Courseiva

CCNA Analyze and optimize technical and business processes Questions

43 questions · Analyze and optimize technical and business processes · All types, answers revealed

1
MCQeasy

A team uses Cloud Build for CI/CD. The builds are taking longer than expected due to dependency downloads. What is the best practice to speed up builds?

A.Increase the machine type to e2-highcpu-32 to speed up compilation.
B.Use Docker layer caching with Cloud Build by specifying a cache image or using Kaniko cache.
C.Use Artifact Registry to store built packages and pull them during build.
D.Store dependencies in Cloud Source Repositories and fetch them during build.
AnswerB

Kaniko or Docker layer caching stores previously built layers in a cache image, so Cloud Build reuses unchanged dependency layers instead of re-downloading and rebuilding them each run. This directly cuts the dependency-download time lengthening builds.

Why this answer

Docker layer caching allows Cloud Build to reuse previously built layers, significantly reducing the time spent re-downloading and re-installing dependencies. By specifying a cache image or using Kaniko's built-in cache, only changed layers are rebuilt, while unchanged dependency layers are pulled from the cache instead of being fetched from the internet each time.

Exam trap

The trap here is that candidates confuse increasing compute resources (Option A) with solving a network-bound problem, or they mistakenly think storing dependencies in a repository (Options C and D) eliminates the need to download them, when in fact only layer caching avoids re-downloading by reusing previously built layers.

How to eliminate wrong answers

Option A is wrong because increasing the machine type to e2-highcpu-32 primarily speeds up CPU-bound compilation tasks, not network-bound dependency downloads; the bottleneck here is network latency and download throughput, not CPU cores. Option C is wrong because Artifact Registry stores built packages (e.g., container images, Maven artifacts), not raw dependency files; pulling pre-built packages from Artifact Registry does not address the initial download of dependencies during the build process. Option D is wrong because Cloud Source Repositories is a Git repository hosting service, not a dependency cache; storing dependencies there would require manual management and does not integrate with standard package managers (e.g., pip, npm, Maven) to avoid re-downloading.

2
MCQeasy

A startup is deploying a new web application on Google Cloud. The application runs in containers on Google Kubernetes Engine (GKE) and uses a Cloud SQL for MySQL instance. The team wants to follow the principle of least privilege for the application's access to Cloud SQL. Which method should the architect recommend for authenticating the application to Cloud SQL?

A.Use Cloud SQL IAM database authentication with a dedicated service account for the application.
B.Configure a Cloud VPN tunnel between the GKE cluster and Cloud SQL, and use IP allowlisting.
C.Create a MySQL user with a strong password and store the password in a Kubernetes Secret.
D.Enable the Cloud SQL Admin API and use the default compute service account for authentication.
AnswerA

Cloud SQL IAM database authentication allows the application to authenticate using a service account's identity, eliminating static passwords. The service account can be granted minimal database roles, following least privilege. This integrates with IAM and provides short-lived credentials, which is the recommended approach for GKE workloads.

Why this answer

Cloud SQL IAM database authentication lets the application authenticate with a service account, removing static passwords and enabling fine-grained IAM roles. This follows least privilege by granting only the necessary database permissions to a dedicated service account. Storing passwords in Kubernetes Secrets, using the default compute service account, or relying on network controls do not provide identity-based least-privilege access.

Exam trap

The trap here is assuming that network-level controls like VPN or IP allowlisting provide authentication and least privilege, when they only restrict network paths.

3
MCQeasy

An online learning platform runs its API on a regional managed instance group behind an external Application Load Balancer. The operations team wants to release new versions with the ability to shift a small percentage of user traffic to the new version first, then increase it gradually, and roll back instantly if error rates rise. What should they implement?

A.Configure Cloud CDN with a cache key that includes the application version header and purge the cache after each deployment.
B.Enable autoscaling on the existing managed instance group and set the target CPU utilization lower during the release window.
C.Use an internal passthrough Network Load Balancer in front of the managed instance group and switch the target pool during the release.
D.Create a second managed instance group for the new version and use the load balancer's backend service with a small weight on the new group.
AnswerD

Two managed instance groups registered as backends of the same backend service let the Application Load Balancer distribute traffic by capacity or weight, enabling a canary release. Shifting weight gradually controls exposure, and setting the new group's weight back to zero reverts traffic immediately without redeploying, which matches the rollback requirement.

Why this answer

The Application Load Balancer supports multiple backends per backend service and can distribute traffic by weight or capacity, so registering a second managed instance group for the new version enables a canary. Adjusting weights shifts exposure gradually, and returning the new group's weight to zero restores the previous version immediately.

Exam trap

The trap here is confusing autoscaling or CDN caching with traffic splitting, when only the load balancer's backend weighting controls the share of requests each version receives.

4
Multi-Selecthard

A company uses Cloud Armor to protect their HTTP load balancer. They need to block traffic from a specific set of IP addresses and also prevent SQL injection attacks. Which two configurations should they use? (Choose TWO.)

Select 2 answers
A.IAM roles to restrict access
B.Firewall rules on the VM instances
C.Ingress rules on the VPC network
D.Security policies with IP deny rules
E.Web Application Firewall (WAF) rules with SQL injection preconfigured rules
AnswersD, E

IP deny rules in a Cloud Armor security policy match source addresses at the edge, dropping packets from the specified set before they reach the load balancer. This directly satisfies the requirement to block traffic from named IP addresses, independently of the SQL injection filtering handled by WAF rules.

Why this answer

Option D is correct because Cloud Armor security policies support IP deny rules (e.g., a rule with action 'deny(403)' and a srcIpRanges match condition) that block traffic from a specified set of source IP addresses at the HTTP(S) load balancer edge. Option E is correct because Cloud Armor provides preconfigured WAF rules, including the 'sqli' (SQL injection) rule set based on ModSecurity CRS signatures, which detect and block SQL injection attempts when attached to the backend service. Options A, B, and C are incorrect: IAM roles govern identity and API access rather than filtering malicious HTTP traffic, VM firewall rules and VPC ingress rules operate at Layers 3/4 on instances or subnets and cannot inspect HTTP payloads for SQL injection, and they are not the Cloud Armor mechanism for protecting an HTTP(S) load balancer.

Exam trap

The trap here is that candidates confuse network-layer controls (firewall rules, VPC ingress) with application-layer protection (WAF), or think IAM roles can filter traffic, when in fact Cloud Armor is the only service that combines IP-based deny rules with WAF capabilities for HTTP load balancers.

5
Drag & Dropmedium

Drag and drop the steps to implement a disaster recovery plan using Cloud Storage and Cloud Functions in the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Versioning protects against accidental deletion. The Cloud Function copies objects to the DR bucket.

6
MCQeasy

A developer is migrating a stateful application to GKE. The application requires persistent storage with high IOPS for a database. Which storage option is most suitable?

A.Local SSD
B.Persistent Disk SSD
C.Cloud Storage Fuse
D.Persistent Disk Standard
AnswerB

Persistent Disk SSD provides block storage backed by solid-state media, delivering the high IOPS a database demands. It supports ReadWriteOnce access for a single stateful pod, matching the persistent, high-performance storage requirement of the migrated application.

Why this answer

Persistent Disk SSD (pd-ssd) is the most suitable option for a stateful database on GKE requiring high IOPS because it provides block storage with consistent, high-performance IOPS and can be dynamically provisioned via PersistentVolumeClaims. Unlike Local SSD, pd-ssd persists data independently of the node lifecycle, ensuring data durability during pod rescheduling or node failures.

Exam trap

Google Cloud often tests the misconception that Local SSD is suitable for stateful workloads because of its high IOPS, but the trap is that candidates forget Local SSD is ephemeral and does not survive pod rescheduling or node failures.

How to eliminate wrong answers

Option A is wrong because Local SSD provides high IOPS but is ephemeral—data is lost if the pod is rescheduled or the node is deleted, making it unsuitable for stateful databases that require persistent storage. Option C is wrong because Cloud Storage Fuse is a file-system interface for Cloud Storage objects, not a block device; it introduces latency and lacks the low-level IOPS consistency needed for database workloads. Option D is wrong because Persistent Disk Standard (pd-standard) uses HDD-based storage with significantly lower IOPS and higher latency, which cannot meet the high IOPS requirements of a database.

7
MCQeasy

A company commits to using Compute Engine for 3 years and wants the maximum discount. Which purchasing option should they use?

A.3-year committed use discount.
B.Pay-as-you-go pricing.
C.Sustained use discounts.
D.1-year committed use discount.
AnswerA

A 3-year committed use discount applies to Compute Engine vCPU and memory spend, delivering the deepest discount (up to 57%) for a fixed three-year term. It directly satisfies the stem's maximum-discount constraint, unlike sustained use discounts, which accrue automatically but cap at 30% and require no commitment.

Why this answer

A 3-year committed use discount (CUD) offers the highest discount rate (up to 57% for most machine types) compared to 1-year CUDs (up to 37%) or pay-as-you-go pricing. By committing to a consistent resource usage for the full 3-year term, the company maximizes the discount on Compute Engine costs.

Exam trap

Google Cloud often tests the misconception that sustained use discounts provide the best long-term savings, but they are automatic and capped at 30%, whereas committed use discounts require a contractual commitment but offer significantly higher discounts for longer terms.

How to eliminate wrong answers

Option B is wrong because pay-as-you-go pricing provides no discount and is the most expensive option for long-term usage. Option C is wrong because sustained use discounts are automatic per-month discounts for running instances over 25% of a month, but they max out at 30% and do not require a commitment; they cannot match the deeper discount of a 3-year CUD. Option D is wrong because a 1-year committed use discount offers a lower discount rate (up to 37%) than a 3-year CUD (up to 57%), so it does not provide the maximum discount.

8
MCQhard

A healthcare company runs a critical patient portal on Compute Engine. The portal uses a Cloud SQL for PostgreSQL database. The company needs to perform a major version upgrade of the database with minimal downtime and wants to minimize the risk of data loss. They also want to be able to roll back quickly if issues arise. Which approach should they take?

A.Use Cloud SQL's in-place major version upgrade feature during a maintenance window, and rely on automated backups for rollback.
B.Export the database to a Cloud Storage bucket, create a new instance with the new version, and import the data.
C.Create a read replica, promote it to primary, and then upgrade the original instance.
D.Use Database Migration Service to migrate to a new Cloud SQL instance with the desired major version, then switch over.
AnswerD

Database Migration Service (DMS) can perform a minimal-downtime migration to a new Cloud SQL instance with a different major version. It continuously replicates data, allowing a quick cutover and keeping the original instance intact for rollback if needed. This meets the requirements for minimal downtime, low data loss risk, and quick rollback.

Why this answer

Database Migration Service enables a minimal-downtime migration to a new Cloud SQL instance with the desired major version. It continuously replicates data, so the cutover is quick and the original instance remains available for rollback. This approach minimizes data loss risk and downtime, unlike in-place upgrades or export/import.

Exam trap

The trap here is assuming that in-place major version upgrades are always safe and reversible, when they can cause downtime and are not easily rolled back.

9
MCQmedium

A media company's analytics team runs a nightly Apache Spark ETL job on a Dataproc cluster with 20 worker nodes. The job processes raw logs from Cloud Storage and writes Parquet files back to Cloud Storage. The cluster is created before the job starts and deleted after the job finishes, taking about 90 minutes total. The team wants to reduce the cost of this workload without changing the Spark code or increasing job runtime. What should they do?

A.Move the Spark job to a Dataproc Serverless for Spark workload to eliminate cluster management.
B.Replace the 20 n1-standard-4 workers with 10 n1-standard-8 workers to reduce node count.
C.Enable Dataproc's autoscaling policy on the cluster so worker nodes scale down during idle periods.
D.Use Spot VMs for the Dataproc worker nodes and set a graceful decommissioning timeout.
AnswerD

Spot VMs cost substantially less than standard VMs, and Dataproc supports them natively for worker nodes with graceful decommissioning so preempted nodes finish in-flight tasks before removal. Since the cluster is ephemeral and Spark can retry tasks, preemption risk is acceptable, directly lowering compute cost without touching code or extending runtime.

Why this answer

Spot VMs are the standard cost lever for fault-tolerant, ephemeral Dataproc batch workloads. Because the cluster exists only for the job duration and Spark tolerates task retries, preemption is an acceptable risk that is offset by a large discount. Autoscaling and resizing do not reduce the per-hour price of compute for a continuously busy job, and moving to Serverless changes the execution model rather than guaranteeing savings.

Exam trap

The trap here is assuming that autoscaling always saves money, when a short-lived, continuously busy batch cluster has no idle capacity for scale-down to reclaim.

10
MCQeasy

A company is running a web application on Compute Engine instances that average 20% CPU utilization. They want to reduce costs without impacting performance. What is the most effective action?

A.Rightsize instances to a smaller machine type based on usage metrics.
B.Change instance type to e2-standard-4.
C.Purchase 3-year committed use discounts.
D.Use preemptible instances for all traffic.
AnswerA

Rightsizing selects a smaller machine type whose vCPU and memory match the observed 20% utilisation, so the workload runs on cheaper instances without performance loss. This directly removes the cost of over-provisioned capacity identified by the usage metrics.

Why this answer

The instances are averaging only 20% CPU utilization, indicating they are over-provisioned. Rightsizing to a smaller machine type directly reduces the compute cost per instance while maintaining adequate performance for the current workload, as the smaller instance can handle the existing load without degradation.

Exam trap

The trap here is that candidates often choose committed use discounts (Option C) as a quick cost-saving measure, failing to realize that rightsizing first yields greater savings without long-term commitment, and that preemptible instances (Option D) are not viable for production traffic due to their ephemeral nature.

How to eliminate wrong answers

Option B is wrong because it specifies a particular machine type (e2-standard-4) without considering the current usage metrics; this is a generic recommendation that may not be the optimal size and could still be over-provisioned or under-provisioned. Option C is wrong because purchasing 3-year committed use discounts locks in a long-term commitment for the current instance types, which may still be over-provisioned; rightsizing first then applying commitments is more cost-effective. Option D is wrong because preemptible instances can be terminated at any time by Google Cloud, making them unsuitable for handling all traffic in a production web application that requires reliability and availability.

11
MCQmedium

A logistics company has a BigQuery dataset that is queried heavily by scheduled reports each morning. Finance wants predictable monthly spend and the ability to attribute query cost to each department. Analysts currently run ad hoc queries against on-demand pricing, and costs vary widely month to month. What should the architect recommend?

A.Set a custom quota on bytes billed per day for each department's service account and let queries fail when the quota is reached.
B.Create a separate project per department and enable BigQuery reservations with slot commitments assigned to each project.
C.Enable the BigQuery flat-rate legacy pricing model by purchasing a fixed number of slots per project.
D.Move the dataset to Cloud Bigtable and run the scheduled reports with a Dataflow job each morning.
AnswerB

BigQuery reservations with committed slots convert variable on-demand query charges into a fixed monthly cost, and assigning reservations per project gives each department an attributable capacity pool. This matches the finance requirement for predictability and per-department attribution, while scheduled reports draw from dedicated slots instead of competing for shared on-demand capacity.

Why this answer

Reservations with committed slots turn variable on-demand query charges into a fixed, forecastable monthly figure, and assigning capacity per project makes each department's usage attributable. This satisfies the finance requirement directly, whereas quotas merely cap usage and alternative engines add complexity without solving the predictability and attribution goals.

Exam trap

The trap here is choosing a quota or a deprecated flat-rate purchase when the requirement is predictable spend plus per-department attribution, which reservations and assignments provide.

12
MCQhard

A Cloud Spanner instance is experiencing high latency for point reads. The instance has 5 nodes and the read throughput is moderate. The table has a primary key with monotonically increasing values. What is the most likely cause and optimization?

A.Use interleaved tables to reduce the number of index lookups.
B.The instance is underprovisioned; add more nodes.
C.The primary key design causes hotspotting; use a hash prefix or add a leading random value.
D.The instance has too many nodes causing transaction conflicts; reduce nodes.
AnswerC

Monotonically increasing keys concentrate all writes on the final key range, so a single split absorbs the load. Adding a hash prefix or leading random value distributes writes across splits, removing the hotspot and restoring point-read latency.

Why this answer

The monotonically increasing primary key causes all writes to be directed to the last tablet (splitting point), creating a hotspot on one node. This hotspot leads to high latency for point reads because that node becomes a bottleneck. Adding a hash prefix or a leading random value distributes writes and reads evenly across all nodes, resolving the hotspotting issue.

Exam trap

Google Cloud often tests the misconception that adding more nodes solves all performance issues, but here the problem is a design flaw (hotspotting) that requires a key distribution strategy, not more capacity.

How to eliminate wrong answers

Option A is wrong because interleaved tables reduce join latency by colocating parent-child rows, but they do not address the root cause of hotspotting from a monotonically increasing primary key. Option B is wrong because the instance has moderate throughput and 5 nodes, so underprovisioning is not indicated; adding more nodes would not fix the hotspotting and could increase costs unnecessarily. Option D is wrong because having too many nodes does not cause transaction conflicts; Cloud Spanner uses a distributed transaction protocol (Paxos-based) that scales with nodes, and reducing nodes would not resolve the hotspotting issue.

13
Multi-Selectmedium

A company stores large amounts of data in Cloud Storage and wants to reduce costs. Which two actions should they take? (Choose two.)

Select 2 answers
A.Disable object versioning to prevent multiple versions.
B.Enable object versioning and configure lifecycle rules to delete noncurrent versions after 90 days.
C.Add bucket labels to track cost by department.
D.Configure lifecycle management to transition objects to Nearline or Coldline storage classes after 30 days.
E.Change the default storage class to Standard for all buckets.
AnswersB, D

Object versioning retains every overwrite and delete, which silently multiplies storage charges. A lifecycle rule that deletes noncurrent versions after 90 days bounds that accumulation while preserving a recovery window, directly reducing the bucket's storage cost.

Why this answer

Option B is correct because enabling object versioning while adding a lifecycle rule to delete noncurrent versions after 90 days prevents old object versions from accumulating indefinitely, which directly reduces storage costs from versioned data. Option D is correct because lifecycle management can automatically transition objects to colder storage classes such as Nearline or Coldline after 30 days, and these classes have lower storage pricing than Standard for infrequently accessed data. Option A is not appropriate because disabling object versioning removes data protection and recovery capability rather than being a cost-optimization best practice.

Option C does not reduce costs; bucket labels only improve cost tracking and reporting by department. Option E would likely increase costs because Standard is the most expensive default storage class for long-term or infrequently accessed data.

Exam trap

Google Cloud often tests the distinction between cost allocation (labels) and direct cost reduction (lifecycle rules), leading candidates to mistakenly choose labeling as a cost-saving measure.

14
Multi-Selecthard

Which THREE steps can reduce processing costs in a Dataflow streaming pipeline? (Choose three.)

Select 3 answers
A.Use side inputs instead of a cross join.
B.Use a batch pipeline for non-critical data.
C.Minimize the use of GroupByKey in streaming mode.
D.Use a custom runner.
E.Increase the number of workers.
AnswersA, B, C

Side inputs broadcast a small lookup dataset to each worker, letting the pipeline enrich events locally instead of performing a cross join. A cross join forces every element to pair with every other, exploding shuffle volume; replacing it with side inputs removes that multiplication, cutting processing cost.

Why this answer

Option A is correct because replacing a cross join with side inputs avoids the expensive fan-out of every element being paired with every element of the other collection, which drastically reduces the number of elements processed and shuffled in the streaming pipeline. Option B is correct because running non-critical data through a batch pipeline lets Dataflow use cheaper batch pricing and more efficient batch-optimized execution rather than paying for continuously running streaming workers. Option C is correct because GroupByKey in streaming mode forces a shuffle and holds state for each key until the window fires, so minimizing it (for example by using Combine or pre-aggregation) lowers shuffle volume, state storage, and processing cost.

Option D is not correct because a custom runner does not reduce Dataflow processing costs and is not a cost-optimization step. Option E is not correct because increasing the number of workers raises the amount of compute used and therefore increases, rather than reduces, processing costs.

Exam trap

Google Cloud often tests the misconception that scaling out (increasing workers) always reduces costs, when in fact it increases costs unless the pipeline is bottlenecked; the trap is to confuse throughput optimization with cost reduction.

15
MCQhard

A retail company runs a customer-facing API on GKE Autopilot in a single region. During a quarterly sales event, traffic triples for six hours and then returns to baseline. The SRE team wants to keep the API responsive during the spike, control spend, and avoid manual intervention. They have already configured a Horizontal Pod Autoscaler based on CPU utilization with a target of 60%. Which additional action best addresses the remaining scaling bottleneck?

A.Add a PodDisruptionBudget and increase the minimum replica count in the Deployment.
B.Expose a custom metric such as requests per second and configure the HPA to scale on it.
C.Configure a Vertical Pod Autoscaler in recommendation mode to right-size pod requests.
D.Increase the HPA target CPU utilization to 80% so pods are added more aggressively.
AnswerB

CPU utilization lags behind actual request load, especially for I/O-bound APIs that block on downstream calls while CPU stays moderate. Scaling on a request-rate metric lets the HPA add replicas as soon as traffic climbs, matching the sales-event pattern. This reduces latency risk and avoids over-provisioning between events, directly addressing the bottleneck.

Why this answer

CPU-based autoscaling reacts after CPU rises, which is too late for a sudden threefold traffic surge, particularly when the API spends time waiting on network or database calls. Scaling on a request-oriented custom metric tied to actual load lets the HPA add pods proactively. This keeps latency stable during the event and lets replicas fall back to baseline afterward, satisfying responsiveness, cost control, and automation goals together.

Exam trap

The trap here is treating CPU utilization as a universal autoscaling signal, when request-driven workloads often saturate on concurrency or downstream latency before CPU becomes the limiting factor.

16
Multi-Selecthard

A company runs a web application on App Engine Standard environment. The application experiences downtime during deployments due to traffic shifting. Which two strategies should they implement to improve reliability? (Choose two.)

Select 2 answers
A.Use Cloud Endpoints to manage API traffic and route deployments.
B.Increase the number of idle instances to handle traffic during deployment.
C.Use traffic splitting to gradually migrate traffic to the new version.
D.Deploy to a separate version and then shift traffic using the App Engine console or gcloud.
E.Set manual scaling to avoid autoscaling delays.
AnswersC, D

Traffic splitting routes a configurable percentage of requests to the new version while the old version keeps serving the remainder. If the new version fails, traffic shifts back without downtime, satisfying the reliability requirement during deployments.

Why this answer

Option C is correct because App Engine traffic splitting lets you migrate user traffic to a new version gradually (for example, by IP address, cookie, or random percentage), so the new version can be validated with a small share of requests before full cutover, avoiding the all-at-once downtime caused by abrupt traffic shifting. Option D is correct because deploying the new code as a separate App Engine version keeps the currently serving version live and healthy, and then you shift traffic to the new version via the App Engine console or gcloud commands (such as gcloud app services set-traffic), which is the standard zero-downtime deployment pattern. Option A is not appropriate because Cloud Endpoints is an API management layer for authentication, monitoring, and quotas, not a mechanism for shifting App Engine version traffic during deployments.

Option B is not appropriate because idle instances only reduce instance startup latency; they do not prevent downtime caused by traffic shifting between versions. Option E is not appropriate because manual scaling disables autoscaling and does not address the deployment traffic-shifting problem, and could actually reduce reliability under load.

Exam trap

Google Cloud often tests the distinction between deployment strategies (traffic splitting/version shifting) and scaling or API management features, leading candidates to confuse operational scaling fixes with deployment reliability improvements.

17
Matchingmedium

Match each GCP migration term to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Move workloads without modification

Tool to migrate VMs to GCP

Physical device for large data transfer

Online data transfer from other clouds or on-prem

Migrate databases to Cloud SQL with minimal downtime

Why these pairings

Correct matches: Migrate for Compute Engine migrates VMs; Cloud Storage Transfer Service handles online data transfers; Transfer Appliance is a physical device for large datasets; Database Migration Service migrates databases to Cloud SQL. Common confusions include swapping the roles of these services.

18
MCQmedium

A company stores backup data in Cloud Storage. They observe high egress costs when clients download backups. Additionally, they must retain backups for 7 years for compliance. Which optimization should they implement first?

A.Use lifecycle rules to transition to Archive after 30 days and delete after 7 years
B.Enable requester pays on the bucket
C.Set up a Cloud CDN for backup downloads
D.Move the backup data to Archive storage class
AnswerB

Requester pays shifts egress charges to the downloading clients, directly addressing the high egress cost constraint. Since backups must still be retained for seven years, this preserves the data unchanged while eliminating the company's own retrieval fees.

Why this answer

High egress costs occur when clients download backups, and enabling requester pays shifts these costs to the clients. This directly addresses the cost issue without changing storage class or retention. Requester pays is the first optimization because it resolves the immediate cost problem while lifecycle rules or storage class changes address separate concerns like retention or storage cost.

Exam trap

Google Cloud often tests the misconception that changing storage class (e.g., to Archive) reduces egress costs, when in fact egress costs are independent of storage class and requester pays is the direct solution for shifting download costs.

How to eliminate wrong answers

Option A is wrong because lifecycle rules manage storage cost and retention, not egress costs; transitioning to Archive after 30 days reduces storage cost but does not shift or reduce the egress charges incurred during downloads. Option C is wrong because Cloud CDN caches content to reduce latency and origin load, but it does not eliminate egress costs from Cloud Storage; egress from Cloud CDN still incurs charges, and backups are typically not cacheable due to infrequent access. Option D is wrong because moving to Archive storage class reduces storage cost but does not affect egress costs; Archive has higher retrieval fees and minimum retention periods that could conflict with the 7-year compliance requirement.

19
MCQeasy

Refer to the exhibit. The output is from `gcloud compute instances describe instance-1 --format=json`. What can you conclude from this output?

A.The instance is billed based on the n1-standard-2 machine type.
B.The instance is using a custom machine type.
C.The instance is using committed use discounts.
D.The instance has a GPU attached.
AnswerA

The JSON output includes the machineType field referencing n1-standard-2, which defines the instance's CPU and memory allocation. Billing for Compute Engine instances derives from the machine type specified at creation, so the exhibited value confirms the instance is charged according to n1-standard-2 pricing.

Why this answer

The output from `gcloud compute instances describe instance-1 --format=json` would include a `machineType` field that specifies the full URL of the machine type, such as `https://www.googleapis.com/compute/v1/projects/.../zones/.../machineTypes/n1-standard-2`. This confirms the instance is using the predefined n1-standard-2 machine type, which has 2 vCPUs and 7.5 GB of memory, and billing is based on that predefined type. The absence of a `custom` suffix or custom CPU/memory values in the machine type field indicates it is not a custom machine type.

Exam trap

Google Cloud often tests the distinction between predefined and custom machine types by hiding the machine type in the `machineType` URL, and candidates mistakenly think any non-standard name implies a custom type, but the key is checking for the `custom-` prefix or explicit CPU/memory fields.

How to eliminate wrong answers

Option B is wrong because a custom machine type would be indicated by a machine type URL ending with `custom-<vCPUs>-<memory>` (e.g., `custom-2-8192`) or by the presence of `custom` in the machine type name, which is not the case for `n1-standard-2`. Option C is wrong because committed use discounts are a billing-level commitment, not visible in the `gcloud compute instances describe` output; they would be shown in billing reports or the `gcloud compute commitments` command, not in instance metadata. Option D is wrong because a GPU attachment would be visible in the `accelerators` field of the instance description, which would list the GPU type and count; its absence means no GPU is attached.

20
MCQmedium

A company uses Cloud Composer to manage Apache Airflow workflows. They want to optimize costs. Which practice is most effective?

A.Configure auto scaling for the Cloud Composer environment
B.Use preemptible VMs for Airflow schedulers
C.Replace Cloud Composer with Cloud Functions for all workflows
D.Use small machine types for all Composer components
AnswerA

Auto scaling adjusts the number of worker nodes to match Airflow workload demand, so idle capacity is not billed during quiet periods. This directly targets the cost optimisation goal without reducing the environment's ability to run scheduled workflows.

Why this answer

Cloud Composer supports autoscaling for its workers, which dynamically adjusts the number of worker pods based on the Airflow task queue depth. This directly optimizes costs by scaling down during low-load periods and scaling up only when needed, avoiding over-provisioning.

Exam trap

The trap here is that candidates often assume preemptible VMs are always the best cost-saving measure, but they fail to recognize that Airflow schedulers and other critical components require persistent, reliable compute resources, making autoscaling a safer and more effective optimization.

How to eliminate wrong answers

Option B is wrong because preemptible VMs cannot be used for Airflow schedulers; schedulers must be reliable and stateful, and preemptible VMs can be terminated at any time, causing workflow failures. Option C is wrong because Cloud Functions is not a replacement for Cloud Composer; Cloud Functions is designed for event-driven, short-lived tasks, not for orchestrating complex, long-running, or dependency-heavy workflows that Airflow handles. Option D is wrong because using small machine types for all components, especially the scheduler and database, can lead to performance bottlenecks, task queuing, and failures, ultimately increasing costs due to retries and delays.

21
MCQmedium

A company migrated their on-premises database to Cloud SQL and now experiences high latency for read-heavy workloads. How can they optimize performance?

A.Switch to a higher machine type.
B.Enable automatic storage increase.
C.Use connection pooling.
D.Add read replicas.
AnswerD

Read replicas serve read-only queries from separate database instances, offloading SELECT traffic from the primary. Distributing read-heavy workloads across replicas reduces contention and latency on the primary instance, directly addressing the high read latency described after the Cloud SQL migration.

Why this answer

Adding read replicas is the correct optimization because Cloud SQL read replicas offload read traffic from the primary instance, reducing latency for read-heavy workloads. Read replicas asynchronously replicate data from the primary using MySQL or PostgreSQL native replication, allowing queries to be distributed across multiple instances. This directly addresses the high latency by scaling read capacity horizontally without impacting write performance.

Exam trap

Google Cloud often tests the misconception that vertical scaling (higher machine type) is the universal fix for performance issues, but the trap here is that read-heavy workloads require horizontal scaling via read replicas to distribute the read load, not just a more powerful single instance.

How to eliminate wrong answers

Option A is wrong because switching to a higher machine type (vertical scaling) may improve performance but does not specifically address read-heavy workloads; it increases cost without distributing the read load, and latency improvements are limited by the single instance's resources. Option B is wrong because enabling automatic storage increase only prevents storage-full errors and does not affect query latency or read throughput; it is a capacity management feature, not a performance optimization. Option C is wrong because connection pooling reduces the overhead of establishing new database connections but does not reduce latency for read-heavy workloads; it improves connection management efficiency, not query execution speed or read distribution.

22
MCQhard

A healthcare analytics firm processes patient records in a Dataflow streaming pipeline that writes enriched events to BigQuery. The pipeline currently uses a fixed number of workers sized for peak load, and utilization is low for most of the day. The team wants the pipeline to scale with incoming volume while keeping late-arriving events correct and bounded in cost. What should they do?

A.Convert the pipeline to batch mode and run it hourly with a Cloud Scheduler trigger, writing each batch to BigQuery.
B.Increase the number of workers permanently and enable disk-based shuffle to give the pipeline more headroom for late data.
C.Keep the fixed worker pool but switch the pipeline to use Streaming Engine and enable the Dataflow Shuffle service.
D.Enable autoscaling on the pipeline and set a windowing strategy with allowed lateness, using accumulation mode to emit updated results.
AnswerD

Autoscaling adjusts worker count to the backlog, so idle capacity during low-volume periods is removed while peak bursts are absorbed. Windowing with allowed lateness and accumulating mode lets late records update previously emitted windows instead of being dropped, preserving correctness for patient events that arrive out of order.

Why this answer

Autoscaling lets Dataflow add and remove workers as the backlog changes, removing the idle capacity of a peak-sized fixed pool. Windowing with allowed lateness and accumulation mode keeps late records correct by updating previously emitted results, so the pipeline scales with volume while bounded cost and data correctness are both preserved.

Exam trap

The trap here is treating Streaming Engine or extra workers as a substitute for autoscaling plus windowing, when only autoscaling addresses idle cost and only allowed lateness preserves late-arriving records.

23
MCQhard

A healthcare company stores patient records in Cloud Storage buckets across multiple projects. An audit reveals that several buckets containing protected health information are publicly accessible. The security team wants a centralized, automated way to detect and remediate public access across all current and future projects, with minimal operational effort. Which solution should the architect recommend?

A.Deploy a Forseti Security instance to scan all projects and automatically remove public IAM bindings.
B.Use Security Command Center with the built-in Cloud Storage public access finding and configure automated remediation via Cloud Functions.
C.Create an organization policy constraint that disables public access on all Cloud Storage buckets.
D.Enable uniform bucket-level access on all buckets and rely on Cloud Audit Logs to detect public access.
AnswerB

Security Command Center detects publicly accessible Cloud Storage buckets as a built-in finding and can aggregate findings across all projects in an organization. Automated remediation can be triggered from the finding using Pub/Sub and Cloud Functions to remove public IAM bindings or apply public access prevention. This provides centralized detection and remediation with minimal operational effort.

Why this answer

Security Command Center provides centralized, organization-wide detection of publicly accessible Cloud Storage buckets through built-in findings. By routing findings to Pub/Sub and triggering Cloud Functions, the team can automatically remediate public access across all current and future projects. Organization policy constraints prevent new exposures but do not detect or fix existing ones, and legacy tools like Forseti are deprecated.

Exam trap

The trap here is confusing prevention controls like organization policy constraints with detection and remediation capabilities, when the scenario explicitly requires both detection and automated remediation.

24
MCQmedium

A company is migrating its on-premises Oracle database to Cloud SQL for PostgreSQL. The database team wants to minimize downtime during migration. Which approach should they use?

A.Set up Oracle GoldenGate to replicate to Cloud SQL.
B.Use Database Migration Service for PostgreSQL with continuous migration from Oracle via Homogeneous Migration.
C.Take a physical backup of Oracle and restore to Cloud SQL.
D.Export the database as a dump file, upload to Cloud Storage, and import into Cloud SQL.
AnswerB

DMS supports minimal downtime via continuous replication.

Why this answer

Database Migration Service (DMS) for PostgreSQL with continuous migration is the correct approach because it supports ongoing change data capture (CDC) from Oracle to Cloud SQL for PostgreSQL, enabling near-zero downtime. DMS handles schema conversion and data replication continuously, allowing the target to stay synchronized until a cutover, which minimizes downtime compared to batch methods.

Exam trap

Google Cloud often tests the misconception that any 'migration service' automatically supports heterogeneous migrations, but here the trap is that Database Migration Service for PostgreSQL is specifically designed for PostgreSQL targets and includes built-in schema conversion from Oracle, whereas options like GoldenGate or dump/restore are either too complex or cause downtime.

How to eliminate wrong answers

Option A is wrong because Oracle GoldenGate is a third-party tool that requires separate licensing, complex configuration, and is not natively integrated with Cloud SQL for PostgreSQL; it is overkill and not the recommended Google Cloud service for this migration. Option C is wrong because a physical backup of Oracle (e.g., RMAN) is platform-specific and cannot be directly restored to Cloud SQL for PostgreSQL, which uses a different database engine and storage format. Option D is wrong because exporting as a dump file and importing is a one-time, offline process that requires the source database to be quiesced or taken offline, causing significant downtime, and does not support continuous replication.

25
MCQhard

A company uses Cloud Armor to protect their HTTP Load Balancer from DDoS attacks. Recently, they experienced a targeted attack that bypassed Cloud Armor's predefined rules. The attack involved a high rate of legitimate-looking requests from a small set of IPs that made the application unresponsive. The team needs to block the attack quickly without affecting legitimate users. What should they do?

A.Increase the load balancer's capacity to absorb the attack.
B.Configure rate limiting with a threshold based on the normal traffic pattern.
C.Enable Google Cloud Armor Adaptive Protection.
D.Add the attacking IPs to a Cloud Armor deny list.
AnswerC

Adaptive Protection applies machine-learning baselining to detect Layer 7 volumetric anomalies, such as the legitimate-looking request flood from few IPs, and generates a tailored WAF rule to block it. Predefined rules cannot profile this behaviour, so this satisfies the requirement to block quickly without affecting legitimate users.

Why this answer

Cloud Armor Adaptive Protection uses machine learning to analyze traffic patterns and automatically create tailored rules to block application-layer DDoS attacks that bypass predefined rules. In this scenario, the attack consists of legitimate-looking requests from a small set of IPs, which Adaptive Protection can detect as anomalous and generate a custom signature to block without manual intervention, preserving access for legitimate users.

Exam trap

The trap here is that candidates may choose Option D (adding IPs to a deny list) because it seems like a quick fix, but Google Cloud tests the understanding that Cloud Armor Adaptive Protection is the correct automated solution for application-layer DDoS attacks with legitimate-looking traffic, not manual IP blocking.

How to eliminate wrong answers

Option A is wrong because increasing the load balancer's capacity only absorbs volumetric attacks but does not address the application-layer nature of this attack; the high rate of legitimate-looking requests will still exhaust application resources regardless of capacity. Option B is wrong because configuring rate limiting with a threshold based on normal traffic patterns requires prior knowledge of those patterns and may inadvertently block legitimate users if the threshold is set too low, or fail to block the attack if the threshold is too high; it also does not leverage Cloud Armor's adaptive capabilities. Option D is wrong because adding the attacking IPs to a deny list is reactive and assumes the IPs are static; the attack may use rotating IPs or spoofed addresses, making manual deny lists ineffective and unsustainable for a rapid response.

26
MCQmedium

A company runs a monolithic application on Compute Engine. They want to modernize by moving to microservices on Google Kubernetes Engine (GKE) to improve deployment frequency and resource utilization. However, they are concerned about the increased operational complexity. Which approach best balances modernization benefits with operational overhead?

A.Keep the monolithic application on Compute Engine and use Cloud Monitoring to optimize resource utilization.
B.Migrate all application components to Cloud Run and use Cloud Tasks for asynchronous communication.
C.Rewrite the entire application as microservices and deploy on GKE with Istio for service mesh.
D.Identify stateless components to migrate to Cloud Run, and keep stateful components on GKE with managed services like Cloud Spanner.
AnswerD

Cloud Run removes cluster management for stateless components, cutting operational overhead, while GKE with managed Spanner keeps stateful workloads reliable. This split directly balances the stated modernization benefits against the concern about increased operational complexity, rather than migrating everything wholesale.

Why this answer

It pragmatically balances modernization benefits with operational overhead by migrating only stateless components to Cloud Run (a fully managed serverless platform that reduces operational complexity) while keeping stateful components on GKE with managed services like Cloud Spanner. This approach improves deployment frequency and resource utilization without requiring a full rewrite, and it leverages Cloud Run's automatic scaling and zero infrastructure management to minimize operational burden.

Exam trap

Google Cloud often tests the misconception that full microservices migration (Option C) is always the best modernization path, but the trap here is that candidates overlook the operational overhead of service mesh and full rewrites, failing to recognize that a hybrid approach using serverless for stateless components reduces complexity while still achieving modernization goals.

How to eliminate wrong answers

Option A is wrong because it fails to modernize the architecture—keeping the monolithic application on Compute Engine does not improve deployment frequency or resource utilization, and Cloud Monitoring alone cannot address the core issues of monolithic scaling and slow deployments. Option B is wrong because migrating all application components to Cloud Run is impractical for stateful workloads (Cloud Run is stateless by design, with no persistent local storage), and Cloud Tasks alone does not solve the complexity of managing stateful services or inter-service communication in a microservices architecture. Option C is wrong because rewriting the entire application as microservices and deploying on GKE with Istio introduces significant operational overhead (service mesh configuration, sidecar proxies, and increased complexity) that contradicts the goal of balancing modernization benefits with operational overhead, and it ignores the possibility of a phased migration.

27
MCQeasy

Refer to the exhibit. A DevOps engineer created this Terraform configuration to deploy a Compute Engine instance. After applying, they notice the instance is not accessible from the internet. What is the most likely cause?

A.The machine type e2-medium does not support public IP addresses.
B.The instance is not attached to a VPC network.
C.No firewall rule allows ingress traffic to the instance.
D.The boot disk size is too small to run the operating system.
AnswerC

Compute Engine instances have no implicit internet ingress; traffic is blocked unless a VPC firewall rule explicitly permits it. Since the configuration defines only the instance, the absence of an ingress rule allowing the required ports is what prevents external access, regardless of external IP assignment.

Why this answer

The most likely cause is that no firewall rule allows ingress traffic to the instance. By default, GCP instances are created with a VPC network that has implied deny-all ingress rules, and unless a specific firewall rule (e.g., allowing tcp:22 for SSH or tcp:80 for HTTP) is applied to the instance's network tags or service account, all inbound traffic from the internet is blocked. The Terraform configuration shown in the exhibit likely omitted a `google_compute_firewall` resource or did not assign the necessary network tags to the instance.

Exam trap

Google Cloud often tests the misconception that assigning a public IP automatically makes an instance internet-accessible, but the trap here is that without a corresponding ingress firewall rule, the instance remains isolated regardless of the public IP.

How to eliminate wrong answers

Option A is wrong because the machine type e2-medium fully supports public IP addresses; public IP assignment is controlled by the `access_config` block in the Terraform resource, not by the machine type. Option B is wrong because every Compute Engine instance is automatically attached to a default VPC network unless explicitly overridden; the exhibit does not indicate any misconfiguration that would leave the instance networkless. Option D is wrong because the boot disk size (e.g., 10 GB default) is sufficient for most operating systems; the issue is about network accessibility, not disk capacity.

28
MCQhard

Your company runs a multi-tier web application on Google Kubernetes Engine (GKE). The application consists of a frontend service, a backend API service, and a PostgreSQL database deployed using a StatefulSet with persistent volumes. The backend service exposes a gRPC endpoint. Recently, the team noticed that the backend service experiences intermittent high latency and occasional timeouts. The frontend service is stateless and scales well. The backend service is CPU-bound. The database is not the bottleneck. The cluster has three nodes of type n1-standard-4. The backend service is deployed with 10 replicas, each requesting 1 CPU and 2 Gi memory. Node utilization is around 70% CPU. The team suspects the network is the issue. However, after reviewing the GKE monitoring dashboard, they see that the network bytes sent/received per second for the backend pods is well below the node's network bandwidth limit. The latency spikes seem correlated with periods of high CPU throttling on the backend pods. The backend service's gRPC requests are small (under 1 KB), and the responses are also small. The team has already optimized the application code. What should the team do to reduce latency?

A.Increase the number of nodes in the cluster to reduce network contention.
B.Increase the number of backend replicas to 20.
C.Increase the CPU request for the backend pods to 2 CPUs.
D.Increase the memory request for the backend pods to 4 Gi.
AnswerC

CPU throttling, not network bandwidth, causes the latency spikes. Raising each backend pod's CPU request to 2 CPUs gives the CPU-bound gRPC service enough quota to avoid throttling, directly removing the constraint correlated with the observed timeouts.

Why this answer

The latency spikes correlate with CPU throttling, and increasing the CPU request to 2 CPUs ensures that each backend pod receives a guaranteed CPU share, reducing throttling under load. Since the backend is CPU-bound and node utilization is 70%, the current 1 CPU request may be insufficient, causing the Kubernetes CPU manager to throttle the pods when the node's CPU is contended. This directly addresses the root cause without adding unnecessary replicas or memory.

Exam trap

The trap here is that candidates may focus on network or scaling solutions (A or B) because the symptom is latency, but the monitoring data explicitly points to CPU throttling, not network saturation, making CPU request adjustment the precise fix.

How to eliminate wrong answers

Option A is wrong because network contention is not the issue—monitoring shows network bytes are well below node bandwidth limits, and the problem is CPU throttling, not network. Option B is wrong because increasing replicas to 20 would increase CPU contention on the existing nodes, worsening throttling and latency, and the frontend already scales well. Option D is wrong because the backend is CPU-bound, not memory-bound; increasing memory does not alleviate CPU throttling and would waste resources.

29
Multi-Selectmedium

A healthcare company runs a regulated patient-portal application on Google Cloud. Auditors require evidence that infrastructure changes are reviewed before they reach production and that production access is limited. The platform team currently applies Terraform changes directly from engineer laptops using personal credentials. Which two practices should the team adopt to satisfy the auditors while keeping delivery efficient? (Choose two.)

Select 2 answers
A.Disable Cloud Audit Logs for Terraform-related API calls to reduce log volume and cost.
B.Grant all platform engineers the Project Editor role so they can resolve production incidents quickly without approval delays.
C.Store Terraform state in a Cloud Storage bucket with versioning and Object Versioning enabled, and grant write access only to the CI/CD service account.
D.Use Cloud Build triggers on pull requests to run terraform plan, require peer review, and apply only from an approved branch using a dedicated service account.
E.Run terraform apply from each engineer's laptop but require them to commit the plan output to Git afterward.
AnswersC, D

Centralizing state in a versioned Cloud Storage bucket with restricted write access prevents engineers from mutating production state locally and creates an auditable history of state changes. This supports the review requirement because all applies flow through a controlled service account, and versioning provides recoverability and evidence for auditors.

Why this answer

Auditors want a controlled, reviewable path to production and a clear record of who deployed what. Running plan in CI on pull requests with mandatory peer review, then applying from an approved branch with a dedicated service account, creates that path. Backing it with a locked-down, versioned remote state bucket prevents out-of-band changes and preserves history.

Together these practices keep delivery automated while producing the evidence and access controls the auditors require.

Exam trap

The trap here is equating documentation with control, assuming that committing plans after a local apply provides the same assurance as enforcing review and apply through a pipeline.

30
MCQhard

A company runs a streaming data pipeline using Dataflow to process real-time data and insert into BigQuery. Recently, workers are frequently failing with out-of-memory errors and the pipeline latency is increasing. What should they do to resolve the issue?

A.Increase the worker machine type and memory
B.Use Cloud Pub/Sub for buffering and then load into BigQuery in batches
C.Enable autoscaling and increase the maximum number of workers
D.Enable Dataflow Streaming Engine
AnswerD

Streaming Engine moves pipeline state and shuffling off the worker VMs to the Dataflow service, so workers no longer hold that memory. This directly removes the out-of-memory cause and reduces latency, satisfying the real-time processing requirement.

Why this answer

Dataflow Streaming Engine offloads the streaming data processing state and shuffle data from worker memory to a backend service, reducing memory pressure on workers. This directly addresses out-of-memory errors and latency increases without requiring manual scaling or machine type changes. It is the recommended solution for streaming pipelines experiencing memory bottlenecks.

Exam trap

Google Cloud often tests the misconception that scaling up resources (more memory or more workers) is the primary fix for streaming pipeline memory issues, when the real solution is to offload state management using Streaming Engine.

How to eliminate wrong answers

Option A is wrong because simply increasing worker machine type and memory does not resolve the root cause of state management overhead in streaming pipelines; it only delays the failure and increases cost without optimizing data flow. Option B is wrong because adding Pub/Sub buffering does not fix the memory issue within Dataflow workers; it shifts the problem to a different layer and may introduce additional latency and complexity. Option C is wrong because enabling autoscaling and increasing max workers can help with throughput but does not reduce per-worker memory consumption; workers may still fail with OOM errors if the pipeline's state or shuffle data exceeds available memory.

31
MCQhard

A company is using BigQuery for analytics and wants to optimize query costs. They have many ad-hoc queries that scan large tables. What is the best practice?

A.Use clustering and partitioning on tables.
B.Use flat-rate pricing.
C.Use BI Engine.
D.Use materialized views.
AnswerA

Partitioning restricts each ad-hoc query to relevant date or range segments, while clustering sorts storage by filtered columns so block pruning applies. Both cut bytes scanned, and on-demand BigQuery pricing charges per byte, so large-table scans cost less.

Why this answer

Clustering and partitioning reduce the amount of data scanned by BigQuery for each query, directly lowering query costs (which are based on bytes processed). Partitioning allows queries to skip entire partitions based on a date or timestamp column, while clustering sorts data within partitions, enabling block-level pruning for filter predicates. This is the most effective and scalable way to optimize ad-hoc queries on large tables without changing the query logic.

Exam trap

Google Cloud often tests the misconception that flat-rate pricing or BI Engine directly reduce per-query costs, when in fact they address capacity or latency, not the fundamental cost driver of bytes scanned.

How to eliminate wrong answers

Option B is wrong because flat-rate pricing (slot-based reservations) does not reduce the amount of data scanned; it only provides predictable costs for a fixed number of slots, and ad-hoc queries still incur slot usage but do not reduce per-query bytes processed. Option C is wrong because BI Engine is an in-memory acceleration service for interactive dashboards and repeated queries, not for optimizing ad-hoc analytical queries that scan large tables; it caches results but does not reduce scan bytes for new queries. Option D is wrong because materialized views precompute and store query results, which can speed up repeated queries but do not help with arbitrary ad-hoc queries that may not match the view definition; they also incur storage costs and require maintenance.

32
MCQeasy

A startup deploys a web application on Compute Engine instances behind an HTTP load balancer. They need to handle unpredictable spikes in traffic with minimal operational overhead. What is the simplest scaling approach?

A.Set up a Kubernetes cluster with horizontal pod autoscaling
B.Use a managed instance group with autoscaling based on CPU utilization
C.Migrate the application to Cloud Run
D.Add more instances manually during peak hours
AnswerB

A managed instance group with CPU-based autoscaling adds or removes Compute Engine instances automatically as demand shifts, absorbing unpredictable spikes without manual intervention. This satisfies the minimal operational overhead constraint while the HTTP load balancer distributes traffic across the group.

Why this answer

Using a managed instance group with autoscaling automatically adds/removes instances based on demand, requiring minimal manual intervention. Other options either require more complex setup or are not optimal.

33
MCQhard

A company has a multi-region deployment of App Engine and wants to optimize request routing for latency and cost. Which GCP service should they use?

A.Cloud Endpoints.
B.Cloud Load Balancing with global anycast.
C.Cloud DNS with latency-based routing.
D.Cloud Traffic Director.
AnswerB

Cloud Load Balancing with global anycast advertises a single global IP, routing each user to the nearest healthy App Engine region at Google's edge. This minimises latency and avoids cross-region egress costs compared with regional or DNS-based routing.

Why this answer

Cloud Load Balancing with global anycast uses Google's global network and anycast IP addresses to route user traffic to the nearest healthy backend, minimizing latency. It also supports premium tier routing for lower latency and standard tier for lower cost, directly addressing the optimization goals for a multi-region App Engine deployment.

Exam trap

The trap here is that candidates often confuse Cloud DNS latency-based routing (a DNS-level, cache-prone approach) with true anycast-based global load balancing, which provides immediate, health-aware routing without DNS caching delays.

How to eliminate wrong answers

Option A is wrong because Cloud Endpoints is an API management service for securing, monitoring, and managing APIs, not a global load balancer for routing traffic across regions based on latency and cost. Option C is wrong because Cloud DNS with latency-based routing is a DNS-level feature that can direct traffic based on latency, but it lacks the fine-grained health checking, anycast IP, and traffic splitting capabilities of a global load balancer, and DNS caching can cause routing delays. Option D is wrong because Cloud Traffic Director is a traffic management service for service mesh (e.g., with Istio on GKE), not designed for global HTTP(S) load balancing to App Engine; it operates at the service mesh layer, not the edge.

34
MCQeasy

A startup is deploying a new web application on Google Cloud. They want to ensure that their development, staging, and production environments are isolated from each other for security and billing purposes. They also want to apply different IAM policies per environment. Which Google Cloud resource hierarchy structure should the architect recommend?

A.Create a single project and use labels to separate environments.
B.Create a separate folder for each environment under the organization node, and place projects within those folders.
C.Create a separate organization for each environment.
D.Create a single project and use separate VPC networks for each environment.
AnswerB

Folders allow you to group projects and apply IAM policies at the folder level, which are inherited by all projects within. This provides isolation between environments and enables separate billing and security controls. It is the recommended way to structure a Google Cloud organization for multiple environments.

Why this answer

Using folders under the organization node allows you to group projects by environment and apply distinct IAM policies at the folder level. This provides both security isolation and separate billing, as each project can have its own billing account. It is the standard Google Cloud best practice for multi-environment setups.

Exam trap

The trap here is confusing network isolation or labeling with full environment isolation, which requires separate projects and folder-level IAM policies.

35
MCQhard

A retail company runs a legacy order-processing system on a single Compute Engine VM with a local SSD. The system is business-critical and must be migrated to Google Cloud with minimal downtime and no data loss. The database is PostgreSQL, and the company wants to move to a managed service. The cutover window is only 30 minutes. Which migration approach should the architect recommend?

A.Take a cold backup of the PostgreSQL database, transfer it to Cloud Storage, and restore it to a new Cloud SQL instance during the cutover window.
B.Use Database Migration Service to perform a continuous replication from the source PostgreSQL to Cloud SQL for PostgreSQL, then promote during the cutover window.
C.Lift and shift the VM to a Compute Engine instance with a persistent disk, then convert it to a Cloud SQL instance later.
D.Create a Cloud SQL read replica from the on-premises PostgreSQL using native replication, then promote the replica during cutover.
AnswerB

Database Migration Service supports continuous replication from a self-managed PostgreSQL source to Cloud SQL, keeping the target in sync until cutover. This minimizes downtime because only the final promotion and connection switch are needed during the 30-minute window. It also avoids data loss by replicating ongoing changes, making it the best fit for the requirements.

Why this answer

Database Migration Service provides continuous replication from a self-managed PostgreSQL source to Cloud SQL, enabling a short cutover window with minimal downtime and no data loss. The other options either require significant downtime, are unsupported, or do not result in a managed service. For a business-critical system with a tight cutover window, continuous replication is the recommended approach.

Exam trap

The trap here is assuming that a cold backup and restore or a lift-and-shift can meet a 30-minute cutover with no data loss, when continuous replication is required for minimal downtime.

36
MCQeasy

A company is using Cloud Storage for backups and wants to minimize costs. The backups are accessed infrequently and can tolerate retrieval delays. Which storage class is most appropriate?

A.Standard
B.Archive
C.Coldline
D.Nearline
AnswerB

Archive storage has the lowest per-gigabyte price of any Cloud Storage class and is designed for data accessed less than once a year. It matches the infrequent access and tolerance for retrieval delays stated in the stem, minimising backup storage cost where latency is acceptable.

Why this answer

Archive storage class is the most cost-effective option for backups that are accessed infrequently and can tolerate retrieval delays. It offers the lowest storage cost among Google Cloud Storage classes, with a default retrieval time of minutes to hours, making it ideal for long-term backup data that does not require immediate access.

Exam trap

Google Cloud often tests the misconception that 'Coldline' is the cheapest storage class, but Archive is actually the lowest-cost option for data that can tolerate retrieval delays of minutes to hours, not just for data that is rarely accessed.

How to eliminate wrong answers

Option A is wrong because Standard storage class is designed for frequently accessed data with no retrieval delay, and its higher cost makes it unsuitable for infrequently accessed backups. Option C is wrong because Coldline storage, while cheaper than Standard, is still more expensive than Archive and has a 90-day minimum storage duration, which may not be optimal for long-term backups with very low access frequency. Option D is wrong because Nearline storage is intended for data accessed less than once a month, but it has a 30-day minimum storage duration and higher cost compared to Archive, making it less cost-efficient for backups that can tolerate retrieval delays.

37
MCQhard

A company runs a large-scale data processing pipeline using Dataflow with streaming data from Pub/Sub. They notice increasing costs due to high data shuffle operations. They want to optimize the pipeline performance and cost. Which approach should they take?

A.Use a larger machine type for workers.
B.Increase the number of workers to reduce shuffle.
C.Optimize the pipeline by partitioning data and using Combine transforms.
D.Switch to batch mode overnight.
AnswerC

Partitioning spreads keys across workers so shuffle no longer funnels everything through single keys, and Combine transforms perform partial aggregation per key before the shuffle. This reduces the volume of data moved between workers, directly addressing the high shuffle cost that is inflating the streaming pipeline's bill.

Why this answer

Optimizing the pipeline by partitioning data and using Combine transforms reduces the amount of data shuffled across workers. Partitioning groups related data together, and Combine performs associative reductions per key, minimizing the data that needs to be moved. This directly addresses high shuffle costs and improves performance.

Exam trap

PCA often tests the misconception that adding more workers or larger machines solves performance issues: candidates may choose to increase workers, but that can worsen shuffle; the correct approach is to optimize the pipeline logic to reduce shuffle.

How to eliminate wrong answers

Option A is wrong because using a larger machine type may provide more resources but does not reduce shuffle operations; it can increase costs without addressing the root cause. Option B is wrong because increasing the number of workers can actually increase shuffle overhead due to more data movement across the network, and it doesn't optimize the pipeline logic. Option D is wrong because switching to batch mode overnight changes the processing paradigm and may not be feasible for streaming data; it doesn't optimize shuffle within the streaming pipeline.

38
MCQhard

A financial services company runs a high-volume transaction processing system on Google Cloud. They need to ensure that the system can handle sudden spikes in traffic during market open and close. The system uses a managed instance group of Compute Engine VMs behind a load balancer. They want to optimize costs while maintaining performance during peak hours. Which approach should the architect recommend?

A.Use a managed instance group with autoscaling based on CPU utilization, and set a minimum size to handle baseline traffic.
B.Use preemptible VMs in the managed instance group to reduce compute costs.
C.Use a managed instance group with autoscaling based on a custom metric that tracks queue depth, and set a minimum size of zero.
D.Use a managed instance group with a fixed size large enough to handle peak traffic at all times.
AnswerA

Autoscaling based on CPU utilization allows the instance group to add VMs during traffic spikes and remove them when demand drops. Setting a minimum size ensures baseline capacity is always available. This directly addresses both performance during peaks and cost optimization by scaling down during off-peak times.

Why this answer

Autoscaling based on CPU utilization with a minimum instance count provides elasticity to handle traffic spikes while ensuring baseline capacity. This allows the system to scale out during market open and close and scale in during quieter periods, optimizing costs without sacrificing performance. Other options either over-provision, use unreliable preemptible VMs, or risk cold starts.

Exam trap

The trap here is assuming that aggressive cost-saving measures like preemptible VMs or scaling to zero will work for a critical, latency-sensitive system, when a baseline of reliable instances is needed.

39
MCQmedium

A company uses BigQuery for analytics. They have a large partitioned table that is queried frequently. The query performance has degraded over time. Which optimization should they try first?

A.Create a materialized view for each frequent query.
B.Increase the number of slots for the project.
C.Apply clustering on frequently filtered columns.
D.Denormalize the table to reduce joins.
AnswerC

Clustering physically co-locates rows sharing the clustered column values, so filters on those columns scan fewer blocks. On a frequently queried partitioned table, clustering the common filter columns prunes data within each partition, improving performance without restructuring partitions.

Why this answer

Clustering on frequently filtered columns reorganizes the data within partitions based on the values of those columns, which allows BigQuery to prune blocks more effectively during queries. This directly addresses the performance degradation by reducing the amount of data scanned, without requiring additional storage or compute resources.

Exam trap

Google Cloud often tests the misconception that adding more slots (Option B) is the default performance fix, when in reality the first step should be to reduce data scanned through clustering or partitioning optimization.

How to eliminate wrong answers

Option A is wrong because creating materialized views for each frequent query would increase storage costs and maintenance overhead, and they are not the first optimization to try for a partitioned table with degraded performance; clustering addresses the root cause of excessive data scanning. Option B is wrong because increasing the number of slots only improves concurrency and throughput, not the efficiency of individual queries; it does not reduce the amount of data read per query. Option D is wrong because denormalizing the table to reduce joins is a schema design change that may help with join-heavy workloads, but it does not address the core issue of scanning too many rows in a large partitioned table; clustering is a more targeted and less disruptive first step.

40
Multi-Selectmedium

A media company uses a multi-project Google Cloud organization. They want to optimize their cloud spend across all projects without sacrificing performance or reliability. They have already implemented committed use discounts for Compute Engine. Which two additional actions should the architect recommend to reduce costs? (Choose two.)

Select 2 answers
A.Use preemptible VMs for all production workloads to reduce compute costs.
B.Implement automatic resource scheduling to shut down non-production VMs during off-hours.
C.Purchase additional committed use discounts for all remaining on-demand instances.
D.Migrate infrequently accessed Cloud Storage data to Nearline or Coldline storage classes.
E.Enable billing export to BigQuery and create cost anomaly detection dashboards.
AnswersB, D

Automatic resource scheduling stops non-production VMs when they are not needed, such as nights and weekends. This directly reduces Compute Engine costs without affecting production performance or reliability. It is a common and effective cost-optimization practice, especially for development and test environments that do not require 24/7 uptime.

Why this answer

Shutting down non-production VMs during off-hours directly cuts compute costs without impacting production reliability. Moving infrequently accessed data to Nearline or Coldline storage reduces storage costs while maintaining low-latency access when needed. Both actions are practical, low-risk optimizations that address different parts of the bill.

Visibility tools and preemptible VMs for production do not meet the requirement, and additional commitments should be based on careful analysis.

Exam trap

The trap here is assuming that any cost-related action, such as enabling billing export or buying more commitments, will reduce spend, when only actions that change resource usage or storage class directly lower the bill.

41
Multi-Selectmedium

A company runs a high-traffic web application on Google Kubernetes Engine (GKE). The application uses a Cloud SQL for MySQL instance as its backend. The operations team wants to optimize the cost of the GKE cluster and the Cloud SQL instance without sacrificing performance or availability. Which two actions should they take? (Choose two.)

Select 2 answers
A.Use preemptible VMs for the GKE nodes to reduce compute costs.
B.Purchase committed use discounts for the GKE nodes' underlying Compute Engine instances.
C.Configure Cloud SQL to use a shared-core machine type to reduce database costs.
D.Schedule regular backups of the Cloud SQL instance to reduce storage costs.
E.Enable GKE cluster autoscaler to automatically adjust the number of nodes based on workload demand.
AnswersB, E

Committed use discounts (CUDs) provide significant savings for steady-state usage by committing to a certain amount of resources for 1 or 3 years. For a high-traffic application with predictable baseline load, purchasing CUDs for the GKE nodes can reduce compute costs without affecting performance or availability.

Why this answer

Enabling cluster autoscaler ensures the GKE cluster scales dynamically with demand, reducing costs during idle periods while maintaining performance. Purchasing committed use discounts for the underlying Compute Engine instances provides cost savings for the baseline load. Together, these actions optimize costs without compromising performance or availability.

Exam trap

The trap here is assuming that preemptible VMs are suitable for all cost-saving scenarios, but they can be terminated and are not appropriate for high-availability production workloads.

42
MCQhard

An e-commerce platform uses Cloud Spanner for order processing. Recently, latency spikes have occurred during flash sales. The team suspects hot spots due to monotonically increasing order IDs. Which table design change would best solve this?

A.Remove the primary key and let Spanner auto-generate it.
B.Use interleaved tables to store orders under customers.
C.Add a random prefix to the order ID primary key.
D.Create a secondary index on the timestamp column.
AnswerC

Randomising the leading key bytes spreads sequential inserts across multiple Spanner splits, eliminating the hot spot caused by monotonically increasing order IDs during flash sales. This directly addresses the stem's constraint: write contention concentrated on the trailing split. Range scans by order ID still work, though they now require prefix-aware query design.

Why this answer

Monotonically increasing primary keys (like sequential order IDs) cause hot spots in Cloud Spanner because all writes are directed to a single split (tablet), overwhelming that node. Adding a random prefix (e.g., a hash of the customer ID) distributes writes across multiple splits, eliminating the hot spot and reducing latency spikes during high-throughput flash sales.

Exam trap

Google Cloud often tests the misconception that secondary indexes or interleaved tables can fix write hot spots, when in reality only primary key distribution strategies (like hash prefixes) address the root cause of split-level contention.

How to eliminate wrong answers

Option A is wrong because removing the primary key and relying on auto-generation still produces monotonically increasing values (e.g., Spanner's auto-generated keys are sequential), which does not solve the hot spot issue. Option B is wrong because interleaved tables organize child rows under a parent row, but if the parent key is monotonically increasing, writes still concentrate on the same split, failing to distribute load. Option D is wrong because a secondary index on the timestamp column does not affect the distribution of primary key writes; it only helps query performance, not write hot spots.

43
MCQhard

An organization runs a Kubernetes cluster on GKE with cluster autoscaling enabled. They notice that pods are frequently in 'Pending' state due to insufficient CPU, but the cluster autoscaler does not add nodes quickly enough. What is the most likely cause?

A.The cluster autoscaler is using the 'least-waste' expander.
B.The horizontal pod autoscaler (HPA) is misconfigured.
C.The pod disruption budget (PDB) is too restrictive.
D.The node pool has reached the maximum node count limit.
AnswerD

When the node pool hits its maximum node count, the cluster autoscaler cannot provision further nodes regardless of pending pods. Pods remain Pending because no capacity is added, explaining the slow scaling despite autoscaling being enabled.

Why this answer

The cluster autoscaler cannot add new nodes if the node pool has already reached its maximum node count limit. This limit is configured at the node pool level in GKE, and once reached, the autoscaler will not scale up further, leaving pods in 'Pending' state due to insufficient CPU resources.

Exam trap

Google Cloud often tests the distinction between pod-level scaling (HPA) and node-level scaling (cluster autoscaler), and the trap here is that candidates confuse a restrictive PDB with a node pool limit, or assume the expander strategy directly causes scaling delays.

How to eliminate wrong answers

Option A is wrong because the 'least-waste' expander selects a node pool that minimizes resource waste after scaling, but it does not prevent the autoscaler from adding nodes; it only affects which node pool is chosen. Option B is wrong because the HPA scales pods based on CPU or memory utilization, not nodes; a misconfigured HPA would cause incorrect pod scaling, not a delay in node addition by the cluster autoscaler. Option C is wrong because a pod disruption budget (PDB) controls the number of pods that can be voluntarily disrupted during maintenance or upgrades, not the ability of the cluster autoscaler to add nodes.

Ready to test yourself?

Try a timed practice session using only Analyze and optimize technical and business processes questions.

CCNA Analyze and optimize technical and business processes Questions | Courseiva