Courseiva

PCA · domain

Manage implementation of cloud architecture

This domain covers deploying and enforcing the architecture you designed: provisioning resources with Deployment Manager or Terraform, enforcing org policy and labels, configuring VPC networking (Cloud NAT, firewall rules, Private Google Access), and controlling access with VPC Service Controls and IAM. Questions are scenario-based, asking which actions meet a stated constraint or which configuration causes a described failure.

65 questions26 easy21 medium18 hard

Focused practice

Practice Manage implementation of cloud architecture questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Manage implementation of cloud architecture

You must be able to choose concrete controls: Organization Policy constraints for labels, VPC Service Controls for data boundaries, Cloud NAT port tuning for outbound connectivity, and BigQuery partitioning/clustering for cost. The single most important thing is matching the enforcement mechanism to the requirement, not just describing the desired outcome.

Enforcing mandatory Compute Engine labels via Organization Policy constraints or custom constraints

Diagnosing Cloud NAT port exhaustion and allocation failures on private instances

Using VPC Service Controls perimeters to restrict data exfiltration across project boundaries

Reducing BigQuery cost with partitioning, clustering, and query result caching

Watch out for

Common Manage implementation of cloud architecture exam traps

  • ▸Assuming Cloud NAT failures are routing or firewall issues instead of checking port allocation and minimum ports per VM.
  • ▸Believing VPC Service Controls encrypts data or replaces IAM; it only restricts access to services inside the perimeter.
  • ▸Trying to enforce labels with a script or startup script instead of an Organization Policy constraint that blocks non-compliant creation.

Question index

All Manage implementation of cloud architecture questions (65)

Click any question to see the full explanation, or start a practice session above.

1

Refer to the exhibit. A cloud administrator is attempting to grant the BigQuery Data Viewer role to an external user (user@example.com) but receives the error shown. What is the most likely cause?

Medium
2

A company wants to deploy a containerized application on Google Cloud and needs persistent storage that can be accessed by multiple pods in a GKE cluster concurrently. Which storage solution should they use?

Easy
3

A media company stores millions of video files in a Cloud Storage bucket and serves them to users worldwide. Users in Asia report slow download speeds, while users in North America are satisfied. The files are immutable after upload and are read frequently for the first 30 days, then almost never. You want to improve global performance while minimizing cost. What should you do?

Medium
4

A company is deploying a web application on Compute Engine. They want to automatically scale the number of instances based on CPU utilization. Which two components are required to set up autoscaling? (Choose two.)

Easy
5

An engineer runs the command above. A few days later, the instance becomes unresponsive. Upon investigation, you find that the boot disk is 100 GB and 95% full. The data disk is 500 GB and only 20% full. What is the most likely cause of the unresponsiveness?

Hard
6

An organization uses Cloud Deployment Manager to manage infrastructure as code. They need to ensure that changes to production resources are reviewed and approved before deployment. What should they do?

Medium
7

A company is migrating its on-premises Hadoop cluster to Google Cloud. They want to use a fully managed service that supports HDFS, Hive, and Spark, and allows them to run ephemeral clusters that can be created and deleted on demand. They also want to minimize infrastructure management. Which Google Cloud service should they use?

Easy
8

Match each IAM role type to its description.

Medium
9

A company is using Cloud Load Balancing to distribute traffic to a managed instance group (MIG) of web servers. The web servers are currently running in us-central1. To improve availability, the company plans to add a second MIG in us-west1. What must be done to ensure traffic is automatically routed to the closest healthy backend?

Medium
10

A healthcare company runs a patient portal on Google Kubernetes Engine (GKE). Auditors require that all container images be scanned for vulnerabilities before deployment and that only images from a trusted registry be admitted to the cluster. You are configuring Binary Authorization. Which TWO actions should you take to meet these requirements? (Choose two.)

Hard
11

A company is planning to deploy a global web application on Google Cloud. They expect low latency for users worldwide and need to serve static content (images, CSS) as well as dynamic API responses. Which architecture should they use?

Easy
12

A startup wants to deploy a web application on Google Cloud with a MySQL database. They anticipate low traffic initially but want the ability to scale seamlessly. They also want to minimize operational overhead. Which combination of services should they choose?

Easy
13

A startup wants to deploy a containerized application with minimal operational overhead. They expect variable traffic. Which compute option should they choose?

Easy
14

A company is using Cloud NAT to allow private instances to access the internet. They notice that outbound connections are failing intermittently. What is the most likely cause?

Easy
15

Your company runs a containerized microservices application on Google Kubernetes Engine (GKE) with a regional cluster. The application consists of a frontend service, a backend API service, and a background worker service that processes messages from Cloud Pub/Sub. The worker service uses a Deployment with 3 replicas. Recently, the team noticed that the worker service is frequently failing with 'ContainerCreating' errors. The error message in the pod events is: 'Failed to pull image "gcr.io/my-project/my-worker:latest": rpc error: code = DeadlineExceeded desc = context deadline exceeded'. The image is stored in Container Registry in the same project. The cluster nodes are n1-standard-2 VMs with 10 GB of disk space. The team has confirmed that the image exists and that the nodes have internet access. What is the most likely cause of the issue?

Hard
16

A company is designing a data pipeline to ingest streaming data from IoT devices and store it in BigQuery for analysis. They need to minimize latency and operational overhead. Which two Google Cloud services should they use? (Choose two.)

Easy
17

Your team is deploying a new internal web application on Compute Engine. The security team requires that all outbound internet traffic from the instances be inspected by a third-party firewall appliance running on a separate VM. You need to implement this with minimal changes to the application instances. What should you do?

Medium
18

Your team is deploying a new three-tier application to Google Cloud. The security team requires that the application's Compute Engine instances never receive public IP addresses, yet the instances must still download OS patches from the public internet and reach a third-party REST API over HTTPS. You need to implement this with the least operational overhead. What should you do?

Medium
19

Your organization is using Google Cloud to host a web application that experiences unpredictable traffic spikes. You need to ensure the application scales automatically and maintains high availability across multiple zones. The application runs on Compute Engine instances behind a load balancer. What should you do?

Easy
20

A developer is using Cloud Build to automate deployments. The build fails with an error: 'Permission 'iam.serviceAccounts.actAs' denied.' What is the most likely cause?

Medium
21

A company is deploying a global web application on Google Cloud. The application serves static content from a Cloud Storage bucket and dynamic content from a managed instance group backend. They want to use a single global IP address and provide low latency to users worldwide. They also want to protect the application from DDoS attacks. Which solution should they implement?

Hard
22

Drag and drop the steps to deploy a containerized application to Google Kubernetes Engine (GKE) using a Deployment into the correct order.

Medium
23

A startup wants to deploy a containerized web application that must scale automatically based on incoming HTTP request volume and must be reachable at a stable HTTPS endpoint. The team has no Kubernetes experience and wants to minimize infrastructure management. Which Google Cloud service should they use?

Easy
24

Which THREE of the following are recommended practices when designing a highly available architecture on Google Cloud using multiple regions?

Hard
25

A startup is setting up a CI/CD pipeline for their web application using Cloud Build and Cloud Deploy. They have configured a Cloud Build trigger that executes on pushes to the main branch of a Cloud Source Repositories repository. The trigger runs a build step that builds a Docker image and pushes it to Artifact Registry, then creates a release using Cloud Deploy. The pipeline fails with an error message indicating that the Cloud Build service account does not have permission to create releases. What should the architect do to resolve the issue?

Easy
26

Your team is deploying a stateful web application on Google Kubernetes Engine (GKE). The application requires each replica to have a stable network identity and its own persistent disk that survives pod restarts. You also need to ensure that the persistent disk is automatically provisioned and attached. Which GKE feature should you use?

Medium
27

A large enterprise is migrating their on-premises data center to Google Cloud. They have hundreds of VMs and need to minimize network latency between on-prem and cloud during migration. They have high bandwidth requirements. Which connectivity solution should they use?

Hard
28

A company runs a batch processing workload on Compute Engine instances in a managed instance group (MIG). The job is CPU-intensive and takes approximately 4 hours to complete. The company wants to reduce costs without sacrificing performance. Which action should they take?

Easy
29

A developer needs to secure secrets (API keys, passwords) used in a Cloud Function. What is the recommended approach?

Easy
30

A startup is migrating a monolithic application to Google Cloud. They want to minimize operational overhead and auto-scale based on HTTP request load. Which compute solution should they choose?

Easy
31

A company is migrating a monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single Compute Engine instance and stores session state in local memory. The migration must support horizontal scaling and high availability. What should the company do to manage session state in the new architecture?

Medium
32

A company is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that each microservice can only communicate with specific other microservices, and they need to enforce this at the network level. They also want to minimize operational overhead. Which approach should they use?

Hard
33

Which TWO of the following are benefits of using a VPC Service Controls perimeter?

Easy
34

You are deploying a new version of a microservices application to a GKE cluster. The deployment must be released to a small subset of users first, and if errors occur, traffic must automatically revert to the previous version. You also need to monitor the error rate and latency of the new version. Which approach should you use?

Medium
35

A company has a Cloud Run service that processes images uploaded by users. The service reads the images from a Cloud Storage bucket and writes processed images to another bucket. The team recently updated the service to use a custom service account named 'image-processor-sa' with minimal permissions. After the update, the service fails with permission errors when trying to read from the source bucket. The team verified that the service account has the Storage Object Viewer role on the source bucket and Storage Object Creator role on the destination bucket. What should the architect do to resolve the issue?

Easy
36

A company is deploying a new application on Compute Engine and wants to automate the installation of a custom agent on every newly created VM in a specific project. Which Google Cloud service should they use?

Medium
37

A financial services company uses VPC Service Controls to protect their project containing BigQuery datasets and Cloud Storage buckets. They have a perimeter that includes the BigQuery service. Users report that they cannot export data from BigQuery to Cloud Storage using the web console. The export job fails with an access denied error. The team needs to allow exports while maintaining data exfiltration prevention. The users have the necessary IAM permissions (BigQuery Data Editor, Storage Object Admin) on the appropriate resources. What should the architect do?

Hard
38

Which THREE factors should be considered when choosing a Google Cloud region for deploying a low-latency application serving global users? (Choose three.)

Hard
39

A developer accidentally deleted a bucket in Cloud Storage. The bucket had object versioning enabled. How can the bucket and its objects be restored?

Easy
40

A company is using Cloud SQL for PostgreSQL and needs to run a one-time heavy analytical query that takes over 30 minutes and uses 100% CPU. The production database is serving user traffic with high QPS. What should the company do to run the query without impacting production?

Medium
41

Your company runs a critical application on Compute Engine instances in a managed instance group across three zones. The application writes logs to local disk. You are asked to improve the reliability of log retention and ensure logs are available in case of instance failure. You have already configured a health check that automatically recreates instances. However, after a recent zonal outage, logs from the affected instances were lost. You need to implement a solution that preserves logs even when instances are terminated. What should you do?

Easy
42

Your organization is moving a legacy monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single virtual machine with a local MySQL database. You need to design a cloud-native architecture that improves scalability and reliability. Which two actions should you take? (Choose TWO.)

Medium
43

A company is migrating an on-premises application to Google Cloud. The application consists of a web front end and a backend that uses a relational database. The company wants to minimize downtime during the migration and ensure that the database remains consistent. They plan to use a phased approach. Which TWO steps should they take to achieve a successful migration? (Choose two.)

Medium
44

A company uses preemptible VMs for batch processing. They notice that during peak hours, many instances are terminated before finishing their tasks. The operations team observes the output shown in the exhibit. Which action would best improve job completion rates without significantly increasing costs?

Medium
45

An organization wants to enforce that all Compute Engine VMs are created with specific disk encryption keys. Which policy mechanism should they use?

Hard
46

Your team has deployed a microservices application on Google Kubernetes Engine (GKE) with multiple services communicating via internal ClusterIP services. You notice that some requests between services are failing intermittently with 'connection refused' errors. The services are defined with readiness probes. What is the most likely cause?

Medium
47

You are designing a solution to store and serve static web content for a global audience. The content consists of HTML, CSS, JavaScript, and images. You need to ensure low latency and high availability. Which Google Cloud service should you use?

Easy
48

Your organization has a policy that all Compute Engine instances must have specific labels (env, team, cost-center) applied. You want to enforce this automatically when instances are created. What should you do?

Medium
49

A company is migrating a monolithic application to Google Cloud. They want to minimize changes to the application code while taking advantage of Cloud Run for serverless containers. Which approach should they take?

Easy
50

A company runs a stateful application on a single Compute Engine instance with a persistent disk. They need to ensure that the application can recover quickly in case of a zone failure. The recovery point objective (RPO) is 5 minutes, and the recovery time objective (RTO) is 15 minutes. Which approach should they take?

Hard
51

A company wants to store customer transaction logs for 7 years for compliance. The logs are accessed rarely but must be retrievable within 24 hours. Which storage option is most cost-effective?

Easy
52

What are two best practices for designing a scalable Kubernetes architecture on GKE?

Easy
53

Which THREE actions can help reduce costs for a BigQuery workload that runs frequent, ad-hoc analytical queries on a large dataset?

Hard
54

A company is using Cloud Load Balancing with backend services across multiple regions. They notice that traffic is not being evenly distributed and some backends are overloaded. Which configuration should they check?

Medium
55

A company runs a batch processing application on Compute Engine that reads data from Cloud Storage and writes results to BigQuery. The application runs on a managed instance group (MIG) with autoscaling. Recently, job failures occurred because instances could not authenticate to BigQuery. You need to ensure that the instances have the necessary permissions without embedding credentials in the application. What should you do?

Hard
56

A company uses Cloud Bigtable for time-series data. They experience high latency and uneven load distribution across nodes. What is the most likely cause?

Hard
57

A company runs multiple microservices on Cloud Run. Each service uses a Serverless VPC Access connector to connect to a shared Cloud Memorystore for Redis instance (standard tier) in a VPC network. The Redis instance is configured with a firewall rule that allows TCP connections on port 6379 from the VPC connector's subnet (10.8.0.0/28). After a recent code update, the order-service fails to connect to Redis, while the user-service continues to work. The error logs in order-service show 'connection refused'. The engineer verifies that both services use the same VPC connector, the same Redis instance IP, and the same service account. The VPC connector's metrics show no errors. What is the most likely cause?

Hard
58

A company wants to store backup data that is accessed rarely but must be available for retrieval within minutes. Which Cloud Storage class is appropriate?

Easy
59

A retail company runs a stateful batch application on a managed instance group. The application writes intermediate results to the boot disk of each VM and takes several hours to complete. The operations team wants rolling updates that replace instances with a new image, but must guarantee that no in-flight job is interrupted. Which configuration should you recommend?

Hard
60

An organization wants to monitor network traffic between VMs in a VPC for troubleshooting. Which TWO services can provide this?

Medium
61

A developer needs to deploy a stateful application that requires persistent storage across pod restarts in Google Kubernetes Engine. Which resource should they use?

Easy
62

A company is designing a highly available architecture for a stateful application on Compute Engine. They need to protect against zonal failures. Which THREE steps should they take?

Hard
63

A developer is trying to deploy a Compute Engine instance from a Cloud Build step. The build fails with the above error. What is the problem?

Easy
64

A company stores sensitive data in Cloud Storage and wants to enforce encryption at rest using customer-managed keys. Which Google Cloud service should they use to manage the keys?

Easy
65

A company runs a critical application on a managed instance group (MIG) with autoscaling enabled. The application experiences sudden traffic spikes, and the team wants to ensure that new instances are added quickly while maintaining cost efficiency. They also want to avoid over-provisioning. Which autoscaling metric should they use?

Hard

Frequently asked questions

What does the Manage implementation of cloud architecture domain cover on the PCA exam?
You must be able to choose concrete controls: Organization Policy constraints for labels, VPC Service Controls for data boundaries, Cloud NAT port tuning for outbound connectivity, and BigQuery partitioning/clustering for cost. The single most important thing is matching the enforcement mechanism to the requirement, not just describing the desired outcome.
How many questions are in this domain?
This page lists all 65 Manage implementation of cloud architecture questions in the PCA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Manage implementation of cloud architecture questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
google-pca GOOGLE-PCA manage implementation Practice Questions