform on GKE. The SRE team wants to measure the error budget for a service level objective (SLO) defined as the proportion of requests served with HTTP 2xx or 3xx status over a 28-day window. They need a monitoring configuration that computes the burn rate and alerts when the budget is being consumed too quickly, while avoiding noisy alerts during brief spikes. What should they do?

A.Create an alerting policy on a log-based metric that counts 5xx responses and alert when the count exceeds a static threshold.
B.Use Cloud Monitoring SLO monitoring to define the request-based SLO, then create a multi-window, multi-burn-rate alerting policy on that SLO.
C.Export request metrics to BigQuery and run a scheduled query that emails the team when the 28-day success ratio drops below the target.
D.Create a Cloud Monitoring uptime check on the service endpoint and alert when two consecutive checks fail.
AnswerB

Cloud Monitoring SLO monitoring supports request-based SLOs and calculates error budgets and burn rates. A multi-window, multi-burn-rate alerting policy fires on fast and slow burn conditions, which reduces noise from brief spikes while still catching sustained budget consumption. This matches the requirement to alert on rapid budget depletion with fewer false positives.

Why this answer

Cloud Monitoring SLO monitoring natively models request-based SLOs, tracks error budgets, and supports burn-rate alerting. Multi-window, multi-burn-rate policies combine a short window for fast detection with a longer window for confirmation, which filters out brief spikes. This is the supported, least-effort way to alert on rapid budget consumption for a 28-day SLO.

Exam trap

The trap here is treating a static threshold on error counts or a simple uptime check as equivalent to burn-rate alerting, when only SLO-based monitoring accounts for the request ratio over the SLO window.

584
Multi-Selecthard

Which THREE actions can help reduce costs for a BigQuery workload that runs frequent, ad-hoc analytical queries on a large dataset?

Select 3 answers
A.Enable automatic schema detection to avoid manual schema definition.
B.Partition the table by a date or timestamp column.
C.Create materialized views for common aggregation queries.
D.Use clustering on columns frequently used in filter clauses.
E.Use flat-rate pricing with reserved slots.
AnswersB, C, D

Partitioning by date or timestamp prunes scanned data, so ad-hoc analytical queries read only relevant partitions rather than the full table. This directly reduces bytes processed, and BigQuery bills on-demand queries by data scanned, satisfying the cost-reduction requirement for frequent large-dataset analysis.

Why this answer

Option B is correct because partitioning the table by a date or timestamp column lets BigQuery prune irrelevant partitions, so ad-hoc queries that filter on that column scan far less data and incur lower on-demand query costs. Option C is correct because materialized views precompute and cache the results of common aggregation queries, so repeated ad-hoc aggregations read the much smaller materialized view instead of rescanning the full large dataset. Option D is correct because clustering on columns frequently used in filter clauses co-locates related data in storage blocks, allowing BigQuery to skip blocks that don't match the filter and further reduce bytes scanned.

Option A is not correct because automatic schema detection only simplifies loading data and has no effect on query cost. Option E is not correct because flat-rate pricing with reserved slots provides predictable capacity billing rather than reducing the cost of a sporadic ad-hoc query workload, which is typically cheaper on on-demand pricing.

Exam trap

Google Cloud often tests the distinction between cost-reduction techniques that reduce bytes scanned (partitioning, clustering, materialized views) versus pricing model choices (flat-rate vs. on-demand), leading candidates to mistakenly select flat-rate pricing as a cost-saving action for ad-hoc queries.

585
MCQmedium

A retail company runs a stateful PostgreSQL database on a Compute Engine VM in project prod-db. The database writes nightly backups to a regional Cloud Storage bucket in a separate project, backup-archive. The security team requires that the VM's service account can upload objects but must not be able to delete or overwrite existing backups. Which IAM configuration should the architect implement?

A.Grant roles/storage.legacyBucketWriter on the bucket to the VM's service account.
B.Grant roles/storage.objectCreator on the bucket to the VM's service account.
C.Grant roles/storage.objectViewer on the bucket to the VM's service account.
D.Grant roles/storage.objectAdmin on the bucket to the VM's service account.
AnswerB

roles/storage.objectCreator allows only the storage.objects.create permission, so the VM can upload new backup objects but cannot delete or overwrite existing ones. Applying it at the bucket level scopes the permission precisely to backup-archive, satisfying the least-privilege requirement while still allowing the nightly uploads to succeed.

Why this answer

The VM's service account needs write-only access to the backup bucket, which maps exactly to the storage.objects.create permission contained in the objectCreator role. Applying that role on the specific bucket limits the grant to backup-archive and prevents deletion or overwriting of existing backups. Broader roles such as objectAdmin or legacyBucketWriter include delete and overwrite permissions that violate the immutability requirement.

Exam trap

The trap here is assuming that any write-capable Storage role is equivalent and overlooking that objectAdmin and legacyBucketWriter also grant delete and overwrite permissions that break the immutability requirement.

586
MCQeasy

A startup is migrating its on-premises MySQL database (5 TB) to Cloud SQL. The database is mission-critical and downtime must be minimized. Which migration service should they use to reduce downtime?

A.Transfer Appliance
B.gcloud sql import command
C.Storage Transfer Service
D.Database Migration Service (DMS)
AnswerD

Database Migration Service uses continuous replication to keep the target Cloud SQL instance synchronised with the source MySQL database, then performs a brief cutover. This minimises downtime for the mission-critical 5 TB database, satisfying the stem's constraint.

Why this answer

Database Migration Service (DMS) supports continuous replication from on-premises MySQL to Cloud SQL, minimizing downtime. Other options like Transfer Appliance or Storage Transfer Service are for file transfers, not live databases.

587
MCQhard

A company is migrating a legacy application to Google Cloud. The application requires a shared file system that can be accessed by multiple Compute Engine instances simultaneously. The file system must be POSIX-compliant, highly available, and scalable. The company wants to minimize management overhead. Which solution should they use?

A.Cloud Storage with a Cloud Storage FUSE mount
B.Filestore
C.Persistent Disk with multi-writer mode
D.Local SSD
AnswerB

Filestore is a fully managed, POSIX-compliant file system service that provides shared file storage for Compute Engine instances. It offers high availability and scalability, and requires minimal management overhead. It supports NFSv3 and is ideal for legacy applications that need a shared file system. This meets all requirements.

Why this answer

Filestore is a managed NFS file system that provides POSIX-compliant shared storage for Compute Engine instances. It is highly available, scalable, and requires minimal management. Cloud Storage FUSE is not fully POSIX-compliant, Persistent Disk multi-writer is not for shared file systems, and Local SSD is not shared.

Exam trap

The trap here is assuming that Cloud Storage FUSE or Persistent Disk multi-writer can serve as a POSIX-compliant shared file system, but they have limitations.

588
MCQmedium

A company is using Cloud Load Balancing with backend services across multiple regions. They notice that traffic is not being evenly distributed and some backends are overloaded. Which configuration should they check?

A.Session affinity settings
B.Firewall rules
C.Cloud CDN caching
D.Health check frequency
AnswerA

Session affinity pins each client to one backend for the session's duration, so new connections bypass least-loaded selection and concentrate on whichever backend the client first reached. Checking this setting satisfies the stem's uneven distribution constraint: disabling or shortening affinity restores per-connection balancing across regional backends.

Why this answer

Session affinity (sticky sessions) directs all requests from a single client to the same backend instance. If enabled, this can cause uneven load distribution because certain clients may generate disproportionately more traffic, overloading their pinned backends while others remain underutilized. Disabling or properly configuring session affinity allows the load balancer to distribute requests based on its default algorithm (e.g., round-robin or least-connections), improving balance across backends.

Exam trap

Google Cloud often tests the misconception that health checks or firewall rules are responsible for load distribution, when in fact session affinity is the primary configuration that can cause uneven traffic patterns by overriding the default balancing algorithm.

How to eliminate wrong answers

Option B is wrong because firewall rules control allowed traffic to/from backends but do not influence how the load balancer distributes incoming requests among healthy instances. Option C is wrong because Cloud CDN caching reduces load on backends by serving cached content at edge locations, but it does not affect the distribution of requests that reach the load balancer's backend pool. Option D is wrong because health check frequency determines how often the load balancer probes backend health, affecting failover speed but not the balancing algorithm or distribution of traffic among healthy backends.

589
Multi-Selectmedium

A healthcare analytics company is designing the Google Cloud landing zone for a new HIPAA-regulated workload. The security team requires that no project in the organization can enable a public Cloud Storage bucket by accident, and that all data-at-rest in BigQuery is encrypted with keys the company rotates on its own schedule. Which two design decisions should the architect include? (Choose two.)

Select 2 answers
A.Create a Cloud KMS keyring in each region where BigQuery datasets reside, and set a default CMEK on each dataset
B.Enable uniform bucket-level access on every bucket through an organization policy constraint
C.Grant the Storage Admin role only to a small group of platform engineers at the organization level
D.Use Google-managed encryption keys for BigQuery and rely on the default rotation performed by Google
E.Apply an organization policy constraint with storage.publicAccessPrevention enforced at the organization node
AnswersA, E

BigQuery datasets accept a default customer-managed encryption key, so every table created in the dataset is encrypted with that key without per-table configuration. Placing keyrings in the same regions as the datasets satisfies data-residency expectations, and the company controls rotation schedule and key destruction through Cloud KMS.

Why this answer

Two controls map directly to the stated requirements. The storage.publicAccessPrevention organization policy is a preventive, inherited guardrail that blocks public bucket grants anywhere in the organization. A default CMEK on each BigQuery dataset, with regional keyrings, gives the company control over the rotation schedule and key lifecycle.

Uniform bucket-level access, Google-managed keys, and narrow role grants do not enforce either requirement.

Exam trap

The trap here is treating uniform bucket-level access as a public-access control, when it only removes object ACLs and still permits allUsers IAM bindings.

590
MCQeasy

A media company wants to serve publicly available images and videos to a global audience with low latency. Which Google Cloud service should they primarily use?

A.Cloud Storage with public bucket serving the files.
B.Cloud CDN with Cloud Storage as the origin.
C.Cloud Run with a container that serves the files.
D.Compute Engine with an HTTP server.
AnswerB

Cloud CDN caches publicly available image and video content at Google's global edge points of presence, so requests are served from locations near each user. Using Cloud Storage as the origin keeps objects durable and cheap, while the CDN layer satisfies the low-latency global delivery constraint.

Why this answer

Cloud CDN with Cloud Storage as the origin is the correct choice because it uses Google's global edge cache to serve publicly available images and videos from Cloud Storage, minimizing latency for a global audience. Cloud CDN caches content at edge locations worldwide, reducing the round-trip time to the origin bucket, while Cloud Storage provides scalable, durable object storage. This combination is purpose-built for delivering static content with low latency and high throughput.

Exam trap

The trap here is that candidates often choose Cloud Storage with a public bucket (Option A) because it seems simplest, overlooking that Cloud CDN is required to achieve global low-latency delivery by caching content at edge locations.

How to eliminate wrong answers

Option A is wrong because a public Cloud Storage bucket serves files directly from the bucket's regional location, which does not provide global edge caching, resulting in higher latency for users far from the bucket's region. Option C is wrong because Cloud Run is a serverless compute platform designed for running containerized applications, not optimized for serving static files at scale; it lacks built-in edge caching and would incur unnecessary compute costs and cold-start latency. Option D is wrong because Compute Engine with an HTTP server requires manual scaling, maintenance, and lacks integrated global caching, making it inefficient and costly for serving static content to a global audience compared to a managed CDN solution.

591
MCQhard

A financial services company is migrating a monolithic Java application to Google Kubernetes Engine (GKE) for improved scalability and reliability. The application serves real-time trading data and has strict latency requirements. Post-migration, the team observes frequent pod restarts due to OutOfMemory (OOM) errors, increased latency during peak trading hours, and occasional database connection timeouts. The current setup uses a single GKE cluster with a node pool of n1-standard-4 machines, a stateless application deployed as a Deployment with resource requests and limits set to 512 Mi memory and 1 CPU. The database is a Cloud SQL PostgreSQL instance with 2 vCPUs and 7.5 GB memory, and applications connect using a hardcoded connection string. The team wants to ensure reliable operation under load and during node maintenance events. Which course of action best addresses the reliability issues?

A.Adjust resource requests to 1 Gi memory and 2 CPU, set limits to 2 Gi and 4 CPU, create an HPA based on a custom metric (e.g., requests per second), enable cluster autoscaler, implement Cloud SQL connection pooling via Cloud SQL Auth Proxy with a max connection pool size, and configure PDB with maxUnavailable 1.
B.Enable GKE node auto-upgrade, configure Pod Disruption Budgets (PDB) with minAvailable 1, and set readiness probes to check application health.
C.Migrate the database to a StatefulSet in GKE with persistent volumes, increase node count to 10, and enable cluster autoscaler.
D.Increase memory limits to 2 Gi and CPU to 2, add Horizontal Pod Autoscaler (HPA) based on CPU utilization, and implement connection pooling using Cloud SQL Auth Proxy.
AnswerA

Raising memory requests and limits above the current 512 Mi stops OOM kills, while the HPA, cluster autoscaler, Cloud SQL Auth Proxy pooling and PDB together address peak-load latency, connection exhaustion and node maintenance disruption — the four reliability symptoms named in the stem.

Why this answer

Best addresses all reliability issues. Adjusting resource requests to 1 Gi memory and 2 CPU ensures proper scheduling, while limits of 2 Gi and 4 CPU prevent OOM errors. The HPA based on custom metrics (e.g., requests per second) scales pods proactively during peak trading hours.

Cluster autoscaler handles node capacity, and Cloud SQL connection pooling via Cloud SQL Auth Proxy with a max pool size prevents database connection timeouts. Finally, a PDB with maxUnavailable 1 ensures availability during node maintenance. Option B misses resource tuning, autoscaling, and connection pooling.

Option C unnecessarily moves the database to GKE, increasing complexity and losing managed DB benefits. Option D lacks custom metric HPA, cluster autoscaler, and PDB, leaving gaps in scalability and maintenance handling.

592
MCQmedium

Your team manages a service with a 99.9% uptime SLO over a 30-day window. The error budget for this period is 43 minutes. In the first week, outages consumed 30 minutes of the budget. You are planning a new release. What should you do?

A.Reduce the SLO to 99.8% to increase the error budget.
B.Proceed with the release because the remaining budget is sufficient.
C.Delay the release and focus on improving reliability to rebuild the error budget.
D.Release the feature but only to a small percentage of users.
AnswerC

Conservative approach: wait until more error budget is earned (e.g., through flawless operation) before releasing.

Why this answer

With only 13 minutes of error budget remaining after the first week, proceeding with the release (Option B) risks exhausting the budget entirely from any unforeseen issues, violating the 99.9% SLO. Delaying the release (Option C) allows the team to focus on reliability improvements, such as implementing canary deployments, adding circuit breakers, or enhancing monitoring with tools like Prometheus and Grafana, to rebuild the error budget over the remaining 23 days. This aligns with the principle of using error budgets to balance innovation with reliability, as defined in Google's SRE practices.

Exam trap

Google Cloud often tests the misconception that a canary release (Option D) is always safe, but the trap here is that it still consumes error budget and does not solve the underlying reliability deficit when the budget is already critically low.

How to eliminate wrong answers

Option A is wrong because reducing the SLO to 99.8% would increase the error budget to 86.4 minutes, but this is a reactive measure that lowers the reliability target rather than addressing the root cause of the outages; it also violates the principle of maintaining a consistent SLO commitment to customers. Option B is wrong because proceeding with the release with only 13 minutes of error budget left is reckless—any minor incident could exhaust the budget, leading to SLO violations and potential service credits or customer dissatisfaction, especially since the first week already consumed 70% of the budget. Option D is wrong because releasing to a small percentage of users (e.g., a canary deployment) is a valid risk mitigation strategy, but it does not address the fact that the error budget is nearly depleted; even a small-scale release could introduce bugs that consume the remaining budget, and the team should first stabilize the service before any new changes.

593
MCQmedium

A company is migrating a legacy monolithic application to Google Cloud. The application runs on a single VM and uses a local MySQL database. The goal is to minimize changes to the application code while improving availability. Which strategy should the company use?

A.Use a managed instance group for the application VM and store the database on a persistent disk attached to the primary instance.
B.Re-architect the application into microservices and use Cloud Run for stateless components.
C.Lift and shift the VM to Compute Engine, and migrate the database to Cloud SQL with a failover replica.
D.Containerize the application and deploy on Google Kubernetes Engine (GKE) with Cloud Spanner as the database.
AnswerC

Lifting the VM to Compute Engine preserves the application unchanged, minimising code modifications. Migrating MySQL to Cloud SQL with a failover replica provides automatic failover to a standby in another zone, satisfying the availability goal without application rewrites.

Why this answer

It minimizes code changes by lifting the application VM to Compute Engine as-is, while migrating the local MySQL database to Cloud SQL with a failover replica. This improves availability through Cloud SQL's managed automatic failover to a standby replica in a different zone, without requiring application code changes to the database connection logic (the application can continue using the same MySQL protocol).

Exam trap

The trap here is that candidates often choose Option A, mistakenly believing that a managed instance group with a persistent disk provides database high availability, but they overlook that the persistent disk cannot be shared across instances in a managed instance group without additional orchestration (e.g., regional persistent disks or a clustered filesystem), and the database process itself is not automatically failed over.

How to eliminate wrong answers

Option A is wrong because storing the database on a persistent disk attached to a single instance in a managed instance group does not provide high availability for the database; if the primary instance fails, the persistent disk cannot be attached to a new instance without manual intervention, and the database state is lost or requires complex recovery. Option B is wrong because re-architecting into microservices and using Cloud Run requires significant application code changes, contradicting the goal of minimizing changes to the application code. Option D is wrong because containerizing and deploying on GKE with Cloud Spanner requires substantial application code changes (Cloud Spanner uses a different SQL dialect and connection protocol than MySQL) and introduces unnecessary complexity, violating the requirement to minimize code changes.

594
MCQeasy

A startup deploys a web application on Compute Engine instances behind an HTTP load balancer. They need to handle unpredictable spikes in traffic with minimal operational overhead. What is the simplest scaling approach?

A.Set up a Kubernetes cluster with horizontal pod autoscaling
B.Use a managed instance group with autoscaling based on CPU utilization
C.Migrate the application to Cloud Run
D.Add more instances manually during peak hours
AnswerB

A managed instance group with CPU-based autoscaling adds or removes Compute Engine instances automatically as demand shifts, absorbing unpredictable spikes without manual intervention. This satisfies the minimal operational overhead constraint while the HTTP load balancer distributes traffic across the group.

Why this answer

Using a managed instance group with autoscaling automatically adds/removes instances based on demand, requiring minimal manual intervention. Other options either require more complex setup or are not optimal.

595
MCQmedium

A healthcare company stores sensitive patient data in Cloud Storage. They must ensure that data is encrypted at rest with a key that they manage, and that the key is automatically rotated every 90 days. They also need to be able to audit key usage. Which approach should they take?

A.Use a Cloud HSM key with a rotation period of 90 days, and configure the bucket with a retention policy that enforces encryption.
B.Use Customer-Supplied Encryption Keys (CSEK) with a 90-day rotation managed by the application, and enable Cloud Audit Logs for Cloud Storage.
C.Create a Cloud KMS key with a rotation period of 90 days, grant the Cloud Storage service account encrypt/decrypt permissions on the key, and configure the bucket to use that key as the default encryption key.
D.Create a Cloud KMS key with a rotation period of 90 days, and use an organization policy constraint to require CMEK on all Cloud Storage buckets.
AnswerC

Cloud KMS supports automatic key rotation, which can be set to 90 days. Granting the Cloud Storage service account permissions on the key allows the bucket to use it for encryption. Setting the bucket default key ensures all objects are encrypted with the CMEK. Cloud KMS audit logs capture key usage, meeting the auditing requirement.

Why this answer

Cloud KMS provides automatic key rotation and audit logging. By setting a bucket default key, all objects are encrypted with the CMEK. Granting the Cloud Storage service account encrypt/decrypt permissions is required for the bucket to use the key.

This approach meets encryption, rotation, and auditing requirements with minimal overhead.

Exam trap

The trap here is assuming that organization policy constraints automatically apply a specific CMEK, when they only enforce that some CMEK is used.

596
MCQhard

A company wants to deploy a microservices architecture on Google Cloud. They need a service mesh to manage traffic, security, and observability across services. They also want to run workloads on both GKE and Compute Engine. Which solution should they use?

A.Cloud Service Mesh (Anthos Service Mesh)
B.Cloud Run for Anthos
C.Istio open-source installation on GKE
D.Traffic Director
AnswerA

Cloud Service Mesh extends across GKE and Compute Engine via Anthos, satisfying the hybrid workload constraint. It provides mTLS, traffic routing and telemetry through sidecar proxies, unlike Istio self-managed or GKE-only Ingress. This unified control plane manages security and observability for both environments without per-platform tooling.

Why this answer

Cloud Service Mesh (formerly Anthos Service Mesh) is Google's managed Istio distribution that provides traffic management, mTLS security, and observability, and it explicitly supports workloads on both GKE and Compute Engine via VM enrollment. It is the only option designed for a hybrid GKE + Compute Engine service mesh. Istio OSS on GKE alone does not natively extend to Compute Engine VMs without significant custom work, and Traffic Director is a control plane for load balancing, not a full service mesh with sidecar-based security and observability.

Exam trap

PCA often tests the distinction between a service mesh (Cloud Service Mesh) and a load-balancing control plane (Traffic Director), so candidates who focus only on 'traffic management' pick Traffic Director and miss the security and observability requirements.

How to eliminate wrong answers

Option B is wrong because Cloud Run for Anthos is a serverless compute platform for running containers on GKE, not a service mesh — it does not manage traffic/security/observability across heterogeneous workloads. Option C is wrong because a self-managed Istio installation on GKE does not include Compute Engine VM support out of the box and adds operational overhead Google manages for you in Cloud Service Mesh. Option D is wrong because Traffic Director is a managed xDS control plane for global load balancing and proxyless gRPC, not a full service mesh with sidecar injection, mTLS, and telemetry for VMs and pods.

597
MCQmedium

A company is migrating 500 TB of on-premises file server data to Cloud Storage. The on-premises network has a 1 Gbps link to Google Cloud, but the migration must complete within 30 days. What is the MOST cost-effective and reliable method?

A.Use Storage Transfer Service over a dedicated interconnect
B.Deploy a VPN and use gsutil rsync
C.Use Database Migration Service
D.Use Transfer Appliance
AnswerD

Transfer Appliance ships data physically, bypassing the 1 Gbps link that would take far longer than 30 days for 500 TB. It is cost-effective for bulk offline transfer and reliable, satisfying both the deadline and cost constraints.

Why this answer

Transfer Appliance is the most cost-effective and reliable method for migrating 500 TB over a 1 Gbps link within 30 days. At 1 Gbps, transferring 500 TB would take approximately 46 days (assuming ideal conditions), exceeding the 30-day deadline. Transfer Appliance physically ships the data, bypassing network bandwidth limitations and reducing transfer time to days.

Exam trap

PCA often tests the misconception that a dedicated interconnect or VPN can overcome bandwidth limitations for large transfers within tight deadlines. Candidates may overlook the physical transfer option when network speeds are insufficient.

How to eliminate wrong answers

Option A is wrong because Storage Transfer Service over a dedicated interconnect still relies on network bandwidth; even with a dedicated 1 Gbps link, the transfer would take over 46 days, missing the deadline. Option B is wrong because a VPN adds encryption overhead and typically reduces throughput, making the transfer even slower. Option C is wrong because Database Migration Service is for databases, not file server data.

598
MCQeasy

An engineer wants to store a database password securely and allow a Cloud Run service to access it. Which GCP service should they use?

A.Secret Manager
B.Cloud Storage
C.Cloud Key Management Service (KMS)
D.Firestore
AnswerA

Secret Manager stores credentials encrypted at rest and exposes them through IAM-controlled API calls, so the Cloud Run service account retrieves the database password at runtime rather than embedding it in code or environment variables. This directly satisfies the requirement for secure storage with service-level access control.

Why this answer

Secret Manager is designed to securely store and manage sensitive data like database passwords, API keys, and certificates. It provides versioning, access control, and audit logging, and integrates with Cloud Run to inject secrets as environment variables or mounted volumes.

Exam trap

PCA often tests the difference between Secret Manager and KMS: candidates may choose KMS for storing secrets, but KMS is for key management, not secret storage.

How to eliminate wrong answers

Option B is wrong because Cloud Storage is for object storage and lacks the security features, access controls, and versioning specifically designed for secrets. Option C is wrong because Cloud KMS is for managing encryption keys, not for storing arbitrary secrets; it encrypts data but does not provide a secret storage mechanism. Option D is wrong because Firestore is a NoSQL document database for application data, not for secure secret storage; it lacks the specialized security and access patterns for secrets.

599
MCQhard

Your team is following an incident management process. After resolving a major incident, you are tasked with conducting a postmortem. What is the PRIMARY goal of the postmortem process in Google Cloud's recommended approach?

A.Understand the root cause and implement changes to prevent recurrence
B.Document the incident timeline and communicate it to stakeholders
C.Calculate the financial impact and bill the responsible team
D.Identify the individual responsible for the incident and take corrective action
AnswerA

Google Cloud's postmortem process is blameless and focuses on identifying the underlying root cause of the incident, then implementing corrective actions so the same failure cannot recur. This satisfies the primary goal of preventing recurrence rather than assigning fault.

Why this answer

Google's recommended postmortem process, derived from SRE practices, is blameless and focused on learning: the primary goal is to understand the root cause(s) of the incident and implement systemic changes to prevent recurrence. It emphasizes identifying contributing factors across technology, process, and human dimensions rather than assigning fault. Documentation and communication are outputs, not the primary goal, and financial or punitive outcomes are explicitly excluded.

Exam trap

PCA often tests the blameless principle — candidates pick the option about identifying the responsible individual, but Google's postmortem explicitly rejects blame in favor of systemic learning.

How to eliminate wrong answers

Option B is wrong because documenting the timeline and communicating to stakeholders is a necessary output of the postmortem, but it is not the primary goal — the goal is learning and prevention, not reporting. Option C is wrong because calculating financial impact and billing a team contradicts Google's blameless culture and is not part of the postmortem process; cost analysis may occur separately but is not the objective. Option D is wrong because identifying an individual to blame and taking corrective action is explicitly antithetical to Google's blameless postmortem philosophy, which holds that blaming individuals discourages transparency and hides systemic issues.

600
MCQeasy

A company deploys a web application on Compute Engine behind an HTTP Load Balancer. They want to ensure only healthy instances receive traffic. What should they configure?

A.Configure the instance group autoscaling based on CPU utilization
B.Configure an HTTP health check with a custom request path that returns a 200 status
C.Configure a TCP health check on port 80
D.Configure an SSL health check to verify TLS handshake
AnswerB

An HTTP health check probes a specified path and marks an instance healthy only when it returns HTTP 200, so the load balancer routes traffic exclusively to instances passing that check. This directly satisfies the requirement that only healthy instances receive traffic.

Why this answer

An HTTP health check with a custom request path that returns a 200 status allows the HTTP Load Balancer to verify that the web application is actually serving requests correctly. This ensures that only instances passing the application-level health check are considered healthy and receive traffic, preventing requests from being routed to instances that may be running but not serving the expected content.

Exam trap

The trap here is that candidates often confuse health checks with autoscaling metrics, assuming that CPU-based autoscaling alone ensures traffic is only sent to healthy instances, when in fact health checks are a separate mechanism required for load balancer traffic routing.

How to eliminate wrong answers

Option A is wrong because autoscaling based on CPU utilization manages the number of instances but does not determine which instances are healthy for traffic routing; the load balancer still needs health checks to decide which instances to send traffic to. Option C is wrong because a TCP health check on port 80 only verifies that the TCP port is open, not that the web application is responding correctly; an instance could have a listening port but return errors or be unresponsive at the application layer. Option D is wrong because an SSL health check verifies the TLS handshake, which is unnecessary for HTTP traffic and does not validate the application's response; it is designed for HTTPS backends, not plain HTTP.

Page 7

Page 8 of 11

Page 9

All pages