Courseiva

PCA · domain

Manage and provision cloud infrastructure

This domain covers deploying and configuring Google Cloud resources: GKE workload identity, Cloud SQL high availability, CMEK and key rotation, and matching Cloud Monitoring and Cloud Logging tools to their purpose. Questions are scenario-based, asking you to pick the correct configuration, IAM binding, or managed service for a stated requirement.

91 questions25 easy37 medium29 hard

Focused practice

Practice Manage and provision cloud infrastructure questions

Scored sessions drawing only from this domain — pick a length below.

Start 20-question practice test →

What this domain covers

What to know about Manage and provision cloud infrastructure

Be able to select and configure the right managed service for a stated requirement: Workload Identity for GKE API access, regional Cloud SQL for failover, CMEK with rotation for encryption, and the correct Monitoring or Logging tool. The key is matching the requirement to the exact feature.

Binding Kubernetes service accounts to IAM service accounts via GKE Workload Identity Federation for keyless API access

Configuring Cloud SQL for MySQL with a regional instance and automatic failover to a standby zone

Encrypting Cloud Storage objects with CMEK in Cloud KMS and setting rotation schedules

Selecting Cloud Monitoring metrics, uptime checks, alerting policies, and Cloud Logging sinks for observability

Watch out for

Common Manage and provision cloud infrastructure exam traps

  • ▸Choosing service account JSON keys for GKE pods instead of Workload Identity, which avoids key management and rotation entirely.
  • ▸Picking a zonal Cloud SQL instance for high availability; automatic failover requires a regional instance with a standby.
  • ▸Assuming CMEK rotation re-encrypts existing objects; Cloud KMS rotates future key versions while old data stays under prior versions.

Question index

All Manage and provision cloud infrastructure questions (91)

Click any question to see the full explanation, or start a practice session above.

1

A company is deploying a microservices application on Google Kubernetes Engine (GKE). The architect needs to ensure that the cluster can automatically scale nodes based on pod resource requests and that pods are scheduled efficiently across nodes. The company also wants to minimize costs by scaling down when demand is low. Which two configurations should the architect implement? (Choose two.)

Medium
2

Refer to the exhibit. A user (ops@example.com) is unable to create a new VPC network in the project. What should the administrator verify first?

Easy
3

A startup is deploying a new web application on Google Kubernetes Engine (GKE). They want to expose the application to the internet with a single global IP address and automatically route users to the closest regional cluster. They also want to minimize operational overhead. Which GKE feature should they use?

Easy
4

Your company runs a critical application on Compute Engine instances in us-central1. The application requires low latency between instances that are all in the same region. You notice that network latency between instances varies and sometimes spikes. You want to ensure consistent low-latency communication. You currently use external IP addresses for communication between instances. What should you do?

Easy
5

A startup is deploying a containerized application on Google Kubernetes Engine (GKE). The development team wants to minimize operational overhead for managing the Kubernetes control plane and nodes. They also want to ensure that nodes are automatically upgraded and repaired. Which GKE mode should they use?

Easy
6

A company is migrating its on-premises data warehouse to BigQuery. The data is currently stored in several CSV files on a Compute Engine instance. The company needs to load the data into BigQuery once and then perform complex analytical queries. The data volume is about 10 TB, and the company wants to minimize cost and loading time. Which approach should the architect recommend?

Medium
7

Which THREE are best practices for managing secrets (e.g., API keys, passwords) in Google Cloud? (Select exactly 3.)

Hard
8

Drag and drop the steps to configure IAM roles for a service account to access Cloud Storage from a Compute Engine instance into the correct order.

Medium
9

Which THREE are required to configure Workload Identity for a GKE cluster? (Choose 3)

Hard
10

A company runs a service on Cloud Run that needs to access a Cloud SQL instance via private IP. Both are in the same VPC network. The service cannot connect to the database. What is the most likely cause?

Hard
11

A company wants to migrate an on-premises Oracle database to Google Cloud. They need high availability and want to minimize application changes. Which service should they use?

Medium
12

A company has two VPC networks in the same project: 'vpc-prod' and 'vpc-dev'. They want to allow communication between instances in both VPCs. What is the simplest method?

Medium
13

Which TWO statements about Google Cloud VPC networks are true? (Choose two.)

Easy
14

A company runs a microservices application on Google Kubernetes Engine (GKE). Each service is deployed as a Deployment with resource requests and limits. After deploying a new version of a service, the pods start crashing with OOMKilled. The team increased the memory limits in the Deployment manifest, but the pods still crash after a few minutes. The cluster has cluster autoscaling enabled. The node pool has sufficient capacity. What is the most likely cause of the issue?

Medium
15

A developer needs to programmatically create and manage Compute Engine instances. Which Google Cloud service should they use to authenticate and authorize service accounts?

Easy
16

An organization has multiple projects in Google Cloud and wants to centralize logging and monitoring for all projects. They need to aggregate logs from all projects into a single project for analysis. Which approach should they use?

Hard
17

A developer runs the command above. The instance is created successfully, but cannot be reached via HTTP from the internet. What is the most likely cause?

Medium
18

A media company stores 400 TB of video assets in a Cloud Storage bucket in the europe-west1 region. Editors in Tokyo and São Paulo complain about slow first-byte times when previewing assets. The architect must improve read latency for these global users while keeping a single canonical copy of each object and avoiding application changes that rewrite object paths. Which approach best meets these requirements?

Hard
19

A startup is deploying a new web application on Compute Engine. The application runs on a managed instance group and must be accessible from the internet over HTTP and HTTPS. The security team requires that the application be protected against common web attacks such as SQL injection and cross-site scripting. Which Google Cloud service should the architect use to meet these requirements?

Easy
20

Your company runs a stateful web application on Compute Engine instances in a managed instance group (MIG) with autoscaling based on CPU utilization. The application maintains session state in memory on each instance. Recently, users have been experiencing session timeouts and data loss during scaling events. Additionally, the application's performance degrades under load due to frequent database queries for session data. You need to design a solution that ensures session persistence, improves performance, and minimizes application changes. The application is written in Java and uses Tomcat. Which of the following should you do?

Hard
21

Refer to the exhibit. A Cloud Deployment Manager deployment fails with the error 'Resource 'my-firewall' already exists'. What is the most likely cause?

Hard
22

A startup runs a stateless web front end on a managed instance group in a single zone. Traffic is unpredictable, and the team wants the instance group to add or remove instances automatically based on CPU utilization without manual intervention. The architect must choose the simplest managed approach. Which option should the architect configure?

Easy
23

A startup is deploying a new web application on Google Cloud. They want to minimize operational overhead and ensure the application scales automatically based on traffic. They also want to pay only for what they use. Which Google Cloud service should the architect recommend?

Easy
24

A company has a production database running on Cloud SQL. They need to ensure high availability with automatic failover in the event of a zone outage. What should they do?

Hard
25

A company is migrating a stateful application to Google Cloud. The application requires persistent disks with low latency and high IOPS for database workloads. They plan to use Compute Engine instances with SSD persistent disks. However, the database performance is lower than expected. Which action should the company take to improve disk performance?

Medium
26

Which THREE of the following are best practices when using Deployment Manager to manage infrastructure? (Choose three.)

Medium
27

A Cloud Function fails to connect to a Cloud SQL instance. The Cloud SQL instance has a private IP. What should the developer check?

Medium
28

A company uses Terraform to manage Google Cloud infrastructure. They want to store the Terraform state file in a remote backend with state locking to prevent concurrent modifications. Which Google Cloud service supports this natively?

Medium
29

An organization wants to enforce a policy that prohibits the creation of Cloud Storage buckets with uniform bucket-level access disabled. What should they use?

Hard
30

A user runs the gsutil command shown in the exhibit and gets an AccessDenied error. The user is not authenticated with gcloud. What should the user do first?

Easy
31

A security team wants to audit all IAM role assignments in an organization. They need a historical record of changes. Which tool should they use?

Hard
32

A company has Compute Engine instances that need to access the internet for updates but should not be reachable from the internet. They also need to access Google APIs and services like Cloud Storage. Which configuration meets these requirements?

Hard
33

A Cloud Run service frequently fails with 502 errors when making requests to a backend service running on Compute Engine. The two services are in the same VPC network. The Cloud Run service is configured with a VPC connector. What is the most likely cause?

Medium
34

A company uses Shared VPC. A project admin in a service project tries to create a subnet in the shared VPC network but receives a permission denied error. What is the most likely cause?

Hard
35

Match each GCP monitoring/logging tool to its purpose.

Medium
36

A financial services company runs a critical application on a managed instance group (MIG) of Compute Engine instances. The application must be highly available and able to survive a zone failure without manual intervention. The company wants to ensure that the MIG automatically recovers from zone failures and maintains capacity. They also want to minimize latency for users across the United States. Which configuration should they use?

Hard
37

An organization needs to audit all changes to network firewall rules in a GCP project. Which service should be used to capture these changes?

Hard
38

A company is deploying a new application on Compute Engine. They need to ensure that the application can automatically recover from a zone failure. What is the best approach?

Medium
39

Which THREE are best practices for designing a highly available application on Compute Engine?

Hard
40

Which TWO statements are true about Google Cloud VPC networks? (Select exactly 2.)

Medium
41

A healthcare company stores sensitive patient data in Cloud Storage buckets. The company must ensure that data is encrypted at rest with keys that are automatically rotated every 90 days and that the keys are managed by the company itself, not by Google. The company also needs to maintain full control over key lifecycle and access policies. Which encryption option should the architect recommend?

Hard
42

Which TWO are best practices when designing a VPC network for a multi-tier application in Google Cloud?

Medium
43

A startup is deploying a new web application on Google Cloud. They want to use a fully managed, serverless platform that automatically scales and requires no infrastructure management. The application is containerized and listens on HTTP. Which Google Cloud service should they use?

Easy
44

A developer notices that web-server-1 is preemptible. They want to ensure their application remains available even if this instance is terminated. What should they do?

Medium
45

Which TWO options are valid ways to connect an on-premises network to a VPC in Google Cloud? (Choose two.)

Medium
46

Your company is using Cloud Storage to store sensitive customer data. The security team requires that all objects be encrypted with a customer-managed encryption key (CMEK) and that the key be automatically rotated every 90 days. You need to implement this without changing the application code. You have created a Cloud KMS key ring and a key with rotation period set to 90 days. What additional configuration is required?

Medium
47

A company runs a batch processing job that runs daily and can handle interruptions. The job runs on a single Compute Engine instance. Which machine configuration is the most cost-effective?

Easy
48

A company is migrating a monolithic application to microservices on Google Cloud. They need to manage service-to-service authentication and authorization. Which service should they use?

Hard
49

When creating a Compute Engine instance from a custom image stored in another project, which gcloud flag is required?

Easy
50

A company runs a stateful application on Google Kubernetes Engine (GKE) that requires persistent storage and low-latency access across multiple zones. The application needs to perform well even during zonal failures. Which storage solution should they use?

Hard
51

A financial services company needs to ensure that all outbound traffic from its Compute Engine instances to the internet goes through a dedicated IP address for allowlisting by a partner. The instances are in a private subnet with no external IP addresses. The company wants to minimize management overhead and avoid single points of failure. Which solution should the architect implement?

Hard
52

A company wants to provision multiple similar environments (dev, test, prod) with consistent networking configurations. Which approach is a best practice for infrastructure as code?

Easy
53

An organization requires that all Compute Engine instances in a project must have a specific tag for firewall rule compliance. How can they enforce this?

Hard
54

Which TWO actions are required to allow a private GKE cluster to pull container images from Artifact Registry in the same project?

Medium
55

An organization has a VPC with two subnets: subnet-a (10.0.1.0/24) and subnet-b (10.0.2.0/24). They launched a Compute Engine instance in subnet-a with an internal IP 10.0.1.2 and a public IP. They want the instance to only allow HTTPS traffic from the internet. Which firewall rule should they create?

Hard
56

A startup is deploying a new web application on Compute Engine. The architect needs to ensure that the application can automatically recover from a zone failure and that the instances are distributed across multiple zones within a region. The application must also scale automatically based on traffic. Which Compute Engine feature should the architect use?

Easy
57

A company is deploying a web application on Compute Engine behind a global HTTP(S) load balancer. They want to restrict access to only traffic from specific IP ranges. Which load balancer feature should they use?

Medium
58

A developer wants to store and retrieve non-relational data with flexible schema and automatic scaling. Which Google Cloud service should they use?

Easy
59

A company deploys a web application on Compute Engine behind a Global HTTPS Load Balancer. They need to restrict access to the application based on the client's IP address. Which Google Cloud service should they use?

Medium
60

An organization uses Cloud SQL for MySQL in a production environment. They need to ensure high availability with automatic failover in case of a zonal failure. Which configuration should they use?

Hard
61

A company is deploying a new application on Google Kubernetes Engine (GKE). They need to ensure that the application can automatically scale based on custom metrics, such as the number of pending requests in a queue. They also want to minimize operational overhead. Which TWO actions should they take? (Choose two.)

Medium
62

A company runs a three-tier web application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier on TCP port 8080. The company wants to enforce these requirements at the network level with minimal administrative overhead and without relying on instance-level firewall software. What should they do?

Medium
63

Match each GCP storage service to its typical use case.

Medium
64

A developer needs to pass a startup script to a Compute Engine instance during creation. Which method should be used to ensure the script runs on first boot?

Easy
65

Drag and drop the steps to migrate a Compute Engine VM to a different region using a snapshot into the correct order.

Medium
66

A company runs a critical application on Compute Engine instances in a managed instance group (MIG) across three zones in us-central1. The application uses a Cloud Spanner database. Recently, the application experienced increased latency and timeouts during peak hours. The operations team noticed that the MIG's CPU utilization is consistently above 80% during peak hours, and the autoscaler is configured to scale based on CPU utilization with a target of 60%. However, the autoscaler is not adding new instances quickly enough, causing performance degradation. The team also observed that new instances take over 5 minutes to become healthy and serve traffic. The health check is a simple TCP check on port 8080. The application startup script downloads large configuration files from Cloud Storage. What should the team do to improve the autoscaling response time and reduce latency?

Hard
67

A financial services company runs a three-tier web application on Compute Engine across three zones in us-central1. Their security team mandates that database traffic must never traverse the public internet, and that the database subnet must be reachable only from the application subnet. The network team has already created a custom VPC named fin-vpc with separate subnets for web, app, and db tiers. Which combination of controls should the architect implement to satisfy these requirements?

Medium
68

A company is migrating a legacy application to Google Cloud. The application requires a shared file system that can be accessed by multiple Compute Engine instances simultaneously. The file system must be POSIX-compliant, highly available, and scalable. The company wants to minimize management overhead. Which solution should they use?

Hard
69

A company is migrating a legacy monolithic application to Google Cloud. The application runs on a single VM and uses a local MySQL database. The goal is to minimize changes to the application code while improving availability. Which strategy should the company use?

Medium
70

A company runs a critical application on a managed instance group in a single zone. The application stores data on a zonal persistent disk. The company wants to ensure that the application can survive a zone failure with minimal data loss and automatic failover. They also want to minimize changes to the application. Which approach should they take?

Hard
71

Which THREE are valid methods to connect an on-premises network to a Google Cloud VPC?

Medium
72

A company runs a web application on Compute Engine with an HTTP Load Balancer. Users report intermittent 502 Bad Gateway errors. What is the most likely cause?

Medium
73

Your company runs a global e-commerce platform on Google Cloud. The application is deployed across multiple regions for low latency. You use Cloud SQL for transactional data and Cloud Spanner for global consistency of inventory. Recently, the operations team reported that the application is experiencing increased latency during peak hours, and the monthly cloud bill has risen significantly. Upon investigation, you find that the Cloud SQL instance is underutilized (CPU < 20%) while Cloud Spanner split utilization is over 80%. The application instances are fronted by a global external HTTPS load balancer. Network egress costs are high. Which course of action would best address both the latency and cost issues?

Easy
74

A company has a global web application deployed across multiple regions. They use an external HTTPS Load Balancer with backend services in us-central1 and europe-west1. They want users to be routed to the closest healthy backend. Which load balancing configuration is required?

Hard
75

A team manages a GKE cluster with node pools using different machine types. They plan to upgrade the cluster to a new Kubernetes version. What is the safest upgrade strategy to minimize application downtime?

Medium
76

Refer to the exhibit. A user reports that the instance 'batch-vm' is unavailable. Based on the output, what is the most likely cause of the unavailability?

Medium
77

A company has Compute Engine instances in us-east1-a and us-east1-b zones. They want to allow communication between these instances with minimal latency and no additional cost. What is the best networking approach?

Medium
78

An organization is migrating a MySQL database to Cloud SQL. They require automatic failover with zero data loss in the event of a zone outage. Which configuration should they use?

Medium
79

Which TWO are required to allow on-premises hosts to access Google APIs using internal IP addresses (Private Google Access)? (Choose 2)

Medium
80

A DevOps team is deploying a microservices application on Google Kubernetes Engine (GKE). They want to ensure that the pods can securely access Google Cloud APIs (e.g., Cloud Storage) without managing service account keys. Which TWO steps should they take? (Choose two.)

Easy
81

A company is using Cloud Storage to store sensitive data. They need to enforce that objects are deleted exactly 30 days after creation. Which object lifecycle rule should they configure?

Hard
82

A developer wants to deploy a stateless web application that automatically scales based on HTTP traffic. The application should be cost-effective and require minimal configuration. Which compute option is best?

Easy
83

A company is designing a highly available web application on Google Cloud. The application consists of stateless compute instances behind a global HTTP(S) Load Balancer. The compute instances must be able to handle sudden spikes in traffic. Which TWO strategies should the company implement? (Choose two.)

Hard
84

A developer needs to deploy a containerized application on Google Kubernetes Engine (GKE) with minimal operational overhead. They want to automatically scale the number of pods based on CPU utilization. Which GKE feature should they use?

Easy
85

A global e-commerce site uses an external HTTPS load balancer with a backend service pointing to a managed instance group. Some users report 503 errors during peak traffic. The backend instances are healthy and not overloaded. What is the most likely cause?

Hard
86

A company wants to minimize egress costs for data transferred between Compute Engine instances in the same region but different zones. What is the best practice?

Easy
87

An administrator is configuring firewall rules in a VPC. Two rules apply to the same traffic: rule 1 allows ingress from 0.0.0.0/0 on TCP 80, rule 2 denies ingress from 10.0.0.0/8 on TCP 80. Rule 1 has priority 1000, rule 2 has priority 500. What is the effective behavior for traffic from 10.0.0.1?

Easy
88

A service account needs to be able to start and stop Compute Engine instances in a specific project. Which IAM role should be assigned at the project level?

Easy
89

A company wants to migrate on-premises workloads to Google Cloud. They need to assess the existing infrastructure, plan the migration, and track progress. Which tool should they use?

Medium
90

A web application running on Compute Engine behind a global HTTP(S) load balancer experiences high latency during traffic spikes. Which quick fix would best address this issue without changing the architecture?

Medium
91

A user wants to store a database password that will be used by a Compute Engine instance. What is the most secure and manageable approach?

Easy

Frequently asked questions

What does the Manage and provision cloud infrastructure domain cover on the PCA exam?
Be able to select and configure the right managed service for a stated requirement: Workload Identity for GKE API access, regional Cloud SQL for failover, CMEK with rotation for encryption, and the correct Monitoring or Logging tool. The key is matching the requirement to the exact feature.
How many questions are in this domain?
This page lists all 91 Manage and provision cloud infrastructure questions in the PCA question bank. The actual exam draws from this domain proportionally to its weighting in the official exam blueprint.
What is the best way to practise this domain?
Start with a short focused session (10 questions) to identify gaps, then work through explanations. Repeat with a longer session once the weak areas feel solid.
Can I practise only Manage and provision cloud infrastructure questions?
Yes — the session launcher on this page filters questions to this domain only. Choose any session length for inline explanations and scoring.
google-pca GOOGLE-PCA manage provision infra Practice Questions