Courseiva

CCNA Design and plan a cloud solution architecture Questions

75 of 106 questions · Page 1/2 · Design and plan a cloud solution architecture · Answers revealed

1
MCQhard

Refer to the exhibit. All five nginx pods are scheduled on the same node (default-pool-1). What is the most likely reason?

A.The node auto-scaler has not created additional nodes yet, but the other nodes are present.
B.The pods have a nodeSelector that matches only default-pool-1.
C.The other nodes have taints that the pods do not tolerate.
D.The resource requests are too high, so the scheduler packed pods onto one node due to resource constraints on the others.
AnswerC

Taints on other nodes repel pods lacking matching tolerations, so the scheduler cannot place them there. With no tolerations defined in the pod spec, every other node rejects the nginx pods, leaving default-pool-1 as the only viable target and concentrating all five replicas on it.

Why this answer

Taints on nodes prevent pods from being scheduled unless the pods have corresponding tolerations. If the other nodes have taints that the nginx pods do not tolerate, the scheduler will only place them on nodes without those taints, which in this case is default-pool-1. This is a common scenario when nodes are dedicated to specific workloads or have special hardware.

Exam trap

This question tests the distinction between taints/tolerations and nodeSelector/affinity in Kubernetes on Google Cloud. Candidates often overlook that taints can silently exclude pods from all but one node, and assume only nodeSelector restricts pod placement.

How to eliminate wrong answers

Option A is wrong because the node auto-scaler adds nodes when pods are unschedulable due to resource constraints, but here all pods are scheduled on one node, indicating the scheduler deliberately chose that node, not that other nodes are missing. Option B is wrong because if a nodeSelector matched only default-pool-1, the pods would be scheduled exclusively there, but the question asks for the 'most likely reason' and taints are a more common cause for pods being forced onto a single node when other nodes exist. Option D is wrong because if resource requests were too high, the scheduler would leave pods pending or spread them across nodes that can fit them, not pack them all onto one node; packing suggests the other nodes are intentionally excluded.

2
MCQeasy

An online retailer runs a stateless containerized API on Google Kubernetes Engine. Traffic is highly seasonal, spiking sharply during flash sales and dropping to near zero overnight. The operations team wants the cluster to add and remove nodes automatically based on pod demand while keeping costs low during idle periods. What should the architect recommend?

A.Deploy the API on Cloud Run and remove the GKE cluster entirely, relying on request-based scaling.
B.Configure a regional managed instance group with a fixed size and enable autoscaling on the deployment only.
C.Set the node pool to a large fixed size sized for peak flash-sale traffic and rely on the scheduler to pack pods efficiently.
D.Enable cluster autoscaler on the node pools and configure a HorizontalPodAutoscaler on the API deployment.
AnswerD

Cluster autoscaler adds nodes when pods cannot be scheduled and removes underutilized nodes when demand falls, directly addressing seasonal spikes and idle overnight periods. The HorizontalPodAutoscaler scales the number of pods based on metrics such as CPU or custom metrics, which in turn drives cluster autoscaler to provision capacity. Together they deliver both pod-level and node-level elasticity for a stateless workload.

Why this answer

Cluster autoscaler and HorizontalPodAutoscaler are complementary controls: the HPA adjusts replica count based on demand signals, and the cluster autoscaler provisions or removes nodes to match the resulting scheduling pressure. This combination gives the retailer elasticity during flash sales and near-zero node cost overnight without manual intervention.

Exam trap

The trap here is confusing pod autoscaling with node autoscaling, when in fact both are required for a workload whose node capacity must also track demand.

3
MCQhard

A financial services firm is designing a new payment processing system on Google Cloud. The system must expose a single global anycast IP address, terminate TLS at the edge, and route requests to the nearest healthy backend across three regions. The backend services run on Compute Engine and must be protected from volumetric DDoS attacks. Which product should you place in front of the backends?

A.Global external Proxy Network Load Balancer with Google Cloud Armor attached to the target proxy.
B.Regional external Application Load Balancer in each region with Cloud CDN enabled for caching.
C.External passthrough Network Load Balancer with a global forwarding rule and Cloud Armor on the backend.
D.Global external Application Load Balancer with Cloud Armor security policies attached to the backend service.
AnswerD

The global external Application Load Balancer provides a single global anycast IP, terminates TLS at Google's edge, and routes to the nearest healthy backend using the premium network tier. Cloud Armor attaches to the backend service to filter and absorb volumetric and application-layer attacks. This combination satisfies the anycast, TLS termination, cross-region routing, and DDoS protection requirements in one architecture.

Why this answer

A global external Application Load Balancer delivers a single global anycast IP, terminates TLS at Google's edge, and uses health-checked backends to route to the nearest region. Cloud Armor security policies attach to the backend service and provide DDoS and web application firewall protection. Regional load balancers cannot offer one global IP, and Layer 4 proxy or passthrough load balancers do not terminate HTTP(S) at the edge or support Cloud Armor in the required way.

Exam trap

The trap here is confusing Layer 4 network load balancing with Layer 7 application load balancing, and assuming Cloud Armor can attach to any load balancer type.

4
Multi-Selecthard

A company has set up an external HTTP(S) load balancer with a backend service pointing to a managed instance group. Some instances are failing health checks. Which TWO actions should the company take to troubleshoot the issue?

Select 2 answers
A.Ensure the health check path specified in the backend service returns a 200 OK status.
B.Verify that the firewall rules allow traffic from the load balancer health check IP ranges.
C.Disable session affinity to allow better distribution of traffic.
D.Change the health check interval from 5 seconds to 30 seconds.
E.Increase the number of instances in the instance group to distribute the load.
AnswersA, B

A failing health check often stems from the probe path returning a non-200 response, so verifying it returns 200 OK directly addresses the backend service's health check configuration. Google Cloud load balancer health checks mark instances unhealthy on any other status code, removing them from rotation, so confirming the path's response satisfies the stem's troubleshooting requirement.

Why this answer

Option A is correct because the health check probe only marks an instance healthy when the configured request path returns an HTTP 200 OK response; if the path returns 404, 500, or a redirect, the instance will be flagged unhealthy, so verifying the path is a primary troubleshooting step. Option B is correct because Google Cloud external HTTP(S) load balancer health checks originate from specific Google health check source IP ranges (e.g., 35.191.0.0/16 and 130.211.0.0/22), and firewall rules must permit ingress from these ranges to the instances on the health check port, otherwise probes are dropped and instances fail. Option C is not relevant because session affinity affects how client traffic is routed, not whether health check probes succeed.

Option D is not a fix because lengthening the interval only delays detection and does not resolve the underlying cause of failed probes. Option E is not appropriate because adding instances does not correct failing health checks and may simply add more unhealthy instances.

Exam trap

The trap here is that candidates often focus on load distribution or scaling solutions (options C and E) rather than the fundamental connectivity and application-level checks (options A and B) that directly determine health check success.

5
MCQmedium

A company runs a multi-tier web application on Google Kubernetes Engine (GKE) with a frontend service, a backend service, and a Cloud SQL for PostgreSQL database. During peak hours, the frontend pod CPU usage is high (consistently above 80%), while the backend service shows moderate CPU usage (around 50%). Response times for user requests increase significantly, often exceeding the 200ms p99 latency target. Cloud SQL metrics show low query latency and no contention. The team wants to improve performance in a cost-effective manner. Which initial step should they take?

A.Add a read replica for Cloud SQL to offload read queries.
B.Migrate the backend service to a custom machine type with more vCPUs.
C.Enable vertical pod autoscaling for the backend service.
D.Increase the number of frontend pods by adjusting the horizontal pod autoscaler's target CPU utilization.
AnswerD

Frontend CPU is high, so scaling out frontend pods will help handle the load and reduce latency. This is cost-effective as it adds only needed capacity.

Why this answer

The frontend pods are CPU-bound during peak hours, causing increased response times. Increasing the number of frontend pods via the Horizontal Pod Autoscaler (HPA) by lowering the target CPU utilization threshold distributes the load across more replicas, directly addressing the bottleneck without additional infrastructure cost. This is the most cost-effective initial step because it leverages existing resources and autoscaling capabilities.

Exam trap

Google Cloud often tests the misconception that backend or database changes are needed when the bottleneck is clearly at the frontend tier, leading candidates to choose expensive or irrelevant scaling options like read replicas or vertical scaling.

How to eliminate wrong answers

Option A is wrong because Cloud SQL metrics show low query latency and no contention, so a read replica would not resolve the frontend CPU bottleneck and would add unnecessary cost. Option B is wrong because the backend service shows only moderate CPU usage (50%), so migrating to a custom machine type with more vCPUs would be over-provisioning and not cost-effective; the bottleneck is the frontend, not the backend. Option C is wrong because vertical pod autoscaling (VPA) adjusts CPU/memory requests for existing pods, but the frontend pods are already CPU-saturated; scaling up vertically would require pod restarts and may hit node limits, whereas horizontal scaling is more appropriate for stateless web tiers.

6
MCQeasy

A media company is designing a new content delivery architecture on Google Cloud. Users worldwide download large video files, and the company wants to serve them from a global edge cache while keeping the origin bucket private. They also want to reduce egress cost by caching at the edge. Which Google Cloud service should you recommend as the front end for this architecture?

A.Cloud CDN with a global external Application Load Balancer and a Cloud Storage backend bucket.
B.A regional external Application Load Balancer in front of a Managed Instance Group that serves the video files from local SSD.
C.Cloud Storage with a multi-region bucket and signed URLs generated per user request.
D.Cloud Interconnect between the company's data center and a Google Cloud region, with the bucket served from that region.
AnswerA

Cloud CDN caches content at Google's globally distributed edge points of presence, reducing latency for worldwide users and offloading repeated requests from the origin. A global external Application Load Balancer can front a Cloud Storage bucket as a backend, and the bucket can remain private because only the load balancer's service account needs read access. This directly meets the global edge caching and cost-reduction goals.

Why this answer

Cloud CDN integrated with a global external Application Load Balancer and a Cloud Storage backend bucket delivers content from Google's global edge, cutting latency for worldwide users and reducing origin egress by serving cached responses. The bucket stays private because only the load balancer's service account is granted read access, so the architecture meets both the caching and privacy requirements.

Exam trap

The trap here is assuming that a multi-region Cloud Storage bucket alone provides edge caching for global users.

7
MCQmedium

A logistics company is planning to migrate a batch ETL pipeline from on-premises Hadoop to Google Cloud. The pipeline processes several terabytes nightly, and the team wants to minimize infrastructure management while keeping the ability to tune the cluster for cost and performance. The data currently resides in an on-premises HDFS cluster. Which combination of services should the architect recommend?

A.BigQuery for storage and analysis, replacing the Spark jobs entirely with SQL.
B.Cloud Storage for durable object storage and Dataproc clusters created per job for processing.
C.Persistent Dataproc clusters with local HDFS storage that run continuously and process jobs on a schedule.
D.Compute Engine VMs running a self-managed Hadoop distribution with Cloud Storage FUSE for input and output.
AnswerB

Cloud Storage provides cheap, durable storage that decouples data from compute, and Dataproc offers managed Spark and Hadoop clusters that can be created for each job and deleted afterward. This pattern eliminates idle cluster costs and reduces operational burden while still allowing the team to choose machine types and cluster sizes per run. It fits the migration and tuning requirements well.

Why this answer

Separating storage from compute with Cloud Storage and using ephemeral Dataproc clusters lets the team process nightly data without paying for idle infrastructure, while still selecting machine types and cluster sizes per job. Persistent clusters, self-managed Hadoop, and a full BigQuery rewrite each fail at least one requirement around management overhead or preserving existing Spark logic.

Exam trap

The trap here is assuming a persistent Dataproc cluster is needed for a recurring batch job, when ephemeral per-job clusters are cheaper and require less management.

8
MCQeasy

A small e-commerce team wants to deploy a containerized storefront to Google Cloud with minimal operational overhead. Traffic is steady, the team has no Kubernetes expertise, and they want to pay only for what they use while the service scales automatically. Which compute option should the architect recommend?

A.Cloud Run services with request-based autoscaling and scale-to-zero enabled.
B.Compute Engine managed instance groups with an autoscaling policy based on CPU utilization.
C.Google Kubernetes Engine Autopilot cluster with a Horizontal Pod Autoscaler.
D.App Engine standard environment with automatic scaling and an instance class sized for peak traffic.
AnswerA

Cloud Run runs container images on a fully managed platform, scales instances automatically with incoming requests, and can scale to zero so the team pays only for requests actually served. There are no clusters or nodes to manage, and the developer workflow is a simple container push and deploy. This directly matches the requirements for minimal operations, automatic scaling, and consumption-based cost.

Why this answer

The deciding factors are the containerized workload, the lack of Kubernetes skills, and the desire for consumption-based pricing with automatic scaling. Cloud Run accepts a container image, manages all infrastructure, and scales instances up and down with request load, including down to zero when idle. That removes cluster operations entirely while still billing per use, which is exactly the profile the team described.

Exam trap

The trap here is equating any autoscaling service with zero operational overhead, when managed instance groups and Kubernetes still require the team to run infrastructure.

9
MCQmedium

A financial analytics firm is deploying a new batch reporting platform on Google Cloud. The platform runs on a Managed Instance Group (MIG) of Compute Engine VMs and reads source data from a single Cloud Storage bucket. The security team requires that the VMs access the bucket without using long-lived service account keys, and that the identity be scoped specifically to this workload. They also want the permission to be automatically revoked when the VMs are deleted. Which approach should you recommend?

A.Use the Compute Engine default service account, which already has the Editor role, and add an IAM condition limiting access to the reporting project.
B.Create a dedicated service account, grant it roles/storage.objectViewer on the bucket, and attach it to the MIG as the instance service account.
C.Enable Cloud Storage public access prevention and make the bucket readable by allAuthenticatedUsers, then restrict network access with VPC firewall rules.
D.Create a service account, generate a JSON key, store it in Secret Manager, and have the application mount it at runtime.
AnswerB

Attaching a dedicated service account to the MIG makes every VM in the group use that identity. Application Default Credentials on the VMs automatically obtain short-lived access tokens from the metadata server, so no keys are stored. Because the identity is tied to the instance template, deleting the VMs removes the workload's ability to authenticate, satisfying the revocation requirement.

Why this answer

Workload-scoped, keyless authentication on Compute Engine is achieved by attaching a dedicated service account to the instance template used by the MIG. The metadata server issues short-lived tokens to the application, so no static keys exist to leak or rotate, and the identity disappears with the instances. Granting only roles/storage.objectViewer on the specific bucket enforces least privilege for the reporting workload.

Exam trap

The trap here is assuming that storing a service account key in Secret Manager makes it a short-lived or keyless credential.

10
MCQhard

A global e-commerce platform is experiencing intermittent latency spikes during flash sales. The application is deployed on Google Kubernetes Engine (GKE) with a regional cluster. The architecture includes a frontend service, a product catalog service using Cloud Spanner, and an order processing service using Cloud Pub/Sub. During high load, the catalog service shows increased query latency, and some requests time out. What should the architect prioritize to address the issue?

A.Use Cloud CDN to cache product catalog responses.
B.Increase the number of nodes in the GKE node pool.
C.Enable Cloud Spanner interleaved tables and add secondary indexes for common query filters.
D.Migrate the catalog service from Cloud Spanner to Cloud Bigtable for better read performance.
AnswerC

Cloud Spanner query latency under flash-sale load stems from scanning non-interleaved tables and full-table reads. Interleaving co-locates child rows with parents, and secondary indexes accelerate the catalog's common filter queries, cutting the data scanned and reducing timeouts at the database layer.

Why this answer

The issue is specifically with Cloud Spanner query latency under high load. Enabling interleaved tables and adding secondary indexes optimizes data locality and query performance, reducing the need for expensive cross-table joins and full table scans. This directly addresses the root cause of increased latency and timeouts in the catalog service.

Exam trap

The trap here is that candidates often confuse horizontal scaling (adding nodes) with database optimization, overlooking that Cloud Spanner performance issues require schema-level tuning rather than infrastructure scaling.

How to eliminate wrong answers

Option A is wrong because Cloud CDN caches static content at edge locations, but the product catalog service uses Cloud Spanner for dynamic, frequently updated data; caching would serve stale data and not resolve database query latency. Option B is wrong because increasing GKE nodes adds compute capacity but does not fix the underlying database query performance issue; the bottleneck is in Cloud Spanner, not in pod scheduling or node resources. Option D is wrong because Cloud Bigtable is optimized for high-throughput, low-latency key-value lookups, not for complex queries with secondary filters or joins; migrating would require significant architectural changes and may not support the catalog service's query patterns.

11
MCQmedium

A global e-commerce company is designing a multi-region architecture on Google Cloud to ensure high availability and low latency for users worldwide. They want to use a global load balancer that can route traffic to the closest healthy backend and support HTTP(S) and TCP traffic. Which Google Cloud load balancing option should they use?

A.Global external HTTP(S) load balancer with TCP proxy
B.Global external TCP/UDP load balancer
C.Global external HTTP(S) load balancer and global external TCP proxy load balancer
D.Global external HTTP(S) load balancer
AnswerC

To support both HTTP(S) and TCP traffic with global load balancing and proximity routing, you can use two separate load balancers: the global external HTTP(S) load balancer for HTTP(S) traffic and the global external TCP proxy load balancer for TCP traffic. Both are global and route to the closest healthy backend. This combination meets all requirements.

Why this answer

Google Cloud offers separate global load balancers for different protocols. The global external HTTP(S) load balancer handles HTTP(S) traffic with proximity-based routing, while the global external TCP proxy load balancer handles TCP traffic with global anycast IP and proximity routing. Using both together provides the required support for both protocols in a multi-region architecture.

Exam trap

The trap here is assuming a single load balancer can handle both HTTP(S) and TCP traffic globally, but Google Cloud separates these into different load balancer types.

12
MCQhard

A financial services firm runs a global trading platform on Google Cloud. The architecture must survive the loss of an entire region with a recovery point objective of zero and a recovery time objective of under one minute, and it must keep strong consistency for order records. Which design should the architect recommend?

A.Deploy the application in two regions behind a global external Application Load Balancer, and store order records in Cloud Spanner with a multi-region instance configuration.
B.Deploy the application in two regions behind a global external Application Load Balancer, and store order records in a Cloud SQL for PostgreSQL instance with a cross-region read replica promoted on failover.
C.Deploy the application in two regions behind a global external Application Load Balancer, and store order records in a Bigtable instance with a multi-cluster routing policy.
D.Deploy the application in two regions behind a global external Application Load Balancer, and store order records in a multi-region Cloud Storage bucket mounted as a file system on the application VMs.
AnswerA

A multi-region Cloud Spanner configuration replicates data synchronously across regions and provides external consistency, so no committed order is lost when a region fails, satisfying the zero RPO. Spanner redirects traffic to surviving replicas automatically, and the global external Application Load Balancer steers users to healthy backends within seconds, meeting the sub-minute RTO. This combination is the standard design for globally consistent, region-fault-tolerant transactional systems on Google Cloud.

Why this answer

Zero RPO with sub-minute RTO for transactional records requires synchronous replication plus automated failover. Cloud Spanner multi-region configurations replicate synchronously and expose externally consistent reads and writes, so a committed order survives a full region outage. The global external Application Load Balancer provides anycast front ends and health-check-based failover to the surviving region.

Together they deliver the availability and consistency guarantees the trading platform needs without manual intervention.

Exam trap

The trap here is treating any multi-region data service as equivalent, when replicas that are asynchronous cannot satisfy a zero recovery point objective.

13
MCQhard

Refer to the exhibit. A developer is trying to connect to the Kubernetes API server from their workstation using the master IP (34.67.89.12) but receives a timeout. The developer can reach other external IPs. What is the most likely reason for the timeout?

A.The cluster is in a different region than the developer's VPC.
B.The developer's workstation does not have the required firewall rule to allow traffic to the master IP.
C.The private cluster is configured with a private endpoint and public endpoint disabled, so the master IP is not accessible from outside the VPC.
D.The Kubernetes Engine API is not enabled in the developer's project.
AnswerC

A private endpoint with public endpoint disabled removes the externally routable master IP entirely, so packets to 34.67.89.12 are dropped before reaching the control plane. The developer's workstation sits outside the VPC, satisfying the stem's constraint that other external IPs remain reachable while the API server times out.

Why this answer

A private GKE cluster with a private endpoint and public endpoint disabled means the Kubernetes API server is only reachable from within the cluster's VPC network. The developer's workstation is outside the VPC, so attempts to reach the master IP (34.67.89.12) will time out, even though other external IPs are reachable. This is a common configuration for security-sensitive workloads that require the API server to be isolated from the public internet.

Exam trap

Google PCA often tests the distinction between a private GKE cluster with public endpoint disabled versus a cluster that is simply in a different region or has firewall issues, leading candidates to overlook the fact that a timeout from outside the VPC indicates the endpoint is not publicly accessible.

How to eliminate wrong answers

Option A is wrong because the cluster being in a different region than the developer's VPC does not inherently cause a timeout; cross-region connectivity is possible via public internet or VPN, and the developer can reach other external IPs, so region mismatch is not the issue. Option B is wrong because the developer's workstation firewall rules are irrelevant if the cluster's API server endpoint is not exposed to the public internet; the timeout occurs at the network level before any firewall on the workstation is evaluated. Option D is wrong because if the Kubernetes Engine API were not enabled, the developer would likely receive an API error (e.g., 403 or 404) rather than a timeout; a timeout indicates a network connectivity issue, not a disabled API.

14
MCQeasy

A startup is deploying a new web application on Google Cloud. They want to minimize infrastructure management and focus on writing code. The application consists of a frontend and a backend API, and they expect variable traffic. They also want to pay only for what they use. Which Google Cloud service should the solutions architect recommend for deploying the application?

A.Google Kubernetes Engine (GKE) with Autopilot.
B.App Engine standard environment.
C.Cloud Run.
D.Compute Engine with managed instance groups.
AnswerC

Cloud Run is a fully managed serverless platform that runs containers and automatically scales based on traffic, including scaling to zero. It abstracts away all infrastructure, allowing the startup to focus on code. It charges only for resources used during request handling, matching the pay-per-use requirement.

Why this answer

Cloud Run is a serverless compute platform that runs stateless containers, scales automatically with traffic, and charges only for resources consumed during request processing. It eliminates infrastructure management, letting the startup focus on code. Its ability to scale to zero and handle variable traffic makes it ideal for a frontend and backend API with unpredictable load.

Exam trap

The trap here is assuming that a managed Kubernetes service like GKE Autopilot is the most serverless option, when Cloud Run requires even less management and is better suited for simple containerized applications.

15
Drag & Dropmedium

Drag and drop the steps to set up a VPC network peering between two projects in Google Cloud into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

VPC peering requires bidirectional connections; both sides must initiate peering. IP ranges must not overlap.

16
Multi-Selecthard

A multinational retailer is planning its Google Cloud landing zone. Each of the company's business units must be able to create projects and manage billing independently, but the central platform team must retain the ability to enforce network and security guardrails across everything. The company also wants to minimize the number of distinct IAM policy bindings it maintains at the top of the hierarchy. Which two design choices should the architect make? (Choose two.)

Select 2 answers
A.Grant each business unit's administrators the Organization Administrator role so they can create projects anywhere in the hierarchy
B.Create every project directly under the organization node and attach a distinct billing account to each project for isolation
C.Apply organization policies such as constraints on allowed resource locations and external IP addresses at the organization node so they are inherited by all folders and projects
D.Use a shared VPC host project per business unit and grant the central team Compute Network Admin on each host project only
E.Create a separate folder per business unit under the organization node and grant each business unit's administrators project creator and billing roles at the folder level
AnswersC, E

Organization policies applied at the organization node are inherited by every descendant folder and project, which enforces guardrails centrally without per-project configuration. This directly supports the requirement that the central platform team retains control while business units operate independently, and it avoids duplicating policy definitions across many projects.

Why this answer

Delegating project creation and billing to folder-level roles gives each business unit autonomy while keeping the grant in one place per unit. Applying organization policies at the organization node enforces network and security guardrails through inheritance, so the central team controls every descendant without per-project work. Together these choices satisfy autonomy, central control, and a small number of top-level IAM bindings.

Exam trap

The trap here is solving delegation by granting a powerful organization-wide role instead of scoping permissions at a folder.

17
MCQmedium

A company hosts a web application on Compute Engine behind a global HTTP(S) load balancer. They notice that some users experience high latency from certain regions. They want to improve performance without adding complexity. What should they do?

A.Add more instances in the same region
B.Use Premium Tier networking
C.Enable Cloud Armor
D.Enable Cloud CDN
AnswerD

Cloud CDN caches content at Google's globally distributed edge points of presence, so users in distant regions fetch objects from a nearby cache rather than the origin. This reduces latency without adding architectural complexity, satisfying the stem's constraint.

Why this answer

Enabling Cloud CDN caches content at Google's globally distributed edge caches, reducing latency for users in regions far from the origin Compute Engine instances. This directly addresses the high-latency issue without adding complexity, as it requires no changes to the application architecture and is a simple configuration toggle on the load balancer backend bucket or backend service.

Exam trap

The trap here is that candidates may confuse network optimization (Premium Tier) with content caching (CDN), assuming that faster routing alone solves geographic latency, but only caching eliminates the need for long-distance round trips.

How to eliminate wrong answers

Option A is wrong because adding more instances in the same region does not reduce latency for users in distant regions; it only increases capacity within that region, leaving cross-continental network hops unchanged. Option B is wrong because Premium Tier networking improves routing performance by using Google's global fiber network, but it does not cache content; it still requires a full round trip to the origin for every request, so it does not eliminate latency from geographic distance. Option C is wrong because Cloud Armor provides security protections like DDoS mitigation and WAF rules; it does not cache or accelerate content delivery, so it has no effect on latency for static or cacheable responses.

18
MCQhard

A company is migrating a monolithic application to Google Cloud. The application consists of a stateful service that writes to local disk and a stateless web server. They want to minimize changes to the code. Which architecture should they use?

A.Run the entire application on Cloud Run and use Cloud Filestore for shared state
B.Use App Engine Flexible Environment for the web server and Cloud SQL for state
C.Refactor the application into microservices and deploy on GKE with StatefulSets
D.Lift and shift to Compute Engine instances with persistent disks for stateful service
AnswerD

Lift and shift preserves the existing monolithic code, satisfying the minimal-change constraint. Compute Engine persistent disks provide durable block storage that survives instance restarts, so the stateful service's local disk writes remain intact without refactoring into Cloud Storage or a managed database.

Why this answer

It represents a lift-and-shift migration that minimizes code changes by running the monolithic application on Compute Engine instances. The stateful service can use persistent disks for local disk writes, while the stateless web server runs on the same or separate instances, preserving the existing architecture without refactoring.

Exam trap

The trap here is that candidates often over-engineer the solution by choosing cloud-native options (like Cloud Run or GKE) that require code changes, ignoring the explicit requirement to minimize changes and the suitability of a simple lift-and-shift with persistent disks.

How to eliminate wrong answers

Option A is wrong because Cloud Run is stateless and does not support local disk writes; Cloud Filestore is a network file system that would require code changes to replace local disk I/O. Option B is wrong because App Engine Flexible Environment does not support local disk writes for stateful services, and migrating to Cloud SQL would require significant code changes to replace local disk-based state. Option C is wrong because refactoring into microservices and using GKE with StatefulSets contradicts the requirement to minimize code changes, as it requires substantial application restructuring.

19
MCQeasy

A company is planning to migrate a batch processing workload to Google Cloud. The workload runs nightly and can be interrupted without impacting the business. The company wants to minimize compute costs. Which Google Cloud service should they use?

A.Google Kubernetes Engine (GKE) with Autopilot
B.Compute Engine committed use discounts (CUDs)
C.Compute Engine preemptible VMs
D.Compute Engine Spot VMs
AnswerD

Spot VMs offer significant discounts (up to 91%) compared to on-demand VMs and can be preempted when resources are needed. They are ideal for batch processing that can tolerate interruptions. Unlike preemptible VMs, Spot VMs do not have a 24-hour maximum runtime, making them more flexible for longer jobs. This minimizes compute costs while meeting the workload's requirements.

Why this answer

Spot VMs provide the deepest discounts for interruptible workloads and have no maximum runtime limit, unlike preemptible VMs. They are perfect for batch processing that can be paused or restarted. Committed use discounts require long-term commitments, and GKE Autopilot adds unnecessary complexity for a simple batch job.

Spot VMs minimize compute costs while meeting the workload's tolerance for interruptions.

Exam trap

The trap here is selecting preemptible VMs instead of Spot VMs, as preemptible VMs have a 24-hour limit and are being deprecated in favor of Spot VMs.

20
MCQmedium

A retail company runs a batch analytics workload on Compute Engine. Jobs run nightly, are fault-tolerant, and can be preempted. Finance wants to minimize compute cost while ensuring the jobs still complete each night. The jobs are managed by a Managed Instance Group (MIG) template that must stay within a single zone for data locality compliance. Which configuration should you recommend?

A.Create a zonal MIG with E2 standard VMs and configure a sustained use discount to lower the price.
B.Create a regional MIG with committed use discounts applied to the template and scale across three zones.
C.Create a zonal MIG with custom machine types and use the committed use discount for one-year terms.
D.Create a zonal MIG with a spot VM instance template and set the autoscaler to scale based on CPU utilization.
AnswerD

Spot VMs provide up to 60-91% discount versus standard VMs and are ideal for fault-tolerant, preemptible batch jobs. A zonal MIG keeps instances in one zone, satisfying the data locality requirement, and the autoscaler adds capacity when CPU rises during the nightly run. The job must tolerate preemption, which it does, so spot VMs directly minimize cost without violating the stated constraints.

Why this answer

Spot VMs offer the largest discount for fault-tolerant, preemptible workloads, and a zonal MIG preserves the single-zone data locality requirement. The autoscaler ensures the nightly job has enough instances to finish on time. Committed use and sustained use discounts target steady-state or long-running workloads, so they do not fit a short nightly batch window.

The combination of spot VMs, zonal placement, and CPU-based autoscaling meets both the cost and compliance constraints.

Exam trap

The trap here is assuming that committed use discounts are always the cheapest option, when they only pay off for steady, long-running workloads rather than nightly preemptible batch jobs.

21
MCQeasy

A retail company is planning to move its on-premises data warehouse to Google Cloud. They need a fully managed, petabyte-scale analytics database that supports standard SQL and can ingest data in real time from Pub/Sub. They also want to minimize administration and cost. Which Google Cloud service should they choose?

A.Bigtable
B.Cloud SQL for PostgreSQL
C.BigQuery
D.Cloud Spanner
AnswerC

BigQuery is a fully managed, petabyte-scale analytics data warehouse that supports standard SQL and integrates natively with Pub/Sub for real-time ingestion via the BigQuery Storage Write API or Dataflow. It eliminates infrastructure management and offers cost-effective pricing models. This directly matches the requirements for a managed, scalable analytics database with real-time ingestion.

Why this answer

BigQuery is the correct choice because it is a fully managed, petabyte-scale analytics database that supports standard SQL and integrates with Pub/Sub for real-time data ingestion. It minimizes administration and offers cost-effective pricing, making it ideal for moving an on-premises data warehouse to Google Cloud.

Exam trap

The trap here is confusing a transactional database like Cloud Spanner with an analytical data warehouse, or assuming that any scalable database can serve as a data warehouse.

22
MCQhard

Refer to the exhibit. A subnet was created with the `--enable-private-ip-google-access` flag. What does this flag enable for instances in this subnet?

A.Instances can use direct peering to connect to on-premises networks.
B.Instances automatically receive internal DNS names for Google services.
C.Instances can access Google APIs and services without requiring an external IP address.
D.Instances can route traffic to the internet through a Cloud NAT gateway.
AnswerC

Private Google Access lets instances with only internal IP addresses reach Google APIs and services through Google's internal network. It removes the need for an external IP or NAT gateway to reach those endpoints, satisfying the subnet's private-only addressing.

Why this answer

The `--enable-private-ip-google-access` flag allows VM instances in a subnet to reach Google APIs and services (such as Cloud Storage, BigQuery, and Cloud Pub/Sub) using only their internal (private) IP addresses, without needing an external IP address. This works by routing traffic through Google's internal network to the Google Front End (GFE), bypassing the public internet.

Exam trap

Google Cloud often tests the distinction between private Google access (which only covers Google APIs and services) and Cloud NAT (which provides outbound internet access for private instances), leading candidates to confuse the two or assume private Google access enables general internet connectivity.

How to eliminate wrong answers

Option A is wrong because direct peering to on-premises networks is enabled by setting up a dedicated interconnect or partner interconnect, not by the `--enable-private-ip-google-access` flag. Option B is wrong because internal DNS names for Google services are automatically provided by the Cloud DNS service for resources within the VPC, not by this subnet-level flag. Option D is wrong because routing traffic to the internet through a Cloud NAT gateway is a separate configuration that requires a Cloud NAT resource and a router, and it is not enabled by this flag; the flag specifically enables access to Google APIs and services, not general internet access.

23
Multi-Selecthard

Your company is deploying a multi-tier application on Google Cloud. The application consists of a web frontend running on Compute Engine instances, a backend API running on Google Kubernetes Engine (GKE), and a Cloud SQL for MySQL database. You need to design the network architecture to ensure that the web frontend can communicate with the backend API, and the backend API can access the Cloud SQL database, while minimizing exposure to the public internet. Which two design choices should you implement? (Choose two.)

Select 2 answers
A.Place the web frontend and backend API in the same VPC network but different subnets, and configure firewall rules to allow traffic only from the frontend subnet to the backend API on the required port.
B.Enable Private Service Access for Cloud SQL so that the backend API can connect to the database using a private IP address within the VPC.
C.Use Cloud VPN to connect the web frontend and backend API over an encrypted tunnel, even though they are in the same Google Cloud region.
D.Assign external IP addresses to all Compute Engine instances and GKE nodes, and use firewall rules to restrict access to specific source IP ranges.
E.Create a separate VPC network for each tier and use VPC peering to connect them, then configure firewall rules to allow traffic between the peered networks.
AnswersA, B

Placing both tiers in the same VPC network allows internal communication using private IP addresses, and firewall rules can restrict access to only the necessary source subnet and port. This minimizes public exposure because the backend API does not need a public IP. It also simplifies routing and security management within a single network.

Why this answer

The correct choices are to place both tiers in the same VPC with firewall rules restricting traffic, and to enable Private Service Access for Cloud SQL. This ensures internal communication without public internet exposure. Using a single VPC simplifies security, and Private Service Access provides private connectivity to Cloud SQL, meeting the requirement to minimize public exposure.

Exam trap

The trap here is thinking that additional network isolation (like separate VPCs or VPNs) automatically improves security, when it often adds complexity and does not reduce public exposure more than proper firewall rules and private service access.

24
MCQeasy

A retail company runs a Black Friday promotion and expects a burst of read traffic against a product-catalog database. The application is read-heavy, tolerates slightly stale data, and the team wants to scale reads horizontally without changing application code. They are using Cloud SQL for MySQL. Which design should the architect recommend?

A.Enable Cloud SQL high availability by adding a standby instance and send read queries to the standby
B.Increase the primary instance's vCPU count and memory to absorb the read burst
C.Migrate the catalog to Firestore in Native mode and let the client SDK cache reads
D.Configure a Cloud SQL read replica in the same region and point read queries at its IP address
AnswerD

Cloud SQL for MySQL supports read replicas that receive asynchronous replication from the primary. Pointing read-only traffic at the replica IP offloads the primary and scales reads horizontally. The application tolerates slight staleness, which matches asynchronous replication, and no schema or code changes are needed beyond routing read connections.

Why this answer

Read replicas are the native Cloud SQL for MySQL mechanism for horizontal read scaling with asynchronous replication. Because the application tolerates slightly stale data, the replication lag is acceptable, and no code changes are needed beyond pointing read connections at the replica. A high-availability standby is not readable, Firestore requires a rewrite, and vertical scaling does not scale reads horizontally.

Exam trap

The trap here is assuming the high-availability standby can serve reads, when it is a non-readable failover target only.

25
MCQhard

A healthcare company is designing a system to process sensitive patient records on Google Cloud. They need to ensure that data is encrypted at rest with keys they control and can rotate on demand. They also require that the encryption keys are stored in a hardware security module (HSM) that is FIPS 140-2 Level 3 validated. Which Google Cloud service should they use?

A.Cloud HSM with Cloud KMS
B.Google-managed encryption keys
C.Customer-managed encryption keys (CMEK) with Cloud KMS
D.Customer-supplied encryption keys (CSEK)
AnswerA

Cloud HSM is a cloud-hosted HSM that is FIPS 140-2 Level 3 validated. When used with Cloud KMS, you can create and manage keys in an HSM, control rotation, and use them for encryption at rest. This meets all requirements: customer-controlled keys, on-demand rotation, and HSM storage with FIPS 140-2 Level 3. It integrates with many Google Cloud services for CMEK.

Why this answer

Cloud HSM with Cloud KMS provides hardware security module-backed keys that are FIPS 140-2 Level 3 validated. It allows you to control key rotation and use them for encryption at rest across Google Cloud services. Google-managed keys do not give customer control, CMEK with standard Cloud KMS does not guarantee HSM storage, and CSEK requires external key management without HSM integration.

Exam trap

The trap here is assuming that CMEK alone provides HSM storage, but only Cloud HSM offers FIPS 140-2 Level 3 validated hardware security modules.

26
MCQhard

A financial services company is designing a multi-region application on Google Kubernetes Engine (GKE) for high availability. They need to serve user requests from the closest region and automatically failover if a region becomes unavailable. Which architecture should they use?

A.Use a global external HTTP(S) load balancer with a single backend service pointing to one regional cluster.
B.Use Cloud CDN in front of a single regional GKE cluster to cache content.
C.Use a single regional GKE cluster with auto-scaling across zones.
D.Deploy GKE clusters in multiple regions and use a multicluster ingress with an external HTTP(S) load balancer set up with the global external backend.
AnswerD

Regional GKE clusters behind a multicluster ingress and global external HTTP(S) load balancer give anycast-style entry, directing users to the nearest healthy region and rerouting automatically when a region fails, meeting both the proximity and failover constraints.

Why this answer

Deploying GKE clusters in multiple regions and using a multicluster ingress with a global external HTTP(S) load balancer enables traffic routing to the closest healthy backend cluster based on latency or geography, and automatically fails over to another region if one becomes unavailable. The global external backend configuration allows the load balancer to distribute traffic across multiple regional GKE clusters, providing both proximity-based routing and high availability.

Exam trap

The trap here is that candidates often confuse zonal high availability (auto-scaling across zones within one region) with regional high availability (multi-region failover), and overlook that a global load balancer with multiple regional backends is required for true multi-region traffic steering and failover.

How to eliminate wrong answers

Option A is wrong because a single backend service pointing to one regional cluster cannot provide multi-region failover or route users to the closest region; it only supports a single region. Option B is wrong because Cloud CDN caches content but does not provide active failover or multi-region traffic steering; it only reduces latency for cached content from a single origin. Option C is wrong because a single regional GKE cluster with auto-scaling across zones provides zonal high availability within one region but cannot serve requests from the closest region or failover to another region if the entire region becomes unavailable.

27
MCQeasy

A logistics company is planning its first Google Cloud landing zone. It has three business units that must be billed separately, a central network team that manages shared VPCs, and a security team that needs to apply guardrails across everything. Which resource hierarchy design should the architect recommend?

A.Create one project per business unit, place all projects directly under the organization node, and use labels to separate billing and security policies.
B.Create folders per business unit and per environment under the organization, place application projects inside those folders, and create a separate shared networking project owned by the central network team.
C.Create a single project for the whole company and use IAM roles and labels to separate business units, environments, and network administration.
D.Create one organization per business unit, each with its own projects, and link them with VPC peering for shared network services.
AnswerB

Folders allow policies and IAM to be inherited and scoped per business unit and environment, satisfying the security team's need for guardrails. Placing application projects inside environment folders keeps production and non-production separated. A dedicated shared networking project, owned centrally, is the standard pattern for shared VPC host projects and keeps network administration distinct from application ownership, supporting separate billing.

Why this answer

The scenario calls for delegated administration, separate billing, central networking, and organization-wide guardrails. A hierarchy of folders by business unit and environment lets policy and IAM inherit cleanly, projects give billing and isolation boundaries, and a dedicated shared networking project is the canonical host for shared VPC. Flattening everything, collapsing into one project, or splitting into multiple organizations each breaks at least one of these requirements.

Exam trap

The trap here is assuming labels can substitute for folders when scoping security policies, but labels do not participate in policy inheritance.

28
MCQhard

Your organization is deploying a global e-commerce platform on Google Cloud. The platform uses a microservices architecture running on GKE, and you need to route external HTTP(S) traffic to different services based on URL paths and also provide global load balancing with low latency. You also want to offload SSL/TLS termination and protect against DDoS attacks. Which Google Cloud service should you use?

A.Internal HTTP(S) Load Balancer with a URL map and Google-managed SSL certificates, integrated with Cloud Armor.
B.TCP Proxy Load Balancer with a backend service and Google-managed SSL certificates, integrated with Cloud Armor.
C.Global external HTTP(S) Load Balancer with a URL map and Google-managed SSL certificates, integrated with Cloud Armor.
D.Regional external HTTP(S) Load Balancer with a URL map and self-managed SSL certificates, integrated with Cloud CDN.
AnswerC

The global external HTTP(S) Load Balancer provides global anycast IP, low-latency routing, and URL path-based routing via URL maps. It supports Google-managed SSL certificates for TLS termination and integrates with Cloud Armor for DDoS protection and WAF rules. This meets all requirements: global load balancing, path-based routing, SSL offload, and DDoS mitigation.

Why this answer

The global external HTTP(S) Load Balancer is the only option that provides global anycast load balancing, URL path-based routing, Google-managed SSL certificates for TLS termination, and integration with Cloud Armor for DDoS protection. It is designed for external HTTP(S) traffic and meets all the stated requirements for a global e-commerce platform.

Exam trap

The trap here is assuming that a regional load balancer or a TCP proxy can provide global HTTP(S) routing with path-based rules, when only the global external HTTP(S) Load Balancer offers all these features together.

29
MCQeasy

A retail company is planning to migrate its on-premises data warehouse to Google Cloud. They want a fully managed, petabyte-scale, and highly scalable analytics data warehouse that supports ANSI SQL and integrates with their existing BI tools. Which Google Cloud service should they choose?

A.Cloud Spanner
B.BigQuery
C.Cloud SQL
D.Cloud Bigtable
AnswerB

BigQuery is a fully managed, petabyte-scale analytics data warehouse that supports ANSI SQL and integrates with many BI tools. It is designed for high-performance analytics and can scale seamlessly. It is serverless and allows you to run fast SQL queries on large datasets. This makes it the ideal choice for migrating an on-premises data warehouse and supporting BI workloads.

Why this answer

BigQuery is Google Cloud's fully managed, petabyte-scale analytics data warehouse that supports ANSI SQL and integrates with BI tools. It is serverless, highly scalable, and designed for analytical workloads. Cloud SQL is for transactional databases, Cloud Spanner is for global transactional consistency, and Cloud Bigtable is a NoSQL database for high-throughput applications, none of which are optimized for petabyte-scale SQL analytics.

Exam trap

The trap here is assuming that any managed database service can serve as a data warehouse, but only BigQuery is purpose-built for petabyte-scale analytics with ANSI SQL support.

30
MCQmedium

A data analytics company runs nightly batch jobs using Compute Engine instances. The jobs can tolerate interruptions, and the company wants to minimize costs. What should they do?

A.Use preemptible VMs for the batch jobs.
B.Use C2 high-CPU machine types for faster processing.
C.Use standard (on-demand) VMs and commit to a 1-year resource-based commitment.
D.Deploy VMs on Sole-tenant nodes for cost isolation.
AnswerA

Preemptible VMs cost substantially less than standard instances but can be reclaimed at any time, with a 24-hour maximum runtime. The batch jobs tolerate interruptions, so this constraint is satisfied. Combining them with a managed instance group and restart logic keeps the nightly workload completing despite preemption.

Why this answer

Preemptible VMs (now called Spot VMs) are Compute Engine instances that last up to 24 hours and can be terminated at any time by Google Cloud. Because the batch jobs are interruptible, using preemptible VMs reduces compute costs by up to 60-91% compared to standard on-demand VMs, directly meeting the goal of minimizing costs.

Exam trap

The trap here is that candidates may confuse preemptible VMs with standard VMs and assume they are unreliable for any workload, but the question explicitly states the jobs can tolerate interruptions, making preemptible VMs the correct cost-saving choice.

How to eliminate wrong answers

Option B is wrong because C2 high-CPU machine types are optimized for compute-intensive workloads, not for cost minimization; they are more expensive per hour than standard machine types and do not address the interruptible nature of the jobs. Option C is wrong because committing to a 1-year resource-based commitment locks the company into a fixed cost for on-demand VMs, which is more expensive than preemptible VMs and unnecessary for interruptible batch jobs that do not require guaranteed availability. Option D is wrong because Sole-tenant nodes provide hardware isolation for compliance or licensing needs, not cost reduction; they actually increase costs due to premium pricing for dedicated hardware.

31
MCQmedium

A retail company is designing a new order-processing system on Google Cloud. The system must expose a REST API that is reachable from the public internet over a custom hostname, must terminate TLS at the edge, and must route requests to different backend services based on URL path prefixes such as /orders and /inventory. The platform team wants a fully managed, globally distributed solution that scales automatically and does not require managing reverse-proxy VMs. Which Google Cloud component should they place in front of the backends?

A.Traffic Director with Envoy sidecars deployed on each backend instance
B.Regional external passthrough Network Load Balancer with backend services in two zones
C.Global external Application Load Balancer with a URL map and a Google-managed SSL certificate
D.Cloud CDN with a signed URL key attached directly to the backend instance groups
AnswerC

The global external Application Load Balancer is a managed Layer 7 proxy that terminates TLS at Google's edge, supports custom hostnames through Google-managed certificates, and uses a URL map to route by path prefix to different backends. It scales globally without reverse-proxy VMs, which matches every stated requirement.

Why this answer

The global external Application Load Balancer is the only listed option that combines managed edge TLS termination, custom hostname support through Google-managed certificates, and URL-map-based path routing to multiple backends. Because it is a fully managed global proxy, it scales automatically and removes the operational burden of running reverse-proxy VMs, satisfying both the functional and operational requirements.

Exam trap

The trap here is assuming that any load balancer can perform HTTP path-based routing, when Layer 4 passthrough network load balancers only forward TCP connections.

32
Drag & Dropmedium

Drag and drop the steps to recover a Cloud SQL instance from a backup into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Restoring to an existing instance may overwrite data; best practice is to restore to a new instance.

33
Multi-Selecthard

A company is migrating a legacy on-premises application to Google Cloud. The application has strict low-latency requirements between its components and requires stateful TCP sessions. Which TWO design decisions should the architect recommend?

Select 2 answers
A.Use regional managed instance groups with internal load balancing.
B.Use Cloud NAT for outbound connectivity.
C.Use global load balancing with Cloud CDN.
D.Use Cloud VPN for on-premises connectivity.
E.Place all components in the same VPC network.
AnswersA, E

Supports session affinity and preserves source IP for stateful protocols.

Why this answer

Regional managed instance groups (MIGs) with internal load balancing are correct because they keep all compute instances within a single region, minimizing network hops and latency between components. Internal load balancing provides a single IP address for stateful TCP sessions without introducing the latency of a global proxy, and it supports session affinity (e.g., client IP affinity) to maintain stateful connections.

Exam trap

The trap here is that candidates often confuse global load balancing (which is for external, stateless, HTTP-based traffic) with internal load balancing, and mistakenly think Cloud CDN or Cloud NAT can help with latency or stateful sessions, when they actually break TCP state or add unnecessary hops.

34
MCQhard

A healthcare analytics company is designing a BigQuery-based data warehouse that ingests patient records from multiple hospitals. Regulatory requirements mandate that queries never move data across regional boundaries and that only authorized analysts can access patient-identifiable columns. The architects want to enforce these controls at the platform level rather than relying on application code. Which combination of Google Cloud features should they design into the solution?

A.BigQuery dataset location set to a single region, authorized views that exclude patient-identifiable columns, and Cloud Armor security policies on the BigQuery API endpoint.
B.BigQuery multi-region dataset, Cloud IAM basic roles for analysts, and Cloud DLP inspection jobs scheduled daily.
C.BigQuery dataset location set to a single region, IAM conditions based on resource names, and customer-managed encryption keys in Cloud KMS.
D.BigQuery dataset location set to a single region, VPC Service Controls perimeter around the project, and column-level security using policy tags in Data Catalog.
AnswerD

BigQuery dataset location pins data to a region, satisfying the no-cross-region requirement. A VPC Service Controls perimeter prevents data exfiltration and restricts access to only authorized networks and identities. Policy tags in Data Catalog enable column-level access control so only approved analysts can read patient-identifiable columns. Together these enforce controls at the platform level without application changes.

Why this answer

Data residency is enforced by pinning the BigQuery dataset to a single region. Preventing exfiltration and restricting access to authorized identities and networks is the role of VPC Service Controls. Column-level least privilege for patient-identifiable fields is achieved with policy tags in Data Catalog, which BigQuery enforces natively.

This trio addresses residency, perimeter, and column-level authorization at the platform layer.

Exam trap

The trap here is treating Cloud DLP as an access-control mechanism, when it only discovers and classifies sensitive data and does not restrict who can query specific columns.

35
MCQhard

A financial services company runs a regulated trading platform in a single Google Cloud region. Regulators require that the platform survive the loss of an entire region with a recovery point objective of zero and a recovery time objective of under one minute. The database is Cloud Spanner, and the application tier runs on Google Kubernetes Engine. Which design should the architect choose?

A.Deploy Cloud Spanner as a regional instance and take scheduled backups exported to a Cloud Storage bucket in another region
B.Deploy Cloud Spanner as a multi-region instance and run GKE regional clusters in two regions behind a global external Application Load Balancer
C.Deploy Cloud Spanner as a multi-region instance and run a single GKE zonal cluster with node pools spread across three zones in the primary region
D.Deploy Cloud Spanner as a regional instance with read replicas in a second region and use change streams to replay writes into the second region after failover
AnswerB

A multi-region Cloud Spanner instance synchronously replicates data across regions with strong consistency, giving a recovery point objective of zero. Regional GKE clusters in two regions behind a global external Application Load Balancer provide health-checked failover with sub-minute recovery. Together they meet both the zero data loss and under-one-minute recovery targets for a region loss.

Why this answer

Zero recovery point objective demands synchronous cross-region replication, which only a multi-region Cloud Spanner instance provides. Sub-minute recovery demands application compute already running in a second region with automated traffic failover. Combining a multi-region Spanner instance with regional GKE clusters in two regions behind a global external Application Load Balancer satisfies both constraints simultaneously.

Exam trap

The trap here is treating backups, change streams, or zone redundancy as substitutes for synchronous cross-region replication and pre-provisioned compute in a second region.

36
MCQmedium

Refer to the exhibit. A Cloud Storage bucket has this IAM policy. What security recommendation should be made?

A.Remove the `allUsers` member and use signed URLs for public access.
B.Change `allUsers` to `allAuthenticatedUsers` to allow only authenticated users.
C.Enable uniform bucket-level access and update the IAM policy.
D.Remove the `roles/storage.objectViewer` role binding entirely.
AnswerA

Removing `allUsers` eliminates anonymous, unauthenticated access to every object, satisfying the least-privilege constraint. Signed URLs instead grant time-limited, cryptographically authenticated access to specific objects, so public distribution still works without exposing the entire bucket's contents to enumeration or unintended reads.

Why this answer

The IAM policy grants `roles/storage.objectViewer` to `allUsers`, which makes the bucket's objects publicly readable by anyone on the internet. This is a security risk because it allows anonymous access without authentication or logging. The recommended practice is to remove the `allUsers` member and instead use signed URLs (which embed a time-limited access token) to grant temporary, controlled access to specific objects.

Exam trap

Google Cloud often tests the misconception that `allAuthenticatedUsers` is a secure alternative to `allUsers`, but the trap is that it still allows any authenticated identity (including attackers) to access the data, whereas signed URLs provide granular, revocable, and auditable access.

How to eliminate wrong answers

Option B is wrong because changing `allUsers` to `allAuthenticatedUsers` still allows any authenticated Google account (including attackers with a free account) to read the objects, which does not provide fine-grained access control and still exposes the data broadly. Option C is wrong because enabling uniform bucket-level access only ensures that all access is governed by IAM policies rather than ACLs, but it does not address the underlying problem of granting public access via `allUsers`. Option D is wrong because simply removing the role binding without replacing it with a secure access method (like signed URLs) would break all access to the objects, which is not a security recommendation but a denial of service.

37
MCQeasy

A small startup wants to deploy a containerized web application that scales automatically and only charges for resources used. They have limited operational experience. Which compute solution should they choose?

A.App Engine Standard Environment with a custom runtime.
B.Google Kubernetes Engine (GKE) with a multi-node pool.
C.Compute Engine with a managed instance group.
D.Cloud Run (fully managed).
AnswerD

Cloud Run is fully managed, scaling container instances to zero when idle, so billing follows actual request usage. It removes cluster and node management, matching the startup's limited operational experience while satisfying automatic scaling and pay-per-use.

Why this answer

Cloud Run (fully managed) is the right choice because it runs containerized applications on a fully managed serverless platform that automatically scales instances up and down (including to zero) based on traffic, and it bills only for the CPU, memory, and request resources actually consumed. This matches the startup's needs: containers, automatic scaling, pay-per-use pricing, and minimal operational overhead since Google manages the underlying infrastructure. App Engine Standard with a custom runtime is more restrictive and less container-native, while GKE with a multi-node pool and Compute Engine with a managed instance group both require the team to manage clusters, nodes, or instances and typically incur costs for provisioned capacity even when idle, which does not fit a low-ops, usage-based model.

38
MCQmedium

A retail company runs its e-commerce checkout service on a single Compute Engine instance in us-central1. The service must survive a zonal outage with minimal data loss and automatic failover, but the operations team is small and does not want to manage replication or failover scripts themselves. Which design should the architect recommend?

A.Deploy the checkout service as a regional managed instance group across three zones in us-central1 behind a global external Application Load Balancer, and store session state in a regional Cloud SQL for PostgreSQL instance with automatic failover.
B.Create a snapshot schedule for the instance boot disk and a Cloud Scheduler job that recreates the VM in a different zone when a Cloud Monitoring uptime check fails.
C.Keep the single instance but attach a regional persistent disk, and add a second instance in another zone that mounts the same disk read-only for reporting.
D.Move the service to two standalone Compute Engine instances in different zones and use a network load balancer with a health check, keeping the database on the original instance's local SSD.
AnswerA

A regional managed instance group spreads instances across three zones and automatically recreates capacity when a zone fails, while the global external Application Load Balancer routes only to healthy backends. A regional Cloud SQL instance maintains a standby in another zone and promotes it automatically, so both compute and data tiers survive a zonal outage without custom failover scripting.

Why this answer

Surviving a zonal outage with minimal data loss and no custom failover logic requires managed, zone-redundant building blocks at every tier. A regional managed instance group combined with a global external Application Load Balancer keeps serving traffic when a zone disappears, and a regional Cloud SQL instance promotes its standby automatically. Together these services remove the need for the small operations team to write or run replication and failover scripts.

Exam trap

The trap here is assuming that a regional persistent disk alone provides automatic failover, when it actually permits only one writer at a time and still requires a manual detach and reattach.

39
MCQhard

A healthcare company must store patient records on Google Cloud. Regulatory requirements mandate that the data encryption keys be generated and stored outside Google Cloud, that the company control key rotation, and that access to the data be denied if the external key is unavailable. The data will be stored in Cloud Storage and BigQuery. Which approach should the architect recommend?

A.Create Cloud KMS keys in a dedicated project and grant the services access to them
B.Encrypt data client-side with a locally stored key before uploading to Cloud Storage and BigQuery
C.Use Google-managed encryption keys and enable default encryption at rest for all services
D.Configure Customer-Managed Encryption Keys by using Cloud KMS with an external key manager via Cloud EKM
AnswerD

Cloud External Key Manager lets Cloud KMS use keys that are generated and stored in an external key management system outside Google Cloud. Access to the data depends on the external key being available, and the company controls rotation, which satisfies all the regulatory constraints for both Cloud Storage and BigQuery.

Why this answer

Cloud External Key Manager allows Cloud KMS to wrap data encryption keys with key material held in an external key management system outside Google Cloud. Because access to the wrapped keys requires the external system, the company controls generation and rotation and can deny access by making the external key unavailable, meeting the regulatory requirements for both Cloud Storage and BigQuery.

Exam trap

The trap here is equating customer-managed Cloud KMS keys with external key custody, when CMEK keys are still generated and stored inside Google Cloud.

40
MCQhard

A financial services firm is designing a new payment-processing platform on Google Cloud. Regulatory requirements mandate that data never leaves the European Union, that encryption keys are generated and stored on hardware the firm controls inside its own data center, and that the firm can revoke key access instantly. The security team wants to use Cloud KMS but is unsure it meets all three requirements. Which combination of services should the architect recommend?

A.Customer-managed encryption keys (CMEK) stored in a Cloud KMS key ring in europe-west1, with Cloud HSM backing.
B.Cloud External Key Manager (Cloud EKM) with a supported external key manager in the firm's data center, plus organization policy constraints to restrict resource locations.
C.Cloud KMS with CMEK and a key ring in europe-west4, combined with VPC Service Controls perimeters around all data services.
D.Cloud KMS with a multi-region key ring in europe, plus organization policy constraints to restrict resource locations.
AnswerB

Cloud EKM lets Cloud KMS call out to a supported external key manager that the firm operates, so keys are generated and stored on hardware inside its own data center while Google services use them through the KMS interface. If the firm cuts connectivity or disables the external key, Google loses the ability to unwrap data encryption keys, giving effectively instant revocation. Organization policy keeps resources in EU locations.

Why this answer

The three requirements are EU data residency, self-controlled key hardware, and instant revocation. Only an external key manager integration satisfies all three because the keys physically live in the firm's data center and Google must reach out to them for every unwrap operation. Location constraints in organization policy handle the residency requirement, and severing the external key path provides the immediate revocation the security team wants.

Exam trap

The trap here is treating Cloud HSM or CMEK as equivalent to holding keys in your own data center, when Google still operates that hardware.

41
MCQmedium

A healthcare company is deploying a new patient portal on Google Cloud. The portal must be accessible globally with low latency, must survive a single region failure, and must use a single anycast IP address. The backend runs on managed instance groups in two regions. Which Google Cloud product should the architect use to expose the service?

A.Global external HTTP(S) Load Balancing
B.Internal HTTP(S) Load Balancer with global access
C.Regional external TCP/SSL proxy load balancer
D.Cloud DNS with geo-routing and health checks
AnswerA

Global external HTTP(S) Load Balancing provides a single anycast IP address, terminates HTTP(S) at Google's edge, and routes users to the closest healthy backend. It supports multi-region managed instance groups and automatically fails over if a region becomes unhealthy. This meets the global low-latency, single IP, and cross-region survivability requirements for the patient portal without additional DNS-based failover mechanisms.

Why this answer

Global external HTTP(S) Load Balancing is the only option that provides a single global anycast IP, edge termination, and automatic multi-region failover for HTTP(S) workloads. Regional proxies lack global anycast, Cloud DNS geo-routing introduces DNS caching delays and multiple IPs, and internal load balancing is not internet-facing. The chosen design satisfies global low latency and region-failure survivability.

Exam trap

The trap here is assuming that Cloud DNS geo-routing with health checks can replace a global load balancer, when DNS TTLs and client caching prevent instant failover and do not provide a single anycast IP.

42
MCQmedium

A logistics company runs a latency-sensitive inventory service on Compute Engine in us-central1. The service writes to a Cloud SQL for MySQL instance and reads from a Memorystore for Redis cache. The architect must design for a zone failure in us-central1 with minimal data loss and automatic failover, without changing the application's connection strings. Which design should the architect choose?

A.Deploy the service in a managed instance group across three zones, use a Cloud SQL for MySQL regional instance with a primary and standby, and configure Memorystore for Redis in Standard Tier with automatic failover.
B.Deploy the service in a multi-region managed instance group, use Cloud Spanner instead of Cloud SQL, and use Memorystore for Redis in Basic Tier.
C.Deploy the service across two zones, use a Cloud SQL for MySQL regional instance, and run a self-managed Redis cluster on Compute Engine with Sentinel.
D.Deploy the service in a zonal managed instance group, use a Cloud SQL for MySQL zonal instance, and enable Memorystore for Redis Basic Tier with read replicas.
AnswerA

A regional managed instance group spreads VMs across zones so a single zone failure does not take down the service. A Cloud SQL regional instance maintains a standby in another zone and fails over automatically with minimal data loss. Memorystore for Redis Standard Tier provides a replica and automatic failover. The application connects through stable endpoints, so no connection string changes are needed.

Why this answer

Spreading the service across zones with a regional managed instance group, pairing it with a Cloud SQL regional instance that has a standby in another zone, and using Memorystore Standard Tier with automatic failover together address zone failure at every tier. Each component exposes stable endpoints, so the application keeps its existing connection strings.

Exam trap

The trap here is assuming that read replicas or a multi-zone application tier alone provide high availability, when the database and cache tiers must also have automatic failover.

43
MCQhard

A financial services firm must design a data residency solution. Regulators require that customer personal data never leaves the country of origin, but the firm wants to use a single centralized analytics project for aggregated, non-personal reporting. Which Google Cloud architecture best satisfies both requirements?

A.Deploy a Shared VPC host project spanning multiple regions and use firewall rules to restrict which regions instances can reach, keeping all data logically within one network.
B.Store all data in a multi-region Cloud Storage bucket and rely on customer-managed encryption keys to satisfy residency, aggregating data in the central project.
C.Use a global BigQuery dataset with column-level security and authorized views, then copy personal data into the central analytics project for processing.
D.Store personal data in regional Cloud Storage buckets and BigQuery datasets located only in the required country, and use VPC Service Controls perimeters to prevent data egress, while aggregating anonymized metrics into the central analytics project.
AnswerD

This design keeps personal data in regionally scoped resources within the mandated country, uses VPC Service Controls to block egress of that data across perimeter boundaries, and only moves aggregated, anonymized metrics to the centralized project. It directly satisfies the residency rule while still enabling centralized reporting on non-personal data.

Why this answer

Data residency is about where bytes are physically stored and replicated, so the architecture must pin personal data to regionally scoped datasets and buckets in the required country and use VPC Service Controls to stop egress. Encryption keys and network topology do not constrain physical location. Only anonymized aggregates may cross into the central analytics project.

Exam trap

The trap here is believing that customer-managed encryption keys or column-level security satisfy data residency, when only the physical location of the stored data and enforced egress controls do.

44
MCQhard

The exhibit shows a command to create a Compute Engine instance. The instance is intended to run a web server that needs to access Cloud Storage buckets using its service account. However, the web server fails to read from a storage bucket. What is the most likely cause?

A.The service account is not attached to the instance
B.The tags http-server and https-server block outbound traffic
C.The boot disk type is SSD, which is not compatible with Cloud Storage
D.The service account lacks IAM permissions to read from Cloud Storage
AnswerD

The instance's attached service account has no IAM role granting storage.objects.get on the bucket, so Cloud Storage returns 403 regardless of network or scope settings. Access scopes only gate the API surface; IAM bindings authorise the actual read, making missing permissions the direct cause of the failure.

Why this answer

The correct answer is D: the service account lacks IAM permissions to read from Cloud Storage. Even when a service account is properly attached to a Compute Engine instance, the instance's applications can only access Cloud Storage buckets if that service account has been granted the appropriate IAM roles (for example, roles/storage.objectViewer) on the bucket or project. The failure to read from the bucket is therefore most likely an authorization issue at the IAM layer rather than a configuration problem with the instance itself.

Option A is not the cause because the scenario states the instance uses its service account, and even a missing attachment would be a different setup issue. Option B is incorrect because firewall tags like http-server and https-server govern inbound HTTP/HTTPS traffic, not outbound access to the Cloud Storage API. Option C is incorrect because the boot disk type (SSD vs. standard) has no bearing on Cloud Storage access.

45
MCQeasy

A media company stores millions of video master files in a Cloud Storage bucket in the us-central1 region. Files are written once, accessed frequently for the first 30 days during editing and publishing, and then almost never accessed again, though they must remain retrievable for seven years. The company wants to minimize storage cost without changing the objects' names or the way applications read them. Which approach should the architect recommend?

A.Configure an Object Lifecycle Management rule on the bucket that transitions objects to Nearline Storage after 30 days and to Coldline Storage after 365 days
B.Create a second bucket with the Coldline storage class and rewrite each object into it after 30 days using a scheduled job
C.Set the bucket's default storage class to Archive and enable Autoclass so objects are promoted on access
D.Keep objects in Standard storage and enable Turbo Replication to improve read performance across regions
AnswerA

Object Lifecycle Management changes the storage class of existing objects in place, so object names and read paths stay identical. Transitioning to Nearline after the editing window and to Coldline later matches the access pattern and lowers cost. This meets the seven-year retention requirement while minimizing spend during the long low-access period.

Why this answer

The access pattern is predictable: hot for 30 days, then cold for years. Object Lifecycle Management transitions objects between storage classes in place, so applications keep reading the same object names while the per-gigabyte cost drops as access frequency falls. Approaches that move objects to another bucket or change the default class either break read paths or fail to reclassify existing data.

Exam trap

The trap here is choosing to move objects into a cheaper bucket instead of transitioning their storage class in place.

46
Multi-Selectmedium

A multinational enterprise is designing its Google Cloud resource hierarchy. They want to enforce centrally managed policies, delegate administration to regional business units, and isolate billing. Which two design choices should the architects make? (Choose two.)

Select 2 answers
A.Create folders per business unit under the organization node and apply organization policies at the appropriate folder level.
B.Create a single project for all business units and use labels to separate their resources.
C.Use a single Shared VPC in the organization host project for all business units without folders.
D.Assign each business unit its own Cloud Billing account and link their projects to that account.
E.Grant every business unit administrator the Organization Administrator role so they can manage their own projects.
AnswersA, D

Folders let you group projects by business unit and apply organization policies and IAM inheritance at the folder level, so central teams enforce guardrails while regional units manage their own projects beneath. This cleanly supports delegated administration and centralized policy control, matching the stated governance goals.

Why this answer

Folders under the organization node enable policy inheritance and delegated administration, letting central teams set guardrails while business units own their projects. Separate Cloud Billing accounts per business unit isolate costs and budgets. Labels, over-broad organization roles, and networking alone do not deliver the required policy control and billing separation.

Exam trap

The trap here is assuming labels or a shared network can substitute for folders and separate billing accounts when enforcing governance and cost isolation.

47
MCQhard

A healthcare company is designing a new patient portal on Google Cloud. Regulatory requirements mandate that all data at rest be encrypted with keys the company controls and can rotate on its own schedule, and that the keys never leave a hardware security module (HSM). The security team also wants to retain the ability to revoke Google's access to the data if the external key becomes unavailable. Which key management design should you recommend?

A.Create a Cloud KMS key ring with HSM protection level and use customer-managed encryption keys (CMEK) for the services.
B.Encrypt data with application-level keys stored in Secret Manager and decrypt in the application before writing to Cloud Storage.
C.Use Google-managed encryption keys (GMEK) with default Cloud KMS encryption for all services.
D.Use Cloud External Key Manager (Cloud EKM) with a supported external key management partner and an HSM-backed external key.
AnswerD

Cloud EKM lets the customer hold key material in an external, partner-hosted HSM while Google Cloud services call out to wrap and unwrap data encryption keys. The customer controls rotation on their own schedule, key material never resides in Google's infrastructure, and disabling or revoking the external key immediately prevents Google from decrypting the data, satisfying the revocation requirement.

Why this answer

Cloud External Key Manager is the only option that keeps key material outside Google Cloud in a partner HSM while still integrating with Google Cloud services for encryption at rest. It supports customer-controlled rotation and, critically, allows the customer to revoke Google's access by disabling the external key. CMEK and GMEK keep key custody inside Google, which does not meet the external control and revocation mandate.

Exam trap

The trap here is treating Cloud KMS CMEK with HSM protection level as equivalent to externally held keys, when the key material still resides in Google Cloud.

48
MCQeasy

A healthcare company is planning to store sensitive patient records in Cloud Storage. They need to ensure that the data is encrypted at rest with keys that they control and can rotate on demand. They also want to maintain an audit trail of key usage. Which Google Cloud service should they use?

A.Cloud HSM with a hardware security module for key storage.
B.Customer-supplied encryption keys (CSEK) stored on-premises.
C.Cloud Key Management Service (Cloud KMS) with customer-managed encryption keys (CMEK).
D.Cloud Storage default encryption with Google-managed keys.
AnswerC

Cloud KMS allows you to create and manage encryption keys, including customer-managed keys. You can rotate these keys on demand and integrate with Cloud Audit Logs to track key usage. This meets the requirements for controlling keys and maintaining an audit trail.

Why this answer

Cloud KMS with customer-managed encryption keys gives the company full control over key creation, rotation, and usage. It integrates with Cloud Audit Logs to record key operations. The other options either do not provide customer control, lack auditability, or are not specific to the requirement.

Exam trap

The trap here is confusing customer-supplied encryption keys with customer-managed keys; the former does not provide audit logs because Google never sees the keys.

49
MCQhard

A healthcare analytics company ingests HL7 messages into Pub/Sub and processes them with a Dataflow streaming pipeline that writes results to BigQuery. During a regional outage, the pipeline stopped and the team discovered that unacknowledged messages were lost after the retention window expired. The company needs a design where a single-region failure does not cause message loss and the pipeline can resume with minimal manual intervention. What should the architect recommend?

A.Increase the Pub/Sub message retention duration to the maximum and add a dead-letter topic so failed messages are preserved for later reprocessing.
B.Replace Pub/Sub with a Cloud Storage bucket in dual-region mode and have Dataflow read new objects with a streaming pipeline triggered by Eventarc notifications.
C.Run the Dataflow pipeline in a single region but enable autoscaling and set the maximum number of workers higher so it drains the backlog faster after an outage.
D.Deploy the Dataflow pipeline as a regional job in two regions with a Pub/Sub subscription in each, and configure the topic to store messages in a second region using message storage policy or a global endpoint.
AnswerD

Pub/Sub already replicates message data within a region, and a message storage policy or global endpoint lets you keep data in additional regions so a topic survives a regional failure. Running the Dataflow job regionally in two locations with a subscription each means one pipeline keeps draining messages while the other region is down, satisfying both durability and low-touch recovery.

Why this answer

The failure mode is losing messages when a single region is unavailable and the retention window closes. Keeping Pub/Sub message data in more than one region through a message storage policy or global endpoint, plus running the Dataflow job regionally in two locations each with its own subscription, gives both durability of the messages and a surviving processing path. Retention tuning, object storage substitution, and autoscaling do not remove the single-region dependency.

Exam trap

The trap here is treating longer retention or a dead-letter topic as disaster recovery, when both remain bound to a single regional topic and cannot survive that region becoming unavailable.

50
MCQhard

A logistics company runs a latency-sensitive order-tracking service on Compute Engine instances spread across three zones in one region. They need the architecture to survive the loss of an entire zone while keeping inter-instance latency low, and they want automatic failover without manual intervention. Which design should the architects implement?

A.Deploy a managed instance group in each of the three zones separately, and place a global external Application Load Balancer in front of all three groups.
B.Deploy a managed instance group with regional distribution across the three zones, front it with a regional external Application Load Balancer, and configure health checks with autoscaling.
C.Deploy standalone Compute Engine instances in each of the three zones with static external IPs and use DNS round-robin to distribute client traffic.
D.Deploy a managed instance group in a single zone, front it with a global external Application Load Balancer, and rely on the load balancer to fail over across regions.
AnswerB

A regional managed instance group spreads instances across zones, so losing one zone leaves capacity in the others. A regional load balancer with health checks automatically stops sending traffic to unhealthy instances and resumes when they recover, delivering unattended failover while keeping traffic within the region for low latency.

Why this answer

Spreading a regional managed instance group across three zones means a zone outage only removes a fraction of capacity, and health-checked load balancing automatically diverts traffic from failed instances and restores it on recovery. This delivers unattended, in-region failover with low latency, unlike single-zone groups, unmanaged instances, or global routing that can add distance.

Exam trap

The trap here is assuming a global load balancer provides zone resilience even when the backend instances all live in a single zone, where there is nothing to fail over to.

51
MCQeasy

A healthcare company needs to run a stateful, containerized electronic medical records application that requires a stable network identity and persistent disk storage per replica. The operations team is already fluent with Kubernetes. Which Google Cloud service should they choose?

A.Cloud Functions
B.Google Kubernetes Engine with a StatefulSet
C.App Engine flexible environment
D.Cloud Run
AnswerB

GKE with a StatefulSet provides stable, unique network identities and stable per-pod persistent storage through PersistentVolumeClaims, which is exactly what a stateful containerized database-style application needs. Since the operations team already knows Kubernetes, GKE offers the right primitives without requiring them to learn a new platform.

Why this answer

Stateful containerized workloads requiring stable identity and persistent storage per replica map directly to Kubernetes StatefulSets, and the team's existing Kubernetes skills make GKE the natural fit. Serverless container and function platforms abstract away the instance, so they cannot provide per-replica persistent disks or stable network identities.

Exam trap

The trap here is treating any container platform as interchangeable, when only an orchestrator exposing StatefulSets provides stable identity and per-pod persistent storage.

52
MCQeasy

A small development team is deploying a stateless containerized API on Google Cloud. They want the simplest possible way to run containers without managing servers or Kubernetes clusters, and they want the service to scale to zero when there is no traffic to minimize cost. The API receives HTTP requests from external clients. Which Google Cloud service should the architect recommend?

A.Cloud Run with a container image deployed from Artifact Registry.
B.Google Kubernetes Engine (GKE) Autopilot with a Horizontal Pod Autoscaler.
C.Compute Engine managed instance groups with an autoscaler and an external HTTP(S) load balancer.
D.App Engine standard environment with a custom runtime.
AnswerA

Cloud Run runs containers in a fully managed serverless environment, scales automatically including to zero when there are no requests, and exposes an HTTPS endpoint for external clients. It requires no cluster or node management. This matches the requirement for simplicity, HTTP ingress, and cost minimization through scale-to-zero.

Why this answer

Cloud Run is a fully managed serverless platform for containers. It accepts container images from Artifact Registry, provides an HTTPS endpoint for external clients, and scales instances automatically, including down to zero when idle. This eliminates server and cluster management and directly addresses the cost-minimization goal.

It is the simplest fit among the options for a stateless containerized HTTP API.

Exam trap

The trap here is equating GKE Autopilot with serverless simplicity, when it still requires Kubernetes constructs and does not scale to zero by default.

53
MCQmedium

An online retailer is deploying a new order-processing system on Google Cloud. The system consists of a regional managed instance group (MIG) of Compute Engine VMs that read from and write to a Cloud SQL for MySQL instance. The database must tolerate the loss of an entire zone within the region with minimal downtime and no manual failover steps, while keeping costs predictable. Which Cloud SQL configuration should the architect recommend?

A.A Cloud SQL read replica in a second region that the application promotes to primary during an outage.
B.A zonal Cloud SQL instance with automated backups and binary logging enabled, restored manually during an outage.
C.A Cloud SQL instance with a larger machine type and increased storage to improve throughput and resilience.
D.A Cloud SQL instance configured with high availability (regional) and a standby instance in a second zone.
AnswerD

Cloud SQL high availability provisions a standby instance in a different zone and synchronously replicates to it. If the primary zone fails, Cloud SQL automatically promotes the standby, so the application reconnects with minimal downtime and no manual steps. This directly satisfies the zone-failure tolerance and predictable cost of a single regional instance pair.

Why this answer

Zone-level resilience for Cloud SQL comes from high availability mode, which maintains a standby in a separate zone and performs automatic failover without operator intervention. Read replicas address regional disasters and require manual promotion, while zonal deployments and vertical scaling leave the database exposed to a single-zone failure. The regional HA configuration matches the availability and operational requirements at a predictable cost.

Exam trap

The trap here is assuming that automated backups or a cross-region read replica provide automatic zone failover, when only Cloud SQL high availability does.

54
MCQhard

A media company stores millions of small image files in a Cloud Storage bucket in the us-central1 region. Users in Europe and Asia report slow image load times. The company wants to improve read latency globally while keeping write operations in us-central1 for cost and simplicity. Which storage configuration should you recommend?

A.Change the bucket to a multi-region location such as US and enable Turbo Replication.
B.Keep the regional bucket in us-central1 and enable Cloud CDN on an external Application Load Balancer serving the images.
C.Move the images to a bucket in the asia-southeast1 region and use a global external Application Load Balancer to route users.
D.Recreate the bucket as a dual-region bucket with us-central1 and europe-west1, then serve images directly from the bucket.
AnswerB

Cloud CDN caches the images at Google's global edge locations, so users in Europe and Asia retrieve them from a nearby point of presence instead of crossing the ocean to us-central1. Writes continue to go to the regional bucket, preserving the simple write model. This directly addresses global read latency without changing the bucket location.

Why this answer

Cloud CDN caches content at Google's globally distributed edge points of presence, so readers in Europe and Asia are served from nearby locations while the authoritative data stays in the us-central1 regional bucket. Writes remain simple and centralized. Changing the bucket to a multi-region or dual-region location does not cover all three continents, and moving the origin to Asia violates the write-location requirement.

Exam trap

The trap here is assuming that changing the bucket's location or enabling replication automatically speeds up global reads, when edge caching through Cloud CDN is what actually reduces read latency.

55
MCQeasy

A company wants to restrict access to a Cloud Storage bucket so that only a specific service account can read objects. The bucket contains sensitive data. Which identity and access management (IAM) approach should the architect use?

A.Grant the service account roles/iam.serviceAccountUser on the bucket.
B.Use a signed URL to allow access for the service account.
C.Grant the service account roles/storage.admin on the bucket.
D.Grant the service account roles/storage.objectViewer on the bucket and remove all other bindings.
AnswerD

Granting `roles/storage.objectViewer` at bucket level binds the service account directly to the resource, satisfying the least-privilege constraint. Removing every other binding ensures no principal inherits access via project-level or inherited roles, so only that service account can read objects. This is the precise mechanism for restricting a sensitive bucket to a single identity.

Why this answer

The principle of least privilege dictates that the service account should be granted only the minimal permissions required to read objects, which is roles/storage.objectViewer. By removing all other bindings, the bucket becomes accessible exclusively to that service account, ensuring that no other identities (users, groups, or other service accounts) can read the sensitive data. This approach directly enforces the requirement using IAM roles on the bucket resource.

Exam trap

Google Cloud often tests the misconception that granting a broad role like roles/storage.admin is acceptable for simplicity, but the trap here is that candidates overlook the principle of least privilege and the specific read-only requirement, leading them to choose an overly permissive role.

How to eliminate wrong answers

Option A is wrong because roles/iam.serviceAccountUser grants permission to impersonate the service account (e.g., to run jobs as that account), not to read objects from a Cloud Storage bucket; it does not provide any storage access. Option B is wrong because signed URLs are used to grant temporary access to specific objects for any user (including non-Google accounts) via a cryptographic signature, not to restrict access to a specific service account; they are not an IAM-based access control mechanism. Option C is wrong because roles/storage.admin grants full control over the bucket, including the ability to delete objects and modify bucket metadata, which violates the principle of least privilege and exceeds the read-only requirement.

56
Multi-Selecthard

A multinational manufacturer is planning its first Google Cloud landing zone. The security team requires that no data be stored outside approved European regions, that all workloads authenticate using short-lived credentials tied to their Google identities, and that network egress to the public internet be centrally inspected and logged. The platform team wants to minimize per-project configuration. Which two design elements should the architect include in the landing zone? (Choose two.)

Select 2 answers
A.Enable Cloud Armor on each project's load balancers and rely on its logging for internet egress visibility.
B.Deploy a centralized Shared VPC host project with a firewall policy and Cloud NAT in a spoke architecture, routing egress through a central inspection project.
C.Apply the constraints/gcp.resourceLocations organization policy at the organization node with an allow list of approved European regions.
D.Configure Cloud Identity-Aware Proxy on every project and require users to authenticate with long-lived service account keys.
E.Grant the Editor role to all developers at the organization node so they can create resources without per-project IAM changes.
AnswersB, C

Shared VPC centralizes network administration in a host project, and combining hierarchical firewall policies with a central inspection project lets the platform team enforce and log egress once rather than per project. This satisfies the centralized inspection requirement while reducing per-project configuration.

Why this answer

The landing zone needs organization-level enforcement that propagates automatically. A resource location organization policy at the root keeps data in approved European regions, and a Shared VPC host project with hierarchical firewall policies and a central inspection project centralizes and logs egress. Together these meet the security requirements while minimizing per-project work.

Exam trap

The trap here is satisfying the security goals with per-project controls such as Cloud Armor or IAP, which do not scale to a landing zone and miss the centralized enforcement the requirements imply.

57
Multi-Selecthard

A financial services firm is designing the network for a new payment processing platform on Google Cloud. Regulatory rules require that no workload can reach the public internet, that all egress to an on-premises fraud-detection system stay off the public internet, and that Google APIs such as Cloud Storage and BigQuery remain reachable without exposing the workloads. The platform runs on Compute Engine VMs in a single VPC. Which two design elements must the architect include? (Choose two.)

Select 2 answers
A.Configure a Cloud NAT gateway with a manual IP address allocation on the VPC so the VMs can reach the fraud-detection system.
B.Deploy a Squid proxy on a VM with an external IP and route all VPC egress through it using a custom route with the proxy as the next hop.
C.Assign ephemeral external IP addresses to the VMs and protect them with a firewall rule that allows only the fraud-detection system's source range.
D.Create the subnet with the --enable-private-ip-google-access option so the VMs can reach Google APIs and services without external IP addresses.
E.Establish a Cloud VPN tunnel or Cloud Interconnect attachment from the VPC to the on-premises network, with routes exchanged over Cloud Router using BGP.
AnswersD, E

Private Google Access lets a VM with only an internal IP address reach the external IP addresses of Google APIs and services. Because the traffic stays on Google's network rather than traversing the internet, it satisfies the requirement to keep Google APIs reachable without giving the workloads public addresses. Without it, a VM lacking an external IP cannot resolve or route to those APIs.

Why this answer

Two independent constraints must be satisfied: Google APIs stay reachable while workloads have no public addresses, and on-premises traffic stays off the internet. Private Google Access on the subnet handles the first by routing API traffic internally, and a Cloud VPN or Interconnect link with Cloud Router BGP handles the second by providing private connectivity to the fraud-detection system. Cloud NAT, external IPs, and proxy VMs all push traffic onto the public internet.

Exam trap

The trap here is reaching for Cloud NAT as the default answer for private workloads, when NAT provides internet egress and does nothing for private on-premises connectivity or Google API access.

58
MCQeasy

A company is migrating a legacy monolithic application to Google Cloud. The application currently runs on a single on-premises server and uses a local MySQL database. The company wants to minimize changes to the application code while improving scalability and reliability. Which migration strategy should the architect recommend?

A.Refactor the application into microservices and deploy on Google Kubernetes Engine.
B.Rehost the application on Compute Engine and use Cloud SQL for MySQL as the database.
C.Containerize the application with Docker and run it on Cloud Run.
D.Migrate the database to Firestore and rewrite the application to use Firestore APIs.
AnswerB

Rehosting on Compute Engine with Cloud SQL for MySQL lifts and shifts the application with minimal code change, satisfying the minimise-changes constraint. Cloud SQL adds managed backups and high availability, improving reliability and scalability over the single on-premises server.

Why this answer

Rehosting (lift-and-shift) the monolithic application to Compute Engine with Cloud SQL for MySQL minimizes code changes while improving scalability and reliability. Cloud SQL provides managed MySQL with automated backups, replication, and failover, addressing the need for reliability without requiring application refactoring.

Exam trap

The trap here is that candidates often over-engineer the solution by choosing containerization or microservices, forgetting that the primary constraint is minimizing code changes, not modernizing the architecture.

How to eliminate wrong answers

Option A is wrong because refactoring into microservices and deploying on GKE introduces significant code changes and complexity, contradicting the requirement to minimize changes. Option C is wrong because containerizing with Docker and running on Cloud Run requires the application to be stateless and HTTP-driven, which a legacy monolithic app with a local MySQL database typically is not; Cloud Run also does not support stateful workloads or persistent MySQL connections natively. Option D is wrong because migrating to Firestore and rewriting the application to use Firestore APIs requires substantial code changes and a shift from SQL to NoSQL, violating the minimize-changes constraint.

59
MCQmedium

A company is migrating an on-premises PostgreSQL database to Cloud SQL with minimal downtime. The database is 1 TB and the network link has 500 Mbps bandwidth. Which migration approach is most appropriate?

A.Set up a Compute Engine instance with PostgreSQL replication and switch over.
B.Use BigQuery Data Transfer Service to replicate data.
C.Export the database as a SQL dump, transfer it to Cloud Storage, and import into Cloud SQL.
D.Use Database Migration Service to perform continuous replication and then promote Cloud SQL.
AnswerD

Database Migration Service performs continuous replication from the on-premises PostgreSQL instance to Cloud SQL, keeping changes synchronised over the 500 Mbps link. Promoting Cloud SQL after replication catches up minimises downtime, unlike a one-off dump and load of 1 TB.

Why this answer

Database Migration Service (DMS) supports continuous replication from on-premises PostgreSQL to Cloud SQL using native PostgreSQL logical replication (pglogical or native publication/slot). This allows near-zero downtime by keeping the target in sync until promotion, which is ideal for a 1 TB database over a 500 Mbps link where a full dump/restore would take hours.

Exam trap

Google Cloud often tests the misconception that a simple dump-and-import (Option C) is acceptable for large databases, but the trap here is ignoring the 'minimal downtime' requirement, which demands a continuous replication solution like DMS rather than a batch export/import.

How to eliminate wrong answers

Option A is wrong because setting up a Compute Engine instance with PostgreSQL replication requires manual configuration of replication slots, failover scripts, and does not integrate with Cloud SQL's managed service, adding operational overhead and risk. Option B is wrong because BigQuery Data Transfer Service is designed for loading data into BigQuery, not for replicating PostgreSQL databases to Cloud SQL; it cannot perform continuous replication or handle transactional consistency. Option C is wrong because exporting a 1 TB database as a SQL dump and transferring it over a 500 Mbps link would take approximately 4.5 hours (1 TB * 8 / 500 Mbps) plus import time, causing significant downtime, and it does not support continuous replication for minimal downtime.

60
MCQhard

An IoT company ingests telemetry from 40,000 devices spread across three continents. The architecture team wants a single logical endpoint that automatically routes each device's writes to the nearest healthy Google Cloud region, and they want to avoid managing per-region DNS records or load-balancer IPs. Which design should the architect choose?

A.A global external Application Load Balancer with a single anycast IP fronting regional backends
B.Cloud Interconnect attachments from each continent into a single regional VPC with a regional internal passthrough Network Load Balancer
C.Cloud DNS with a geolocation routing policy pointing to regional external passthrough Network Load Balancer IPs
D.A global external proxy Network Load Balancer with a single anycast IP and a TCP proxy target proxy
AnswerD

A global external proxy Network Load Balancer exposes one anycast IP and terminates TCP or SSL sessions at the Google edge, then routes to the closest healthy backend service. It supports arbitrary TCP ports, including MQTT over TLS on 8883, and health-checks backends across regions, giving the single logical endpoint with automatic nearest-region routing the team wants.

Why this answer

The requirement is one logical anycast endpoint that terminates arbitrary TCP and picks the nearest healthy region. A global external proxy Network Load Balancer does exactly that, with SSL or TCP proxy target proxies and health-checked regional backends. Application Load Balancers are HTTP(S)-only, DNS geolocation needs per-region records, and Interconnect plus an internal passthrough load balancer cannot accept public device traffic.

Exam trap

The trap here is confusing the global external Application Load Balancer, which is HTTP(S)-only, with the global external proxy Network Load Balancer that handles arbitrary TCP.

61
Multi-Selectmedium

A logistics company is planning a new order-tracking platform on Google Cloud. The platform must handle sudden, unpredictable spikes from holiday promotions, keep costs low during idle periods, and provide a relational store that scales reads without the team managing replication. The architect is choosing between fully managed services and self-managed alternatives. Which two design choices meet these requirements? (Choose two.)

Select 2 answers
A.Use Cloud Spanner with a regional instance configuration, which scales reads and writes horizontally and replicates automatically.
B.Deploy the API tier on a Compute Engine managed instance group with a fixed size sized for peak holiday traffic.
C.Run PostgreSQL on Compute Engine with streaming replication to a standby VM, and use a load balancer to split reads.
D.Use Cloud SQL for PostgreSQL with read replicas, and have the team script replica promotion for failover.
E.Run the API tier on Cloud Run, which scales to zero when idle and scales out automatically under load.
AnswersA, E

Cloud Spanner is a fully managed, horizontally scalable relational database that handles read and write scaling automatically through its regional configuration and synchronous replication. It provides strong consistency and requires no replica management or promotion scripts, satisfying the relational store requirement that scales reads without operational replication work.

Why this answer

Cloud Run scales to zero and then out automatically, which matches unpredictable promotional spikes while keeping idle cost near zero. Cloud Spanner provides a managed relational store that scales reads and writes horizontally with automatic replication, so the team never manages replicas or failover. Together they cover the compute and data tiers without the operational overhead of self-managed alternatives.

Exam trap

The trap here is reading fully managed as merely hosted, when services like Cloud SQL with read replicas still require the team to size, monitor, and promote replicas.

62
MCQhard

A healthcare company is designing a new patient-records API on Google Cloud. The API must serve read-heavy traffic globally with low latency, tolerate the failure of an entire region, and keep operational overhead low. The data is stored in Cloud Spanner. Which design should the architect recommend?

A.Deploy a regional Cloud Spanner instance and run the API on Compute Engine managed instance groups in two zones behind a regional external Application Load Balancer.
B.Deploy a multi-region Cloud Spanner instance and use Cloud DNS with a geoproximity routing policy that resolves clients to a regional external Application Load Balancer in the closest region.
C.Deploy a multi-region Cloud Spanner instance and run the API on a global external Application Load Balancer with serverless NEGs pointing to Cloud Run services in multiple regions.
D.Deploy a multi-region Cloud Spanner instance and run the API on Compute Engine VMs in two regions, using a global external proxy Network Load Balancer with a single global backend service.
AnswerC

A multi-region Cloud Spanner instance replicates data across regions with strong consistency and automatic failover, while a global external Application Load Balancer routes users to the nearest healthy Cloud Run backend. This combination delivers low-latency global reads, regional failure tolerance, and minimal operational burden because both services are managed. It directly satisfies all three stated requirements.

Why this answer

Global external Application Load Balancers route HTTP traffic to the nearest healthy backend across regions and support serverless NEGs for Cloud Run, while multi-region Cloud Spanner provides strongly consistent, automatically replicated data with regional failover. Together they meet the global latency, regional resilience, and low-overhead goals. Regional load balancers, proxy network load balancers, and DNS-based routing each fall short on at least one requirement.

Exam trap

The trap here is treating a regional load balancer with multi-zone backends as sufficient for regional failure tolerance, when only a global load balancer plus multi-region data layer survives a full region outage.

63
MCQmedium

A company is migrating on-premises workloads to Google Cloud. They have a critical application that requires consistent low-latency access to a database, with read replicas in multiple regions for disaster recovery. The application is expected to grow by 10x over the next year. Which database service and configuration should the architect choose to meet these requirements?

A.Use Cloud Bigtable with multi-region replication
B.Use Cloud SQL for PostgreSQL with cross-region read replicas
C.Use Cloud Spanner with multi-region configuration
D.Use Firestore in native mode with multi-region location
AnswerC

Cloud Spanner's multi-region configuration synchronously replicates data across regions using TrueTime, delivering strong consistency with low read latency and automatic failover for disaster recovery. Its horizontally scalable architecture handles 10x growth without manual sharding, satisfying the stem's combined demands for consistent low latency, multi-region replicas and elastic scale.

Why this answer

Cloud Spanner with a multi-region configuration is the correct choice because it provides strong global consistency, low-latency reads and writes across regions, and automatic horizontal scaling to handle a 10x growth in workload. Its multi-region replication ensures synchronous replication for disaster recovery while maintaining ACID transactions, which is critical for a database requiring consistent low-latency access.

Exam trap

The trap here is that candidates often confuse Cloud Spanner's multi-region capabilities with simpler replication options like Cloud SQL read replicas or Bigtable's eventual consistency, failing to recognize that only Spanner provides strong global consistency and horizontal scaling for transactional workloads.

How to eliminate wrong answers

Option A is wrong because Cloud Bigtable is a NoSQL wide-column database designed for high-throughput analytical workloads, not for transactional applications requiring strong consistency and low-latency access to a single database; its multi-region replication is asynchronous and does not guarantee strong consistency. Option B is wrong because Cloud SQL for PostgreSQL supports cross-region read replicas, but the primary database is single-region and cannot scale horizontally to handle a 10x growth; read replicas are asynchronous and do not provide strong consistency for writes, making it unsuitable for a critical application requiring consistent low-latency access. Option D is wrong because Firestore in native mode is a NoSQL document database with eventual consistency by default (unless using transactions) and does not support the strong global consistency and horizontal scaling needed for a relational database workload with 10x growth; its multi-region location provides replication but not the ACID transactional guarantees required.

64
Multi-Selectmedium

A healthcare analytics company must build a data platform on Google Cloud that stores patient records subject to strict privacy rules. The design must ensure that analysts can query aggregated data without being able to read individual patient identifiers, and that all access to the raw records is logged for audit. Which two design choices should the architect include? (Choose two.)

Select 2 answers
A.Use Sensitive Data Protection (Cloud DLP) to de-identify or tokenize patient identifiers before loading records into the analytics dataset.
B.Store raw records in a Cloud Storage bucket with uniform bucket-level access and rely on object versioning for protection.
C.Encrypt the raw records with customer-managed encryption keys in Cloud KMS and rotate the keys every 90 days.
D.Enable Cloud Audit Logs Data Access logging on the services that store or serve the raw patient records.
E.Grant all analysts the BigQuery Data Viewer role at the project level so they can explore datasets efficiently.
AnswersA, D

Sensitive Data Protection can detect and transform identifiable fields such as names and medical record numbers, producing de-identified or tokenized output that analysts can query without seeing raw identifiers. This directly satisfies the requirement that aggregated analysis be possible while individual identifiers remain unreadable, and it can be applied during ingestion so the analytics layer never holds the original values.

Why this answer

The two goals are preventing analysts from reading identifiers and logging all access to raw records. De-identifying or tokenizing identifiers before the analytics layer sees them meets the first goal, and enabling Data Access audit logs on the services holding raw records meets the second. Broad viewer grants, generic storage protections, and encryption alone do not de-identify data or provide the necessary read-level audit trail.

Exam trap

The trap here is believing encryption at rest hides data from authorized users, when keys and IAM still allow plaintext reads.

65
MCQmedium

A startup is developing a real-time analytics dashboard that ingests data from IoT devices. The data volume is unpredictable but can spike to millions of events per second. The dashboard must display near real-time aggregations with sub-second latency. Which Google Cloud architecture should the architect recommend?

A.Ingest via Cloud IoT Core directly to Cloud Bigtable, then query with BigQuery.
B.Ingest via Cloud Pub/Sub, process with Cloud Dataproc, store in Cloud Storage, and query with BigQuery.
C.Ingest via Cloud Pub/Sub, store raw data in Cloud Storage, and use Cloud SQL for aggregations.
D.Ingest via Cloud Pub/Sub, process with Cloud Dataflow, store in Cloud Bigtable, and query from the dashboard.
AnswerD

Cloud Pub/Sub absorbs unpredictable spikes to millions of events per second without backpressure, while Dataflow provides streaming windowed aggregations. Bigtable's row-key design delivers the low-latency point and range reads the dashboard needs, satisfying the sub-second latency constraint that batch warehouses such as BigQuery cannot meet for continuous refreshes.

Why this answer

Cloud Pub/Sub provides scalable, asynchronous ingestion for unpredictable IoT data spikes, Cloud Dataflow enables stream processing for near real-time aggregations with sub-second latency, and Cloud Bigtable offers low-latency, high-throughput storage ideal for serving aggregated results directly to a dashboard. This combination meets the requirements of unpredictable volume, real-time processing, and low-latency queries.

Exam trap

The trap here is that candidates often choose batch-oriented services like BigQuery or Dataproc for real-time requirements, overlooking that Cloud Dataflow's stream processing and Cloud Bigtable's low-latency storage are specifically designed for sub-second, high-throughput dashboard use cases.

How to eliminate wrong answers

Option A is wrong because Cloud IoT Core directly to Cloud Bigtable lacks a buffering layer for unpredictable spikes, and BigQuery is not designed for sub-second query latency on real-time dashboards. Option B is wrong because Cloud Dataproc is batch-oriented and introduces higher latency for stream processing, and Cloud Storage with BigQuery adds significant query latency unsuitable for sub-second dashboard responses. Option C is wrong because Cloud SQL cannot handle millions of events per second for real-time aggregations and lacks native stream processing capabilities.

66
MCQhard

An enterprise is migrating a latency-sensitive trading application from an on-premises data centre to Google Cloud. The application's components exchange hundreds of thousands of small messages per second and require sub-millisecond inter-process communication. The architect must choose a compute and networking design. What should the architect recommend?

A.Deploy the components on GKE Autopilot pods spread across three zones with a PodDisruptionBudget and topology spread constraints.
B.Deploy the components on Cloud Run services in the same region and connect them through a Serverless VPC Access connector to a shared VPC.
C.Deploy the components on Compute Engine VMs in the same zone with compact placement, and enable high-priority network traffic using the `--network-performance-configs` total-egress-bandwidth-tier setting.
D.Deploy the components on Compute Engine VMs in different zones of the same region and connect them with a global VPC using external IP addresses for direct communication.
AnswerC

Compact placement policies pack instances onto the same rack and physical network segment, which minimizes network hops between them and supports the low-latency, high-message-rate requirement. Setting the total egress bandwidth tier to the higher tier raises the VM network throughput ceiling so the small-message flood is not throttled. Keeping everything in one zone eliminates inter-zone round trips, making this the appropriate design for tightly coupled latency-sensitive components.

Why this answer

Ultra-low latency between tightly coupled components depends on physical proximity and adequate network throughput. Compact placement policies schedule instances close together on the same rack, reducing switch hops and jitter, while the higher total egress bandwidth tier removes the default throughput cap that would otherwise throttle a heavy small-message workload. Keeping all components in a single zone avoids inter-zone round trips entirely, which is essential for the stated sub-millisecond requirement.

Exam trap

The trap here is optimizing for availability with multi-zone spread when the workload's dominant constraint is deterministic, sub-millisecond latency between components.

67
MCQmedium

A healthcare analytics company ingests continuous streams of device telemetry that must be processed in near real time, enriched with reference data from a Cloud SQL for MySQL instance, and written into BigQuery for analyst queries. The team wants minimal operational overhead and wants to use managed Google Cloud services. Which combination should the architect select?

A.Cloud Tasks for ingestion, Cloud Functions for processing, Cloud SQL for storage and analytics
B.Pub/Sub for ingestion, Dataflow for stream processing and enrichment, BigQuery for storage and analytics
C.Pub/Sub for ingestion, Dataproc with Spark Streaming for processing, Cloud Storage for storage and analytics
D.Pub/Sub for ingestion, Dataflow for stream processing, Bigtable for storage and analytics
AnswerB

Pub/Sub durably buffers the telemetry stream and decouples producers from consumers. Dataflow provides managed, autoscaling stream processing with exactly-once semantics and can join against Cloud SQL reference data. BigQuery ingests the processed records and serves analyst queries at scale. This pipeline is fully managed, matching the low operational overhead goal and the near real-time requirement.

Why this answer

The pipeline needs durable stream ingestion, managed stream processing with enrichment, and a warehouse for analyst SQL. Pub/Sub absorbs bursts and decouples producers, Dataflow handles autoscaling stream transforms and joins, and BigQuery stores and queries the results. Alternatives either require cluster management, cannot run analytics at scale, or use services not intended for continuous streaming.

Exam trap

The trap here is pairing a correct streaming ingestion service with a storage service that cannot serve analytical SQL queries.

68
MCQeasy

A company is migrating to Google Cloud and needs to connect their on-premises network to a VPC. They require high bandwidth and a reliable connection with a Service Level Agreement (SLA). Which solution should they choose?

A.Cloud VPN with dynamic routing
B.Dedicated Interconnect
C.Partner Interconnect via a service provider
D.Direct Peering
AnswerB

Dedicated Interconnect offers high bandwidth and an SLA.

Why this answer

Dedicated Interconnect provides a direct, private physical connection between your on-premises network and Google's network, offering high bandwidth (10 or 100 Gbps per link) and a 99.99% uptime SLA when configured with redundant links. This meets the requirements for high bandwidth and a reliable, SLA-backed connection better than any other option.

Exam trap

The trap here is that candidates often confuse Partner Interconnect with Dedicated Interconnect, assuming any 'Interconnect' offers an SLA, but only Dedicated Interconnect provides a direct physical link with a 99.99% SLA, while Partner Interconnect's SLA depends on the partner's network and is typically lower.

How to eliminate wrong answers

Option A is wrong because Cloud VPN uses the public internet with IPsec tunnels, offering no SLA and limited bandwidth (typically up to 3 Gbps per tunnel), making it unsuitable for high-bandwidth, SLA-backed requirements. Option C is wrong because Partner Interconnect relies on a third-party service provider's network, which may introduce additional latency and does not provide the same direct, dedicated SLA as Dedicated Interconnect; it is designed for cases where a direct physical connection is not feasible. Option D is wrong because Direct Peering is a non-SLA, best-effort connection established via public exchange points, intended for traffic exchange with Google services, not for dedicated, SLA-backed connectivity to a VPC.

69
MCQmedium

The exhibit shows a Cloud Storage bucket IAM policy. A developer (admin@example.com) wants to upload a file to the bucket but gets a permission denied error. What is the most likely reason?

A.An organization policy denies all write operations
B.The developer is not a member of the project
C.The service account my-sa overrides the developer's permissions
D.The developer is assigned only the objectViewer role
AnswerD

The objectViewer role grants read-only access to objects, so it cannot authorise uploads. Uploading requires storage.objects.create, which objectViewer excludes. The permission denied error therefore stems from the developer lacking a write-capable role such as objectCreator or objectAdmin, matching the stem's upload constraint.

Why this answer

The correct answer is D: the developer is assigned only the objectViewer role. The objectViewer role (roles/storage.objectViewer) grants read-only access to objects, including listing and downloading, but it does not include storage.objects.create, so any upload attempt will fail with a permission denied error. Options A and B are unlikely because an organization policy denying all writes or project non-membership would typically produce broader failures or different errors, and there is no evidence in the scenario.

Option C is incorrect because IAM permissions are additive; a service account's permissions do not override or reduce a user's granted roles, so my-sa cannot strip the developer's access.

70
Multi-Selecthard

A company is planning a hybrid cloud architecture using Anthos to manage workloads across on-premises data centers and Google Cloud. They need to select two key components that enable consistent configuration, policy, and security across environments. Which two should they choose?

Select 2 answers
A.Cloud Interconnect
B.GKE on-prem
C.Cloud Build
D.Config Sync
E.Cloud Load Balancing
AnswersB, D

GKE on-prem extends the Anthos control plane to on-premises data centres, running Kubernetes clusters under the same configuration and policy management as Google Cloud. This directly satisfies the stem's requirement for consistent configuration, policy and security across both environments, since clusters register with Anthos and inherit its governance.

Why this answer

GKE on-prem (B) is correct because it extends the Google Kubernetes Engine control plane to on-premises data centers, letting the company run the same Kubernetes-based workload platform in both environments so configuration and security policies can be applied consistently. Config Sync (D) is correct because it continuously reconciles cluster configuration and policy from a central source of truth (typically a Git repository) across both on-prem and Google Cloud clusters, which is exactly what Anthos uses to enforce consistent configuration, policy, and security at scale. Cloud Interconnect (A) only provides private, high-bandwidth network connectivity between on-premises and Google Cloud and does not manage configuration or policy.

Cloud Build (C) is a CI/CD service for building and deploying artifacts, not a mechanism for enforcing cross-environment configuration or policy. Cloud Load Balancing (E) distributes traffic to backends and provides no configuration, policy, or security consistency across environments.

Exam trap

The trap here is that candidates often confuse connectivity services (Cloud Interconnect) or traffic management (Cloud Load Balancing) with configuration and policy consistency, failing to recognize that Anthos relies on GitOps-based tools like Config Sync and the on-prem Kubernetes runtime (GKE on-prem) to achieve unified management.

71
MCQeasy

Refer to the exhibit. What is the primary benefit of the `--preemptible` flag in this command?

A.Significant cost reduction compared to standard instances.
B.Faster instance startup time due to optimized kernel.
C.Higher availability through automatic restart on failure.
D.Access to specialized hardware like GPUs at no extra cost.
AnswerA

Preemptible instances cost substantially less than standard instances because Compute Engine can reclaim them, so the flag's primary benefit is significant cost reduction. The workload must tolerate interruption, but the flag's purpose is cheaper compute.

Why this answer

The `--preemptible` flag in Google Cloud Platform (GCP) creates preemptible VM instances, which are short-lived, cost-effective instances that can be terminated at any time by GCP. The primary benefit is a significant cost reduction—up to 60-91% lower than standard instances—making them ideal for batch jobs, fault-tolerant workloads, and non-critical tasks. This flag does not affect startup time, availability guarantees, or provide free access to specialized hardware.

Exam trap

Google Cloud often tests the misconception that `--preemptible` provides high availability or automatic restarts, when in reality it sacrifices availability for cost savings, and candidates may confuse it with managed instance groups or autohealing features.

How to eliminate wrong answers

Option B is wrong because the `--preemptible` flag does not optimize the kernel or affect instance startup time; startup time depends on the image and machine type, not the preemptible nature. Option C is wrong because preemptible instances have no automatic restart on failure—they are terminated after 24 hours or when capacity is needed, and they do not offer higher availability; in fact, they have lower availability than standard instances. Option D is wrong because preemptible instances do not provide access to specialized hardware like GPUs at no extra cost; GPUs are still billed separately, and preemptible instances with GPUs are subject to the same preemption risks and cost structure.

72
MCQmedium

Your organization runs a batch analytics platform that ingests data from a Pub/Sub topic into Cloud Storage, then loads it into BigQuery using a Dataflow streaming pipeline. The pipeline must handle sudden bursty traffic during month-end reporting, and you want to minimize operational overhead while ensuring the pipeline scales automatically. Which architectural approach should you choose?

A.Deploy a Compute Engine managed instance group running a custom ingestion script, and configure an autoscaler based on Pub/Sub queue depth.
B.Use a Dataflow streaming pipeline with autoscaling enabled, reading from Pub/Sub and writing to Cloud Storage and BigQuery.
C.Use a Dataproc cluster with autoscaling to run a Spark Streaming job that reads from Pub/Sub and writes to BigQuery.
D.Create a Cloud Function that triggers on each Pub/Sub message and writes directly to BigQuery and Cloud Storage.
AnswerB

Dataflow streaming with autoscaling dynamically adjusts the number of workers based on backlog and CPU utilization, matching bursty Pub/Sub traffic without manual intervention. It natively integrates with Pub/Sub, Cloud Storage, and BigQuery, so you avoid managing infrastructure. This directly satisfies the requirement for automatic scaling and minimal operational overhead for a streaming analytics pipeline.

Why this answer

A Dataflow streaming pipeline with autoscaling is the most suitable choice because it automatically adjusts worker count to handle bursty Pub/Sub traffic, integrates natively with Cloud Storage and BigQuery, and minimizes operational overhead. It provides exactly-once processing and handles backpressure, ensuring reliable and scalable analytics during month-end peaks.

Exam trap

The trap here is assuming that any autoscaling compute service (like managed instance groups or Dataproc) is equally low-overhead, when managed Dataflow specifically abstracts infrastructure and integrates with the data services.

73
MCQmedium

A retail company operates a global e-commerce platform on Google Cloud. Their architects need to choose a load balancing solution that terminates TLS at the edge, provides a single global anycast IP address, and automatically routes users to the closest healthy backend. Which Google Cloud load balancing product should they select?

A.Internal Application Load Balancer (HTTP(S))
B.Regional external Application Load Balancer (HTTP(S))
C.Global external Application Load Balancer (HTTP(S))
D.External passthrough Network Load Balancer
AnswerC

The global external Application Load Balancer uses a single global anycast IP, terminates TLS at Google's edge, and routes traffic to the closest healthy backend using Google's global network. This matches all three requirements: edge TLS termination, one global IP, and proximity-based routing for a worldwide e-commerce audience.

Why this answer

The global external Application Load Balancer is built for internet-facing global services: it provides a single anycast IP, terminates TLS at Google's edge, and uses Google's global network to send each user to the nearest healthy backend. A regional load balancer cannot give one global IP, and layer 4 passthrough options do not terminate TLS or perform HTTP-aware global routing.

Exam trap

The trap here is assuming any Application Load Balancer is global, when in fact regional and internal variants exist that lack the single global anycast IP and edge TLS behavior.

74
MCQhard

A healthcare company is designing a solution to ingest and process millions of patient records daily. The data must be stored in a way that supports SQL queries and also allows for real-time analytics. The company wants to minimize operational overhead and needs a fully managed, petabyte-scale data warehouse. Which Google Cloud service should the solutions architect recommend?

A.Cloud Spanner.
B.Cloud Bigtable.
C.BigQuery.
D.Cloud SQL for PostgreSQL.
AnswerC

BigQuery is a fully managed, petabyte-scale data warehouse that supports ANSI SQL and real-time analytics through streaming inserts. It requires no infrastructure management, aligning with the goal of minimizing operational overhead. It can ingest millions of records daily and scale seamlessly, making it ideal for the healthcare company's requirements.

Why this answer

BigQuery is a serverless, highly scalable data warehouse that supports SQL and real-time analytics. It is fully managed, so the healthcare company can focus on analyzing data rather than managing infrastructure. It handles petabyte-scale datasets and daily ingestion of millions of records without manual scaling, making it the best fit for the requirements.

Exam trap

The trap here is assuming that any managed database with SQL support can serve as a petabyte-scale data warehouse, when BigQuery is specifically designed for that purpose while others are optimized for transactional or NoSQL workloads.

75
MCQmedium

A retail company is deploying a customer-facing API on Google Cloud. The API must survive the loss of an entire region with minimal data loss and must serve users in North America, Europe, and Asia with low latency. The database layer must support strongly consistent reads and writes. Which design should the architect choose for the data tier?

A.Firestore in Datastore mode with a multi-region location and client-side caching of query results.
B.Bigtable with a multi-cluster routing policy and application-level retries for failed writes.
C.Cloud Spanner with a multi-region instance configuration, with application instances reading and writing through regional endpoints.
D.A single Cloud SQL for PostgreSQL instance in us-central1 with cross-region read replicas in europe-west1 and asia-east1.
AnswerC

Cloud Spanner's multi-region configurations replicate synchronously across regions with external consistency, so a region loss does not lose committed data and reads remain strongly consistent. Serving from regional endpoints keeps latency low for users on each continent while the multi-region quorum preserves durability.

Why this answer

Cloud Spanner is the Google Cloud database that provides synchronous multi-region replication with external consistency, so losing a region does not lose committed writes and reads stay strongly consistent. Regional endpoints let each continent's application instances talk to nearby replicas while the multi-region quorum maintains durability and correctness.

Exam trap

The trap here is assuming that cross-region read replicas on a single-primary database provide both regional failover and strongly consistent reads at global scale.

Page 1 of 2 · 106 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design and plan a cloud solution architecture questions.