PCA · domain
Manage and provision cloud infrastructure
This domain covers deploying and configuring Google Cloud resources: GKE workload identity, Cloud SQL high availability, CMEK and key rotation, and matching Cloud Monitoring and Cloud Logging tools to their purpose. Questions are scenario-based, asking you to pick the correct configuration, IAM binding, or managed service for a stated requirement.
Focused practice
Practice Manage and provision cloud infrastructure questions
Scored sessions drawing only from this domain — pick a length below.
Start 20-question practice test →What this domain covers
What to know about Manage and provision cloud infrastructure
Be able to select and configure the right managed service for a stated requirement: Workload Identity for GKE API access, regional Cloud SQL for failover, CMEK with rotation for encryption, and the correct Monitoring or Logging tool. The key is matching the requirement to the exact feature.
Binding Kubernetes service accounts to IAM service accounts via GKE Workload Identity Federation for keyless API access
Configuring Cloud SQL for MySQL with a regional instance and automatic failover to a standby zone
Encrypting Cloud Storage objects with CMEK in Cloud KMS and setting rotation schedules
Selecting Cloud Monitoring metrics, uptime checks, alerting policies, and Cloud Logging sinks for observability
Watch out for
Common Manage and provision cloud infrastructure exam traps
- ▸Choosing service account JSON keys for GKE pods instead of Workload Identity, which avoids key management and rotation entirely.
- ▸Picking a zonal Cloud SQL instance for high availability; automatic failover requires a regional instance with a standby.
- ▸Assuming CMEK rotation re-encrypts existing objects; Cloud KMS rotates future key versions while old data stays under prior versions.
Question index
All Manage and provision cloud infrastructure questions (91)
Click any question to see the full explanation, or start a practice session above.
A company is deploying a microservices application on Google Kubernetes Engine (GKE). The architect needs to ensure that the cluster can automatically scale nodes based on pod resource requests and that pods are scheduled efficiently across nodes. The company also wants to minimize costs by scaling down when demand is low. Which two configurations should the architect implement? (Choose two.)
Medium2Refer to the exhibit. A user (ops@example.com) is unable to create a new VPC network in the project. What should the administrator verify first?
Easy3A startup is deploying a new web application on Google Kubernetes Engine (GKE). They want to expose the application to the internet with a single global IP address and automatically route users to the closest regional cluster. They also want to minimize operational overhead. Which GKE feature should they use?
Easy4Your company runs a critical application on Compute Engine instances in us-central1. The application requires low latency between instances that are all in the same region. You notice that network latency between instances varies and sometimes spikes. You want to ensure consistent low-latency communication. You currently use external IP addresses for communication between instances. What should you do?
Easy5A startup is deploying a containerized application on Google Kubernetes Engine (GKE). The development team wants to minimize operational overhead for managing the Kubernetes control plane and nodes. They also want to ensure that nodes are automatically upgraded and repaired. Which GKE mode should they use?
Easy6A company is migrating its on-premises data warehouse to BigQuery. The data is currently stored in several CSV files on a Compute Engine instance. The company needs to load the data into BigQuery once and then perform complex analytical queries. The data volume is about 10 TB, and the company wants to minimize cost and loading time. Which approach should the architect recommend?
Medium7Which THREE are best practices for managing secrets (e.g., API keys, passwords) in Google Cloud? (Select exactly 3.)
Hard8Drag and drop the steps to configure IAM roles for a service account to access Cloud Storage from a Compute Engine instance into the correct order.
Medium9Which THREE are required to configure Workload Identity for a GKE cluster? (Choose 3)
Hard10A company runs a service on Cloud Run that needs to access a Cloud SQL instance via private IP. Both are in the same VPC network. The service cannot connect to the database. What is the most likely cause?
Hard11A company wants to migrate an on-premises Oracle database to Google Cloud. They need high availability and want to minimize application changes. Which service should they use?
Medium12A company has two VPC networks in the same project: 'vpc-prod' and 'vpc-dev'. They want to allow communication between instances in both VPCs. What is the simplest method?
Medium13Which TWO statements about Google Cloud VPC networks are true? (Choose two.)
Easy14A company runs a microservices application on Google Kubernetes Engine (GKE). Each service is deployed as a Deployment with resource requests and limits. After deploying a new version of a service, the pods start crashing with OOMKilled. The team increased the memory limits in the Deployment manifest, but the pods still crash after a few minutes. The cluster has cluster autoscaling enabled. The node pool has sufficient capacity. What is the most likely cause of the issue?
Medium15A developer needs to programmatically create and manage Compute Engine instances. Which Google Cloud service should they use to authenticate and authorize service accounts?
Easy16An organization has multiple projects in Google Cloud and wants to centralize logging and monitoring for all projects. They need to aggregate logs from all projects into a single project for analysis. Which approach should they use?
Hard17A developer runs the command above. The instance is created successfully, but cannot be reached via HTTP from the internet. What is the most likely cause?
Medium18A media company stores 400 TB of video assets in a Cloud Storage bucket in the europe-west1 region. Editors in Tokyo and São Paulo complain about slow first-byte times when previewing assets. The architect must improve read latency for these global users while keeping a single canonical copy of each object and avoiding application changes that rewrite object paths. Which approach best meets these requirements?
Hard19A startup is deploying a new web application on Compute Engine. The application runs on a managed instance group and must be accessible from the internet over HTTP and HTTPS. The security team requires that the application be protected against common web attacks such as SQL injection and cross-site scripting. Which Google Cloud service should the architect use to meet these requirements?
Easy20Your company runs a stateful web application on Compute Engine instances in a managed instance group (MIG) with autoscaling based on CPU utilization. The application maintains session state in memory on each instance. Recently, users have been experiencing session timeouts and data loss during scaling events. Additionally, the application's performance degrades under load due to frequent database queries for session data. You need to design a solution that ensures session persistence, improves performance, and minimizes application changes. The application is written in Java and uses Tomcat. Which of the following should you do?
Hard21Refer to the exhibit. A Cloud Deployment Manager deployment fails with the error 'Resource 'my-firewall' already exists'. What is the most likely cause?
Hard22A startup runs a stateless web front end on a managed instance group in a single zone. Traffic is unpredictable, and the team wants the instance group to add or remove instances automatically based on CPU utilization without manual intervention. The architect must choose the simplest managed approach. Which option should the architect configure?
Easy23A startup is deploying a new web application on Google Cloud. They want to minimize operational overhead and ensure the application scales automatically based on traffic. They also want to pay only for what they use. Which Google Cloud service should the architect recommend?
Easy24A company has a production database running on Cloud SQL. They need to ensure high availability with automatic failover in the event of a zone outage. What should they do?
Hard25A company is migrating a stateful application to Google Cloud. The application requires persistent disks with low latency and high IOPS for database workloads. They plan to use Compute Engine instances with SSD persistent disks. However, the database performance is lower than expected. Which action should the company take to improve disk performance?
Medium26Which THREE of the following are best practices when using Deployment Manager to manage infrastructure? (Choose three.)
Medium27A Cloud Function fails to connect to a Cloud SQL instance. The Cloud SQL instance has a private IP. What should the developer check?
Medium28A company uses Terraform to manage Google Cloud infrastructure. They want to store the Terraform state file in a remote backend with state locking to prevent concurrent modifications. Which Google Cloud service supports this natively?
Medium29An organization wants to enforce a policy that prohibits the creation of Cloud Storage buckets with uniform bucket-level access disabled. What should they use?
Hard30A user runs the gsutil command shown in the exhibit and gets an AccessDenied error. The user is not authenticated with gcloud. What should the user do first?
Easy31A security team wants to audit all IAM role assignments in an organization. They need a historical record of changes. Which tool should they use?
Hard32A company has Compute Engine instances that need to access the internet for updates but should not be reachable from the internet. They also need to access Google APIs and services like Cloud Storage. Which configuration meets these requirements?
Hard33A Cloud Run service frequently fails with 502 errors when making requests to a backend service running on Compute Engine. The two services are in the same VPC network. The Cloud Run service is configured with a VPC connector. What is the most likely cause?
Medium34A company uses Shared VPC. A project admin in a service project tries to create a subnet in the shared VPC network but receives a permission denied error. What is the most likely cause?
Hard35Match each GCP monitoring/logging tool to its purpose.
Medium36A financial services company runs a critical application on a managed instance group (MIG) of Compute Engine instances. The application must be highly available and able to survive a zone failure without manual intervention. The company wants to ensure that the MIG automatically recovers from zone failures and maintains capacity. They also want to minimize latency for users across the United States. Which configuration should they use?
Hard37An organization needs to audit all changes to network firewall rules in a GCP project. Which service should be used to capture these changes?
Hard38A company is deploying a new application on Compute Engine. They need to ensure that the application can automatically recover from a zone failure. What is the best approach?
Medium39Which THREE are best practices for designing a highly available application on Compute Engine?
Hard40Which TWO statements are true about Google Cloud VPC networks? (Select exactly 2.)
Medium41A healthcare company stores sensitive patient data in Cloud Storage buckets. The company must ensure that data is encrypted at rest with keys that are automatically rotated every 90 days and that the keys are managed by the company itself, not by Google. The company also needs to maintain full control over key lifecycle and access policies. Which encryption option should the architect recommend?
Hard42Which TWO are best practices when designing a VPC network for a multi-tier application in Google Cloud?
Medium43A startup is deploying a new web application on Google Cloud. They want to use a fully managed, serverless platform that automatically scales and requires no infrastructure management. The application is containerized and listens on HTTP. Which Google Cloud service should they use?
Easy44A developer notices that web-server-1 is preemptible. They want to ensure their application remains available even if this instance is terminated. What should they do?
Medium45Which TWO options are valid ways to connect an on-premises network to a VPC in Google Cloud? (Choose two.)
Medium46Your company is using Cloud Storage to store sensitive customer data. The security team requires that all objects be encrypted with a customer-managed encryption key (CMEK) and that the key be automatically rotated every 90 days. You need to implement this without changing the application code. You have created a Cloud KMS key ring and a key with rotation period set to 90 days. What additional configuration is required?
Medium47A company runs a batch processing job that runs daily and can handle interruptions. The job runs on a single Compute Engine instance. Which machine configuration is the most cost-effective?
Easy48A company is migrating a monolithic application to microservices on Google Cloud. They need to manage service-to-service authentication and authorization. Which service should they use?
Hard49When creating a Compute Engine instance from a custom image stored in another project, which gcloud flag is required?
Easy50A company runs a stateful application on Google Kubernetes Engine (GKE) that requires persistent storage and low-latency access across multiple zones. The application needs to perform well even during zonal failures. Which storage solution should they use?
Hard51A financial services company needs to ensure that all outbound traffic from its Compute Engine instances to the internet goes through a dedicated IP address for allowlisting by a partner. The instances are in a private subnet with no external IP addresses. The company wants to minimize management overhead and avoid single points of failure. Which solution should the architect implement?
Hard52A company wants to provision multiple similar environments (dev, test, prod) with consistent networking configurations. Which approach is a best practice for infrastructure as code?
Easy53An organization requires that all Compute Engine instances in a project must have a specific tag for firewall rule compliance. How can they enforce this?
Hard54Which TWO actions are required to allow a private GKE cluster to pull container images from Artifact Registry in the same project?
Medium55An organization has a VPC with two subnets: subnet-a (10.0.1.0/24) and subnet-b (10.0.2.0/24). They launched a Compute Engine instance in subnet-a with an internal IP 10.0.1.2 and a public IP. They want the instance to only allow HTTPS traffic from the internet. Which firewall rule should they create?
Hard56A startup is deploying a new web application on Compute Engine. The architect needs to ensure that the application can automatically recover from a zone failure and that the instances are distributed across multiple zones within a region. The application must also scale automatically based on traffic. Which Compute Engine feature should the architect use?
Easy57A company is deploying a web application on Compute Engine behind a global HTTP(S) load balancer. They want to restrict access to only traffic from specific IP ranges. Which load balancer feature should they use?
Medium58A developer wants to store and retrieve non-relational data with flexible schema and automatic scaling. Which Google Cloud service should they use?
Easy59A company deploys a web application on Compute Engine behind a Global HTTPS Load Balancer. They need to restrict access to the application based on the client's IP address. Which Google Cloud service should they use?
Medium60An organization uses Cloud SQL for MySQL in a production environment. They need to ensure high availability with automatic failover in case of a zonal failure. Which configuration should they use?
Hard61A company is deploying a new application on Google Kubernetes Engine (GKE). They need to ensure that the application can automatically scale based on custom metrics, such as the number of pending requests in a queue. They also want to minimize operational overhead. Which TWO actions should they take? (Choose two.)
Medium62A company runs a three-tier web application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier on TCP port 8080. The company wants to enforce these requirements at the network level with minimal administrative overhead and without relying on instance-level firewall software. What should they do?
Medium63Match each GCP storage service to its typical use case.
Medium64A developer needs to pass a startup script to a Compute Engine instance during creation. Which method should be used to ensure the script runs on first boot?
Easy65Drag and drop the steps to migrate a Compute Engine VM to a different region using a snapshot into the correct order.
Medium66A company runs a critical application on Compute Engine instances in a managed instance group (MIG) across three zones in us-central1. The application uses a Cloud Spanner database. Recently, the application experienced increased latency and timeouts during peak hours. The operations team noticed that the MIG's CPU utilization is consistently above 80% during peak hours, and the autoscaler is configured to scale based on CPU utilization with a target of 60%. However, the autoscaler is not adding new instances quickly enough, causing performance degradation. The team also observed that new instances take over 5 minutes to become healthy and serve traffic. The health check is a simple TCP check on port 8080. The application startup script downloads large configuration files from Cloud Storage. What should the team do to improve the autoscaling response time and reduce latency?
Hard67A financial services company runs a three-tier web application on Compute Engine across three zones in us-central1. Their security team mandates that database traffic must never traverse the public internet, and that the database subnet must be reachable only from the application subnet. The network team has already created a custom VPC named fin-vpc with separate subnets for web, app, and db tiers. Which combination of controls should the architect implement to satisfy these requirements?
Medium68A company is migrating a legacy application to Google Cloud. The application requires a shared file system that can be accessed by multiple Compute Engine instances simultaneously. The file system must be POSIX-compliant, highly available, and scalable. The company wants to minimize management overhead. Which solution should they use?
Hard69A company is migrating a legacy monolithic application to Google Cloud. The application runs on a single VM and uses a local MySQL database. The goal is to minimize changes to the application code while improving availability. Which strategy should the company use?
Medium70A company runs a critical application on a managed instance group in a single zone. The application stores data on a zonal persistent disk. The company wants to ensure that the application can survive a zone failure with minimal data loss and automatic failover. They also want to minimize changes to the application. Which approach should they take?
Hard71Which THREE are valid methods to connect an on-premises network to a Google Cloud VPC?
Medium72A company runs a web application on Compute Engine with an HTTP Load Balancer. Users report intermittent 502 Bad Gateway errors. What is the most likely cause?
Medium73Your company runs a global e-commerce platform on Google Cloud. The application is deployed across multiple regions for low latency. You use Cloud SQL for transactional data and Cloud Spanner for global consistency of inventory. Recently, the operations team reported that the application is experiencing increased latency during peak hours, and the monthly cloud bill has risen significantly. Upon investigation, you find that the Cloud SQL instance is underutilized (CPU < 20%) while Cloud Spanner split utilization is over 80%. The application instances are fronted by a global external HTTPS load balancer. Network egress costs are high. Which course of action would best address both the latency and cost issues?
Easy74A company has a global web application deployed across multiple regions. They use an external HTTPS Load Balancer with backend services in us-central1 and europe-west1. They want users to be routed to the closest healthy backend. Which load balancing configuration is required?
Hard75A team manages a GKE cluster with node pools using different machine types. They plan to upgrade the cluster to a new Kubernetes version. What is the safest upgrade strategy to minimize application downtime?
Medium76Refer to the exhibit. A user reports that the instance 'batch-vm' is unavailable. Based on the output, what is the most likely cause of the unavailability?
Medium77A company has Compute Engine instances in us-east1-a and us-east1-b zones. They want to allow communication between these instances with minimal latency and no additional cost. What is the best networking approach?
Medium78An organization is migrating a MySQL database to Cloud SQL. They require automatic failover with zero data loss in the event of a zone outage. Which configuration should they use?
Medium79Which TWO are required to allow on-premises hosts to access Google APIs using internal IP addresses (Private Google Access)? (Choose 2)
Medium80A DevOps team is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that the pods can securely access Google Cloud APIs (e.g., Cloud Storage) without managing service account keys. Which TWO steps should they take? (Choose two.)
Easy81A company is using Cloud Storage to store sensitive data. They need to enforce that objects are deleted exactly 30 days after creation. Which object lifecycle rule should they configure?
Hard82A developer wants to deploy a stateless web application that automatically scales based on HTTP traffic. The application should be cost-effective and require minimal configuration. Which compute option is best?
Easy83A company is designing a highly available web application on Google Cloud. The application consists of stateless compute instances behind a global HTTP(S) Load Balancer. The compute instances must be able to handle sudden spikes in traffic. Which TWO strategies should the company implement? (Choose two.)
Hard84A developer needs to deploy a containerized application on Google Kubernetes Engine (GKE) with minimal operational overhead. They want to automatically scale the number of pods based on CPU utilization. Which GKE feature should they use?
Easy85A global e-commerce site uses an external HTTPS load balancer with a backend service pointing to a managed instance group. Some users report 503 errors during peak traffic. The backend instances are healthy and not overloaded. What is the most likely cause?
Hard86A company wants to minimize egress costs for data transferred between Compute Engine instances in the same region but different zones. What is the best practice?
Easy87An administrator is configuring firewall rules in a VPC. Two rules apply to the same traffic: rule 1 allows ingress from 0.0.0.0/0 on TCP 80, rule 2 denies ingress from 10.0.0.0/8 on TCP 80. Rule 1 has priority 1000, rule 2 has priority 500. What is the effective behavior for traffic from 10.0.0.1?
Easy88A service account needs to be able to start and stop Compute Engine instances in a specific project. Which IAM role should be assigned at the project level?
Easy89A company wants to migrate on-premises workloads to Google Cloud. They need to assess the existing infrastructure, plan the migration, and track progress. Which tool should they use?
Medium90A web application running on Compute Engine behind a global HTTP(S) load balancer experiences high latency during traffic spikes. Which quick fix would best address this issue without changing the architecture?
Medium91A user wants to store a database password that will be used by a Compute Engine instance. What is the most secure and manageable approach?
EasyOther domains
All PCA exam domains
Frequently asked questions
- What does the Manage and provision cloud infrastructure domain cover on the PCA exam?
- Be able to select and configure the right managed service for a stated requirement: Workload Identity for GKE API access, regional Cloud SQL for failover, CMEK with rotation for encryption, and the correct Monitoring or Logging tool. The key is matching the requirement to the exact feature.
- How many questions are in this domain?
- This page lists all 91 Manage and provision cloud infrastructure questions in the PCA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
- What is the best way to practise this domain?
- Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
- Can I practise only Manage and provision cloud infrastructure questions?
- Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.