Courseiva

CCNA Design and plan a cloud solution architecture Questions

31 of 106 questions · Page 2/2 · Design and plan a cloud solution architecture · Answers revealed

76
MCQeasy

A financial services firm is designing a new application on Google Cloud. The application must store sensitive customer data and comply with regulations that require encryption at rest with keys managed by the company. The company also needs to control key rotation and revocation. Which Google Cloud service should the solutions architect use to meet these requirements?

A.Cloud Key Management Service (Cloud KMS) with customer-managed encryption keys (CMEK).
B.Cloud HSM to provide hardware security modules for key storage.
C.Cloud Data Loss Prevention (DLP) to discover and redact sensitive data.
D.Cloud Identity-Aware Proxy (IAP) to enforce access control and encrypt data in transit.
AnswerA

Cloud KMS with CMEK allows the company to create and manage encryption keys, including rotation and revocation, while Google Cloud services use those keys to encrypt data at rest. This provides the required control over keys for compliance. It is the standard service for managing encryption keys in Google Cloud and integrates with many services like Cloud Storage and BigQuery.

Why this answer

Cloud KMS with customer-managed encryption keys gives the company full control over the lifecycle of encryption keys, including rotation and revocation, while integrating with Google Cloud services to encrypt data at rest. This meets the regulatory requirement for company-managed keys. Other services like IAP or DLP address different aspects of security and do not provide key management.

Exam trap

The trap here is confusing access control or data loss prevention services with encryption key management, when only Cloud KMS with CMEK provides the required control over keys.

77
MCQhard

A financial services company is designing a Google Cloud landing zone. Regulators require that production workloads be isolated from non-production workloads, that each business unit control its own billing and quotas, and that a central team enforce network and security policies across everything. The company wants to minimize the number of projects it must manage manually. Which structure should the architect propose?

A.A flat set of projects directly under the organization node, with a distinct service account per project and firewall rules copied into each project's VPC.
B.A folder per business unit, with production and non-production subfolders under each, projects created inside those subfolders, and organization policies plus shared VPC set at the folder level.
C.One project per environment (production, staging, development) under the organization node, with folders used only for IAM groups.
D.Two folders, one for production and one for non-production, with all business unit projects placed in the matching folder and billing separated by project labels.
AnswerB

Folder-per-business-unit with environment subfolders gives each unit its own projects and billing accounts while letting a central team attach organization policies and Shared VPC host configuration at the folder level, so those controls inherit to every current and future project. This is the recommended resource hierarchy pattern and avoids per-project manual policy assignment as the company grows.

Why this answer

The recommended Google Cloud resource hierarchy nests environment subfolders inside business-unit folders, because organization policies, IAM, and Shared VPC settings attached at a folder are inherited by every project beneath it, including projects created later. This satisfies workload isolation, delegated billing and quota ownership per unit, and centralized policy enforcement while keeping manual per-project work to a minimum as the estate grows.

Exam trap

The trap here is treating billing separation as achievable through labels, when a billing account must be linked to a project or be inherited from a parent, and labels are only metadata.

78
Multi-Selectmedium

A healthcare analytics company is designing the Google Cloud landing zone for a new HIPAA-regulated workload. The security team requires that no project in the organization can enable a public Cloud Storage bucket by accident, and that all data-at-rest in BigQuery is encrypted with keys the company rotates on its own schedule. Which two design decisions should the architect include? (Choose two.)

Select 2 answers
A.Create a Cloud KMS keyring in each region where BigQuery datasets reside, and set a default CMEK on each dataset
B.Enable uniform bucket-level access on every bucket through an organization policy constraint
C.Grant the Storage Admin role only to a small group of platform engineers at the organization level
D.Use Google-managed encryption keys for BigQuery and rely on the default rotation performed by Google
E.Apply an organization policy constraint with storage.publicAccessPrevention enforced at the organization node
AnswersA, E

BigQuery datasets accept a default customer-managed encryption key, so every table created in the dataset is encrypted with that key without per-table configuration. Placing keyrings in the same regions as the datasets satisfies data-residency expectations, and the company controls rotation schedule and key destruction through Cloud KMS.

Why this answer

Two controls map directly to the stated requirements. The storage.publicAccessPrevention organization policy is a preventive, inherited guardrail that blocks public bucket grants anywhere in the organization. A default CMEK on each BigQuery dataset, with regional keyrings, gives the company control over the rotation schedule and key lifecycle.

Uniform bucket-level access, Google-managed keys, and narrow role grants do not enforce either requirement.

Exam trap

The trap here is treating uniform bucket-level access as a public-access control, when it only removes object ACLs and still permits allUsers IAM bindings.

79
MCQeasy

A media company wants to serve publicly available images and videos to a global audience with low latency. Which Google Cloud service should they primarily use?

A.Cloud Storage with public bucket serving the files.
B.Cloud CDN with Cloud Storage as the origin.
C.Cloud Run with a container that serves the files.
D.Compute Engine with an HTTP server.
AnswerB

Cloud CDN caches publicly available image and video content at Google's global edge points of presence, so requests are served from locations near each user. Using Cloud Storage as the origin keeps objects durable and cheap, while the CDN layer satisfies the low-latency global delivery constraint.

Why this answer

Cloud CDN with Cloud Storage as the origin is the correct choice because it uses Google's global edge cache to serve publicly available images and videos from Cloud Storage, minimizing latency for a global audience. Cloud CDN caches content at edge locations worldwide, reducing the round-trip time to the origin bucket, while Cloud Storage provides scalable, durable object storage. This combination is purpose-built for delivering static content with low latency and high throughput.

Exam trap

The trap here is that candidates often choose Cloud Storage with a public bucket (Option A) because it seems simplest, overlooking that Cloud CDN is required to achieve global low-latency delivery by caching content at edge locations.

How to eliminate wrong answers

Option A is wrong because a public Cloud Storage bucket serves files directly from the bucket's regional location, which does not provide global edge caching, resulting in higher latency for users far from the bucket's region. Option C is wrong because Cloud Run is a serverless compute platform designed for running containerized applications, not optimized for serving static files at scale; it lacks built-in edge caching and would incur unnecessary compute costs and cold-start latency. Option D is wrong because Compute Engine with an HTTP server requires manual scaling, maintenance, and lacks integrated global caching, making it inefficient and costly for serving static content to a global audience compared to a managed CDN solution.

80
Multi-Selectmedium

A healthcare company is planning a Google Cloud landing zone for a new regulated workload. They must enforce organization-wide guardrails, centralize billing visibility, and give each business unit autonomy over its own projects. The security team needs to apply policies that cannot be overridden by project owners. Which two design choices should you recommend? (Choose two.)

Select 2 answers
A.Enable Cloud Billing export to BigQuery and create a shared log sink to a central project for audit and cost analysis.
B.Place all projects directly under the organization root and rely on project-level IAM to enforce security policies.
C.Create a folder hierarchy under the organization that mirrors business units, and apply organization policies at the folder level.
D.Give each business unit the Organization Administrator role so they can manage their own projects independently.
E.Grant each business unit the Billing Account Administrator role on the shared billing account to give them billing autonomy.
AnswersA, C

Exporting billing data to BigQuery enables centralized cost analysis and chargeback reporting across all business units. A shared log sink to a central project aggregates audit logs for compliance and security monitoring. Together these provide the centralized visibility the company needs while allowing business units to manage their own projects under the folder hierarchy.

Why this answer

A folder hierarchy lets the company apply organization policies that inherit to all descendant projects and cannot be overridden by project owners, satisfying the guardrail requirement. Exporting billing data to BigQuery and centralizing logs provide the centralized billing and audit visibility. Granting broad roles like Billing Account Administrator or Organization Administrator, or flattening the hierarchy, undermines centralized control and least privilege.

Exam trap

The trap here is equating business unit autonomy with granting organization-wide or billing administrator roles, when autonomy should be delegated through folder-scoped IAM and inherited policies.

81
Multi-Selecteasy

Which THREE practices are recommended for organizing projects in a Google Cloud organization?

Select 3 answers
A.Create a separate project to hold organization policies.
B.Use a separate project for each environment (e.g., development, staging, production).
C.Apply IAM policies at the folder level instead of the organization level when possible.
D.Use a shared VPC host project for multiple service projects to centralize network management.
E.Consolidate all production resources into a single project for simplicity.
AnswersB, C, D

Separate projects isolate environments and allow independent management and billing.

Why this answer

Using separate projects for each environment (development, staging, production) enforces resource isolation, prevents accidental cross-environment changes, and allows independent IAM policies, billing, and quotas. This aligns with Google Cloud's recommended resource hierarchy best practices for managing lifecycle and security boundaries.

Exam trap

The trap here is that candidates often confuse the purpose of organization policies with project-level resources, mistakenly thinking a separate project is needed to hold policies, when in fact policies are inherited through the resource hierarchy (organization → folder → project).

82
MCQeasy

A financial services firm is designing a new analytics platform on Google Cloud. Regulatory requirements mandate that data must never be replicated or processed outside the European Union, and the company wants to prevent accidental resource creation in non-EU regions regardless of which engineer is deploying. Which mechanism should the architect use to enforce this constraint?

A.Organization Policy constraints that restrict resource locations to approved EU regions.
B.IAM roles that grant project creators permissions only in EU projects.
C.VPC Service Controls perimeters around each project to block data exfiltration.
D.Cloud Asset Inventory alerts that notify security teams when non-EU resources appear.
AnswerA

Organization Policy constraints such as gcp.resourceLocations let administrators define an allowlist of locations at the organization, folder, or project level. Any attempt to create a resource in a non-approved region is denied centrally, regardless of a user's IAM permissions. This provides the deterministic, organization-wide enforcement the regulator requires and cannot be bypassed by individual engineers.

Why this answer

Organization Policy constraints enforce location restrictions centrally and deny non-compliant resource creation before it happens, independent of user permissions. IAM governs identity, VPC Service Controls govern API access and exfiltration, and Asset Inventory provides detection after the fact. Only the organization policy provides the preventive, organization-wide geographic guarantee the regulation demands.

Exam trap

The trap here is confusing VPC Service Controls, which limit data exfiltration through APIs, with Organization Policy constraints, which actually restrict where resources can be created.

83
MCQmedium

A company is deploying a new microservices application on Google Kubernetes Engine (GKE). They need to ensure that each microservice can be independently scaled and updated without affecting other services. They also want to minimize the blast radius of a failure in one microservice. Which design approach should they use?

A.Deploy all microservices in a single Deployment with multiple containers per pod.
B.Deploy each microservice as a separate pod without a controller, and manage them manually.
C.Use a single StatefulSet for all microservices to maintain persistent identities.
D.Deploy each microservice as a separate Deployment with its own Horizontal Pod Autoscaler and use separate namespaces for isolation.
AnswerD

Separate Deployments allow independent scaling and updates. Each can have its own Horizontal Pod Autoscaler based on its specific metrics. Using separate namespaces provides logical isolation, reducing the blast radius of failures and simplifying resource management. This is a standard GKE design for microservices.

Why this answer

Using separate Deployments for each microservice enables independent scaling and rolling updates. Each Deployment can have its own HPA, and namespaces provide isolation. This design minimizes the impact of a failure in one service and aligns with microservices best practices.

The other options either couple services together or lack automation and resilience.

Exam trap

The trap here is assuming that grouping containers in a single pod or using a StatefulSet simplifies management, when it actually reduces isolation and independent scalability.

84
MCQeasy

A media company is preparing to migrate a batch reporting application to Google Cloud. The application currently runs on physical servers that are used at about 20 percent CPU on average, but it has two short month-end peaks each quarter when utilization reaches 90 percent for about six hours. The company wants to reduce infrastructure cost while guaranteeing the application always has enough capacity during the peaks. What should the architect recommend?

A.Deploy the application on a managed instance group with autoscaling based on CPU utilization, with a minimum size that covers baseline load and a maximum size that covers the peaks.
B.Deploy the application on a managed instance group of Compute Engine VMs sized for the month-end peak, using a committed use discount for the full capacity.
C.Deploy the application to a Google Kubernetes Engine cluster with a single large node pool and enable cluster autoscaler with a minimum node count equal to the peak requirement.
D.Deploy the application to Cloud Run with a minimum instance count set to the number of instances needed at peak and concurrency set to one.
AnswerA

An autoscaling managed instance group adds VMs when CPU rises and removes them when demand falls, so the company pays for baseline capacity most of the time and scales out only during the month-end peaks. Setting the minimum to baseline and the maximum to peak capacity guarantees headroom. This matches the workload's spiky profile directly.

Why this answer

The workload is spiky, with a low average and short, predictable peaks. Horizontal autoscaling on managed instance groups matches that shape: the group grows during the month-end surge and shrinks afterward, so cost tracks actual demand while the maximum size preserves guaranteed headroom. Fixed peak sizing, cluster autoscaler with a peak-sized minimum, and pinned Cloud Run minimum instances all keep peak capacity running continuously.

Exam trap

The trap here is equating a committed use discount or a high autoscaler minimum with cost optimization, when both lock in peak capacity that runs during the long low-utilization periods.

85
MCQeasy

Your company has migrated its legacy web application from a single Compute Engine instance to a managed instance group (MIG) behind an HTTP(S) load balancer. The application was updated to a new version as part of the migration. After the migration, users report intermittent 502 Bad Gateway errors. The application logs show no errors, and the load balancer backend health checks are reported as healthy. On investigation, the developers discover that the new version requires a specific environment variable for authentication to a downstream service. This variable was set manually on the original instance but is missing from the MIG's instance template. The health check endpoint does not depend on this variable and always returns a 200 status even when the variable is absent. As a result, instances created from the template are considered healthy by the load balancer, but when they receive requests that require authentication, they fail and return a 502 error to the client. What is the most likely cause of the 502 errors?

A.The missing environment variable causes authentication failures on new instances.
B.The health check is configured to check the old application path, which no longer exists.
C.The load balancer's backend timeout is too short for the application's response time.
D.The MIG is not scaling out fast enough to handle peak traffic.
AnswerA

The instance template omits the downstream authentication variable, so every MIG instance starts without it. Because the health check endpoint never exercises that authentication path, the load balancer keeps routing traffic to instances that fail downstream calls, producing 502s. Supplying the variable in the template restores authentication.

Why this answer

The 502 errors occur because the new application version requires a specific environment variable for authentication to a downstream service. The health check endpoint does not depend on this variable, so instances are marked healthy even though they cannot authenticate real requests. When the load balancer routes traffic to these instances, the missing variable causes authentication failures, leading to 502 Bad Gateway errors.

Exam trap

The trap here is that candidates assume healthy health checks guarantee the application is fully functional, but Google Cloud tests the nuance that health checks may not cover all dependencies, leading to 'false healthy' instances that fail on real requests.

How to eliminate wrong answers

Option B is wrong because the health check is reported as healthy, indicating it is hitting a valid endpoint (the old path would cause health check failures, not intermittent 502s). Option C is wrong because backend timeout issues would typically cause 504 Gateway Timeout errors, not 502 Bad Gateway errors, and the application logs show no errors. Option D is wrong because scaling issues would cause 503 Service Unavailable errors or increased latency, not 502 errors, and the MIG is not reported as overloaded.

86
MCQmedium

A financial services company runs a payment processing platform on Compute Engine. Compliance requires that all data at rest be encrypted with keys the company controls and that key material never leave their on-premises HSM appliances. They must also minimize operational overhead for key rotation. Which Google Cloud solution should the architect recommend?

A.Default Google-managed encryption at rest with CMEK disabled
B.Customer-supplied encryption keys (CSEK) stored in a local vault
C.Cloud External Key Manager (Cloud EKM) with an external key manager
D.Cloud KMS with CMEK and automatic rotation
AnswerC

Cloud EKM allows Compute Engine disks and other resources to use CMEK whose key material lives in an external key manager, including on-premises HSM-backed systems. Google never sees the key material; it only sends wrap/unwrap requests. This satisfies the requirement that keys remain in the company's HSMs while still integrating with Google Cloud services, and rotation is handled in the external key manager.

Why this answer

The strict requirement is that key material must remain in the company's on-premises HSMs while still protecting Google Cloud resources. Cloud EKM is designed exactly for this: it lets Cloud services use CMEK backed by an external key manager, so Google never holds the key material. CSEK requires manual key handling, Cloud KMS stores keys in Google Cloud, and default encryption gives no customer control.

Exam trap

The trap here is assuming that CMEK via Cloud KMS keeps key material on-premises, when in fact Cloud KMS holds the key material unless Cloud EKM is used.

87
Matchingmedium

Match each GCP security service to its function.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Manage encryption keys

Hardware security module for key protection

Store API keys, passwords, certificates

Manage access control

Centralized security and risk management

Why these pairings

Cloud Armor protects against DDoS and web attacks; IAP controls access based on identity; KMS handles encryption keys; DLP protects sensitive data. Distractors swap these functions.

88
Multi-Selectmedium

A retail company is designing a new microservices architecture on Google Cloud. They want to minimize operational overhead, enable independent deployment of services, and ensure that a failure in one service does not cascade to others. They also want to use managed services where possible. Which two design choices should the architect recommend? (Choose two.)

Select 2 answers
A.Implement asynchronous communication between services using Pub/Sub topics
B.Deploy each microservice as a separate Cloud Run service with its own service account
C.Deploy all microservices into a single Google Kubernetes Engine cluster with a shared namespace
D.Use a single Compute Engine instance running all microservices in Docker containers
E.Use a shared Cloud SQL instance with a single database for all microservices
AnswersA, B

Pub/Sub provides durable, asynchronous messaging that decouples services and absorbs traffic spikes. If a downstream service is unavailable, messages are retained and delivered later, preventing cascading failures. This supports independent deployment and fault isolation because services do not need to be online simultaneously. Using Pub/Sub reduces operational overhead compared to self-managed message brokers, making it a suitable choice for the microservices design.

Why this answer

Cloud Run per microservice with distinct service accounts provides managed scaling, independent deployment, and least-privilege isolation. Pub/Sub enables asynchronous, durable communication that prevents cascading failures and decouples services. Together they meet the goals of minimal operational overhead, independent deployability, and fault isolation.

Shared databases, single VMs, and shared GKE namespaces introduce coupling and operational burden.

Exam trap

The trap here is assuming that a single GKE cluster with namespaces automatically provides fault isolation and minimal operational overhead, when in fact it still requires cluster management and does not isolate failures as cleanly as separate managed services.

89
MCQmedium

A company is designing a hybrid cloud architecture where on-premises applications need to access data stored in a Cloud Storage bucket. The company requires that traffic between on-premises and Google Cloud does not traverse the public internet and must be encrypted. They also need dedicated bandwidth. Which Google Cloud service should the solutions architect use?

A.VPC Network Peering between on-premises and Google Cloud.
B.Cloud CDN with private origin access.
C.Cloud VPN with HA VPN.
D.Cloud Interconnect with Dedicated Interconnect.
AnswerD

Dedicated Interconnect provides a direct physical connection between on-premises and Google Cloud, bypassing the public internet. It offers dedicated bandwidth and supports encryption via MACsec or application-level encryption. This meets all requirements: private connectivity, dedicated bandwidth, and encryption.

Why this answer

Dedicated Interconnect offers a private, dedicated connection between on-premises and Google Cloud, avoiding the public internet and providing consistent bandwidth. It supports encryption through MACsec or higher-layer protocols. This satisfies the requirements for private, encrypted, and dedicated connectivity for accessing Cloud Storage data.

Exam trap

The trap here is confusing Cloud VPN, which uses the public internet, with Cloud Interconnect, which provides a private dedicated connection, and overlooking that Dedicated Interconnect can also support encryption.

90
MCQeasy

A small development team is prototyping a containerized application on Google Cloud. They want the least operational overhead for running containers, automatic scaling based on incoming requests, and the ability to scale to zero when there is no traffic. They do not need Kubernetes APIs or custom networking. Which compute option should the architect recommend?

A.Google Kubernetes Engine Autopilot cluster
B.Cloud Run services with request-based autoscaling
C.Compute Engine managed instance groups with an autoscaler
D.Cloud Functions with a container image as the deployment artifact
AnswerB

Cloud Run runs containers in a fully managed, request-driven environment, scales automatically with incoming requests, and can scale to zero when idle so the team pays nothing during quiet periods. It requires no cluster or node management and no Kubernetes expertise, making it the lowest-overhead fit for this prototype.

Why this answer

Cloud Run is a fully managed serverless platform for containers that scales automatically based on requests and can scale to zero when idle. It removes the need to manage clusters, nodes, or autoscaling policies, which directly addresses the team's desire for minimal operational overhead and cost efficiency during periods without traffic.

Exam trap

The trap here is assuming that serverless containers require Kubernetes, when Cloud Run provides container execution without any cluster management.

91
MCQmedium

A retail company runs a monolithic Java application on Compute Engine instances in a single managed instance group behind an external Application Load Balancer. During a flash sale, the application becomes unresponsive, and the operations team observes that the CPU utilization of all instances reaches 100%. The team wants to ensure that the application remains available during similar events. They need a solution that automatically adjusts capacity based on demand and minimizes manual intervention. Which approach should they take?

A.Increase the size of each Compute Engine instance to a larger machine type to handle the peak load.
B.Set up a Cloud Monitoring alert that notifies the operations team when CPU utilization exceeds 80%, so they can manually add instances.
C.Deploy the application to a Google Kubernetes Engine cluster with a Horizontal Pod Autoscaler based on CPU utilization.
D.Configure an autoscaler on the managed instance group to scale based on CPU utilization with a target of 60%.
AnswerD

An autoscaler on the managed instance group can automatically add or remove instances based on CPU utilization. Setting a target of 60% ensures that the group scales out before CPU saturation causes unresponsiveness. This is the standard, low-effort solution for handling variable load on Compute Engine and directly addresses the observed 100% CPU condition.

Why this answer

The managed instance group autoscaler with a CPU utilization target automatically adjusts the number of instances to maintain performance. It is the native, direct solution for scaling Compute Engine workloads based on demand, requiring no application changes. The other options either do not provide automatic scaling, require significant re-architecture, or rely on manual actions that cannot respond quickly enough.

Exam trap

The trap here is assuming that a notification alert or vertical scaling solves the scaling problem, when the requirement explicitly calls for automatic capacity adjustment with minimal manual intervention.

92
MCQmedium

A financial services company is designing a hybrid cloud architecture. They have an on-premises data center and want to extend their VPC network to Google Cloud. They require a dedicated, high-bandwidth, low-latency connection with a SLA, and they need to encrypt traffic in transit. They also want to avoid using the public internet. Which connectivity option should they choose?

A.Cloud Interconnect - Partner Interconnect
B.Cloud VPN with HA VPN
C.Cloud Interconnect - Dedicated Interconnect
D.Cloud CDN with Cloud VPN
AnswerC

Dedicated Interconnect provides a direct physical connection between the on-premises network and Google Cloud, offering high bandwidth, low latency, and an SLA. It does not traverse the public internet, and traffic can be encrypted with application-level encryption or MACsec. This meets the requirements for a dedicated, high-bandwidth, low-latency connection with SLA and no public internet usage.

Why this answer

Dedicated Interconnect is the correct choice because it offers a direct, dedicated physical connection with high bandwidth, low latency, and an SLA, and it does not use the public internet. It can be encrypted with MACsec or application-level encryption, satisfying the security requirement. Partner Interconnect and HA VPN do not provide the same dedicated, high-performance characteristics.

Exam trap

The trap here is assuming that HA VPN or Partner Interconnect can match Dedicated Interconnect's dedicated bandwidth and low latency, when they either use the public internet or involve third-party networks with less predictable performance.

93
MCQhard

A company is designing a VPC architecture for a multi-tenant SaaS platform. Each tenant has isolated workloads that must not communicate with each other. They also need centralized network security and logging. Which VPC design meets these requirements?

A.Dedicated Cloud VPN connections per tenant
B.Use a Shared VPC with separate subnets for each tenant and firewall rules to enforce isolation
C.Single VPC with network tags and IAP tunnels
D.Peered VPCs for each tenant with Cloud NAT
AnswerB

A Shared VPC centralises firewall rules and logging in the host project while separate subnets per tenant, combined with firewall rules, prevent cross-tenant traffic. This satisfies both the isolation requirement and the demand for centralised network security and logging across the multi-tenant platform.

Why this answer

Option B is correct because a Shared VPC in Google Cloud lets a host project centrally own and manage the VPC network, subnets, firewall rules, and logging while each tenant's service project gets its own subnet; firewall rules scoped to those subnets or service accounts enforce isolation so tenant workloads cannot communicate with each other. This design also satisfies the centralized network security and logging requirement, since the host project retains control of firewall policies and VPC Flow Logs across all tenant subnets. Option A does not provide tenant isolation or centralized logging, as Cloud VPN only establishes encrypted tunnels to on-premises or remote networks.

Option C is unsuitable because a single VPC with network tags and IAP tunnels does not create hard tenant boundaries and IAP is for identity-based TCP access, not tenant segmentation. Option D is wrong because VPC peering connects networks rather than isolating tenants, and Cloud NAT only provides outbound internet access, not centralized security or logging.

Exam trap

Candidates may incorrectly think that VPC peering (Option D) provides the same isolation and centralization as Shared VPC, but peering still requires management of multiple VPCs and does not offer a single point for logging and security policies.

94
MCQmedium

Refer to the exhibit. An engineer deploys this Terraform configuration. After deployment, they can SSH into the VM using its public IP. However, they want to restrict SSH access to only a specific IP range (203.0.113.0/24). What change is required?

A.Change the 'source_ranges' in the firewall rule to ['203.0.113.0/24']. The instance already has the required tag.
B.Modify the instance to use a network tag 'restricted-ssh' and update the firewall rule target_tags accordingly.
C.Add a new firewall rule with higher priority allowing SSH from 203.0.113.0/24, and keep the existing rule but change its priority to 100.
D.Update the 'source_ranges' in the firewall rule to ['203.0.113.0/24'] and remove the 'ssh-allowed' tag from the instance.
AnswerA

Editing the firewall rule's `source_ranges` to `['203.0.113.0/24']` narrows the permitted source addresses at the VPC firewall layer, satisfying the requirement to restrict SSH to that range. Because the instance already carries the matching target tag, the rule continues to apply, so no other configuration change is needed.

Why this answer

The firewall rule already targets the instance via the 'ssh-allowed' tag, so the only change needed is to narrow the source_ranges from the current open range (e.g., 0.0.0.0/0) to ['203.0.113.0/24']. Since the instance already carries the required tag, no tag modification is necessary — just update the source range in the existing rule. This is the minimal, correct change to restrict SSH to the specified CIDR.

Exam trap

PCA often tests whether candidates over-engineer the fix by adding tags or new rules when the existing rule already targets the instance correctly and only the source range needs tightening.

How to eliminate wrong answers

Option B is wrong because it proposes changing the instance's network tag to 'restricted-ssh' and updating target_tags, which is unnecessary since the existing tag already matches the firewall rule — this adds complexity without solving the source-range problem. Option C is wrong because adding a new higher-priority allow rule for 203.0.113.0/24 while keeping the existing open rule (even at priority 100) still permits SSH from anywhere via the original rule, defeating the restriction. Option D is wrong because removing the 'ssh-allowed' tag from the instance would cause the firewall rule to no longer apply to the instance at all, potentially blocking all SSH rather than restricting it to the desired range.

95
MCQmedium

Refer to the exhibit. An engineer deployed this Terraform configuration and can SSH to the instance using the external IP. However, they notice that the instance has a public IP address even though they intended to have no public IP. What change should be made to the configuration to ensure the instance does not get a public IP?

A.Change the metadata key enable-oslogin to FALSE.
B.Remove the entire access_config block from the network_interface configuration.
C.Set access_config = [] instead of leaving it empty.
D.Set the network to a custom VPC that does not have external internet access.
AnswerB

In Google Compute Engine, a public IP is assigned only when the network_interface contains an access_config block. Removing it entirely leaves the interface with no external address, satisfying the requirement that the instance have no public IP.

Why this answer

The `access_config` block in a Terraform `google_compute_instance` resource is what assigns a public (external) IP address to the instance's network interface. By removing the entire `access_config` block, the instance will only receive a private IP address, fulfilling the requirement of no public IP. Leaving the block empty (as in option C) still creates an ephemeral external IP by default, so it does not solve the problem.

Exam trap

A common trap in Google PCA is that an empty `access_config` block in Terraform for GCP still provisions a public IP, tricking candidates into thinking it means 'no public IP' when the correct fix is to remove the block entirely.

How to eliminate wrong answers

Option A is wrong because `enable-oslogin` controls OS Login authentication, not public IP assignment; disabling it has no effect on whether an external IP is provisioned. Option C is wrong because setting `access_config = []` is syntactically equivalent to an empty block and still triggers the creation of an ephemeral external IP; the block must be entirely absent to avoid a public IP. Option D is wrong because using a custom VPC without external internet access does not prevent the instance from being assigned a public IP; the `access_config` block directly controls that assignment, regardless of the VPC's routing or internet access capabilities.

96
MCQmedium

A company is designing a microservices architecture on Google Kubernetes Engine (GKE) for a global user base. They require high availability across multiple zones, automatic scaling, and rolling updates without downtime. Which Kubernetes workload resource should they use for each service?

A.StatefulSet with volumeClaimTemplates for persistent storage
B.Deployment with pod anti-affinity rules spread across zones
C.Job for batch processing
D.DaemonSet to ensure one pod per node
AnswerB

A Deployment manages stateless replicas and performs rolling updates, satisfying the no-downtime requirement. Pod anti-affinity rules spread those replicas across zones, delivering the multi-zone high availability the stem demands, while the Horizontal Pod Autoscaler handles automatic scaling.

Why this answer

The correct option is B: a Deployment with pod anti-affinity rules spread across zones. Deployments are the standard GKE workload for stateless microservices, providing declarative rolling updates (via RollingUpdate strategy with maxSurge/maxUnavailable) and integration with the Horizontal Pod Autoscaler for automatic scaling, while pod anti-affinity (or topologySpreadConstraints) spreads replicas across multiple zones for high availability. StatefulSet (A) is designed for stateful workloads needing stable network identities and per-pod PersistentVolumes, not for stateless services requiring rolling updates and autoscaling.

Job (C) runs finite batch tasks to completion rather than long-running services, and DaemonSet (D) schedules one pod per node for node-level agents, not scalable service replicas.

97
MCQmedium

A retail company runs its order-processing platform on Compute Engine instances in a single managed instance group (MIG) spread across three zones in us-central1. During seasonal peaks, the application must handle up to 10x normal traffic while keeping median request latency under 200 ms. The architecture team wants to add a caching layer that can absorb repeated catalogue reads and survive the loss of an entire zone without manual intervention. Which design should they choose?

A.Deploy Memorystore for Redis in Standard Tier with a replica in a second zone and configure the application to read from the Redis endpoint.
B.Deploy Memorystore for Redis in Basic Tier and place the instance in the same zone as the majority of the MIG instances to reduce network latency.
C.Deploy a self-managed Redis cluster on Compute Engine instances distributed across three zones and manage replication and failover with your own scripts.
D.Enable Cloud CDN with a backend service pointed at the MIG, and rely on edge caching to serve repeated catalogue reads.
AnswerA

Memorystore for Redis Standard Tier provides automatic replication to a replica in a different zone and failover if the primary zone is lost, which satisfies the zone-survival requirement. Redis itself absorbs repeated catalogue reads at sub-millisecond latency, offloading the MIG instances. Because the service endpoint is stable, the application needs no manual reconfiguration when failover occurs, matching the no-manual-intervention constraint.

Why this answer

The requirement combines zone-level resilience, low-latency repeated reads, and no manual failover. A managed in-memory cache with automatic cross-zone replication satisfies all three simultaneously: replication handles the zone loss, in-memory storage handles the latency, and the managed endpoint removes manual steps. Options that lack a replica or that push orchestration onto the team fail at least one stated constraint, and edge HTTP caching does not fit dynamic internal reads.

Exam trap

The trap here is assuming that any in-memory cache is equally resilient, when the Basic Tier is single-node and cannot survive the loss of a zone.

98
MCQhard

A global e-commerce company is designing its application architecture on Google Cloud. The application must serve users from multiple regions with low latency and must be able to fail over between regions automatically in case of a regional outage. The company wants to minimize operational overhead and ensure that the database layer supports multi-region writes with strong consistency. Which database solution should they choose?

A.Cloud SQL for PostgreSQL with cross-region read replicas.
B.Cloud Bigtable with a multi-region cluster.
C.Cloud Spanner with a multi-region configuration.
D.Firestore in Datastore mode with multi-region replication.
AnswerC

Cloud Spanner is a globally distributed, horizontally scalable database that supports multi-region configurations with strong consistency. It provides automatic failover and low-latency reads and writes across regions. This meets the requirements for multi-region writes, strong consistency, and minimal operational overhead.

Why this answer

Cloud Spanner is the only Google Cloud database that offers multi-region writes with strong consistency and automatic failover. It is designed for global applications requiring low latency and high availability. The other options either do not support multi-region writes or do not provide strong consistency across regions.

Exam trap

The trap here is assuming that cross-region read replicas or NoSQL databases can handle multi-region writes with strong consistency, when they typically offer read-only replicas or eventual consistency.

99
MCQhard

A logistics company runs a batch route-optimization job that reads 50 TB from Cloud Storage, performs CPU-intensive computation, and writes results back to Cloud Storage. The job runs for about four hours each night and must finish before the morning dispatch window. The team wants the lowest cost while guaranteeing completion within the window. Which compute design should the architect choose?

A.A managed instance group of preemptible VMs with an instance template that runs the batch job
B.A Cloud Run service with 8 vCPU and 32 GiB memory processing the job on a nightly Cloud Scheduler trigger
C.A Dataproc cluster with autoscaling enabled and secondary workers on preemptible VMs
D.A Batch job with a task group that specifies a machine type and a maximum run duration, using standard provisioning
AnswerD

Batch provisions Compute Engine capacity for the task group, supports specifying machine type and a maximum run duration, and can use standard (non-preemptible) VMs, which guarantees the resources are not reclaimed mid-run. It handles job scheduling, retries, and Cloud Storage staging, and the four-hour window fits comfortably within standard VM availability.

Why this answer

Batch is the managed service for running containerized batch workloads on Compute Engine. Specifying a task group with standard provisioning and a maximum run duration guarantees capacity for the four-hour job, and Batch handles Cloud Storage staging, retries, and job lifecycle. Preemptible options risk termination, Dataproc targets Spark and Hadoop, and Cloud Run timeouts prevent long-running jobs.

Exam trap

The trap here is optimizing for the lowest raw compute price with preemptible VMs, while ignoring that a hard completion deadline rules out reclaimable capacity.

100
Multi-Selectmedium

A retail company is planning a Google Cloud organization structure for a new e-commerce platform. They want to isolate production from non-production, allow central network and security teams to apply guardrails across all projects, and give application teams self-service within their own boundaries. Which two design choices support these goals? (Choose two.)

Select 2 answers
A.Use a Shared VPC host project owned by the central network team, with application projects attached as service projects.
B.Create separate folders for production and non-production under the organization node, and apply organization policies at the folder level.
C.Place every project directly under the organization node and manage IAM individually per project.
D.Assign each application team the Project Creator role at the organization node so they can create projects anywhere.
E.Grant the central network team the Organization Administrator role so they can manage all projects directly.
AnswersA, B

Shared VPC centralizes subnet, firewall, and routing control in a host project managed by the network team, while service projects consume those networks. Application teams can deploy resources into their own service projects without managing network topology, giving them self-service within boundaries and allowing the central team to apply consistent network guardrails across all workloads.

Why this answer

A folder hierarchy with production and non-production branches lets central teams apply organization policies and IAM that inherit downward, while application teams create projects inside their assigned folder. Pairing that with a Shared VPC host project centralizes network control and lets service projects consume the network, so application teams get self-service deployment without owning network topology.

Exam trap

The trap here is equating central control with granting broad organization-level roles instead of using folder-scoped policies and Shared VPC.

101
MCQmedium

A retail company runs a Java-based order service on Compute Engine. The service currently reads its database credentials from a plaintext file on the boot disk. A security review requires that the credentials be removed from disk, be automatically rotated every 30 days, and be retrievable by the application through a single API call. You want the least operational overhead. What should you do?

A.Encrypt the credentials file with a Cloud KMS key, keep it on the boot disk, and grant the VM's service account roles/cloudkms.cryptoKeyDecrypter so the application can decrypt it at startup.
B.Store the credentials in a Cloud Storage bucket with uniform bucket-level access and grant the VM's service account roles/storage.objectViewer, then have the application download the file at startup.
C.Store the credential in a custom metadata key on the instance and grant the VM's service account the compute.instanceAdmin.v1 role so it can read its own metadata.
D.Store the credential as a version in Secret Manager, grant the VM's service account roles/secretmanager.secretAccessor on that secret, and configure a rotation schedule that publishes to a Pub/Sub topic.
AnswerD

Secret Manager is the managed service for this exact requirement: the secret never needs to live on disk, access is granted per-secret through IAM to the VM's attached service account, and a rotation schedule with a Pub/Sub notification lets a Cloud Function rotate the database password automatically. The application fetches the current version through one API call.

Why this answer

The requirements point to a managed secret store with per-secret IAM and built-in rotation. Secret Manager keeps the credential off disk, lets the application retrieve it with one API call, and supports a rotation schedule that notifies a Pub/Sub topic so an automated workflow can update the underlying database password. Object storage, metadata, and KMS-wrapped files all leave the credential materialized on the instance or require custom rotation logic.

Exam trap

The trap here is assuming that encrypting a credential with Cloud KMS satisfies a requirement to remove it from disk and rotate it, when KMS rotates the wrapping key rather than the credential itself.

102
MCQeasy

A multinational e-commerce company needs a globally distributed database that provides strong consistency and transactional support for order processing. Which Google Cloud database service should they use?

A.Cloud SQL
B.Cloud Spanner
C.Cloud Bigtable
D.Cloud Firestore
AnswerB

Cloud Spanner satisfies both constraints simultaneously: global distribution and strong consistency with ACID transactions. Its TrueTime-based synchronisation delivers external consistency across regions, unlike Cloud SQL (regional) or Firestore, which offers strong consistency only within limited configurations.

Why this answer

Cloud Spanner is the correct choice because it is a globally distributed, horizontally scalable relational database service that provides strong consistency and full ACID transactional support across regions. Unlike other Google Cloud databases, Spanner uses synchronous replication and the TrueTime API to guarantee external consistency, making it ideal for order processing systems that require both global scale and transactional integrity.

Exam trap

The trap here is that candidates often confuse Cloud Spanner with Cloud SQL, assuming that a traditional relational database like Cloud SQL can be scaled globally by adding replicas, but they miss that Cloud SQL replicas are read-only and cannot provide the strong consistency and write scalability needed for a globally distributed transactional system.

How to eliminate wrong answers

Option A is wrong because Cloud SQL is a regional, single-writer database that cannot scale horizontally across multiple regions, and it does not provide the global strong consistency needed for a globally distributed order processing system. Option C is wrong because Cloud Bigtable is a NoSQL wide-column database designed for high-throughput analytical workloads, not for transactional order processing that requires strong consistency and ACID transactions. Option D is wrong because Cloud Firestore is a NoSQL document database that offers eventual consistency by default (unless using transactions in a single region) and is not designed for the complex, strongly consistent transactional workloads of a global e-commerce order processing system.

103
MCQhard

An analytics team runs a batch pipeline that reads several terabytes of data from a Cloud Storage bucket in us-central1 every night. To reduce egress and improve throughput, they decide to run the pipeline on Compute Engine VMs in the same region and want the traffic to stay on Google's internal network without traversing the public internet. They also want the VMs to reach Google APIs such as Cloud Storage and BigQuery. Which configuration should the architect recommend?

A.Configure the VMs without external IPs and enable Private Google Access on the subnet
B.Assign external IP addresses to the VMs and rely on default internet routing to reach Google APIs
C.Deploy a NAT gateway on a separate VM and route all API traffic through it
D.Create a VPC peering connection between the project and the googleapis.com service project
AnswerA

Private Google Access allows VMs with only internal IP addresses to reach Google APIs and services through internal routing, keeping traffic off the public internet. This satisfies both the private connectivity goal and the requirement to access Cloud Storage and BigQuery from the same-region VMs without assigning external addresses.

Why this answer

Private Google Access on the subnet is the supported mechanism that lets VMs with internal-only addresses reach Google APIs and services over Google's internal network. Because the VMs and the Cloud Storage bucket are in the same region, this configuration also keeps traffic local, reduces public internet exposure, and avoids the cost and complexity of NAT gateways or external IP addresses.

Exam trap

The trap here is conflating internet access for VMs with private access to Google APIs, when Private Google Access specifically enables the latter without external IPs.

104
Multi-Selecthard

A media company is designing a hybrid architecture that connects its on-premises data center to a Google Cloud VPC. The company needs high-bandwidth, low-latency, private connectivity that does not traverse the public internet, and it wants redundancy so that a single link failure does not interrupt traffic. The architect is evaluating interconnect options. Which two characteristics apply to Dedicated Interconnect in this scenario? (Choose two.)

Select 2 answers
A.It can be created entirely over the public internet using IPsec tunnels between the customer gateway and a Cloud VPN gateway.
B.It automatically encrypts all traffic with MACsec at the link layer without any customer configuration.
C.It requires the customer to establish a minimum of two Interconnect attachments in different edge availability domains to achieve 99.99% availability.
D.It provides a direct physical connection between the customer's network and Google's network at a supported colocation facility.
E.It is provisioned through a third-party service provider that already has connectivity to Google, without the customer needing colocation space.
AnswersC, D

Google's 99.99% availability SLA for Dedicated Interconnect requires at least two attachments in two different edge availability domains, which map to distinct Google network locations. A single attachment provides 99.9% at best and represents a single point of failure. This redundancy requirement matches the company's goal of surviving a single link failure.

Why this answer

Dedicated Interconnect provides a private physical connection at a supported colocation facility and offers a 99.99% SLA only when at least two attachments are placed in different edge availability domains. Partner Interconnect, HA VPN, and automatic MACsec encryption describe different products or optional features, so they do not accurately characterize Dedicated Interconnect for this hybrid design.

Exam trap

The trap here is conflating Dedicated Interconnect with Partner Interconnect, or assuming traffic on a dedicated circuit is encrypted by default when MACsec must be configured explicitly.

105
MCQeasy

A company runs a web application on Compute Engine instances behind a global HTTP(S) Load Balancer. The application uses Cloud SQL for MySQL for user data. Users report that during peak hours, the page load times increase significantly. The development team notices that the number of database connections exceeds the maximum allowed, causing some requests to fail. The application is designed to use connection pooling with a maximum pool size of 100 connections per instance. There are currently 10 instances. The Cloud SQL instance is configured with 4 vCPUs and 15 GB memory, and the maximum connections is set to 400. The application team wants to minimize cost while resolving the issue. What should the architect recommend?

A.Reduce the max pool size per instance to 40 connections.
B.Increase the Cloud SQL instance tier to have more vCPUs and memory.
C.Implement connection pooling at the global HTTP(S) Load Balancer level.
D.Use Cloud SQL Proxy with connection pooling.
AnswerA

Ten instances at 100 pooled connections each demand 1,000 connections, far exceeding the 400 limit. Lowering the pool to 40 caps demand at exactly 400, matching the configured maximum without resizing the costly Cloud SQL instance, directly resolving the connection exhaustion at minimum cost.

Why this answer

With 10 instances each configured for a max pool of 100 connections, the theoretical peak is 1,000 connections — far exceeding Cloud SQL's 400-connection limit. Reducing the pool to 40 per instance yields a maximum of 400 connections, which fits within the limit and resolves the failures without any cost increase. This is the only option that addresses the root cause (over-provisioned pools) while honoring the 'minimize cost' constraint.

Exam trap

The trap is that candidates instinctively choose 'scale up the database' (Option B) because it sounds like the obvious fix, ignoring the explicit 'minimize cost' constraint and the fact that the pool size is the actual misconfiguration.

How to eliminate wrong answers

Option B is wrong because increasing the Cloud SQL tier adds cost and only raises the connection ceiling — it does not fix the fundamental mismatch between 1,000 potential connections and the application's actual concurrency needs. Option C is wrong because a global HTTP(S) Load Balancer operates at Layer 7 for HTTP traffic and has no awareness of MySQL connection pooling; it cannot pool database connections. Option D is wrong because Cloud SQL Proxy provides secure IAM-based connectivity, not connection pooling — it does not reduce the number of connections the application opens.

106
Multi-Selectmedium

A financial services firm is planning its Google Cloud resource hierarchy before migrating production workloads. The architecture team wants to enforce separation between business units, centralize network administration, and apply consistent IAM and policy controls across many projects. Which two design choices should the architect recommend? (Choose two.)

Select 2 answers
A.Grant the roles/owner role to each business unit's administrators at the organization level to simplify management
B.Use a Shared VPC host project to centralize network administration while service projects host the workloads
C.Place all projects directly under the organization node and manage permissions only at the project level
D.Create a separate organization node for each business unit to isolate billing and IAM
E.Create a folder per business unit under the organization node and apply IAM policies and Organization Policy constraints at the folder level
AnswersB, E

Shared VPC allows a host project to own the VPC network and subnets while service projects attach their resources to those subnets. Network administration stays centralized with the host project's administrators, and service project teams can deploy workloads without managing network topology, matching the separation and centralization requirements.

Why this answer

A folder-based hierarchy with inherited IAM and Organization Policy constraints gives centralized, consistent governance while separating business units. A Shared VPC host project centralizes network administration so service projects can consume subnets without owning network topology. Together these choices provide the separation, centralization, and consistent controls the firm requires while avoiding the risks of flat hierarchies or excessive organization-level permissions.

Exam trap

The trap here is treating the organization node as something that can be created per business unit, when it actually maps to a single identity domain and is created once.

← PreviousPage 2 of 2 · 106 questions total

Ready to test yourself?

Try a timed practice session using only Design and plan a cloud solution architecture questions.