Courseiva

Google PCA Practice Question: Managing and Provisioning a Solution Infrastructure

An organization wants to ensure that all Compute Engine instances in a project are patched with the latest security updates. They also want to enforce a custom configuration (e.g., disable root SSH login) across all instances. Which TWO Google Cloud services should they use together?

⚠ Common exam trap

PCA often tests the distinction between infrastructure provisioning (Deployment Manager) and ongoing configuration management (OS Config), causing candidates to pick Deployment Manager for enforcement tasks.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OS Config patch management

Option B, OS Config patch management, is correct because it is the Google Cloud service that lets you scan and automatically apply OS security patches to Compute Engine instances across a project, satisfying the requirement to keep all instances patched with the latest security updates. Option D, OS Config OS policies, is correct because it lets you define and enforce a custom desired-state configuration (such as disabling root SSH login via an OS policy assignment) across all instances in the project. Together, patch management handles patching while OS policies enforce the custom configuration, which is exactly the combined outcome the organization wants. Option A, Cloud Monitoring, is not correct because it only observes metrics, logs, and alerts; it does not patch or enforce configuration. Option C, Cloud Deployment Manager, is not correct because it is an infrastructure-as-code deployment tool for provisioning resources, not for ongoing OS patching or enforcing in-guest configuration. Option E, Cloud Asset Inventory, is not correct because it only inventories and tracks cloud assets and their metadata; it cannot patch instances or apply OS-level policies.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Cloud Monitoring

    Why it's wrong here

    Cloud Monitoring collects metrics, logs and alerts; it cannot push OS patches or apply configuration state to instances. It is tempting because it surfaces patch-compliance data, but that is visibility, not remediation. The correct pairing is OS Config patch and OS Policy assignments, which actually execute on each VM.

  • ✓

    OS Config patch management

    Why this is correct

    OS Config patch management automates security update deployment across Compute Engine instances, satisfying the patching requirement. It operates via the OS Config agent on each VM, applying patch jobs on schedules you define. However, it alone cannot enforce the custom configuration; that needs OS Policy assignment, which is why pairing both services is required.

  • ✗

    Cloud Deployment Manager

    Why it's wrong here

    Deployment Manager provisions infrastructure declaratively at deploy time; it cannot continuously patch running instances or enforce ongoing OS configuration drift correction. It is tempting because templates can embed startup scripts, but these run once. OS Config patch jobs and OS Policy assignments provide the recurring enforcement the scenario demands.

  • ✓

    OS Config OS policies

    Why this is correct

    OS Config OS policies deliver both capabilities: patch management applies security updates on a schedule, while OS policy assignments enforce desired-state configuration such as disabling root SSH login across Compute Engine instances. Together they satisfy the stem's dual requirement for automated patching and consistent custom configuration enforcement.

  • ✗

    Cloud Asset Inventory

    Why it's wrong here

    Cloud Asset Inventory only inventories and exports resource metadata; it neither applies OS patches nor enforces configuration settings on instances. The scenario needs patch deployment plus configuration enforcement. Cloud Asset Inventory suits auditing, compliance reporting and asset-change tracking across projects.

About these practice questions

Courseiva writes every PCA question from scratch — 807 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Google Cloud exam blueprint

This PCA practice question is part of Courseiva's free Google Cloud certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCA exam.