Courseiva

CCNA Manage implementation of cloud architecture Questions

65 questions · Manage implementation of cloud architecture · All types, answers revealed

1
MCQmedium

Refer to the exhibit. A cloud administrator is attempting to grant the BigQuery Data Viewer role to an external user (user@example.com) but receives the error shown. What is the most likely cause?

Answer options not yet available.

Why this answer

The error indicates that the organization's policy constraints/iam.allowedPolicyMemberDomains is blocking the addition of an external user. This constraint restricts IAM policy bindings to only allow members from specified domains, and since user@example.com is from an external domain, the binding is denied. The error message directly references this constraint, making it the most likely cause.

Exam trap

Google often tests the distinction between IAM permission errors and organization policy constraints, where candidates mistakenly focus on the administrator's permissions (Option C) rather than the broader policy that blocks external members.

How to eliminate wrong answers

Option B is wrong because domain-wide delegation is a Google Workspace feature for service accounts to access user data, not related to granting IAM roles to external users. Option C is wrong because the error message does not indicate a permissions issue for the administrator; the error is about policy constraints, not missing IAM permissions. Option D is wrong because Google Groups are not required for granting IAM roles to external users; the constraint blocks any external member regardless of group membership.

2
MCQeasy

A company wants to deploy a containerized application on Google Cloud and needs persistent storage that can be accessed by multiple pods in a GKE cluster concurrently. Which storage solution should they use?

Answer options not yet available.

Why this answer

Filestore is the correct choice because it provides a managed NFS file server that supports the ReadWriteMany (RWX) access mode, allowing multiple pods in a GKE cluster to concurrently read from and write to the same persistent storage volume. This is essential for workloads like content management systems or shared data processing that require simultaneous access from multiple pods.

Exam trap

The trap here is that candidates often confuse Persistent Disk's ReadWriteOnce capability with ReadWriteMany, or incorrectly assume that Cloud Storage FUSE provides the same concurrent POSIX access as a true shared filesystem like NFS.

How to eliminate wrong answers

Option A is wrong because Persistent Disk volumes in GKE support only ReadWriteOnce (RWO) access mode, meaning they can be mounted by only a single pod at a time, not multiple pods concurrently. Option B is wrong because Cloud Storage via Storage FUSE provides a file-system interface to object storage, but it does not offer true POSIX-compliant concurrent read-write access from multiple pods and introduces latency and consistency limitations. Option C is wrong because Compute Engine persistent disks attached to each node are local to that node and cannot be shared across multiple nodes or pods; they also default to ReadWriteOnce mode.

3
MCQmedium

A media company stores millions of video files in a Cloud Storage bucket and serves them to users worldwide. Users in Asia report slow download speeds, while users in North America are satisfied. The files are immutable after upload and are read frequently for the first 30 days, then almost never. You want to improve global performance while minimizing cost. What should you do?

Answer options not yet available.

Why this answer

Serving immutable objects through Cloud CDN puts copies at Google's edge points of presence, which directly improves download speeds for users far from the origin. Pairing that with a lifecycle rule that transitions rarely accessed objects to Nearline Storage after 30 days aligns storage cost with the actual access pattern, so performance improves without unnecessary expense.

Exam trap

The trap here is reaching for multi-region storage to fix latency, when multi-region placement improves durability and availability rather than edge delivery to end users.

4
Multi-Selecteasy

A company is deploying a web application on Compute Engine. They want to automatically scale the number of instances based on CPU utilization. Which two components are required to set up autoscaling? (Choose two.)

Answer options not yet available.

Why this answer

Option C (Instance template) is correct because a managed instance group requires an instance template to define the machine type, boot disk image, network, and other configuration used when automatically creating new VM instances during scaling. Option D (Managed instance group) is correct because autoscaling in Compute Engine operates on a managed instance group (MIG), where the autoscaler adds or removes instances based on the specified CPU utilization target. Cloud Functions (A) is a serverless event-driven compute service and plays no role in Compute Engine autoscaling.

Cloud Load Balancing (B) is commonly used to distribute traffic to the instances but is not a required component to configure the autoscaling policy itself. Cloud Monitoring (E) can surface metrics and alerts, but the autoscaler uses the MIG's built-in CPU utilization signal and does not require a separate Monitoring configuration.

Exam trap

The trap here is that candidates often think Cloud Monitoring is required because autoscaling uses CPU metrics, but the autoscaler automatically accesses those metrics without requiring Cloud Monitoring to be separately configured.

How to eliminate wrong answers

Option A is wrong because Cloud Functions is a serverless compute platform for event-driven code, not a component for configuring autoscaling of Compute Engine instances. Option B is wrong because Cloud Load Balancing distributes traffic across instances but is not a required component for autoscaling based on CPU utilization; autoscaling can work without a load balancer. Option E is wrong because Cloud Monitoring provides metrics and alerts but is not a required component; the autoscaler uses its own built-in CPU utilization metric without needing Cloud Monitoring to be explicitly set up.

5
MCQhard

An engineer runs the command above. A few days later, the instance becomes unresponsive. Upon investigation, you find that the boot disk is 100 GB and 95% full. The data disk is 500 GB and only 20% full. What is the most likely cause of the unresponsiveness?

Answer options not yet available.

Why this answer

The boot disk is 95% full, which leaves insufficient free space for the operating system to write temporary files, logs, or perform essential system operations. When a Linux or Windows boot disk runs out of space, the OS can become unresponsive because critical processes (e.g., systemd, journald, or the Windows Registry) cannot write to disk. In Google Cloud, the boot disk is the root device (typically /dev/sda1), and filling it to 95% on a 100 GB disk means only 5 GB remains, which is easily exhausted by normal system activity.

Exam trap

Google Cloud often tests the distinction between disk space exhaustion and performance bottlenecks; the trap here is that candidates may focus on disk type (pd-standard vs pd-ssd) or IOPS limits instead of recognizing that a nearly full boot disk directly causes OS unresponsiveness.

How to eliminate wrong answers

Option B is wrong because pd-standard disks are HDD-based and can cause I/O bottlenecks, but the data disk is only 20% full and the question states the instance became unresponsive due to disk space, not I/O performance. Option C is wrong because pd-ssd is a high-performance SSD type, not too slow for typical workloads; the issue is space exhaustion, not speed. Option D is wrong because running out of IOPS would cause performance degradation or throttling, not unresponsiveness due to disk space; the boot disk is nearly full, which is a capacity problem, not an IOPS limit.

6
MCQmedium

An organization uses Cloud Deployment Manager to manage infrastructure as code. They need to ensure that changes to production resources are reviewed and approved before deployment. What should they do?

Answer options not yet available.

Why this answer

Integrating Cloud Deployment Manager with Cloud Build allows you to create a CI/CD pipeline that includes a manual approval step. This ensures that changes to production resources are reviewed and approved before the deployment config is applied, meeting the requirement for change control.

Exam trap

The trap here is that candidates often confuse code review (pull request approval) with deployment approval, thinking that merging code with approval automatically ensures deployment approval, but Cloud Deployment Manager requires a separate approval step in the deployment pipeline to control when infrastructure changes are actually applied.

How to eliminate wrong answers

Option A is wrong because Cloud Scheduler is a cron job service for triggering actions on a schedule; it does not provide any review or approval mechanism, and reviewing logs after deployment does not prevent unapproved changes. Option C is wrong because a Cloud Deployment Manager preview deployment only shows what changes would be made without actually applying them, but it does not enforce a formal review and approval workflow; manual approval of a preview is not a built-in feature of Deployment Manager. Option D is wrong because while using Cloud Build with a trigger on a branch that requires pull request approval before merging enforces code review, it does not directly integrate with Cloud Deployment Manager to control the deployment of infrastructure; it only controls the merge of code, not the deployment of resources.

7
MCQeasy

A company is migrating its on-premises Hadoop cluster to Google Cloud. They want to use a fully managed service that supports HDFS, Hive, and Spark, and allows them to run ephemeral clusters that can be created and deleted on demand. They also want to minimize infrastructure management. Which Google Cloud service should they use?

Answer options not yet available.

Why this answer

Cloud Dataproc is the only service that provides a managed Hadoop and Spark environment with support for HDFS, Hive, and ephemeral clusters. It allows you to create clusters on demand and delete them when jobs are complete, reducing operational overhead. The other services are not Hadoop-compatible or do not support the required tools.

Exam trap

The trap here is assuming that BigQuery or Dataflow can replace Hadoop workloads; they are different paradigms and do not support HDFS or Hive.

8
Matchingmedium

Match each IAM role type to its description.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Legacy roles like Owner, Editor, Viewer

Fine-grained roles managed by Google

User-defined roles with specific permissions

Another name for Basic roles

Identity for applications, not users

Why these pairings

In GCP, IAM roles are categorized into basic (broad), predefined (service-specific), and custom (user-defined). Common confusions arise between predefined and custom roles.

9
MCQmedium

A company is using Cloud Load Balancing to distribute traffic to a managed instance group (MIG) of web servers. The web servers are currently running in us-central1. To improve availability, the company plans to add a second MIG in us-west1. What must be done to ensure traffic is automatically routed to the closest healthy backend?

Answer options not yet available.

Why this answer

A global external HTTP(S) load balancer can route traffic to backends in multiple regions and automatically directs requests to the closest healthy backend based on the client's geographic location and backend health. Adding both MIGs as backends to this single anycast IP ensures traffic is distributed to the nearest region without additional DNS-based routing or redirects.

Exam trap

The trap here is that candidates confuse regional load balancers (Network Load Balancer, TCP/UDP Proxy) with global load balancers, assuming any external load balancer can span regions, but only the global external HTTP(S) load balancer (and the global external SSL proxy) support multi-region backends with automatic proximity-based routing.

How to eliminate wrong answers

Option A is wrong because a Network Load Balancer is regional and cannot route traffic across regions; a redirect would introduce a single point of failure and latency, not automatic closest-backend routing. Option C is wrong because internal TCP/UDP load balancers are regional and cannot be used for external traffic; DNS-based routing would require manual configuration and does not provide automatic proximity-based routing with health-aware failover. Option D is wrong because an external TCP/UDP Network Load Balancer is regional (not global) and cannot distribute traffic to backends in multiple regions; it only supports backends within a single region.

10
Multi-Selecthard

A healthcare company runs a patient portal on Google Kubernetes Engine (GKE). Auditors require that all container images be scanned for vulnerabilities before deployment and that only images from a trusted registry be admitted to the cluster. You are configuring Binary Authorization. Which TWO actions should you take to meet these requirements? (Choose two.)

Answer options not yet available.

Why this answer

Binary Authorization enforces deploy-time policy based on attestations. Enabling Container Analysis provides automated vulnerability scanning of registry images, and defining an attestor that your trusted build pipeline signs ensures only verified images are admitted. Together they create a verifiable chain from scanning to admission, which satisfies the auditors' requirements.

Exam trap

The trap here is assuming that Kubernetes PodSecurityPolicy or NetworkPolicy can restrict image sources, when only Binary Authorization evaluates image provenance at admission time.

11
MCQeasy

A company is planning to deploy a global web application on Google Cloud. They expect low latency for users worldwide and need to serve static content (images, CSS) as well as dynamic API responses. Which architecture should they use?

Answer options not yet available.

Why this answer

Cloud CDN in front of an external HTTPS Load Balancer with backend services in multiple regions is correct because it provides global anycast IP termination, low-latency content delivery via Google's edge cache for static content, and dynamic API requests are forwarded to the nearest healthy backend in the closest region. This architecture meets both the low-latency requirement for users worldwide and the need to serve both static and dynamic content efficiently.

Exam trap

Google Cloud often tests the misconception that DNS geo-routing alone (Option C) can provide low-latency global content delivery, but it lacks caching and introduces DNS resolution delays, making it unsuitable for static content without a CDN.

How to eliminate wrong answers

Option B is wrong because Cloud NAT is used for outbound internet access from private instances, not for distributing static content or reducing latency for global users; it does not provide any caching or global load balancing. Option C is wrong because Cloud DNS with geo-routing directs traffic based on DNS resolution, but it cannot cache static content and introduces DNS propagation delays; Cloud Run services alone do not include a CDN for static assets. Option D is wrong because VPC Network Peering connects VPCs for private networking but does not provide global load balancing, caching, or low-latency content delivery; serving from a central location would increase latency for distant users.

12
MCQeasy

A startup wants to deploy a web application on Google Cloud with a MySQL database. They anticipate low traffic initially but want the ability to scale seamlessly. They also want to minimize operational overhead. Which combination of services should they choose?

Answer options not yet available.

Why this answer

App Engine Standard Environment provides a fully managed, autoscaling platform for web applications, while Cloud SQL offers a managed MySQL database with automatic replication and backups. This combination minimizes operational overhead because Google handles infrastructure provisioning, patching, and scaling, and Cloud SQL integrates natively with App Engine via the Cloud SQL proxy or Unix socket, requiring no manual configuration for connectivity.

Exam trap

Google Cloud often tests the misconception that Kubernetes (GKE) is always the best choice for scalability, but the trap here is that for a low-traffic application with minimal operational overhead requirements, a fully managed platform like App Engine Standard Environment is more appropriate than the complex orchestration overhead of GKE.

How to eliminate wrong answers

Option A is wrong because Compute Engine with a self-managed MySQL instance requires the startup to manually handle OS patching, database backups, replication, and scaling, which increases operational overhead and contradicts the goal of minimizing it. Option B is wrong because Cloud Spanner is a globally distributed, strongly consistent relational database designed for high-throughput, horizontal scaling, which is overkill and more expensive for a low-traffic web application that only needs a MySQL-compatible database. Option D is wrong because Google Kubernetes Engine (GKE) introduces significant operational complexity for managing container orchestration, node pools, and networking, which is unnecessary for a low-traffic application that could be served by a simpler, fully managed platform like App Engine.

13
MCQeasy

A startup wants to deploy a containerized application with minimal operational overhead. They expect variable traffic. Which compute option should they choose?

Answer options not yet available.

Why this answer

Cloud Run is the correct choice because it is a fully managed serverless compute platform that automatically scales from zero based on traffic, charges only for resources used during request processing, and eliminates all infrastructure management. This aligns perfectly with the startup's requirement for minimal operational overhead and handling variable traffic patterns without provisioning or scaling concerns.

Exam trap

The trap here is that candidates often confuse Cloud Run with App Engine Flexible Environment, assuming both are fully managed, but App Engine Flexible Environment does not scale to zero and requires VM-level management, making Cloud Run the only option that truly minimizes operational overhead for variable traffic.

How to eliminate wrong answers

Option A is wrong because App Engine Flexible Environment requires you to manage the underlying VM instances and does not scale to zero, incurring costs even when idle, which contradicts the goal of minimal operational overhead and cost efficiency for variable traffic. Option C is wrong because a single Compute Engine VM provides no autoscaling, requires manual capacity planning and maintenance, and cannot handle variable traffic without manual intervention or over-provisioning, leading to either downtime or wasted resources. Option D is wrong because Google Kubernetes Engine (GKE) introduces significant operational overhead for cluster management, node scaling, and Kubernetes configuration, which is excessive for a simple containerized application with variable traffic and contradicts the 'minimal operational overhead' requirement.

14
MCQeasy

A company is using Cloud NAT to allow private instances to access the internet. They notice that outbound connections are failing intermittently. What is the most likely cause?

Answer options not yet available.

Why this answer

Cloud NAT uses source network address translation (SNAT) to map private instance IPs to a single public IP address. Each NAT IP has a limited pool of source ports (typically 64,512 per IP for TCP/UDP). When concurrent connections exceed this capacity, new outbound connections are dropped, causing intermittent failures.

This is the most likely cause given the symptom of intermittent failures.

Exam trap

The trap here is that candidates confuse intermittent failures with firewall misconfigurations or DNS issues, but the key clue is 'intermittent'—which points to a resource exhaustion problem like port capacity, not a static policy or configuration error.

How to eliminate wrong answers

Option A is wrong because DNS server misconfiguration would cause name resolution failures, not intermittent connection drops after resolution; Cloud NAT operates at the network layer and is independent of DNS. Option B is wrong because VPC firewall rules blocking egress traffic would cause consistent, not intermittent, failures; the question states failures are intermittent, which points to resource exhaustion rather than a static rule. Option C is wrong because Cloud NAT explicitly supports TCP, UDP, and ICMP connections; it performs SNAT for all these protocols.

15
MCQhard

Your company runs a containerized microservices application on Google Kubernetes Engine (GKE) with a regional cluster. The application consists of a frontend service, a backend API service, and a background worker service that processes messages from Cloud Pub/Sub. The worker service uses a Deployment with 3 replicas. Recently, the team noticed that the worker service is frequently failing with 'ContainerCreating' errors. The error message in the pod events is: 'Failed to pull image "gcr.io/my-project/my-worker:latest": rpc error: code = DeadlineExceeded desc = context deadline exceeded'. The image is stored in Container Registry in the same project. The cluster nodes are n1-standard-2 VMs with 10 GB of disk space. The team has confirmed that the image exists and that the nodes have internet access. What is the most likely cause of the issue?

Answer options not yet available.

Why this answer

The error 'context deadline exceeded' when pulling an image indicates that the kubelet timed out while trying to download the container image. With only 10 GB of disk space on n1-standard-2 nodes, the node's disk may be nearly full, causing the image pull to stall or fail due to insufficient space to unpack the layers. This is the most likely cause because the image exists and internet access is confirmed, ruling out authentication or connectivity issues.

Exam trap

Google Cloud often tests the distinction between image pull errors that are due to permissions (e.g., 'unauthorized') versus resource exhaustion (e.g., disk full), and candidates mistakenly assume internet connectivity or permissions are the issue when the error message explicitly mentions a deadline exceeded.

How to eliminate wrong answers

Option A is wrong because node affinity is used to constrain pod scheduling to specific nodes, but the error is about pulling an image, not scheduling; the pods are already being created but fail during container setup. Option C is wrong because if nodes lacked permissions to access Container Registry, the error would be 'unauthorized' or 'access denied', not a deadline exceeded timeout; the team confirmed the image exists and nodes have internet access. Option D is wrong because a regional cluster distributes pods across zones by default, and even if all pods were in one zone, resource contention would manifest as 'Unschedulable' or 'CPU/memory pressure', not a pull timeout.

16
Multi-Selecteasy

A company is designing a data pipeline to ingest streaming data from IoT devices and store it in BigQuery for analysis. They need to minimize latency and operational overhead. Which two Google Cloud services should they use? (Choose two.)

Answer options not yet available.

Why this answer

Cloud Pub/Sub is the recommended service for ingesting streaming data, and Cloud Dataflow can process the data and write it directly to BigQuery with low latency. Cloud Storage is for batch uploads, Cloud Functions is event-driven but not ideal for high-throughput streaming, and Cloud Dataproc is for batch processing.

17
MCQmedium

Your team is deploying a new internal web application on Compute Engine. The security team requires that all outbound internet traffic from the instances be inspected by a third-party firewall appliance running on a separate VM. You need to implement this with minimal changes to the application instances. What should you do?

Answer options not yet available.

Why this answer

Routing outbound traffic through a third-party firewall is typically done by creating a custom route for 0.0.0.0/0 with the firewall's internal IP as the next hop, and enabling IP forwarding on the firewall VM. This transparently redirects traffic without modifying application instances. Other options involve services not designed for this purpose or require unsupported configuration changes.

Exam trap

The trap here is assuming that a load balancer can act as a default gateway for outbound traffic, when it is only for inbound or internal distribution.

18
MCQmedium

Your team is deploying a new three-tier application to Google Cloud. The security team requires that the application's Compute Engine instances never receive public IP addresses, yet the instances must still download OS patches from the public internet and reach a third-party REST API over HTTPS. You need to implement this with the least operational overhead. What should you do?

Answer options not yet available.

Why this answer

Cloud NAT provides managed, regional outbound internet access for instances that have no external IP address. It satisfies both the security constraint and the functional need for patch downloads and third-party API calls, without introducing proxy servers, ephemeral public addresses, or on-premises dependencies. This is the lowest-overhead native option.

Exam trap

The trap here is assuming that firewall rules can substitute for removing a public IP address, when the requirement is about address assignment rather than traffic filtering.

19
MCQeasy

Your organization is using Google Cloud to host a web application that experiences unpredictable traffic spikes. You need to ensure the application scales automatically and maintains high availability across multiple zones. The application runs on Compute Engine instances behind a load balancer. What should you do?

Answer options not yet available.

Why this answer

A managed instance group with autoscaling and multi-zone deployment provides automatic scaling and high availability. An external HTTP(S) load balancer is designed for web traffic, offering global distribution and SSL termination. This combination meets the requirements for unpredictable traffic and multi-zone availability.

Exam trap

The trap here is confusing internal and external load balancers, or assuming that an unmanaged instance group can autoscale.

20
MCQmedium

A developer is using Cloud Build to automate deployments. The build fails with an error: 'Permission 'iam.serviceAccounts.actAs' denied.' What is the most likely cause?

Answer options not yet available.

Why this answer

The error 'Permission iam.serviceAccounts.actAs denied' occurs when a Cloud Build build step tries to impersonate a service account (e.g., to deploy resources) but the Cloud Build service account lacks the Service Account User role on that target service account. Option D correctly identifies that the Cloud Build service account does not have the `roles/iam.serviceAccountUser` role on the service account used in the build steps, which is required to delegate access.

Exam trap

Google Cloud often tests the distinction between granting permissions to a user versus granting roles to a service account, and the trap here is that candidates mistakenly think the developer needs the `actAs` permission directly (Option A), when in fact it is the Cloud Build service account that requires the Service Account User role on the target service account.

How to eliminate wrong answers

Option A is wrong because the `iam.serviceAccounts.actAs` permission is not granted directly to the developer; it is granted to a service account (the Cloud Build service account) on another service account. The error is about the Cloud Build service account lacking this permission, not the developer. Option B is wrong because a missing build step would typically cause a syntax or execution error, not a specific IAM permission denial.

Option C is wrong because the Cloud Build service account is enabled by default when Cloud Build is used; the error is about missing IAM roles on that service account, not its existence.

21
MCQhard

A company is deploying a global web application on Google Cloud. The application serves static content from a Cloud Storage bucket and dynamic content from a managed instance group backend. They want to use a single global IP address and provide low latency to users worldwide. They also want to protect the application from DDoS attacks. Which solution should they implement?

Answer options not yet available.

Why this answer

The external HTTP(S) load balancer provides a global anycast IP and supports both backend services and backend buckets, allowing static and dynamic content to be served from the same IP. Cloud CDN caches static content for low latency, and Cloud Armor protects against DDoS and other attacks. This integrated solution meets all the requirements without third-party dependencies.

Exam trap

The trap here is assuming that a TCP proxy load balancer can serve HTTP(S) traffic and integrate with Cloud CDN; it operates at layer 4 and lacks these features.

22
Drag & Dropmedium

Drag and drop the steps to deploy a containerized application to Google Kubernetes Engine (GKE) using a Deployment into the correct order.

Drag or tap steps into the slots.

Steps
Order

Why this order

The image must be in a registry before the Deployment can reference it. The Service provides external access.

23
MCQeasy

A startup wants to deploy a containerized web application that must scale automatically based on incoming HTTP request volume and must be reachable at a stable HTTPS endpoint. The team has no Kubernetes experience and wants to minimize infrastructure management. Which Google Cloud service should they use?

Answer options not yet available.

Why this answer

Cloud Run is a fully managed container platform that scales automatically in response to request volume and exposes an HTTPS endpoint by default. Because it abstracts away clusters and VMs, it fits a team without Kubernetes skills that wants to minimize infrastructure management while still running a containerized web application.

Exam trap

The trap here is equating containers with Kubernetes, when a managed serverless container platform can run the same image with far less operational effort.

24
Multi-Selecthard

Which THREE of the following are recommended practices when designing a highly available architecture on Google Cloud using multiple regions?

Answer options not yet available.

Why this answer

Option B is correct because a global external HTTP(S) load balancer uses a single anycast IP and automatically routes users to the closest healthy backend service across multiple regions, providing global failover and low-latency access. Option C is correct because Cloud Spanner offers a multi-region configuration with synchronous replication and strong consistency, and cross-region replication for databases ensures data survives a regional outage. Option D is correct because health checks detect unhealthy endpoints and Cloud DNS weighted routing (or failover routing policies) can automatically direct traffic away from a failed region.

Option A is not recommended because a single regional managed instance group confines instances to one region, so a regional outage takes down the whole workload. Option E is not recommended because a single Cloud VPN tunnel is a single point of failure; highly available designs require redundant tunnels or Cloud Interconnect with multiple paths.

Exam trap

Google Cloud often tests the misconception that a single regional managed instance group or a single VPN tunnel is sufficient for multi-region high availability, but the exam expects you to recognize that redundancy across regions and elimination of single points of failure are mandatory.

How to eliminate wrong answers

Option A is wrong because deploying Compute Engine instances in a single regional managed instance group limits availability to one region; if that region fails, the application becomes unavailable, which violates the goal of multi-region high availability. Option E is wrong because a single Cloud VPN tunnel creates a single point of failure for connectivity between regions; for high availability, you should use multiple tunnels (e.g., with dynamic routing and BGP) or Cloud Interconnect with redundant connections.

25
MCQeasy

A startup is setting up a CI/CD pipeline for their web application using Cloud Build and Cloud Deploy. They have configured a Cloud Build trigger that executes on pushes to the main branch of a Cloud Source Repositories repository. The trigger runs a build step that builds a Docker image and pushes it to Artifact Registry, then creates a release using Cloud Deploy. The pipeline fails with an error message indicating that the Cloud Build service account does not have permission to create releases. What should the architect do to resolve the issue?

Answer options not yet available.

Why this answer

The Cloud Build service account (typically the Compute Engine default service account or a custom service account) needs the Cloud Deploy Developer IAM role (roles/clouddeploy.developer) to create releases in Cloud Deploy. This role grants the necessary permissions, such as clouddeploy.releases.create, which are required for the Cloud Build trigger to successfully create a release after building and pushing the Docker image. Without this role, the pipeline fails with a permission error, making option A the correct resolution.

Exam trap

The trap here is that candidates might assume the Cloud Build service account has sufficient permissions by default (e.g., via the Editor role) or confuse Cloud Deploy permissions with Cloud Run permissions, leading them to select the Cloud Run Admin role instead of the specific Cloud Deploy Developer role.

How to eliminate wrong answers

Option B is wrong because the cloudbuild.yaml file's correctness is irrelevant to the permission error; the error explicitly states the Cloud Build service account lacks permissions, not that the build steps are misconfigured. Option C is wrong because if the Cloud Deploy API were not enabled, the error would typically indicate that the API is not available or that the resource is not found, not a specific permission denied error for creating releases. Option D is wrong because the Cloud Run Admin role (roles/run.admin) grants permissions for Cloud Run services, not for Cloud Deploy release creation; Cloud Deploy uses its own IAM roles (e.g., Cloud Deploy Developer) to manage releases and delivery pipelines.

26
MCQmedium

Your team is deploying a stateful web application on Google Kubernetes Engine (GKE). The application requires each replica to have a stable network identity and its own persistent disk that survives pod restarts. You also need to ensure that the persistent disk is automatically provisioned and attached. Which GKE feature should you use?

Answer options not yet available.

Why this answer

StatefulSets are the correct choice for stateful applications on GKE because they provide stable network identities and persistent storage per replica. The volumeClaimTemplates automatically create PVCs, which dynamically provision persistent disks. Deployments, DaemonSets, and CronJobs lack these features, making them unsuitable for this scenario.

Exam trap

The trap here is assuming that a Deployment with a PersistentVolumeClaim can provide stable network identities and per-replica storage, but Deployments are designed for stateless workloads and do not offer these guarantees.

27
MCQhard

A large enterprise is migrating their on-premises data center to Google Cloud. They have hundreds of VMs and need to minimize network latency between on-prem and cloud during migration. They have high bandwidth requirements. Which connectivity solution should they use?

Answer options not yet available.

Why this answer

Cloud Interconnect provides a dedicated, high-bandwidth, low-latency connection between on-premises data centers and Google Cloud, bypassing the public internet. This is ideal for large-scale migrations with hundreds of VMs where minimizing latency and ensuring consistent throughput is critical.

Exam trap

The trap here is that candidates often confuse Cloud VPN with Cloud Interconnect, assuming VPN is sufficient for high-bandwidth, low-latency needs, but VPN's reliance on the public internet introduces jitter and bandwidth constraints that make it unsuitable for large-scale migrations.

How to eliminate wrong answers

Option B (Cloud VPN) is wrong because it uses IPSec tunnels over the public internet, which introduces variable latency, lower throughput limits, and no SLA for bandwidth, making it unsuitable for high-bandwidth, latency-sensitive migrations. Option C (Cloud NAT) is wrong because it is used to enable outbound internet access for private VMs without public IPs, not for establishing a private, low-latency connection between on-prem and cloud. Option D (Peering with Google) is wrong because it provides connectivity to Google services (e.g., YouTube, Gmail) via public peering points, not a dedicated private connection to a specific VPC network, and lacks SLA-backed bandwidth and latency guarantees required for enterprise migration.

28
MCQeasy

A company runs a batch processing workload on Compute Engine instances in a managed instance group (MIG). The job is CPU-intensive and takes approximately 4 hours to complete. The company wants to reduce costs without sacrificing performance. Which action should they take?

Answer options not yet available.

Why this answer

Preemptible VMs are significantly cheaper than standard VMs but can be terminated at any time. For a batch processing workload that is CPU-intensive and runs for 4 hours, using preemptible VMs in a MIG with a checkpointing mechanism allows the job to resume from the last saved state after an interruption, thus reducing costs without sacrificing performance.

Exam trap

Google Cloud often tests the misconception that committed use discounts are the best cost-saving option for any workload, but they are only cost-effective for predictable, always-on instances, not for batch jobs that can leverage preemptible VMs.

How to eliminate wrong answers

Option A is wrong because committed use discounts require a 1- or 3-year commitment and do not reduce costs for short-lived or interruptible workloads; they are best for steady-state, always-on instances. Option B is wrong because changing to a smaller machine type would reduce performance, potentially increasing job duration and negating cost savings. Option D is wrong because provisioning additional reserved VMs increases costs without addressing the need to reduce them, and reserved VMs are not cost-effective for batch jobs that can tolerate interruptions.

29
MCQeasy

A developer needs to secure secrets (API keys, passwords) used in a Cloud Function. What is the recommended approach?

Answer options not yet available.

Why this answer

Secret Manager is the recommended approach for securing sensitive data like API keys and passwords in Cloud Functions because it provides encrypted storage, fine-grained access control via IAM, and automatic rotation. Unlike environment variables, which are visible in the Cloud Console and logs, Secret Manager ensures secrets are never exposed in plaintext and are injected securely at runtime.

Exam trap

Google Cloud often tests the misconception that environment variables are a secure way to store secrets because they are 'hidden' from code, but in reality they are plaintext and accessible via the Cloud Console and logs.

How to eliminate wrong answers

Option A is wrong because environment variables are not encrypted by default and can be viewed in the Cloud Console, logs, or by anyone with access to the function's configuration, making them insecure for secrets. Option B is wrong because storing secrets in Cloud Storage requires managing bucket permissions and encryption keys manually, and downloading at runtime introduces latency and potential exposure if the bucket is misconfigured. Option D is wrong because hard-coding secrets in function code exposes them in source control, build artifacts, and logs, violating security best practices and making rotation nearly impossible.

30
MCQeasy

A startup is migrating a monolithic application to Google Cloud. They want to minimize operational overhead and auto-scale based on HTTP request load. Which compute solution should they choose?

Answer options not yet available.

Why this answer

Cloud Run is the best choice because it is a fully managed serverless platform that automatically scales from zero based on HTTP request load, minimizing operational overhead. It abstracts away infrastructure management, supports containerized applications, and charges only for resources used during request processing, aligning perfectly with the requirement to auto-scale based on HTTP traffic.

Exam trap

The trap here is that candidates often choose GKE or Compute Engine for 'auto-scaling' without recognizing that serverless options like Cloud Run offer the same capability with significantly less operational overhead for HTTP-based workloads.

How to eliminate wrong answers

Option A is wrong because Compute Engine managed instance groups with autoscaling require managing virtual machines, patching OS, and configuring scaling policies, which increases operational overhead compared to serverless options. Option B is wrong because Google Kubernetes Engine (GKE) introduces cluster management, node patching, and container orchestration complexity, which is not minimal operational overhead for a simple HTTP workload. Option C is wrong because Cloud Functions is designed for event-driven, short-lived functions, not for running a monolithic application that typically requires a persistent runtime environment and longer request handling.

31
MCQmedium

A company is migrating a monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single Compute Engine instance and stores session state in local memory. The migration must support horizontal scaling and high availability. What should the company do to manage session state in the new architecture?

Answer options not yet available.

Why this answer

Migrating to a stateless architecture with Cloud Memorystore for Redis allows the application to scale horizontally without session state being tied to any single pod. By externalizing session state to a managed, highly available Redis service, any pod can handle any request, which is essential for high availability and autoscaling in GKE.

Exam trap

Google Cloud often tests the distinction between 'making the application stateless' versus 'using sticky sessions or StatefulSets'—the trap here is that candidates may think session affinity (Option C) is sufficient for high availability, but it actually creates a single point of failure at the pod level.

How to eliminate wrong answers

Option B is wrong because StatefulSets with headless services are designed for stateful workloads that require stable network identities and persistent storage, not for managing session state in a horizontally scalable stateless application. Option C is wrong because GKE Ingress with session affinity (sticky sessions) ties a client to a specific pod, which prevents true horizontal scaling and high availability—if that pod fails, the session is lost. Option D is wrong because Cloud SQL is a relational database not optimized for high-speed session state access; using it for session storage would introduce latency and unnecessary overhead compared to an in-memory data store like Redis.

32
MCQhard

A company is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that each microservice can only communicate with specific other microservices, and they need to enforce this at the network level. They also want to minimize operational overhead. Which approach should they use?

Answer options not yet available.

Why this answer

Kubernetes NetworkPolicies are the native, low-overhead way to enforce pod-level network segmentation in GKE. They allow you to define which pods can communicate based on labels and namespaces, and they are enforced by the CNI plugin. This meets the requirement for fine-grained control with minimal operational effort compared to a service mesh or node-level firewall rules.

Exam trap

The trap here is assuming that VPC firewall rules can provide pod-level isolation, but they operate at the node level and cannot distinguish between pods.

33
Multi-Selecteasy

Which TWO of the following are benefits of using a VPC Service Controls perimeter?

Answer options not yet available.

Why this answer

VPC Service Controls perimeters are designed to mitigate data exfiltration risks for managed services such as BigQuery, Cloud Storage, and other Google Cloud APIs, so option A is correct because the perimeter restricts data movement across its boundary even when credentials are valid. Option E is also correct because a perimeter defines an authorized boundary (based on VPC networks, projects, and access levels) from which managed services can be reached, effectively allowing access only from authorized VPC networks. Option B is wrong because VPC Service Controls is not a network firewall for Compute Engine instances; that role belongs to VPC firewall rules and hierarchical firewall policies.

Option C is wrong because encryption in transit between on-premises and Google Cloud is handled by mechanisms such as Cloud VPN, Cloud Interconnect with MACsec, or application-layer TLS, not by VPC Service Controls. Option D is wrong because VPC Service Controls complements rather than replaces IAM; IAM still governs identities and permissions, while the perimeter adds an independent context-aware boundary.

Exam trap

Google Cloud often tests the misconception that VPC Service Controls are a firewall or encryption mechanism, when in fact they are a context-aware access boundary that works alongside IAM and network controls.

How to eliminate wrong answers

Option B is wrong because VPC Service Controls do not act as a network firewall; they control access to managed services via API-level policies, not packet filtering for Compute Engine instances, which is handled by VPC firewall rules. Option C is wrong because encryption of data in transit between on-premises and Google Cloud is provided by protocols like TLS or IPSec VPNs, not by VPC Service Controls, which focus on access boundaries. Option D is wrong because VPC Service Controls do not replace IAM; they complement IAM by adding a context-aware perimeter layer, while IAM still governs individual permissions on resources.

34
MCQmedium

You are deploying a new version of a microservices application to a GKE cluster. The deployment must be released to a small subset of users first, and if errors occur, traffic must automatically revert to the previous version. You also need to monitor the error rate and latency of the new version. Which approach should you use?

Answer options not yet available.

Why this answer

Anthos Service Mesh offers advanced traffic management, including canary deployments with precise traffic splitting and automated rollback triggered by monitoring metrics. This aligns with the need to release to a subset, monitor, and revert automatically. The other options lack either the fine-grained traffic control or the automation required.

Exam trap

The trap here is assuming that a Kubernetes rolling update or Ingress can perform canary releases with automatic rollback, but they lack native traffic splitting and metric-based automation.

35
MCQeasy

A company has a Cloud Run service that processes images uploaded by users. The service reads the images from a Cloud Storage bucket and writes processed images to another bucket. The team recently updated the service to use a custom service account named 'image-processor-sa' with minimal permissions. After the update, the service fails with permission errors when trying to read from the source bucket. The team verified that the service account has the Storage Object Viewer role on the source bucket and Storage Object Creator role on the destination bucket. What should the architect do to resolve the issue?

Answer options not yet available.

Why this answer

The error occurs because the Cloud Run service is not using the custom service account 'image-processor-sa' despite it being created and granted permissions. By default, Cloud Run uses the Compute Engine default service account unless explicitly overridden. Redeploying with the --service-account flag attaches the correct identity to the Cloud Run revision, allowing it to authenticate with Cloud Storage using the minimal permissions already assigned.

Exam trap

Google Cloud often tests the distinction between granting permissions to a service account versus actually attaching that service account to a resource; candidates mistakenly assume that creating and granting roles to a service account automatically makes it the active identity of the Cloud Run service.

How to eliminate wrong answers

Option B is wrong because the Cloud Run Invoker role grants permission to invoke the service (i.e., call its HTTP endpoint), not to read from Cloud Storage; it does not resolve the missing identity binding. Option C is wrong because assigning Storage Admin is an overly permissive solution that violates the principle of least privilege; the service account already has the necessary Object Viewer and Object Creator roles, so the issue is not about missing permissions but about the service not using the correct account. Option D is wrong because the Cloud Storage API is enabled by default when Cloud Storage is used; the error is not due to a disabled API but due to the service running under the wrong identity.

36
MCQmedium

A company is deploying a new application on Compute Engine and wants to automate the installation of a custom agent on every newly created VM in a specific project. Which Google Cloud service should they use?

Answer options not yet available.

Why this answer

VM Manager (OS Config) with a guest policy is the correct choice because it provides a native, agent-based configuration management service that can enforce the installation of a custom agent on all existing and newly created VMs in a project without requiring changes to instance templates or startup scripts. Guest policies are evaluated and applied at VM boot time and periodically thereafter, ensuring consistent agent deployment across the fleet.

Exam trap

The trap here is that candidates often confuse configuration management (OS Config guest policies) with provisioning-time automation (startup scripts in instance templates), assuming that startup scripts are sufficient for fleet-wide enforcement when they only apply at creation time and are not re-evaluated.

How to eliminate wrong answers

Option B is wrong because instance templates with startup scripts only apply to VMs created from that specific template; they do not automatically cover VMs created from other templates, images, or via other methods, and they do not enforce the agent on existing VMs. Option C is wrong because Deployment Manager is an infrastructure-as-code tool for deploying resources, not a configuration management service; it cannot automatically apply agent installation to VMs created outside its deployment scope. Option D is wrong because Cloud Build is a CI/CD service for building and testing artifacts, and it cannot be triggered directly by new VM creation events; there is no native event trigger for Compute Engine VM creation in Cloud Build.

37
MCQhard

A financial services company uses VPC Service Controls to protect their project containing BigQuery datasets and Cloud Storage buckets. They have a perimeter that includes the BigQuery service. Users report that they cannot export data from BigQuery to Cloud Storage using the web console. The export job fails with an access denied error. The team needs to allow exports while maintaining data exfiltration prevention. The users have the necessary IAM permissions (BigQuery Data Editor, Storage Object Admin) on the appropriate resources. What should the architect do?

Answer options not yet available.

Why this answer

VPC Service Controls perimeters enforce data exfiltration prevention by default, blocking egress from protected services (like BigQuery) to unprotected services (like Cloud Storage). Adding Cloud Storage to the same perimeter allows BigQuery to export data to Cloud Storage while still preventing data from leaving the perimeter. The users already have the necessary IAM roles (BigQuery Data Editor and Storage Object Admin), so the issue is solely the perimeter boundary, not permissions.

Exam trap

The trap here is that candidates often confuse IAM permissions with VPC Service Controls boundaries, assuming that granting the correct IAM roles (like Storage Object Admin) will resolve the access denied error, when in fact the error is caused by the perimeter blocking cross-service egress, not by insufficient IAM privileges.

How to eliminate wrong answers

Option B is wrong because removing BigQuery from the perimeter would disable all VPC Service Controls protections for BigQuery, exposing the datasets to data exfiltration risks, which contradicts the requirement to maintain data exfiltration prevention. Option C is wrong because access levels control ingress based on client attributes (e.g., IP address, device state) and do not affect egress permissions between services within a perimeter; the export failure is a perimeter boundary issue, not an access level restriction. Option D is wrong because the users already have the Storage Object Admin role at the bucket level (as stated in the question), and the error is an access denied from the perimeter, not from IAM; granting the same role again does not resolve the VPC Service Controls boundary.

38
Multi-Selecthard

Which THREE factors should be considered when choosing a Google Cloud region for deploying a low-latency application serving global users? (Choose three.)

Answer options not yet available.

Why this answer

Option A is correct because placing the region close to the user base reduces round-trip network latency, which is the primary driver of perceived responsiveness for a low-latency application serving global users. Option B is correct because not every Google Cloud service or machine type is available in every region, so you must confirm the required services (for example, specific compute SKUs or managed services) exist in the chosen region before deploying. Option D is correct because data residency and privacy regulations such as GDPR or CCPA can legally require that user data be stored and processed within specific jurisdictions, directly constraining which regions are permissible.

Option C is not among the marked answers because, while regional pricing differences exist, cost optimization is secondary to latency, service availability, and legal compliance when the explicit goal is low-latency global service. Option E is not among the marked answers because the number of zones affects fault tolerance and high availability rather than the latency experienced by global users, and zone count is not the deciding factor for region selection in this scenario.

Exam trap

This exam often tests the misconception that high availability (zones) is equivalent to low latency for global users, but zones only provide redundancy within a region, not reduced network distance for geographically distributed users.

How to eliminate wrong answers

Option C is wrong because while pricing differences exist between regions, cost is not a primary factor for a low-latency application serving global users; the focus should be on performance and latency optimization, not cost minimization. Option E is wrong because the number of zones in a region affects high availability and fault tolerance within that region, but it does not directly address latency for global users; for global low-latency, you would use multiple regions with global load balancing, not just multiple zones in a single region.

39
MCQeasy

A developer accidentally deleted a bucket in Cloud Storage. The bucket had object versioning enabled. How can the bucket and its objects be restored?

Answer options not yet available.

Why this answer

When a Cloud Storage bucket is deleted, even with versioning enabled, the bucket itself is removed along with its objects. Google Cloud does not provide a self-service restore option for deleted buckets; instead, it maintains an internal, undisclosed backup for a limited time (typically 7 days). Only Cloud Support can initiate the restoration process from this backup, making Option A the correct approach.

Exam trap

Google Cloud often tests the misconception that versioning provides a safety net for bucket deletion, but versioning only protects objects within an existing bucket—it does not prevent or undo the deletion of the bucket itself.

How to eliminate wrong answers

Option B is wrong because Cloud Storage does not have a 'Trash' feature for buckets; the Trash in Cloud Console is for Compute Engine resources like VM instances, not for storage buckets. Option C is wrong because bucket lock is a feature for retention policies (e.g., preventing object deletion or modification), not for undoing a bucket deletion; once a bucket is deleted, there is no 'undo deletion' operation. Option D is wrong because the `gsutil ls -a` command lists object versions within an existing bucket, not deleted buckets; there is no `gsutil` command to list or restore a deleted bucket.

40
MCQmedium

A company is using Cloud SQL for PostgreSQL and needs to run a one-time heavy analytical query that takes over 30 minutes and uses 100% CPU. The production database is serving user traffic with high QPS. What should the company do to run the query without impacting production?

Answer options not yet available.

Why this answer

A read replica in Cloud SQL for PostgreSQL is a separate instance that asynchronously replicates data from the primary. Running the heavy analytical query on the replica offloads the CPU-intensive workload from the production primary, ensuring user-facing traffic with high QPS is not impacted. The replica can handle read-only queries without affecting the primary's performance or availability.

Exam trap

Google Cloud often tests the distinction between a read replica (which offloads read traffic) and a clone (which is a point-in-time copy not kept in sync), leading candidates to choose the clone option because they confuse it with a replica's ability to handle production queries without impact.

How to eliminate wrong answers

Option A is wrong because even during low traffic hours, a query using 100% CPU on the primary instance will still degrade performance for any concurrent user requests, risking latency spikes or timeouts. Option C is wrong because pgBouncer is a connection pooler that manages database connections, not a query scheduler or resource isolator; it cannot queue or throttle a single heavy query to prevent CPU saturation. Option D is wrong because a clone creates a new primary instance from a snapshot, which requires provisioning time and does not provide ongoing replication; it is suitable for testing or development but not for running a one-time query without impacting production, as the clone is not kept in sync and the heavy query still runs on a separate instance that does not offload the primary's workload.

41
MCQeasy

Your company runs a critical application on Compute Engine instances in a managed instance group across three zones. The application writes logs to local disk. You are asked to improve the reliability of log retention and ensure logs are available in case of instance failure. You have already configured a health check that automatically recreates instances. However, after a recent zonal outage, logs from the affected instances were lost. You need to implement a solution that preserves logs even when instances are terminated. What should you do?

Answer options not yet available.

Why this answer

The Cloud Logging agent streams logs directly to Cloud Logging (now part of Google Cloud's operations suite), which stores logs independently of the Compute Engine instances. This ensures logs are preserved even if instances are terminated due to a zonal outage or health check recreation, as logs are sent to a centralized, durable logging service rather than being stored on local disk.

Exam trap

Google Cloud often tests the misconception that persistent disks or Cloud Storage buckets are sufficient for log durability, but the key requirement is centralized log management with automatic streaming, which only Cloud Logging provides without additional complexity or latency.

How to eliminate wrong answers

Option A is wrong because increasing local SSD size and retention period does not protect logs from instance termination; local SSDs are ephemeral and their data is lost when an instance is deleted or recreated. Option B is wrong because persistent disks are not automatically retained after instance deletion unless the 'delete-on-terminate' flag is set to false, and even then, logs would be tied to a specific disk that may not survive a zonal outage if not replicated; the question requires a solution that works across instance failures, not just disk retention. Option D is wrong because while gcsfuse can mount a Cloud Storage bucket, writing logs directly to a bucket introduces latency and potential consistency issues, and the bucket is not a log management solution; Cloud Logging is purpose-built for log ingestion, analysis, and retention.

42
Multi-Selectmedium

Your organization is moving a legacy monolithic application to Google Kubernetes Engine (GKE). The application currently runs on a single virtual machine with a local MySQL database. You need to design a cloud-native architecture that improves scalability and reliability. Which two actions should you take? (Choose TWO.)

Answer options not yet available.

Why this answer

Option B is correct because refactoring the monolith into microservices and deploying each as a separate Deployment in GKE enables independent scaling, rolling updates, and fault isolation, which directly improves scalability and reliability in a cloud-native architecture. Option D is correct because moving the local MySQL database to Cloud SQL for MySQL provides a managed, highly available, and automatically backed-up database service, decoupling state from the cluster and allowing the application tier to scale independently. Option A is not appropriate because a single large container on a custom machine type preserves the monolithic scaling and single-point-of-failure limitations rather than adopting cloud-native elasticity.

Option C is not the best choice because a basic LoadBalancer Service only provides L4 round-robin distribution and does not by itself deliver the architectural scalability and reliability improvements required. Option E is incorrect because a single Pod with multiple containers communicating via localhost tightly couples the components, prevents independent scaling, and keeps the database co-located with the application, undermining reliability.

Exam trap

Google Cloud often tests the misconception that simply containerizing a monolith or using a larger machine type is sufficient for cloud-native scalability, when in fact true scalability requires decoupling components into independently scalable units and separating stateful services like databases.

How to eliminate wrong answers

Option A is wrong because deploying the entire application in a single container with a large custom machine type does not improve scalability or reliability; it replicates the monolithic architecture's single point of failure and limits scaling to vertical scaling only, which is less flexible and cost-effective than horizontal scaling. Option C is wrong because exposing the application using a simple Service of type LoadBalancer with round-robin distribution is a valid networking pattern but does not address the core need to improve scalability and reliability of the application itself; it only distributes traffic at the network layer without addressing the monolithic database or application architecture. Option E is wrong because using a single Pod with multiple containers that communicate via localhost reduces latency but does not improve scalability or reliability; it still runs as a single unit that cannot scale independently, and a Pod failure would take down all containers together.

43
Multi-Selectmedium

A company is migrating an on-premises application to Google Cloud. The application consists of a web front end and a backend that uses a relational database. The company wants to minimize downtime during the migration and ensure that the database remains consistent. They plan to use a phased approach. Which TWO steps should they take to achieve a successful migration? (Choose two.)

Answer options not yet available.

Why this answer

Establishing a secure network connection and using Database Migration Service for continuous replication are critical for a low-downtime migration. The network connection enables data transfer, and Database Migration Service keeps the target in sync until cutover. These steps ensure minimal downtime and data consistency, unlike manual export/import or unrelated scaling measures.

Exam trap

The trap here is focusing on post-migration scaling or high availability features instead of the core steps needed to perform the migration with minimal downtime.

44
MCQmedium

A company uses preemptible VMs for batch processing. They notice that during peak hours, many instances are terminated before finishing their tasks. The operations team observes the output shown in the exhibit. Which action would best improve job completion rates without significantly increasing costs?

Answer options not yet available.

Why this answer

Using a mixed instance group with both preemptible and regular VMs allows the batch processing job to continue on regular VMs when preemptible VMs are terminated during peak hours. This balances cost and reliability: preemptible VMs handle most of the workload at low cost, while regular VMs act as a fallback to ensure job completion without the full expense of switching entirely to regular VMs.

Exam trap

Google Cloud often tests the misconception that simply adding more preemptible VMs or switching entirely to regular VMs is the solution, but the correct answer requires a hybrid approach that balances cost and reliability using instance groups with a mix of VM types.

How to eliminate wrong answers

Option A is wrong because simply increasing the number of preemptible instances does not address the root cause of terminations during peak hours; it only increases the likelihood of more terminations and may lead to higher costs from repeated restarts. Option B is wrong because sole-tenant nodes provide dedicated hardware but do not prevent preemption; they are used for compliance or licensing, not for improving job completion rates of preemptible VMs. Option D is wrong because committed use discounts require a 1-year commitment and apply to regular VMs, not preemptible VMs, so they would increase costs without solving the termination issue.

Option E is wrong because switching all critical jobs to regular VMs would significantly increase costs, as regular VMs are more expensive than preemptible VMs, and the question asks for an improvement without significantly increasing costs.

45
MCQhard

An organization wants to enforce that all Compute Engine VMs are created with specific disk encryption keys. Which policy mechanism should they use?

Answer options not yet available.

Why this answer

The Organization Policy constraint `constraints/compute.restrictDiskEncryptionKeyTypes` allows administrators to enforce that all Compute Engine VMs must use specific disk encryption key types (e.g., CMEK or CSEK). This policy is evaluated at resource creation time and blocks any VM that does not comply with the allowed key types, providing a preventive control rather than a reactive one.

Exam trap

The trap here is confusing IAM permissions (who can do something) with Organization Policy constraints (what is allowed to be done), leading candidates to choose IAM roles instead of the correct policy mechanism.

How to eliminate wrong answers

Option B is wrong because IAM roles with `compute.diskEncryptionKey` permissions control who can set or view encryption keys, but they do not enforce which key types must be used on VMs; IAM is an authorization mechanism, not a policy enforcement mechanism. Option C is wrong because VPC Service Controls are designed to protect data exfiltration by controlling access to Google Cloud APIs from outside a VPC perimeter, not to enforce disk encryption key types on Compute Engine VMs. Option D is wrong because Cloud Scheduler is a cron-like job scheduler that can trigger compliance checks, but it is a reactive, after-the-fact mechanism and cannot prevent non-compliant VM creation in real time.

46
MCQmedium

Your team has deployed a microservices application on Google Kubernetes Engine (GKE) with multiple services communicating via internal ClusterIP services. You notice that some requests between services are failing intermittently with 'connection refused' errors. The services are defined with readiness probes. What is the most likely cause?

Answer options not yet available.

Why this answer

The 'connection refused' error indicates that the client is attempting to connect to a port on which no process is listening. In GKE, when a readiness probe fails, Kubernetes removes the pod's IP from the corresponding ClusterIP service's endpoints. If all pods for a service fail their readiness probes, the service has no healthy endpoints, and any request to the ClusterIP will be refused because there is no backend to accept the connection.

This matches the intermittent nature of the issue, as pods may temporarily fail the probe and then recover.

Exam trap

Google Cloud often tests the distinction between readiness and liveness probes, where candidates may incorrectly assume that a failing liveness probe (which restarts the pod) is the cause of 'connection refused', but the key is that readiness probes control endpoint membership, directly causing the error when all endpoints are removed.

How to eliminate wrong answers

Option B is wrong because VPC peering is used for connectivity between separate VPC networks, not for internal service-to-service communication within the same GKE cluster; ClusterIP services are inherently reachable within the cluster without any peering. Option C is wrong because NodePort and LoadBalancer are service types for external exposure, not for internal pod-to-pod communication; port conflicts are not a typical cause of 'connection refused' errors within a cluster, and NodePort does not affect internal ClusterIP functionality. Option D is wrong because an Ingress resource is used for external HTTP/S traffic routing to services, not for internal service-to-service communication; the absence of an Ingress has no impact on direct ClusterIP-based communication between microservices.

47
MCQeasy

You are designing a solution to store and serve static web content for a global audience. The content consists of HTML, CSS, JavaScript, and images. You need to ensure low latency and high availability. Which Google Cloud service should you use?

Answer options not yet available.

Why this answer

Cloud Storage with a multi-region bucket provides durable, highly available storage, and Cloud CDN caches content globally to reduce latency. This is the simplest and most cost-effective solution for static web content. The other options involve unnecessary compute resources or management overhead.

Exam trap

The trap here is overcomplicating the solution by using compute services when a simple storage and CDN combination suffices.

48
MCQmedium

Your organization has a policy that all Compute Engine instances must have specific labels (env, team, cost-center) applied. You want to enforce this automatically when instances are created. What should you do?

Answer options not yet available.

Why this answer

Organization Policy Service with a custom constraint allows you to enforce that all Compute Engine instances must have specific labels (env, team, cost-center) at creation time. This is a preventive control that blocks creation of non-compliant instances, unlike reactive or permission-based approaches. Custom constraints use the `compute.googleapis.com/instance` resource type and can require label keys or values using CEL (Common Expression Language) syntax.

Exam trap

The trap here is that candidates often choose reactive solutions (like Cloud Functions or alerts) because they seem simpler, but the exam emphasizes preventive enforcement using Organization Policy constraints for compliance-driven requirements.

How to eliminate wrong answers

Option A is wrong because Cloud Audit Logs and metric-based alerts are reactive — they only detect non-compliant instances after creation, not prevent them, and do not enforce the policy automatically. Option B is wrong because a Cloud Function that listens for instance creation events and adds labels is also reactive; it can fail or be bypassed, and the instance is created without labels initially, violating the policy. Option C is wrong because removing the default `compute.instances.create` permission would prevent all instance creation, not just unlabeled ones, and a custom IAM role cannot enforce label requirements at creation time — it only controls who can create instances, not what labels they must include.

49
MCQeasy

A company is migrating a monolithic application to Google Cloud. They want to minimize changes to the application code while taking advantage of Cloud Run for serverless containers. Which approach should they take?

Answer options not yet available.

Why this answer

Cloud Run can run any containerized application that listens on HTTP requests on port 8080. By packaging the existing monolithic application as a container and adding a lightweight web server (e.g., Express, Flask, or Nginx), the company can deploy it to Cloud Run with minimal code changes, leveraging serverless scaling and pay-per-use pricing without refactoring into microservices.

Exam trap

Google Cloud often tests the misconception that serverless containers require microservices architecture, but Cloud Run can run any containerized application, including a monolithic one, as long as it listens for HTTP requests.

How to eliminate wrong answers

Option A is wrong because App Engine standard environment requires the application to conform to specific runtime constraints (e.g., Java Servlet, Python WSGI) and does not support arbitrary containers, so it would likely require significant code changes. Option B is wrong because lifting and shifting to Compute Engine instances behind a load balancer does not minimize changes but also fails to take advantage of serverless containers, requiring manual management of VMs, scaling, and patching. Option C is wrong because refactoring the monolithic application into microservices is a major architectural change that contradicts the requirement to minimize changes to the application code.

50
MCQhard

A company runs a stateful application on a single Compute Engine instance with a persistent disk. They need to ensure that the application can recover quickly in case of a zone failure. The recovery point objective (RPO) is 5 minutes, and the recovery time objective (RTO) is 15 minutes. Which approach should they take?

Answer options not yet available.

Why this answer

A regional persistent disk synchronously replicates data across two zones, ensuring an RPO of zero. By automating failover to a standby instance in the other zone, you can achieve the 15-minute RTO. This is the most suitable solution for a stateful application requiring zone failure recovery.

The other options either do not meet the RPO/RTO or require significant application changes.

Exam trap

The trap here is assuming that frequent snapshots can meet a 5-minute RPO, but snapshot frequency is limited and restore times may exceed the RTO.

51
MCQeasy

A company wants to store customer transaction logs for 7 years for compliance. The logs are accessed rarely but must be retrievable within 24 hours. Which storage option is most cost-effective?

Answer options not yet available.

Why this answer

Cloud Storage Archive class is the most cost-effective option for data that is accessed rarely and requires retrieval within 24 hours. Archive class offers the lowest storage cost among Google Cloud Storage classes, with a default retrieval time of 12 hours, which comfortably meets the 24-hour requirement. This makes it ideal for long-term compliance retention of transaction logs that are infrequently accessed.

Exam trap

Google Cloud often tests the misconception that Coldline is the cheapest storage class, but Archive class actually has the lowest storage cost, with retrieval times up to 24 hours, making it the correct choice for rarely accessed data with flexible retrieval requirements.

How to eliminate wrong answers

Option B (Cloud Storage Nearline class) is wrong because it is designed for data accessed less than once a month, with a 30-day minimum storage duration, and its storage cost is higher than Archive, making it less cost-effective for 7-year retention. Option C (Cloud Storage Coldline class) is wrong because it targets data accessed less than once a quarter, with a 90-day minimum storage duration, and its storage cost is higher than Archive, so it is not the most cost-effective for rarely accessed logs. Option D (Cloud Storage Standard class) is wrong because it is optimized for frequently accessed data with no minimum storage duration and has the highest storage cost, making it prohibitively expensive for long-term archival of rarely accessed logs.

52
Multi-Selecteasy

What are two best practices for designing a scalable Kubernetes architecture on GKE?

Answer options not yet available.

Why this answer

Option C is correct because enabling Horizontal Pod Autoscaling (HPA) lets GKE automatically adjust the number of pod replicas based on metrics such as CPU utilization or custom metrics, which is essential for handling variable load in a scalable architecture. Option D is correct because using multiple node pools with different machine types allows you to right-size workloads, isolate resource-intensive or specialized workloads (e.g., GPU, memory-optimized), and scale each pool independently, improving both efficiency and scalability. Option A is incorrect because StatefulSets are designed for stateful applications requiring stable network identities and persistent storage, not stateless workloads, which are better served by Deployments.

Option B is incorrect because disabling the Cluster Autoscaler prevents nodes from being added or removed automatically as demand changes, undermining scalability. Option E is incorrect because a single-zone cluster concentrates resources in one zone, reducing availability and limiting the ability to scale resiliently across zones.

Exam trap

Google Cloud often tests the misconception that StatefulSets are interchangeable with Deployments for stateless apps, or that disabling Cluster Autoscaler simplifies management, but the trap here is that candidates may overlook the need for multi-zonal clusters and autoscaling mechanisms to achieve true scalability and resilience in GKE.

How to eliminate wrong answers

Option A is wrong because StatefulSets are designed for stateful applications (e.g., databases) that require stable network identities and persistent storage, not for stateless applications which should use Deployments or ReplicaSets for easier scaling and rolling updates. Option B is wrong because disabling Cluster Autoscaler prevents the cluster from automatically adding or removing nodes based on pod resource demands, leading to either resource starvation or wasted capacity, which undermines scalability. Option E is wrong because using a single zone cluster creates a single point of failure and limits scalability; best practices for high availability and scalability on GKE involve multi-zonal or regional clusters to distribute workloads across failure domains.

53
Multi-Selecthard

Which THREE actions can help reduce costs for a BigQuery workload that runs frequent, ad-hoc analytical queries on a large dataset?

Answer options not yet available.

Why this answer

Option B is correct because partitioning the table by a date or timestamp column lets BigQuery prune irrelevant partitions, so ad-hoc queries that filter on that column scan far less data and incur lower on-demand query costs. Option C is correct because materialized views precompute and cache the results of common aggregation queries, so repeated ad-hoc aggregations read the much smaller materialized view instead of rescanning the full large dataset. Option D is correct because clustering on columns frequently used in filter clauses co-locates related data in storage blocks, allowing BigQuery to skip blocks that don't match the filter and further reduce bytes scanned.

Option A is not correct because automatic schema detection only simplifies loading data and has no effect on query cost. Option E is not correct because flat-rate pricing with reserved slots provides predictable capacity billing rather than reducing the cost of a sporadic ad-hoc query workload, which is typically cheaper on on-demand pricing.

Exam trap

Google Cloud often tests the distinction between cost-reduction techniques that reduce bytes scanned (partitioning, clustering, materialized views) versus pricing model choices (flat-rate vs. on-demand), leading candidates to mistakenly select flat-rate pricing as a cost-saving action for ad-hoc queries.

How to eliminate wrong answers

Option A is wrong because enabling automatic schema detection is a convenience feature for data ingestion, not a cost-reduction mechanism; it does not reduce the amount of data scanned or query costs. Option E is wrong because flat-rate pricing with reserved slots provides predictable billing and is beneficial for steady-state workloads, but it does not inherently reduce costs for frequent ad-hoc queries—it may actually increase costs if the workload does not fully utilize the reserved capacity, and it does not optimize per-query data scanning.

54
MCQmedium

A company is using Cloud Load Balancing with backend services across multiple regions. They notice that traffic is not being evenly distributed and some backends are overloaded. Which configuration should they check?

Answer options not yet available.

Why this answer

Session affinity (sticky sessions) directs all requests from a single client to the same backend instance. If enabled, this can cause uneven load distribution because certain clients may generate disproportionately more traffic, overloading their pinned backends while others remain underutilized. Disabling or properly configuring session affinity allows the load balancer to distribute requests based on its default algorithm (e.g., round-robin or least-connections), improving balance across backends.

Exam trap

Google Cloud often tests the misconception that health checks or firewall rules are responsible for load distribution, when in fact session affinity is the primary configuration that can cause uneven traffic patterns by overriding the default balancing algorithm.

How to eliminate wrong answers

Option B is wrong because firewall rules control allowed traffic to/from backends but do not influence how the load balancer distributes incoming requests among healthy instances. Option C is wrong because Cloud CDN caching reduces load on backends by serving cached content at edge locations, but it does not affect the distribution of requests that reach the load balancer's backend pool. Option D is wrong because health check frequency determines how often the load balancer probes backend health, affecting failover speed but not the balancing algorithm or distribution of traffic among healthy backends.

55
MCQhard

A company runs a batch processing application on Compute Engine that reads data from Cloud Storage and writes results to BigQuery. The application runs on a managed instance group (MIG) with autoscaling. Recently, job failures occurred because instances could not authenticate to BigQuery. You need to ensure that the instances have the necessary permissions without embedding credentials in the application. What should you do?

Answer options not yet available.

Why this answer

Assigning a dedicated service account with the BigQuery Data Editor role to the managed instance group allows instances to obtain credentials from the metadata server, adhering to security best practices. This avoids key management and ensures least privilege. The other options either use insecure key files or grant excessive permissions to the default service account.

Exam trap

The trap here is thinking that you must use a service account key file for authentication, but Compute Engine instances can use their attached service account via the metadata server.

56
MCQhard

A company uses Cloud Bigtable for time-series data. They experience high latency and uneven load distribution across nodes. What is the most likely cause?

Answer options not yet available.

Why this answer

Cloud Bigtable partitions data by row key range and distributes tablets across nodes. A single row key pattern (e.g., monotonically increasing timestamps) causes all writes to target the same tablet, creating a hot spot. This leads to uneven load distribution and high latency because one node is overwhelmed while others remain idle.

Exam trap

Google Cloud often tests the misconception that column families or read consistency levels are the root cause of performance issues, when in fact row key design is the primary driver of load distribution in Bigtable.

How to eliminate wrong answers

Option A is wrong because storing data in a single column family does not cause uneven load distribution; column families affect storage and read performance but not row key distribution. Option B is wrong because strong reads (read-after-write consistency) add latency but do not cause uneven load distribution across nodes; the issue is about write hot spotting, not read consistency. Option D is wrong because having too many nodes would reduce load per node, not increase latency or cause uneven distribution; the cluster would be over-provisioned, not hot-spotted.

57
MCQhard

A company runs multiple microservices on Cloud Run. Each service uses a Serverless VPC Access connector to connect to a shared Cloud Memorystore for Redis instance (standard tier) in a VPC network. The Redis instance is configured with a firewall rule that allows TCP connections on port 6379 from the VPC connector's subnet (10.8.0.0/28). After a recent code update, the order-service fails to connect to Redis, while the user-service continues to work. The error logs in order-service show 'connection refused'. The engineer verifies that both services use the same VPC connector, the same Redis instance IP, and the same service account. The VPC connector's metrics show no errors. What is the most likely cause?

Answer options not yet available.

Why this answer

The order-service successfully connects to the same Redis instance before the code update. After the update, it fails with 'connection refused', while the user-service still works. Since both services share the same networking configuration and the firewall only allows port 6379, the most likely cause is that the order-service code now attempts to connect on a different port (e.g., 6380) that is not allowed by the firewall.

Other options would affect both services or are inconsistent with the symptoms.

58
MCQeasy

A company wants to store backup data that is accessed rarely but must be available for retrieval within minutes. Which Cloud Storage class is appropriate?

Answer options not yet available.

Why this answer

Nearline storage is designed for data accessed less than once a month but requires retrieval within minutes, making it ideal for backup data that needs quick availability. It offers lower cost than Standard storage while still supporting sub-minute retrieval times, aligning with the scenario's access and latency requirements.

Exam trap

Google Cloud often tests the distinction between 'retrieval within minutes' and 'retrieval within hours' to confuse candidates into selecting Coldline or Archive, assuming 'rarely accessed' automatically means the cheapest option, but the key is the specific retrieval time requirement.

How to eliminate wrong answers

Option A is wrong because Standard storage is for frequently accessed data (e.g., multiple times per month) and costs more, making it unsuitable for rarely accessed backups. Option C is wrong because Coldline storage is for data accessed less than once a quarter, with retrieval times that can be minutes to hours, but it is optimized for even colder data than Nearline, and its cost structure (including retrieval fees) is less appropriate for backups needing consistent minute-level access. Option D is wrong because Archive storage is for long-term retention with retrieval times typically in hours (e.g., 1-12 hours), not minutes, and is intended for data that is accessed extremely rarely, such as regulatory archives.

59
MCQhard

A retail company runs a stateful batch application on a managed instance group. The application writes intermediate results to the boot disk of each VM and takes several hours to complete. The operations team wants rolling updates that replace instances with a new image, but must guarantee that no in-flight job is interrupted. Which configuration should you recommend?

Answer options not yet available.

Why this answer

A stateful managed instance group combined with an opportunistic update gives the operations team explicit control over when each instance is replaced. Because replacements occur only when an instance is deliberately deleted or recreated, the team can wait for each batch job to finish, update the image on the template, and then replace instances one at a time without interrupting work.

Exam trap

The trap here is thinking that proactive rolling updates plus health checks will gracefully wait for long-running work, when health checks only govern traffic serving and not job completion.

60
Multi-Selectmedium

An organization wants to monitor network traffic between VMs in a VPC for troubleshooting. Which TWO services can provide this?

Answer options not yet available.

Why this answer

Packet Mirroring (Network Intelligence Center) (B) is correct because it captures full packet payloads from specified VM instances in a VPC and forwards them to a collector instance for deep troubleshooting and analysis of traffic between VMs. VPC Flow Logs (C) is correct because it records IP flow information (5-tuple, bytes, packets, timestamps) for traffic to and from VM instances, subnets, and VPCs, providing visibility into network traffic patterns for troubleshooting. Cloud Audit Logs (A) only records administrative and data-access API activity, not network traffic between VMs.

Cloud Monitoring (D) collects metrics and uptime checks but does not capture network flow or packet-level traffic data. Cloud Logging (E) stores and queries log entries but is not itself a network traffic capture service.

Exam trap

Google Cloud often tests the distinction between services that capture raw packet data (Packet Mirroring) versus those that log only metadata or metrics (VPC Flow Logs). Candidates may incorrectly think only one is correct, but both can be used for troubleshooting network traffic between VMs, depending on the depth of information needed.

How to eliminate wrong answers

Option A is wrong because Cloud Audit Logs record administrative actions and API calls (e.g., who created a VM), not the actual network traffic between VMs. Option D is wrong because Cloud Monitoring collects metrics (e.g., CPU utilization, packet counts) and provides dashboards and alerts, but it does not capture or inspect individual packets or flows. Option E is wrong because Cloud Logging ingests log entries from various sources (e.g., application logs, system logs), but it does not capture network packet data or flow-level details between VMs.

61
MCQeasy

A developer needs to deploy a stateful application that requires persistent storage across pod restarts in Google Kubernetes Engine. Which resource should they use?

Answer options not yet available.

Why this answer

A PersistentVolumeClaim (PVC) is the correct resource because it allows a pod to request persistent storage that survives pod restarts. In GKE, a PVC binds to a PersistentVolume (PV), which can be backed by Compute Engine persistent disks, ensuring data remains available even if the pod is rescheduled or restarted.

Exam trap

The trap here is that candidates confuse ephemeral volumes (EmptyDir) with persistent storage, or assume ConfigMaps/Secrets can store application data, when in fact they are for configuration and secrets only.

How to eliminate wrong answers

Option A is wrong because a ConfigMap is used to inject configuration data (e.g., environment variables, files) into pods, not for persistent storage. Option B is wrong because an EmptyDir volume is ephemeral—it is created when a pod starts and is deleted when the pod is removed, so data does not persist across pod restarts. Option C is wrong because a Secret is designed to store sensitive data (e.g., passwords, tokens) and is not a storage volume for application data.

62
Multi-Selecthard

A company is designing a highly available architecture for a stateful application on Compute Engine. They need to protect against zonal failures. Which THREE steps should they take?

Answer options not yet available.

Why this answer

Option B is correct because a global external Application Load Balancer (or global external proxy Network Load Balancer) with health checks distributes traffic across healthy backends in multiple zones and automatically stops routing to unhealthy instances, providing resilience against a zonal failure. Option D is correct because regional persistent disks synchronously replicate data between two zones in the same region, so a stateful application's data remains available if one zone fails. Option E is correct because a managed instance group (MIG) spread across multiple zones maintains capacity and automatically recreates instances in surviving zones when a zone becomes unavailable.

Option A is wrong because storing session state only in memory ties the state to a single instance and is lost on failure, breaking high availability. Option C is wrong because a single-zone instance group has no protection against a zonal outage.

Exam trap

A common misconception is that in-memory session state (Option A) is sufficient for high availability, but it fails because state is lost on instance failure; instead, external session stores (e.g., Cloud Memorystore or Cloud Spanner) are needed for stateful applications on Google Cloud.

How to eliminate wrong answers

Option A is wrong because storing session state in memory is volatile and does not survive instance or zone failures, making it unsuitable for high availability across zones. Option C is wrong because a single zone instance group cannot protect against zonal failures; it concentrates all instances in one zone, so a zonal outage would take down the entire application.

63
MCQeasy

A developer is trying to deploy a Compute Engine instance from a Cloud Build step. The build fails with the above error. What is the problem?

Answer options not yet available.

Why this answer

The error occurs because Cloud Build needs to impersonate the Compute Engine default service account to create a VM instance. The Cloud Build service account requires the 'iam.serviceAccounts.actAs' permission on the target service account to delegate its identity. Without this permission, the build step fails even if the Cloud Build service account has 'compute.instances.create' permission.

Exam trap

Google Cloud often tests the subtle distinction between having resource-level permissions (like 'compute.instances.create') and the 'actAs' permission required to impersonate a service account, leading candidates to incorrectly choose the missing resource permission.

How to eliminate wrong answers

Option A is wrong because service account quotas are separate from IAM permissions; exceeding a quota would produce a different error (e.g., 'quota exceeded'), not a permission denied error. Option B is wrong because the error message specifically indicates an 'actAs' permission issue, not a missing 'compute.instances.create' permission; if that were the problem, the error would reference 'compute.instances.create' directly. Option D is wrong because Cloud Build uses its own service account for execution, not the developer's personal account; the error is about the Cloud Build service account's permissions, not the developer's.

64
MCQeasy

A company stores sensitive data in Cloud Storage and wants to enforce encryption at rest using customer-managed keys. Which Google Cloud service should they use to manage the keys?

Answer options not yet available.

Why this answer

Cloud KMS (Key Management Service) is the correct choice because it is the native Google Cloud service for managing cryptographic keys, including customer-managed encryption keys (CMEK). It allows you to create, rotate, and control access to keys used to encrypt data at rest in Cloud Storage, and it integrates directly with Cloud Storage's CMEK feature. Cloud HSM is a hardware-backed key management option but is built on top of Cloud KMS, not a separate service for key management.

Exam trap

The trap here is that candidates confuse Cloud HSM as a separate key management service, but Cloud HSM is actually a hardware-backed key storage option that requires Cloud KMS for key management, not a replacement for it.

How to eliminate wrong answers

Option A is wrong because Cloud HSM is a hardware security module service that provides FIPS 140-2 Level 3 validated key storage, but it is an add-on to Cloud KMS, not a standalone key management service; you still use Cloud KMS to manage the keys stored in HSM. Option B is wrong because Secret Manager is designed to store and manage secrets such as API keys, passwords, and certificates, not for managing encryption keys used for data at rest in Cloud Storage. Option D is wrong because IAM (Identity and Access Management) is a service for managing access control and permissions, not for creating, storing, or managing encryption keys.

65
MCQhard

A company runs a critical application on a managed instance group (MIG) with autoscaling enabled. The application experiences sudden traffic spikes, and the team wants to ensure that new instances are added quickly while maintaining cost efficiency. They also want to avoid over-provisioning. Which autoscaling metric should they use?

Answer options not yet available.

Why this answer

HTTP load balancing serving capacity is the best metric for scaling a web application behind an HTTP(S) load balancer because it directly measures the load on the backend instances. It enables rapid scaling in response to traffic spikes and helps maintain cost efficiency by avoiding over-provisioning. Other metrics may not accurately reflect the incoming traffic or may introduce delays.

Exam trap

The trap here is assuming that CPU utilization is always the most responsive metric for autoscaling, but for web applications behind a load balancer, serving capacity provides a more direct and immediate signal of traffic load.

Ready to test yourself?

Try a timed practice session using only Manage implementation of cloud architecture questions.