Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure
An organization wants to ensure that all Compute Engine instances in a project are patched with the latest security updates. They also want to enforce a custom configuration (e.g., disable root SSH login) across all instances. Which TWO Google Cloud services should they use together?
⚠ Common exam trap
PCA often tests the distinction between infrastructure provisioning (Deployment Manager) and ongoing configuration management (OS Config), causing candidates to pick Deployment Manager for enforcement tasks.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OS Config patch management
Option B, OS Config patch management, is correct because it is the Google Cloud service that lets you scan and automatically apply OS security patches to Compute Engine instances across a project, satisfying the requirement to keep all instances patched with the latest security updates. Option D, OS Config OS policies, is correct because it lets you define and enforce a custom desired-state configuration (such as disabling root SSH login via an OS policy assignment) across all instances in the project. Together, patch management handles patching while OS policies enforce the custom configuration, which is exactly the combined outcome the organization wants. Option A, Cloud Monitoring, is not correct because it only observes metrics, logs, and alerts; it does not patch or enforce configuration. Option C, Cloud Deployment Manager, is not correct because it is an infrastructure-as-code deployment tool for provisioning resources, not for ongoing OS patching or enforcing in-guest configuration. Option E, Cloud Asset Inventory, is not correct because it only inventories and tracks cloud assets and their metadata; it cannot patch instances or apply OS-level policies.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Cloud Monitoring
Why it's wrong here
Cloud Monitoring collects metrics, logs and alerts; it cannot push OS patches or apply configuration state to instances. It is tempting because it surfaces patch-compliance data, but that is visibility, not remediation. The correct pairing is OS Config patch and OS Policy assignments, which actually execute on each VM.
- ✓
OS Config patch management
Why this is correct
OS Config patch management automates security update deployment across Compute Engine instances, satisfying the patching requirement. It operates via the OS Config agent on each VM, applying patch jobs on schedules you define. However, it alone cannot enforce the custom configuration; that needs OS Policy assignment, which is why pairing both services is required.
- ✗
Cloud Deployment Manager
Why it's wrong here
Deployment Manager provisions infrastructure declaratively at deploy time; it cannot continuously patch running instances or enforce ongoing OS configuration drift correction. It is tempting because templates can embed startup scripts, but these run once. OS Config patch jobs and OS Policy assignments provide the recurring enforcement the scenario demands.
- ✓
OS Config OS policies
Why this is correct
OS Config OS policies deliver both capabilities: patch management applies security updates on a schedule, while OS policy assignments enforce desired-state configuration such as disabling root SSH login across Compute Engine instances. Together they satisfy the stem's dual requirement for automated patching and consistent custom configuration enforcement.
- ✗
Cloud Asset Inventory
Why it's wrong here
Cloud Asset Inventory only inventories and exports resource metadata; it neither applies OS patches nor enforces configuration settings on instances. The scenario needs patch deployment plus configuration enforcement. Cloud Asset Inventory suits auditing, compliance reporting and asset-change tracking across projects.
Go deeper
Related to this question
Learn chapter
Resource Monitoring and Logging with Cloud Operations
Key term
Compute Engine
Compute Engine is Google Cloud's Infrastructure-as-a-Service (IaaS) offering that lets you create and run virtual machines on Google's infrastructure.
Key term
Organization
An Organization is a top-level container in Google Cloud that represents your company or entities and serves as the root node for all your cloud resources, policies, and access control.
About these practice questions
Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Google Cloud exam blueprint
This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.