Courseiva

CCNA Manage and provision cloud infrastructure Questions

75 of 91 questions · Page 1/2 · Manage and provision cloud infrastructure · Answers revealed

1
Multi-Selectmedium

A company is deploying a microservices application on Google Kubernetes Engine (GKE). The architect needs to ensure that the cluster can automatically scale nodes based on pod resource requests and that pods are scheduled efficiently across nodes. The company also wants to minimize costs by scaling down when demand is low. Which two configurations should the architect implement? (Choose two.)

Select 2 answers
A.Enable Cluster Autoscaler on the node pool with a minimum and maximum node count.
B.Configure Horizontal Pod Autoscaler (HPA) based on CPU utilization.
C.Set pod resource requests and limits for CPU and memory.
D.Use a regional cluster with multiple zones.
E.Enable node auto-provisioning for the cluster.
AnswersA, C

Cluster Autoscaler automatically adjusts the number of nodes in a node pool based on the resource requests of pending pods. It scales up when pods cannot be scheduled due to insufficient resources and scales down when nodes are underutilized. Setting a minimum and maximum node count ensures cost control and availability. This directly addresses the need to scale nodes based on pod demands and minimize costs during low demand.

Why this answer

Cluster Autoscaler scales the number of nodes in a node pool based on pending pod resource requests, and setting pod resource requests ensures that the scheduler and autoscaler have accurate information to make scaling decisions. Together, they enable automatic node scaling and efficient scheduling while allowing scale-down to reduce costs. The other options either address pod scaling, add unnecessary complexity, or improve availability without meeting the core requirements.

Exam trap

The trap here is assuming that Horizontal Pod Autoscaler alone can scale nodes; it only scales pod replicas, not the underlying node pool.

2
MCQeasy

Refer to the exhibit. A user (ops@example.com) is unable to create a new VPC network in the project. What should the administrator verify first?

A.The user has been granted roles/compute.admin.
B.The user has the project owner role.
C.The user has the roles/storage.admin role.
D.The user has appropriate IAM roles such as roles/compute.networkAdmin.
AnswerD

Verify that ops@example.com holds roles/compute.networkAdmin or equivalent permissions on the project. VPC network creation requires compute.networks.create, granted through IAM roles rather than Microsoft Entra ID directory roles. Checking this binding first confirms whether the authorisation failure stems from missing project-level permissions.

Why this answer

To create a VPC network in Google Cloud, the user needs the compute.networks.create permission. The roles/compute.networkAdmin IAM role includes this permission, along with others needed to manage VPC networks. Option D correctly identifies that the user must have appropriate IAM roles, specifically roles/compute.networkAdmin or a custom role with the necessary compute.networks.create permission.

Exam trap

Google Cloud often tests the principle of least privilege and the specific IAM roles required for VPC operations, trapping candidates who assume that a broad role like compute.admin or owner is the first thing to verify, rather than the more specific networkAdmin role.

How to eliminate wrong answers

Option A is wrong because roles/compute.admin is a highly privileged role that includes all compute permissions, but it is not the minimum required role; the question asks what the administrator should verify first, and checking for a more specific role like roles/compute.networkAdmin is more appropriate. Option B is wrong because the project owner role (roles/owner) includes all permissions, but it is overly broad and not the first thing to verify; the administrator should check for the specific network admin role first. Option C is wrong because roles/storage.admin grants permissions for Cloud Storage, not for VPC network creation, which requires compute.networks.* permissions.

3
MCQeasy

A startup is deploying a new web application on Google Kubernetes Engine (GKE). They want to expose the application to the internet with a single global IP address and automatically route users to the closest regional cluster. They also want to minimize operational overhead. Which GKE feature should they use?

A.GKE Ingress with a global external Application Load Balancer
B.GKE Gateway with a regional gateway class
C.GKE Network Endpoint Groups (NEGs) with a standalone global load balancer
D.GKE Service of type LoadBalancer with a regional external passthrough Network Load Balancer
AnswerA

GKE Ingress automatically creates a global external Application Load Balancer when you create an Ingress resource. This provides a single global IP address and routes traffic to the closest backend service across multiple regional clusters. It integrates with GKE and requires minimal operational overhead, as the load balancer is managed by GKE. This meets the requirement for global exposure and low management effort.

Why this answer

GKE Ingress automatically provisions a global external Application Load Balancer, providing a single global IP and intelligent routing to the closest regional backends. It is fully integrated with GKE and requires minimal operational effort. The other options either provide regional load balancing or require manual configuration, which does not meet the requirement for minimal overhead and global reach.

Exam trap

The trap here is assuming that a Service of type LoadBalancer provides a global IP, when it actually creates a regional load balancer, or that GKE Gateway with a regional class is global.

4
MCQeasy

Your company runs a critical application on Compute Engine instances in us-central1. The application requires low latency between instances that are all in the same region. You notice that network latency between instances varies and sometimes spikes. You want to ensure consistent low-latency communication. You currently use external IP addresses for communication between instances. What should you do?

A.Move instances to the same zone to reduce network hops.
B.Upgrade to larger machine types to improve network bandwidth.
C.Use internal IP addresses instead of external IPs for inter-instance communication.
D.Set up a Cloud VPN connection between instances.
AnswerC

External IP traffic between instances traverses Google's edge network and public routing, adding variable hops that cause latency spikes. Internal IP addresses stay on the regional VPC network, giving direct, consistent paths between instances in us-central1 and satisfying the consistent low-latency requirement.

Why this answer

Using internal IP addresses (RFC 1918) for inter-instance communication avoids the overhead of NAT, external routing, and potential egress bottlenecks. Traffic stays within Google's internal network fabric, reducing latency variability and eliminating spikes caused by external internet path fluctuations.

Exam trap

The trap here is that candidates assume moving to the same zone or upgrading machine types will fix latency, but the root cause is the external IP routing path, not proximity or bandwidth.

How to eliminate wrong answers

Option A is wrong because moving instances to the same zone reduces physical distance but does not address the fundamental issue of using external IPs, which still forces traffic through external gateways and can introduce latency spikes. Option B is wrong because larger machine types increase network bandwidth (throughput) but do not reduce latency or eliminate the variability caused by external IP routing. Option D is wrong because Cloud VPN is designed for secure connectivity between on-premises and VPC, not for inter-instance communication within the same region; it adds encryption overhead and does not solve the external IP latency problem.

5
MCQeasy

A startup is deploying a containerized application on Google Kubernetes Engine (GKE). The development team wants to minimize operational overhead for managing the Kubernetes control plane and nodes. They also want to ensure that nodes are automatically upgraded and repaired. Which GKE mode should they use?

A.GKE Standard mode with a regional cluster and node auto-repair enabled.
B.GKE Autopilot mode with a regional cluster.
C.GKE Standard mode with a zonal cluster and manually managed node pools.
D.GKE Autopilot mode with a zonal cluster.
AnswerB

GKE Autopilot mode provides a fully managed control plane and node management, including automatic upgrades and repairs. It minimizes operational overhead by handling node provisioning, scaling, and security. A regional cluster provides high availability across zones. This mode directly satisfies the requirements of reduced overhead and automatic node lifecycle management.

Why this answer

GKE Autopilot mode is designed to minimize operational overhead by fully managing the control plane and nodes, including automatic upgrades and repairs. A regional cluster provides high availability across multiple zones. Together, they meet the startup's requirements for reduced management and automatic node lifecycle operations.

Exam trap

The trap here is assuming that enabling node auto-repair in Standard mode is equivalent to the fully managed node lifecycle in Autopilot.

6
MCQmedium

A company is migrating its on-premises data warehouse to BigQuery. The data is currently stored in several CSV files on a Compute Engine instance. The company needs to load the data into BigQuery once and then perform complex analytical queries. The data volume is about 10 TB, and the company wants to minimize cost and loading time. Which approach should the architect recommend?

A.Create a Dataproc cluster and run a Spark job to read the CSV files and write them to BigQuery.
B.Use BigQuery Data Transfer Service to schedule a recurring transfer from the Compute Engine instance.
C.Upload the CSV files to a Cloud Storage bucket, then use a BigQuery load job to load the data from Cloud Storage into a BigQuery table.
D.Use the bq command-line tool to load the CSV files directly from the Compute Engine instance into BigQuery.
AnswerC

Uploading the CSV files to Cloud Storage and then using a BigQuery load job is the recommended approach. BigQuery load jobs from Cloud Storage are fast, support parallel loading, and are free for loading data (you only pay for storage and queries). This minimizes loading time and cost for a 10 TB dataset.

Why this answer

A BigQuery load job from Cloud Storage is the most efficient and cost-effective method for a one-time load of 10 TB. It leverages massively parallel loading, has no loading charges, and avoids the overhead of managing additional services. Uploading to Cloud Storage first is a standard best practice for large-scale data ingestion into BigQuery.

Exam trap

The trap here is assuming that a direct load from Compute Engine or a custom Dataproc job is needed, when the native Cloud Storage to BigQuery load job is simpler, faster, and cheaper.

7
Multi-Selecthard

Which THREE are best practices for managing secrets (e.g., API keys, passwords) in Google Cloud? (Select exactly 3.)

Select 3 answers
A.Rotate secrets regularly and automatically where possible.
B.Encrypt secrets and store them in source code repositories.
C.Use Secret Manager to store and version secrets.
D.Grant access to secrets using IAM roles at the project or secret level.
E.Pass secrets as environment variables to Compute Engine instances.
AnswersA, C, D

Regular rotation reduces the risk of compromised secrets.

Why this answer

Regular, automated rotation of secrets limits the window of exposure if a secret is compromised. Secret Manager supports automatic rotation policies with a rotation period and next rotation time, and can trigger a Cloud Function or Cloud Run service to generate a new secret version, ensuring secrets are rotated without manual intervention.

Exam trap

Google Cloud often tests the misconception that encrypting secrets before storing them in code repositories is acceptable, when in fact any storage in source control violates the principle of separation of secrets from code, and that environment variables are a secure method for passing secrets to Compute Engine instances, whereas they are easily exposed through metadata endpoints or process inspection.

8
Drag & Dropmedium

Drag and drop the steps to configure IAM roles for a service account to access Cloud Storage from a Compute Engine instance into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

The service account must be attached to the instance before it can be used. Granting roles is done on the service account.

9
Multi-Selecthard

Which THREE are required to configure Workload Identity for a GKE cluster? (Choose 3)

Select 3 answers
A.Create a Google Cloud service account
B.Create a Kubernetes service account
C.Enable Workload Identity on the GKE cluster
D.Bind the Kubernetes service account to the Google Cloud service account using a Kubernetes RoleBinding
E.Use a node pool that has Workload Identity enabled
AnswersA, B, C

The GSA is used to grant permissions to the Kubernetes service account.

Why this answer

A Google Cloud service account (GSA) is required to authenticate to Google Cloud APIs from within GKE. Workload Identity maps a Kubernetes service account (KSA) to a GSA, allowing pods to inherit the GSA's IAM permissions without managing static keys. The GSA must be created first to define the identity that workloads will assume.

Exam trap

Google Cloud often tests the distinction between Kubernetes RoleBinding (for RBAC) and IAM policy binding (for Workload Identity), leading candidates to incorrectly select a RoleBinding as the binding mechanism.

10
MCQhard

A company runs a service on Cloud Run that needs to access a Cloud SQL instance via private IP. Both are in the same VPC network. The service cannot connect to the database. What is the most likely cause?

A.Cloud Run must be deployed in the same zone as Cloud SQL.
B.The IAM permissions for Cloud Run to access Cloud SQL are missing.
C.A firewall rule is blocking traffic.
D.Cloud Run needs a Serverless VPC Access connector.
E.The Cloud SQL instance needs a public IP assigned.
AnswerD

Cloud Run egresses through a shared serverless environment, so it cannot reach a private IP inside the VPC without a Serverless VPC Access connector. That connector routes traffic into the VPC, resolving the connection failure.

Why this answer

Cloud Run services run in a Google-managed environment and cannot directly reach resources on a VPC network via private IP. A Serverless VPC Access connector is required to bridge the serverless environment to the VPC, enabling private IP connectivity to Cloud SQL. Without this connector, the Cloud Run service cannot route traffic to the Cloud SQL private IP, even if both are in the same VPC network.

Exam trap

Google Cloud often tests the misconception that being in the same VPC network automatically grants connectivity, but serverless services like Cloud Run require an explicit Serverless VPC Access connector to route traffic into the VPC.

How to eliminate wrong answers

Option A is wrong because Cloud Run is a serverless, zonal-agnostic service; it does not need to be in the same zone as Cloud SQL, and zone affinity does not affect private IP connectivity. Option B is wrong because IAM permissions (e.g., Cloud SQL Client role) control access to the Cloud SQL API for management operations, not network-level connectivity to the database's private IP; the issue is network routing, not authorization. Option C is wrong because firewall rules control traffic at the network layer, but Cloud Run cannot even send traffic into the VPC without a connector, so a firewall rule is not the primary cause.

Option E is wrong because the question specifies that the Cloud SQL instance uses private IP; assigning a public IP would expose the database to the internet and is unnecessary for private connectivity, and the problem is the lack of a routing path, not the IP type.

11
MCQmedium

A company wants to migrate an on-premises Oracle database to Google Cloud. They need high availability and want to minimize application changes. Which service should they use?

A.Cloud SQL for MySQL
B.Bare Metal Solution
C.Cloud Spanner
D.Compute Engine with Oracle license
AnswerB

Bare Metal Solution offers dedicated Oracle-optimized hardware with minimal application changes.

Why this answer

Bare Metal Solution is correct because it provides dedicated physical servers for Oracle workloads, enabling high availability through Oracle RAC or Data Guard while preserving the existing Oracle database architecture. This minimizes application changes since the database remains Oracle-native, unlike managed services that require migration to a different database engine.

Exam trap

The trap here is that candidates often choose Compute Engine with Oracle license (Option D) thinking it is the most flexible, but they overlook the high-availability requirement and the operational overhead of manually configuring Oracle RAC or Data Guard, which Bare Metal Solution simplifies with a managed infrastructure.

How to eliminate wrong answers

Option A is wrong because Cloud SQL for MySQL is a managed MySQL service, not compatible with Oracle databases, requiring a full database migration and application code changes. Option C is wrong because Cloud Spanner is a globally distributed, horizontally scalable relational database that uses a proprietary SQL dialect, not Oracle-compatible, necessitating significant application rewrites. Option D is wrong because Compute Engine with Oracle license requires manual configuration for high availability (e.g., setting up Oracle RAC or Data Guard) and does not provide the same level of managed infrastructure as Bare Metal Solution, increasing operational complexity.

12
MCQmedium

A company has two VPC networks in the same project: 'vpc-prod' and 'vpc-dev'. They want to allow communication between instances in both VPCs. What is the simplest method?

A.Create a VPC Network Peering connection between them
B.Set up a Cloud VPN tunnel between the two VPCs
C.Configure a custom route in each VPC pointing to the other's subnet
D.Add firewall rules allowing traffic between the VPCs
AnswerA

VPC Network Peering enables direct, private connectivity.

Why this answer

VPC Network Peering is the simplest method because it directly connects two VPCs using Google's internal infrastructure, allowing private RFC 1918 IP communication across the networks without requiring external gateways, VPN tunnels, or additional bandwidth costs. It requires no routes to be manually configured—Google automatically adds the necessary routes for each peered VPC's subnets—and only a single firewall rule to permit traffic between the instances.

Exam trap

Google Cloud often tests the misconception that firewall rules alone can enable inter-VPC communication, but candidates must remember that firewall rules are only effective after a connectivity mechanism (like peering or VPN) is in place.

How to eliminate wrong answers

Option B is wrong because a Cloud VPN tunnel introduces unnecessary complexity and latency by routing traffic over the public internet or through Cloud VPN gateways, whereas VPC peering uses Google's internal backbone with lower latency and no per-tunnel charges. Option C is wrong because custom routes alone cannot enable inter-VPC communication; routes only direct traffic to a next hop, but without a peering connection or VPN tunnel, there is no path for the packets to travel between the VPCs. Option D is wrong because firewall rules only control allowed traffic within a VPC or between VPCs that already have a connectivity mechanism (like peering or VPN); they do not establish the underlying network link required for packets to leave one VPC and enter another.

13
Multi-Selecteasy

Which TWO statements about Google Cloud VPC networks are true? (Choose two.)

Select 2 answers
A.Subnets are regional resources.
B.VPC networks are global resources.
C.VPC networks are project-level resources.
D.Firewall rules are regional.
E.Subnets are zonal resources.
AnswersA, B

Subnets are regional and can span zones.

Why this answer

Subnets in Google Cloud VPC are regional resources. When you create a subnet, you specify a region and a CIDR block, and the subnet spans all zones within that region. This allows resources in different zones of the same region to use the same subnet without additional configuration.

Exam trap

The trap here is that candidates often confuse subnets as zonal resources (like in AWS or on-premises networking) and firewall rules as regional, but Google Cloud VPC treats subnets as regional and firewall rules as global, which is a key differentiator tested on the PCA exam.

14
MCQmedium

A company runs a microservices application on Google Kubernetes Engine (GKE). Each service is deployed as a Deployment with resource requests and limits. After deploying a new version of a service, the pods start crashing with OOMKilled. The team increased the memory limits in the Deployment manifest, but the pods still crash after a few minutes. The cluster has cluster autoscaling enabled. The node pool has sufficient capacity. What is the most likely cause of the issue?

A.The Horizontal Pod Autoscaler is configured with a wrong target metric
B.The cluster autoscaler is not scaling up quickly enough
C.The application has a memory leak
D.The pods are hitting the node's ephemeral storage limit
AnswerC

Raising memory limits only delays OOMKilled termination; pods still crash once consumption exceeds the new ceiling. Steadily growing memory that eventually exhausts any limit indicates a leak in the application code, not insufficient node capacity or autoscaling.

Why this answer

The pods are crashing with OOMKilled even after increasing memory limits, and the node pool has sufficient capacity. This indicates the application itself has a memory leak, where memory usage grows unbounded over time until it exceeds the new limit, causing the OOMKiller to terminate the pod. Increasing limits only delays the crash if the leak persists.

Exam trap

The trap here is that candidates confuse resource limits with scaling mechanisms, assuming that increasing limits or enabling autoscaling fixes memory exhaustion, rather than recognizing the application-level memory leak as the root cause.

How to eliminate wrong answers

Option A is wrong because the Horizontal Pod Autoscaler (HPA) scales the number of pods based on CPU/memory utilization, but it does not prevent individual pods from being OOMKilled; the issue is per-pod memory exhaustion, not scaling. Option B is wrong because cluster autoscaler scales node count when pods are unschedulable due to resource shortage, but the node pool has sufficient capacity, so the autoscaler is not the bottleneck. Option D is wrong because ephemeral storage limits affect disk space, not memory; OOMKilled is a memory-related termination, not a storage issue.

15
MCQeasy

A developer needs to programmatically create and manage Compute Engine instances. Which Google Cloud service should they use to authenticate and authorize service accounts?

A.Cloud Audit Logs
B.Cloud Key Management Service (KMS)
C.Cloud Scheduler
D.Cloud IAM
AnswerD

Cloud IAM provides the identity and access management layer for Google Cloud, letting code authenticate as a service account and receive scoped permissions to create and manage Compute Engine instances. It satisfies the stem's need for both authentication and authorisation of programmatic service account access.

Why this answer

Cloud IAM is the correct service because it provides the identity and access management framework for authenticating and authorizing service accounts. When a developer creates Compute Engine instances, they must attach a service account and grant IAM roles (e.g., roles/compute.instanceAdmin) to define what actions that service account can perform. Cloud IAM handles the authentication via OAuth 2.0 tokens and authorization via role-based access control (RBAC), making it the foundational service for managing service account permissions.

Exam trap

Google Cloud often tests the misconception that Cloud Audit Logs or Cloud KMS can handle authentication/authorization, but candidates must remember that only Cloud IAM manages identities and permissions, while the other options serve logging or encryption purposes.

How to eliminate wrong answers

Option A is wrong because Cloud Audit Logs is a logging service that records API calls and administrative actions, not a service for authenticating or authorizing service accounts. Option B is wrong because Cloud Key Management Service (KMS) manages cryptographic keys for encryption, not identity or permission management for service accounts. Option C is wrong because Cloud Scheduler is a cron-job service for triggering tasks on a schedule, and it has no role in authentication or authorization of service accounts.

16
MCQhard

An organization has multiple projects in Google Cloud and wants to centralize logging and monitoring for all projects. They need to aggregate logs from all projects into a single project for analysis. Which approach should they use?

A.Export logs from each project to a Cloud Storage bucket and then import them into BigQuery.
B.Enable Cloud Audit Logs for all projects and view them from the central project.
C.Install the Stackdriver agent on all VMs and point them to the central project.
D.Create a logs sink in each project that exports logs to a BigQuery dataset in the central project.
AnswerD

A logs sink in each project routes log entries to a BigQuery dataset hosted in the central project, aggregating all projects' logs for centralised analysis. This satisfies the requirement to consolidate logs into a single project without per-project querying.

Why this answer

Google Cloud's logs sink feature allows you to route logs from multiple source projects to a centralized BigQuery dataset in a single destination project. This approach aggregates logs efficiently without requiring agents or manual import steps, and it supports real-time log export for analysis.

Exam trap

The trap here is that candidates confuse the Stackdriver agent (which collects logs from VMs) with the logs sink feature (which routes logs from projects), leading them to choose Option C instead of the correct centralized export method.

How to eliminate wrong answers

Option A is wrong because exporting logs to Cloud Storage and then importing them into BigQuery adds unnecessary latency and complexity; logs sinks can export directly to BigQuery. Option B is wrong because Cloud Audit Logs are enabled per project and cannot be centrally viewed without aggregation; they must be exported via sinks to a central project. Option C is wrong because the Stackdriver agent (now legacy) is used for collecting VM metrics and logs, but it cannot aggregate logs from multiple projects into a single central project; logs sinks are the correct mechanism for cross-project log aggregation.

17
MCQmedium

A developer runs the command above. The instance is created successfully, but cannot be reached via HTTP from the internet. What is the most likely cause?

A.There is no firewall rule allowing ingress traffic on ports 80 and 443.
B.The machine type n1-standard-2 is not suitable for HTTP.
C.The image family debian-10 does not support HTTP.
D.The boot disk type pd-standard is too slow.
AnswerA

Compute Engine instances have no implicit inbound access; the default network's firewall rules govern traffic. Without an ingress rule permitting TCP 80 and 443 from the relevant source ranges, HTTP requests from the internet are dropped before reaching the instance, even though it booted successfully.

Why this answer

The most likely cause is that there is no firewall rule allowing ingress traffic on ports 80 and 443. By default, Google Cloud Platform (GCP) firewall rules block all incoming traffic from the internet. Even though the instance is created successfully, HTTP/HTTPS traffic cannot reach it unless a firewall rule explicitly permits ingress on TCP ports 80 and 443, typically via a target tag like 'http-server' or 'https-server'.

Exam trap

Google Cloud often tests the misconception that creating a VM with a public IP automatically makes it reachable from the internet, when in reality GCP's default firewall rules block all ingress traffic until explicitly opened.

How to eliminate wrong answers

Option B is wrong because the machine type n1-standard-2 is a general-purpose machine that fully supports HTTP traffic; machine type does not affect protocol support. Option C is wrong because the image family debian-10 is a standard Linux distribution that supports HTTP out of the box; the OS image does not determine network reachability. Option D is wrong because the boot disk type pd-standard (standard persistent disk) provides sufficient I/O for basic HTTP serving; disk speed does not prevent the instance from being reached via HTTP from the internet.

18
MCQhard

A media company stores 400 TB of video assets in a Cloud Storage bucket in the europe-west1 region. Editors in Tokyo and São Paulo complain about slow first-byte times when previewing assets. The architect must improve read latency for these global users while keeping a single canonical copy of each object and avoiding application changes that rewrite object paths. Which approach best meets these requirements?

A.Enable Cloud CDN on a global external Application Load Balancer with a backend bucket pointing at the existing Cloud Storage bucket.
B.Use Storage Transfer Service to copy objects into regional buckets in asia-northeast1 and southamerica-east1, and update the application to select the closest bucket.
C.Change the bucket's default storage class to Standard and enable Autoclass so objects are served from the nearest edge cache.
D.Create a multi-region bucket and migrate the objects, then serve reads from the same object names in the new bucket.
AnswerA

A backend bucket on a global external Application Load Balancer with Cloud CDN caches objects at Google's global edge, so editors in Tokyo and São Paulo fetch from a nearby point of presence. The bucket remains the single canonical source, object paths are unchanged, and no application rewrite is needed.

Why this answer

Cloud CDN attached to a global external Application Load Balancer with a backend bucket serves Cloud Storage content from Google's globally distributed edge caches. Readers in Tokyo and São Paulo are answered by a nearby point of presence, improving first-byte latency, while the europe-west1 bucket remains the sole origin and canonical copy. Because requests still use the same object paths through the load balancer, no application rewrite is required.

Exam trap

The trap here is confusing Cloud Storage location options such as multi-region with actual edge caching, when only Cloud CDN places content near global readers.

19
MCQeasy

A startup is deploying a new web application on Compute Engine. The application runs on a managed instance group and must be accessible from the internet over HTTP and HTTPS. The security team requires that the application be protected against common web attacks such as SQL injection and cross-site scripting. Which Google Cloud service should the architect use to meet these requirements?

A.Identity-Aware Proxy (IAP) with OAuth consent screen and context-aware access policies.
B.Cloud Armor with a security policy attached to the backend service of an external HTTP(S) load balancer.
C.VPC firewall rules that allow only HTTP and HTTPS traffic to the managed instance group.
D.Cloud CDN with signed URLs and origin access identity to restrict access to the backend instances.
AnswerB

Cloud Armor security policies can be attached to the backend service of an external HTTP(S) load balancer. It provides preconfigured WAF rules for SQL injection and cross-site scripting, as well as IP allowlisting and denylisting. This directly meets the requirement to protect the application from common web attacks.

Why this answer

Cloud Armor is the correct service because it provides a web application firewall with preconfigured rules for SQL injection and cross-site scripting, and it integrates directly with external HTTP(S) load balancers. Attaching a security policy to the backend service enforces these protections at the edge before traffic reaches the application.

Exam trap

The trap here is confusing network-layer firewall rules or identity-based access controls with application-layer WAF protection, which Cloud Armor specifically provides.

20
MCQhard

Your company runs a stateful web application on Compute Engine instances in a managed instance group (MIG) with autoscaling based on CPU utilization. The application maintains session state in memory on each instance. Recently, users have been experiencing session timeouts and data loss during scaling events. Additionally, the application's performance degrades under load due to frequent database queries for session data. You need to design a solution that ensures session persistence, improves performance, and minimizes application changes. The application is written in Java and uses Tomcat. Which of the following should you do?

A.Rewrite the application to be stateless by moving all state to the frontend using JWT tokens, eliminating the need for server-side sessions.
B.Deploy Cloud Memorystore for Redis as a session store, and configure Tomcat to use Redis-backed session persistence using the Redisson or Spring Session framework.
C.Configure the load balancer to use session affinity (sticky sessions) and increase the instance size to handle more sessions per instance.
D.Store session data in Cloud SQL using Spring Session JDBC, and configure the application to retrieve sessions from the database.
AnswerB

Cloud Memorystore for Redis externalises session state, so instances in the MIG share sessions and survive scaling or restarts. Tomcat integrates via Redisson or Spring Session with minimal code changes, and Redis caching reduces the frequent database queries degrading performance.

Why this answer

It introduces an external, highly available, in-memory session store (Cloud Memorystore for Redis) that decouples session state from individual Compute Engine instances. This eliminates session loss during autoscaling events and reduces database load by serving session data from fast Redis memory, all while requiring minimal application changes via Tomcat's built-in session persistence or Spring Session integration.

Exam trap

The trap here is that candidates often choose session affinity (sticky sessions) thinking it solves session persistence, but it only routes traffic to the same instance and does not protect against session loss when that instance is terminated during autoscaling or maintenance.

How to eliminate wrong answers

Option A is wrong because rewriting the application to be stateless with JWT tokens moves session state to the frontend, which requires significant application changes and does not address the existing Tomcat session management; it also shifts security and token management complexity without solving the immediate session persistence issue. Option C is wrong because session affinity (sticky sessions) ties a user to a specific instance, which does not prevent session loss when that instance is terminated during autoscaling; increasing instance size only delays the problem and does not provide a shared, durable session store. Option D is wrong because storing session data in Cloud SQL (a relational database) introduces latency and contention for frequent session reads/writes, degrading performance under load, and it does not leverage the in-memory speed needed for session persistence; it also requires more application changes than using Redis with Tomcat.

21
MCQhard

Refer to the exhibit. A Cloud Deployment Manager deployment fails with the error 'Resource 'my-firewall' already exists'. What is the most likely cause?

A.The user lacks IAM permissions to create firewall rules.
B.The network reference in the firewall rule is incorrect.
C.A firewall rule with the name 'my-firewall' already exists in the project.
D.The deployment does not include a 'delete' policy for existing resources.
AnswerC

A pre-existing firewall rule named 'my-firewall' in the project directly triggers the "already exists" conflict, because Cloud Deployment Manager refuses to create a resource whose name is already taken. The stem's constraint is a naming collision within the target project, so the deployment cannot proceed until that rule is renamed or removed.

Why this answer

The error message 'Resource 'my-firewall' already exists' directly indicates that a firewall rule with the exact name 'my-firewall' is already present in the project. Cloud Deployment Manager creates resources by name, and if a resource with the same name exists (even if it was created outside the deployment), the deployment will fail unless the deployment is configured to adopt or manage that existing resource. The error is not about permissions, network references, or missing delete policies—it is a name collision.

Exam trap

Google Cloud often tests the distinction between resource name conflicts and other common errors (permissions, invalid references) to see if candidates can interpret the exact error message rather than guessing based on general troubleshooting.

How to eliminate wrong answers

Option A is wrong because an IAM permission issue would produce an error like 'Permission denied' or 'Required permission compute.firewalls.create', not a 'Resource already exists' error. Option B is wrong because an incorrect network reference would cause a validation error such as 'Invalid value for field 'network'' or a 400 Bad Request, not a resource name conflict. Option D is wrong because Deployment Manager does not require a 'delete' policy for existing resources; the 'delete' policy controls what happens to resources when the deployment is deleted, not whether a deployment can create a resource with a duplicate name.

22
MCQeasy

A startup runs a stateless web front end on a managed instance group in a single zone. Traffic is unpredictable, and the team wants the instance group to add or remove instances automatically based on CPU utilization without manual intervention. The architect must choose the simplest managed approach. Which option should the architect configure?

A.Replace the managed instance group with a single large Compute Engine instance and enable live migration for maintenance events.
B.Deploy the front end to a second zone and use a global external Application Load Balancer to distribute traffic between the two instance groups.
C.Attach an autoscaling policy based on CPU utilization to the managed instance group and set minimum and maximum instance counts.
D.Create a Cloud Scheduler job that calls the Compute Engine API every five minutes to resize the managed instance group based on a Cloud Monitoring metric.
AnswerC

Managed instance group autoscaling natively supports CPU utilization policies and respects minimum and maximum replica bounds, adding or removing instances automatically as load changes. It requires no custom code or external scheduler and is the simplest managed mechanism for scaling a stateless front end.

Why this answer

A managed instance group supports autoscaling policies directly, including CPU utilization targets, and honors minimum and maximum instance counts so capacity tracks demand automatically. This is a built-in, fully managed capability that requires no custom scheduler or external automation, making it the simplest way to scale a stateless front end in response to unpredictable traffic.

Exam trap

The trap here is assuming you must script scaling through Cloud Scheduler and the Compute Engine API when managed instance group autoscaling already performs that loop natively.

23
MCQeasy

A startup is deploying a new web application on Google Cloud. They want to minimize operational overhead and ensure the application scales automatically based on traffic. They also want to pay only for what they use. Which Google Cloud service should the architect recommend?

A.Compute Engine managed instance groups with autoscaling.
B.Cloud Run.
C.App Engine standard environment.
D.Google Kubernetes Engine (GKE) with cluster autoscaler.
AnswerB

Cloud Run is a fully managed serverless platform that automatically scales containers based on traffic, including scaling to zero when there is no traffic. It abstracts away infrastructure management, so the startup only pays for resources used during request processing. This minimizes operational overhead and aligns with the pay-per-use requirement.

Why this answer

Cloud Run is a fully managed serverless platform that automatically scales based on traffic, scales to zero, and charges only for resources used during request processing. It requires no infrastructure management, making it ideal for minimizing operational overhead while meeting autoscaling and pay-per-use requirements.

Exam trap

The trap here is assuming that managed instance groups or GKE are less operational overhead because they are managed, but they still require significant configuration and maintenance.

24
MCQhard

A company has a production database running on Cloud SQL. They need to ensure high availability with automatic failover in the event of a zone outage. What should they do?

A.Export the database to Cloud Storage and import in another region.
B.Enable Cloud SQL High Availability (HA) configuration.
C.Create a cross-region read replica.
D.Configure automated backups.
AnswerB

Cloud SQL High Availability provisions a standby instance in a separate zone with synchronous replication, enabling automatic failover during a zone outage. This directly satisfies the stated availability constraint, whereas read replicas and backups do not provide automatic failover.

Why this answer

Enabling Cloud SQL High Availability (HA) configuration provisions a standby instance in a different zone within the same region, using synchronous replication to ensure zero data loss. In the event of a zone outage, Cloud SQL automatically fails over to the standby instance, typically within 60 seconds, providing high availability without manual intervention.

Exam trap

Google Cloud often tests the distinction between high availability (automatic failover within a region) and disaster recovery (cross-region replication or backups), leading candidates to confuse read replicas or backups with HA solutions.

How to eliminate wrong answers

Option A is wrong because exporting to Cloud Storage and importing in another region is a manual, disaster recovery process that does not provide automatic failover and incurs significant downtime. Option C is wrong because a cross-region read replica is designed for read scaling and asynchronous replication, not for automatic failover; promoting a read replica requires manual steps and may result in data loss. Option D is wrong because automated backups protect against data corruption or accidental deletion but do not provide a standby instance for automatic failover during a zone outage.

25
MCQmedium

A company is migrating a stateful application to Google Cloud. The application requires persistent disks with low latency and high IOPS for database workloads. They plan to use Compute Engine instances with SSD persistent disks. However, the database performance is lower than expected. Which action should the company take to improve disk performance?

A.Change the persistent disk type to standard persistent disk.
B.Increase the disk size to increase baseline IOPS.
C.Use local SSDs with RAID 0 configuration for the database data.
D.Enable disk encryption to improve I/O throughput.
AnswerC

Local SSDs attach directly to the host, delivering far lower latency and higher IOPS than persistent SSD disks. RAID 0 stripes data across multiple local SSDs, multiplying throughput to meet the database workload's performance requirement.

Why this answer

Local SSDs provide the highest IOPS and lowest latency of any disk option on Compute Engine, and striping them with RAID 0 aggregates their performance. This directly addresses the need for high IOPS and low latency for database workloads, unlike persistent disks which have performance ceilings tied to disk size and instance limits.

Exam trap

The trap here is that candidates often assume increasing persistent disk size is the only way to improve IOPS, overlooking that local SSDs provide dramatically higher performance by being directly attached to the instance, and that RAID 0 is a common technique to aggregate their performance.

How to eliminate wrong answers

Option A is wrong because standard persistent disks have lower IOPS and higher latency than SSD persistent disks, which would worsen performance, not improve it. Option B is wrong because while increasing disk size does increase baseline IOPS for SSD persistent disks, the performance gain is limited by the persistent disk's architecture and does not match the raw throughput of local SSDs; it also increases cost without solving the latency issue. Option D is wrong because enabling disk encryption (e.g., using CMEK or CSEK) does not improve I/O throughput; encryption adds a small CPU overhead for encryption/decryption operations and can slightly reduce performance.

26
Multi-Selectmedium

Which THREE of the following are best practices when using Deployment Manager to manage infrastructure? (Choose three.)

Select 3 answers
A.Use raw REST API calls in templates.
B.Use templates to define resources modularly.
C.Use only YAML configuration files.
D.Use imports to reference shared configurations.
E.Use composite types to bundle related resources.
AnswersB, D, E

Templates decompose infrastructure into reusable, independently deployable modules, satisfying Deployment Manager's requirement for modular resource definitions. This enables consistent parameterised deployments across environments, reduces duplication, and supports version control of individual components rather than monolithic configurations.

Why this answer

Option B is correct because Deployment Manager templates let you define resources modularly, so reusable building blocks (for example a VM template) can be instantiated multiple times with different properties instead of duplicating configuration. Option D is correct because imports allow a configuration or template to reference shared, external templates (such as a common network or firewall template), promoting reuse and consistent configuration across deployments. Option E is correct because composite types bundle multiple related resources into a single reusable type, which simplifies managing and repeating multi-resource patterns.

Option A is not a best practice: raw REST API calls inside templates bypass the declarative template model and make configurations harder to maintain and reuse. Option C is not a best practice: Deployment Manager supports both YAML and Jinja/Python templates, so restricting yourself to only YAML configuration files unnecessarily limits templating and logic capabilities.

Exam trap

The trap here is assuming that only YAML is supported or that raw API calls are acceptable for advanced use. Candidates may overlook that Deployment Manager supports Python and Jinja2, and that modularity via imports and composite types is encouraged.

27
MCQmedium

A Cloud Function fails to connect to a Cloud SQL instance. The Cloud SQL instance has a private IP. What should the developer check?

A.Ensure the Cloud SQL Proxy is running and configured.
B.Verify the Cloud Function's network settings.
C.Ensure either Cloud SQL Proxy is running or a VPC connector is configured, and IAM permissions are correct.
D.Configure a VPC connector for the Cloud Function.
AnswerC

Both connectivity and authorization must be in place.

Why this answer

A Cloud Function with a private IP Cloud SQL instance requires either the Cloud SQL Proxy (which uses the Cloud SQL Auth proxy to establish an encrypted connection via the public IP, but if the instance has only a private IP, the proxy must be run within the same VPC) or a VPC connector to enable private networking. Additionally, proper IAM permissions (e.g., Cloud SQL Client role) are necessary for the proxy or connector to authenticate and connect. Without both the network path and IAM permissions, the connection will fail.

Exam trap

Google Cloud often tests the misconception that either a VPC connector or the Cloud SQL Proxy alone is sufficient, when in fact both the network path (via VPC connector or proxy in the VPC) and correct IAM permissions are required for private IP connectivity.

How to eliminate wrong answers

Option A is wrong because simply ensuring the Cloud SQL Proxy is running and configured is insufficient if the Cloud Function is not in the same VPC or lacks a VPC connector; the proxy alone cannot reach a private IP Cloud SQL instance from outside the VPC. Option B is wrong because verifying the Cloud Function's network settings is too vague and does not address the specific requirement of establishing a private network path via a VPC connector or proxy within the VPC. Option D is wrong because configuring a VPC connector alone is not enough; the Cloud SQL Proxy must also be running (or the connector must be paired with proper IAM permissions and the Cloud SQL Auth proxy) to handle authentication and encryption, and IAM permissions must be correct.

28
MCQmedium

A company uses Terraform to manage Google Cloud infrastructure. They want to store the Terraform state file in a remote backend with state locking to prevent concurrent modifications. Which Google Cloud service supports this natively?

A.Cloud Firestore
B.Cloud Spanner
C.Bigtable
D.Cloud Storage
E.Cloud SQL
AnswerD

Correct. Cloud Storage is the native Terraform backend for GCP.

Why this answer

Google Cloud Storage (GCS) is the only option that natively supports Terraform's remote state backend with state locking. Terraform uses GCS's object versioning and a write-lock mechanism via a separate lock file (e.g., `default.tflock`) stored in the same bucket, leveraging GCS's strong consistency for atomic operations. This prevents concurrent `terraform apply` commands from corrupting the state.

Exam trap

Google Cloud often tests the misconception that any database with locking (like Cloud Spanner or Cloud SQL) can serve as a Terraform backend, but the exam requires knowing that only services with a native Terraform backend implementation—specifically Cloud Storage—are supported for state locking.

How to eliminate wrong answers

Option A is wrong because Cloud Firestore is a NoSQL document database designed for mobile/web apps, not for Terraform state locking; it lacks native Terraform backend support. Option B is wrong because Cloud Spanner is a globally distributed relational database with strong consistency, but Terraform does not provide a native Spanner backend for state storage. Option C is wrong because Bigtable is a wide-column NoSQL database optimized for high-throughput analytics, not for Terraform state management; it has no native Terraform backend integration.

Option E is wrong because Cloud SQL is a managed relational database service (MySQL/PostgreSQL/SQL Server) that Terraform does not support as a native state backend; it would require custom tooling for locking.

29
MCQhard

An organization wants to enforce a policy that prohibits the creation of Cloud Storage buckets with uniform bucket-level access disabled. What should they use?

A.Organization policy with a list constraint.
B.IAM roles with custom permissions to deny bucket creation.
C.Cloud Audit Logs to monitor bucket creation.
D.Cloud Armor security policies.
AnswerA

An organisation policy with a list constraint enforces exactly this prohibition: the constraint `storage.uniformBucketLevelAccess` accepts allowed values, and denying `false` blocks bucket creation where uniform bucket-level access is disabled. This satisfies the stem's requirement to prevent, rather than merely detect, non-compliant buckets across the organisation.

Why this answer

Organization policies can enforce constraints like constraints/storage.uniformBucketLevelAccess to require uniform bucket-level access. Option B (IAM roles with custom permissions) cannot deny bucket creation with specific settings. Option C (Cloud Audit Logs) is for logging, not enforcement.

Option D (Cloud Armor) is for security policies at the edge.

30
MCQeasy

A user runs the gsutil command shown in the exhibit and gets an AccessDenied error. The user is not authenticated with gcloud. What should the user do first?

A.Create a service account and download a JSON key.
B.Grant public write access to the bucket.
C.Use gcloud config set project my-project to set the project.
D.Run gcloud auth login to authenticate with their Google account.
AnswerD

gsutil relies on credentials from gcloud authentication. Since the user is not authenticated, no access token exists, so the request fails with AccessDenied. Running gcloud auth login establishes the Google account credentials gsutil then uses, resolving the authentication failure before any permission check occurs.

Why this answer

The error occurs because the user is not authenticated with gcloud. The gsutil command requires valid authentication credentials to access Google Cloud Storage resources. Running `gcloud auth login` initiates the OAuth 2.0 flow, which authenticates the user with their Google account and generates the access token that gsutil uses for API calls.

This is the prerequisite step before any gsutil operation can succeed.

Exam trap

Google Cloud often tests the distinction between authentication (who you are) and authorization (what you can do); the trap here is that candidates may confuse the AccessDenied error with a bucket permission issue and jump to granting public access or setting a project, when the root cause is simply missing authentication credentials.

How to eliminate wrong answers

Option A is wrong because creating a service account and downloading a JSON key is an alternative authentication method, but it is not the first step; the user must first authenticate with gcloud (either via user account or service account) before gsutil can use those credentials. Option B is wrong because granting public write access to the bucket would bypass authentication entirely, which is a severe security misconfiguration and not a solution for an unauthenticated user; the error is about missing credentials, not bucket permissions. Option C is wrong because `gcloud config set project my-project` only sets the default project for gcloud commands but does not authenticate the user; without authentication, gsutil still cannot access any bucket regardless of the project setting.

31
MCQhard

A security team wants to audit all IAM role assignments in an organization. They need a historical record of changes. Which tool should they use?

A.Cloud Asset Inventory
B.Access Transparency
C.Cloud Audit Logs
D.Security Command Center
AnswerC

Cloud Audit Logs records IAM policy and role binding changes as immutable, timestamped Admin Activity entries retained for the project or organisation. This provides the historical change record the audit requires, unlike current-state views such as IAM policy queries.

Why this answer

Cloud Audit Logs (specifically Admin Activity audit logs) record all API calls that modify IAM policies, including role assignments. These logs are immutable and retained for the default retention period (400 days for Admin Activity logs), providing a historical record of changes. Cloud Asset Inventory (A) shows the current state but not historical changes, Access Transparency (B) logs Google staff access to your data, and Security Command Center (D) provides security findings and posture, not a change history.

Exam trap

Google Cloud often tests the distinction between tools that show current state (Cloud Asset Inventory) versus tools that record historical changes (Cloud Audit Logs), leading candidates to pick Cloud Asset Inventory because it 'audits' resources, but it does not provide a change history.

How to eliminate wrong answers

Option A is wrong because Cloud Asset Inventory provides a snapshot of current IAM role assignments and other resources, but it does not maintain a historical record of changes; it lacks the audit trail capability. Option B is wrong because Access Transparency logs actions performed by Google personnel when accessing your data, not IAM role assignment changes made by your own users or services. Option D is wrong because Security Command Center is a security and risk management platform that aggregates findings and vulnerabilities, but it does not natively record a chronological history of IAM policy modifications.

32
MCQhard

A company has Compute Engine instances that need to access the internet for updates but should not be reachable from the internet. They also need to access Google APIs and services like Cloud Storage. Which configuration meets these requirements?

A.Use Cloud NAT for outbound internet and enable Private Google Access on the subnet.
B.Assign external IPs to all instances and configure firewall rules to block inbound traffic.
C.Configure a VPN tunnel to an on-premises proxy server for internet access.
D.Use Cloud NAT for outbound internet and use external IPs for Google API access.
AnswerA

Cloud NAT provides outbound internet access for instances lacking external IP addresses, while Private Google Access lets those instances reach Google APIs and Cloud Storage internally. Together they satisfy both requirements without exposing instances to inbound internet traffic.

Why this answer

Cloud NAT provides outbound internet connectivity for instances without external IPs, while Private Google Access allows those same instances to reach Google APIs and services (like Cloud Storage) using internal IPs via the subnet's default route. This combination ensures instances can initiate outbound connections to the internet and Google services but remain unreachable from the internet, meeting both security and functional requirements.

Exam trap

The trap here is that candidates often think Cloud NAT alone is sufficient for Google API access, but they miss that Private Google Access must be explicitly enabled on the subnet for instances without external IPs to reach Google APIs and services.

How to eliminate wrong answers

Option B is wrong because assigning external IPs makes instances directly reachable from the internet, even with firewall rules blocking inbound traffic; the external IP itself exposes the instance to potential attacks (e.g., DDoS) and violates the requirement that instances should not be reachable from the internet. Option C is wrong because a VPN tunnel to an on-premises proxy server adds unnecessary complexity, latency, and dependency on on-premises infrastructure; it does not directly address the need for Google API access, which is better served by Private Google Access. Option D is wrong because using external IPs for Google API access defeats the purpose of Cloud NAT; instances with external IPs are still reachable from the internet (even if only for API calls), and the requirement explicitly states instances should not be reachable from the internet.

33
MCQmedium

A Cloud Run service frequently fails with 502 errors when making requests to a backend service running on Compute Engine. The two services are in the same VPC network. The Cloud Run service is configured with a VPC connector. What is the most likely cause?

A.The Cloud Run service needs to be peered with the VPC using VPC Network Peering.
B.The VPC connector is set to a low number of instances, causing traffic throttling.
C.The VPC connector is not attached to the correct subnet, or the firewall rules are blocking traffic from the connector's IP range.
D.The Cloud Run service's service account lacks the roles/compute.instanceAdmin role.
AnswerC

Serverless VPC access routes Cloud Run egress through the connector's own subnet and IP range, not the service's. If the connector sits in the wrong subnet or firewall rules omit its range, Compute Engine silently drops packets, surfacing as 502 responses.

Why this answer

Cloud Run uses a VPC connector to send requests to resources in a VPC. If the connector is attached to the wrong subnet, its egress traffic may not reach the Compute Engine instance, or firewall rules may block traffic from the connector's IP range (e.g., 10.8.0.0/28). This results in 502 errors from the backend, as the Cloud Run service cannot establish a TCP connection to the Compute Engine instance.

Exam trap

The trap here is that candidates confuse VPC Network Peering (used for inter-VPC connectivity) with the VPC connector (used for serverless-to-VPC access), and they overlook the firewall rules that must explicitly allow traffic from the connector's IP range.

How to eliminate wrong answers

Option A is wrong because VPC Network Peering is used to connect two separate VPC networks, not to connect a serverless service to its own VPC; Cloud Run uses a VPC connector, not peering. Option B is wrong because a low number of VPC connector instances causes throttling or increased latency, not 502 errors; 502 errors indicate a failure to reach or get a valid response from the backend, not a capacity issue. Option D is wrong because the roles/compute.instanceAdmin role grants permissions to manage Compute Engine instances, but Cloud Run does not need that role to make HTTP requests to a backend; it only needs network connectivity via the VPC connector.

34
MCQhard

A company uses Shared VPC. A project admin in a service project tries to create a subnet in the shared VPC network but receives a permission denied error. What is the most likely cause?

A.Only the Shared VPC host project admin can create subnets.
B.The service project admin lacks the compute.subnetworks.create permission on the host project.
C.The Shared VPC is not enabled for the service project.
D.Subnets must be created in the service project, not the host project.
AnswerB

In Shared VPC, subnet creation rights reside with the host project, not the service project. The service project admin needs the compute.subnetworks.create permission granted on the host project, which explains the permission denied error when attempting to create the subnet.

Why this answer

In a Shared VPC architecture, subnet creation is a privileged operation that can only be performed by a user with the compute.subnetworks.create permission on the host project. The service project admin, by default, does not have this permission in the host project, which is why the permission denied error occurs. Granting this permission to the service project admin at the host project level would resolve the issue.

Exam trap

Google Cloud often tests the misconception that service project admins have full control over the shared network, when in reality they only have usage permissions unless explicitly granted administrative permissions on the host project.

How to eliminate wrong answers

Option A is wrong because it is not strictly 'only the host project admin' who can create subnets; any user with the compute.subnetworks.create permission on the host project can do so, including a service project admin if that permission is explicitly granted. Option C is wrong because the Shared VPC being enabled for the service project is a prerequisite for using the shared network, but the error here is about permissions, not about the feature being disabled. Option D is wrong because subnets in a Shared VPC must be created in the host project, not the service project; the service project consumes subnets from the host project.

35
Matchingmedium

Match each GCP monitoring/logging tool to its purpose.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Metrics, dashboards, alerts

Centralized log storage and analysis

Distributed tracing for latency analysis

Inspect code behavior in production

CPU and memory profiling

Why these pairings

Correct matches: Cloud Monitoring monitors performance, Cloud Logging manages logs, Error Reporting tracks errors. Confusion often arises between logging and monitoring roles.

36
MCQhard

A financial services company runs a critical application on a managed instance group (MIG) of Compute Engine instances. The application must be highly available and able to survive a zone failure without manual intervention. The company wants to ensure that the MIG automatically recovers from zone failures and maintains capacity. They also want to minimize latency for users across the United States. Which configuration should they use?

A.Regional MIG with autoscaling enabled and a load balancer with a single backend service
B.Regional MIG with autoscaling enabled and a global external HTTP(S) load balancer
C.Regional MIG with autoscaling enabled and an internal TCP/UDP load balancer
D.Zonal MIG with autoscaling enabled and a global external HTTP(S) load balancer
AnswerB

A regional MIG spreads instances across multiple zones in a region, so if one zone fails, instances in other zones continue to serve traffic. Autoscaling ensures capacity is maintained. A global external HTTP(S) load balancer provides a single anycast IP and routes users to the closest healthy backend, minimizing latency across the US. This combination meets high availability and low latency requirements.

Why this answer

A regional managed instance group distributes instances across multiple zones, ensuring that a zone failure does not take down the application. Autoscaling maintains capacity. A global external HTTP(S) load balancer uses a single anycast IP and routes traffic to the nearest healthy backend, reducing latency for users across the United States.

This combination provides both high availability and low latency.

Exam trap

The trap here is confusing internal and external load balancers, or assuming that a zonal MIG with a global load balancer can survive a zone failure.

37
MCQhard

An organization needs to audit all changes to network firewall rules in a GCP project. Which service should be used to capture these changes?

A.Cloud Logging
B.Cloud Monitoring
C.Cloud Audit Logs
D.VPC Flow Logs
AnswerC

Cloud Audit Logs records Admin Activity and Data Access entries, including firewall rule insertions, updates and deletions in a GCP project. It is the native service that captures these configuration changes for audit, satisfying the requirement to track all firewall rule modifications.

Why this answer

Cloud Audit Logs (specifically Admin Activity audit logs) record all API calls that modify the configuration or metadata of resources, including changes to firewall rules. When a firewall rule is created, updated, or deleted, an audit log entry is automatically generated with details such as the user, timestamp, and the change made. This makes Cloud Audit Logs the correct service for auditing changes to network firewall rules in a GCP project.

Exam trap

The trap here is that candidates confuse Cloud Logging (which is a general log storage and analysis platform) with Cloud Audit Logs (which is a specific type of log that records administrative actions), leading them to pick A instead of C.

How to eliminate wrong answers

Option A is wrong because Cloud Logging is a service for ingesting, storing, and analyzing log data from various sources, but it does not natively capture configuration changes to firewall rules; it would require custom log sinks or agents to collect such data. Option B is wrong because Cloud Monitoring focuses on metrics, uptime checks, and alerting based on performance and health indicators, not on recording API-driven configuration changes. Option D is wrong because VPC Flow Logs capture network traffic metadata (e.g., source/destination IPs, ports, protocols) for flow-level analysis, not the administrative changes to firewall rule definitions.

38
MCQmedium

A company is deploying a new application on Compute Engine. They need to ensure that the application can automatically recover from a zone failure. What is the best approach?

A.Create a managed instance group with instances in multiple zones.
B.Use a global load balancer in front of a single instance.
C.Create a single VM in a single zone and rely on live migration.
D.Use Cloud Storage to store application state and restore from a snapshot.
AnswerA

A managed instance group spanning multiple zones maintains capacity when one zone fails, satisfying the automatic zone-failure recovery requirement. The group's regional distribution and autohealing replace unhealthy instances in surviving zones, unlike a single-zone group or manual restart, which cannot survive zone loss.

Why this answer

A managed instance group (MIG) with instances in multiple zones provides automatic recovery from a zone failure by distributing instances across zones and using auto-healing to recreate failed instances. If one zone becomes unavailable, the load balancer routes traffic to healthy instances in other zones, ensuring high availability without manual intervention.

Exam trap

Google Cloud often tests the distinction between live migration (which handles host maintenance but not zone failures) and multi-zone MIGs (which handle zone failures), leading candidates to mistakenly choose live migration as a recovery mechanism.

How to eliminate wrong answers

Option B is wrong because a global load balancer in front of a single instance does not provide zone-level redundancy; if the zone fails, the single instance becomes unavailable, and the load balancer has no healthy backend to route traffic to. Option C is wrong because live migration only protects against host maintenance events, not zone failures; if the entire zone fails, the VM is lost and cannot be recovered automatically. Option D is wrong because storing application state in Cloud Storage and restoring from a snapshot is a disaster recovery approach, not an automatic recovery mechanism; it requires manual steps to recreate the VM and does not provide seamless failover.

39
Multi-Selecthard

Which THREE are best practices for designing a highly available application on Compute Engine?

Select 3 answers
A.Use local SSDs for stateful data
B.Use a single large machine type
C.Use managed instance groups with autoscaling
D.Use an external load balancer with health checks
E.Distribute instances across multiple zones
AnswersC, D, E

Managed instance groups with autoscaling maintain instances across multiple zones, automatically replacing failed VMs and scaling capacity to match demand. This directly satisfies the high-availability requirement by eliminating single points of failure and absorbing load spikes without manual intervention, ensuring continuous service during zone outages or traffic surges.

Why this answer

Option C is correct because a managed instance group (MIG) with autoscaling automatically maintains the desired number of healthy VM instances and replaces failed ones, which is fundamental to high availability on Compute Engine. Option D is correct because an external load balancer with health checks only routes traffic to healthy backends and removes unhealthy instances from rotation, preventing users from hitting failed VMs. Option E is correct because distributing instances across multiple zones protects the application from a single-zone failure, since zonal outages do not affect instances in other zones within the same region.

Option A is not appropriate because local SSDs are ephemeral and tied to a single VM, so they cannot store durable stateful data for a highly available design. Option B is not appropriate because a single large machine type creates a single point of failure and cannot provide redundancy or fault tolerance.

Exam trap

Google Cloud often tests the misconception that local SSDs are suitable for stateful data in HA designs, but the trap is that local SSDs are ephemeral and data is lost on instance failure, so they should only be used for cache or temporary data, not for persistent state.

40
Multi-Selectmedium

Which TWO statements are true about Google Cloud VPC networks? (Select exactly 2.)

Select 2 answers
A.Each VPC network is regional in scope.
B.By default, no firewall rules are created in a new VPC.
C.Subnets are regional resources and can span zones.
D.VPC Peering allows private RFC 1918 connectivity across VPCs.
E.VPC Peering supports transitive routing.
AnswersC, D

Subnets are regional and each subnet can have IP ranges across zones.

Why this answer

Google Cloud VPC subnets are regional resources that can span multiple zones within the same region. This allows resources in different zones to use the same subnet without requiring additional routing or VPN configuration, providing high availability and fault tolerance within a region.

Exam trap

The trap here is that candidates often confuse VPC scope with subnet scope, assuming VPCs are regional like in AWS, but Google Cloud VPCs are global, and they may also mistakenly believe VPC Peering supports transitive routing, which it explicitly does not.

41
MCQhard

A healthcare company stores sensitive patient data in Cloud Storage buckets. The company must ensure that data is encrypted at rest with keys that are automatically rotated every 90 days and that the keys are managed by the company itself, not by Google. The company also needs to maintain full control over key lifecycle and access policies. Which encryption option should the architect recommend?

A.Cloud External Key Manager (Cloud EKM) with keys stored in a third-party HSM.
B.Google-managed encryption keys (GMEK) with default encryption.
C.Customer-managed encryption keys (CMEK) using Cloud KMS with a 90-day rotation schedule.
D.Customer-supplied encryption keys (CSEK) provided with each request.
AnswerC

Customer-managed encryption keys in Cloud KMS allow the company to create and manage keys, set rotation schedules (e.g., every 90 days), and define access policies via IAM. CMEK integrates with Cloud Storage to encrypt data at rest, and the company retains full control over key lifecycle. This meets all requirements: encryption at rest, automatic rotation, and self-management.

Why this answer

Customer-managed encryption keys (CMEK) in Cloud KMS allow the healthcare company to manage its own encryption keys, set a 90-day rotation schedule, and control access via IAM. This satisfies the requirements for encryption at rest, automatic key rotation, and full control over key lifecycle. Other options either do not provide self-management or lack automatic rotation.

Exam trap

The trap here is confusing customer-managed encryption keys (CMEK) with customer-supplied encryption keys (CSEK); CSEK are not stored in Cloud KMS and do not support automatic rotation.

42
Multi-Selectmedium

Which TWO are best practices when designing a VPC network for a multi-tier application in Google Cloud?

Select 2 answers
A.Disable VPC Flow Logs to reduce cost.
B.Create separate subnets for each application tier.
C.Use firewall rules to restrict traffic between tiers to only necessary ports.
D.Use a single subnet for all tiers to simplify IP management.
E.Rely on the default priority of firewall rules to ensure proper ordering.
AnswersB, C

Subnets allow segmentation and granular firewall rules.

Why this answer

Creating separate subnets for each application tier (e.g., web, application, database) allows you to apply granular firewall rules and routing policies per tier. This segmentation improves security by isolating traffic between tiers and aligns with Google Cloud's best practices for multi-tier architectures. It also simplifies network troubleshooting and scaling by keeping each tier's IP space distinct.

Exam trap

The trap here is that candidates assume a single subnet simplifies management (Option D) or that disabling flow logs is a harmless cost-saving measure (Option A), but the exam expects you to prioritize security and observability over minor cost savings or administrative convenience.

43
MCQeasy

A startup is deploying a new web application on Google Cloud. They want to use a fully managed, serverless platform that automatically scales and requires no infrastructure management. The application is containerized and listens on HTTP. Which Google Cloud service should they use?

A.Cloud Run
B.Google Kubernetes Engine (GKE)
C.Compute Engine
D.App Engine flexible environment
AnswerA

Cloud Run is a fully managed serverless platform that runs containerized applications. It automatically scales based on traffic, including scaling to zero when there is no traffic. It abstracts away all infrastructure management. It supports HTTP and gRPC, making it ideal for this web application. This meets all requirements.

Why this answer

Cloud Run is a fully managed serverless platform that runs containers and automatically scales, including to zero. It requires no infrastructure management, making it ideal for a startup wanting to deploy a containerized web application. Compute Engine and GKE require more management, and App Engine flexible environment is not fully serverless.

Exam trap

The trap here is confusing GKE Autopilot or App Engine flexible with a fully serverless platform that scales to zero and requires no infrastructure management.

44
MCQmedium

A developer notices that web-server-1 is preemptible. They want to ensure their application remains available even if this instance is terminated. What should they do?

A.Modify the instance's preemptible flag to false.
B.Create a managed instance group for web-server-1 and set an autoscaler.
C.Create a load balancer pointing to web-server-1's external IP.
D.Create a snapshot schedule for web-server-1.
AnswerB

A managed instance group replaces the single preemptible VM with multiple identical instances, so termination of one does not cause an outage. The autoscaler maintains capacity and recreates instances automatically, satisfying the availability requirement despite preemption.

Why this answer

A managed instance group (MIG) with an autoscaler ensures that if the preemptible instance is terminated, the MIG automatically recreates it to maintain the desired number of instances. This provides resilience against preemption by restoring capacity without manual intervention. The load balancer can then distribute traffic across healthy instances in the group.

Exam trap

Google Cloud often tests the misconception that a load balancer alone provides high availability, but without a managed instance group to recreate terminated instances, the load balancer has no healthy backends to route traffic to.

How to eliminate wrong answers

Option A is wrong because modifying the preemptible flag to false would make the instance a standard (non-preemptible) instance, but this does not address availability during termination—it only prevents future preemption, and the instance could still fail for other reasons. Option C is wrong because a load balancer pointing to a single instance's external IP does not provide high availability; if the instance is terminated, the load balancer has no healthy backend and traffic is lost. Option D is wrong because a snapshot schedule only backs up persistent disks, it does not recreate the instance or maintain application availability after termination.

45
Multi-Selectmedium

Which TWO options are valid ways to connect an on-premises network to a VPC in Google Cloud? (Choose two.)

Select 2 answers
A.Cloud VPN.
B.Dedicated Interconnect.
C.Cloud NAT.
D.VPC Network Peering.
E.Private Google Access.
AnswersA, B

Cloud VPN provides IPsec tunnels to on-premises.

Why this answer

Cloud VPN is a valid way to connect an on-premises network to a VPC in Google Cloud. It uses IPsec (IKEv1 or IKEv2) to create an encrypted tunnel over the public internet between your on-premises VPN gateway and a Cloud VPN gateway in your VPC. This allows secure communication between your on-premises resources and your VPC subnets, making it a standard hybrid connectivity option.

Exam trap

Google Cloud often tests the distinction between services that provide connectivity to a VPC (like VPN and Interconnect) versus services that only enable outbound internet access or internal VPC-to-VPC peering, leading candidates to mistakenly select Cloud NAT or VPC Network Peering.

46
MCQmedium

Your company is using Cloud Storage to store sensitive customer data. The security team requires that all objects be encrypted with a customer-managed encryption key (CMEK) and that the key be automatically rotated every 90 days. You need to implement this without changing the application code. You have created a Cloud KMS key ring and a key with rotation period set to 90 days. What additional configuration is required?

A.Set a bucket lifecycle rule to transition objects to a different storage class.
B.Create a custom customer-supplied encryption key (CSEK) and provide it in each request.
C.Grant the Cloud KMS CryptoKey Encrypter/Decrypter role to the Cloud Storage service account.
D.Set the default encryption key of the Cloud Storage bucket to the Cloud KMS key.
AnswerD

Setting the bucket's default encryption key to the Cloud KMS key applies CMEK automatically to every newly written object, satisfying the customer-managed key requirement without application changes. Cloud KMS handles the 90-day rotation transparently, since rotation generates new key versions while the key resource name stays constant, so existing object references remain valid.

Why this answer

Setting the default encryption key of the Cloud Storage bucket to the Cloud KMS key ensures that all objects written to the bucket are automatically encrypted with that CMEK, without requiring any application code changes. The Cloud KMS key's rotation period of 90 days is already configured, so the key will be rotated automatically, meeting the security team's requirement.

Exam trap

The trap here is that candidates may think granting the Cloud KMS role to the Cloud Storage service account (Option C) is sufficient, but they overlook the critical step of actually setting the key as the default encryption key on the bucket to enforce automatic encryption.

How to eliminate wrong answers

Option A is wrong because bucket lifecycle rules manage object transitions between storage classes or deletion, not encryption key configuration or rotation. Option B is wrong because CSEK requires providing the key in each request, which would necessitate changing application code, and CSEK keys cannot be automatically rotated by Cloud KMS. Option C is wrong because granting the Cloud KMS CryptoKey Encrypter/Decrypter role to the Cloud Storage service account is necessary for the service account to use the key, but it is not the additional configuration required to enforce encryption on the bucket; the key must also be set as the default encryption key on the bucket.

47
MCQeasy

A company runs a batch processing job that runs daily and can handle interruptions. The job runs on a single Compute Engine instance. Which machine configuration is the most cost-effective?

A.A n2-standard-4 VM with sustained use discount
B.A standard n1-standard-4 VM
C.A preemptible n1-standard-4 VM
D.A n1-standard-4 VM with a GPU
AnswerC

Preemptible VMs cost up to 80% less than standard instances, and the batch job tolerates interruption, satisfying the stem's fault-tolerance constraint. A 24-hour maximum runtime suits a daily job. The n1-standard-4 provides four vCPUs and 15 GB memory, adequate for batch processing without over-provisioning.

Why this answer

A preemptible VM costs significantly less than a standard VM (up to 80% discount) and is ideal for batch processing jobs that can handle interruptions. The job runs daily and can tolerate being stopped, so the lower cost of a preemptible instance provides the most cost-effective solution without sacrificing functionality.

Exam trap

Google Cloud often tests the misconception that sustained use discounts are the most cost-effective option, but the trap here is that preemptible VMs provide a much deeper discount for fault-tolerant workloads, and candidates may overlook the 'can handle interruptions' requirement in the question.

How to eliminate wrong answers

Option A is wrong because a n2-standard-4 VM with sustained use discount is more expensive than a preemptible VM; sustained use discounts apply automatically for running instances over a month, but they do not match the deep discount of preemptible instances, and the n2 series is a newer, higher-performance generation that is unnecessary for a batch job that can handle interruptions. Option B is wrong because a standard n1-standard-4 VM incurs full on-demand pricing, which is not cost-effective for a fault-tolerant batch job that can use cheaper preemptible instances. Option D is wrong because adding a GPU to an n1-standard-4 VM increases cost significantly and provides no benefit for a batch processing job that does not require GPU acceleration, making it the least cost-effective option.

48
MCQhard

A company is migrating a monolithic application to microservices on Google Cloud. They need to manage service-to-service authentication and authorization. Which service should they use?

A.Cloud NAT
B.Cloud Identity-Aware Proxy
C.Cloud Endpoints
D.Service Mesh (Anthos)
AnswerD

Anthos Service Mesh issues mutual TLS identities to each workload, so service-to-service authentication and authorisation are enforced without application code changes. This satisfies the microservices requirement for cryptographic workload identity and policy-based access control across the mesh.

Why this answer

Service Mesh (Anthos) provides a dedicated infrastructure layer for managing service-to-service communication, including mutual TLS (mTLS) authentication, fine-grained authorization policies, and observability. It uses sidecar proxies (Envoy) to intercept traffic and enforce security policies without modifying application code, making it ideal for microservices authentication and authorization.

Exam trap

The trap here is that candidates often confuse Cloud Endpoints (API management for external clients) with the internal service-to-service security needs of microservices, or assume Cloud IAP can be extended to internal traffic, but IAP only works for user-facing HTTP(S) requests and cannot enforce policies between backend services.

How to eliminate wrong answers

Option A is wrong because Cloud NAT is a network address translation service for outbound internet access from private instances, not for service-to-service authentication or authorization. Option B is wrong because Cloud Identity-Aware Proxy (IAP) is designed for user-to-application authentication and access control at the edge, not for internal service-to-service communication within a VPC. Option C is wrong because Cloud Endpoints is an API management service that handles API keys, authentication, and quotas for external-facing APIs, but it does not provide the sidecar-based, fine-grained service-to-service authentication and authorization needed for microservices.

49
MCQeasy

When creating a Compute Engine instance from a custom image stored in another project, which gcloud flag is required?

A.--image-project
B.--source-instance
C.--image
D.--image-family
AnswerA

The --image-project flag specifies which project owns the custom image, satisfying the requirement to create an instance from an image stored in another project. Without it, gcloud searches only the instance's own project and fails to resolve the image reference.

Why this answer

When creating a Compute Engine instance from a custom image stored in another project, the `--image-project` flag is required to specify the project that contains the image. Without this flag, gcloud defaults to the current project and will not find the image. The `--image` flag is also required to specify the image name, but the question specifically highlights the cross-project situation, making `--image-project` the distinctive required flag.

Exam trap

Candidates often think that `--image` is sufficient, but when using an image from another project, `--image-project` is mandatory; otherwise the instance creation will fail.

How to eliminate wrong answers

Option A is wrong because `--image-project` is not required when using a custom image from another project; it is only needed when specifying a public image from a different project (e.g., `--image-project debian-cloud`). Option B is wrong because `--source-instance` is used to create an image from an existing instance, not to specify an image when creating a new instance. Option D is wrong because `--image-family` is used to select the latest non-deprecated image from a family (e.g., `ubuntu-2204-lts`), not to reference a specific custom image by name.

50
MCQhard

A company runs a stateful application on Google Kubernetes Engine (GKE) that requires persistent storage and low-latency access across multiple zones. The application needs to perform well even during zonal failures. Which storage solution should they use?

A.Zonal persistent disk with snapshots to another zone
B.Local SSDs attached to nodes
C.Cloud Filestore
D.Regional persistent disk
AnswerD

Regional persistent disks synchronously replicate data across two zones within a region, so the stateful workload survives a zonal failure while retaining low-latency block access. This satisfies the stem's simultaneous multi-zone durability and zonal-failure performance constraints.

Why this answer

Regional persistent disks (RPDs) synchronously replicate data across two zones in the same region, providing both the persistent storage and low-latency access required by the stateful application. This ensures that if one zone fails, the disk can be attached to a pod in the surviving zone without data loss or significant performance degradation, meeting the high-availability and multi-zone access requirements.

Exam trap

The trap here is that candidates confuse high-availability features like snapshots or local SSDs with true synchronous replication, overlooking that only regional persistent disks provide both persistence and zero-RPO failover across zones without manual restore steps.

How to eliminate wrong answers

Option A is wrong because zonal persistent disks with snapshots to another zone introduce recovery time (snapshot restore) and potential data loss (snapshot frequency), failing to provide the synchronous, low-latency multi-zone access needed during zonal failures. Option B is wrong because local SSDs are ephemeral and tied to a specific node; data is lost if the node or zone fails, and they cannot be shared across zones, violating the persistent storage requirement. Option C is wrong because Cloud Filestore is a managed NFS file storage service designed for shared file systems, not for low-latency block storage access required by stateful applications on GKE, and it introduces network latency compared to directly attached persistent disks.

51
MCQhard

A financial services company needs to ensure that all outbound traffic from its Compute Engine instances to the internet goes through a dedicated IP address for allowlisting by a partner. The instances are in a private subnet with no external IP addresses. The company wants to minimize management overhead and avoid single points of failure. Which solution should the architect implement?

A.Assign external IP addresses to all instances and use Cloud DNS to map them to a single hostname for the partner.
B.Configure a Cloud NAT gateway with a manual IP address allocation and attach it to the VPC network in the region where the instances reside.
C.Create a VPN tunnel to the partner's network and route all internet-bound traffic through the partner's gateway.
D.Deploy a third-party firewall appliance on a Compute Engine instance with an external IP and route all outbound traffic through it using a custom route.
AnswerB

Cloud NAT with manual IP allocation lets you reserve specific external IP addresses that are used for all outbound traffic from the private instances. It is a regional, managed service that scales automatically and avoids single points of failure, meeting the allowlisting requirement with minimal management overhead.

Why this answer

Cloud NAT with manual IP allocation is the correct solution because it provides a managed, regional service that uses reserved external IP addresses for outbound traffic from private instances. It scales automatically, has no single point of failure, and requires minimal operational effort, directly satisfying the partner allowlisting requirement.

Exam trap

The trap here is thinking that a self-managed NAT instance or VPN is needed for a dedicated egress IP, when Cloud NAT with manual IP allocation provides this as a managed service.

52
MCQeasy

A company wants to provision multiple similar environments (dev, test, prod) with consistent networking configurations. Which approach is a best practice for infrastructure as code?

A.Use Ansible playbooks to run ad-hoc commands.
B.Use a single Terraform configuration with workspaces.
C.Run separate gcloud commands for each environment.
D.Use Cloud Deployment Manager templates with environment-specific parameters.
AnswerB

Workspaces allow reusable configuration across environments.

Why this answer

Terraform workspaces allow you to manage multiple distinct environments (e.g., dev, test, prod) from a single configuration by maintaining separate state files. This ensures consistent networking configurations across environments while avoiding duplication of code, which is a core best practice for infrastructure as code.

Exam trap

Google Cloud often tests the misconception that environment-specific parameters in Deployment Manager templates are equivalent to Terraform workspaces, but the trap is that Terraform's workspace feature provides native state isolation and multi-cloud portability, whereas Deployment Manager is GCP-specific and lacks the same level of abstraction for consistent multi-environment management.

How to eliminate wrong answers

Option A is wrong because Ansible playbooks are primarily for configuration management and ad-hoc command execution, not for declaratively provisioning cloud infrastructure with state management and drift detection. Option C is wrong because running separate gcloud commands for each environment is imperative, error-prone, and lacks version control and repeatability, violating IaC principles. Option D is wrong because Cloud Deployment Manager templates with environment-specific parameters can work but are less portable and flexible than Terraform workspaces, and Terraform is the more widely adopted multi-cloud IaC tool for consistent provisioning.

53
MCQhard

An organization requires that all Compute Engine instances in a project must have a specific tag for firewall rule compliance. How can they enforce this?

A.Use IAM roles to restrict instance creation
B.Use a startup script to add the tag
C.Use a mandatory tag via organization policy
D.Use Cloud Asset Inventory
AnswerC

Organization policies can enforce constraints like `compute.requireTags`.

Why this answer

Organization Policies in Google Cloud can enforce constraints that require resources, including Compute Engine instances, to have specific labels or tags. The `compute.requireOsLogin` or custom constraint `compute.requireInstanceTag` can be used to mandate that all instances must have a particular tag, and any instance creation that violates this policy will be denied at the API level, ensuring compliance without relying on user behavior.

Exam trap

The trap here is that candidates often confuse IAM roles with Organization Policies, thinking that restricting creation permissions (Option A) is sufficient, but IAM cannot enforce resource-level attributes like tags, which is a common misconception in policy-based governance questions.

How to eliminate wrong answers

Option A is wrong because IAM roles control who can create instances, not what tags are applied to the instances; they cannot enforce a specific tag value. Option B is wrong because a startup script runs after the instance is created, so it cannot prevent the creation of an instance without the required tag, and the instance would already exist in violation of the firewall rule compliance. Option D is wrong because Cloud Asset Inventory is a service for discovering and monitoring cloud resources, not for enforcing policies or preventing non-compliant resource creation.

54
Multi-Selectmedium

Which TWO actions are required to allow a private GKE cluster to pull container images from Artifact Registry in the same project?

Select 2 answers
A.Create a firewall rule allowing outbound traffic to Artifact Registry IP ranges.
B.Set up VPC Network Peering with the Artifact Registry service.
C.Configure Cloud NAT for the GKE cluster.
D.Enable Private Google Access on the subnet where the GKE nodes are deployed.
E.Grant the Artifact Registry Reader role to the GKE service account.
AnswersD, E

Private Google Access allows nodes without external IPs to reach Google APIs.

Why this answer

Private Google Access enables GKE nodes with only internal IP addresses to reach Google APIs and services, including Artifact Registry, over Google's private network rather than the public internet. Option E is correct because the GKE node's service account must have the Artifact Registry Reader role (roles/artifactregistry.reader) to authenticate and pull container images from the registry.

Exam trap

Google Cloud often tests the misconception that Cloud NAT is required for private clusters to access Google APIs, but Private Google Access is the correct mechanism for reaching Google-managed services like Artifact Registry without public IPs.

55
MCQhard

An organization has a VPC with two subnets: subnet-a (10.0.1.0/24) and subnet-b (10.0.2.0/24). They launched a Compute Engine instance in subnet-a with an internal IP 10.0.1.2 and a public IP. They want the instance to only allow HTTPS traffic from the internet. Which firewall rule should they create?

A.Ingress rule: allow tcp:0-65535, source 0.0.0.0/0, target tag 'https-server'
B.Egress rule: allow tcp:443, destination 0.0.0.0/0, target tag 'https-server'
C.Ingress rule: allow tcp:443, source 10.0.0.0/16, target tag 'https-server'
D.Ingress rule: allow tcp:443, source 0.0.0.0/0, target tag 'https-server'
AnswerD

An ingress rule permitting tcp:443 from 0.0.0.0/0 satisfies the HTTPS-only requirement, since Google Cloud VPC firewall rules are stateful and default-deny, so all other inbound ports remain blocked. Applying the target tag 'https-server' scopes the rule to the tagged Compute Engine instance in subnet-a, leaving other instances unaffected.

Why this answer

The instance needs to accept incoming HTTPS traffic (TCP port 443) from the internet. An ingress firewall rule with source 0.0.0.0/0 allows traffic from any external IP, and applying it to instances with the target tag 'https-server' ensures only tagged instances are affected. This matches the requirement to allow only HTTPS from the internet.

Exam trap

The trap here is that candidates often confuse ingress vs. egress rules or mistakenly restrict the source to the VPC range (10.0.0.0/16) thinking it includes the internet, when in fact it only allows traffic from within the VPC.

How to eliminate wrong answers

Option A is wrong because it allows all TCP ports (0-65535) from the internet, which violates the requirement to allow only HTTPS traffic (port 443). Option B is wrong because it is an egress rule, which controls outbound traffic from the instance, not inbound HTTPS traffic from the internet. Option C is wrong because it restricts the source to the internal VPC range (10.0.0.0/16), which blocks all internet traffic and does not meet the requirement for allowing HTTPS from the internet.

56
MCQeasy

A startup is deploying a new web application on Compute Engine. The architect needs to ensure that the application can automatically recover from a zone failure and that the instances are distributed across multiple zones within a region. The application must also scale automatically based on traffic. Which Compute Engine feature should the architect use?

A.Sole-tenant nodes with autoscaling.
B.Preemptible VMs with a managed instance group.
C.Unmanaged instance group with instances in a single zone.
D.Managed instance group with regional distribution and autoscaling.
AnswerD

A regional managed instance group distributes instances across multiple zones within a region, providing resilience to zone failures. It supports autoscaling based on metrics like CPU utilization or load balancing capacity. This directly meets the requirements for automatic recovery from zone failure and automatic scaling based on traffic, making it the appropriate choice for the web application.

Why this answer

A regional managed instance group spreads instances across multiple zones, ensuring that the application survives a zone failure. It also supports autoscaling based on traffic, allowing the application to handle varying loads. The other options either lack zone distribution, automatic scaling, or reliability, making them unsuitable for the startup's requirements.

Exam trap

The trap here is confusing a managed instance group with an unmanaged one; only managed instance groups support autoscaling and autohealing.

57
MCQmedium

A company is deploying a web application on Compute Engine behind a global HTTP(S) load balancer. They want to restrict access to only traffic from specific IP ranges. Which load balancer feature should they use?

A.Cloud Armor security policies.
B.VPC firewall rules.
C.Identity-Aware Proxy (IAP).
D.Cloud CDN.
AnswerA

Cloud Armor security policies attach directly to the global HTTP(S) load balancer's backend service, letting you define allow or deny rules matching source IP ranges. This satisfies the requirement to restrict access to specific IP ranges at the edge, before traffic reaches Compute Engine instances.

Why this answer

Cloud Armor security policies are the correct choice because they allow you to define IP-based allow/deny rules at the edge of Google's network, directly integrated with the global HTTP(S) load balancer. This provides granular access control based on source IP ranges before traffic reaches your backend instances, which is exactly what the requirement specifies.

Exam trap

The trap here is that candidates often confuse VPC firewall rules with Cloud Armor, assuming that firewall rules can filter on the original client IP behind a load balancer, but in reality, VPC firewall rules only see the load balancer's proxy IPs, making Cloud Armor the only viable option for IP-based access control at the edge.

How to eliminate wrong answers

Option B is wrong because VPC firewall rules operate at the instance level (network interface) and cannot filter traffic based on the original client IP when a global HTTP(S) load balancer is used, as the load balancer's health check and proxy IPs are seen instead. Option C is wrong because Identity-Aware Proxy (IAP) controls access based on user identity and context (e.g., Google accounts, OAuth), not on source IP ranges, and is designed for application-layer authentication, not network-layer IP filtering. Option D is wrong because Cloud CDN is a content delivery network that caches content at edge locations to improve latency and reduce load, and it does not provide any IP-based access control or security policy enforcement.

58
MCQeasy

A developer wants to store and retrieve non-relational data with flexible schema and automatic scaling. Which Google Cloud service should they use?

A.Cloud Bigtable.
B.Cloud SQL.
C.Firestore.
D.Cloud Spanner.
AnswerC

Firestore is a serverless NoSQL document database offering flexible schemas and automatic horizontal scaling, matching the non-relational, flexible-schema, auto-scaling requirement. It suits application data needing real-time sync and scales without manual sharding, unlike Cloud SQL's fixed relational schema.

Why this answer

Firestore is a NoSQL document database that supports flexible schema and automatic scaling, making it ideal for non-relational data. It offers real-time synchronization, offline support, and serverless scaling, which aligns with the requirement for storing and retrieving data without manual sharding or capacity planning.

Exam trap

Google Cloud often tests the distinction between NoSQL databases by presenting Cloud Bigtable as a trap for 'non-relational' requirements, but candidates overlook that Bigtable is optimized for analytical workloads with fixed column families, not for flexible schema and automatic scaling in transactional applications.

How to eliminate wrong answers

Option A is wrong because Cloud Bigtable is a wide-column NoSQL database designed for large analytical workloads (e.g., time-series, IoT) with high throughput, but it does not support flexible schema in the same way as Firestore (it requires predefined column families) and is not optimized for transactional, real-time client-side access. Option B is wrong because Cloud SQL is a fully managed relational database service (MySQL, PostgreSQL, SQL Server) that enforces a fixed schema and does not automatically scale beyond its instance limits without manual resizing or read replicas. Option D is wrong because Cloud Spanner is a globally distributed relational database that provides strong consistency and horizontal scaling, but it requires a predefined schema and SQL-based relational model, making it unsuitable for non-relational data with flexible schema.

59
MCQmedium

A company deploys a web application on Compute Engine behind a Global HTTPS Load Balancer. They need to restrict access to the application based on the client's IP address. Which Google Cloud service should they use?

A.VPC firewall rules
B.Identity-Aware Proxy (IAP)
C.Cloud Armor
D.Cloud CDN
AnswerC

Cloud Armor attaches security policies to the Global HTTPS Load Balancer's backend service, filtering requests by source IP address at the edge. This satisfies the client-IP restriction requirement, which VPC firewall rules cannot enforce for external clients.

Why this answer

Cloud Armor is the correct choice because it provides IP-based access control at the edge of Google's network, integrated directly with the Global HTTPS Load Balancer. It allows you to create security policies with IP allow/deny rules that are evaluated before traffic reaches your Compute Engine instances, making it the appropriate service for client IP restriction at the load balancer level.

Exam trap

The trap here is that candidates often confuse VPC firewall rules with edge security, not realizing that VPC firewall rules cannot see the original client IP when a Global Load Balancer is in front, making Cloud Armor the only option for IP-based access control at the load balancer level.

How to eliminate wrong answers

Option A is wrong because VPC firewall rules operate at the instance network interface level, not at the load balancer edge, and they cannot inspect the original client IP address when traffic passes through a Global HTTPS Load Balancer (the source IP becomes the load balancer's IP). Option B is wrong because Identity-Aware Proxy (IAP) controls access based on user identity and context (e.g., OAuth2, device security), not on client IP addresses; it is designed for authentication and authorization, not network-layer IP filtering. Option D is wrong because Cloud CDN is a content delivery network service that caches content at edge locations to improve latency and reduce load; it does not provide IP-based access control or security policy enforcement.

60
MCQhard

An organization uses Cloud SQL for MySQL in a production environment. They need to ensure high availability with automatic failover in case of a zonal failure. Which configuration should they use?

A.Create a read replica in a different region.
B.Create a regional Cloud SQL instance with automatic failover.
C.Export the database daily and import into a new instance if failure occurs.
D.Deploy Cloud SQL across multiple regions using cross-region replication.
AnswerB

A regional instance replicates synchronously across two zones in the same region and promotes the standby automatically on zonal failure, satisfying the automatic failover requirement. A zonal instance offers no standby, so it cannot meet the stated high-availability constraint.

Why this answer

A regional Cloud SQL instance with automatic failover uses a primary and a standby zone within the same region, with synchronous replication between them. If the primary zone fails, Cloud SQL automatically promotes the standby to primary, ensuring high availability without data loss. This configuration meets the requirement for automatic failover during a zonal failure.

Exam trap

The trap here is that candidates confuse cross-region replication (available for other database engines) with the zonal high-availability feature for Cloud SQL for MySQL, or assume that a read replica can be used for automatic failover when it requires manual promotion.

How to eliminate wrong answers

Option A is wrong because a read replica in a different region provides read scalability and disaster recovery across regions, but it does not support automatic failover for the primary instance; failover would require manual promotion, which is not automatic. Option C is wrong because daily exports and manual imports are a backup and restore strategy, not a high-availability solution; it introduces significant downtime and potential data loss, failing the automatic failover requirement. Option D is wrong because Cloud SQL for MySQL does not support cross-region replication for automatic failover; cross-region replication is available for Cloud SQL for PostgreSQL and SQL Server, but for MySQL, it is limited to read replicas, which do not provide automatic failover.

61
Multi-Selectmedium

A company is deploying a new application on Google Kubernetes Engine (GKE). They need to ensure that the application can automatically scale based on custom metrics, such as the number of pending requests in a queue. They also want to minimize operational overhead. Which TWO actions should they take? (Choose two.)

Select 2 answers
A.Use a Kubernetes Cluster Autoscaler to add nodes when pods are pending.
B.Configure a Vertical Pod Autoscaler (VPA) to adjust resource requests.
C.Deploy the application as a DaemonSet to ensure one pod per node.
D.Export the custom metric to Cloud Monitoring using the Cloud Monitoring API or a sidecar.
E.Enable Horizontal Pod Autoscaler (HPA) with custom metrics from Cloud Monitoring.
AnswersD, E

For HPA to use custom metrics, they must be available in Cloud Monitoring. This can be done via the Cloud Monitoring API or by using a sidecar like the Stackdriver adapter. Exporting the metric is a prerequisite for HPA to scale based on it. This action, combined with enabling HPA, fulfills the requirement.

Why this answer

To scale based on custom metrics in GKE, the metrics must be exported to Cloud Monitoring, and then the Horizontal Pod Autoscaler can be configured to use those metrics. This approach leverages managed GKE features, minimizing operational overhead. Cluster Autoscaler and VPA address different scaling dimensions and are not required for custom metric scaling.

Exam trap

The trap here is confusing Horizontal Pod Autoscaler with Vertical Pod Autoscaler or Cluster Autoscaler, and forgetting that custom metrics must be exported to Cloud Monitoring first.

62
MCQmedium

A company runs a three-tier web application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier on TCP port 8080. The company wants to enforce these requirements at the network level with minimal administrative overhead and without relying on instance-level firewall software. What should they do?

A.Create a VPC firewall rule that allows TCP port 8080 from the web tier's network tag to the application tier's network tag, and another rule that allows the database port from the application tier's network tag to the database tier's network tag.
B.Place the database tier in a separate VPC and use VPC Network Peering to connect it to the application tier's VPC, then allow all traffic between the peered networks.
C.Configure each instance with iptables rules that permit only the required traffic, and disable VPC firewall rules for the project.
D.Create a single VPC firewall rule that allows all TCP traffic between all instances in the VPC, and rely on the application code to restrict access.
AnswerA

VPC firewall rules use source and target tags to scope traffic to specific instances. Allowing TCP 8080 from the web tier tag to the application tier tag enforces the web-to-app path, and allowing the database port from the app tier tag to the database tier tag enforces the app-to-database path. This meets the requirement at the network level without instance-level software.

Why this answer

Tag-based VPC firewall rules are the standard way to enforce tier-to-tier access on Compute Engine. By allowing only TCP 8080 from the web tier tag to the application tier tag, and only the database port from the application tier tag to the database tier tag, the company implements least-privilege network segmentation centrally. This avoids instance-level firewall software and keeps administration simple.

Exam trap

The trap here is assuming that creating separate VPCs or subnets automatically restricts traffic between tiers, when in fact firewall rules must explicitly allow the required flows.

63
Matchingmedium

Match each GCP storage service to its typical use case.

Drag a concept onto its matching description — or click a concept then click the description.

Concepts
Matches

Object storage for unstructured data

Managed NFS file server

Block storage for VM instances

NoSQL database for large analytical workloads

Globally distributed relational database

Why these pairings

Cloud Storage is for unstructured object storage, Cloud SQL for relational data, Cloud Bigtable for wide-column NoSQL analytics, and Firestore for document NoSQL apps. Common confusions involve mixing storage types with database services.

64
MCQeasy

A developer needs to pass a startup script to a Compute Engine instance during creation. Which method should be used to ensure the script runs on first boot?

A.Use gcloud compute instances create with --metadata=startup-script=...
B.Create a custom image with the script baked in.
C.Use gcloud compute instances add-metadata after creating the instance.
D.Use gcloud compute instances create with --startup-script flag.
AnswerA

The startup-script metadata key is read by the Compute Engine guest agent, which executes its value on first boot. Passing it via --metadata during instance creation satisfies the requirement that the script run at startup.

Why this answer

The `--metadata=startup-script=...` flag on `gcloud compute instances create` passes the script as instance metadata. Compute Engine automatically executes the value of the `startup-script` metadata key on every boot, including the first boot. This is the standard, documented method for providing a startup script at instance creation time.

Exam trap

The trap here is that candidates confuse the nonexistent `--startup-script` flag with the correct `--metadata=startup-script=...` syntax, or assume that adding metadata after creation will trigger the script on the first boot.

How to eliminate wrong answers

Option B is wrong because baking the script into a custom image makes it part of the image itself, not a dynamically assigned startup script; it would run on every boot of instances created from that image, but the question specifically asks for a method to pass the script during creation, not to embed it in the image. Option C is wrong because `gcloud compute instances add-metadata` modifies metadata on an already-running instance; the script would only run on the next boot, not on the first boot (which has already occurred). Option D is wrong because `gcloud compute instances create` does not support a `--startup-script` flag; the correct flag is `--metadata=startup-script=...`.

65
Drag & Dropmedium

Drag and drop the steps to migrate a Compute Engine VM to a different region using a snapshot into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

Snapshots are global resources, but disks are regional. Create the disk in the target region, then create the VM.

66
MCQhard

A company runs a critical application on Compute Engine instances in a managed instance group (MIG) across three zones in us-central1. The application uses a Cloud Spanner database. Recently, the application experienced increased latency and timeouts during peak hours. The operations team noticed that the MIG's CPU utilization is consistently above 80% during peak hours, and the autoscaler is configured to scale based on CPU utilization with a target of 60%. However, the autoscaler is not adding new instances quickly enough, causing performance degradation. The team also observed that new instances take over 5 minutes to become healthy and serve traffic. The health check is a simple TCP check on port 8080. The application startup script downloads large configuration files from Cloud Storage. What should the team do to improve the autoscaling response time and reduce latency?

A.Increase the minimum number of instances in the MIG to handle peak load.
B.Reduce the autoscaler target CPU utilization to 40% so it scales earlier.
C.Create a custom Compute Engine image that includes the application and configuration, and use it in the MIG.
D.Change the health check to HTTP and reduce the initial delay and check intervals.
AnswerC

Baking the application and configuration into a custom image removes the startup script's download of large files from Cloud Storage, cutting the over-five-minute initialisation delay. Instances therefore become healthy faster, letting the autoscaler add capacity quickly enough to hold CPU near the 60% target.

Why this answer

The primary bottleneck is the long instance startup time (over 5 minutes) caused by downloading large configuration files from Cloud Storage at boot. By creating a custom Compute Engine image that bakes the application and configuration into the image, new instances can start serving traffic almost immediately, drastically reducing the time before they become healthy and the autoscaler can consider them in scaling decisions. This directly addresses the root cause of slow autoscaling response, as the autoscaler cannot add instances faster than they become healthy.

Exam trap

The trap here is that candidates focus on tuning the autoscaler parameters (CPU target, health check intervals) rather than identifying the actual bottleneck—the instance startup time—which is a common misconception that autoscaling speed is purely a function of scaling policy settings.

How to eliminate wrong answers

Option A is wrong because increasing the minimum number of instances only handles baseline load, not the dynamic scaling speed during peak hours; it does not fix the slow instance startup time that delays autoscaler response. Option B is wrong because reducing the target CPU utilization to 40% would cause the autoscaler to trigger earlier, but it still cannot add instances faster than the 5-minute startup delay; it would only increase the number of pending instances without improving latency. Option D is wrong because changing the health check to HTTP and reducing intervals only affects how quickly the MIG detects an instance as healthy after it starts, but the fundamental problem is the 5-minute startup time itself—no health check tuning can make the instance boot faster.

67
MCQmedium

A financial services company runs a three-tier web application on Compute Engine across three zones in us-central1. Their security team mandates that database traffic must never traverse the public internet, and that the database subnet must be reachable only from the application subnet. The network team has already created a custom VPC named fin-vpc with separate subnets for web, app, and db tiers. Which combination of controls should the architect implement to satisfy these requirements?

A.Create a firewall rule on fin-vpc that allows ingress to the db subnet only from the app subnet's CIDR range, and do not assign external IP addresses to the database instances.
B.Create a second VPC for the database tier and peer it to fin-vpc, then rely on the default firewall rules to block non-app traffic.
C.Enable Private Google Access on the db subnet and remove external IPs from the database instances so all traffic stays internal to Google's network.
D.Assign internal IP addresses to the databases and place them behind an external TCP proxy load balancer so only the app tier can resolve the backend.
AnswerA

Firewall rules in a VPC scope by target and source, so allowing ingress to the db subnet only from the app subnet CIDR restricts reachability to that tier, while omitting external IPs keeps the database off the public internet entirely. Together these satisfy both the isolation and no-public-internet mandates without extra products.

Why this answer

Restricting access at the subnet level with a VPC firewall rule that permits ingress only from the application tier's CIDR, combined with withholding external IP addresses from database instances, directly implements both the least-privilege reachability requirement and the no-public-internet mandate. No additional networking products are needed because VPC firewall rules already scope traffic by source range and target, and internal-only addressing keeps the tier off the public internet.

Exam trap

The trap here is assuming that removing external IP addresses alone isolates a tier, when reachability from other subnets still depends on firewall rule scoping.

68
MCQhard

A company is migrating a legacy application to Google Cloud. The application requires a shared file system that can be accessed by multiple Compute Engine instances simultaneously. The file system must be POSIX-compliant, highly available, and scalable. The company wants to minimize management overhead. Which solution should they use?

A.Cloud Storage with a Cloud Storage FUSE mount
B.Filestore
C.Persistent Disk with multi-writer mode
D.Local SSD
AnswerB

Filestore is a fully managed, POSIX-compliant file system service that provides shared file storage for Compute Engine instances. It offers high availability and scalability, and requires minimal management overhead. It supports NFSv3 and is ideal for legacy applications that need a shared file system. This meets all requirements.

Why this answer

Filestore is a managed NFS file system that provides POSIX-compliant shared storage for Compute Engine instances. It is highly available, scalable, and requires minimal management. Cloud Storage FUSE is not fully POSIX-compliant, Persistent Disk multi-writer is not for shared file systems, and Local SSD is not shared.

Exam trap

The trap here is assuming that Cloud Storage FUSE or Persistent Disk multi-writer can serve as a POSIX-compliant shared file system, but they have limitations.

69
MCQmedium

A company is migrating a legacy monolithic application to Google Cloud. The application runs on a single VM and uses a local MySQL database. The goal is to minimize changes to the application code while improving availability. Which strategy should the company use?

A.Use a managed instance group for the application VM and store the database on a persistent disk attached to the primary instance.
B.Re-architect the application into microservices and use Cloud Run for stateless components.
C.Lift and shift the VM to Compute Engine, and migrate the database to Cloud SQL with a failover replica.
D.Containerize the application and deploy on Google Kubernetes Engine (GKE) with Cloud Spanner as the database.
AnswerC

Lifting the VM to Compute Engine preserves the application unchanged, minimising code modifications. Migrating MySQL to Cloud SQL with a failover replica provides automatic failover to a standby in another zone, satisfying the availability goal without application rewrites.

Why this answer

It minimizes code changes by lifting the application VM to Compute Engine as-is, while migrating the local MySQL database to Cloud SQL with a failover replica. This improves availability through Cloud SQL's managed automatic failover to a standby replica in a different zone, without requiring application code changes to the database connection logic (the application can continue using the same MySQL protocol).

Exam trap

The trap here is that candidates often choose Option A, mistakenly believing that a managed instance group with a persistent disk provides database high availability, but they overlook that the persistent disk cannot be shared across instances in a managed instance group without additional orchestration (e.g., regional persistent disks or a clustered filesystem), and the database process itself is not automatically failed over.

How to eliminate wrong answers

Option A is wrong because storing the database on a persistent disk attached to a single instance in a managed instance group does not provide high availability for the database; if the primary instance fails, the persistent disk cannot be attached to a new instance without manual intervention, and the database state is lost or requires complex recovery. Option B is wrong because re-architecting into microservices and using Cloud Run requires significant application code changes, contradicting the goal of minimizing changes to the application code. Option D is wrong because containerizing and deploying on GKE with Cloud Spanner requires substantial application code changes (Cloud Spanner uses a different SQL dialect and connection protocol than MySQL) and introduces unnecessary complexity, violating the requirement to minimize code changes.

70
MCQhard

A company runs a critical application on a managed instance group in a single zone. The application stores data on a zonal persistent disk. The company wants to ensure that the application can survive a zone failure with minimal data loss and automatic failover. They also want to minimize changes to the application. Which approach should they take?

A.Convert the zonal persistent disk to a regional persistent disk and configure the managed instance group to be regional.
B.Use a multi-writer persistent disk and attach it to instances in two zones.
C.Create a snapshot schedule for the zonal persistent disk and configure the managed instance group to automatically create instances from the snapshot in another zone.
D.Deploy the application on a regional managed instance group and use a Cloud Storage bucket mounted via FUSE for data storage.
AnswerA

A regional persistent disk replicates data synchronously across two zones, providing a recovery point objective (RPO) of zero and a recovery time objective (RTO) of minutes. By making the managed instance group regional, instances can be distributed across zones, and if one zone fails, the application can fail over to the other zone with the same disk. This requires minimal application changes and meets the requirements for zone failure survival and automatic failover.

Why this answer

A regional persistent disk replicates data synchronously across two zones, ensuring zero data loss on zone failure. When combined with a regional managed instance group, the application can automatically fail over to the healthy zone. This approach requires minimal changes to the application and meets the requirements for survival and automatic failover.

The other options either involve data loss or are not designed for cross-zone failover.

Exam trap

The trap here is assuming that snapshot schedules provide automatic failover or that multi-writer disks can span zones, when in fact they are zonal and not synchronous.

71
Multi-Selectmedium

Which THREE are valid methods to connect an on-premises network to a Google Cloud VPC?

Select 3 answers
A.Dedicated Interconnect
B.Cloud VPN
C.Cloud Router
D.VPC peering
E.Partner Interconnect
AnswersA, B, E

Dedicated Interconnect provides direct physical connection.

Why this answer

Dedicated Interconnect (A) provides a direct physical connection between your on-premises network and Google Cloud, offering high bandwidth and a Service Level Agreement (SLA) of up to 99.99% availability. It uses a cross-connect in a colocation facility to attach your on-premises router to a Google Cloud router, enabling private, low-latency connectivity to your VPC without traversing the public internet.

Exam trap

The trap here is that candidates confuse Cloud Router as a standalone connectivity method, when it is actually a routing component that must be paired with a VPN tunnel or Interconnect to function.

72
MCQmedium

A company runs a web application on Compute Engine with an HTTP Load Balancer. Users report intermittent 502 Bad Gateway errors. What is the most likely cause?

A.Load balancer quota exceeded.
B.Firewall rules block health checks.
C.SSL certificate expired.
D.Backend instances are unhealthy or overloaded.
AnswerD

An HTTP(S) load balancer returns 502 when it cannot obtain a valid response from a backend. Unhealthy instances removed by health checks, or overloaded instances timing out, both produce this, matching the intermittent pattern reported.

Why this answer

The 502 Bad Gateway error from an HTTP Load Balancer typically indicates that the backend instances are failing to respond to the load balancer's health checks or are overwhelmed, causing the load balancer to consider them unhealthy and return a 502 error. This is the most common cause because the load balancer relies on healthy backends to forward traffic, and overloaded or failing instances cannot handle requests.

Exam trap

The trap here is that candidates often confuse 502 errors with SSL or quota issues, but the PCA exam specifically tests that 502 errors from an HTTP Load Balancer are almost always due to backend unavailability or overload, not frontend configuration problems.

How to eliminate wrong answers

Option A is wrong because exceeding a load balancer quota would result in a 429 Too Many Requests or a 503 Service Unavailable error, not a 502 Bad Gateway. Option B is wrong because firewall rules blocking health checks would cause the load balancer to mark backends as unhealthy, but the error would typically be a 502 only if the health check fails and no healthy backends remain; however, the question asks for the most likely cause, and overloaded backends are more common than misconfigured firewalls in intermittent 502 scenarios. Option C is wrong because an expired SSL certificate on the load balancer would cause SSL handshake failures and a 502 error only if the certificate is used for backend-to-load-balancer communication, but the load balancer terminates SSL and uses its own certificate; an expired certificate on the backend would not cause a 502 from the load balancer's perspective.

73
MCQeasy

Your company runs a global e-commerce platform on Google Cloud. The application is deployed across multiple regions for low latency. You use Cloud SQL for transactional data and Cloud Spanner for global consistency of inventory. Recently, the operations team reported that the application is experiencing increased latency during peak hours, and the monthly cloud bill has risen significantly. Upon investigation, you find that the Cloud SQL instance is underutilized (CPU < 20%) while Cloud Spanner split utilization is over 80%. The application instances are fronted by a global external HTTPS load balancer. Network egress costs are high. Which course of action would best address both the latency and cost issues?

A.Reduce the Cloud SQL instance tier to a lower machine type to save costs, and add read replicas in other regions for failover.
B.Add more nodes to the Cloud SQL instance and enable automatic storage increase to handle peak loads.
C.Increase the number of splits in Cloud Spanner to reduce hot spots, and configure Cloud CDN in front of the load balancer to cache static content.
D.Move the transactional database to Cloud Spanner and decommission Cloud SQL to reduce complexity.
AnswerC

Increasing splits improves Spanner performance; Cloud CDN reduces egress costs and latency for static content.

Why this answer

The primary performance issue is Cloud Spanner split utilization over 80%, indicating hot spots that cause increased latency. Increasing the number of splits redistributes load across more nodes, reducing contention. Additionally, configuring Cloud CDN caches static content at edge locations, reducing network egress costs and latency by serving content closer to users.

Exam trap

The trap here is that candidates focus on the underutilized Cloud SQL instance and assume it is the problem, ignoring that the real bottleneck is Cloud Spanner split utilization and network egress costs, which require a different solution (split management and CDN caching).

How to eliminate wrong answers

Option A is wrong because reducing the Cloud SQL instance tier would not address the high Cloud Spanner split utilization or network egress costs; Cloud SQL is underutilized, so downsizing it does not solve the root cause. Option B is wrong because adding nodes to Cloud SQL does not fix Cloud Spanner hot spots or high egress costs; Cloud SQL is not the bottleneck. Option D is wrong because moving transactional data to Cloud Spanner would increase complexity and cost without addressing the specific split utilization and egress issues; Cloud SQL is underutilized, so decommissioning it is unnecessary and could introduce migration risks.

74
MCQhard

A company has a global web application deployed across multiple regions. They use an external HTTPS Load Balancer with backend services in us-central1 and europe-west1. They want users to be routed to the closest healthy backend. Which load balancing configuration is required?

A.Internal HTTP(S) Load Balancer
B.External HTTPS Load Balancer with global backend
C.External TCP/UDP Network Load Balancer
D.Classic Application Load Balancer
E.Regional external HTTPS Load Balancer
AnswerB

A global external HTTPS Load Balancer with a global backend uses Google's premium tier anycast VIP, so each user's request enters the Google network at the nearest edge and is proxied to the closest healthy backend across us-central1 and europe-west1, satisfying the proximity routing requirement.

Why this answer

An External HTTPS Load Balancer with a global backend configuration uses Google Cloud's global anycast IP and the Premium Tier network to route users to the closest healthy backend based on latency and proximity. This setup ensures that traffic from users worldwide is directed to the nearest region (us-central1 or europe-west1) with a healthy instance group, providing optimal performance and failover.

Exam trap

The trap here is that candidates often confuse 'global' with 'regional' load balancers, mistakenly thinking a regional external HTTPS load balancer can serve multiple regions, but only the global external HTTPS load balancer supports cross-region backend services with anycast routing.

How to eliminate wrong answers

Option A is wrong because an Internal HTTP(S) Load Balancer is used for traffic within a VPC network, not for external user traffic from the internet. Option C is wrong because an External TCP/UDP Network Load Balancer operates at Layer 4 and does not support HTTPS termination, content-based routing, or global backend selection across regions. Option D is wrong because Classic Application Load Balancer is a legacy GCP resource that does not support global backends or cross-region routing; it is regionally scoped.

Option E is wrong because a Regional external HTTPS Load Balancer is confined to a single region and cannot route traffic to backends in multiple regions like us-central1 and europe-west1.

75
MCQmedium

A team manages a GKE cluster with node pools using different machine types. They plan to upgrade the cluster to a new Kubernetes version. What is the safest upgrade strategy to minimize application downtime?

A.Perform a rolling upgrade by draining all nodes simultaneously.
B.Create a new cluster with the desired version and migrate workloads.
C.Use a surge upgrade to add new nodes before removing old ones.
D.Upgrade the node pool configuration one by one.
AnswerC

A surge upgrade provisions replacement nodes running the new Kubernetes version before cordoning and draining the old ones, so workloads reschedule onto ready capacity. This satisfies the stem's downtime constraint: pods are evicted only once healthy successors exist, and mixed machine types across node pools are handled per pool.

Why this answer

A surge upgrade in GKE adds new nodes with the desired Kubernetes version before removing old nodes, ensuring capacity is maintained throughout the process. This minimizes application downtime by allowing pods to be rescheduled onto new nodes before old nodes are drained, following a controlled rolling update pattern that respects PodDisruptionBudgets.

Exam trap

Google Cloud often tests the misconception that draining all nodes simultaneously is a valid rolling upgrade strategy, when in fact it causes complete downtime and violates Kubernetes best practices for workload availability.

How to eliminate wrong answers

Option A is wrong because draining all nodes simultaneously would remove all running pods at once, causing complete application downtime and violating PodDisruptionBudgets if configured. Option B is wrong because creating a new cluster and migrating workloads requires manual or tool-based migration, which introduces significant operational overhead and potential downtime during the cutover, and is not the safest or most efficient strategy for an existing cluster. Option D is wrong because upgrading node pool configuration one by one does not specify a surge or rolling mechanism; without surge, it would drain nodes in the pool sequentially, potentially causing capacity shortages and downtime if the pool is under-provisioned.

Page 1 of 2 · 91 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Manage and provision cloud infrastructure questions.