Courseiva

CCNA Managing and Provisioning a Solution Infrastructure Questions

75 of 84 questions · Page 1/2 · Managing and Provisioning a Solution Infrastructure · Answers revealed

1
MCQmedium

A company wants to grant a service account in Project A the ability to push containers to Artifact Registry in Project B. They want to follow the principle of least privilege. Which IAM roles should they assign?

A.Grant the service account the Storage Object Admin role (roles/storage.objectAdmin) on Project B
B.Grant the service account the Artifact Registry Writer role (roles/artifactregistry.writer) on the repository in Project B
C.Grant the service account the Artifact Registry Admin role (roles/artifactregistry.admin) on the repository in Project B
D.Grant the service account the Artifact Registry Reader role (roles/artifactregistry.reader) on the repository in Project B
AnswerB

Granting roles/artifactregistry.writer on the specific repository in Project B satisfies least privilege: the role permits pushing and reading artifacts but not deleting repositories or managing IAM, and scoping the binding to the repository rather than the whole project limits the service account to exactly the target it needs.

Why this answer

The Artifact Registry Writer role (roles/artifactregistry.writer) grants permissions to push and pull artifacts, which is exactly what the service account needs to push containers. Assigning it at the repository level in Project B follows least privilege by limiting access to only that repository. This role includes the necessary permissions like artifactregistry.repositories.uploadArtifacts without granting broader admin rights.

Exam trap

PCA often tests the difference between project-level and repository-level IAM, and candidates may choose Admin or Reader roles instead of the precise Writer role for push access.

How to eliminate wrong answers

Option A is wrong because Storage Object Admin is for Cloud Storage buckets, not Artifact Registry; Artifact Registry uses its own IAM roles. Option C is wrong because Artifact Registry Admin grants full control, including delete and manage permissions, which violates least privilege. Option D is wrong because Artifact Registry Reader only allows pulling, not pushing, so the service account could not upload containers.

2
MCQmedium

An organization runs a stateful application on GKE that must not lose data during cluster upgrades or node repairs. The application uses persistent volumes with ReadWriteOnce access mode. The team wants to ensure pods are not evicted simultaneously. Which Kubernetes resource should they configure?

A.PodDisruptionBudget
B.ClusterAutoscaler
C.HorizontalPodAutoscaler
D.VerticalPodAutoscaler
AnswerA

A PodDisruptionBudget (PDB) specifies the minimum number or percentage of replicas that must remain available during voluntary disruptions, such as cluster upgrades or node repairs. By setting `maxUnavailable: 0` or `minAvailable: 1`, the PDB prevents the simultaneous eviction of pods using ReadWriteOnce persistent volumes, thereby satisfying the requirement that no data be lost and pods are not evicted concurrently.

Why this answer

A PodDisruptionBudget (PDB) limits how many pods of a given workload can be voluntarily disrupted at once, ensuring that during node drains (cluster upgrades, node repairs) not all replicas of a stateful application are evicted simultaneously. By setting minAvailable or maxUnavailable, the PDB forces the eviction API to respect availability constraints, protecting data integrity for ReadWriteOnce volumes that cannot be mounted by multiple pods at once.

Exam trap

The trap is confusing autoscaling resources (HPA, VPA, ClusterAutoscaler) with disruption-control resources; candidates often pick HPA because it 'manages pods,' but only PDB governs eviction during maintenance.

How to eliminate wrong answers

Option B is wrong because ClusterAutoscaler adjusts the number of nodes in the cluster based on pending pods — it does not control pod eviction ordering or protect against simultaneous disruption. Option C is wrong because HorizontalPodAutoscaler scales the number of pod replicas based on metrics like CPU or custom metrics; it does not govern eviction during node drains. Option D is wrong because VerticalPodAutoscaler adjusts CPU/memory requests and limits of existing pods, potentially restarting them, but it does not prevent simultaneous eviction during maintenance.

3
MCQmedium

You need to create a private GKE cluster with Workload Identity enabled to allow pods to access Google Cloud APIs without static service account keys. What must you configure for the cluster?

A.Enable Binary Authorization on the cluster
B.Enable Workload Identity on the cluster and set the --workload-pool flag at cluster creation
C.Create a node pool with a service account that has the necessary IAM roles and assign that SA to pods
D.Use Cloud NAT to allow pods to communicate with Google APIs
AnswerB

Workload Identity binds Kubernetes service accounts to Google Cloud service accounts, letting pods obtain short-lived credentials without static keys. Setting --workload-pool at creation links the cluster to the identity pool, satisfying the keyless access requirement.

Why this answer

To enable Workload Identity on a GKE cluster, you must enable it at the cluster level and specify the workload pool using the --workload-pool flag (e.g., PROJECT_ID.svc.id.goog) during cluster creation. This establishes the trust relationship between Kubernetes service accounts and Google Cloud IAM, allowing pods to impersonate IAM service accounts without static keys.

Exam trap

PCA often tests Workload Identity setup, and candidates frequently choose the node pool service account option because it sounds like it grants pods access — but that approach does not eliminate static keys and is the legacy method.

How to eliminate wrong answers

Option A is wrong because Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed; it has nothing to do with Workload Identity or eliminating static keys. Option C is wrong because assigning a node pool service account to pods is the legacy approach that grants all pods on the node the same permissions and still relies on the node's service account, not Workload Identity. Option D is wrong because Cloud NAT provides outbound internet access for private nodes; it does not enable pods to authenticate to Google Cloud APIs.

4
MCQhard

A global logistics company runs a three-tier application on Compute Engine in a single region. The database tier must survive the loss of an entire zone without data loss, and the application tier must continue serving traffic with minimal disruption during a zonal failure. The architect wants the smallest operational change that satisfies both requirements. Which design should the architect implement?

A.Deploy the application tier in a regional managed instance group across three zones and move the database to a Cloud SQL for PostgreSQL instance with high availability enabled.
B.Deploy the application tier in a zonal managed instance group and replicate the database to a read replica in a second zone using asynchronous replication.
C.Deploy the application tier in a regional managed instance group across three zones and keep the database on a single-zone Cloud SQL instance with daily automated backups.
D.Deploy the application tier in a zonal managed instance group and configure Cloud SQL with automated backups and point-in-time recovery enabled.
AnswerA

A regional managed instance group distributes application instances across zones and replaces failed members automatically, so a zonal outage leaves serving capacity intact. Cloud SQL high availability maintains a standby in a different zone and fails over automatically, providing synchronous replication with no committed data loss. Together they meet both the compute continuity and database durability requirements with minimal re-architecture of the existing three-tier application.

Why this answer

A regional managed instance group spreads application instances across zones and self-heals when a zone fails, while Cloud SQL high availability keeps a synchronized standby in another zone and fails over automatically without losing committed transactions. That pairing satisfies both continuity and durability with minimal change to the existing three-tier design.

Exam trap

The trap here is treating backups, point-in-time recovery, or an asynchronous read replica as equivalent to synchronous high availability for a no-data-loss requirement.

5
MCQmedium

Your organization requires all container images deployed to GKE to be signed by an approved authority. Which service enforces that only signed images are allowed to run?

A.Binary Authorization
B.Cloud Asset Inventory
C.Artifact Registry
D.Container Analysis
AnswerA

Binary Authorization enforces deploy-time admission control on GKE, verifying cryptographic signatures against attestors you define before permitting a pod to start. This directly satisfies the stem's requirement that only images signed by an approved authority may run, blocking unsigned or unverified images at admission rather than merely scanning them afterwards.

Why this answer

Binary Authorization is a deploy-time security control on GKE and Cloud Run that only permits container images that satisfy a defined policy — typically requiring attestations from trusted authorities (e.g., a vulnerability scanner or a signing step in the CI pipeline). It integrates with Container Analysis, which stores the attestations, but Binary Authorization is the component that actually blocks unsigned or unattested images from being admitted to the cluster.

Exam trap

The trap is conflating the scanner (Container Analysis) with the enforcer (Binary Authorization) — the exam expects you to know that scanning alone does not prevent deployment.

How to eliminate wrong answers

Option B is wrong because Cloud Asset Inventory is a metadata catalog for discovering and monitoring GCP resources — it has no admission-control capability. Option C is wrong because Artifact Registry is a container image repository; it stores images but does not enforce signature verification at deploy time. Option D is wrong because Container Analysis performs vulnerability scanning and stores metadata/attestations, but it does not itself block deployments — it feeds the data that Binary Authorization evaluates.

6
Multi-Selecthard

A company wants to implement a CI/CD pipeline for a Java application that will be deployed to Cloud Run. They use Cloud Build and Artifact Registry. The pipeline must compile the Java code, run unit tests, build a container image, and deploy to Cloud Run. Which THREE steps are required in the cloudbuild.yaml? (Choose 3)

Select 3 answers
A.Step with image 'gcloud' and entrypoint: 'gcloud', args: ['container', 'clusters', 'get-credentials']
B.Step with image 'docker' and args: ['build', '-t', '...']
C.Step with image 'maven' and args: ['mvn', 'compile', 'test']
D.Step with image 'node' and entrypoint: 'npm', args: ['test']
E.Step with image 'gcloud' and entrypoint: 'gcloud', args: ['run', 'deploy', ...]
AnswersB, C, E

The docker builder executes the container image build, tagging the artefact that Artifact Registry will store. This satisfies the pipeline's requirement to produce a deployable image from the application source before the Cloud Run deployment step runs.

Why this answer

Option B is correct because building the container image for the Java application requires a Docker build step (e.g., image 'docker' with args ['build', '-t', '...']), which produces the image that will later be pushed to Artifact Registry and deployed to Cloud Run. Option C is correct because compiling the Java code and running unit tests is done with Maven, so a step using the 'maven' image with args ['mvn', 'compile', 'test'] satisfies the compile-and-test requirement of the pipeline. Option E is correct because deploying the built image to Cloud Run requires a gcloud step invoking 'gcloud run deploy' with the appropriate service, image, region, and platform flags.

Option A is not needed because 'gcloud container clusters get-credentials' configures kubectl access to a GKE cluster, which is irrelevant when the target is Cloud Run. Option D is not needed because an npm test step applies to Node.js projects, not a Java application built with Maven.

Exam trap

PCA often tests the confusion between GKE and Cloud Run deployment steps, leading candidates to select GKE-specific commands like 'get-credentials' when Cloud Run is the target.

7
MCQhard

A healthcare analytics company stores protected health information in Cloud Storage buckets. Auditors require that data be encrypted with customer-managed encryption keys (CMEK) and that key usage be logged separately from data access. The security team wants the ability to revoke access to the data by disabling a single key without deleting the data. Which configuration should the architect recommend?

A.Enable Bucket Lock on the bucket and configure a retention policy, then use Google-managed keys with Object Lifecycle Management to transition objects to Coldline storage.
B.Use Google-managed encryption keys and enable Data Access audit logs on the bucket to record every object read and write.
C.Create a Cloud KMS key ring and key in the same region as the bucket, set the bucket's default KMS key to that key, and enable Cloud KMS Data Access audit logs.
D.Store the data in a Cloud Storage bucket encrypted with a customer-supplied encryption key (CSEK) and rotate the key by re-uploading all objects with a new key each quarter.
AnswerC

CMEK on a Cloud Storage bucket is configured by setting a default KMS key, which must be in the same location as the bucket. Cloud KMS Data Access audit logs record every cryptographic operation separately from Cloud Storage data access logs, satisfying the separation requirement. Disabling the key version or the key itself renders the data unreadable without deleting objects, enabling revocation.

Why this answer

Customer-managed encryption keys in Cloud KMS let the organization control key lifecycle, and setting a bucket's default KMS key applies CMEK to every object automatically. Cloud KMS Data Access audit logs capture cryptographic operations independently of Cloud Storage access logs, meeting the separation requirement. Disabling the key version immediately makes objects unreadable, achieving revocation without deleting data, which is exactly the auditor's ask.

Exam trap

The trap here is confusing CSEK with CMEK, since both involve customer-supplied key material but only Cloud KMS CMEK provides centralized audit logging and disable-to-revoke behavior.

8
MCQmedium

A team is deploying a microservice on Cloud Run that needs to access a Cloud SQL database securely. They want to avoid using public IPs and ensure traffic stays within Google's network. Which configuration should they use?

A.Configure Cloud SQL with a public IP and use Cloud SQL Proxy in the Cloud Run service
B.Enable Private Google Access on the VPC subnet
C.Use Serverless VPC Access and assign a private IP to the Cloud SQL instance
D.Create a VPC network peering between the Cloud Run tenant project and the Cloud SQL project
AnswerC

Serverless VPC Access routes Cloud Run egress through a VPC connector, reaching Cloud SQL via its private IP entirely within Google's network. This satisfies the no-public-IP constraint, unlike the Cloud SQL Auth Proxy, which secures connectivity but still requires a public IP or private path.

Why this answer

To keep Cloud Run traffic private and avoid public IPs, you use Serverless VPC Access to connect the Cloud Run service to a VPC, and the Cloud SQL instance is configured with a private IP in that VPC. This keeps all traffic within Google's network and avoids exposing the database publicly. The connector allows the serverless service to reach internal resources by IP.

Exam trap

PCA often tests the confusion between Private Google Access (for Google APIs) and Serverless VPC Access (for reaching VPC resources like Cloud SQL private IPs), leading candidates to pick the wrong connectivity mechanism.

How to eliminate wrong answers

Option A is wrong because using a public IP on Cloud SQL, even with the Cloud SQL Proxy, still exposes the instance to the public internet (the proxy encrypts but does not eliminate the public endpoint), violating the requirement to avoid public IPs. Option B is wrong because Private Google Access only allows VMs without external IPs to reach Google APIs and services; it does not provide connectivity from Cloud Run to a private Cloud SQL instance. Option D is wrong because VPC network peering between the Cloud Run tenant project and the Cloud SQL project is not a supported or necessary configuration — Cloud Run uses Serverless VPC Access connectors, not direct peering, to reach VPC resources.

9
MCQhard

A financial services company requires that all audit logs be retained for 7 years in a cost-effective, immutable storage. They also need to run ad-hoc SQL queries on the logs. Which configuration should they use?

A.Create a log sink to BigQuery with a 7-year partition expiration and use BigQuery's SQL capabilities
B.Use Cloud Logging's default retention and set up a log-based metric to trigger a Cloud Function that copies logs to BigQuery
C.Export logs to Cloud Storage with a retention policy set to 7 years and use Cloud Storage SQL interface
D.Create two log sinks: one to BigQuery for querying, and one to Cloud Storage with object retention policy for immutable storage
AnswerD

BigQuery provides the ad-hoc SQL querying the logs require, while a Cloud Storage bucket with an object retention policy enforces immutability for the full 7-year period. Splitting the sinks lets each backend serve its purpose, and Cloud Storage's low cost per gigabyte satisfies the cost-effectiveness constraint.

Why this answer

The requirement has two parts: immutable 7-year retention and ad-hoc SQL querying. A dual-sink approach satisfies both: one sink to BigQuery for SQL analysis, and one sink to Cloud Storage with an object retention policy (or bucket lock) for immutable, cost-effective long-term storage. This separates query and archival concerns while meeting compliance.

Exam trap

PCA often tests the misconception that BigQuery or Cloud Storage alone can satisfy both immutability and SQL querying, when in fact a dual-sink architecture is required.

How to eliminate wrong answers

Option A is wrong because BigQuery partition expiration deletes data after the period, which is the opposite of immutable 7-year retention, and BigQuery alone does not provide immutable storage guarantees. Option B is wrong because Cloud Logging's default retention is only 30 days, and a log-based metric triggering a Cloud Function is an unreliable, complex pattern that does not guarantee immutability or complete log capture. Option C is wrong because Cloud Storage does not have a native SQL interface for ad-hoc queries; you would need to load data into BigQuery or use external tables, and a retention policy alone does not make objects immutable (you need object retention or bucket lock).

10
MCQhard

A company has a Shared VPC with a service project hosting GKE clusters. The GKE nodes need to access Cloud SQL instances in the host project. The team wants to avoid public IP and use Private Service Access. They have configured a VPC peering between the host VPC and the service producer VPC for Cloud SQL. However, the GKE pods cannot reach the Cloud SQL instance. What is the most likely cause?

A.The Cloud SQL instance is not configured with a private IP
B.The service project needs a Private Service Connect endpoint to access the Cloud SQL instance
C.The service project is not authorized in the Cloud SQL instance
D.The firewall rules in the host VPC block egress from the service project
AnswerC

Correct. After setting up VPC peering with Private Service Access, you must also authorize the service project's VPC network in the Cloud SQL instance's private network settings. Without this authorization, the Cloud SQL instance rejects connections from the GKE pods.

Why this answer

The most likely cause is that the service project is not authorized in the Cloud SQL instance. After configuring Private Service Access (VPC peering) between the host VPC and the service producer VPC, you must explicitly authorize the service project's VPC network in the Cloud SQL instance's private network configuration. Without this authorization, connection attempts from GKE pods will fail.

Option B is incorrect because Private Service Connect is not required; VPC peering is sufficient for connectivity once authorization is granted. Option A is incorrect because the Cloud SQL instance is configured with a private IP via Private Service Access. Option D is incorrect because firewall rules in the host VPC do not block traffic over VPC peering by default; the issue is authorization, not firewall rules.

11
MCQhard

A company is migrating its on-premises MongoDB database to Google Cloud. They want a fully managed, highly available NoSQL database that is compatible with MongoDB drivers. Which Google Cloud service should they choose?

A.Cloud Firestore
B.MongoDB Atlas on Google Cloud Marketplace
C.Cloud Bigtable
D.Cloud SQL
AnswerB

MongoDB Atlas is a fully managed service that preserves native MongoDB wire-protocol compatibility, so existing drivers connect unchanged. Running it via Google Cloud Marketplace satisfies the managed, highly available requirement while avoiding the operational burden of self-managed MongoDB on Compute Engine.

Why this answer

MongoDB Atlas on Google Cloud Marketplace is the correct choice because it is a fully managed MongoDB service that is wire-protocol compatible with native MongoDB drivers, allowing the company to migrate its on-premises MongoDB workload with minimal application changes. It provides high availability, automated backups, and scaling while running on Google Cloud infrastructure.

Exam trap

PCA often tests the distinction between fully managed third-party services available on Google Cloud Marketplace (like MongoDB Atlas) and native Google Cloud databases (Firestore, Bigtable), tricking candidates into choosing a native service that is not driver-compatible.

How to eliminate wrong answers

Option A is wrong because Cloud Firestore is a proprietary Google NoSQL document database that uses its own API and is not compatible with MongoDB drivers or query language. Option C is wrong because Cloud Bigtable is a wide-column NoSQL database designed for high-throughput analytical workloads and does not support MongoDB drivers or document data model. Option D is wrong because Cloud SQL is a managed relational database service (MySQL, PostgreSQL, SQL Server) and cannot host MongoDB workloads.

12
Multi-Selectmedium

A company has a legacy application that runs on a single Compute Engine VM and expects to use a fixed IP address. They want to migrate the VM to a different region with minimal downtime. Which TWO actions should they take?

Select 2 answers
A.Use gcloud compute instances move command
B.Delete the original VM before creating the new one
C.Convert the VM to a managed instance group
D.Reserve a static external IP address in the target region
E.Create a snapshot of the boot disk and create a new VM from the snapshot in the target region
AnswersD, E

A static external IP is regional, so the address must be reserved in the destination region before the new VM exists. This satisfies the fixed-IP constraint, letting the migrated instance retain a predictable address after cutover.

Why this answer

Option D is correct because a static external IP address is region-scoped in Google Cloud, so to keep the legacy application's fixed IP behavior in the new region, a static external IP must be reserved in the target region and attached to the new VM. Option E is correct because creating a snapshot of the boot disk and then creating a new VM from that snapshot in the target region is the standard way to relocate a single Compute Engine VM's disk and data with minimal downtime. Option A is incorrect because gcloud compute instances move only moves an instance between zones within the same region, not to a different region.

Option B is incorrect because deleting the original VM before creating the new one increases downtime and risks losing the working instance. Option C is incorrect because converting to a managed instance group changes the architecture and does not by itself provide a fixed IP or a cross-region migration path.

Exam trap

PCA often tests the regional scope of external IP addresses — candidates assume an IP can be moved across regions like a global resource, but static external IPs are region-bound and must be re-reserved.

13
MCQeasy

A startup runs a batch analytics job on a single Compute Engine instance that takes about nine hours and reads 2 TB from a Cloud Storage bucket each run. The team wants to reduce cost without changing the application code, and the job can be interrupted and resumed from checkpoints. Which machine configuration should the architect recommend?

A.A Spot VM with local SSD scratch space, since the job reads data from Cloud Storage and can resume from checkpoints.
B.A sole-tenant node with a custom machine type sized to the job's peak memory usage.
C.A standard predefined machine type with a balanced persistent disk, billed on demand.
D.A committed use discount for a one-year term on a memory-optimized machine type.
AnswerA

Spot VMs offer deep discounts over on-demand pricing and can be preempted at any time, which is acceptable because the job checkpoints and resumes. Reading source data from Cloud Storage means local SSD is only scratch space, so losing it on preemption does not threaten the workload, making this the most cost-effective fit.

Why this answer

Spot VMs provide the largest discount available on Compute Engine and are appropriate when a workload can tolerate preemption and resume from checkpoints. Because the job reads its source data from Cloud Storage and only uses local SSD as scratch, losing the instance mid-run does not corrupt results, so the cost reduction comes with acceptable risk.

Exam trap

The trap here is assuming preemptible capacity is unsafe for long jobs, when checkpointing and external data storage make interruption harmless.

14
MCQhard

A GKE cluster has a Horizontal Pod Autoscaler (HPA) configured for CPU utilization. The pods are not scaling up even though CPU usage is high. What could be the reason?

A.The cluster autoscaler is disabled
B.The HPA is configured with the wrong metric name
C.The node pool is out of capacity
D.The pods do not have resource requests defined
AnswerD

Without CPU resource requests, the HPA cannot calculate utilisation as a percentage of the requested amount, so it treats the metric as unavailable and refuses to scale. Defining requests on the container spec satisfies the HPA's prerequisite for computing the target utilisation ratio.

Why this answer

HPA for CPU utilization calculates utilization as a percentage of the pod's CPU request, not of the node or a raw usage value. If pods have no resource requests defined, the HPA cannot compute a utilization percentage and will not scale, even when CPU usage is high. Defining CPU requests on the pods resolves this.

Exam trap

PCA often tests the HPA utilization formula — candidates assume HPA scales on raw CPU usage, but it actually scales on usage relative to the pod's CPU request, so missing requests silently break scaling.

How to eliminate wrong answers

Option A is wrong because the cluster autoscaler scales nodes, not pods; HPA scaling decisions are independent of node capacity, and disabling it would not prevent HPA from calculating desired replicas. Option B is wrong because a wrong metric name would typically cause the HPA to report an error or unknown metric, not silently fail to scale while CPU is high. Option C is wrong because node pool capacity affects whether new pods can be scheduled, but HPA would still attempt to scale and show pending pods — the root cause here is the missing request that blocks utilization calculation.

15
MCQmedium

An engineer needs to share a VPC network across multiple projects in an organization while maintaining centralized network administration. Which approach should they use?

A.Shared VPC
B.VPC peering between all projects
C.Private Google Access
D.Cloud VPN between projects
AnswerA

Shared VPC lets a host project's network be shared into service projects, so subnets, firewall rules and routes stay centrally administered by the host project's admins while each service project's resources attach to it. This directly satisfies the requirement to share one VPC across projects with centralised network administration.

Why this answer

Shared VPC in Google Cloud lets an organization designate a host project whose VPC network is shared with multiple service projects. This centralizes network administration (subnets, firewall rules, routes managed in the host project) while allowing teams in service projects to deploy resources into the shared network. It is the canonical answer for cross-project network sharing with centralized control.

Exam trap

PCA often tests the distinction between Shared VPC (centralized admin, host/service projects) and VPC peering (decentralized, non-transitive) — candidates may pick peering thinking it achieves the same centralized control.

How to eliminate wrong answers

Option B is wrong because VPC peering connects separate VPC networks but does not centralize administration — each project still manages its own VPC, and peering is non-transitive, complicating many-project topologies. Option C is wrong because Private Google Access only allows VM instances without external IPs to reach Google APIs and services; it does not share a VPC across projects. Option D is wrong because Cloud VPN provides encrypted connectivity between networks (on-prem or other clouds), not intra-organization VPC sharing with centralized admin.

16
MCQeasy

A DevOps team wants to automate the deployment of infrastructure on Google Cloud using a declarative configuration language. They need to support Python and Jinja templates for reusable modules. Which service should they use?

A.Config Connector
B.Terraform on Google Cloud
C.Cloud Deployment Manager
D.Cloud Build
AnswerC

Cloud Deployment Manager uses YAML or Python plus Jinja templates, satisfying the declarative configuration and reusable-module constraints. Unlike Terraform's HCL or Config Connector's Kubernetes-style resources, its native Python and Jinja support directly matches the team's stated templating requirement.

Why this answer

Cloud Deployment Manager is Google Cloud's native infrastructure as code service that uses declarative YAML or Python/Jinja templates. It supports Python and Jinja templates for reusable modules, making it the correct choice for automating infrastructure deployment with those requirements.

Exam trap

PCA often tests the difference between infrastructure as code tools, and candidates may confuse Cloud Deployment Manager with Config Connector or Terraform, especially regarding template languages.

How to eliminate wrong answers

Option A is wrong because Config Connector is a Kubernetes add-on that allows you to manage Google Cloud resources through Kubernetes manifests, not a standalone declarative language with Python/Jinja templates. Option B is wrong because Terraform on Google Cloud uses HashiCorp Configuration Language (HCL), not Python or Jinja templates. Option D is wrong because Cloud Build is a CI/CD service that can run builds and deployments, but it is not a declarative infrastructure configuration language itself.

17
MCQmedium

A retail company runs a stateless web front end on a managed instance group of Compute Engine VMs behind an external Application Load Balancer. Traffic has grown, and the operations team wants to reduce the cost of idle capacity while still absorbing sharp, unpredictable spikes in user requests. They also want to avoid managing a separate autoscaling policy for each instance group. Which provisioning approach should the architect recommend?

A.Configure the existing managed instance group with a CPU utilization autoscaling policy and set the minimum replicas to the peak observed load.
B.Deploy the front end on Cloud Run with a serverless network endpoint group as the Application Load Balancer backend, letting Cloud Run scale instances automatically from zero request-based capacity.
C.Create a second managed instance group in a different region and use an external proxy Network Load Balancer to split traffic manually.
D.Replace the managed instance group with a single large Compute Engine VM using a committed use discount to lower the hourly rate.
AnswerB

Cloud Run scales stateless containers automatically based on incoming requests, including scaling from zero when idle, which removes the cost of idle VMs. A serverless network endpoint group lets the existing external Application Load Balancer route to Cloud Run, so the team keeps one front door while gaining request-driven elasticity and no per-group autoscaling policy to maintain.

Why this answer

The requirement is to cut idle capacity cost while absorbing unpredictable spikes without maintaining per-group autoscaling policies. Cloud Run provides request-driven autoscaling that can scale to zero and back out rapidly, and a serverless network endpoint group lets the existing external Application Load Balancer keep fronting the service. This removes idle VM cost and centralizes elasticity in the platform rather than in hand-tuned policies.

Exam trap

The trap here is assuming that a CPU-based autoscaling policy on the managed instance group is equivalent to request-driven serverless scaling, when CPU is a lagging signal that cannot react fast enough to sharp spikes.

18
MCQmedium

A company wants to use Cloud Deploy to automate deployments to GKE. They need to configure an approval gate that requires manual approval before promoting a release to a production cluster. Where is this approval gate defined?

A.In the delivery pipeline YAML under the 'target' definition
B.In the Cloud Scheduler job
C.In the GKE cluster as a constraint
D.In the cloudbuild.yaml file
AnswerA

Cloud Deploy approval gates are declared within the delivery pipeline YAML, attached to the relevant target definition, so promotion to the production cluster pauses for manual approval. Defining it elsewhere, such as the Skaffold manifest or release notes, would not enforce the gate.

Why this answer

In Google Cloud Deploy, approval gates are defined within the delivery pipeline configuration, specifically under the target definition. The target represents a deployment environment (e.g., production cluster) and can include a 'requireApproval' field to enforce manual approval before any release is promoted to that target. This ensures that promotions to sensitive environments are gated by human intervention.

Exam trap

PCA often tests the misconception that approval gates are configured in Cloud Build or GKE, when they are actually part of the Cloud Deploy delivery pipeline's target definition.

How to eliminate wrong answers

Option B is wrong because Cloud Scheduler is used to schedule jobs, not to define deployment approval gates; it has no role in Cloud Deploy's promotion workflow. Option C is wrong because GKE cluster constraints (such as network policies or resource quotas) are unrelated to deployment approval; Cloud Deploy approvals are not enforced at the cluster level. Option D is wrong because cloudbuild.yaml is used by Cloud Build to define build steps, not to configure Cloud Deploy pipelines or approval gates.

19
MCQeasy

An organization wants to manage Google Cloud infrastructure as code using declarative configuration files. They need a solution that supports Python and Jinja templating languages. Which service should they choose?

A.Cloud Composer
B.Terraform on Google Cloud
C.Cloud Deployment Manager
D.Cloud Build
AnswerC

Cloud Deployment Manager consumes YAML or Python configuration plus Jinja templates, matching the stem's Python and Jinja requirement for declarative Google Cloud infrastructure as code. Unlike Terraform's HCL or Config Connector's Kubernetes-style manifests, it natively supports both templating languages, satisfying the stated constraint directly.

Why this answer

Cloud Deployment Manager is Google Cloud's native infrastructure-as-code service that uses YAML declarative configuration files and explicitly supports Python and Jinja2 templating for parameterization and reuse. It integrates directly with GCP IAM and APIs, making it the correct choice when the requirement calls out Python and Jinja support. Terraform uses HCL, not Python/Jinja, so it fails the stated requirement.

Exam trap

PCA often tests the distinction between IaC tools by their templating language — candidates see 'Python and Jinja' and incorrectly jump to Terraform or Cloud Build instead of recognizing Deployment Manager as the GCP-native option.

How to eliminate wrong answers

Option A is wrong because Cloud Composer is a managed Apache Airflow workflow orchestration service for data pipelines, not an infrastructure-as-code provisioning tool. Option B is wrong because Terraform on Google Cloud uses HashiCorp Configuration Language (HCL) and its own templating, not Python or Jinja. Option D is wrong because Cloud Build is a CI/CD service that executes build steps from a cloudbuild.yaml, not a declarative IaC manager for GCP resources.

20
MCQeasy

A developer wants to deploy a containerized web application on Google Cloud that can scale to zero when not in use and charges only for resources consumed during request processing. Which compute service should they choose?

A.Cloud Run
B.Google Kubernetes Engine (GKE)
C.App Engine Flexible Environment
D.Compute Engine instance group
AnswerA

Cloud Run runs stateless containers on a fully managed, request-driven platform that scales to zero when idle, billing only per request and consumed CPU/memory. This directly satisfies the stem's constraints: containerised deployment, automatic scale-to-zero, and pay-only-during-request-processing charging.

Why this answer

Cloud Run is a fully managed serverless container platform that scales to zero when there is no traffic and bills only for CPU/memory consumed during request processing (and optionally during background work). It runs any containerized HTTP application, making it the exact match for the stated requirements. GKE and Compute Engine do not scale to zero, and App Engine Flexible keeps at least one instance running.

Exam trap

PCA often tests the difference between serverless container options — candidates confuse App Engine Flexible (always-on instances) with Cloud Run (true scale-to-zero, per-request billing) when the question emphasizes cost only during request processing.

How to eliminate wrong answers

Option B is wrong because GKE clusters always have at least one node running (unless using Autopilot with scale-to-zero on specific workloads, but the cluster itself incurs cost), so it does not truly scale to zero. Option C is wrong because App Engine Flexible Environment requires a minimum of one instance and bills for the underlying VM even when idle. Option D is wrong because a Compute Engine instance group maintains a minimum instance count and bills for VMs continuously, not per request.

21
MCQmedium

A Cloud Run service needs to connect to a Cloud SQL MySQL instance privately without using public IP. What must be configured?

A.Set up VPC Network Peering between Cloud Run and Cloud SQL
B.Enable Private Google Access on the VPC subnet
C.Use Cloud SQL Proxy as a sidecar container
D.Deploy a VPC connector and attach it to the Cloud Run service
AnswerD

A Serverless VPC Access connector gives Cloud Run a private network path, letting it reach the Cloud SQL instance over its internal IP. Attaching the connector to the service satisfies the no-public-IP constraint, since traffic never traverses the internet.

Why this answer

To connect a Cloud Run service to a Cloud SQL instance privately without using public IP, you must deploy a Serverless VPC Access connector and attach it to the Cloud Run service. This connector allows Cloud Run to route traffic to the VPC network, where Cloud SQL's private IP resides. The connection uses the VPC's internal IP range, ensuring private communication.

Exam trap

The trap is confusing VPC peering with Serverless VPC Access connectors; candidates may think peering directly connects Cloud Run to Cloud SQL, but Cloud Run requires a connector to join the VPC network.

How to eliminate wrong answers

Option A is wrong because VPC Network Peering is used between VPC networks, not between Cloud Run (a serverless product) and Cloud SQL; Cloud Run does not have a VPC network to peer. Option B is wrong because Private Google Access allows VMs without external IPs to reach Google APIs, but it does not enable Cloud Run to reach Cloud SQL private IPs. Option C is wrong because Cloud SQL Proxy is typically used for external connections or from Compute Engine; while it can be used as a sidecar in GKE, Cloud Run does not support sidecar containers natively in the same way, and the standard private connection method is a VPC connector.

22
MCQhard

A team is running a GKE cluster with a workload that has variable CPU and memory usage. They want to automatically adjust pod resource requests and limits based on historical usage to improve resource efficiency. Which feature should they use?

A.Vertical Pod Autoscaler (VPA)
B.PodDisruptionBudget (PDB)
C.Horizontal Pod Autoscaler (HPA)
D.Cluster Autoscaler
AnswerA

Vertical Pod Autoscaler continuously analyses historical CPU and memory consumption from the metrics pipeline, then recalculates and applies pod resource requests and limits automatically. This directly satisfies the stem's requirement to right-size requests and limits from observed usage, rather than scaling replica counts horizontally or reacting only to live thresholds.

Why this answer

The Vertical Pod Autoscaler (VPA) automatically adjusts pod resource requests and limits based on historical usage, right-sizing workloads to improve resource efficiency. It observes CPU and memory consumption over time and updates the pod's resource specifications, either by restarting pods (Recreate mode) or, in newer versions, by in-place updates. This directly matches the requirement to adjust requests and limits based on historical usage.

Exam trap

PCA often tests the VPA vs. HPA distinction — candidates see 'variable CPU and memory' and pick HPA, but the key phrase is 'adjust pod resource requests and limits,' which is VPA's job, not HPA's.

How to eliminate wrong answers

Option B is wrong because PodDisruptionBudget (PDB) limits the number of pods that can be voluntarily disrupted during maintenance or scaling — it does not adjust resource requests or limits. Option C is wrong because Horizontal Pod Autoscaler (HPA) scales the number of pod replicas based on metrics like CPU utilization, not the resource requests/limits of individual pods. Option D is wrong because Cluster Autoscaler adjusts the number of nodes in the cluster based on pending pods, not pod-level resource specifications.

23
MCQmedium

A media company runs a batch transcoding job on Compute Engine. The job pulls source files from a Cloud Storage bucket in the same project. Security policy forbids assigning external IP addresses to any VM. The VMs must reach the Cloud Storage API without traversing the public internet. What should the architect configure?

A.Enable Private Google Access on the subnet used by the VMs and ensure the VMs have no external IP addresses.
B.Create a Cloud NAT gateway and route all VM egress through it.
C.Assign the VMs an internal IP address and add a static route to the default internet gateway for the Cloud Storage IP ranges.
D.Configure the VMs to use the restricted.googleapis.com VIP and add a firewall rule allowing egress to 199.36.153.4/30.
AnswerA

Private Google Access lets VMs without external IP addresses reach Google APIs and services, including Cloud Storage, using the internal IP address and Google's internal routing. Enabling it on the subnet is sufficient for the transcoding VMs to read source objects without public internet exposure. This directly satisfies the policy against external IPs while keeping API traffic on Google's network.

Why this answer

Private Google Access allows instances that only have internal IP addresses to reach Google APIs and services such as Cloud Storage over Google's internal network. Enabling it on the subnet is the supported, low-overhead way to let the transcoding VMs read source objects while complying with the no-external-IP policy, without introducing NAT or custom routing.

Exam trap

The trap here is reaching for Cloud NAT as the default way to give private VMs outbound connectivity, when Private Google Access is the specific mechanism for reaching Google APIs without external IPs.

24
MCQeasy

Which GCP service provides distributed tracing to help analyze latency in microservices applications?

A.Cloud Profiler
B.Cloud Trace
C.Cloud Logging
D.Cloud Monitoring
AnswerB

Cloud Trace collects and correlates latency data across microservice calls, producing distributed traces that pinpoint slow spans in request paths. This directly satisfies the need to analyse latency in microservices applications, unlike logging or monitoring services that lack span-level tracing.

Why this answer

Cloud Trace is Google Cloud's distributed tracing service, designed to collect latency data across microservices and display it as traces and spans. It helps identify performance bottlenecks in distributed applications. Cloud Profiler, Logging, and Monitoring serve different observability roles and do not provide distributed tracing.

Exam trap

PCA often tests the difference between observability tools — candidates confuse Cloud Trace (distributed tracing) with Cloud Profiler (code profiling) or Cloud Monitoring (metrics) when the question specifically asks for latency analysis across microservices.

How to eliminate wrong answers

Option A is wrong because Cloud Profiler is a continuous CPU and heap profiler for application code, not a distributed tracing system. Option C is wrong because Cloud Logging aggregates and queries log entries but does not provide trace spans or latency waterfall views. Option D is wrong because Cloud Monitoring collects metrics, dashboards, and alerts, but distributed tracing is handled by Cloud Trace (though Monitoring can surface Trace-derived metrics).

25
MCQeasy

An organization wants to manage DNS records for a domain they own (e.g., example.com) and use Google Cloud for authoritative DNS. They also need to resolve internal hostnames for resources within their VPC. Which Cloud DNS configuration should they use?

A.Create a single public managed zone and use DNS peering for internal resolution
B.Create a single private managed zone for both external and internal DNS resolution
C.Use Google Groups DNS to manage both public and private records
D.Create a public managed zone for example.com and a private managed zone for internal VPC resources
AnswerD

A public managed zone serves authoritative answers for example.com to internet resolvers, while a private managed zone scoped to the VPC resolves internal hostnames for resources inside that network. Two zones satisfy both the public authoritative and internal resolution requirements.

Why this answer

To serve authoritative public DNS for example.com and resolve internal VPC hostnames, the correct design is a public managed zone for example.com and a separate private managed zone associated with the VPC for internal names. This separation ensures public queries resolve to public records while internal queries resolve to private records, and it avoids exposing internal names publicly.

Exam trap

PCA often tests whether candidates understand that public and private DNS zones are separate constructs — a common mistake is assuming a single private zone can serve public authoritative DNS or that DNS peering replaces public zones.

How to eliminate wrong answers

Option A is wrong because DNS peering is used to forward queries between VPCs or to on-premises, not to serve public authoritative DNS for a domain. Option B is wrong because a single private managed zone cannot serve public authoritative DNS for example.com — private zones are only visible within associated VPCs. Option C is wrong because 'Google Groups DNS' is not a Google Cloud DNS feature; Google Groups is for mailing lists and permissions, not DNS management.

26
MCQhard

A healthcare company runs a three-tier application on Compute Engine. The database tier must be reachable only from the application tier, and the application tier must be reachable from the web tier. All tiers are in the same VPC in project prod-apps. The security team requires that rules be evaluated by source identity rather than IP ranges, and that no instance can reach the database unless explicitly allowed. Which configuration should the architect use?

A.Use VPC firewall rules with target tags and source tags, assigning matching tags to instances in each tier.
B.Deploy all tiers into a single managed instance group and use instance group membership as the source selector in firewall rules.
C.Create ingress firewall rules using source IP ranges for each tier, and apply them with network tags on the instances.
D.Assign each tier a unique service account and create ingress firewall rules that specify those service accounts as sources, along with the appropriate target service accounts.
AnswerD

Firewall rules on VPC networks can use service accounts as both source and target, which authorizes traffic based on the identity attached to the instance rather than its IP. Unique service accounts per tier plus service-account-based rules enforce least privilege and satisfy the identity-based evaluation requirement without depending on address ranges.

Why this answer

VPC firewall rules support service accounts as source and target selectors, so attaching a distinct service account to each tier and referencing those accounts in ingress rules authorizes traffic by workload identity. This enforces that only the application tier can reach the database and only the web tier can reach the application tier, without relying on IP ranges or tags.

Exam trap

The trap here is treating network tags and service accounts as interchangeable firewall selectors, when only service accounts provide identity-based authorization for the source.

27
MCQmedium

A company runs a critical application on Compute Engine instances. They want to automatically patch the operating system on a weekly schedule to meet compliance requirements. Which Google Cloud service should they use?

A.Cloud Monitoring
B.Cloud Security Command Center
C.Cloud Build
D.OS Config
AnswerD

OS Config's patch management applies OS updates to Compute Engine instances on a schedule you define, satisfying the weekly compliance requirement without manual intervention. It targets the guest OS directly, unlike image-level tooling, and reports patch compliance per instance, which is exactly what the stem demands.

Why this answer

OS Config, part of VM Manager, provides patch management capabilities including scheduled patching and compliance reporting.

28
Multi-Selecthard

A security team wants to monitor and audit all changes to IAM policies in a Google Cloud organization. They need to set up real-time alerts when a new binding is added. Which THREE services should they combine to achieve this?

Select 3 answers
A.Cloud Scheduler
B.Cloud Pub/Sub
C.Cloud Functions
D.Cloud Audit Logs
E.Cloud Storage
AnswersB, C, D

Cloud Pub/Sub carries the audit log events onward, letting a subscriber receive IAM policy change notifications in real time. Combined with Cloud Logging log sinks and a notification channel, it delivers the alerting pipeline the security team requires for new bindings.

Why this answer

Cloud Audit Logs (D) is correct because Admin Activity audit logs automatically record IAM policy changes such as SetIamPolicy events, which capture when a new binding is added, providing the source of truth for auditing and monitoring. Cloud Pub/Sub (B) is correct because a log sink can route those filtered audit log entries to a Pub/Sub topic in real time, decoupling log ingestion from downstream processing. Cloud Functions (C) is correct because a function can be triggered by messages published to that Pub/Sub topic to evaluate the new binding and send real-time alerts.

Cloud Scheduler (A) is not needed since it only runs jobs on a time schedule and does not provide event-driven, real-time reaction to IAM changes. Cloud Storage (E) is not needed because it is object storage for retaining or archiving data, not a real-time alerting or event-processing service.

29
Multi-Selectmedium

A healthcare analytics team must run a stateless containerized API on Google Cloud. The platform must scale to zero when there is no traffic, expose an HTTPS endpoint with a managed certificate, and require no cluster or node management by the team. The architect is choosing among Google Cloud container platforms. Which two characteristics make Cloud Run the appropriate choice here? (Choose two.)

Select 2 answers
A.Cloud Run scales the service to zero instances when no requests arrive, and bills only for resources consumed while handling requests.
B.Cloud Run allows the team to choose and manage the operating system image and patch cadence of the worker nodes running the containers.
C.Cloud Run supports persistent local SSD storage attached to each instance for stateful session data across requests.
D.Cloud Run manages the underlying infrastructure entirely, so the team never provisions, patches, or sizes cluster nodes or node pools.
E.Cloud Run requires a GKE cluster in the same project so the service can schedule pods onto managed node pools.
AnswersA, D

Cloud Run's request-driven autoscaling can reduce the service to zero instances during idle periods, which removes idle infrastructure cost entirely. That directly satisfies the requirement to scale to zero when no traffic exists, and the consumption-based billing model means the team pays only for the CPU and memory used while requests are being processed, which is exactly the economic behavior the scenario demands.

Why this answer

Cloud Run fits because it scales to zero when idle, charging only for request-driven consumption, and because it fully abstracts the compute layer so no cluster or node administration is needed. Those two properties align with the stateless, low-traffic API and the team's desire to avoid managing infrastructure.

Exam trap

The trap here is conflating Cloud Run with GKE-based container hosting and assuming the team must still manage nodes or choose node images.

30
MCQeasy

A startup wants to deploy a stateless containerized API that must scale automatically from zero and be billed only when requests are processed. The team has no Kubernetes expertise and wants minimal operational overhead. Which Google Cloud service should the architect recommend?

A.App Engine flexible environment with automatic scaling.
B.Compute Engine managed instance group behind an external Application Load Balancer.
C.Google Kubernetes Engine with a cluster autoscaler and Horizontal Pod Autoscaler.
D.Cloud Run with the container image deployed as a service.
AnswerD

Cloud Run runs stateless containers, scales automatically including down to zero when there is no traffic, and bills per request and resource usage. It abstracts away cluster and node management, so a team without Kubernetes expertise can deploy a container image and get a managed HTTPS endpoint. This matches the scaling, billing, and low-overhead requirements precisely.

Why this answer

Cloud Run is the managed serverless container platform that scales to zero, bills per request and resource consumption, and removes cluster and node operations. Deploying the container image as a Cloud Run service gives the startup an HTTPS endpoint with automatic scaling and no idle cost, matching the stateless API, minimal operations, and pay-per-use requirements.

Exam trap

The trap here is equating autoscaling with scale-to-zero, when GKE, managed instance groups, and App Engine flexible all keep minimum capacity running and bill for it even with no traffic.

31
Multi-Selecthard

You are designing a multi-region deployment for a critical application on GKE. The application must withstand a regional outage and automatically redirect traffic to the healthy region. Which THREE components must be configured? (Choose 3)

Select 3 answers
A.Cloud Spanner
B.Global HTTP(S) Load Balancer
C.Regional Cloud SQL
D.Multi-cluster Ingress
E.Cloud NAT
AnswersA, B, D

Cloud Spanner provides a globally distributed, strongly consistent database with multi-region replication, so application data survives a full regional outage. Its synchronous replication across regions satisfies the durability constraint that the critical application must keep serving from the healthy region.

Why this answer

Option A (Cloud Spanner) is correct because it is a globally distributed, strongly consistent, multi-region database with automatic synchronous replication and 99.999% SLA, which lets the application survive a full regional outage without data loss or manual failover. Option B (Global HTTP(S) Load Balancer) is correct because it provides a single global anycast IP, health-check-based backend selection, and automatic traffic redirection to the healthy region when a regional backend fails. Option D (Multi-cluster Ingress) is correct because it is the GKE feature that registers multiple regional GKE clusters as backends of a Global HTTP(S) Load Balancer and performs cross-region failover based on cluster health.

Option C (Regional Cloud SQL) is not appropriate because a regional instance is confined to one region and cannot serve traffic after that region fails. Option E (Cloud NAT) is not relevant because it only provides outbound internet access for private GKE nodes and does not contribute to cross-region failover or traffic redirection.

Exam trap

The trap is assuming that a regional database like Cloud SQL can be made multi-region or that Cloud NAT provides high availability. Candidates must recognize that true multi-region resilience requires globally distributed data and traffic management.

32
MCQmedium

A DevOps team uses Cloud Build to deploy Docker images to GKE. They want to ensure that only images that have passed a vulnerability scan and been signed by a trusted authority can be deployed. Which service should they integrate with Cloud Build and GKE?

A.Artifact Analysis
B.Cloud Security Scanner
C.Cloud Key Management Service
D.Binary Authorization
AnswerD

Binary Authorization enforces deploy-time admission control on GKE, permitting only images with valid attestations from trusted authorities. Cloud Build creates attestations after the vulnerability scan and signing steps, satisfying the stem's requirement that solely scanned, signed images reach the cluster.

Why this answer

Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed to GKE. It integrates with Cloud Build to sign images after vulnerability scanning and with GKE to enforce policies that only allow signed images. This directly meets the requirement of ensuring only scanned and signed images are deployed.

Exam trap

The trap is confusing vulnerability scanning (Artifact Analysis) with enforcement (Binary Authorization). Candidates might think that scanning alone is sufficient, but enforcement requires a policy engine like Binary Authorization.

How to eliminate wrong answers

Option A is wrong because Artifact Analysis provides vulnerability scanning but does not enforce deployment policies or signing. Option B is wrong because Cloud Security Scanner is for scanning web applications, not container images. Option C is wrong because Cloud KMS manages encryption keys but does not enforce deployment policies or image signing by itself.

33
MCQeasy

An organization requires that only container images signed by a trusted authority can be deployed on Google Kubernetes Engine (GKE). Which Google Cloud service should they implement?

A.Artifact Registry
B.Binary Authorization
C.Secret Manager
D.Cloud Deploy
AnswerB

Binary Authorization enforces deploy-time attestation on GKE, admitting only container images whose signatures match trusted attestors. This directly satisfies the requirement that solely images signed by a trusted authority can be deployed, blocking unsigned or tampered images before they reach the cluster.

Why this answer

Binary Authorization is a Google Cloud service that enforces deploy-time policies on GKE, allowing only container images signed by trusted authorities to be deployed. It integrates with Container Analysis and attestations to verify signatures before admission.

Exam trap

PCA often tests the confusion between Artifact Registry (storage) and Binary Authorization (policy enforcement), causing candidates to pick the repository service when the requirement is signature-based admission control.

How to eliminate wrong answers

Option A is wrong because Artifact Registry is a repository for storing and managing container images and packages; it does not enforce signing or admission policies. Option C is wrong because Secret Manager stores sensitive data like API keys and passwords; it has no role in image signing or deployment admission. Option D is wrong because Cloud Deploy is a continuous delivery service for deploying to GKE and other targets; it orchestrates deployments but does not itself enforce image signature verification.

34
MCQeasy

Which Google Cloud service allows you to create alerting policies based on log entries?

A.Cloud Logging
B.Cloud Audit Logs
C.Error Reporting
D.Cloud Monitoring
AnswerD

Cloud Monitoring creates alerting policies from log-based metrics, which are counters derived from log entries via log-based metric filters. This satisfies the stem's requirement to alert on log entries, since the metric is generated directly from matching log data rather than from infrastructure measurements alone.

Why this answer

Cloud Monitoring (formerly Stackdriver) is the Google Cloud service that lets you create alerting policies, including log-based alerts that trigger on specific log entries. You define a query against Cloud Logging data, and Cloud Monitoring evaluates it and fires alerts when matching entries appear. This is the correct service for alerting based on log content.

Exam trap

PCA often tests the distinction between Cloud Logging (stores and queries logs) and Cloud Monitoring (creates alerts and dashboards) — candidates pick Cloud Logging because the question mentions log entries, missing that alerting policies live in Cloud Monitoring.

How to eliminate wrong answers

Option A is wrong because Cloud Logging is the service that stores and queries logs, but it does not itself create alerting policies — it is the data source, not the alerting engine. Option B is wrong because Cloud Audit Logs are a specific category of logs (admin activity, data access, system events) stored in Cloud Logging, not an alerting service. Option C is wrong because Error Reporting aggregates and displays application errors but does not create configurable alerting policies based on arbitrary log entries — it is a specialized error-viewing tool.

35
MCQmedium

A healthcare company is migrating a legacy on-premises Oracle database to Google Cloud. The database is used for a patient records application that requires strong consistency, ACID transactions, and a relational schema with complex joins. The company wants a fully managed, highly available relational database service that minimizes administrative overhead while supporting their existing SQL workloads. Which Google Cloud service should they choose?

A.Cloud Spanner
B.Bigtable
C.Firestore
D.Cloud SQL for PostgreSQL
AnswerD

Cloud SQL for PostgreSQL is a fully managed relational database service that supports ACID transactions, complex joins, and strong consistency, making it ideal for migrating Oracle workloads that require a relational schema. It handles replication, backups, and patching automatically, reducing administrative overhead. The service supports high availability configurations with automatic failover, aligning with the healthcare application's requirements for uptime and data integrity.

Why this answer

Cloud SQL for PostgreSQL is the best choice because it provides a fully managed relational database with ACID compliance, strong consistency, and support for complex SQL queries, matching the legacy Oracle workload's needs. It reduces operational burden with automated backups, replication, and high availability. Other options are either NoSQL databases lacking relational features or overly complex for the required scale.

Exam trap

The trap here is assuming that a globally distributed database like Cloud Spanner is always the best choice for relational workloads, when in fact it may be overkill and incompatible with existing Oracle SQL syntax.

36
MCQeasy

A retail company runs a stateless web tier on a managed instance group (MIG) of Compute Engine VMs behind an external Application Load Balancer. Traffic spikes every evening and the operations team currently resizes the MIG manually. They want the group to add and remove VMs automatically based on CPU utilization without changing the instance template. What should the architect configure?

A.A Cloud Scheduler job that calls the Compute Engine API to resize the managed instance group every evening.
B.A network endpoint group (NEG) that automatically registers new VM instances when CPU usage rises.
C.A preemptible VM pool that the load balancer adds to the backend service during peak hours.
D.An autoscaling policy on the managed instance group using a CPU utilization target.
AnswerD

Autoscaling policies on a MIG add or remove instances based on signals such as average CPU utilization across the group. Because the web tier is stateless and already sits behind a load balancer, scaling the MIG horizontally is the intended pattern and requires no changes to the instance template.

Why this answer

A managed instance group autoscaling policy is the native mechanism for adding and removing Compute Engine VMs in response to load signals such as CPU utilization. Because the web tier is stateless and already behind a load balancer, horizontal scaling is safe and does not require rebuilding the instance template.

Exam trap

The trap here is assuming that scheduling a resize or using preemptible capacity counts as autoscaling, when only a MIG autoscaling policy reacts automatically to utilization metrics.

37
MCQhard

An engineer is troubleshooting a Cloud Build trigger that fails with the error 'PERMISSION_DENIED: Cloud Build service account does not have permission to access Artifact Registry'. The build needs to push a Docker image to Artifact Registry. What is the correct IAM role to assign to the Cloud Build service account?

A.roles/artifactregistry.writer
B.roles/artifactregistry.viewer
C.roles/editor
D.roles/storage.objectAdmin
AnswerA

Granting roles/artifactregistry.writer provides the write permissions Cloud Build requires to push Docker images into Artifact Registry, satisfying the PERMISSION_DENIED constraint. This role permits uploading and creating repository content without granting broader administrative capabilities, so the build service account can complete its image push securely.

Why this answer

Cloud Build's service account needs to push images to Artifact Registry, which requires write access to repositories. The predefined role roles/artifactregistry.writer grants exactly the permissions needed to upload and delete artifacts (including Docker image push) within Artifact Registry repositories. Assigning this role to the Cloud Build service account resolves the PERMISSION_DENIED error while following least privilege.

Exam trap

The trap is assuming that a broad role like roles/editor or a storage-related role will cover Artifact Registry access — the exam expects you to know the service-specific predefined roles and to apply least privilege.

How to eliminate wrong answers

Option B is wrong because roles/artifactregistry.viewer only allows reading and listing artifacts, not pushing or writing them, so the build would still fail with PERMISSION_DENIED. Option C is wrong because roles/editor is a broad basic role that grants excessive permissions across many services and violates least privilege; while it may technically allow the push, it is not the correct or recommended answer for this scenario. Option D is wrong because roles/storage.objectAdmin applies to Cloud Storage buckets, not Artifact Registry repositories, so it does not grant the required artifactregistry.* permissions.

38
MCQmedium

An organization has multiple GCP projects managed by a central operations team. They want to define a common VPC configuration in a host project and allow service projects to use it. Which networking feature should they use?

A.Shared VPC
B.Private Service Connect
C.Cloud VPN
D.VPC peering
AnswerA

Shared VPC lets a host project export subnets to service projects, so the central team retains control of the VPC configuration while each service project deploys its own resources into those shared subnets. This directly satisfies the requirement for one common VPC defined centrally and reused across multiple GCP projects.

Why this answer

Shared VPC allows an organization to designate a host project that owns the VPC network and subnets, and then attach service projects so their resources (VMs, GKE clusters, etc.) can use that shared network. This centralizes network administration under the operations team while letting service teams deploy workloads in their own projects. It is the canonical GCP feature for exactly this host-project/service-project pattern.

Exam trap

The trap is confusing VPC peering with Shared VPC — peering connects two independently managed VPCs, whereas Shared VPC centralizes ownership in a host project, which is what the question's 'host project / service project' wording demands.

How to eliminate wrong answers

Option B is wrong because Private Service Connect is used to privately access Google APIs or third-party services via internal IP endpoints, not to share a VPC network across projects. Option C is wrong because Cloud VPN provides encrypted tunnels between on-premises or other clouds and a VPC, not cross-project VPC sharing. Option D is wrong because VPC peering connects two separate VPC networks so they can communicate, but each project still owns and manages its own VPC — it does not provide the centralized host-project ownership model the question requires.

39
Multi-Selectmedium

A team is deploying a stateful application on GKE. They want to ensure that the application's pods are distributed across different zones for high availability and that during cluster upgrades, at least one pod remains available. Which THREE features should they configure?

Select 3 answers
A.Pod topology spread constraints
B.StatefulSet for the application
C.Cluster autoscaler
D.Horizontal Pod Autoscaler
E.PodDisruptionBudget
AnswersA, B, E

Pod topology spread constraints control how pods are distributed across topology domains such as zones, letting you require even spreading so replicas land in different zones. This satisfies the high-availability requirement by preventing all pods being scheduled into a single zone.

Why this answer

Option A (Pod topology spread constraints) is correct because topologySpreadConstraints with topologyKey set to topology.kubernetes.io/zone (and a whenUnsatisfiable policy such as DoNotSchedule or ScheduleAnyway) explicitly spreads pods evenly across zones, which is exactly what the team needs for zonal high availability. Option B (StatefulSet) is correct because a stateful application requires stable network identities, ordered deployment/scaling, and persistent volume claims per replica, all of which StatefulSet provides via its governing Service and volumeClaimTemplates. Option E (PodDisruptionBudget) is correct because a PDB with minAvailable: 1 (or maxUnavailable: 0) ensures that during voluntary disruptions such as node drains in a cluster upgrade, at least one pod remains running.

Option C (Cluster autoscaler) is not correct because it only adds or removes nodes based on pending pods and resource pressure; it does not control zonal pod distribution or guarantee availability during upgrades. Option D (Horizontal Pod Autoscaler) is not correct because it scales replica counts based on metrics like CPU or custom metrics, which addresses load-based scaling rather than zonal spreading or upgrade-time availability guarantees.

Exam trap

The trap is picking autoscaling features (Cluster Autoscaler, HPA) as if they provide HA — they scale capacity, not placement or disruption protection, which is what the question actually asks for.

40
MCQeasy

A developer needs to store a database password securely and access it from a Cloud Run service. Which Google Cloud service should they use?

A.Cloud Storage
B.Firestore
C.Secret Manager
D.Cloud KMS
AnswerC

Secret Manager stores sensitive values such as database passwords encrypted at rest, and Cloud Run can retrieve them at runtime via mounted secrets or the API. This satisfies the requirement to keep the credential secure rather than embedding it in code or environment variables.

Why this answer

Secret Manager is Google Cloud's dedicated service for storing, managing, and accessing sensitive data such as API keys, passwords, and certificates. It provides versioning, IAM-based access control, audit logging, and automatic rotation, and Cloud Run can mount secrets as environment variables or volumes. This makes it the correct choice for storing a database password securely.

Exam trap

The trap is confusing Secret Manager with Cloud KMS — candidates often pick KMS because it deals with keys and encryption, but KMS manages encryption keys, not application secrets like database passwords.

How to eliminate wrong answers

Option A is wrong because Cloud Storage is object storage for files and blobs, not a secrets management service — storing a password there lacks versioning, rotation, and fine-grained secret-specific access controls. Option B is wrong because Firestore is a NoSQL document database for application data, not a secure secret store. Option D is wrong because Cloud KMS manages encryption keys used to encrypt data, but it does not store application secrets like passwords; you would use KMS to encrypt a secret, but Secret Manager is the store.

41
MCQeasy

A company needs to store secrets such as API keys and database passwords securely and access them from Compute Engine instances. Which service provides secret storage with built-in IAM integration and automatic rotation?

A.Secret Manager
B.Cloud HSM
C.Cloud Storage
D.Cloud KMS
AnswerA

Secret Manager stores API keys and database passwords encrypted, integrates natively with IAM for least-privilege access from Compute Engine instances, and supports automatic rotation. It satisfies the secure storage, IAM integration and rotation requirements in one managed service.

Why this answer

Google Cloud Secret Manager is a secure and convenient storage system for API keys, passwords, certificates, and other sensitive data. It provides built-in IAM integration for access control and supports automatic rotation of secrets via Cloud Functions or other mechanisms, making it the correct choice for storing and accessing secrets from Compute Engine instances.

Exam trap

PCA often tests the distinction between Secret Manager, Cloud KMS, and Cloud HSM, where candidates may confuse key management with secret storage; Secret Manager is specifically for storing and rotating secrets, while KMS manages encryption keys.

How to eliminate wrong answers

Option B is wrong because Cloud HSM is a hardware security module service for cryptographic key operations, not a secret storage service with automatic rotation for application secrets. Option C is wrong because Cloud Storage is an object storage service for unstructured data, not designed for secure secret storage with IAM integration and rotation. Option D is wrong because Cloud KMS is a key management service for encryption keys, not for storing arbitrary secrets like API keys and passwords; it manages cryptographic keys but does not provide secret storage with rotation of application secrets.

42
MCQmedium

A team is using Cloud Build to deploy a microservice to Cloud Run. They want to ensure that only containers built from a specific trusted branch in their source repository are deployed to production. Which Cloud Build feature should they use?

A.Binary Authorization attestors
B.Cloud Build trigger branch filtering
C.Cloud Deploy delivery pipeline approvals
D.Artifact Registry IAM permissions
AnswerB

Branch filtering restricts a trigger to builds originating from a named branch, so only commits from the trusted branch fire the deploy pipeline. This directly enforces the stem's constraint that production deploys come solely from that trusted source branch.

Why this answer

Cloud Build triggers support branch filtering via the 'Branch' field (regex) in the trigger configuration, so a trigger can be scoped to only fire on pushes to a specific branch such as 'refs/heads/main' or 'release/*'. This ensures that only builds originating from the trusted branch proceed to the deploy step, satisfying the requirement with a native Cloud Build feature.

Exam trap

PCA often tests the difference between source-side controls (trigger branch filtering) and deploy-side controls (Binary Authorization, Cloud Deploy approvals) — candidates frequently pick Binary Authorization because it sounds more 'secure' but it does not filter by branch.

How to eliminate wrong answers

Option A is wrong because Binary Authorization attestors verify container image provenance at deploy time (via a signed attestation), but they do not restrict which source branch produced the image — you still need a trigger-level filter to control the source. Option C is wrong because Cloud Deploy approvals gate promotion between environments in a delivery pipeline, not the source branch of the build. Option D is wrong because Artifact Registry IAM controls who can push or pull images, not which branch a build originated from.

43
Multi-Selectmedium

A company wants to monitor the performance of their microservices deployed on Cloud Run. They need to capture request latencies and error rates, and also trace requests across services. Which TWO services should they use?

Select 2 answers
A.Cloud Trace
B.Error Reporting
C.Cloud Profiler
D.Cloud Logging
E.Cloud Monitoring
AnswersA, E

Cloud Trace captures distributed traces across microservices, satisfying the requirement to trace requests spanning services. It records per-request latency data, letting you pinpoint slow spans within a call chain. Error rates, however, come from Cloud Monitoring, so Trace alone covers only the tracing and latency constraints in the stem.

Why this answer

Cloud Trace (A) is correct because it is Google Cloud's distributed tracing service, which collects and correlates latency data across microservices so a single request can be followed from one Cloud Run service to the next. Cloud Monitoring (E) is correct because it ingests Cloud Run request metrics such as request count, latency, and error rates, and lets you build dashboards and alerting policies on them. Together they satisfy the stated requirements of capturing request latencies and error rates while tracing requests across services.

Error Reporting (B) only aggregates and groups application exceptions, Cloud Profiler (C) analyzes CPU and memory usage of running code, and Cloud Logging (D) stores log entries; none of these provide distributed tracing or the request-level latency and error-rate metrics required here.

Exam trap

PCA often tests the distinction between logging, monitoring, and tracing services; candidates might confuse Cloud Logging with Cloud Monitoring or overlook Cloud Trace for distributed tracing.

44
MCQeasy

A media company stores finished video masters in a Cloud Storage bucket. Legal requires that every object be retained for exactly seven years and that no user, including project owners, be able to delete or overwrite an object before that period ends. Which bucket configuration should the architect apply?

A.Enable Uniform Bucket-Level Access and grant the Storage Object Admin role only to the security team.
B.Apply a bucket lock with a retention policy of seven years and grant users the Storage Object Creator role.
C.Enable Object Versioning on the bucket and grant users only the Storage Object Viewer role.
D.Configure a lifecycle rule that moves objects to Archive storage after 30 days and deletes them after 2,555 days.
AnswerB

A retention policy blocks deletion or replacement of objects until the retention period elapses, and locking the bucket makes the policy permanent so that even a project owner cannot shorten or remove it. Setting the period to seven years satisfies the legal hold exactly, and restricting users to object creation prevents them from altering existing masters while still allowing new uploads.

Why this answer

Immutability for a fixed period is delivered by a bucket retention policy, and locking the bucket makes that policy irreversible so no principal can shorten it or delete protected objects early. Seven years expressed as a retention duration plus restricted write access satisfies the legal hold while still permitting new masters to be uploaded to the bucket.

Exam trap

The trap here is confusing versioning or lifecycle management with true immutability, when only a locked retention policy prevents early deletion by privileged users.

45
MCQmedium

A developer wants to deploy a Cloud Function that is triggered whenever a new object is created in a Cloud Storage bucket. Which trigger type should they choose?

A.Firestore trigger
B.Cloud Storage trigger
C.Pub/Sub trigger
D.HTTP trigger
AnswerB

A Cloud Storage trigger fires on object events such as finalise or create, which is precisely the event the stem requires. It is delivered through Eventarc, so the function runs whenever a new object lands in the bucket, satisfying the "new object created" constraint without polling.

Why this answer

A Cloud Storage trigger is specifically designed to invoke a Cloud Function in response to object events in a Cloud Storage bucket, such as object creation (google.storage.object.finalize). This is the direct and native trigger type for 'new object created in a bucket' scenarios. It eliminates the need for additional event routing or polling.

Exam trap

PCA often tests the distinction between direct Cloud Storage triggers and indirect Pub/Sub triggers, so candidates must recognize that the native trigger for bucket object events is Cloud Storage trigger.

How to eliminate wrong answers

Option A is wrong because a Firestore trigger responds to document changes in Firestore, not to Cloud Storage object events. Option C is wrong because a Pub/Sub trigger responds to messages published to a Pub/Sub topic; while Cloud Storage can publish events to Pub/Sub, using a Pub/Sub trigger directly is an indirect approach and not the primary trigger type for bucket object creation. Option D is wrong because an HTTP trigger invokes the function via an HTTP request, which is unrelated to bucket object creation events.

46
MCQhard

A media company streams video from a global user base. The architect must provision a load balancer that terminates TLS, routes requests by URL path to different backend services, and provides a single global anycast IP address. The backend services run on managed instance groups in three regions. Which Google Cloud load balancer should the architect deploy?

A.External passthrough Network Load Balancer
B.Regional external Application Load Balancer
C.Global external Application Load Balancer
D.Internal TCP/UDP Load Balancer
AnswerC

The global external Application Load Balancer is a layer 7 proxy that terminates TLS at the edge, supports URL map path-based routing to multiple backend services, and exposes a single global anycast IP. Backends in multiple regions are reached through the Google front end, so it matches every stated requirement for this global video workload.

Why this answer

A single global anycast IP, edge TLS termination, and URL path routing to backends in three regions all point to the global external Application Load Balancer. Its layer 7 proxy architecture inspects HTTP requests and uses URL maps to direct traffic, while the Google front end absorbs TLS and distributes requests across regional managed instance groups without requiring a separate IP per region.

Exam trap

The trap here is confusing the regional and global Application Load Balancer tiers, since both terminate TLS and route by URL path, but only the global tier provides a single anycast IP spanning multiple regions.

47
Multi-Selectmedium

Which TWO services can be used to create a CI/CD pipeline for a containerized application on Google Cloud? (Choose 2)

Select 2 answers
A.Cloud Deploy
B.Cloud Functions
C.Cloud Build
D.Cloud Scheduler
E.Cloud Run
AnswersA, C

Cloud Deploy is Google Cloud's managed continuous delivery service, orchestrating progressive rollouts to GKE, Cloud Run and Anthos targets via declarative delivery pipelines and targets. It supplies the deployment stage of the CI/CD pipeline, satisfying the continuous-delivery half of the requirement.

Why this answer

Cloud Build (C) is correct because it is Google Cloud's managed CI service that executes build steps defined in a cloudbuild.yaml (or Dockerfile) to build, test, and push container images to Artifact Registry, and it can trigger pipelines from Cloud Source Repositories, GitHub, or Bitbucket. Cloud Deploy (A) is correct because it is Google Cloud's managed continuous delivery service that takes a built container image and progressively rolls it out to GKE, Cloud Run, or Anthos target environments using declarative delivery pipelines and promotion/approval stages. Together they form the CI (Cloud Build) and CD (Cloud Deploy) halves of a containerized CI/CD pipeline.

Cloud Functions (B) is a serverless event-driven compute service for running code snippets, not a pipeline orchestrator. Cloud Scheduler (D) is a cron-based job scheduler that can trigger jobs but does not build or deploy containers. Cloud Run (E) is a serverless container runtime that hosts the application, not a service for constructing the CI/CD pipeline itself.

Exam trap

PCA often tests the CI versus CD split — candidates pick Cloud Run thinking it 'runs the pipeline', but Cloud Run is the runtime target, not the pipeline service.

48
MCQeasy

A development team wants to automate the process of building container images from their GitHub repository and storing them in Artifact Registry. Which Google Cloud service should they use to create a build trigger that runs on every push to the main branch?

A.Container Registry
B.Cloud Build
C.Artifact Registry
D.Cloud Deploy
AnswerB

Cloud Build provides build triggers that watch a connected GitHub repository and execute a build on each push, then push the resulting image to Artifact Registry. Artifact Registry itself only stores images, and other services do not offer repository-triggered builds.

Why this answer

Cloud Build is the correct service because it provides build triggers that can be configured to automatically build container images from source repositories like GitHub. When a push to the main branch occurs, Cloud Build can execute a build using a Dockerfile or buildpack, and then push the resulting image to Artifact Registry. This directly addresses the requirement to automate image building and storage.

Exam trap

PCA often tests the distinction between building and storing container images, so candidates might confuse Artifact Registry (storage) with Cloud Build (building).

How to eliminate wrong answers

Option A is wrong because Container Registry is a deprecated service for storing container images, not for building them; it lacks build trigger capabilities. Option C is wrong because Artifact Registry is a repository service for storing and managing container images and other artifacts, but it does not provide build automation or triggers. Option D is wrong because Cloud Deploy is a service for continuous delivery to GKE and other targets, not for building container images from source code.

49
MCQeasy

A company wants to automatically apply security patches to Compute Engine instances running Windows Server. They need a solution that can schedule patch installations and report compliance. Which service should they use?

A.OS Config
B.Cloud Monitoring
C.Cloud Deploy
D.Cloud Build
AnswerA

OS Config provides patch management for Windows Server and Linux VMs, letting you create patch jobs on a schedule and view compliance reports per instance. It satisfies both the scheduling and reporting requirements without custom scripting.

Why this answer

OS Config (now part of VM Manager) provides patch management for Compute Engine instances, including Windows Server, with the ability to schedule patch jobs, define patch windows, and report compliance through the OS Config API and Cloud Console. It is the native Google Cloud service designed for OS patch deployment and compliance reporting across fleets of VMs.

Exam trap

PCA often tests the difference between observability (Cloud Monitoring) and configuration management (OS Config) — the trap is selecting Cloud Monitoring because it can show patch-related metrics, when only OS Config can actually schedule and apply patches.

How to eliminate wrong answers

Option B is wrong because Cloud Monitoring is an observability service for metrics, logs, and alerts — it can report on patch status if metrics are exported, but it cannot schedule or apply patches. Option C is wrong because Cloud Deploy is a continuous delivery service for deploying applications to GKE and other targets, not for OS patch management. Option D is wrong because Cloud Build is a CI/CD service for building and testing software artifacts, not for patching VM operating systems.

50
MCQeasy

A media startup wants to give its data science team isolated environments for experimentation while keeping billing and user management under one organization. Each environment must have its own quotas and IAM boundary, and the team wants to add or remove environments quickly without renegotiating billing. Which Google Cloud resource hierarchy construct should the architect use for each environment?

A.A single project with separate VPC networks and firewall rules for each environment.
B.A separate Google Cloud organization for each environment, each linked to its own billing account.
C.A folder under the organization, with one project per environment and IAM policies inherited from the folder.
D.A standalone project not attached to the organization, with billing enabled directly on the project.
AnswerC

Folders let an organization group projects and apply IAM and organization policies that are inherited by all contained projects, creating a clean boundary per environment. Projects give each environment its own quotas and resource namespace, and the whole structure stays under the single organization and billing account, so environments can be created or removed quickly.

Why this answer

Folders sit between the organization and projects and let administrators apply IAM and organization policies that projects inherit, giving each environment a consistent administrative boundary. Each project supplies its own quotas, APIs, and resource namespace, so experiments stay isolated. Because everything remains inside one organization and billing account, environments can be spun up or torn down quickly without touching billing or identity setup.

Exam trap

The trap here is assuming that separate VPC networks inside one project provide the same isolation as separate projects, when IAM and quotas remain shared.

51
Multi-Selecthard

A finance company needs to ensure that all compute instances in their VPC can only communicate with Google APIs (e.g., Cloud Storage) over internal IPs. Additionally, instances without external IPs should be able to access the internet for updates. Which TWO configurations should they implement?

Select 2 answers
A.Configure Cloud NAT
B.Create a firewall rule allowing egress to 0.0.0.0/0
C.Enable Private Google Access on the subnet
D.Assign external IPs to all instances
E.Use VPC peering with Google's public network
AnswersA, C

Cloud NAT lets instances lacking external IPs reach the internet for updates, satisfying that requirement without exposing them publicly. It complements Private Google Access, which handles the internal-IP path to Google APIs; NAT alone cannot provide that private API connectivity.

Why this answer

Option A (Configure Cloud NAT) is correct because Cloud NAT lets instances that have no external IP addresses initiate outbound connections to the internet for updates, while keeping them unreachable from inbound internet traffic. Option C (Enable Private Google Access on the subnet) is correct because it allows instances without external IPs to reach Google APIs and services such as Cloud Storage using internal IP addresses rather than public ones. Together these two settings satisfy both requirements: private access to Google APIs and outbound internet access without external IPs.

Option B is not needed because a firewall egress rule to 0.0.0.0/0 only permits traffic and does not by itself provide NAT or a route to the internet for instances lacking external IPs. Option D is wrong because assigning external IPs contradicts the goal of using internal IPs for Google API access and exposes instances to the internet. Option E is wrong because VPC peering connects VPC networks to each other and does not provide access to Google's public APIs or general internet connectivity.

Exam trap

PCA often tests the difference between Private Google Access and Cloud NAT, and candidates might think that one alone can handle both Google APIs and internet access, but they serve different purposes.

52
MCQmedium

A team wants to deploy a microservice on Cloud Run that needs to access a Cloud Memorystore for Redis instance in the same region. The Redis instance is in a VPC network. Which configuration is required for Cloud Run to reach the Redis instance?

A.Configure a Cloud NAT gateway
B.Create a Serverless VPC Access connector and configure Cloud Run to use it
C.Use Private Google Access
D.Deploy Cloud Run within a VPC
AnswerB

Serverless VPC Access provides a connector that lets Cloud Run send traffic into the specified VPC, reaching the Redis instance's private IP. Without it, Cloud Run egress cannot route to Memorystore, which has no public endpoint.

Why this answer

Cloud Run is serverless and runs outside the customer VPC by default. To reach a Memorystore Redis instance inside a VPC, you must create a Serverless VPC Access connector and attach it to the Cloud Run service, enabling egress to the VPC. This provides private IP connectivity to Redis.

Exam trap

PCA often tests the misconception that Cloud Run can be placed directly in a VPC — candidates pick 'deploy within a VPC' instead of the correct Serverless VPC Access connector.

How to eliminate wrong answers

Option A is wrong because Cloud NAT provides outbound internet access for private instances, not connectivity into a VPC from serverless. Option C is wrong because Private Google Access allows VMs without external IPs to reach Google APIs, not Memorystore Redis. Option D is wrong because Cloud Run cannot be 'deployed within a VPC' in the traditional sense; it uses Serverless VPC Access connectors for VPC egress.

53
MCQmedium

A healthcare analytics company must store patient records in Cloud Storage. Compliance requires that the data be encrypted with keys the company generates and rotates itself, and that the company retain the ability to revoke access by disabling the key. The data must remain readable by authorized applications in the same project. What should the architect implement?

A.Customer-supplied encryption keys (CSEK) passed with every object write and read request.
B.Customer-managed encryption keys (CMEK) in Cloud KMS, referenced by the bucket's default encryption configuration.
C.Google-managed encryption keys, relying on Cloud Storage default encryption.
D.Client-side encryption performed by the analytics application before uploading objects to Cloud Storage.
AnswerB

CMEK lets the organization create and rotate keys in Cloud KMS and control their lifecycle, including disabling a key to revoke access. Configuring the bucket's default encryption with a CMEK key ensures new objects are encrypted with that key, and authorized applications in the project can decrypt through IAM permissions on the key.

Why this answer

Customer-managed encryption keys in Cloud KMS give the organization ownership of key material, rotation control, and the ability to disable a key to revoke access. Setting the bucket default encryption to a CMEK key applies that key to newly written objects, and IAM on the key governs which applications can decrypt.

Exam trap

The trap here is confusing customer-supplied keys, where the raw key never reaches Google, with customer-managed keys in Cloud KMS that still support centralized rotation and disablement.

54
MCQmedium

A Cloud Run service needs to access resources in a VPC network (e.g., a Cloud SQL instance). The service should be able to send requests to the VPC and receive responses. What is the correct configuration?

A.Create a VPC connector and configure the Cloud Run service to use it for egress
B.Place the Cloud Run service in a VPC subnet
C.Use Cloud NAT to allow Cloud Run to access the VPC
D.Use VPC peering between Cloud Run and the VPC
AnswerA

A Serverless VPC Access connector provides a path from Cloud Run into the VPC, letting the service send requests to private resources such as Cloud SQL and receive responses, which is exactly the bidirectional VPC access the scenario requires.

Why this answer

Cloud Run services run outside the customer's VPC by default, so to reach private VPC resources like a Cloud SQL instance with a private IP, you must attach a Serverless VPC Access connector. The connector provides a bridge from the serverless environment into the specified VPC network and subnet, allowing outbound requests to private IPs and return traffic. Configuring the service to use the connector for egress (all traffic or private ranges only) is the documented, supported pattern for this requirement.

Exam trap

PCA often tests the misconception that serverless services like Cloud Run can be 'placed in a subnet' or reached via VPC peering, when in reality they require a Serverless VPC Access connector (or Direct VPC egress) to bridge into the VPC.

How to eliminate wrong answers

Option B is wrong because Cloud Run is a fully managed serverless platform and does not allow you to place a service directly into a VPC subnet; there is no 'deploy into subnet' setting. Option C is wrong because Cloud NAT provides outbound internet access for resources already inside a VPC (such as GCE VMs or GKE nodes) and does nothing to connect a serverless service to private VPC IPs. Option D is wrong because VPC peering connects two VPC networks, and Cloud Run does not expose a VPC network that can be peered; peering cannot bridge the serverless environment to your VPC.

55
MCQhard

A company wants to deploy a microservice on Cloud Run that requires high throughput and low latency. The service processes requests that can spike unpredictably. The team wants to minimize cold starts and ensure availability during traffic bursts. Which combination of Cloud Run settings should they configure?

A.min-instances = 1, max-instances = 1, concurrency = 80
B.min-instances = 0, max-instances = 100, concurrency = 1
C.min-instances = 0, max-instances = 10, concurrency = 80
D.min-instances = 1, max-instances = 100, concurrency = 80
AnswerD

Setting min-instances to 1 keeps one warm instance, eliminating cold starts for the baseline load, while max-instances = 100 caps horizontal scaling during unpredictable spikes. Concurrency = 80 lets each instance handle many simultaneous requests, improving throughput and reducing latency, satisfying the burst-availability constraint.

Why this answer

To minimize cold starts, the team must keep at least one warm instance, so min-instances must be 1 (not 0). To handle unpredictable spikes, max-instances must be high enough to scale out, so 100 is appropriate. Concurrency of 80 allows each instance to handle many simultaneous requests, maximizing throughput per instance and reducing the number of instances needed.

Only option D combines a warm minimum, a high ceiling, and high concurrency.

Exam trap

The trap is equating 'minimize cold starts' with cost optimization and choosing min-instances = 0, or confusing concurrency with instance count — candidates must recognize that a warm minimum plus high concurrency is what actually reduces cold starts and handles bursts.

How to eliminate wrong answers

Option A is wrong because max-instances = 1 caps the service at a single instance, so it cannot scale during traffic bursts and will queue or reject requests. Option B is wrong because min-instances = 0 allows the service to scale to zero, guaranteeing cold starts, and concurrency = 1 severely limits throughput per instance, forcing many instances and increasing latency. Option C is wrong because min-instances = 0 still permits scale-to-zero and cold starts, and max-instances = 10 may be too low for unpredictable high-throughput bursts.

56
Multi-Selectmedium

An organization wants to monitor and alert on custom application metrics from a GKE cluster. They also need to view logs in real-time and create metrics from log content. Which two GCP services should they use? (Choose two.)

Select 2 answers
A.Error Reporting
B.Cloud Monitoring
C.Cloud Profiler
D.Cloud Trace
E.Cloud Logging
AnswersB, E

Cloud Monitoring ingests custom application metrics from GKE, evaluates alerting policies against them, and can define log-based metrics from log content. It therefore satisfies both the custom metric alerting and log-derived metric requirements within one service.

Why this answer

Cloud Monitoring (B) is correct because it is the GCP service that ingests custom application metrics, lets you build dashboards, and configure alerting policies on those metrics from GKE workloads. Cloud Logging (E) is correct because it collects and streams logs in real time, and its log-based metrics feature lets you create counter or distribution metrics directly from log content. Together they satisfy both requirements: metric monitoring/alerting and real-time log viewing with metrics derived from logs.

Error Reporting (A) only aggregates and groups application errors, not general metrics or log-based metrics. Cloud Profiler (C) analyzes CPU and heap usage for performance profiling, not metric alerting or log viewing. Cloud Trace (D) captures distributed latency traces across services, which is unrelated to custom metric alerting or log-based metric creation.

57
Multi-Selectmedium

A company is migrating a legacy application that uses a file server to GCP. The application requires a shared file system that supports the NFS protocol and can be mounted by multiple Compute Engine instances. The team also needs to use Cloud NAT to allow the instances to download updates. Which TWO services should they use? (Choose 2)

Select 2 answers
A.Cloud NAT
B.Cloud VPN
C.Cloud Storage Fuse
D.Cloud Filestore
E.Private Google Access
AnswersA, D

Cloud NAT provides managed outbound internet connectivity for Compute Engine instances without external IP addresses, letting them download updates. It satisfies the requirement directly and is the correct service pairing alongside the shared NFS file system.

Why this answer

Cloud Filestore (D) is correct because it is GCP's fully managed file storage service that natively supports the NFSv3 protocol and can be mounted simultaneously by multiple Compute Engine instances, which is exactly what the legacy application requires for its shared file system. Cloud NAT (A) is correct because it provides outbound internet access for instances without external IP addresses, allowing them to download updates while remaining unreachable from the internet. Cloud VPN (B) is not appropriate here because it establishes encrypted tunnels to on-premises or other networks, not a shared NFS file system or outbound NAT.

Cloud Storage Fuse (C) is not correct because it mounts Cloud Storage buckets as a local file system via a FUSE adapter, which does not provide a true NFS-protocol shared file system for multiple instances. Private Google Access (E) is not correct because it only enables instances without external IPs to reach Google APIs and services, not general internet downloads, which is what Cloud NAT handles.

Exam trap

The trap is confusing Private Google Access with Cloud NAT — candidates pick Private Google Access for outbound internet, but it only covers Google APIs, while Cloud NAT handles general outbound internet access.

58
MCQmedium

A company has a Cloud Run service that processes high-throughput requests. They want to reduce latency by keeping a baseline of warm instances always ready to handle traffic. Which Cloud Run configuration parameters should they adjust?

A.Set min-instances to 0 and max-instances to 100
B.Set max-instances to a high value and concurrency to 1
C.Set min-instances to 10 and CPU to always-on
D.Set max-instances to 0 (unlimited) and concurrency to 80
AnswerC

Min-instances keeps a baseline of warm instances alive so cold starts do not add latency, while CPU set to always-on prevents throttling between requests. Together they satisfy the requirement for always-ready capacity under high-throughput load.

Why this answer

Setting min-instances to a value greater than zero (e.g., 10) ensures that Cloud Run keeps that many instances warm and ready at all times, eliminating cold-start latency for the baseline traffic. Additionally, setting CPU to 'always-on' (also called 'CPU always allocated') prevents the CPU from being throttled to near-zero when no requests are being processed, which is critical for background work and for maintaining warm instances that can respond immediately. Together, these two parameters directly address the requirement to keep a baseline of warm instances and reduce latency.

Exam trap

PCA often tests the misconception that setting max-instances high or concurrency low will keep instances warm, but only min-instances > 0 and CPU always-on actually guarantee warm instances and eliminate cold starts.

How to eliminate wrong answers

Option A is wrong because setting min-instances to 0 allows Cloud Run to scale down to zero instances when there is no traffic, causing cold starts and increased latency for the next request. Option B is wrong because setting concurrency to 1 forces each instance to handle only one request at a time, which drastically reduces efficiency and increases the number of instances needed, and max-instances alone does not keep instances warm. Option D is wrong because max-instances set to 0 is not a valid configuration (it would mean no instances allowed), and concurrency to 80 does not ensure warm instances; it only controls how many concurrent requests each instance can handle.

59
MCQhard

A company wants to enforce that only container images built and signed by their CI/CD pipeline can be deployed in their GKE cluster. Which Google Cloud service should they use?

A.Artifact Analysis
B.Binary Authorization
C.Cloud Audit Logs
D.Cloud Security Command Center
AnswerB

Binary Authorization enforces deploy-time attestations, letting only images signed by your CI/CD pipeline's attestors run in GKE. It satisfies the stem's constraint that solely pipeline-built and pipeline-signed container images be admitted, by validating cryptographic attestations against a defined policy before the admission controller permits the workload.

Why this answer

Binary Authorization is the Google Cloud service that enforces deploy-time policies on GKE, allowing only container images that meet attestation requirements (e.g., signed by the CI/CD pipeline) to be deployed. It integrates with Container Analysis/Artifact Analysis to verify signatures and attestations before admitting a pod.

Exam trap

The trap is confusing Artifact Analysis (scanning/metadata) with Binary Authorization (enforcement) — candidates pick Artifact Analysis because it deals with images, but only Binary Authorization enforces the signed-image policy at deploy time.

How to eliminate wrong answers

Option A (Artifact Analysis) is wrong because it provides vulnerability scanning and metadata storage for container images, not deploy-time admission control — it can supply attestations but does not enforce them. Option C (Cloud Audit Logs) is wrong because it records API activity for auditing, not policy enforcement at deployment time. Option D (Cloud Security Command Center) is wrong because it aggregates security findings and posture management; it does not block unsigned images from being deployed.

60
Multi-Selectmedium

An organization wants to ensure that all Compute Engine instances in a project are patched with the latest security updates. They also want to enforce a custom configuration (e.g., disable root SSH login) across all instances. Which TWO Google Cloud services should they use together?

Select 2 answers
A.Cloud Monitoring
B.OS Config patch management
C.Cloud Deployment Manager
D.OS Config OS policies
E.Cloud Asset Inventory
AnswersB, D

OS Config patch management automates security update deployment across Compute Engine instances, satisfying the patching requirement. It operates via the OS Config agent on each VM, applying patch jobs on schedules you define. However, it alone cannot enforce the custom configuration; that needs OS Policy assignment, which is why pairing both services is required.

Why this answer

Option B, OS Config patch management, is correct because it is the Google Cloud service that lets you scan and automatically apply OS security patches to Compute Engine instances across a project, satisfying the requirement to keep all instances patched with the latest security updates. Option D, OS Config OS policies, is correct because it lets you define and enforce a custom desired-state configuration (such as disabling root SSH login via an OS policy assignment) across all instances in the project. Together, patch management handles patching while OS policies enforce the custom configuration, which is exactly the combined outcome the organization wants.

Option A, Cloud Monitoring, is not correct because it only observes metrics, logs, and alerts; it does not patch or enforce configuration. Option C, Cloud Deployment Manager, is not correct because it is an infrastructure-as-code deployment tool for provisioning resources, not for ongoing OS patching or enforcing in-guest configuration. Option E, Cloud Asset Inventory, is not correct because it only inventories and tracks cloud assets and their metadata; it cannot patch instances or apply OS-level policies.

Exam trap

PCA often tests the distinction between infrastructure provisioning (Deployment Manager) and ongoing configuration management (OS Config), causing candidates to pick Deployment Manager for enforcement tasks.

61
MCQmedium

A retail company runs a stateful PostgreSQL database on a Compute Engine VM in project prod-db. The database writes nightly backups to a regional Cloud Storage bucket in a separate project, backup-archive. The security team requires that the VM's service account can upload objects but must not be able to delete or overwrite existing backups. Which IAM configuration should the architect implement?

A.Grant roles/storage.legacyBucketWriter on the bucket to the VM's service account.
B.Grant roles/storage.objectCreator on the bucket to the VM's service account.
C.Grant roles/storage.objectViewer on the bucket to the VM's service account.
D.Grant roles/storage.objectAdmin on the bucket to the VM's service account.
AnswerB

roles/storage.objectCreator allows only the storage.objects.create permission, so the VM can upload new backup objects but cannot delete or overwrite existing ones. Applying it at the bucket level scopes the permission precisely to backup-archive, satisfying the least-privilege requirement while still allowing the nightly uploads to succeed.

Why this answer

The VM's service account needs write-only access to the backup bucket, which maps exactly to the storage.objects.create permission contained in the objectCreator role. Applying that role on the specific bucket limits the grant to backup-archive and prevents deletion or overwriting of existing backups. Broader roles such as objectAdmin or legacyBucketWriter include delete and overwrite permissions that violate the immutability requirement.

Exam trap

The trap here is assuming that any write-capable Storage role is equivalent and overlooking that objectAdmin and legacyBucketWriter also grant delete and overwrite permissions that break the immutability requirement.

62
MCQeasy

An engineer wants to store a database password securely and allow a Cloud Run service to access it. Which GCP service should they use?

A.Secret Manager
B.Cloud Storage
C.Cloud Key Management Service (KMS)
D.Firestore
AnswerA

Secret Manager stores credentials encrypted at rest and exposes them through IAM-controlled API calls, so the Cloud Run service account retrieves the database password at runtime rather than embedding it in code or environment variables. This directly satisfies the requirement for secure storage with service-level access control.

Why this answer

Secret Manager is designed to securely store and manage sensitive data like database passwords, API keys, and certificates. It provides versioning, access control, and audit logging, and integrates with Cloud Run to inject secrets as environment variables or mounted volumes.

Exam trap

PCA often tests the difference between Secret Manager and KMS: candidates may choose KMS for storing secrets, but KMS is for key management, not secret storage.

How to eliminate wrong answers

Option B is wrong because Cloud Storage is for object storage and lacks the security features, access controls, and versioning specifically designed for secrets. Option C is wrong because Cloud KMS is for managing encryption keys, not for storing arbitrary secrets; it encrypts data but does not provide a secret storage mechanism. Option D is wrong because Firestore is a NoSQL document database for application data, not for secure secret storage; it lacks the specialized security and access patterns for secrets.

63
MCQhard

A healthcare analytics company stores sensitive patient datasets in a Cloud Storage bucket in the us-central1 region. A new regulation requires that the data never leave the United States and that access be restricted to a defined set of projects. The security team wants a guardrail that prevents any future project from reading the bucket unless it is explicitly authorized, while keeping administration simple. What should the architect implement?

A.Create an organization policy with the constraints/gcp.resourceLocations constraint set to allow only us-central1, and attach it to the organization node.
B.Enable Object Versioning and a retention policy on the bucket, then share the bucket with the authorized projects using signed URLs.
C.Create a VPC Service Controls perimeter around the authorized projects with the Cloud Storage bucket as a protected resource, and grant access only through the perimeter.
D.Apply a bucket-level IAM policy that grants roles/storage.objectViewer only to the authorized projects' service accounts and enable uniform bucket-level access.
AnswerC

VPC Service Controls creates a security perimeter that blocks access to protected services such as Cloud Storage from outside the perimeter, regardless of IAM grants. Placing the bucket and the authorized projects inside the perimeter ensures that any future project outside it cannot read the data even if it receives an IAM role, which directly meets the guardrail requirement while keeping administration centralized.

Why this answer

The regulation requires both a location boundary and a hard restriction on which projects may read the data. VPC Service Controls builds a perimeter that denies access to protected services from outside the perimeter, so even a project that later receives an IAM role cannot read the bucket unless it is inside the perimeter. This gives a centralized guardrail that IAM or resource location constraints alone cannot provide.

Exam trap

The trap here is treating an IAM policy or a resource location constraint as a complete data-residency guardrail, when only a VPC Service Controls perimeter blocks access from projects outside an authorized boundary.

64
MCQmedium

A company uses Cloud Build to deploy a Java application to Artifact Registry. They want to automatically trigger a build only when changes are pushed to the 'main' branch in their Cloud Source Repository. Which configuration should they use?

A.Configure a Cloud Function that listens for Pub/Sub messages from Cloud Source Repo and calls Cloud Build API
B.Create a Cloud Build trigger with an included branch filter set to '^main$'
C.Create a Cloud Scheduler job that runs a Pub/Sub push to Cloud Build every hour
D.Use a Cloud Build build step that checks the branch name and aborts if not main
AnswerB

An included branch filter using the regex ^main$ restricts the trigger to pushes on the main branch only, satisfying the stem's requirement. Without that filter, the trigger would fire on every branch push, causing unwanted builds.

Why this answer

Cloud Build triggers natively support branch filtering via the `included` or `ignored` branch filters. Setting the included branch filter to the regex `^main$` ensures the trigger only fires when a push event occurs on the `main` branch. This is the intended, serverless, and declarative way to achieve branch-specific builds without custom code or polling.

The `^` and `$` anchors guarantee an exact match, preventing accidental triggers on branches like `feature/main` or `main-dev`.

Exam trap

PCA often tests the difference between event-driven triggers and polling mechanisms, and candidates may overcomplicate the solution by choosing custom Cloud Functions or build-step checks instead of using the native branch filter feature of Cloud Build triggers.

How to eliminate wrong answers

Option A is wrong because it introduces unnecessary complexity and latency by using a Cloud Function to relay Pub/Sub messages to the Cloud Build API, whereas Cloud Build triggers already integrate directly with Cloud Source Repositories and support branch filtering natively. Option C is wrong because a Cloud Scheduler job that runs hourly is a time-based poll, not an event-driven trigger; it would build regardless of whether changes were pushed, and it cannot filter by branch. Option D is wrong because a build step that checks the branch name runs only after the build has already started, wasting resources and time; it also requires custom scripting and does not prevent the trigger from firing on other branches.

65
Multi-Selectmedium

A healthcare company must store patient documents in Cloud Storage. Compliance requires that the data be encrypted with keys the company controls and that key usage be centrally audited and revocable. The architect plans to use Cloud KMS. Which two actions should the architect take to meet these requirements? (Choose two.)

Select 2 answers
A.Create a customer-supplied encryption key (CSEK) and store it in Secret Manager for each object upload.
B.Enable Cloud External Key Manager (Cloud EKM) backed by keys held in a third-party HSM.
C.Create a Cloud KMS key ring and a customer-managed encryption key (CMEK) in the same region as the bucket, and configure the bucket to use that key as its default encryption key.
D.Enable uniform bucket-level access on the bucket to force CMEK usage.
E.Grant the Cloud Storage service agent the roles/cloudkms.cryptoKeyEncrypterDecrypter role on the CMEK.
AnswersC, E

Using a CMEK as the bucket's default encryption key ensures that every object written to the bucket is encrypted with a key the company controls. Because Cloud KMS logs key operations in Cloud Audit Logs, the company gains centralized visibility and can disable or destroy the key to revoke access, satisfying both compliance requirements.

Why this answer

Meeting the compliance goals requires a customer-managed encryption key configured as the bucket's default encryption key, plus the Cloud Storage service agent holding cryptoKeyEncrypterDecrypter on that key. Together these ensure all objects are encrypted with a company-controlled key and that every key operation is recorded in Cloud Audit Logs, enabling auditing and revocation through Cloud KMS.

Exam trap

The trap here is assuming that enabling uniform bucket-level access or using customer-supplied keys provides the same central auditing and revocation as a Cloud KMS CMEK, when neither does.

66
MCQeasy

Which GCP service should be used to automatically scale a GKE cluster's number of nodes based on pending pods?

A.Vertical Pod Autoscaler (VPA)
B.Cluster Autoscaler
C.Node Auto-Provisioning
D.Horizontal Pod Autoscaler (HPA)
AnswerB

Cluster Autoscaler adds or removes nodes in a GKE node pool when pods remain pending due to insufficient allocatable resources, directly satisfying the stem's requirement to scale node count from pending pods. It watches the scheduler's unschedulable queue, unlike Horizontal Pod Autoscaler, which only adjusts replica counts of workloads.

Why this answer

The GKE Cluster Autoscaler watches for pods that cannot be scheduled due to insufficient node capacity and automatically adds nodes to the node pool (and removes underutilized nodes). This is exactly the behavior described — scaling the cluster's node count based on pending pods.

Exam trap

PCA often tests the confusion between HPA (scales pods), VPA (scales pod resources), and Cluster Autoscaler (scales nodes) — candidates who see 'pending pods' and pick HPA miss that HPA cannot help when there is no node capacity to schedule onto.

How to eliminate wrong answers

Option A is wrong because Vertical Pod Autoscaler adjusts CPU/memory requests and limits of individual pods, not the number of nodes in the cluster. Option C is wrong because Node Auto-Provisioning creates new node pools with different machine types when needed, but it is a complementary feature that works alongside Cluster Autoscaler and does not by itself handle the basic pending-pod scale-up scenario. Option D is wrong because Horizontal Pod Autoscaler scales the number of pod replicas based on metrics like CPU, not the number of underlying nodes.

67
MCQmedium

You want to monitor the latency of an application running on Compute Engine and create an alert if the 99th percentile latency exceeds 500ms for more than 5 minutes. Which approach should you use?

A.Use Cloud Trace to analyze latency and set a trace-based alert
B.Use Error Reporting to capture latency errors
C.Create a Metric Threshold alert using the 'Latency' metric with a percentile alignment
D.Create a log-based metric from application logs and set an alert on that metric
AnswerC

A metric threshold alert with percentile alignment computes the 99th percentile latency over the window and fires when it exceeds 500ms for more than 5 minutes. This directly matches the stated latency percentile and duration condition on the Compute Engine application.

Why this answer

To monitor latency and alert on the 99th percentile exceeding 500ms for more than 5 minutes, you should create a Metric Threshold alert in Cloud Monitoring using the appropriate latency metric (e.g., from a load balancer or application) with a percentile alignment. This allows you to aggregate latency data over a window and trigger an alert when the condition is met.

Exam trap

PCA often tests the confusion between monitoring and tracing tools, where candidates might choose Cloud Trace for alerting because it deals with latency, but it lacks native alerting capabilities.

How to eliminate wrong answers

Option A is wrong because Cloud Trace is for analyzing request traces and does not natively support alerting on latency percentiles; it is a diagnostic tool, not an alerting mechanism. Option B is wrong because Error Reporting captures errors and exceptions, not latency metrics, and cannot alert on latency thresholds. Option D is wrong because log-based metrics are derived from logs and may not provide the precise latency percentile data needed; they are better suited for counting specific log events.

68
MCQmedium

A company runs a stateful application on GKE that requires persistent storage. They want to ensure that during cluster upgrades, pods are not disrupted and storage is preserved. Which configuration should they use?

A.Enable Cluster Autoscaler on the node pool
B.Use a Deployment with a HorizontalPodAutoscaler
C.Use a StatefulSet with a PodDisruptionBudget
D.Use PersistentVolumeClaims with ReadWriteMany access mode
AnswerC

A StatefulSet guarantees stable network identities and preserves each pod's PersistentVolumeClaim across rescheduling, satisfying the storage-preservation constraint. Adding a PodDisruptionBudget limits voluntary evictions during node draining, so cluster upgrades cannot disrupt more pods than the budget permits, keeping the stateful application available throughout.

Why this answer

To ensure stateful pods are not disrupted during cluster upgrades and storage is preserved, you should use a StatefulSet with a PodDisruptionBudget (PDB). StatefulSets provide stable network identities and persistent storage for stateful applications, while PDBs ensure that a minimum number of pods remain available during voluntary disruptions like upgrades.

Exam trap

PCA often tests the confusion between stateless and stateful workload management, where candidates might choose Deployments or HPA for stateful applications, overlooking the need for StatefulSets and PDBs to ensure availability during upgrades.

How to eliminate wrong answers

Option A is wrong because Cluster Autoscaler adjusts node pool size based on demand and does not directly protect pods from disruption during upgrades. Option B is wrong because a Deployment with HorizontalPodAutoscaler is designed for stateless applications and does not provide stable storage or identity; HPA scales pods but does not prevent disruptions. Option D is wrong because PersistentVolumeClaims with ReadWriteMany access mode allow multiple pods to access the same volume, but this alone does not ensure pod disruption protection during upgrades; it is a storage configuration, not a disruption control.

69
MCQeasy

A startup is deploying a new containerized web application to Google Cloud. The team wants the simplest way to run containers without managing Kubernetes nodes, needs automatic scaling from zero, and wants to pay only when requests are being handled. Which Google Cloud service should the architect recommend?

A.App Engine flexible environment with a custom runtime for the container.
B.Google Kubernetes Engine with a zonal cluster and cluster autoscaler enabled.
C.Cloud Run, deploying the container image and configuring the service to allow unauthenticated or authenticated invocations.
D.Compute Engine managed instance groups running the container with a startup script that installs Docker.
AnswerC

Cloud Run runs containers on a fully managed platform, scales automatically including to zero when there is no traffic, and bills based on request handling and resource usage. There are no nodes to manage. It directly matches the startup's need for simplicity, scale-from-zero, and pay-per-use without Kubernetes operational overhead.

Why this answer

Cloud Run is a fully managed container runtime that abstracts away nodes, scales instances down to zero when idle, and charges for the resources consumed while handling requests. Deploying a container image and choosing the invocation authentication model is all that is required. This matches the startup's priorities of minimal operational effort, automatic scale-from-zero, and consumption-based billing without adopting Kubernetes.

Exam trap

The trap here is equating App Engine flexible environment with scale-to-zero, when the flexible environment keeps at least one instance and bills for it even when idle.

70
MCQeasy

A developer is writing a Cloud Function that processes files uploaded to a Cloud Storage bucket. Which trigger should they use?

A.HTTP trigger
B.Firestore trigger
C.Cloud Storage trigger
D.Pub/Sub trigger
AnswerC

A Cloud Storage trigger fires the function in response to object events such as finalise or delete in a bucket, which is exactly the upload-processing pattern described. Eventarc delivers these Cloud Storage events, so no polling or manual invocation is needed.

Why this answer

To process files uploaded to a Cloud Storage bucket, the developer should use a Cloud Storage trigger. This trigger type is specifically designed to invoke a Cloud Function in response to events in a Cloud Storage bucket, such as object creation, deletion, or metadata updates.

Exam trap

PCA often tests the appropriate trigger for a given event source, and candidates might choose Pub/Sub because Cloud Storage can publish to Pub/Sub, but the direct Cloud Storage trigger is the intended answer for simplicity and native integration.

How to eliminate wrong answers

Option A is wrong because an HTTP trigger is used for functions invoked via HTTP requests, not for reacting to storage events. Option B is wrong because a Firestore trigger responds to changes in a Firestore database, not Cloud Storage. Option D is wrong because a Pub/Sub trigger is used for messages published to a Pub/Sub topic; while Cloud Storage can send notifications to Pub/Sub, the direct trigger for Cloud Functions is the Cloud Storage trigger, which simplifies the integration.

71
MCQeasy

A startup wants to deploy a containerized web application that must scale automatically based on incoming request concurrency. The team wants to avoid managing Kubernetes nodes or clusters and prefers a fully managed serverless platform with per-request billing. Which Google Cloud service should the architect recommend?

A.Google Kubernetes Engine Autopilot
B.Cloud Run
C.Compute Engine managed instance group with autoscaling
D.App Engine standard environment
AnswerB

Cloud Run runs containers on a fully managed serverless platform, scales automatically based on request concurrency, scales to zero when idle, and bills per request and resource usage. It requires no cluster or node management, which aligns exactly with the startup's stated constraints for this web application.

Why this answer

Cloud Run is the managed serverless container platform that scales on request concurrency, scales to zero, and bills per request, with no cluster or node administration. It accepts standard container images, so the startup can deploy its existing artifact directly while gaining automatic scaling and usage-based pricing that the other options cannot provide.

Exam trap

The trap here is treating GKE Autopilot as serverless and per-request, when it still bills for cluster infrastructure and targets Kubernetes workloads rather than request-driven container scaling.

72
Multi-Selectmedium

A company is deploying a critical application on GKE and wants to ensure high availability during node upgrades and failures. Which TWO configurations should they implement? (Choose 2.)

Select 2 answers
A.Enable Workload Identity for the service account
B.Configure a PodDisruptionBudget for the deployment
C.Create a multi-zonal node pool to spread nodes across multiple zones
D.Use a HorizontalPodAutoscaler with high target utilization
E.Enable Cluster Autoscaler on the node pool
AnswersB, C

A PodDisruptionBudget guarantees a minimum number of replicas remain available during voluntary disruptions such as node upgrades, directly satisfying the high-availability requirement. It prevents GKE's node drain from evicting too many pods simultaneously, though it does not protect against unplanned node failures.

Why this answer

Option B is correct because a PodDisruptionBudget (PDB) with minAvailable or maxUnavailable ensures that voluntary disruptions such as node drains during upgrades keep a minimum number of replicas running, preserving availability. Option C is correct because a multi-zonal node pool spreads nodes across multiple zones in the region, so a zone-level failure or maintenance event does not take down all nodes hosting the application's pods. Option A (Workload Identity) only maps Kubernetes service accounts to Google Cloud IAM identities for secure API access and does not affect availability during upgrades or failures.

Option D (HorizontalPodAutoscaler) scales replicas based on load metrics but does not protect against node drains or zone outages. Option E (Cluster Autoscaler) adds or removes nodes based on pending pods and capacity, which helps with scaling but does not by itself guarantee availability during upgrades or zonal failures.

Exam trap

The trap here is confusing scaling features (HPA, Cluster Autoscaler) with availability features (PDB, multi-zonal node pools) — candidates often pick autoscaling options because they sound like they improve resilience.

73
Multi-Selecthard

A financial services firm is deploying a three-tier application on Google Cloud. The web tier runs on managed instance groups behind an external HTTP(S) load balancer, the application tier runs on GKE, and the database tier runs on Cloud SQL. Security requires that the database tier accept connections only from the application tier and that no component be reachable from the public internet except the web tier. The architect must design the network and firewall configuration. (Choose two.)

Select 2 answers
A.Place the web tier and application tier in the same subnet and use a single firewall rule that allows all internal traffic between them to simplify management.
B.Attach an external IP to each GKE node and rely on Kubernetes NetworkPolicy to block inbound traffic from the internet.
C.Deploy the GKE cluster with private nodes and use a VPC-native cluster so pods receive IP addresses from a secondary range in the VPC.
D.Create a VPC firewall rule that allows ingress to the Cloud SQL instance's private IP on port 5432 only from the GKE pods' secondary IP range used for pods.
E.Configure the Cloud SQL instance with a public IP and add authorized networks for the GKE node external IPs so the application tier can connect.
AnswersC, D

A VPC-native cluster assigns pod IPs from a secondary range, making pods first-class VPC endpoints that firewall rules can target. Private nodes remove external IPs from nodes, so the application tier is not directly reachable from the internet. This supports the firewall rule scoped to the pod range and satisfies the requirement that only the web tier be public.

Why this answer

Private connectivity plus precise firewall scoping achieves the required segmentation. Giving Cloud SQL a private IP and allowing only the GKE pods' secondary range on the database port ensures the application tier alone reaches the database. Making the GKE cluster VPC-native with private nodes gives pods routable VPC addresses and removes node external IPs, so only the web tier behind the load balancer is internet-facing.

Together these satisfy both constraints.

Exam trap

The trap here is treating Kubernetes NetworkPolicy as equivalent to VPC firewall rules, when NetworkPolicy governs pod-to-pod traffic and cannot prevent internet ingress to nodes with external IPs.

74
MCQeasy

What is the purpose of a Pod Disruption Budget (PDB) in GKE?

A.To automatically scale pods based on CPU usage
B.To distribute pods across different zones
C.To ensure a minimum number of pods are always available during voluntary disruptions
D.To prevent any pod from being terminated
AnswerC

A PDB defines the minimum available replicas that must remain during voluntary disruptions such as node drains or upgrades, so GKE blocks eviction requests that would breach that threshold. This directly satisfies the stem's requirement for guaranteed availability during planned, administrator-initiated disruptions.

Why this answer

A Pod Disruption Budget (PDB) in GKE (and Kubernetes generally) limits the number of pods of a replicated application that can be voluntarily disrupted at once, ensuring a minimum number (minAvailable) or maximum unavailable (maxUnavailable) is maintained. It applies to voluntary disruptions like node drains during upgrades, not involuntary ones like node crashes. This keeps the application highly available during maintenance operations.

Exam trap

PCA often tests the distinction between voluntary and involuntary disruptions — candidates who think a PDB prevents all pod termination (including crashes) pick the 'prevent any pod from being terminated' option.

How to eliminate wrong answers

Option A is wrong because automatic scaling based on CPU is the job of the Horizontal Pod Autoscaler (HPA), not a PDB — PDBs do not scale anything. Option B is wrong because distributing pods across zones is achieved via topology spread constraints or anti-affinity rules, not PDBs; a PDB only constrains how many pods can be taken down at once. Option D is wrong because a PDB does not prevent pod termination entirely — setting minAvailable equal to replicas can block voluntary evictions, but it does not stop involuntary disruptions (node failure, OOM kill) or direct pod deletion via kubectl delete.

75
MCQhard

A security team wants to enforce that only container images signed by their internal CI/CD pipeline can run on GKE clusters. They also need to ensure that unsigned images are rejected at admission time. Which combination of services and configurations should they use?

A.GKE PodSecurityPolicy with allowed registries
B.Binary Authorization with Cloud KMS for signing
C.Cloud Build with Container Analysis
D.Artifact Registry vulnerability scanning and IAM roles
AnswerB

Binary Authorization enforces admission-time policy on GKE, verifying image signatures against attestors before pods deploy. Cloud KMS holds the asymmetric signing key the CI/CD pipeline uses to sign images, so only pipeline-signed images pass and unsigned ones are rejected at admission.

Why this answer

Binary Authorization is the GKE feature that enforces admission-time policies requiring container images to be signed by trusted authorities. Cloud KMS provides the signing keys used by the CI/CD pipeline to create attestations. Together they ensure only images signed by the internal pipeline are admitted to the cluster.

Exam trap

PCA often tests the difference between vulnerability scanning (Container Analysis/Artifact Registry) and admission-time signature enforcement (Binary Authorization) — candidates pick scanning options thinking they enforce signing.

How to eliminate wrong answers

Option A (GKE PodSecurityPolicy with allowed registries) is wrong because PSP controls pod security context and can restrict registries, but it does not verify image signatures and is deprecated in favor of Pod Security Admission. Option C (Cloud Build with Container Analysis) is wrong because Cloud Build builds images and Container Analysis scans for vulnerabilities and metadata; neither enforces signature verification at admission. Option D (Artifact Registry vulnerability scanning and IAM roles) is wrong because vulnerability scanning and IAM control access to the registry, not admission of signed images to the cluster.

Page 1 of 2 · 84 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Managing and Provisioning a Solution Infrastructure questions.