Courseiva

Google Professional Cloud Architect (PCA) — Questions 601–675

807 questions total · 11pages · All types, answers revealed

Page 8

Page 9 of 11

Page 10
601
MCQhard

A healthcare analytics company stores sensitive patient datasets in a Cloud Storage bucket in the us-central1 region. A new regulation requires that the data never leave the United States and that access be restricted to a defined set of projects. The security team wants a guardrail that prevents any future project from reading the bucket unless it is explicitly authorized, while keeping administration simple. What should the architect implement?

A.Create an organization policy with the constraints/gcp.resourceLocations constraint set to allow only us-central1, and attach it to the organization node.
B.Enable Object Versioning and a retention policy on the bucket, then share the bucket with the authorized projects using signed URLs.
C.Create a VPC Service Controls perimeter around the authorized projects with the Cloud Storage bucket as a protected resource, and grant access only through the perimeter.
D.Apply a bucket-level IAM policy that grants roles/storage.objectViewer only to the authorized projects' service accounts and enable uniform bucket-level access.
AnswerC

VPC Service Controls creates a security perimeter that blocks access to protected services such as Cloud Storage from outside the perimeter, regardless of IAM grants. Placing the bucket and the authorized projects inside the perimeter ensures that any future project outside it cannot read the data even if it receives an IAM role, which directly meets the guardrail requirement while keeping administration centralized.

Why this answer

The regulation requires both a location boundary and a hard restriction on which projects may read the data. VPC Service Controls builds a perimeter that denies access to protected services from outside the perimeter, so even a project that later receives an IAM role cannot read the bucket unless it is inside the perimeter. This gives a centralized guardrail that IAM or resource location constraints alone cannot provide.

Exam trap

The trap here is treating an IAM policy or a resource location constraint as a complete data-residency guardrail, when only a VPC Service Controls perimeter blocks access from projects outside an authorized boundary.

602
Multi-Selectmedium

A healthcare company is planning a Google Cloud landing zone for a new regulated workload. They must enforce organization-wide guardrails, centralize billing visibility, and give each business unit autonomy over its own projects. The security team needs to apply policies that cannot be overridden by project owners. Which two design choices should you recommend? (Choose two.)

Select 2 answers
A.Enable Cloud Billing export to BigQuery and create a shared log sink to a central project for audit and cost analysis.
B.Place all projects directly under the organization root and rely on project-level IAM to enforce security policies.
C.Create a folder hierarchy under the organization that mirrors business units, and apply organization policies at the folder level.
D.Give each business unit the Organization Administrator role so they can manage their own projects independently.
E.Grant each business unit the Billing Account Administrator role on the shared billing account to give them billing autonomy.
AnswersA, C

Exporting billing data to BigQuery enables centralized cost analysis and chargeback reporting across all business units. A shared log sink to a central project aggregates audit logs for compliance and security monitoring. Together these provide the centralized visibility the company needs while allowing business units to manage their own projects under the folder hierarchy.

Why this answer

A folder hierarchy lets the company apply organization policies that inherit to all descendant projects and cannot be overridden by project owners, satisfying the guardrail requirement. Exporting billing data to BigQuery and centralizing logs provide the centralized billing and audit visibility. Granting broad roles like Billing Account Administrator or Organization Administrator, or flattening the hierarchy, undermines centralized control and least privilege.

Exam trap

The trap here is equating business unit autonomy with granting organization-wide or billing administrator roles, when autonomy should be delegated through folder-scoped IAM and inherited policies.

603
MCQmedium

A developer needs to build a serverless event-driven application that responds to Cloud Storage object uploads by processing the file and storing results in Firestore. Which compute service is the best fit?

A.Cloud Functions
B.App Engine Flexible Environment
C.Cloud Run for Anthos
D.Compute Engine with startup scripts
AnswerA

Cloud Functions is event-driven and serverless, so it triggers directly on Cloud Storage object-finalise events without provisioning servers. It satisfies the requirement to respond to uploads, process the file, then write results to Firestore, with automatic scaling and pay-per-invocation billing.

Why this answer

Cloud Functions is a serverless event-driven compute service that can be triggered directly by Cloud Storage events, ideal for simple processing tasks.

604
MCQmedium

A company needs to connect their on-premises data center to Google Cloud with a dedicated, low-latency connection that provides a Service Level Agreement (SLA) of 99.99% uptime. They anticipate high bandwidth usage (10 Gbps). Which connectivity option should they choose?

A.Cloud VPN with static routing
B.Cloud CDN
C.Partner Interconnect
D.Dedicated Interconnect
AnswerD

Dedicated Interconnect provides a private physical connection with a 99.99% uptime SLA and supports 10 Gbps circuits. It satisfies the stem's dedicated, low-latency, high-bandwidth requirements, unlike Partner Interconnect or Cloud VPN, which cannot guarantee that SLA.

Why this answer

Dedicated Interconnect provides a direct physical connection between the on-premises data center and Google Cloud, offering high bandwidth (10 Gbps or 100 Gbps) and a 99.99% uptime SLA. It is the most appropriate choice for a dedicated, low-latency connection with high bandwidth requirements. Partner Interconnect also offers 99.99% SLA but is provided through a service provider and may not be dedicated; however, the question specifies 'dedicated' and 10 Gbps, which aligns with Dedicated Interconnect.

Exam trap

The trap is confusing Partner Interconnect with Dedicated Interconnect; candidates may pick Partner because it also offers 99.99% SLA, but the question specifies 'dedicated' and 10 Gbps, which points to Dedicated Interconnect.

How to eliminate wrong answers

Option A is wrong because Cloud VPN with static routing uses the public internet and does not provide a dedicated connection or a 99.99% SLA; it typically offers 99.9% SLA and lower bandwidth. Option B is wrong because Cloud CDN is a content delivery network for caching web content, not a connectivity option between on-premises and Google Cloud. Option C is wrong because Partner Interconnect, while offering 99.99% SLA, is not a dedicated connection—it uses a partner's network and may not provide the same level of dedication as Dedicated Interconnect, and the question emphasizes 'dedicated'.

605
MCQmedium

A company uses Cloud Build to deploy a Java application to Artifact Registry. They want to automatically trigger a build only when changes are pushed to the 'main' branch in their Cloud Source Repository. Which configuration should they use?

A.Configure a Cloud Function that listens for Pub/Sub messages from Cloud Source Repo and calls Cloud Build API
B.Create a Cloud Build trigger with an included branch filter set to '^main$'
C.Create a Cloud Scheduler job that runs a Pub/Sub push to Cloud Build every hour
D.Use a Cloud Build build step that checks the branch name and aborts if not main
AnswerB

An included branch filter using the regex ^main$ restricts the trigger to pushes on the main branch only, satisfying the stem's requirement. Without that filter, the trigger would fire on every branch push, causing unwanted builds.

Why this answer

Cloud Build triggers natively support branch filtering via the `included` or `ignored` branch filters. Setting the included branch filter to the regex `^main$` ensures the trigger only fires when a push event occurs on the `main` branch. This is the intended, serverless, and declarative way to achieve branch-specific builds without custom code or polling.

The `^` and `$` anchors guarantee an exact match, preventing accidental triggers on branches like `feature/main` or `main-dev`.

Exam trap

PCA often tests the difference between event-driven triggers and polling mechanisms, and candidates may overcomplicate the solution by choosing custom Cloud Functions or build-step checks instead of using the native branch filter feature of Cloud Build triggers.

How to eliminate wrong answers

Option A is wrong because it introduces unnecessary complexity and latency by using a Cloud Function to relay Pub/Sub messages to the Cloud Build API, whereas Cloud Build triggers already integrate directly with Cloud Source Repositories and support branch filtering natively. Option C is wrong because a Cloud Scheduler job that runs hourly is a time-based poll, not an event-driven trigger; it would build regardless of whether changes were pushed, and it cannot filter by branch. Option D is wrong because a build step that checks the branch name runs only after the build has already started, wasting resources and time; it also requires custom scripting and does not prevent the trigger from firing on other branches.

606
MCQeasy

A team wants to define an SLO for a service that requires 99.9% availability over a 30-day window. They need to measure the ratio of successful requests to total requests. Which SLI should they use?

A.Request success rate
B.SRE
C.Request latency
D.Error budget
AnswerA

Request success rate measures the proportion of successful requests against total requests, expressed as a ratio. This directly satisfies the stem's 99.9% availability SLO over a 30-day window, since availability is defined by served versus total valid requests.

Why this answer

An SLI is a measure of service performance. For availability, the standard SLI is the proportion of successful requests (e.g., HTTP 2xx) to total requests. Latency SLI measures response times.

Error budget is derived from SLO. SRE is the practice.

607
Multi-Selecteasy

Which THREE practices are recommended for organizing projects in a Google Cloud organization?

Select 3 answers
A.Create a separate project to hold organization policies.
B.Use a separate project for each environment (e.g., development, staging, production).
C.Apply IAM policies at the folder level instead of the organization level when possible.
D.Use a shared VPC host project for multiple service projects to centralize network management.
E.Consolidate all production resources into a single project for simplicity.
AnswersB, C, D

Separate projects isolate environments and allow independent management and billing.

Why this answer

Using separate projects for each environment (development, staging, production) enforces resource isolation, prevents accidental cross-environment changes, and allows independent IAM policies, billing, and quotas. This aligns with Google Cloud's recommended resource hierarchy best practices for managing lifecycle and security boundaries.

Exam trap

The trap here is that candidates often confuse the purpose of organization policies with project-level resources, mistakenly thinking a separate project is needed to hold policies, when in fact policies are inherited through the resource hierarchy (organization → folder → project).

608
MCQhard

A government agency must run sensitive analytics in BigQuery while ensuring that analysts can see aggregated results but never the raw values of specific personal data columns. Analysts use SQL and must not be able to bypass the restriction by writing their own queries. The agency also needs to record who queried which columns. Which combination should the architect use?

A.Encrypt the sensitive columns with a customer-managed key and grant analysts the crypto key decrypter role only for aggregate queries.
B.Create a view that omits the sensitive columns and grant analysts access only to the view, revoking access to the base table.
C.Grant analysts roles/bigquery.dataViewer on the dataset and rely on BigQuery's default access controls to prevent them from seeing sensitive columns.
D.Create a policy tag taxonomy in Data Catalog, assign a policy tag to the sensitive columns, and grant analysts the fine-grained reader role on the tag so they see masked values, while column access is recorded in audit logs.
AnswerD

Policy tags in Data Catalog applied to specific columns let BigQuery return masked values to principals who hold only the fine-grained reader role on the tag, while fully privileged principals see raw data. Because the masking is enforced at the column level by BigQuery itself, analysts cannot circumvent it by rewriting SQL. Data access audit logs then record the column-level reads for the compliance requirement.

Why this answer

Column-level security in BigQuery is delivered through policy tags in Data Catalog. Assigning a policy tag to the sensitive columns and granting analysts only the fine-grained reader role on that tag causes BigQuery to return masked values for those columns while still allowing aggregation over the rest of the table. Because enforcement happens inside the query engine, analysts cannot bypass it with custom SQL, and column access is captured in data access audit logs.

Exam trap

The trap here is assuming that dataset-level roles or views prevent analysts from reading sensitive columns, when only column-level policy tags enforce masking inside the query engine.

609
Multi-Selectmedium

A company wants to improve the reliability of their microservices architecture on Google Cloud. Which TWO practices should they implement? (Choose 2)

Select 2 answers
A.Design with a single point of failure for simplicity
B.Implement retry with exponential backoff
C.Use synchronous communication between all services
D.Implement circuit breaker pattern
E.Disable health checks to reduce latency
AnswersB, D

Retry with backoff handles transient failures without overwhelming the system.

Why this answer

B is correct because implementing retry with exponential backoff allows transient failures (e.g., network timeouts, temporary service unavailability) to be handled gracefully by automatically retrying the request after increasing delays, reducing load on the recovering service. This pattern is essential in microservices on Google Cloud to improve reliability without overwhelming downstream dependencies.

Exam trap

Google Cloud often tests the misconception that synchronous communication is more reliable because it provides immediate feedback, but in distributed systems, asynchronous patterns and resilience mechanisms like retries and circuit breakers are actually critical for reliability.

610
MCQeasy

A company wants to ensure that all access to their Cloud Storage bucket is logged for compliance purposes. Which type of audit log should they enable?

A.Admin Activity audit logs
B.Data Access audit logs
C.System Event audit logs
D.Access Transparency logs
AnswerB

Data Access audit logs record read and write operations on Cloud Storage objects, capturing who accessed bucket data and when. This satisfies the compliance requirement to log all access, unlike Admin Activity logs which only cover configuration changes.

Why this answer

Data Access audit logs (Option B) are required to log every API call that reads, writes, or deletes data in a Cloud Storage bucket, such as object GETs and PUTs. Admin Activity logs only record configuration changes, not data access, so they would not capture the read/write operations needed for compliance logging.

Exam trap

Candidates often confuse Admin Activity logs with Data Access logs, thinking that Admin Activity logs cover data access operations, but they only record configuration changes; Data Access logs are needed for actual data access auditing.

How to eliminate wrong answers

Option A is wrong because Admin Activity audit logs record only metadata or configuration changes (e.g., creating or deleting a bucket), not the actual data access events like reading or writing objects. Option C is wrong because System Event audit logs capture Google Cloud system actions (e.g., automatic maintenance or VM live migration), not user-driven data access to Cloud Storage. Option D is wrong because Access Transparency logs provide logs of Google personnel accessing your data, not your own users' access to Cloud Storage objects.

611
Multi-Selectmedium

A healthcare company must store patient documents in Cloud Storage. Compliance requires that the data be encrypted with keys the company controls and that key usage be centrally audited and revocable. The architect plans to use Cloud KMS. Which two actions should the architect take to meet these requirements? (Choose two.)

Select 2 answers
A.Create a customer-supplied encryption key (CSEK) and store it in Secret Manager for each object upload.
B.Enable Cloud External Key Manager (Cloud EKM) backed by keys held in a third-party HSM.
C.Create a Cloud KMS key ring and a customer-managed encryption key (CMEK) in the same region as the bucket, and configure the bucket to use that key as its default encryption key.
D.Enable uniform bucket-level access on the bucket to force CMEK usage.
E.Grant the Cloud Storage service agent the roles/cloudkms.cryptoKeyEncrypterDecrypter role on the CMEK.
AnswersC, E

Using a CMEK as the bucket's default encryption key ensures that every object written to the bucket is encrypted with a key the company controls. Because Cloud KMS logs key operations in Cloud Audit Logs, the company gains centralized visibility and can disable or destroy the key to revoke access, satisfying both compliance requirements.

Why this answer

Meeting the compliance goals requires a customer-managed encryption key configured as the bucket's default encryption key, plus the Cloud Storage service agent holding cryptoKeyEncrypterDecrypter on that key. Together these ensure all objects are encrypted with a company-controlled key and that every key operation is recorded in Cloud Audit Logs, enabling auditing and revocation through Cloud KMS.

Exam trap

The trap here is assuming that enabling uniform bucket-level access or using customer-supplied keys provides the same central auditing and revocation as a Cloud KMS CMEK, when neither does.

612
MCQhard

A company runs a critical application on a managed instance group in a single zone. The application stores data on a zonal persistent disk. The company wants to ensure that the application can survive a zone failure with minimal data loss and automatic failover. They also want to minimize changes to the application. Which approach should they take?

A.Convert the zonal persistent disk to a regional persistent disk and configure the managed instance group to be regional.
B.Use a multi-writer persistent disk and attach it to instances in two zones.
C.Create a snapshot schedule for the zonal persistent disk and configure the managed instance group to automatically create instances from the snapshot in another zone.
D.Deploy the application on a regional managed instance group and use a Cloud Storage bucket mounted via FUSE for data storage.
AnswerA

A regional persistent disk replicates data synchronously across two zones, providing a recovery point objective (RPO) of zero and a recovery time objective (RTO) of minutes. By making the managed instance group regional, instances can be distributed across zones, and if one zone fails, the application can fail over to the other zone with the same disk. This requires minimal application changes and meets the requirements for zone failure survival and automatic failover.

Why this answer

A regional persistent disk replicates data synchronously across two zones, ensuring zero data loss on zone failure. When combined with a regional managed instance group, the application can automatically fail over to the healthy zone. This approach requires minimal changes to the application and meets the requirements for survival and automatic failover.

The other options either involve data loss or are not designed for cross-zone failover.

Exam trap

The trap here is assuming that snapshot schedules provide automatic failover or that multi-writer disks can span zones, when in fact they are zonal and not synchronous.

613
MCQhard

A company is deploying a multi-tenant SaaS application on GKE. Each tenant's data must be isolated at the network level. They want to use a single GKE cluster but ensure that pods from different tenants cannot communicate with each other. Which GCP feature should they use?

A.Istio service mesh
B.VPC Service Controls
C.Kubernetes Network Policies
D.GKE Sandbox
AnswerC

Kubernetes Network Policies are pod-level firewall rules applied within a single cluster, selecting pods by label and restricting ingress and egress. This isolates each tenant's pods so cross-tenant traffic is denied, meeting the network-level isolation constraint without separate clusters.

Why this answer

Kubernetes Network Policies are the native Kubernetes feature that allows you to define rules controlling traffic between pods. By creating NetworkPolicy resources that select pods based on labels (e.g., tenant labels), you can isolate tenants so that pods from different tenants cannot communicate with each other. This provides network-level isolation within a single GKE cluster.

Exam trap

The trap is confusing network isolation with other GKE features like GKE Sandbox (which isolates workloads at the kernel level) or Istio (which provides service mesh capabilities). The question specifically asks for network-level isolation between pods, which is achieved with Kubernetes Network Policies.

How to eliminate wrong answers

Option A is wrong because Istio service mesh provides traffic management, security, and observability, but it is not the primary mechanism for network isolation; it can enforce policies but requires additional configuration and is not the native Kubernetes feature for pod-level network isolation. Option B is wrong because VPC Service Controls is designed to protect Google Cloud managed services (like Cloud Storage, BigQuery) from data exfiltration, not to isolate pod-to-pod communication within a GKE cluster. Option D is wrong because GKE Sandbox provides an additional layer of isolation between the container and the host kernel using gVisor, but it does not control network communication between pods; it is for workload isolation, not network segmentation.

614
Multi-Selecthard

A company runs a microservices-based application on Google Kubernetes Engine (GKE) with a Regional cluster. They want to improve reliability by implementing best practices for pod scheduling and resilience. Which TWO actions should they take? (Choose two.)

Select 2 answers
A.Set terminationGracePeriodSeconds to 0 for faster pod termination during scale-down
B.Enable cluster autoscaler to automatically add nodes when pods are pending
C.Define a PodDisruptionBudget for each deployment to limit the number of concurrent disruptions
D.Set resource requests equal to limits to ensure guaranteed QoS class
E.Configure pod anti-affinity to spread replicas across different zones
AnswersC, E

Correct: PDB ensures minimum availability during voluntary disruptions.

Why this answer

A PodDisruptionBudget (PDB) limits the number of Pods of a replicated application that can be down simultaneously from voluntary disruptions, such as node maintenance or cluster upgrades. This ensures that a minimum number of replicas remain available, improving application reliability during planned events.

Exam trap

Google Cloud often tests the distinction between voluntary disruptions (handled by PDB) and involuntary disruptions (e.g., node failure), and the trap here is that candidates confuse resource optimization (requests/limits) or scaling (cluster autoscaler) with resilience mechanisms like PDB and anti-affinity.

615
MCQeasy

A financial services firm is designing a new analytics platform on Google Cloud. Regulatory requirements mandate that data must never be replicated or processed outside the European Union, and the company wants to prevent accidental resource creation in non-EU regions regardless of which engineer is deploying. Which mechanism should the architect use to enforce this constraint?

A.Organization Policy constraints that restrict resource locations to approved EU regions.
B.IAM roles that grant project creators permissions only in EU projects.
C.VPC Service Controls perimeters around each project to block data exfiltration.
D.Cloud Asset Inventory alerts that notify security teams when non-EU resources appear.
AnswerA

Organization Policy constraints such as gcp.resourceLocations let administrators define an allowlist of locations at the organization, folder, or project level. Any attempt to create a resource in a non-approved region is denied centrally, regardless of a user's IAM permissions. This provides the deterministic, organization-wide enforcement the regulator requires and cannot be bypassed by individual engineers.

Why this answer

Organization Policy constraints enforce location restrictions centrally and deny non-compliant resource creation before it happens, independent of user permissions. IAM governs identity, VPC Service Controls govern API access and exfiltration, and Asset Inventory provides detection after the fact. Only the organization policy provides the preventive, organization-wide geographic guarantee the regulation demands.

Exam trap

The trap here is confusing VPC Service Controls, which limit data exfiltration through APIs, with Organization Policy constraints, which actually restrict where resources can be created.

616
MCQhard

A company needs to store archival data that is accessed less than once a year, with retrieval times of up to 12 hours acceptable. The data must be kept for 10 years for compliance. What is the most cost-effective Cloud Storage solution?

A.Cloud Storage Coldline class with a retention policy
B.Cloud Storage Nearline class
C.Cloud Storage Archive class with a lifecycle policy that deletes objects after 10 years
D.Cloud Storage Standard class with object versioning
AnswerC

Archive class offers the lowest storage price with retrieval within 12 hours, matching the stem's acceptable retrieval window. A lifecycle policy deleting objects after 10 years satisfies the compliance retention requirement, making this the most cost-effective option.

Why this answer

Cloud Storage Archive class is the most cost-effective option for data accessed less than once a year with retrieval times up to 12 hours, as it offers the lowest storage cost among Google Cloud Storage classes. A lifecycle policy that deletes objects after 10 years ensures compliance with the retention requirement without incurring ongoing storage costs beyond the mandated period.

Exam trap

The trap here is that candidates often confuse 'retention policy' (which prevents deletion) with 'lifecycle policy' (which automates deletion), leading them to choose Coldline or Nearline with a retention policy, missing that Archive class with a lifecycle delete rule is the most cost-effective and compliant solution.

How to eliminate wrong answers

Option A is wrong because Coldline class is designed for data accessed at most once every 90 days, not less than once a year, and its storage cost is higher than Archive class; a retention policy prevents deletion but does not automatically delete data after 10 years, leading to unnecessary costs. Option B is wrong because Nearline class is intended for data accessed less than once a month, with higher storage cost than Archive, and it lacks a built-in mechanism to enforce a 10-year deletion. Option D is wrong because Standard class is for frequently accessed data, has the highest storage cost, and object versioning increases storage costs by retaining multiple versions, making it unsuitable for long-term archival with minimal access.

617
MCQeasy

A startup wants to encrypt data at rest in Cloud Storage using Customer-Managed Encryption Keys (CMEK). They have already created a Cloud KMS key ring and key. What additional step is required to enable CMEK for a new Cloud Storage bucket?

A.Enable the Cloud KMS API in the project where the bucket will reside.
B.Create a Cloud HSM key instead, as CMEK requires HSM.
C.Add a label to the key ring to associate it with the bucket.
D.Grant the Cloud Storage service account the Cloud KMS CryptoKey Encrypter/Decrypter role on the key.
AnswerD

CMEK requires the Cloud Storage service account to hold the CryptoKey Encrypter/Decrypter role on the KMS key, otherwise Cloud Storage cannot wrap and unwrap data encryption keys. Granting this IAM binding is the mandatory step after creating the key ring and key.

Why this answer

To use CMEK with Cloud Storage, the Cloud Storage service account must be granted the Cloud KMS CryptoKey Encrypter/Decrypter role on the specific key. This permission allows the bucket's underlying storage system to encrypt and decrypt objects using the customer-managed key. Without this IAM binding, the bucket cannot access the key, and CMEK operations will fail.

Exam trap

A common misconception is that enabling the Cloud KMS API or using Cloud HSM is required for CMEK, when the actual critical step is granting the Cloud KMS CryptoKey Encrypter/Decrypter role to the Cloud Storage service account on the key.

How to eliminate wrong answers

Option A is wrong because the Cloud KMS API is automatically enabled when you create a key ring or key via the console or gcloud, and it is not a prerequisite for CMEK on a bucket; the bucket itself does not need the KMS API enabled separately. Option B is wrong because CMEK supports both Cloud KMS software keys and Cloud HSM keys; HSM is not required, and the question explicitly states a Cloud KMS key has already been created. Option C is wrong because labels on a key ring are metadata tags and have no role in associating a key with a bucket; the association is done via IAM permissions on the key, not labels.

618
MCQmedium

A company is deploying a new microservices application on Google Kubernetes Engine (GKE). They need to ensure that each microservice can be independently scaled and updated without affecting other services. They also want to minimize the blast radius of a failure in one microservice. Which design approach should they use?

A.Deploy all microservices in a single Deployment with multiple containers per pod.
B.Deploy each microservice as a separate pod without a controller, and manage them manually.
C.Use a single StatefulSet for all microservices to maintain persistent identities.
D.Deploy each microservice as a separate Deployment with its own Horizontal Pod Autoscaler and use separate namespaces for isolation.
AnswerD

Separate Deployments allow independent scaling and updates. Each can have its own Horizontal Pod Autoscaler based on its specific metrics. Using separate namespaces provides logical isolation, reducing the blast radius of failures and simplifying resource management. This is a standard GKE design for microservices.

Why this answer

Using separate Deployments for each microservice enables independent scaling and rolling updates. Each Deployment can have its own HPA, and namespaces provide isolation. This design minimizes the impact of a failure in one service and aligns with microservices best practices.

The other options either couple services together or lack automation and resilience.

Exam trap

The trap here is assuming that grouping containers in a single pod or using a StatefulSet simplifies management, when it actually reduces isolation and independent scalability.

619
MCQhard

A company uses Cloud KMS with CMEK to encrypt data stored in BigQuery. They need to audit who has used the encryption key and when. Which type of audit log should they enable?

A.Network Security audit logs
B.Admin Activity audit logs
C.System Event audit logs
D.Data Access audit logs
AnswerD

Data Access audit logs record every read, write, and cryptographic operation against BigQuery data, including Cloud KMS key usage for CMEK decryption. Admin Activity logs only capture configuration changes, not key use. Enabling Data Access logging therefore reveals who used the key and when, satisfying the audit requirement.

Why this answer

Data Access audit logs record API calls that read or modify user data, including calls to Cloud KMS for encryption and decryption operations. To audit who used a CMEK key and when, you need Data Access audit logs for Cloud KMS, as these logs capture key usage events such as Encrypt, Decrypt, and GenerateDataKey. Admin Activity logs only record changes to resource configurations, not data access.

Exam trap

The trap is assuming Admin Activity logs capture key usage because they are always on and record administrative actions; however, key usage (encrypt/decrypt) is a data access operation, so Data Access logs are required.

How to eliminate wrong answers

Option A is wrong because Network Security audit logs are not a standard audit log type in Google Cloud; audit logs are categorized as Admin Activity, Data Access, System Event, and Policy Denied. Option B is wrong because Admin Activity audit logs record operations that modify the configuration or metadata of resources (e.g., creating a key, changing IAM policies), but they do not capture data access operations like using a key to encrypt or decrypt data. Option C is wrong because System Event audit logs record Google Cloud administrative actions that modify resources, not user-initiated data access.

620
MCQeasy

Which GCP service should be used to automatically scale a GKE cluster's number of nodes based on pending pods?

A.Vertical Pod Autoscaler (VPA)
B.Cluster Autoscaler
C.Node Auto-Provisioning
D.Horizontal Pod Autoscaler (HPA)
AnswerB

Cluster Autoscaler adds or removes nodes in a GKE node pool when pods remain pending due to insufficient allocatable resources, directly satisfying the stem's requirement to scale node count from pending pods. It watches the scheduler's unschedulable queue, unlike Horizontal Pod Autoscaler, which only adjusts replica counts of workloads.

Why this answer

The GKE Cluster Autoscaler watches for pods that cannot be scheduled due to insufficient node capacity and automatically adds nodes to the node pool (and removes underutilized nodes). This is exactly the behavior described — scaling the cluster's node count based on pending pods.

Exam trap

PCA often tests the confusion between HPA (scales pods), VPA (scales pod resources), and Cluster Autoscaler (scales nodes) — candidates who see 'pending pods' and pick HPA miss that HPA cannot help when there is no node capacity to schedule onto.

How to eliminate wrong answers

Option A is wrong because Vertical Pod Autoscaler adjusts CPU/memory requests and limits of individual pods, not the number of nodes in the cluster. Option C is wrong because Node Auto-Provisioning creates new node pools with different machine types when needed, but it is a complementary feature that works alongside Cluster Autoscaler and does not by itself handle the basic pending-pod scale-up scenario. Option D is wrong because Horizontal Pod Autoscaler scales the number of pod replicas based on metrics like CPU, not the number of underlying nodes.

621
Multi-Selectmedium

Which THREE are valid methods to connect an on-premises network to a Google Cloud VPC?

Select 3 answers
A.Dedicated Interconnect
B.Cloud VPN
C.Cloud Router
D.VPC peering
E.Partner Interconnect
AnswersA, B, E

Dedicated Interconnect provides direct physical connection.

Why this answer

Dedicated Interconnect (A) provides a direct physical connection between your on-premises network and Google Cloud, offering high bandwidth and a Service Level Agreement (SLA) of up to 99.99% availability. It uses a cross-connect in a colocation facility to attach your on-premises router to a Google Cloud router, enabling private, low-latency connectivity to your VPC without traversing the public internet.

Exam trap

The trap here is that candidates confuse Cloud Router as a standalone connectivity method, when it is actually a routing component that must be paired with a VPN tunnel or Interconnect to function.

622
MCQmedium

A company runs a public-facing web application on Compute Engine instances behind an external HTTP(S) load balancer. They want to protect the application from common web attacks such as SQL injection and cross-site scripting, and they also want to restrict access to known IP ranges. Which Google Cloud service should they use?

A.VPC firewall rules to allow only specific IP ranges and block malicious traffic.
B.Cloud CDN with signed URLs to restrict access and cache content.
C.Cloud Armor security policy with preconfigured WAF rules and IP allowlist rules.
D.Identity-Aware Proxy (IAP) to authenticate users and enforce access policies.
AnswerC

Cloud Armor provides WAF capabilities with preconfigured rules for OWASP Top 10 threats like SQL injection and XSS, and it supports IP allowlist/denylist rules. It integrates with external HTTP(S) load balancers to filter traffic at the edge. This directly meets both requirements: protecting against web attacks and restricting access by IP. It is the native Google Cloud solution for this scenario.

Why this answer

Cloud Armor is the correct choice because it provides both WAF protection against common web attacks and IP-based access control. It is designed to work with external HTTP(S) load balancers, making it the appropriate service for securing a public web application. The other options either lack WAF capabilities or are intended for different use cases such as performance or identity-based access.

Exam trap

The trap here is confusing network-layer firewall rules with application-layer WAF, or assuming IAP provides WAF protection.

623
MCQhard

A multinational corporation operates in multiple regions and must comply with GDPR. They use Cloud Load Balancing to distribute traffic across regional backends. Their security team wants to block traffic from specific countries (e.g., non-EU countries) at the edge. What should they use?

A.Configure Cloud CDN to serve content only to EU-based users.
B.Use Cloud Armor security policies with geographic-based denylist rules.
C.Set VPC firewall rules to allow traffic only from EU IP ranges.
D.Configure Identity-Aware Proxy (IAP) to require user authentication from allowed countries.
AnswerB

Cloud Armor security policies attach to the load balancer's backend service and evaluate rules at the edge, including geographic denylists keyed on source country. This blocks non-EU traffic before it reaches regional backends, satisfying the GDPR constraint.

Why this answer

Cloud Armor security policies support geographic-based access control using denylist or allowlist rules that match client IP addresses against country-level geolocation data. This allows the security team to block traffic from specific countries at the edge, before it reaches the backend, which is the most efficient and compliant approach for GDPR enforcement.

Exam trap

The trap here is that candidates often confuse VPC firewall rules (which filter by IP ranges) with Cloud Armor's geolocation-based policies, or they assume Cloud CDN or IAP can enforce geographic access control, when in fact only Cloud Armor provides native country-level blocking at the edge.

How to eliminate wrong answers

Option A is wrong because Cloud CDN caches content but does not enforce geographic access control; it can serve cached content to any user regardless of location, and its 'geo restrictions' are only for signed URLs, not for blocking traffic at the edge. Option C is wrong because VPC firewall rules operate at the network layer and cannot reliably block traffic based on country-level geolocation; they only filter by IP ranges, which are not accurate for country-level blocking due to IP reassignment and lack of granularity. Option D is wrong because Identity-Aware Proxy (IAP) controls access based on user identity and context, not on the geographic origin of the IP address; it cannot block traffic at the edge based solely on country.

624
MCQmedium

A company runs a web application on Compute Engine with an HTTP Load Balancer. Users report intermittent 502 Bad Gateway errors. What is the most likely cause?

A.Load balancer quota exceeded.
B.Firewall rules block health checks.
C.SSL certificate expired.
D.Backend instances are unhealthy or overloaded.
AnswerD

An HTTP(S) load balancer returns 502 when it cannot obtain a valid response from a backend. Unhealthy instances removed by health checks, or overloaded instances timing out, both produce this, matching the intermittent pattern reported.

Why this answer

The 502 Bad Gateway error from an HTTP Load Balancer typically indicates that the backend instances are failing to respond to the load balancer's health checks or are overwhelmed, causing the load balancer to consider them unhealthy and return a 502 error. This is the most common cause because the load balancer relies on healthy backends to forward traffic, and overloaded or failing instances cannot handle requests.

Exam trap

The trap here is that candidates often confuse 502 errors with SSL or quota issues, but the PCA exam specifically tests that 502 errors from an HTTP Load Balancer are almost always due to backend unavailability or overload, not frontend configuration problems.

How to eliminate wrong answers

Option A is wrong because exceeding a load balancer quota would result in a 429 Too Many Requests or a 503 Service Unavailable error, not a 502 Bad Gateway. Option B is wrong because firewall rules blocking health checks would cause the load balancer to mark backends as unhealthy, but the error would typically be a 502 only if the health check fails and no healthy backends remain; however, the question asks for the most likely cause, and overloaded backends are more common than misconfigured firewalls in intermittent 502 scenarios. Option C is wrong because an expired SSL certificate on the load balancer would cause SSL handshake failures and a 502 error only if the certificate is used for backend-to-load-balancer communication, but the load balancer terminates SSL and uses its own certificate; an expired certificate on the backend would not cause a 502 from the load balancer's perspective.

625
MCQeasy

A media company is preparing to migrate a batch reporting application to Google Cloud. The application currently runs on physical servers that are used at about 20 percent CPU on average, but it has two short month-end peaks each quarter when utilization reaches 90 percent for about six hours. The company wants to reduce infrastructure cost while guaranteeing the application always has enough capacity during the peaks. What should the architect recommend?

A.Deploy the application on a managed instance group with autoscaling based on CPU utilization, with a minimum size that covers baseline load and a maximum size that covers the peaks.
B.Deploy the application on a managed instance group of Compute Engine VMs sized for the month-end peak, using a committed use discount for the full capacity.
C.Deploy the application to a Google Kubernetes Engine cluster with a single large node pool and enable cluster autoscaler with a minimum node count equal to the peak requirement.
D.Deploy the application to Cloud Run with a minimum instance count set to the number of instances needed at peak and concurrency set to one.
AnswerA

An autoscaling managed instance group adds VMs when CPU rises and removes them when demand falls, so the company pays for baseline capacity most of the time and scales out only during the month-end peaks. Setting the minimum to baseline and the maximum to peak capacity guarantees headroom. This matches the workload's spiky profile directly.

Why this answer

The workload is spiky, with a low average and short, predictable peaks. Horizontal autoscaling on managed instance groups matches that shape: the group grows during the month-end surge and shrinks afterward, so cost tracks actual demand while the maximum size preserves guaranteed headroom. Fixed peak sizing, cluster autoscaler with a peak-sized minimum, and pinned Cloud Run minimum instances all keep peak capacity running continuously.

Exam trap

The trap here is equating a committed use discount or a high autoscaler minimum with cost optimization, when both lock in peak capacity that runs during the long low-utilization periods.

626
MCQeasy

Your company has migrated its legacy web application from a single Compute Engine instance to a managed instance group (MIG) behind an HTTP(S) load balancer. The application was updated to a new version as part of the migration. After the migration, users report intermittent 502 Bad Gateway errors. The application logs show no errors, and the load balancer backend health checks are reported as healthy. On investigation, the developers discover that the new version requires a specific environment variable for authentication to a downstream service. This variable was set manually on the original instance but is missing from the MIG's instance template. The health check endpoint does not depend on this variable and always returns a 200 status even when the variable is absent. As a result, instances created from the template are considered healthy by the load balancer, but when they receive requests that require authentication, they fail and return a 502 error to the client. What is the most likely cause of the 502 errors?

A.The missing environment variable causes authentication failures on new instances.
B.The health check is configured to check the old application path, which no longer exists.
C.The load balancer's backend timeout is too short for the application's response time.
D.The MIG is not scaling out fast enough to handle peak traffic.
AnswerA

The instance template omits the downstream authentication variable, so every MIG instance starts without it. Because the health check endpoint never exercises that authentication path, the load balancer keeps routing traffic to instances that fail downstream calls, producing 502s. Supplying the variable in the template restores authentication.

Why this answer

The 502 errors occur because the new application version requires a specific environment variable for authentication to a downstream service. The health check endpoint does not depend on this variable, so instances are marked healthy even though they cannot authenticate real requests. When the load balancer routes traffic to these instances, the missing variable causes authentication failures, leading to 502 Bad Gateway errors.

Exam trap

The trap here is that candidates assume healthy health checks guarantee the application is fully functional, but Google Cloud tests the nuance that health checks may not cover all dependencies, leading to 'false healthy' instances that fail on real requests.

How to eliminate wrong answers

Option B is wrong because the health check is reported as healthy, indicating it is hitting a valid endpoint (the old path would cause health check failures, not intermittent 502s). Option C is wrong because backend timeout issues would typically cause 504 Gateway Timeout errors, not 502 Bad Gateway errors, and the application logs show no errors. Option D is wrong because scaling issues would cause 503 Service Unavailable errors or increased latency, not 502 errors, and the MIG is not reported as overloaded.

627
Multi-Selectmedium

A company wants to implement a zero-trust access model for internal web applications running on Compute Engine. They need to authenticate users using corporate credentials and enforce context-aware access based on device posture and IP address. Which TWO services should they use?

Select 2 answers
A.VPC Service Controls
B.Cloud VPN
C.Cloud Identity
D.Cloud Armor
E.Identity-Aware Proxy (IAP)
AnswersC, E

Cloud Identity provides the corporate credential directory and user authentication, which IAP then consumes to verify identity. It supplies the identity plane needed for zero-trust access to the Compute Engine applications, satisfying the corporate credentials requirement.

Why this answer

Cloud Identity (C) is correct because it provides the identity provider and user/group management that lets the company authenticate users with their corporate credentials, which is the foundation of a zero-trust identity model. Identity-Aware Proxy (IAP) (E) is correct because it enforces context-aware access to internal web applications on Compute Engine, evaluating user identity plus device posture and IP address before granting access, exactly matching the scenario's requirements. VPC Service Controls (A) is not correct here because it protects Google Cloud APIs and services at the perimeter level rather than authenticating users to internal web apps.

Cloud VPN (B) only provides encrypted network connectivity and does not perform user authentication or context-aware access control. Cloud Armor (D) is a WAF/DDoS protection service that filters traffic at the edge but does not authenticate users or enforce device-posture-based access.

Exam trap

PCA often tests... the components of zero-trust architecture, and candidates might confuse IAP with Cloud Armor or VPC Service Controls, which serve different purposes.

628
MCQeasy

Your company runs a global e-commerce platform on Google Cloud. The application is deployed across multiple regions for low latency. You use Cloud SQL for transactional data and Cloud Spanner for global consistency of inventory. Recently, the operations team reported that the application is experiencing increased latency during peak hours, and the monthly cloud bill has risen significantly. Upon investigation, you find that the Cloud SQL instance is underutilized (CPU < 20%) while Cloud Spanner split utilization is over 80%. The application instances are fronted by a global external HTTPS load balancer. Network egress costs are high. Which course of action would best address both the latency and cost issues?

A.Reduce the Cloud SQL instance tier to a lower machine type to save costs, and add read replicas in other regions for failover.
B.Add more nodes to the Cloud SQL instance and enable automatic storage increase to handle peak loads.
C.Increase the number of splits in Cloud Spanner to reduce hot spots, and configure Cloud CDN in front of the load balancer to cache static content.
D.Move the transactional database to Cloud Spanner and decommission Cloud SQL to reduce complexity.
AnswerC

Increasing splits improves Spanner performance; Cloud CDN reduces egress costs and latency for static content.

Why this answer

The primary performance issue is Cloud Spanner split utilization over 80%, indicating hot spots that cause increased latency. Increasing the number of splits redistributes load across more nodes, reducing contention. Additionally, configuring Cloud CDN caches static content at edge locations, reducing network egress costs and latency by serving content closer to users.

Exam trap

The trap here is that candidates focus on the underutilized Cloud SQL instance and assume it is the problem, ignoring that the real bottleneck is Cloud Spanner split utilization and network egress costs, which require a different solution (split management and CDN caching).

How to eliminate wrong answers

Option A is wrong because reducing the Cloud SQL instance tier would not address the high Cloud Spanner split utilization or network egress costs; Cloud SQL is underutilized, so downsizing it does not solve the root cause. Option B is wrong because adding nodes to Cloud SQL does not fix Cloud Spanner hot spots or high egress costs; Cloud SQL is not the bottleneck. Option D is wrong because moving transactional data to Cloud Spanner would increase complexity and cost without addressing the specific split utilization and egress issues; Cloud SQL is underutilized, so decommissioning it is unnecessary and could introduce migration risks.

629
MCQeasy

You need to create a Cloud Logging sink that exports logs to a BigQuery dataset for long-term analysis. Which destination type should you specify?

A.Cloud Storage
B.BigQuery
C.Pub/Sub
D.Custom HTTP endpoint
AnswerB

Cloud Logging sinks route log entries to supported destinations, and BigQuery is a native sink destination that stores exported logs in datasets for SQL analysis and long-term retention. Specifying BigQuery as the destination type satisfies the requirement to export logs into a BigQuery dataset.

Why this answer

Cloud Logging sinks support three destination types: Cloud Storage, BigQuery, and Pub/Sub (plus custom destinations via Pub/Sub or Logging API). BigQuery is the correct choice here because the requirement is long-term analysis of log data, and BigQuery provides a fully managed, serverless data warehouse with SQL querying, partitioning, and clustering capabilities ideal for analytical workloads on exported logs.

Exam trap

PCA often tests the distinction between log routing destinations by matching the destination to the use case — candidates incorrectly pick Pub/Sub for 'analysis' when the question implies batch SQL analytics, which is BigQuery's domain.

How to eliminate wrong answers

Option A is wrong because Cloud Storage is designed for object storage and archival, not for running analytical SQL queries over log data — it is best suited for cold storage or log retention rather than analysis. Option C is wrong because Pub/Sub is a messaging service used to stream logs to downstream consumers in real time, not a storage or analytics destination for long-term analysis. Option D is wrong because a custom HTTP endpoint is not a native Logging sink destination type; custom destinations require routing through Pub/Sub or the Logging API.

630
MCQhard

A financial services firm stores sensitive customer records in Cloud Storage and must ensure that only identities in its corporate domain can read the objects, that no object can ever be made publicly accessible, and that access decisions are evaluated centrally. The firm wants the least administrative overhead while keeping these guarantees across many buckets created by different teams. What should the architect implement?

A.Use a customer-managed encryption key for every bucket and grant roles/storage.objectAdmin only to a single service account that proxies all reads for the corporate domain.
B.Enable VPC Service Controls with a service perimeter around the projects and grant roles/storage.objectViewer to the domain using a Google Group.
C.Apply an organization policy constraint with the storage.publicAccessPrevention enforced across the organization, and grant bucket access through IAM conditions that restrict principals to the corporate domain.
D.Set each bucket's default object ACL to private and rely on Cloud Storage's default uniform bucket-level access to block public reads, while granting roles/storage.objectViewer to all authenticated users.
AnswerC

Organization policy constraints enforce the public access prevention setting across every project and bucket beneath the organization, so no team can override it. IAM conditions on role bindings can restrict access to principals whose email matches the corporate domain, letting the firm centralize access decisions without per-bucket ACL management. Together these controls meet the guarantee and minimize ongoing administration across many teams.

Why this answer

The firm needs a preventive control that no team can bypass and an access model that is scoped to the corporate domain. Enforcing the public access prevention organization policy makes the no-public-access guarantee inherited and non-overridable at lower levels. IAM conditions limiting principals to the corporate domain keep read access inside the firm while allowing centralized administration.

This pairing addresses both the exposure guarantee and the identity restriction with minimal per-bucket work.

Exam trap

The trap here is treating encryption as an access control when key possession does not grant or deny read permission on a Cloud Storage object.

631
MCQmedium

A financial services company runs a payment processing platform on Compute Engine. Compliance requires that all data at rest be encrypted with keys the company controls and that key material never leave their on-premises HSM appliances. They must also minimize operational overhead for key rotation. Which Google Cloud solution should the architect recommend?

A.Default Google-managed encryption at rest with CMEK disabled
B.Customer-supplied encryption keys (CSEK) stored in a local vault
C.Cloud External Key Manager (Cloud EKM) with an external key manager
D.Cloud KMS with CMEK and automatic rotation
AnswerC

Cloud EKM allows Compute Engine disks and other resources to use CMEK whose key material lives in an external key manager, including on-premises HSM-backed systems. Google never sees the key material; it only sends wrap/unwrap requests. This satisfies the requirement that keys remain in the company's HSMs while still integrating with Google Cloud services, and rotation is handled in the external key manager.

Why this answer

The strict requirement is that key material must remain in the company's on-premises HSMs while still protecting Google Cloud resources. Cloud EKM is designed exactly for this: it lets Cloud services use CMEK backed by an external key manager, so Google never holds the key material. CSEK requires manual key handling, Cloud KMS stores keys in Google Cloud, and default encryption gives no customer control.

Exam trap

The trap here is assuming that CMEK via Cloud KMS keeps key material on-premises, when in fact Cloud KMS holds the key material unless Cloud EKM is used.

632
MCQhard

A company runs a batch processing application on Compute Engine that reads data from Cloud Storage and writes results to BigQuery. The application runs on a managed instance group (MIG) with autoscaling. Recently, job failures occurred because instances could not authenticate to BigQuery. You need to ensure that the instances have the necessary permissions without embedding credentials in the application. What should you do?

A.Enable the BigQuery API on the project and grant the Compute Engine default service account the BigQuery Data Editor role.
B.Generate a service account key file and store it in Cloud Storage. Configure the application to download the key at startup and use it for authentication.
C.Create a service account with the BigQuery Data Editor role and assign it to the MIG as the instance service account.
D.Use Application Default Credentials (ADC) by setting the GOOGLE_APPLICATION_CREDENTIALS environment variable to point to a JSON key file stored on each instance's local SSD.
AnswerC

Assigning a service account with the necessary BigQuery permissions to the MIG allows all instances to authenticate automatically via the metadata server. This eliminates the need to embed credentials and follows best practices for IAM. The BigQuery Data Editor role provides the required write access to datasets.

Why this answer

Assigning a dedicated service account with the BigQuery Data Editor role to the managed instance group allows instances to obtain credentials from the metadata server, adhering to security best practices. This avoids key management and ensures least privilege. The other options either use insecure key files or grant excessive permissions to the default service account.

Exam trap

The trap here is thinking that you must use a service account key file for authentication, but Compute Engine instances can use their attached service account via the metadata server.

633
MCQeasy

Your organization wants to use Cloud SQL for a MySQL database with automatic failover in the event of a zone outage. Which configuration should you choose?

A.Set up Cloud SQL with external replication to a VM in another zone
B.Create a Cloud SQL instance with a cross-region read replica
C.Create a single-zone Cloud SQL instance with automatic backups enabled
D.Create a regional Cloud SQL instance (high availability) with a primary and standby zone
AnswerD

A regional instance maintains a standby in a different zone within the same region, with synchronous replication and automatic failover. This satisfies the zone-outage requirement, whereas a zonal instance has no standby and cannot fail over automatically.

Why this answer

A regional Cloud SQL instance (high availability) provisions a primary and a standby instance in two zones within the same region, with automatic failover to the standby if the primary zone fails. This is the native Cloud SQL HA configuration for zone-outage resilience. Cross-region read replicas and external replication are for read scaling or DR, not automatic same-region failover.

Exam trap

PCA often tests the difference between HA (regional instance with standby for automatic failover) and read replicas (for scaling/DR) — candidates pick cross-region replicas thinking they provide automatic failover.

How to eliminate wrong answers

Option A is wrong because external replication to a VM in another zone is a manual, self-managed setup that does not provide Cloud SQL's automatic failover. Option B is wrong because a cross-region read replica is for read scaling and disaster recovery across regions, not automatic failover within a region. Option C is wrong because a single-zone instance with automatic backups provides data recovery via restore, but no automatic failover during a zone outage — the instance goes down until the zone recovers or you manually restore.

634
Multi-Selecthard

An organization needs to comply with FedRAMP requirements and restrict data storage to specific regions. They also need to audit all admin activities and data access. Which three components should they implement? (Choose three.)

Select 3 answers
A.VPC Service Controls
B.Data Access audit logs
C.Cloud Armor
D.Admin Activity audit logs
E.Assured Workloads
AnswersB, D, E

Data Access audit logs record every read and write against stored data, satisfying the stem's requirement to audit all data access. Unlike Admin Activity logs, which capture only configuration changes, these logs provide the per-object visibility FedRAMP auditors demand for demonstrating continuous monitoring of regulated data.

Why this answer

Assured Workloads (E) is correct because it is the Google Cloud service specifically designed to enforce regulatory compliance frameworks such as FedRAMP and to restrict data storage and processing to specific regions through its compliance controls. Admin Activity audit logs (D) are correct because they record all administrative and configuration changes made to resources, which is required to audit all admin activities. Data Access audit logs (B) are correct because they capture read and write operations on user data, satisfying the requirement to audit all data access.

VPC Service Controls (A) is not selected because, while it provides service perimeter security to mitigate data exfiltration, it does not itself enforce FedRAMP compliance or regional data residency. Cloud Armor (C) is not selected because it is a WAF/DDoS protection service for external HTTP(S) load balancers and does not address compliance, data residency, or audit logging requirements.

635
Multi-Selectmedium

A healthcare company stores protected health information in Cloud Storage and BigQuery. Compliance requires that access to this data be auditable and that no single administrator can both modify data and erase the audit trail. The security architect is designing the logging and access model. Which two actions should the architect take? (Choose two.)

Select 2 answers
A.Use BigQuery row-level security to restrict which rows each analyst can read, and rely on that as the sole audit mechanism for PHI access.
B.Grant project owners the Logging Admin role so they can manage log sinks and adjust retention as operational needs change.
C.Create a dedicated log bucket with a locked retention policy and grant the security team roles/logging.viewer on it while removing Logging Admin from data project owners.
D.Enable Cloud Audit Logs Data Access logs for Cloud Storage and BigQuery and route them to a log bucket in a separate project with a locked retention policy.
E.Store audit logs in the same Cloud Storage bucket as the PHI so that access reviews cover both data and logs in a single IAM policy.
AnswersC, D

A locked retention policy on a dedicated log bucket prevents deletion or modification of logs for the retention period, even by project owners, which enforces immutability. Granting the security team only Logging Viewer separates audit review from data administration, ensuring no single admin controls both data changes and the audit record.

Why this answer

Auditability and separation of duties require capturing Data Access logs for the services holding PHI and storing them where data administrators cannot alter them. Routing logs to a separate project's log bucket with a locked retention policy makes the trail immutable, and limiting the security team to Logging Viewer while removing Logging Admin from data owners ensures no single person can both change data and erase the evidence.

Exam trap

The trap here is treating log retention as a routine operational setting that project owners should manage, when locked retention and role separation are what actually prevent an administrator from erasing the audit trail.

636
Matchingmedium

Match each GCP security service to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manage encryption keys

Hardware security module for key protection

Store API keys, passwords, certificates

Manage access control

Centralized security and risk management

Why these pairings

Cloud Armor protects against DDoS and web attacks; IAP controls access based on identity; KMS handles encryption keys; DLP protects sensitive data. Distractors swap these functions.

637
MCQhard

A company has a global web application deployed across multiple regions. They use an external HTTPS Load Balancer with backend services in us-central1 and europe-west1. They want users to be routed to the closest healthy backend. Which load balancing configuration is required?

A.Internal HTTP(S) Load Balancer
B.External HTTPS Load Balancer with global backend
C.External TCP/UDP Network Load Balancer
D.Classic Application Load Balancer
E.Regional external HTTPS Load Balancer
AnswerB

A global external HTTPS Load Balancer with a global backend uses Google's premium tier anycast VIP, so each user's request enters the Google network at the nearest edge and is proxied to the closest healthy backend across us-central1 and europe-west1, satisfying the proximity routing requirement.

Why this answer

An External HTTPS Load Balancer with a global backend configuration uses Google Cloud's global anycast IP and the Premium Tier network to route users to the closest healthy backend based on latency and proximity. This setup ensures that traffic from users worldwide is directed to the nearest region (us-central1 or europe-west1) with a healthy instance group, providing optimal performance and failover.

Exam trap

The trap here is that candidates often confuse 'global' with 'regional' load balancers, mistakenly thinking a regional external HTTPS load balancer can serve multiple regions, but only the global external HTTPS load balancer supports cross-region backend services with anycast routing.

How to eliminate wrong answers

Option A is wrong because an Internal HTTP(S) Load Balancer is used for traffic within a VPC network, not for external user traffic from the internet. Option C is wrong because an External TCP/UDP Network Load Balancer operates at Layer 4 and does not support HTTPS termination, content-based routing, or global backend selection across regions. Option D is wrong because Classic Application Load Balancer is a legacy GCP resource that does not support global backends or cross-region routing; it is regionally scoped.

Option E is wrong because a Regional external HTTPS Load Balancer is confined to a single region and cannot route traffic to backends in multiple regions like us-central1 and europe-west1.

638
MCQmedium

An organization needs to run a stateful application on Google Kubernetes Engine (GKE) where the nodes are fully managed by Google and the application workload SLAs are guaranteed. They want to minimize operational overhead. Which GKE mode should they use?

A.GKE Standard with Cluster Autoscaler
B.GKE Standard with node auto-provisioning
C.GKE Standard with sole-tenant nodes
D.GKE Autopilot
AnswerD

GKE Autopilot provisions and manages the node infrastructure itself, including scaling, patching and node pool configuration, while enforcing workload resource requests and SLA-backed reliability. This removes node-level operational overhead, satisfying the requirement for fully Google-managed nodes with guaranteed workload SLAs.

Why this answer

GKE Autopilot manages the entire node infrastructure including node provisioning, scaling, and maintenance. It provides workload-level SLAs (e.g., 99.95% for pods). Standard mode requires the user to manage node pools.

639
MCQmedium

You want to monitor the latency of an application running on Compute Engine and create an alert if the 99th percentile latency exceeds 500ms for more than 5 minutes. Which approach should you use?

A.Use Cloud Trace to analyze latency and set a trace-based alert
B.Use Error Reporting to capture latency errors
C.Create a Metric Threshold alert using the 'Latency' metric with a percentile alignment
D.Create a log-based metric from application logs and set an alert on that metric
AnswerC

A metric threshold alert with percentile alignment computes the 99th percentile latency over the window and fires when it exceeds 500ms for more than 5 minutes. This directly matches the stated latency percentile and duration condition on the Compute Engine application.

Why this answer

To monitor latency and alert on the 99th percentile exceeding 500ms for more than 5 minutes, you should create a Metric Threshold alert in Cloud Monitoring using the appropriate latency metric (e.g., from a load balancer or application) with a percentile alignment. This allows you to aggregate latency data over a window and trigger an alert when the condition is met.

Exam trap

PCA often tests the confusion between monitoring and tracing tools, where candidates might choose Cloud Trace for alerting because it deals with latency, but it lacks native alerting capabilities.

How to eliminate wrong answers

Option A is wrong because Cloud Trace is for analyzing request traces and does not natively support alerting on latency percentiles; it is a diagnostic tool, not an alerting mechanism. Option B is wrong because Error Reporting captures errors and exceptions, not latency metrics, and cannot alert on latency thresholds. Option D is wrong because log-based metrics are derived from logs and may not provide the precise latency percentile data needed; they are better suited for counting specific log events.

640
MCQmedium

A company wants to enforce that all secrets used by applications running on Compute Engine are rotated automatically every 30 days. Which GCP service should they use to store and manage these secrets?

A.Cloud Key Management Service with CMEK
B.Secret Manager
C.Environment variables
D.Cloud KMS
AnswerB

Secret Manager stores application secrets and supports automatic rotation schedules, meeting the 30-day rotation requirement. Compute Engine workloads retrieve secrets via the API or client libraries, so credentials are never hard-coded, and rotation happens centrally without redeploying applications.

Why this answer

Google Cloud Secret Manager is purpose-built for storing, versioning, and rotating secrets such as API keys, passwords, and certificates. It supports automatic rotation via Pub/Sub notifications and Cloud Functions/Cloud Run, and it integrates natively with Compute Engine workloads through IAM and the Secret Manager API. Cloud KMS, by contrast, manages encryption keys, not application secrets.

Exam trap

PCA often tests the confusion between Cloud KMS (encryption keys) and Secret Manager (application secrets) — candidates must distinguish 'managing keys that encrypt data' from 'storing and rotating credentials.'

How to eliminate wrong answers

Option A is wrong because Cloud KMS with CMEK manages customer-managed encryption keys used to encrypt data at rest — it does not store or rotate application secrets like database passwords. Option C is wrong because environment variables are a delivery mechanism, not a secret store; they are visible in process listings, lack versioning, auditing, and rotation, and are explicitly discouraged for secrets by Google's best practices. Option D is wrong because Cloud KMS is a key management service for cryptographic keys (symmetric/asymmetric), not a secret vault — it cannot store arbitrary secret payloads or rotate them on a 30-day schedule.

641
MCQmedium

A team manages a GKE cluster with node pools using different machine types. They plan to upgrade the cluster to a new Kubernetes version. What is the safest upgrade strategy to minimize application downtime?

A.Perform a rolling upgrade by draining all nodes simultaneously.
B.Create a new cluster with the desired version and migrate workloads.
C.Use a surge upgrade to add new nodes before removing old ones.
D.Upgrade the node pool configuration one by one.
AnswerC

A surge upgrade provisions replacement nodes running the new Kubernetes version before cordoning and draining the old ones, so workloads reschedule onto ready capacity. This satisfies the stem's downtime constraint: pods are evicted only once healthy successors exist, and mixed machine types across node pools are handled per pool.

Why this answer

A surge upgrade in GKE adds new nodes with the desired Kubernetes version before removing old nodes, ensuring capacity is maintained throughout the process. This minimizes application downtime by allowing pods to be rescheduled onto new nodes before old nodes are drained, following a controlled rolling update pattern that respects PodDisruptionBudgets.

Exam trap

Google Cloud often tests the misconception that draining all nodes simultaneously is a valid rolling upgrade strategy, when in fact it causes complete downtime and violates Kubernetes best practices for workload availability.

How to eliminate wrong answers

Option A is wrong because draining all nodes simultaneously would remove all running pods at once, causing complete application downtime and violating PodDisruptionBudgets if configured. Option B is wrong because creating a new cluster and migrating workloads requires manual or tool-based migration, which introduces significant operational overhead and potential downtime during the cutover, and is not the safest or most efficient strategy for an existing cluster. Option D is wrong because upgrading node pool configuration one by one does not specify a surge or rolling mechanism; without surge, it would drain nodes in the pool sequentially, potentially causing capacity shortages and downtime if the pool is under-provisioned.

642
MCQhard

A company has a multi-region deployment of App Engine and wants to optimize request routing for latency and cost. Which GCP service should they use?

A.Cloud Endpoints.
B.Cloud Load Balancing with global anycast.
C.Cloud DNS with latency-based routing.
D.Cloud Traffic Director.
AnswerB

Cloud Load Balancing with global anycast advertises a single global IP, routing each user to the nearest healthy App Engine region at Google's edge. This minimises latency and avoids cross-region egress costs compared with regional or DNS-based routing.

Why this answer

Cloud Load Balancing with global anycast uses Google's global network and anycast IP addresses to route user traffic to the nearest healthy backend, minimizing latency. It also supports premium tier routing for lower latency and standard tier for lower cost, directly addressing the optimization goals for a multi-region App Engine deployment.

Exam trap

The trap here is that candidates often confuse Cloud DNS latency-based routing (a DNS-level, cache-prone approach) with true anycast-based global load balancing, which provides immediate, health-aware routing without DNS caching delays.

How to eliminate wrong answers

Option A is wrong because Cloud Endpoints is an API management service for securing, monitoring, and managing APIs, not a global load balancer for routing traffic across regions based on latency and cost. Option C is wrong because Cloud DNS with latency-based routing is a DNS-level feature that can direct traffic based on latency, but it lacks the fine-grained health checking, anycast IP, and traffic splitting capabilities of a global load balancer, and DNS caching can cause routing delays. Option D is wrong because Cloud Traffic Director is a traffic management service for service mesh (e.g., with Istio on GKE), not designed for global HTTP(S) load balancing to App Engine; it operates at the service mesh layer, not the edge.

643
MCQmedium

Refer to the exhibit. A user reports that the instance 'batch-vm' is unavailable. Based on the output, what is the most likely cause of the unavailability?

A.The VM was stopped manually by a user.
B.The preemptible VM was terminated by Google due to its preemptible nature.
C.The VM lost its external IP address.
D.The VM crashed due to an out-of-memory error.
AnswerB

Preemptible VMs run at lower cost but Google can reclaim them at any time with a 30-second warning, stopping the instance abruptly. The exhibit's terminated status and preemptible flag confirm this involuntary reclaim, not a crash or quota issue.

Why this answer

The exhibit shows the instance 'batch-vm' with a status of 'TERMINATED' and the 'preemptible' flag set to 'true'. Preemptible VMs in Google Cloud have a maximum runtime of 24 hours and can be terminated at any time by Google Compute Engine due to resource constraints. The termination reason is typically 'preemption', which matches the scenario of a user reporting unavailability without manual intervention.

Exam trap

Google Cloud often tests the distinction between 'STOPPED' (user-initiated, billable for attached resources) and 'TERMINATED' (preempted or deleted, no longer billable), and candidates confuse preemption with a manual stop or a crash.

How to eliminate wrong answers

Option A is wrong because a manual stop would show the VM status as 'STOPPED' (not 'TERMINATED') and would not be caused by Google's infrastructure; the exhibit does not indicate any user-initiated stop action. Option C is wrong because losing an external IP address does not terminate a VM; the VM would still be running (status 'RUNNING') but inaccessible via that IP, and the exhibit shows the VM as 'TERMINATED'. Option D is wrong because an out-of-memory error would cause the VM to become unresponsive or crash, but the VM would remain in a 'RUNNING' or 'STOPPING' state, not transition to 'TERMINATED'; termination is a distinct lifecycle state typically triggered by preemption, deletion, or explicit stop.

644
MCQmedium

A financial services company runs a containerized trading platform on Google Kubernetes Engine (GKE). Compliance requires that all inter-pod traffic be encrypted without modifying application code, and that the encryption keys be managed by the company rather than Google. The security team wants to enforce this at the infrastructure level. Which approach should they take?

A.Configure Istio with mutual TLS (mTLS) and a custom certificate authority managed by the company.
B.Enable Application-layer Secrets Encryption with a Cloud KMS key on the GKE cluster.
C.Use VPC Service Controls to create a service perimeter around the GKE cluster.
D.Enable GKE network policy enforcement and create NetworkPolicy resources to allow only encrypted traffic.
AnswerA

Istio with mTLS encrypts all service-to-service traffic transparently without application changes. When you integrate Istio's certificate authority with a company-managed CA, the keys and certificates are controlled by the organization, satisfying the requirement that keys be company-managed. This approach enforces encryption at the infrastructure layer for all inter-pod communication.

Why this answer

Istio's mutual TLS encrypts all service-to-service traffic within the mesh without requiring application changes. By integrating Istio's certificate authority with a company-managed CA, the organization retains control over encryption keys. NetworkPolicy and VPC Service Controls do not encrypt traffic, and Application-layer Secrets Encryption only protects secrets at rest, not network data in transit.

Exam trap

The trap here is assuming that GKE NetworkPolicy or VPC Service Controls provide encryption, when they only control traffic flow or API perimeters.

645
MCQmedium

A company runs a stateful application on GKE that requires persistent storage. They want to ensure that during cluster upgrades, pods are not disrupted and storage is preserved. Which configuration should they use?

A.Enable Cluster Autoscaler on the node pool
B.Use a Deployment with a HorizontalPodAutoscaler
C.Use a StatefulSet with a PodDisruptionBudget
D.Use PersistentVolumeClaims with ReadWriteMany access mode
AnswerC

A StatefulSet guarantees stable network identities and preserves each pod's PersistentVolumeClaim across rescheduling, satisfying the storage-preservation constraint. Adding a PodDisruptionBudget limits voluntary evictions during node draining, so cluster upgrades cannot disrupt more pods than the budget permits, keeping the stateful application available throughout.

Why this answer

To ensure stateful pods are not disrupted during cluster upgrades and storage is preserved, you should use a StatefulSet with a PodDisruptionBudget (PDB). StatefulSets provide stable network identities and persistent storage for stateful applications, while PDBs ensure that a minimum number of pods remain available during voluntary disruptions like upgrades.

Exam trap

PCA often tests the confusion between stateless and stateful workload management, where candidates might choose Deployments or HPA for stateful applications, overlooking the need for StatefulSets and PDBs to ensure availability during upgrades.

How to eliminate wrong answers

Option A is wrong because Cluster Autoscaler adjusts node pool size based on demand and does not directly protect pods from disruption during upgrades. Option B is wrong because a Deployment with HorizontalPodAutoscaler is designed for stateless applications and does not provide stable storage or identity; HPA scales pods but does not prevent disruptions. Option D is wrong because PersistentVolumeClaims with ReadWriteMany access mode allow multiple pods to access the same volume, but this alone does not ensure pod disruption protection during upgrades; it is a storage configuration, not a disruption control.

646
Multi-Selectmedium

A retail company is designing a new microservices architecture on Google Cloud. They want to minimize operational overhead, enable independent deployment of services, and ensure that a failure in one service does not cascade to others. They also want to use managed services where possible. Which two design choices should the architect recommend? (Choose two.)

Select 2 answers
A.Implement asynchronous communication between services using Pub/Sub topics
B.Deploy each microservice as a separate Cloud Run service with its own service account
C.Deploy all microservices into a single Google Kubernetes Engine cluster with a shared namespace
D.Use a single Compute Engine instance running all microservices in Docker containers
E.Use a shared Cloud SQL instance with a single database for all microservices
AnswersA, B

Pub/Sub provides durable, asynchronous messaging that decouples services and absorbs traffic spikes. If a downstream service is unavailable, messages are retained and delivered later, preventing cascading failures. This supports independent deployment and fault isolation because services do not need to be online simultaneously. Using Pub/Sub reduces operational overhead compared to self-managed message brokers, making it a suitable choice for the microservices design.

Why this answer

Cloud Run per microservice with distinct service accounts provides managed scaling, independent deployment, and least-privilege isolation. Pub/Sub enables asynchronous, durable communication that prevents cascading failures and decouples services. Together they meet the goals of minimal operational overhead, independent deployability, and fault isolation.

Shared databases, single VMs, and shared GKE namespaces introduce coupling and operational burden.

Exam trap

The trap here is assuming that a single GKE cluster with namespaces automatically provides fault isolation and minimal operational overhead, when in fact it still requires cluster management and does not isolate failures as cleanly as separate managed services.

647
MCQeasy

A startup is deploying a new containerized web application to Google Cloud. The team wants the simplest way to run containers without managing Kubernetes nodes, needs automatic scaling from zero, and wants to pay only when requests are being handled. Which Google Cloud service should the architect recommend?

A.App Engine flexible environment with a custom runtime for the container.
B.Google Kubernetes Engine with a zonal cluster and cluster autoscaler enabled.
C.Cloud Run, deploying the container image and configuring the service to allow unauthenticated or authenticated invocations.
D.Compute Engine managed instance groups running the container with a startup script that installs Docker.
AnswerC

Cloud Run runs containers on a fully managed platform, scales automatically including to zero when there is no traffic, and bills based on request handling and resource usage. There are no nodes to manage. It directly matches the startup's need for simplicity, scale-from-zero, and pay-per-use without Kubernetes operational overhead.

Why this answer

Cloud Run is a fully managed container runtime that abstracts away nodes, scales instances down to zero when idle, and charges for the resources consumed while handling requests. Deploying a container image and choosing the invocation authentication model is all that is required. This matches the startup's priorities of minimal operational effort, automatic scale-from-zero, and consumption-based billing without adopting Kubernetes.

Exam trap

The trap here is equating App Engine flexible environment with scale-to-zero, when the flexible environment keeps at least one instance and bills for it even when idle.

648
MCQmedium

A team wants to provide a consistent, low-latency experience for global users accessing static content (images, CSS, JS) hosted on Cloud Storage. They also need to be able to invalidate cached content quickly when updates occur. Which service should they use?

A.Cloud NAT
B.Cloud Load Balancing with backend bucket
C.Cloud Storage transfer service
D.Cloud CDN
AnswerD

Cloud CDN caches static content at Google's global edge locations, reducing latency for worldwide users while serving from Cloud Storage origins. Its cache invalidation feature lets the team purge stale objects quickly after updates, satisfying both the latency and invalidation constraints.

Why this answer

Cloud CDN caches content at edge locations for low latency. Cache invalidation allows purging updated content, which is essential for static assets.

649
MCQmedium

A company is designing a VPC Service Controls perimeter to protect data stored in Google Cloud. They need to allow access from their on-premises network via a Cloud VPN tunnel while blocking all internet-based access. What is the most secure and manageable approach?

A.Configure firewall rules to only allow traffic from the on-premises CIDR to the VPC.
B.Use Cloud VPN and Private Google Access to allow on-premises access without public IPs.
C.Configure a VPC Service Controls perimeter and create an access level that includes the on-premises CIDR range.
D.Use Cloud IAP (Identity-Aware Proxy) to restrict access based on identity and context.
AnswerC

An access level containing the on-premises CIDR range permits traffic arriving through the Cloud VPN tunnel while denying internet-originated requests. This satisfies both the on-premises access requirement and the block-all-internet constraint within one manageable perimeter.

Why this answer

VPC Service Controls (VPC SC) is the only Google Cloud-native mechanism that can create a security perimeter around managed services (like Cloud Storage, BigQuery) and restrict access based on an access level that includes the on-premises CIDR range. This ensures that only traffic originating from the on-premises network (via the Cloud VPN tunnel) is allowed, while all internet-based access is blocked, even if the request uses valid credentials. Firewall rules alone cannot restrict access to Google-managed APIs, and Private Google Access does not enforce a perimeter around services.

Exam trap

The trap here is that candidates often confuse network-level controls (firewall rules, Private Google Access) with service-level perimeter controls, mistakenly believing that blocking traffic at the VPC level is sufficient to protect Google-managed APIs that are accessed via external endpoints.

How to eliminate wrong answers

Option A is wrong because firewall rules only control traffic at the VPC network level and cannot block access to Google-managed APIs (e.g., Cloud Storage, BigQuery) that are accessed via external IPs; they do not create a service perimeter. Option B is wrong because Private Google Access allows on-premises traffic to reach Google APIs via private IPs but does not block internet-based access to those same APIs; it lacks the ability to define a perimeter that denies all external traffic. Option D is wrong because Cloud IAP controls access based on identity and context at the application layer, but it does not enforce network-level perimeter controls and cannot block access from the internet to the underlying Google Cloud services (e.g., Cloud Storage buckets) that are not fronted by IAP.

650
MCQeasy

A startup is deploying a new web application on Google Cloud. They want to ensure that their development, staging, and production environments are isolated from each other for security and billing purposes. They also want to apply different IAM policies per environment. Which Google Cloud resource hierarchy structure should the architect recommend?

A.Create a single project and use labels to separate environments.
B.Create a separate folder for each environment under the organization node, and place projects within those folders.
C.Create a separate organization for each environment.
D.Create a single project and use separate VPC networks for each environment.
AnswerB

Folders allow you to group projects and apply IAM policies at the folder level, which are inherited by all projects within. This provides isolation between environments and enables separate billing and security controls. It is the recommended way to structure a Google Cloud organization for multiple environments.

Why this answer

Using folders under the organization node allows you to group projects by environment and apply distinct IAM policies at the folder level. This provides both security isolation and separate billing, as each project can have its own billing account. It is the standard Google Cloud best practice for multi-environment setups.

Exam trap

The trap here is confusing network isolation or labeling with full environment isolation, which requires separate projects and folder-level IAM policies.

651
Multi-Selecteasy

A company runs a batch processing job that uses preemptible VMs. The job occasionally fails due to VM preemption. They want to improve reliability without significantly increasing cost. Which TWO actions should they take? (Choose TWO.)

Select 2 answers
A.Use a managed instance group with autoscaling and preemptible VMs
B.Use sole-tenant nodes to reduce risk of preemption
C.Switch to regular (non-preemptible) VMs
D.Implement a retry mechanism in the job to re-run failed tasks
E.Increase the number of preemptible VMs
AnswersA, D

A managed instance group automatically recreates preempted VMs, directly addressing the reliability constraint while retaining preemptible pricing. Autoscaling maintains capacity by adding instances when demand rises, so the batch job recovers without manual intervention. This satisfies the requirement to improve resilience without significantly increasing cost, since preemptible rates still apply.

Why this answer

Option A is correct because a managed instance group (MIG) with autoscaling and preemptible VMs automatically maintains the desired number of instances, replacing preempted VMs with new ones so the batch job can continue running with minimal disruption and without paying for non-preemptible capacity. Option D is correct because preemptible VMs can be reclaimed at any time, so building a retry mechanism into the job lets failed tasks be re-run on surviving or replacement instances, directly improving reliability at essentially no extra cost. Option B is not appropriate because sole-tenant nodes isolate hardware for compliance/licensing reasons and do not reduce the risk of preemption.

Option C would improve reliability but significantly increases cost, which the scenario explicitly wants to avoid. Option E merely adds more preemptible VMs; it does not address task recovery and still leaves the job vulnerable to preemption.

652
Multi-Selecthard

A company is moving a legacy application to Compute Engine. The application has inconsistent resource usage and the team wants to optimise costs without performance degradation. They are evaluating committed use discounts (CUDs) and other discount types. Which THREE statements are correct about CUDs? (Choose 3)

Select 3 answers
A.CUDs require a minimum of 10 instances to qualify
B.Spend-based CUDs are applied automatically to all eligible projects in the billing account
C.CUDs cannot be combined with sustained use discounts
D.CUDs provide a discount in exchange for committing to a minimum spend or resource usage for 1 or 3 years
E.Resource-based CUDs apply to a specific machine series and region
AnswersB, D, E

Spend-based CUDs are billing-account-level commitments, so Google Cloud automatically applies the resulting discount credits across all eligible projects under that billing account without per-project configuration. This satisfies the stem's cost-optimisation goal for inconsistent usage, since no resource-level matching is required.

Why this answer

Option B is correct because spend-based (flexible) committed use discounts are automatically applied across all eligible projects within the billing account, requiring no per-project management. Option D is correct because CUDs fundamentally exchange a 1-year or 3-year commitment to a minimum spend or resource usage for a discounted rate on Compute Engine resources. Option E is correct because resource-based CUDs are scoped to a specific machine family/series and region, so the commitment only discounts matching vCPUs and memory in that region.

Option A is wrong because CUDs have no 10-instance minimum; commitments are made in terms of spend or resource quantities. Option C is wrong because CUDs can be combined with sustained use discounts, with SUDs applying to usage not already covered by the CUD.

653
MCQmedium

A team is migrating a monolithic application to microservices on GKE. They want to gradually shift users to the new microservices version while keeping the old monolithic version running. They need to route a small percentage of users based on a cookie. Which traffic management approach should they use?

A.Use Istio VirtualService with match rules based on cookie and weighted destinations
B.Use Kubernetes Services with multiple Deployments and manual scaling
C.Configure an HTTP(S) load balancer with URL maps and backend services
D.Deploy two separate GKE clusters and use DNS-based traffic splitting
AnswerA

Istio VirtualService supports match conditions on request headers such as cookies, combined with weighted destination routing, enabling a defined percentage of cookie-matched users to reach the microservices version while the remainder continue to the monolith. This satisfies the gradual, cookie-based traffic shift.

Why this answer

Istio traffic management allows fine-grained routing based on HTTP headers, cookies, or other attributes. It supports traffic splitting and canary deployments with precise percentage control.

654
MCQhard

A company runs a stateful application on Compute Engine with persistent disks. They want to ensure data durability across a zone failure. What is the best approach?

A.Replicate data at application level to another instance in a different zone
B.Use Google Cloud NetApp Volumes with replication
C.Use regional persistent disks
D.Take regular snapshots of the persistent disks and store them in a multiregional bucket
AnswerC

Regional persistent disks synchronously replicate data across two zones within the same region, so a zone failure leaves a healthy replica available. Zonal persistent disks reside in a single zone and cannot satisfy the cross-zone durability constraint.

Why this answer

Regional persistent disks (RPDs) synchronously replicate data between two zones in the same region, providing an RPO of zero and automatic failover without application-level changes. This ensures data durability across a zone failure while maintaining consistent performance and low latency.

Exam trap

Google Cloud often tests the distinction between synchronous replication (regional persistent disks) and asynchronous backup (snapshots), leading candidates to choose snapshots for durability when they actually need zero RPO across a zone failure.

How to eliminate wrong answers

Option A is wrong because replicating data at the application level adds complexity, latency, and requires custom code, whereas Compute Engine offers a managed, synchronous replication solution. Option B is wrong because Google Cloud NetApp Volumes is a third-party service that is not natively integrated with Compute Engine for this use case and introduces additional cost and management overhead. Option D is wrong because regular snapshots stored in a multiregional bucket provide point-in-time recovery but have an RPO of minutes to hours and do not offer synchronous replication, so data written between snapshots is lost during a zone failure.

655
MCQhard

A company uses Cloud Bigtable for time-series data. They experience high latency and uneven load distribution across nodes. What is the most likely cause?

A.The data is stored in a single column family
B.The app is using strong reads instead of eventual consistency
C.The table has a single row key pattern that causes hot spotting
D.The cluster has too many nodes
AnswerC

Bigtable shards rows by row-key range, so a monotonically increasing or otherwise uniform key pattern funnels all writes to one tablet, creating hot spotting. That concentrated load explains both the uneven node distribution and the elevated latency.

Why this answer

Cloud Bigtable partitions data by row key range and distributes tablets across nodes. A single row key pattern (e.g., monotonically increasing timestamps) causes all writes to target the same tablet, creating a hot spot. This leads to uneven load distribution and high latency because one node is overwhelmed while others remain idle.

Exam trap

Google Cloud often tests the misconception that column families or read consistency levels are the root cause of performance issues, when in fact row key design is the primary driver of load distribution in Bigtable.

How to eliminate wrong answers

Option A is wrong because storing data in a single column family does not cause uneven load distribution; column families affect storage and read performance but not row key distribution. Option B is wrong because strong reads (read-after-write consistency) add latency but do not cause uneven load distribution across nodes; the issue is about write hot spotting, not read consistency. Option D is wrong because having too many nodes would reduce load per node, not increase latency or cause uneven distribution; the cluster would be over-provisioned, not hot-spotted.

656
MCQeasy

A company is migrating its on-premises data warehouse to BigQuery. They want to minimize the cost of storing large amounts of historical data that is rarely queried. The data must remain available for queries but can tolerate slightly longer query times. What should they do?

A.Export the data to Cloud Storage Nearline and delete it from BigQuery.
B.Partition the table by date and set a partition expiration to delete old data.
C.Use BigQuery's flexible pricing with flat-rate slots to reduce query costs.
D.Store the data in BigQuery long-term storage by ensuring the table is not modified for 90 consecutive days.
AnswerD

BigQuery automatically moves data to long-term storage after 90 days of no modifications, reducing storage costs by about 50%. The data remains queryable, and query performance is generally not affected. This approach requires no manual intervention and is ideal for rarely queried historical data.

Why this answer

BigQuery long-term storage automatically applies lower pricing to data that hasn't been modified for 90 days. This is the simplest and most cost-effective way to store rarely queried historical data while keeping it available for queries. Other options either make data unavailable, delete it, or address query costs instead of storage.

Exam trap

The trap here is assuming that exporting data to a cheaper storage class is the best way to reduce costs, but that would make the data unavailable for direct BigQuery queries.

657
MCQhard

A company runs multiple microservices on Cloud Run. Each service uses a Serverless VPC Access connector to connect to a shared Cloud Memorystore for Redis instance (standard tier) in a VPC network. The Redis instance is configured with a firewall rule that allows TCP connections on port 6379 from the VPC connector's subnet (10.8.0.0/28). After a recent code update, the order-service fails to connect to Redis, while the user-service continues to work. The error logs in order-service show 'connection refused'. The engineer verifies that both services use the same VPC connector, the same Redis instance IP, and the same service account. The VPC connector's metrics show no errors. What is the most likely cause?

A.The order-service is deployed in a different region than the Redis instance.
B.The order-service code now attempts to connect to Redis on port 6380.
C.The VPC connector is out of memory.
D.The Redis instance has reached its maximum number of connections.
AnswerB

Redis standard tier listens on TCP 6379, so a firewall rule permitting only that port would refuse a connection on 6380. The unchanged user-service confirms the connector and instance are healthy, isolating the port change in order-service code.

Why this answer

The order-service successfully connects to the same Redis instance before the code update. After the update, it fails with 'connection refused', while the user-service still works. Since both services share the same networking configuration and the firewall only allows port 6379, the most likely cause is that the order-service code now attempts to connect on a different port (e.g., 6380) that is not allowed by the firewall.

Other options would affect both services or are inconsistent with the symptoms.

658
MCQmedium

A data engineer needs to analyze data in BigQuery but must mask personally identifiable information (PII) based on user roles. Which service should they use?

A.BigQuery column-level security
B.Cloud Key Management Service
C.Cloud Data Catalog
D.Cloud Data Loss Prevention (DLP)
AnswerA

BigQuery column-level security uses policy tags in Data Catalog to restrict access to specific columns, masking or denying PII according to the user's role. This satisfies the requirement to mask personally identifiable information based on user roles without duplicating datasets.

Why this answer

BigQuery column-level security allows you to apply fine-grained access controls to specific columns containing PII, such as by using policy tags to restrict access based on user roles. This directly meets the requirement to mask sensitive data in BigQuery without moving or duplicating data, as it integrates with Cloud IAM to enforce role-based access at query time.

Exam trap

A common trap in Google PCA exams is confusing Cloud DLP (which is for classification and de-identification before data storage) with BigQuery column-level security (which provides runtime access control based on roles). DLP does not enforce role-based masking at query time; column-level security with policy tags does.

How to eliminate wrong answers

Option B (Cloud Key Management Service) is wrong because it manages encryption keys for data at rest or in transit, not role-based masking or access control at the column level in BigQuery. Option C (Cloud Data Catalog) is wrong because it is a metadata management and discovery service for tagging and searching assets, not a tool for enforcing data masking or access policies. Option D (Cloud Data Loss Prevention) is wrong because while it can inspect and classify PII, it is not a runtime access control service; it is typically used for scanning and de-identification before ingestion, not for dynamic role-based masking within BigQuery queries.

659
MCQeasy

A developer is writing a Cloud Function that processes files uploaded to a Cloud Storage bucket. Which trigger should they use?

A.HTTP trigger
B.Firestore trigger
C.Cloud Storage trigger
D.Pub/Sub trigger
AnswerC

A Cloud Storage trigger fires the function in response to object events such as finalise or delete in a bucket, which is exactly the upload-processing pattern described. Eventarc delivers these Cloud Storage events, so no polling or manual invocation is needed.

Why this answer

To process files uploaded to a Cloud Storage bucket, the developer should use a Cloud Storage trigger. This trigger type is specifically designed to invoke a Cloud Function in response to events in a Cloud Storage bucket, such as object creation, deletion, or metadata updates.

Exam trap

PCA often tests the appropriate trigger for a given event source, and candidates might choose Pub/Sub because Cloud Storage can publish to Pub/Sub, but the direct Cloud Storage trigger is the intended answer for simplicity and native integration.

How to eliminate wrong answers

Option A is wrong because an HTTP trigger is used for functions invoked via HTTP requests, not for reacting to storage events. Option B is wrong because a Firestore trigger responds to changes in a Firestore database, not Cloud Storage. Option D is wrong because a Pub/Sub trigger is used for messages published to a Pub/Sub topic; while Cloud Storage can send notifications to Pub/Sub, the direct trigger for Cloud Functions is the Cloud Storage trigger, which simplifies the integration.

660
Multi-Selectmedium

Your organization is implementing a Disaster Recovery plan for a critical database. Which THREE components are essential for a robust DR strategy? (Choose 3)

Select 3 answers
A.A single global load balancer for both regions.
B.Automated failover process to switch traffic to the DR region.
C.Data replication strategy (synchronous or asynchronous) to a secondary region.
D.Regular DR drills (testing failover at least once per quarter).
E.Using a single zone for the primary region.
AnswersB, C, D

Automation minimizes manual errors and reduces RTO.

Why this answer

An automated failover process is essential for minimizing Recovery Time Objective (RTO) in a Disaster Recovery strategy. Without automation, manual intervention introduces delays and risks of human error, which can extend downtime significantly. In cloud or on-premises environments, automated failover typically relies on health checks, DNS updates, or traffic manager rules to seamlessly redirect traffic to the DR region when the primary fails.

Exam trap

Google Cloud often tests the misconception that a single global load balancer provides high availability, when in fact it becomes a single point of failure unless it is itself deployed in a redundant, multi-region architecture.

661
MCQeasy

A startup runs a public API on Compute Engine behind an external HTTP(S) load balancer. The security team wants to block common web attacks such as SQL injection and cross-site scripting at the edge, with minimal changes to the application, and they want the protection rules to be managed centrally and updated as new signatures are released. What should the architect recommend?

A.Enable Identity-Aware Proxy on the backend service and require Google account authentication for all API calls.
B.Install a third-party WAF on each Compute Engine instance and configure it to read request bodies before the application does.
C.Deploy Cloud Armor security policies with preconfigured WAF rules and attach the policy to the backend service of the external HTTP(S) load balancer.
D.Create VPC firewall rules that deny traffic containing suspicious URL patterns to the load balancer's forwarding rule.
AnswerC

Cloud Armor attaches to the backend service of an external HTTP(S) load balancer and offers preconfigured WAF rules based on the ModSecurity core rule set, covering SQL injection and cross-site scripting. Google maintains and updates the signatures, so the startup gets edge protection without modifying application code, matching the centralized management requirement.

Why this answer

Cloud Armor is Google Cloud's edge security service that attaches to external HTTP(S) load balancer backend services. Its preconfigured WAF rules, derived from the ModSecurity core rule set, detect and block SQL injection, cross-site scripting, and other OWASP-style attacks. Because Google manages the rule signatures and policies are configured once at the load balancer, the application needs no changes and protection is centralized.

Exam trap

The trap here is confusing identity-based access control or network firewall rules with application-layer attack filtering, which only Cloud Armor performs at the load balancer edge.

662
MCQeasy

A startup wants to deploy a containerized web application that must scale automatically based on incoming request concurrency. The team wants to avoid managing Kubernetes nodes or clusters and prefers a fully managed serverless platform with per-request billing. Which Google Cloud service should the architect recommend?

A.Google Kubernetes Engine Autopilot
B.Cloud Run
C.Compute Engine managed instance group with autoscaling
D.App Engine standard environment
AnswerB

Cloud Run runs containers on a fully managed serverless platform, scales automatically based on request concurrency, scales to zero when idle, and bills per request and resource usage. It requires no cluster or node management, which aligns exactly with the startup's stated constraints for this web application.

Why this answer

Cloud Run is the managed serverless container platform that scales on request concurrency, scales to zero, and bills per request, with no cluster or node administration. It accepts standard container images, so the startup can deploy its existing artifact directly while gaining automatic scaling and usage-based pricing that the other options cannot provide.

Exam trap

The trap here is treating GKE Autopilot as serverless and per-request, when it still bills for cluster infrastructure and targets Kubernetes workloads rather than request-driven container scaling.

663
MCQeasy

Which Google Cloud service allows organizations to define perimeters that protect resources and data from exfiltration to other VPCs or networks?

A.Private Service Connect
B.Identity-Aware Proxy (IAP)
C.Cloud Armor
D.VPC Service Controls
AnswerD

VPC Service Controls define service perimeters that restrict access to Google Cloud resources, preventing data exfiltration across project, VPC or network boundaries. This directly satisfies the requirement to protect resources and data from unauthorised movement to other VPCs or networks.

Why this answer

VPC Service Controls lets organizations define service perimeters that restrict access to Google Cloud services and prevent data exfiltration across project, VPC, or network boundaries. It enforces context-aware access at the API level, blocking operations that would move data outside the perimeter even if IAM would otherwise allow them. This is exactly the 'protect resources and data from exfiltration to other VPCs or networks' requirement.

Exam trap

PCA often tests the confusion between network-level controls (Private Service Connect, Cloud Armor) and API-level data-exfiltration controls (VPC Service Controls) — the key discriminator is whether the question mentions preventing data movement across boundaries.

How to eliminate wrong answers

Option A is wrong because Private Service Connect provides private connectivity to Google APIs and third-party services via internal IPs — it controls how traffic reaches services, not whether data can be exfiltrated across perimeters. Option B is wrong because Identity-Aware Proxy (IAP) controls user access to web applications and VMs based on identity and context, but it does not define data-exfiltration perimeters around GCP services. Option C is wrong because Cloud Armor is a WAF/DDoS protection service that filters HTTP(S) traffic at the edge — it protects against attacks, not against data exfiltration between projects or VPCs.

664
MCQhard

A healthcare company stores patient records in a Cloud Storage bucket. Compliance requires that all data be encrypted with customer-managed keys, and that the company can revoke access to the data by disabling the key. They also need to audit every key usage. Which approach should they take?

A.Use Customer-Managed Encryption Keys (CMEK) with Cloud KMS and enable Cloud Audit Logs for Cloud KMS.
B.Use default Google encryption and configure a Cloud Storage retention policy.
C.Use Customer-Supplied Encryption Keys (CSEK) and enable Cloud Audit Logs for Cloud Storage.
D.Use Google-managed encryption keys (GMEK) and enable Cloud Audit Logs for Cloud Storage.
AnswerA

CMEK allows the customer to manage keys in Cloud KMS, including disabling or destroying them to revoke access. Enabling Cloud Audit Logs for Cloud KMS records all key usage, satisfying the audit requirement. This approach meets both the encryption control and auditability needs for compliance.

Why this answer

Customer-Managed Encryption Keys (CMEK) in Cloud KMS allow the organization to control the encryption key lifecycle, including disabling the key to revoke access to data. Enabling Cloud Audit Logs for Cloud KMS provides an audit trail of all key operations, which is essential for compliance. This combination meets both the encryption control and auditing requirements.

Exam trap

The trap here is assuming that Customer-Supplied Encryption Keys (CSEK) provide the same centralized management and audit capabilities as CMEK, but CSEK keys are managed externally and lack integrated audit logging.

665
MCQhard

An organization is migrating a legacy monolithic application to Google Cloud. The application currently runs on a single server with an on-premises database. The application is stateful and requires low-latency access to the database. The migration must minimize downtime and ensure high availability. Which architecture should the company adopt?

A.Deploy on GKE with StatefulSets and use Cloud Spanner for global consistency.
B.Deploy on Compute Engine with a regional persistent disk and use Cloud SQL for PostgreSQL with regional high availability.
C.Deploy on App Engine Standard Environment and use Cloud Firestore in Datastore mode.
D.Deploy on Cloud Run and use Cloud SQL with read replicas.
AnswerB

A regional persistent disk keeps the stateful application's data synchronously replicated across zones, while Cloud SQL for PostgreSQL regional HA provides an automatic standby in a second zone. Together they deliver the required high availability and low-latency database access, and minimise downtime during cutover.

Why this answer

It combines Compute Engine with a regional persistent disk for synchronous replication across zones, ensuring high availability with minimal downtime during a zonal failure. Cloud SQL for PostgreSQL with regional high availability provides a managed, low-latency database with automatic failover, meeting the stateful application's need for low-latency access and high availability without the complexity of container orchestration.

Exam trap

The trap here is that candidates often overcomplicate the solution by choosing containerized or serverless options (GKE, Cloud Run, App Engine) without recognizing that a legacy monolithic stateful application with low-latency requirements is best served by a simple, proven VM-based architecture with regional persistent disks and a managed relational database with synchronous replication.

How to eliminate wrong answers

Option A is wrong because GKE with StatefulSets introduces orchestration overhead and potential downtime during cluster upgrades or node failures, and Cloud Spanner, while globally consistent, adds latency and cost overkill for a single-region low-latency requirement. Option C is wrong because App Engine Standard Environment is stateless by design and does not support stateful applications with persistent local storage, and Cloud Firestore in Datastore mode is a NoSQL database that does not provide the relational consistency and low-latency access expected from a legacy monolithic database. Option D is wrong because Cloud Run is stateless and ephemeral, requiring external storage for state, and Cloud SQL with read replicas does not provide synchronous replication for high availability; read replicas are asynchronous and cannot guarantee zero data loss during a failover.

666
MCQmedium

A company is designing a hybrid cloud architecture where on-premises applications need to access data stored in a Cloud Storage bucket. The company requires that traffic between on-premises and Google Cloud does not traverse the public internet and must be encrypted. They also need dedicated bandwidth. Which Google Cloud service should the solutions architect use?

A.VPC Network Peering between on-premises and Google Cloud.
B.Cloud CDN with private origin access.
C.Cloud VPN with HA VPN.
D.Cloud Interconnect with Dedicated Interconnect.
AnswerD

Dedicated Interconnect provides a direct physical connection between on-premises and Google Cloud, bypassing the public internet. It offers dedicated bandwidth and supports encryption via MACsec or application-level encryption. This meets all requirements: private connectivity, dedicated bandwidth, and encryption.

Why this answer

Dedicated Interconnect offers a private, dedicated connection between on-premises and Google Cloud, avoiding the public internet and providing consistent bandwidth. It supports encryption through MACsec or higher-layer protocols. This satisfies the requirements for private, encrypted, and dedicated connectivity for accessing Cloud Storage data.

Exam trap

The trap here is confusing Cloud VPN, which uses the public internet, with Cloud Interconnect, which provides a private dedicated connection, and overlooking that Dedicated Interconnect can also support encryption.

667
Multi-Selectmedium

A company is deploying a critical application on GKE and wants to ensure high availability during node upgrades and failures. Which TWO configurations should they implement? (Choose 2.)

Select 2 answers
A.Enable Workload Identity for the service account
B.Configure a PodDisruptionBudget for the deployment
C.Create a multi-zonal node pool to spread nodes across multiple zones
D.Use a HorizontalPodAutoscaler with high target utilization
E.Enable Cluster Autoscaler on the node pool
AnswersB, C

A PodDisruptionBudget guarantees a minimum number of replicas remain available during voluntary disruptions such as node upgrades, directly satisfying the high-availability requirement. It prevents GKE's node drain from evicting too many pods simultaneously, though it does not protect against unplanned node failures.

Why this answer

Option B is correct because a PodDisruptionBudget (PDB) with minAvailable or maxUnavailable ensures that voluntary disruptions such as node drains during upgrades keep a minimum number of replicas running, preserving availability. Option C is correct because a multi-zonal node pool spreads nodes across multiple zones in the region, so a zone-level failure or maintenance event does not take down all nodes hosting the application's pods. Option A (Workload Identity) only maps Kubernetes service accounts to Google Cloud IAM identities for secure API access and does not affect availability during upgrades or failures.

Option D (HorizontalPodAutoscaler) scales replicas based on load metrics but does not protect against node drains or zone outages. Option E (Cluster Autoscaler) adds or removes nodes based on pending pods and capacity, which helps with scaling but does not by itself guarantee availability during upgrades or zonal failures.

Exam trap

The trap here is confusing scaling features (HPA, Cluster Autoscaler) with availability features (PDB, multi-zonal node pools) — candidates often pick autoscaling options because they sound like they improve resilience.

668
MCQeasy

A small development team is prototyping a containerized application on Google Cloud. They want the least operational overhead for running containers, automatic scaling based on incoming requests, and the ability to scale to zero when there is no traffic. They do not need Kubernetes APIs or custom networking. Which compute option should the architect recommend?

A.Google Kubernetes Engine Autopilot cluster
B.Cloud Run services with request-based autoscaling
C.Compute Engine managed instance groups with an autoscaler
D.Cloud Functions with a container image as the deployment artifact
AnswerB

Cloud Run runs containers in a fully managed, request-driven environment, scales automatically with incoming requests, and can scale to zero when idle so the team pays nothing during quiet periods. It requires no cluster or node management and no Kubernetes expertise, making it the lowest-overhead fit for this prototype.

Why this answer

Cloud Run is a fully managed serverless platform for containers that scales automatically based on requests and can scale to zero when idle. It removes the need to manage clusters, nodes, or autoscaling policies, which directly addresses the team's desire for minimal operational overhead and cost efficiency during periods without traffic.

Exam trap

The trap here is assuming that serverless containers require Kubernetes, when Cloud Run provides container execution without any cluster management.

669
MCQmedium

A company has Compute Engine instances in us-east1-a and us-east1-b zones. They want to allow communication between these instances with minimal latency and no additional cost. What is the best networking approach?

A.Configure VPC Network Peering between two separate VPC networks.
B.Use a single VPC network that includes both zones.
C.Create a new subnet in each zone and use Cloud NAT.
D.Set up a Cloud VPN between the zones.
AnswerB

A single VPC network spans all zones within a region, so instances in us-east1-a and us-east1-b communicate over Google's internal network using private RFC 1918 addresses. Traffic stays within the region, giving low latency with no additional egress cost.

Why this answer

A single VPC network spans all regions and zones, allowing instances in different zones (us-east1-a and us-east1-b) to communicate using internal IP addresses with low latency and no additional cost. This is because VPC networks provide flat, global networking by default, and traffic between zones within the same VPC uses Google's internal backbone without incurring egress charges.

Exam trap

The trap here is that candidates may overcomplicate the solution by thinking they need separate networks or VPNs for zone-to-zone communication, when in fact a single VPC inherently supports flat, cost-free internal connectivity across zones.

How to eliminate wrong answers

Option A is wrong because VPC Network Peering is used to connect separate VPC networks, which adds complexity and is unnecessary when instances are in the same VPC; it also does not reduce latency or cost compared to a single VPC. Option C is wrong because Cloud NAT is designed for outbound internet access from private instances, not for inter-zone communication, and it would introduce additional latency and cost. Option D is wrong because Cloud VPN is a site-to-site VPN solution for connecting on-premises networks or different VPCs across regions, not for intra-VPC zone-to-zone communication, and it adds latency and cost.

670
MCQmedium

A company runs a critical application on Compute Engine instances in a managed instance group (MIG) with autoscaling. During a traffic spike, some instances become unhealthy but are not automatically replaced. What is the most likely cause?

A.The MIG is regional and one zone failed.
B.The autohealing health check is misconfigured.
C.The instance template has a startup script error.
D.The HTTP load balancer's health check is failing.
AnswerB

Autohealing relies on a health check to detect and recreate unhealthy instances. If that health check is misconfigured — wrong path, port, or thresholds — the MIG never marks instances unhealthy, so no automatic replacement occurs despite the traffic spike.

Why this answer

The most likely cause is that the autohealing health check is misconfigured. In a managed instance group, autohealing relies on a health check to detect unhealthy instances and trigger replacement. If the health check is misconfigured (e.g., wrong port, path, or protocol), the MIG will not recognize instances as unhealthy and will not automatically replace them, even during a traffic spike.

Exam trap

Google Cloud often tests the distinction between the MIG's autohealing health check and the load balancer's health check, leading candidates to incorrectly attribute instance replacement failures to load balancer issues rather than the MIG's own health check configuration.

How to eliminate wrong answers

Option A is wrong because a regional MIG with a single zone failure would still trigger autohealing in the remaining healthy zones, and the MIG would replace instances in the failed zone if the health check is correctly configured. Option C is wrong because a startup script error would cause instances to fail at boot, but the MIG would still attempt to replace them based on the health check; the issue is not about the template but the detection mechanism. Option D is wrong because the HTTP load balancer's health check is separate from the MIG's autohealing health check; a failing load balancer health check does not prevent the MIG from replacing unhealthy instances if its own health check is properly configured.

671
Multi-Selectmedium

A company is moving a legacy monolithic application to a microservices architecture on Google Cloud. They want to minimize operational overhead and automatically scale each service independently. Which TWO compute services should they consider? (Choose two.)

Select 2 answers
A.Cloud Run
B.Compute Engine with managed instance groups
C.Google Kubernetes Engine (GKE) Standard
D.Cloud Functions
E.Google Kubernetes Engine (GKE) Autopilot
AnswersA, E

Cloud Run runs containerised services serverlessly, scaling each one independently from zero based on incoming requests. This directly satisfies the stem's constraints: minimal operational overhead, since no cluster or nodes are managed, and per-service automatic scaling, which the monolithic-to-microservices migration requires.

Why this answer

Cloud Run (A) is correct because it is a fully managed serverless container platform that abstracts away all infrastructure, scales each containerized microservice automatically (including to zero), and charges only for resources used, directly minimizing operational overhead. GKE Autopilot (E) is correct because it is a fully managed Kubernetes mode where Google provisions and manages the nodes and control plane, while still providing Kubernetes orchestration that lets each microservice scale independently with minimal operational burden. Compute Engine with managed instance groups (B) is not ideal because it requires managing VMs, OS patching, and capacity planning, which increases operational overhead.

GKE Standard (C) is not the best fit because, although it orchestrates containers, the cluster's nodes and infrastructure remain the customer's responsibility, adding operational overhead compared to Autopilot. Cloud Functions (D) is not appropriate here because it is an event-driven FaaS for short-lived functions, not a general platform for running long-lived containerized microservices.

Exam trap

The trap is that GKE Standard and Compute Engine MIGs sound 'managed,' but the exam expects you to recognize that only Cloud Run and GKE Autopilot remove node-level operational overhead.

672
Multi-Selectmedium

A company wants to improve the performance of their Cloud SQL for PostgreSQL instance. They notice many idle connections and slow queries. Which THREE actions could help? (Choose 3)

Select 3 answers
A.Add appropriate indexes
B.Add read replicas
C.Use PgBouncer for connection pooling
D.Enable private IP
E.Increase disk size
AnswersA, B, C

Indexes let PostgreSQL satisfy query predicates without sequential scans, cutting execution time for the slow queries observed. This addresses the query-performance half of the scenario directly, reducing per-query resource consumption on the Cloud SQL instance.

Why this answer

Option A (Add appropriate indexes) is correct because missing indexes force sequential scans on large tables, and creating B-tree or other suitable indexes lets PostgreSQL satisfy WHERE, JOIN, and ORDER BY clauses with index scans, directly reducing slow query latency. Option B (Add read replicas) is correct because Cloud SQL read replicas offload read-only SELECT traffic from the primary instance, increasing read throughput and reducing contention on the primary for read-heavy workloads. Option C (Use PgBouncer for connection pooling) is correct because PgBouncer multiplexes many client connections over a small pool of backend PostgreSQL connections, which directly addresses the many idle connections consuming memory and backend process slots.

Option D (Enable private IP) is not correct because private IP only changes network routing and security exposure; it does not improve query performance or reduce idle connections. Option E (Increase disk size) is not correct because disk size affects storage capacity and, on some tiers, IOPS, but it does not address idle connections or slow queries caused by poor indexing or connection churn.

673
MCQeasy

A healthcare company stores patient documents in Cloud Storage. Compliance requires that documents be retained for seven years and that no user, including administrators, can delete or overwrite them during that period. The company wants the simplest configuration that enforces this. What should the architect implement?

A.Enable Object Versioning and configure a lifecycle rule to delete noncurrent versions after seven years.
B.Apply a bucket-level IAM policy that denies the storage.objects.delete permission to all users.
C.Set a bucket retention policy with a retention period of seven years and lock the policy.
D.Use a Cloud Storage transfer job to copy objects to a second bucket in a different region every day.
AnswerC

A locked retention policy prevents objects from being deleted or overwritten until the retention period expires, and it cannot be removed or shortened once locked. This enforces immutability for seven years for all users, including administrators, with minimal configuration. It directly satisfies the compliance requirement without custom code or external tooling.

Why this answer

The requirement is for immutable retention that even administrators cannot bypass. A bucket retention policy sets a minimum retention period during which objects cannot be deleted or replaced, and locking the policy makes it permanent. Object Versioning, IAM deny rules, and cross-bucket copies do not provide the same enforceable, time-bound guarantee against both deletion and overwrite.

Exam trap

The trap here is assuming that versioning or IAM restrictions provide immutability, when only a locked retention policy prevents both deletion and overwrite by any user.

674
Multi-Selecthard

Which THREE options are valid strategies for disaster recovery (DR) in Google Cloud?

Select 3 answers
A.Store hourly snapshots of Compute Engine disks in the same region.
B.Deploy a mirrored environment in another region and use Traffic Director to fail over.
C.Enable Cloud CDN to cache static content from multiple origins.
D.Use a Cloud Storage bucket in a different region with Object Versioning enabled.
E.Configure a cross-region replica for Cloud SQL and promote it during failover.
AnswersB, D, E

A mirrored environment in a second region provides a warm or hot standby, and Traffic Director performs global load balancing with health-checked failover, redirecting traffic when the primary region fails. This satisfies the requirement for a cross-region DR strategy on Google Cloud.

Why this answer

Option B is correct because deploying a mirrored environment in a second region and using Traffic Director for global load balancing and failover provides true cross-region DR, ensuring workloads survive a full regional outage. Option D is correct because a Cloud Storage bucket in a different region with Object Versioning enabled gives durable, geographically separated copies of data and protects against accidental deletion or overwrite, which is a valid DR strategy. Option E is correct because a Cloud SQL cross-region replica can be promoted to a standalone primary during a regional failure, restoring database availability in another region.

Option A is not a valid DR strategy because snapshots stored in the same region are lost if that region fails, so they do not provide disaster recovery. Option C is not a DR strategy because Cloud CDN caching static content from multiple origins improves performance and availability but does not by itself recover from a regional disaster or protect stateful data.

Exam trap

The trap here is confusing high-availability features (like snapshots or CDN) with true disaster recovery, which requires geographic separation and automated failover mechanisms.

675
Multi-Selectmedium

A retail company is building a new application on Google Cloud. The security team requires that all data at rest be encrypted with keys the company manages, that key usage be auditable, and that the application on Compute Engine never store long-lived credentials on disk. The architect is selecting controls for the design. (Choose two.)

Select 2 answers
A.Enable Cloud External Key Manager with a third-party provider to hold the root key material for all disks and databases.
B.Use Google-managed encryption keys for the disks and rely on Cloud Audit Logs to record who accessed the data.
C.Store a service account key JSON file in Secret Manager and mount it into the instance at boot through a startup script.
D.Create a Cloud KMS key ring in the same region as the data and use a customer-managed encryption key (CMEK) to encrypt the disks and databases.
E.Attach a service account to the Compute Engine instances and use the metadata server to obtain short-lived access tokens for Google Cloud APIs.
AnswersD, E

CMEK lets the company own the key lifecycle and rotate or disable keys on its own schedule, which satisfies the requirement that the company manage the keys. Cloud KMS records key usage in Cloud Audit Logs, so every wrap and unwrap operation is attributable. Placing the key ring in the same region as the data also keeps the encryption path local and reduces latency for the data services using the key.

Why this answer

The two requirements are company-controlled encryption keys and no long-lived credentials on the instances. Customer-managed encryption keys in Cloud KMS satisfy the first, with audit logging of key use built in. Attaching a service account and pulling short-lived tokens from the metadata server satisfies the second, because the workload never needs a downloaded key file.

Together they cover the mandated controls without adding an external key manager dependency.

Exam trap

The trap here is assuming that storing a service account key in Secret Manager makes it acceptable, when the credential is still long-lived and still lands on the instance.

Page 8

Page 9 of 11

Page 10

All pages