Courseiva

CCNA Analysing and Optimising Technical and Business Processes Questions

75 questions · Analysing and Optimising Technical and Business Processes · All types, answers revealed

1
MCQhard

A company uses BigQuery for large-scale analytics. They have a fixed monthly budget and want to ensure predictable costs for query processing, even when many users run concurrent queries. Which BigQuery pricing model should they use?

A.On-demand pricing with flat-rate discounts
B.Autoscaling slot reservations
C.Flat-rate pricing with slot reservations
D.On-demand pricing with committed use discounts
AnswerC

Flat-rate pricing with slot reservations provisions dedicated query-processing capacity for a fixed monthly fee, decoupling cost from query volume. This satisfies the stem's requirement for predictable spend under concurrent workloads, unlike on-demand pricing, which scales with bytes processed.

Why this answer

Flat-rate pricing with slot reservations is correct because it provides a fixed monthly cost for a committed number of slots, making query processing costs predictable regardless of concurrent query volume. This aligns with a fixed budget and many concurrent users, since slots are dedicated capacity rather than per-query billing.

Exam trap

PCA often tests the difference between on-demand and flat-rate pricing — candidates pick autoscaling or committed-use discounts, but only flat-rate reservations give a truly fixed monthly cost.

How to eliminate wrong answers

Option A is wrong because on-demand pricing with flat-rate discounts is not a real BigQuery model; on-demand is per-TB scanned and inherently variable. Option B is wrong because autoscaling slot reservations adjust capacity dynamically, which can increase costs beyond a fixed budget. Option D is wrong because on-demand pricing with committed use discounts still bills per query and does not guarantee predictable monthly costs under concurrent load.

2
MCQhard

A financial services firm runs batch risk calculations nightly using a large Compute Engine VM with a GPU. Jobs complete in 4 hours but are not time-sensitive. To reduce costs without sacrificing reliability, the firm enables preemptible VMs but finds that jobs are interrupted and restarting from scratch causes delays. What is the best approach to improve reliability while maintaining cost savings?

A.Request a committed use discount for the GPU and use a standard VM without preemptible.
B.Use a non-preemptible VM but downgrade the GPU type to reduce cost.
C.Use a spot VM with a high availability SLA, relying on low preemption rates.
D.Use a managed instance group with preemptible VMs and implement checkpointing to save progress periodically.
AnswerD

A managed instance group with preemptible VMs plus periodic checkpointing preserves completed work to persistent storage, so an interrupted job resumes from the last checkpoint rather than restarting. This maintains preemptible cost savings while satisfying the reliability requirement.

Why this answer

Preemptible VMs are up to 80% cheaper but can be terminated at any time with only a 30-second warning, so long-running jobs must be resilient to interruption. Combining a managed instance group (MIG) with preemptible VMs allows automatic recreation of terminated instances, and implementing checkpointing lets the batch job resume from the last saved state rather than restarting from zero. This preserves the cost savings while dramatically improving reliability for the 4-hour nightly job.

Exam trap

PCA often tests the misconception that spot/preemptible VMs come with any availability guarantee — candidates pick 'spot VM with HA SLA' believing Google provides reliability assurances, when in fact no SLA exists for spot VMs.

How to eliminate wrong answers

Option A is wrong because committed use discounts still require paying for standard (non-preemptible) VMs, which eliminates the cost savings the firm is trying to achieve — it solves reliability by abandoning the cost optimization entirely. Option B is wrong because downgrading the GPU reduces performance and may not even be possible for the workload, and it still uses non-preemptible VMs, so no cost savings from preemption are realized. Option C is wrong because spot VMs (the successor to preemptible VMs) do not come with a high availability SLA — Google explicitly does not offer an SLA for spot VMs, and relying on 'low preemption rates' is not a reliability strategy.

3
MCQmedium

Your company uses Cloud SQL for PostgreSQL to support a web application. During peak hours, the database experiences high read load, causing slow query responses. You need to improve read performance while ensuring data consistency. What should you do?

A.Increase the machine type of the Cloud SQL instance to a larger size with more vCPUs and memory.
B.Enable high availability (HA) on the Cloud SQL instance to distribute read traffic across multiple zones.
C.Configure Cloud SQL to use SSD storage instead of HDD to improve read throughput.
D.Create a read replica and configure the application to send read queries to the replica.
AnswerD

Creating a read replica offloads read traffic from the primary instance, improving read performance. Cloud SQL read replicas are asynchronously replicated, which may introduce slight replication lag, but for many read-heavy workloads, this is acceptable. The application can be configured to direct read queries to the replica, reducing load on the primary and improving response times. This approach maintains data consistency for reads that can tolerate eventual consistency.

Why this answer

Creating a read replica allows read queries to be offloaded from the primary instance, directly addressing high read load and improving performance. It scales reads horizontally and is a standard pattern for read-heavy applications. Other options either do not distribute read traffic or provide only temporary vertical scaling.

Exam trap

The trap here is assuming that high availability (HA) can be used for read scaling; HA provides failover, not additional read capacity.

4
MCQhard

A company's BigQuery costs are higher than expected. They run many ad-hoc queries with filters on the 'transaction_date' column and 'customer_id' column. They also have a materialized view that is rarely used. Which combination of actions will MOST effectively reduce query costs?

A.Convert to a clustered table on transaction_date and disable caching
B.Use flat-rate pricing for all queries and cluster on transaction_date
C.Partition on customer_id and use materialized views for all queries
D.Partition on transaction_date, cluster on customer_id, and drop the unused materialized view
AnswerD

Partitioning on transaction_date enables partition pruning for date filters, clustering on customer_id co-locates rows for that filter, and dropping the unused materialized view removes its storage and refresh costs. Together these cut bytes scanned, the dominant BigQuery cost driver.

Why this answer

Partitioning by transaction_date reduces scanned data for date filters. Clustering by customer_id further reduces bytes billed for queries filtering on that column. Dropping unused materialized views avoids storage costs.

5
MCQeasy

A company wants to analyze their Google Cloud spending and receive recommendations for rightsizing resources. Which tool provides this functionality?

A.BigQuery Reservations
B.Active Assist
C.Google Cloud Pricing Calculator
D.Cloud Billing reports
AnswerB

Active Assist applies Google Cloud's recommender engine to analyse usage telemetry and surface rightsizing recommendations, directly satisfying the stem's requirement for spend analysis plus resource optimisation guidance. It covers idle resource detection, committed use discounts and machine-type adjustments natively, unlike generic billing exports or third-party cost tools that lack built-in recommendation logic.

Why this answer

Active Assist includes recommendations for rightsizing Compute Engine VMs, Cloud SQL instances, and more. BigQuery Reservations is for slot management. Cloud Billing reports show costs but not recommendations.

Pricing Calculator estimates costs.

6
MCQmedium

A media company runs a monthly batch pipeline that transcodes video uploads stored in Cloud Storage. The pipeline runs on a Managed Instance Group of Compute Engine VMs and typically completes in 6 hours. The VMs are only needed during this window, but the team wants to minimise the operational effort of stopping and starting the group. Which approach best optimises both cost and operational overhead?

A.Move the transcoding workload to a Cloud Run service with a minimum instance count of zero.
B.Create an instance schedule that starts and stops the managed instance group on a recurring monthly calendar.
C.Convert the VMs to preemptible instances and configure a restart policy.
D.Enable autoscaling on the managed instance group based on CPU utilisation.
AnswerB

Instance schedules let you define recurring start and stop times for managed instance groups, so the VMs are not billed outside the transcode window. This directly reduces compute cost without manual intervention, and the schedule is managed centrally in Compute Engine, meeting the low operational effort requirement for a predictable monthly workload.

Why this answer

The workload has a known, recurring schedule, so the most efficient optimisation is to stop paying for VMs when the pipeline is not running. Instance schedules on a managed instance group start and stop instances automatically, which lowers compute cost and removes manual start/stop toil. Autoscaling, preemptible VMs, and Cloud Run do not eliminate the idle monthly window in the same controlled way.

Exam trap

The trap here is assuming that autoscaling or cheaper VM types will address idle time, when the real cost driver is the predictable period when the group is not needed at all.

7
Multi-Selectmedium

A company wants to implement blameless postmortems as part of their SRE practices. Which THREE principles should they follow?

Select 3 answers
A.Only involve senior management in the review
B.Create actionable recommendations to prevent recurrence
C.Focus on identifying the root cause without blaming individuals
D.Assign responsibility to the team that caused the incident
E.Share findings with all relevant stakeholders
AnswersB, C, E

Blameless postmortems must produce concrete follow-up actions, not just narrative. Actionable recommendations that prevent recurrence close the loop between incident analysis and reliability improvement, satisfying the SRE requirement that postmortems drive measurable change rather than assign fault.

Why this answer

Option B is correct because blameless postmortems must produce concrete, actionable recommendations and follow-up items that reduce the likelihood or impact of recurrence, rather than stopping at description. Option C is correct because the core of blameless postmortems is analyzing systemic and contributing causes of the incident without attributing fault to individuals, which encourages honest reporting. Option E is correct because findings, timelines, and lessons learned should be documented and shared with relevant stakeholders so the whole organization benefits and improves.

Option A is incorrect because limiting participation to senior management excludes the engineers and responders who hold the technical details and undermines learning. Option D is incorrect because assigning responsibility to the team that caused the incident is blame-oriented and contradicts the blameless principle.

Exam trap

The trap here is conflating 'blameless' with 'no accountability' or assuming leadership must be the sole reviewer — candidates pick option A or D because they sound like governance best practices, when they actually undermine the SRE blameless culture.

8
MCQhard

Your company runs a stateful application on Compute Engine instances in a managed instance group. The application requires that each instance maintains a unique identity and persistent storage. You need to ensure that instances can be recreated without data loss and that they retain their identities. What should you do?

A.Configure the MIG to use preemptible instances and attach a local SSD to each instance.
B.Create a separate unmanaged instance group and manually attach persistent disks to each instance.
C.Use a stateless MIG and store application state in a shared Cloud Storage bucket.
D.Use a stateful managed instance group (MIG) with instance names and persistent disks.
AnswerD

A stateful MIG allows you to preserve instance names, persistent disks, and metadata when instances are recreated or restarted. This ensures that each instance maintains its unique identity and persistent storage. It is designed for stateful workloads and supports autohealing and updates without losing state. This directly meets the requirements for identity and data persistence.

Why this answer

A stateful managed instance group (MIG) preserves instance names, persistent disks, and metadata across recreations, ensuring that each instance retains its identity and data. It is the recommended solution for stateful workloads on Compute Engine. Other options either use ephemeral storage, lack automation, or do not preserve identity.

Exam trap

The trap here is assuming that a stateless MIG with shared storage can replace a stateful MIG, but it does not preserve instance identity or provide the same persistence guarantees.

9
MCQmedium

A company runs a web application on Compute Engine behind a HTTP(S) Load Balancer. They want to reduce latency for users worldwide. Which Google Cloud service should they use?

A.Cloud CDN
B.Cloud Armor
C.Cloud NAT
D.Cloud VPN
AnswerA

Cloud CDN caches HTTP(S) load balancer responses at Google's globally distributed edge points of presence, serving repeat requests close to users. This directly reduces round-trip latency for worldwide users, the stated constraint, without changing the existing Compute Engine backend.

Why this answer

Cloud CDN caches content at Google's globally distributed edge points of presence, reducing latency by serving requests from locations closer to users. It integrates directly with HTTP(S) Load Balancer to accelerate web application delivery worldwide.

Exam trap

PCA often tests the distinction between services that improve performance (Cloud CDN) and those that provide security (Cloud Armor) or connectivity (Cloud VPN, Cloud NAT), causing candidates to select a security service for latency reduction.

How to eliminate wrong answers

Option B is wrong because Cloud Armor provides DDoS protection and WAF capabilities, not content caching or latency reduction. Option C is wrong because Cloud NAT enables outbound internet access for private instances, not content delivery. Option D is wrong because Cloud VPN provides secure connectivity between on-premises and GCP, not global content acceleration.

10
MCQeasy

A company wants to set a monthly spending limit for their Compute Engine usage and receive alerts when spending exceeds a threshold. Which tool should they use?

A.Cloud Monitoring
B.Cloud Budget alerts
C.Cloud Logging
D.Cloud Armor
AnswerB

Cloud Budget alerts let you set a monthly spend threshold scoped to a billing account or project and trigger notifications when actual or forecast spend exceeds it. This directly satisfies the stem's requirement for a spending limit with threshold-based alerts, which Compute Engine quotas cannot provide.

Why this answer

Budget alerts in Cloud Billing allow you to set a spending budget and receive notifications when actual spending exceeds thresholds. They can be scoped to projects or services.

11
MCQmedium

A company runs batch analytics workloads on Compute Engine that can tolerate interruptions. They want to reduce compute costs by up to 60-90%. Which compute option is the most cost-effective?

A.On-demand VMs
B.Committed use discounts (1-year)
C.Preemptible VMs
D.Sustained use discounts
AnswerC

Preemptible VMs offer up to 80% discounts versus standard instances, directly meeting the 60–90% cost-reduction constraint. They suit interruption-tolerant batch analytics because Compute Engine terminates them after 24 hours maximum, with 30-second preemption notice. This makes them the cheapest option for workloads that can checkpoint and resume.

Why this answer

Preemptible VMs are Google's spot-equivalent instances that can be terminated at any time when resources are needed elsewhere, and they offer discounts of up to 60-91% compared to on-demand pricing. Since the batch analytics workloads are explicitly described as interruption-tolerant, they are the ideal fit for preemptible VMs, which is why they deliver the greatest cost savings here.

Exam trap

PCA often tests the distinction between discount mechanisms — candidates confuse sustained use discounts (automatic, ~30%) and committed use discounts (contractual, ~57%) with preemptible/spot pricing (up to 91%), and forget that preemptible VMs require fault-tolerant workloads.

How to eliminate wrong answers

Option A is wrong because on-demand VMs are the baseline full-price option with no discount, so they cannot reduce costs by 60-90%. Option B is wrong because committed use discounts only save roughly 20-57% and require a 1- or 3-year commitment, which is less than the 60-90% target and locks in spend. Option D is wrong because sustained use discounts apply automatically to long-running on-demand VMs (up to ~30%) and do not reach the 60-90% savings level.

12
MCQmedium

Your company runs a microservices application on Google Kubernetes Engine (GKE). The development team complains that they lack visibility into which service is causing latency spikes during peak hours. You need to implement a solution that provides distributed tracing and service-level metrics without modifying application code. Which approach should you use?

A.Install the Cloud Logging agent on each node and create log-based metrics for latency.
B.Use Cloud Profiler to continuously profile the application and identify latency bottlenecks.
C.Deploy Anthos Service Mesh and enable its built-in telemetry features, including Cloud Trace and Cloud Monitoring integration.
D.Enable Cloud Trace on the GKE cluster and instrument each service with the OpenTelemetry SDK.
AnswerC

Anthos Service Mesh (ASM) provides automatic distributed tracing and service-level metrics without requiring application code changes. It uses sidecar proxies to capture telemetry and integrates with Cloud Trace and Cloud Monitoring. This meets the requirement for visibility into service latency without modifying code, making it the correct solution.

Why this answer

Anthos Service Mesh provides automatic telemetry collection, including distributed tracing and service-level metrics, without requiring changes to application code. It leverages sidecar proxies to capture traffic and integrates with Cloud Trace and Cloud Monitoring, giving the needed visibility into latency spikes. Other options either require code instrumentation or do not provide the necessary tracing and metrics.

Exam trap

The trap here is assuming that Cloud Trace alone can provide service-level metrics without code changes, when it actually requires instrumentation and does not offer metrics out of the box.

13
MCQmedium

A company is migrating 50 on-premises VMs to Compute Engine. They need to minimise downtime and want an automated lift-and-shift migration that replicates disks incrementally. Which Google Cloud service should be used?

A.Database Migration Service
B.Migrate for Compute Engine
C.Storage Transfer Service
D.Transfer Appliance
AnswerB

Migrate for Compute Engine performs automated lift-and-shift replication of on-premises VM disks to Compute Engine, continuously syncing changes so cutover downtime is minimal. This satisfies the incremental disk replication and low-downtime constraints for the 50 VMs without manual rebuilds.

Why this answer

Migrate for Compute Engine (formerly Velostrata) performs agentless, incremental replication of VM disks to Compute Engine, enabling minimal downtime migrations.

14
Multi-Selectmedium

An e-commerce platform uses Cloud SQL (MySQL) for its transactional database. They are experiencing performance degradation during peak hours due to high read traffic. They need to improve read throughput without modifying the application code. Which TWO actions should they take? (Choose 2)

Select 2 answers
A.Add a Cloud SQL Auth Proxy with connection pooling
B.Increase the number of vCPUs on the primary instance
C.Use Cloud Memorystore for caching session data
D.Enable query caching in Cloud SQL
E.Enable read replicas
AnswersB, E

Increasing vCPUs scales the primary instance vertically, allowing it to handle more read queries concurrently, improving throughput without application modification.

Why this answer

To improve read throughput without modifying application code, the best approaches are increasing the number of vCPUs on the primary instance (B) to handle more concurrent read operations, and enabling read replicas (E) to offload read traffic from the primary instance. Cloud SQL Auth Proxy (A) only provides a secure tunnel and does not offer connection pooling; connection pooling requires separate middleware. Using Memorystore (C) for session data caching reduces database load but does not directly improve read throughput for transactional queries, and query caching (D) is deprecated and not recommended.

15
MCQeasy

A company wants to reduce costs for a batch analytics job that runs nightly for 4 hours on Compute Engine VMs. The job is fault-tolerant and can handle instance restarts. Which Compute Engine VM pricing model is MOST cost-effective?

A.3-year committed use discount (CUD)
B.1-year committed use discount (CUD)
C.Sustained use discounts
D.Preemptible VMs
AnswerD

Preemptible VMs suit this fault-tolerant nightly batch job because they cost up to 80% less than standard instances, and the workload already tolerates restarts. The 24-hour maximum lifetime exceeds the 4-hour runtime, so forced preemption risk is acceptable, satisfying the cost-reduction constraint without disrupting analytics.

Why this answer

Preemptible VMs offer the lowest cost (up to 80% discount) and are ideal for fault-tolerant, short-lived batch workloads that can handle interruptions. Sustained use discounts apply automatically but require running a VM for at least 25% of a month. Committed use discounts require a 1- or 3-year commitment and are not as flexible for a short nightly job.

16
MCQhard

A company runs a microservices application on Google Kubernetes Engine (GKE). They want to ensure that each service can only communicate with the services it explicitly depends on, and they need to enforce this at the network layer without modifying application code. They also want to monitor allowed and denied traffic. What should they do?

A.Use Istio service mesh with mutual TLS and authorization policies.
B.Implement Kubernetes Network Policies and enable GKE network policy logging.
C.Use Anthos Service Mesh with access logging and policy enforcement.
D.Configure firewall rules in the VPC to allow only specific traffic between nodes.
AnswerB

Kubernetes Network Policies allow you to define ingress and egress rules for pods, enforcing communication only with specified services. GKE supports network policy logging, which provides visibility into allowed and denied traffic. This meets the requirement without modifying application code, as policies are applied at the network layer.

Why this answer

Kubernetes Network Policies provide pod-level network segmentation and are enforced by the container network interface (CNI) plugin. GKE supports network policy logging, which records allowed and denied connections. This approach does not require application code changes and operates at the network layer.

Exam trap

The trap here is confusing service mesh capabilities with network policy enforcement; service meshes operate at Layer 7 and often require sidecars, while Network Policies work at Layer 3/4 without code changes.

17
MCQmedium

Your organization runs a critical application on Compute Engine. The monthly bill shows sustained use discounts but the finance team wants to reduce costs further. The workload runs 24/7 with predictable usage for at least the next 12 months. You need to achieve the maximum possible discount without affecting performance or availability. What should you do?

A.Switch all instances to preemptible VMs to get the largest discount.
B.Enable automatic sustained use discounts by ensuring instances run for the full month.
C.Migrate the workload to a managed instance group with autoscaling.
D.Purchase a 1-year commitment for the specific vCPU and memory machine types used.
AnswerD

Committed use discounts (CUDs) provide up to 57% discount for a 1-year commitment on Compute Engine resources. Since the workload is predictable and runs 24/7 for at least 12 months, purchasing a commitment for the exact resources used is the most cost-effective option. It does not affect performance or availability because the resources remain dedicated to your project.

Why this answer

Committed use discounts offer substantial savings for predictable workloads. Because the application runs continuously for at least a year, committing to the specific resources ensures the highest discount without impacting performance or availability. Other options either compromise reliability or do not provide additional savings beyond existing discounts.

Exam trap

The trap here is assuming that preemptible VMs are always the cheapest option, but they are unsuitable for critical always-on workloads because they can be terminated.

18
MCQhard

Your organization runs a microservices application on Google Kubernetes Engine (GKE). Each microservice has its own deployment and horizontal pod autoscaler. You want to implement a robust cost governance process that provides chargeback to each team and prevents budget overruns. You need to attribute costs accurately without modifying application code. What should you do?

A.Deploy a third-party cost monitoring agent as a DaemonSet on each node.
B.Enable GKE cost allocation and use labels on namespaces to map costs to teams.
C.Create a separate GKE cluster for each team and enable billing export to BigQuery.
D.Use Kubernetes resource quotas and limit ranges to enforce budgets.
AnswerB

GKE cost allocation uses a combination of resource requests and actual usage to distribute cluster costs to namespaces, and you can apply labels to namespaces for team attribution. This requires no application changes and provides accurate chargeback data in Cloud Billing. It also supports budget alerts by label, enabling proactive governance.

Why this answer

GKE cost allocation is designed to break down cluster costs by namespace and label, enabling accurate chargeback without code changes. By labeling namespaces with team identifiers, you can generate reports and budget alerts per team. Other options either increase cost, do not provide attribution, or require additional tooling.

Exam trap

The trap here is thinking that resource quotas or separate clusters solve cost attribution, when they actually address consumption limits or isolation, not chargeback.

19
MCQmedium

A team uses Cloud CDN to cache static assets. They update assets by deploying new versions with new URLs. However, sometimes they need to invalidate the cache for a critical fix immediately without changing the URL. What should they do?

A.Increase the TTL to max
B.Change the URL to a new version
C.Use cache invalidation to remove the cached objects
D.Set a short TTL (e.g., 1 minute)
AnswerC

Cache invalidation removes specific cached objects from Cloud CDN edge servers, forcing subsequent requests to fetch fresh content from the origin. This directly satisfies the stem's requirement to purge a critical fix immediately without altering the URL, unlike versioned deployments which rely on new URLs to bypass cached entries.

Why this answer

Cache invalidation is the correct mechanism when content must be refreshed immediately without changing the URL. Cloud CDN supports explicit invalidation requests that purge cached objects from edge locations, forcing subsequent requests to fetch fresh content from the origin. This is the only option that removes already-cached content on demand rather than waiting for TTL expiry or relying on URL changes.

Exam trap

The trap here is confusing TTL tuning with immediate cache control — candidates pick 'short TTL' thinking it approximates invalidation, but only explicit invalidation purges content on demand.

How to eliminate wrong answers

Option A is wrong because increasing the TTL extends how long stale content remains cached, directly worsening the problem. Option B is wrong because changing the URL is the versioning strategy already in use and does not address the scenario where the URL must stay the same. Option D is wrong because a short TTL only reduces the maximum staleness window; it does not guarantee immediate removal of the currently cached object.

20
MCQhard

Your company uses a CI/CD pipeline that builds container images and stores them in Artifact Registry. The images are deployed to Google Kubernetes Engine (GKE). You need to ensure that only images that have been scanned for vulnerabilities and approved by a security team can be deployed to the production GKE cluster. You want to enforce this policy automatically without modifying the CI/CD pipeline. What should you do?

A.Configure a Kubernetes admission webhook that calls the security team's API to validate each image before deployment.
B.Restrict Artifact Registry permissions so that only the security team can push images to the production repository.
C.Enable Binary Authorization on the GKE cluster and configure a policy that requires attestations from the security team's attestor.
D.Use Container Analysis to scan images and set a vulnerability threshold that blocks deployment if any critical vulnerability is found.
AnswerC

Binary Authorization is a deploy-time security control that ensures only trusted container images are deployed on GKE. By configuring a policy that requires an attestation from the security team's attestor, only images that have been scanned and approved can be admitted. This enforcement happens at the cluster level without changing the CI/CD pipeline.

Why this answer

Binary Authorization enforces deploy-time policies on GKE by requiring cryptographic attestations that prove an image was scanned and approved. The security team can sign attestations after scanning, and the GKE cluster will only admit images with valid attestations. This meets the requirement without altering the CI/CD pipeline and provides automated enforcement.

Exam trap

The trap here is confusing vulnerability scanning with deployment enforcement; scanning alone does not block unapproved images from being deployed.

21
MCQmedium

A company operates a critical application on Google Cloud and wants to define a Service Level Objective (SLO) for its latency. They need to measure the proportion of requests that complete within 200 ms over a 28-day rolling window. They also want to alert when the error budget is being consumed too quickly. What should they use?

A.Cloud Trace with analysis reports and custom alerts.
B.Cloud Monitoring SLOs with error budget burn rate alerts.
C.Cloud Logging with log-based metrics and custom dashboards.
D.Cloud Monitoring with uptime checks and alerting policies based on latency thresholds.
AnswerB

Cloud Monitoring allows you to define SLOs based on latency distributions, set a performance goal (e.g., 99% of requests under 200 ms), and create alerting policies based on error budget burn rates. This directly meets the requirement to measure the proportion and alert on rapid consumption.

Why this answer

Cloud Monitoring SLOs allow you to define service level objectives based on metrics like latency, set a goal, and monitor error budgets. Burn rate alerts notify when the error budget is consumed faster than desired, enabling proactive response.

Exam trap

The trap here is thinking that uptime checks or log-based metrics can serve as SLOs, but they lack the integrated error budget and burn rate alerting that Cloud Monitoring SLOs provide.

22
MCQmedium

A team runs periodic BigQuery queries on a large dataset. They notice high costs due to full table scans. They want to reduce costs and improve query performance. Which two actions should they take? (Choose two options that best fit the scenario.)

A.Use SELECT * only when necessary
B.Partition the table by a date/timestamp column
C.Use materialized views to pre-aggregate data
D.Cluster the table on frequently filtered columns
AnswerB, D

Partitioning splits the table by date or timestamp, so a query with a date filter prunes irrelevant partitions and scans only the matching ones. This reduces bytes processed, lowering cost and improving performance versus full table scans.

Why this answer

The correct actions are B (partition the table by a date/timestamp column) and D (cluster the table on frequently filtered columns). Partitioning restricts scans to only the relevant date partitions, and clustering physically sorts data by the filtered columns so BigQuery prunes blocks it doesn't need, both directly cutting bytes scanned and cost. Option A (avoiding SELECT *) is a general best practice but doesn't address full table scans on a large dataset, and option C (materialized views) helps only for recurring aggregate patterns, not the broad scan-cost problem described.

23
MCQmedium

Your organization runs a customer-facing web application on a managed instance group of Compute Engine VMs behind an HTTP(S) load balancer. The monthly bill shows that the VMs are running at only 15% average CPU utilization, yet the team insists they need the current number of VMs to handle peak traffic. You want to reduce compute costs without risking performance during traffic spikes. What should you do?

A.Move the application to a single large Compute Engine instance to reduce the number of VMs.
B.Purchase committed use discounts for all current VM instances for a one-year term.
C.Enable autoscaling on the managed instance group based on CPU utilization, and set the minimum number of instances to a lower value.
D.Change the machine type of all instances to a smaller size that matches the average CPU utilization.
AnswerC

Autoscaling adjusts the number of VM instances in the group based on load, so you pay only for what you need. Setting a lower minimum reduces cost during low-traffic periods, while the autoscaler adds instances when CPU or other metrics rise, preserving performance during peaks. This directly addresses the low average utilization without manual intervention.

Why this answer

The managed instance group is overprovisioned for average load but sized for peak. Autoscaling with a lower minimum lets the group shrink during low demand and expand during spikes, aligning cost with actual usage. The other options either reduce peak capacity, lock in excess capacity, or remove redundancy, none of which solve the cost problem while preserving performance.

Exam trap

The trap here is assuming that committed use discounts or smaller machine types automatically optimize cost, when the real issue is the fixed number of instances that never scales down.

24
MCQhard

A global SaaS company wants to reduce the latency of its API for users in Asia, Europe, and North America. The API is stateless and runs on GKE in a single region. The company wants a solution that improves latency for all users without changing the application code. Which approach should the architect recommend?

A.Use Traffic Director with a global load balancing policy to distribute traffic across regional backends.
B.Deploy the API to GKE clusters in multiple regions and use a global external Application Load Balancer with a single anycast IP address.
C.Enable Cloud CDN on the existing regional load balancer and cache API responses at the edge.
D.Increase the machine type of the GKE nodes in the single region to handle more concurrent requests.
AnswerB

A global external Application Load Balancer provides a single anycast IP and routes each user to the closest healthy backend based on latency and health. By deploying the stateless API in multiple regions behind this load balancer, users in each geography are served from a nearby region, reducing latency without code changes. This is the standard global serving pattern in Google Cloud.

Why this answer

To reduce latency for a global user base without code changes, the application must run close to users and be fronted by a global entry point. Deploying the stateless API in multiple regions and placing a global external Application Load Balancer in front provides a single anycast IP that directs users to the nearest healthy backend. CDN, Traffic Director, and vertical scaling do not achieve this global proximity for dynamic API traffic.

Exam trap

The trap here is assuming that caching at the edge or scaling up a single region will fix global latency, when the real fix is to serve from multiple regions behind a global anycast load balancer.

25
MCQmedium

A company is performing a TCO analysis to compare on-premises costs with Google Cloud. Which cost should they include as a hidden operational cost on-premises?

A.Compute Engine instance costs
B.Power, cooling, and physical security
C.Egress charges
D.Software license costs
AnswerB

Power, cooling, and physical security are ongoing operational costs rarely captured in on-premises hardware quotes, so including them gives a truer TCO comparison against Google Cloud's consumption pricing, where the provider absorbs these facilities costs.

Why this answer

On-premises hidden costs include facility costs (power, cooling, space), hardware maintenance, personnel for patching and upgrades. Egress costs are cloud costs, not on-prem. Compute Engine instance cost is a direct cloud cost.

Software licenses depend on licensing model.

26
MCQmedium

You are the architect for a company that runs a three-tier web application on Compute Engine. The CTO wants to reduce the monthly cloud bill without impacting performance or availability. You review the billing export in BigQuery and notice that the VMs are sized for peak load, but CPU utilization rarely exceeds 20% on weekdays and 5% on weekends. The application is stateless and uses an external Cloud SQL database. Which cost optimization strategy should you implement first?

A.Create a managed instance group with autoscaling and right-size the instance template based on actual utilization.
B.Purchase a 3-year commitment for the current VM sizes.
C.Move the application to Cloud Run.
D.Enable committed use discounts for the VMs.
AnswerA

This directly addresses the overprovisioning by scaling the number of instances to match demand and using a smaller machine type that fits actual CPU usage. It maintains availability because the managed instance group can span zones and replace unhealthy instances, and it does not require application changes since the app is stateless.

Why this answer

The application is stateless and overprovisioned, so the most effective first step is to right-size instances and use autoscaling to match capacity to demand. This reduces cost while maintaining performance and availability. Committed use discounts and long-term commitments only make sense after you have optimized the instance shape and quantity.

Exam trap

The trap here is assuming that committed use discounts or long-term commitments are the primary cost optimization, when in fact they should be applied only after right-sizing.

27
MCQmedium

Your organization is adopting a multi-cloud strategy and wants to ensure consistent security policies across Google Cloud and another cloud provider. You need to centrally manage and enforce security policies, such as preventing public access to storage buckets, across both environments. What should you do?

A.Use Google Cloud's Organization Policy Service to define constraints and apply them to all projects.
B.Configure VPC Service Controls in Google Cloud and replicate the same configuration in the other cloud.
C.Use Terraform to define infrastructure as code and apply the same policies to both clouds.
D.Implement a third-party cloud security posture management (CSPM) tool that supports multi-cloud policy enforcement.
AnswerD

A multi-cloud CSPM tool can provide a single pane of glass to define, monitor, and enforce security policies across Google Cloud and other providers. It can detect and remediate misconfigurations like public storage buckets consistently. This meets the requirement for centralized management across multiple clouds.

Why this answer

For multi-cloud security policy management, a third-party CSPM tool is designed to work across different cloud providers, offering centralized policy definition, monitoring, and enforcement. Google Cloud native tools like Organization Policy Service and VPC Service Controls are limited to Google Cloud, and Terraform is for provisioning, not continuous enforcement.

Exam trap

The trap here is assuming that Google Cloud's native security tools can manage policies in other clouds, but they are limited to Google Cloud resources.

28
MCQeasy

An organization wants to reduce costs for a batch data processing job that runs nightly and is resilient to interruptions. The job can be restarted from checkpoints. Which Compute Engine VM pricing model should be used?

A.On-demand VMs
B.Sustained use discounts
C.Committed use discounts (1-year)
D.Preemptible VMs
AnswerD

Preemptible VMs cost substantially less than standard instances but can be terminated at any time with a 30-second warning. Because the nightly batch job is resilient to interruptions and restarts from checkpoints, this pricing model satisfies the stem's cost-reduction goal without risking data loss.

Why this answer

Preemptible VMs and Spot VMs are significantly cheaper than standard VMs and can be terminated by Google Cloud at any time. Since the job is batch and can resume from checkpoints, interruptions are acceptable. Sustained use discounts apply automatically to standard VMs, but preemptible/spot VMs offer the lowest cost for fault-tolerant workloads.

29
MCQmedium

A company is migrating an on-premises PostgreSQL database (5 TB) to Cloud SQL. They need minimal downtime and automated schema conversion if needed. Which GCP service should they use?

A.Database Migration Service (DMS)
B.Datastream
C.Migrate for Compute Engine (formerly Velostrata)
D.Transfer Appliance
AnswerA

Database Migration Service performs continuous replication from the on-premises PostgreSQL source to Cloud SQL, keeping downtime to a minimum during cutover. Its built-in schema conversion handles incompatible objects automatically, satisfying the automated conversion requirement for the 5 TB migration.

Why this answer

Database Migration Service (DMS) is the correct choice because it is a fully managed GCP service designed to migrate databases to Cloud SQL with minimal downtime, supporting continuous replication and automated schema conversion via the Database Migration Service conversion workspace. It handles homogeneous migrations like PostgreSQL to Cloud SQL for PostgreSQL and can perform schema conversion when needed. Datastream is a change data capture service, not a full migration tool, and the other options are for different migration scenarios.

Exam trap

The trap here is confusing Datastream (CDC only) with Database Migration Service (full migration with schema conversion), so candidates must remember that DMS is the end-to-end migration service while Datastream is for replication.

How to eliminate wrong answers

Option B is wrong because Datastream is a serverless change data capture (CDC) and replication service for streaming data into BigQuery, Cloud SQL, or Cloud Storage, but it does not perform schema conversion or manage the full database migration lifecycle. Option C is wrong because Migrate for Compute Engine is for migrating VMs from on-premises or other clouds to Compute Engine, not for database migrations to Cloud SQL. Option D is wrong because Transfer Appliance is a physical appliance for transferring large datasets to Cloud Storage, not a database migration service.

30
MCQeasy

An engineer wants to migrate an on-premises MySQL database (5.6) to Cloud SQL for MySQL with minimal downtime. Which service should they use?

A.Migrate for Compute Engine (formerly Velostrata)
B.Storage Transfer Service
C.BigQuery Data Transfer Service
D.Database Migration Service
AnswerD

Database Migration Service performs continuous, log-based replication from the on-premises MySQL 5.6 source to Cloud SQL, keeping the target synchronised until cutover. This satisfies the minimal-downtime constraint, since only a brief final promotion is needed rather than a full dump-and-restore outage.

Why this answer

Database Migration Service (DMS) is purpose-built for migrating relational databases like MySQL 5.6 to Cloud SQL with minimal downtime. It performs an initial full load followed by continuous change data capture (CDC) replication from the source, allowing cutover with seconds of downtime. DMS natively supports MySQL, PostgreSQL, and SQL Server sources into Cloud SQL and AlloyDB.

Exam trap

PCA often tests whether candidates confuse data-movement services — the trap is picking Storage Transfer Service or BigQuery Data Transfer Service for a database migration when only Database Migration Service handles schema + CDC replication into Cloud SQL.

How to eliminate wrong answers

Option A is wrong because Migrate for Compute Engine (Velostrata) migrates VM workloads to Compute Engine, not managed database schemas into Cloud SQL. Option B is wrong because Storage Transfer Service moves object/blob data between storage buckets, not relational database contents. Option C is wrong because BigQuery Data Transfer Service loads data into BigQuery for analytics, not into Cloud SQL for MySQL.

31
MCQhard

A financial services company is designing a new application on Google Cloud. The application must comply with PCI DSS and internal policies that require strict separation of duties and least privilege. The security team wants to ensure that developers cannot modify production resources, but they need to deploy code frequently. Which approach should the cloud architect recommend to meet these requirements while supporting continuous deployment?

A.Use Google Cloud Deploy to manage deployments. Grant developers the roles/clouddeploy.developer role in the production project, and configure approval gates before production deployment. Developers can approve their own deployments.
B.Use a single Google Cloud project with IAM conditions that restrict developers to only modify resources with a specific label (e.g., env=dev). Grant developers roles/editor, and use a Cloud Build service account with roles/owner to deploy to production.
C.Create separate Google Cloud projects for development and production. Grant developers the roles/editor role in the development project and roles/viewer in the production project. Use Cloud Build with a service account that has the necessary permissions to deploy to production.
D.Implement a CI/CD pipeline using Cloud Build and Artifact Registry. Grant developers the roles/cloudbuild.builds.editor role to trigger builds. Store production deployment credentials in Secret Manager and allow developers to access them.
AnswerC

Separate projects enforce isolation. Developers have editor in dev (can deploy and test) but only viewer in prod (cannot modify). Cloud Build uses a dedicated service account with least privilege to deploy to production, ensuring developers cannot directly modify prod. This meets separation of duties and least privilege while enabling CI/CD through automation.

Why this answer

Separate projects provide strong isolation. Developers with editor in dev can work freely, but viewer in prod prevents direct modifications. Cloud Build with a least-privilege service account automates deployments, so developers cannot directly change production.

This enforces separation of duties and least privilege while enabling frequent deployments via CI/CD.

Exam trap

The trap here is using a single project with IAM conditions or granting developers production roles with approval gates, which may seem sufficient but fails to enforce strict separation of duties and least privilege.

32
MCQmedium

A company runs batch analytics workloads each night on Compute Engine VMs. The workloads are fault-tolerant and can be interrupted. The finance team wants to reduce compute costs. Which Compute Engine pricing model should they use?

A.Committed use discounts (1-year or 3-year)
B.Preemptible VMs
C.Sustained use discounts
D.Sole-tenant nodes
AnswerB

Preemptible VMs suit fault-tolerant batch jobs because they cost up to 80% less than standard instances, though Compute Engine may terminate them within 24 hours. Since the nightly analytics workloads can be interrupted without harm, this discount directly satisfies the finance team's cost-reduction constraint.

Why this answer

Preemptible VMs are short-lived, heavily discounted Compute Engine instances (up to ~80% off) that can be terminated by Google at any time with a 30-second notice. They are ideal for fault-tolerant, interruptible batch workloads like nightly analytics jobs, which is exactly the scenario described.

Exam trap

PCA often tests the difference between sustained use discounts (automatic, for long-running VMs) and committed use discounts (contractual, for steady-state) versus preemptible/Spot VMs (for interruptible workloads) — candidates frequently pick CUDs when the workload is clearly interruptible.

How to eliminate wrong answers

Option A is wrong because committed use discounts require a 1- or 3-year commitment and are best for steady-state, always-on workloads — not interruptible nightly batch jobs. Option C is wrong because sustained use discounts apply automatically to long-running VMs that run for a significant portion of the month; nightly batch jobs do not run long enough to earn meaningful SUDs. Option D is wrong because sole-tenant nodes are for physical isolation and compliance/licensing requirements, and they are more expensive, not a cost-reduction mechanism.

33
MCQmedium

A media company stores video files in Cloud Storage for streaming. Infrequently accessed videos older than 90 days are currently in Standard storage. To reduce costs, they want to automatically move these files to a lower-cost storage class and delete them after 3 years. Which configuration should they use?

A.Configure a Pub/Sub notification on object changes and process via Dataflow.
B.Use gsutil rewrite command with -s option manually for each file.
C.Use a lifecycle rule with condition 'age > 90 days' to set storage class to Nearline, and another rule with 'age > 1095 days' to delete.
D.Create a Cloud Function that moves objects monthly using a cron job.
AnswerC

Object Lifecycle Management transitions objects between storage classes and deletes them based on age conditions, applied automatically without manual intervention. Setting Nearline at 90 days and deletion at 1095 days matches both the cost-reduction and three-year retention requirements for the infrequently accessed videos.

Why this answer

Cloud Storage lifecycle rules are the native, automated way to transition objects between storage classes and delete them based on age. A rule with condition 'age > 90 days' setting storage class to Nearline (or Coldline) reduces cost for infrequent access, and a second rule with 'age > 1095 days' (3 years) deletes the objects. This is declarative, server-side, and requires no custom code.

Exam trap

PCA often tests whether candidates recognize that lifecycle rules are the built-in, automated solution for storage class transitions and deletions, rather than custom code or manual commands.

How to eliminate wrong answers

Option A is wrong because Pub/Sub + Dataflow is an event-driven processing pipeline, not a lifecycle management solution; it adds complexity and cost without providing automatic storage class transitions or deletions. Option B is wrong because gsutil rewrite with -s manually changes storage class per file, which is not automated and does not handle deletion. Option D is wrong because a Cloud Function with a cron job is a custom, maintenance-heavy approach that duplicates functionality already provided by lifecycle rules.

34
MCQeasy

An organization is planning to move 500 TB of archival data from on-premises to Cloud Storage. The data is not frequently accessed, and the network bandwidth is limited to 100 Mbps. What is the most efficient migration approach?

A.Use Transfer Appliance
B.Use gsutil rsync with parallel composite uploads
C.Use Migrate for Compute Engine
D.Use Storage Transfer Service over the internet
AnswerA

Transfer Appliance bypasses the 100 Mbps network constraint entirely by shipping encrypted physical hardware, making it far faster than any online transfer for 500 TB. Its suitability for infrequently accessed archival data matches the stem's access pattern, whereas Storage Transfer Service or gsutil would take months over the limited link.

Why this answer

Transfer Appliance is a physical device for shipping large amounts of data when bandwidth is low. At 100 Mbps, 500 TB would take over 500 days; Transfer Appliance bypasses network constraints.

35
MCQeasy

A company has a Cloud SQL for PostgreSQL instance that experiences high connection overhead. Developers frequently open and close connections. Which solution reduces connection overhead without code changes?

A.Increase max_connections in Cloud SQL
B.Configure PgBouncer as a sidecar
C.Switch to Private IP
D.Use Cloud SQL Auth Proxy
AnswerB

PgBouncer pools and reuses backend PostgreSQL connections, so frequent open/close cycles from developers hit the pooler rather than Cloud SQL directly. This satisfies the no-code-changes constraint because applications connect to PgBouncer's endpoint transparently, while transaction pooling cuts the per-connection authentication and process-fork overhead that caused the bottleneck.

Why this answer

PgBouncer is a lightweight connection pooler that sits between the application and Cloud SQL for PostgreSQL, maintaining a pool of persistent backend connections and multiplexing many short-lived client connections onto them. This eliminates the TCP/TLS handshake and PostgreSQL authentication overhead per request without any application code changes, since the app simply connects to PgBouncer's endpoint instead of directly to the database.

Exam trap

PCA often tests the confusion between authentication/security proxies (Cloud SQL Auth Proxy) and connection poolers (PgBouncer) — candidates pick Auth Proxy thinking it reduces overhead, but it only secures the connection, it does not pool it.

How to eliminate wrong answers

Option A is wrong because increasing max_connections only raises the ceiling on concurrent connections — it does not reduce the per-connection setup cost, and it can actually worsen memory pressure on the instance. Option C is wrong because switching to Private IP changes the network path (no public internet) but does not address connection churn or handshake overhead. Option D is wrong because Cloud SQL Auth Proxy provides secure IAM-based authentication and encryption, but it still establishes a new connection per client session — it is not a connection pooler.

36
MCQmedium

A company wants to use BigQuery with a predictable monthly cost, regardless of query volume. They have a steady state of around 500 concurrent slots. Which pricing model should they choose?

A.Sustained use discounts
B.Committed use discounts for BigQuery
C.Slot reservations (flat-rate)
D.On-demand pricing
AnswerC

Slot reservations, billed as flat-rate capacity, provision a fixed number of slots for a committed period, so cost stays constant regardless of query volume. This satisfies the predictable monthly cost requirement, matching the steady 500-slot workload without on-demand per-query charges.

Why this answer

BigQuery slot reservations (flat-rate) provide a fixed monthly cost based on reserved slots, suitable for predictable workloads. On-demand pricing charges per query and can vary.

37
MCQeasy

Which Google Cloud service automatically computes the optimal size or tier for underutilized Compute Engine instances and generates recommendations to reduce cost?

A.Cloud Monitoring
B.Cloud Profiler
C.Cost Management
D.Recommender (Active Assist)
AnswerD

Recommender, part of Active Assist, analyses Compute Engine utilisation metrics and generates rightsizing recommendations for underutilised instances. It automatically computes the optimal machine type or tier, directly satisfying the requirement to reduce cost through sizing guidance.

Why this answer

Recommender (part of Active Assist) analyzes Compute Engine utilization and automatically generates rightsizing recommendations to reduce cost by resizing underutilized VMs. It is the GCP service specifically built to surface optimal machine type and size suggestions.

Exam trap

PCA often tests the difference between monitoring, cost reporting, and recommendation engines — candidates pick Cost Management because it 'reduces cost,' but only Recommender (Active Assist) computes optimal sizes and tiers.

How to eliminate wrong answers

Option A is wrong because Cloud Monitoring collects metrics and creates dashboards/alerts but does not generate rightsizing recommendations. Option B is wrong because Cloud Profiler analyzes application CPU and memory usage at the code level for performance tuning, not VM rightsizing for cost. Option C is wrong because Cost Management (Cloud Billing reports and budgets) shows spend and forecasts but does not compute optimal instance sizes or tiers.

38
MCQhard

Your company uses Cloud Monitoring to track the performance of a microservices application. The SRE team wants to define an SLO for the latency of a critical API. They need to measure the proportion of requests that complete within 200 ms over a rolling 30-day window. Which approach should they use to implement this SLO?

A.Configure a log-based metric that counts requests with latency under 200 ms, then create an alert if the count drops.
B.Use Cloud Monitoring's SLO monitoring feature to define a latency SLO with a distribution cut based on a histogram metric.
C.Set up an uptime check that measures the API response time and alerts if it exceeds 200 ms.
D.Create a custom metric that logs each request latency, then use a dashboard to manually calculate the percentage within 200 ms.
AnswerB

Cloud Monitoring's SLO monitoring allows you to define service level objectives based on metrics. For latency, you can use a distribution cut on a histogram metric to specify the threshold (200 ms) and calculate the ratio of good requests to total requests over a rolling window. This provides automated tracking, error budget calculation, and alerting.

Why this answer

Cloud Monitoring's SLO monitoring is designed for defining and tracking SLOs. Using a distribution cut on a histogram metric allows precise measurement of the proportion of requests within the latency threshold over a rolling period. It also provides error budget and alerting, which are essential for SRE practices.

Exam trap

The trap here is confusing uptime checks with latency SLOs; uptime checks measure availability from external probes, not the latency distribution of actual user requests.

39
MCQhard

An engineer is designing a Bigtable schema for time-series data consisting of sensor readings. Each sensor emits a reading every second. The access pattern is to retrieve all readings for a specific sensor within a time range. Which row key design will provide the best performance?

A.Use row key: [sensor_id]#[reverse_timestamp]
B.Use a single row per sensor with column qualifiers as timestamps
C.Use timestamp as the row key and sensor ID as column qualifier
D.Use a random prefix to distribute writes evenly
AnswerA

Reversing the timestamp places the newest reading first within each sensor's contiguous row range, so a time-range scan reads sequential rows without hotspots. Prefixing sensor_id keeps each sensor's data co-located, matching the access pattern exactly.

Why this answer

Bigtable stores rows sorted by key. A row key structured as [sensor_id]#[reverse_timestamp] ensures that all data for a sensor is contiguous, and sorting by reverse timestamp allows recent data to be retrieved first. A single row key per sensor with column qualifiers would cause hotspots and limit scalability.

40
MCQmedium

A company runs a critical application on Compute Engine. The operations team wants to improve the mean time to recovery (MTTR) for incidents. They currently use manual runbooks stored in a wiki. You need to recommend a solution that automates incident response and integrates with existing monitoring. What should you do?

A.Deploy a third-party AIOps platform on Compute Engine.
B.Implement Cloud Monitoring alerting policies that trigger Cloud Functions to execute remediation steps.
C.Migrate the application to GKE and use liveness probes for automatic restarts.
D.Use Cloud Scheduler to run a script every 5 minutes that checks for issues and fixes them.
AnswerB

Cloud Monitoring alerting policies can send notifications to Pub/Sub, which can trigger Cloud Functions. This allows automated remediation such as restarting a VM or scaling a deployment. It integrates with existing monitoring and reduces MTTR by removing manual steps. This is a native, serverless approach that requires no additional infrastructure.

Why this answer

Cloud Monitoring alerting policies can trigger Pub/Sub, which invokes Cloud Functions to perform automated remediation. This is a native, serverless, event-driven approach that integrates with existing monitoring and reduces MTTR. Other options either require architectural changes, are not event-driven, or add unnecessary complexity.

Exam trap

The trap here is assuming that scheduled scripts or platform migrations are needed, when the goal is event-driven automation integrated with monitoring.

41
MCQmedium

A company runs a web application on Compute Engine behind a Global HTTPS Load Balancer. Users report slow page loads, especially for static assets. The development team wants to cache content closer to users without modifying code. Which GCP service should they enable?

A.Cloud CDN
B.Cloud NAT
C.Cloud Armor
D.Cloud DNS
AnswerA

Cloud CDN caches static assets at Google edge points of presence, so repeated requests terminate near users rather than traversing to the Compute Engine backends. Enabling it on the existing Global HTTPS Load Balancer requires no application code changes, directly addressing the slow static asset loads.

Why this answer

Cloud CDN is the correct service because it caches HTTP(S) load balancer content at Google's globally distributed edge points of presence, reducing latency for static assets without any application code changes. It integrates directly with the Global HTTPS Load Balancer, so enabling it requires only a checkbox or gcloud command on the backend service. This satisfies the requirement to cache content closer to users while keeping the existing architecture intact.

Exam trap

The trap is assuming that any network-related GCP service can improve latency — candidates may pick Cloud DNS or Cloud NAT thinking they accelerate traffic, but only Cloud CDN caches content at the edge.

How to eliminate wrong answers

Option B is wrong because Cloud NAT provides outbound internet access for private instances, not content caching or edge delivery. Option C is wrong because Cloud Armor is a WAF/DDoS protection service, not a caching layer. Option D is wrong because Cloud DNS is a managed DNS service that resolves names; it does not cache HTTP content or reduce asset latency.

42
MCQmedium

A company stores infrequently accessed data in Cloud Storage Standard class. To reduce costs, they want to automatically move objects older than 90 days to a lower-cost storage class. Which approach should they use?

A.Configure a lifecycle policy to transition to Archive class
B.Use gsutil rewrite to manually change storage class
C.Set up Pub/Sub notifications for object changes
D.Enable object versioning
AnswerA

A lifecycle policy applies transition rules based on object age, automatically moving objects from Standard to Archive after 90 days without manual intervention. This directly satisfies the requirement to reduce storage costs for infrequently accessed data through automated class transitions.

Why this answer

Object Lifecycle Management in Cloud Storage is designed exactly for this use case: automatically transitioning objects to lower-cost storage classes based on age or other conditions. Configuring a lifecycle rule to transition objects older than 90 days to the Archive class (A) reduces cost while preserving durability and access when needed. Lifecycle policies run asynchronously and are the standard, supported mechanism for automated class transitions.

Exam trap

PCA often tests whether candidates confuse manual class-change commands (gsutil rewrite) with automated lifecycle policies, or mistakenly believe Pub/Sub notifications or versioning can drive cost-optimization transitions.

How to eliminate wrong answers

Option B is wrong because gsutil rewrite is a manual, one-off operation that changes an object's storage class but does not automate the process based on object age — it would require scripting and repeated execution, defeating the purpose. Option C is wrong because Pub/Sub notifications merely alert on object changes; they do not perform storage class transitions and would require custom code to act on the events. Option D is wrong because object versioning retains multiple versions of objects for recovery purposes; it increases storage cost rather than reducing it and does nothing to change storage class.

43
Multi-Selectmedium

A team is designing a disaster recovery plan for a critical application. They need to ensure RPO of less than 1 hour and RTO of less than 4 hours. The application runs on Compute Engine with persistent disks and uses Cloud SQL for MySQL. Which THREE actions should they take? (Choose 3.)

Select 3 answers
A.Deploy a Transfer Appliance to copy data to another region weekly
B.Use a regional managed instance group and rely on Google's automatic failover
C.Store application configuration and scripts in a multi-regional Cloud Storage bucket
D.Configure Cloud SQL cross-region replication to a replica in another region
E.Take regular snapshots of Compute Engine persistent disks and replicate them to another region using Cloud Storage
AnswersC, D, E

Multi-regional Cloud Storage provides durable, geo-redundant storage for configuration and deployment scripts, so rebuilds after a regional failure can retrieve them without depending on the failed region. This supports the four-hour RTO by accelerating Compute Engine re-provisioning.

Why this answer

Option C is correct because storing application configuration and scripts in a multi-regional Cloud Storage bucket ensures they remain available even if one region fails, supporting recovery within the 4-hour RTO without manual rebuild delays. Option D is correct because Cloud SQL cross-region replication continuously replicates the MySQL database to a replica in another region, enabling a low RPO (well under 1 hour) and a fast promotion/failover path to meet the 4-hour RTO. Option E is correct because regular persistent disk snapshots replicated to another region via Cloud Storage provide a restorable copy of Compute Engine disk data in the DR region, which is necessary to rebuild instances within the RTO and keep data loss under the RPO.

Option A is not appropriate because Transfer Appliance is an offline, batch data-transfer appliance with weekly cadence, which cannot meet an RPO under 1 hour or an RTO under 4 hours. Option B is not sufficient because a regional managed instance group only provides automatic failover across zones within a single region, not cross-region disaster recovery, so a region-wide outage would still exceed the required RTO/RPO.

44
Multi-Selectmedium

A company is planning to migrate a large on-premises Oracle database (10 TB) to Cloud SQL for PostgreSQL. They need to minimise downtime and ensure data integrity. Which TWO services or tools should they use? (Choose TWO.)

Select 1 answer
A.Migrate for Compute Engine
B.Cloud Dataflow
C.Cloud Scheduler
D.Database Migration Service (DMS)
E.Cloud SQL Auth Proxy
AnswersD

Database Migration Service (DMS) supports online migration from Oracle to Cloud SQL for PostgreSQL with minimal downtime.

Why this answer

Database Migration Service (DMS) supports online migration from Oracle to Cloud SQL for PostgreSQL with minimal downtime by using continuous replication. Cloud SQL Auth Proxy is a tool for secure client connections to Cloud SQL instances; it is not required for the migration process itself. Cloud Dataflow is for data processing, Cloud Scheduler for job scheduling, and Migrate for Compute Engine for VM migration.

Exam trap

Candidates may think Cloud SQL Auth Proxy is needed for migration because it is commonly used with Cloud SQL, but it is only for client-side secure connectivity, not for the migration process itself.

45
MCQeasy

A company runs batch machine learning training jobs that can be interrupted. They want to reduce compute costs. Which Compute Engine VM pricing model is MOST cost-effective?

A.Preemptible VMs
B.Standard VMs
C.Sustained use discounts
D.Committed use discounts
AnswerA

Preemptible VMs cost up to 80% less than standard instances, satisfying the cost-reduction constraint. Because the batch training jobs tolerate interruption, the 24-hour maximum lifespan and abrupt termination risk are acceptable. Spot VMs offer similar discounts but with different eviction behaviour; preemptible suits this workload's fault tolerance.

Why this answer

Preemptible VMs are the most cost-effective for interruptible batch ML training jobs because they offer up to 80% discount compared to standard VMs. They can be terminated at any time by Compute Engine, but since the jobs can be interrupted, this is acceptable. Other pricing models like sustained use discounts apply automatically to standard VMs but offer smaller discounts, and committed use discounts require a 1- or 3-year commitment, which may not be suitable for temporary or variable workloads.

Exam trap

PCA often tests the distinction between preemptible VMs and committed use discounts, and candidates may incorrectly choose committed use discounts for cost savings without considering the interruptible nature of the workload.

How to eliminate wrong answers

Option B is wrong because standard VMs are priced at full rate and do not provide the deep discounts needed for cost reduction. Option C is wrong because sustained use discounts are automatic discounts for running VMs for a significant portion of the month, but they are less aggressive than preemptible discounts and do not require interruptibility. Option D is wrong because committed use discounts require a long-term commitment (1 or 3 years) and are best for steady-state workloads, not interruptible batch jobs.

46
MCQmedium

An application uses Cloud Bigtable and experiences high latency for reads. The row key is a timestamp prefix followed by a random ID. Queries often scan a range of timestamps for a specific ID. What design change would MOST improve read performance?

A.Change the row key to start with the random ID followed by timestamp
B.Add more Bigtable nodes
C.Use a separate column family for the ID
D.Enable Bigtable replication
AnswerA

Cloud Bigtable sorts rows lexicographically by row key, so a timestamp prefix scatters a single ID's rows across the entire table, forcing wide scans. Leading with the random ID groups all of one ID's rows contiguously, letting queries read a narrow, adjacent range.

Why this answer

For Bigtable, row key design is critical. Scanning a range of timestamps for a specific ID is inefficient if the key starts with timestamp (scans across all IDs). Prepending the ID ensures all data for that ID is contiguous, making range scans efficient.

Adding nodes increases throughput but doesn't fix the key design issue. Using a column family is about grouping columns, not performance.

47
MCQeasy

A company wants to ensure that their development teams follow best practices for cost optimization. They want to implement a process that reviews architecture decisions before deployment and provides recommendations. Which Google Cloud tool should they use to get automated cost recommendations for their existing resources?

A.Cloud Billing reports
B.Active Assist
C.Cloud Asset Inventory
D.Cloud Monitoring
AnswerB

Active Assist uses machine learning to analyze resource usage and provide recommendations, such as identifying idle VMs, unattached disks, or overprovisioned instances. It can also recommend committed use discounts. This directly meets the requirement for automated cost recommendations and helps teams follow best practices.

Why this answer

Active Assist is a suite of tools that provides automated recommendations for cost, security, and performance. It analyzes resource usage and suggests optimizations such as right-sizing or deleting idle resources. This directly supports the goal of implementing a process for cost optimization recommendations.

Exam trap

The trap here is confusing cost visibility tools like Cloud Billing reports with recommendation engines like Active Assist.

48
MCQhard

An application uses Cloud SQL (PostgreSQL) and experiences high connection overhead, often exhausting the max connections limit. The team wants to maintain a pool of persistent connections without modifying application code. Which solution should they implement?

A.Use Cloud Memorystore as a connection cache
B.Increase the max connections flag in Cloud SQL
C.Configure Cloud SQL Auth Proxy with max connections
D.Deploy PgBouncer on a Compute Engine instance
AnswerD

PgBouncer sits between the application and Cloud SQL, multiplexing many client connections onto a small pool of persistent backend connections. This satisfies the no-code-change constraint and relieves connection overhead, since the application still connects normally to the proxy.

Why this answer

PgBouncer is a lightweight connection pooler that sits between the application and Cloud SQL, maintaining a pool of persistent connections and multiplexing many client connections onto a smaller number of database connections. This reduces connection overhead and prevents exhausting the max_connections limit without requiring application code changes. Cloud SQL Auth Proxy is for secure authentication, not pooling, and increasing max_connections only postpones the problem.

Exam trap

PCA often tests the misconception that Cloud SQL Auth Proxy provides connection pooling; it does not—it only handles authentication and encryption.

How to eliminate wrong answers

Option A is wrong because Cloud Memorystore is a Redis/Memcached service, not a PostgreSQL connection pooler. Option B is wrong because increasing max_connections does not reduce connection overhead and can lead to resource exhaustion. Option C is wrong because Cloud SQL Auth Proxy provides secure access but does not pool connections; it still creates a new connection per client.

49
MCQeasy

A company wants to automate the deployment of their infrastructure on Google Cloud using a declarative approach. They need to manage resources such as VPCs, subnets, and Compute Engine instances in a repeatable and version-controlled manner. They also want to preview changes before applying them. Which tool should they use?

A.Ansible with the Google Cloud collection
B.Google Cloud Deployment Manager
C.Google Cloud Console and gcloud CLI scripts
D.Terraform with the Google Cloud provider
AnswerD

Terraform is a declarative infrastructure as code tool that supports version control and provides a 'terraform plan' command to preview changes before applying. The Google Cloud provider allows management of all GCP resources. This meets the requirements for repeatability, version control, and change preview.

Why this answer

Terraform is the industry-standard declarative infrastructure as code tool that supports version control and provides a plan phase to preview changes. The Google Cloud provider enables management of all relevant resources, ensuring repeatability and safety.

Exam trap

The trap here is assuming that Deployment Manager is the only Google-native option and that it provides preview capabilities; actually, Terraform is more widely used and supports preview via plan.

50
Multi-Selectmedium

A retail company runs its order-processing system on Google Kubernetes Engine (GKE). The operations team wants to improve the reliability and cost efficiency of the cluster. They observe that several workloads have no resource requests or limits set, and some nodes are consistently underutilised while others are overcommitted. Which two actions should the architect recommend to address these issues? (Choose two.)

Select 2 answers
A.Disable the horizontal pod autoscaler to avoid fluctuating replica counts.
B.Migrate all workloads to a single, larger node pool with no autoscaling.
C.Configure resource requests and limits for all pods based on observed usage.
D.Enable the cluster autoscaler on all node pools with appropriate minimum and maximum sizes.
E.Set the pod disruption budget for all deployments to zero.
AnswersC, D

Setting requests and limits gives the scheduler accurate information to place pods and prevents noisy-neighbour problems. It also enables the cluster autoscaler to make better scaling decisions and allows vertical pod autoscaling to right-size workloads. Without them, the scheduler cannot bin-pack efficiently, leading to the underutilisation and overcommitment described.

Why this answer

The core problems are inaccurate resource signalling and static node capacity. Defining requests and limits lets the scheduler place pods correctly and enables autoscaling features to work effectively. Enabling the cluster autoscaler then adjusts node pool size to match actual demand, adding capacity when pods are pending and removing idle nodes.

Together they improve reliability during peaks and reduce cost during low usage.

Exam trap

The trap here is thinking that simply adding more nodes or disabling autoscalers will fix utilisation, when the underlying issue is that pods lack the resource requests the scheduler needs.

51
MCQmedium

An enterprise is planning to migrate 200 on-premises VMs to Google Cloud. The CIO wants to ensure that the migration aligns with the business goal of reducing IT operational overhead by 30% while maintaining application performance. The team has already completed a technical assessment of the VMs. Which additional step should the cloud architect take to ensure the migration plan is aligned with the stated business goal?

A.Conduct a business impact analysis to map each application to business processes and identify criticality and dependencies.
B.Perform a detailed network latency test between on-premises and Google Cloud to determine the best interconnect option.
C.Develop a detailed total cost of ownership (TCO) model comparing on-premises and Google Cloud costs for all 200 VMs.
D.Create a proof of concept for migrating a single non-critical VM to validate the migration process.
AnswerA

A business impact analysis (BIA) links applications to business processes, revealing criticality, dependencies, and potential operational overhead. This helps prioritize migrations and identify opportunities to reduce overhead, such as retiring redundant applications or consolidating. It ensures the migration plan supports the business goal, not just technical feasibility. Without BIA, the plan may miss cost-saving and risk-reduction opportunities.

Why this answer

The business goal is to reduce IT operational overhead by 30% while maintaining performance. A business impact analysis (BIA) identifies which applications are critical, their dependencies, and how they support business processes. This allows the architect to prioritize migrations, retire redundant systems, and consolidate workloads, directly contributing to overhead reduction.

Technical assessments alone do not ensure business alignment.

Exam trap

The trap here is assuming that technical validation or cost modeling alone satisfies business alignment, when the goal specifically requires understanding application criticality and dependencies to reduce operational overhead.

52
MCQhard

A financial services firm runs a three-tier application on Google Cloud. The security team requires that all outbound traffic from the application tier to the internet be inspected by a centralised next-generation firewall appliance, and that the application tier have no public IP addresses. The network team wants to minimise changes to the existing VPC. Which design should the architect recommend?

A.Deploy the firewall appliance as a managed instance group in the application VPC and use a custom route with the appliance as the next hop for the default route.
B.Enable Private Google Access on the application subnet and use Private Service Connect for all external destinations.
C.Configure a Cloud NAT gateway on the application subnet and route all egress through it.
D.Create a separate VPC for the firewall appliance and use VPC peering to connect it to the application VPC.
AnswerA

Placing the appliance in the same VPC and overriding the default route to use the appliance as the next hop forces all egress through it for inspection. Instances keep private IPs and no public IPs, and the existing VPC is reused with only route and firewall rule changes, minimising network redesign. This is the standard hub-and-spoke or inline inspection pattern in a single VPC.

Why this answer

Centralised inspection of internet-bound traffic requires the traffic to traverse the firewall appliance. By deploying the appliance in the same VPC and setting a custom default route whose next hop is the appliance, all egress from the application tier is forced through it. Instances remain private, and the existing VPC is preserved.

Cloud NAT, VPC peering, and Private Service Connect do not insert an inspection middlebox into the egress path.

Exam trap

The trap here is confusing network address translation or private connectivity features with traffic inspection, when only an explicit route through the appliance can force egress through a firewall.

53
MCQmedium

A company runs a global application that requires strong consistency across regions for financial transactions. Which database should they choose?

A.Cloud SQL
B.Cloud Bigtable
C.Firestore
D.Cloud Spanner
AnswerD

Cloud Spanner provides externally consistent reads and linearisable transactions globally, using TrueTime to synchronise commit timestamps across regions. This satisfies the stem's requirement for strong consistency across regions for financial transactions, unlike eventually consistent multi-region databases.

Why this answer

Cloud Spanner is a globally distributed, strongly consistent database service that provides ACID transactions across regions. It is designed for applications that require strong consistency and high availability across multiple regions, making it ideal for financial transactions.

Exam trap

The trap is confusing strong consistency with high availability; Cloud SQL and Firestore can be highly available but do not provide cross-region strong consistency.

How to eliminate wrong answers

Option A is wrong because Cloud SQL is a regional database service that does not provide global strong consistency; it is typically used for single-region applications. Option B is wrong because Cloud Bigtable is a NoSQL database that provides eventual consistency and is optimized for high-throughput analytics, not strong consistency for transactions. Option C is wrong because Firestore is a NoSQL document database that provides strong consistency within a region but not across regions; it is more for mobile and web apps.

54
MCQeasy

A startup is migrating its on-premises MySQL database (5 TB) to Cloud SQL. The database is mission-critical and downtime must be minimized. Which migration service should they use to reduce downtime?

A.Transfer Appliance
B.gcloud sql import command
C.Storage Transfer Service
D.Database Migration Service (DMS)
AnswerD

Database Migration Service uses continuous replication to keep the target Cloud SQL instance synchronised with the source MySQL database, then performs a brief cutover. This minimises downtime for the mission-critical 5 TB database, satisfying the stem's constraint.

Why this answer

Database Migration Service (DMS) supports continuous replication from on-premises MySQL to Cloud SQL, minimizing downtime. Other options like Transfer Appliance or Storage Transfer Service are for file transfers, not live databases.

55
MCQmedium

A company is migrating 500 TB of on-premises file server data to Cloud Storage. The on-premises network has a 1 Gbps link to Google Cloud, but the migration must complete within 30 days. What is the MOST cost-effective and reliable method?

A.Use Storage Transfer Service over a dedicated interconnect
B.Deploy a VPN and use gsutil rsync
C.Use Database Migration Service
D.Use Transfer Appliance
AnswerD

Transfer Appliance ships data physically, bypassing the 1 Gbps link that would take far longer than 30 days for 500 TB. It is cost-effective for bulk offline transfer and reliable, satisfying both the deadline and cost constraints.

Why this answer

Transfer Appliance is the most cost-effective and reliable method for migrating 500 TB over a 1 Gbps link within 30 days. At 1 Gbps, transferring 500 TB would take approximately 46 days (assuming ideal conditions), exceeding the 30-day deadline. Transfer Appliance physically ships the data, bypassing network bandwidth limitations and reducing transfer time to days.

Exam trap

PCA often tests the misconception that a dedicated interconnect or VPN can overcome bandwidth limitations for large transfers within tight deadlines. Candidates may overlook the physical transfer option when network speeds are insufficient.

How to eliminate wrong answers

Option A is wrong because Storage Transfer Service over a dedicated interconnect still relies on network bandwidth; even with a dedicated 1 Gbps link, the transfer would take over 46 days, missing the deadline. Option B is wrong because a VPN adds encryption overhead and typically reduces throughput, making the transfer even slower. Option C is wrong because Database Migration Service is for databases, not file server data.

56
MCQeasy

A team wants to define an SLO for a service that requires 99.9% availability over a 30-day window. They need to measure the ratio of successful requests to total requests. Which SLI should they use?

A.Request success rate
B.SRE
C.Request latency
D.Error budget
AnswerA

Request success rate measures the proportion of successful requests against total requests, expressed as a ratio. This directly satisfies the stem's 99.9% availability SLO over a 30-day window, since availability is defined by served versus total valid requests.

Why this answer

An SLI is a measure of service performance. For availability, the standard SLI is the proportion of successful requests (e.g., HTTP 2xx) to total requests. Latency SLI measures response times.

Error budget is derived from SLO. SRE is the practice.

57
MCQmedium

A team wants to provide a consistent, low-latency experience for global users accessing static content (images, CSS, JS) hosted on Cloud Storage. They also need to be able to invalidate cached content quickly when updates occur. Which service should they use?

A.Cloud NAT
B.Cloud Load Balancing with backend bucket
C.Cloud Storage transfer service
D.Cloud CDN
AnswerD

Cloud CDN caches static content at Google's global edge locations, reducing latency for worldwide users while serving from Cloud Storage origins. Its cache invalidation feature lets the team purge stale objects quickly after updates, satisfying both the latency and invalidation constraints.

Why this answer

Cloud CDN caches content at edge locations for low latency. Cache invalidation allows purging updated content, which is essential for static assets.

58
Multi-Selecteasy

A company runs a batch processing job that uses preemptible VMs. The job occasionally fails due to VM preemption. They want to improve reliability without significantly increasing cost. Which TWO actions should they take? (Choose TWO.)

Select 2 answers
A.Use a managed instance group with autoscaling and preemptible VMs
B.Use sole-tenant nodes to reduce risk of preemption
C.Switch to regular (non-preemptible) VMs
D.Implement a retry mechanism in the job to re-run failed tasks
E.Increase the number of preemptible VMs
AnswersA, D

A managed instance group automatically recreates preempted VMs, directly addressing the reliability constraint while retaining preemptible pricing. Autoscaling maintains capacity by adding instances when demand rises, so the batch job recovers without manual intervention. This satisfies the requirement to improve resilience without significantly increasing cost, since preemptible rates still apply.

Why this answer

Option A is correct because a managed instance group (MIG) with autoscaling and preemptible VMs automatically maintains the desired number of instances, replacing preempted VMs with new ones so the batch job can continue running with minimal disruption and without paying for non-preemptible capacity. Option D is correct because preemptible VMs can be reclaimed at any time, so building a retry mechanism into the job lets failed tasks be re-run on surviving or replacement instances, directly improving reliability at essentially no extra cost. Option B is not appropriate because sole-tenant nodes isolate hardware for compliance/licensing reasons and do not reduce the risk of preemption.

Option C would improve reliability but significantly increases cost, which the scenario explicitly wants to avoid. Option E merely adds more preemptible VMs; it does not address task recovery and still leaves the job vulnerable to preemption.

59
Multi-Selecthard

A company is moving a legacy application to Compute Engine. The application has inconsistent resource usage and the team wants to optimise costs without performance degradation. They are evaluating committed use discounts (CUDs) and other discount types. Which THREE statements are correct about CUDs? (Choose 3)

Select 3 answers
A.CUDs require a minimum of 10 instances to qualify
B.Spend-based CUDs are applied automatically to all eligible projects in the billing account
C.CUDs cannot be combined with sustained use discounts
D.CUDs provide a discount in exchange for committing to a minimum spend or resource usage for 1 or 3 years
E.Resource-based CUDs apply to a specific machine series and region
AnswersB, D, E

Spend-based CUDs are billing-account-level commitments, so Google Cloud automatically applies the resulting discount credits across all eligible projects under that billing account without per-project configuration. This satisfies the stem's cost-optimisation goal for inconsistent usage, since no resource-level matching is required.

Why this answer

Option B is correct because spend-based (flexible) committed use discounts are automatically applied across all eligible projects within the billing account, requiring no per-project management. Option D is correct because CUDs fundamentally exchange a 1-year or 3-year commitment to a minimum spend or resource usage for a discounted rate on Compute Engine resources. Option E is correct because resource-based CUDs are scoped to a specific machine family/series and region, so the commitment only discounts matching vCPUs and memory in that region.

Option A is wrong because CUDs have no 10-instance minimum; commitments are made in terms of spend or resource quantities. Option C is wrong because CUDs can be combined with sustained use discounts, with SUDs applying to usage not already covered by the CUD.

60
MCQeasy

A company is migrating its on-premises data warehouse to BigQuery. They want to minimize the cost of storing large amounts of historical data that is rarely queried. The data must remain available for queries but can tolerate slightly longer query times. What should they do?

A.Export the data to Cloud Storage Nearline and delete it from BigQuery.
B.Partition the table by date and set a partition expiration to delete old data.
C.Use BigQuery's flexible pricing with flat-rate slots to reduce query costs.
D.Store the data in BigQuery long-term storage by ensuring the table is not modified for 90 consecutive days.
AnswerD

BigQuery automatically moves data to long-term storage after 90 days of no modifications, reducing storage costs by about 50%. The data remains queryable, and query performance is generally not affected. This approach requires no manual intervention and is ideal for rarely queried historical data.

Why this answer

BigQuery long-term storage automatically applies lower pricing to data that hasn't been modified for 90 days. This is the simplest and most cost-effective way to store rarely queried historical data while keeping it available for queries. Other options either make data unavailable, delete it, or address query costs instead of storage.

Exam trap

The trap here is assuming that exporting data to a cheaper storage class is the best way to reduce costs, but that would make the data unavailable for direct BigQuery queries.

61
Multi-Selectmedium

A company wants to improve the performance of their Cloud SQL for PostgreSQL instance. They notice many idle connections and slow queries. Which THREE actions could help? (Choose 3)

Select 3 answers
A.Add appropriate indexes
B.Add read replicas
C.Use PgBouncer for connection pooling
D.Enable private IP
E.Increase disk size
AnswersA, B, C

Indexes let PostgreSQL satisfy query predicates without sequential scans, cutting execution time for the slow queries observed. This addresses the query-performance half of the scenario directly, reducing per-query resource consumption on the Cloud SQL instance.

Why this answer

Option A (Add appropriate indexes) is correct because missing indexes force sequential scans on large tables, and creating B-tree or other suitable indexes lets PostgreSQL satisfy WHERE, JOIN, and ORDER BY clauses with index scans, directly reducing slow query latency. Option B (Add read replicas) is correct because Cloud SQL read replicas offload read-only SELECT traffic from the primary instance, increasing read throughput and reducing contention on the primary for read-heavy workloads. Option C (Use PgBouncer for connection pooling) is correct because PgBouncer multiplexes many client connections over a small pool of backend PostgreSQL connections, which directly addresses the many idle connections consuming memory and backend process slots.

Option D (Enable private IP) is not correct because private IP only changes network routing and security exposure; it does not improve query performance or reduce idle connections. Option E (Increase disk size) is not correct because disk size affects storage capacity and, on some tiers, IOPS, but it does not address idle connections or slow queries caused by poor indexing or connection churn.

62
MCQeasy

A healthcare company stores patient documents in Cloud Storage. Compliance requires that documents be retained for seven years and that no user, including administrators, can delete or overwrite them during that period. The company wants the simplest configuration that enforces this. What should the architect implement?

A.Enable Object Versioning and configure a lifecycle rule to delete noncurrent versions after seven years.
B.Apply a bucket-level IAM policy that denies the storage.objects.delete permission to all users.
C.Set a bucket retention policy with a retention period of seven years and lock the policy.
D.Use a Cloud Storage transfer job to copy objects to a second bucket in a different region every day.
AnswerC

A locked retention policy prevents objects from being deleted or overwritten until the retention period expires, and it cannot be removed or shortened once locked. This enforces immutability for seven years for all users, including administrators, with minimal configuration. It directly satisfies the compliance requirement without custom code or external tooling.

Why this answer

The requirement is for immutable retention that even administrators cannot bypass. A bucket retention policy sets a minimum retention period during which objects cannot be deleted or replaced, and locking the policy makes it permanent. Object Versioning, IAM deny rules, and cross-bucket copies do not provide the same enforceable, time-bound guarantee against both deletion and overwrite.

Exam trap

The trap here is assuming that versioning or IAM restrictions provide immutability, when only a locked retention policy prevents both deletion and overwrite by any user.

63
Multi-Selectmedium

Your company is designing a new application on Google Cloud. The security team requires that all data at rest be encrypted with customer-managed encryption keys (CMEK) and that access to these keys be audited. You need to implement a solution that meets these requirements. (Choose two.)

Select 2 answers
A.Use Cloud KMS to create a key ring and crypto key, and grant the Cloud KMS CryptoKey Encrypter/Decrypter role to the service account used by the application.
B.Enable VPC Service Controls to restrict access to Cloud KMS resources.
C.Use customer-supplied encryption keys (CSEK) for all Google Cloud services that support them.
D.Enable Cloud Audit Logs for Cloud KMS and configure log sinks to export logs to a central logging project.
E.Configure default encryption at rest using Google-managed encryption keys for all services.
AnswersA, D

Cloud KMS allows you to create and manage customer-managed encryption keys (CMEK). By granting the appropriate IAM role to the service account, the application can use the key to encrypt and decrypt data. This meets the requirement for CMEK. Additionally, Cloud KMS integrates with Cloud Audit Logs to track key usage, satisfying the auditing requirement.

Why this answer

Using Cloud KMS to create and manage CMEK, and granting the application's service account the CryptoKey Encrypter/Decrypter role, ensures data is encrypted with customer-managed keys. Enabling Cloud Audit Logs for Cloud KMS and exporting them to a central project provides the required auditing of key access. Together, these meet the security requirements.

Exam trap

The trap here is confusing customer-supplied encryption keys (CSEK) with customer-managed encryption keys (CMEK); CSEK does not provide Cloud KMS auditing.

64
MCQmedium

A company wants to automatically move data from Cloud Storage Standard to Nearline after 30 days and to Archive after 90 days. Which approach should they use?

A.Write a custom script using Cloud Functions triggered by Pub/Sub to move objects
B.Use Object Versioning to automatically change storage class
C.Set up a Cloud Storage lifecycle policy with rules to transition to Nearline after 30 days and to Archive after 90 days
D.Enable Requester Pays on the bucket to reduce storage costs
AnswerC

A lifecycle policy applies rule-based transitions based on object age, moving data from Standard to Nearline at 30 days and to Archive at 90 days automatically. This satisfies the stem's requirement for scheduled storage-class transitions without manual intervention.

Why this answer

Cloud Storage lifecycle policies are the native, automated way to transition objects between storage classes based on age. A single lifecycle rule can specify a transition to Nearline after 30 days and another transition to Archive after 90 days, applied to the bucket or specific prefixes. This eliminates the need for custom code and ensures cost optimization automatically.

Exam trap

PCA often tests whether candidates know that lifecycle policies are the native, no-code solution for storage class transitions — many pick custom scripts or confuse versioning with class changes.

How to eliminate wrong answers

Option A is wrong because writing a custom Cloud Function with Pub/Sub is over-engineered and unnecessary when lifecycle policies natively support time-based transitions. Option B is wrong because Object Versioning is for retaining object versions, not for changing storage classes. Option D is wrong because Requester Pays shifts egress costs to the requester and does not transition storage classes.

65
MCQhard

Your company runs a microservices application on GKE. The development team wants to adopt a progressive delivery strategy to reduce the risk of new releases. They need to route a small percentage of production traffic to a new version, monitor key metrics, and automatically roll back if errors increase. Which approach should you recommend?

A.Implement a canary deployment using Istio with traffic splitting and Prometheus-based analysis.
B.Configure a rolling update on the Kubernetes Deployment with a maxSurge and maxUnavailable setting.
C.Use a blue/green deployment by creating a full second environment and switching all traffic at once after testing.
D.Deploy the new version to a separate namespace and use a Kubernetes Ingress with weight-based routing.
AnswerA

Istio provides fine-grained traffic splitting to route a percentage of traffic to the canary. Combined with Prometheus metrics and analysis, you can automatically promote or roll back based on error rates. This directly supports progressive delivery with automated rollback, meeting the requirement for risk reduction and monitoring.

Why this answer

A canary deployment with Istio allows you to route a small percentage of traffic to the new version and monitor metrics. Prometheus can feed analysis into an automated process that rolls back if error rates exceed a threshold. This provides the progressive delivery and automated risk mitigation the team needs, unlike blue/green, rolling updates, or basic Ingress.

Exam trap

The trap here is thinking that a rolling update or blue/green deployment provides canary-style traffic splitting and automated rollback, which they do not.

66
Multi-Selectmedium

Your organization is adopting Google Cloud and wants to establish a cost governance framework. You need to implement mechanisms that provide visibility into spending and allow proactive control over costs. (Choose two.)

Select 2 answers
A.Set up budget alerts in Cloud Billing to notify stakeholders when spending exceeds a defined threshold.
B.Assign the Billing Account Administrator role to all project owners to ensure they can view and manage costs.
C.Use the Pricing Calculator to estimate costs before deploying new resources.
D.Enable committed use discounts for all Compute Engine instances to reduce the effective cost per hour.
E.Export billing data to BigQuery and create custom dashboards in Looker Studio to analyze cost trends by project and label.
AnswersA, E

Budget alerts provide proactive notifications when costs approach or exceed predefined limits. They do not stop spending, but they enable timely action. This is a core cost governance mechanism that increases awareness and allows teams to react before costs escalate. It complements detailed analysis by providing early warnings.

Why this answer

Cost governance requires both visibility and proactive control. Exporting billing data to BigQuery with Looker Studio dashboards provides deep visibility into spending patterns, while budget alerts notify stakeholders when thresholds are breached. Together, they enable analysis and timely intervention.

The other options are either optimization tactics, overly broad permissions, or planning tools that lack ongoing monitoring.

Exam trap

The trap here is equating cost optimization techniques like committed use discounts with governance, which actually requires visibility and alerting.

67
MCQeasy

A company wants to migrate a MySQL database running on-premises to Cloud SQL with minimal downtime. Which GCP service should they use?

A.Migrate for Compute Engine
B.Storage Transfer Service
C.Transfer Appliance
D.Database Migration Service
AnswerD

Database Migration Service performs continuous, near-zero-downtime replication from on-premises MySQL into Cloud SQL, then promotes the replica at cutover. This directly satisfies the stem's minimal-downtime constraint, unlike dump-and-restore approaches that require taking the source offline.

Why this answer

Database Migration Service (DMS) is purpose-built for migrating MySQL, PostgreSQL, and SQL Server databases to Cloud SQL with minimal downtime. It handles continuous replication and cutover, which is exactly what's needed for a live database migration.

Exam trap

The trap is confusing data transfer services (Storage Transfer Service, Transfer Appliance) with database migration services; the exam expects you to know that DMS is the only GCP service designed for live database migration with minimal downtime.

How to eliminate wrong answers

Option A is wrong because Migrate for Compute Engine is for migrating VMs, not databases. Option B is wrong because Storage Transfer Service moves object data between storage buckets, not relational databases. Option C is wrong because Transfer Appliance is a physical appliance for bulk data transfer to GCP, not for database migration with minimal downtime.

68
MCQmedium

Your company has a complex legacy application that runs on a single large VM. The application is stateful and has a monolithic architecture. You are tasked with migrating it to Google Cloud with minimal changes, but you also want to improve its reliability and scalability over time. Which migration strategy should you initially recommend?

A.Refactor the application into microservices on GKE to improve scalability and reliability.
B.Replatform the application by moving it to a managed database service and modifying the code to use cloud-native APIs.
C.Repurchase by replacing the application with a SaaS solution that provides similar functionality.
D.Rehost the application by moving the VM to Compute Engine using Migrate for Compute Engine.
AnswerD

Rehosting (lift and shift) moves the application with minimal changes, often using Migrate for Compute Engine to replicate the VM to Google Cloud. This meets the immediate goal of minimal modification. It also provides a foundation for later optimization, such as refactoring or replatforming, once the application is running in the cloud.

Why this answer

Rehosting with Migrate for Compute Engine allows you to move the VM to Compute Engine with minimal changes, satisfying the immediate requirement. Once in the cloud, you can take advantage of reliability features like snapshots and managed instance groups, and later consider refactoring or replatforming. The other strategies involve significant changes or replacements that contradict the minimal-change constraint.

Exam trap

The trap here is opting for a more modern architecture like microservices when the requirement explicitly asks for minimal changes initially.

69
Multi-Selecteasy

A development team uses BigQuery for analytical queries. They want to reduce query costs for a large table that is frequently filtered by a date column and a customer_id column. Which TWO table design strategies will reduce the amount of data scanned? (Choose 2)

Select 2 answers
A.Partition the table by date.
B.Create an index on customer_id.
C.Use wildcard tables with date suffixes.
D.Normalize the table into multiple tables.
E.Cluster the table on customer_id.
AnswersA, E

Partitioning by date divides the table into segments, so queries filtering on the date column prune irrelevant partitions and scan only matching ones. This directly reduces bytes scanned, satisfying the cost-reduction goal for date-filtered analytical queries.

Why this answer

Option A is correct because partitioning the table by the date column means BigQuery only scans the partitions that match the query's date filter, dramatically reducing bytes processed for date-filtered queries. Option E is correct because clustering on customer_id physically sorts and co-locates data by that column, so filters on customer_id prune blocks within partitions and further cut data scanned. Together, partitioning by date and clustering by customer_id directly address the two frequent filter columns in this scenario.

Option B is incorrect because BigQuery does not support traditional secondary indexes on columns like customer_id; clustering is the equivalent mechanism. Option C is incorrect because wildcard tables with date suffixes are a query-time convenience for sharding, not a table design that reduces scanned data by itself. Option D is incorrect because normalizing into multiple tables does not inherently reduce bytes scanned and may even require more joins and data reads.

70
MCQmedium

An application running on Compute Engine frequently makes connection requests to a Cloud SQL for PostgreSQL instance. The connections are short-lived and many are created per second. What should be implemented to reduce latency and connection overhead?

A.Deploy PgBouncer on the application server or as a sidecar
B.Increase the number of vCPUs on the Cloud SQL instance
C.Enable connection scaling in Cloud SQL
D.Use Cloud SQL Auth Proxy with private IP
AnswerA

PgBouncer pools and reuses backend connections, so many short-lived client connections multiplex onto a small set of persistent Cloud SQL connections. This removes per-request connection setup overhead, directly addressing the stem's high connection rate and latency constraint.

Why this answer

Connection pooling reuses database connections instead of creating new ones for each request. PgBouncer is a lightweight connection pooler for PostgreSQL. Cloud SQL Auth Proxy is for secure connections but does not pool.

71
MCQmedium

An e-commerce application uses Firestore for product catalog. They need to run complex analytical queries on the catalog data, such as aggregations and joins, without impacting production performance. What is the best approach?

A.Create a second Firestore database for analytics
B.Use Cloud SQL to query Firestore directly
C.Use Firestore `!=` operator to filter data
D.Export Firestore data to BigQuery for analytics
AnswerD

Exporting Firestore data to BigQuery satisfies the isolation constraint: BigQuery runs aggregations and joins on a columnar engine, separate from Firestore's document-oriented production workload. Firestore natively lacks joins and efficient aggregation, so offloading analytics prevents read contention and preserves catalog latency.

Why this answer

The best approach is to export Firestore data to BigQuery for analytics. BigQuery is a columnar, serverless analytics warehouse designed for aggregations and joins at scale, and it can query exported Firestore data without touching the production Firestore instance. This isolates analytical workloads from production traffic and provides the SQL capabilities Firestore lacks.

Exam trap

PCA often tests the misconception that Firestore can be queried like a relational database, tempting candidates to pick a second Firestore database or Cloud SQL federation instead of the correct export-to-BigQuery pattern.

How to eliminate wrong answers

Option A is wrong because creating a second Firestore database still leaves you with a document store that cannot perform efficient aggregations or joins, and it duplicates operational overhead without solving the analytical query problem. Option B is wrong because Cloud SQL cannot query Firestore directly — they are separate database engines with no native query federation. Option C is wrong because the Firestore `!=` operator is a simple inequality filter, not an analytical capability; it cannot perform aggregations or joins and would still run against production.

72
MCQmedium

An organization deploys a web application on Compute Engine behind a global HTTPS load balancer. They want to reduce latency for users worldwide and minimize load on backend instances. Which GCP service should they use?

A.Cloud Armor
B.Cloud NAT
C.Cloud CDN
D.VPC Network Peering
AnswerC

Cloud CDN caches content at Google's globally distributed edge points of presence, serving repeated requests close to users. This directly reduces latency for worldwide users and offloads origin traffic, satisfying the requirement to minimise load on the Compute Engine backend instances behind the global HTTPS load balancer.

Why this answer

Cloud CDN uses Google's global edge caches to serve content closer to users, reducing latency and backend load. Cloud Armor provides security, Cloud NAT is for outbound connectivity, and VPC peering is for network connectivity, not caching.

73
MCQmedium

A company is migrating a 200 TB on-premises file server to Cloud Storage. The network bandwidth is limited to 100 Mbps. The migration must complete within 30 days. Which approach should they use?

A.Use Storage Transfer Service from another cloud
B.Use gsutil rsync over the network
C.Use Cloud Data Fusion
D.Use Transfer Appliance
AnswerD

At 100 Mbps, transferring 200 TB over the network would take roughly 200 days, far exceeding the 30-day deadline. Transfer Appliance ships data physically via a rackable appliance, sidestepping the bandwidth constraint and completing the migration within the required window.

Why this answer

Transfer Appliance is a physical device shipped to the customer, loaded with data, and shipped back to Google, making it ideal for large datasets (200 TB) over limited bandwidth (100 Mbps). At 100 Mbps, transferring 200 TB would take far longer than 30 days, so a physical transfer method is required.

Exam trap

PCA often tests whether candidates can calculate transfer time versus bandwidth; the trap is choosing an online transfer tool without realizing that 200 TB over 100 Mbps cannot meet a 30-day deadline.

How to eliminate wrong answers

Option A is wrong because Storage Transfer Service from another cloud is designed for online transfers between cloud storage systems and is still constrained by network bandwidth. Option B is wrong because gsutil rsync over the network is also limited by the 100 Mbps link and would take months for 200 TB. Option C is wrong because Cloud Data Fusion is a data integration service for ETL pipelines, not a bulk migration tool for file servers.

74
MCQeasy

A company is adopting Site Reliability Engineering (SRE) practices. After a major incident, they want to conduct a review to understand what went wrong and how to prevent recurrence, without blaming individuals. Which SRE practice should they follow?

A.Define SLOs and SLIs
B.Create an error budget policy
C.Perform capacity planning
D.Conduct a blameless postmortem
AnswerD

A blameless postmortem examines the systemic and process failures behind an incident, documenting contributing causes and corrective actions without attributing fault to individuals. This directly satisfies the stem's dual requirement: understanding what went wrong and preventing recurrence, while preserving the psychological safety that encourages honest reporting.

Why this answer

A blameless postmortem focuses on learning from incidents without assigning blame. Error budgets are for measuring reliability, SLOs/SLIs are for defining targets, and capacity planning is for scaling.

75
Multi-Selecthard

A company runs a latency-sensitive web application on Compute Engine in us-east1. They want to improve response times for users in Europe and Asia without changing the application architecture. Which TWO actions should they take? (Choose 2.)

Select 2 answers
A.Use preemptible VMs to reduce cost
B.Enable Cloud CDN on the load balancer
C.Deploy additional instances in us-west1
D.Create a multi-region load balancer and deploy backends in europe-west1 and asia-east1
E.Use Cloud Armor to block high-latency requests
AnswersB, D

Cloud CDN caches static and cacheable responses at edge points of presence near European and Asian users, cutting round-trip latency to the us-east1 origin. This satisfies the stem's latency goal without altering application architecture, since caching happens transparently at the load balancer layer.

Why this answer

Option B is correct because enabling Cloud CDN on the load balancer caches static and cacheable content at Google's globally distributed edge points of presence, so users in Europe and Asia are served from nearby edge locations instead of being backhauled to us-east1, reducing latency without any application changes. Option D is correct because a multi-region (global external) load balancer with backends in europe-west1 and asia-east1 places compute capacity close to those user populations, and the global anycast VIP routes each user to the nearest healthy backend, directly cutting round-trip time while preserving the existing architecture. Option A is not appropriate because preemptible VMs only reduce cost and can be terminated at any time, which harms latency-sensitive availability rather than improving response times.

Option C does not help because us-west1 is on the US West Coast, which is not closer to European or Asian users than us-east1. Option E is wrong because Cloud Armor is a WAF/DDoS protection service that filters malicious traffic and cannot reduce network latency for legitimate users.

Exam trap

The trap here is that candidates pick cost or security options (preemptible VMs, Cloud Armor) because they sound operationally relevant, missing that the question is strictly about reducing geographic latency for global users.

Ready to test yourself?

Try a timed practice session using only Analysing and Optimising Technical and Business Processes questions.